DARPA Issues $2mil Cyber Grand Challenge
First time accepted submitter Papa Fett writes "DARPA announced the Cyber Grand Challenge (CGC)--the first-ever tournament for fully automatic network defense systems. International teams will compete to build systems that reason about software flaws, formulate patches and deploy them on a network in real time. Teams would be scored against each other based on how capably their systems can protect hosts, scan the network for vulnerabilities, and maintain the correct function of software. The winning team would receive a cash prize of $2 million , with second place earning $1 million and third place taking home $750,000." Also at Slashcloud.
Chump change for a project like this. No one with the skills to build a good solution will give it away for two million.
I thought they already have it running. Did their crash and lost the backup?
Darpa's intention is not to build a secured system, but rather, finding fresh international talents to enable NSA to break more systems all over the world.
I am an American, and it is not that I do not trust my own country.
I do trust my country.
I simply have lost all trust to my own government.
Muchas Gracias, Señor Edward Snowden !
This may be why the kids don't want those "potentially secure" cybersecurity jobs.
It's an excuse to pay less and pay most people nothing at all.
length or end string packet match iptables -I INPUT-s $SRCIP -j DROP
It's impossible anyway, may as well offer 2 million to solve the halting problem.
Windows 3.0, no known network vulnerabilities after all these years.
Of course, no networking but that is besides the point.
If you could "build systems that reason" you'd be able to get a whole lot more than $2mil - why would anyone divulge this technology to the government when they could license it to Google, Apple, Microsoft, IBM, and everyone else? If I had this technology, my first stop would be the patent office and I would patent it out the wazoo and start licensing it. If the government wants it, they can get in line.
it's just cheaper to lure all the hackers in the world into one single competition and then offer them a job over prison time.
I'd like to see a software system effectively deal with social engineering as well as other criminal vectors. Software is only going to be able to protect its own silo of information.
Also, we see a lot of programmers relying on code from outside sources. They don't typically debug someone else's code which is a ripe area for exploit vectors.
Combine these elements and you have our present day situation. I don't see any of this addressed in the competition.
They appear to be assuming the network is not corrupted from within.
The dangers of knowledge trigger emotional distress in human beings.
if you can make a system like this, you can make billions in the private sector. why would you give it to DARPA for a lousy two million?
if the DoD is going to spend 12 billion a year making a jet that we dont need, why not give two billion to the group that comes up with a solid working solution? i assure you, two billion dollars will get you a hell of a lot of attention from the best people out there, with teams of hundreds of experts. a global challenge would result in a much better chance of success.
Anons need not reply. Questions end with a question mark.
Sooo we'll have ICE in 5 years? How long before we can off people remotely?
Bonus being that the winner can then be arrested for hacking with a fine of $2 million..
Under that draconian anti-terrorist_cum_anti-hacker_cum_anti-everything law that we have in America they could throw the book at the winner, get a court ruling for fine of 40 gazillion.
Plus, in the so-called plea-bargain stage the winner would be tricked to sign away all his/her/their rights and end up as indentured servants to do all the dirty works for NSA, for life.
Do not ever say it is impossible.
The United States of America is no longer a land of the free and the home of the braves.
No, what should be done is when a first post is offtopic, like yours, moderators should mod it down and commenters shouldn't respond. Good luck with that, though.
Not only is your idea offtopic, it's stupid and won't work.
I don't know why everyone is so excited about getting FP, get a subscription and it's easy. You can even RTFA before it's officially posded and you know exactly when it's going to be posted, so you can craft an insightful comment in a text editor, quickly paste it in a comment, and get an instant +5, assuming you are actually capable of making an insightful comment.
Why an AC would want FP is beyond me. I fail to see the attraction.
LOL this sounds like Skynet v1.0 to me. Roll the dice, baby, roll it!!!
You cannot have cyber security by having some software (or hardware) around to just do it for you. Real security is about HOW you do everything else. It appears someone thinks all security exploits are just badly implemented API calls?
now we need to go OSS in diesel cars
Wouldn't it save a lot of time if slashdot either auto-posted an "first post" along with an article, or at least pre-filled the form for the first user? =)
Then it would be just an extension of the summary; the summary ending in an auto-generated post, followed with the first post by the first real poster, bragging about being a human. Since the ones made by ACs are the ones usually making the issues that are disliked, blocking an AC from making the first post might be a better solution.
The title of my contest entry will be called the MCP (Master Control Program). It will enslave all other programs on the network.