SolarWinds defense: How to stop similar attacks

General News

Summary

Its too late for anything but damage control for SolarWinds, but The Linux Foundation has found several lessons to make sure your programs, whether open source or proprietary, avoid SolarWinds-style disasters. For example, Equifaxs infamous failure was due to its simply not paying attention when a public fix was issued for the Apache Struts library it used in its programs. To be fair, theres a chicken-and-egg problem here: specifications are in the process of being updated, tools are in development, and many software producers arent ready to provide SBOMs. "For many OSS projects this can typically be done, at least in part, by providing package management information that identifies their direct and indirect dependencies (e.g., in package.json, requirements.txt, Gemfile, Gemfile.lock, and similar files). Finally, Wheeler believes, "Organizations should invest in OpenChain conformance and require their suppliers to implement a process designed to improve trust in a supply chain."

Classifications

industries
No industries detected
applications
AI & Machine learning

AskAI Classifications

Labels
Cybersecurity Software Endpoint Security Cloud Security

Linked Companies

GitHub, Inc.
$1M to $5M
SolarWinds Worldwide LLC
$250M to $500M