/* ---- Google Analytics Code Below */
Showing posts with label MITRE. Show all posts
Showing posts with label MITRE. Show all posts

Friday, November 25, 2022

MITRE Attack Framework

 When I worked with the Govt in the past, worked with MITRE,  impressive overall. I noted this recent introduction to their 'Threat actors' capability.  (which I did not use at the time).   Of interest. 

Introduction to MITRE ATT&CK - Featuring Version 12 (2022)

Josh Darby MacLellan, on Nov 22, 2022

Have you ever wondered how to create a prioritized list of threat actors? Or identify what malicious tactics and techniques are most relevant? Or what security controls should be improved first? The MITRE ATT&CK Framework can help. Version 12 has just been released and this blog will help you understand what the Framework is and what’s new.

What is MITRE?

MITRE is a US-based not-for-profit organization that supports the US federal government in advancing national security by providing a range of technical, cyber, and engineering services to the government. In 2013, MITRE launched a research project to track cyber threat actors’ behavior, developing a framework named Adversarial Tactics, Techniques, and Common Knowledge, or in short form: ATT&CK.

What is the MITRE ATT&CK Framework?

The MITRE ATT&CK Framework contains a taxonomy of threat actor behavior during an attack lifecycle, broken down into 14 tactics that each contain a subset of more specific techniques and sub-techniques (covering the TT in TTPs). The Framework is split into three separate matrices, Enterprise (attacks against enterprise IT networks and cloud), Mobile (attacks targeting mobile devices), and industrial control systems (attacks targeting ICS).

The Framework contains a wealth of knowledge based on real-world observations. To give you an indication of scope, the October 2022 iteration of ATT&CK for Enterprise contains 193 techniques, 401 sub-techniques, 135 threat actor groups, 14 campaigns, and 718 pieces of software/malware.

Screenshot of the MITRE ATT&CK Framework for Enterprise with some but not all techniques.

Each technique can be explored to reveal sub-techniques and there is an entire MITRE knowledge base that feeds the matrices. This database contains a colossal amount of information on threat actor groups, malware, campaigns, descriptions of techniques and sub-techniques, mitigations, detection strategies, references for external resources, an ID system for tracking, and more.   ... ' 

Wednesday, March 23, 2022

MITR Examines Attack Threat Techniques

 In the past worked with Mitre corp to support US Defense systems, here they offer a white paper on threat detection and related practical use cases.  

Using MITRE ATT&CK™ Techniques in Threat Hunting and Detection

A Preface to the MITRE ATT&CK™ Framework and Practical Use Cases

Prioritizing Threats

How do you prioritize the many threats to your organization? How do you address them with the tools you already have?

MITRE ATT&CK Framework

MITRE ATT&CK, an open framework and knowledge base of adversary tactics and techniques based on real-world observations, provides a structured method to help you answer these questions.

Understand Your Adversaries 

ATT&CK is a powerful way to classify and study adversary techniques and understand their intent. You can use it to enhance, analyze, and test your threat hunting and detection efforts.

What You Will Learn in This Whitepaper: 

The structure of ATT&CK, comprising tactics, techniques, examples, mitigation, and detection

How to use ATT&CK to assess, enhance, and test your monitoring, threat detection, and threat hunting efforts How to apply five common MITRE ATT&CK techniques in your threat detection and hunting practice

Saturday, April 10, 2021

Snythetic Data in Medical Research

Sounds like a bad idea, but you can use the idea of synthetic data to construct innovative models as starting points for serious research.   We did this to understand how product sold in mock stores,  then moved the models to real stores.   It often gave us real insight to the data and its use.  I remember working with Mitre years ago and even then they used the concept of mock data contexts.  Always can be a good way to think through model data design. We did not do enough of it. 

The People in This Medical Research Are Fake. The Innovations Are Real.  By Dov Lieber, April 6, 2021, The Wall Street Journal 

Medical researchers and data scientists are generating artificial patients algorithmically from real-life datasets to accelerate the development of innovations with real-world applications. Allan Tucker at the U.K.'s Brunel University London said, "The key advantage that synthetic data offers for healthcare is a large reduction in privacy risks that have bugged numerous projects [and] to open up healthcare data for the research and development of new technologies." The Covid-19 pandemic fueled demand for synthetic-data solutions as medical providers and researchers raced to understand the pathogen and develop treatments. Israel is a major testbed, using the MDClone startup's platform for creating synthetic data from medical records, for example. Not all synthetic-data research relies on real-life medical records: U.S. nonprofit Mitre's open source Synthea tool can generate populations of artificial patients from scratch, using publicly available data sources.  ... ' 

Tuesday, October 27, 2020

Deception and Concealment Technology

Worked with MITRE way back.  Now it is also about active defense.  Not much revealed here, but its interesting. 

MITRE Shield Matrix Highlights Deception & Concealment Technology

The role that these technologies play in the MITRE Shield matrix is a clear indicator that they are an essential part of today's security landscape.

It's an age-old question: How do you know if you need more security? MITRE has been diligently working to document tactics and techniques to assess security readiness and answer this very challenging question. In late August, MITRE, a nonprofit organization, released a new knowledge matrix, called MITRE Shield, to complement the ATT&CK matrix.

The organization called it "an active defense knowledge base MITRE is developing to capture and organize what we are learning about active defense and adversary engagement." With its focus on active defense measures, MITRE designed Shield to help defenders understand their cybersecurity options and take proactive steps to defend their assets. Among the most common active defense techniques are cyber-deception and concealment technologies, which are featured heavily in the new Shield matrix.  ... "