Recommending Defenses Against Cyber Threats: An Approach Inspired by Machine Translation
摘要
Faced with the constant threat of crippling cyber-attacks by adversaries motivated by financial or geopolitical gain, Western governments are pouring significant funding into efforts to understand the threats and beef up defenses against them. An example is the work being done by the US Cybersecurity and Infrastructure Security Agency (CISA), MITRE and others, which has resulted in the MITRE ATT&CK framework (MITRE. 2015–2024. MITRE ATT&CK [1]) and the Secure Cloud Business Applications (SCuBA) Project (Cybersecurity and Infrastructure Security Agency. n.d. Secure cloud business applications (SCuBA) project [2]). MITRE describes ATT&CK as ‘a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations’. In this framework, Tactics, Techniques, and Procedures (TTPs) are patterns of activity used by threat actors. ATT&CK lists several hundred TTPs. SCuBA, on the other hand, focuses on ‘baseline policies’ that can be put in place to defend against cyber threats. As an example, a baseline policy might state that a Federal agency ‘shall not’ enable external Microsoft Teams meeting participants to request control of shared desktops. There has been an effort also to map TTPs to relevant baseline controls—in effect, to suggest which controls can mitigate each TTP threat. In this paper, we explore an approach inspired by machine translation and cross-language information retrieval to automate the process of this type of mapping, both saving labor and potentially enhancing possibilities for cyber defense ( https://attack.mitre.org/techniques/enterprise/ ).