ATC-NY INC — Department of Defense SBIR Phase I: A16-098

ATC-NY INC — SBIR Phase I award from Department of Defense.

Amount
$99,918
Agency
Department of Defense · Army
Program / Phase
SBIR · Phase I
Topic
A16-098
Solicitation
2016.2
NAICS
Place of performance
NY
Period
2016-11-07 → 2017-05-06

Description

Automated software assurance tools are critical for finding vulnerabilities or malicious code in Commercial Off The Shelf (COTS) software and systems, but current tools do not address the threats posed by modern, heterogeneous runtime systems such as distributed/cloud computing or Graphics Processing Unit (GPU) accelerated code. Many tools require source code access, which may not be available. Existing tools also focus on specific software modules (akin to unit testing) or attack methods (e.g., fuzz testing) and do not provide the context needed to evaluate alerts. The result is that many alerts are false alarms or go unheeded, while critical problems are not appropriately emphasized. To address this need, ATC-NY will design and build SEASHORE, a software assurance tool for heterogeneous runtime environments. SEASHORE uses function call and API hooking to detect misuse or unexpected call sequences, via rules and machine learning techniques, then unifies the results of this analysis with external probes, configuration tests, and third-party tools in a hierarchical risk model. In doing so, SEASHORE helps the security analyst discover vulnerabilities and potentially malicious code in GPU-accelerated COTS software, then determine the risks those vulnerabilities pose to mission success.