Preparing Your Business for Software Supply Chain Attacks

Software Supply Chain Attacks

Supply chain attacks occur when third-party tools and software you have been supplied with are breached. This gives an entry point to your data, with the threat emanating outside your initial security network.

To rely on your company’s own security is a recipe for disaster. As more organizations are using third-party tools, processing increased amounts of data remotely, checking the supply chain is imperative. Unfortunately, this is not something many businesses do, or at least on a regular basis. Since 2020, supply chain attacks have increased by around 300%. This is why you need to secure your company.

Understanding Software Supply Chain Attacks

A supply chain attack occurs when tools and services supplied by a third party are infiltrated and enter a system or network. They are also referred to as value attacks or third-party attacks. The more third-party tools a company uses, the more entry points are available, and the bigger the danger becomes. Knowing how to prevent software supply chain attacks is tough, especially in larger organisations.

Many supply chain attacks are also indirect. They don’t go to the company directly, but to the tools they use. A standard website with plugins can have hundreds of software entry points, for example. Hackers will get into these third-party applications and add their code. This will then be sent to hundreds of customers, who add it to their systems and allow network access.

The process begins with the upstream attack, a name given to the period when attackers gain access to a third-party system. This can be done in several ways, often using one of the most popular hacking trends, such as phishing or zero-day attacks. The downstream attack is the subsequent action when attackers gain access through the third-party supply chain and execute their malware.

Where Do Supply Chain Attacks Come From?

One place supply chain attacks come from is open source software. Open source means anyone can use the software and contribute to its development. While it is great because it uses collective knowledge, it is ripe for hackers to introduce threats. Luckily, other members of the community often notice this and create a solution.

Software products coming from commercial companies are one of the most common places in which supply chain attacks emanate. Gaining access here is a gold mine for hackers. If they can get code into a company’s software, which is then shared, they have access to hundreds or thousands of businesses. They also do not have to go through a company’s system directly, which is often the most robust part.

Lastly, many of these attacks come from hostile foreign countries and rogue states. Products that are manufactured for the Internet of Things can have vulnerabilities deliberately input into them at this point. This does not even have to be state-sanctioned. When sold to other countries, these manufacturers then know how to launch attacks.

Well-Known Supply Chain Attacks

Based in San Francisco, Okta is an American identity and access management company. Essentially, they build products that authenticate identity and then manage and secure its use in applications. In October 2023, it reported that confidential data on consumers could be accessed through obtaining credentials in the customer management and support systems.

Even companies which base their entire business on security, such as Norton, are not immune. The anti-virus company reported in May 2023 that a zero-day vulnerability had been discovered in the managed file transfer which moves files between Norton and its customers. Norton was actually held to ransom by the hackers, who threatened to release the data if it was not paid.

Even flight company Airbus had an attack, which took place at the start of 2023. It happened through Turkish Airlines, one of its consumers, and an account they held. The threat actor known as USDoD managed to gain access to the employee’s account and go into their systems, allowing them to get personal information on business customers.

Preventing Supply Chain Attacks

Supply chain attacks are hard to work against, as much of it is out of your control. Yet you can make sure you monitor your supply chain, managing it and reviewing systems and access. Thorough documentation of them is also essential. Unfortunately, this does take a lot of work on top of your existing security protocols.

A period of due diligence should also be done with any new supplier. Make sure you question their security, and look for previous attacks they may have had. Ensure you know how they learned from the mistake. You should also check contractual agreements with any existing ones, making amendments or finding new suppliers as appropriate.

Supply chain attacks are going to increase. That means most companies will have attacks on their third-party software. Safeguarding against them is important, but having plans in place to deal with them if they do occur is vital. 

Ashwin S

A cybersecurity enthusiast at heart with a passion for all things tech. Yet his creativity extends beyond the world of cybersecurity. With an innate love for design, he's always on the lookout for unique design concepts.