You are here

veriScan

Award Information
Agency: Department of Defense
Branch: Missile Defense Agency
Contract: HQ0147-17-C-7106
Agency Tracking Number: B2-2331
Amount: $998,599.00
Phase: Phase II
Program: STTR
Solicitation Topic Code: OSD06-SP2
Solicitation Number: 2006.0
Timeline
Solicitation Year: 2006
Award Year: 2017
Award Start Date (Proposal Award Date): 2017-03-10
Award End Date (Contract End Date): 2019-03-09
Small Business Information
315 Wynn Drive
Huntsville, AL 35805
United States
DUNS: 174265736
HUBZone Owned: No
Woman Owned: Yes
Socially and Economically Disadvantaged: No
Principal Investigator
 Kevin Counselman
 Senior Analyst
 (256) 430-0860
 kevin.counselman@sentar.com
Business Contact
 Sharon Yalowitz
Phone: (256) 430-0860
Email: sharon.yalowitz@sentar.com
Research Institution
 Georgia Tech Research Institute
 Ryan Spanier
 (404) 407-6216
 Nonprofit College or University
Abstract

The goal of the Information Assurance Run-time Auditing (IARA) Phase I project was to provide a framework that promotes the specification of software system monitoring, audit, analysis, and threat mitigation capabilities in large scale software intensive systems (LSSIS). IARA was designed to promote software assurance by incorporating novel tools that help certify the operations of untrusted software within a trusted environment. For the Phase II effort, Sentar has re-framed IARA as veriScan to better address the software assurance requirements whos critical operations require off-line analysis. veriScan is envisioned as a software assurance platform for statically and dynamically analyzing and assessing both source and binary software files for the presence of program vulnerabilities, coding weaknesses, and malicious intent. veriScan automates the execution of a critical mass of analysis programs for verifying large scale, mixed programming language systems that are implicitly trusted. veriScan performs risk assessments; reports on those risks in the face of reuse; and provides decision support to enable the mitigation of any risks identified. This Phase II project is particularly focused on developing advanced scanning capabilities for systems software written in FORTRAN and ADA. In addition, this capability will support dynamic vulnerability identification and verification. Approved for Public Release | 16-MDA-8863 (22 September 16)

* Information listed above is at the time of submission. *

US Flag An Official Website of the United States Government