Suppr超能文献

使用网络安全文化框架评估MITRE ATT&CK风险

Assessing MITRE ATT&CK Risk Using a Cyber-Security Culture Framework.

作者信息

Georgiadou Anna, Mouzakitis Spiros, Askounis Dimitris

机构信息

Decision Support Systems Laboratory, National Technical University of Athens, Iroon Polytechniou 9, 15780 Zografou, Greece.

出版信息

Sensors (Basel). 2021 May 9;21(9):3267. doi: 10.3390/s21093267.

Abstract

The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) Framework provides a rich and actionable repository of adversarial tactics, techniques, and procedures. Its innovative approach has been broadly welcomed by both vendors and enterprise customers in the industry. Its usage extends from adversary emulation, red teaming, behavioral analytics development to a defensive gap and SOC (Security Operations Center) maturity assessment. While extensive research has been done on analyzing specific attacks or specific organizational culture and human behavior factors leading to such attacks, a holistic view on the association of both is currently missing. In this paper, we present our research results on associating a comprehensive set of organizational and individual culture factors (as described on our developed cyber-security culture framework) with security vulnerabilities mapped to specific adversary behavior and patterns utilizing the MITRE ATT&CK framework. Thus, exploiting MITRE ATT&CK's possibilities towards a scientific direction that has not yet been explored: security assessment and defensive design, a step prior to its current application domain. The suggested cyber-security culture framework was originally designed to aim at critical infrastructures and, more specifically, the energy sector. Organizations of these domains exhibit a co-existence and strong interaction of the IT (Information Technology) and OT (Operational Technology) networks. As a result, we emphasize our scientific effort on the hybrid MITRE ATT&CK for Enterprise and ICS (Industrial Control Systems) model as a broader and more holistic approach. The results of our research can be utilized in an extensive set of applications, including the efficient organization of security procedures as well as enhancing security readiness evaluation results by providing more insights into imminent threats and security risks.

摘要

MITRE ATT&CK(对抗战术、技术和常识)框架提供了一个丰富且可操作的对抗战术、技术和程序知识库。其创新方法受到了行业内供应商和企业客户的广泛欢迎。其用途涵盖从对手模拟、红队测试、行为分析开发到防御差距和安全运营中心(SOC)成熟度评估等方面。虽然已经对分析特定攻击或导致此类攻击的特定组织文化和人类行为因素进行了广泛研究,但目前缺少对两者关联的整体看法。在本文中,我们展示了我们的研究成果,即将一套全面的组织和个人文化因素(如我们开发的网络安全文化框架中所描述的)与利用MITRE ATT&CK框架映射到特定对手行为和模式的安全漏洞相关联。因此,利用MITRE ATT&CK的可能性朝着一个尚未探索的科学方向发展:安全评估和防御设计,这是其当前应用领域之前的一个步骤。所建议的网络安全文化框架最初旨在针对关键基础设施,更具体地说是能源领域。这些领域的组织呈现出信息技术(IT)和运营技术(OT)网络的共存和强烈交互作用。因此,我们强调我们在企业和工业控制系统(ICS)混合MITRE ATT&CK模型方面的科学努力,这是一种更广泛、更全面的方法。我们的研究结果可用于广泛的应用中,包括安全程序的高效组织,以及通过提供对紧迫威胁和安全风险的更多洞察来加强安全准备评估结果。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/c165/8125987/7372b60cd29c/sensors-21-03267-g001.jpg

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验