FireEye_Training_SOW_Final.docx
DOCX document 24 KB Posted
- Attached to
- FireEye: On-site Malware Analysis Master Course Federal contract opportunity
- Solicitation number
- N0018919Q0498
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 4.01_RFQ_N0018919Q0498.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
For NCDOC’s Training Needs
1. SCOPE
To provide Malware Analysts with FireEye Software essential topics as listed herein, at NCDOC, 112 Lake View Parkway, Suffolk, Virginia, 23435.
2. BACKGROUND
The Navy Cyber Defense Operations Command (NCDOC) requires extensive in-depth malware training because malware authors (hackers) are developing new techniques on a daily basis, quicker than conventional malware software detection can be developed and deployed. NCDOC’s malware analysts need to be able to successfully determine the malware’s capabilities, reverse engineer it, and determine the best deterrent/protection from further cyber-attacks. This meets or exceeds the DOD requirements outlined to perform Defensive Cyber Operations.
3. REQUIREMENTS
3.1. Instructor(s) shall provide:
All materials (to include, but not limited to: preconfigured virtual machines, lab exercises, malicious samples, proprietary tools, etc.) needed for the course shall be brought with the instructor, in a ready to use capacity, or be sent via secure download to NCDOC personnel at least one month prior to beginning of the course, with personnel able to provide installation, set-up, and troubleshooting guidance as needed, to ensure that the classroom is ready to go at the start of the first day of training. The aim of this requirement is to reduce typical first-day troubleshooting issues, in order to maximize learning time.
Lab exercises conducted in the class shall be left with NCDOC personnel to continue practicing knowledge obtained after the conclusion of the course.
3.2. The method of delivery shall be instructor led in-class presentation to be scheduled as a five-day session with up to twenty (20) participants per session. Each session shall include all required content and consist of five, 8-hour days of instruction with one-hour lunch break daily.
3.3. Period of Performance shall be 30 September 2019 – 29 August 2020 for the session to be scheduled, held and completed..
3.4. Instructor(s) shall possess extensive expertise in the FireEye area, and at least 5 years of experience with reverse engineering of malware. Instructors must be practitioners who are in the field daily, responding to attacks, analyzing new malware samples or conducting red teaming engagements against enterprise networks. The course shall provide an optimal learning experience through a combination of instructor-led lectures and discussions supported by hands-on labs, all informed by the latest cyber threat intelligence; and shall provide customized instruction and deliver the required content to as many as twenty (20) attendees for the essential courses listed below.
Instructor must possess a minimum of a SECRET clearance. This is because the classroom will be located within a secure facility.
3.5 Essential Course
Malware Analysis Master Course
| - | Objective 1 - Grasp how shellcode works, including position independence, symbol resolution and decoders |
| - | Objective 2 - Comprehend the inner workings and limitations of disassemblers such as IDA Pro as well as how to |
circumvent the anti-disassembly mechanisms that malware authors use to thwart analysis
| - | Objective 3 - Automate IDA Pro using Python and IDC to help analyze malware more efficiently |
| - | Objective 4 - Understand how to combat anti-debugging, including bypassing timing checks, Windows debugger detection and debugger vulnerabilities |
| - | Objective 5 - Fool malware so it cannot detect what is running in a safe environment. |
| - | Objective 6 - Understand how malware analysis is influenced by C++ concepts like inheritance, polymorphism and objects |
| - | Objective 7 - Recognize common C++ structures from the disassembly |
| - | Objective 8 - Use disassembler features to enhance the reverse engineering process of C++ binaries |
| - | Objective 9 – Unpack manually by studying various packer algorithms and generic techniques to quickly defeat them |
- Objective 10 - See how x64 changes the game for malware analysis, including how WOW64 works and the architecture changes from x86
- Objective 11 - Grasp string obfuscation techniques that are commonly used by malware, then take malware communications and analyze network packet captures
- Objective 12 - Reverse engineer .NET bytecode and work with obfuscation techniques used by attackers
- Objective 13 - Understand how malware hides its execution, including process injection, process replacement and userspace rootkits
4. INSTRUCTOR POINT OF CONTACT – Shall be provided by contractor at time of award.
5. NCDOC POINT OF CONTACT – Shall be provided by Government at time of award.
6. NCDOC ATTENDEES ( 20 MAX) – Shall be provided by Government at time of award.
7. Enterprise-wide Contractor Manpower Reporting Application (ECMRA) In accordance with NMCARS clause 5237.102-90(b), the contractor shall report contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for the Navy via a secure data collection site. Contracted services excluded from reporting are based on Product Service Codes (PSCs). The excluded PSCs are:
(1) W, Lease/Rental of Equipment;
(2) X, Lease/Rental of Facilities;
(3) Y, Construction of Structures and Facilities;
(4) S, Utilities ONLY;
(5) V, Freight and Shipping ONLY.
The contractor is required to completely fill in all required data fields using the following web address https://doncmra.nmci.navy.mil.
Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year. Contractors may direct questions to the help desk, linked at https://doncmra.nmci.navy.mil.
File details come from the government source that posted it.