https://urgentcomm.com/wp-content/themes/ucm_child/assets/images/logo/footer-new-logo.png
  • Home
  • News
  • Multimedia
    • Back
    • Multimedia
    • Video
    • Podcasts
    • Galleries
    • IWCE’s Video Showcase
    • IWCE 2022 Winter Showcase
    • IWCE 2023 Pre-event Guide
  • Commentary
    • Back
    • Commentary
    • Urgent Matters
    • View From The Top
    • All Things IWCE
    • Legal Matters
  • Resources
    • Back
    • Resources
    • Webinars
    • White Papers
    • Reprints & Reuse
  • IWCE
    • Back
    • IWCE
    • Conference
    • Special Events
    • Exhibitor Listings
    • Premier Partners
    • Floor Plan
    • Exhibiting Information
    • Register for IWCE
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Terms of Service
    • Privacy Statement
    • Cookie Policy
  • Related Sites
    • Back
    • American City & County
    • IWCE
    • Light Reading
    • IOT World Today
    • Mission Critical Technologies
    • TU-Auto
  • In the field
    • Back
    • In the field
    • Broadband Push-to-X
    • Internet of Things
    • Project 25
    • Public-Safety Broadband/FirstNet
    • Virtual/Augmented Reality
    • Land Mobile Radio
    • Long Term Evolution (LTE)
    • Applications
    • Drones/Robots
    • IoT/Smart X
    • Software
    • Subscriber Devices
    • Video
  • Call Center/Command
    • Back
    • Call Center/Command
    • Artificial Intelligence
    • NG911
    • Alerting Systems
    • Analytics
    • Dispatch/Call-taking
    • Incident Command/Situational Awareness
    • Tracking, Monitoring & Control
  • Network Tech
    • Back
    • Network Tech
    • Interoperability
    • LMR 100
    • LMR 200
    • Backhaul
    • Deployables
    • Power
    • Tower & Site
    • Wireless Networks
    • Coverage/Interference
    • Security
    • System Design
    • System Installation
    • System Operation
    • Test & Measurement
  • Operations
    • Back
    • Operations
    • Critical Infrastructure
    • Enterprise
    • Federal Government/Military
    • Public Safety
    • State & Local Government
    • Training
  • Regulations
    • Back
    • Regulations
    • Narrowbanding
    • T-Band
    • Rebanding
    • TV White Spaces
    • None
    • Funding
    • Policy
    • Regional Coordination
    • Standards
  • Organizations
    • Back
    • Organizations
    • AASHTO
    • APCO
    • DHS
    • DMR Association
    • ETA
    • EWA
    • FCC
    • IWCE
    • NASEMSO
    • NATE
    • NXDN Forum
    • NENA
    • NIST/PSCR
    • NPSTC
    • NTIA/FirstNet
    • P25 TIG
    • TETRA + CCA
    • UTC
Urgent Communications
  • NEWSLETTER
  • Home
  • News
  • Multimedia
    • Back
    • Video
    • Podcasts
    • Omdia Crit Comms Circle Podcast
    • Galleries
    • IWCE’s Video Showcase
    • IWCE 2023 Pre-event Guide
    • IWCE 2022 Winter Showcase
  • Commentary
    • Back
    • All Things IWCE
    • Urgent Matters
    • View From The Top
    • Legal Matters
  • Resources
    • Back
    • Webinars
    • White Papers
    • Reprints & Reuse
    • UC eZines
    • Sponsored content
  • IWCE
    • Back
    • Conference
    • Why Attend
    • Exhibitor Listing
    • Floor Plan
    • Exhibiting Information
    • Join the Event Mailing List
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Cookie Policy
    • Terms of Service
    • Privacy Statement
  • Related Sites
    • Back
    • American City & County
    • IWCE
    • Light Reading
    • IOT World Today
    • TU-Auto
  • newsletter
  • In the field
    • Back
    • Internet of Things
    • Broadband Push-to-X
    • Project 25
    • Public-Safety Broadband/FirstNet
    • Virtual/Augmented Reality
    • Land Mobile Radio
    • Long Term Evolution (LTE)
    • Applications
    • Drones/Robots
    • IoT/Smart X
    • Software
    • Subscriber Devices
    • Video
  • Call Center/Command
    • Back
    • Artificial Intelligence
    • NG911
    • Alerting Systems
    • Analytics
    • Dispatch/Call-taking
    • Incident Command/Situational Awareness
    • Tracking, Monitoring & Control
  • Network Tech
    • Back
    • Cybersecurity
    • Interoperability
    • LMR 100
    • LMR 200
    • Backhaul
    • Deployables
    • Power
    • Tower & Site
    • Wireless Networks
    • Coverage/Interference
    • Security
    • System Design
    • System Installation
    • System Operation
    • Test & Measurement
  • Operations
    • Back
    • Critical Infrastructure
    • Enterprise
    • Federal Government/Military
    • Public Safety
    • State & Local Government
    • Training
  • Regulations
    • Back
    • Narrowbanding
    • T-Band
    • Rebanding
    • TV White Spaces
    • None
    • Funding
    • Policy
    • Regional Coordination
    • Standards
  • Organizations
    • Back
    • AASHTO
    • APCO
    • DHS
    • DMR Association
    • ETA
    • EWA
    • FCC
    • IWCE
    • NASEMSO
    • NATE
    • NXDN Forum
    • NENA
    • NIST/PSCR
    • NPSTC
    • NTIA/FirstNet
    • P25 TIG
    • TETRA + CCA
    • UTC
acc.com

Security


Partner content

4 integrated-circuit security threats and how to protect against them

4 integrated-circuit security threats and how to protect against them

  • Written by Matthew Areno / Dark Reading
  • 14th July 2021

Today’s computing systems are up against an extraordinary volume of threats, and many of them target where these systems originate — in the supply chain and around critical integrated circuits (ICs). In fact, according to the ITRC, supply chain attacks impacted 694 entities in 2020, which ultimately affected more than 42 million individuals. Therefore, you can’t overstate the importance of understanding and addressing supply chain risks proactively. The best way to do this is to assess all potential attack vectors throughout the life cycle of an IC and a computing system.

There is a wide range of possible attacks throughout every stage of the IC life cycle. This can make ensuring the integrity of a computing system from end to end extremely challenging. To better understand these challenges, let’s explore some key IC supply chain threats and how to protect against them.

Four Lesser-Known Supply Chain Threats

There are a variety of known supply-chain threats, and they continue to evolve quickly. These attacks can happen across the various stages of the component life cycle, from design, integration, and fabrication to testing, provisioning, and deployment. While some are more commonly known — such as insider threats, malicious third-party plug-ins or design tools, design network attacks, malicious hardware and firmware, reverse engineering of components, physical alteration in transit, and fictitious recycling — let’s focus on some of the lesser-known vectors.

1. Design Alteration — Design modifications might occur during several different stages by various actors. A supplier might suggest a seemingly innocuous change that can induce an undefined state of execution in the system. An integrator might make a covert change to the design files provided as part of an integration effort. Some believe that design alteration was the end goal of the AutoCAD malware, and more recently, it played a role with SUNSPOT in the SolarWinds attack.

How can you mitigate this threat? Consider isolating design networks from traditional corporate networks, restrict third-party plug-in usage to trusted sources, and cryptographically validate all design tools, updates, and plug-ins before installation. Also, companies should use internally maintained repositories of design tools and use blockchain technology (or some other auditing tool) to create a ledger of all access events and modified design files.

2. Trojan Circuitry Insertion — While still mostly an academic case, there’s evidence that multiple hardware Trojans exist but are not yet activated. Activation would expose the Trojan, so an attacker would wait to produce the biggest impact before triggering it. Trojan circuitry might occur during one of several different phases. Beyond Trojan circuitry in malicious hardware, other circuitry modifications could be made directly to printed circuit boards (PCBs). The result might be disclosure of sensitive information, control of the system, or part of a larger, multistep Trojan activation sequence. You can learn more about hardware Trojan insertion on IEEE or in this recent DEF CON presentation.

To read the complete article, visit Dark Reading.

 

Tags: Applications Critical Infrastructure Cybersecurity Enterprise Federal Government/Military Incident Command/Situational Awareness News Policy Public Safety Security Software State & Local Government Subscriber Devices System Design System Operation Tracking, Monitoring & Control Partner content

Most Recent


  • How AT&T won DFW Airport's $10 million private 5G business
    According to Mike Youngs, it all started with the bathrooms at Dallas Fort Worth (DFW) International Airport. Youngs, the airport’s VP for IT, wanted to use wireless technology to reduce crowding in restroom lines during the COVID-19 pandemic. His team installed sensors and lights above stalls and monitors outside restrooms to let people know when […]
  • Russia's war in Ukraine shows cyberattacks can be war crimes
    Russia’s cyberattacks against Ukrainian civilian and critical infrastructure has shown what it looks like when cyberattacks are part of warfare. What remains to be seen is whether the world will treat them as war crimes. “For too long, the world has been considering cyber terrorism as something unrealistic, too sci-fi-ish, and cyber weapons as not […]
  • FCC grants 700 MHz Band 14 license renewal to FirstNet Authority
    An FCC bureau yesterday renewed the FirstNet Authority’s spectrum license into at least 2027, allowing the nationwide public-safety broadband network (NPSBN) to continue operating over the 700 MHz Band 14 airwaves—a key component of the FirstNet Authority’s 25-year agreement with contractor AT&T. Approved by the FCC Public Safety and Homeland Security Bureau (PSHSB), the license […]
  • How vehicle insurance and autonomy intertwined
    In early 2023 Oxbotica claimed at an event, which was held at Lloyd’s of London about the Future of Autonomy that insurance and autonomy are intertwined. At the event, Sam Tiltman, sharing economy and mobility leader for the UK & Ireland at Marsh, claimed that the combined impact of Mobility-as-a-Service (MaaS), electric vehicles and automation is huge. […]

Leave a comment Cancel reply

To leave a comment login with your Urgent Comms account:

Log in with your Urgent Comms account

Or alternatively provide your name, email address below:

Your email address will not be published. Required fields are marked *

Related Content

  • Recent attacks lead to renewed calls for banning ransom payments
  • 10 mistakes companies make in their ransomware responses
  • Don't crown Big Tech the global communications kings just yet
  • Does China's crackdown mean curtains for cryptojacking via IoT?

Commentary


Updated: How ‘sidelink’ peer-to-peer communications can enhance public-safety operations

  • 1
27th February 2023

NG911 needed to secure our communities and nation

24th February 2023

How 5G is making cities safer, smarter, and more efficient

26th January 2023
view all

Events


UC Ezines


IWCE 2019 Wrap Up

13th May 2019
view all

Twitter


UrgentComm

How AT&T won DFW Airport’s $10 million private 5G business dlvr.it/Spj4Pt

27th May 2023
UrgentComm

Russia’s war in Ukraine shows cyberattacks can be war crimes dlvr.it/Spj3c2

27th May 2023
UrgentComm

FCC grants 700 MHz Band 14 license renewal to FirstNet Authority dlvr.it/Spj2Ny

27th May 2023
UrgentComm

Broadband for Critical Communications Everywhere Providing Connectivity When Seconds Count dlvr.it/Sph602

26th May 2023
UrgentComm

How vehicle insurance and autonomy intertwined dlvr.it/SpglBb

26th May 2023
UrgentComm

World’s least-expensive self-driving vehicle revealed dlvr.it/Spgc88

26th May 2023
UrgentComm

Voice calling is finally making its way onto 5G dlvr.it/SpdtYW

26th May 2023
UrgentComm

With many cities facing a fiscal cliff as ARPA funding ends, debt ceiling debate continues on Capitol Hill dlvr.it/Spdsnq

26th May 2023

Newsletter

Sign up for UrgentComm’s newsletters to receive regular news and information updates about Communications and Technology.

Expert Commentary

Learn from experts about the latest technology in automation, machine-learning, big data and cybersecurity.

Business Media

Find the latest videos and media from the market leaders.

Media Kit and Advertising

Want to reach our digital and print audiences? Learn more here.

DISCOVER MORE FROM INFORMA TECH

  • American City & County
  • IWCE
  • Light Reading
  • IOT World Today
  • Mission Critical Technologies
  • TU-Auto

WORKING WITH US

  • About Us
  • Contact Us
  • Events
  • Careers

FOLLOW Urgent Comms ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.