North American Systems
International
Where Innovation
Meets Solutions
HP-UX is a highly secure commercial UNIX operating system that provides the fortification your business needs to prevail against hacking and cyber attacks.
Whitepaper on HP-UX Security (.pdf)
HP-UX 11i has been submitted for evaluation to the Common Criteria Controlled Access Protection Profile evaluation assurance level EAL4. It is designed to exceed the Trusted Computer System Evaluation Criteria (TCSEC) Class C2 functionality requirements, with notable extensions being access control lists (a Class B3 feature) and boot authentication.
System Security Features and Benefits
Network Security Features and Benefits
Intrusion Detection System (IDS/9000) is a built-in feature of HP-UX 11i security capabilities, making HP the only systems vendor to offer its own host intrusion detection product. IDS/9000 enhances local host-level security with near-real-time automatic monitoring of> each configured host for signs of potentially damaging intrusions. IDS/9000 continuously monitors for patterns of suspicious activities that suggest security breach or misuse is under way.
When IDS/9000 detects a potential intrusion, it immediately reports an alert to its management station and logs the event in a log file. The IDS/9000 also has the ability to execute any HP-UX command or program so that a response can be triggered immediately without waiting for human intervention. It is also integrated with HP OpenView Vantage Point Operation (VPO) to provide manageability for both security and system management.
HP Virtualvault includes a trusted version of the HP-UX 11i operating system, a securely integrated Web server, and a strictly partitioned Web runtime environment. It is the only trusted and proven Web server platform on the market with no reported successful attacks. Virtualvault protects Web applications and transactions at more than 130 financial institutions in 24 countries with over $7 trillion in total assets, including three of the top five banks in both the U.S. and Japan.
HP demonstrates its commitment to network security with HP-UX 11i’s rich set of standards-based and directory-enabled network security features, which enable you to build your business without compromising corporate security.
As your enterprise extends outward to include partners, customers, and suppliers for information sharing and increased collaboration, you need the protection to allow only the right people in. HP provides this added protection through directory-enabled computing with Netscape Directory Server for HP-UX.
Enterprise customers can reduce administration costs with centralized account management and grow your business with the scalability of LDAP using the LDAP-UX integration product. LDAP-UX unleashes the power of the Netscape directory, providing account and configuration management of HP-UX.
Additionally, the flexibility of LDAP-UX unifies authentication, authorization, and management of HP-UX and Windows Active Directory users.
Another authentication solution, PAM_Kerberos, allows you access to any Kerberos Distribution Center so you can become authorized and receive a Kerberos ticket to gain secure access to Kerberos based applications.
| System Security Features and Benefits | |
|---|---|
| Security Patch Check |
|
| Stack Buffer Overflow Protection |
|
| Access Control List (ACL) |
|
| Generic Security Services |
|
| Sendmail-8.9.3 |
|
| Cryptographic Algorithms |
|
| Hp-UX Bastille | Bastille, a security-hardening tool, gives
|
| Network Security Features and Benefits | |
|---|---|
| IPSec/9000 |
|
| IPFilter/9000 |
|
| HP-UX Kerberos server |
|
| HP-UX AAA server |
|
Pluggable Authentication Module (PAM) |
|
| BIND 9.2.0 |
|
| HP-UX secure shell | A powerful software-based approach
to encrypted
|
| Operating Environment | Included | Designed For |
|---|---|---|
| Base/Internet | Manageability and security features | Web servers, content and front-end servers |
| Enterprise | Basic OE plus resource management features, and features for monitoring, availability, and online data administration | Database application and logic servers |
| Mission Critical | Enterprise OE includes HA and workload Management features plus security enhancements | Large corporate database servers |
| Technical | Basic OE with optimized performance and scalability | Compute-intensive applications |