Investigating co-occurrences of MITRE ATT\&CK Techniques
Md Rayhanur Rahman, Laurie Williams

TL;DR
This study analyzes how cyber adversaries deploy multiple techniques together using the MITRE ATT&CK framework, providing insights into common co-occurrences and strategies for detection and mitigation.
Contribution
It introduces a comprehensive co-occurrence analysis of adversarial techniques from MITRE ATT&CK, identifying key technique pairs and proposing targeted defense strategies.
Findings
Command and scripting interface techniques co-occur with many other techniques.
Adversaries frequently use System Information Discovery to inform their actions.
Defense evasion and discovery tactics are the most commonly deployed techniques.
Abstract
Cyberattacks use adversarial techniques to bypass system defenses, persist, and eventually breach systems. The MITRE ATT\&CK framework catalogs a set of adversarial techniques and maps between adversaries and their used techniques and tactics. Understanding how adversaries deploy techniques in conjunction is pivotal for learning adversary behavior, hunting potential threats, and formulating a proactive defense. The goal of this research is to aid cybersecurity practitioners and researchers in choosing detection and mitigation strategies through co-occurrence analysis of adversarial techniques reported in MITRE ATT&CK. We collect the adversarial techniques of 115 cybercrime groups and 484 malware from the MITRE ATT\&CK. We apply association rule mining and network analysis to investigate how adversarial techniques co-occur. We identify that adversaries pair T1059: Command and scripting…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Information and Cyber Security · Network Security and Intrusion Detection
