GRAMMATECH INC — Department of Defense SBIR Phase II: SB131-003

GRAMMATECH INC — SBIR Phase II award from Department of Defense.

Amount
$1,500,000
Agency
Department of Defense · Defense Advanced Research Projects Agency
Program / Phase
SBIR · Phase II
Topic
SB131-003
Solicitation
2013.1
NAICS
Place of performance
NY
Period
2014-05-19 → 2017-05-17

Description

Recent studies have shown that embedded systems are extremely vulnerable to security attacks. Some published exploits include remote hijacking of the electronic systems in a modern car and using IP phones and smart televisions to perform covert surveillance of their owners. In this project, we are building a system that removes known vulnerabilities from embedded software and adds protections to prevent exploits of undiscovered vulnerabilities; by integrating with vulnerability detection technology, we will largely automate vulnerability patching, although without formal specifications, some human review will be necessary. Our system uses static rewriting of the software binaries either prior to or after deployment and will integrate with and complement other GrammaTech tools developed under various DoD contracts.The proposed system will operate directly on software binaries, even in the absence of source code or symbol information, applying both to newly developed software and legacy software. The system will be retargetable to different instruction sets to accommodate a variety of embedded systems platforms. To ensure that added protections do not break the functionality of a program, the proposed system will verify that the rewritten program is semantically equivalent to the original program, except for the corrected flaws.