HP-UX 11i Security

like the foundation of this bridge, the HP-UX OE provides a solid base for your infrastructure

HP-UX is a highly secure commercial UNIX operating system that provides the fortification your business needs to prevail against hacking and cyber attacks.

Whitepaper on HP-UX Security (.pdf)

HP-UX 11i has been submitted for evaluation to the Common Criteria Controlled Access Protection Profile evaluation assurance level EAL4. It is designed to exceed the Trusted Computer System Evaluation Criteria (TCSEC) Class C2 functionality requirements, with notable extensions being access control lists (a Class B3 feature) and boot authentication.

System Security Features and Benefits
Network Security Features and Benefits

System Security

Intrusion Detection System (IDS/9000) is a built-in feature of HP-UX 11i security capabilities, making HP the only systems vendor to offer its own host intrusion detection product. IDS/9000 enhances local host-level security with near-real-time automatic monitoring of> each configured host for signs of potentially damaging intrusions. IDS/9000 continuously monitors for patterns of suspicious activities that suggest security breach or misuse is under way.

When IDS/9000 detects a potential intrusion, it immediately reports an alert to its management station and logs the event in a log file. The IDS/9000 also has the ability to execute any HP-UX command or program so that a response can be triggered immediately without waiting for human intervention. It is also integrated with HP OpenView Vantage Point Operation (VPO) to provide manageability for both security and system management.

HP Virtualvault includes a trusted version of the HP-UX 11i operating system, a securely integrated Web server, and a strictly partitioned Web runtime environment. It is the only trusted and proven Web server platform on the market with no reported successful attacks. Virtualvault protects Web applications and transactions at more than 130 financial institutions in 24 countries with over $7 trillion in total assets, including three of the top five banks in both the U.S. and Japan.

Network Security

HP demonstrates its commitment to network security with HP-UX 11i’s rich set of standards-based and directory-enabled network security features, which enable you to build your business without compromising corporate security.

Directory-Enabled Computing

As your enterprise extends outward to include partners, customers, and suppliers for information sharing and increased collaboration, you need the protection to allow only the right people in. HP provides this added protection through directory-enabled computing with Netscape Directory Server for HP-UX.

Enterprise customers can reduce administration costs with centralized account management and grow your business with the scalability of LDAP using the LDAP-UX integration product. LDAP-UX unleashes the power of the Netscape directory, providing account and configuration management of HP-UX.

Additionally, the flexibility of LDAP-UX unifies authentication, authorization, and management of HP-UX and Windows Active Directory users.

Another authentication solution, PAM_Kerberos, allows you access to any Kerberos Distribution Center so you can become authorized and receive a Kerberos ticket to gain secure access to Kerberos based applications.

System Security Features and Benefits
Security Patch Check
  • Perl script that performs analysis of file sets and patches installed on an HP-UX machine and generates a report of recommended security patches
Stack Buffer Overflow Protection
  • Uses a combination of highly efficient software and existing memory management hardware to protect against both known and unknown stack buffer overflow attacks. Eliminates need to modify a program’s code to get stack buffer overflow protection, unlike other products that require time consuming program modifications, recompilation, or relinking
  • Provides a “trial mode” that assures application owners that it will not interfere with legitimate
    applications
  • Provides a “zone bypass” feature that allows application owners to mark particular binaries as having a legitimate need to execute code located on their stack(s). Programs so marked are exempt from the HP-UX stack buffer overflow protection
Access Control List (ACL)
  • Stores a series of entries that identify specific users or groups and their access privileges for a directory or file
  • Specifies detailed access permissions for multiple users and groups
  • Supports Journaled File System (JFS 3.3)
Generic Security Services
  • Contains all the GSS APIs in RFC 2743 and is Application Programming implemented as C programming language Interface (GSS API) interfaces
  • Provides security services for client/server applications independent of various underlying security mechanisms and communication protocols, including authentication, integrity, and confidentiality services
  • Enables application developers writing secure applications to write code only once, eliminating the need to change it whenever the underlying security mechanism changes
Sendmail-8.9.3
  • Uses the first sendmail release to include antispam rule sets, which give mail administrators significantly more power to reduce spam
Cryptographic Algorithms
  • HP implementations of RSA, AES, DES, and triple-DES cryptographic algorithms use advanced features of assembly language for both PA-RISC 2.0 and IPF, taking full advantage of 64-bit architectures
  • Achieves almost twice the encryption speed of other leading software implementations
Hp-UX Bastille

Bastille, a security-hardening tool, gives
administrators a question-and-answer method
to harden or lock down HP-UX server systems. It
accommodates the various degrees of hardening
required of servers used for Webs, applications,
and databases:

  • Answer security questions
  • Answer usability questions
  • Lock-down appropriate to HP-UX server use
  • Produce a profile script
  • Use the script to harden many servers in the same category

Network Security Features and Benefits
IPSec/9000
  • Provides secure and private communication over the Internet and within the enterprise—without modifying existing applications
  • Incorporates Internet Key Exchange (IKE) as an automated protocol for dynamically negotiating the IPSec parameters. IKE provides dynamic secret key generation and exchange for IPSec and allows for scalability
  • Inter operates with over 25 other IPSec implementations, including Linux and those of Cisco Systems and Microsoft®
IPFilter/9000
  • A stateful inspection host-based firewall system that provides filtering of selected IP traffic into or out of the system
HP-UX Kerberos server
  • Provides key distribution facilities to implement the Kerberos authentication protocol in network-distributed enterprises
  • Provides strong authentication for client/server applications by using secret-key cryptography
  • Enables encryption of all communications to ensure privacy and data integrity
  • Provides the foundation for secure single sign-on to applications and multi-platform resources
HP-UX AAA server
  • Provides authentication, authorization, and accounting services using the RADIUS protocols
  • Enables service providers or enterprises to authenticate users and then account for time and billing use of network services
  • Supports EAP (Extensible Authentication Protocol) for wireless LAN security

Pluggable Authentication Module (PAM)

  • Industry-standard authentication framework gives system administrators the flexibility to choose any authentication service available on the system
  • Allows new authentication service modules to be plugged in and made available without modifying the applications
BIND 9.2.0
  • Provides data integrity and authentication to applications using cryptographic digital signature
  • Prevents non-authorized access to DNS and prevents tampering with name-to-address mapping over the wire
  • Restricts DHCP updates to those authorized to perform them
  • Guarantees the integrity of zone data using digital signatures
HP-UX secure shell

A powerful software-based approach to encrypted
network security:

  • Provides secure remote login
  • Encrypts data sent over the network using SSH-1 or SSH-2 protocols
  • Decrypts data once it reaches its destination

 

Operating Environment Included Designed For
Base/Internet Manageability and security features Web servers, content and front-end servers
Enterprise Basic OE plus resource management features, and features for monitoring, availability, and online data administration Database application and logic servers
Mission Critical Enterprise OE includes HA and workload Management features plus security enhancements Large corporate database servers
Technical Basic OE with optimized performance and scalability Compute-intensive applications

North American Systems has been providing IT solutions, sevices and hardware for over 15 years.

If you want learn more about what we can do for your IT, please contact us at 800-927-7474, or send us an email at sales@nasi.com to get in touch with one of our experienced account executives.

Want to find out more about what North American Systems has to offer?

Fill out the form below, and one of our account executives will follow up with you promptly







Feel free to contact us at 800-927-7474, or email info@nasi.com