RAM LABORATORIES — Department of Homeland Security SBIR Phase II: 15.OATS-002
RAM LABORATORIES — SBIR Phase II award from Department of Homeland Security.
- Amount
- $749,994
- Agency
- Department of Homeland Security
- Program / Phase
- SBIR · Phase II
- Topic
- 15.OATS-002
- Solicitation
- DHS SBIR-2015.OATS
- NAICS
- —
- Place of performance
- CA
- Period
- 2015-09-28 → 2017-10-13
Description
Software developers are faced with a variety of security challenges when developing and deploying new systems. The software may be subject to malicious insiders, external threats and supply chain threats that access systems through poor software hygiene or the presence of zero-day vulnerabilities that the vendor is not aware of. While an array of software assurance tools have been developed that audit code at the source code or static binary level, existing tools do not perform dynamic binary analysis with source code checking to assist developers, nor do they provide a drill-down into software libraries to assist supply chain management in gaining a compliance assessment for the entire software solution. To address these shortfalls, this project extends the research and development of RAM Laboratories' Real-Time Application Security Analyzer (RASAR) tool. RASAR currently detects and characterizes security vulnerabilities (including zero-day vulnerabilities) in both under development and 3rd party software through source code analysis and dynamic binary instrumentation. This project will add capabilities to the tool suite that prioritize the vulnerabilities as defined by Common Weakness Enumeration, correlate identified binary vulnerabilities with both vulnerabilities found in the Common Vulnerability Exposure database and available source code flaws, and provide a compliance dashboard that tracks and reports supply chain issues for the user. Additionally, audit results will be visualized by the user through the use of a compliance dashboard. The resulting tool will be integrated within the Software Assurance Marketplace.