The SolarWinds Hack: Zero-Day Security and US National Security
This paper examines the SolarWinds cyberattack of 2020, one of the largest supply-chain hacks ever recorded, in which malicious code was embedded in the Orion network monitoring platform and distributed to over 18,000 customers worldwide. The paper traces how the attack unfolded — from a suspected GitHub misconfiguration to the deployment of the SUNBURST backdoor — and identifies victims including multiple US federal agencies. It then analyzes zero-day security vulnerabilities exploited by the attackers and evaluates the broad implications for US national security, ranging from leaked classified information to threats against critical infrastructure. The paper concludes with practical recommendations for government agencies and private organizations to improve software vetting, anomaly investigation, and adversarial security testing.
- Introduction: National security implications of the SolarWinds breach
- Background: SolarWinds and the Orion Platform: Company profile and why Orion was targeted
- How the Attack Took Place: SUNBURST delivery, dormant code, and backdoor access
- The Victims of the Attack: Federal agencies and 18,000+ customers compromised
- Purpose of the Hack and Zero-Day Security: Attacker motives and zero-day vulnerability exploitation
- Potential Implications for US National Security: Risks to classified data, infrastructure, and defense
- Recommendations and Conclusion: Software vetting, anomaly investigation, and adversarial testing
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- The paper moves logically from technical background to impact analysis, making complex cybersecurity concepts accessible to a general academic audience without oversimplifying them.
- It draws clear connections between the technical mechanics of the attack — dormant code, spoofed authentication, supply-chain delivery — and broader geopolitical and national security consequences.
- The recommendations section adds practical value by proposing concrete policy and procedural changes, grounding the analysis in actionable outcomes rather than stopping at description.
Key academic technique demonstrated
The paper demonstrates effective use of causal reasoning across sections: it establishes what happened technically, then systematically traces the chain of consequences — from agency-level data exposure to potential nuclear and presidential security risks — supporting each step with cited sources. This layered cause-and-effect structure is a strong model for policy-focused security analysis papers.
Structure breakdown
The paper opens with a thesis-level introduction summarizing national security implications, then provides company and product background before walking through the attack chronology. Subsequent sections cover victims, attacker intent, zero-day mechanics, and escalating national security scenarios. The final section pivots to recommendations, closing the analytical loop from problem identification to proposed solutions. This introduction-analysis-recommendation arc is typical of undergraduate security policy papers.
Introduction
The implications of the SolarWinds hack for US national security include foreign actors' ability to disrupt essential infrastructure assets within the United States. These assets include oil and gas pipelines, electrical grids, and the defense sector. Foreign actors can misuse personal data through malware, spyware, and other advanced tools, resulting in extortion and ransomware campaigns. These implications are both tangible and intangible. Tangible elements include interruptions of infrastructure (e.g., communication, food distribution, power grids, and transportation), industry (e.g., aerospace, biomedical, healthcare, and waste management), and utilities (e.g., gas, electric, sewage, and water). Intangible implications include the erosion of consumer confidence in everything from online retail to election integrity.
Background: SolarWinds and the Orion Platform
The SolarWinds hack was significant because it affected thousands of organizations, including the United States government.1 SolarWinds is a software company based in Tulsa, Oklahoma, that offers system management tools for infrastructure and network monitoring. One of the company's performance monitoring systems is called Orion. Orion had privileged access to IT systems, obtaining their system logs and performance data. The privileged position held by Orion and its broad deployment across networks made it an attractive target for hackers.2
Using the Orion system, hackers managed to gain access to thousands of SolarWinds customers' systems, networks, and data. The attack is one of the largest supply-chain attacks ever recorded. Over 30,000 private and public organizations use the Orion network management system to manage their IT resources. The public organizations include local, state, and federal agencies.
How the Attack Took Place
The attack began in early 2020 but was not discovered until nearly the end of that year.3 The attackers were patient, and the nature of the attack suggests they targeted multiple entities simultaneously. SolarWinds Orion had advised its customers to exclude the software from antivirus and endpoint detection and response (EDR) monitoring. Because of this exclusion, the attackers were able to access the network and data of victims without detection, since their attack relied upon — and behaved like — a legitimate Orion system. The attackers launched multiple lines of access, control, and communication from within the Orion monitoring system.
The hack may have originated from a GitHub misconfiguration error.4 Server credentials were exposed in a public repository, which set the stage for the attack. Once the hackers obtained those credentials, they added malicious code to the Orion software and waited for SolarWinds to push the update to its customers. The attackers created a digital signature and certification similar to the one used by Orion to mask their Trojan malware. After the code was installed on a victim's computer, it remained dormant for two weeks before beginning to scan the environment to confirm no malware monitoring systems were active.5 Once the coast was clear, the malware made its initial connection to a remote server, masking itself as genuine network traffic. The malware was hiding in plain sight, and no one recognized or flagged the traffic it generated. The code then allowed the hackers to open additional backdoors and gain access to companies and organizations across the network.6
Remote access enabled the hackers to copy data, emails, and other network traffic without triggering alerts.
References
Datta, P. (2021). Hannibal at the gates: Cyberwarfare & the SolarWinds sunburst hack. Journal of Information Technology Teaching Cases, 2043886921993126.
FireEye. (2020). Highly evasive attacker leverages SolarWinds supply chain to compromise multiple global victims with SUNBURST backdoor.
Mar, S. (2021). The aftermath of SolarWinds. The Internal Auditor, 18–18.
Massacci, F., Jaeger, T., & Peisert, S. (2021). SolarWinds and the challenges of patching: Can we ever stop dancing with the devil? IEEE Security & Privacy, 19(02), 14–19.
Shlapentokh-Rothman, M., Kelly, J., Baral, A., Hemberg, E., & O'Reilly, U.-M. (2021). Coevolutionary modeling of cyber attack patterns and mitigations using public datasets. Proceedings of the Genetic and Evolutionary Computation Conference.
Wolff, E. D., Crowley, K. M., & Gruden, M. G. (2021). Navigating the SolarWinds supply chain attack.
Always verify citation format against your institution’s current style guide requirements.