paper-with-me

Papers

Learning the Associations of MITRE ATT&CK Adversarial Techniques

2020-04-16 · Rawan Al-Shaer, Jonathan M. Spring, Eliana Christou

The MITRE ATT&CK Framework provides a rich and actionable repository of adversarial tactics, techniques, and procedures (TTP). However, this information would be highly useful for attack diagnosis (i.e., forensics) and mitigation (i.e., intrusion response) if we can reliably construct technique associations that will enable predicting unobserved attack techniques based on observed ones. In this paper, we present our statistical machine learning analysis on APT and Software attack data reported by MITRE ATT&CK to infer the technique clustering that represents the significant correlation that can be used for technique prediction. Due to the complex multidimensional relationships between techniques, many of the traditional clustering methods could not obtain usable associations. Our approach, using hierarchical clustering for inferring attack technique associations with 95% confidence, provides statistically significant and explainable technique correlations. Our analysis discovers 98 different technique associations (i.e., clusters) for both APT and Software attacks. Our evaluation results show that 78% of the techniques associated by our algorithm exhibit significant mutual information that indicates reasonably high predictability.

📄 PDF Abstract BibTeX arXiv:2005.01654

Code (0)

등록된 구현이 없습니다.

Tasks

Clustering

Similar Papers 제목 키워드 기반

SynthCTI: LLM-Driven Synthetic CTI Generation to enhance MITRE Technique Mapping

2025-07-21 · Álvaro Ruiz-Ródenas, Jaime Pujante Sáez, Daniel García-Algora, Mario Rodríguez Béjar 외 arxiv

Cyber Threat Intelligence (CTI) mining involves extracting structured insights from unstructured threat data, enabling organizations to understand and respond to evolving adversarial behavior. A key task in CTI mining is…

Data Augmentation

Machine Learning Based Approach to Recommend MITRE ATT&CK Framework for Software Requirements and Design Specifications

2023-02-10 · Nicholas Lasky, Benjamin Hallis, Mounika Vanamala, Rushit Dave 외

Engineering more secure software has become a critical challenge in the cyber world. It is very important to develop methodologies, techniques, and tools for developing secure software. To develop secure software, softwa…

Decision Making

MITRE ATT&CK Applications in Cybersecurity and The Way Forward

2025-02-15 · Yuning Jiang, Qiaoran Meng, Feiyang Shang, Nay Oo 외

The MITRE ATT&CK framework is a widely adopted tool for enhancing cybersecurity, supporting threat intelligence, incident response, attack modeling, and vulnerability prioritization. This paper synthesizes research on it…

Network Defense is Not a Game

2021-04-20 · Andres Molina-Markham, Ransom K. Winder, Ahmad Ridley

Research seeks to apply Artificial Intelligence (AI) to scale and extend the capabilities of human operators to defend networks. A fundamental problem that hinders the generalization of successful AI approaches -- i.e., …

reinforcement-learningReinforcement Learning (RL)

AnnoCTR: A Dataset for Detecting and Linking Entities, Tactics, and Techniques in Cyber Threat Reports

2024-04-11 · Lukas Lange, Marc Müller, Ghazaleh Haratinezhad Torbati, Dragan Milchevski 외

Monitoring the threat landscape to be aware of actual or potential attacks is of utmost importance to cybersecurity professionals. Information about cyber threats is typically distributed using natural language reports. …

Data Augmentation