4 papers
Beyond Single Reports: Evaluating Automated ATT&CK Technique Extraction in Multi-Report Campaign Settings
Md Nazmul Haque, Sivana Hamer, Brandon Wroblewski +2
Large-scale cyberattacks, referred to as campaigns, are documented across multiple CTI reports from diverse sources, with some providing a high-level overview of attack techniques…
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
Sivana Hamer, Jacob Bowen, Md Nazmul Haque +3
The MITRE Adversarial Tactics, Techniques and Common Knowledge (MITRE ATT&CK) Attack Technique to Proactive Software Supply Chain Risk Management Framework (P-SSCRM) Task mapping d…
Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ Utils
Sivana Hamer, Jacob Bowen, Md Nazmul Haque +3
Software supply chain frameworks, such as the US NIST Secure Software Development Framework (SSDF), detail what tasks software development organizations are recommended or mandated…
Analyzing Challenges in Deployment of the SLSA Framework for Software Supply Chain Security
Mahzabin Tamanna, Sivana Hamer, Mindy Tran +3
In 2023, Sonatype reported a 200\% increase in software supply chain attacks, including major build infrastructure attacks. To secure the software supply chain, practitioners can f…