HOME     MENU     SEARCH     NEWSLETTER    
NEWS & INFORMATION FOR TECHNOLOGY PURCHASERS. UPDATED 14 MINUTES AGO.
You are here: Home / Enterprise I.T. / DARPA's Cyber Contest Not Enough
Build Apps 5x Faster
For Half the Cost Enterprise Cloud Computing
On Force.com
Does DARPA's Cyber Challenge Go Far Enough?
Does DARPA's Cyber Challenge Go Far Enough?
By Jennifer LeClaire / NewsFactor Network Like this on Facebook Tweet this Link thison Linkedin Link this on Google Plus
PUBLISHED:
OCTOBER
24
2013

The Defense Advanced Research Projects Agency (DARPA) is launching what it calls a Cyber Grand Challenge. It’s a tournament, of sorts, to develop fully automatic network defense systems.

DARPA envisions teams creating automated systems that would compete against each other to evaluate software, test for vulnerabilities, generate security patches and apply them to protected computers on a network. A whopping $2 million goes to the team that can bridge the expert gap between security software and cutting-edge program analysis research.

DARPA expects the competition to draw teams of experts from across a wide range of computer security disciplines including reverse engineering, formal methods, program analysis and computer security competition. Second place wins $1 million and third place takes home $750,000.

“Today, our time to patch a newly discovered security flaw is measured in days," said Mike Walker, DARPA program manager. “Through automatic recognition and remediation of software flaws, the term for a new cyber attack may change from zero day to zero second.”

What About the Attacker?

We caught up with Michael Davis, CTO of cyber attack detection service CounterTack, to get his take on the DARPA challenge. He told us he’s excited about the challenge because it drives more awareness of the problem, which he sees growing larger, more complex, and more costly to defend.

Davis applauds DARPA for wanting to change that, but he doesn’t feel the agency is going far enough. That, he said, is because based on the details he’s read DARPA wants to focus on the automatic identification of vulnerabilities and then patches for those vulnerabilities.

“I believe they are missing the largest part of the problem: the attacker,” Davis said. “History has shown us that cybersecurity is an arm's race and while the DARPA challenge will raise the bar, I believe it is akin to providing soldiers with a new semi-automatic weapon while the enemy has an old single shot rifle rather than changing the state of the war.”

Where We Should Focus?

New weapons move the arms race forward, he said, but the fact still remains that attackers will undoubtedly continue to research and identify new ways to breach enterprise security. Those ways, he said, might not be detected by the automated capabilities from DARPA, making them ineffective.

“The ever-changing arms race is why I believe most security teams should focus less on trying to find the unknown zero-day holes that attackers are looking for, which are ever changing, and more on the indicators that show that an attacker has bypassed security controls and is performing unauthorized activity, which are relatively static,” he said.

“If DARPA can incorporate automated analysis of attacker behavior into their challenge I think they will have a much more well-rounded and attacker resistant solution,” he added.

Tell Us What You Think
Comment:

Name:

Like Us on FacebookFollow Us on Twitter
TOP STORIES NOW
MAY INTEREST YOU
Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.
MORE IN ENTERPRISE I.T.
Product Information and Resources for Technology You Can Use To Boost Your Business

NETWORK SECURITY SPOTLIGHT
An easily avoided security lapse -- failure to use two-factor authentication on a single server -- is being blamed for the massive computer breach that hit JPMorgan Chase this past summer.

ENTERPRISE HARDWARE SPOTLIGHT
Flying under the radar just before Christmas, HP has launched a new version of its Chromebook 14, most notable for its touch screen and full high-definition display, plus more powerful specs.
© Copyright 2014 NewsFactor Network, Inc. All rights reserved. Member of Accuserve Ad Network.