Current Challenges of Cyber Threat and Vulnerability Identification Using Public Enumerations
Luk\'a\v{s} Sadlek, Pavel \v{C}eleda, Daniel Tovar\v{n}\'ak

TL;DR
This paper reviews current challenges in cyber threat and vulnerability identification using public enumerations, highlighting issues in asset discovery, data quality, and the integration of threat modeling approaches.
Contribution
It identifies key issues in vulnerability and threat identification processes and evaluates the usability of MITRE ATT&CK for threat modeling from network data.
Findings
Enumerations face challenges in asset discovery and data quality.
Threat identification is moving towards tactics, techniques, and procedures.
Network monitoring can effectively model most MITRE ATT&CK tactics.
Abstract
Identification of cyber threats is one of the essential tasks for security teams. Currently, cyber threats can be identified using knowledge organized into various formats, enumerations, and knowledge bases. This paper studies the current challenges of identifying vulnerabilities and threats in cyberspace using enumerations and data about assets. Although enumerations are used in practice, we point out several issues that still decrease the quality of vulnerability and threat identification. Since vulnerability identification methods are based on network monitoring and agents, the issues are related to the asset discovery, the precision of vulnerability discovery, and the amount of data. On the other hand, threat identification utilizes graph-based, nature-language, machine-learning, and ontological approaches. The current trend is to propose methods that utilize tactics, techniques,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
