Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

EyeON

Software ·
DOI:https://doi.org/10.11578/dc.20241223.6· OSTI ID:code-149447 · Code ID:149447
 [1];  [1];  [1];  [1]
  1. Lawrence Livermore National Laboratory (LLNL), Livermore, CA (United States)

EyeON: Eye on Operational technology Software Supply Chain attacks have risen drastically over the past few years, none more well-known and impactful than the SolarWinds compromise. Criminal organizations inserted an attack vector into a specific version of the source code, giving themselves an air of credibility. Once news broke on SolarWinds, identifying compromised sites was very difficult, even knowing the culprit update. Software Bills of Materials (SBOM) have been touted as the solution to reclaiming control of your software supply chain. Deployment of SBOMs has been slow, however, due to conflicting standards, opaque storage requirements, and vendor adoption. Additionally, the path from obtaining an SBOM and securing your supply chain is unclear; how can an SBOM library be leveraged to provide insight to your attack surface? The EyeON tool, sponsored by Department of Energy Cybersecurity, Energy Security, and Emergency Response (DoE CESER), aims to address these gaps by providing an encapsulated solution to tracking which updates have been installed in an enterprise, and alerting system administrators to vulnerabilities as they become known. Similar to a virus scanner, EyeON is a command line tool to parse either a single file, nested directory structure, or filesystem. It collects data such as signature (hashes), version information, VirusTotal tags, compiler, compilation date, and code signing information. Users will anonymously submit scan data periodically to DoE CESER, who will then compile a database of known software products employed by Critical Infrastructure and broadcast alerts based on discovered flaws as they arise.

Short Name / Acronym:
EyeON
Site Accession Number:
LLNL-CODE-2001017
Software Type:
Scientific
License(s):
MIT License
Research Organization:
Lawrence Livermore National Laboratory (LLNL), Livermore, CA (United States)
Sponsoring Organization:
USDOE National Nuclear Security Administration (NNSA)

Primary Award/Contract Number:
AC52-07NA27344
DOE Contract Number:
AC52-07NA27344
Code ID:
149447
OSTI ID:
code-149447
Country of Origin:
United States

Similar Records

Towards a New Supply Chain Cybersecurity Risk Analysis Technique
Technical Report · Sun Aug 01 00:00:00 EDT 2021 · OSTI ID:1877401

SCA Tools - SCRM Value Add or Lossy Noise Machines
Conference · Wed Oct 30 00:00:00 EDT 2024 · OSTI ID:2479528

Prioritizing ICS Beachhead Systems for Cyber Vulnerability Testing
Technical Report · Mon Feb 28 23:00:00 EST 2022 · OSTI ID:1856808

Related Subjects