# Project MSL-04 — CYBER SECURITY

**Program element:** 0602025E — Making, Maintaining, Supply CHAIN AND Logistics  
**Project:** MSL-04  
**Component:** Defense-Wide  
**Appropriation:** 0400 — RDT&E, Defense-Wide  
**Budget Activity:** 2 — Applied Research  
**Vintage:** President's Budget PB2027  
**Canonical URL:** https://hitchintel.com/programs/0602025E/MSL-04  
**Parent:** https://hitchintel.com/programs/0602025E

## Summary

Project MSL-04 — CYBER SECURITY requests $157.1M in FY2027, 9.7% of the $1.62B requested for program element 0602025E, up 13% on FY2026. 11 R-2A activities decompose the request.

## Funding profile

| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 0.0 |
| FY2026 | Enacted | 139.5 |
| FY2027 | Request | 157.1 |
| FY2028 | Outyear | 225.5 |
| FY2029 | Outyear | 236.5 |
| FY2030 | Outyear | 260.6 |
| FY2031 | Outyear | 269.2 |

> Estimate types are not summed. This project is one leaf of PE 0602025E; the PE total is the sum of its projects, never added to them.

## What project MSL-04 buys

The Cyber Security project is developing the computing, networking, and cyber security technologies required to protect Department of War, U.S. Government, and U.S. civilian information, information infrastructure, cyber-physical and embedded systems, critical infrastructure, and other computation-intensive mission-critical systems. Information technologies enable important existing and new military capabilities and drive the productivity gains essential to U.S. industry. Meanwhile, cyber threats grow in sophistication and number, and put data, computer programs, key information systems, and U.S. economic competitiveness at risk. The technologies developed in this project will enhance the resilience of information systems to current and emerging cyber threats; enable broad situational awareness of the cyber domain; and provide the basis for accurate, calibrated, and safe cyber response. Prior to FY 2026, efforts in this Project were funded in PE 0602303E, Project IT-03.

## Activities (R-2A) — 11

| Activity | FY2025 | FY2026 | FY2027 | Move | Page |
|---|---|---|---|---|---|
| Cyber Security and Resilience Studies and Concepts | — | 11.2 | 40.5 | +261% | [a7](https://hitchintel.com/programs/0602025E/MSL-04/a7) |
| Cyber Operations Studies and Concepts | — | 9.0 | 39.5 | +337% | [a8](https://hitchintel.com/programs/0602025E/MSL-04/a8) |
| Constellation | — | 28.1 | 25.0 | −11% | [a0](https://hitchintel.com/programs/0602025E/MSL-04/a0) |
| Intelligent Generation of Tools for Security (INGOTS) | — | 11.1 | 12.6 | +13% | [a1](https://hitchintel.com/programs/0602025E/MSL-04/a1) |
| Business Process Logic (BPL) | — | 11.5 | 11.8 | +3% | [a2](https://hitchintel.com/programs/0602025E/MSL-04/a2) |
| Provably Weird Network Deployment and Detection (PWND²) | — | 14.3 | 9.4 | −34% | — |
| Reclaiming Bus-based Systems During Compromise (Red-C) | — | 5.6 | 6.2 | +10% | — |
| Pipelined Reasoning of Verifiers Enabling Robust Systems (PROVERS) | — | 25.8 | 6.1 | −76% | — |
| Cyber Agents for Security Testing and Learning Environments (CASTLE) | — | 13.5 | 6.1 | −55% | — |
| Hardening Development Toolchains Against Emergent Execution Engines (HARDEN) | — | 6.8 | — | −100% | — |
| Signature Management using Operational Knowledge and Environments (SMOKE) | — | 2.4 | — | −100% | — |

> Activities carry the prior, current and budget year only — no five-year plan. In the request year they partition this project exactly; in earlier years they can under-cover it.

### Cyber Security and Resilience Studies and Concepts

- Develop interactive tools that facilitate understanding of formal mathematical proofs for high assurance software systems. - Create formal compilation and verification techniques that improve the resistance of computing systems to soft errors. - Develop techniques and tools that integrate verification and validation with model-based…

Full year-by-year narrative: https://hitchintel.com/programs/0602025E/MSL-04/a7

### Cyber Operations Studies and Concepts

- Develop techniques for automated identification of latent behaviors for heterogenous mega-systems to enable novel defenses. - Develop techniques for digital continuity of operations. - Use on-board sensor data to enable timely detection of cyber attacks. - Discover and prove logic flaws in security protocol implementations. - Learn to…

Full year-by-year narrative: https://hitchintel.com/programs/0602025E/MSL-04/a8

### Constellation

- Refine and integrate cyber operational prototypes with established DoW programs and systems to create a cohesive, robust, and effective cyber warfighting architecture. - Develop, test, evaluate, and operationalize cyber technologies, prototypes, and capabilities in collaboration with DoW cyber stakeholders. - Coordinate with U.S. cyber…

Full year-by-year narrative: https://hitchintel.com/programs/0602025E/MSL-04/a0

### Intelligent Generation of Tools for Security (INGOTS)

- Develop and demonstrate techniques for fully automated exploit chain synthesis, including link replacement and repair, in complex systems. - Advance the analysis and modelling of exploit chains to forecast exploit chain lifecycle in complex software systems that have state-of-the-art defenses. - Demonstrate the capability to reproduce…

Full year-by-year narrative: https://hitchintel.com/programs/0602025E/MSL-04/a1

### Business Process Logic (BPL)

- Extend ingest and process model generation to handle noisy or incomplete system information of real-world BL systems. - Demonstrate automated fault identification capability on an enterprise system of interconnected BL systems. - Evaluate the performance of techniques for identification and resolution of BL faults to existing and new…

Full year-by-year narrative: https://hitchintel.com/programs/0602025E/MSL-04/a2

### Provably Weird Network Deployment and Detection (PWND²)

**FY2027 planned work.** - Refine approaches for formally modeling adversaries that actively hunt for hidden or obfuscated communications. - Demonstrate the scalability of approaches using highly realistic network environments.

**FY2026 to FY2027 change.** The FY 2027 decrease reflects a shift from demonstration to refinement and transition.

**FY2026 plans — current year.** - Develop approaches for quantifying the scalability, security, and privacy of weird networks in the context of a capable adversary alerted to the possibility of hidden or obfuscated communications. - Analyze weird networks as components of larger systems that can support hidden communications at global scales. - Demonstrate weird network use cases, such as internet freedom and others where the fact that entities are communicating needs to be hidden or obfuscated.

### Reclaiming Bus-based Systems During Compromise (Red-C)

**FY2027 planned work.** - Implement techniques for peer-based monitoring, detection, and remediation of bus cyber-attacks. - Conduct demonstrations of bus resilience technologies implemented as firmware updates suitable for deployment to common bus-based systems and components.

**FY2026 to FY2027 change.** The FY 2027 increase reflects a shift from development of bus resilience technologies to demonstration.

**FY2026 plans — current year.** - Formulate approaches for instrumenting bus-based systems to enable collective monitoring and detection of cyber-attacks by bus peers. - Explore techniques for responding to attack and compromise of bus-based systems through collaborative software patch creation and real-time repair by bus peers.

### Pipelined Reasoning of Verifiers Enabling Robust Systems (PROVERS)

**FY2027 planned work.** - Demonstrate the ability of regular DoW development staff to incorporate formal-methods-based tooling into development processes at minimal cost. - Demonstrate cybersecurity benefits of formal-methods development integration.

**FY2026 to FY2027 change.** The FY 2027 decrease reflects a shift from development to demonstration.

**FY2026 plans — current year.** - Create novel system-architecture modelling and analysis tools that enable integration of formal-methods early in the development lifecycle. - Evaluate the barriers-to-adoption of formal-methods-based tooling into DoW software development workflows. - Collaborate with DoW stakeholders on controlled formal methods-based experiments on selected high-assurance and mission-critical military software systems. - Implement formal-methods-based tools that are capable of the specification and verification of DoW-relevant cybersecurity properties. - Quantify cost of incorporating formal-methods-based proof maintenance and repair capabilities in software development workflow.

### Cyber Agents for Security Testing and Learning Environments (CASTLE)

**FY2027 planned work.** - Refine environment simulations and agent training to transition partner operational priorities. - Extend environments to support training goals of defensive cyber operators.

**FY2026 to FY2027 change.** The FY 2027 decrease reflects a shift from demonstration to refinement and transition.

**FY2026 plans — current year.** - Extend agent training in larger network environments and automate defensive responses to attacks while maintaining operations. - Automate instantiation of exemplar network environments and execution of agent strategies. - Demonstrate automated system security of realistic network environments.

### Hardening Development Toolchains Against Emergent Execution Engines (HARDEN)

**FY2026 to FY2027 change.** The FY 2027 decrease reflects program completion.

**FY2026 plans — current year.** - Demonstrate and evaluate the effectiveness of mitigations against unintended system behaviors to reduce risk of adversarial reuse and emergent execution. - Refine tools for emergent execution mitigation to enhance potential integration across the SDLC.

### Signature Management using Operational Knowledge and Environments (SMOKE)

**FY2026 to FY2027 change.** The FY 2027 decrease reflects program completion.

**FY2026 plans — current year.** Harden cyber planning and risk management tools and transition capabilities to operational partners.

## What is NOT on this page

Congressional marks, the R-2 mission description and acquisition strategy, the industry vs government split of the whole request, and related program elements are recorded at **program-element** grain — an NDAA mark lands on a PE, never on a project. They are at https://hitchintel.com/programs/0602025E.

## Source & machine access

- **Source:** FY2027 Office of the Secretary of Defense RDT&E Budget Justification, Exhibits R-2/R-2A/R-3, PE 0602025E project MSL-04 (PB PB2027).
- **MCP:** `mcp.hitchintel.com` — `budget_get_program_element(pe="0602025E")`.

*HitchAI is an independent intelligence service, not affiliated with the U.S. Department of Defense. Budget figures are requests/estimates, not obligations.*