论文标题

对安全控制和MITER ATT \&CK技术的调查

An investigation of security controls and MITRE ATT\&CK techniques

论文作者

Rahman, Md Rayhanur, Williams, Laurie

论文摘要

攻击者利用网络攻击中的大量对抗技术来损害目标组织和系统的机密性,完整性和可用性。 ISO/IEC等信息安全标准(例如NIST)指定了数百个安全控制,组织可以强制执行保护和捍卫信息系统免受对抗技术的影响。但是,同时实施所有可用的控件可能是不可行的,并且还需要根据其对网络攻击中使用的对抗技术的缓解能力进行调查。这项研究的目的是帮助组织通过调查当前网络攻击中使用的对抗技术来对安全控制做出明智的选择,以防御网络危机。在这项研究中,我们调查了298个NIST SP800-53对照的缓解程度,超过了669个网络犯罪组中使用的188个对抗技术,并且基于对控件和技术之间的现有映射,在斜切ATT \&CK框架中分类的恶意软件。我们确定,根据映射,只有298个控制中只有101个能够减轻对抗技术。但是,我们还确定,任何现有控制措施都无法减轻53种对抗技术,并且这些技术主要帮助对手绕过系统辩护并发现目标系统信息。我们确定了一组20个关键控制,可以减轻134种对抗技术,平均而言,可以减轻98%\%用斜切对手使用的所有技术中的72%\%。我们敦促没有执行任何控制权的组织,以实施研究中确定的最高控制。

Attackers utilize a plethora of adversarial techniques in cyberattacks to compromise the confidentiality, integrity, and availability of the target organizations and systems. Information security standards such as NIST, ISO/IEC specify hundreds of security controls that organizations can enforce to protect and defend the information systems from adversarial techniques. However, implementing all the available controls at the same time can be infeasible and security controls need to be investigated in terms of their mitigation ability over adversarial techniques used in cyberattacks as well. The goal of this research is to aid organizations in making informed choices on security controls to defend against cyberthreats through an investigation of adversarial techniques used in current cyberattacks. In this study, we investigated the extent of mitigation of 298 NIST SP800-53 controls over 188 adversarial techniques used in 669 cybercrime groups and malware cataloged in the MITRE ATT\&CK framework based upon an existing mapping between the controls and techniques. We identify that, based on the mapping, only 101 out of 298 control are capable of mitigating adversarial techniques. However, we also identify that 53 adversarial techniques cannot be mitigated by any existing controls, and these techniques primarily aid adversaries in bypassing system defense and discovering targeted system information. We identify a set of 20 critical controls that can mitigate 134 adversarial techniques, and on average, can mitigate 72\% of all techniques used by 98\% of the cataloged adversaries in MITRE ATT\&CK. We urge organizations, that do not have any controls enforced in place, to implement the top controls identified in the study.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源