-
Published24/07/2013
-
Deadline02/09/2013
-
Awarded10/04/2014
-
Today08/08/2026
Utilities
- indicates CPV codes deduced from the text of the procedure
Belgium-Brussels: 13.R&T.RP.563 — Advanced persistent threats — detection (APT-D)
Background:
Cyber defence is one of the priorities in the EDA capability development plan (CDP). A project team (PT) of EDA and its participating Member States' (pMS) representatives is responsible to jointly develop these cyber defence capabilities, for crisis management and operations within the EU common security and defence policy (CSDP). A network of EDA and pMS research & technology (R&T) experts, the so-called CapTech network ('IAP4' in this case), will support this work by collaborative activities delivering the required technologies at the right time. To this end, a cyber defence R&T roadmap is currently under development, while at the same time there is need to respond to obvious urgent challenges, such as advanced persistent threats (APTs). The subject contract on 'Advanced persistent threats detection (APT-D)' is a first step towards building a capability in the defence environment aiming at early detection and smart mitigation of APTs. In this first step, the feasibility of suitable early detection support shall be assessed and at the end be demonstrated by a prototype. If positive, further steps following this contract, shall lead to the development of a fully-fledged tool (set).
Capability requirement:
Governmental institutions are among the most prominent targets for APTs and to a large extent exposed to cyber espionage. The aim of attackers is to inject malware into a system and remain undetected by firewalls, intrusion detection systems and other protective measures. This is done in order to be able to serve as a 'stealth information hub' and collect information from the users of that system as long as possible ('persistent'). While a number of hard- and software tools are being offered on the commercial market in relation to counter-APT, EDA and its pMS experts believe that a military APT defence capability will have to rely on information-sharing and exploitation, supported by tools in an optimal way (= suitable for the military defence environment). 'Detection' is among the most urgent capability elements in this respect.
Detail (basis for the technical specifications of the tender which will be addressed to candidates selected for the second round of evaluation):
In the subject APT-D study, the contractor will be required:
— to design or leverage on an information sharing model (partners, communities, sharing rules, etc.),
— to build or leverage on relevant data models for APT detection as basis to capture threats, but also to build the scenario(s) for the proof of concept and the demonstration,
— to implement and validate an 'APT detection engine' which is able to integrate and correlate different sources (e.g. external/internal networks, hosts, log files, etc.),
— to visualise detections for human validation,
— to establish an integration and validation environment,
— to perform the proof of concept demonstration.
Framework agreement with single operator
This content published on this page is meant purely as an additional service and has no legal effect. The Union's institutions do not assume any liability for its contents. The official versions of the relevant tendering notices are those published in the Supplement of Official Journal of the European Union and available in TED. Those official texts are directly accessible through the links embedded in this page. For more information please see Public Procurement Explainability and Liability notice.