Skip to main navigation Skip to search Skip to main content

Beyond SolarWinds: The systemic risks of critical infrastructures, state of play, and future directions

  • Simone Raponi*
  • , Maurantonio Caprolu
  • , Roberto Di Pietro
  • *Corresponding author for this work

Research output: Contribution to journalConference articlepeer-review

Abstract

The just concluded 16th edition of the World Economic Forum's Global Risks Report has ranked Cybersecurity failure as a significant global threat. This awakening is not surprising, maybe even late, as witnessed by the reliance of large part of critical sectors on the cyber infrastructure during the undergoing pandemic, or like shown by the recent and devastating SolarWinds attacks, whose implications and aftermaths are still to be completely understood. In this paper, we provide several contributions towards the provisioning of a comprehensive, robust, and reliable framework for the cybersecurity of critical infrastructures. In particular, we first revise the scope and definition of critical infrastructures. Later, we expand the introduced concept to capture the modern deployment and operations of critical infrastructures, highlighting their interconnectedness and dependency with the software supply chain. Then, we show how the SolarWinds attack has exploited the defined model to perform one of the most devastating black hat operations ever seen. Finally, we also show some research directions to secure the software supply chain, calling for an approach that necessarily requires the interplay of sound theory, viable solutions, and legislation interventions.

Original languageEnglish
Pages (from-to)394-405
Number of pages12
JournalCEUR Workshop Proceedings
Volume2940
Publication statusPublished - 2021
Externally publishedYes
Event5th Italian Conference on Cybersecurity, ITASEC 2021 - Virtual, Online
Duration: 7 Apr 20219 Apr 2021

Keywords

  • Critical infrastructures security
  • Industrial control systems
  • SolarWinds attack
  • Supply chain

Fingerprint

Dive into the research topics of 'Beyond SolarWinds: The systemic risks of critical infrastructures, state of play, and future directions'. Together they form a unique fingerprint.

Cite this