HR001123S0025 Proposers Profiles.pdf
PDF 2 MB Posted
- Attached to
- Faithful Integration and Reverse-engineering and Emulation (FIRE) Federal contract opportunity
- Solicitation number
- HR001123S0025
View the file
Other files for this federal contract opportunity
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DARPA FIRE Proposer Profile March 16, 2023
• Peter L. Levin
• Founder and CEO
• Amida Technology Solutions
• peter@amida.com
• 900 19th Street NW
• Suite 203
• Washington, DC 20006
• 202-735-1790
• Amida.com
Achilles Suite of Products (ASoP) Technical Competencies:
• Our mission is to develop cutting edge solutions to address chip level security issues.
• We offer novel solutions in the nation’s most challenging security domain – semiconductor components themselves.
• Our technology enables on-chip, real-time, and in-system anomaly and intrusion detection, offering unprecedented diagnostic granularity.
• ASoP are designed to provide security and trust: securing microelectronic devices in the era of distributed production.
Expertise desired from other teams/organizations:
1. IP
• Processor IP and/or application-specific IP
• Potential IP and FPGA design
• IP to run thru our cores
• FPGA hardware and/or IP
• FPGA Prototyping System
• RISC five core
• IP
• Contractor for security validation and verification
• Embedded FPGA IP
2. Emulators
• Emulator
• IP
• Access and training to an emulation system(s)
• Verification Tools
• EDA Tools - parser
• IP to run thru our cores
3. Analog solutions
• Analog IP to augment future need instruments
—---------------------CAPABILITY STATEMENT—--------------------
COMPANY OVERVIEW
Attic Research is a small business located in Dayton, OH. We develop state-of-the art cyber capabilities to address complex technical problems and specialize in reverse engineering, software modeling, and vulnerability discovery for a wide range of systems. Attic Research provides full spectrum cyber solutions through development of custom software tools, hardware analysis, and rapid prototyping to meet customer requirements.
CORE COMPETENCIES
• Hardware and software reverse engineering
• Software system analysis
• Cyber security
• Modeling and simulation
• Offensive cyber operations
• Software development
• Digital forensics
• Exploit development
• Cryptographic hardware analysis
• Custom tool development
• Hardware-In-The-Loop (HITL) Testing
Our Team Attic Research was founded on the idea that novel cyber security capability comes from dedicated interdisciplinary engineers. Our team is made up of highly qualified engineers from diverse technical backgrounds with years of experience working for the Department of Defense (DoD). Everyone on our team is cleared TS/SCI with additional accesses.
- Electrical Engineering
- Computer Engineering
- Systems Engineering
- Cyber Security
- CEH, CISSP, OSCP, OSWE, OSCE
Past Projects
Complex full system assessments: hardware + software reverse engineering, custom test hardware, HW/SW emulation, communications analysis, data forensics and recovery. More details available upon request.
Reverse Engineering
Full system reverse engineering requires a set of skills that demands a unique mindset. Our team has years of experience using and developing reverse engineering tools and techniques to provide thorough investigations of systems, building complete hardware + software interface models, and accurately representing the system’s environment.
WHO WE ARE
CAGE Code: 9ETH5
NAICS Codes:
541511 Custom Computer Programming Services 541512 Software Consulting Services
541715 Engineering Research and Development
541330 Engineering Services
Contact: Leanne Felix, Co-founder & CEO Email: leanne.felix@atticresearch.com Phone: 505-620-5939 Address: 81 Shelford Way Dayton OH 45440
Website: atticresearch.com
Christopher Wright - cwright@grammatech.com - 832-310-8396 https://grammatech.github.io/ GrammaTech, Inc.
6903 Rockledge Drive, Suite 1250 Bethesda, MD 20817 Technical Competencies and existing tools:
Bindle – automatic fuzzing harness generation and see-input collection. This makes dynamic testing of software binaries more accessible, by reducing the need for reverse engineering and domain knowledge.
Proteus – automatically find and fix vulnerabilities in software binaries. It uses exploitability analysis to prioritize software weaknesses for remediation.
REAFFIRM – platform for firmware analysis, component identification and extraction, and testing in emulation.
HALucinator – re-host and audit firmware binaries, by using software emulation of peripheral-device communication.
Chisel – automatically rewrite binary executables and libraries to strip out unused functionality, as well as enabling users to selectively remove features.
Discover & CodeSentry – vulnerability analysis and discovery in binaries.
LibMatch – Function matching in binaries against known Libraries.
REFacts & CapFinding – Find capabilities and component identification in binaries.
ModelGen – generate software models to replace hardware.
DDisasm – A fast and accurate disassembler. Disassemble with accuracy sufficient to enable modification and reassembly.
GTIRB – An intermediate representation for binary analysis and rewriting. It seeks to be an LLVM-IR for reverse engineering.
SEL – Software Evolution Library provides programmatic interface for parsing, analysis, and rewriting software source code for many programming languages through a single generic API.
Mnemosyne – automated software development assistant. Autocomplete, type inference, invariant inference, bug repair, and test case generation.
TFPGA – allows users to assess and establish trust in FPGAs sourced through an untrusted supply-chain.
FVA – detect vulnerabilities in FPGA designs.
ConfINE – end-to-end toolchain for configuring and securing complex, network-composed systems built from COTS and open-source components.
SySense – cyber security solution to monitor the execution of, detect anomalies in, and mitigate potential attacks on, UEFI firmware.
Bin2Math – extract and understand the mathematical algorithms implemented in binary programs.
A-CERT – automate the process of evidence generation when certifying software for use in high-assurance systems.
CodeSonar – Static Application Security Testing, SBOMS, Static Analysis with textual descriptions, path visualization and call tree visualization.
mailto:cwright@grammatech.com https://grammatech.github.io/
Proposer Profile for DARPA-SN-23-38
Name: Guru Prasadh Venkataramani Organization: George Washington University Email: guruv@gwu.edu Telephone: (202) 994-2980 Mailing Address: Department of Electrical and Computer Engineering, Science and Engineering Hall, 800 22nd St NW, Suite 6600 Washington, DC 20052
Website: http://www2.seas.gwu.edu/~guruv/ Technical competencies: Systems and Hardware security with extensive prior modeling/simulation experience covering side and covert channels, trusted execution environment, program analysis; computer architecture; software security including application binaries and communication protocols.
Desired expertise: Teaming opportunities with organizations that can lead effort in preparation, integration and engineering support mailto:guruv@gwu.edu http://www2.seas.gwu.edu/~guruv/
High Peaks Cyber Proposer Profile
Dr. Joseph Sharkey, 315-520-8106, sharkeyj@highpeakscyber.com 421 Broad Street STE 13, Utica, NY 13501 - www.highpeakscyber.com
High Peaks Cyber Overview High Peaks Cyber is a small business dedicated to the development, delivery, and support of elite cyber tools & research for the DoD and IC. We specialize in tackling the hardest cyber challenges to help our customers achieve their mission. We aim to reimagine offensive cyber R&D to be more nimble and impactful. We have staff cleared up to the TS/SCI level.
Dr. Sharkey, has a decade and a half of experience leading R&D efforts for customers including AFRL and DARPA. He is a recognized industry leader with 2 issued and 2 pending patents in defensive cyber technologies and has presented at prestigious venues including BlackHat in 2016. His expertise includes: vulnerability discovery, exploit development, Android security, hypervisor development, and trusted computing.
Technical Competencies Relevant to FIRE Before entering the cyber security defense contracting in 2007, Dr. Sharkey’s PhD research was in Computer Architecture and Microprocessor design (with 24+ IEEE/ACM peer reviewed publications), making him & his team uniquely qualified to tackle cyber R&D efforts that focus on interactions between the hardware & software. The larger High Peaks Cyber team has experience with such technologies ranging from cache issues & side channels, to peripheral DMA controllers bypassing security paradigms of the main CPU, to identifying vulnerabilities in trusted boot chains that arise from complex interactions between components of the computing architecture.
High Peaks Cyber has developed custom extensions to the unicorn emulator to rehost firmware for speedy automated analysis. Our extensions include custom integration of sanitizers (KCOV / KASAN like) to support coverage guided fuzzing & efficient dynamic analysis. We also have experience developing Ghidra scripts to support static analysis of firmware and binaries for embedded systems.
Desired teammate role We are seeking a subcontractor role, particularly in TA1 or TA2.
mailto:sharkeyj@highpeakscyber.com http://www.highpeakscyber.com
Eliminating Risk
Mirabilis Design| 2010 El Camino Real Suite 1061, Santa Clara, CA 95050 | www.mirabilisdesign.com Tel: 408-569-1704 | Fax: 408-519-6719 | Email: info@mirabilisdesign.com
Cyber-Physical System Design for Vulnerability and Risk Elimination
Contact Information Company: Mirabilis Design Inc.
Address: 2010 El Camino Real, Suite 1061 Santa Clara, CA 95050 Contact: Deepak Shankar Tel: 408-569-1704 Email: dshankar@mirabilisdesign.com Web: https://www.mirabilisdesign.com
Mirabilis Design is the leading enabler of system-level design, debugging and test for cyber-physical, semiconductor and software systems. This system design infrastructure identifies bottlenecks, unexpected behaviors, power deviation impacts and failures, thus eliminating risk in product design and ensure vulnerabilities are detected prior to product implementation.
VisualSim brings together all engineering disciplines in a single multi-simulator kernel and enables the analysis of reliability, efficiency, performance, power, and security of the cyber-physical system. CPS modeling and simulation ensures significantly higher productivity, generates an executable specification, minimizes implementation bugs, and enables continuous testing from requirements to field deployment. The eco-system has been fully validated and well-proven by product teams in aerospace, automotive, defense and semiconductors.
CPS model with VisualSim provides a single graphical modeling language for all engineering domains to create an accurate model that is easily scalable from a single to 100’s of nodes.
The intelligent reporting ensures that debugging is targeted and greatly reduces the number of tests on the physical system. For example, the flight avionics and UAV system were modeled in under 2 weeks, and simulation completed in 10-30 min. UAV model includes compute, storage, software, power system, network, and chassis backplanes. The model was tested for failures to hardware, software, network, power, external errors, and human intervention.
The key to modeling success is the rich library of components, network, and software; open API and integration tools; polymorphic data structure, graphical modeling, and an XML backend.
Reports generated by VisualSim Architect include reliability, mean-time to detection, mean-time to respond, intrusion success rate, latency, signal weakness, throughput, power consumed, temperate change, functional correctness, scheduling, and quality-of-service.
Mirabilis Design is looking to team with a company developing a cyber-physical system who can provide test cases, domain expertise in system vulnerability, and access to data for confirmation of behavior accuracy.
http://www.mirabilisdesign.com/ mailto:dshankar@mirabilisdesign.com
DARPA Faithful Integrated Reverse- Engineering and Exploitation (FIRE) Proposers Day Pacific Northwest National Laboratory
Experience
• PNNL has 200 cyber security scientists, engineers, and analysts developing new detection, proactive defense, and resilience technologies.
• PNNL has 80 electrical and power system engineers modelling, studying and improving grid resilience and security.
• PNNL provides threat intelligence for critical infrastructure for DOE and utilities.
Capabilities
▪ Robust testing and evaluation capabilities (TA 3 & 4)
▪ Mature powerNET testbed
▪ Mature cyberNET testbed
▪ Secure software as a service capability (Shamrock)
▪ High fidelity hardware in loop mod/sim capabilities (TA 1 & 2)
▪ Combining HIL with GridLab-D, PowerWorld, and Realtime digital simulators, PNNL can model complex cyber physical systems for communication, component and system performance and vulnerability analysis.
▪ Asset discovery and vulnerability management (TA 1)
▪ PNNL has developed several active and passive scanning technologies for DOE (MEEDS, SSASS-E) that can monitor complex cyber-physical systems for changes, vulnerabilities, and updates that effect security.
Partner capability needs
▪ Additional Vulnerability discovery methods
▪ Automated, reliable, non-invasive patching and vulnerability mitigation methods.
Contacts and partners
▪ Technical P.O.C. David Manz, PhD david@pnnl.gov (509) 372-5995
▪ Exploring industry partnership with Siemens
▪ T CST CSI-US
▪ T SDT DRS-US
▪ Exploring research partnership with Georgia Tech and GTRI
▪ Institute for Cybersecurity and Resilient Infrastructure Studies (ICARIS)
▪ Cyber-Physical Security Lab (CPSec)
▪ School of Cybersecurity and Privacy (SCP)
▪ School of Electrical and Computer Engineering (ECE)
▪ Trusted Microelectronics, GTRI
▪ CIPHER Lab, GTRI mailto:david@pnnl.gov
Contact Information
Mr. Cody Tews Principal Engineer Schweitzer Engineering Laboratories 2545 NE Hopkins Ct, Pullman, WA 99163 Phone: (509) 592-0461 Email: cody_tews@selinc.com Website: https://www.selinc.com
Technical Competencies Schweitzer Engineering Laboratories (SEL) designs and manufactures solutions which help the power system function reliably, safely, and economically, from the power plan to the end user.
With our over 6,100 employees, we build, test and ship products from our US based facilities to over 168 countries worldwide.
Cyber Physical Systems In alignment with the DARPA-FIRE proposer’s day, our primary business is the protection and control of cyber-physical systems. Because of the design, development, and manufacturing of our product, we have deep technical background into composition the of hardware, firmware, software, and physical subsystems which protect of critical infrastructure.
Cyber Analysis To mitigate unforeseen risks, our vulnerability analysis team has active experience in reverse engineering of the hardware systems, communication protocols, software, and firmware of these embedded systems. Analyzed microprocessors include: x86/64, NXP Coldfire, PowerPC, ARM, and 8051.
AI Schematic Capture To reduce legacy system support efforts, SEL has developed a novel machine learning based capability which extracts electrical engineering models from paper and legacy static schematics.
To support this effort, we have leveraged our corporate repository of design data. We believe this work can be extended to include the physical layouts from printed circuit board (PCB) imagery.
A unique capability of SEL is our new, 162,000 square-foot, PCB factory which may provide novel insights and data for the application of machine learning algorithms in the rapid analysis of PCB topologies.
mailto:cody_tews@selinc.com https://www.selinc.com/ bhay@securityworks.com
Name: Brian Hay and David Newman Organization: Security Works Email: bhay@securityworks.com Phone: 907-452-1529 Web: https://www.securityworks.com
Members of our team have been researching complex cyber-physical systems for over 25 years, with a particular focus on reliability and resilience characteristics at the system level. This has included the assessment of several critical real-world cyber physical systems in order to identify vulnerabilities, and to improve reliability and resilience. This work resulted in improvements to such systems, and, in the case of vulnerability detection, validated results when the systems failed in the predicted manner.
We expect to focus efforts on TA1 and TA2 to build on our previous work and experience to produce a highly configurable model and simulation engine that can be quickly configured to describe a given specific cyber physical system, based on a combination of the topology of the system, and the physics/rules which govern the behavior of the components and connections.
The behavior of the configured model can be analyzed over long-time scales in order to identify system level vulnerabilities and emergent properties. System characteristics to address vulnerabilities can then be added and tested across long time scales, and the fidelity at which each or all components are described can be increased in order to examine the system at shorter time scales.
Name: Trent Brunson, Ph.D.
Organization: Trail of Bits, Inc.
Email: trent@trailofbits.com Telephone: (806) 282-1182 Mailing address: 228 Park Ave Suite #80688, New York, NY 10003 Website: https://www.trailofbits.com
Over the last 12 years, Trail of Bits has specialized in binary translation, static and dynamic program analysis, exploit development and patching, and low-level software security. The company established its reputation during the Cyber Grand Challenge and has performed on the following DARPA programs with technologies akin to the FIRE Program: LADS, CFAR, CHESS, PACE, AMP, V-SPELLS, and SafeDocs.
Trail of Bits is interested in participating in TA1 of FIRE as a subcontractor. In particular, we believe that the company’s research in run-time analysis for software can also be ported to study hardware and sub-system interfaces. For software, our open-source tool, PolyTracker, tracks the data flow of every single input byte of a program, recording how the data affects the control flow and output. It can identify the semantic purpose of functions in a parser and detect program inputs that can be arbitrarily modified without affecting program output, indicating data validation bugs. See https://www.github.com/trailofbits for more information.
Trail of Bits would also be interested in teaming with partners needing binary lifting and translation expertise. Our work studies techniques and builds tools to bring machine code to a goto-free C-like representation. Thus, Trail of Bits’ engineers specialize in LLVM and MLIR (Multi-level Intermediate Representations) and compilers. We value our open-source contributions to the community, found at https://www.github.com/lifting-bits.
mailto:trent@trailofbits.com https://www.trailofbits.com https://www.github.com/trailofbits https://www.github.com/lifting-bits
Technical Competencies Applicable to Faithful Integrated Reverse-Engineering and Exploitation (FIRE)
Two Six Technologies (TST) has extensive expertise in hardware reverse engineering, hardware and firmware vulnerability research, and work with cyber-physical systems including:
• Hardware in-the-loop fuzzing (HWIL) - e.g., bitstream fuzzing, glitching, FW modification
• Firmware reverse engineering - including bare-metal, RTOS, and embedded Linux
• Circuit board (PCB) reverse engineering - e.g., identify hidden debug access points, sensitive communication busses, firmware storage
• Firmware extraction - including via chip-off, in-memory or memory-mapped via JTAG, in-situ, live extraction and exfiltration (e.g., via UART, USB, eth)
• Anti-tamper circumvention - both physical defeats and digital bypasses/resets
• Voltage, memory bus, and other glitching - e.g., bypass bootloader security, gain access, extract firmware
• FPGA bitstream reverse engineering - experience & proven success on certain FPGAs
• Electromagnetic fault injection (EMFI) - e.g., gain access, extract firmware
• Cryptographic analysis - e.g., key ladder analysis and reverse engineering
• PCB and Integrate circuit rework - including BGA
TST also has expertise modeling and verifying properties of complex hardware and software systems. Examples include analyzing custom cryptographic processors, building tools to maintain development, and designing techniques for modular verification of legacy code. Our researchers’ deep experience with cyber-physical system (CPS) verification is highly relevant to FIRE.
Formal methods for CPS verification have matured greatly in recent years, and TST can apply these new techniques to address the technical challenges posed by FIRE. TST has extensive experience in differential dynamic logic (DDL) and its extensions, which can represent sensor attacks and information leakage through physical side-channels in CPS. Our expertise with tools such as the KeyMaeraX hybrid systems theorem prover enables us to construct concise but powerful models of multi-component CPS and to give rigorous analyses of the robustness or vulnerability of such systems to side-channel and other attacks.
TST’s Pilot Security tool automates security analysis for firmware to rapidly identify vulnerabilities and possible patches. As applied to FIRE, Pilot may be leveraged to reduce the time to find, exploit, and patch vulnerabilities in cyber-physical systems.
TST is open to collaborating and teaming on multiple aspects.
TWOSIXTECH.COM TWOSIXFIRE@GOOGLEGROUPS.COM 703-543-9662
901 N. STUART STREET, SUITE 1000 ARLINGTON, VA 22203
Vector 35 Authors of Binary Ninja, A Reverse Engineering Platform
Contact
Peter LaFosse - peter@vector35.com
Jordan Wiens - jordan@vector35.com
Brian Knudson - bk@vector35.com https://binary.ninja
730 E. Strawbridge Ave Suite 214
Melbourne, FL 32901
Core Competencies
Program analysis and decompilation
Dynamic binary analysis
Software reverse engineering
Machine learning
Vulnerability research
Company Profile
Vector 35 Inc. is a Florida-based small business (17 employees) specializing in the development of static and dynamic software reverse engineering tools. Vector 35 is primarily known for its powerful Binary
Ninja reverse engineering platform and decompiler. Some of our employees hold up to TS//SCI clearances though we primarily seek unclassified work. As a small business, Vector 35 is seeking to be a subcontractor and enhance the capabilities of Binary Ninja in support of a prime’s objectives. On previous
DARPA and DoD programs, Vector 35 has provided the following:
● Machine learning-based approach to function similarity matching
● Automatic recognition of inlined function calls
● Hierarchical clustering of functions based on shared dataflow state
● Automated import and export to share analysis between tools
● Development of Binary Ninja-based plugins in support of customer goals including program understanding, vulnerability research, and exploit development
Product Profile
Binary Ninja is an interactive decompiler, disassembler, debugger, and binary analysis platform.
Decompilation is performed by lifting disassembled code to a unique stack of progressively higher abstraction, architecture-agnostic intermediate representations. The most highly abstracted, HLIL, is converted directly into other languages, providing direct decompilation to C. Binary Ninja also provides a superior API and user interface for accessing and interacting with these layers of abstraction, allowing customers to quickly extend Binary Ninja’s core capabilities for program analysis, vulnerability research, and more.
mailto:peter@vector35.com mailto:jordan@vector35.com mailto:bk@vector35.com https://binary.ninja/
Company Information
� Company Name: Venus Fly Trap Software Solutions LLC
� Email: venusflytrap@fastmail.com
� Phone: 503-530-0491, Signal/SMS preferred
� Location: Bend, OR
Competencies
Mostly TA1 in the software and hardware components. We develop and use emulation software named Co-bralily to help reverse engineer, find vulnerabilities in, and exploit cyber-physical systems. About Cobralily:
� Scriptable, automatable, rewindable, introspectable full-system emulation and debugging framework
� Aids black-box reverse engineering, vulnerability research, exploit development on embedded targets
� Designed for exotic targets that use arbitrary interfaces, like RF or low level hardware buses
� Possible to expose scriptable control over any physical input to the guest
� Lowers barrier to entry for performing research on embedded devices
� Can leverage hardware on host computer to communicate with physical devices
� Internally designed to reuse code, reducing time to develop support for new guests
� Currently supports:
– ARMv7-M,R, partially A
– MIPS64 release 2
– Andestar NDS32 (partial)
– Nanomips (partial)
Seeking
We are an extremely small organization. However, one of Cobralily’s design goals is to be easily integratable with other tools using C and Python bindings, which should make it mutually beneficial to team up with other organizations.
Ideal teammates’ competencies:
� (TA2) Simulation, especially when relating how physical phenomenon convert into the bit representa-tion that software would act on.
� (TA3) Tools that automatically identify components, connections, and/or board layouts will cut down on development time for new guests even more.
� (TA4) Integration with other tools; Cobralily was designed to be easy to incorporate with other tools, we have our own tools and can make more, but other teams could also make effective tools too.
| Amida Proposer Profile |
| AtticResearch_CapabilityStatement |
| FIRE_Profile_GrammaTech |
| GWU FIRE Profile |
| Proposer Profile High Peaks Cyber |
| DARPA_FIRE_Single_Page_Mirabilis_Design |
| Contact Information |
| DARPA Faithful Integrated Reverse PNNL |
| SEL - Proposer Profile |
| FIRE_securityworks_profile |
| Trail of Bits - DARPA FIRE - Profile Page |
| Two Six Tech Profile for FIRE Proposers Day v4 |
| Company Profile |
| VenusFlyTrap_BusinessProfile |
File details come from the government source that posted it. Updated .