SolarWinds Software Supply Chain Security: Better Protection with Enforced Policies and Technologies

Jeong Yang,Young Lee,Arlen P. McDonald
DOI: https://doi.org/10.1007/978-3-030-92317-4_4
2022-01-01
Abstract:A recent cybersecurity attack took place on US governments and companies utilizing a popular network performance monitoring tool, SolarWinds. The attack appears to be not only extensive but also comprehensive in the scope of the common security tools that have been breached. This attack targeted the complex software supply chain. The wave of those attacks was mainly focused on the critical departments of the U.S. government and of many other leading corporations. Even if the attackers did not actively exploit their systems, the comprehensive nature of these breaches seems to indicate that there are fundamental flaws with existing security infrastructure. This paper investigates what caused this significant attack and what solutions we might have to prevent similar attacks in the future. The paper concludes that a combined set of actions of the government and industries on better policies and technologies is needed to develop a unified strategy in each organization.
What problem does this paper attempt to address?