Dynamic characterisation of cyberattacks based on the MITRE ATT&CK framework applied to the optimisation of a mitigation selection process

Carmen Sánchez-Zas, Xavier A. Larriva-Novo, Víctor A. Villagrá, Sonia Solera-Cotanilla, Mario Sanz · Future Generation Computer Systems · 2025

• Model to improve risk assessment processes by characterising cyberattacks. • MITRE ATT&CK Techniques identification in network behaviour. • Countermeasure selection support method based on MITRE recommendations. • Use case for system validation The main cybersecurity challenges identified nowadays arise around the need to know information about cyberattacks, in order to characterise them and applying the most appropriate mitigation techniques according to their behaviour. Current advances in cybersecurity focus on the detection of zero-day attacks, adaptability to attackers’ behaviour, and automated incident response. However, this evolution should not oppose the proven need for defence-in-depth policy, collaboration, and information sharing that can help other organisations prepare for new cyberattacks. Moreover, as a constantly changing context, cybersecurity must adapt dynamically to respond to emerging tactics and techniques. New generations of attacks, which apply enhanced malware, cannot be detected by traditional methods. For this reason, tools such as Artificial Intelligence (AI) are essential to maintain the confidentiality, integrity, and availability of any infrastructure, in combination with the adoption of a risk analysis and management methodology appropriate to any industrial environment. To this end, we propose a characterisation model for cyberattacks, composed by a ML algorithm trained to identify techniques in traffic log incidents and its integration with decision making systems that infers the recommended mitigations for the incident detected according to its characterisation.

Read the paper · More papers on PaperTik