【24h】

Supply chain risk mitigation for IT electronics

机译:减轻IT电子产品供应链风险

获取原文

摘要

Supply Chain Risk Management (SCRM) is one of the 12 Comprehensive National Cybersecurity Inititiatives (CNCI), but the range of supply chain problems has not been defined rigorously, and effective defenses have not yet been developed. Risks range from the increased unreliability of counterfeits to data exfiltration and adversary control enabled by hardware Trojan horses embedded in chips. Risks are different for military vs. non-military Government vs. civilian organizations. We cite cases that underscore the reality of supply chain risk, and analyze the structure of supply chains that affect different part of the market for IT electronics, in order to provide a better understanding of attack methods. We discuss techniques for defending against the range of threats, and propose a practical solution based on a suite of simple, inexpensive test procedures that could be used to build an "80% solution" for detection of counterfeits and embedded malicious implants before they are deployed. Tests we have prototyped include power signatures and of IR thermographic signatures of boot events. Deployment of such a test suite would change the SCRM game by making it significantly more difficult for supply chain exploits to succeed.
机译:供应链风险管理(SCRM)是12个国家网络安全综合计划(CNCI)之一,但是尚未严格定义供应链问题的范围,并且尚未开发出有效的防御措施。风险范围从伪造品不可靠的增加到通过芯片中嵌入的硬件特洛伊木马实现的数据泄露和对手控制。军事与非军事政府与民间组织的风险是不同的。我们列举了强调供应链风险现实的案例,并分析了影响IT电子市场不同部分的供应链结构,以便更好地了解攻击方法。我们讨论了防御威胁范围的技术,并基于一套简单,廉价的测试程序提出了一种实用的解决方案,该程序可用于构建“ 80%解决方案”,以在部署假冒产品和嵌入式恶意植入物之前对其进行检测。我们原型化的测试包括电源签名和引导事件的IR热成像签名。部署这样的测试套件将使供应链漏洞获得成功的难度大大增加,从而改变SCRM游戏。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号