There’s no question that software supply chain attacks are increasing and even the largest enterprises are under siege.
By one estimate, there has been a 742% average annual increase in software supply chain attacks. And consulting firm Gartner predicts that by 2025, 45% of organizations will have experienced such an attack.
Yet even as they are aware of the growing problem, many organizations — including Fortune 500 companies IBM, Cisco, Siemens and Alibaba — have had a massive software supply chain security exposure, putting them and their customers at risk, according to a new research from Aqua Nautilus.
Conducted from an attacker’s perspective, the investigation by cybersecurity company Aqua Security’s research team discovered 250 million artifacts and 65,600 container images that were exposed through misconfigured registries and artifact repositories.
“Today's typical software development lifecycle, even for a small company, is quite complex, with multiple tools and pipelines,” said Weinberger, staff software engineer at Aqua Security. “Threat actors only need to find a single weak point to achieve a major impact.”
SDLC, registries, repositories explainedThe software development life cycle (SDLC) automates the process of building, testing and deploying software, said Assaf Morag, Aqua Security’s lead threat intelligence and data analyst. Once code is written, built, tested and validated, it is deployed to production or stored in container image or artifact registries for future use.
A registry is a central location for storing and managing packages, and a repository is a specific collection of packages within a registry. An artifact management system, meanwhile, is a type of registry for managing binary files.
All three are critical to the software supply chain, Morag said — and therefore a prime target for threat actors because they contain highly confidential and sensitive proprietary code, secrets, IP and personally identifiable information (PII).
“They sit on a very important junction in the software development life cycle,” he said. “They are part of the pipeline.”
Critical misconfigurations, easily accessible keys and upload permissionsMorag explained that Aqua Nautilus continuously keeps track of misconfigurations in the cloud, including Docker APIs, k8s API servers and registries. In this instance, the team went a step further to identify organizations behind these misconfigured servers, how exactly they were exposed and how those exposures could be rectified.
Notably, they discovered the following:
- Sensitive keys — including secrets, credentials or tokens — on 1,400 distinct hosts, and private sensitive addresses of end points on 156 hosts.
- 57 registries with critical misconfigurations; 15 of which allowed admin access with the default password.
- 2,100 artifact registries with upload permissions, which may allow an attacker to “poison” the registry with malicious code.
For instance, the team found one organization with an exposed artifact management system containing an AWS admin token. As Morag explained, “an attacker can wreak havoc with an admin AWS key.”
Another misconfiguration belonged to a bank. A hypothetical attacker could have found the payment application, downloaded the container, tweaked the code and modified it to divert a fraction of any transaction to their bank account, Morag said.
Following this investigation, the Aqua Nautilus team reported findings through designated channels and found that many security teams were “eager” to learn from their discoveries, take immediate corrective action and seek out long-term solutions.
“However,” Morag and Weinberger wrote in a blog post outlining the findings, “we were surprised that some major corporations ignored our warnings, which put both their businesses and customers at significant risk.”
Software supply chain attacks increasingOrganizations have difficulty recognizing and identifying all the means of exploitation because the contemporary software supply chain consists of multiple components that go into developing an application — including people, processes, dependencies and tools, said Katie Norton, senior research analyst at market intelligence firm IDC.
In particular, to create digital products and services, large organizations can have tens of thousands of developers, hundreds of applications teams and upwards of 15 tools in their toolchains — oftentimes all from different vendors, she pointed out.
“All an attacker needs is one misconfiguration or one hardcoded secret or one developer's credentials to infiltrate a supply chain,” said Norton.
If secrets are inadvertently embedded in code and exposed, attackers have the “keys to the software factory” and the ability to move laterally, she explained. Bad actors can use those keys to shut down services, steal intellectual property or upload malware.
“Every organization building software is now a target for a software supply chain attack, and needs to be diligent to avoid being the next victim of a high-profile security breach,” she said.
Ignorance, human error, shadow IT main culpritsThere are many reasons container images are exposed, Morag said, but the three main categories are lack of knowledge, proper training, guidelines and work procedures; human error; and shadow IT.
To the first point, an employee might download a configuration file from the internet without understanding it and accidently expose the organization. In terms of human error, there are many scenarios: Say an organization has an open-source container image registry that should only contain open-source content, but someone might accidentally upload the organization’s secrets, sensitive data, IP or proprietary content.
Shadow IT, meanwhile, is unauthorized use of services and devices. In this sense, imagine that an employee creates a test server and accidentally connects it to the internet, he said. Because it’s shadow IT, the security controls often used to secure other virtual assets are not used.
“What is unique about container and artifact registries compared to other targets is their strategic position between the developers and the runtime environment,” Weinberger explained. “Threat actors can target both directions, which can result in a significant impact.”
Education, holistic measures critical to fighting supply chain attacksThe good news is that organizations are beginning to acknowledge the threat an insecure software supply chain presents, Norton said. For instance, IDC has predicted that securing the software supply chain will be embraced as a core competency by 75% of large digital innovators by 2023.
Norton pointed out that Aqua Nautilus’ research is helpful because it provides tangible examples and remediation advice. Organizations should also look to research, guidelines and best practices emerging from the community — such as the Supply Chain Levels for Software Artifacts (SLSA) security framework, the National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF) or the Open Software Supply Chain Attack Reference (OSC&R).
The marketplace of tools is also growing rapidly, Norton said, and IDC is increasingly seeing DevOps, DevSecOps and cloud-native application security vendors adding capabilities in the area. There are also an “unbelievable amount” of startups emerging with innovative solutions.
Ultimately, Norton emphasized, “organizations need to examine their software supply chain to have a clearer picture of frisk and how best to mitigate it.”
While this can be tricky due to so many sources and digital components, “the software supply chain should be viewed holistically because focusing on only one dimension is inadequate,” she said.
Comments