Automated Profiling of Cyber Attacks Based on MITRE ATT&CK
2024 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE credits
Student thesisAlternative title
Automatiserad Profilering av Cyberattacker Baserat på MITRE ATT&CK (Swedish)
Abstract [en]
This Master thesis presents a framework for automated profiling of cyber attacks based on mitre att&ck®. The framework includes two components: (1) a component for automated mapping of sequences of attacker actions to the corresponding tactics and techniques in mitre att&ck®; and (2) a component for probabilistic profiling of attacker actions based on testbed measurements. The latter component models the relation between attacker actions and testbed measurements using a hidden Markov model, which allows to estimate the most likely attack sequence using probabilistic inference. The experimental part of this thesis includes extensive profiling of emulated attacks in the Cyber Security Learning Environment (csle), which is a platform for emulating attacks and defenses in virtualized IT environments. Our experimental results show that our framework is able to automatically map attacker actions in csle to mitre att&ck® and that it can accurately estimate the start time of an attack based on testbed measurements.
Abstract [sv]
Denna masteruppsats presenterar ett ramverk för automatisk profilering av cyberattacker baserat på mitre att&ck®. Ramverket inkluderar två kompo- nenter: (1) en komponent för automatisk kartläggning av attacksekvenser till motsvarande taktiker i mitre att&ck®; och (2) en komponent för probabi- listisk profilering av attackaktioner baserat på mätdata från en testbädd. Den senare komponenten modellerar relationen mellan attackaktioner och mätdata från testbädden genom dolda Markovmodeller, vilket möjliggör estimering av den mest sannolika attacksekvensen med hjälp av probabilistisk inferens. Den experimentella delen av den här uppsatsen inkluderar omfattande profilering av emulerade cyberattacker i “the Cyber Security Learning Environment (csle)", vilket är en plattform för att emulera cyberangrepp och försvar i en virtuell IT-miljö. Resultaten visar att vårt ramverk automatiskt kan kartlägga attackaktioner i csle baserat på mitre att&ck® och att den kan estimera starttiden för en attack med hög träffsäkerhet baserat på mätdata från testbädden.
Place, publisher, year, edition, pages
2024. , p. 45
Series
TRITA-EECS-EX ; 2024:738
Keywords [en]
Attack emulation, Attack profiling, Autonomous network security, Cyber security, Hidden Markov Model, Mitre Att&ck, The Cyber Security Learning Environment (CSLE)
Keywords [sv]
Attack emulering, Attack profilering, Autonom nätverkssäkerhet, Cybersä- kerhet, Dold Markovmodell, Mitre Att&ck, The Cyber Security Learning Environment (CSLE)
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:kth:diva-360096OAI: oai:DiVA.org:kth-360096DiVA, id: diva2:1938354
Supervisors
Examiners
2025-02-202025-02-182025-02-20Bibliographically approved