Attachment 2 - Task Order 1 SOO.pdf

PDF 181 KB Posted

Attached to
Trusted and Elastic Military Platforms and Electronic Warfare (EW) System Technologies (TEMPEST) Federal contract opportunity
Solicitation number
FA8650-20-S-1958-Call-03
Issued by
Department of the Air Force Materiel Command Research Laboratory

About this file

This Statement of Objectives describes the requirements for a task order to develop cybersecurity technologies to improve the resilience of avionics systems. The scope includes developing tools for assessing and testing avionics vulnerabilities, modeling environments for testing protections, identifying vulnerabilities through reverse engineering, detecting malware, mitigating vulnerabilities through cyber hardening, techniques for detecting and adapting to novel attacks, and securing novel avionics architectures. The contractor will perform tasks such as developing assessment, testing and secure development tools; technologies for mitigating vulnerabilities and cyber hardening; technologies for detecting, responding to and adapting against attacks; and integrating protections for novel systems. The contractor must also demonstrate technologies through experimentation and integrate solutions on relevant test platforms. The Air Force Research Laboratory will provide support including laboratory space and equipment for conducting the work.

View the file

Other files for this federal contract opportunity

Other files attached to Trusted and Elastic Military Platforms and Electronic Warfare (EW) System Technologies (TEMPEST), newest first.
File Type Posted
TEMPEST Call 03 - ODA2 TO2 SOO Amendment 1.pdf PDF
Questions and Answers.pdf PDF
TEMPEST Call 03 Amendment 1.pdf PDF
Attachment 6 - Model Contract.pdf PDF
Attachment 4 - CDRLs.pdf PDF
Attachment 3 - Task Order 2 SOO.pdf PDF
Attachment 5 - DD254.pdf PDF
Call.pdf PDF
Attachment 1 - Basic IDIQ SOO.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Resilient Avionics Development (RAD)

ARPA Task Order 01 ‐ STATEMENT OF OBJECTIVES (SOO)

2 Nov 2020

1.0 OBJECTIVE

The objective of this Task Order is to develop, prototype, and demonstrate various cyber security technologies to protect the avionics in Air Force weapon systems. The security technologies will include: assessment and testing tools, vulnerability mitigation and cyber‐hardening technologies, malware detection and adaptive response techniques, and different technologies to secure open system and agile architecture based platforms.

The overarching goal of these activities is to make legacy and future Air Force Weapon Systems far more resilient to cyber‐attacks.

2.0 SCOPE

The scope of this Task Order consists of the development and demonstration of various technologies that can improve the security and resiliency of legacy and future avionics systems. The scope includes the following cyber security technologies: 1) tools and techniques for avionics vulnerability assessment and testing, 2) modeling and simulation environments and testbeds used to develop and test avionics and cyber protection technologies, 3) reverse engineering and system assurance tools to identify vulnerabilities or malicious logic in software, firmware or hardware, 4) malware detection tools and countermeasures, 5) technologies to mitigate vulnerabilities and cyber‐harden avionics systems, 6) techniques to detect, adapt and react to novel cyber‐ attacks, 7) techniques to develop cyber‐security and resiliency for next‐generation avionics systems and architectures. The scope includes improving the resiliency of avionics at different stages of the acquisition lifecycle from hardening existing legacy systems to designing and integrating cutting‐edge security technologies with future avionics systems and paradigms.

3.0 BACKGROUND

The Air Force (and DoD) needs to rapidly and efficiently field cyber resilient warfighting capabilities to maintain technological advantage in highly contested and consistently changing environments. The purpose of this Task

Order is to research and develop novel cyber security technologies to improve the cyber resiliency of Air Force and DoD platforms. To do so, the Air Force needs to develop different avionics cyber security technologies that can be used to assess and test, cyber‐harden, and improve the cyber‐resiliency of avionics and aircraft platforms. The end goal will be to transition these technologies to legacy and future Air Force platforms to improve security and resilience to potential cyber‐attacks.

4.0 TASKS/TECHNICAL REQUIREMENTS

4.1 Avionics Cyber Assessment, Testing and Development Tools

4.1.1 Tool and Testbed Development

The contractor will develop, mature, or enhance avionics cyber‐security testing tools and testbeds including, but not limited to: tools which automate the process of modeling platform or aircraft system attack surface, threats, and susceptibilities; tools for negative testing and fuzzing avionics systems and sub‐systems; tools that enable testing software in an emulated environment; tools to instrument avionics to observe or collect data regarding cyber effects; testbeds which provide a simulated environmental context for cyber testing; tools to simulate cyber‐attacks or effects on a mission‐level scale; and testbeds to assess or demonstrate the efficacy of developed cyber protections or mitigations. This task includes necessary documentation including User’s

Guides, Design Documents and other AF policy required documents as appropriate.

4.1.2 Secure Development Tools

The contractor will develop, modify, or enhance tools that facilitate automated software testing including security and negative testing during the process of continuous integration/continuous deployment of software. CI/CD introduces ongoing automation and continuous monitoring throughout the lifecycle of software, from integration and testing phases to delivery and deployment. The contractor will investigate tools that facilitate security aspects of system design for the Department of Defense’s (DoD’s) Digital Engineering

(DE) initiative. DE is an integrated digital approach that uses authoritative sources of system data and models as a continuum across disciplines to support lifecycle activities from concept through disposal. Related tools will enhance the security of software developed through these processes. This task includes necessary documentation including User’s Guides, Design Documents and other AF policy required documents as appropriate.

4.2 Avionics Vulnerability Mitigations and Cyber‐hardening Technologies

4.2.1 Mitigation and Cyber‐hardening Technology Development

The contractor will develop, mature, or enhance technologies that reduce weapon system vulnerability to cyber‐attack. Cyber hardening techniques include different methods to remove or mitigate identified system vulnerabilities as well as methods to prevent introduction of malicious elements to the system. Concepts of interest include, but are not limited to: attestation techniques that determine if a system’s software, firmware, or data has been improperly modified before, during or after system start‐up; technologies to secure and authenticate communications over legacy and next‐generation communication protocols within or between weapon system platforms; techniques to prevent the introduction of malicious elements to avionics systems before, during, and after the mission; technologies to prevent unauthorized program execution or data access in avionics sub‐systems; and technologies to enable the secure integration of non‐organic weapons, pods, roll‐ on‐roll‐off equipment, or other systems to the main weapon system platform. This task includes necessary documentation including User’s Guides, Design Documents and other AF policy required documents as appropriate.

4.3 Cyber‐Resilient Technologies

4.3.1 Cyber‐Resilient Technology Development

The contractor will develop, mature, or enhance technologies that counter both known and unknown attacks, including supply chain, remote and insider threat, that occur pre‐flight or are triggered/executed in‐flight, to maintain mission operations in cyber‐contested environments. To achieve cyber resilience, focus should be on developing a defense‐in‐depth strategy with the ability to prevent, mitigate or protect against attacks on critical mission software, operating systems, firmware, hardware, and data. Static and dynamic tools, such as disassemblers, decompilers, and other program analysis tools should be used to detect and mitigate malware implants injected into mission software and firmware. Advanced artificial intelligence, machine learning, genetic/evolutionary algorithms, as well as the corresponding cyber sensors that provide a source of telemetry data to these algorithms, should be developed to detect, diagnose, reason, respond, and adapt to cyber‐ attacks both pre‐flight and in‐flight during mission operations. This task includes necessary documentation including User’s Guides, Design Documents and other AF policy required documents as appropriate.

4.4 Integrated Cyber Technologies for Novel Avionics Systems

4.4.1 Development of Security for Novel Avionics Systems

The contractor will develop, mature, or enhance technologies to secure novel and next‐generation avionics systems and architectures. The focus of this effort will be to mature or integrate known cybersecurity solutions into new aircraft systems and architectures. An emphasis will be made to design and integrate security technologies appropriately to secure next‐generation avionics systems. Topics of interest include, but are not limited to: security of high speed or novel on‐board and off‐board communications systems; real‐time operating systems, hypervisors, or containers that can isolate and secure flexible mission system software applications and mission capabilities; and the secure integration of different Open Systems standards. The contractor will integrate approaches for cybersecurity, and open system/agile architecture technologies with system prototypes. This task includes necessary documentation including User’s Guides, Design Documents and other AF policy required documents as appropriate.

4.5 Collaborative Integration, Experimentation, and Demonstration

4.5.1 Advanced Prototyping, Experimentation, and Demonstration

The contractor will integrate technology solutions and prototype components developed in the previous technical areas of this SOO to conduct collaborative experimentation and demonstrations of innovative capabilities. These experiments and demonstrations will show the efficacy of technologies developed for this

Task Order. Demonstrations will use relevant mission simulations and scenarios. These events may require software/hardware builds, documentation, and testing prior to demonstration. The contractor will participate in third‐party software/subsystem integration with the established test beds within AFRL/RYWA, as needed, to demonstrate the relevant cyber security and resiliency technologies.

4.5.2 Development and Operation of Research Infrastructure, Networks and Platforms

The contractor will develop, operate, and maintain research infrastructure, networks, and platforms as necessary for proper design, development, and evaluation of different avionics security and resilience technologies. Activities may include system backups, commercial software upgrades, and preparations of computer security certification and accreditation packages as appropriate to ensure the networks compatibility and readiness to complete this TO. The contractor will plan, execute, and manage all tasks required to configure the research networks and platforms for evaluation of identified advanced technologies.

The contractor will purchase, develop in‐house, or construct any additional hardware, firmware, or software required for successful completion of this task. This includes, but is not limited to, complying with all requirements for properly processing all acquired, developed, or constructed hardware, firmware, and software. Once configured, the contractor will execute all tests, collect and store associated data, and perform post data processing as requested. The contractor will document and record network descriptions, layouts, and features as appropriate for the type of network or platform under consideration.

4.6 Associate Contractor Agreements

4.6.1 The Contractor shall enter into Associate Contractor Agreements (ACA) for any portion of the contract requiring joint participation in the accomplishment of the Government’s requirement. The agreements shall include the basis for sharing information, data, technical knowledge, expertise, and/or resources essential to the integration of the Resilient Avionics Development program, which shall ensure the greatest degree of cooperation for the development of the program to meet the terms of the contract.

4.6.2 Provide a copy of such agreement to the Contracting Officer for review before execution of the document by the cooperating contractors.

4.6.3 ACAs will include the following general information:

Identify the associate contractors and their relationships.

Identify the program involved and the relevant Government contracts of the associate contractors

Describe the associate contractor interfaces by general subject matter

Specify the categories of information to be exchanged or support to be provided

Include the expiration date (or event) of the ACA.

Identify potential conflicts between relevant Government contracts and the ACA; include agreements on protection of proprietary data and restrictions on employees.

4.6.4 The Contractor is not relieved of any contract requirements or entitled to any adjustments to the contract terms because of a failure to resolve a disagreement with an associate contractor

4.6.5 Liability for the improper disclosure of any proprietary data contained in or referenced by any agreement shall rest with the parties to the agreement, and not the Government

4.6.6 All costs associated with the agreements are included in the negotiated cost of this contract. Agreements may be amended as required by the Government during the performance of this contract.

4.6.7 The following contractors are associate contractors with whom agreements are required.

Contractor Address Program/Contract Number

5.0 MANAGEMENT

5.1 Program Administrative and Financial Functions. The contractor will follow program management processes to administer the program (functionally and financially) including, at a minimum, scheduling and tracking milestones and activities; managing subcontracts and Contract Data Requirements Lists (CDRLs);

reporting program technical, schedule, and cost status; planning, forecasting, and recommending funding or funding changes; and documenting technical breakthroughs or discoveries.

5.2 Management at Various Facilities. The contractor will support R&D on site (i.e., at a government facility) and off site (i.e., at the contractor’s facility), as appropriate.

5.3 Risk Management. The contractor will maintain a risk management process throughout the program identifying, analyzing, assessing, mitigating, and monitoring technical, schedule, and cost risks which will be included as part of the monthly status report.

6.0 DELIVERABLES

Data will be delivered in accordance with the CDRLs, DD Form 1423‐1. The contractor will document all technical work accomplished and information gained during the performance of this acquisition. This documentation will include all pertinent observations, the nature of any problems, positive and negative results, design criteria established (where applicable), procedures followed, processes developed, lessons learned, and so forth. The contractor will document the details of all technical work to permit full understanding of the techniques and procedures used in evolving the technology or processes developed.

Separate design, engineering, or process specifications delivered during this acquisition will be cross‐ referenced to permit a full understanding of the total acquisition. Final software and hardware (including source code, firmware, libraries, and executables) developed on this effort will be delivered, with unlimited rights and with software in a format acceptable to both parties, at the end of the technical period of performance.

7.0 TECHNICAL REVIEWS

The contractor will hold a kickoff meeting at AFRL within 30 days after contract award. The contractor will host quarterly program management reviews and conduct ad hoc reviews as required with the government, stakeholders, and associate contractors. The contractor will involve required contractors, subcontractors, AFRL, and other research personnel as appropriate.

8.0 SECURITY

8.1 Program Security Requirements. In order for individuals to work on classified portions of this effort, the contractor will ensure that all individuals are U.S. citizens, understanding that they may be required to have

SCI DCID 6/4 Top Secret Eligibility based on a SSBI/SBPR. The contractor will require that all SCI and SAP work be conducted within an accredited Special Access Program Facility (SAPF) and/or a Sensitive Compartmented

Information Facility (SCIF). The government will outline specific security details and requirements in future

TOs. The contractor will ensure that all classified efforts comply with National Industrial Security Program

Operating Manual (NISPOM) and other regulations/policies that may apply to this contract, such as Joint Air

Force‐Army‐Navy (JAFAN) 6/0 (Revision 1); DoD Directive 5205.07 (Volumes 1–4); Air Force Manual (AFMAN)

16‐703 V3; SAF/AAZ Memorandum “Air Force Special Access Programs Nomination Process (SAPNP)” (30 Sep

2013); Under Secretary of Defense for Intelligence (USD(I)) Memorandum, “Special Access Programs

Nomination Process” (20 May 2013); JAFAN 6/3 Implementation Guide, Version 1 (Sep 2006); DoD Security

Assistance Policy Coordinating Office (SAPCO) Memorandum, “Transition to the Risk Management Framework

(RMF)” (18 Dec 2013); Joint Special Access Program Implementation Guide (JSIG) (9 Oct 2013); Intelligence

Community Directives (ICDs) 704 and 705; other applicable SCI regulations and policies; other applicable

Security Classification Guides (SCGs); and other applicable regulations/policies and subsequent revisions.

Access to Joint Worldwide Intelligence Communications System (JWICS) is authorized for performance of SCI work, users shall be briefed NATO SECRET IAW the NISPOM, Para 10‐706, prior to access).

8.2 Operational Security (OPSEC). General Operations Security (OPSEC) procedures, policies and awareness are required in an effort to reduce program vulnerability from successful adversary collection and exploitation of critical information. OPSEC will be applied throughout the life cycle of the contract. The Critical Information

List (CIL) and the RY OPSEC Plan will be provided upon request by AFRL/RYOY Information Protection Office.

While working on the government installation, OPSEC guidance and OPSEC training will be provided by

AFRL/RYOY Information Protection Office. This training will ensure contractors are familiar with RY’s CIL and

RY’s OPSEC Plan as it pertains to their contract. The contractor shall apply OPSEC in their management of their current program IAW AFI 10‐701 Operations Security and WPAFB Supplement to AFI‐10‐701.

8.3 Security Training. The contractor will participate in the U.S. Government’s (USG’s) in‐house and web‐based security training program under the terms of the contract. The USG will provide the contractor with access to the online system. The contractor will take specialized security training as deemed applicable by USG.

8.4 Security Duties. The contractor will be required to perform normal services under this contract between the hours of 0600‐1800 excluding Federal Holidays. The contractor shall perform the following security tasks incidental to R&D efforts: End of day security; open, operate and close classified facilities; activate and deactivate alarms which requires access to alarm codes and alarm panel; facilitate access to classified information which will require combinations to locks for safes and doors during normal workhours and extended duty days. This may also include, at the discretion of the government, responsibility for performing after‐hours alarm response which may require 24/7 building access in accordance with AF and DoD requirements. The government maintains the overall responsibility for all security related activities and is incumbent upon the contractor to officially communicate to the government these objectives and requirements have been appropriately completed in a timely and efficient manner.

8.5 Program Protection Plan. All DoD contractors (including subcontractors) shall supplement their current security practices by requiring any personnel involved in executing this contract where critical program information (CPI) has been identified to protect the CPI to the standards articulated in the Program Protection

Plan and in accordance with DoDI 5200.39. Upon contract award, all identified DoD contractors (including subcontractors) shall acknowledge and meet the requirements stated by the Program Manager for the protection of CPI. The DoD contractor must immediately notify the U.S. Government upon the discovery of any nonconformance with CPI protection. Applicable PPPs include, but are not limited to, the following:

“Standards Management Program Protection Plan”, Open Architecture Management Office, Air Force Lifecycle

Management Center (AFLCMC), Wright‐Patterson AFB OH, dated 1 Jan 2019; PlatformNxt (PNxt) Program

Protection Plan (PPP), AFRL/RY, dated 10 May 2018.

9.0 SAFETY

The contractor will comply with all Air Force, federal, state, and local safety and environmental regulations.

The contractor will develop and have an approved Safety Plan (AFI 91‐202 AFRL Sup 1) before any experiment may be conducted outside of a laboratory environment. The contractor will comply with safety requirements contained in MIL‐STD 882E, Section 4, “General Requirements,” for any deliverable system or hardware. The contractor will identify safety‐critical components of those systems or hardware and software interfaces with those components. The contractor will test and verify the safety‐critical hardware and software for safety acceptance.

10.0 BASE SUPPORT

AFRL/RYWA will provide the contractor with laboratory space, equipment (on a non‐interference basis), and computer/network access for conducting this effort, if proposed.

File details come from the government source that posted it. Updated .