Abstract
My technical project and STS research are united in addressing the problem of securing sophisticated systems from advanced cyberattacks. In my technical project, I collected information about the availability of Proof-of-Concept (PoC) programs, which are important tools for preventing advanced cyberattacks. In my STS research, I examine an example of one such cyberattack: the 2020 SolarWinds breach. While my technical project provides insight on the availability of cybersecurity resources, my STS research examines the background of one cyberattack and how the infected software product reached so many systems. Together, both provide information on how to prevent dangerous cyberattacks.
In my technical project, I built a database of 14,933 PoC programs. Each PoC demonstrates how one or more known vulnerabilities in public software packages can be exploited by malicious attackers, with the intent of allowing developers to add defenses to their software. Furthermore, many automated cybersecurity systems such as intrusion detection systems rely on PoCs to predict patterns of malicious behavior. Therefore, the quantity of available PoCs plays a vital role in stopping advanced cyberattacks that may attempt to remain undetected in systems for long periods. In my work, I collected a large quantity of PoCs in an attempt to better understand how many PoCs are currently available and how quickly new PoCs are being created. My results reveal important trends in PoC production, such as an increase in PoCs produced per year. These results inform PoC researchers and developers, allowing greater understanding of and access to data sources.
In my STS research, I examined an example of one such cyberattack: the 2020 SolarWinds breach. In this attack spanning over a year, nation-state attackers successfully infiltrated the SolarWinds code deployment system undetected and injected malicious code into packages in the Orion software product. When the infected version of the Orion product was distributed, the virus gained root access to hundreds of clients around the globe, including industry leaders such as Microsoft and US government agencies such as the State Department. I employed Thomas Hughes's framework of technological momentum, which describes technologies as primarily receiving influence from society in earlier stages but primarily exerting influence over society in later stages, to argue that the Orion product gained significant influence through three key factors: popular and powerful features, strong sociotechnical investment from SolarWinds, and the positive reputation of SolarWinds prior to the breach.
Through completing both projects together, I was able to gain a holistic view of both the factors contributing to successful cyberattacks and the tools researchers and developers use to combat them. For example, as I saw the damage the SolarWinds attackers inflicted by remaining undetected in the system for a long period, I better understood the need for successful intrusion detection systems, which usually rely on PoCs. The technical and STS projects supported each other and enhanced my learning experience.