RAM LABORATORIES — Department of Defense SBIR Phase I: The Phase I effort proposes to address the problem of unauthorized and surreptitious data
RAM LABORATORIES — SBIR Phase I award from Department of Defense.
- Amount
- $99,999
- Agency
- Department of Defense · Army
- Program / Phase
- SBIR · Phase I
- Solicitation
- 2010.2
- NAICS
- —
- Place of performance
- CA
- Period
- 2011-01-14
Description
The Phase I effort proposes to address the problem of unauthorized and surreptitious data exfiltration, from cyber network nodes, of sensitive data by malware, and specifically rootkits. The proposed solution takes advantage of virtualization technology and exploits the synergies of in-VM and out-of-VM security mechanisms. The architecture employs a hypervisor that supplies an Untrusted VM or"guest VM"that hosts the user"s OS and web-interface functionalities. A separate,"Trusted VM"houses a hidden address space that contains the executable files and cyber assets that implement the in-VM mechanisms. The in-VM mechanisms form a layered defense by providing three primary modes of protection. These are: (1) correlation of data exfiltration with user and application activity, flagging exfiltrations having no such correlation, (2) performing rootkit detection and (3) key logger detection. The out-of-VM security entails the isolation of these mechanisms within a Trusted VM or an address space hidden from the guest VM. The Trusted VM operates at a higher privilege level than the guest VM"s OS, giving the advantage over malware. The solution is to have a modular architecture for extend-ability, scalability, and interoperability. It supports flexible security configuration via a graphical Administrator interface for specification of security policy.