Faced with the constant threat of crippling cyber-attacks by adversaries motivated by financial or geopolitical gain, Western governments are pouring significant funding into efforts to understand the threats and beef up defenses against them. An example is the work being done by the US Cybersecurity and Infrastructure Security Agency (CISA), MITRE and others, which has resulted in the MITRE ATT&CK framework (MITRE. 2015–2024. MITRE ATT&CK [1]) and the Secure Cloud Business Applications (SCuBA) Project (Cybersecurity and Infrastructure Security Agency. n.d. Secure cloud business applications (SCuBA) project [2]). MITRE describes ATT&CK as ‘a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations’. In this framework, Tactics, Techniques, and Procedures (TTPs) are patterns of activity used by threat actors. ATT&CK lists several hundred TTPs. SCuBA, on the other hand, focuses on ‘baseline policies’ that can be put in place to defend against cyber threats. As an example, a baseline policy might state that a Federal agency ‘shall not’ enable external Microsoft Teams meeting participants to request control of shared desktops. There has been an effort also to map TTPs to relevant baseline controls—in effect, to suggest which controls can mitigate each TTP threat. In this paper, we explore an approach inspired by machine translation and cross-language information retrieval to automate the process of this type of mapping, both saving labor and potentially enhancing possibilities for cyber defense ( https://attack.mitre.org/techniques/enterprise/ ).

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Recommending Defenses Against Cyber Threats: An Approach Inspired by Machine Translation

  • Peter A. Chew

摘要

Faced with the constant threat of crippling cyber-attacks by adversaries motivated by financial or geopolitical gain, Western governments are pouring significant funding into efforts to understand the threats and beef up defenses against them. An example is the work being done by the US Cybersecurity and Infrastructure Security Agency (CISA), MITRE and others, which has resulted in the MITRE ATT&CK framework (MITRE. 2015–2024. MITRE ATT&CK [1]) and the Secure Cloud Business Applications (SCuBA) Project (Cybersecurity and Infrastructure Security Agency. n.d. Secure cloud business applications (SCuBA) project [2]). MITRE describes ATT&CK as ‘a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations’. In this framework, Tactics, Techniques, and Procedures (TTPs) are patterns of activity used by threat actors. ATT&CK lists several hundred TTPs. SCuBA, on the other hand, focuses on ‘baseline policies’ that can be put in place to defend against cyber threats. As an example, a baseline policy might state that a Federal agency ‘shall not’ enable external Microsoft Teams meeting participants to request control of shared desktops. There has been an effort also to map TTPs to relevant baseline controls—in effect, to suggest which controls can mitigate each TTP threat. In this paper, we explore an approach inspired by machine translation and cross-language information retrieval to automate the process of this type of mapping, both saving labor and potentially enhancing possibilities for cyber defense ( https://attack.mitre.org/techniques/enterprise/ ).