RAM LABORATORIES — Department of Defense SBIR Phase I: The Phase I effort proposes to address the problem of unauthorized and surreptitious data

RAM LABORATORIES — SBIR Phase I award from Department of Defense.

Amount
$99,999
Agency
Department of Defense · Army
Program / Phase
SBIR · Phase I
Solicitation
2010.2
NAICS
Place of performance
CA
Period
2011-01-14

Description

The Phase I effort proposes to address the problem of unauthorized and surreptitious data exfiltration, from cyber network nodes, of sensitive data by malware, and specifically rootkits. The proposed solution takes advantage of virtualization technology and exploits the synergies of in-VM and out-of-VM security mechanisms. The architecture employs a hypervisor that supplies an Untrusted VM or"guest VM"that hosts the user"s OS and web-interface functionalities. A separate,"Trusted VM"houses a hidden address space that contains the executable files and cyber assets that implement the in-VM mechanisms. The in-VM mechanisms form a layered defense by providing three primary modes of protection. These are: (1) correlation of data exfiltration with user and application activity, flagging exfiltrations having no such correlation, (2) performing rootkit detection and (3) key logger detection. The out-of-VM security entails the isolation of these mechanisms within a Trusted VM or an address space hidden from the guest VM. The Trusted VM operates at a higher privilege level than the guest VM"s OS, giving the advantage over malware. The solution is to have a modular architecture for extend-ability, scalability, and interoperability. It supports flexible security configuration via a graphical Administrator interface for specification of security policy.