DARK WOLF SOLUTIONS, LLC — Department of Defense SBIR Phase I: X224-OCSO1

DARK WOLF SOLUTIONS, LLC — SBIR Phase I award from Department of Defense.

Amount
$73,771
Agency
Department of Defense · Air Force
Program / Phase
SBIR · Phase I
Topic
X224-OCSO1
Solicitation
X22.4
NAICS
Place of performance
VA
Period
2022-11-01 → 2023-02-03

Description

DARK MASS will be delivered as a Software as a Service (SaaS) subscription-based product that provides quick access to vetted product data, a streamlined software procurement workflow, and built-in management and monitoring tools to secure software toolchains. While DARK MASS could replace an entire toolchain management lifecycle, it is modular to integrate with and enhance a customer’s existing processes and systems and can connect with commonly used tools such as JIRA.  DARK MASS consists of two core features: 1. Product Research and 2. Toolchain Management. For the research capability, DARK MASS comprises a library of product and company data, which will be procured through a combination of complex web-scraping and manual inputs and impressions of internal Subject Matter Experts.  Some product data is static and will be scraped from different reliable online sources such as the product website.  Other types of data are more abstract and are considered “expert impressions,” i.e., points of educated opinion from Subject Matter Experts (SME) such as “product is considered low cost,” “considered easy to learn,” or “good for smaller teams.” These abstract data points help provide more meaningful comparisons between products, especially when overlaid with information such as product costs which can vary significantly between environments. Key functions include: Product data will be continually updated and will help inform the Toolchain Management wing of DARK MASS by scraping and monitoring for new products, new license types, and security risks: New product monitoring will scan the internet for products or solutions that may be similar or superior to products currently employed in a customer’s toolchain, with related alerts;  Potential security risks will be identified by scanning the internet for public disclosures of risk in products employed in the customer’s toolchain; Each product within a customer’s toolchain will be categorized based on how critical it is to the software toolchain as a whole: Critical products such as CI/CD and cloud infrastructure will be considered “Toolchain Core” products; Less critical products such as event management and logging tools will be considered “Toolchain Secondary;”  “Supplementary Products” are products that are not directly connected to the deployment itself, such as Slack or JIRA;  Regardless of categorization, DARK MASS will notify and recommend a course of action or contingency product related to a potential security breach.  Both Product Research and Toolchain Management features will be displayed via the DARK MASS user interface. Product Research will comprise details, e.g., product name and  evaluation criteria. The Toolchain Management will focus on toolchain health and status based on the nature of a risk and the types of products it affects within the toolchain. This will create awareness of critical updates and potential security threats or compromises to the toolchain.