Published January 13, 2025 | Version author version
Journal article Open

Advanced Persistent Threats Based on Supply Chain Vulnerabilities: Challenges, Solutions & Future Directions

Description

Due to the ever increasing inter-dependency across a variety of diverse software and hardware components in Information and Communications Technology (ICT) provisioning, Supply Chain Vulnerabilities (SCVs) targeting such dependencies have evolved as a primary choice for malicious actors to stealthy and complex cyber-attacks. The current modus operandi in the cyber threat spectrum is solely correlated with Advanced Persistent Threats (APTs) that have shown to be prevalent across diversified attacks underpinning cyberwarfare, and cybercrime. Hence, defense against such threats is undoubtedly considered as a high priority on a global scale. Nonetheless, the reliance on third-party supply chain software and device across diverse ICT ecosystems, combined with the current defense mechanisms’ inability to identify specific compromised entry points, results in an increased risk of APTs. This survey explores the state-of-the-art to stratify and showcase the properties of supply chain-based APTs, elaborate on reported risks from such APTs, and expand on existing defense methods. This study connects academic research with industry practices to highlight a new and growing problem. It examines supply chain compromises, offers unique insight into how these exploitations occur, and equips cybersecurity practitioners with the knowledge required to design next-generation APT defense mechanisms.

Files

iot_journal_accepted_n.pdf

Files (806.0 kB)

Name Size Download all
md5:1e1f9827773ad92618a27c753d10134e
806.0 kB Preview Download

Additional details

Funding

European Commission
COCOON – COoperative Cyber prOtectiON for modern power grids 101120221
European Commission
TRACE – Integration and Harmonization of Logistics Operations 101104278