A Supply Chain Incident Taxonomy

Eric Byres

S4x24 - ICS Security Conference · Day 3 · Main Stage

Overview

In this insightful S4 talk, veteran cybersecurity expert Eric Byres addresses a fundamental challenge plaguing the understanding and defense against supply chain attacks: the lack of a comprehensive and meaningful taxonomy. Byres, reflecting on two decades of experience in the field, including early encounters with sophisticated threats like the Dragonfly attacks in 2014, highlights the critical need for a better way to define and classify these complex incidents. He argues that existing definitions, such as the one from CISA, are often too narrow, failing to encompass the full spectrum of observed attacks and hindering effective communication and defense strategies.

Watch on YouTube

Visual summary for A Supply Chain Incident Taxonomy by Eric Byres
Visual summary for A Supply Chain Incident Taxonomy by Eric Byres

Key moments

  1. 2:00 Problem with narrow supply chain attack definitions
  2. 3:30 Criteria for an effective, meaningful supply chain taxonomy
  3. 4:30 Critique of existing MITRE and Landissa taxonomies
  4. 7:00 Deriving top-level categories: Creation and Delivery

A Supply Chain Incident Taxonomy

Speakers: Eric Byres

Conference: S4

YouTube: https://www.youtube.com/watch?v=ZHQgJ23qZbE

Overview

In this insightful S4 talk, veteran cybersecurity expert Eric Byres addresses a fundamental challenge plaguing the understanding and defense against supply chain attacks: the lack of a comprehensive and meaningful taxonomy. Byres, reflecting on two decades of experience in the field, including early encounters with sophisticated threats like the Dragonfly attacks in 2014, highlights the critical need for a better way to define and classify these complex incidents. He argues that existing definitions, such as the one from CISA, are often too narrow, failing to encompass the full spectrum of observed attacks and hindering effective communication and defense strategies.

Byres' primary objective is to introduce a more inclusive and actionable taxonomy that accurately groups and classifies supply chain attacks based on their characteristics. This endeavor is crucial for security professionals to communicate effectively about specific attack types, understand their underlying mechanisms, and subsequently design more robust and targeted defensive controls. The talk underscores that without a clear and shared understanding of what constitutes a supply chain attack, efforts to mitigate them will remain fragmented and inefficient, leaving organizations vulnerable to increasingly sophisticated adversaries.

Background

▶ Watch: Problem with narrow supply chain attack definitions (2:00)

Eric Byres' journey into the complexities of supply chain security dates back over a decade, with a significant turning point in 2014 when he became aware of the Dragonfly attacks. These sophisticated operations, attributed to a Russian intelligence agency (possibly GRU), aimed to infiltrate the plant floors of pharmaceutical and energy companies in Europe by injecting malware into software. At the time, Byres was involved in firewall research with the Tafino firewall, but he quickly realized that traditional network defenses were inadequate against this emerging threat vector. This realization prompted him to pivot his focus, collaborating with figures like Billy Rios, Jonathan Butts, and Doug Ma at DHS to explore defenses against Operational Technology (OT) supply chain attacks.

Over the past decade, significant progress has been made, particularly with the development of the Software Bill of Materials (SBOM), which Byres acknowledges as a "phenomenal development" for communicating supply chain information. However, he identifies a more foundational problem: the inconsistent and often overly narrow definitions of what constitutes a supply chain attack. He cites the CISA definition, which states an attack occurs "when a threat actor penetrates the network of a software supplier and injects malicious code," as a prime example. While this definition aptly describes incidents like SolarWinds, it falls short for others, such as the Wizera attacks perpetrated by North Korea or attacks targeting open-source projects, where a supplier's network might not be directly involved. Such narrow definitions, Byres notes, have led to academic and industry papers, like one from ISA, excluding legitimate supply chain attacks because they didn't fit prescribed criteria.

This intellectual vacuum underscores the urgent need for an inclusive and meaningful taxonomy. Byres reviewed over a dozen papers, articles, and standards that either hinted at or explicitly laid out taxonomies. He critiqued the implied taxonomy within the MITRE ATT&CK framework, which broadly categorizes supply chain attacks into compromises of dependencies, software, and hardware. Byres found this too shallow and "fuzzy" on the distinction between dependencies and software. Conversely, he praised the paper "Taxonomy of Attacks on Open Source Software Supply Chains" by Landissa and colleagues, which meticulously defined 107 different forms of attack. However, its limitation was its singular focus on the open-source developer segment of the supply chain. Byres' work aims to synthesize the best aspects of these efforts into a broader, more universally applicable framework.

Key Findings

▶ Watch: Criteria for an effective, meaningful supply chain taxonomy (3:30)

The central finding of Eric Byres' research is the proposal of a new, more inclusive, and meaningful taxonomy for supply chain incidents, built upon a fundamental division of the supply chain into two distinct phases: creation and delivery/distribution. This two-phase model provides a robust top-level categorization that addresses the shortcomings of existing definitions and taxonomies.

Byres observed that regardless of the specific supply chain definition, they consistently divided the process into these two overarching stages: "creation and delivery" or "production and distribution." He argues that attacks naturally align with these phases:

  1. Attacks against the software creation system: These target the development, manufacturing, or build environment of software. The goal is to inject malicious code or compromise integrity at the source.
  2. Attacks against the software delivery system: These focus on the distribution channels, mechanisms, or processes used to get software to the end-user after it has been created. The objective here is to tamper with or substitute legitimate software during transit or deployment.

This distinction is critical because it allows for a clearer understanding of the attacker's objective and the specific vulnerabilities exploited. For instance, SolarWinds is a quintessential example of an attack targeting the creation phase, where malicious code was injected directly into the software manufacturing system before distribution. In contrast, Stuxnet, while highly sophisticated, involved the theft of code signing keys to facilitate the delivery of malware, circumventing trust mechanisms during distribution rather than altering the core software production.

By adopting this meaningful top-level classification, Byres aims to facilitate better communication among security professionals, enable more precise description of controls, and ultimately lead to more effective defensive strategies tailored to the specific phase of the supply chain being targeted. The taxonomy is designed to be comprehensive, drawing from and improving upon existing frameworks while avoiding the pitfalls of narrow or "dumb" classifications that do not genuinely aid in understanding or defense.

Technical Deep Dive

▶ Watch: Critique of existing MITRE and Landissa taxonomies (4:30)

Byres' proposed taxonomy hinges on the fundamental division of the software supply chain into creation and delivery phases, a distinction he found common across "hundreds of definitions" of a supply chain. This bifurcation provides a meaningful top-level classification criterion, addressing the limitations of prior approaches.

To elaborate, the creation phase encompasses all activities related to the design, development, coding, testing, and building of software. This includes source code management, build servers, developer workstations, and integrated development environments (IDEs). An attack targeting the creation system seeks to compromise the integrity of the software before it is finalized for distribution. The SolarWinds incident serves as a prime example: attackers gained access to SolarWinds' software build environment and injected malicious code into legitimate updates for the Orion platform. This meant that customers received digitally signed, seemingly legitimate software that already contained a backdoor, demonstrating a compromise at the very heart of the software manufacturing process.

Conversely, the delivery phase encompasses all processes involved in packaging, signing, distributing, and deploying the software to its end-users. This includes package repositories, update servers, content delivery networks (CDNs), and the mechanisms for installing or updating software on target systems. Attacks on the delivery system aim to intercept, tamper with, or substitute legitimate software as it moves from the producer to the consumer. Byres cites Stuxnet as an example, where the attackers' primary supply chain exploit involved stealing code signing keys. While Stuxnet's development was complex, the critical supply chain attack vector was the use of stolen digital certificates to sign malicious drivers, allowing them to appear legitimate during the distribution and installation on target systems, thereby circumventing trust mechanisms in the delivery phase. The Wizera attacks against cryptocurrency users, which involved distributing malicious software through compromised websites or social engineering, also align with delivery-phase compromises, focusing on getting malicious payloads to users rather than injecting them into the upstream creation process.

Byres' critique of existing taxonomies further underscores the technical necessity of his approach. The MITRE ATT&CK framework, for example, classifies supply chain attacks into three categories: "compromise dependencies," "compromise software," and "compromise hardware." Byres finds this "not deep enough" and "too narrow," particularly noting the "fuzzy" distinction between "dependencies" and "software." From a technical standpoint, a dependency is a form of software, and compromising it often leads to a compromise of the overall software product. MITRE's categories, while useful for mapping TTPs, do not provide the clear, actionable distinction necessary for designing phase-specific defenses.

In contrast, the "Taxonomy of Attacks on Open Source Software Supply Chains" by Landissa and colleagues, which identified 107 distinct attack types, is acknowledged as "outstanding" in its detail. However, its limitation is its specific scope, focusing exclusively on the open-source developer ecosystem. Byres' goal is to build upon such detailed work by providing a higher-level, more generalized framework that can then incorporate the granular insights from specialized taxonomies like Landissa's for specific segments (e.g., open-source attacks would fall under the "creation" phase, or possibly the "delivery" phase if targeting package managers).

The criteria for an effective taxonomy, as outlined by Byres, are:

  1. Group and classify attacks by characteristics: This allows for logical organization and identification of commonalities.
  2. Facilitate communication: A shared vocabulary helps professionals discuss and understand attacks clearly.
  3. Describe controls and defenses: The classification should directly inform how defenses are designed and implemented.
  4. Be meaningful: The distinctions made must have practical significance for understanding and mitigating threats, avoiding "dumb classifications" like grouping "Attila the Hun and Winnie the Poo" by their middle name.

By dividing attacks into creation and delivery, Byres provides a meaningful, high-level framework that directly impacts defensive strategies. Attacks on the creation phase demand robust Secure Software Development Lifecycle (SSDLC) practices, code integrity checks, build environment hardening, and developer security training. Attacks on the delivery phase necessitate strong code signing policies, secure update mechanisms, supply chain integrity verification (e.g., using SBOMs and cryptographic attestations), and secure distribution channels. This technical distinction allows for a more granular and effective allocation of security resources and implementation of controls.

Demo / Proof of Concept

▶ Watch: Deriving top-level categories: Creation and Delivery (7:00)

The provided transcript does not describe any specific demonstration or proof of concept undertaken or presented by Eric Byres during his talk. His presentation focused on the conceptual framework of the supply chain incident taxonomy and its theoretical underpinnings.

Defensive Implications

Eric Byres' proposed taxonomy, by clearly distinguishing between attacks on the creation system and the delivery system, offers profound defensive implications for organizations across all sectors, particularly in OT environments. This refined classification moves beyond ambiguous definitions to enable more targeted and effective cybersecurity strategies.

Firstly, a clear understanding of whether an attack targets the software's creation or its delivery allows defenders to allocate resources more efficiently. For creation-phase attacks, organizations must prioritize hardening their Secure Software Development Lifecycle (SSDLC). This includes implementing rigorous code review processes, utilizing static and dynamic application security testing (SAST/DAST), securing build pipelines, enforcing multi-factor authentication for developer accounts, and segmenting development environments. Tools that monitor source code repositories for unauthorized changes, verify build integrity, and track developer activity become paramount. The goal is to detect and prevent malicious code injection or tampering at the earliest possible stage, before the software is even released.

For delivery-phase attacks, the focus shifts to ensuring the integrity and authenticity of software as it moves from the producer to the consumer. This necessitates robust code signing practices, including secure management of private keys and regular audits of certificate usage. Organizations should implement strong supply chain integrity verification mechanisms, leveraging Software Bill of Materials (SBOMs) to identify and track components, and using cryptographic attestations to verify the origin and integrity of software packages. Secure update mechanisms, protected distribution channels, and endpoint security solutions capable of validating software integrity upon installation are also critical. Furthermore, proactive monitoring of public repositories for typosquatting or dependency confusion attacks, which exploit the delivery mechanism, becomes essential.

The taxonomy also improves communication among security teams, vendors, and regulators. When discussing an incident, classifying it as a "creation-phase compromise via compromised build server" versus a "delivery-phase compromise via stolen code signing key" provides immediate clarity on the attack vector and the required response. This precise language facilitates better incident response planning, clearer reporting, and more effective collaboration across the supply chain. It helps organizations describe their controls more accurately, aligning specific security measures with the phase of the supply chain they are designed to protect. For instance, an organization can clearly state it has controls in place for "secure software creation" (e.g., developer training, secure coding standards) and "secure software delivery" (e.g., signed packages, SBOM verification).

Ultimately, this meaningful taxonomy empowers defenders to move from a reactive, broad-strokes approach to a proactive, surgical defense posture. By understanding the specific "where" and "how" of a supply chain attack within the creation or delivery continuum, organizations can build resilience, reduce their attack surface, and protect critical assets more effectively against sophisticated adversaries.

Key Takeaways

  • Existing definitions of supply chain attacks are often too narrow, hindering effective communication and defense (e.g., CISA's definition not covering open-source or Wizera attacks).
  • A meaningful taxonomy is crucial for classifying attacks, facilitating communication, and designing appropriate defensive controls.
  • The supply chain can be fundamentally divided into two phases: creation and delivery/distribution, which serves as a robust top-level classification for attacks.
  • Creation-phase attacks target the development and manufacturing environment (e.g., SolarWinds), requiring strong SSDLC and build integrity controls.
  • Delivery-phase attacks target the distribution channels and mechanisms (e.g., Stuxnet's code signing key theft), necessitating robust code signing, SBOM verification, and secure update processes.
  • This new taxonomy enables targeted defensive strategies, allowing organizations to allocate resources and implement specific controls more effectively based on the attack's phase.

About the Speaker(s)

Eric Byres is a highly experienced and respected figure in the cybersecurity community, with a career spanning over two decades, particularly in the realm of industrial control systems (ICS) and operational technology (OT) security. He has been a long-time participant at S4, noting his first appearance on stage 20 years prior. Byres' concern for supply chain attacks against OT environments intensified over a decade ago, notably after becoming aware of the Dragonfly attacks in 2014, which targeted critical infrastructure. This experience led him to shift his professional focus, moving from his work with the Tafino firewall to collaborate with experts like Billy Rios, Jonathan Butts, and Doug Ma at DHS on addressing OT supply chain threats. He has been deeply involved in advancing supply chain security, acknowledging the significant progress made with initiatives like the Software Bill of Materials (SBOM), and recognizing the contributions of individuals such as Dr. Alan Friedman, Josh Corman, and JC Hutz. His talk at S4 underscores his continued dedication to establishing foundational frameworks that improve the industry's ability to understand and defend against complex cyber threats.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Byres' S4 talk presents a much-needed, novel taxonomy for supply chain incidents, fundamentally dividing attacks into "creation" and "delivery" phases. This framework addresses the critical shortcomings of overly narrow existing definitions, enabling security professionals to better classify, communicate about, and defend against these complex threats. His deep experience and thorough research provide a robust, actionable model that significantly advances the industry's understanding and defensive posture against supply chain compromises like SolarWinds and Stuxnet.

Heather Calloway (CISO) — STRONG ACCEPT

Eric Byres' S4 talk on a supply chain incident taxonomy offers a clear, actionable framework that addresses a critical gap in our collective understanding and defense. His fundamental division of supply chain attacks into 'creation' and 'delivery' phases is not just an academic exercise; it's a meaningful distinction that directly informs governance, risk ownership, and the design of targeted security controls. This work moves beyond generic definitions to provide the clarity necessary for security leaders to make informed decisions and allocate resources effectively.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference