Description

Supply chain security is paramount in a world increasingly reliant on third-party libraries and binaries, which often introduce hidden vulnerabilities and risks into software systems. We focus on understanding and addressing these risks by employing static and dynamic techniques. We understand and score the quality of library code through precise static analysis.  Through static transformations, we harden third-party components against known and unknown vulnerabilities, reducing their attack surface and enhancing their reliability. Complementing this, dynamic monitoring and enforcement ensure that these components behave securely at runtime, detecting and mitigating potential threats as they occur. Additionally, we have technologies to automatically retrofit compartmentalization onto third-party libraries, implementing runtime protections that mitigate the exploitation of potential vulnerabilities and limit their impact. By securing the software supply chain end-to-end, we enable organizations to integrate third-party software while minimizing exposure to evolving threats confidently.

Projects

DRIFT

Enhancing SBOMs to solve vulnerability discovery, reachability and remediation.

PI: Michael Gordon

Technical Areas: Static Analysis, Dynamic Analysis, Binary Patching, Supply Chain Security, Vulnerability Remediation, Vulnerability Reachability

ClearScope

Precise and comprehensive runtime monitoring of sensitive behaviors in Android apps.

PI: Michael Gordon

Technical Areas: Dynamic Analysis, Runtime Protection, Supply Chain Security, Vulnerability Discovery

Arya (TA2)

Automated exploitation and vulnerability validation across diverse systems

PI: Jeff Perkins

Technical Areas: Dynamic Analysis, Supply Chain Security, Vulnerability Discovery

Aria

Transforming AppSec with in-application, zero-trust privileges and secure computation offloading.

PI: Ricardo Baratto

Technical Areas: Runtime Protection, Supply Chain Security, Vulnerability Discovery, Vulnerability Remediation, Vulnerability Reachability

Recent Blog Posts and News

Papers