MITRE ATT&CK Applications in Cybersecurity and The Way Forward
Jiang, Yuning, Meng, Qiaoran, Shang, Feiyang, Oo, Nay, Minh, Le Thi Hong, Lim, Hoon Wei, Sikdar, Biplab
–arXiv.org Artificial Intelligence
The MITRE ATT&CK framework is a widely adopted tool for enhancing cybersecurity, supporting threat intelligence, incident response, attack modeling, and vulnerability prioritization. This paper synthesizes research on its application across these domains by analyzing 417 peer-reviewed publications. We identify commonly used adversarial tactics, techniques, and procedures (TTPs) and examine the integration of natural language processing (NLP) and machine learning (ML) with ATT&CK to improve threat detection and response. Additionally, we explore the interoperability of ATT&CK with other frameworks, such as the Cyber Kill Chain, NIST guidelines, and STRIDE, highlighting its versatility. The paper further evaluates the framework from multiple perspectives, including its effectiveness, validation methods, and sector-specific challenges, particularly in industrial control systems (ICS) and healthcare. We conclude by discussing current limitations and proposing future research directions to enhance the applicability of ATT&CK in dynamic cybersecurity environments.
arXiv.org Artificial Intelligence
Feb-15-2025
- Country:
- Asia
- Afghanistan > Kabul Province
- Kabul (0.04)
- India > NCT
- Delhi (0.04)
- Malaysia (0.04)
- Middle East
- Israel (0.04)
- Saudi Arabia (0.04)
- North Korea (0.04)
- Singapore > Central Region
- Singapore (0.04)
- South Korea > Gyeongsangnam-do
- Changwon (0.04)
- Afghanistan > Kabul Province
- Europe
- Italy > Molise
- Campobasso Province > Campobasso (0.04)
- Poland > Lesser Poland Province
- Kraków (0.04)
- Serbia > Central Serbia
- Belgrade (0.04)
- Switzerland > Basel-City
- Basel (0.04)
- United Kingdom > Wales (0.04)
- Italy > Molise
- North America
- Canada (0.04)
- Mexico > Veracruz (0.04)
- United States
- Florida > Orange County
- Orlando (0.04)
- New York > New York County
- New York City (0.04)
- Florida > Orange County
- Asia
- Genre:
- Overview (1.00)
- Research Report > New Finding (0.46)
- Industry:
- Government > Military
- Cyberwarfare (1.00)
- Information Technology > Security & Privacy (1.00)
- Government > Military
- Technology:
- Information Technology
- Artificial Intelligence
- Machine Learning
- Learning Graphical Models > Undirected Networks
- Markov Models (0.67)
- Neural Networks > Deep Learning (1.00)
- Performance Analysis (0.67)
- Statistical Learning (1.00)
- Learning Graphical Models > Undirected Networks
- Natural Language
- Chatbot (1.00)
- Large Language Model (1.00)
- Text Processing (0.67)
- Representation & Reasoning > Ontologies (0.67)
- Machine Learning
- Communications > Networks (1.00)
- Data Science > Data Mining (1.00)
- Security & Privacy (1.00)
- Artificial Intelligence
- Information Technology