Analyzing Threat Vectors in ICS Cyberattacks
Ismael Villanueva-Miranda, Monika Akbar · 2023
The rise in cyberattacks on Industrial Control Systems (ICS) shows the need for enhanced security measures. Integrating diverse cybersecurity datasets is essential to provide a comprehensive view of the threat landscape. This paper presents an approach to automatically connect Common Weakness Enumeration (CWEs) and ICS-specific MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) techniques. We present studies on how embedding-based approaches such as SBERT and BERT and frequency-based approaches such as TF-IDF perform in detecting connections between ICS ATT&CK Techniques and CWEs. Furthermore, we employ advanced analytical methods to identify common attack patterns. We present three case studies to demonstrate the potential of embedding-based approaches for mapping multiple datasets. Our approach holds promise for detecting ICS weaknesses, showing how integrating expert knowledge and domain-specific data can be used for advanced threat analytics.