国际清算银行-北极星项目:缩小CBDC网络威胁建模差距(英)-2023.7-51页_2mb
报告摘要
This report analyzes gaps in cyber threat modeling for Central Bank Digital Currencies (CBDC) using insights from Decentralized Finance (DeFi) attacks mapped to the MITRE ATT&CK framework. The BIS Cyber Resilience Coordination Centre, in partnership with PA Consulting, conducted this analysis via Project Polaris, examining six high-profile DeFi attacks to identify deficiencies in existing threat models. Key findings reveal that DeFi's use of Distributed Ledger Technology (DLT) and smart contracts introduces unique vulnerabilities applicable to CBDCs, with the MITRE ATT&CK framework insufficient for covering novel attack tactics, techniques, and procedures (TTPs). Gaps identified include new attack vectors requiring TTP updates, such as brute-force contract id hashing and re-entrancy exploits. Recommendations emphasize crowdsourcing to catalog new threats, extending the framework for CBDC-specific coverage, and reviewing other security standards like NIST or ISO guidelines. The analysis also highlights a "mean time to attack" of approximately 10 months post-implementation, underscoring the need for proactive cyber defenses in CBDC rollouts.
-
Key Findings:
- DeFi attacks demonstrate potential CBDC vulnerabilities through shared technologies.
- MITRE ATT&CK gaps: Insufficient coverage for new TTPs, necessitating framework extensions.
- Attack timeline: Compromises often occur around 10 months after launch.
-
Recommendations:
- Crowdsourcing initiatives for TTP mapping and security control suggestions.
- Official extension of the MITRE ATT&CK framework to include CBDC/DeFi matrices.
- Augmentation of existing cyber frameworks like NIST CSF or ISO 27001 with DLT-specific controls.
试读结束,高清完整版pdf/doc/ppt,请点下载