Share this
The SolarWinds Orion Hack Explained
by Brett Daniel on Jan 11, 2021 1:41:01 PM
Graphic: The SolarWinds hack shook American businesses and federal agencies in December. We're unpacking the hack in this blog post.
Table of Contents
- What is the SolarWinds Hack?
- How did hackers get into SolarWinds?
- Who was affected by the SolarWinds hack?
- How can similar attacks be prevented?
- Conclusion: Trenton Systems' Team of Trust
The SolarWinds hack.
It’s raising questions that everyone wants answers to: how did it happen, who was affected, but perhaps most importantly, how can a similar attack be prevented going forward?
One thing is undeniable: the attack was devastating, and it will take major businesses and government agencies a while to fully recover. Many will need to rebuild their entire networks from the ground up.
Oh, yes, you read that correctly. Experts say that those affected will need to "burn their networks to the ground" to ensure that they're clean.
In the meantime, it's important to discuss prevention. There's no perfect preventative solution, and as the SolarWinds hack proved, hackers are continuing to devise more highly sophisticated ways to surreptitiously steal, manipulate, or delete your most sensitive data.
But that's not an excuse. There are discussions to be had.
For this blog post, we called upon two of our technology partner companies - Star Lab, a Wind River company, and NGD Systems - to help us unpack the hack and talk preventative measures from their perspectives.
Throughout, we'll provide some background on the hack by describing exactly what happened with SolarWinds, how the hack was able to occur, how and which major companies and government agencies were affected, and how cybersecure servers, hardware protections, and signing release packages securely can help prevent another SolarWinds-style hack.
What is the SolarWinds hack?
The SolarWinds hack was a software supply chain attack perpetrated against American software company SolarWinds, which develops and maintains network monitoring tools used by major businesses and government agencies.
The hack, believed to have been perpetrated by an outside nation state, exploited SolarWinds’ Orion® software updates. These updates were subsequently installed by many of SolarWinds’ Orion customers, which include Fortune 500 businesses and federal agencies.
In fact, the hack is believed to have affected more than 250 of those businesses and agencies.
Graphic: Hackers purportedly compromised SolarWinds' Orion software build via an already-compromised Microsoft Office 365 account. Backdoors were later distributed into user networks once tainted Orion updates were installed.
How did hackers get into SolarWinds?
According to a statement by SolarWinds, the hackers inserted malware into two Orion software updates, which were installed by customers in the spring of 2020.
But the hackers had already gained access to SolarWinds’ software development system in October of 2019, according to Security Week, likely through SolarWinds’ already-compromised Microsoft Office 365 account.
The hackers then spent months implementing botnet command-and-control protocols, and in March of 2020, began inserting trojans into the updates that customers would ultimately install.
Once installed, this malware, dubbed SUNBURST, distributed backdoors that communicate to third-party servers into customers’ systems, giving the hackers remote access to emails, confidential documents, and other sensitive information.
But here’s the worst part: neither SolarWinds nor its customers knew that any sort of breach had occurred until December of 2020, more than a year after the hackers initially gained access to SolarWinds’ build environment and nine months after the first poisoned update was released in March.
To both SolarWinds and its customers, the trojanized updates appeared to be just another run-of-the-mill software modification to the Orion software.
But how could this be?
Well, the malicious code was inserted into an Orion plug-in called SolarWinds.Orion.Core.BusinessLayer.dll, a typical library component found in Orion software updates.
This compromised plug-in was digitally signed by a seemingly valid but actually compromised SolarWinds certificate. In other words, it was able to masquerade, totally undetected, as a legitimate, trusted, SolarWinds-verified library file that, once executed, whether during an automatic update or manually by the user, would begin to wreak its havoc, the user unwitting all the while.
Even scarier is that the backdoor was designed to remain dormant for 14 days before retrieving and executing commands that include the ability to transfer files, execute files, profile the system, reboot the machine, and disable system services, according to cybersecurity company FireEye, which was also affected by the attack.
Who was affected by the SolarWinds hack?
According to numerous media sources, the following businesses and agencies have been affected by the hack:
Businesses
- Microsoft
- Intel
- NVIDIA
- Cisco
- Belkin
- VMware
- FireEye
Agencies
- The United States Department of Homeland Security
- The United States Treasury Department
- The United States Department of Defense
- The United States Department of Commerce
- The United States Department of State
- The United States Department of Energy
- The United States Nuclear Security Administration
The extent of the hack, the data accessed, modified, stolen, or deleted, and whether other major businesses and agencies were affected are still being investigated.
Graphic: Secure code signing to verify trusted software sources can help prevent a SolarWinds-style attack in the future.
How can similar attacks be prevented?
Going forward, secure code signing and hardware-based protections are two of many practices that could help prevent SolarWinds-style hacks.
Jonathan Kline, Chief Technical Officer at cybersecurity software company Star Lab, a Wind River company, and a Trenton Systems technology partner, stresses the importance of signing release packages securely but admits that there’s no one-size-fits-all solution.
One possible approach to securely signing software uses an offline approach combined with some form of hardware security module (HSM). Within this model, the software is developed and transferred to a staging area. In the staging area, the software is signed using a non-extractable key, presumably by a trusted individual within your organization. The software is then transferred back to the release or deployment environment.
This process could be made more secure by requiring the key stored within the HSM to use some kind of multi-factor authentication. This would then prevent someone who had access to the HSM from being able to sign their own packages. It doesn’t, however, directly prevent someone from modifying or injecting build artifacts into the development environment before they are transferred to the staging environment.
- Jonathan Kline
Securely signing release packages is not an easy undertaking, Kline says, but particularly in light of the SolarWinds breach, it remains an altogether security-crucial aspect of software development and software release, if the industry is to protect itself from another SolarWinds, that is.
Scott Shadley, Vice President of Marketing at NGD Systems, a manufacturer of state-of-the-art computational storage drives (CSDs) and also a Trenton Systems technology partner, explained how NGD's drives can protect your sensitive data.
Our CSDs actually leverage the security protocols of self-encrypting data. The benefit is, since we have an OS inside the drive, we can read, decrypt, work on, modify, encrypt, and store the data on the drive without any external access to it. There's no movement outside the device itself. We can then provide results and value from the raw encrypted and stored data on the drive to the user without risking any leak of data from the drive itself.
So, to put this into perspective, a stream of data, such as video from a drone, is stored in real-time on the device using an encryption key. The data is then analyzed by the local OS on the CSD from NGD Systems to identify the target of the video stream. The raw data is secure on the drive, but the image or results needed by the host to make value of that data is sent off the drive, encrypted. So, the raw data is 100-percent secure from the moment it's captured.
- Scott Shadley
Check out these other great resources for more preventative measures:
- How Malicious Software Updates Endanger Everyone
- The SolarWinds Sunburst Attack: How to Protect Yourself from 5th Generation Cyberattacks
- Detection Is Better Than Cure: Seeing and Preventing Supply Chain Attacks
Graphic: Trenton Systems partners with Star Lab, a Wind River company, and Futura Cyber to help protect its rugged servers and workstations from common software and hardware attacks.
Conclusion: Trenton Systems' Team of Trust
Trenton Systems partners with leading cybersecurity and secure data storage companies, like Star Lab, a Wind River company, FUTURA Cyber, and NGD Systems, that excel in both hardware and software security protections that help protect against malicious attackers. We also have our own cybersecurity protections in place, creating quite the expansive team trust for our customers.
Star Lab’s Titanium Security Suite boasts the most robust Linux operating-system hardening and security capabilities available on the market. Designed using a threat model that assumes an attacker has already gained root or administrative access to a system, the suite still maintains the integrity and confidentiality of critical applications, data, and configurations while also assuring field and operational success.
FUTURA Cyber’s drive security manager (DSM) for FIPS-140-2 self-encrypting drives (SEDs) helps businesses, agencies, and organizations centrally, efficiently, and securely manage and store cryptographic keys and policies to better protect data at rest.
NGD Systems' CSDs can process data internally, where data is encrypted, rather than having to unencrypt it and transfer the data across the bus, where it could be intercepted.
Furthermore, Trenton Systems is currently working toward obtaining its Cybersecurity Maturity Model Certification (CMMC) for the protection of controlled unclassified information (CUI) through the Office of the Under Secretary of Defense for Acquisition & Sustainment. We also take DFARS-compliance very seriously and are continuously managing our adherence, implementing new and innovative ways to protect your sensitive data, and mitigating the potential impact of supply chain attacks internally.
For more information about our cybersecurity practices and the measures we’re taking to help secure your data, feel free to reach out to us.
Share this
- High-performance computers (42)
- Military computers (38)
- Rugged computers (32)
- Cybersecurity (25)
- Industrial computers (25)
- Military servers (24)
- MIL-SPEC (20)
- Rugged servers (19)
- Press Release (17)
- Industrial servers (16)
- MIL-STD-810 (16)
- 5G Technology (14)
- Intel (13)
- Rack mount servers (12)
- processing (12)
- Computer hardware (11)
- Edge computing (11)
- Rugged workstations (11)
- Made in USA (10)
- Partnerships (9)
- Rugged computing (9)
- Sales, Marketing, and Business Development (9)
- Trenton Systems (9)
- networking (9)
- Peripheral Component Interconnect Express (PCIe) (7)
- Encryption (6)
- Federal Information Processing Standards (FIPS) (6)
- GPUs (6)
- IPU (6)
- Joint All-Domain Command and Control (JADC2) (6)
- Server motherboards (6)
- artificial intelligence (6)
- Computer stress tests (5)
- Cross domain solutions (5)
- Mission-critical servers (5)
- Rugged mini PCs (5)
- AI (4)
- BIOS (4)
- CPU (4)
- Defense (4)
- Military primes (4)
- Mission-critical systems (4)
- Platform Firmware Resilience (PFR) (4)
- Rugged blade servers (4)
- containerization (4)
- data protection (4)
- virtualization (4)
- Counterfeit electronic parts (3)
- DO-160 (3)
- Edge servers (3)
- Firmware (3)
- HPC (3)
- Just a Bunch of Disks (JBOD) (3)
- Leadership (3)
- Navy (3)
- O-RAN (3)
- RAID (3)
- RAM (3)
- Revision control (3)
- Ruggedization (3)
- SATCOM (3)
- Storage servers (3)
- Supply chain (3)
- Tactical Advanced Computer (TAC) (3)
- Wide-temp computers (3)
- computers made in the USA (3)
- data transfer (3)
- deep learning (3)
- embedded computers (3)
- embedded systems (3)
- firmware security (3)
- machine learning (3)
- Automatic test equipment (ATE) (2)
- C6ISR (2)
- COTS (2)
- COVID-19 (2)
- Compliance (2)
- Compute Express Link (CXL) (2)
- Computer networking (2)
- Controlled Unclassified Information (CUI) (2)
- DDR (2)
- DDR4 (2)
- DPU (2)
- Dual CPU motherboards (2)
- EW (2)
- I/O (2)
- Military standards (2)
- NVIDIA (2)
- NVMe SSDs (2)
- PCIe (2)
- PCIe 4.0 (2)
- PCIe 5.0 (2)
- RAN (2)
- SIGINT (2)
- SWaP-C (2)
- Software Guard Extensions (SGX) (2)
- Submarines (2)
- Supply chain security (2)
- TAA compliance (2)
- airborne (2)
- as9100d (2)
- chassis (2)
- data diode (2)
- end-to-end solution (2)
- hardware security (2)
- hardware virtualization (2)
- integrated combat system (2)
- manufacturing reps (2)
- memory (2)
- mission computers (2)
- private 5G (2)
- protection (2)
- secure by design (2)
- small form factor (2)
- software security (2)
- vRAN (2)
- zero trust (2)
- zero trust architecture (2)
- 3U BAM Server (1)
- 4G (1)
- 4U (1)
- 5G Frequencies (1)
- 5G Frequency Bands (1)
- AI/ML/DL (1)
- Access CDS (1)
- Aegis Combat System (1)
- Armed Forces (1)
- Asymmetric encryption (1)
- C-RAN (1)
- COMINT (1)
- CPUs (1)
- Cloud-based CDS (1)
- Coast Guard (1)
- Compliance testing (1)
- Computer life cycle (1)
- Containers (1)
- D-RAN (1)
- DART (1)
- DDR5 (1)
- DMEA (1)
- Data Center Modular Hardware System (DC-MHS) (1)
- Data Plane Development Kit (DPDK) (1)
- Defense Advanced Research Projects (DARP) (1)
- ELINT (1)
- EMI (1)
- EO/IR (1)
- Electromagnetic Interference (1)
- Electronic Warfare (EW) (1)
- FIPS 140-2 (1)
- FIPS 140-3 (1)
- Field Programmable Gate Array (FPGA) (1)
- Ground Control Stations (GCS) (1)
- Hardware-based CDS (1)
- Hybrid CDS (1)
- IES.5G (1)
- ION Mini PC (1)
- IP Ratings (1)
- IPMI (1)
- Industrial Internet of Things (IIoT) (1)
- Industry news (1)
- Integrated Base Defense (IBD) (1)
- LAN ports (1)
- LTE (1)
- Life cycle management (1)
- Lockheed Martin (1)
- MIL-S-901 (1)
- MIL-STD-167-1 (1)
- MIL-STD-461 (1)
- MIL-STD-464 (1)
- MOSA (1)
- Multi-Access Edge Computing (1)
- NASA (1)
- NIC (1)
- NIC Card (1)
- NVMe (1)
- O-RAN compliant (1)
- Oil and Gas (1)
- Open Compute Project (OCP) (1)
- OpenRAN (1)
- P4 (1)
- PCIe card (1)
- PCIe lane (1)
- PCIe slot (1)
- Precision timestamping (1)
- Product life cycle (1)
- ROM (1)
- Raytheon (1)
- Remotely piloted aircraft (RPA) (1)
- Rugged computing glossary (1)
- SEDs (1)
- SIM Card (1)
- Secure boot (1)
- Sensor Open Systems Architecture (SOSA) (1)
- Small form-factor pluggable (SFP) (1)
- Smart Edge (1)
- Smart NIC (1)
- SmartNIC (1)
- Software-based CDS (1)
- Symmetric encryption (1)
- System hardening (1)
- System hardening best practices (1)
- TME (1)
- Tech Partners (1)
- Total Memory Encryption (TME) (1)
- Transfer CDS (1)
- USB ports (1)
- VMEbus International Trade Association (VITA) (1)
- Vertical Lift Consortium (VLC) (1)
- Virtual machines (1)
- What are embedded systems? (1)
- Wired access backhaul (1)
- Wireless access backhaul (1)
- accredidation (1)
- aerospace (1)
- air gaps (1)
- airborne computers (1)
- asteroid (1)
- authentication (1)
- autonomous (1)
- certification (1)
- cognitive software-defined radios (CDRS) (1)
- command and control (C2) (1)
- communications (1)
- cores (1)
- custom (1)
- customer service (1)
- customer support (1)
- data linking (1)
- data recording (1)
- ethernet (1)
- full disk encryption (1)
- hardware monitoring (1)
- heat sink (1)
- hypervisor (1)
- in-house technical support (1)
- input (1)
- integrated edge solution (1)
- international business (1)
- licensed spectrum (1)
- liquid cooling (1)
- mCOTS (1)
- microelectronics (1)
- missile defense (1)
- mixed criticality (1)
- moving (1)
- multi-factor authentication (1)
- network slicing (1)
- neural networks (1)
- new headquarters (1)
- next generation interceptor (1)
- non-volatile memory (1)
- operating system (1)
- output (1)
- outsourced technical support (1)
- post-boot (1)
- pre-boot (1)
- private networks (1)
- public networks (1)
- radio access network (RAN) (1)
- reconnaissance (1)
- secure flash (1)
- security (1)
- self-encrypting drives (SEDs) (1)
- sff (1)
- software (1)
- software-defined radios (SDRs) (1)
- speeds and feeds (1)
- standalone (1)
- storage (1)
- systems (1)
- tactical wide area networks (1)
- technical support (1)
- technology (1)
- third-party motherboards (1)
- troposcatter communication (1)
- unlicensed spectrum (1)
- volatile memory (1)
- vpx (1)
- zero trust network (1)
- November 2024 (1)
- October 2024 (1)
- August 2024 (1)
- July 2024 (1)
- May 2024 (1)
- April 2024 (3)
- February 2024 (1)
- November 2023 (1)
- October 2023 (1)
- July 2023 (1)
- June 2023 (3)
- May 2023 (7)
- April 2023 (5)
- March 2023 (7)
- December 2022 (2)
- November 2022 (6)
- October 2022 (7)
- September 2022 (8)
- August 2022 (3)
- July 2022 (4)
- June 2022 (13)
- May 2022 (10)
- April 2022 (4)
- March 2022 (11)
- February 2022 (4)
- January 2022 (4)
- December 2021 (1)
- November 2021 (4)
- September 2021 (2)
- August 2021 (1)
- July 2021 (2)
- June 2021 (3)
- May 2021 (4)
- April 2021 (3)
- March 2021 (3)
- February 2021 (8)
- January 2021 (4)
- December 2020 (5)
- November 2020 (5)
- October 2020 (4)
- September 2020 (4)
- August 2020 (6)
- July 2020 (9)
- June 2020 (11)
- May 2020 (13)
- April 2020 (8)
- February 2020 (1)
- January 2020 (1)
- October 2019 (1)
- August 2019 (2)
- July 2019 (2)
- March 2019 (1)
- January 2019 (2)
- December 2018 (1)
- November 2018 (2)
- October 2018 (5)
- September 2018 (3)
- July 2018 (1)
- April 2018 (2)
- March 2018 (1)
- February 2018 (9)
- January 2018 (27)
- December 2017 (1)
- November 2017 (2)
- October 2017 (3)
No Comments Yet
Let us know what you think