CyberGuardのMLS搭載のCGLinuxって


FireWallアプライアンスのベースに使用されているOSはCGLinuxというMLSが搭載されているLinux
もちろんCCはEAL4+を取得済み。


CGLinuxのWhitePaperはコレ↓
http://www.cyberguard.com/download/white_paper/en_cg_secure_to_the_core.pdf


簡単な解説はコレ↓
http://www.cyberguard.com/company/Fed_Sales/WhyGov.html?lang=de_EN

Platform security - CyberGuard has designed security into the Operating System by incorporating Multilevel Security (MLS) and Mandatory access control (MAC) functions into the application and OS. This goes beyond the normal Harding most vendors perform which is really only involves turning of unnecessary services. The OS is the most vulnerable part of any security device. If a network security device can not protect it self from attack. How can it protect your entire network? See CGLinux OS whitepaper


製品説明はコレ↓
http://www.cyberguard.com/products/firewall/Classic_Family/FS300_600/index.html?lang=de_EN

Multilevel Security
Multilevel security treats each layer of the hardened operating system (OS) discretely, separating network from system levels to provide a virtually impenetrable firewall environment - a unique CyberGuard feature that removes access to the operating system from would-be hackers.


とか、

Certifications
The secure OS was originally designed to meet TCSEC/NCSC criteria at the Orange Book B1 level. Today, FS carries the highest levels of independent, objective security certifications - Common Criteria Evaluation Assurance Level 4+ (EAL4+), ITSEC E3 and VPNC. CyberGuard is the only firewall vendor enrolled in Common Criteria Assurance Maintenance, which protects your investment by ensuring that upgrades retain the original level of certification.


が、セキュアOS関連の解説


CyberGuard社は去年にSecureComputing社に買収されたけど、
SecureComputingのSideWinderで使用されているOSはTEを搭載したSecureOSなので、
アプライアンスで考えるとセキュアOSの導入ってめちゃくちゃ多い。
すでにたくさん導入されていますよって説明したほうがいいのかも。
SELinuxの売り方もアプライアンスからのほうが良さそうなんだけど、SRGateぐらい?
そのうちたくさん出荷されると思うけど。