{"id":5175,"date":"2024-09-06T09:00:00","date_gmt":"2024-09-06T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/using-transparency-and-sharing-to-defend-critical-infrastructure"},"modified":"2024-09-06T09:00:00","modified_gmt":"2024-09-06T14:00:00","slug":"using-transparency-sharing-to-defend-critical-infrastructure","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/06\/using-transparency-sharing-to-defend-critical-infrastructure\/","title":{"rendered":"Using Transparency &amp; Sharing to Defend Critical Infrastructure"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt6dfef2942d23ce95\/66da09e55356fc623f3eb51d\/Infrastructure%281800%29_Science_Photo_Library_Alamy_Stock_Photo.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As cyber threats grow increasingly sophisticated, protecting critical infrastructure is essential. State-sponsored actors,&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/us-govt-reportedly-trying-to-disrupt-volt-typhoon-attack-infrastructure\" rel=\"noopener\">such as the notorious Volt Typhoon<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, continue to target critical infrastructure, using advanced cyber techniques. The stakes are high: <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/using-transparency-and-sharing-to-defend-critical-infrastructure\" rel=\"noopener\">Cyberattacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of this caliber can lead to significant disruptions to critical infrastructure, threats to democracy, global economic crises, and potentially loss of life. There is an urgent need for enhanced cybersecurity measures to protect these functions and services \u2014 it&#8217;s a matter of public safety and national security. In order to combat these sophisticated threats, the industry must develop an approach that is focused on transparency, information sharing, and enhanced visibility.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Volt Typhoon, a sophisticated cyber-espionage group associated with China, employs advanced stealth techniques to infiltrate critical infrastructure networks. It primarily targets US military and government entities, accessing systems via vulnerabilities in products within these environments. Its attacks are characterized by the use of &#8220;living off the land&#8221; tactics, which leverage existing legitimate tools and processes within the target systems to evade detection. Since it does not rely on malware to infiltrate its victims, its attacks are difficult to detect and track.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Transparency and Information Sharing Can Help Safeguard Our Systems\">Transparency and Information Sharing Can Help Safeguard Our Systems<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Transparency is crucial in responding to these cyber threats effectively. When an incident occurs, the ability to act swiftly is paramount \u2014 not just for the affected organizations, but also for the government agencies tasked with investigating and mitigating these attacks. This is especially critical when signs suggest they are malicious state-sponsored actors. Transparency allows for more efficiently coordinated and timely responses to mitigate an incident from escalating.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Enter software bills of materials (SBOMs), which the US federal government has recognized the importance of as a crucial tool to enhance cybersecurity,&nbsp;directing the National Telecommunications and Information Administration to publish <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/\" rel=\"noopener\">minimum standards for federal agencies to adopt and implement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The need for SBOMs, however, extends beyond federal agencies and government contractors. SBOMs can play a crucial role in protecting against and preventing these types of attacks by providing a fine-grained list of components and interdependencies, including open source and third-party components. Since they provide a detailed inventory of all the software components and transitive dependencies within a system, they make it easier to quickly identify unusual or unauthorized components that might indicate a Volt Typhoon attack.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/wanted-sbom-standard-to-rule-them-all\" rel=\"noopener\">the SBOM is an extremely important artifact<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, it may overstate the actual risks of the vulnerability without the Vulnerability Exploitability eXchange (VEX) companion document. The VEX document can provide a complete picture of risk in the specific context to the SBOM, reducing the time to investigate and accelerating the time to remediate vulnerabilities by providing a greater understanding of the components. If a vulnerability truly presents a risk or if compensating controls are already in place to mitigate the risk. Utilizing the SBOM data in conjunction with the VEX, organizations can gain a comprehensive picture of their environment, allowing them to make decisions based on security intelligence provided in the data to enhance their overall security posture against cyber threats like those posed by Volt Typhoon and other bad actors.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Strong Partnerships Between the Public and Private Sectors Are Critical to Fight Cyberattacks\">Strong Partnerships Between the Public and Private Sectors Are Critical to Fight Cyberattacks<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Public-private partnerships play a crucial role in this ecosystem of transparency and security. Through these partnerships, the government can share intelligence on emerging risks and provide the public sector with the insights needed to bolster their defenses. In return, public entities can contribute by sharing real-time data on the threats they encounter, creating a continuous exchange of critical information. This back-and-forth flow of intelligence and information sharing strengthens the collective ability to prevent and counter cyber threats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Transparency within partnerships, which is enabled by strategies like SBOMs, creates an environment where both sides trust each other and openly share information about threats and vulnerabilities. A high level of trust within these relationships also encourages private organizations to disclose critical data without worrying about misuse, which again allows public organizations to offer better support and resources in response to cyber threats. Beyond just information sharing, this mutual confidence strengthens the overall cybersecurity posture by enabling both parties to work together to quickly resolve these issues.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Enhanced Visibility Into Complex IT Systems Enables Organizations to Enhance Cybersecurity Efforts\">Enhanced Visibility Into Complex IT Systems Enables Organizations to Enhance Cybersecurity Efforts<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In addition to external efforts, visibility within organizations, both public and private, is equally important in combating cyberattacks. Modern IT environments grow more complex by the day, often consisting of hybrid infrastructures and multicloud environments. Responding quickly to cyber incidents requires a deep understanding of these systems. Solutions like observability can provide a critical lift, as they help detect anomalies as they occur. By providing real-time insights into the status of an entire IT environment, observability empowers IT teams to act swiftly and prevent an incident from occurring or escalating.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The effort to gain better visibility and insights into systems and processes \u2014 as well as the promotion of partner transparency \u2014 are two important pillars of the SolarWinds&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.solarwinds.com\/secure-by-design-resources\" rel=\"noopener\">Secure by Design<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;initiative, which is a framework that aims to bolster cyber resiliency and security across both public and private sectors. Organizations can take a similar approach to help develop a clear road map toward achieving an enhanced cybersecurity posture.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The need for ongoing collaboration and innovation in cybersecurity cannot be overstated. In today\u2019s rapidly evolving cyber landscape, no organization can single-handedly defend against sophisticated cybercriminals and nation-state threats. It is imperative for governments and private sector entities to continue collaborating, sharing information, and developing robust defenses against cyber threats. By leveraging the power of SBOMs and observability, we can build a more resilient and secure future, and by working together, we can create a safer and more secure environment that can face today\u2019s cyber threats.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/using-transparency-and-sharing-to-defend-critical-infrastructure\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY As cyber threats grow increasingly sophisticated, protecting critical infrastructure<\/p>\n","protected":false},"author":12,"featured_media":5176,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5175","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/using-transparency-sharing-to-defend-critical-infrastructure.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5175","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5175"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5175\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5176"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5175"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5175"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}