Punch Cyber Corp. — Department of Defense SBIR Phase II: SCO 20.3-001
Punch Cyber Corp. — SBIR Phase II award from Department of Defense.
Phase II SBIR prototype / development signal
- Phase II is where Department of Defense funds deeper R&D after feasibility. Incumbents with Phase II history are serious competitors on adjacent topics.
- Use this award as past-performance context and to map customer organizations for STRATFI/TACFI-style transition planning.
- Obligated amount $1,459,803 is consistent with substantial Phase II-scale effort; compare to related awards from the same agency.
- Topic code SCO 20.3-001 links this award to a solicitation family — search the same topic stem for incumbents and recompete timing.
- Amount
- $1,459,803
- Agency
- Department of Defense
- Program / Phase
- SBIR · Phase II
- Topic
- SCO 20.3-001
- Solicitation
- 20.3
- NAICS
- —
- Place of performance
- VA
- Period
- 2021-12-17 → 2023-12-16
Description
PUNCH proposes DCOFlow, a defensive cyber operations (DCO) ML analytic pipeline to train, manage, and deploy a suite of unsupervised ML algorithms that leverage contextual cyber features. DCOFlow fills a current need within ML-based methods used in cyber – to update, monitor, and deploy ML-based analytic methods in a context-aware, dynamic way into different mission environments. DCOFlow is designed to deploy optimized ML-based analytics in multiple cyber operation configurations to include commodity 1U servers, portable analytic workstations, and large-scale distributed computing environments. DCOFlow provides a robust suite of unsupervised ML algorithms using cyber data repositories for continuous training and evaluation. Detections are geared toward coverage of MITRE’s ATT&CK matrix and results are combined using ensemble techniques in order to improve the generated alerts. The resulting is an end-to-end, integrated solution for contextual feature engineering, model training, and delivery of ML-based analytics into cyber operations. DCOFlow provides timely, relevant, accurate, and explainable results via common formats to provide and improve actionable, operational threat detection.