The Federal Service for Technical and Export Control has concluded a contract with the Institute of System Programming of the Russian Academy of Sciences (ISP RAN) to establish a technological center for the research of operating system security based on the Linux kernel. The contract also involves creating a software-hardware complex for the operating system security research center. The contract amount is 300 million rubles. The completion date is December 25, 2023.
Among the tasks specified in the technical assignment:
- Formation of a domestic branch of the Linux kernel and ensuring its security support while continuously synchronizing with international open projects for Linux kernel development.
- Preparation of patches to eliminate vulnerabilities in operating systems based on the Linux kernel and their testing. Communicating these patches to the operating system developers.
- Development of a methodology for architectural analysis, static analysis of the kernel source code, fuzz testing of the kernel, system and module testing, and full system dynamic analysis. Application of the prepared methods for testing the Linux kernel software used for creating domestic operating systems.
- Preparation of information on vulnerabilities in operating systems based on the Linux kernel for inclusion in the database of information security threats of FSTEC Russia, identified through analysis and testing.
- Preparation of recommendations for implementing secure development measures for operating systems based on the Linux kernel.
Goals of establishing the Technological Center:
- Reduction of potential socio-economic consequences from computer attacks on the critical information infrastructure of the Russian Federation by increasing the level of security of domestic operating systems based on the Linux kernel;
- Improvement of the quality and unification of domestic operating systems by enhancing the quality and security of the Linux kernel;
- Enhancement of domestic tools for software development and testing;
- Improvement of the qualifications of specialists involved in the development of domestic operating systems based on the Linux kernel;
- Enhancement of regulatory and methodological support for the safe software development processes in the Russian Federation.
Source: opennet.ru
