Article navigation
Purpose

The purpose of this study is to investigate how to enhance cybersecurity strategies by integrating semantic network analysis with the MITRE ATT&CK framework. This study’s primary goal was to deepen understanding of advanced persistent threats (APTs) dynamics by examining how various attack techniques are connected and their roles within cyberattacks.

Design/methodology/approach

This study used a detailed analysis of data from the MITRE ATT&CK framework, applying semantic network analysis to examine how different attack techniques are interconnected across various environments, including enterprise systems, industrial control systems and mobile networks. The methodology focused on identifying central techniques and the relational dynamics among tactics that contribute to the efficacy of APTs.

Findings

The findings of this study reveal that certain techniques, such as “Valid Accounts” and “Credential Dumping,” consistently play central roles in multiple attack pathways, making them critical targets for cybersecurity defenses. The analysis also uncovers intricate patterns of interconnections among various tactics and techniques, demonstrating how attackers exploit these relationships in a sequential manner. This knowledge is crucial for developing targeted defense strategies that effectively mitigate the most significant threats and address the interconnected nature of APT attacks.

Research limitations/implications

This study primarily relies on the MITRE ATT&CK framework, which may not encompass all emerging techniques, potentially limiting the generalizability of the findings. Additionally, the focus on specific domains (enterprise, industrial control systems and mobile) might overlook other critical areas like cloud services or Internet of Things devices. Interpretation of semantic network analysis results involve some subjectivity, which could introduce bias.

Practical implications

By identifying key techniques with high centrality, this study provides actionable insights for cybersecurity professionals. The results can guide the development of more focused defense strategies, particularly by prioritizing techniques that are central to multiple attack pathways. This can lead to more efficient resource allocation for monitoring and protecting critical points in a network.

Social implications

Improving cybersecurity defenses against APTs can protect critical infrastructure, enterprises and individuals from significant threats, including data breaches, intellectual property theft and sabotage. Enhanced understanding and mitigation of APTs can contribute to national security, economic stability and the safeguarding of personal privacy in an increasingly interconnected world.

Originality/value

The integration of semantic network analysis with the MITRE ATT&CK framework represents a novel approach to cybersecurity analysis. This methodology provides a comprehensive means to identify and prioritize key areas of vulnerability, thereby enhancing defensive measures against sophisticated cyber threats. This research offers detailed analysis and practical insights that can guide cybersecurity professionals in strengthening defenses against the evolving landscape of APTs.

Licensed re-use rights only
You do not currently have access to this content.
Don't already have an account? Register

Purchased this content as a guest? Enter your email address to restore access.

Pay-Per-View Access
$41.00
Rental

or Create an Account

Close Modal
Close Modal