TERASENSE, INC. — Department of Defense SBIR Phase II: AFX234-DCSO2
TERASENSE, INC. — SBIR Phase II award from Department of Defense.
- Amount
- $1,249,983
- Agency
- Department of Defense · Air Force
- Program / Phase
- SBIR · Phase II
- Topic
- AFX234-DCSO2
- Solicitation
- X23.4
- NAICS
- —
- Place of performance
- MD
- Period
- 2023-02-10 → 2024-08-09
Description
There is an immediate need to confirm the integrity of Kessel Run (KR) software supply chain (IAW EO 14028, Improving the Nation's Cybersecurity) and ensure deployed solutions are secure and function as intended. Kessel Run developers leverage software comprised of different components to enable capabilities for mission outcomes. However, unknown components can cause systems to perform in unexpected ways and open the door to attacks from malicious threat actors (China, Russia). Knowledge of the components and their provenance allows for the AF to conduct risk assessments, identify and address vulnerabilities, and prevent future exposure through hardening. The DAF requires a solution which ensures software supply chain integrity, defines policy early in development cycles, and proactively addresses vulnerabilities. TeraSense, a digital engineering firm advancing mission capability by commercializing modern software solutions, is proposing a research and development effort with Kessel Run to build a prototype security scanning tool which ensures software supply chain security while capturing the Software Bill of Materials (SBOM) early in the software life-cycle. Codenamed Ocelot, the software solution automates the scanning of containerized applications, their environment, and software-at-rest to discover, report, and address vulnerabilities. Ocelot enables Continuous ATO and Certificate to Field with zero-touch deployment in a consistent, continuous, and automated fashion.