Home AIBeyond the software supply chain: digital service chains

Beyond the software supply chain: digital service chains

by OmarAli
CNR/IMATI

Read here how the MIRANDA project addresses the security implications of networked digital services and what normative gap exists

Service chains are the intuitive counterpart to software supply chains when it comes to shifting scope from development to operations. They bring additional risks to businesses in an increasingly interconnected digital world, compounded by the highly fragmented nature of cybersecurity operations.

The MIRANDA project initially proposed the concept of Cybersecurity Digital Twin to promote collaboration between providers in multi-owner environments.

What is “networking”?

Today, digital applications increasingly rely on external third-party services. These include, to name just the most common, computing infrastructures (e.g., public cloud or edge deployments), block and object storage, communications networks (wired, Wi-Fi, cellular, long-haul), data sets (e.g., measurements from sensors, schedules, georeferenced maps), and remote procedure calls (e.g., Lambda functions). The connection of software, devices, data and infrastructure brings with it a large number of interconnected, recursive and often hidden supplier-consumer relationships that enable the construction of digital service chains (DSCs).

Service chains are all around us

Service chains now exist in almost all sectors of the economy, especially in those with deep integration of digital technologies. A non-exhaustive list of domains includes:

  • Smart city.
  • Automobile.
  • Intelligent network.
  • Intelligent manufacturing.
  • Precision agriculture.
  • 5G industries.

Security lags behind

The increasing adoption of software-defined infrastructure and services has laid the foundation for the creation of dynamic and adaptive DSCs between multiple providers. In fact, cloud applications can be easily scaled or redeployed on different infrastructure within minutes.

However, the same level of integration and interoperability is not available for cybersecurity processes. Today, collaboration between different sectors is mostly limited to a slow, partial and often inaccurate exchange of incident reports and cyber threat intelligence. This approach is largely ineffective because such information is only available once malicious activity is detected and likely spread to connected domains.

Guess or real threat?

Supply chain attacks are indeed an increasing threat to businesses. According to industry surveys, 97% of companies have been negatively impacted by at least one breach in their supply chain.

The growing number of digital connections is expected to exacerbate the problem as security controls between different domains become more relaxed, exposing them to lateral movement between digital service providers (DSPs). Although most examples of DSCs are currently limited to a few providers (e.g. public cloud services and sensor networks), several factors such as high bandwidth, massive connectivity, the Internet of Things (IoT), virtualization and multi-tenancy make 5/6G verticals fertile ground for attacks.

The core of the matter

The prevailing fragmentation of cybersecurity operations in multi-owner systems hinders visibility across domains. Many organizations rely on their suppliers’ protective measures and do not implement their own controls to address remaining vulnerabilities.

To improve service chain security, DSPs must collectively anticipate attacks and respond as they occur, building a collective response capacity that is greater and more effective than the mere sum of their parts.

The MIRANDA approach

The concept of Cybersecurity Digital Twin (CDT) has recently been used to denote a live model of the security characteristics of ICT systems that can be used to conduct security assessments and mimic cyberattacks and defense scenarios without disrupting the operational counterpart. In MIRANDA we have further developed the concept by providing modeling and prediction capabilities for the evolution of cyberattacks and the risk of potential threats in the current or hypothetical context in which the system operates.

A live model of attacks and kill chains

The MIRANDA CDT is a collection of multiple bidirectional models that abstract the composition, topology and security properties of interconnected systems. These models are continuously synchronized with the real world by feeding them security events and known vulnerabilities.

They are then, in turn, used to predict the evolution of cyberattacks based on shared threat intelligence. In addition, existing detection, analysis, protection and response processes will be improved jointly between providers.

The normative gap

The MIRANDA framework provides an effective solution for collaborative cybersecurity operations. However, a more sophisticated normative framework is required to overcome the typical reluctance of organizations in this direction. The current implementation of the European Union’s NIS2 Directive in Member States typically results in a purely reactive, static and fragmented approach:

  • Identify suppliers with manual registration and annual updates.
  • Narrow scope: operators of critical and essential services.
  • Hub-and-spoke topology between operators and national authorities.
  • Cyber ​​incident notification.
  • Cybersecurity commitments.
  • Risk management.

This may have worked a few years ago, but today it is already ineffective against the growing generation of cyber threats based on artificial intelligence. A future NIS3 should move to more proactive, dynamic, adaptive and autonomous cooperation models that can address constantly evolving threats in real time. Confidentiality and privacy conscious CDTs are already on the verge of becoming a reality. However, consistent further development of the legal framework is required in order to consolidate business opportunities and create incentives for further investments in bringing technology to market.

https://www.openaccessgovernment.org/article/beyond-the-software-supply-chain-digital-service-chains/212502/

Viral Trends

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More