New program seeks to reveal backdoors and other hidden malicious functionality in commercial IT devices

Dec 03, 2012

The scenario is one that information security experts dread: widespread dissemination of commercial technology that is secretly wired to function in unintended ways or even spy on its users. From this vantage point, mobile phones, network routers, computer work stations and any other device hooked up to a network can provide a point of entry for an adversary.

For the Department of Defense this issue is even more of a concern now than ever before as DoD personnel rely on equipment bought in large quantities and built with components manufactured all over the world. DoD's growing dependence on the makes device, software and firmware security an imperative. Backdoors, and other vulnerabilities unknown to the user could enable an adversary to use a device to accomplish a variety of harmful objectives, including the exfiltration of and the of critical operations. Determining the security of every device DoD uses in a timely fashion is beyond current capabilities.

To address the threat of , DARPA is starting the Vetting Commodity IT Software and Firmware (VET) program to look for innovative, large-scale approaches to verifying the security and functionality of commodity IT devices (those commercial information technology devices bought by DoD) to ensure they are free of hidden backdoors and malicious functionality. On December 12th, DARPA will host a Proposers' Day in Arlington, Va. Here, participants will be briefed on the program and anticipated solicitation.

"DoD relies on millions of devices to bring network access and functionality to its users," said Tim Fraser, DARPA program manager. "Rigorously vetting software and firmware in each and every one of them is beyond our present capabilities, and the perception that this problem is simply unapproachable is widespread. The most significant output of the VET program will be a set of techniques, tools and demonstrations that will forever change this perception."

VET will attempt to address three technical challenges:

  • Defining malice: Given a sample device, how can DoD analysts produce a prioritized checklist of software and firmware components to examine and broad classes of hidden malicious functionality to rule out?
  • Confirming the absence of malice: Given a checklist of software and firmware components to examine and broad classes of hidden malicious functionality to rule out, how can DoD analysts demonstrate the absence of those broad classes of hidden malicious functionality?
  • Examining equipment at scale: Given a means for DoD analysts to demonstrate the absence of broad classes of hidden malicious functionality in sample devices in the lab, how can this procedure scale to non-specialist technicians who must vet every individual new device used by DoD prior to deployment?

Explore further: Cyber experts engage on DARPA's Plan X

More information: go.usa.gov/gjEA

add to favorites email to friend print save as pdf

Related Stories

Cyber experts engage on DARPA's Plan X

Oct 18, 2012

When the team behind DARPA's Plan X mapped out where it wanted to go with research in the development of cyber capabilities and platforms, it knew the DARPA approach to problem solving included soliciting ...

NIST provides draft guidelines to secure mobile devices

Nov 01, 2012

The National Institute of Standards and Technology (NIST) has published draft guidelines that outline the baseline security technologies mobile devices should include to protect the information they handle. Smart phones, ...

Recommended for you

Patented system better secures digitally stored data

4 hours ago

(Phys.org) —Arizona State University computer scientist Gail-Joon Ahn has been granted a U.S. patent for a novel identity management system that helps protect personal identity information stored on digital devices.

UC Davis startup changes listening experience

20 hours ago

Fifteen years of research at the University of California, Davis, is being turned into commercial products by Dysonics, a startup company based in San Francisco. Since becoming the first "graduate" from the Engineering Translational ...

Research finds new channels to trigger mobile malware

May 16, 2013

(Phys.org) —Researchers at the University of Alabama at Birmingham (UAB) have uncovered new hard-to-detect methods that criminals may use to trigger mobile device malware that could eventually lead to targeted ...

User comments : 0

More news stories

Green conversion of heat to electricity

Soon, it will be possible to produce electricity from heat over 30 degrees emitted from a waste incinerator, refinery, or data processor. The start-up Osmoblue has just confirmed the feasibility of this new ...

If you can remember it, you can remember it wrong

(Medical Xpress)—Native peoples in regions where cameras are uncommon sometimes react with caution when their picture is taken. The fear that something must have been stolen from them to create the photo ...