BAA-RQKS-2015-0008-Atch1.pdf
PDF 49 KB Posted
- Attached to
- Avionics Vulnerability Assessment Mitigation and Protection (AVAMP) Federal contract opportunity
- Solicitation number
- BAA-RQKS-2015-0008
About this file
Basic IDIQ Statement of Objectives
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| BAA-RQKS-2015-0008_Amendment_4.pdf | ||
| BAA-RQKS-2015-0008-Amd3.pdf | ||
| BAA-RQKS-2015-0008-Amd2.pdf | ||
| BAA-RQKS-2015-0008-Amd1.pdf | ||
| BAA-RQKS-2015-0008-Atch8.pdf | ||
| BAA-RQKS-2015-0008.pdf | ||
| BAA-RQKS-2015-0008-Atch7.pdf | ||
| BAA-RQKS-2015-0008-Atch5.pdf | ||
| BAA-RQKS-2015-0008-Atch6.pdf | ||
| BAA-RQKS-2015-0008-Atch4.pdf | ||
| BAA-RQKS-2015-0008-Atch3.pdf | ||
| BAA-RQKS-2015-0008-Atch2.pdf | ||
| BAA-RQKS-2015-0008-IndustryDayQ As.pdf | ||
| BAA-RQKS-2015-0008-IndustryDayBriefing.pdf | ||
| BAA-RQKS-2015-0008-AVAMP-IntroCharts.pdf | ||
| BAA-RQKS-2015-0008-IndustryDayAttendees.pdf | ||
| BAA-RQKS-2015-0008-IndustryDay.pdf | ||
| BAA-RQKS-2015-0008.pdf |
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
BAA-RQKS-2015-0008 Attachment 1
STATEMENT OF OBJECTIVES
BASIC IDIQ
AVIONICS VULNERABILITY ASSESSMENT, MITIGATIONS, AND
PROTECTIONS (AVAMP)
5-19-2015
1.0 BACKGROUND
The Avionics Vulnerability Mitigation branch (AFRL/RYWA) in the Sensors Directorate conducts basic and applied research and advanced development to understand and improve cyber security of
U.S. Air Force (USAF) platforms and weapon systems operating in a contested cyber domain. The activity involves understanding the threat to legacy and future weapon systems, discovering, characterizing, and mitigating cyber vulnerabilities and developing protections against cyber-attack to provide fight-through capability. The Air Force Research Laboratory (AFRL) solicits innovative research proposals to address these needs and to integrate, test, and evaluate developed technologies into the AFRL AVAMP cyber research platform. Performers under this activity will advance the state-of-the-art in USAF systems cyber security, offering novel and innovative approaches to understand and defeat advanced cyber threats and protect our systems so they operate as intended and provide mission assurance to the commander. Some or all elements of the research may be performed at AFRL facilities at Wright-Patterson Air Force Base (WPAFB) or at appropriate contractor facilities. The integration, test, and evaluation will be performed in appropriate facilities at AFRL, WPAFB. (See section 4.0) AFRL seeks and encourages small business participation through teaming arrangements and/or as performers on individual task and subtask research activities.
2.0 OBJECTIVE
The objective of this research program is to investigate and develop methodologies, tools, techniques, and capabilities to identify susceptibilities and mitigate vulnerabilities in avionics systems and to protect those systems against cyber-attack. Responsive research will explore new and emerging concepts related to development, integration, assessment, evaluation, and demonstration of cyber security technologies. Attack vectors of interest include physical, remote, and supply chain access. For this solicitation, avionics is defined to include both manned and remotely piloted vehicles, on-board Intelligence, Surveillance, and Reconnaissance (ISR) systems, munitions, and any equipment, component, or subsystem that could compromise mission assurance of the Air Force weapon system. Mitigation and protection techniques and solutions developed under this program are expected to interface and interoperate with anti-tamper and open avionics system architectures and be applied to a wide-range of associated platforms and in contested environments including but not limited to, electronic warfare systems, space systems, and mobile devices.
Identified technical challenges to accomplish objectives include, but are not limited to, (1) developing automated tools to support avionics vulnerability assessments, (2) developing automated reverse engineering, program understanding and software assurance tools to identify and detect weaknesses in avionics software/firmware/hardware, (3) developing malware detection tools and countermeasures, and (4) developing techniques to detect, respond and adapt to never-before-seen attacks in operationally relevant time scales.
3.0 TECHNICAL REQUIREMENTS
The AVAMP program will develop, mature, and demonstrate avionics cyber vulnerability mitigation and protection technologies to achieve mission assurance. The effort will develop technology plans for research and development to meet the requirements as identified in specific task areas. The program will integrate, test and evaluate these technologies. The program will support research and development in the following areas: (1) Avionics Cyber Vulnerability Characterization, (2) Avionics
Cyber Vulnerability Mitigation Techniques, (3) Automated Software Analysis and Assurance
Techniques, (4) Real-time Cyber Threat Detection and Response for Avionics Systems, (5) Dynamic
Learning and Adaptation for Avionics Protections, and (6) Cyber-Resilient Avionics Systems, each with specific objectives defined within task orders.
3.1 TECHNICAL AREAS
3.1.1 Avionics Cyber Vulnerability Characterization
The objective of this task area is to characterize avionics cyber vulnerabilities, determine their root causes, and create tools that enhance these processes. Avionics cyber vulnerabilities are discovered by conducting vulnerability assessments. These assessments follow AFRL’s rigorous vulnerability assessment process and are aided through the application of tools to increase assessment efficiency and for identifying classes of weaknesses and vulnerabilities. Research to improve established vulnerability assessment processes and techniques are documented and incorporated as best practice.
The results of these assessments are analyzed to determine a taxonomy of vulnerabilities and may be linked to root causes. Many systems and components contribute to the overall state of vulnerability of an avionics system. These systems and major components include items like line replaceable units (LRUs), support equipment, Radio Frequency (RF) interfaces (e.g. transponders, Global
Positioning Satellites (GPS), navigation aids), individual components (e.g., Field Programmable
Gate Arrays (FPGAs), Complex Programmable Logic Device (CPLDs), avionics data & control buses, and software components.) The process of characterization can also include demonstrations of “proof of concepts” or other exploratory activities to more fully understand sources of vulnerability. Other tools may include bus analysis tools, RF fuzzing & evaluation tools, system/component emulators and virtualization, and other tools that permit assessing the cyber strength of avionics systems (Cyber Test & Evaluation).
3.1.2 Avionics Cyber Vulnerability Mitigation Techniques
The objective of this task area is to develop mitigations to multiple classes of avionics cyber vulnerabilities. Applying mitigations may be assisted through the development of automated assistance tools and other techniques to improve the timeliness and affordability of vulnerability mitigations. Other tools under this category include software/firmware authenticity verification
(attestation) and other methods of mitigating cyber vulnerabilities.
3.1.3 Automated Software Analysis and Assurance Techniques
The objective of this task area is to develop advanced automated software analysis tools and protection techniques to prevent exploitation of cyber susceptibilities in avionics systems. The susceptibilities could result from architecture or design choices that did not consider security, latent security defects in the system that were not detected during normal system testing, lack of data validation on input, or the result of intentional insertion of malicious logic. Left undetected, these susceptibilities could potentially disrupt normal execution of the mission software. Since much of the functionality of AF weapon systems is in software, this problem poses a significant risk to survivability and mission success. Current analysis tools are unable to detect all susceptibilities and also generate many false positives. Additionally, these tools primarily operate on source code, not binary code. Lastly, while reverse engineering tools provide some benefit, they require specific expertise to develop, are not robust, and for the most part, do not address real-time embedded system architectures. Thus, a proactive strategy to prevent exploitation of susceptibilities in fielded software is needed. This strategy would include discovery and mitigation of likely attack vectors, remediation of susceptibilities, and safeguards to assure the integrity of embedded software.
Techniques to understand binary code (both static and dynamic), analyze system and software architectures to identify weaknesses, and improved techniques to define and characterize weaknesses are of interest.
3.1.4 Real-time Cyber Threat Detection and Response for Avionics Systems
The objective of this task area is to develop real-time detect and response countermeasures to exploits and protection solutions for malware that target avionics systems. We assume that threat information concerning the targeted avionics system is gathered offline and pre-programmed attack detection and response techniques are developed by human programmers to address these and other unforeseen threats. The threat is assumed to have one or more access paths to the avionics system, including remote access (e.g., via common data links, RF, wireless channels), physical access, or access to the supply chain. The adversary’s goals are to pirate, reverse engineer, or tamper with critical avionics software, firmware, and hardware in order to gain a technological or operational advantage. Both software-only and hardware-assisted anti-exploitation and anti-malware countermeasures and tools are needed in which to securely interrogate or monitor software/firmware execution as well as bus traffic between various avionics system components and provide real-time intelligent response to the threat during mission operations.
3.1.5 Dynamic Learning and Adaptation for Avionics Protections
The objective of this task area is to develop real-time interdependent online learning and adaptation mechanisms that will become elements of future avionics cyber protection systems. Key functions of this technology include: understanding and deciding what information entering and leaving the avionics system with respect to the dynamics of the mission and threat activity is important and needed to improve the effectiveness of the protection system, developing near-term cyber-attack prediction capabilities which compensate for internal processing latencies while minimizing risk to mission critical processes, learning from real-time information not available prior to deployment in order to increase robustness of automated threat response, and adapting protection techniques, prioritization and attention in real-time to prematurely discover never-before-seen attacks. This system must have the capability to detect, classify, and understand unknown malware in avionics software and firmware in order to dynamically adapt our defenses and optimize a response to the threat. A paradigm shift in hardware implementation from current commercial-off-the-shelf (COTS) integrated circuits is required to ultimately achieve the full capability of a robust self-protecting system that entails online adaptability, dynamic learning, and avionics cyber-attack pattern recognition. In summary, this task requires research and development of new hardware/software architectures and implementations that can support a protection system with the capability for autonomous online learning, real-time adaptation, and self-protection to prevent/mitigate never-before-seen attacks.
3.1.6 Cyber-Resilient Avionics Systems
The objective of this task area is to research, develop, and demonstrate avionics protections that are resilient to cyber attack, but do not require the direct detection of the attack to avert mission compromise. Concern over hardware and software supply chain attacks that can compromise avionics systems underscore the need for protections that will provide the ability to operate in the presence of the threat. The quantity and diversity of untrusted COTS hardware and software/firmware components present in an avionics system further necessitates a need for inherent avionics system resiliency. A lack of tools required to analyze, test, and compare inspected parts to known good (i.e., uncompromised) samples non-destructively, together with the inability to fully inspect every component gives rise to questions whether any protection solution designed to keep malware out of the system will be fully effective against a determined adversary. As a result, avionics systems require protections that do not rely on our ability to directly detect malware that might be deeply and subtly embedded in the system. This research area assumes that a subset of the avionics system has been compromised through a supply chain attack or other means and seeks solutions to maintain mission assurance in the presence of these threats.
3.1.7 Test and Integration
The objective of this task area is to integrate techniques and solutions developed as part of this program as well as other solutions developed under separate contracted programs to produce a robust security solution that addresses the requirements of this solicitation. Mitigation and protection techniques and solutions need to address numerous threat vectors targeting avionics systems, and as a result, solutions that address different vulnerabilities will need to be integrated to produce an overall capability demonstration. This task will also apply, integrate, test, and evaluate these solutions relative to specific platforms as designated by AFRL.
3.1.8 Application, Exercise and Field Test
The objective of this task area is to integrate and apply technology as defined above to a prototype, Line Replaceable Unit (LRU), subsystem, system or platform. This technology area is intended to investigate and provide in-depth understanding of the technologies, their performance, and overall impact. Due the nature of the technology areas above, the contractor may be required to participate in technology planning and roadmapping, special field test and evaluation programs, quick deployment and implementation, wargame/exercises, data collection, system engineering, architecture analysis, or training development.
3.1.8.1 This may involve performing one or more areas (listed above) on a system concept(s), research concept(s) or prototype(s). (3600)
3.1.8.2 This may involve performing one or more areas (listed above) on a production unit or system under development. (3010/3080)
3.1.8.3 This may involve performing one or more areas (listed above) on a system or unit currently fielded. (3400)
4.0 PROGRAM/CONTRACT MANAGEMENT
4.1 Administrative Management
The contractor shall exercise program administrative and financial functions during the course of this effort. These functions shall include: scheduling and tracking activities/milestones;
subcontractor management; reporting program status and identifying risks, problems, and mitigation strategies; ensuring deliveries; planning, forecasting, and recommending funding, funding changes, and follow-on efforts; and documenting technical breakthroughs or discoveries. The contractor shall research and development both on-site (i.e., at a Government facility) and off-site (i.e., at the contractor’s facility) as appropriate for each task order.
4.2 Project Status
The contractor shall continually determine the status of the effort and report progress toward the accomplishment of contract requirements. The contractor shall provide in a monthly status report progress-to-date, concerns/issues, and future plans to the AFRL technical point of contact via encrypted electronic mail. Additionally, the contractor shall provide monthly contract funds status reports.
4.3 Technical Reviews
The contractor shall plan and conduct periodic technical review meetings as specified in the contract schedule. The contractor shall ensure contractor, subcontractor(s), AFRL, and other research personnel are invited to these technical reviews.
4.4 Final Report
The contractor shall prepare a final report at the end of each task order under the contract following
AFRL’s latest guidance on final technical reports.
4.5 Security
Ability to access Top Secret / Special Compartmented Information (TS/SCI) and Special Access
Programs. Security procedures shall be in accordance with the Contract Security Classification
Specification (DD Form 254) for this contract.
5.0 DELIVERABLES
Data shall be delivered in accordance with the Contracts Data Requirements List (CDRL) as shown below. Specific hardware/software deliverables will be included in each task order, as applicable.
CDRL
Data Item
Description Delivery Schedule
A001 DI-MISC-80711A/T, Scientific and Technical Reports, Final Report End of Tech Effort
A002 DI-FNCL-80912/T, Performance and Cost Report Monthly A003 DI-FNCL-80331A/T, Funds and Man-Hour Expenditure Report Monthly A004 DI-MISC-80711A/T Spend Plan Monthly A005 DI-MGMT-81468/T, Contract Funds Status Report (CFSR) Quarterly
A006 DI-MGMT-80368A/T, Status Report Monthly A007 DI-ADMN-81373/T, Presentation Material As Required A008 DI-IPSC-81488A/T, Source Code 1 Time A009 DI-MGMT-80507C/T, Project Planning Chart As Generated A010 DI-IPSC-81443A/T, Software User Manual End of Tech Effort A011 DI-MISC-80711A/T Hardware User Manual End of Tech Effort
6.0 OPERATIONAL SECURITY (OPSEC)
General OPSEC procedures, policies and awareness are required in an effort to reduce program vulnerability from successful adversary collection and exploitation of critical information. OPSEC will be applied throughout the lifecycle of the contract. The Critical Information List will be provided upon request by the AFRL Sensors Directorate Information Protection and Intelligence
Office. While working on the government installation, OPSEC will be provided by the AFRL
Sensors Directorate Information Protection and Intelligence Office.
7.0 SAFETY
The contractor shall comply with all Air Force, federal, state, and local safety and environmental regulations. The contractor shall develop an approved Safety Plan (AFI 91-202 AFRL Sup 1) before any experiment is conducted outside of a laboratory environment.
8.0 OTHER REQUIREMENTS
8.1 Government Furnished Property/Equipment (GFP/E)
Any GFP/E required will be specified in each task order. The need for additional GFP/E will be addressed on a case-by-case basis.
8.2 Contractor Acquired Property (CAP)
Any CAP required will be specified in each task order. The need for additional CAP will be addressed on a case-by-case basis.
8.3 Base Support
The Avionics Vulnerability Assessment, Mitigations and Protections (AVAMP) Laboratory is available to the contractor for on-site research. These facilities are state-of-the-art and provide the infrastructure needed to meet government requirements. It consists of space for up to 30 people in
Building 620, Sensors Directorate, Area B, Wright-Patterson AFB OH. Adequate laboratory space/equipment (on a non-interference basis) and computer/network access are included for the purpose of conducting basic , applied and advanced scientific research.
File details come from the government source that posted it. Updated .