The technology research arm of the US Department of Defense has launched a cyber-security grand challenge – a contest to take on a fundamental problem in cyber-security – tasking teams to create a system capable of automatically defending a network by generating security patches.
Modelled after the grand challenges for the development of automated vehicles and cheap space flight, the Defence Advanced Research Projects Agency (DARPA) contest aims to help give companies, academic institutions and government agencies the ability to react to vulnerabilities in near real time. DARPA envisions the winning system as one that finds vulnerable software, generates a patch for the issue and plugs the holes. The top-three teams in the event will split $3.75 million (£2.4m) in prize money, with the top team taking home $2 million.
“The growth trends we’ve seen in cyber-attacks and malware point to a future where automation must be developed to assist IT security analysts,” Dan Kaufman, director of DARPA’s Information Innovation Office, said in a statement.
The challenges were to stop epidemic-style worm and virus attacks, develop highly trustworthy systems capable of securely handling critical functions, create security risk management systems that are as good as financial risk management systems, and deliver to end users the ability to easily control their privacy and security.
“I would argue – without much opposition from anyone knowledgeable, I daresay – that we have not made any measurable progress against any of these goals, and have probably lost ground in at least two,” he wrote. “Why is that? Largely economics, and bad understanding of what good security involves.”
In the DARPA competition, the research agency will create a set of digital attack simulations against which the automated systems have to defend. In the first event, the teams will have to automatically analyse software programs and find vulnerabilities, with later simulations requiring that contenders automatically patch the software’s vulnerabilities.
The DARPA challenge, however, will not likely solve any of the fundamental problems in security because it is not a grand-enough challenge, said Michael Davis, chief technology officer for CounterTack, a cyber-security consultancy.
“I believe they are missing the largest part of the problem: the attacker,” he said in a statement sent to eWEEK. “New weapons move the arms race forward, but the fact still remains that attackers will undoubtedly continue to research and identify new ways to breach enterprise security and those ways might not be detected by the automated capabilities from DARPA making it ineffective.”
Rather than focus on vulnerabilities, the challenge should focus on finding and detecting bad behaviours on the systems, he said.
Do you know all about biometric technology? Take our quiz.
Originally published on eWeek.
Troubled battery maker Northvolt reportedly considers Chapter 11 bankruptcy protection in the United States as…
Microsoft's cloud business practices are reportedly facing a potential anti-competitive investigation by the FTC
Ilya Lichtenstein sentenced to five years in prison for hacking into a virtual currency exchange…
Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…
Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…
Elon Musk continues to provoke the ire of various leaders around the world with his…