RAM LABORATORIES — Department of Defense SBIR Phase I: AF161-079
RAM LABORATORIES — SBIR Phase I award from Department of Defense.
- Amount
- $149,999
- Agency
- Department of Defense · Air Force
- Program / Phase
- SBIR · Phase I
- Topic
- AF161-079
- Solicitation
- 2016.1
- NAICS
- —
- Place of performance
- CA
- Period
- 2016-09-20 → 2016-11-30
Description
ABSTRACT: To address embedded software security challenges found in Cyber Physical Systems, we propose to build a Detecting Embedded Vulnerabilities in Software (DEVIS) toolkit that employs dynamic binary analysis in a manner that (1) better manages the resources of the target system and software being executed, (2) determines and ranks the severity of vulnerabilities found, and (3) targets hardware instruction sets independent of the operating system. The solution uses a combination of selective symbolic execution and taint analysis to determine whether or not a specific vulnerability resides along the path to the state in question. DEVIS then employs an enhanced constraint solver) that uses the dynamic binary analysis-in-the-loop to search for paths that result in severe or high priority vulnerabilities. As results are executed by dynamic binary analysis, metrics for each path will be gathered based on the vulnerability found and the amount of memory and computing power used when detecting it. Next, DEVIS will work with the a constraint solver to determine which paths result in efficient or optimal resource allocation and the identification of the most severe vulnerabilities. Software targets from a variety of embedded processing environments will be used to test the results of DEVIS.; BENEFIT: This project will develop Detecting Embedded Vulnerabilities in Software (DEVIS), a solution for providing binary analysis for detecting security flaws in embedded cyber physical infrastructure supporting machinery and control systems. Such systems can be subverted by malicious insiders, external hackers and/or supply chain threats. Additional security challenges include supply chain issues associated with counterfeit and foreign-developed or foreign-manufactured chipsets used in populating embedded systems. The DEVIS also addresses performance and computing resources challenges associated with the vulnerability detection process, which is a key technical challenge. DEVIS thus addresses the vulnerability management and device vulnerability assessment market segments.While this project is focused on machinery and control systems, the processes and techniques can be adopted to other Cyber Physical environments, including SCADA systems and Smart Grids. Power systems have borne the brunt of Cyber Physical attacks including the Shamoon, Duqu, Flame and Stuxnet viruses that have been used to bring down foreign power generation and refining systems. Adapting DEVIS for power generation enables us to target a fast growing market with known, well-documented problems with cyber attacks. According to a Zpryme Research study, the market for smart grid cyber is expected to grow to $7.25B by 2020. Leading vendors include BAE Systems, IOActive, IBM, Lockheed Martin, ABB Ltd., Siemens, Schneider Electric, Honeywell, Rockwell Automation, GE, and Invensys. RAM Laboratories already has working relationships in place with several of these organizations.