MITRE ATT&CK: State of the Art and Way Forward

被引:1
|
作者
Al-sada, Bader [1 ]
Sadighian, Alireza [1 ]
Oligeri, Gabriele [1 ]
机构
[1] Hamad Bin Khalifa Univ, Qatar Fdn, Coll Sci & Engn, Div Informat & Comp Technol, Doha, Qatar
关键词
MITRE ATT&CK framework; cyber-threat intelligence; security risk analysis; FRAMEWORK;
D O I
10.1145/3687300
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
MITRE ATT&CK is a comprehensive framework of adversary tactics, techniques, and procedures based on real-world observations. It has been used as a foundation for threat modeling in different sectors, such as government, academia, and industry. To the best of our knowledge, no previous work has been devoted to the comprehensive collection, study, and investigation of the current state of the art leveraging the MITRE ATT&CK framework. We select and inspect more than 50 major research contributions, while conducting a detailed analysis of their methodology and objectives in relation to the MITRE ATT&CK framework. We provide a categorization of the identified papers according to different criteria such as use cases, application scenarios, adopted methodologies, and the use of additional data. Finally, we discuss open issues and future research directions involving not only the MITRE ATT&CK framework but also the fields of threat analysis, threat modeling, and in general cyber-threat intelligence.
引用
收藏
页数:37
相关论文
共 50 条
  • [1] Introduction to MITRE ATT&CK: Concepts and Use Cases
    Son, Seok Bin
    Park, Soohyun
    Lee, Haemin
    Kim, Youngkee
    Kim, Dongwan
    Kim, Joongheon
    2023 INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING, ICOIN, 2023, : 158 - 161
  • [2] Linking CVE's to MITRE ATT&CK Techniques
    Kuppa, Aditya
    Aouad, Lamine
    Nhien-An Le-Khac
    ARES 2021: 16TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, 2021,
  • [3] Exploring the MITRE ATT&CK® Matrix in SE Education
    Bleiman, Rachel
    Williams, Jamie
    Rege, Aunshul
    Williams, Katorah
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON CYBERSECURITY, SITUATIONAL AWARENESS AND SOCIAL MEDIA, CYBER SCIENCE 2022, 2023, : 133 - 149
  • [4] Learning the Associations of MITRE ATT&CK Adversarial Techniques
    Al-Shaer, Rawan
    Spring, Jonathan M.
    Christou, Eliana
    2020 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2020,
  • [5] How does Endpoint Detection use the MITRE ATT&CK Framework?
    Virkud, Apurva
    Inam, Muhammad Adil
    Riddle, Andy
    Liu, Jason
    Wang, Gang
    Bates, Adam
    PROCEEDINGS OF THE 33RD USENIX SECURITY SYMPOSIUM, SECURITY 2024, 2024, : 3891 - 3908
  • [6] Cyberattack Models for Ship Equipment Based on the MITRE ATT&CK Framework
    Jo, Yonghyun
    Choi, Oongjae
    You, Jiwoon
    Cha, Youngkyun
    Lee, Dong Hoon
    SENSORS, 2022, 22 (05)
  • [7] Labeling NIDS Rules with MITRE ATT&CK Techniques Using ChatGPT
    Daniel, Nir
    Kaiser, Florian Klaus
    Dzega, Anton
    Elyashar, Aviad
    Puzis, Rami
    COMPUTER SECURITY. ESORICS 2023 INTERNATIONAL WORKSHOPS, CPS4CIP, PT II, 2024, 14399 : 76 - 91
  • [8] CVE2ATT&CK: BERT-Based Mapping of CVEs to MITRE ATT&CK Techniques
    Grigorescu, Octavian
    Nica, Andreea
    Dascalu, Mihai
    Rughinis, Razvan
    ALGORITHMS, 2022, 15 (09)
  • [9] Analysis and Characterization of Cyber Threats Leveraging the MITRE ATT&CK Database
    Al-Sada, Bader
    Sadighian, Alireza
    Oligeri, Gabriele
    IEEE ACCESS, 2024, 12 : 1217 - 1234
  • [10] Assessing Cyber Risks of an INS Using the MITRE ATT&CK Framework
    Oruc, Aybars
    Amro, Ahmed
    Gkioulos, Vasileios
    SENSORS, 2022, 22 (22)