EPP: Empirical Privilege Profiling for Black-box Software

Award Information
Agency:
Department of Defense
Branch
Defense Advanced Research Projects Agency
Amount:
$98,999.00
Award Year:
2004
Program:
SBIR
Phase:
Phase I
Contract:
W31P4Q-04-C-R260
Agency Tracking Number:
04SB1-0276
Solicitation Year:
2004
Solicitation Topic Code:
SB041-016
Solicitation Number:
2004.1
Small Business Information
ATC - NY
33 Thornwood Drive, Suite 500, Ithaca, NY, 14850
Hubzone Owned:
N
Socially and Economically Disadvantaged:
N
Woman Owned:
N
Duns:
101321479
Principal Investigator:
Carla Marceau
Senior Principal Scientis
(607) 257-1975
carla@atc-nycorp.com
Business Contact:
Richard Smith
Controller
(607) 257-1975
rick@atc-nycorp.com
Research Institution:
n/a
Abstract
The Principle of Least Privilege says that programs should operate with sufficient privilege to get the job done, but no more, in order to minimize the harm that can be done in case of error. The Empirical Privilege Profiling system (EPP) will collect data about privileges actually exercised by running programs and use them to create a composite abstract privilege profile for the program, which can be used to guide system administrators in granting program privileges. To create EPP, ATC-NY will develop novel technologies for finding the privileges exercised by programs and for building composite abstract profiles.

* information listed above is at the time of submission.

Agency Micro-sites

US Flag An Official Website of the United States Government