본문 바로가기
  • Home

Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training

  • Journal of The Korea Society of Computer and Information
  • Abbr : JKSCI
  • 2020, 25(9), pp.71-80
  • DOI : 10.9708/jksci.2020.25.09.071
  • Publisher : The Korean Society Of Computer And Information
  • Research Area : Engineering > Computer Science
  • Received : July 29, 2020
  • Accepted : September 5, 2020
  • Published : September 29, 2020

Donghwa Kim 1 Yong-Hyun Kim 2 Myung Kil Ahn 3 Heejo Lee 1

1고려대학교
2국방과학연구소
3중앙대학교

Accredited

ABSTRACT

As societies become hyperconnected, we need more cyber security experts. To this end, in this paper, based on the analysis results of the real world cyber attacks and the MITRE ATT&CK framework, we developed CyTEA that can model cyber threats and generate simulated cyber threats in a cyber security training system. In order to confirm whether the simulated cyber threat has the effectiveness of the actual cyber threat level, the simulation level was examined based on procedural, environmental, and consequential similarities. in addition, it was confirmed that the actual defense training using cyber simulation threats is the same as the expected defense training when using real cyber threats in the cyber security training system.

Citation status

* References for papers published after 2023 are currently being built.

This paper was written with support from the National Research Foundation of Korea.