Tech – AIS Home | Assured Information Security https://www.ainfosec.com Tue, 19 Jan 2021 16:26:24 +0000 en-US hourly 1 https://wordpress.org/?v=6.6.2 https://www.ainfosec.com/wp-content/uploads/2022/10/cropped-ais-icon-1-32x32.png Tech – AIS Home | Assured Information Security https://www.ainfosec.com 32 32 AIS Wins Largest Prime DARPA Contract in Company History https://www.ainfosec.com/ais-wins-largest-darpa-contract-in-company-history?utm_source=rss&utm_medium=rss&utm_campaign=ais-wins-largest-prime-darpa-contract-in-company-history Wed, 30 Dec 2020 20:45:37 +0000 https://www.ainfosec.com/?p=12467 ...]]>

This $9 million contract will enable the Systems Analysis and Exploitation (SAE) Team, along with teaming partners Cummins Incorporated, Colorado State University and GRIMM, to develop challenge problems and evaluate performer’s solutions to problems related to heavy-duty engine systems.

This contract is in support of the DARPA/I2O Assured Micropatching (AMP) program, which aims to develop solutions capable of rapidly producing and deploying embedded system security patches. AIS will seed vulnerabilities throughout embedded systems, guide other performers on the challenge of addressing them and verify successful patching. The goal of the other AMP program performers is to identify those vulnerabilities and patch them without replacing all of the software on the device.

Projected challenge problems and testbed development will focus on devices commonly used to support heavy-duty engine systems used in the trucking industry, marine, power generation and military ground vehicle systems. This is a focus area AIS is not only very interested in, but one in which we have the experience necessary to develop the required challenge problems. The devices we will be working with support automotive and heavy trucking. We’ll take a computer that can be inserted into a truck and drop a vulnerability into it. Then, we will verify that the solutions provided by the other performers address the vulnerability and do not impact the normal operation of the system.

While this initiative is focused on the target space of automotive and heavy trucks, the same engine controllers are also in use in military systems, expanding the application of our efforts to the government.

This is a direct result of AIS putting in the effort, learning the customer and the technology space, and building relationships. We cannot wait to get our hands dirty and work on the AMP program and start playing with trucks.

*The views, opinions, and/or findings expressed are those of the author(s) and should not be interpreted as representing the official views or policies of the Department of Defense or the U.S. Government.

Approved for Public Release, Distribution Unlimited.

]]>
2020 Tech Council Update https://www.ainfosec.com/tech-council-update?utm_source=rss&utm_medium=rss&utm_campaign=2020-tech-council-update Wed, 30 Dec 2020 20:41:11 +0000 https://www.ainfosec.com/?p=12465 ...]]>

Throughout 2020, the Tech Council has continued to deliver on its purpose statement through the facilitation of communications amongst teams, contributions to research integrity and quality and sharing of lessons learned on the COVID-driven changes in workforce structure. These contributions are in the spirit of delivering excellence to our customers and supporting our teams that deliver that excellence daily. Our focus has been on three main points:

Cross-Team Communication Flows

Our regular meetings have shifted focus in 2020, with major topics including DevOps and development automation, technical brainstorming and continuous alignment of AIS’s unique business requirements with the compliance initiative. We’ve also been sharing lessons learned through COVID-19 and how we can successfully on-ramp and engage an almost entirely remote staff while staying highly responsive to our customers. Information sharing across our company is invaluable. Technical leaders from the Adaptive Systems Technology  and the Cross Domain Virtualization Solutions Teams collaborated on a lessons learned exchange with regards to effectively shaping our software development processes to our customer’s needs. As a result, the processes are continually evolving to be efficient, effective and agile.

Research Integrity and Product Quality

Internal research and development (IRaD) projects set direction for long-term initiatives and strategy areas, so making sound decisions is critical. Our feedback helps shape concepts and ideas that create our future programs and provide value to customers and stakeholders. In collaboration and close alignment with the AIS Chief Technology Officer, the Tech Council is actively involved in the IRaD proposal review process and a subset of members have contributed to strategy for projects in 2021 and beyond.

Facilitating New Research Opportunities

An initial down-select of government Small Business Innovation Research (SBIR) topics by the Tech Council and Business Development Department provides potential proposal teams a more focused selection of topics with clear alignment to AIS capabilities and future strategies. In 2020, we identified Tech Council representatives to sup-port the effort and had two rounds of filtering, reviewing more than 100 SBIR topics to allow potential AIS proposal authors to quickly review highly applicable topics before turning their attention to the broader list.

Looking Ahead

In 2021, the Tech Council is looking forward to staying true to its purpose statement through direct daily engagement with teams while also further engaging business development and culture initiatives.

About the AIS Tech Council

The purpose of the Tech Council is to provide advisement and support on issues and initiatives with regards to technical information flows, research integrity, product quality, enhancing culture, enabling vision and fostering an enjoyable work environment.

]]>
ACCESS – A Year in Review at AIS https://www.ainfosec.com/year-in-review?utm_source=rss&utm_medium=rss&utm_campaign=access-a-year-in-review-at-ais Wed, 30 Dec 2020 19:46:36 +0000 https://www.ainfosec.com/?p=12446 ...]]>

A Year In Review

The year 2020 was without question, a challenging one. However, our company has made many strides and we would be amiss to not celebrate the achievements of our talented team and growing organization. Many of these achievements are also highlighted in our 7th issue of ACCESS. Take a look

Growth Without Compromise, How the AIS Culture is Evolving

From wearing slippers in the hallways to hanging a pirate flag up at the office, the beginnings of our company are anything but typical. The AIS culture is rooted in innovation, collaboration, resilience and just being different. From our start in 2001, we’ve grown into a 350-employee company with offices and customer locations across the nation. With this growth, the need to nurture and evolve the culture that has made us who we are is essential. Read more >>

Keeping Employees Safe During COVID-19

When the pandemic emerged, AIS responded swiftly. With the COVID-19 still ever-present, we’ve created a Workplace Safety Committee (WSC). The WSC been working diligently to stay informed on local, state and country-wide guidelines and restrictions. Using this information, they are continuously developing policies and guidelines to keep employees and their families as healthy as possible. Read more >>

Senior Vice President, Barry McKinney, Retires

In November 2020, Barry McKinney, Senior Vice President, retired after more than 15 years at AIS. McKinney and his growing family made this decision together and are looking forward to making new memories. Read more >>

Leadership Team Welcomes New Members

Our leaders continue to move us forward. This year, we welcomed:

Can You Hack It?® Challenge Reaches New Milestones

The AIS Can You Hack It?® Challenge site contains several different programming challenges for anyone who is willing to test their skills. As of December 2020, the site has challenged more than 5,500 people internationally and has resulted in multiple talented hires at AIS. Read more >>

Leadership Changes at GreyCastle Security

On January 1, 2020, Dan Kalil was named the Chief Executive Officer (CEO) at GreyCastle Security. Prior to becoming CEO, Kalil served as the company’s Board Chairman and Chief Strategy Officer since 2016, when AIS acquired majority interest in the business. As one of the co-founders of AIS, Kalil also continues to serve as the company’s Vice President of Commercial Operations and Corporate Communications. Read more >>

2020 Tech Council Update

Throughout 2020, the Tech Council has continued to deliver on its purpose statement through the facilitation of communications amongst teams, contributions to research integrity and quality and sharing of lessons learned on the COVID-driven changes in workforce structure. These contributions are in the spirit of delivering excellence to our customers and supporting our teams that deliver that excellence daily. Read more >>

Employees Make Mark in Transportation Sector

This year, AIS and the National Motor Freight Traffic Association, Inc. (NMFTA) published a vulnerability within trailer Power Line Communications (PLC) signals. Read more >>

AIS Wins Largest Prime DARPA Contract in Company History

This $9 million contract will enable the Systems Analysis and Exploitation Team, along with teaming partners Cummins Incorporated, Colorado State University and GRIMM, to develop challenge problems and evaluate performer’s solutions to problems related to heavy-duty engine systems. Read more >>

2020 Patents

With our increased research efforts at AIS, we have a growing number of patents that have been filed and several that have been awarded. Congratulations to our brilliant employees on their achievements in innovation.  Read more >>

Forward Thinking, CTO Round-Up

In September 2019, we launched our plan to reinvigorate the AIS Research Program. The vision for this initiative was to provide a foundation of intellectual property, talent, partnerships and community to support our company’s strong commitment towards our people, our customers and innovation. Since beginning this process, we’ve hit multiple milestones and have further developed our goals in accordance to our five-year plan. Read More >>

See You Next Year!

These are just a few of the exciting milestones achieved in 2020 at AIS. Looking ahead to 2021, we will continue to challenge the impossible to create a secure future for our customers, employees and community.

]]>
Top Ten Gifts for the Engineer in Your Life https://www.ainfosec.com/engineer-gift-guide?utm_source=rss&utm_medium=rss&utm_campaign=top-ten-gifts-for-engineers Wed, 09 Dec 2020 19:11:15 +0000 https://www.ainfosec.com/?p=12362 ...]]>

Without the expertise of software engineers and research scientists, the world would be a much different place. Let’s make sure they have the best holiday season with these cool finds:

  1. Blue Light Blocking Computer Glasses – They are always in front of the screen! Let’s protect their eyes.
  2. Tinkering Labs Stem Kit for Kids – For the next generation coders!
  3. Chopstick LightSabers – Need we say more?
  4. 3D Printer – More expensive gift but worth it!
  5. Coded Candle – Everyone needs a good candle, even engineers.
  6. Internal/external hard drives – Who couldn’t use more of these?
  7. Fungineer Shirt – Because engineers are fun too!
  8. Steam gift cards – So many games to choose from!
  9. Mechanical keyboard – They use them all day, give them one to last!
  10. Robotic Arm – Because every engineer deserves a robot.
]]>
AIS Publishes Vulnerability in Trailer Power Line Communications https://www.ainfosec.com/vulnerability-trailer?utm_source=rss&utm_medium=rss&utm_campaign=ais-publishes-vulnerability-in-trailer-power-line-communications Mon, 10 Aug 2020 20:19:56 +0000 https://www.ainfosec.com/?p=11780 ...]]>

AIS and the National Motor Freight Traffic Association, Inc. (NMFTA) have published a vulnerability within trailer Power Line Communications (PLC) signals. The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) advisory to bring awareness of the vulnerability to the transportation systems sector.

This research indicates that it is possible to read PLC signals reliably using active antennas at six feet and up to eight feet away. NMFTA researcher Ben Gardiner and AIS researchers Dan Salloum, Chris Poore and Eric Thayer reported this vulnerability to CISA.

“This vulnerability could lead to the exposure of sensitive information, traversing the vehicle bus,” said Thayer, Principal Investigator at AIS. “We expect to be able to build upon this research to identify other potential issues that could impact the reliability and integrity of connected systems.”

CVE-2020-14514 has been assigned to this vulnerability and it has been given a Common Vulnerability Scoring System Version Three (CVSS v3) base score of 4.3.

“This is the first ICS-CERT advisory that AIS has had published,” said Cat Hulser, Program Manager at AIS. “Not only is this an exciting accomplishment for our team, it’s also rewarding to know that we’re contributing to a safer transportation sector in our community.”

To learn more about this advisory, click here.

]]>
Bareflank Community Call – June 12 https://www.ainfosec.com/bareflank-call?utm_source=rss&utm_medium=rss&utm_campaign=bareflank-community-call-june-12 Tue, 09 Jun 2020 18:01:23 +0000 https://www.ainfosec.com/?p=11619 ...]]>

AIS will be holding a Bareflank Community Call at 3pm UTC on Friday June 12, 2020 via Zoom. The goal of the call is to:

  • Provide users with an opportunity to ask questions and meet the team.
  • Learn more about the future of Bareflank projects including the hypervisor, Boxy/MicroV, the BSL, PAL and the Standalone C++ library.

As we get closer to the call, the Zoom information as well as an agenda will be posted in Github. Everyone is welcome to join and add items to the agenda.

For details, visit https://github.com/Bareflank/hypervisor/issues/915.

For more information about Bareflank, click here.

]]>
Announcing New AIS Website https://www.ainfosec.com/announcing-new-ais-website/?utm_source=rss&utm_medium=rss&utm_campaign=announcing-new-ais-website Mon, 23 Mar 2020 09:00:03 +0000 https://www.ainfosec.com/?p=11001 ...]]>

Erin Bushinger – Rome, NY
Senior Manager of Corporate Communications
One minute read

We are extremely excited to announce the launch of the brand new AIS website. After a year of research, planning, hard work and overcoming a few obstacles here and there, we are ready to share this all-new site that is strategically designed to align with the goals of the company. The team wanted to create a site that captures the essence of AIS culture and the groundbreaking work we do.

As an industry leader, it’s important for us to provide our various audiences easily accessible information regarding our research, capabilities, services, people and culture. To do this, we ensured the site had a highly interactive and user-friendly design, as well as updated and modernized content. The new website has exciting new features and content including all new resources, research, capabilities and services pages, Q&As, tech insights, blogs, updated culture and careers pages, employee stories and much, much more.

We will be continuously updating our content with cutting-edge thought leadership, research information and company announcements and successes. Along with new content, we also integrated a live chat to foster communication with whoever may want to chat with us!

In the future, we are looking forward to enhancing the site with new information and features including video podcasts, site-specific office information and highlights, case studies and a refreshed open-source page.

]]>