BAA-RQKS-2015-0008-Atch3.pdf
PDF 44 KB Posted
- Attached to
- Avionics Vulnerability Assessment Mitigation and Protection (AVAMP) Federal contract opportunity
- Solicitation number
- BAA-RQKS-2015-0008
About this file
Task Order 0002 Statement of Objectives
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| BAA-RQKS-2015-0008_Amendment_4.pdf | ||
| BAA-RQKS-2015-0008-Amd3.pdf | ||
| BAA-RQKS-2015-0008-Amd2.pdf | ||
| BAA-RQKS-2015-0008-Amd1.pdf | ||
| BAA-RQKS-2015-0008-Atch8.pdf | ||
| BAA-RQKS-2015-0008.pdf | ||
| BAA-RQKS-2015-0008-Atch7.pdf | ||
| BAA-RQKS-2015-0008-Atch5.pdf | ||
| BAA-RQKS-2015-0008-Atch6.pdf | ||
| BAA-RQKS-2015-0008-Atch4.pdf | ||
| BAA-RQKS-2015-0008-Atch2.pdf | ||
| BAA-RQKS-2015-0008-Atch1.pdf | ||
| BAA-RQKS-2015-0008-IndustryDayQ As.pdf | ||
| BAA-RQKS-2015-0008-IndustryDayBriefing.pdf | ||
| BAA-RQKS-2015-0008-AVAMP-IntroCharts.pdf | ||
| BAA-RQKS-2015-0008-IndustryDayAttendees.pdf | ||
| BAA-RQKS-2015-0008-IndustryDay.pdf | ||
| BAA-RQKS-2015-0008.pdf |
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
BAA-RQKS-2015-0008 Attachment 3
STATEMENT OF OBJECTIVES
TASK ORDER 0002
Avionics Cyber Vulnerability Mitigations Technologies
5-19-2015
1.0 BACKGROUND
This task order focuses on basic and applied scientific research and advanced development involving cyber, computer, and information security assessment, mitigation, and protection of avionics systems. The research seeks advances in cyber security for USAF computer and information processing systems employed on and directly relevant to the operation of aircraft, remotely piloted platforms, and other existing and future weapon systems. Systems and elements considered include, but are not limited to military and commercial avionics systems, data links, data buses, directly-attached maintenance, test, and support equipment, and other information processing systems found on commercial and military aircraft, weapon systems, satellites, and vehicles.
2.0 SCOPE
This Statement of Objectives (SOO) advances the science of assessing systems for cyber vulnerabilities and research and development of tools, technologies and techniques to mitigate the impact of such vulnerabilities in the context of mission readiness. This task supports the following detailed objectives from the Basic SOO: (1) Avionics Cyber Vulnerability
Characterization, (2) Avionics Cyber Vulnerability Mitigation Techniques, (3) Automated
Software Analysis and Assurance Techniques, and (4) Cyber-Resilient Avionics Systems.
3.0 OBJECTIVES
The objective of this research is to advance the state of the art in discovering, categorizing, and mitigating vulnerabilities in avionics systems in order to increase mission assurance to warfighters operating in a cyber-contested environment. Platforms of interest include, but are not limited to, processors and operating systems associated with real-time embedded systems, data buses and links as they relate to avionics systems, and any support and maintenance equipment that loads data to such systems or otherwise directly impacts their operation. This task will provide realistic and actionable strategies for discovering vulnerabilities in existing systems and approaches to validating the resilience of these systems in a cyber-contested environment. Additionally, vulnerabilities will be characterized such that resources can be judiciously applied towards mitigation efforts with highest impact/return on investment. Having made that determination, mitigations will be developed and employed in realistic settings.
3.1 Avionics System Assessment
The objectives are to research and develop processes, methods, and tools to discover weaknesses and vulnerabilities in avionics systems. Assessing legacy and future cyber systems builds a foundation for discovering and classifying weaknesses and mitigating vulnerabilities through robust techniques. Several aspects of avionics system assessment must be developed, including:
3.1.1 Advanced Reverse Engineering Tools
and vulnerabilities in avionics systems. The focus of this subtask is to develop and apply improved methods to assist artisans with understanding executables, message protocols, and other elements of systems for understanding where weaknesses may exist. This task may include proof of concept threat demonstrations – illustrating the “art of the possible” is important for building understanding of potential threats to cyber systems.
3.1.2 Virtualization Techniques
and vulnerabilities in avionics systems. The focus of this subtask is to develop and apply virtualization and/or emulation technologies to improve the weakness discovery, and to assist artisans with understanding executables, message protocols, and other elements of avionics systems. This task may include proof of concept threat demonstrations – illustrating the “art of the possible” is important for building understanding of potential threats to cyber systems.
3.1.3 Message Fuzzing
The objectives are to research and develop processes, methods, and tools to discover weaknesses and vulnerabilities in avionics systems. The focus of this subtask is to develop and apply message fuzzing techniques over mediums that may include RF data links, avionics/weapon system data buses, and other data passing mechanisms in order to assess the security of avionics systems and discover weaknesses. Testing scenarios include, but are not limited to, black box and white box testing, and developed solutions must consider not only the capability to fuzz interfaces but the capability to determine the effects. This task may include proof of concept threat demonstrations – illustrating the “art of the possible” is important for building understanding of potential threats to avionics systems.
3.1.4 Automated Cyber Vulnerability Assessment
and vulnerabilities in avionics systems. The focus of this subtask is to develop and apply tools and methods to automate testing of developmental avionics systems for cybersecurity and suggest remediation approaches. Objectives may include, but are not limited to, automated analysis of both source and binary executables targeted for avionics systems in order to discover weaknesses. Developed tools and techniques will greatly reduce the burden on cyber testers as they attempt to ensure the cyber security of such systems.
3.2 Vulnerability Characterization
The objectives are to research and develop methods to characterize weaknesses and vulnerabilities in avionics systems. The focus of this task is to:
• Develop and apply a taxonomy to discovered weaknesses and vulnerabilities in avionics systems
• Develop and apply a taxonomy for describing the criticality and severity of discovered weaknesses and vulnerabilities
• Analyze discovered weaknesses and vulnerabilities to determine common causes and criticality
3.3 Vulnerability Mitigation
The objectives are to research and develop methods to mitigate cyber weaknesses and vulnerabilities in avionics systems. The focus of this task is to:
• Develop methods to externally validate the integrity of avionics systems
• Develop methods to verify mitigations effectively combat discovered weaknesses and vulnerabilities
• Develop tools to detect, alert and/or react to anomalous behavior in avionics systems, across a data transport, or in other system elements
• Develop tools and or methods to insure that data inputs to legacy systems are properly formatted and are not “out of bounds”
• Develop tools and/or methods to authenticate data messages to ensure they are sourced by an expected sender
3.4 Cyber Resilient System Development and Test
The objectives are to research and develop processes, methods, and tools to design-in and build-in cyber resilience for avionics systems. This includes developing, operating, and supporting the appropriate test-bed(s) to verify and validate these systems. Several aspects of avionics systems must be addressed for implementing cyber resiliency including:
3.4.1 Securing Avionics Systems Operating Systems
in cyber resilience for avionics systems. This research task applies specifically to securing operating systems relevant to avionics systems. Research areas may include, but are not limited to, processes, methods, and tools that improve the ability to understand and manage data flows, susceptibility analyses, attack trees, and using other architectural understanding tools to reduce vulnerabilities in avionics systems.
3.4.2 Securing Components of Avionics Systems
in cyber resilience for avionics systems. This research task applies specifically to securing integrated circuits (ICs) and components of cyber systems (e.g. FPGAs), data buses and links, and other hardware elements. Research areas may include, but are not limited to, processes, methods, and tools that improve the ability to understand and manage data flows, data links, bus protocols, susceptibility analyses, attack trees, and using other architectural understanding tools to reduce vulnerabilities in avionics systems.
3.4.3 Securing Direct-Attach Support Tools
in cyber resilience for avionics systems. This research task applies specifically to avionics directly-attached support tools (e.g. Portable Aircraft Testers). Research areas may include, but are not limited to, processes, methods, and tools that improve the ability to understand and manage data flows, data links, bus protocols, susceptibility analyses, attack trees, and using other architectural understanding tools to reduce vulnerabilities in avionics systems due to directly-attached support tools.
3.5 Test-Bed Development and Operation
The objectives are to develop, operate, and support the appropriate test-bed(s) to verify and validate the processes, methods, and tools created in this research effort. Test-bed capabilities should include the ability to provide emulation/simulation/stimulation capability for avionics systems (e.g. stimulating avionics systems to exercise them in a “simulated flight” environment).
4.0 PERIOD OF PERFORMANCE
The period of performance for this task order (TO) shall not exceed 39 months, consisting of 36 months for the technical period of performance with an additional 3 months to complete the final report.
5.0 FUNDING PROFILE:
Fiscal Year FY15 FY16 FY17 FY18 TOTAL
3600 funds $100K $2300K $2300K $1700K $6400K
6.0 REPORTING REQUIREMENTS
All data items : A001 through A011 for TO 0002 effort will be required. The contractor may propose additional deliverables as appropriate to the TO.
Contract Data Requirements List (CDRL):
CDRL
Data Item
Description Delivery Schedule
A001 DI-MISC-80711A/T, Scientific and Technical Reports, Final
Report End of Tech Effort
A002 DI-FNCL-80912/T, Performance and Cost Report Monthly
A003 DI-FNCL-80331A/T, Funds and Man-Hour Expenditure Report Monthly
A004 DI-MISC-80711A/T Spend Plan Monthly
A005 DI-MGMT-81468/T, Contract Funds Status Report (CFSR) Quarterly
A006 DI-MGMT-80368A/T, Status Report Monthly
A007 DI-ADMN-81373/T, Presentation Material As Required
A008 DI-IPSC-81488A/T, Source Code 1 Time
A009 DI-MGMT-80507C/T, Project Planning Chart As Generated
A010 DI-IPSC-81443A/T, Software User Manual End of Tech Effort
A011 DI-MISC-80711A/T Hardware User Manual End of Tech Effort
In addition, software (related software for project implementation) and hardware (items such as specially modified equipment) should be delivered under this TO.
7.0 BASE SUPPORT: The Avionics Vulnerability Assessment, Mitigations and Protections
(AVAMP) Laboratory is available to the contractor for on-site research. These facilities are state-of-the-art and provide the infrastructure needed to meet government requirements. It consists of space in Building 620, Sensors Directorate, Area B, Wright-Patterson AFB OH.
8.0 GOVERNMENT FURNISHED PROPERTY (GFP): Contractor should identify any GFP needed to perform the research.
9.0 CONTRACTOR ACQUIRED PROPERTY (CAP): Contractor should identify any CAP needed to perform the research.
10.0 SECURITY CLASSIFICATION: Top Secret / Special Compartmented Information
(TS/SCI) and Special Access Programs. See DD Form 254.
11.0 EXPORT CONTROL: The contractor will be required to generate or require access to export-controlled items.
12.0 OPERATIONAL SECURITY (OPSEC): General OPSEC procedures, policies and awareness are required in an effort to reduce program vulnerability from successful adversary collection and exploitation of critical information. OPSEC will be applied throughout the lifecycle of the contract. The Critical Information List will be provided upon request by the
AFRL Sensors Directorate Information Protection and Intelligence Office. While working on the government installation, OPSEC will be provided by the AFRL Sensors Directorate Information
Protection and Intelligence Office.
13.0 SAFETY: The contractor must comply with all federal, state, and local safety and environmental regulations.
Requires an approved Safety Plan IAW AFI 91-202 AFRL Supplement 1 before any experiment may be conducted. The contractor must comply with all Air Force safety and environmental regulations.
The contractor must comply with system safety requirements contained in MIL-STD 882D, Section 4 “General Requirements” for any deliverable systems or hardware. The contractor must identify safety-critical components of those systems or hardware, and software interfaces with those components. Must test and verify the safety-critical hardware and software for safety acceptance.
File details come from the government source that posted it. Updated .