-
-
News
News Highlights
- Books
Featured Books
- smt007 Magazine
Latest Issues
Current IssueSpotlight on India
We invite you on a virtual tour of India’s thriving ecosystem, guided by the Global Electronics Association’s India office staff, who share their insights into the region’s growth and opportunities.
Supply Chain Strategies
A successful brand is built on strong customer relationships—anchored by a well-orchestrated supply chain at its core. This month, we look at how managing your supply chain directly influences customer perception.
What's Your Sweet Spot?
Are you in a niche that’s growing or shrinking? Is it time to reassess and refocus? We spotlight companies thriving by redefining or reinforcing their niche. What are their insights?
- Articles
- Columns
- Links
- Media kit
||| MENU - smt007 Magazine
DARPA Taps RTX to Strengthen Cyber Resiliency
November 11, 2024 | RTXEstimated reading time: 2 minutes
RTX's BBN Technologies was awarded a contract to support DARPA's Compartmentalization and Privilege Management, or CPM, program. The CPM program aims to enhance cyber resilience by automatically subdividing software systems into smaller, secure compartments, preventing initial breaches from escalating into successful cyberattacks while maintaining system efficiency.
According to the U.S. Government Accountability Office, the U.S. Department of Defense has experienced more than 12,000 cyber incidents since 2015. These incidents threaten personal privacy as well as national security. The most common exploit involves a hacker gaining access to a system and then taking advantage of coding errors that allow them to escalate their system privileges to gain access to sensitive data or to take control of the system.
Under CPM, BBN is developing the Analysis and Restructuring for Containment (ARC) tool to thwart unauthorized privilege escalations and lateral movements within software systems. ARC will be engineered to automatically analyze large code bases and construct smaller, secure compartments. By applying the principle of least privilege at a sub-program level, the tool will ensure that only the minimum access necessary is granted for code to execute. This approach to software security will significantly limit the scope of potential damage in the event of a successful infiltration of the software.
"Today's complex attack surfaces and increasingly sophisticated cyberattacks mean that even a single point of vulnerability can compromise an entire system," said Aaron Paulos, BBN principal investigator. "Our solution will enhance the security of critical software systems while preserving performance, which is essential for maintaining operational readiness. The goal is to create compartments that isolate risks, making systems more resistant to cyberattacks."
A key element of the program is the requirement to minimize the impact of compartmentalization on overall performance while producing secure, tight compartments. To achieve this, ARC will generate solutions that balance multiple objectives. For instance, some parts of software application will require performant access, while others might introduce significant exposure to risk. The tool will enable system administrators to selectively apply security measures to those areas deemed most critical, as a way of managing the trade-offs between performance and security.
ARC builds on several unique capabilities from BBN's prior work in cybersecurity and software analysis. The team intends to integrate capabilities that use:
- Automated program analysis to assess and identify potential threats in software, ensuring thorough evaluation and security.
- Verifiable program restructuring to improve security and controls, including adjustments to memory and function usage.
- Automated reasoning to develop effective security solutions by exploring different options and balancing performance with risk management.
- The BBN-led team includes Northwestern University, George Washington University and Kestrel Institute. Work on the program will be completed in Cambridge, Massachusetts; Evanston, Illinois; Washington, D.C.; and Palo Alto, California.
This material is based upon work supported by the United States Air Force and DARPA under contract number FA8750-23-C-B031. Any opinions, findings, and conclusions or recommendations expressed in this material are those of the author and do not reflect the views of the United States Air Force and DARPA.
Testimonial
"We’re proud to call I-Connect007 a trusted partner. Their innovative approach and industry insight made our podcast collaboration a success by connecting us with the right audience and delivering real results."
Julia McCaffrey - NCAB GroupSuggested Items
Siemens, TRUMPF Partner to Accelerate Digital Manufacturing and AI Readiness
09/16/2025 | SiemensTechnology company Siemens and leading machine tools and laser manufacturer TRUMPF announced a partnership that promises to elevate industrial production by harnessing advanced digital manufacturing solutions.
Bittium Launches New Ultra Secure Bittium Tough Mobile 3 and Establishes a Strategic Collaboration with HMD Secure
09/10/2025 | CisionBittium Corporation announces the launch of its new generation high-security Bittium Tough Mobile 3 smartphone. At the heart of the device is Bittium’s secure software technology, which provides users with a comprehensive communication solution designed to meet the ever-growing requirements for mobile security and performance.
I-Connect007 Editor’s Choice: Five Must-Reads for the Week
09/05/2025 | Andy Shaughnessy, I-Connect007It’s almost fall here in Atlanta, and that means that the temperature is finally dropping. And it quit raining! It’s been raining since March, and I’m so over it, as the social influencers say. Last night we grilled out on the deck, and it wasn’t hot, and we didn’t get rained on. Life is good. It was a busy week in the industry. In this installment of my must-reads, we say goodbye to Walt Custer, the man who made PCB data points interesting for the rest of us.
What EMS Firms Want From Their Software—and What They Get
09/03/2025 | Thiago Guimaraes, Global Electronics AssociationLast November, the Global Electronics Association [as IPC] surveyed EMS and OEM companies to better understand the software tools driving their operations and uncover trends in adoption, satisfaction, and challenges. The survey assessed software tools across critical functions, including ERP, MES, PLM, QMS, LMS, quoting systems, and CRM. Participants shared insights on tool adoption, satisfaction, and selection priorities.
Peak Rock Capital Affiliate Completes Acquisition of Aegis Software
08/25/2025 | Aegis SoftwareAn affiliate of Peak Rock Capital, a leading middle-market private investment firm, announced that it has completed the acquisition of Aegis Industrial Software, a global provider of innovative manufacturing execution system (MES) software for electronic components and discrete manufacturing across the aerospace & defense, medical device, consumer electronics, and diversified industrial end-markets.