Software Update Frameworks and the CI Supply Chain

Опубликовано: 25 Март 2026
на канале: S4 Events
156
5

The ability to update software on devices is a valuable tool for protecting critical systems from evolving threats. However, this capability is not without risk. There have been an alarming number of vulnerabilities that were introduced through a malicious software patch or a flaw in the update process. New software update frameworks have been developed to mitigate this risk, but they come with new levels of complexity, and they may not work on segmented network architectures or be suitable for embedded devices.

Brian focuses on TUF (The Update Framework), a software update approach that addresses many common vulnerabilities and consider how it can be applied in a critical infrastructure environment. It is compared against SUIT (Software Update for IoT) and UpKit, two alternative structures that are intended for use on embedded systems.

Attack trees are used to compare these models and visually explain the strengths and challenges that may be encountered when they are applied in a network that follows the Purdue or ISA-99/IEC 62443 network architecture. The role of metadata such as an SBOM and vendor test results are also be considered. These concepts are merged to re-cast software updates into the context of an integrated supply-chain and configuration management system.