TY - JOUR
T1 - Analysis and Characterization of Cyber Threats Leveraging the MITRE ATT&CK Database
AU - Al-Sada, Bader
AU - Sadighian, Alireza
AU - Oligeri, Gabriele
N1 - Publisher Copyright:
© 2013 IEEE.
PY - 2024/12/18
Y1 - 2024/12/18
N2 - MITRE ATT&CK is a comprehensive knowledge-base of adversary tactics, techniques, and procedures (TTP) based on real-world attack scenarios. It has been used in different sectors, such as government, academia, and industry, as a foundation for threat modeling, risk assessment, and defensive strategies. There are valuable insights within MITRE ATT&CK knowledge-base that can be applied to various fields and applications, such as risk assessment, threat characterization, and attack modeling. No previous work has been devoted to the comprehensive collection and investigation of statistical insights of the MITRE ATT&CK dataset. Hence, this work aims to extract, analyze, and represent MITRE ATT&CK statistical insights providing valuable recommendations to improve the security aspects of Enterprise, Industrial Control Systems (ICS), and mobile digital infrastructures. For this purpose, we conduct a hierarchical analysis starting from MITRE ATT&CK threat profiles toward the list of techniques in the MITRE ATT&CK database. Finally, we summarize our key findings while providing recommendations that will pave the way for future research in the area.
AB - MITRE ATT&CK is a comprehensive knowledge-base of adversary tactics, techniques, and procedures (TTP) based on real-world attack scenarios. It has been used in different sectors, such as government, academia, and industry, as a foundation for threat modeling, risk assessment, and defensive strategies. There are valuable insights within MITRE ATT&CK knowledge-base that can be applied to various fields and applications, such as risk assessment, threat characterization, and attack modeling. No previous work has been devoted to the comprehensive collection and investigation of statistical insights of the MITRE ATT&CK dataset. Hence, this work aims to extract, analyze, and represent MITRE ATT&CK statistical insights providing valuable recommendations to improve the security aspects of Enterprise, Industrial Control Systems (ICS), and mobile digital infrastructures. For this purpose, we conduct a hierarchical analysis starting from MITRE ATT&CK threat profiles toward the list of techniques in the MITRE ATT&CK database. Finally, we summarize our key findings while providing recommendations that will pave the way for future research in the area.
KW - Advanced persistent threat
KW - Cyber security
KW - Cyber threat analysis
KW - Cyber threat intelligence
KW - Mitre att&ck
UR - http://www.scopus.com/inward/record.url?scp=85181580017&partnerID=8YFLogxK
U2 - 10.1109/ACCESS.2023.3344680
DO - 10.1109/ACCESS.2023.3344680
M3 - Article
AN - SCOPUS:85181580017
SN - 2169-3536
VL - 12
SP - 1217
EP - 1234
JO - IEEE Access
JF - IEEE Access
ER -