USA flag logo/image

An Official Website of the United States Government

Software Protection Vulnerability Assessment through Kernel Analysis and…

Award Information

Agency:
Department of Defense
Branch:
Office of the Secretary of Defense
Award ID:
78116
Program Year/Program:
2006 / STTR
Agency Tracking Number:
O064-NC4-1011
Solicitation Year:
N/A
Solicitation Topic Code:
N/A
Solicitation Number:
N/A
Small Business Information
Pikewerks Corporation
105 A Church Street Madison, AL -
View profile »
Woman-Owned: No
Minority-Owned: No
HUBZone-Owned: No
 
Phase 1
Fiscal Year: 2006
Title: Software Protection Vulnerability Assessment through Kernel Analysis and Relationship Maps
Agency / Branch: DOD / OSD
Contract: FA8650-06-M-8076
Award Amount: $99,999.00
 

Abstract:

Traditional development efforts leave software vulnerable to reverse engineering, tamper, and access by unauthorized individuals (insider threat). While these threats are not new, advancements in easily hidden removable media such as USB drives and memory cards make them more prevalent. One low-cost technique for software protection is to utilize a kernel module capable of securely decrypting and executing protected software without inhibiting the users' activity. To some extent, this approach mimics the concepts employed by kernel "rootkits," or toolkits used by attackers to conceal unauthorized access. Because this approach to software protection is relatively new, few capabilities exist to conduct comprehensive vulnerability analysis. We propose to demonstrate the use of relationship maps as a means of analyzing the strength of these protection capabilities. The maps generated will enable AT-SPI to gather detailed forensics data about the executing software (including the kernel functionality) in a visual form. In addition to beneficial red-team analysis, this technology can be utilized as a security tool to detect and reverse engineer sophisticated kernel rootkits. As our past research has demonstrated, these are highly efficient methods that can be incorporated into both Government and commercial applications with tremendous success.

Principal Investigator:

Sandra Ring
CTO
7039696404
sandy@pikewerks.com

Business Contact:

Sandra Ring
CEO
7039696404
sandy@pikewerks.com
Small Business Information at Submission:

PIKEWERKS CORP.
2308 Mount Vernon Avenue #212 Alexandria, VA 22301

EIN/Tax ID: 331040567
DUNS: N/A
Number of Employees:
Woman-Owned: No
Minority-Owned: No
HUBZone-Owned: No
Research Institution Information:
PURDUE UNIV.
CERIAS, 656 Oval Drive
West Lafayette, IN 47907
Contact: Eugene Spafford
Contact Phone: (765) 494-7841
RI Type: Nonprofit college or university