SBIR-STTR Award

Hybrid Prediction for Embedded Malware
Award last edited on: 4/7/2017

Sponsored Program
SBIR
Awarding Agency
DHS
Total Award Amount
$846,753
Award Phase
2
Solicitation Topic Code
H-SB016.1-003
Principal Investigator
Ang Cui

Company Information

Red Balloon Security Inc (AKA: RBS)

336 West 37th Street Suite 1024
New York, NY 10018
   (201) 906-3438
   info@redballoonsecurity.com
   www.redballoonsecurity.com
Location: Single
Congr. District: 12
County: New York

Phase I

Contract Number: HSHQDC-16-C-00072
Start Date: 5/4/2016    Completed: 11/3/2016
Phase I year
2016
Phase I Amount
$99,997
Predicting malware trends and designing defenses to defeat the next generation of malware is difficult but necessary in order to significantly increase the cost to attackers of developing malware and executing successful attacks. Without such malware trend predictions, we will continually be defending against yesterday's attacks and will remain unprepared for new threats. Embedded devices are becoming the next target for attackers as traditional workstations and servers become more secure. We will create a hybrid approach toward embedded device malware trend prediction. Our approach targets both long-term malware trend prediction utilizing attack graphs and short-term approaches monitoring malware and capturing forensic data to provide real-time predictions. A hybrid of short-term and long-term approaches offers many benefits. Captured samples would confirm or better inform the long-term predictions of what evasions and attack paths malware uses. Long-term predictions would enable advanced defenses to be prepared to capture malware samples. Our hybridized predictive malware trending scheme will significantly increase situational awareness into both short-term and long-term attack trends. Furthermore, our output will enhance embedded attack incidence response capabilities at an enterprise level and predict future attack trends at both tactical and strategic time scales.

Phase II

Contract Number: HSHQDC-17-C-00007
Start Date: 4/15/2017    Completed: 4/14/2019
Phase II year
2017
Phase II Amount
$746,756
Predicting malware trends and designing defenses to defeat the next generation of malware is difficult but necessary in order to significantly increase the cost to attackers of developing malware and executing successful attacks. Without such malware trend predictions, we will continually be defending against yesterday's attacks and will remain unprepared for new threats. Embedded devices are becoming the next target for attackers as traditional workstations and servers become more secure.