<p>Threat modeling based on attack graphs can be used to understand and evaluate system security, and has become an important means of enterprise system security protection. However, existing approaches suffer from several major drawbacks: (a) insufficient automation and extensibility, (b) insufficient coverage of the generated attack graph for threats, and (c) incomplete threat analysis. Therefore, we are motivated to propose an approach for generating attack graphs and analyzing threats. First, we design an automatic attack graph generation model based on Common Attack Pattern Enumeration and Classification (CAPEC) and MITRE ATT&amp;CK Matrix. The model is implemented using the Meta Attack Language to ensure the extensibility of model rules. Second, we use the attack chain analysis method to construct the automatic generation model, and map the attack patterns, techniques and tactics involved in the attack chain to the corresponding attack patterns in CAPEC and ATT&amp;CK framework, so as to improve the coverage of the generated attack graph to threats. Third, we propose an approach for attack path analysis. The process of this approach includes attack graph structure optimization, node evaluation, attack simulation and mitigation measure generation, which can infer a list of attack paths sorted by risk degree. A tool supporting the approach is also proposed. This paper evaluates the proposed approach and tool through illustrative exemplars and comparative studies. The results show that this approach can effectively support users to threat modeling for large systems, and attack graph analysis results can assist enterprise users to make effective security decisions.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An approach to generating attack graphs and analyzing threats based on CAPEC and ATT&CK matrix

  • Changlan Fu,
  • He Zhang,
  • Yaochen Zhou

摘要

Threat modeling based on attack graphs can be used to understand and evaluate system security, and has become an important means of enterprise system security protection. However, existing approaches suffer from several major drawbacks: (a) insufficient automation and extensibility, (b) insufficient coverage of the generated attack graph for threats, and (c) incomplete threat analysis. Therefore, we are motivated to propose an approach for generating attack graphs and analyzing threats. First, we design an automatic attack graph generation model based on Common Attack Pattern Enumeration and Classification (CAPEC) and MITRE ATT&CK Matrix. The model is implemented using the Meta Attack Language to ensure the extensibility of model rules. Second, we use the attack chain analysis method to construct the automatic generation model, and map the attack patterns, techniques and tactics involved in the attack chain to the corresponding attack patterns in CAPEC and ATT&CK framework, so as to improve the coverage of the generated attack graph to threats. Third, we propose an approach for attack path analysis. The process of this approach includes attack graph structure optimization, node evaluation, attack simulation and mitigation measure generation, which can infer a list of attack paths sorted by risk degree. A tool supporting the approach is also proposed. This paper evaluates the proposed approach and tool through illustrative exemplars and comparative studies. The results show that this approach can effectively support users to threat modeling for large systems, and attack graph analysis results can assist enterprise users to make effective security decisions.