U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

Cryptographic Module Validation Program CMVP

Certificate #3878

Details

Module Name
Network Security Platform Sensor NS3100, NS3200, NS5100 and NS5200
Standard
FIPS 140-2
Status
Active
Sunset Date
3/29/2026
Overall Level
2
Caveat
When operated with the tamper evident seals installed as indicated in the Security Policy
Security Level Exceptions
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Module Type
Hardware
Embodiment
Multi-Chip Stand Alone
Description
Network Security Platform products (formerly known as IntruShield) are Intrusion Prevention Systems (IPS) that protect network infrastructures and endpoints from intrusions such as zero-day, DoS, spyware, VoIP, botnet, malware, phishing, and encrypted attacks with highly accurate, enterprise-class risk-aware intrusion prevention. The Network Security Management system manages the sensor deployments and permits the customer to receive real-time network status updates and alerts, implement customized security policies and incident response plans, and perform forensic analysis of attacks.
Tested Configuration(s)
  • N/A
FIPS Algorithms
AES Cert. #C1556
CKG vendor affirmed
CVL Certs. #C1557 and #C1558
DRBG Cert. #C1556
ECDSA Cert. #C1556
HMAC Cert. #C1556
KAS-SSC vendor affirmed
KTS AES Cert. #C1556 and HMAC Cert. #C1556; key establishment methodology provides 128 or 256 bits of encryption strength
KTS AES Cert. #C1556; key establishment methodology provides 128 or 256 bits of encryption strength
RSA Certs. #C1555 and #C1556
SHS Certs. #C1555 and #C1556
Allowed Algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)
Hardware Versions
P/Ns IPS-NS3100 Version 1.00, IPS-NS3200 Version 1.00, IPS-NS5100 Version 1.00 and IPS-NS5200 Version 1.00; FIPS Kit P/N IAC-FIPS-KT2
Firmware Versions
10.1.17.63

Vendor

Trellix
6220 America Center Drive
San Jose, CA 95005
USA

Product Certifications
sec_certs@mcafee.com
Phone: 888-847-8766
Fax: N/A

Validation History

Date Type Lab
3/30/2021 Initial ACUMEN SECURITY, LLC
6/1/2021 Update ACUMEN SECURITY, LLC
6/29/2022 Update ACUMEN SECURITY, LLC