KRYPTOWIRE, LLC — Department of Homeland Security SBIR Phase II: H-SB018.1-008
KRYPTOWIRE, LLC — SBIR Phase II award from Department of Homeland Security.
Phase II SBIR prototype / development signal
- Phase II is where Department of Homeland Security funds deeper R&D after feasibility. Incumbents with Phase II history are serious competitors on adjacent topics.
- Use this award as past-performance context and to map customer organizations for STRATFI/TACFI-style transition planning.
- Obligated amount $999,950 is consistent with substantial Phase II-scale effort; compare to related awards from the same agency.
- Topic code H-SB018.1-008 links this award to a solicitation family — search the same topic stem for incumbents and recompete timing.
- Amount
- $999,950
- Agency
- Department of Homeland Security
- Program / Phase
- SBIR · Phase II
- Topic
- H-SB018.1-008
- Solicitation
- FY18.1
- NAICS
- —
- Place of performance
- VA
- Period
- 2019-04-16 → 2020-09-30
Description
To address the supply chain threats that stem from vulnerable or malicious software distributed through firmware on mobile and IoT devices via binary firmware images, we propose a scalable, comprehensive, and automated framework to detect firmware-borne threats, both malicious and (un)intentionally insecure, present in Android and iOS devices. We use a workflow encompassing three analysis techniques: forced-path execution, static analysis, and dynamic analysis across multiple software modules and applications. The novelty of our approach is based on its capability to provide analysis of software across different vendors, operating system versions, and applications as opposed to single application testing that has been our aim for previous work on mobile application testing. Being able to identify and trace data and control flow between different applications, the operating system, and back-end services for Android and iOS devices (mobile and IoT) is necessary to uncover code vulnerabilities and threats in the presence of software bundles such as the firmware images. In addition, recognizing that no single binary code analysis approach is without its shortcomings, so we address and complement the shortcomings of each individual approach, by employing a more comprehensive analysis using a diversity of analysis techniques. We detail a feasibility study for the design and implementation of, a novel system that will automatically identify, trigger, and analyze vulnerabilities in firmware. Our goal is to uncover any code vulnerabilities and design errors and their effects by efficiently enumerating and null-fuzzing all statically and dynamically accessible software components on the firmware.