Content deleted Content added
No edit summary |
|||
Line 10:
Lessons learned from the pilot deployments provided valuable insight to the HBSS program, eventually leading to the [[Defense Information Systems Agency]] (DISA) supplying both pre-loaded HBSS hardware as well as providing an HBSS software image that could be loaded on compliant hardware platforms. This proved to be invaluable to easing the deployment task on the newly trained HBSS System Administrators and provided a consistent department-wide software baseline. DISA further provided step-by-step documentation for completing an HBSS baseline creation from a freshly installed operating system. The lessons learned from the NIPRNet deployments simplified the process of deploying HBSS on the SIPRNet.
=== Significant HBSS
* Summer 2005: ESSG gathered information on establishing an HBSS automated system
* March 2006: BAE Systems and McAfee awarded contract for HBSS establishment and deployment
Line 17:
* November, 2009: The [[Air Force]] awarded [[Northrop Grumman|Northrop Grumman, Inc.]] with the deployment of HBSS on the SIPRNet<ref>Henry Kenyon, ''Northrop Grumman Wins Air Force SIPRNET Contract'',http://www.afcea.org/signal/signalscape/index.php/2009/11/northrop-grumman-wins-air-force-siprnet-contract/, 3/13/2010</ref>
== HBSS
Throughout its lifetime, HBSS has undergone several major baseline updates as well as minor maintenance releases. The first major release of HBSS was known as Baseline 1.0 and contained the McAfee ePolicy
As of January, 2011, HBSS is currently at Baseline 4.5, Maintenance Release 2.0 (MR2). MR2 contains the following software:
=== HBSS Baseline 4.5 MR2
{| class="wikitable collapsible" style="width:100%;"
|-
Line 29:
| <div style="height: 500px;overflow:-moz-scrollbars-vertical;overflow-y:auto;">
==== Microsoft
{| class=redtable border=1
|-
! Software
! Version
|-
Line 38:
| 2003 SP2 (5.2.3790)
|-
| Microsoft .NET
| 1.1.4322.2433
|-
| Microsoft .NET
| 2.2.30729
|-
| Microsoft .NET
| 3.2.30729
|-
| Microsoft .NET
| 3.5.30729.1
|-
Line 57:
|}
==== Optional
{| class=redtable border=1
|-
! Software
! Version
|-
| Symantec SEP/SAV
| 1.3, plugin 1.2
|-
| VirusScan Enterprise
| 8.7.0.570 (
|-
| VirusScan Enterprise 8.7
| 8.7.0.195
|-
| VirusScan
| 1.1.0.154
|}
==== SIPRNet-only
{| class=redtable border=1
|-
! Software
! Version
|-
Line 92:
== How HBSS works ==
The heart of the HBSS is the McAfee ePolicy
* Providing a consistent front-end to the point products
* Consolidating point product data for analysis
Line 116:
==== Policy auditor ====
Policy auditor (PA) was introduced in HBSS Baseline 2.0. Policy
==== Assets baseline module ====
Line 122:
==== Rogue system detection ====
The rogue system detector (RSD) component of HBSS is used to provide real-time detection of new hosts attaching to the network. RSD monitors network segments and reports all hosts seen on the network to the ePO Server. The ePO Server then determines whether the system is connected to the ePO server, has a McAfee
==== Device control module/data loss prevention ====
The DCM component of HBSS was introduced in HBSS Baseline 2.0 specifically to address the use of USB devices on DOD
==== Assets publishing service ====
Line 131:
== Obtaining HBSS ==
According to JTF-GNO CTO 07-12, all DOD agencies are required to deploy HBSS to their networks. DISA has made HBSS software available for download on their [[Public key infrastructure|PKI]] protected [https://patches.csd.disa.mil/ patch server]. Users attempting to download the software are required to have a [[
Additionally, HBSS
== Learning HBSS ==
In order to receive and administer an HBSS
== HBSS
The DISA [[
{|
Line 151:
|}
== The
At its current pace, HBSS has been updated several times from the original Baseline 1.0 to the current Baseline 3.0, MR3 version. Within Baseline 3.0, maintenance releases have been introduced every two to four months, bringing better stability and security with each release. HBSS follows McAfee ePO version updates closely and it is expected to continue this trend as ePO is continuously developed.
|