Published August 23, 2022 | Version v1

MITRE ATT&CK-driven Cyber Risk Assessment

  • 1. University of Greenwich, United Kingdom
  • 2. University of Piraeus, Greece

Description

Assessing the risk posed by Advanced Cyber Threats (APTs) is challenging without understanding the methods and tactics adversaries use to attack an organisation. The MITRE ATT&CK provides information on the motivation, capabilities, interests and tactics, techniques and procedures (TTPs) used by threat actors. In this paper, we leverage these characteristics of threat actors to support informed cyber risk characterisation and assessment. In particular, we utilise the MITRE repository of known adversarial TTPs along with attack graphs to determine the attack probability as well as the likelihood of success of an attack. We further identify attack paths with the highest likelihood of success considering the techniques and procedures of a threat actor. The assessment is supported by a case study of a health care organisation to identify the level of risk against two adversary groups– Lazarus and menuPass.

Files

ahmed2022MITRE (1).pdf

Files (1.1 MB)

Name Size Download all
md5:026831cf84c30c72b3050a0d6625a192
1.1 MB Preview Download

Additional details

Funding

European Commission
SECONDO - a Security ECONomics service platform for smart security investments and cyber insurance pricing in the beyonD 2020 netwOrking era 823997
European Commission
CyberSec4Europe - Cyber Security Network of Competence Centres for Europe 830929