Back to news

August 5, 2019 | Local, Security

Hacker Community to Take on DARPA Hardware Defenses at DEF CON 2019

This month, DARPA will bring a demonstration version of a secure voting ballot box equipped with hardware defenses in development on the System Security Integrated Through Hardware and Firmware (SSITH) program to the DEF CON 2019 Voting Machine Hacking Village (Voting Village). The SSITH program is developing methodologies and design tools that enable the use of hardware advances to protect systems against software exploitation of hardware vulnerabilities. To evaluate progress on the program, DARPA is incorporating the secure processors researchers are developing into a secure voting ballot box and turning the system loose for public assessment by thousands of hackers and DEF CON community members.

Many of today's hardware defenses cover very specific instances or vulnerabilities, leaving much open to attack or compromise. Instead of tackling individual instances, SSITH researchers are building defenses that address classes of vulnerabilities. In particular, SSITH is tackling seven vulnerabilities classes identified by the NIST Common Weakness Enumeration Specification (CWE), which span exploitation of permissions and privilege in the system architectures, memory errors, information leakage, and code injection.

“There are a whole set of cyber vulnerabilities that happen in electronic systems that are at their core due to hardware vulnerabilities – or vulnerabilities that hardware could block,” said Dr. Linton Salmon, the program manager leading SSITH. “Current efforts to provide electronic security largely rely on robust software development and integration, utilizing an endless cycle of developing and deploying patches to the software firewall without addressing the underlying hardware vulnerability. The basic concept around SSITH is to make hardware a more significant participant in cybersecurity, rather than relegating system security only to software.”

Under the SSITH program, researchers are exploring a number of different design approaches that go well beyond patching. These include using metadata tagging to detect unauthorized system access; employing formal methods to reason about integrated circuit systems and guarantee the accuracy of security characteristics; and combining hardware performance counters (HPCs) with machine learning to detect attacks and establish protective fences within the hardware. One team from the University of Michigan is developing a novel security approach that changes the unspecified semantics of a system every 50 milliseconds. Currently, attackers continuously probe a system to locate these undefined sections and, over time, are able to create a system map to identify possible hacks. By changing the construct every 50 milliseconds, attackers do not have enough time to find those weaknesses or develop an accurate representation of the system as a whole.

To evaluate the hardware security concepts in development on the SSITH program, DARPA – working with Galois – is pursuing a voting system evaluation effort to provide a demonstration system that facilitates open challenges. The program elected to use a voting system as its demonstration platform to provide researchers with an accessible application that can be evaluated in an open forum. Further, the topic of election system security has become an increasingly critical area of concern for the hacker and security community, as well as the United States more broadly.

“DARPA focuses on creating technologies to enhance national defense, and election system security falls within that remit. Eroding trust in the election process is a threat to the very fabric of our democracy,” noted Salmon.

While protecting democracy is a critical national defense issue, SSITH is not trying to solve all issues with election system security nor is it working to provide a specific solution to use during elections. “We expect the voting booth demonstrator to provide tools, concepts, and ideas that the election enterprise can use to increase security, however, our true aim is to improve security for all electronic systems. This includes election equipment, but also defense systems, commercial devices, and beyond,” said Salmon.

During DEF CON 2019, the SSITH voting system demonstrator will consist of a set of RISC-V processors that the research teams will modify to include their SSITH security features. These processors will be mounted on field programmable gate arrays (FPGAs) and incorporated into a secure ballot box. Hackers will have access to the system via an Ethernet port as well as a USB port, through which they can load software or other attacks to challenge the SSITH hardware. Since SSITH's research is still in the early stages, only two prototype versions of the 15 processors in development will be available for evaluation.

“At this year's Voting Village, hackers may find issues with the processors and quite frankly we would consider that a success. We want to be transparent about the technologies we are creating and find any problems in these venues before the technology is placed in another venue where a compromise could be more dangerous,” said Salmon.

Following DEF CON 2019, the voting system evaluation effort will go on a university roadshow where additional cybersecurity experts will have an opportunity to further analyze and hack the technology. In 2020, DARPA plans to return to DEF CON with an entire voting system, which will incorporate fixes to the issues discovered during the previous year's evaluation efforts. The 2020 demonstrator will use the STAR-Vote system architecture, which is a documented, open source architecture that includes a system of microprocessors for the voting booth, ballot box, and other components. It also includes a verifiable paper ballot, providing both digital and physical representations of the votes cast within the booth.

“While the 2020 demonstrator will provide a better representation of the full attack surface, the exercise will not result in a deployable voting system. To aid in the advancement of secure election equipment as well as electronic systems more broadly, the hardware design approaches and techniques developed during the SSITH program will be made available to the community as open-source items,” concluded Salmon.

https://www.darpa.mil/news-events/2019-08-01

On the same subject

  • Pushing fighter jet deadline raises questions on which jets can do the work: experts

    March 2, 2020 | Local, Aerospace

    Pushing fighter jet deadline raises questions on which jets can do the work: experts

    Amanda Connolly GlobalNews.ca WATCH: Canadian fighter jets intercepted two Russian bombers travelling near the North American coastline. While they were in international airspace they entered an area patrolled by the Canadians. The two American aerospace firms that want the Canadian government to buy their fighter jets say they did not request an extension on the deadline for bids. At the same time, defence experts say the decision to grant the extension reflects the bigger challenge facing a government that has repeatedly insisted a competition is the only way to move forward with the $19-billion procurement, despite there being a limited pool of options. “The government believes it needs to run a competition, but there're many situations where, in reality, there's only one or two competitors that can actually meet the needs of the Canadian Forces,” said Richard Shimooka, a senior fellow at the Macdonald-Laurier Institute and an expert on defence. “So the government's put in a bit of a pickle by its rhetoric where it wants to portray that ‘yeah, we're having a competition or we're providing value for money and all these kind of important things for Canada', but in fact knows there's really only one competitor.” On Tuesday, the government announcement that the March 30 deadline will be pushed back three months, to June 30 instead. READ MORE: Canadian fighter jet replacement project hit with another delay In a press release on the decision earlier in the week, the government had said this extension was being granted “at the request of industry.” “Procurements of this magnitude are complex, and submission of a good proposal is important for suppliers and for Canada,” the government said in the press release. “This extension allows eligible suppliers to address recent feedback on their security offers, ensuring that Canada receives competitive proposals that meet its technical, cost and economic benefits requirements.” Global News has since been told that feedback included specific assessments about whether a firm would be able to meet the Canadian government's requirements for inter-operability with key allies, including the U.S. and the Five Eyes, and whether allies would be comfortable with them. Because the government is using a process known as phased bids for the fighter jet procurement, bidders get the chance to address any findings of non-compliance with those requirements before submitting their final proposals. And because of how closely Canada and the U.S. work together on issues ranging from intelligence sharing, continental defence and others, inter-operability – or the ability for jets to work seamlessly across various areas where Canadian and American systems overlap – is considered key to this contest. “We've got to buy aircraft that can be completely and seamlessly inter-operable with the U.S.,” said Dave Perry, vice president of the Canadian Global Affairs Institute and an expert on defence procurement. “They've asked the bidders to put forward a proposal on how they're going to make that work.” Perry noted that in the past, questions around how aircraft will operate between Canadian and American systems hasn't been relevant because Canadian fighter jets have always been American. Now, with foreign bidders like Sweden's Saab, the onus is on them to demonstrate their jets can actually do the work. “Saab is the only competitor that is not part of either Five Eyes or Two Eyes and as a result, it would have the greatest amount of work in order to meet the requirements of the Royal Canadian Airforce,” said Shimooka. “Right off the bat, it requires the greatest amount of work for this.” While the government wouldn't say which firm asked for the deadline extension, both Lockheed Martin and Boeing offered statements saying it wasn't them. “We did not request the extension,” said Boeing spokesperson Stephanie Townend. A spokesperson for Lockheed Martin offered a similar response. “We have not requested an extension of delivery for the FFCP preliminary proposal,” said Amanda Hauck, strategic communications lead for the firm. A spokesperson for Saab was less clear. “While Canada's FFCP competition prohibits bidders from commenting publicly on confidential elements of the RFP process, Saab was prepared, and remains prepared, to submit a bid based on the Government of Canada's schedule,” said Patrick Palmer, executive vice president of sales and marketing for Saab Canada. “Saab will continue to finalize its response to all stated requirements of the RFP and can confirm that we will submit a fully compliant response to the Future Fighter Capability Program RFP. We are confident that our offer will provide the best value and best solution for Canada, industry and Canadians for generations to come.” Global News followed up with a request for Palmer to clarify whether the bid Saab said it was prepared to submit by the March 30 deadline would have been a fully compliant one. The company has not yet clarified its response. Saab is offering its Gripen fighter jet in the contest while Lockheed Martin is offering its controversial F-35 and Boeing is offering its Super Hornet. Two other European firms – Airbus and Dassault – dropped out of the contest over the past year-and-a-half, citing security requirements and associated extra costs for the suppliers if chosen. The competition is complicated though by questions and past concerns about both of the American offerings. Boeing brought a trade tribunal complaint against the Canadian aerospace firm Bombardier in 2018 which resulted in Bombardier being forced to pay steep duties on imports of its C-Series plane to the United States. Innovation Minister Navdeep Bains said shortly afterward that the government would weigh a company's “economic behaviour” and that those who had caused economic harm to Canada would be at a disadvantage in the fighter jet competition. That clause still exists in the criteria being used to assess the projects. But Prime Minister Justin Trudeau also promised during the 2015 election campaign not to buy the F-35, the planned procurement of which under the previous Conservative government had been dogged with accusations of hidden costs and sole-sourcing. Since the launch of the competition, the F-35 has become widely-viewed by military experts as a frontrunner in the contest. A government source speaking on background insisted the extension will not impact the expected decision date. The result of the contest are due in 2022 with expected delivery of whichever jet is chosen beginning in 2025. https://q107.com/news/6600416/canada-fighter-jet-competition/

  • $20M in funding available for innovative prototypes

    January 18, 2021 | Local, Aerospace, Naval, Land, C4ISR, Security

    $20M in funding available for innovative prototypes

    Testing Stream Now Open Our Testing Stream is now accepting applications. We have $20M in funding to test your late-stage, pre-commercial innovations in real-life settings with government partners. You could receive up to $550k to test your standard (non-military) innovation, or up to $1.15M to test your military innovation. This Testing Stream call for proposals closes February 5th, 2021 at 14:00 EST. Learn more Who is eligible? We are looking for innovative products and services at technology readiness levels (TRL) 7-9. We have launched two concurrent calls for proposals for: Canadian SMEs Non-SMEs: Sole proprietor, individual, large business, not-for profit, or an academic institution Read all eligibility requirements here. Direct sales for SMEs We are introducing a new program feature for SMEs! SMEs who complete an initial testing contract may be eligible to qualify for our innovation source list. SMES who qualify for our innovation source list will: be eligible to sell to the Government of Canada without further competition for 3 years be eligible for additional contracts (*to a maximum of $8M per contract) Visit our website for all details about the Testing Stream calls for proposals.

  • Analysis: New defence chief's main job could be to preside over budget cuts

    September 14, 2020 | Local, Aerospace, Naval, Land, C4ISR, Security

    Analysis: New defence chief's main job could be to preside over budget cuts

    Premium content David Pugliese, Ottawa Citizen, Postmedia News (dpugliese@ottawacitizen.com) Published: Sep 11 at 7 a.m. Updated: Sep 11 at 2:01 p.m. Candidates have been interviewed for the country's top military position but whoever is selected will likely have the tough job of presiding over significant cuts to the Canadian Forces as the federal government tries to get its fiscal house in order. Prime Minister Justin Trudeau announced July 23 that Gen. Jonathan Vance would leave the position as chief of the defence staff, the job he has held since July 2015. Trudeau said he expected a new CDS to be named in the coming months. Defence and government sources say interviews for the position were held this week with a number of candidates. Lt.-Gen. Christine Whitecross, who is heading into retirement, is considered the front-runner for the job if she wants it. Whitecross still has an office at defence headquarters at Carling Avenue and there is an interest in the Liberal government to have a woman in the job of defence chief for the first time. The view that Whitecross has strong support within the Liberal government was further solidified when Trudeau took the unusual step on July 18 of singling out the lieutenant general on Twitter. He thanked the officer for her three decades of service in the Canadian Forces and for “being a strong voice for gender equality in the military.” Among the other individuals considered to be candidates for the chief of defence staff job are Lt.-Gen. Mike Rouleau, who recently took over as second-in-command of the Canadian Forces, navy commander Vice Adm. Art McDonald, air force commander Lt.-Gen. Al Meinzinger and army commander Lt.-Gen. Wayne Eyre. Vice-Admiral Darren Hawco's name has also been mentioned. At least eight individuals were to be interviewed, according to various government sources. But the new CDS is expected to face the challenge of dealing with significant budget cuts because of the financial strain on federal coffers created by the novel coronavirus pandemic. Spending on various emergency relief programs has resulted in Canada's deficit increasing to $343 billion this year, according to the federal government's economic snapshot released in early July. Trudeau has acknowledged that the full economic impact of the pandemic is unknown. A second COVID-19 wave could further worsen the economic situation. Department of National Defence deputy minister Jody Thomas said in a June 5 interview with The Canadian Press that she hasn't seen any indication defence spending, and the government's defence policy called Strong, Secure, Engaged, or SSE, will even be affected at all by COVID-19. There have been no slowdowns and the DND and Canadian Forces has been aggressively pushing forward on implementing SSE, according to Thomas. Behind the scenes, however, there is significant concern within some quarters in the military about the cuts expected in the coming years. Some organizations within National Defence headquarters have already told staff to prepare for a rocky road in the future. The Canadian Armed Forces and Department of National Defence, with the largest source of discretionary funds in the federal government, is a ripe target for cost-cutting. DND's current budget is listed as $21.9 billion. SSE has been billed by the Liberal government and its supporters as “a historical investment in Canada's military” since it promises $497 billion for the Canadian Armed Forces over 20 years. But the policy was always built on shaky foundations, as was the previous Canada First Defence Strategy brought in by the Conservative government and largely undercut by funding reductions at that time. Despite defence analysts' cheerleading on both policies, the fact is that such strategies only promise future spending. There is no guarantee and plans can be jettisoned as fiscal circumstances change. In 1994 the Liberal government of Prime Minister Jean Chretien embarked on significant cost-cutting measures throughout the federal government as it struggled to deal with the deficit. The Canadian Forces and the DND were a prime target during that period. Equipment was mothballed. Military and civilian staff were cut. The coming years could see a replay of similar cost-reduction measures. Copyright Postmedia Network Inc., 2020 https://www.saltwire.com/news/canada/analysis-new-defence-chiefs-main-job-could-be-to-preside-over-budget-cuts-495666/

All news