分析417篇论文,梳理MITRE ATT&CK在安全实战中的应用与改进方向
MITRE ATT&CK Applications in Cybersecurity and The Way Forward
- 系统整合417篇文献,提炼常见攻击战术与技术
- 融合NLP与机器学习提升威胁检测效率
- 适合安全研究人员、攻防团队及框架设计者参考
MITRE ATT&CK框架是广泛用于提升网络安全的工具,支持威胁情报、事件响应、攻击建模和漏洞优先级排序。本文通过分析417篇同行评审论文,梳理其在各领域的应用。研究识别出常见的攻击战术、技术与程序(TTPs),探讨自然语言处理(NLP)与机器学习(ML)与ATT&CK的融合,以增强威胁检测与响应能力。同时,评估其与其它框架(如Cyber Kill Chain、NIST指南、STRIDE)的互操作性,展现其多功能性。从有效性、验证方法及行业挑战(特别是工业控制系统和医疗领域)多角度进行评价,并指出当前局限,提出未来研究方向,以提升其在动态网络安全环境中的适用性。
原文摘要 · Abstract (English)
The MITRE ATT&CK framework is a widely adopted tool for enhancing cybersecurity, supporting threat intelligence, incident response, attack modeling, and vulnerability prioritization. This paper synthesizes research on its application across these domains by analyzing 417 peer-reviewed publications. We identify commonly used adversarial tactics, techniques, and procedures (TTPs) and examine the integration of natural language processing (NLP) and machine learning (ML) with ATT&CK to improve threat detection and response. Additionally, we explore the interoperability of ATT&CK with other frameworks, such as the Cyber Kill Chain, NIST guidelines, and STRIDE, highlighting its versatility. The paper further evaluates the framework from multiple perspectives, including its effectiveness, validation methods, and sector-specific challenges, particularly in industrial control systems (ICS) and healthcare. We conclude by discussing current limitations and proposing future research directions to enhance the applicability of ATT&CK in dynamic cybersecurity environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。