Georgiadou Anna, Mouzakitis Spiros, Askounis Dimitris
Decision Support Systems Laboratory, National Technical University of Athens, Iroon Polytechniou 9, 15780 Zografou, Greece.
Sensors (Basel). 2021 May 9;21(9):3267. doi: 10.3390/s21093267.
The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) Framework provides a rich and actionable repository of adversarial tactics, techniques, and procedures. Its innovative approach has been broadly welcomed by both vendors and enterprise customers in the industry. Its usage extends from adversary emulation, red teaming, behavioral analytics development to a defensive gap and SOC (Security Operations Center) maturity assessment. While extensive research has been done on analyzing specific attacks or specific organizational culture and human behavior factors leading to such attacks, a holistic view on the association of both is currently missing. In this paper, we present our research results on associating a comprehensive set of organizational and individual culture factors (as described on our developed cyber-security culture framework) with security vulnerabilities mapped to specific adversary behavior and patterns utilizing the MITRE ATT&CK framework. Thus, exploiting MITRE ATT&CK's possibilities towards a scientific direction that has not yet been explored: security assessment and defensive design, a step prior to its current application domain. The suggested cyber-security culture framework was originally designed to aim at critical infrastructures and, more specifically, the energy sector. Organizations of these domains exhibit a co-existence and strong interaction of the IT (Information Technology) and OT (Operational Technology) networks. As a result, we emphasize our scientific effort on the hybrid MITRE ATT&CK for Enterprise and ICS (Industrial Control Systems) model as a broader and more holistic approach. The results of our research can be utilized in an extensive set of applications, including the efficient organization of security procedures as well as enhancing security readiness evaluation results by providing more insights into imminent threats and security risks.
MITRE ATT&CK(对抗战术、技术和常识)框架提供了一个丰富且可操作的对抗战术、技术和程序知识库。其创新方法受到了行业内供应商和企业客户的广泛欢迎。其用途涵盖从对手模拟、红队测试、行为分析开发到防御差距和安全运营中心(SOC)成熟度评估等方面。虽然已经对分析特定攻击或导致此类攻击的特定组织文化和人类行为因素进行了广泛研究,但目前缺少对两者关联的整体看法。在本文中,我们展示了我们的研究成果,即将一套全面的组织和个人文化因素(如我们开发的网络安全文化框架中所描述的)与利用MITRE ATT&CK框架映射到特定对手行为和模式的安全漏洞相关联。因此,利用MITRE ATT&CK的可能性朝着一个尚未探索的科学方向发展:安全评估和防御设计,这是其当前应用领域之前的一个步骤。所建议的网络安全文化框架最初旨在针对关键基础设施,更具体地说是能源领域。这些领域的组织呈现出信息技术(IT)和运营技术(OT)网络的共存和强烈交互作用。因此,我们强调我们在企业和工业控制系统(ICS)混合MITRE ATT&CK模型方面的科学努力,这是一种更广泛、更全面的方法。我们的研究结果可用于广泛的应用中,包括安全程序的高效组织,以及通过提供对紧迫威胁和安全风险的更多洞察来加强安全准备评估结果。