English
Related papers

Related papers: An investigation of security controls and MITRE AT…

200 papers

The increasing cyber threats to critical infrastructure highlight the importance of private companies and government agencies in detecting and sharing information about threat activities. Although the need for improved threat information…

Cryptography and Security · Computer Science 2026-01-28 Adam Hahn , Rubin Krief , Daniel Rebori-Carretero , Rami Puzis , Aviad Elyashar , Nik Urlaub

The aviation industry faces significant vulnerabilities from both physical and cybersecurity threats, highlighting the urgent need for enhanced cybersecurity measures amid increasingly sophisticated attacks. This paper systematically…

Cryptography and Security · Computer Science 2026-04-28 Suphannee Sivakorn , Nuttaya Rujiratanapat , Yotsapat Ruangpaisarn , Chanond Duangpayap , Sakulchai Saramat

This paper presents a study on detecting cyberattacks on industrial control systems (ICS) using unsupervised deep neural networks, specifically, convolutional neural networks. The study was performed on a SecureWater Treatment testbed…

Cryptography and Security · Computer Science 2018-12-12 Moshe Kravchik , Asaf Shabtai

Identification of cyber threats is one of the essential tasks for security teams. Currently, cyber threats can be identified using knowledge organized into various formats, enumerations, and knowledge bases. This paper studies the current…

Cryptography and Security · Computer Science 2022-06-30 Lukáš Sadlek , Pavel Čeleda , Daniel Tovarňák

MITRE ATT&CK is a cybersecurity knowledge base that organizes threat actor and cyber-attack information into a set of tactics describing the reasons and goals threat actors have for carrying out attacks, with each tactic having a set of…

Neural networks are increasingly used for intrusion detection on industrial control systems (ICS). With neural networks being vulnerable to adversarial examples, attackers who wish to cause damage to an ICS can attempt to hide their attacks…

Cryptography and Security · Computer Science 2021-10-05 Giulio Zizzo , Chris Hankin , Sergio Maffeis , Kevin Jones

Technical standards are a longstanding method of communicating best practice recommendations based on expert consensus. Cybersecurity standards are particularly important for informing policies that protect critical systems and sensitive…

Cryptography and Security · Computer Science 2025-06-11 Noah Apthorpe , Boen Beavers , Yan Shvartzshnaider , Brett Frischmann

We address a fundamental challenge in cybersecurity operations of translating governance frameworks into actionable mitigation decisions under realistic resource constraints. Frameworks such as the NIST Cybersecurity Framework (CSF) provide…

Cryptography and Security · Computer Science 2026-05-12 Philip Huff , Dakota Dale , Harshith Guduru , Rohan Singh , Qinghua Li

This work evaluates the performance of Cyber Threat Intelligence (CTI) extraction methods in identifying attack techniques from threat reports available on the web using the MITRE ATT&CK framework. We analyse four configurations utilising…

Cryptography and Security · Computer Science 2025-05-07 Hoang Cuong Nguyen , Shahroz Tariq , Mohan Baruwal Chhetri , Bao Quoc Vo

Cyberattacks are becoming more frequent, and attackers can use different mechanisms, such as denial of service (DoS) and false data injection (FDI). Furthermore, multiple attack types can be launched simultaneously, known as hybrid attacks,…

Systems and Control · Electrical Eng. & Systems 2024-04-04 Milad Beikbabaei , Ali Mehrizi-Sani

Over the last years, Industrial Control Systems (ICS) have become increasingly exposed to a wide range of cyber-physical threats. Efficient models and techniques able to capture their complex structure and identify critical cyber-physical…

Cryptography and Security · Computer Science 2019-11-22 Martín Barrère , Chris Hankin , Demetrios G. Eliades , Nicolas Nicolau , Thomas Parisini

In recent years, Industrial Control Systems (ICS) have become an appealing target for cyber attacks, having massive destructive consequences. Security metrics are therefore essential to assess their security posture. In this paper, we…

Cryptography and Security · Computer Science 2019-05-14 Martín Barrère , Chris Hankin , Nicolas Nicolau , Demetrios G. Eliades , Thomas Parisini

In the wake of the arrival of digital media, the Internet, the web, and online social media, a flood of new cyber security research questions have emerged. There is a lot of money being lost around the world because of cyber-attacks. As a…

Cryptography and Security · Computer Science 2023-08-29 Kashif Ishaq , Sidra Fareed

Cyberattacks targeting critical infrastructures, such as water treatment facilities, represent significant threats to public health, safety, and the environment. This paper introduces a systematic approach for modeling and assessing covert…

Cryptography and Security · Computer Science 2025-11-07 Victor Mattos , João Henrique Schmidt , Amit Bhaya , Alan Oliveira de Sá , Daniel Sadoc Menasché , Gaurav Srivastava

Cybersecurity planning supports the selection of and implementation of security controls in resource-constrained settings to manage risk. Doing so requires considering adaptive adversaries with different levels of strategic sophistication…

Optimization and Control · Mathematics 2023-02-07 Eric B. DuBois , Ashley Peper , Laura A. Albert

Attacks in cyberspace have got attention due to risk at privacy, breach of trust and financial losses for individuals as well as organizations. In recent years, these attacks have become more complex to analyze technically, as well as to…

Networking and Internet Architecture · Computer Science 2016-06-13 Koustav Sadhukhan , Rao Arvind Mallari , Tarun Yadav

Large-scale cyberattacks, referred to as campaigns, are documented across multiple CTI reports from diverse sources, with some providing a high-level overview of attack techniques and others providing technical details. Extracting attack…

Software Engineering · Computer Science 2026-04-10 Md Nazmul Haque , Sivana Hamer , Brandon Wroblewski , Md Rayhanur Rahman , Laurie Williams

Cyber threat intelligence (CTI) encoded in STIX and structured according to the MITRE ATT&CK framework has become a global reference for describing adversary behavior. However, ATT&CK was designed as a descriptive knowledge base rather than…

Cryptography and Security · Computer Science 2026-05-08 Ágney Lopes Roth Ferraz , Sidnei Barbieri , Murray Evangelista de Souza , Lourenço Alves Pereira Júnior

The techniques used in modern attacks have become an important factor for investigation. As we advance further into the digital age, cyber attackers are employing increasingly sophisticated and highly threatening methods. These attacks…

Cryptography and Security · Computer Science 2026-01-21 Alexander Shim

The paper presents an alignment evaluation between the mitigations present in the MITRE's ATT&CK framework and the essential cyber security requirements of the recently introduced Cyber Resilience Act (CRA) in the European Union. In…

Cryptography and Security · Computer Science 2025-10-16 Jukka Ruohonen , Eun-Young Kang , Qusai Ramadan