industry news
Subscribe Now

Protecting Security-Sensitive Software From Spectre

Protection against Spectre attacks added to GrammaTech’s Cyber Hardening Services for Intel and AMD processors.

Ithaca, NY (USA) — January 11, 2018 – GrammaTech, Inc., a leading developer of commercial embedded software assurance tools and advanced cybersecurity solutions, today announced that mitigation against Spectre attacks has been added to GrammaTech’s Cyber Hardening Services for Intel and AMD processors, with support for ARM in development. This service allows legacy applications to be protected from branch target injection attacks without having to recompile the application.

This became an overnight necessity for cybersecurity practitioners that are concerned about Spectre, the recently announced security vulnerability in modern processors that can be leveraged to leak confidential information. The cyber community has been scrambling to make patches available for popular compilers to mitigate the attack. However, recompiling application or system firmware source code is not always an option in IoT, Defense, Consumer, Medical and Industrial systems. This leaves these systems vulnerable to exploits that leak information such as personal data, passwords or other confidential information from otherwise error-free applications.

Through GrammaTech’s Cyber Hardening Services, practitioners can protect critical applications and libraries from Spectre attacks. This service uses binary analysis to determine vulnerable locations in the code, then transforms the original application binary by adding mitigation code to these locations. The mitigation code follows the ‘retpolines’ approach published by Google.

“GrammaTech’s binary transformation technology is a key tool in the protection of today’s modern software systems,” says Alexey Loginov, VP of Research at GrammaTech, Inc. “The fact that applications can be protected without going back to the source code allows security professionals to turn around a fix much sooner. This mitigation for Spectre based on Google’s retpolines approach is one of the capabilities that make up GrammaTech’s Cyber Hardening solution. This technology can also protect against, or monitor for, buffer overruns and many other problems of the Common Weakness Enumeration list.”

Cyber professionals with legacy applications who need to ensure their information remains safe and need a quick turnaround – but are unable to modify source code – can benefit immediately from this technology. To ensure your applications remain safe, contact GrammaTech for more information on Cyber Hardening Services.

About GrammaTech:

GrammaTech’s advanced static analysis tools are used by software developers worldwide, spanning a myriad of embedded software industries including avionics, government, medical, military, industrial control, and other applications where reliability and security are paramount. Originally developed within Cornell University, GrammaTech is now a leading research center for software security and a commercial vendor of software-assurance tools and advanced cyber-security solutions. With both static and dynamic analysis tools that analyze source code as well as binary executables, GrammaTech continues to advance the science of superior software analysis, providing technology for developers to produce safer software. For more information, visit www.grammatech.com or follow us on LinkedIn.

Leave a Reply

featured blogs
Apr 23, 2024
The automotive industry's transformation from a primarily mechanical domain to a highly technological one is remarkable. Once considered mere vehicles, cars are now advanced computers on wheels, embodying the shift from roaring engines to the quiet hum of processors due ...
Apr 22, 2024
Learn what gate-all-around (GAA) transistors are, explore the switch from fin field-effect transistors (FinFETs), and see the impact on SoC design & EDA tools.The post What You Need to Know About Gate-All-Around Designs appeared first on Chip Design....
Apr 18, 2024
Are you ready for a revolution in robotic technology (as opposed to a robotic revolution, of course)?...

featured video

How MediaTek Optimizes SI Design with Cadence Optimality Explorer and Clarity 3D Solver

Sponsored by Cadence Design Systems

In the era of 5G/6G communication, signal integrity (SI) design considerations are important in high-speed interface design. MediaTek’s design process usually relies on human intuition, but with Cadence’s Optimality Intelligent System Explorer and Clarity 3D Solver, they’ve increased design productivity by 75X. The Optimality Explorer’s AI technology not only improves productivity, but also provides helpful insights and answers.

Learn how MediaTek uses Cadence tools in SI design

featured chalk talk

Exploring the Potential of 5G in Both Public and Private Networks – Advantech and Mouser
Sponsored by Mouser Electronics and Advantech
In this episode of Chalk Talk, Amelia Dalton and Andrew Chen from Advantech investigate how we can revolutionize connectivity with 5G in public and private networks. They explore the role that 5G plays in autonomous vehicles, smart traffic systems, and public safety infrastructure and the solutions that Advantech offers in this arena.
Apr 1, 2024
3,047 views