2023-07-18-国际清算银行-北极星项目_缩小CBDC网络威胁建模差距_51页_2mb
报告摘要
Project Polaris: Closing the CBDC Cyber Threat Modelling Gaps
Executive Summary
Decentralized finance (DeFi) is revolutionizing the financial industry, but the underlying technology introduces unique cybersecurity vulnerabilities. As central banks consider issuing central bank digital currencies (CBDCs) as an alternative to cryptocurrencies, analysis reveals gaps in existing threat modeling frameworks. The MITRE ATT&CK framework was used to map notable DeFi attacks, identifying that current threat modeling techniques may not adequately address CBDC threats. Despite the absence of reported successful attacks against operational CBDC systems, the analysis underscores the necessity for an extended MITRE ATT&CK framework or new threat models to properly protect CBDC systems utilizing DLT or smart contracts.
Analysis Overview
This analysis mapped six high-profile DeFi attacks—Poly Network, Axie/Ronin, BadgerDAO, Wormhole/Solana, Beanstalk, and Fei Protocol—to the MITRE ATT&CK framework to identify gaps relevant to CBDC cybersecurity. The mapping uncovered:
- Some attack techniques align with existing MITRE ATT&CK entries (Group 1)
- Existing entries require refinement or adjustments (Group 2)
- New attack types not represented in the current framework but tie to existing tactics (Group 3)
- Entirely new attack types that do not fit within the Enterprise Matrix (Group 4)
Key Findings
| Group Classification | Details |
|---|---|
| Group 1 | Existing MITRE ATT&CK entries can be directly applied to parts of the analyzed attacks. This suggests that general cybersecurity frameworks still offer foundational applicability to CBDC systems, particularly for known threat vectors. |
| Group 2 | Some descriptions within MITRE ATT&CK require slight updates or adjustments to accurately reflect the evolving threat landscape. Addressing these gaps would enhance the framework's relevance to CBDC-specific risks. |
| Group 3 | New types of attacks were identified that are not present in the current framework. These included novel cryptomining and DeFi-tailored attack vectors, such as Brute Force: Credential Access (Brute forcing of contract ID hash) and Exploitation of Remote Services. This group highlights areas requiring expansion. |
| Group 4 | Entirely new attack types were identified that do not fit within the existing Enterprise Matrix. These included consensus logic exploits specific to DeFi platforms, such as Consensus Logic Exploitation: Abuse smart contract hierarchical ownership (Bypassing). These gaps indicate the need for framework extensions. |
| New Tactics/Techniques | New attack vectors and methodologies were identified, reflecting the evolving sophistication of threats targeting DLT systems. Examples include Acquire Infrastructure (Crypto accounts) to launder stolen funds and Circumvent voting majority controls (Obtain majority of voting rights), which do not align with current threat modeling approaches. |
Summary of Conclusions
- Threat Modeling Gaps: Existing security frameworks, including MITRE ATT&CK, manifest gaps when applied to CBDC risks, particularly for systems leveraging DLT or smart contracts.
- Extension Need: An official extension of the MITRE ATT&CK framework may be necessary to adequately address CBDC- and DeFi-specific threat vectors.
- Time to Attack: Between DeFi launches and successful compromises, the average time is approximately ten months. This emphasizes the need for proactive defense measures.
- Future Work: Crowdsourcing efforts are proposed to map attacks, define new TTPs, and refine threat models. Additionally, examining other cybersecurity standards for DLT-specific adaptations will support CBDC resilience.
About the MITRE ATT&CK Framework
The MITRE ATT&CK Framework is globally recognized for threat modeling and penetration testing. Its key advantages include consistency, customization, community-driven development, and evidence-based threat descriptions. However, its scope must be extended to cover DeFi and CBDC risks.
试读结束,高清完整版pdf/doc/ppt,请点下载