A review of SolarWinds attack on Orion platform using persistent threat agents and techniques for gaining unauthorized access
Antigoni Kruti, Usman Butt, Rejwan Bin Sulaiman

TL;DR
This paper reviews the SolarWinds Orion Platform attack, analyzing the threat agents, attack techniques, and security gaps, providing insights into defense strategies and incident response improvements.
Contribution
It offers a comprehensive analysis of the SolarWinds attack, highlighting technical vulnerabilities, attack methods, and proposing security enhancements for future defense.
Findings
Identification of key attack vectors and techniques used by hackers.
Analysis of security gaps in the Orion Platform and supply chain.
Recommendations for improving incident response and cyber hygiene.
Abstract
This paper of work examines the SolarWinds attack, designed on Orion Platform security incident. It analyses the persistent threats agents and potential technical attack techniques to gain unauthorized access. In 2020 SolarWinds attack indicates an initial breach disclosure on Orion Platform software by malware distribution on IT and government organizations such as Homeland Security, Microsoft and Intel associated with supply chains leaks consequences from small loopholes in security systems. Hackers increased the number of infected company and businesses networks during the supply-chain attack, hackers were capable to propagate the attack by using a VMware exploit. On the special way they started to target command injections, privilege escalations, and use after free platforms of VMware. In this way, they gained access to Virtual Machines and in the east way pivot other servers. This…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · IoT and Edge/Fog Computing · Advanced Malware Detection Techniques
