MITRE-Based APT Attack Generation and Prediction
摘要
Due to the increasing sophistication of recent cyberattacks, novel techniques and approaches are needed to proactively predict and react to their execution in order to efficiently protect and defend cybersystems. In this work, we propose a framework to generate and predict APT attacks, where an APT attack scenario is modeled as the execution of a series of MITRE ATT&CK techniques executed through exploiting system vulnerabilities. Our framework consists of six steps. Initially, data is gathered, linking vulnerabilities to their exploitation techniques or connecting two techniques, where the execution of one leads to the execution of the other. After a preprocessing phase, this data is used to construct a graph of attack scenarios. Next, we leverage the output of a deployed Vulnerability Management System to refine the generated graph, retaining only those scenarios that could be executed within the defended network. The resulting scenarios are extracted by applying a set of constraints ensuring their validity. Finally, we employ a Markov Chain model to predict either the next attacker step or the number of steps required for attackers to reach an undesirable state starting from a detected one. We conclude that our solution is able to generate both known and novel APT attack scenarios in addition to predicting next attacker step, thereby significantly enhancing cybersystem security.