<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>An ATT&amp;CK-KG for Linking Cybersecurity Attacks to Adversary Tactics and Techniques?</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Kabul Kurniawan</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andreas Ekelhart</string-name>
          <email>aekelhart@sba-research.org</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Elmar Kiesling</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>SBA Research</institution>
          ,
          <addr-line>Floragasse 7, Vienna</addr-line>
          ,
          <country country="AT">Austria</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>WU Wien - Vienna University of Economics and Business</institution>
          ,
          <addr-line>Welthandelsplatz 1, Vienna</addr-line>
          ,
          <country country="AT">Austria</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Leveraging knowledge graph techniques to detect and analyze cyber attacks is a promising research direction at the interface between the semantic web and security research communities. In this paper, we build on prior work and develop a vocabulary to extend a cybersecurity knowledge graph with adversary tactics and techniques. Using this vocabulary, we represent rich threat intelligence instance data from MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&amp;CK) in a knowledge graph. This knowledge can be used to contextualize indicators of compromise from log messages, identify potential attack steps, and link them to cybersecurity knowledge. To demonstrate the bene ts of the approach, we link low-level threat alerts produced by community rules to the cybersecurity knowledge graph.</p>
      </abstract>
      <kwd-group>
        <kwd>Cybersecurity</kwd>
        <kwd>Knowledge Graph</kwd>
        <kwd>Attack Pattern</kwd>
        <kwd>ATT&amp;CK</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Cybersecurity Threat Intelligence (CTI) can help defenders to identify
vulnerabilities, understand malware behavior, and contextualize attack patterns.
ATT&amp;CK3, published by MITRE, is a well-established source of such
intelligence; it provides a taxonomy and instance knowledge for adversary tactics and
techniques curated from real-world observations. ATT&amp;CK supports various
security use cases from the adversary and defender perspective, such as adversary
emulation, red teaming, defensive gap assessment, identi cation and modeling
of adversary behavior [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>
        Although such CTI resources can be very useful for security experts, they
are also typically di cult to relate to other cybersecurity information and
operational data and not suitable for querying and automated machine
interpre? Copyright © 2021 for this paper by its authors. Use permitted under Creative Commons
License Attribution 4.0 International (CC BY 4.0). This work was sponsored by the Austrian
Science Fund (FWF) and netidee SCIENCE under grant P30437-N31. The competence
center SBA Research (SBA-K1) is funded within the framework of COMET | Competence
Centers for Excellent Technologies by BMVIT, BMDW, and the federal state of Vienna,
managed by the FFG. The authors thank the funders for their generous support.
3 https://attack.mitre.org/matrices/enterprise/
tation [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Several researchers addressed this limitation by introducing
knowledge graphs for related cybersecurity information. Uni ed Cybersecurity
Ontology (UCO) [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], for instance, integrates a number of cybersecurity standards
(STIX4, CyBox5, CVE6, CAPEC7, CEE8, and CVSS9) into an openly available
ontology. The SEPSES Cybersecurity Knowledge Graph (CSKG)[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] builds on a
similar set of standards, but provides a continuously updated, integrated
cybersecurity knowledge graph with rich instance data accessible via various access
mechanism. Neither UCO nor the SEPSES CSKG, however, include the CTI
embodied in ATT&amp;CK. Xiong et al. [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] propose a threat modelling language
called enterpriseLang based on the MITRE ATT&amp;CK Matrix. It uses a
domainspeci c language (DSL) based on the Meta Attack Language (MAL) framework
to describe system assets, attack steps, and defenses. Hemberg et al. [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] propose
BRON, which links MITRE ATT&amp;CK, CVE, CWE10, and CAPEC to identify
tactics and techniques via a graph database. However, both enterpriseLang and
BRON rely on custom, hard-coded data models and do not provide a standard
model for ATT&amp;CK. Furthermore, such custom data models lack semantic
interoperability and make it di cult to, e.g., store and exchange the model and
query the data via SPARQL.
      </p>
      <p>We ll this gap by developing a standard model for ATT&amp;CK based on
RDF-S11 and OWL12, and integrate its instance data into the SEPSES CSKG.
To identify high-level attack steps while abstracting from low-level indicators,
we introduce a method to (i) translate community-based threat detection rules
from sources such as Sigma13 into SPARQL queries and (ii) to link the alerts
they produce to adversarial tactics and techniques de ned in ATT&amp;CK. Figure 1
illustrates the resulting overall process to link cybersecurity attacks to adversary
tactics and techniques.
4 Structured Threat Information Expression, https://stixproject.github.io/
5 Cyber Observable eXpression, https://cyboxproject.github.io/
6 Common Vulnerability Exposure, https://cve.mitre.org/
7 Common Attack Pattern Enumeration and Classi cation, https://capec.mitre.org/
8 Common Event Expression, https://cee.mitre.org/language/syntax.html
9 Common Vulnerability Scoring System, https://www.first.org/cvss/
10 Common Weakness Enumeration, https://cwe.mitre.org/
11 Resource Description Framework Schema, https://www.w3.org/TR/rdf-schema/
12 Web Ontology Language, https://www.w3.org/TR/owl-features/
13 Sigma rule repository, https://github.com/SigmaHQ/sigma
2</p>
    </sec>
    <sec id="sec-2">
      <title>Knowledge Graph Construction</title>
      <p>
        We rst de ned an ontology based on the existing schema by MITRE to
represent and publish attack data [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Figure 2 provides an overview of the
re
      </p>
      <p>Fig. 2: An extended SEPSES CSKG Ontology with ATT&amp;CK
sulting ATT&amp;CK ontology14. The ontology consists of ve main classes (i.e.,
Tactic, Technique, Mitigation, AdversaryGroup, and Software) and
a set of data and object properties. The Tactic class represents tactical
adversary goals during the attack, whereas a Technique represents how an
adversary achieves the tactical objective; the att:accomplishesTactic property links
Techniques and Tactics. Techniques may have more speci c sub-techniques;
to this end, the att:isSubTechnique property can be used to self-link the
Technique class. Mitigation represents measures that can be used to prevent
Techniques from being executed. We de ned the att:preventsTechnique
property to link between mitigations and Techniques. The AdversaryGroup
represents a threat/actor group that typically represents persistent threat
activity. The att:usesTechnique property links the group to the Technique
class. Software represent software/tools that are used to implement a
Technique, which is expressed via the property att:implementsTechnique. We also
de ned several inverse properties such as at:hasMitigation, hasTechnique,
hasSoftware, etc. Furthermore, Technique links to the existing CAPEC
attack pattern knowledge in the SEPSES CSKG via the att:hasCAPEC property.</p>
      <p>We used RML16, a declarative RDF mapping language to map and transform
MITRE ATT&amp;CK resources17 into RDF based on the developed ATT&amp;CK
ontology. The constructed RDF graphs are automatically stored in a triplestore
together with the existing SEPSES CSKG and integrated with information from
14 https://w3id.org/sepses/vocab/ref/attack
15 As per August 2, 2021 (cf. https://w3id.org/sepses/dumps/attack).
16 RDF Mapping Language, https://rml.io/
17 MITRE publishes the ATT&amp;CK resource in a JSON format
#Axiom
61
#Class
5
#ObjectProperty
10
#DataProperty
7
#Individual
4054
other standards, such as CAPEC, CVE, CWE, CPE18 and CVSS (see Figure 3
steps (1) and (2)). Table 1 provides summary statistics on the elements currently
in the ATT&amp;CK knowledge graph.
3</p>
    </sec>
    <sec id="sec-3">
      <title>Prototype Implementation</title>
      <p>We implemented the threat detection concept introduced in Section 1 using
Sigma, an open, community-driven, and generic rule format for threat detection
in logs and included them in our threat detection pipeline. Sigma provides more
than 95019 rules/signatures (written in a YAML) for di erent log sources (e.g.,
application, network, web logs) and platforms (e.g Linux &amp; Windows).</p>
      <p>Figure 3 shows an example; based on the Sigma rule speci cation20, we
translate the existing Sigma rules into SPARQL queries and also transform other rule
metadata (e.g. title, description, log source, and tags21) into RDF (3).</p>
      <p>The translated rules can then be used to detect Indicators of Compromise
(IoCs) in RDF log graphs22 (4). Once detected, the respected alert will
automatically be linked to the corresponding attack technique in the ATT&amp;CK
knowledge graph (5).</p>
      <p>As we can see, the execution of /tmp/vUgefal located in /tmp/ has been
detected based on a Sigma rule. Consequently, a Program Execution in
Suspicious Folder alert has been raised. The detected alert is automatically linked to
the T1204.002 23 (User Execution: Malicious File ) technique in the ATT&amp;CK
knowledge graph, as it is identi ed in the Sigma rule (see tags value). Finally,
an analyst can further explore and integrate additional information from the
ATT&amp;CK knowledge graph (e.g. via SPARQL Query federation) as de ned in
the ontology (e.g. tactics, mitigations, adversary group, and attack patterns
(CAPEC)).
4</p>
    </sec>
    <sec id="sec-4">
      <title>Conclusions and Future Work</title>
      <p>
        In this paper, we extended the SEPSES CSKG with threat intelligence from
MITRE ATT&amp;CK and used it to link indicators of compromise to adversarial
18 Common Platform Enumeration, https://nvd.nist.gov/products/cpe
19 As per August 2 2021.
20 https://github.com/SigmaHQ/sigma/wiki/Specification
21 tags associates Sigma rules with ATT&amp;CK techniques.
22 Note: tools such as SLOGERT [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] or [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] can be used to transform log data into RDF.
23 https://w3id.org/sepses/resource/attack/technique/T1204.002
tactics and techniques. The result is of high practical relevance, as demonstrated
in the application that automatically identi es, contextualizes and links alerts
from log messages to rich knowledge on techniques, tactics, attack patterns,
vulnerabilities, and potential mitigations in the CSKG. For future work, we plan
to evaluate the approach in a real-world setting, incorporate various alternative
detection mechanisms (e.g., provenance-based detection and graph queries), and
develop mechanisms to link individual steps in an attack campaign. Ultimately,
this will provide a foundation for a new generation of tooling to support semantic
security analytics.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Ekelhart</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ekaputra</surname>
            ,
            <given-names>F.J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kiesling</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          :
          <article-title>The SLOGERT Framework for Automated Log Knowledge Graph Construction</article-title>
          . In: ESWC (
          <year>2021</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Hemberg</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kelly</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shlapentokh-Rothman</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Reinstadler</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Xu</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rutar</surname>
          </string-name>
          , N.,
          <string-name>
            <surname>O'Reilly</surname>
            ,
            <given-names>U.</given-names>
          </string-name>
          <article-title>M.: Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and A ected Platform Con gurations for Cyber Hunting</article-title>
          . arXiv:
          <year>2010</year>
          .00533 [cs] (
          <year>2021</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Kiesling</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ekelhart</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kurniawan</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ekaputra</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          :
          <article-title>The SEPSES Knowledge Graph: An Integrated Resource for Cybersecurity</article-title>
          . In: ISWC (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Kurniawan</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ekelhart</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kiesling</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Winkler</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Quirchmayr</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tjoa</surname>
            ,
            <given-names>A.M.</given-names>
          </string-name>
          :
          <article-title>Virtual Knowledge Graphs for Federated Log Analysis</article-title>
          .
          <source>In: ARES</source>
          (
          <year>2021</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Strom</surname>
            ,
            <given-names>B.E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Applebaum</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Miller</surname>
            ,
            <given-names>D.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nickels</surname>
            ,
            <given-names>K.C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pennington</surname>
            ,
            <given-names>A.G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Thomas</surname>
            ,
            <given-names>C.B.</given-names>
          </string-name>
          :
          <string-name>
            <surname>Mitre</surname>
            <given-names>ATT</given-names>
          </string-name>
          &amp;
          <article-title>CK: Design and Philosophy</article-title>
          .
          <source>Technical report</source>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Syed</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Padia</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Finin</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mathews</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>UCO: A Uni ed Cybersecurity Ontology</article-title>
          .
          <source>In: Proceedings of the AAAI Workshop on Arti cial Intelligence for Cyber Security</source>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Xiong</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Legrand</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Aberg</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          , Lagerstrom, R.:
          <article-title>Cyber security threat modeling based on the MITRE Enterprise ATT&amp;CK Matrix</article-title>
          .
          <source>Software and Systems Modeling</source>
          (
          <year>2021</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>