Host Based Security System: Difference between revisions

Content deleted Content added
Smash591 (talk | contribs)
m How HBSS works: fixed sentence about heart of HBSS
m clean up, replaced: Air ForceAir Force
Line 1:
{{Orphan|date=June 2011}}
 
The '''Host Based Security System''' ('''HBSS''') is the official name given to the United States [[United States Department of Defense|Department of Defense]] (DOD) [[Commercial off-the-shelf|commercial- off-the-shelf]] (COTS) suite of software applications used within the DOD to monitor, detect, and defend the DOD computer networks and systems. The [[Enterprise-wide Information Assurance and computer Network Defense Solutions Steering Group]] (ESSG) sponsored the acquisition of the HBSS System for use within the DOD Enterprise Network. HBSS is deployed on both the [[NIPRNet|Non-Classified Internet Protocol Routed Network]] (NIPRNet) and [[SIPRNet|Secret Internet Protocol Routed Network]] (SIPRNet) networks, with priority given to installing it on the NIPRNet. HBSS is based on [[McAfee|McAfee, Inc]]'s [[ePolicy Orchestrator]] (ePO) and other McAfee point product security applications such as [[Host Intrusion Prevention System]] (HIPS).
 
== History ==
Seeing the need to supply a comprehensive, department-wide security suite of tools for DOD System Administrators, the ESSG started to gather requirements for the formation of a host-based security system in the summer of 2005. In March 2006, [[BAE Systems]] and McAfee were awarded a contract to supply an automated host-based security system to the department. After the award, 22 pilot sites were identified to receive the first deployments of HBSS.<ref>''Host Based Security System'', http://www.disa.mil/hbss/index.html, 3/13/2010</ref> During the pilot roll out, DOD System Administrators around the world were identified and trained on using the HBSS software in preparation for software deployment across DOD.
 
On October 9, 2007, the [[Joint Task Force for Global Network Operations]] (JTF-GNO) released [[Communications Tasking Order]] (CTO) 07-12 (''Deployment of Host Based Security System (HBSS)'') mandating the deployment of HBSS on all Combatant Command, Service and Agency (CC/S/A) networks within DOD with the completion date by the 3rd quarter of 2008.<ref>''Host Based Security System HBSS)'',[http://www.afcea.org/events/landwarnet/08/infoexchange.asp Host Based Security System HBSS]'', 3/13/2010</ref> The release of this CTO brought HBSS to the attention of all major department heads and CC/S/A's, providing the ESSG with the necessary authority to enforce its deployment. Agencies not willing to comply with the CTO now risked being disconnected from the DOD [[Global Information Grid]] (GIG) for any lack of compliance.
 
Lessons learned from the pilot deployments provided valuable insight to the HBSS program, eventually leading to the [[Defense Information Systems Agency]] (DISA) supplying both pre-loaded HBSS hardware as well as providing an HBSS software image that could be loaded on compliant hardware platforms. This proved to be invaluable to easing the deployment task on the newly trained HBSS System Administrators and provided a consistent department-wide software baseline. DISA further provided step-by-step documentation for completing an HBSS baseline creation from a freshly installed operating system. The lessons learned from the NIPRNet deployments simplified the process of deploying HBSS on the SIPRNet.
Line 15:
* March 27, 2007: The ESSG approved the HBSS for full-scale deployment throughout the DoD enterprise
* October 9, 2007: The [[Joint Task Force for Global Network Operations|JTF-GNO]] releases CTO 07-12
* November, 2009: The [[United States Air Force|Air Force]] awarded [[Northrop Grumman|Northrop Grumman, Inc.]] with the deployment of HBSS on the SIPRNet<ref>Henry Kenyon, ''Northrop Grumman Wins Air Force SIPRNET Contract'',http://www.afcea.org/signal/signalscape/index.php/2009/11/northrop-grumman-wins-air-force-siprnet-contract/, 3/13/2010</ref>
 
== HBSS components ==