Search Contract Opportunities

Enhanced SBOM for Optimized Software Sustainment (E-BOSS) Special Notice

ID: DARPA-SN-24-17 • Type: Special Notice

Description

The goal of the E-BOSS program is to develop Enhanced Software Bill of Material (eSBOM) metadata technology to enable rapid triage-and-remediation of vulnerabilities in software at scale. The toolchain components developed will emit advanced metadata alongside other SBOM information to effectively analyze and verify software. The metadata incorporated in the eSBOMs will enable trace back of discovered flaw evidence to its triggers, starting from a crash and walking back through complex inter-component interactions, transfers, and transformations to derive the triggers. Rapid remediation is then achieved by blocking the triggers and / or utilizing the metadata to identify what and where to apply fixes. Through eSBOMs, E-BOSS enables cyber-reasoning and assured transformations of the software deliverable for improved software development, testing, and sustainment.
Background
The E-BOSS program, sponsored by the Defense Advanced Research Projects Agency (DARPA) Information Innovation Office (I2O), aims to develop Enhanced Software Bill of Material (eSBOM) metadata technology to enable rapid triage-and-remediation of vulnerabilities in software at scale. The goal is to enhance SBOMs and SBOM-driven technologies with new types of metadata and cyber-reasoning algorithms to determine whether flawed or sensitive code is actually reachable and triggerable. This program is in response to the critical need recognized by Executive Order (EO) 14028 to protect the software supply chain from widespread dependency risks and create a policy foundation for software component transparency in software supply chains by requiring Software Bill of Materials (SBOMs) that specify the components and dependencies of a software product.

Work Details
The E-BOSS program aims to develop the capability to preempt or rapidly triage and remediate software vulnerabilities at infrastructure scale, through revolutionary changes in software build chains and runtime systems that enhance and complement SBOM technologies. The program envisions new metadata and cyber-reasoning technologies as an intrinsic part of software build systems, development toolchains, and development, security, and operations (DevSecOps) pipelines, to enable early mitigation of software vulnerabilities and optimize software maintenance and sustainment for security.

Place of Performance
The Proposers Day for the E-BOSS program will be held at the unclassified level on December 13, 2023, from 10:00 AM to 4:00 PM (ET) in person at the Executive Conference Center, located at 4075 Wilson Blvd, Arlington, Virginia, 22203, as well as virtually on ZoomGov.

Overview

Response Deadline
Dec. 8, 2023, 12:00 p.m. EST Past Due
Posted
Dec. 1, 2023, 3:01 p.m. EST
Set Aside
None
Place of Performance
Not Provided
Source
SAM

Current SBA Size Standard
1000 Employees
Pricing
Multiple Types Common
On 12/1/23 Defense Advanced Research Projects Agency issued Special Notice DARPA-SN-24-17 for Enhanced SBOM for Optimized Software Sustainment (E-BOSS) Special Notice due 12/8/23.
Primary Contact
Name
BAA Coordinator   Profile
Phone
None

Documents

Posted documents for Special Notice DARPA-SN-24-17

Question & Answer

Incumbent or Similar Awards

Contracts Similar to Special Notice DARPA-SN-24-17

Potential Bidders and Partners

Awardees that have won contracts similar to Special Notice DARPA-SN-24-17

Similar Active Opportunities

Open contract opportunities similar to Special Notice DARPA-SN-24-17

Additional Details

Source Agency Hierarchy
DEPT OF DEFENSE > DEFENSE ADVANCED RESEARCH PROJECTS AGENCY (DARPA) > DEF ADVANCED RESEARCH PROJECTS AGCY
FPDS Organization Code
97AE-HR0011
Source Organization Code
500035490
Last Updated
Dec. 14, 2023
Last Updated By
darpa.fbo.gov@darpa.mil
Archive Date
Dec. 14, 2023