Content deleted Content added
m clean up, typo(s) fixed: counter attacks → counterattacks using AWB |
m clean up spacing around commas and other punctuation fixes, replaced: ,h → , h (2) |
||
(39 intermediate revisions by 31 users not shown) | |||
Line 1:
{{Short description|Department of Defense suite of software applications}}
{{
== History ==
Seeing the need to supply a comprehensive, department-wide security suite of tools for DOD System Administrators, the ESSG started to gather requirements for the formation of a host-based security system in the summer of 2005. In March 2006, [[BAE Systems]] and McAfee were awarded a contract to supply an automated host-based security system to the department. After the award, 22 pilot sites were identified to receive the first deployments of HBSS.<ref>
On October 9, 2007, the [[Joint Task Force for Global Network Operations]] (JTF-GNO) released [[Communications Tasking Order]] (CTO) 07-12 (''Deployment of Host Based Security System (HBSS)'') mandating the deployment of HBSS on all Combatant Command, Service and Agency (CC/S/A) networks within DOD with the completion date by the 3rd quarter of 2008.<ref>
Lessons learned from the pilot deployments provided valuable insight to the HBSS program, eventually leading to the [[Defense Information Systems Agency]] (DISA) supplying both pre-loaded HBSS hardware as well as providing an HBSS software image that could be loaded on compliant hardware platforms. This proved to be invaluable to easing the deployment task on the newly trained HBSS System Administrators and provided a consistent department-wide software baseline. DISA further provided step-by-step documentation for completing an HBSS baseline creation from a freshly installed operating system. The lessons learned from the NIPRNet deployments simplified the process of deploying HBSS on the SIPRNet.
=== Significant HBSS
* Summer 2005: ESSG gathered information on establishing an HBSS automated system
* March 2006: BAE Systems and McAfee awarded contract for HBSS establishment and deployment
* March 27, 2007: The ESSG approved the HBSS for full-scale deployment throughout the DoD enterprise
* October 9, 2007: The [[Joint Task Force for Global Network Operations|JTF-GNO]] releases CTO 07-12
* November, 2009: The [[United States Air Force|Air Force]] awarded [[Northrop Grumman
== HBSS
Throughout its lifetime, HBSS has undergone several major baseline updates as well as minor maintenance releases. The first major release of HBSS was known as Baseline 1.0 and contained the McAfee ePolicy
=== HBSS Baseline 4.5 MR2 components ===
As of January, 2011, HBSS is currently at Baseline 4.5, Maintenance Release 2.0 (MR2). MR2 contains the following software: {| class=
|-
▲==== Microsoft Products ====
▲! Software Application
! Version
|-
Line 38 ⟶ 32:
| 2003 SP2 (5.2.3790)
|-
| Microsoft .NET
| 1.1.4322.2433
|-
| Microsoft .NET
| 2.2.30729
|-
| Microsoft .NET
| 3.2.30729
|-
| Microsoft .NET
| 3.5.30729.1
|-
Line 57 ⟶ 51:
|}
==== Optional
{|
|-
! Software
! Version
|-
| Symantec SEP/SAV
| 1.3, plugin 1.
|-
| McAfee VirusScan Enterprise
| 8.7.0.570 (
|-
| McAfee VirusScan Enterprise 8.7
| 8.7.0.195
|-
| McAfee VirusScan
| 1.1.0.154
|}
==== SIPRNet-only
{|
|-
! Software
! Version
|-
Line 87 ⟶ 81:
| Rollup Extender
| 1.2.8
|}
== How HBSS
The heart of
* Providing a consistent front-end to the point products
* Consolidating point product data for analysis
Line 99 ⟶ 91:
* Ensure application patch compliance
<!----==== Security
The
---->
=== McAfee
McAfee considers a point product to be the individual software applications controlled by the ePO server. The HBSS point products consist of the following:
* Host
* Policy
* Assets
* Rogue
* Device
* Asset
==== Host
The
==== Policy
Policy
==== Assets baseline
The
==== Rogue
The
==== Device
The DCM component of HBSS was introduced in HBSS Baseline 2.0 specifically to address the use of USB devices on DOD
==== Assets
The
== Obtaining HBSS ==
According to JTF-GNO CTO 07-12, all DOD agencies are required to deploy HBSS to their networks. DISA has made HBSS software available for download on their [[Public key infrastructure|PKI]] protected [https://patches.csd.disa.mil/ patch server]. Users attempting to download the software are required to have a [[Common Access Card]] (CAC) and be on a .mil network. DISA provides software and updates free of charge to DOD entities.
Additionally, HBSS
== Learning HBSS ==
In order to receive and administer an HBSS
== HBSS
The DISA Risk Management Executive Office (RE) formerly [[
{|
|Email: disa.tinker.eis.mbx.cdk21-
|-
|[[Defense Switched Network|DSN]]:
|-
|Toll Free:
|}
== The
At its current pace, HBSS has been updated several times from the original Baseline 1.0 to the current Baseline 3.0, MR3 version. Within Baseline 3.0, maintenance releases have been introduced every two to four months, bringing better stability and security with each release. HBSS follows McAfee ePO version updates closely and it is expected to continue this trend as ePO is continuously developed.
== References ==
{{Reflist}}
== External links ==
* [http://www.afcea.org/signal/articles/templates/200904SIGNALConnections.asp?articleid=1909&zoneid=258 End-Point Security Spreads Throughout Military]
* [http://www.afcea.org/
* [http://iase.disa.mil Information Assurance Support Environment]
* [http://www.mcafee.com McAfee, Inc.]
|