RunSafe Security, Inc. — Department of Defense SBIR Phase II: AF193-CSO1

RunSafe Security, Inc. — SBIR Phase II award from Department of Defense.

Amount
$587,697
Agency
Department of Defense · Air Force
Program / Phase
SBIR · Phase II
Topic
AF193-CSO1
Solicitation
DoD SBIR X19.2
NAICS
Place of performance
VA
Period
2020-05-01 → 2021-08-31

Description

Many of the most damaging cyberattacks exploit memory corruption vulnerabilities (e.g. heap overflow, stack overflow). In its September report “Top 25 Most Dangerous Software Errors”, MITRE identified the highest-ranking weakness as CWE-119, buffer overflow. RunSafe Security launched Alkemist in 2018, an automated software transformation tool that hardens code from these types of attacks via a moving-target-defense approach. Rather than hunt down obscure, hard to find bugs, Alkemist removes the underlying construct in software that makes these attacks viable. Our tool is TRL 8 in the commercial market, with implementations and trials on-going with Vertiv, Avocent, Bosch, Samsung, and Qualcomm. Our tool is TRL 6/7 in the DoD market, with initial implementations with NAVWAR and NAVAIR. The proposed SBIR Phase 2 prototype development further aligns the Alkemist tool with Air Force DevSecOps practices. Development focuses on three areas: (1) automating Alkemist application to software delivered in Docker images, (2) launching cyber response of re-hardening software rapidly and automatically if alerted via the Kubernetes sidecar monitoring process, and (3) extending support for ARM 64-bit based embedded systems. In this way, RunSafe contributes to both initial hardening and continuous monitoring, two key Air Force DevSecOps tenets.