MITRE Engenuity’s Center for Threat Informed Defense partnered with several security vendors and alliances to create a data format describing adversary behavior sequences to help identify cyberthreat choke points. Project partners include Fortinet, Cybereason, Microsoft, Verizon, Fujitsu, Anomali, AttackIQ, Citi, and HCA Healthcare. 

The Attack Flow project offers machine-readable information including a list of actions, assets, knowledge properties, and causal relationships between those actions and assets. It addresses the challenges of explaining targeted assets to executives and figuring out steps after identifying specific tactics, techniques, and procedures (TTPs).

Attackers have a very large toolkit today for ransomware or phishing campaigns, and “they all have different but often similar techniques that they're using,” Derek Manky, chief of security insights and VP of Global Threat Alliances at Fortinet, told SDxCentral. “So this is why it's really important to understand and essentially map what's happening with the latest attack techniques.”

The project is focused on helping security teams “​​​​express adversary activity in that sequence in that chain of activities to more richly describe what they were seeing happen and be able to share intel with that,” added Ingrid Skoog, assistant director of research and development at MITRE Engenuity's Center for Threat-Informed Defense.

She shared an example of one key use case for the project. When MITRE had an adversary in its network, the organization had to figure out the response plan, including how to brief C-suite executives. 

The project is “a pictorial showing of what the adversary did at each step, and that's such a valuable thing to show up to executives,” Skoog said. “It's a means to communicate across different technical expertise with what's happening.”

Watch and Learn

It is also designed to understand lessons learned from earlier incidents and build adversary emulation scenarios. 

Attack Flow is the second project coming from the MITRE and Fortinet partnership following the Sightings project. It analyzed data from project participants and other data contributors to build a “heat map” showing the most used cyberattacker TTPs.

Those projects help organizations to get ahead of adversaries and “​​identify things like choke points we call them, where could we cut off the snake to be able to not have them achieve their goals and help defend our organizations and customers better,” Skoog explained.

“The choke point is very important because this is a disruption piece we often talk about … this is a way that we can actually hit them with a pain point by disrupting their model,” Manky echoed. “That's a cost on their end and that's a win in our books.”