News

U.S. Semiconductor Research Hub achieves key milestones in supply chain resilience

The hub's cyber test range reached initial operating capacity and is now analysing threats to semiconductor technologies, integrated circuits, and the supply chain behind them.

By Ojasvi Rana, Junior Fellow ·

U.S. Semiconductor Research Hub achieves key milestones in supply chain resilience

The U.S. Semiconductor Research Hub, led by Principal Investigators Dr. Sarah Kreps at the institute and Dr. Gregory Falco in the Aerospace Adversary Laboratory in Cornell's College of Engineering, has reached a significant milestone, achieving initial operating capacity for its cyber test range. That infrastructure is now actively analysing cybersecurity threats and vulnerabilities affecting semiconductor technologies, integrated circuits, and their supply chain.

Beyond hardware dependencies on sole-source suppliers, the intersection of software and hardware introduces further complexity. Software is integral to the design, testing, and operation of semiconductor devices, and software failures can produce hardware malfunctions, yield losses, and security vulnerabilities. A flaw in the software controlling a chip's fabrication process could result in defective products, causing financial and reputational damage to the company and carrying national security implications for end users in the aerospace and defence sector.

The cybersecurity picture complicates matters further. A semiconductor company's security posture is only as strong as its most vulnerable supplier, so a breach at a third-party vendor can become an entry point that compromises the entire chain.

Mapping the network

A major focus of the hub's research is constructing an empirical network model of the semiconductor industry. Drawing on financial datasets and supply chain records, researchers are mapping the web of cyber suppliers and identifying critical bottlenecks. The analysis uses centrality measures to pinpoint key players, community detection to understand industry clustering, and degree distribution analysis to assess systemic vulnerabilities. These insights will shape strategic supply chain interventions.

Understanding the real-world impact of cyber threats is another element of the work. Documenting past intrusions that disrupted supply chains, among them SolarWinds, CrowdStrike, and Stuxnet, provides empirical grounding for risk mitigation. From those case studies the team is developing proactive security frameworks tailored to the challenges semiconductor firms actually face.

Data and partnership

Access to high-quality supply chain data is paramount for this work, and commercially available data does not always meet the standards required. The hub is therefore establishing strategic partnerships to trace sub-suppliers at every level. We are proud to be working with a major semiconductor firm as a strategic partner on supply chain mapping and cyber risk assessment, a significant step toward resilience across the sector.

By integrating advanced threat intelligence with cybersecurity research, the hub is working to fortify the semiconductor ecosystem against emerging threats.

Ojasvi Rana is a Junior Fellow in the U.S. Semiconductor Research Hub.