{"product_id":11128,"v_id":11128,"product_name":"Fidelis Network and Fidelis Deception v9.3.3","certification_status":"Certified","certification_date":"2021-04-15T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Fidelis Cybersecurity Inc.","website":"https://www.fidelissecurity.com"},"vendor_poc":"Anubhav Arora","vendor_phone":"1-800-652-4020","vendor_email":"support@fidelissecurity.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>Fidelis Network and Deception monitors network traffic for malicious content coming into the network (intrusion) and for sensitive and secure data leaving the network (extrusion). It operates continuously, observing network traffic as it is perceived on the attached networks. Traffic observed by a Fidelis Network sensor is reassembled into sessions, protocols and applications are identified, and contents are analyzed in order to determine if they contain inappropriate data, based on configured policy rules. When inappropriate content is identified, the sensor takes action as defined by the rule that was triggered, such as alert, prevent, throttle, quarantine, reroute, or whitelist. A rule may invoke several actions for a single violation.</p>\r\n<p>The focus of the evaluation was on functionality meeting the requirements specified in collaborative Protection Profile for Network Devices, Version 2.2e, including: protection of communications between TOE components and between the TOE and trusted external IT entities; identification and authentication of administrators; auditing of security-relevant events; verification of the source and integrity of updates to the TOE; and use of approved cryptographic mechanisms.</p>","evaluation_configuration":"<p class=\"Body\">The Fidelis Network and Deception Target of Evaluation (TOE) is a combination of the following Fidelis components in a distributed deployment:</p>\r\n<p class=\"Body\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Fidelis Network v9.3.3 CommandPost management console</p>\r\n<p class=\"Body\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Fidelis Network Collector v9.3.3</p>\r\n<p class=\"Body\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Fidelis Network Sensor component v9.3.3</p>\r\n<p class=\"Body\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Fidelis Sandbox appliance v9.3.3</p>\r\n<p class=\"Body\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"><!-- [if !supportLists]--><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\">&middot;<span style=\"font: 7.0pt 'Times New Roman';\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]-->Decoy Server appliance v9.3.3.</p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">The CommandPost, Collector, Sensor, and Decoy Server components are outlined in the following table:</span></p>\r\n<table class=\"MsoTableGrid\" style=\"border-collapse: collapse; border: none; height: 740px;\" border=\"1\" width=\"729\" cellspacing=\"0\" cellpadding=\"0\">\r\n<thead>\r\n<tr style=\"mso-yfti-irow: 0; mso-yfti-firstrow: yes; page-break-inside: avoid;\">\r\n<td style=\"width: 155.8pt; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; background: #B8CCE4; mso-background-themecolor: accent1; mso-background-themetint: 102; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">Component</span></strong></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #B8CCE4; mso-background-themecolor: accent1; mso-background-themetint: 102; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">Appliance Models (Revision J)</span></strong></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border: solid windowtext 1.0pt; border-left: none; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; background: #B8CCE4; mso-background-themecolor: accent1; mso-background-themetint: 102; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">Virtual Models</span></strong></p>\r\n</td>\r\n</tr>\r\n</thead>\r\n<tbody>\r\n<tr style=\"mso-yfti-irow: 1;\">\r\n<td style=\"width: 155.8pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">CommandPost</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">CommandPost appliance</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">CommandPost VM</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 2;\">\r\n<td style=\"width: 155.8pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">Collector</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Collector SA2</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Collector XA2</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Collector XA4</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Collector Controller 2</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Collector Controller 10G</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Collector SA VM</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 3;\">\r\n<td style=\"width: 155.8pt; border-top: none; border-left: solid windowtext 1.0pt; border-bottom: none; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">Sensor</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Direct 50</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Direct 100</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Direct 250</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Direct 500</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Direct 1000</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Direct 2500</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Direct 5000</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Direct 10G</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Direct VM</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 4;\">\r\n<td style=\"width: 155.8pt; border-top: none; border-left: solid windowtext 1.0pt; border-bottom: none; border-right: solid windowtext 1.0pt; mso-border-left-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">&nbsp;</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Internal 1000</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Internal 2500</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Internal 5000</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Internal 10G</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Internal VM</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 5;\">\r\n<td style=\"width: 155.8pt; border-top: none; border-left: solid windowtext 1.0pt; border-bottom: none; border-right: solid windowtext 1.0pt; mso-border-left-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">&nbsp;</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Web</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Web VM</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 6;\">\r\n<td style=\"width: 155.8pt; border: solid windowtext 1.0pt; border-top: none; mso-border-left-alt: solid windowtext .5pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">&nbsp;</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Mail 250</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Mail 500</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Mail 1000</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Mail 5000</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Mail VM 250</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Mail VM 500</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Mail VM 1000</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Mail VM 5000</span></p>\r\n</td>\r\n</tr>\r\n<tr style=\"mso-yfti-irow: 7; mso-yfti-lastrow: yes;\">\r\n<td style=\"width: 155.8pt; border: solid windowtext 1.0pt; border-top: none; mso-border-top-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\">Decoy Server</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Decoy Server</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">FDH-3000</span></p>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">FDH-1000</span></p>\r\n</td>\r\n<td style=\"width: 155.85pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; mso-border-top-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt;\" valign=\"top\" width=\"208\">\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 3.0pt 0in;\"><span style=\"font-family: 'Times',serif; mso-fareast-font-family: 'Times New Roman';\">Decoy Server VM</span></p>\r\n</td>\r\n</tr>\r\n</tbody>\r\n</table>\r\n<p class=\"MsoNormal\" style=\"line-height: normal; margin: 3.0pt 0in 6.0pt 0in;\"><span style=\"mso-fareast-font-family: 'Times New Roman';\"><br />The Sandbox component is available in a single appliance form factor.</span></p>","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the TOE was judged are described in Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 5.&nbsp;The evaluation methodology used by the evaluation team to conduct the evaluation is Common Methodology for Information Technology Security Evaluation, Version 3.1 revision 5. The product, when delivered and configured as described in the guidance documentation, satisfies all of the security functional requirements stated in the&nbsp;Fidelis Network v9.3.3 Security Target. The project underwent CCEVS validation team review. The evaluation was completed in March 2021. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: normal;\"><strong><em style=\"mso-bidi-font-style: normal;\"><span style=\"color: black;\">Security Audit</span></em></strong></p>\r\n<p class=\"Body\">The TOE generates audit records of security relevant events. Generated audit records include the date and time of the event, the event type, the subject identity and the outcome of the event. For audit events resulting from the actions of identified users, the identity of the user is recorded in the generated audit record. The TOE can be configured to store audit records locally on the CommandPost appliance so they can be accessed by an administrator and can also be configured to export the audit records to an external audit server.</p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: normal; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Cryptographic Support</em></strong></p>\r\n<p class=\"Body\">The TOE is operated in FIPS mode and includes an OpenSSL cryptographic module with CAVP approved algorithms. The module provides key management, random bit generation, encryption/decryption, digital signature and cryptographic hashing and keyed-hash message authentication features in support of higher level cryptographic protocols, including TLS and HTTPs.</p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: normal; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Communication</em></strong></p>\r\n<p class=\"Body\">The TOE is deployed as a distributed configuration. Initial configuration for each of the appliances is performed by directly attaching a keyboard and monitor to the appliance. The System Setup is used to set network parameters and certificate files. After initial configuration and connection of each appliance to the network, the administrator adds each appliance to CommandPost to register them. After registration, CommandPost communicates to each newly registered appliance at its configured IP address using TLS.</p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: normal; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Identification and Authentication</em></strong></p>\r\n<p class=\"Body\">The TOE requires users (i.e., administrators) to be successfully identified and authenticated before they can access any security management functions available in the TOE. Administrators manage the TOE remotely using the CommandPost web-based GUI accessed via HTTPS or locally using the CLI by a directly connected USB keyboard and a monitor to the appliance VGA connector. The TOE supports the local (i.e., on device) definition of administrators with usernames and passwords on all of the TOE components. Additionally, the TOE can be configured to authenticate remote administrators to use the services of trusted LDAP servers in the operational environment..</p>\r\n<p class=\"Body\">The TOE can detect when a configurable number of failed remote authentication attempts has been made. When the configured number of unsuccessful authentication attempts has been reached, the remote administrator is locked out until a local administrator resets the password. If all remote administrators are locked out, the CommandPost can be accessed by the default admin account, thus preventing any condition where no administrator access is available.</p>\r\n<p class=\"Body\">The TOE supports the local (i.e., on device) definition of administrators with usernames and passwords. Passwords can be composed of any combination of upper and lower case letters, numbers, and the following special characters: &ldquo;!&rdquo;, &ldquo;@&rdquo;, &ldquo;#&rdquo;, &ldquo;$&rdquo;, &ldquo;%&rdquo;, &ldquo;^&rdquo;, &ldquo;&amp;&rdquo;, &ldquo;*&rdquo;, &ldquo;(&ldquo;, &ldquo;)&rdquo;, blank space, &ldquo;~&rdquo;, &ldquo;`&rdquo;, &ldquo;_&rdquo;, &ldquo;+&rdquo;, &ldquo;-&ldquo;, &ldquo;=&rdquo;, &ldquo;{&ldquo;, &ldquo;}&rdquo;, &ldquo;|&rdquo;, &ldquo;[&ldquo;, &ldquo;]&rdquo;, &ldquo;:&rdquo;, &ldquo;;&rdquo;, &ldquo;&lt;&rdquo;, &ldquo;&gt;&rdquo;, and &ldquo;/&rdquo;. The administrator can configure a minimum password length, which can be set to any length from 1 to 999 characters including 15.</p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: normal; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Security Management</em></strong></p>\r\n<p class=\"Body\">Administrators manage the TOE remotely using the CommandPost web-based GUI accessed via HTTPS or locally through the Command Line Interface using a keyboard and a monitor directly connected<span style=\"mso-spacerun: yes;\">&nbsp; </span>to the appliance&rsquo;s VGA connector.</p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: normal;\">The TOE also provides the ability to manage the TOE locally using the CLI by directly attaching a keyboard and monitor to the appliance. However, the TOE is designed to be managed using the CommandPost GUI from a remote HTTPS/TLS client. Following the initial configuration, all changes should be performed by an authorized user from CommandPost. The TOE provides the System Administrator role which corresponds to the [CPP_ND_V2.2E] Security Administrator.</p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: normal; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Protection of the TSF</em></strong></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: 11.0pt; mso-layout-grid-align: none; punctuation-wrap: simple; text-autospace: none; vertical-align: baseline;\"><span style=\"mso-fareast-font-family: SimSun;\">In the distributed deployment, the TOE protects communication between its components using HTTPS/TLS.</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: 11.0pt; mso-layout-grid-align: none; punctuation-wrap: simple; text-autospace: none; vertical-align: baseline;\"><span style=\"mso-fareast-font-family: SimSun;\">The TOE protects sensitive data such as stored passwords and cryptographic keys so that they are not accessible even by an administrator. The TOE includes a hardware-based real-time clock that in conjunction with an NTP server in the operational environment ensures that reliable time information is available (e.g., for log accountability).</span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: 11.0pt; mso-layout-grid-align: none; punctuation-wrap: simple; text-autospace: none; vertical-align: baseline;\"><span style=\"mso-fareast-font-family: SimSun;\">The TOE includes a suite of power on self-tests that confirm the integrity of the TOE software and demonstrate correct operation of the TOE at start up. </span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: normal; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><span style=\"mso-fareast-font-family: SimSun;\">The TOE verifies the integrity of updates to the TOE&rsquo;s software and firmware prior to installation by calculating a cryptographic hash of the update and allowing the administrator to confirm its correctness against a hash value published by Fidelis. </span></p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: normal; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">TOE Access</em></strong></p>\r\n<p class=\"Body\">The TOE can be configured to display an administrator-defined advisory banner before establishing an administrative user session and to terminate both local and remote interactive sessions after a configurable period of inactivity. It also provides users the capability to terminate their own interactive sessions.</p>\r\n<p class=\"MsoNormal\" style=\"margin-bottom: 6.0pt; line-height: normal; page-break-after: avoid; mso-layout-grid-align: none; text-autospace: none;\"><strong style=\"mso-bidi-font-weight: normal;\"><em style=\"mso-bidi-font-style: normal;\">Trusted Path/Channels</em></strong></p>\r\n<p class=\"Body\">The TOE protects interactive communication with remote administrators using HTTPS.</p>\r\n<p class=\"Body\">The TOE uses TLS v1.2 to protect communications with the following external IT entities: audit server; authentication server; Fidelis Insight Server.</p>","features":[]}