Software supply chain attacks, a threat to global cybersecurity: SolarWinds' case study

The work

AuthorsJeferson Martínez; Javier M. Durán
Editors
Typearticle
Year2021
Citekeymartinez2021software

Where it appeared

Published inInternational Journal of Safety and Security Engineering
Volume11
Issue5
Pages537--545

Identifiers

DOI10.18280/ijsse.110505

Abstract

Exploitation of a vulnerability that compromised the source code of the Solar Winds’ Orion system, a software that is used widely by different government and industry actors in the world for the administration and monitoring of networks; brought to the fore a type of stealth attack that has been gaining momentum: supply chain attacks. The main problem in the violation of the software supply chain is that, from 85% to 97% of the code currently used in the software development industry comes from the reuse of open source code frameworks, repositories of third-party software and APIs, creating potential vulnerabilities in the development cycle of a software product. This research analyzes the SolarWinds case study from an exploratory review of academic literature, government information, but also from the articles and reports that are published by different cybersecurity consulting firms and software providers. Then, a set of good practices is proposed such as: Zero trust, Multi-Factor authentication mechanisms (MFA), strategies such as SBOM and the recommendations of the CISA guide to defend against this type of attack. Finally, the research discusses about how to improve response times and prevention against this type of attacks, also future research related to the subject is suggested, such as the application of Machine Learning and Blockchain technologies. Additionally for risk reduction, in addition to the management and articulation of IT teams that participate in all the actors that are part of the software life cycle under a DevSecOps approach.

A copy is held

pdf, 1.5 MB. Not published — it may be under copyright. The facts and links here are.

How it got here

How it got hereimport via bibtex
Added2026-08-04 00:00 UTC
Approved bya person 2026-08-16 15:38 UTC

Cite it as

@article{martinez2021software,
  title        = {Software supply chain attacks, a threat to global cybersecurity: SolarWinds' case study},
  author       = {Jeferson Martínez and Javier M. Durán},
  year         = {2021},
  journal      = {International Journal of Safety and Security Engineering},
  volume       = {11},
  number       = {5},
  pages        = {537--545},
  doi          = {10.18280/ijsse.110505},
}

This record lives at https://refs.drheap.org/martinez2021software/ and will keep doing so.