VirusTotal_BNJ_Redacted.pdf

PDF 96 KB Posted

Attached to
Virus Total Intelligence Database (VTID) Federal contract opportunity
Solicitation number
HS0021-17-Q-0041
Issued by
Defense Counterintelligence and Security Agency

About this file

Brand Name Justification for Virus Total Intelligence Database (VTID)

View the file

Other files for this federal contract opportunity

Other files attached to Virus Total Intelligence Database (VTID), newest first.
File Type Posted
HS0021-17-Q-0041.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

JUSTIFICATION FOR OTHER THAN FULL AND OPEN COMPETITION < SAT

FOR BRAND NAME JUSTIFICATION

VirusTotal Intelligence Database (VTID)

FOR OFFICIAL USE ONLY

PROCUREMENT SENSITIVE

SOURCE SELECTION SENSITIVE

REFERENCES:

• FAR 13.106-1 (b) states that, “For purchases not exceeding the simplified acquisition threshold, contracting officers may solicit from one source if the contracting officer determines that the circumstances of the contract action deem only one source reasonably available (e.g., urgency, exclusive licensing agreements, brand name, or industrial mobilization). The following documentation constitutes the rationale for this decision.

DOCUMENTATION:

(1) Requiring Activity:

Contracting Activity DSS Office of Acquisitions (AQ) 27130 Telegraph Road Quantico, VA 22134

(2) Supplies or services being procured:

VTI is a human interface to VirusTotal's dataset whereby one can search and download malware samples according to binary properties (binary content, size, headers, file type, etc.), antivirus detections (e.g. Zbot, Win32.Tatanga.AX, etc.), behavioral patterns, view previously conducted analysis, and interact with many different malware researchers and authors to discuss malicious actor tactics.

DSS utilizes VTI to collectively provide a comprehensive collection of malicious indicators on the Internet. The ability to identify malicious attackers and attribute those to ongoing malicious activity or correlate with past malicious activity is crucial to developing subjects for investigation.

The table below includes a description for the VTI requirement, the Period of Performance and the estimated total cost for the life of the contract.

Description Period of Performance Total Estimated

Cost Software Subscription for VirusTotal Intelligence (VTI) database access, to include 300 queries and downloads per month and placement of Yara rules against database/site, immediate feedback/analysis results of samples of interest and access to a community of interest concerning malware submissions.

One-year Base period and four, one-year option periods

(3) Reason that this is a brand name procurement:

This is a renewal for VTI subscription that has proven under to provide capabilities that have assisted mission which is to identify subjects of a counterintelligence investigation/operation. VTI offers two unique capabilities that aids contribution to the . These capabilities were only found to be offered under VTI, as identified in the market research.

employs the concepts of pivot analysis—enhanced by various tools and datasets—to develop and predict technical infrastructure and capabilities in order to discover adversaries and victims of malicious cyber activity. The relationships between adversary, victim, capability, and infrastructure produces cyber threat intelligence that will help defend information systems and networks, provide Law Enforcement/ Counterintelligence/Intelligence Community (LE/CI/IC) partners with collection and exploitation opportunities and degrades the effectiveness of the adversary.

VTI offers a unique database for discovering relationships between the infrastructure, adversary, victim, and capability pivots. VTI is unique because it is the only database which allows for to hunt for adversarial malware. VTI allows users to deploy Yara signatures based on all samples submitted to discover when malware has been uploaded. Once discovered VTI supplies a plethora of information regarding the malware capability, infrastructure used, and victims targeted. Victims are identified by unique submitter identifications (IDs) and location.

A pattern over time can be developed to identify when adversaries are testing their malware and the pattern of victim targeting. can use that information to discover the relationship between the victim/adversary pair and determine intent. Determining intent will allow to anticipate the adversary targets.

Because VTI gives information on the capabilities employed by the malware and the vulnerabilities it leverages, DSS can forewarn cleared contractors of the impending actions and provide accurate indicators from which the cleared contractor can use to protect themselves. Conversely, DSS can use the anticipatory intelligence garnered from VTI to assist other government agencies.

DSS previously purchased VTI on contract for a total cost of . The contract was for a base year and a one year option for a period of performance This requirement is to renew the subscription to the VTI database.

(4) Market survey (indicate if any other firms were contacted or expressed interest)

As stated above, VTI subscription was purchased from in FY 2015 on contract Market research was conducted to identify other malware scanning sites similar to VirusTotal. The customer reached out to the manufacturers of the various sites below for additional information. Unfortunately, for most cases, no response was received. Based on the research received, the other sites do not provided the same capability as Virus Total.

Below is a list of the sites researched by and the market research obtained.

1. -- Does not allow Yara to be used for catching specific malware in past submissions (sample files). They may offer this in the future. Uses which the has placed limits on government use and barring use completely by the Defense of Department is currently under discussion at the highest level of US government.

2. – Shutdown the multi-engine Antivirus scanner due to high costs of maintenance and does not offer anymore the possibility to download malware samples or to scan files with a web Application Program Interface

(API).

3. – Plan to add Yara signatures in the second half of 2018 and does not offer community support, we don’t offer such a program

4. -- Researched of capabilities indicate it does not meet requirement. Have emailed company for a direct response regarding their capabilities to meet DSS requirement; no response received at this time.

5. -- Researched of capabilities indicate it does not meet requirement. Have emailed company for a direct response regarding their capabilities to meet DSS requirement; no response received at this time.

6. -- Researched of capabilities indicate it does not meet requirement. Have emailed company for a direct response regarding their capabilities to meet DSS requirement; no response received at this time.

7. -- Researched of capabilities indicate it does not meet requirement. Have emailed company for a direct response regarding their capabilities to meet DSS requirement; no response received at this time.

8. -- Researched of capabilities indicate it does not meet requirement. Have emailed company for a direct response regarding their capabilities to meet DSS requirement; no response received at this time.

While these vendors provide a malware upload and virus scan capability, they do not provide the database which allows for to hunt for adversary malware, using Yara rules/signatures. These competitors only provide some routine metadata and the antivirus engines that catch the malware. With the limited capability offered by these services DSS CI Cyber Division would be overcome by the amount of data housed by them and would spend critical time trying to determine whether samples are related to adversaries of interest. It would be nearly impossible for to find accurate and validated infrastructure, capability, victim, and adversary pivots to exploit for offensive and defensive cyber operations. Thus, rendering analysis uncertain.

VTI eliminates the confusion and is the only service that allows for Yara signatures to be deployed against their database. Deploying these signatures makes much more efficient and is critical to the overall success of the

Based on the previous contract, the requirement was competed as a 100% total small business set-aside. Two quotes were received from small businesses. The two small businesses were contacted regarding the FY 2017 requirement.

Both confirmed they can still provide VTI. Based on past history and current research performed by the CS, a Request for Quote (RFQ) will be posted on Federal Business Opportunities utilizing North America Industry Classification System (NAICS) code 541519 (Other Computer Related Services) with a size standard of $27,500,000.00.

(5) Technical requirements personnel certification

I hereby certify that this justification is made in good faith, that the supporting data and information are accurate and complete to the best of my knowledge and belief, and that I would not be making this request if it were feasible to fully compete this requirement. I further certify that this request is not the result of lack of advanced planning or a desire to expend funds while those funds are still available.

(6) Price Reasonableness Determination:

This product/service is available from multiple authorized resellers. Based on market research, it is anticipated that open market pricing will be fair and reasonable. Quotes received for the FY 2017 requirement can be compared to historical prices paid and the IGCE in order to make a determination of fair and reasonable.

(7) Contracting Officer’s certification

I hereby certify that this justification is made in good faith, that the supporting data and information are accurate and complete to the best of my knowledge.

REFERENCES:
DOCUMENTATION:
(2) Supplies or services being procured:
(3) Reason that this is a brand name procurement:
(4) Market survey (indicate if any other firms were contacted or expressed interest)
(5) Technical requirements personnel certification
(6) Price Reasonableness Determination:
(7) Contracting Officer’s certification

File details come from the government source that posted it. Updated .