Application Security
6/3/2014
04:05 PM
Sara Peters
Sara Peters
Quick Hits
Connect Directly
Twitter
RSS
E-Mail
50%
50%

DARPA Announces Teams For First Cyber Grand Challenge

DEF CON 2016 will host the final competition for DARPA's first-of-its-kind tournament for developing automated security systems that can fight against cyber attacks as fast as they are launched.

Thirty-five teams of security researchers have signed up to compete in DARPA's first Grand Cyber Challenge, a two-year project to develop better systems that can automatically react to security attacks. DARPA describes it as "the first computer security tournament designed to test the wits of machines, not experts." The project will culminate with a capture the flag competition at DEF CON 2016.

As described in the announcement today:

'Today’s security methods involve experts working with computerized systems to identify attacks, craft corrective patches and signatures and distribute those correctives to users everywhere -- a process that can take months from the time an attack is first launched,' said Mike Walker, DARPA program manager. 'The only effective approach to defending against today’s ever-increasing volume and diversity of attacks is to shift to fully automated systems capable of discovering and neutralizing attacks instantly.'

The Grand Cyber Challenge is DARPA's effort to accelerate that process.

To create a safe, isolated test/dev lab for the competitors, DARPA today released an open-source Linux extension, called DECREE, that is "incompatible with any other software in the world." It is also developing custom data-visualization technology that will enable spectators across the globe to follow the action.

Although the competitors have all committed themselves to a two-year project, the spoils of victory are considerable. The first-place prize is $2 million. Second place is $1 million and third-place is $750,000.

There's still time to sign up. Registration closes November 2.

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
6/5/2014 | 12:28:48 PM
Re: Spectators
@AaronM283  I'm afraid I haven't seen any further information about the visualization tool they're developing, but I'll poke around and see what I can find.
AaronM283
50%
50%
AaronM283,
User Rank: Apprentice
6/5/2014 | 9:45:34 AM
Spectators
Sara was there any other information regardin?

"It is also developing custom data-visualization technology that will enable spectators across the globe to follow the action."

 
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
DevOps’ Impact on Application Security
DevOps’ Impact on Application Security
Managing the interdependency between software and infrastructure is a thorny challenge. Often, it’s a “developers are from Mars, systems engineers are from Venus” situation.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-5367
Published: 2015-08-27
The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows local users to gain privileges via unspecified vectors.

CVE-2015-5368
Published: 2015-08-27
The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows remote attackers to modify data or cause a denial of service, or execute arbitrary code, via unspecified vectors.

CVE-2013-7424
Published: 2015-08-26
The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to pin...

CVE-2015-2139
Published: 2015-08-26
HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5403.

CVE-2015-2140
Published: 2015-08-26
HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

Dark Reading Radio
Archived Dark Reading Radio
Another Black Hat is in the books and Dark Reading was there. Join the editors as they share their top stories, biggest lessons, and best conversations from the premier security conference.