GRAMMATECH INC — Department of Defense SBIR Phase I: SB161-004

GRAMMATECH INC — SBIR Phase I award from Department of Defense.

Amount
$150,000
Agency
Department of Defense · Defense Advanced Research Projects Agency
Program / Phase
SBIR · Phase I
Topic
SB161-004
Solicitation
2016.1
NAICS
Place of performance
NY
Period
2016-06-09 → 2017-07-19

Description

Software is riddled with critical vulnerabilities, many of which are exploited to pave way for malware payloads, leading to serious repercussions. Modern software is often a complexcombination of components, typically including third-party code, providing a vast attack surface that is becoming increasing difficult to defend.We propose a project called X-Discover which aims to find known critical bugs in a software ecosystem utilizing big code. We aim to leverage knowledge from known exploits and vulnerabilities, and apply a combination of programming language and statistical techniques to efficiently find whether a given code base has any known exploitable vulnerability. To do this, we will curate a database of critical vulnerabilities,and extract relevant parts of the binary for each vulnerability. Then, for each vulnerability, a variety of relevant semantic code features that bring out identifying characteristics are extracted; a large code corpus is employed to learn parameters and thresholds necessary to effectively search binary code for the curated bugs. The search results are validated and fed back into the curated database to improve search parameters. This infrastructure is evolved into a tool capable of scanning semantic patterns in software ecosystems to quickly find known high-risk bugs.