Application Security
6/3/2014
04:05 PM
Sara Peters
Sara Peters
Quick Hits
Connect Directly
Twitter
RSS
E-Mail
50%
50%

DARPA Announces Teams For First Cyber Grand Challenge

DEF CON 2016 will host the final competition for DARPA's first-of-its-kind tournament for developing automated security systems that can fight against cyber attacks as fast as they are launched.

Thirty-five teams of security researchers have signed up to compete in DARPA's first Grand Cyber Challenge, a two-year project to develop better systems that can automatically react to security attacks. DARPA describes it as "the first computer security tournament designed to test the wits of machines, not experts." The project will culminate with a capture the flag competition at DEF CON 2016.

As described in the announcement today:

'Today’s security methods involve experts working with computerized systems to identify attacks, craft corrective patches and signatures and distribute those correctives to users everywhere -- a process that can take months from the time an attack is first launched,' said Mike Walker, DARPA program manager. 'The only effective approach to defending against today’s ever-increasing volume and diversity of attacks is to shift to fully automated systems capable of discovering and neutralizing attacks instantly.'

The Grand Cyber Challenge is DARPA's effort to accelerate that process.

To create a safe, isolated test/dev lab for the competitors, DARPA today released an open-source Linux extension, called DECREE, that is "incompatible with any other software in the world." It is also developing custom data-visualization technology that will enable spectators across the globe to follow the action.

Although the competitors have all committed themselves to a two-year project, the spoils of victory are considerable. The first-place prize is $2 million. Second place is $1 million and third-place is $750,000.

There's still time to sign up. Registration closes November 2.

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
6/5/2014 | 12:28:48 PM
Re: Spectators
@AaronM283  I'm afraid I haven't seen any further information about the visualization tool they're developing, but I'll poke around and see what I can find.
AaronM283
50%
50%
AaronM283,
User Rank: Apprentice
6/5/2014 | 9:45:34 AM
Spectators
Sara was there any other information regardin?

"It is also developing custom data-visualization technology that will enable spectators across the globe to follow the action."

 
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
DevOps’ Impact on Application Security
DevOps’ Impact on Application Security
Managing the interdependency between software and infrastructure is a thorny challenge. Often, it’s a “developers are from Mars, systems engineers are from Venus” situation.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-2595
Published: 2014-08-31
The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, enables MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls for an unrestricted mmap interface, which all...

CVE-2013-2597
Published: 2014-08-31
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that lever...

CVE-2013-2598
Published: 2014-08-31
app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite signature-verification code via crafted boot-image load-destination header values that specify memory ...

CVE-2013-2599
Published: 2014-08-31
A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.3.x enables debug logging, which allows attackers to obtain sensitive disk-encryption pas...

CVE-2013-6124
Published: 2014-08-31
The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command, as demonstrated by changing the permissions of an arbitrary fil...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.