logo
DARPA touts ‘formal methods' for nipping cyber disasters in the bud

DARPA touts ‘formal methods' for nipping cyber disasters in the bud

Yahoo21-02-2025
Officials at the Defense Advanced Research Programs Agency have begun nudging Defense Department managers to utilize idling DARPA cybersecurity tools meant to preempt hacks and accidents in critical programs.
A series of high-profile incidents in recent years has highlighted a kind of passivity among defense officials in the face of the damage caused, according to Kathleen Fisher, the director of DARPA's Information Innovation Office. Believing that systems can't stave off catastrophic cyber incidents caused by software vulnerabilities, the department often focuses instead on reactive fixes, she said.
But proactive tools for building more resilient software already exist in the Pentagon's arsenal of countermeasures, she said at a demonstration day at the agency's Arlington, VA headquarters earlier this month.
'We have many critical mission systems that have these kinds of vulnerabilities in them, and the way we've learned to deal with them is after they've been attacked, after we've learned, 'OK, that's a bad one,' we then go and fix it,' Fisher said. 'We pay billions of dollars after the fact to go fix these problems.'
In 2017, Russia conducted a cyberattack against Ukraine that's now known as NotPetya.
While the attack targeted Ukraine's power infrastructure, it ended up spreading outside the country, affecting infrastructure and businesses across Europe, including a Danish logistics company, Maersk, which is responsible for about 20% of global container shipping. In seven minutes, the attack destroyed 50,000 of the firm's computers and nearly wiped out the active directory system tracking its container ships. The company estimated the damage at around $300 million.
Seven years later, in July 2024, faulty software from security firm CrowdStrike took millions of government and private sector computers offline, delaying thousands of commercial flights and canceling medical procedures as part of the global outage. The disruption was widespread, but the root cause was determined to be an accident — a software glitch that spread through a routine update.
Events like these — adversarial or accidental — have become more prevalent in recent years. And according to Fisher, they highlight troubling software vulnerabilities in critical infrastructure. In response, the Defense Department and the broader U.S. government have developed a sense of 'learned helplessness' when it comes to addressing software vulnerabilities.
Over the last 10 to 15 years, DARPA has proven that a software design approach called 'formal methods' can address these vulnerabilities before they're exploited by a coding error or an attack. Rather than validate the security of software code solely by testing it after it's already written, a formal-methods approach designs software through rigorous mathematical analysis, verifying its performance before and as it's being built.
Some of the tools DARPA has developed have made their way into DOD programs of record, but adoption has been limited. Now, as concerns grow about the cybersecurity of military weapon systems, the agency is trying to raise awareness in the defense acquisition community that these solutions exist and are available for use.
'We can imagine a world without these software vulnerabilities, where we can eliminate the sense of learned helplessness across DOD, where we can rapidly secure critical systems . . . and where we can create a sustainable ecosystem of formal-methods tools that are ready and off the shelf for people to use,' Fisher said.
One early DARPA program to showcase the utility of formal methods was the High-Assurance Cyber Military Systems effort, or HACMS. The program ran from 2012 to 2016 and culminated with two demonstrations, the first using a small quadcopter drone and then, in 2017, using Boeing's autonomous helicopter, the Unmanned Little Bird.
During the second demonstration, a red team of hackers tried unsuccessfully to infiltrate the aircraft, according to Darren Cofer, a principal fellow at Collins Aerospace, whose predecessor Rockwell Collins was a contractor on HACMS.
'In HACMS, we showed that formal methods could be used to eliminate important security vulnerabilities from embedded systems in real aircraft,' Cofer said during the DARPA demo day.
The agency has since pursued several other efforts to improve the usability of formal methods for DOD platforms. One of those programs, called SafeDocs, addresses vulnerabilities in parsers – software tools that convert data into a usable format. Another effort, Assured Micro Patching or AMP, provides a way to fix software bugs without the source code and ensure that the fix itself doesn't do more damage.
These tools have all transitioned to DOD programs in a limited capacity, and DARPA has several other ongoing efforts aimed at further improving formal methods. Fisher noted that because the problem hasn't been fully solved, there's a tendency for programs to hold off on adopting it. But DARPA sees potential for these technologies to be planted more widely now -- both to secure existing DOD software installed on legacy platforms and to design software for future systems.
'We have plenty of technology that's ready for prime time and we should go ahead and transition and use that technology now because it will dramatically improve the security of our systems,' she said. 'We can't afford to wait until we've solved the whole problem to use the technology that we've got now.'
How quickly and broadly the Defense Department adopts these tools depends on a number of factors — including funding and prioritization within the military services.
To help spread the word and address barriers to adoption, DARPA kicked off the Capstone program last year. Through a partnership with the Undersecretary of Defense for Research and Engineering and the Director of Operational Test and Evaluation, the agency is working with the services to identify platforms that could benefit from formal methods.
DARPA is providing some matching funds to make the tools available and, according to program manager Steve Kuhn, expects to identify the platforms by May. Once the Capstone programs are selected, the agency will help identify and fix software vulnerabilities within them and capture lessons learned to be compiled in a best practice guide that all programs will be able to access.
DARPA's hope, Kuhn said, is that the guide will help DOD program offices see how resilient software tools are being applied and offer a resource that helps with that implementation.
'Part of the strategy that we've been embarking on is really an adoption plan that brings these resilient software tools to both our defense industrial base, our partners and the services themselves,' Kuhn said. 'We're not going to fix everything, but can we really capture what it takes to bring these tools to the masses?'
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Akamai raises annual results forecast on cybersecurity demand
Akamai raises annual results forecast on cybersecurity demand

Yahoo

time4 days ago

  • Yahoo

Akamai raises annual results forecast on cybersecurity demand

(Reuters) -Akamai Technologies raised its annual revenue and profit forecast on Thursday, helped by steady demand for its cloud infrastructure services and content delivery network offerings. The company is seeing strong momentum in its security and compute verticals, as enterprises ramp up investments in securing applications and web infrastructure amid the accelerating adoption of cloud technologies. Akamai is also well-positioned to benefit from the surge in mobile data traffic, fueled by the growing use of mobile apps and services. It provides content delivery network services to optimize web performance and reduce bandwidth congestion. It also offers cloud infrastructure solutions that improve the security and reliability of apps and web assets from data centers to end users. Akamai's customers include Adobe, eBay and Electronic Arts, as well as the U.S. Defense and Labor departments. The cybersecurity company now expects annual revenue between $4.14 billion and $4.21 billion, ahead of its prior projection of $4.05 billion to $4.20 billion. On an adjusted basis, Akamai sees per-share earnings in the range of $6.60 to $6.80, from its earlier forecast of between $6.10 and $6.40 apiece. It expects revenue between $1.04 billion and $1.05 billion for the third quarter, compared with the analysts' average estimate of $1.04 billion, according to data compiled by LSEG. Akamai posted revenue of $1.04 billion for the quarter ended June 30, compared to analysts' consensus estimate of $1.02 billion.

FUJIFILM's Q1 Earnings Decline Y/Y, Imaging Solutions Boost Revenues
FUJIFILM's Q1 Earnings Decline Y/Y, Imaging Solutions Boost Revenues

Yahoo

time4 days ago

  • Yahoo

FUJIFILM's Q1 Earnings Decline Y/Y, Imaging Solutions Boost Revenues

FUJIFILM Holdings Corporation FUJIY reported a first-quarter fiscal 2025 (ended June 30, 2025) net income of ¥53.8 billion compared with ¥60.7 billion in the year-ago quarter. The decrease was primarily as a result of foreign exchange losses. Revenues of ¥749.5 billion inched up 0.1% year over year. The stable performance was primarily driven by strong performances in Bio CDMO, Semiconductor Materials and Imaging segments, offsetting the impact of foreign exchange fluctuations. Segment Details of FUJIY In June 2024, the company established the Advanced Functional Materials division by integrating its display materials, industrial products and fine chemicals businesses. In the fiscal first quarter, Healthcare segment revenues were ¥228.5 billion, down 2.9% from the year-ago quarter. Within Healthcare, Medical Systems revenues were down 8.7% year over year to ¥144 billion. Revenues decreased primarily due to lower demand for medical consumables in China and the absence of large-scale orders for X-ray imaging diagnostic equipment, which had contributed significantly in the previous year. However, this decline was partially offset by strong sales of medical IT solutions such as PACS, along with solid performance in in-vitro diagnostics (IVD) and endoscopes. Bio CDMO revenues were up 12.8% to ¥53.2 billion. Revenues grew primarily due to the commencement of operations at the new Danish facilities and the resumption of operations at the Texas facilities. This growth was partially offset by the impact of regularly scheduled maintenance at the existing Danish sciences revenues grew 3.2% to ¥31.3 billion, driven by a recovery in the culture media market and robust sales of reagents. Fujifilm Holdings Corp. Price, Consensus and EPS Surprise Fujifilm Holdings Corp. price-consensus-eps-surprise-chart | Fujifilm Holdings Corp. Quote In the Electronics segment, revenues amounted to ¥102.1 billion, down 0.9% year over year. Semiconductor Materials revenues rose 3.8% to ¥64.7 billion. Revenues grew on the back of strong sales in advanced applications, particularly in CMP slurry. AF materials revenues amounted to ¥37.5 billion, down 8.2% year over year. This was due to a decline in data tape sales following significant purchases by IT companies in the previous year, while strong sales of new materials boosted the performance of display materials. The Business Innovation Solutions segment's revenues were ¥273.6 billion, decreasing 2.3% from the year-ago quarter's figure. Business solutions moved up 7% on a year-over-year basis to ¥75.8 billion. Revenues were supported by strong sales of digital transformation (DX) solutions and services to municipalities in Japan, along with increased business process outsourcing (BPO) revenue from markets outside Japan. Office solutions and Graphic Communications revenues decreased 5.3% and 5.6% on a year-over-year basis to ¥120 billion and ¥77.8 billion, respectively. In the Office Solutions segment, revenues were adversely impacted by a strategic reduction in the range of low-profit products sold in China. Within Graphic Communications, analog printing faced weaker demand for plate-making and the discontinuation of low-margin products, while inkjet printhead sales declined due to reduced demand from the ceramics market. The Imaging Solutions segment's revenues were ¥145.3 billion, up 11.2% from the year-ago quarter's level. Consumer Imaging and Professional Imaging revenues rose 3.7% and 21.2% on a year-over-year basis to ¥77.3 billion and ¥68 billion, respectively. In the Consumer Imaging segment, strong sales of Instax instant photo systems drove growth, supported by the popularity of models such as the Instax WIDE 400 and Instax WIDE Evo, along with contributions from the newly launched Instax mini 41. In the Professional Imaging segment, robust sales of FUJIFILM X and GFX series digital cameras contributed to strong performance, with particularly high demand for the FUJIFILM X100VI and X-M5 models, as well as positive contributions from the newly introduced FUJIFILM GFX100RF and X half. FUJIY's Operating Details In the fiscal first quarter, selling, general and administrative expenses decreased 4.6% to ¥196.6 billion. Research and development expenses increased 0.9% to ¥40.6 billion. Operating income increased 21.1% year over year to ¥75.3 billion, primarily due to higher sales in the Imaging segment, while the effect of U.S. tariff policies remained minimal. FUJIY's Balance Sheet & Cash Flow As of June 30, 2025, cash and cash equivalents were ¥160 billion, down from ¥172.1 billion as of March 31, 2025. Total debt was ¥749.8 billion as of March 31, 2025, compared with ¥685.9 billion on as of March 31, 2025. For full-year 2025, FUJIFILM is planning an annual dividend of ¥70 per share, marking the 16th consecutive year of dividend increases. FUJIY's Guidance FUJIFILM reiterated its guidance for fiscal 2025. The company expects revenues of ¥3,280 billion for fiscal 2025, indicating growth of 2.6% year over year. The operating income is anticipated to be ¥331 billion, implying 0.3% growth. Net income is expected to increase 0.4% year over year to ¥262 billion. For fiscal 2025, revenues from Healthcare, Electronics, Business Innovation and Imaging Solutions are anticipated to be ¥1,110 billion, ¥420 billion, ¥1,220 billion and ¥540 billion, respectively. Zacks Rank of FUJIY Currently, FUJIFILM has a Zacks Rank #3 (Hold). In the past six months, shares have soared 8.8% compared with the Zacks Semiconductor Equipment – Photomasks industry's decline of 13.4%. You can see the complete list of today's Zacks #1 Rank (Strong Buy) stocks here. Image Source: Zacks Investment Research Recent Performance of Other Companies in Tech Space Blackbaud, Inc. BLKB reported second-quarter 2025 non-GAAP earnings per share (EPS) of $1.21, which surpassed the Zacks Consensus Estimate by 15.2%. The bottom line increased around 12% year over year. Total revenues decreased 2.1% year over year to $281.4 million. This was due to the divestiture of EVERFI. The top line surpassed the Zacks Consensus Estimate by 1.3%. In the past year, shares of BLKB have lost 17.5%. Fortive Corporation FTV reported second-quarter 2025 adjusted EPS of 58 cents from continuing operations, which missed the Zacks Consensus Estimate of 60 cents. The bottom line increased 3.6% year over year. Revenues declined 0.4% year over year to $1.02 billion. The top line beat the Zacks Consensus Estimate by 0.8%. Core revenues decreased 0.7% year over year. In the past, shares of FTV have declined 27.7% Flex Ltd. FLEX reported first-quarter fiscal 2026 adjusted EPS of 72 cents, which surpassed the Zacks Consensus Estimate by 14.3%. The bottom line compared favorably with 51 cents posted in the prior-year quarter. Revenues increased 4.1% year over year to $6.6 billion. Also, it beat the consensus mark by 5.6%. The uptick was driven by strong data center growth in both the cloud and power end markets. Shares of FLEX have surged 79.9% in the past year. Want the latest recommendations from Zacks Investment Research? Today, you can download 7 Best Stocks for the Next 30 Days. Click to get this free report Fujifilm Holdings Corp. (FUJIY) : Free Stock Analysis Report Flex Ltd. (FLEX) : Free Stock Analysis Report Blackbaud, Inc. (BLKB) : Free Stock Analysis Report Fortive Corporation (FTV) : Free Stock Analysis Report This article originally published on Zacks Investment Research ( Zacks Investment Research

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store