Poster: M 2 ASK: A Correlation-Based Multi-Step Attack Scenario Detection Framework Using MITRE ATT&CK Mapping

Qiaoran Meng, Nay Oo, Yuning Jiang, Hoon Wei Lim, Biplab Sikdar · 2024

Traditional Network Intrusion Detection Systems (NIDS) often generate large volumes of alerts with redundancies and false positives, incapable of correlating detected attack actions. This adds difficulty for security analysts to construct a comprehensive understanding of multi-step attacks. To address these limitations, we present a novel MITRE-based Multi-step Attack Scenario Construction (M2ASK) algorithm that enhances cyber threat intelligence (CTI) by integrating MITRE ATT&CK tactic and technique mapping, facilitating the interpretation of multi-step attacks and informing response strategies. Our approach processes alert data from NIDSs, transforming it into a network communication graph. Graph-based correlation techniques are employed, combined with MITRE ATT&CK and Cyber Kill Chain stage profiling to construct comprehensive network attack scenarios. Our key contributions include: (1) the development of a Cyber Kill Chain based model for constructing attack scenarios; (2) the alert correlation approach based on MITRE ATT&CK tagging of attack actions.

Read the paper · More papers on PaperTik