DIU: Cyber Threat Telemetry

Suspense: 20 January 2021 Description:  The Department of Defense seeks visibility into the vast amount of public, private, and open source cyber threat telemetry and innovative threat data solutions. Combined, this data is necessary for maintaining situational awareness of threat activity and understanding the attributes of malicious cyber activities and actors.

Category: Opportunity

DoD Communities of Interest: Cyber

Subject: Cyber Threat Telemetry

Due Date: 2021-01-20 23:59:59 US/Eastern Time

Government Organization: DIU

Description

Project Description

Executive Summary

The Department of Defense seeks visibility into the vast amount of public, private, and open source cyber threat telemetry and innovative threat data solutions. Combined, this data is necessary for maintaining situational awareness of threat activity and understanding the attributes of malicious cyber activities and actors.

DIU expects a 12 month prototype period to first demonstrate capability, then demonstrate integration to existing analytic workflows and platforms, and finally to integrate into Department of Defense big data solutions. 

Prospective bidders are invited to submit their proposals (“Solution Brief”) per the guidelines below. Solutions should be commercial products that leverage a deployment track record and wide customer base to ensure off-the-shelf compatibility with a continuously growing base of managed cloud services.

Vendors selected for phase two will deliver an in-person pitch as well as a live product demonstration in early 2021. The demonstration event will allow the evaluation team to assess the current maturity of the proposed solution.

The DoD seeks to prototype a readily available and commercially validated solution that includes the ability to:

Augment existing Threat Intelligence Platforms and feeds

Provide compatible data formats for operators and analysts who query the data source such as JSON, CSV or STIX/TAXI

Provide analytical commentary on trends, timelines, scope, scale, global insights, and other threat data sources

Present processed and unprocessed threat and telemetry data via visualizations and dashboards, accessed via a pool of concurrent use licenses

Provide access to threat research, reporting and queries on areas as defined by the USG

Provide APIs and other programmatic access to data and/or data feeds

Provide a real-time situational awareness of blue, grey and red space

Provide access to original data sources

In addition to submission instructions below, companies should include links to the following in their solution briefs*. 

Administration/user guide of the current shipping product

Technical guides of the current shipping product

*Please note, it is expected to be part of the 5 pg white paper or 15 page slide deck described in the Solution Brief requirements below.

Notes

The Government may facilitate teaming arrangements among submissions offering complimentary capabilities to achieve desired effect. Companies are also welcome to present their own teaming arrangements in their solution briefs. 

Companies must be US-owned.

Companies without a CAGE code will be required to register in SAM if selected. The Government recommends that prospective companies begin this process as early as possible.

Resellers, integrators, and academic research proposals are not desired.

We are not looking for a Threat Intelligence Platform that only aggregates open source or subscribed feeds.

We are not looking for a managed SOC or managed threat intelligence in this solicitation.

Priority will be given to OEM vendors with original data sources.

Solutions should be readily available and have commercial viability

Solution Brief Requirements

Solution Briefs will be no more than five (5) written pages, 12-point font. In the alternative you may submit slides. Solution Brief slides will be no more than fifteen (15) slides.

Website: http://diu.mil