← Back to NASA Technology Projects

Fuzzing Flight Software: A "Black Hat" Approach to Software Testing

Completed TRL 6 (started at 3, targeting 6)

Description

This project aims to apply the software testing technique called Fuzz Testing (fuzzing for short) to the core Flight System (cFS) flight software suite. Fuzzing is a technique traditionally used by security researchers, and sometimes hackers, to find vulnerabilities in software, but is increasingly being used as part of holistic approach to fixing buggy software. This project has the potential to revolutionize the way software testing is done at NASA, resulting in the reduction of failures in critical applications.

Benefits

The Fuzzing technique has the potential to significantly improve the robustness of flight software as it can mimic the effects of a radiation-induced bit flip more effectively than traditional testing methods. Because the cFS framework is so widely used on GSFC missions, the results of this IRAD will be directly beneficial to a wide variety of current and future GSFC missions and software products. The truly radical part of this project is that, when successful, this technique could be applied to any software project across the whole of NASA, meaning that the entirety of NASA could benefit from this state-of-the-art testing methodology.

Details

Technology areaSoftware, Modeling, Simulation, and Information Processing > Software Development, Engineering, and Integrity > Tools and Methodologies for Software Design and Development
ProgramCenter Independent Research & Development: GSFC IRAD (GSFC IRAD)
Lead organizationGoddard Space Flight Center, Greenbelt, MD
Start date2019-10-01
End date2020-09-30

Project contacts

Listed on TechPort itself — the most direct way to ask about this specific project.

How to get involved

This is early/mid-stage (TRL 6) — the most realistic path in is NASA SBIR/STTR, which funds small businesses and research institutions to develop technology aligned with NASA's needs (equity-free, phased funding). Check whether a current SBIR/STTR solicitation topic overlaps with this project's technology area, or contact the project directly (above) to ask.

None of these are guaranteed paths for this specific project — TechPort itself doesn't have an "apply" button. Reaching out to the contact(s) above with a specific question is usually the fastest way to find out what's actually open.