黑客
计算机科学
分析
计算机安全
风险管理
风险管理框架
风险分析(工程)
设计科学
设计科学研究
知识管理
数据科学
信息系统
业务
风险评估
工程类
财务
IT风险管理
电气工程
作者
Benjamin Ampel,Sagar Samtani,Hongyi Zhu,Hsinchun Chen,Jay F. Nunamaker
标识
DOI:10.1080/07421222.2023.2301178
摘要
Cyberattacks have been increasing in volume and intensity, necessitating proactive measures. Cybersecurity risk management frameworks are deployed to provide actionable intelligence to mitigate potential threats by analyzing the available cybersecurity data. Existing frameworks, such as MITRE ATT&CK, provide timely mitigation strategies against attacker capabilities yet do not account for hacker data when developing cyber threat intelligence. Therefore, we developed a novel information technology artifact, ATT&CK-Link, which incorporates a novel transformer and multi-teacher knowledge distillation design, to link hacker threats to this broadly used framework. Here, we illustrated how hospital systems can use this framework to proactively protect their cyberinfrastructure against hacker threats. Our ATT&CK-Link framework has practical implications for cybersecurity professionals, who can implement our framework to generate strategic, operational, and tactical cyber threat intelligence. ATT&CK-Link also contributes to the information systems knowledge base by providing design principles to pursue targeted cybersecurity analytics, risk management, and broader text analytics research through simultaneous multi-modal (e.g., text and code) distillation and classification.
科研通智能强力驱动
Strongly Powered by AbleSci AI