Enhancing the STIX Representation of MITRE ATT&CK for Group Filtering and Technique Prioritization
Autor: | Mateusz Zych, Vasileios Mavroeidis |
---|---|
Rok vydání: | 2022 |
Předmět: | |
Zdroj: | European Conference on Cyber Warfare and Security. 21:385-391 |
ISSN: | 2048-8610 2048-8602 |
DOI: | 10.34190/eccws.21.1.349 |
Popis: | In this paper, we enhance the machine-readable representation of the ATT&CK Groups knowledge base provided by MITRE in STIX 2.1 format to make available and queryable additional types of contextual information. Such information includes the motivations of activity groups, the countries they have originated from, and the sectors and countries they have targeted. We demonstrate how to utilize the enhanced model to construct intelligible queries to filter activity groups of interest and retrieve relevant tactical intelligence. |
Databáze: | OpenAIRE |
Externí odkaz: |