MATE: Summarizing Alerts to Interpretable Outcomes with MITRE ATT&CK

Derek Lin · 2022 IEEE International Conference on Big Data (Big Data) · 2022

Enterprise security operations centers are inundated with a volume of alerts. Whether fact-based or anomaly-based, a multitude of alerts from security products and services are difficult to investigate when each is viewed in isolation. Pivoting from one alert to another in an attempt to connect the dots during investigation is a time-consuming and labor-intensive process. This paper introduces a practical system that automatically organizes and summarizes alerts to cases for prioritization and investigation. The system outputs interpretable threat candidates with a timeline of activities modeled after attack stages grounded in the MITRE ATT&CK framework.

Read the paper · More papers on PaperTik