How the CSE-CIC-IDS2018 Dataset is Related to the MITRE Matrix
Б. Б. Борисенко, Sergey D. Erokhin, I. D. Martishin, А. С. Фадеев · 2022
In this article we provide an overview of the main tactics for developing network attacks according to the MITRE ATT&CK (Adversarial Tactics, Techniques & Common Knowledge) matrix. MITRE ATT&CK combines four groups of matrices: PRE-ATT&CK, Enterprise, Mobile, and ATT&CK for ICS (Industrial Control Systems). The matrix is constantly updated and at the moment of analysis includes 191 techniques and 386 attack sub-techniques for Windows, Linux and Mac OS. The MITRE ATT&CK matrix is structured into 14 tactics, ranging from initial access to control taking and data theft. The work provides a brief overview of existing classes of network attacks, and their classification is presented. The characteristics and features of modern datasets used in setting up intrusion detection systems (IDS) are reviewed. Attack classes of intrusion detection system implemented based on the CSE-CIC-IDS2018 dataset and MITRE ATT&CK network attack development tactics are compared