GuardLink: Dynamic Linking of CVE to MITRE ATT&CK Techniques using Machine Learning

Saad El Jaouhari, Nouredine Tamani, Rohan Isaac Jacob · 2024

As our dependence on digital technologies continues to expand, the need to strengthen our cyber defenses against the increasing threats posed by malicious entities becomes more critical. While existing cybersecurity frameworks and databases like MITRE ATT&CK and Common Vulnerabilities and Exposures (CVE) offer valuable insights for effective threat mitigation, they often operate independently, leading to siloed information. We assert that the automatic linking of vulnerabilities from the CVE database to MITRE ATT&CK adversarial techniques and tactics, particularly focusing on new ones, can provide essential information to empower blue teams in enhancing their cybersecurity defenses against cyberattacks. Gaining proactive insight into an attacker’s potential next moves is pivotal for effective defense strategies. Therefore, we introduce in this paper GuardLink, a dynamic approach for linking CVE identifiers (IDs) to MITRE ATT&CK techniques. We first studied, reproduced, evaluated, and improved state of the art models in the field. Furthermore, we proposed a new multi-label classification model that outperforms the existing ones and achieves an accuracy of 97.83%. To ensure transparency and reproducibility, the source code for GuardLink is made openly accessible on GitHub.

Read the paper · More papers on PaperTik