RAPIDFORT INC — Department of Defense SBIR Phase I: X224-OCSO1
RAPIDFORT INC — SBIR Phase I award from Department of Defense.
- Amount
- $74,997
- Agency
- Department of Defense · Air Force
- Program / Phase
- SBIR · Phase I
- Topic
- X224-OCSO1
- Solicitation
- X22.4
- NAICS
- —
- Place of performance
- CA
- Period
- 2022-11-02 → 2023-02-04
Description
Software Supply Chain Cyberattacks are increasing in severity and frequency. For example, the number of intentional supply chain attacks is estimated to have increased in industry by 650% in 2021 with 2022’s growth to be on a similar trajectory. A wave of software supply chain attacks is coming particularly in light of the War in Eastern Europe. To meet these new threats a new cybersecurity approach is being mandated that requires unused software to be removed. Developer tools MUST also be removed to comply with new ORA/ABC Cybersecurity requirements. These developer tools if left in software can be used by attackers to move deeper into breached systems as they can be used to inspect the software to discover weaknesses and further vectors of attack. This hacking technique is called “lateral movement” whereby a breach is made and once the hacker is in the infrastructure moves towards the high value target. This mapping of infrastructure requires inspection tools to find weaknesses. RapidFort has developed groundbreaking technology to remove the unused software AND developers tools in minutes. This results in containers free of developer tools, that are 80% smaller, 80% more secure in terms of vulnerability count, that are cheaper to build, patch, and maintain. That boot 300% faster, and use less memory and bandwidth. Ground breaking improvements at a time when they are most needed! RapidFort’s technology is the solution to the software supply chain problem and has been deployed at SpaceForce where it is delivering spectacular results. MOUs for additional licenses and for other features have been signed by PlatformOne, GBSD, LevelUpCodeWorks, SpaceWerx, and RogueBlueSoftware. United States Air Force Nuclear Weapons Center is highly enthusiastic about the solution, and evaluating the technology where it is has been “selected” and at the “confirmation stage” that will occur on 24 August 2024. One key problem now being faced is once the developer tools are removed, the container cannot be inspected in the event there is a production outage. Without the missing tools developers are not able to administer their containers. They are now “blind.” RapidFort has developed a solution whereby a “Hot-Tool-Pack” can be applied whereby the inspection tools can be re-inserted into the software container, used by the developer, and then removed once inspection is completed. This solution is seamless, quick, and highly effectively. This enables the original functionary of the container to be preserved without compromising security. RapidFort has a prototype that is working for Ubuntu based containers but is seeking financial support through this grant to build a proto-type to evaluate efficacy for the technology used in the DAF container reference design that use the UBI8 Operating System, where other hardening has been done.