• Journal of Internet Computing and Services
    ISSN 2287 - 1136 (Online) / ISSN 1598 - 0170 (Print)
    https://jics.or.kr/

Cyber attack group classification based on MITRE ATT&CK model


Chang-hee Choi, Chan-ho Shin, Sung-uk Shin, Journal of Internet Computing and Services, Vol. 23, No. 6, pp. 1-13, Dec. 2022
10.7472/jksii.2022.23.6.1, Full Text:
Keywords: Cyber Attack, attack group similarity, attack group classification, APT, MITRE ATT&CK

Abstract

As the information and communication environment develops, the environment of military facilities is also development remarkably. In proportion to this, cyber threats are also increasing, and in particular, APT attacks, which are difficult to prevent with existing signature-based cyber defense systems, are frequently targeting military and national infrastructure. It is important to identify attack groups for appropriate response, but it is very difficult to identify them due to the nature of cyber attacks conducted in secret using methods such as anti-forensics. In the past, after an attack was detected, a security expert had to perform high-level analysis for a long time based on the large amount of evidence collected to get a clue about the attack group. To solve this problem, in this paper, we proposed an automation technique that can classify an attack group within a short time after detection. In case of APT attacks, compared to general cyber attacks, the number of attacks is small, there is not much known data, and it is designed to bypass signature-based cyber defense techniques. As an attack model, we used MITRE ATT&CKⓇ which modeled many parts of cyber attacks. We design an impact score considering the versatility of the attack techniques and proposed a group similarity score based on this. Experimental results show that the proposed method classified the attack group with a 72.62% probability based on Top-5 accuracy.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from November 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[APA Style]
Choi, C., Shin, C., & Shin, S. (2022). Cyber attack group classification based on MITRE ATT&CK model. Journal of Internet Computing and Services, 23(6), 1-13. DOI: 10.7472/jksii.2022.23.6.1.

[IEEE Style]
C. Choi, C. Shin, S. Shin, "Cyber attack group classification based on MITRE ATT&CK model," Journal of Internet Computing and Services, vol. 23, no. 6, pp. 1-13, 2022. DOI: 10.7472/jksii.2022.23.6.1.

[ACM Style]
Chang-hee Choi, Chan-ho Shin, and Sung-uk Shin. 2022. Cyber attack group classification based on MITRE ATT&CK model. Journal of Internet Computing and Services, 23, 6, (2022), 1-13. DOI: 10.7472/jksii.2022.23.6.1.