ASSURED INFORMATION SECURITY, INC. — Department of Defense SBIR Phase I: ABSTRACT: Cloud users should have the ability to fight-through attacks and protect sensit

ASSURED INFORMATION SECURITY, INC. — SBIR Phase I award from Department of Defense.

Amount
$149,974
Agency
Department of Defense · Air Force
Program / Phase
SBIR · Phase I
Solicitation
2014.1
NAICS
Place of performance
NY
Period
2014-06-24 → 2015-03-24

Description

ABSTRACT: Cloud users should have the ability to fight-through attacks and protect sensitive data on cloud infrastructure that they may or may not physically control. The user must be able to deploy these defenses themselves, without any support from the cloud provider. This will ensure that the critical functions of the United States Government and Private Sector do not cease when cloud architectures are compromised. AIS proposes the Resilient Environment for Secure Cloud Execution (RESCuE) technology to address this need. The capability will consist of a kernel driver that remote cloud users can load into a compromised environment. The driver will suspend the compromised operating system and its applications and then install a custom, lightweight operating system. The operating system will then restore critical services by retrieving and executing their binaries in an environment with obfuscated system call tables and anti-forensic techniques. By taking control of the compromised instance, RESCuE technology will disable traditional compromises that occur at the operating system and application level. By employing obfuscated system call tables and anti-forensic techniques it will invalidate the a priori knowledge that lower, infrastructure level attacks typically require to degrade, deceive, and disrupt critical operations. BENEFIT: The RESCuE capability will allow cloud users to fight-through attacks and protect sensitive data on a cloud infrastructure that they may or may not physically control without relying on support from the cloud provider. The technology will provide full protection against attacks at every layer of the cloud infrastructure: eliminating compromises at the kernel or user level of cloud instances and disabling infrastructure level attacks through obfuscation and anti-forensics. The resulting capability will ensure that the United States Government and Private Sector retain control over their cloud instances and that their critical operations do not cease when cloud architectures are compromised.