The Georgia Institute of Technology has been awarded a $2 million Navy contract for cybersecurity research. The contract covers two projects.
One project, titled “BFT++: Attack Tolerance in Hard Real-Time Systems,” will research attack-tolerant cyber systems, according to a university news release. The university will work on techniques that eliminate common software vulnerabilities in different nodes of a networked group and distribute a security protection into multiple nodes of the group. The protection will not extend to all nodes, however, so that protection strength remains undiluted without reducing the performance overhead.
“Many intrusion tolerance techniques slow down the control system, which is undesirable and may be life-threatening in a weapons system,” said primary investigator Taesoo Kim, assistant professor in the School of Computer Science at Georgia Tech. “We will develop the techniques to detect failure due to an attack, replace the compromised node with a back-up, and reconstitute it – all within the hard, real-time requirement. In addition, we will develop software and system diversification techniques to ensure that an attack is detected early.”
The second project, titled “Embedasploit: a Pen-test in a Box for Industrial Control Systems,” will create a system to fingerprint an industrial control network, catalog its known flaws, emulate the whole system for simulation and outline a model that prevents hackers from listening to system activity, injecting malicious traffic or obtaining binary code, according to the announcement. The research will be tested on engine control units in a modern car.
“Assessing the security of industrial control systems today often takes the form of a ‘penetration test’ that requires someone familiar with security practices, reverse engineering, real-world exploitation and the intricacies of a particular industrial domain,” said primary investigator Wenke Lee, director of the Georgia Tech Information Security Center in the School of Computer Science. “All of that is rare in a single team or person, so we propose an end-to-end system that can automatically detect, and adapt inside new systems and networks.”
Both projects will span three years.




