0% found this document useful (0 votes)
17 views3 pages

Software Supply Chain Attack Insights

The document discusses software supply chain attacks and how attackers can remain anonymous on the World Wide Web. It provides examples of recent supply chain attacks targeting companies like SolarWinds and CCleaner. The attacks involve exploiting vulnerabilities in vendor networks, injecting malware into software updates, and signing malicious code with stolen certificates to appear legitimate.

Uploaded by

satesh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
17 views3 pages

Software Supply Chain Attack Insights

The document discusses software supply chain attacks and how attackers can remain anonymous on the World Wide Web. It provides examples of recent supply chain attacks targeting companies like SolarWinds and CCleaner. The attacks involve exploiting vulnerabilities in vendor networks, injecting malware into software updates, and signing malicious code with stolen certificates to appear legitimate.

Uploaded by

satesh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Discussion

Have you heard of a software supply chain attack? These attacks one of the most insidious
forms of cyber attacks as they tend to hide themselves within apps and software that users
trust.
Review the article on the following site: “A Mysterious Hacker Group Is On a Supply Chain
Hijacking Spree | WIRED,” Andy Greenburg, 5 March 2019. [Online]. Available:
[Link] (the link will open in new window)
Without concentrating on the finer details, use your knowledge from domain 4 and 5 to identify
how this case is an example of identity theft and how this case shows how attackers can remain
“anonymous” on the World Wide Web by circumventing communications and network security.
Adversaries are increasingly targeting software supply chain to gain access to the secure
computing environments of software vendors customers. One example of such an attack is
where cyber threat actor infiltrates a software vendors/suppliers’ network and attempts to deploy
malicious code into the vendor’s software to comprise it before the vendor pushes it out to their
customers.
Customers trust vendors/suppliers and unwittingly distribute malware to their entire client
network which exploits that trusted relationship between the entities. The compromised software
is then introduced into the client’s data or network allowing the attacker to pivot to other
networks and downstream attack surfaces through the chain of trust. This is a form of identity
theft because the attacker’s software appears to be coming from the trusted vendor.
The article “A Mysterious Hacker Group is on a Supply Chain Hijacking Spree” refers to a
number of the most recent high profile supply chain attacks involving suppliers such as Asus,
CCleaner, Piriform, NetSarang all caried out by a hacker group named “Barium”.
The potential impact of the CCleaner attack is could be similar to or exceed that caused by the
NotPetya attack which targeted accounting software used in the Ukraine and is estimated to
have caused $10B in damage. The attack sharessome similarities with previous supply chain
attacks targeting the customers of SolarWinds, such as FireEye..
It is apparent that several common attack techniques are being employed by Barium hackers to
execute software supply chain attacks such as:
Exploiting vulnerabilities in supplier/vendor networks arising from insecure permissions,
inadequate security measures and misconfigurations
Injecting malware into a software update delivered by a software vendor
Malicious code injected into publicly available open sources code libraries
Stealing code-signing certificates and signing malicious code/applications using the identity of a
trusted supplier/vendor
Objective is to deliver a trojanized component that is digitally signed (to validate authenticity and
integrity) and which contains a backdoor that allows for remote access by the attacker (e.g., via
3rd party servers).
backdoored software update using a unique hashing function, malicious code injected into
similar place in software’s runtime functions
hackers' backdoor was designed to activate and reach out to a command-and-control server
Hiding communication between target and attacker within the domain name system protocol
Create malware that does not trigger anti-virus alerts
This attack can be comparted to the Solar Winds attack as we can see some similarities.
The Solar Winds Orion attack worked this way:

This study source was downloaded by 100000826943830 from [Link] on 10-03-2023 13:29:18 GMT -05:00

[Link]
Malicious payload injected into a SolarWinds Dynamic Link Library file (.dll file), file was digitally
signed asset of software that was a disguise needed to gain access to client base
Modified a legitimate utility on the targeted system with malicious one, executed it, and then
replaced it back with the legitimate one
Remote access trojan (RAT) activated when compromised software installed, gives access to
infected host for data theft (exfiltration)
Malware payload –acted as keylogger and password-stealer
This case shows how attackers can remain “anonymous on WWW”. The use of deception to
achieve anonymity has been highlighted: using hidden command and control, using stolen e-
mail accounts (form of masquerading), using compromised third party networks, and using
compromised third party services. These attacks were done so stealthily and went undetected
for some time allowing the cyber threat actors ability to spy on companies and organizations. In
some cases, the hackers broke into email accounts and networks in departments of high-
ranking officials.
This case in this article is a good example of identity theft as access to customer and client PII
was breached and non-compliance with the various privacy acts such as GDPR, Privacy Act of
1974 and the Electronic Communications Privacy act of 1986 were violated.
When clients would perform updates with compromised software from the service provider, the
malicious code that had been installed gives the same permissions as the digitally signed
software. The goal of the cyber threat actor was to target a single organization to gain an initial
foothold, and then compromise hundreds of thousands of other organizations simultaneously
with minimal effort.
Due to their sophistication and the number of organizations and systems involved, software
supply chain attacks can be difficult to detect. The following provides a list of potential impacts
of a supply chain attack:
Financial Impact: massive impact on one or more organizations – organizations can endure
direct or indirect financial repercussions. Damages can include cost of incident response and
forensic investigations, business interruptions, lost revenue, and loss of reputation.
Data Breach: since vendors use, store, and transmit sensitive PII, business information, credit
card numbers, industrial espionage (theft of trade secrets) – when vendor is compromised a
vast amount of data becomes readily accessible to the hackers and can be used as
ransomware.
Compliance Violations: Supply chain attacks can cause organizations to violate regulations or
industry standards – that may result in stringent fines or further audits of the organization.
The following is a list of best practices to mitigate risk associated with 3rd parties to prevent
supply chain attacks:
Critical to do proper due diligence:
o Trustworthiness checks of vendors and suppliers
o Ensure 3rd party vendors are compliant with relevant and appropriate of cybersecurity
standards - can make use security questionnaires to analyze vendors security practices
(governance polices, compliance processes, security posture and technical security controls)
o Where possible, establish binding contractual cyber security requirements on
vendors/suppliers. The stringency of these requires should be based upon the level of cyber
security risk acceptable to the purchaser.
Identify Attack Vectors- in order to mitigate risk it is imperative to understand how threat actors

This study source was downloaded by 100000826943830 from [Link] on 10-03-2023 13:29:18 GMT -05:00

[Link]
infiltrate organizations. If possible remove attack vectors, or protect them if required.
Two factor authentication could increase the difficulty of performing supply chain attacks. For
instance, if the vendor uses this security technique for controlling remote access to their
software deployment sites, threat actors will have an extra barrier to cross before gaining
access to vendors software deployment system
Applying zero-trust networking principles and role-based access controls not just to users, but
also to applications and servers. – Micro segmentation is promoted by zero trust whereby
attackers must reauthenticate to proceed into different zones within a network
Protecting against malware: Command and control attacks which may be hidden in software
updates can be blocked by using DNS filtering.
Create an incident response plan- to establish a plan before attack occurs based on risk and
should included regulatory reporting requirements
Conduct Security Awareness training – Should include password security, social engineering
attack methods. Employees also need to understand how software supply chain attacks occur
and the role they play in remediation, detection, and prevention of threats.

This study source was downloaded by 100000826943830 from [Link] on 10-03-2023 13:29:18 GMT -05:00

[Link]
Powered by TCPDF ([Link])

You might also like