RAM LABORATORIES — Department of Homeland Security SBIR Phase II: 15.OATS-002

RAM LABORATORIES — SBIR Phase II award from Department of Homeland Security.

Amount
$749,994
Agency
Department of Homeland Security
Program / Phase
SBIR · Phase II
Topic
15.OATS-002
Solicitation
DHS SBIR-2015.OATS
NAICS
Place of performance
CA
Period
2015-09-28 → 2017-10-13

Description

Software developers are faced with a variety of security challenges when developing and deploying new systems. The software may be subject to malicious insiders, external threats and supply chain threats that access systems through poor software hygiene or the presence of zero-day vulnerabilities that the vendor is not aware of. While an array of software assurance tools have been developed that audit code at the source code or static binary level, existing tools do not perform dynamic binary analysis with source code checking to assist developers, nor do they provide a drill-down into software libraries to assist supply chain management in gaining a compliance assessment for the entire software solution. To address these shortfalls, this project extends the research and development of RAM Laboratories' Real-Time Application Security Analyzer (RASAR) tool. RASAR currently detects and characterizes security vulnerabilities (including zero-day vulnerabilities) in both under development and 3rd party software through source code analysis and dynamic binary instrumentation. This project will add capabilities to the tool suite that prioritize the vulnerabilities as defined by Common Weakness Enumeration, correlate identified binary vulnerabilities with both vulnerabilities found in the Common Vulnerability Exposure database and available source code flaws, and provide a compliance dashboard that tracks and reports supply chain issues for the user. Additionally, audit results will be visualized by the user through the use of a compliance dashboard. The resulting tool will be integrated within the Software Assurance Marketplace.