This past year, Effectual’s Modernization Engineers partnered with specialized R&D firm Galois to support the launch of DARPA’s first public bug bounty program – Finding Exploits to Thwart Tampering (FETT). The project represents a highly unique use case showcasing Effectual’s application expertise, and was approved this week to be featured on the AWS Partner Network (APN) Blog.

Key Takeaways

  • Effectual partnered with R&D firm Galois to support the launch of DARPA's first public bug bounty program, Finding Exploits to Thwart Tampering (FETT).
  • The work originated from Galois's BESSPIN project for DARPA's SSITH program, which needed to scale hardware-security testing beyond on-premises FPGA resources.
  • Galois used Amazon EC2 F1 instances to scale infrastructure and accelerate FPGA development for stress-testing SSITH hardware platforms.
  • Effectual's role was to secure a reliable AWS environment and build a serverless web application enabling click-button FPGA SoC provisioning for red-team researchers.
  • The collaboration was significant enough to be featured on the official AWS Partner Network (APN) Blog, authored by an Effectual Cloud Architect.

Authored by Effectual Cloud Architect Kurt Hopfer, the blog will reach both AWS customers and technologists interested in learning how to solve complex technical challenges and accelerate innovation using AWS services.

 

Read the full post on the AWS APN Blog

 

In 2017, the Defense Advanced Research Projects Agency (DARPA) engaged research and development firm Galois to lead the BESSPIN project (Balancing Evaluation of System Security Properties with Industrial Needs) as part of its System Security Integrated through Hardware and Firmware (SSITH) program.

The objective was to develop tools and techniques to measure the effectiveness of SSITH hardware security architectures, as well as to establish a set of “baseline” Government Furnished Equipment (GFE) systems-on-chip (SoCs) without hardware security enhancements.

While Galois’s initial work on BESSPIN was carried out entirely using on-premises FPGA resources, the pain points of scaling out to a secure, widely-available bug bounty program soon emerged.

It was clear that researchers needed to be able to stress test SSITH hardware platforms without having to acquire their own dedicated hardware and infrastructure. Galois leveraged Amazon EC2 F1 instances to scale infrastructure, increase efficiencies, and accelerate FPGA development.

The company then engaged AWS Premier Consulting Partner Effectual to ensure a secure and reliable AWS environment, as well as to develop a serverless web application that allowed click-button FPGA SoC provisioning to red team researchers for the different processor variants.

The result was DARPA’s first public bug bounty program—Finding Exploits to Thwart Tampering (FETT).

Frequently Asked Questions

What is DARPA's FETT program?

FETT (Finding Exploits to Thwart Tampering) is DARPA's first public bug bounty program, developed to stress-test hardware security architectures under its SSITH initiative.

What was Effectual's role in the FETT program?

Effectual, engaged by R&D firm Galois, ensured a secure and reliable AWS environment and developed a serverless web application that gave red-team researchers click-button provisioning of FPGA SoCs for different processor variants.

Why did Galois move from on-premises FPGA resources to AWS?

Scaling a secure, widely-available bug bounty program on on-premises FPGA hardware alone created bottlenecks, so Galois used Amazon EC2 F1 instances to scale infrastructure, increase efficiency, and accelerate FPGA development.

What is the BESSPIN project?

BESSPIN (Balancing Evaluation of System Security Properties with Industrial Needs) is a DARPA project led by Galois under the SSITH program to develop tools for measuring the effectiveness of hardware security architectures.

Where was this work published?

The project was featured on the official AWS Partner Network (APN) Blog, authored by Effectual Cloud Architect Kurt Hopfer.