MITRE ATT&CK Applications in Cybersecurity and The Way Forward

📅 2025-02-15
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This paper addresses critical limitations of the MITRE ATT&CK framework—namely, poor real-world adaptability, weak cross-framework interoperability, and limited domain generalizability. Conducting the largest systematic review and empirical study to date (417 publications), we analyze TTP usage patterns, align ATT&CK with complementary frameworks (Cyber Kill Chain, NIST SP 800-53, STRIDE), and construct ATT&CK knowledge graph mappings. Our analysis reveals, for the first time, empirically grounded frequency distributions and effectiveness boundaries of high-utility TTPs. We propose a novel NLP- and ML-integrated ATT&CK enhancement paradigm enabling dynamic threat detection and response. Furthermore, we conduct the first large-scale empirical evaluation of ATT&CK’s applicability in critical domains—including industrial control systems and healthcare—identifying concrete adaptation bottlenecks and proposing actionable, deployable framework enhancements.

Technology Category

Application Category

📝 Abstract
The MITRE ATT&CK framework is a widely adopted tool for enhancing cybersecurity, supporting threat intelligence, incident response, attack modeling, and vulnerability prioritization. This paper synthesizes research on its application across these domains by analyzing 417 peer-reviewed publications. We identify commonly used adversarial tactics, techniques, and procedures (TTPs) and examine the integration of natural language processing (NLP) and machine learning (ML) with ATT&CK to improve threat detection and response. Additionally, we explore the interoperability of ATT&CK with other frameworks, such as the Cyber Kill Chain, NIST guidelines, and STRIDE, highlighting its versatility. The paper further evaluates the framework from multiple perspectives, including its effectiveness, validation methods, and sector-specific challenges, particularly in industrial control systems (ICS) and healthcare. We conclude by discussing current limitations and proposing future research directions to enhance the applicability of ATT&CK in dynamic cybersecurity environments.
Problem

Research questions and friction points this paper is trying to address.

Analyzes MITRE ATT&CK framework applications in cybersecurity
Explores integration of NLP and ML for threat detection
Evaluates interoperability with frameworks like NIST and STRIDE
Innovation

Methods, ideas, or system contributions that make the work stand out.

Integrates NLP and ML
Enhances threat detection
Interoperates with multiple frameworks
🔎 Similar Papers
No similar papers found.
Y
Yuning Jiang
National University of Singapore, Singapore
Q
Qiaoran Meng
National University of Singapore, Singapore
F
Feiyang Shang
National University of Singapore, Singapore
N
Nay Oo
NCS Cyber Special Ops R&D, Singapore
L
Le Thi Hong Minh
National University of Singapore, Singapore
Hoon Wei Lim
Hoon Wei Lim
Singtel
Data Security & PrivacyApplied CryptographySecurity Analytics
Biplab Sikdar
Biplab Sikdar
Provost's Chair Professor, National University of Singapore
Internet of ThingsCyber-Physical SystemsComputer Networks