当前位置:首页 > 报告详情

数字井中的毒药:基于情报的供应链攻击防御.pdf

上传人: S** 编号:1241077 2026-05-16 16页 1.39MB

1、Poison in the Digital WellIntelligence-Driven Defense Against Supply Chain Attacks“If the well is poisoned upstream,every customer drinks downstream.”Shilpi Mittal Attackers compromise something you depend on(software,vendor,service).It works with updates and integrations inherit trust;the blast rad

2、ius spreads fast.Our goal is to reduce auto-trust with visibility,gates,and practiced rollback.What Is A Supply Chain Attack?OVERVIEWWhat this talk is about120252026 threat landscape:why the supply chain is surging2Case study:September 2025 NPM compromise and its blast radius3Why are multiple servic

3、es disproportionately exposed4Intelligence-driven defense:reference architecture+controls5Detection&response playbookFRAMINGSupply chain risk is“trust transitivity”at internet scaleWhat makes it differentA compromise upstream inherits your trustBlast radius scales across customers instantly Small su

4、ppliers bypass hardened perimetersWhere attackers win Maintainer phishing/account takeover Poisoned updates to popular dependencies CI/build pipeline or vendor access compromiseTrust graphUpstreamPackage/VendorBuildPipelineYourAppsCustomers&PartnersYour“attack surface”includes code and access you do

5、 not fully control.Poison in the Digital Well FramingCASE STUDYSeptember 2025 NPM Supply Chain AttackWhat happened(high level)18 widely used npm packages were modified2.6B weekly downloads created massive downstream exposureLikely maintainer compromise;malicious versions spread via normal updatesCom

6、pressed timeline(illustrative)Day 0(Initial Access)Maintainer accountCompromisedHours(Trust boundary breached)Malicious versionpublishedHoursDaysCI/CD pulls updateinto buildsDaysIndicators shared;orgs pin/rollbackPoison in the Digital Well Case StudyTHE DATAThird-party involvement doubled to 30%of b

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
1. **供应链攻击激增**:2025年第三方相关 breaches 占30%,成为主要入侵路径;供应链攻击平均检测+ containment 时间长达267天,成本更高。 2. **攻击特点**:依赖信任传递(如NPM 2.6B周下载量恶意包)、快速扩散(传递依赖+CI缓存)、小供应商绕过防御。 3. **防御核心**:需构建“可信软件工厂”,通过SBOM(软件物料清单)、SLSA(供应链级别保证)实现可见性+策略控制(如签名、允许列表)。 4. **关键行动**:强制MFA/硬件认证、CI加固(临时运行器、最小权限)、自动生成SBOM+证明、威胁情报驱动包检测(如发布异常行为)。 5. **响应流程**:快速回滚+凭证轮换,依赖SBOM+证明定位影响范围。
**供应链攻击?** **如何防御?** **信任如何建立?**
客服
商务合作
小程序
服务号
折叠