HR001117S0050-Amendment-01.pdf

PDF 835 KB Posted

Attached to
Active Social Engineering Defense (ASED) Federal contract opportunity
Solicitation number
HR001117S0050
Issued by
Defense Advanced Research Projects Agency

About this file

Not Listed

View the file

Other files for this federal contract opportunity

Other files attached to Active Social Engineering Defense (ASED), newest first.
File Type Posted
HR001117S0050-Amendment-02.pdf PDF
HR001117S0050.pdf PDF
ASED_BAA_proposal_LoE_table_template_-_SkillSets.xlsx XLSX spreadsheet
ASED_BAA_Attachment_Proposal_Summary_Chart_Template.pptx PPTX presentation

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Broad Agency Announcement Active Social Engineering Defense (ASED)

HR001117S0050

September 8, 2017

Amendment 1

Amended on October 10, 2017

Defense Advanced Research Projects Agency Information Innovation Office 675 North Randolph Street Arlington, VA 22203-2114

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 2

Table of Contents

I. Funding Opportunity Description

A. Introduction/Background

B. Program Description/Scope

C. Program Structure

D. Government-furnished Property/Equipment/Information

E. Program Metrics and Targets

F. Intellectual Property

II. Award Information

A. Awards

B. Fundamental Research

C. Disclosure of Information and Compliance with Safeguarding Covered Defense Information Controls

III. Eligibility Information

A. Eligible Applicants

B. Organizational Conflicts of Interest

C. Cost Sharing/Matching

D. Other Eligibility Requirements

IV. Application and Submission Information

A. Address to Request Application Package

B. Content and Form of Application Submission

C. Submission Dates and Times

D. Funding Restrictions

E. Other Submission Requirements

V. Application Review Information

A. Evaluation Criteria

B. Review and Selection Process

VI. Award Administration Information

A. Abstract Responses

B. Proposal Selection Notices

C. Administrative and National Policy Requirements

D. Reporting

VII. Agency Contacts

VIII. Other Information

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 3

A. Frequently Asked Questions (FAQs)

B. Proposers Day

C. Submission Checklist

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 4

PART I: OVERVIEW INFORMATION

Federal Agency Name: Defense Advanced Research Projects Agency (DARPA), Information Innovation Office (I2O)

Funding Opportunity Title: Active Social Engineering Defense (ASED)

Announcement Type: Initial Announcement

Funding Opportunity Number: HR001117S0050

Catalog of Federal Domestic Assistance Numbers (CFDA):

12.910 Research and Technology Development

Dates o Posting Date: September 08, 2017 o Proposers Day: August 7, 2017, 9:00 a.m. (ET) o Abstract Due Date: September 19, 2017, 12:00 noon (ET) o Proposal Due Date: November 9 28, 2017, 12:00 noon (ET) o BAA Closing Date: November 9 28, 2017, 12:00 noon (ET)

Anticipated Individual Awards: DARPA anticipates multiple awards under this solicitation.

Types of Instruments that May be Awarded: Procurement contracts, cooperative agreements or Other Transaction

Agency Contacts o Technical POC: Wade Shen, Program Manager, DARPA/I2O o BAA Email: ASED@darpa.mil o BAA Mailing Address:

DARPA/I2O

ATTN: HR001117S0050

675 North Randolph Street Arlington, VA 22203-2114 o I2O Solicitation Website: http://www.darpa.mil/work-with-us/opportunities mailto:ASED@darpa.mil http://www.darpa.mil/work-with-us/opportunities

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 5

PART II: FULL TEXT OF ANNOUNCEMENT

I. Funding Opportunity Description

DARPA is soliciting innovative research proposals in the area of automated defense against social engineering attacks. Proposed research should investigate innovative approaches that enable revolutionary advances in science, devices, or systems. Specifically excluded is research that primarily results in evolutionary improvements to the existing state of practice.

This Broad Agency Announcement (BAA) is being issued, and any resultant selection will be made, using procedures under Federal Acquisition Regulation (FAR) 6.102(d)(2) and 35.016.

Any negotiations and/or awards will use procedures under FAR 15.4 (or 32 CFR § 200.203 for cooperative agreements). Proposals received as a result of this BAA shall be evaluated in accordance with evaluation criteria specified herein through a scientific review process.

DARPA BAAs are posted on the Federal Business Opportunities (FBO) website (https://www.fbo.gov/) and the Grants.gov website (http://www.grants.gov/).

The following information is for those wishing to respond to this BAA.

A. Introduction/Background

Over the past 40 years, our world has become increasingly connected. These connections have enabled major advances in national security from pervasive real-time intelligence and communications to optimal logistics. With this connectivity has come the threat of cyber attacks on both military systems and critical infrastructure. While we focus the vast majority of our security efforts on protecting computers and networks, more than 80% of cyber attacks and over 70% of those from nation states are initiated by exploiting humans rather than computer or network security flaws. To build secure cyber systems, it is necessary to protect not only the computers and networks that make up these systems but the humans as well.

We call attacks on humans “social engineering” because they manipulate or “engineer” users into performing desired actions or divulging sensitive information. The most general social engineering attacks simply attempt to get unsuspecting internet users to click on malicious links.

More focused attacks attempt to elicit sensitive information, such as passwords or private information from organizations or steal things of value from particular individuals by earning unwarranted trust.

These attacks always have an “ask”, a desired behavior that the attacker wants to induce from the victim. To do this, they need trust from the victim, which is typically earned through interaction or co-opted via a spoofed or stolen identity. Depending on the level of sophistication, these attacks will go after individuals, organizations, or wide swathes of the population.

Social engineering attacks work because it is difficult for users to verify each and every communication they receive; moreover, that verification requires a level of technical expertise that most users lack. To compound the problem, the number of users that have access to privileged information is often large, creating a commensurately large attack surface.

https://www.fbo.gov/ http://www.grants.gov/

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 6

B. Program Description/Scope

The core technology to be developed in this program is the capability to automatically elicit information from a malicious adversary in order to identify, disrupt, and investigate social engineering attacks. ASED will do this by mediating communications between users and potential attackers with bots that actively detect attacks and coordinate investigations to discover the identity of the attacker.

Technical Areas (TAs)

The ASED program is divided into three technical areas:

1. Automated Detection of Social Engineering Attacks

2. Automated Investigation of Social Engineers

3. Scalable Evaluation Team

Figure 1 shows the TAs 1-3 diagrammatically with a U.S. Government-provided test range designed to evaluate ASED’s automated defense measures. The program will construct a test range using the email/phone systems of a real organization. This testbed is designed to create realistic environments for TAs 1-3 technology evaluation. To support the defensive goals of ASED, the program will enlist TA3 performers to generate a series of realistic attacks in this testbed, allowing the program to conduct controlled experiments comparing ASED technologies against existing baselines. The Government and the TA3 evaluation teams will measure the ability of TA1 systems to detect and prevent attacks from succeeding. Similarly, the U.S.

Government evaluation team will measure the ability of TA2 systems to identify attackers.

ASED test range

Volunteer subject pool

TA3 Attackers

1. Witting and savvy subjects

2. Existing penetration-test IRB

TA1/2 Defenders

1. Human attackers

2. Automated attackers

Figure 1: ASED Technical Areas and Evaluation Strategy

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 7

TA1: Automated Detection of Social Engineering Attacks

TA1 performers will develop technology to automatically detect social engineering attacks. This will require a way to observe the signatures of social engineering attacks and validate the identities of communicants.

To facilitate detection, TA1 systems will address three technical challenges:

1. Examine mechanisms used by attackers;

2. Force attackers to leave a detectable trace; and

3. Validate the trust mechanism used by a potential attacker.

TA1 performers will develop communications bots that mediate and observe communications between attackers and potential victims (as shown in Figure 2). These bots must be able to see communications from an attacker to multiple victims via information sharing across bots (enabling challenge 1) and intervene when a victim may be under attack to actively validate the identity of the potential attacker (enabling challenge 3).

ASED

Attacker

Victim 2

Victim 1

Figure 2: Virtual Alter Ego Bot Infrastructure

To address challenge 2, TA1 systems will develop approaches to coordinate multiple bots per user, each managing a set of “virtual alter egos.” These virtual alter egos are purpose-based, communications channels where each channel allows one entity (or group of associated entities) to legitimately ask a victim for information. Many people already use such channels, for example communicating via different email addresses and phone numbers to separate work and personal activities. In the limit, imagine having a different channel for everyone you communicate with, and each channel being mediated by its own bot. To make using multiple channels practical, TA1 systems must automatically route communications appropriately.

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 8

The purpose of these channels is twofold:

1. First, they create multiple vantage points for detection of broad phishing attacks; and

2. Second, in order to spoof the identity of someone the victim already trusts, an attacker must select the exact channel for that identity. Consider as an example an attacker who knows that a victim is a My State Bank customer and wants to phish his account password. He now has to find the exact email address the victim uses to communicate with My State Bank in order to successfully phish. If the attacker chooses to multiple victim email addresses, each virtual alter ego will receive similar phishing attempts, creating a detectable signature.

Proposers to TA1 will create a detection capability that aggregates communications for an enterprise on email, SMS, and social media channels to enable identification of attack mechanisms. The resulting systems must include tools to help users easily route communications via appropriate channels. And while TA1 and TA2 systems will have access to the communications of an entire enterprise, these systems should safeguard private user information and prevent its disclosure to other members of the enterprise.

TA1 systems will use this capability to:

Perform passive detection: Because these bots share data across potential victims and channels, they can assess whether specific communications from attackers have multiple users, individuals or organizations. This should allow for passive detection of phishing attacks even when the content of a communication is highly personalized.

Perform active detection: The attacker may find the right channel and mount a highly personalized attack, especially when communicants within the victim’s social network have been compromised. In these cases, ASED bots must be able to actively verify the communication. Both out-of-band verification and challenge/response approaches are of interest. Out-of-band verification could be done, for example, by testing the content of links, or by validating emails and/or text messages through alternate communications channels. Because these attacks are likely to be highly personalized and often from co-opted accounts, TA1 systems must also be capable of using dialog-based challenges and responses to validate the identity of the sender. For example, this could be accomplished by asking the sender to verify shared secrets: information that only the sender and victim would know. TA1 systems might keep track of this kind of identifying information automatically by aggregating prior communications from the attacker to the victim and analyzing their contents. TA1 systems may request help from the victim to curate, edit, and/or select potential challenges.

Ultimately, the goal of TA1 systems will be to detect attacks while minimizing the number of behaviors an attacker is able to elicit from potential victims within an enterprise deploying ASED. To evaluate TA1 systems, the evaluation team will measure the detection characteristics of TA1 systems (in Pd/Pfa terms; Pd = Probability of detection, Pfa = Probability of false alarm) and the cost (measured in terms of the total number of challenges and out-of-band communications needed to perform a detection).

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 9

TA2: Automated Investigation of Social Engineers

When an attack is detected, the ASED program envisions the use of automated, virtual, alter-ego bots to coordinate active investigation and tracing of the attacker’s identity. To facilitate this, each bot should be able to manage a set of resources that it can trade to gain identifying information about the attacker. These resources could include sandboxed virtual machines, disposable accounts, etc.

These bots should automatically optimize the use of these resources to elicit as much identifying information as possible. Information could come in the form of direct or indirect disclosure or via transactions that leave observable traces. ASED should be capable of coordinating multiple bots to investigate attacks with multiple victims, as shown in Figure 3.

ASED-managed alter egos

From: jenny@gmail.com

Hi. Just writing to let you know my trip has been a mess… I need you to loan me some money. I'll refund it when I get back.

Consumables’

Protected resources Consumables’’

V’

Can you send me your number?

Let’s meet @ Main st. @ 10am

I’ll wire money to your account.

V’’

Figure 3: Active and coordinated investigation

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 10

Smart adversaries may not be willing to disclose identifying information. In these cases, ASED bots should be able to maintain dialogs for multiple turns, to distract and increase the work factor for the adversary.

TA2 systems will develop technologies that semi-automatically conduct coordinated, active investigations and perform adversary distraction. Investigation and distraction tasks may make use of the victim(s) to help edit, author, mediate or curate potential elicitations or distractions while minimizing the amount of victim effort needed. TA2 systems must also be able to optimally coordinate these activities across multiple victims.

TA2 auto-investigation and distraction solutions will be integrated with TA1 systems during bi-annual evaluation events. TA2 systems will be evaluated in terms of the rate at which they can retrieve or force the emissions of identifying information from an attacker and the cost (both in terms of an expendable resource needed and dialog turns required) per identifier retrieved.

TA3: Scalable Evaluation Team

TA3 performers will evaluate TA1/TA2 performers and measure their progress via social engineering attacks. TA3 performers will curate and maintain a set of social engineering scenarios that they will employ for testing and training. TA3 teams will also recruit a set of human attackers to perform attacks based on these scenarios on a live testbed. These attacks and their transcripts will help train TA1/TA2 systems.

During program evaluations TA3 performers will need to employ multiple variations of each scenario for each of the TA1-TA2 defensive systems to be evaluated and analyzed in statistically meaningful ways. To increase the number of attack samples per scenario, TA3 teams must develop an automated mechanism that dynamically generates attack variants and executes them in a repeatable and cost-effective manner that takes these transcripts as inputs. These systems should be able to dynamically replay scenarios automatically, and in their entirety, from early stage planning through attack execution.

TA3 systems and teams will be required to deploy on a U.S. Government-provided test range for continuous evaluation as described below in Section I.C. TA3 teams must work with the U.S.

Government team to manage the deployment of their systems and the evaluation of bi-annual improvements of TA1-TA2 systems throughout the program.

C. Program Structure

Figure 4 shows the anticipated program schedule for ASED. The program is divided into two phases (18 months and 30 months). During the first phase of the program, performers will develop initial TA1-3 technologies. At the end of phase one, teams will begin to integrate their systems in the government provided test bed.

Biannual evaluations will be held as part of 2-week long integration exercises that are required for all teams. During these exercises, TA1 and TA2 teams will be required to integrate and deploy systems into the ASED test range against TA3 opponents. Evaluations will run continuously between deployment cycles and scored by the U.S. Government team. These two-week events will also encompass program PI meetings.

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 11

TA1: Attack detection

TA2: Active investigation

TA3: Scalable red-team and evaluation

Integrated toolkit / prelim system Transition System

Phase 1 (18 months) Phase 2 (30 months)

Automatically and adaptively personalized phishing/scams

Human-in-the loop testbed

Corpus/scenario development + live red-team exercises

Automated victim discovery

Coordinated alter ego distraction Coordinated elicitation

Direct elicitation Indirect elcitation

Automated channel management

Passive collective assessment of links and personas

Active verification

Bi-annual evaluation

Figure 4: ASED Program Structure

Proposers may submit proposals to TA1 and/or TA2 or to TA3. Proposals to TA3 must be separate from proposals to TA1 and/or TA2. Proposers may submit to all technical areas, but to maintain the independence of the TA3 evaluation team, and to avoid an organizational conflict of interest, the same organization may not perform on TA3 and on TA1 and/or TA2. The Government reserves the right to choose which proposals to select for award.

D. Government-furnished Property/Equipment/Information

DARPA will provide a test range to be used by all TA1-3 performers for deployment and evaluation. Experimentation and evaluation will be performed exclusively on this platform in order to centralize human subjects research with the U.S. Government-supplied test range and ensure uniformity of testing. TA1 and TA2 performers’ systems will be supplied with accounts and virtual alter egos from participants in the test range. TA3 performers must create and manage their own identities.

E. Program Metrics and Targets

Figure 5 shows the evaluation metrics to be used for ASED and the program targets for each phase (P1 and P2; P0 denotes pre-program estimates of current state of the art methods).

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 12

Figure 5: Program metrics and targets

TA1 metrics for detection are measured in relation to the number of challenges needed (i.e. the cost of detection). This balances the “annoyance” factor (i.e. how frequently non-malicious communications require extra verification) against detection accuracy.

Similarly, TA2 metrics are designed to help evaluate the retrieval accuracy of attribution information against the number of resources and interactions needed to accomplish this retrieval.

For TA3 we evaluate the ability of systems to detect susceptible victims given a number of potential seeds. We also measure the success rate of attacks mounted by TA3 performers.

Note: TA3 program targets are defined as success rates for non-ASED defended systems whereas TA1 and TA2 metrics are defined relative to TA3 attackers.

F. Intellectual Property

The program will emphasize creating and leveraging adaptable open source/open architecture technology solutions. Intellectual property rights asserted by proposers are strongly encouraged to be aligned with non-viral open source regimes. Make sure to carefully document and explain these reasons in submitted proposals. See Section VI.B for more details on intellectual property.

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 13

II. Award Information

A. Awards

Multiple awards are anticipated. The level of funding for individual awards made under this solicitation has not been predetermined and will depend on the quality of the proposals received and the availability of funds. Awards will be made to proposers whose proposals are determined to be the most advantageous to the Government, all factors considered, including the potential contributions of the proposed work, overall funding strategy, and availability of funding. See Section V for further information.

The Government reserves the right to:

select for negotiation all, some, one, or none of the proposals received in response to this solicitation;

make awards without discussions with proposers;

conduct discussions with proposers if it is later determined to be necessary;

segregate portions of resulting awards into pre-priced options;

accept proposals in their entirety or to select only portions of proposals for award;

fund proposals in increments and/or with options for continued work at the end of one or more phases;

request additional documentation once the award instrument has been determined (e.g., representations and certifications); and remove proposers from award consideration should the parties fail to reach agreement on award terms within a reasonable time or the proposer fails to provide requested additional information in a timely manner.

Proposals selected for award negotiation may result in a procurement contract, cooperative agreement, or Other Transaction (OT) depending upon the nature of the work proposed, the required degree of interaction between parties, and other factors.

Proposers looking for innovative, commercial-like contractual arrangements are encouraged to consider requesting Other Transactions. To understand the flexibility and options associated with Other Transactions, consult http://www.darpa.mil/work-with-us/contract-management#OtherTransactions.

In all cases, the Government contracting officer shall have sole discretion to select award instrument type, regardless of instrument type proposed, and to negotiate all instrument terms and conditions with selectees. DARPA will apply publication or other restrictions, as necessary, if it determines that the research resulting from the proposed effort will present a high likelihood of disclosing performance characteristics of military systems or manufacturing technologies that are unique and critical to defense. Any award resulting from such a determination will include a requirement for DARPA permission before publishing any information or results on the program. For more information on publication restrictions, see the section below on Fundamental Research.

http://www.darpa.mil/work-with-us/contract-management#OtherTransactions http://www.darpa.mil/work-with-us/contract-management#OtherTransactions

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 14

B. Fundamental Research

It is DoD policy that the publication of products of fundamental research will remain unrestricted to the maximum extent possible. National Security Decision Directive (NSDD) 189 defines fundamental research as follows:

‘Fundamental research’ means basic and applied research in science and engineering, the results of which ordinarily are published and shared broadly within the scientific community, as distinguished from proprietary research and from industrial development, design, production, and product utilization, the results of which ordinarily are restricted for proprietary or national security reasons.

As of the date of publication of this BAA, the Government expects that program goals as described herein may be met by proposers intending to perform fundamental research and does not anticipate applying publication restrictions of any kind to individual awards for fundamental research that may result from this BAA. Notwithstanding this statement of expectation, the Government is not prohibited from considering and selecting research proposals that, while perhaps not qualifying as fundamental research under the foregoing definition, still meet the BAA criteria for submissions. If proposals are selected for award that offer other than a fundamental research solution, the Government will either work with the proposer to modify the proposed statement of work to bring the research back into line with fundamental research or else the proposer will agree to restrictions in order to receive an award.

Proposers should indicate in their proposal whether they believe the scope of the research included in their proposal is fundamental or not. While proposers should clearly explain the intended results of their research, the Government shall have sole discretion to select award instrument type and to negotiate all instrument terms and conditions with selectees. Appropriate clauses will be included in resultant awards for non-fundamental research to prescribe publication requirements and other restrictions, as appropriate. This clause can be found at http://www.darpa.mil/work-with-us/additional-baa.

For certain research projects, it may be possible that although the research being performed by the awardee is restricted research, a subawardee may be conducting fundamental research. In those cases, it is the awardee’s responsibility to explain in their proposal why its subawardee’s effort is fundamental research

C. Disclosure of Information and Compliance with Safeguarding Covered Defense Information Controls

The following provisions and clause apply to all solicitations and contracts; however, the definition of “controlled technical information” clearly exempts work considered fundamental research and therefore, even though included in the contract, will not apply if the work is fundamental research.

DFARS 252.204-7000, “Disclosure of Information” DFARS 252.204-7008, “Compliance with Safeguarding Covered Defense Information Controls” DFARS 252.204-7012, “Safeguarding Covered Defense Information and Cyber Incident Reporting” http://www.darpa.mil/work-with-us/additional-baa

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 15

The full text of the above solicitation provision and contract clauses can be found at http://www.darpa.mil/work-with-us/additional-baa#NPRPAC.

Compliance with the above requirements includes the mandate for proposers to implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (see https://doi.org/10.6028/NIST.SP.800-171r1) that are in effect at the time the BAA is issued, or as authorized by the Contracting Officer, not later than December 31, 2017.

For awards where the work is considered fundamental research, the contractor will not have to implement the aforementioned requirements and safeguards; however, should the nature of the work change during performance of the award, work not considered fundamental research will be subject to these requirements.

http://www.darpa.mil/work-with-us/additional-baa#NPRPAC https://doi.org/10.6028/NIST.SP.800-171r1

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 16

III. Eligibility Information

A. Eligible Applicants

DARPA welcomes engagement from all responsible sources capable of satisfying the Government's needs, including academia (colleges and universities); businesses (large, small, small disadvantaged, etc.); other organizations (including non-profit); entities (foreign, domestic, and government); FFRDCs; minority institutions; and others.

DARPA welcomes engagement from non-traditional sources in addition to current DARPA performers.

1. Federally Funded Research and Development Centers (FFRDCs) and Government Entities

a. FFRDCs FFRDCs are subject to applicable direct competition limitations and cannot propose to this BAA in any capacity unless they meet the following conditions: (1) FFRDCs must clearly demonstrate that the proposed work is not otherwise available from the private sector. (2) FFRDCs must provide a letter on official letterhead from their sponsoring organization citing the specific authority establishing their eligibility to propose to Government solicitations and compete with industry, and their compliance with the associated FFRDC sponsor agreement’s terms and conditions. This information is required for FFRDCs proposing to be awardees or subawardees.

b. Government Entities Government Entities (e.g., Government/National laboratories, military educational institutions, etc.) are subject to applicable direct competition limitations. Government entities must clearly demonstrate that the work is not otherwise available from the private sector and provide written documentation citing the specific statutory authority and contractual authority, if relevant, establishing their ability to propose to Government solicitations.

c. Authority and Eligibility At the present time, DARPA does not consider 15 U.S.C. § 3710a to be sufficient legal authority to show eligibility. While 10 U.S.C.§ 2539b may be the appropriate statutory starting point for some entities, specific supporting regulatory guidance, together with evidence of agency approval, will still be required to fully establish eligibility. DARPA will consider FFRDC and Government entity eligibility submissions on a case-by-case basis; however, the burden to prove eligibility for all team members rests solely with the proposer.

2. Foreign Participation Non-U.S. organizations and/or individuals may participate to the extent that such participants comply with any necessary nondisclosure agreements, security regulations, export control laws, and other governing statutes applicable under the circumstances.

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 17

B. Organizational Conflicts of Interest

FAR 9.5 Requirements In accordance with FAR 9.5, proposers are required to identify and disclose all facts relevant to potential OCIs involving the proposer’s organization and any proposed team member (subawardee, consultant). Under this Section, the proposer is responsible for providing this disclosure with each proposal submitted to the BAA. The disclosure must include the proposer’s, and as applicable, proposed team member’s OCI mitigation plan. The OCI mitigation plan must include a description of the actions the proposer has taken, or intends to take, to prevent the existence of conflicting roles that might bias the proposer’s judgment and to prevent the proposer from having unfair competitive advantage. The OCI mitigation plan will specifically discuss the disclosed OCI in the context of each of the OCI limitations outlined in FAR 9.505-1 through FAR 9.505-4.

Agency Supplemental OCI Policy In addition, DARPA has a supplemental OCI policy that prohibits contractors/performers from concurrently providing Scientific Engineering Technical Assistance (SETA), Advisory and Assistance Services (A&AS) or similar support services and being a technical performer.

Therefore, as part of the FAR 9.5 disclosure requirement above, a proposer must affirm whether the proposer or any proposed team member (subawardee, consultant) is providing SETA, A&AS, or similar support to any DARPA office(s) under: (a) a current award or subaward; or (b) a past award or subaward that ended within one calendar year prior to the proposal’s submission date.

If SETA, A&AS, or similar support is being or was provided to any DARPA office(s), the proposal must include:

The name of the DARPA office receiving the support;

The prime contract number;

Identification of proposed team member (subawardee, consultant) providing the support; and An OCI mitigation plan in accordance with FAR 9.5.

Government Procedures In accordance with FAR 9.503, 9.504 and 9.506, the Government will evaluate OCI mitigation plans to avoid, neutralize or mitigate potential OCI issues before award and to determine whether it is in the Government’s interest to grant a waiver. The Government will only evaluate OCI mitigation plans for proposals that are determined selectable under the BAA evaluation criteria and funding availability.

The Government may require proposers to provide additional information to assist the Government in evaluating the proposer’s OCI mitigation plan.

If the Government determines that a proposer failed to fully disclose an OCI; or failed to provide the affirmation of DARPA support as described above; or failed to reasonably provide additional information requested by the Government to assist in evaluating the proposer’s OCI mitigation plan, the Government may reject the proposal and withdraw it from consideration for award.

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 18

C. Cost Sharing/Matching

Cost sharing is not required; however, it will be carefully considered where there is an applicable statutory condition relating to the selected funding instrument (e.g., OTs under the authority of 10 U.S.C. § 2371).

D. Other Eligibility Requirements

1. Ability to Receive Awards in Multiple Technical Areas - Conflicts of Interest While proposers may submit proposals for all three technical areas, proposers selected for TA3 cannot be selected for any portion of the other two technical areas, whether as a prime, subcontractor, or in any other capacity from an organizational to an individual level. This is to avoid OCI situations between the technical areas and to ensure objective test and evaluation results. The decision as to which proposal to consider for award is at the discretion of the Government.

2. Ability to Support Classified Deployment Although the technical work in TA1-3 is not classified, there may be transition-related deployments of ASED systems that require security clearances from proposers. In your proposals, please provide applicable Commercial and Government Entity (CAGE) code and security point(s) of contact in your proposals. This information should be included on the Cover Sheet of your proposal.

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 19

IV. Application and Submission Information

A. Address to Request Application Package

This document contains all information required to submit a response to this solicitation. No additional forms, kits, or other materials are needed except as referenced herein. No request for proposal (RFP) or additional solicitation regarding this opportunity will be issued, nor is additional information available except as provided at the Federal Business Opportunities website (https://www.fbo.gov), the Grants.gov website (http://www.grants.gov/), or referenced herein.

B. Content and Form of Application Submission

1. Abstracts Proposers are highly encouraged to submit an abstract in advance of a proposal to minimize effort and reduce the potential expense of preparing an out of scope proposal. The abstract provides a synopsis of the proposed project, including brief answers to the following questions:

What is the proposed work attempting to accomplish or do?

How is it done today, and what are the limitations?

Who will care and what will the impact be if the work is successful?

How much will it cost, and how long will it take?

Abstract Format: Abstracts may address a single technical area for TA1 through TA3.

Abstracts may also address TA1 and TA2 jointly; however, proposals addressing TA3 should not be combined with any other technical area efforts due to the nature of the work required by TA3. Submissions addressing other combinations of TAs will not be accepted.

Abstracts shall not exceed a maximum of 5 pages including the cover sheet and all figures, tables, and charts. The page limit does not include a submission letter (optional).

All pages shall be formatted for printing on 8-1/2 by 11-inch paper with 1-inch margins and font size not smaller than 12 point. Font sizes of 8 or 10 point may be used for figures, tables, and charts. Document files must be in .pdf, .odx, .doc, .docx, .xls, or .xlsx formats.

Submissions must be written in English. All pages should be numbered.

Abstracts must include the following components:

Cover Sheet: Provide the administrative and technical points of contact (name, address, phone, email, lead organization). Include the BAA number, title of the proposed project, primary subcontractors, estimated cost, duration of the project, and the label “Abstract.”

Goals and Impact: Describe what is being proposed and what difference it will make (qualitatively and quantitatively) if successful. Describe the innovative aspects of the project in the context of existing capabilities and approaches, clearly delineating the relationship of this work to any other projects from the past and present.

https://www.fbo.gov/ http://www.grants.gov/

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 20

Technical Plan: Outline and address all technical challenges inherent in the approach and possible solutions for overcoming potential problems. Provide appropriate specific milestones (quantitative, if possible) at intermediate stages of the project to demonstrate progress.

Capabilities/Management Plan: Provide a brief summary of expertise of the team, including subcontractors and key personnel. Identify a principal investigator for the project and include a description of the team’s organization including roles and responsibilities. Describe the organizational experience in this area, existing intellectual property required to complete the project, and any specialized facilities to be used as part of the project. List Government-furnished property, facilities, or data assumed to be available. Please include a brief bibliography with links to relevant papers, reports, or resumes of key performers. Do not include more than two resumes as part of the abstract. Resumes count against the abstract page limit.

Statement of Work, Cost, and Schedule: Provide a cost estimate for resources over the proposed timeline of the project, broken down by year. Include labor, materials, a list of deliverables and delivery schedule. Provide cost estimates for each subcontractor (may be a rough order of magnitude).

2. Proposals Proposals consist of Volume 1: Technical and Management Proposal (including mandatory Appendix A); Volume 2: Cost Proposal; the Level of Effort Summary by Task Excel spreadsheet; and the PowerPoint summary slide.

All pages shall be formatted for printing on 8-1/2 by 11-inch paper with 1-inch margins, single-line spacing, and a font size no smaller than 12 point. Font sizes as small as 8 point may be used for figures, tables, and charts. Document files must be in .pdf, .odx, .doc, .docx, .xls, or .xlsx formats. Submissions must be written in English. All pages of Volume 1 should be numbered.

A summary slide of the proposed effort, in PowerPoint format, should be submitted with the proposal. A template slide is provided as an attachment to the BAA. Submit this PowerPoint file in addition to Volumes 1 and 2 of your full proposal, and the Level of Effort Summary by Task Excel spreadsheet. This summary slide does not count towards the total page count.

Proposals may address a single technical area for TA1 through TA3. Proposals may also address TA1 and TA2 jointly; however, proposals addressing TA3 should not be combined with any other technical area efforts due to the nature of the work required by TA3.

Submissions should separate costs, statement of work and level-of-effort for each technical area proposed. Submissions addressing other combinations of TAs will not be accepted.

Proposals not meeting the format prescribed herein may not be reviewed.

a. Volume 1: Technical and Management Proposal The maximum page count for Volume 1 is 25 pages for proposals addressing one technical area, and 35 pages for those addressing two technical areas, including all figures, tables, and

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 21

charts but not including the cover sheet, table of contents or appendices. A submission letter is optional and is not included in the page count. Appendix A and bibliographies do not count against the page limit and is mandatory.

Volume 1 must include the following components:

i. Cover Sheet: Include the following information.

Label: “Proposal: Volume 1” BAA number (HR001117S0050) Technical Area Proposal title Lead organization (prime contractor) name Type of organization, selected from the following categories: Large Business, Small Disadvantaged Business, Other Small Business, HBCU, MI, Other Educational, or Other Nonprofit

Technical point of contact (POC) including name, mailing address, telephone, and email

Administrative POC including name, mailing address, telephone number, and email address

Award instrument requested: procurement contract (specify type), cooperative agreement or OT.1

Total amount of the proposed effort Place(s) and period(s) of performance Other team member (subcontractors and consultants) information (for each, include Technical POC name, organization, type of organization, mailing address, telephone number, and email address)

Proposal validity period (minimum 120 days) Data Universal Numbering System (DUNS) number2 Taxpayer identification number3 Commercial and Government Entity (CAGE) code4 Proposer’s reference number (if any)

ii. Table of Contents

iii. Executive Summary: Provide a synopsis of the proposed project, including answers to the following questions:

What is the proposed work attempting to accomplish or do?

How is it done today, and what are the limitations?

1 Information on award instruments can be found at http://www.darpa.mil/work-with-us/contract-management.

2 The DUNS number is used as the Government's contractor identification code for all procurement-related activities. Go to http://fedgov.dnb.com/webform/index.jsp to request a DUNS number (may take at least one business day). For further information regarding this subject, please see www.darpa.mil/work-with-us/additional-baa for further information.

3 See http://www.irs.gov/businesses/small/international/article/0,,id=96696,00.html for information on requesting a TIN. Note, requests may take from 1 business day to 1 month depending on the method (online, fax, mail).

4 A CAGE Code identifies companies doing or wishing to do business with the Federal Government. For further information regarding this subject, please see www.darpa.mil/work-with-us/additional-baa.

http://www.darpa.mil/work-with-us/contract-management http://fedgov.dnb.com/webform/index.jsp http://www.darpa.mil/work-with-us/additional-baa http://www.darpa.mil/work-with-us/additional-baa http://www.irs.gov/businesses/small/international/article/0,,id=96696,00.html

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 22

Who or what will be affected and what will be the impact if the work is successful?

How much will it cost, and how long will it take?

The executive summary should include a description of the key technical challenges, a concise review of the technologies proposed to overcome these challenges and achieve the project’s goal, and a clear statement of the novelty and uniqueness of the proposed work.

iv. Innovative Claims and Deliverables: Describe the innovative aspects of the project in the context of existing capabilities and approaches, clearly delineating the uniqueness and benefits of this project in the context of the state of the art, alternative approaches, and other projects from the past and present. Describe how the proposed project is revolutionary and how it significantly rises above the current state of the art.

Describe the deliverables associated with the proposed project and any plans to commercialize the technology, transition it to a customer, or further the work. Discuss the mitigation of any issues related to sustainment of the technology over its entire lifecycle, assuming the technology transition plan is successful.

v. Technical Plan: Outline and address technical challenges inherent in the approach and possible solutions for overcoming potential problems. Demonstrate a deep understanding of the technical challenges and present a credible (even if risky) plan to achieve the project’s goal. Discuss mitigation of technical risk. Provide appropriate measurable milestones (quantitative if possible) at intermediate stages of the project to demonstrate progress and a plan for achieving the milestones.

vi. Management Plan: Provide a summary of expertise of the proposed team, including any subcontractors/consultants and key personnel who will be executing the work.

Identify a principal investigator (PI) for the project. Provide a clear description of the team’s organization including an organization chart that includes, as applicable, the relationship of team members; unique capabilities of team members; task responsibilities of team members; teaming strategy among the team members; and key personnel with the amount of effort to be expended by each person during the project. Provide a detailed plan for coordination including explicit guidelines for interaction among collaborators/subcontractors of the proposed project. Include risk management approaches. Describe any formal teaming agreements that are required to execute this project. List Government-furnished materials or data assumed to be available.

vii. Personnel, Qualifications, and Commitments: List key personnel (no more than one page per person), showing a concise summary of their qualifications, discussion of previous accomplishments, and work in this or closely related research areas. Indicate the level of effort in terms of hours to be expended by each person during each contract year and other (current and proposed) major sources of support for them and/or commitments of their efforts. DARPA expects all key personnel associated with a proposal to make a substantial time commitment to the proposed activity and the proposal will be evaluated accordingly. It is DARPA’s intention to put key personnel conditions into the awards, so proposers should not propose personnel that are not anticipated to execute the award.

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 23

Include a table of key individual time commitments as follows:

Hours on Project Key

Individual Project

Status (Current, Pending, Proposed) Phase 1 Phase 2 Phase 3 ASED Proposed x x x

Project Name 1 Current x x n/aName 1 Project Name 2 Pending n/a x x

ASED Proposed x x x Name 2

Project Name 3 Proposed x x x

viii. Capabilities: Describe organizational experience in relevant subject area(s), existing intellectual property, or specialized facilities. Discuss any work in closely related research areas and previous accomplishments.

ix. Statement of Work (SOW): The SOW must provide a detailed task breakdown, citing specific tasks and their connection to the interim milestones and metrics, as applicable. Each phase of the project should be separately defined. The SOW must not include proprietary information. For each defined task/subtask, provide:

A general description of the objective.

A detailed description of the approach to be taken to accomplish each defined task/subtask.

Identification of the primary organization responsible for task execution (prime contractor, subcontractor(s), consultant(s)), by name.

A measurable milestone, (e.g., a deliverable, demonstration, or other event/activity that marks task completion).

A definition of all deliverables (e.g., data, reports, software) to be provided to the Government in support of the proposed tasks/subtasks.

Identify any tasks/subtasks (by the prime or subcontractor) that will be accomplished at a university and believed to be fundamental research.

x. Schedule and Milestones: Provide a detailed schedule showing tasks (task name, duration, work breakdown structure element as applicable, performing organization), milestones, and the interrelationships among tasks. The task structure must be consistent with that in the SOW. Measurable milestones should be clearly articulated and defined in time relative to the start of the project.

xi. Appendix A: This section is mandatory and must include all of the following components. If a particular subsection is not applicable, state “NONE”.

(1). Team Member Identification: Provide a list of all individual team members from the prime, subcontractor(s), and consultant(s), as applicable.

Identify specifically whether any are a non-US organization or individual, FFRDC and/or Government entity. Use the following format for this list:

HR001117S0050 ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) 24

Non-US?

Individual

Name

Role (Prime, Subcontractor or Consultant)

Organization Org Ind.

FFRDC

or

Govt?

(2). Government or FFRDC Team Member Proof of Eligibility to Propose:

If none of the team member organizations (prime or subcontractor) are a Government entity or FFRDC, state “NONE”.

If any of the team member organizations are a Government entity or FFRDC, provide documentation (per Section III.A.1) citing the specific authority that establishes the applicable team member’s eligibility to propose to Government solicitations to include: 1) statutory authority; 2) contractual authority; 3) supporting regulatory guidance; and 4) evidence of agency approval for applicable team member participation.

(3). Government or FFRDC Team Member Statement of Unique Capability: If none of the team member organizations (prime or subcontractor) are a Government entity or FFRDC, state “NONE”.

If any of the team member organizations are a Government entity or FFRDC, provide a statement (per Section III.A.1) that demonstrates the work to be performed by the Government entity or FFRDC team member is not otherwise available from the private sector.

(4). Organizational Conflict of Interest Affirmations and Disclosure: If none of the proposed team members are currently providing SETA or similar support as described in Section III.B, state “NONE”.

If any of the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .