home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: alt.security
- From: hancock@clada.enet.dec.com (Tomas Hancock)
- Subject: Re: Looking for UNIX security products like COPS but commerical
- Message-ID: <1992Jul14.171303.7690@rdg.dec.com>
- Organization: Digital Equipment Corporation
- References: <01050022.ie0rlu@skyline.UUCP>
- Date: Tue, 14 Jul 1992 17:13:03 GMT
-
-
-
-
-
- Gary,
- I have included below the Software Product Description for
- DECinspect Compliance Manager for ULTRIX (also runs on SunOS),
- which performs security reporting on ULTRIX systems. This may also
- be of interest to you.
-
-
- regards,
- Tom Hancock.
-
- ----------------------------cut here------------------------------------------
-
-
-
-
- Software
- Product
- Description
-
- ___________________________________________________________________
-
- PRODUCT NAME: DECinspect[TM] SPD 41.26.00
- Compliance Manager for ULTRIX[TM] Ver-
- sion 2.2
-
- DESCRIPTION
-
- DECinspect Compliance Manager (DECinspect CM) for ULTRIX is a soft-
- ware tool that a security or system manager uses to establish a cus-
- tom security analysis and reporting system to manage the security of
- a network of distributed systems. With this tool, the security man-
- ager can implement and maintain a security standard that is consis-
- tent with corporate security policy for the ULTRIX nodes in the dis-
- tributed computing environment.
-
- Customers can purchase security consulting services for assistance in
- designing and implementing a security analysis and reporting system
- that balances business needs with security requirements. Local Dig-
- ital offices can assist customers in determining the appropriate ser-
- vices for their requirements.
-
- Security managers define tests to examine the settings of the security-
- relevant operating system parameters according to the organization's
- security policy. Using DECinspect CM's menu interface, these tests are
- grouped into inspectors, which are run to test for compliance with the
- security policy.
-
- DECinspect CM provides tests to examine the following categories of
- system settings:
-
- o File and directory protections
-
- o Accounts
-
- o Passwords
-
- DIGITAL April 1992
-
- AE-PM8CA-TE
-
-
-
-
-
- DECinspect[TM] SPD 41.26.00
- Compliance Manager for ULTRIX[TM] Version 2.2
-
- o Network access
-
- - TCP/IP
-
- - DECnet[TM]
-
- - UUCP
-
- - Remote login
-
- - NFS
-
- o Auditing
-
- Inspectors arrange tests hierarchically into subsystems, test collec-
- tions and tests. The system settings that DECinspect CM tests are de-
- fined as parameters to the tests within the inspector. When DECinspect
- CM runs inspectors, it generates the following:
-
- o Reports - DECinspect CM mails reports summarizing the results of
- the inspection to a distribution list specified for each inspec-
- tor.
-
- o Lockdown scripts - DECinspect CM generates lockdown scripts that
- you can use to automatically reset parameters that do not comply
- with the requirements of the inspector.
-
- Note: Lockdown command procedures should never be run without as-
- sessing the impact of parameter changes to system operations. Each
- command in a lockdown command procedure should be examined to make
- sure that the suggested solution is compatible with the particu-
- lar environment.
-
- o Unlockdown scripts - DECinspect CM generates unlockdown scripts that
- can be used to reverse the operation of the corresponding lockdown
- file. DECinspect CM generates a corresponding unlockdown script ev-
- ery time it generates a lockdown script. DECinspect CM also cre-
- ates a corresponding unlockdown log file.
-
-
-
- 2
-
-
-
-
-
- DECinspect[TM] SPD 41.26.00
- Compliance Manager for ULTRIX[TM] Version 2.2
-
- o Tokens - DECinspect CM generates tokens after executing a special
- type of inspector. This inspector is called the Required Inspec-
- tor and is described in the following section. Tokens contain sum-
- maries of the results of the Required Inspector. DECinspect CM trans-
- mits these tokens to a DECinspect SRF node where the information
- is stored in a relational database. Designated users can access this
- information to monitor the security compliance of all the nodes in
- a network.
-
- There are two types of inspectors, the Required Inspector and customized
- inspectors.
-
- The Required Inspector is the inspector that DECinspect CM uses to test
- the compliance of the system to the security baseline in force. It de-
- fines the basic security settings required for compliance with your
- organization's baseline security standard. The DECinspect CM database
- contains one Required Inspector on each system.
-
- Customized inspectors do not generate tokens, but are used by the lo-
- cal system manager for specialized testing.
-
- The following list describes some situations in which customized in-
- spectors could be useful:
-
- o Before executing the Required Inspector - If you copy the Required
- Inspector to a customized inspector, you can test the system's se-
- curity compliance without sending tokens to the DECsrf node. This
- allows you to correct security weaknesses before DECinspect CM per-
- forms an inspection using the Required Inspector.
-
- o After operating system upgrades and installations
-
- o To inspect the system after changes in system software, resources,
- or utilities
-
- o When you discover that a user is accessing the system during un-
- usual hours
-
- o When you discover modifications to file protections that you can-
- not explain
-
- 3
-
-
-
-
-
- DECinspect[TM] SPD 41.26.00
- Compliance Manager for ULTRIX[TM] Version 2.2
-
- o When you suspect security compromises - Inspect the system using
- a customized inspector if daily audit reports reveal suspicious se-
- curity events.
-
- o When you want to check project file and directory permissions - Project
- managers that are responsible for security in their particular area
- can use a customized inspector to check file and directory permis-
- sions for their area.
-
- While DECinspect CM is effective when used alone in small distributed
- systems, managing a large number of nodes is difficult. To solve this
- problem, use DECinspect CM software with DECinspect SRF (Security Re-
- porting Facility) for VMS[TM] software. DECinspect SRF software is de-
- signed to run on one or more nodes to support centralized collection
- and management of compliance information from DECinspect installations
- which can include VMS, ULTRIX and SunOS[TM][1] systems. It provides
- centralized management for distributed DECinspect CM client nodes. DECin-
- spect SRF extracts data from tokens sent by nodes running DECinspect
- CM and maintains this data in a relational database for management re-
- porting. DECinspect SRF can provide management reports for networks
- of ULTRIX, VMS, and SunOS nodes. See SPD 26.N2.00 for more informa-
- tion on managing network security, see the DECinspect SRF Software Prod-
- uct Description.
-
- DECinspect PRODUCTS
-
- The following other DECinspect products are available:
-
- o DECinspect Compliance Manager
-
- o for VMS (SPD 26.N1.00)
-
- o for SunOS (SPD 41.25.00)
-
- o DECinspect Security Reporting Facility (DECinspect SRF) for VMS (SPD
- 26.N2.00)
-
- o DECinspect Intrusion Detector (DECinspect ID) for VMS
-
- ____________________
-
- [1] SunOS is a registered trademark of Sun Microsystems Inc.
-
- 4
-
-
-
-
-
- DECinspect[TM] SPD 41.26.00
- Compliance Manager for ULTRIX[TM] Version 2.2
-
- HARDWARE REQUIREMENTS
-
- System, components, and peripherals as specified in the System Sup-
- port Addendum (SSA 41.26.00-A).
-
- SOFTWARE REQUIREMENTS
-
- For Systems Using Terminals:
-
- ULTRIX Operating System
-
- For Workstations:
-
- ULTRIX Worksystem Software
-
- Refer to the System Support Addendum (SSA 41.26.00-A) for availabil-
- ity and required versions of prerequisite/optional software.
-
- ORDERING INFORMATION
-
- VAX[TM]-Based Systems:
-
- Software Licenses: QL-MLAA*-**
- Software Media: QA-MLAA*-**
- Software Documentation: QA-MLAAA-GZ
- Software Product Services: QT-MLAA*-**
-
- RISC-Based Systems:
-
- Software Licenses: QL-MLBA*-**
- Software Media: QA-MLBA*-**
- Software Documentation: QA-MLBAA-GZ
- Software Product Services: QT-MLBA*-**
-
- * Denotes variant fields. For additional information on available li-
- censes, services and media refer to the appropriate price book.
-
-
-
-
-
- 5
-
-
-
-
-
- DECinspect[TM] SPD 41.26.00
- Compliance Manager for ULTRIX[TM] Version 2.2
-
- SOFTWARE LICENSING
-
- This software is furnished under the licensing provisions of Digital
- Equipment Corporation's Standard Terms and Conditions. For more in-
- formation about Digital's licensing terms and policies, contact your
- local Digital office.
-
- LICENSE MANAGEMENT FACILITY SUPPORT
-
- This Layered Product supports the ULTRIX License Management Facility.
-
- License units for this product are allocated on an unlimited basis.
-
- For more information on the License Management Facility, refer to the
- ULTRIX Operating System Software Product Description (SPD 26.40.xx)
- or the Guide to Software Licensing in the ULTRIX Operating System documentation set.
-
- SOFTWARE PRODUCT SERVICES (SPS)
-
- A variety of service options are available from Digital. For more in-
- formation, contact your local Digital office.
-
- In addition to standard SPS remedial services, consulting services for
- assistance in planning, designing, and implementing a custom security
- analysis and reporting system with the DECinspect CM and DECinspect
- SRF tools are also available. For more information, contact your lo-
- cal Digital office.
-
- SOFTWARE WARRANTY
-
- Warranty for this software product is provided by Digital with the pur-
- chase of a license for the product as defined in the Software Warranty
- Addendum of this SPD.
-
-
-
-
-
-
-
- 6
-
-
-
-
-
- DECinspect[TM] SPD 41.26.00
- Compliance Manager for ULTRIX[TM] Version 2.2
-
-
-
- [TM]The following are trademarks of Digital Equipment Corporation:
- the DIGITAL logo, DEC, DECinspect, DECnet, ULTRIX, VAX, and
- VMS.
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- 7
-
-
-
- --
-
-
- Tomas Hancock Email: hancock@clada.enet.dec.com
- Digital Equipment Corporation.
-
- My opinions are my own and not those of my employer
-
-