paper-with-me

홈 › Papers

MITRE ATT&CK Applications in Cybersecurity and The Way Forward

2025-02-15 · Yuning Jiang, Qiaoran Meng, Feiyang Shang, Nay Oo, Le Thi Hong Minh, Hoon Wei Lim, Biplab Sikdar

The MITRE ATT&CK framework is a widely adopted tool for enhancing cybersecurity, supporting threat intelligence, incident response, attack modeling, and vulnerability prioritization. This paper synthesizes research on its application across these domains by analyzing 417 peer-reviewed publications. We identify commonly used adversarial tactics, techniques, and procedures (TTPs) and examine the integration of natural language processing (NLP) and machine learning (ML) with ATT&CK to improve threat detection and response. Additionally, we explore the interoperability of ATT&CK with other frameworks, such as the Cyber Kill Chain, NIST guidelines, and STRIDE, highlighting its versatility. The paper further evaluates the framework from multiple perspectives, including its effectiveness, validation methods, and sector-specific challenges, particularly in industrial control systems (ICS) and healthcare. We conclude by discussing current limitations and proposing future research directions to enhance the applicability of ATT&CK in dynamic cybersecurity environments.

📄 PDF Abstract BibTeX arXiv:2502.10825

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

MITRE-SAGE: A Multi-Agent Cybersecurity Question-Answering Model

2026-08-03 · Ali Habibzadeh, Farid Feyzi, Reza Ebrahimi Atani arxiv

Effective cybersecurity operations require timely and accurate analysis of large-scale heterogeneous security information; however, analysts increasingly struggle with information overload, alert fatigue, and time-constr…

Question Answering

AnnoCTR: A Dataset for Detecting and Linking Entities, Tactics, and Techniques in Cyber Threat Reports

2024-04-11 · Lukas Lange, Marc Müller, Ghazaleh Haratinezhad Torbati, Dragan Milchevski 외

Monitoring the threat landscape to be aware of actual or potential attacks is of utmost importance to cybersecurity professionals. Information about cyber threats is typically distributed using natural language reports. …

Data Augmentation

Constructing Multi-label Hierarchical Classification Models for MITRE ATT&CK Text Tagging

2026-01-21 · Andrew Crossman, Jonah Dodd, Viralam Ramamurthy Chaithanya Kumar, Riyaz Mohammed 외 arxiv

MITRE ATT&CK is a cybersecurity knowledge base that organizes threat actor and cyber-attack information into a set of tactics describing the reasons and goals threat actors have for carrying out attacks, with each tactic…

Crimson: Empowering Strategic Reasoning in Cybersecurity through Large Language Models

2024-03-01 · Jiandong Jin, Bowen Tang, Mingxuan Ma, Xiao Liu 외

We introduces Crimson, a system that enhances the strategic reasoning capabilities of Large Language Models (LLMs) within the realm of cybersecurity. By correlating CVEs with MITRE ATT&CK techniques, Crimson advances thr…

HallucinationRetrieval

CRAKEN: Cybersecurity LLM Agent with Knowledge-Based Execution

2025-05-21 · Minghao Shao, Haoran Xi, Nanda Rani, Meet Udeshi 외

Large Language Model (LLM) agents can automate cybersecurity tasks and can adapt to the evolving cybersecurity landscape without re-engineering. While LLM agents have demonstrated cybersecurity capabilities on Capture-Th…

Large Language ModelTask PlanningVulnerability Detection