SolarWinds through a first principle lens. [CSO Perspectives]

Published: April 11, 2022, 7 a.m.

Enjoy this sample of CSO Perspectives, a CyberWire Pro podcast. Like what you hear? Consider subscribing to CyberWire Pro for $99/year.\xa0Learn more.\nOn this episode, host Rick Howard discusses if the first principles theories prevent material impact in the real world, such as the latest SolarWinds attack.\nPrevious episodes referenced:\nS1E6: 11 MAY: Cybersecurity First Principles\nS1E7: 18 MAY: Cybersecurity first principles: zero trust\nS1E8: 26 MAY: Cybersecurity first principles: intrusion kill chains.\nS1E9: 01 JUN: Cybersecurity first principles - resilience\nS1E11: 15 JUN: Cybersecurity first principles - risk\nS2E3: 03 AUG: Incident response: a first principle idea.\nS2E4: 10 AUG: Incident response: around the Hash Table.\xa0\nS2E7: 31 AUG: Identity Management: a first principle idea.\nS2E8: 07 SEP: Identity Management: around the Hash Table.\nOther resources:\n\u201cA BRIEF HISTORY OF SUPPLY CHAIN ATTACKS,\u201d by Secarma, 1 September 2018.\n\u201cAnalyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers,\u201d by 365 Defender Research Team and the Threat Intelligence Center (MSTIC), Microsoft, 18 December 2020.\n\u201cA Timeline Perspective of the SolarStorm Supply-Chain Attack,\u201d by Unit 42, Palo Alto Networks, 23 December 2020.\n\u201cCobalt Strike,\u201d by MALPEDIA.\n\u201cCountdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon,\u201d by Kim Zetter, Published by Crown, 3 June 2014.\n\u201cCybersecurity Canon,\u201d by Ohio State University.\n\u201cFireEye shares jump back to pre-hack levels,\u201d Melissa Lee, CNBC, 23 December 2020.\n"Implementing Intrusion Kill Chain Strategies by Creating Defensive Campaign Adversary Playbooks," by Rick Howard, Ryan Olson, and Deirdre Beard (Editor), The Cyber Defense Review, Fall 2020.\n\u201cOrion Platform,\u201d by SolarWinds.\n\u201cSandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers,\u201d by Andy Greenberg, Published by Doubleday, 7 May 2019.\xa0\n\u201cSolarstorm,\u201d by Unit 42, Palo Alto Networks, 23 December 2020.\n\u201cThe Cybersecurity Canon: Countdown to Zero Day: Stuxnet and the Launch of the World\u2019s First Digital Weapon,\u201d by Rick Howard, The Cybersecurity Canon Project, 28 January 2015.\n\u201cUsing Microsoft 365 Defender to protect against Solorigate,\u201d by the Microsoft 365 Defender Team, 28 December 2020.\nLearn more about your ad choices. Visit megaphone.fm/adchoices