Abstract
Cybersecurity intelligence involves gathering and analyzing data to understand cyber adversaries’ capabilities, intentions, and behaviors to establish adequate security measures. The MITRE ATT&CK framework is valuable for gaining insight into cyber threats since it details attacker tactics, techniques, and procedures. However, to fully understand an attacker’s behavior, it is necessary to connect individual tactics. In this context, Process Mining (PM) can be used to analyze runtime events from information systems, thereby discovering causal relations between those events. This article presents a novel approach combining Process Mining with the MITRE ATT&CK framework to discover process models of different attack strategies. Our approach involves mapping low-level system events to corresponding event labels from the MITRE ATT&CK taxonomy, increasing the abstraction level for attacker profiling. We demonstrate the effectiveness of our approach using real datasets of human and automated (malware) behavior. This exploration helps to develop more efficient and adaptable security strategies to combat current cyber threats and provides valuable guidelines for future research.
Publisher
Sociedade Brasileira de Computacao - SB
Reference40 articles.
1. Aslan, O. and Samet, R. (2020). A comprehensive review on malware detection approaches. IEEE Access, 8:6249-6271. DOI: 10.1109/ACCESS.2019.2963724.
2. Azzini, A., Braghin, C., Damiani, E., and Zavatarelli, F. (2013). Using semantic lifting for improving process mining: a data loss prevention system case study. In Proc. of the 3rd Intl. Symp. on Data-driven Process Discovery and Analysis, volume 1027 of CEUR Workshop Proceedings, pages 62-73. CEUR-WS.org. Available online [link].
3. Berady, A., Jaume, M., Triem Tong, V. V., and Guette, G. (2022). Pwnjutsu: A dataset and a semantics-driven approach to retrace attack campaigns. IEEE Transactions on Network and Service Management, 19(4):5252-5264. DOI: 10.1109/TNSM.2022.3183476.
4. Center, C. S. R. (2015). Cyber attack: Definition. Available online [link].
5. Charter, B. (2008). EVTX and Windows EventLogging. Technical report, SANS Institute. Available online [link].