SBIR-STTR Award

Dependable DevOps: Building Reliable and Secure Software via Automated Bug Finding
Award last edited on: 2/17/21

Sponsored Program
SBIR
Awarding Agency
DOD : AF
Total Award Amount
$74,942
Award Phase
1
Solicitation Topic Code
AF192-005
Principal Investigator
Clark L Coleman

Company Information

Zephyr Software LLC

4826 Stony Point Road
Barboursville, VA 22923
   (434) 242-4280
   jwd@zephyr-software.com
   www.zephyr-software.com
Location: Single
Congr. District: 07
County: Greene

Phase I

Contract Number: FA8730-19-P-0025
Start Date: 00/00/00    Completed: 00/00/00
Phase I year
2019
Phase I Amount
$74,942
Despite advances, modern software development methods still result in code being deployed with severe errors. There are many reasons why, including growing software complexity and required rapid development needed to quickly deliver systems. Unreliable software is especially problematic in high-value systems such as critical infrastructure (e.g., the power grid) or military and government systems where bugs can result in severe security breaches. To improve software quality, we propose augmenting the software development process with automatic bug finding. This approach goes beyond merely using inadequate programmer-developed tests. Instead, software bugs are immediately and automatically discovered pre-deployment. Using Zafl, our automatic bug-finding system based on binary-only fuzzing, serious bugs can be found early in development. Being binary-only, Zafl easily integrates with complex build systems as no changes are necessary to the development processes. Instead, Zafl operates directly on built binary programs (which must already be packaged and shipped before software use). Key benefits of this approach are finding bugs in any source language (compiled in any manner), and automatically filing actionable bug reports. We propose to containerize Zafl for easy scaling to production environments and include automatic bug reporting and forensics to help developers deploy significantly more dependable and secure software.

Phase II

Contract Number: ----------
Start Date: 00/00/00    Completed: 00/00/00
Phase II year
----
Phase II Amount
----