{"id":87905,"date":"2023-02-14T08:30:00","date_gmt":"2023-02-14T08:30:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/?p=87905"},"modified":"2023-02-14T08:30:00","modified_gmt":"2023-02-14T08:30:00","slug":"oscr-framework-to-stop-supply-chain-attacks-in-the-wild","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=87905","title":{"rendered":"OSC&amp;R framework to stop supply chain attacks in the wild"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2023\/02\/oscr-framework-to-stop-supply-chain-attacks-in-the-wild.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>A team of cyber security leaders and influencers have joined together to launch an open framework to help security teams improve their understanding of threats to their <a href=\"https:\/\/www.techtarget.com\/searcherp\/definition\/supply-chain-security\">software supply chains<\/a>, and evaluate and get to grips with them.<\/p>\n<p>The Open Software Supply Chain Attack Reference, or OSC&amp;R, is a MITRE ATT&amp;CK-like framework created with input from the likes of Check Point, Fortinet, GitLab, Google, Microsoft, OWASP, and others, led by <a href=\"https:\/\/www.ox.security\/\">Ox Security<\/a>, an Israel-based supply chain security specialist.<\/p>\n<p>In light of the growing number of major cyber incidents that began via exploitation of vulnerabilities in software, whether closed or open source, the group believes there is a concrete need for a solid framework to let experts understand and measure their supply chain risk, which up to now, they say, could only really be done via a combination of intuition and lived experience.<\/p>\n<p>\u201cTrying to talk about supply chain security without a common understanding of what constitutes the software supply chain isn\u2019t productive,\u201d said Neatsun Ziv, a former <a href=\"https:\/\/www.checkpoint.com\/\">Check Point<\/a> vice-president, who founded Ox Security \u2013 which emerged from stealth in September 2022 backed by $34m of funding.<\/p>\n<p>\u201cWithout an agreed-upon definition of the software supply chain, security strategies are often siloed,\u201d he said.<\/p>\n<p>OSC&amp;R will supposedly help this by establishing a common language and structure to help security teams understand and analyse the tactics, techniques and procedures (TTPs) that threat actors use to compromise downstream victims via their software supply chains.<\/p>\n<p>The framework, <a href=\"https:\/\/pbom.dev\/\">which is set out in more detail here<\/a>, is already available and ready to be used to help teams evaluate their defences, define what threats they need to prioritise, understand how their existing security postures might address said threats, and to help track attacker behaviours.<\/p>\n<p>Its backers hope to update it as new TTPs emerge and evolve, and eventually plan to have the framework assist <a href=\"https:\/\/www.computerweekly.com\/opinion\/How-does-red-teaming-test-the-ultimate-limits-of-cyber-security\">red-teaming activities<\/a> by helping set the scope of exercises, serving as a kind of scorecard during and after such testing. It is also open to other security practitioners to contribute to, should they wish.<\/p>\n<p>\u201cOSC&amp;R helps security teams build their security strategy with confidence,\u201d said Hiroki Suezawa, senior security engineer at <a href=\"https:\/\/about.gitlab.com\/\">Gitlab<\/a>.&nbsp;\u201cWe wanted to give the security community a single point of reference to proactively assess their own strategies for securing their software supply chains and to compare solutions.\u201d<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"More work needed?\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>More work needed?<\/h3>\n<p>Tim Mackey, head of software supply chain risk strategy at the <a href=\"https:\/\/www.synopsys.com\/software-integrity.html\">Synopsys Software Integrity Group<\/a>, said that the project held much potential, but that more work needed to be done.<\/p>\n<p>Since software supply chains are prone to complexity thanks to the multiple relationships between developers, infrastructure providers, data processors and software operators, the inherent risks are deeply entwined and difficult to determine.<\/p>\n<p>\u201cThe OSC&amp;R model that has been proposed by the Pipeline Bill of Materials [PBOM] community is one way to describe weaknesses in the form of an attack model. In its current state however, it lacks significant detail to describe examples of potential attacks, mitigations and detections,\u201d he said.<\/p>\n<p>\u201cIt will be interesting to see how OSC&amp;R evolves, and to see how it ultimately aligns with proven models such as MITRE ATT&amp;CK where it\u2019s possible that OSC&amp;R might represent a richer level of granularity than currently exists for compromise software supply chain.\u201d<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>A team of cyber security leaders and influencers have joined together to launch an open framework to help security teams improve their understanding of threats to their software supply chains, and evaluate and get to grips with them. The Open Software Supply Chain Attack Reference, or OSC&amp;R, is a MITRE ATT&amp;CK-like framework created with input [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":87906,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-87905","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/87905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=87905"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/87905\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/87906"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=87905"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=87905"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=87905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}