Summaries of the 5 funded SBIR’s AVR en Cryptocommunicaton projects in phase 2

Make Fuzzing applicable – Riscure B.V.

Riscure’s project is aimed at making fuzzing applicable for more people by automating the connection and analysis. Fuzzing is a newer testing method that is aimed at testing software packages for vulnerabilities. Excellent open soruce fuzzer test methods are available, but these are generally only used in academic circles, as configuration of a fuzzer to the software it needs to test takes a lot of time. In addition, analysis of the results requires a vast amount of knowledge.

Intelligent decision support of expert code review – Software Improvement Group B.V.

Software Improvement Group (SIG) is developing an AVR-module that substantially impoves the detection of vulnerabilities in source code. This module of their Sigrid platform contains hybrid AI that harnesses the expertise of experienced reviewers in combination with self-learning algorithms. Utilising this, reviewers can work more efficiently, find more vulnerabilities than fully automatic AVR-tools, and the group of reviewers can grow faster. In this Phase 2 project, SIG is developing a prototype, will be evaluating it in pilots, and will collaborate with Radboud University and TNO.

EYE and APTA – Eye Control B.V.

EYE and APTA are developing a service to automate sharing of the incident response process. This allows analysts to determine the required actions to contaminate and solve the incident faster. The technology is based on a machine learning algorithm, which analyses software models for aberrant behaviour by hosts, and can distinguish between known behaviour, and behaviour not seen before. Research during Phase 1 showed that this technology is suitable for learning and reasoning. Now this service will be developed further and made ready for the market.

Microchip design new generation cryptocommunication – Fox Crypto B.V.

With increasing threats to national security by persons, groups and organisations, it’s also becoming increasingly likely that hardware supply chain attacks will take place, instead of just software attacks. Fox Crypto’s project involves research and development into Dutch microchips, that will lead to renewed security products for cryptocommunications, with potential for further development. This is becoming ever more important, as challenges in trustworthiness of the supply chain are growing. The goal of this project is to increase resilience and evaluability of a new generation of security products for Dutch microchips.

Large-scale feasibility diabetic foot care with MPC – Groepspraktijk Ed Wender B.V.

Groepspraktijk Ed Wender B.V. is testing the applicability of large-scale Multi-Party Computation (MPC) health care in collaboration with Roseman Labs. With health care costs on the rise, healthcare providers and government require a means to measure the effectiveness of health care. Currrently it’s complicated to perform a study with several health care parties, as they are hesitant to share data. This project will focus on diabetic footcare, as it is seen as an example and leader for the 106 other professional associations in health care.