SBIR-STTR Award

Firmware Automated Analysis at Scale with Testing
Award last edited on: 7/17/2019

Sponsored Program
SBIR
Awarding Agency
DHS
Total Award Amount
$1,149,766
Award Phase
2
Solicitation Topic Code
H-SB018.1-008
Principal Investigator
Ang Cui

Company Information

Red Balloon Security Inc (AKA: RBS)

336 West 37th Street Suite 1024
New York, NY 10018
   (201) 906-3438
   info@redballoonsecurity.com
   www.redballoonsecurity.com
Location: Single
Congr. District: 12
County: New York

Phase I

Contract Number: 70RSAT18C00000023
Start Date: 5/2/2018    Completed: 11/1/2018
Phase I year
2018
Phase I Amount
$149,969
The firmware running on mobile, embedded, and Internet of things devices is often treated as a blackbox by organizations. These firmware images can contain a myriad of n-day vulnerabilities, both malicious and unintentional backdoors, and other unwanted functionality. Unfortunately, analyzing these firmware images is a difficult and time-consuming task as each firmware can be packed with layers of compression and obfuscation along with specialized operating systems and filesystems. We propose Firmware Automated Analysis at Scale with Testing (FAAST), a technology built on top of Red Balloon Security's FRAK technology, a proprietary framework for unpacking, analyzing, modifying, and packing firmware images. FAAST will integrate additional specialized FRAK analyzers and utilize FRAK's client server architecture to automatically unpack and analyze firmware images returning human and machine readable reports back to the user.

Phase II

Contract Number: 70RSAT19C00000006
Start Date: 5/1/2019    Completed: 11/1/2020
Phase II year
2019
Phase II Amount
$999,797
The firmware running on mobile, embedded, and Internet of things devices is often treated as a blackbox by organizations. These firmware images can contain a myriad of n-day vulnerabilities, both malicious and unintentional backdoors, and other unwanted functionality. Unfortunately, analyzing these firmware images is a difficult and time-consuming task as each firmware can be packed with layers of compression and obfuscation along with specialized operating systems and filesystems. We propose Firmware Automated Analysis at Scale with Testing (FAAST), a technology built on top of Red Balloon Security's FRAK technology, a proprietary framework for unpacking, analyzing, modifying, and packing firmware images. FAAST will integrate additional specialized FRAK analyzers and utilize FRAK's client server architecture to automatically unpack and analyze firmware images returning human and machine readable reports back to the user.