SIMVENTIONS INC — Department of Defense SBIR Phase II: A19-080

SIMVENTIONS INC — SBIR Phase II award from Department of Defense.

Amount
$1,099,958
Agency
Department of Defense · Army
Program / Phase
SBIR · Phase II
Topic
A19-080
Solicitation
19.1
NAICS
Place of performance
VA
Period
2020-07-08 → 2022-03-22

Description

There are embedded control systems throughout our combat systems including thousands of Single Board Computers (SBCs) and Programable Logic Controllers (PLCs) installed in various defense systems such as ground based defense, aircraft, land vehicles and combat ships. These systems are typically not connected to a network yet are vulnerable to cyber-attack through various other mechanisms.  There is currently no way to quickly, continuously and easily verify the cyber security stance of these systems.     This Phase II proposal describes Embedded Logic Systems Security Evaluator (ELSSE), a system that is envisioned to provide toolsets to two end-user communities, engineers, and soldiers. Engineers will be able to evaluate and baseline the cybersecurity of an embedded system. Soldiers will be able to quickly plug in a hand held device and get a green/yellow/red indicator of cyber readiness of that equipment.  ELSSE will enable minimally trained technicians the mechanisms to easily verify the hardware and firmware installed in these systems is up to date and has not been tampered with. The mechanisms enabled by ELSSE will also be able to conduct penetration tests against the binary objects running on these devices. The Initial Phase I (six-month) period concluded with the creation of a breadboard-level demonstratable prototype field engineering device and concept of operations that demonstrated tools and techniques that could be extended and matured during Phase II to verify the integrity of firmware, operating system, and applications utilized on embedded systems. The initial effort concentrated on evaluating extraction, modification, and verification of the Basic Input Output System (BIOS) of the Extreme Engineering Solutions (XES) Xpedite 7672 SBC though the SBC JTAG interface.  These techniques are extensible to other common connectors such as USB and Ethernet and higher levels of the software stack.  During Phase I, we were able to apply these techniques to the firmware and software residing at the operating system level. The following components of ELSSE were demonstrated at the six-month mark: Concept of Operations flow and simple demonstration Results of explorations into black box examination of binaries. Techniques for extracting the BIOS from the system for use in scanning and verifying the firmware. Techniques to simplify scanning at the BIOS and Operating System (OS) level for use at the technician level of expertise. Use of inexpensive commodity hardware to create a device that enables a soldier or engineer to quickly and efficiently scan a device for firmware, Operating System, and Application software integrity. Initial design and operation of the ELSSE user interface on a hand-held device.