数字井中的毒药:基于情报的供应链攻击防御.pdf
1、Poison in the Digital WellIntelligence-Driven Defense Against Supply Chain Attacks“If the well is poisoned upstream,every customer drinks downstream.”Shilpi Mittal Attackers compromise something you depend on(software,vendor,service).It works with updates and integrations inherit trust;the blast rad
2、ius spreads fast.Our goal is to reduce auto-trust with visibility,gates,and practiced rollback.What Is A Supply Chain Attack?OVERVIEWWhat this talk is about120252026 threat landscape:why the supply chain is surging2Case study:September 2025 NPM compromise and its blast radius3Why are multiple servic
3、es disproportionately exposed4Intelligence-driven defense:reference architecture+controls5Detection&response playbookFRAMINGSupply chain risk is“trust transitivity”at internet scaleWhat makes it differentA compromise upstream inherits your trustBlast radius scales across customers instantly Small su
4、ppliers bypass hardened perimetersWhere attackers win Maintainer phishing/account takeover Poisoned updates to popular dependencies CI/build pipeline or vendor access compromiseTrust graphUpstreamPackage/VendorBuildPipelineYourAppsCustomers&PartnersYour“attack surface”includes code and access you do
5、 not fully control.Poison in the Digital Well FramingCASE STUDYSeptember 2025 NPM Supply Chain AttackWhat happened(high level)18 widely used npm packages were modified2.6B weekly downloads created massive downstream exposureLikely maintainer compromise;malicious versions spread via normal updatesCom
6、pressed timeline(illustrative)Day 0(Initial Access)Maintainer accountCompromisedHours(Trust boundary breached)Malicious versionpublishedHoursDaysCI/CD pulls updateinto buildsDaysIndicators shared;orgs pin/rollbackPoison in the Digital Well Case StudyTHE DATAThird-party involvement doubled to 30%of b





点击查看更多