サプライチェーン攻撃とは?
サプライチェーン攻撃は、組織と外部関係者の間の信頼関係を悪用するように設計されています。 これらの関係には、パートナーシップ、ベンダーとの関係、またはサードパーティソフトウェアの使用が含まれる場合があります。 サイバー脅威アクターは、ある組織を侵害し、サプライチェーンを上流し、これらの信頼関係を利用して他の組織の環境にアクセスします。
サプライチェーン攻撃が急増
Given the outsized impact they can have, it is unsurprising that supply chain attacks have dramatically increased in recent years. Data shows that from 2021 to 2023, supply chain attacks grew by 431%.
- More recent data from Check Point’s State of Cyber Security 2025 report found hardware and software supply chains experienced the highest surge of attacks in 2024.
- The report found that the average number of attacks targeting software, hardware, and semiconductor companies increased by 179%.
Experts state this is due to the increased global demand for hardware and the focus on AI technologies. As a vital component of modern infrastructure and innovations, the technological supply chain is becoming a significant target for cyber criminals.
Exploiting supply chain vulnerabilities in these sectors provides many opportunities for:
- Financial gain
- Espionage
- Disruption
High-Profile Supply Chain Incidents
リモートワークや圧倒的なセキュリティチームによって生み出された新たな攻撃ベクトルにより、サイバー犯罪者はサプライチェーン攻撃を実行する多くの機会を得ています。 近年の最大のものには、次のようなものがあります。
- SolarWinds: 2020年、ハッキンググループがSolarWindsの本番環境にアクセスし、ネットワーク監視製品Orionのアップデートにバックドアを埋め込みました。 悪意のあるアップデートを実行しているSolarWindsのお客様は、データ侵害やその他のセキュリティ インシデントに見舞われました。
- カセヤ: REvilランサムウェア集団は、マネージドサービスプロバイダー(MSP)にソフトウェアを提供するソフトウェア会社であるKaseyaを悪用し、1,000人以上の顧客を ランサムウェアに感染させました。 このグループは、影響を受けたすべての顧客に復号化キーを提供するために、7,000万ドルの身代金を要求しました。
- Codecov: Codecovはソフトウェアテスト組織であり、そのBashアップローダースクリプト(コードカバレッジレポートを会社に送信するために使用される)が攻撃者によって変更されました。 このサプライチェーンのエクスプロイトにより、攻撃者はソースコードやシークレットなどの機密情報をCodeCovの顧客から自社のサーバーにリダイレクトすることができました。
- NotPetya: NotPetyaは、コンピューターを暗号化する偽のランサムウェアマルウェアでしたが、復号化のために秘密鍵を保存しませんでした。 それを「ワイパー」に変えるというものです。
- NotPetya攻撃は、ウクライナの会計事務所が侵害され、マルウェアが悪意のあるアップデートに含まれていたことから、サプライチェーン攻撃として始まりました。
- Atlassian: 2020 年 11 月、 チェックポイント リサーチ (CPR) は、SSO 経由で接続されているアカウントとさまざまなアトラシアン アプリを制御するために悪用される可能性のある一連の脆弱性を発見しました。
- この脆弱性がサプライチェーン攻撃の可能性があるのは、攻撃者がこれらの欠陥を悪用してアカウントを制御できると、将来利用できるバックドアをインストールできることです。
- これにより、損傷が発生した後にのみ検出および制御される重大な危害が生じる可能性があります。
- チェックポイント リサーチは責任を持ってこの情報をアトラシアン チームに開示し、ユーザーがさまざまなプラットフォームで安全に情報を共有し続けられるようにするためのソリューションを導入しました
- ブリティッシュエアウェイズ: 2018年、ブリティッシュ・エアウェイズ(British Airways)はMagecart攻撃を受け、同社のウェブサイトで38万件以上の取引が侵害されました。 この攻撃は、航空会社のベンダーの1つを侵害し、ブリティッシュ・エアウェイズ(British Airways)やチケットマスター(Ticketmaster)などの企業に広がったサプライチェーン攻撃によって可能になりました。
-
Linux XZ
Discovered in 2024, the Linux XZ supply chain attack was a multi-year operation to insert a backdoor into the open-source project. XZ utilities are regularly used for compression in Linux.
The backdoor enabled remote code execution to attackers with a specific key.
The compromised version of XZ utilities was not widely deployed when the vulnerability was discovered. But, it was present in development versions. Experts stated that if undetected, the Linux XZ backdoor could have given the attackers access to hundreds of millions of systems around the world.
サプライチェーン攻撃の仕組み
サプライチェーン攻撃は、異なる組織間の信頼関係を利用します。 すべての組織は、自社のネットワーク内に自社のソフトウェアをインストールして使用したり、ベンダーとして協力したりする際に、他社に対して一定の暗黙の信頼関係を築いています。
サプライチェーン攻撃は、信頼の連鎖の最も弱いリンクを標的にします。 ある組織が強力なサイバーセキュリティを持っていても、安全でない信頼できるベンダーを持っている場合、攻撃者はそのベンダーを標的にします。 ベンダーのネットワークに足場を築いた攻撃者は、その信頼関係を利用して、より安全なネットワークに軸足を移すことができます。
サプライチェーン攻撃の一般的な標的の1つは、マネージドサービスプロバイダー(MSP)です。 MSPは顧客のネットワークに深くアクセスでき、攻撃者にとって非常に貴重です。 MSPを悪用した後、攻撃者は顧客ネットワークに簡単に拡張できます。 サプライチェーンの脆弱性を悪用することで、これらの攻撃者はより大きな影響を与え、直接攻撃するのがはるかに難しいネットワークにアクセスできる可能性があります。 このようにして、Kaseyaの攻撃者は非常に多くの組織をランサムウェアに感染させることに成功しました。
その他のサプライチェーン攻撃では、ソフトウェアを使用して組織の顧客にマルウェアを配信します。 たとえば、SolarWindsの攻撃者は、同社のビルドサーバーにアクセスし、ネットワーク監視製品「SolarWinds Orion」のアップデートにバックドアを注入しました。 この更新コードが顧客にプッシュされると、攻撃者は顧客のネットワークにもアクセスできるようになりました。
サプライチェーン攻撃の影響
サプライチェーン攻撃は、攻撃者に組織の防御を突破する別の方法を提供するだけです。 これらは、次のようなあらゆる種類の サイバー攻撃を実行するために使用できます。
- データ侵害: サプライチェーン攻撃は、データ侵害を実行するために一般的に使用されます。 たとえば、SolarWindsのハッキングでは、複数の公的機関や民間部門の組織の機密データが流出しました。
- マルウェア感染: サイバー犯罪者は、サプライチェーンの脆弱性を悪用して、標的となる組織にマルウェアを配信することがよくあります。 SolarWindsには悪意のあるバックドアの配信が含まれており、Kaseyaの攻撃により、それらを悪用するように設計されたランサムウェアが発生しました。
What Makes Supply Chain Attacks Dangerous
Supply chain attacks are a significant concern because they don’t target your systems directly, but rather exploit your trust in others. Whenever you install and use a vendor’s software or add a third-party dependency to your own code, you’re implicitly placing your trust in that vendor’s security.
This exposes you to any mistakes that might be made by external organizations and developers.
For instance, you assume they didn’t accidentally introduce vulnerabilities to their software and regularly update their code to patch out new exploits as they are discovered.
This is a particular concern for open-source dependencies…
Open-Source Software
Relying on unpaid developers to continually update their open-source projects and respond to new threats can be a major supply chain weakness.
Supply chain attacks aren’t trying to exploit the strongest link in the chain, they target the weakest. Therefore, you can be left exposed even if you develop extensive internal security controls to protect your systems without proper third-party risk management strategies.
Supply Chain Breach & Backdoor
Plus, once hackers have a supply chain breach and add a backdoor to a piece of software that is widely used, they can launch far-reaching attacks with many victims. Cybercriminals can get a much larger return on investment by compromising third-party code.
Rather than attacking an organization head-on and getting one victim, they can go after the software supply chain and get many more victims from a single vulnerability.
This attracts some of the most sophisticated hackers and groups to find supply chain attack vectors.
How to Prevent Supply Chain Attacks
While these attacks are hard to detect and remediate, there are best practices for supply chain cybersecurity that you can implement to limit their impact. These processes can be broken down into third-party risk management approaches that improve your supply chain resilience, and internal practices that limit the impact of compromised systems.
Third-Party Risk Management
Assessing vendor security standards and managing the risk of using external software and dependencies is a critical aspect of supply chain cybersecurity. You need to rigorously assess your vendors and determine the security of their development practices.
Performing third-party risk assessments allows you to identify specific security policies you want vendors to implement to work with you.
Plus, you can group vendors based on the risk they pose (their internal security practices and how much access they have to your sensitive business data). Then, prioritize monitoring each vendor based on their vulnerability level. This includes:
- Identifying all open source dependencies
- Ensuring they remain active projects that still push updates based on the latest threats.
Beyond open source projects, patch management is a vital aspect across supply chain cybersecurity.
You have to maintain the latest software versions to ensure the window of risk posed by new vulnerabilities is as small as possible.
サプライチェーン攻撃を特定して軽減するためのベストプラクティス
サプライチェーン攻撃は、企業と他の組織との間の安全でない信頼関係を利用します。 これらの攻撃のリスクを軽減する方法には、次のようなものがあります。
- 最小特権を実装します。 多くの組織では、従業員、パートナー、ソフトウェアに過剰なアクセスとアクセス許可を割り当てています。 これらの過剰な権限により、サプライチェーン攻撃が実行されやすくなります。 最小限の特権を実装し、すべてのユーザーとソフトウェアに、ジョブの実行に必要なアクセス許可のみを割り当てます。
- ネットワーク セグメンテーションを実行します。 サードパーティのソフトウェアやパートナー組織は、ネットワークの隅々まで自由にアクセスする必要はありません。 ネットワーク セグメンテーションを使用して、ビジネス機能に基づいてネットワークをゾーンに分割します。 これにより、サプライチェーン攻撃によってネットワークの一部が危険にさらされた場合でも、ネットワークの残りの部分は保護されます。
- DevSecOps プラクティスに従う: セキュリティを開発ライフサイクルに統合することで、Orionアップデートなどのソフトウェアが悪意を持って変更されているかどうかを検出できます。
- 自動化された脅威対策と脅威ハンティング:セキュリティ オペレーション センター (SOC) のアナリストは、エンドポイント、ネットワーク、クラウド、モバイルなど、組織のすべての環境にわたって攻撃から保護する必要があります。
Minimizing the Impact of a Supply Chain Breach
To minimize third-party supply chain risks, you need to reduce the access these systems have within your network. This includes introducing zero trust practices based on least privilege access. This makes applications and users continually verify their identity while only providing access to the systems they need, nothing more.
Another Zero Trust Network Access (ZTNA) technique is network segmentation, which divides your systems into siloed sections with strong security controls when moving between them.
ZTNA reduces the impact of supply chain breaches by preventing lateral movement.
The attacker only has access to the initial compromised system and struggles to extend their access further. Other techniques to help prevent supply chain attacks include:
- Following DevSecOps best practices to test for vulnerabilities in any dependencies you use. You can improve software development visibility through a Software Bill of Materials (SBOM) that tracks details (source, version, etc.) of every dependency.
- Regularly scanning your system with malware prevention tools to prevent attacks from executing.
- Develop incident response plans that include considerations for supply chain attacks. This could implement sandboxing new code before executing it to mitigate any backdoors.
- Track all of the applications and services employees use and uncover any shadow IT (unsanctioned applications) to ensure your supply chain attack surface is not larger than you realise.
チェック・ポイントによるサプライチェーン攻撃からの保護
Supply chain attackers take advantage of a lack of monitoring within an organization’s environment. Check Point Check Point Endpoint Security helps an organization to protect against these threats by monitoring applications for suspicious behavior that might point to compromise.
To learn more about the types of attacks that Check Point Endpoint Security protects against, check out Check Point’s 2021 Cyber Security Report. Then, take a security checkup to learn about the security issues within your environment. You can also learn how to close these security gaps with a free demo.
