Print Print  
Award Information
Proposal Number: 0522003
Proposal Title: Hardware-based Computer Security System
Topic Number: H-SB05.2-004
Phase: Phase II
Topic Title: HARDWARE-ASSISTED SYSTEM SECURITY MONITOR
Organization: Cybernet Systems Corporation
Address: 3741 Plaza Drive
Ann Arbor, MI 48108-1655  
Abstract: Rootkits are programs that hide pieces of software from the operating system. Rootkits replace or modify intrusion and system status applications, falsely reporting a clean system, when in fact the system has been compromised. A recent McAfee article stated rootkit infections for Windows-based PCs were up 700% for first quarter 2006, and this trend is expected to continue. A compromised system cannot audit itself; our solution relies on a PCI-Express add-on card running Linux that can monitor file accesses, prevent designated sectors modification, and can scan physical memory. This card provides a physically isolated process that monitors the host system, making it impossible for a rootkit to hide completely on the host. The card also logs forensic information and monitors network traffic to scan for malicious behavior. Software developed for our Phase I feasibility study demonstrated that our key components, file hashing and memory scanning, are capable of detecting current and expected rootkit technologies.Another component allows enterprise administration and information gathering across large organizations, and aggregates periodic information snapshots for security auditing and forensics. Requiring physical USB port access for configuration is an option.A bootable CD-ROM rootkit detection and repair tool for Windows would be a valuable spin-off.
Award/Contract Number: NBCHC070050
Period of Performance: 04/30/2007 - 04/29/2010
Award/Contract Value: $749,937.00
Award/Obligated Amount: $749,937.00