This exploitation result consists in cybersecurity consultancy services supported by ResilBlockly (former Blockly4SoS), a Model-Driven Engineering tool that has been developed in the context of BIECO.
Describe the innovation content of the result:
A low complexity, still rigorous, solution for system-of-systems modelling supporting risk assessment and cybersecurity consultancies. The tool will enable the provision of these services at design time, during the early prototyping phase.
Who will be the customer?
Reference market is the critical infrastructures and systems, starting from the existing customers of Resiltech in transportation (e.g. automotive, railway, maritime). However, thanks to the modelling feature of the tool, which allows modelling at different levels of abstraction, and thanks to the implementation of a general risk assessment methodology, the value proposition is suitable to be used in several domains and the potential market embraces in general the SMEs interested in cybersecurity and risk assessment consultancies
What benefit will it bring to the customers?
Early identification of weaknesses and prompt performance of modifications on any existing infrastructures; identification of existing vulnerabilities to be eliminated or which likelihood of exploit needs to be significantly reduced.
When is the expected date of achievement in the project (Mth/yr)?
When is the time to market (Mth/yr)?
What are the costs to be incurred after the project and before exploitation?
Cost of tool maintenance: €20,000 (1 year), €35,000 (1-3 years)
• Cost of marketing initiatives and material: €3,000 (1 year), €7,500 (1-3 years)
• Cost of internal training and training of new resources: €2,000 (1 year), €5,000 (1-3 years)
• Personnel cost: €60,000 (1 year), €240,000 (1-3 years)
What is the approximate price range of this result/price of licences?
Price of consultancies to be determined (licensing is currently not in the plans)
What are the market size in Millions € for this result and relevant trend?
The security consulting services market reached $23.5 billion (approx. €20 billion) in 2020; source: Gartner Research)
How will this result rank against competing products in terms of price/performance?
To be determined
Who are the competitors for this result?
Competitors are companies and organizations in different domains trying to enter this market and offering risk assessment services, especially with the assistance of dedicated and proprietary software tools and following the approach of model-driven engineering and threat modelling
How fast and in what ways will the competition respond to this result?
Unknown at the moment
Who are the partners involved in the result?
Who are the industrial partners interested in the result (partners, sponsors, etc.)?
Unknown at the moment
Have you protected or will you protect this result? How? When?
IP rights for the source code of the tool are already reserved. The tool is currently available for the authorized partners of the project only.
BIECO Integrated Platform will integrate the tools in a loosely coupled way.
Data Collection Tool (DCT) stores information from relevant vulnerability related datasets, providing a single access point to information required by the vulnerability detection and forecasting tools developed in T3.3, as well as for the failure prediction tools developed in T4.2.
Vulnerability Detection Tool will detect existing vulnerabilities within the source code which may lead to the successful execution of an attack.
Vulnerability Exploitability Forecasting Tool will estimate the probability of a vulnerability to be exploited in the next 3, 6 or 12 months.
Vulnerability Propagation Tool will calculate and offer the paths affected by a vulnerability in the source code.
Fuzzing Tool will test System Under Test (SUT) security vulnerabilities or inputs not contemplated that could compromise the system; as a black-box process, by using unintended or incorrect inputs and monitoring their corresponding outputs.