GRAMMATECH INC — Department of Defense SBIR Phase II: SB153-003

GRAMMATECH INC — SBIR Phase II award from Department of Defense.

Amount
$1,499,999
Agency
Department of Defense · Defense Advanced Research Projects Agency
Program / Phase
SBIR · Phase II
Topic
SB153-003
Solicitation
15.3
NAICS
Place of performance
NY
Period
2017-03-21 → 2020-05-31

Description

GrammaTech proposes Bug-Injector, a tool for generating cyber defense evaluation benchmarks through the injection of vulnerable code into existing host software. Bug-Injector is highly configurable, providing users the transparency required of a tool used to compare commercial products and perform security audits, and the customizability to enable focused evaluation of specific defensive tools, host programs, domains, and vulnerability classes. Bug-Injector is implemented independently of leading cyber defensive techniques, thus avoiding the potential circularity in which technical shortcomings limit the generated benchmark used to evaluate those very same techniques. Bug-Injector works by iteratively injecting vulnerabilities into a host program while simultaneously modifying, i.e. "mutating," the program to enable subsequent injections and camouflage previous injections. This process is guided using an evolutionary computation (EC) algorithm that favors candidate programs approximating a target vulnerability distribution and retaining syntactic and functional similarity to the original program.GrammaTech proposes Bug-Injector, a tool for generating cyber defense evaluation benchmarks through the injection of vulnerable code into existing host software. Bug-Injector is highly configurable, providing users the transparency required of a tool used to compare commercial products and perform security audits, and the customizability to enable focused evaluation of specific defensive tools, host programs, domains, and vulnerability classes. Bug-Injector is implemented independently of leading cyber defensive techniques, thus avoiding the potential circularity in which technical shortcomings limit the generated benchmark used to evaluate those very same techniques. Bug-Injector works by iteratively injecting vulnerabilities into a host program while simultaneously modifying, i.e. "mutating," the program to enable subsequent injections and camouflage previous injections. This process is guided using an evolutionary computation (EC) algorithm that favors candidate programs approximating a target vulnerability distribution and retaining syntactic and functional similarity to the original program.