Visible to the public Vetting Commodity IT Software and Firmware (VET) Conflict Detection Enabled

TitleVetting Commodity IT Software and Firmware (VET)
Publication TypeWeb Article
Year of Publication2021
AuthorsRaymond Richards
Access DateOctober 26, 2021
PublisherDARPA
Type of MediumWebsite Article
KeywordsAutomation, C3E, cyber, firmware, formal, information technology, IT, Software, Supply chains, Trust
Abstract

Government agencies and the military rely upon many kinds of Commercial Off-the-Shelf (COTS) commodity Information Technology (IT) devices, including mobile phones, printers, computer workstations and many other everyday items. Each of these devices is the final product of long supply chains involving many vendors from many nations providing various components and subcomponents, including considerable amounts of software and firmware. Long supply chains provide adversaries with opportunities to insert hidden malicious functionality into this software and firmware that adversaries can exploit to accomplish harmful objectives, including exfiltration of sensitive data and sabotage of critical operations.

URLhttps://www.darpa.mil/program/vetting-commodity-it-software-and-firmware
Citation Keynode-80014