Back to news

June 8, 2023 | Local, Aerospace

FFCP Industry Engagement Event Presentation

Download the presentation

On the same subject

  • Hacker Community to Take on DARPA Hardware Defenses at DEF CON 2019

    August 5, 2019 | Local, Security

    Hacker Community to Take on DARPA Hardware Defenses at DEF CON 2019

    This month, DARPA will bring a demonstration version of a secure voting ballot box equipped with hardware defenses in development on the System Security Integrated Through Hardware and Firmware (SSITH) program to the DEF CON 2019 Voting Machine Hacking Village (Voting Village). The SSITH program is developing methodologies and design tools that enable the use of hardware advances to protect systems against software exploitation of hardware vulnerabilities. To evaluate progress on the program, DARPA is incorporating the secure processors researchers are developing into a secure voting ballot box and turning the system loose for public assessment by thousands of hackers and DEF CON community members. Many of today's hardware defenses cover very specific instances or vulnerabilities, leaving much open to attack or compromise. Instead of tackling individual instances, SSITH researchers are building defenses that address classes of vulnerabilities. In particular, SSITH is tackling seven vulnerabilities classes identified by the NIST Common Weakness Enumeration Specification (CWE), which span exploitation of permissions and privilege in the system architectures, memory errors, information leakage, and code injection. “There are a whole set of cyber vulnerabilities that happen in electronic systems that are at their core due to hardware vulnerabilities – or vulnerabilities that hardware could block,” said Dr. Linton Salmon, the program manager leading SSITH. “Current efforts to provide electronic security largely rely on robust software development and integration, utilizing an endless cycle of developing and deploying patches to the software firewall without addressing the underlying hardware vulnerability. The basic concept around SSITH is to make hardware a more significant participant in cybersecurity, rather than relegating system security only to software.” Under the SSITH program, researchers are exploring a number of different design approaches that go well beyond patching. These include using metadata tagging to detect unauthorized system access; employing formal methods to reason about integrated circuit systems and guarantee the accuracy of security characteristics; and combining hardware performance counters (HPCs) with machine learning to detect attacks and establish protective fences within the hardware. One team from the University of Michigan is developing a novel security approach that changes the unspecified semantics of a system every 50 milliseconds. Currently, attackers continuously probe a system to locate these undefined sections and, over time, are able to create a system map to identify possible hacks. By changing the construct every 50 milliseconds, attackers do not have enough time to find those weaknesses or develop an accurate representation of the system as a whole. To evaluate the hardware security concepts in development on the SSITH program, DARPA – working with Galois – is pursuing a voting system evaluation effort to provide a demonstration system that facilitates open challenges. The program elected to use a voting system as its demonstration platform to provide researchers with an accessible application that can be evaluated in an open forum. Further, the topic of election system security has become an increasingly critical area of concern for the hacker and security community, as well as the United States more broadly. “DARPA focuses on creating technologies to enhance national defense, and election system security falls within that remit. Eroding trust in the election process is a threat to the very fabric of our democracy,” noted Salmon. While protecting democracy is a critical national defense issue, SSITH is not trying to solve all issues with election system security nor is it working to provide a specific solution to use during elections. “We expect the voting booth demonstrator to provide tools, concepts, and ideas that the election enterprise can use to increase security, however, our true aim is to improve security for all electronic systems. This includes election equipment, but also defense systems, commercial devices, and beyond,” said Salmon. During DEF CON 2019, the SSITH voting system demonstrator will consist of a set of RISC-V processors that the research teams will modify to include their SSITH security features. These processors will be mounted on field programmable gate arrays (FPGAs) and incorporated into a secure ballot box. Hackers will have access to the system via an Ethernet port as well as a USB port, through which they can load software or other attacks to challenge the SSITH hardware. Since SSITH's research is still in the early stages, only two prototype versions of the 15 processors in development will be available for evaluation. “At this year's Voting Village, hackers may find issues with the processors and quite frankly we would consider that a success. We want to be transparent about the technologies we are creating and find any problems in these venues before the technology is placed in another venue where a compromise could be more dangerous,” said Salmon. Following DEF CON 2019, the voting system evaluation effort will go on a university roadshow where additional cybersecurity experts will have an opportunity to further analyze and hack the technology. In 2020, DARPA plans to return to DEF CON with an entire voting system, which will incorporate fixes to the issues discovered during the previous year's evaluation efforts. The 2020 demonstrator will use the STAR-Vote system architecture, which is a documented, open source architecture that includes a system of microprocessors for the voting booth, ballot box, and other components. It also includes a verifiable paper ballot, providing both digital and physical representations of the votes cast within the booth. “While the 2020 demonstrator will provide a better representation of the full attack surface, the exercise will not result in a deployable voting system. To aid in the advancement of secure election equipment as well as electronic systems more broadly, the hardware design approaches and techniques developed during the SSITH program will be made available to the community as open-source items,” concluded Salmon. https://www.darpa.mil/news-events/2019-08-01

  • European-built fighter aircraft: did they ever stand a chance in Canada’s competition?

    October 11, 2019 | Local, Aerospace

    European-built fighter aircraft: did they ever stand a chance in Canada’s competition?

    DAVID PUGLIESE, OTTAWA CITIZEN Canada's future fighter jet competition has already lost two European competitors. Will it lose a third, the Gripen built by Saab of Sweden? At the end of August, the United Kingdom's Ministry of Defence and Airbus Defence and Space informed the Canadian government of their decision to withdraw from Canada's future fighter competition. Airbus had been offering Canada the Eurofighter Typhoon. Last year the European firm Dassault informed the Canadian government it would not be competing in the competition. It had been planning to offer Canada the Rafale fighter jet. Airbus and the UK Defence Ministry noted that their decision to withdraw was the result of a detailed review of Canada's request for proposals which was released to industry on July 23. Airbus pointed to the changes Canada made to the industrial benefits package to appease Lockheed Martin as well as the excessive costs that U.S.-Canadian security requirements placed on a company based outside North America. “A detailed review has led the parties to conclude that NORAD security requirements continue to place too significant of a cost on platforms whose manufacture and repair chains sit outside the United States-Canada 2-EYES community,” the statement from Airbus and the UK Defence Ministry noted. “Second, both parties concluded that the significant recent revision of industrial technological benefits obligations does not sufficiently value the binding commitments the Typhoon Canada package was willing to make, and which were one of its major points of focus.” The $19 billion competition has been dogged by allegations it is designed to favour Lockheed Martin's F-35 stealth fighter. Take for instance, the response that Defence Minister Harjit Sajjan provided when the Liberal government in November 2016 announced the purchase of 18 interim Boeing Super Hornets. That deal was eventually scuttled after Boeing decided to go after Bombardier in a trade dispute over civilian aircraft. But at the time when the purchase was announced, Sajjan was asked why Canada was buying the Super Hornet and not one of the other fighter jets on the market. “When you look at the various aircraft, we have our NORAD commitment's (which are) extremely important,” the defence minister responded. “There's certainly interoperability issues as well.” Procurement Minister Judy Foote was more blunt. “From our perspective, we're working with the American government, so we have to look at an American plane.” So how is that different from the aircraft to be selected for the future fighter jet competition? Sajjan and Foote were stating in November 2016 that Canada needed to buy American because of its NORAD commitments and other interoperability concerns with the U.S. Nothing appears to have changed in the last three years, at least as far as the federal government and Canadian Forces are concerned. https://ottawacitizen.com/news/national/defence-watch/european-built-fighter-aircraft-did-they-ever-stand-a-chance-in-canadas-competition

  • Government expects to award contract for new fighter jet fleet in 2022 (but admits it could face delays)

    April 26, 2019 | Local, Aerospace

    Government expects to award contract for new fighter jet fleet in 2022 (but admits it could face delays)

    DAVID PUGLIESE, OTTAWA CITIZEN Though the federal government expects to award a contract for a new fleet of fighter jets in 2022, it admits that schedule is aggressive and could yet face further delays. A request for bids to provide 88 new jets to the Royal Canadian Air Force will be released next month, according to a new update on major Department of National Defence projects released Wednesday, with the proposals to be evaluated by 2021 and a contract to be awarded a year later. But in the update DND also admits that timeline is tenuous. “The approved schedule is considered very aggressive,” it said. “The project team is managing a number of risks which have the potential to impact schedule.” The document doesn't outline the specific risks but DND officials have acknowledged that government negotiations with private contractors on the industrial benefits that are to be linked to the project could cause delays. The Liberals have committed to purchasing the new jets in a program expected to cost up to $19 billion. The competition was launched on Dec. 12, 2017, and Canada expects to examine four different fighter jets as candidates for the RCAF's new fleet. The project team is managing a number of risks which have the potential to impact schedule The first of the jets is expected to be delivered in the mid-2020s, with the full capability available in the early 2030s, according to the DND document. The document also outlines the plan to purchase used Australian F-18s in the interim, which the RACF will use to boost the capability of its current fleet of CF-18s until the new generation aircraft are in service. The first of the Australian jets has already been delivered, with final delivery set for the end of 2021, according to the update. However, the parliamentary budget officer has found this interim solution could cost more than $1 billion, and the auditor general's office has pointed out that the air force is lacking pilots and maintenance crews for the planes it already operates. Wednesday's DND update points out success stories as well as challenges with some of DND's multi-billion dollar projects. Some programs, such as the purchase of Chinook helicopters and tactical armoured patrol vehicles, are completed or are nearing completion with few problems. A new $2-billion program to buy heavy trucks is among those expected to be proceed without issues. Canada also expects to award a contact next year for a mid-life upgrade of the fleet of Cormorant search-and-rescue helicopters, and the conversion of former U.S. presidential helicopters so they can join the flight line for rescue operations. But the report warns there could be problems with other upcoming projects such as the purchase of a fleet of drones. It noted that there might not be enough procurement staff with the required expertise to move that program forward on schedule. The department hopes to deal with the problem by hiring contractors. A draft invitation to qualify for that project was released April 5 and a contact is expected to be awarded in 2022, the document said. The first of a fleet of new fixed-wing search-and-rescue aircraft, meanwhile, are to be delivered in December. The first plane will be sent to 19 Wing Comox, B.C. in the spring of 2020. The 16 new planes will be phased in between 2020 and 2022. But DND acknowledged it is keeping an eye on the potential that schedule could be affected because of the “complexities associated with transitioning to the new fleet while maintaining the current search and rescue posture.” In addition, DND is keeping watch on problems with its new upgraded light armoured vehicles. Though the vehicles have been delivered on time, some technical issues will be fixed through a retrofit program. There have also been problems with software design and qualification of components in another new fleet of armoured vehicles that will be used for battlefield surveillance, the first of which is to be delivered next year. The first new supply ship for the Royal Canadian Navy, being built in Vancouver, is expected in 2023 but won't be ready for operations until a year later. The delivery of the second supply ship “is currently under review,” the update added. In the meantime, the navy has access to MV Asterix, the supply ship at the heart of the court case involving Vice-Admiral Mark Norman. That ship, currently being leased to the navy by Quebec firm Davie Shipbuilding, was delivered on time and on budget and is considered a procurement success story. https://ottawacitizen.com/news/canada/government-expects-to-award-contract-for-new-fighter-jet-fleet-in-2022-but-admits-it-could-face-delays/wcm/a34c8b83-3838-4ff9-87ac-1741fd434059

All news