Raytheon joins 'STONESOUP' team to improve software security
Raytheon Company has been selected as a subcontractor on a program to foil attacks against software of uncertain origin.
Engineers from Raytheon Integrated Defense Systems (IDS) have joined a team led by GrammaTech, Inc., to develop a technology that prevents the exploitation of vulnerabilities in software whose pedigree, or provenance in cyberparlance, is uncertain. The contract is part of STONESOUP - Securely Taking On New Executable Software Of Uncertain Provenance - a program of the Intelligence Advanced Research Projects Activity.
The multiyear contract administered by the Air Force Research Laboratory is for $12.9 million. GrammaTech, a manufacturer of software-analysis tools, is located in Ithaca, N.Y. Other team members include the University of Virginia and the Georgia Institute of Technology. Raytheon's piece of the contract is estimated at $2.5 million.
"Software developers often bundle software components from various sources, not knowing the vulnerabilities that these components bring with them," said Tom Bracewell, Raytheon's principal investigator. "An attacker may know how to exploit these vulnerabilities. Our goal is to eliminate the supply chain risk by removing these vulnerabilities or rendering them harmless."
The team's approach is to remove or mask vulnerabilities through automated analysis, repair, diversification, and visualization of executable code.
Raytheon will perform its role of technology integration, test, evaluation, and transition at IDS' Customer Integration Center in Arlington, Va.
Source: Raytheon
More from Digital Battlespace
-
Lockheed Martin completes tactical satellite demonstration and prepares for launch
The tactical satellite (TacSat) is an intelligence, surveillance and reconnaissance (ISR) system and will participate in exercises in 2025.
-
AUSA 2024: General Micro Systems adds four new products to the X9 Spider family
The airborne three-domain, the two ground-based and the ¼ ATR OpenVPX-based cross-domain systems were engineered to provide real-time security across multi-domain operations.
-
BAE Systems gets go-ahead for second phase of mission communications programme
DARPA’s Mission-Integrated Network Control (MINC) programme was set up to develop an autonomous tactical network and enable critical data flow in contested environments.
-
Just Released: Space Technology Report
Why space is an essential part of modern military capabilities
-
Work-from-home warfare: the power of mixed reality
Defence-secure mixed reality headsets can save hours, or even weeks, of travel time to fix defunct equipment or get subject experts effectively “on-site” where they are needed.