Centro de Documentação da PJ | ||||
| ENISA Threat landscape for supply chain attacks [Documento electrónico].- [Attiki] : European Union Agency for Cybersecurity, ENISA, 2021.- 1 CD-ROM ; 12 cm Ficheiro de 4,78 MB em formato PDF (57 p.). ISBN 978-92-9204-509-8 CRIME INFORMÁTICO, SEGURANÇA INFORMÁTICA, PROTECÇÃO DE SOFTWARE, SEGURANÇA DE DADOS Introduction. 2. What is a supply chain attack? 2.1. Taxonomy of supply chain attacks. 2.2. Attack techniques used to compromise a supply chain. 2.3. Supplier assets targeted by a supply chain attack. 2.4. Attack techniques used to compromise a customer. 2.5. Customer assets targeted by a supply chain attack. 2.6. How to make use of the taxonomy. 2.7. Supply chain taxonomy and other frameworks. 2.7.1. MITRE ATT&CK® Knowledge Base. 2.7.2. Lockheed Martin Cyber Kill Chain® Framework. 3. The lifecycle of a supply chain attack. 4. Prominent supply chain attacks. 4.1. Solarwinds orion: it management and remote monitoring. 4.2. Mimecast: cloud cybersecurity services. 4.3. Ledger: hardware wallet. 4.4. kaseya: it management services compromised with ransomware. 4.5. an example of many unknowns: sita passenger service system. 5. Analysis of supply chain incidents. 5.1. Timeline of supply chain attacks. 5.2. Understanding the flow of attacks. 5.3. Goal oriented attackers. 5.4. Most attack vectors to compromise suppliers remain unknown. 5.5. Sophisticated attacks attributed to apt groups. 6. Not everything is a supply chain attack. 7. Recommendations. 8. Conclusions. Annex A: summary of supply chain attacks. |