Vetting Commodity IT Software and Firmware (VET)
Title | Vetting Commodity IT Software and Firmware (VET) |
Publication Type | Web Article |
Year of Publication | 2021 |
Authors | Raymond Richards |
Access Date | October 26, 2021 |
Publisher | DARPA |
Type of Medium | Website Article |
Keywords | Automation, C3E, cyber, firmware, formal, information technology, IT, Software, Supply chains, Trust |
Abstract | Government agencies and the military rely upon many kinds of Commercial Off-the-Shelf (COTS) commodity Information Technology (IT) devices, including mobile phones, printers, computer workstations and many other everyday items. Each of these devices is the final product of long supply chains involving many vendors from many nations providing various components and subcomponents, including considerable amounts of software and firmware. Long supply chains provide adversaries with opportunities to insert hidden malicious functionality into this software and firmware that adversaries can exploit to accomplish harmful objectives, including exfiltration of sensitive data and sabotage of critical operations. |
URL | https://www.darpa.mil/program/vetting-commodity-it-software-and-firmware |
Citation Key | node-80014 |