SETTLETOP INC — Department of Defense SBIR Phase I: AF211-CSO1
SETTLETOP INC — SBIR Phase I award from Department of Defense.
- Amount
- $49,504
- Agency
- Department of Defense · Air Force
- Program / Phase
- SBIR · Phase I
- Topic
- AF211-CSO1
- Solicitation
- X21.1
- NAICS
- —
- Place of performance
- MA
- Period
- 2021-04-13 → 2021-07-19
Description
Software attacks and hacking have become more sophisticated in recent years, but more recently the SolarWinds attack has shown that highly invasive hacking of the software supply chain can go undetected for very long periods of time. In June 2020, SolarWinds, a company that makes IT monitoring and management solutions, experienced a sophisticated supply chain attack from a simple software update that compromised its software build and code signing infrastructure, exposing 18,000 clients and costing the company, Microsoft and US government agencies, including the US Treasury and departments of Homeland Security, State, Defense, and Commerce an estimated $100 billion. This attack will result in one of the most massive breaches of US cybersecurity in recent history. Such events are a vital concern for the United States Air Force (USAF), forcing the need to ensure the highest standards of software assurance, authenticity, integrity and security of their deployed technology assets. To revolutionize the way software assets are secured, deployed, and upgraded requires access to a large dataset of relevant metrics in the end-to-end DevOps process, and currently such a solution is not available to the USAF. To help realize this vision, SettleTop’s team of industry experts in software risk and security continue to build solutions that address the need for software risk assessment in the DOD and commercial arenas. Currently, our platform provides the mechanism to understand how to assess risk of a software asset across the base categories of: Software Quality, Economic Health, Architectural Health, and Open-Source Composition. The SettleTop proposal is to provide a solution that is capable of increasing the USAF’s security rigor by creating a Chain of Authenticity and Integrity that identifies security and vulnerability risks in the entire end-to-end DevOps cycle for the software implementation, build, and deployment phases.