Home Cyber Security Learn how to Interpret the 2023 MITRE ATT&CK Analysis Outcomes

Learn how to Interpret the 2023 MITRE ATT&CK Analysis Outcomes

0
Learn how to Interpret the 2023 MITRE ATT&CK Analysis Outcomes

[ad_1]

Sep 22, 2023The Hacker InformationMITRE ATT&CK / Cybersecurity

MITRE ATT&CK Evaluation

Thorough, impartial exams are a significant useful resource for analyzing supplier’s capabilities to protect in opposition to more and more subtle threats to their group. And maybe no evaluation is extra broadly trusted than the annual MITRE Engenuity ATT&CK Analysis.

This testing is essential for evaluating distributors as a result of it is nearly inconceivable to judge cybersecurity distributors based mostly on their very own efficiency claims. Together with vendor reference checks and proof of worth evaluations (POV) — a reside trial — the MITRE outcomes add extra goal enter to holistically assess cybersecurity distributors.

Let’s dive into the 2023 MITRE ATT&CK Analysis outcomes. On this weblog, we’ll unpack MITRE’s methodology to check safety distributors in opposition to real-world threats, provide our interpretation of the outcomes and determine prime takeaways rising from Cynet’s analysis.

How does MITRE Engenuity take a look at distributors in the course of the analysis?

The MITRE ATT&CK Analysis is carried out by MITRE Engenuity and exams endpoint safety options in opposition to a simulated assault sequence based mostly on real-life approaches taken by well-known superior persistent risk (APT) teams. The 2023 MITRE ATT&CK Analysis examined 31 vendor options by emulating the assault sequences of Turla, a classy Russia-based risk group identified to have contaminated victims in over 45 international locations.

An necessary caveat is that MITRE doesn’t rank or rating vendor outcomes. As an alternative, the uncooked take a look at knowledge is revealed together with some primary on-line comparability instruments. Patrons then use that knowledge to judge the distributors based mostly on their group’s distinctive priorities and wishes. The collaborating distributors’ interpretations of the outcomes are simply that — their interpretations.

So, how do you interpret the outcomes?

That is an awesome query — one which lots of people are asking themselves proper now. The MITRE ATT&CK Analysis outcomes aren’t offered in a format that many people are used to digesting ( you, magical graph with quadrants).

And impartial researchers usually declare “winners” to lighten the cognitive load of determining which distributors are the highest performers. On this case, figuring out the “greatest” vendor is subjective. Which, if you do not know what to search for, can really feel like a problem for those who’re already annoyed with attempting to evaluate which safety vendor is the fitting match to your group.

With these disclaimers issued, let’s now assessment the outcomes themselves to match and distinction how collaborating distributors carried out in opposition to Turla.

MITRE ATT&CK Outcomes Abstract

The next tables current Cynet’s evaluation and calculation of all vendor MITRE ATT&CK take a look at outcomes for crucial measurements: General Visibility, Detection Accuracy, and General Efficiency. There are plenty of different methods to have a look at the MITRE outcomes, however we think about these to be most indicative of an answer’s potential to detect threats.

General Visibility is the whole variety of assault steps detected throughout all 143 sub-steps. Cynet defines Detection High quality as the share of assault sub-steps that included “Analytic Detections – those who determine the tactic (why an exercise could also be occurring) or method (each why and the way the method is occurring).

Moreover, it is necessary to have a look at how every answer carried out earlier than the seller adjusted configuration settings as a consequence of lacking a risk. MITRE permits distributors to reconfigure their techniques to aim to detect threats that they missed or to enhance the data they provide for detection. In the true world we do not have the luxurious of reconfiguring our techniques as a consequence of missed or poor detection, so the extra practical measure is detections earlier than configuration adjustments are carried out.

How’d Cynet do?

Based mostly on Cynet’s evaluation, our group is happy with our efficiency in opposition to Turla on this 12 months’s MITRE ATT&CK Analysis, outperforming nearly all of distributors in a number of key areas. Listed here are our prime takeaways:

  • Cynet delivered 100% Detection: (19 of 19 assault steps) with NO CONFIGURATION CHANGES
  • Cynet delivered 100% Visibility: (143 of 143 assault sub-steps) with NO CONFIGURATION CHANGES
  • Cynet delivered 100% Analytic Protection: (143 of 143 detections) with NO CONFIGURATION CHANGES
  • Cynet delivered 100% Actual-time Detections: (0 Delays throughout all 143 detections)

See the complete evaluation of Cynet’s efficiency within the 2023 MITRE ATT&CK Analysis.

Let’s dive just a little deeper into Cynet’s evaluation of a number of the outcomes.

Cynet was a prime performer when evaluating each visibility and detection high quality. This evaluation illustrates how properly an answer does in detecting threats and offering the context essential to make the detections actionable. Missed detections are an invite for a breach, whereas poor high quality detections create pointless work for safety analysts or doubtlessly trigger the alert to be ignored, which once more, is an invite for a breach.

MITRE ATT&CK Evaluation

Cynet delivered 100% visibility and completely detected each one of many 143 assault steps utilizing no configuration adjustments. The next chart reveals the share of detections throughout all 143 assault sub-steps earlier than the distributors carried out configuration adjustments. Cynet carried out in addition to two very giant, well-known, safety corporations regardless of being a fraction their dimension and much better than a number of the largest names in cybersecurity.

MITRE ATT&CK Evaluation

Cynet supplied analytic protection for 100% of the 143 assault steps utilizing no configuration adjustments. The next chart reveals the share of detections that contained necessary tactic or method data throughout the 143 assault sub-steps, once more earlier than configuration adjustments have been carried out. Cynet carried out in addition to Palo Alto Networks, a $76 billion publicly traded firm with 50 instances the variety of workers and much better than many established, publicly traded manufacturers.

MITRE ATT&CK Evaluation

Nonetheless have questions?

Comprehensible.

In this webinar, Cynet CTO Aviad Hasnis and ISMG SVP Editorial Tom Subject assessment the just lately launched outcomes and share skilled recommendation for cybersecurity leaders to interpret the outcomes to search out the seller that most closely fits the precise wants of their group. He’ll additionally share extra particulars on Cynet’s efficiency in the course of the exams and the way that might translate to your group’s distinctive targets.

Discovered this text fascinating? Comply with us on Twitter and LinkedIn to learn extra unique content material we submit.



[ad_2]