@article{ART002627073},
author={Donghwa Kim and Yong-Hyun Kim and Myung Kil Ahn and Heejo Lee},
title={Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2020},
volume={25},
number={9},
pages={71-80},
doi={10.9708/jksci.2020.25.09.071}
TY - JOUR
AU - Donghwa Kim
AU - Yong-Hyun Kim
AU - Myung Kil Ahn
AU - Heejo Lee
TI - Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training
JO - Journal of The Korea Society of Computer and Information
PY - 2020
VL - 25
IS - 9
PB - The Korean Society Of Computer And Information
SP - 71
EP - 80
SN - 1598-849X
AB - As societies become hyperconnected, we need more cyber security experts. To this end, in this paper, based on the analysis results of the real world cyber attacks and the MITRE ATT&CK framework, we developed CyTEA that can model cyber threats and generate simulated cyber threats in a cyber security training system. In order to confirm whether the simulated cyber threat has the effectiveness of the actual cyber threat level, the simulation level was examined based on procedural, environmental, and consequential similarities. in addition, it was confirmed that the actual defense training using cyber simulation threats is the same as the expected defense training when using real cyber threats in the cyber security training system.
KW - Red team emulation;cyber range;ATT&CK;Operation Dust Storm;threat emulation
DO - 10.9708/jksci.2020.25.09.071
ER -
Donghwa Kim, Yong-Hyun Kim, Myung Kil Ahn and Heejo Lee. (2020). Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training. Journal of The Korea Society of Computer and Information, 25(9), 71-80.
Donghwa Kim, Yong-Hyun Kim, Myung Kil Ahn and Heejo Lee. 2020, "Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training", Journal of The Korea Society of Computer and Information, vol.25, no.9 pp.71-80. Available from: doi:10.9708/jksci.2020.25.09.071
Donghwa Kim, Yong-Hyun Kim, Myung Kil Ahn, Heejo Lee "Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training" Journal of The Korea Society of Computer and Information 25.9 pp.71-80 (2020) : 71.
Donghwa Kim, Yong-Hyun Kim, Myung Kil Ahn, Heejo Lee. Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training. 2020; 25(9), 71-80. Available from: doi:10.9708/jksci.2020.25.09.071
Donghwa Kim, Yong-Hyun Kim, Myung Kil Ahn and Heejo Lee. "Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training" Journal of The Korea Society of Computer and Information 25, no.9 (2020) : 71-80.doi: 10.9708/jksci.2020.25.09.071
Donghwa Kim; Yong-Hyun Kim; Myung Kil Ahn; Heejo Lee. Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training. Journal of The Korea Society of Computer and Information, 25(9), 71-80. doi: 10.9708/jksci.2020.25.09.071
Donghwa Kim; Yong-Hyun Kim; Myung Kil Ahn; Heejo Lee. Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training. Journal of The Korea Society of Computer and Information. 2020; 25(9) 71-80. doi: 10.9708/jksci.2020.25.09.071
Donghwa Kim, Yong-Hyun Kim, Myung Kil Ahn, Heejo Lee. Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training. 2020; 25(9), 71-80. Available from: doi:10.9708/jksci.2020.25.09.071
Donghwa Kim, Yong-Hyun Kim, Myung Kil Ahn and Heejo Lee. "Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training" Journal of The Korea Society of Computer and Information 25, no.9 (2020) : 71-80.doi: 10.9708/jksci.2020.25.09.071