Back to news

August 5, 2019 | Local, Security

Hacker Community to Take on DARPA Hardware Defenses at DEF CON 2019

This month, DARPA will bring a demonstration version of a secure voting ballot box equipped with hardware defenses in development on the System Security Integrated Through Hardware and Firmware (SSITH) program to the DEF CON 2019 Voting Machine Hacking Village (Voting Village). The SSITH program is developing methodologies and design tools that enable the use of hardware advances to protect systems against software exploitation of hardware vulnerabilities. To evaluate progress on the program, DARPA is incorporating the secure processors researchers are developing into a secure voting ballot box and turning the system loose for public assessment by thousands of hackers and DEF CON community members.

Many of today's hardware defenses cover very specific instances or vulnerabilities, leaving much open to attack or compromise. Instead of tackling individual instances, SSITH researchers are building defenses that address classes of vulnerabilities. In particular, SSITH is tackling seven vulnerabilities classes identified by the NIST Common Weakness Enumeration Specification (CWE), which span exploitation of permissions and privilege in the system architectures, memory errors, information leakage, and code injection.

“There are a whole set of cyber vulnerabilities that happen in electronic systems that are at their core due to hardware vulnerabilities – or vulnerabilities that hardware could block,” said Dr. Linton Salmon, the program manager leading SSITH. “Current efforts to provide electronic security largely rely on robust software development and integration, utilizing an endless cycle of developing and deploying patches to the software firewall without addressing the underlying hardware vulnerability. The basic concept around SSITH is to make hardware a more significant participant in cybersecurity, rather than relegating system security only to software.”

Under the SSITH program, researchers are exploring a number of different design approaches that go well beyond patching. These include using metadata tagging to detect unauthorized system access; employing formal methods to reason about integrated circuit systems and guarantee the accuracy of security characteristics; and combining hardware performance counters (HPCs) with machine learning to detect attacks and establish protective fences within the hardware. One team from the University of Michigan is developing a novel security approach that changes the unspecified semantics of a system every 50 milliseconds. Currently, attackers continuously probe a system to locate these undefined sections and, over time, are able to create a system map to identify possible hacks. By changing the construct every 50 milliseconds, attackers do not have enough time to find those weaknesses or develop an accurate representation of the system as a whole.

To evaluate the hardware security concepts in development on the SSITH program, DARPA – working with Galois – is pursuing a voting system evaluation effort to provide a demonstration system that facilitates open challenges. The program elected to use a voting system as its demonstration platform to provide researchers with an accessible application that can be evaluated in an open forum. Further, the topic of election system security has become an increasingly critical area of concern for the hacker and security community, as well as the United States more broadly.

“DARPA focuses on creating technologies to enhance national defense, and election system security falls within that remit. Eroding trust in the election process is a threat to the very fabric of our democracy,” noted Salmon.

While protecting democracy is a critical national defense issue, SSITH is not trying to solve all issues with election system security nor is it working to provide a specific solution to use during elections. “We expect the voting booth demonstrator to provide tools, concepts, and ideas that the election enterprise can use to increase security, however, our true aim is to improve security for all electronic systems. This includes election equipment, but also defense systems, commercial devices, and beyond,” said Salmon.

During DEF CON 2019, the SSITH voting system demonstrator will consist of a set of RISC-V processors that the research teams will modify to include their SSITH security features. These processors will be mounted on field programmable gate arrays (FPGAs) and incorporated into a secure ballot box. Hackers will have access to the system via an Ethernet port as well as a USB port, through which they can load software or other attacks to challenge the SSITH hardware. Since SSITH's research is still in the early stages, only two prototype versions of the 15 processors in development will be available for evaluation.

“At this year's Voting Village, hackers may find issues with the processors and quite frankly we would consider that a success. We want to be transparent about the technologies we are creating and find any problems in these venues before the technology is placed in another venue where a compromise could be more dangerous,” said Salmon.

Following DEF CON 2019, the voting system evaluation effort will go on a university roadshow where additional cybersecurity experts will have an opportunity to further analyze and hack the technology. In 2020, DARPA plans to return to DEF CON with an entire voting system, which will incorporate fixes to the issues discovered during the previous year's evaluation efforts. The 2020 demonstrator will use the STAR-Vote system architecture, which is a documented, open source architecture that includes a system of microprocessors for the voting booth, ballot box, and other components. It also includes a verifiable paper ballot, providing both digital and physical representations of the votes cast within the booth.

“While the 2020 demonstrator will provide a better representation of the full attack surface, the exercise will not result in a deployable voting system. To aid in the advancement of secure election equipment as well as electronic systems more broadly, the hardware design approaches and techniques developed during the SSITH program will be made available to the community as open-source items,” concluded Salmon.

https://www.darpa.mil/news-events/2019-08-01

On the same subject

  • CRIAQ START-UP - Deadline January 22nd 2021

    January 11, 2021 | Local, Aerospace, C4ISR, Security

    CRIAQ START-UP - Deadline January 22nd 2021

    Program details The CRIAQ Start-up Grant is targeted for Quebec start-ups active in the aerospace sector. Through a competitive process, CRIAQ will award two $10,000 grants per year in support of the technological development of two start-ups, under the rationale that this funding will help to bring the development of the product or service into alignment with potential users and customers. Project submission and approval process To be eligible for this grant, the company must be a start-up in and at least a portion of its activities must be geared toward the aerospace industry (products, services, solutions) and must be a good standing member of CRIAQ or must commit to become one before the grant is awarded. Elements to be considered will include the following: Date of incorporation within the last two years Number of employees (fewer than ten) Participation in a recognized incubator or accelerator Etc. Proposals will be evaluated according to the following four (4) criteria: Novelty of the product or service Technical feasibility Aerospace business opportunity potential Quality of the team It is also important to note that applications from companies stemming from a CRIAQ research project will be evaluated positively. Application and additional information The form below must be completed and submitted no later than January 22, 2021. The evaluation will be completed by February 5, 2021. Recipients must be available between February 16-19, 2021 for the announcement to be made at the CRIAQ RDV Forum. https://www.criaq.aero/en/program/criaq-start-up/

  • Canada selects SkyAlyne as preferred future aircrew training bidder - Skies Mag

    July 25, 2023 | Local, Aerospace

    Canada selects SkyAlyne as preferred future aircrew training bidder - Skies Mag

    SkyAlyne Canada has been identified as the preferred bidder to prepare future pilots and sensor operators for the Royal Canadian Air Force.

  • F-35: Lockheed Martin promet des retombées de 16,9 milliards $ au Canada d’ici 2058

    August 6, 2020 | Local, Aerospace

    F-35: Lockheed Martin promet des retombées de 16,9 milliards $ au Canada d’ici 2058

    PAUL-ROBERT RAYMOND Le Soleil Le Canada est un partenaire de premier plan dans le programme de l'avion de chasse F-35 depuis les débuts de celui-ci, il y a plus de 20 ans. Celui-ci apporterait des retombées économiques se chiffrant à 16,9 milliards $ jusqu'en 2058 et maintiendrait entre 1675 et 2525 emplois annuellement au pays dans des secteurs de pointe. C'est le message qu'a voulu livrer l'avionneur Lockheed Martin jeudi matin. Lors d'une conférence sur Zoom, Lockheed Martin a signifié que le programme de fabrication de l'avion F-35 implique en ce moment 110 entreprises canadiennes dans 200 projets industriels. Les contrats accordés à celles-ci représentent 2 milliards $ en occasions d'affaires et font travailler 150 000 personnes durant la réalisation du programme. L'avionneur a procédé à cet exercice de relations publiques presque une semaine après avoir officialisé son intention de participer au processus de remplacement de la flotte de chasseurs du Canada. Rappelons que Boeing, avec son Super Hornet Block III (la version la plus moderne du F-18), et Saab, avec son JAS 39 Gripen, sont dans les rangs dans cet appel d'offres visant à acquérir 88 avions de chasse pour l'Aviation royale canadienne (ARC). Les retombées économiques ne seront pas uniquement générées par la construction de ces 88 avions, «mais pour l'ensemble des plus de 3000 avions qui seront commandés dans le monde», assure Steve Callaghan, vice-président à la stratégie et au développement des affaires chez Lockheed Martin. Sachant qu'un autre concurrent pourrait être choisi, il a voulu se faire rassurant. «Si le Canada ne choisit pas le F-35, nous honorerons les contrats avec les entreprises canadiennes jusqu'à leur échéance», a-t-il dit. «Même si le programme du F-35 est mondial, l'industrie canadienne est complètement intégrée dans celui-ci. Nous croyons qu'elle continuera à y contribuer même si le choix de l'ARC est autre que celui du F-35.» Par ailleurs, M. Callaghan assure que les délais encourus en raison de la pandémie de COVID-19 n'affecteraient pas les livraisons des avions pour les Forces armées canadiennes. «Nous commencerons comme prévu la production de vos avions en 2025», a-t-il dit. D'ici la fin de l'année 2020, Lockheed Martin prévoit livrer 141 appareils aux huit forces aériennes qui ont commencé à l'utiliser. Parmi les entreprises canadiennes qui participent au programme F-35, au Québec, il y a Héroux-Devtek, basée à Laval. Plusieurs autres entreprises sont localisées, dans les provinces maritimes, au Manitoba, en Colombie-Britannique, et en Ontario, notamment. https://www.lesoleil.com/affaires/f-35-lockheed-martin-promet-des-retombees-de-169-milliards--au-canada-dici-2058-da3dae8df5db9ac1dd4ef7e7e2944e87

All news