공급망 공격이란?

공급망 공격은 조직과 외부 당사자 간의 신뢰 관계를 악용하도록 설계되었습니다. 이러한 관계에는 파트너십, 공급업체 관계 또는 타사 소프트웨어 사용이 포함될 수 있습니다. 사이버 위협 행위자는 한 조직을 손상시킨 다음 공급망 위로 이동하여 이러한 신뢰할 수 있는 관계를 활용하여 다른 조직의 환경에 액세스할 수 있습니다.

공격을 막으시겠습니까? 사이버 보안 보고서

공급망 공격이란?

급증하는 공급망 공격

Given the outsized impact they can have, it is unsurprising that supply chain attacks have dramatically increased in recent years. Data shows that from 2021 to 2023, supply chain attacks grew by 431%.

  • More recent data from Check Point’s State of Cyber Security 2025 report found hardware and software supply chains experienced the highest surge of attacks in 2024.
  • The report found that the average number of attacks targeting software, hardware, and semiconductor companies increased by 179%.

Experts state this is due to the increased global demand for hardware and the focus on AI technologies. As a vital component of modern infrastructure and innovations, the technological supply chain is becoming a significant target for cyber criminals.

Exploiting supply chain vulnerabilities in these sectors provides many opportunities for:

  • Financial gain
  • Espionage
  • Disruption

High-Profile Supply Chain Incidents

원격 근무와 과중한 보안 팀으로 인해 생성된 새로운 공격 벡터로 인해 사이버 범죄자는 공급망 공격을 수행할 수 있는 많은 기회를 갖게 되었습니다. 최근 몇 년 동안 가장 큰 것 중 일부는 다음과 같습니다.

  • SolarWinds: 2020년에 해킹 그룹이 SolarWinds의 프로덕션 환경에 액세스하여 Orion 네트워크 모니터링 제품 업데이트에 백도어를 내장했습니다. 악성 업데이트를 실행하는 SolarWinds 고객은 데이터 침해 및 기타 보안 사고를 겪었습니다.
  • 카세야: REvil 랜섬웨어 갱단은 MSP(Managed Services Provider)용 소프트웨어를 제공하는 소프트웨어 회사인 Kaseya를 악용하여 1,000명 이상의 고객을 랜섬웨어로 감염시켰습니다.  이 그룹은 영향을 받는 모든 고객에게 암호 해독 키를 제공하기 위해 7천만 달러의 몸값을 요구했습니다. 
  • 코덱 : Codecov는 Bash 업로더 스크립트(회사에 코드 커버리지 보고서를 보내는 데 사용됨)가 공격자에 의해 수정된 소프트웨어 테스트 조직입니다. 이 공급망 익스플로잇을 통해 공격자는 소스 코드, 비밀 등과 같은 민감한 정보를 CodeCov 고객의 자체 서버로 리디렉션할 수 있었습니다.
  • 낫페트야: NotPetya는 컴퓨터를 암호화했지만 암호 해독을 위한 비밀 키를 저장하지 않은 가짜 랜섬웨어 멀웨어였습니다. 그것을 "와이퍼"로 바꾸는 것이라고합니다.
    • 낫페트야(NotPetya) 공격은 우크라이나 회계법인이 해킹을 당하고 멀웨어가 악성 업데이트에 포함되면서 공급망 공격으로 시작됐다.
  • 아틀라시안: 2020년 11월, Check Point Research(CPR) 는 결합될 때 SSO를 통해 연결된 계정과 다양한 Atlassian 앱을 제어하는 데 악용될 수 있는 일련의 취약점을 발견했습니다.
    • 이 취약점을 잠재적인 공급망 공격으로 만드는 이유는 공격자가 이러한 결함을 악용하고 계정을 제어하면 나중에 활용할 수 있는 백도어를 설치할 수 있기 때문입니다.
    • 이로 인해 심각한 피해가 발생할 수 있으며 손상이 발생한 후에만 감지되고 제어됩니다.
    • Check Point Research는이 정보를 Atlassian 팀에 책임감 있게 공개했으며, 사용자가 다양한 플랫폼에서 정보를 계속 안전하게 공유 할 수 있도록 솔루션을 배포했습니다
  • 영국항공: 2018년 영국항공은 Magecart 공격을 받아 항공사 웹사이트에서 380,000건 이상의 거래가 중단되었습니다. 이 공격은 공급망 공격으로 인해 항공사 공급업체 중 하나가 손상되고 British Airways, Ticketmaster 및 기타 회사로 확산되었습니다.
  • Linux XZ

    Discovered in 2024, the Linux XZ supply chain attack was a multi-year operation to insert a backdoor into the open-source project. XZ utilities are regularly used for compression in Linux.

    The backdoor enabled remote code execution to attackers with a specific key.

    The compromised version of XZ utilities was not widely deployed when the vulnerability was discovered. But, it was present in development versions. Experts stated that if undetected, the Linux XZ backdoor could have given the attackers access to hundreds of millions of systems around the world.

공급망 공격의 작동 방식

공급망 공격은 서로 다른 조직 간의 신뢰 관계를 이용합니다. 모든 조직은 네트워크 내에서 회사의 소프트웨어를 설치 및 사용하거나 공급업체로 협력할 때 다른 회사에 대한 암묵적인 신뢰 수준을 가지고 있습니다.

공급망 공격은 신뢰 체인에서 가장 취약한 링크를 대상으로 합니다. 한 조직에 강력한 사이버 보안이 있지만 안전하지 않은 신뢰할 수 있는 공급업체가 있는 경우 공격자는 해당 공급업체를 표적으로 삼습니다. 벤더의 네트워크에 발판을 마련한 공격자는 신뢰할 수 있는 관계를 사용하여 보다 안전한 네트워크로 전환할 수 있습니다.

공급망 공격 대상의 일반적인 유형 중 하나는 관리형 서비스 제공업체(MSP)입니다. MSP는 고객의 네트워크에 심층적으로 액세스할 수 있으며, 이는 공격자에게 매우 중요합니다. 공격자는 클라우드 관리 서비스(MSP)를 악용한 후 고객 네트워크로 쉽게 확장할 수 있습니다. 이러한 공격자는 공급망 취약성을 악용하여 더 큰 영향을 미치고 직접 공격하기 훨씬 더 어려운 네트워크에 액세스할 수 있습니다. 이것이 Kaseya 공격자가 랜섬웨어로 많은 조직을 감염시킨 방법입니다.

 

다른 공급망 공격은 소프트웨어를 사용하여 조직의 고객에게 멀웨어를 제공합니다.  예를 들어, SolarWinds 공격자는 회사의 빌드 서버에 대한 액세스 권한을 얻고 SolarWinds Orion 네트워크 모니터링 제품에 대한 업데이트에 백도어를 주입했습니다.  이 업데이트 코드가 고객에게 푸시되었을 때 공격자는 네트워크에도 액세스할 수 있었습니다.

공급망 공격의 영향

공급망 공격은 공격자에게 조직의 방어를 뚫을 수 있는 또 다른 방법을 제공할 뿐입니다. 다음과 같은 모든 유형의 사이버 공격을 수행하는 데 사용할 수 있습니다.

  • 데이터 유출: 공급망 공격은 일반적으로 데이터 침해를 수행하는 데 사용됩니다. 예를 들어, SolarWinds 해킹은 여러 공공 및 민간 부문 조직의 민감한 데이터를 노출시켰습니다.
  • 멀웨어 감염: 사이버 범죄자들은 종종 공급망 취약성을 악용하여 대상 조직에 멀웨어를 전달합니다. SolarWinds에는 악성 백도어 전달이 포함되었으며, Kaseya 공격은 이를 악용하도록 설계된 랜섬웨어로 이어졌습니다.

What Makes Supply Chain Attacks Dangerous

Supply chain attacks are a significant concern because they don’t target your systems directly, but rather exploit your trust in others. Whenever you install and use a vendor’s software or add a third-party dependency to your own code, you’re implicitly placing your trust in that vendor’s security.

This exposes you to any mistakes that might be made by external organizations and developers.

For instance, you assume they didn’t accidentally introduce vulnerabilities to their software and regularly update their code to patch out new exploits as they are discovered.

This is a particular concern for open-source dependencies…

Open-Source Software

Relying on unpaid developers to continually update their open-source projects and respond to new threats can be a major supply chain weakness.

Supply chain attacks aren’t trying to exploit the strongest link in the chain, they target the weakest. Therefore, you can be left exposed even if you develop extensive internal security controls to protect your systems without proper third-party risk management strategies.

Supply Chain Breach & Backdoor

Plus, once hackers have a supply chain breach and add a backdoor to a piece of software that is widely used, they can launch far-reaching attacks with many victims. Cybercriminals can get a much larger return on investment by compromising third-party code.

Rather than attacking an organization head-on and getting one victim, they can go after the software supply chain and get many more victims from a single vulnerability.

This attracts some of the most sophisticated hackers and groups to find supply chain attack vectors.

How to Prevent Supply Chain Attacks

While these attacks are hard to detect and remediate, there are best practices for supply chain cybersecurity that you can implement to limit their impact. These processes can be broken down into third-party risk management approaches that improve your supply chain resilience, and internal practices that limit the impact of compromised systems.

Third-Party Risk Management

Assessing vendor security standards and managing the risk of using external software and dependencies is a critical aspect of supply chain cybersecurity. You need to rigorously assess your vendors and determine the security of their development practices.

Performing third-party risk assessments allows you to identify specific security policies you want vendors to implement to work with you.

Plus, you can group vendors based on the risk they pose (their internal security practices and how much access they have to your sensitive business data). Then, prioritize monitoring each vendor based on their vulnerability level. This includes:

  • Identifying all open source dependencies
  • Ensuring they remain active projects that still push updates based on the latest threats.

Beyond open source projects, patch management is a vital aspect across supply chain cybersecurity.

You have to maintain the latest software versions to ensure the window of risk posed by new vulnerabilities is as small as possible.

공급망 공격 식별 및 완화를 위한 모범 사례

공급망 공격은 회사와 다른 조직 간의 안전하지 않은 신뢰 관계를 이용합니다. 이러한 공격의 위험을 완화하는 몇 가지 방법은 다음과 같습니다.

  • 최소 권한 구현: 많은 조직에서는 직원, 파트너 및 소프트웨어에 과도한 액세스 및 사용 권한을 할당합니다. 이러한 과도한 권한으로 인해 공급망 공격을 더 쉽게 수행할 수 있습니다. 최소 권한을 구현하고 모든 사용자와 소프트웨어에 작업을 수행하는 데 필요한 권한만 할당합니다.
  • 네트워크 세그멘테이션 수행: 타사 소프트웨어 및 파트너 조직은 네트워크의 모든 구석에 대한 무제한 액세스가 필요하지 않습니다. 네트워크 세그멘테이션을 사용하여 비즈니스 기능에 따라 네트워크를 영역으로 나눕니다. 이렇게 하면 공급망 공격으로 네트워크의 일부가 손상되더라도 네트워크의 나머지 부분은 계속 보호됩니다.
  • DevSecOps 사례 준수: 보안을 개발 수명 주기에 통합하면 Orion 업데이트와 같은 소프트웨어가 악의적으로 수정되었는지 여부를 감지할 수 있습니다.
  • 자동화된 위협 차단 및 위협 헌팅: SOC(보안 운영 센터) 분석가는 엔드포인트, 네트워크, 클라우드 및 모바일을 포함한 조직의 모든 환경에서 공격으로부터 보호해야 합니다.

Minimizing the Impact of a Supply Chain Breach

To minimize third-party supply chain risks, you need to reduce the access these systems have within your network. This includes introducing zero trust practices based on least privilege access. This makes applications and users continually verify their identity while only providing access to the systems they need, nothing more.

Another Zero Trust Network Access (ZTNA) technique is network segmentation, which divides your systems into siloed sections with strong security controls when moving between them.

ZTNA reduces the impact of supply chain breaches by preventing lateral movement.

The attacker only has access to the initial compromised system and struggles to extend their access further. Other techniques to help prevent supply chain attacks include:

  • Following DevSecOps best practices to test for vulnerabilities in any dependencies you use. You can improve software development visibility through a Software Bill of Materials (SBOM) that tracks details (source, version, etc.) of every dependency.
  • Regularly scanning your system with malware prevention tools to prevent attacks from executing.
  • Develop incident response plans that include considerations for supply chain attacks. This could implement sandboxing new code before executing it to mitigate any backdoors.
  • Track all of the applications and services employees use and uncover any shadow IT (unsanctioned applications) to ensure your supply chain attack surface is not larger than you realise.

체크 포인트로 공급망 공격으로부터 보호

Supply chain attackers take advantage of a lack of monitoring within an organization’s environment. Check Point Check Point Endpoint Security helps an organization to protect against these threats by monitoring applications for suspicious behavior that might point to compromise.

 

To learn more about the types of attacks that Check Point Endpoint Security protects against, check out Check Point’s 2021 Cyber Security Report. Then, take a security checkup to learn about the security issues within your environment. You can also learn how to close these security gaps with a free demo.