{"product_id":11436,"v_id":11436,"product_name":"KlasOS Keel 5.4.0","certification_status":"Certified","certification_date":"2024-07-16T00:00:00Z","tech_type":"Firewall, Network Device","vendor_id":{"name":"Anduril","website":"https://www.klasgroup.com"},"vendor_poc":"Toby Stidham","vendor_phone":"657-791-0983","vendor_email":"tstidham@anduril.com","assigned_lab":{"cctl_name":"Acumen Security"},"product_description":"<p>The TOE is KlasOS Keel 5.4.0 running on the VoyagerVMm, TRX R2 and Voyager VM3.0 platforms (herein referred to as the TOE). It runs the KlasOS Keel 5.4.0 firmware combining both connectivity and local compute capabilities. Network connectivity includes ethernet and SDWAN. Computing and firewall capabilities are combined in one unit. This provides users with cloud connectivity when necessary and local processing power for analytics when there is no backhaul. Administration can be performed locally or over a trusted SSH channel.&nbsp;</p>","evaluation_configuration":"<p style=\"margin: 0in 0in 0in 27pt; font-size: 10pt; font-family: 'Times New Roman', serif;\"><span style=\"font-size: 11.0pt; font-family: Calibri, sans-serif;\">All testing was conducted on the TRX, VM3 and VMM TOE models outlined in the Security Target. The final version of the TOE software running on the devices is KlasOS.keel.v5.4.0rc7.bin. Testing took place at the Acumen Security offices located at 2400 Research Blvd Suite #395, Rockville, MD 20850. Testing occurred from May 2023 through July 2024. </span></p>","security_evaluation_summary":"<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE provides the security functions required by the Collaborative Protection Profile for Network Devices, hereafter referred to as NDcPP v2.2e or NDcPP. In addition, the TOE provides security functions for the PP-Configuration for Network Devices and Stateful Traffic Filter Firewalls. The TOE implements the following security requirements:<em><span style=\"color: red;\"> </span></em></p>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\"><em><span style=\"color: red;\">&nbsp;</span></em></p>\r\n<ul style=\"margin-bottom: 0in; margin-top: 0px;\">\r\n<li style=\"margin: 0in 0in 0in 24px; font-size: 11pt; font-family: Calibri, sans-serif;\">Security Audit (FAU)</li>\r\n<li style=\"margin: 0in 0in 0in 24px; font-size: 11pt; font-family: Calibri, sans-serif;\">Cryptographic Support (FCS)</li>\r\n<li style=\"margin: 0in 0in 0in 24px; font-size: 11pt; font-family: Calibri, sans-serif;\">User Data Protection (FDP)</li>\r\n<li style=\"margin: 0in 0in 0in 24px; font-size: 11pt; font-family: Calibri, sans-serif;\">Firewall (FFW)</li>\r\n<li style=\"margin: 0in 0in 0in 24px; font-size: 11pt; font-family: Calibri, sans-serif;\">Identification and Authentication (FIA)</li>\r\n<li style=\"margin: 0in 0in 0in 24px; font-size: 11pt; font-family: Calibri, sans-serif;\">Security Management (FMT)</li>\r\n<li style=\"margin: 0in 0in 0in 24px; font-size: 11pt; font-family: Calibri, sans-serif;\">Protection of the TSF (FPT)</li>\r\n<li style=\"margin: 0in 0in 0in 24px; font-size: 11pt; font-family: Calibri, sans-serif;\">TOE Access (FTA)</li>\r\n<li style=\"margin: 0in 0in 0in 24px; font-size: 11pt; font-family: Calibri, sans-serif;\">Trusted Path/Channels (FTP)</li>\r\n</ul>","environmental_strengths":"<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The TOE supports local and remote management of its security functions including:</p>\r\n<ul style=\"margin-top: 0in; margin-bottom: 0in;\" type=\"disc\">\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to configure the access banner</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to configure the session inactivity time before session termination or locking</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to update the TOE, and to verify the updates using [<em><u>digital signature</u></em>] capability prior to installing those updates</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to configure the authentication failure parameters for FIA_AFL.1</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to start and stop services</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to modify the behaviour of the transmission of audit data to an external IT entity</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to manage the cryptographic keys</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to configure the cryptographic functionality</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to re-enable an Administrator account</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to set the time which is used for time-stamps</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to configure NTP</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to configure the reference identifier for the peer</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to manage the TOE's trust store and designate X509.v3 certificates as trust anchors</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to import X.509v3 certificates to the TOE's trust store</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to manage the trusted public keys database</li>\r\n<li style=\"margin-top: 0in; margin-right: 0in; margin-bottom: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">Ability to configure firewall rules</li>\r\n</ul>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">&nbsp;</p>\r\n<p style=\"margin: 0in; font-size: 11pt; font-family: Calibri, sans-serif;\">The administrative user can perform all the above security-related management functions.</p>","features":[{"id":3628,"feature_name":"Asymmetric Key Generation"},{"id":3627,"feature_name":"Auditing"},{"id":3643,"feature_name":"Certificate Authentication"},{"id":3644,"feature_name":"Certificate Validation"},{"id":3631,"feature_name":"Cryptographic Hashing"},{"id":3629,"feature_name":"Cryptographic Key Establishment"},{"id":3633,"feature_name":"Cryptographic Signature Generation"},{"id":3634,"feature_name":"Cryptographic Signature Verification"},{"id":3626,"feature_name":"DRBG"},{"id":3639,"feature_name":"DTLS 1.2"},{"id":3636,"feature_name":"DTLS Client"},{"id":3635,"feature_name":"DTLS Server with Mutual Authentication"},{"id":3625,"feature_name":"Firewall"},{"id":3641,"feature_name":"HTTPS Server without Mutual Authentication"},{"id":3630,"feature_name":"Key Destruction"},{"id":3632,"feature_name":"Keyed-hash message authentication"},{"id":3645,"feature_name":"Network Device"},{"id":3646,"feature_name":"SD-WAN"},{"id":3642,"feature_name":"SSH Client"},{"id":3640,"feature_name":"SSH Server"},{"id":3638,"feature_name":"TLS 1.2"},{"id":3637,"feature_name":"TLS Server without Mutual Authentication"}]}