Cyber security threat modeling based on the MITRE Enterprise ATT&CK Matrix

Wenjun Xiong,Emeline Legrand,Oscar Åberg,Robert Lagerström
DOI: https://doi.org/10.1007/s10270-021-00898-7
2021-06-18
Abstract:Abstract Enterprise systems are growing in complexity, and the adoption of cloud and mobile services has greatly increased the attack surface. To proactively address these security issues in enterprise systems, this paper proposes a threat modeling language for enterprise security based on the MITRE Enterprise ATT&CK Matrix. It is designed using the Meta Attack Language framework and focuses on describing system assets, attack steps, defenses, and asset associations. The attack steps in the language represent adversary techniques as listed and described by MITRE. This entity-relationship model describes enterprise IT systems as a whole; by using available tools, the proposed language enables attack simulations on its system model instances. These simulations can be used to investigate security settings and architectural changes that might be implemented to secure the system more effectively. Our proposed language is tested with a number of unit and integration tests. This is visualized in the paper with two real cyber attacks modeled and simulated.
computer science, software engineering
What problem does this paper attempt to address?