
רמי פוזיס
Extending the ATT&CK coverage of logical attack graphs
Logical attack graphs (LAGs) are used to analyze non-trivial relationships between organizational assets and vulnerabilities for cybersecurity risk assessment in complex computerized environments. They help identify dangerous attack scenarios that extend beyond the immediate impact of vulnerability exploitations. In this article, we focus on MulVAL, one of the most popular open-source LAG frameworks. The expressiveness and extensibility of LAG frameworks allow the addition of new attack scenarios in the form of logical interaction rules. However, the existing set of rules developed for MulVAL covers just 20% of the adversarial techniques listed in the MITRE ATT&CK knowledge base. Furthermore, due to the absence of common coding conventions, the previously proposed interaction rules could not be incorporated into one unified library. In this paper, we define uniform coding conventions based on an ontology proposed by Iannacone et al. and incorporate 351 interaction rules identified in the literature into one comprehensive library supported by a software tool for exploring and managing the interaction rules. Further, we propose a methodology and a semi-automated framework for developing new interaction rules to fill the gap in MITRE ATT&CK coverage and demonstrate them using techniques associated with the MITRE Engenuity ATT&CK Evaluations APT29 scenario.
| שפת פרסום | אנגלית |
| כתב עת | Computers and Security |
| כרך | 170 |
| סטטוס פרסום | פורסם - 01.11.2026 |
| מספר מאמר | 105040 |