13.4 C
New York
Wednesday, February 28, 2024

Learn how to interpret the MITRE Engenuity ATT&CK® Evaluations: Enterprise • Graham Cluley


How to interpret the MITRE Engenuity ATT&CK® Evaluations: EnterpriseHow to interpret the MITRE Engenuity ATT&CK® Evaluations: Enterprise

Graham Cluley Safety Information is sponsored this week by the parents at Cynet. Because of the good staff there for his or her assist!

George tubinGeorge tubin
George Tubin, Director of Product Technique, Cynet

Thorough, impartial assessments are an important useful resource as cybersecurity leaders and their groups consider distributors’ skills to protect in opposition to more and more refined threats to their group. And maybe no evaluation is extra extensively trusted than the annual MITRE Engenuity ATT&CK Evaluations: Enterprise.

This analysis is important for testing distributors as a result of it’s just about unimaginable to judge cybersecurity distributors primarily based on their very own efficiency claims. Together with vendor reference checks and proof of worth evaluations (POV) — a stay trial — of their atmosphere, the MITRE Engenuity outcomes add further goal enter to holistically assess cybersecurity distributors.

On this piece, we’ll unpack MITRE Engenuity’s most up-to-date methodology to check safety distributors in opposition to real-world threats, supply our interpretation of the outcomes and establish the highest takeaways rising from the analysis of Cynet’s all-in-one safety resolution.

How does MITRE Engenuity take a look at distributors in the course of the analysis?
The MITRE Engenuity ATT&CK Analysis is carried out by MITRE Engenuity and assessments the endpoint safety options in opposition to a simulated assault sequence primarily based on real-life approaches taken by well-known superior persistent menace (APT) teams. The MITRE Engenuity ATT&CK Evaluations: Enterprise examined 29 vendor options by emulating the assault sequences of Turla, a complicated Russia-based menace group recognized to have contaminated victims in over 45 nations.

An necessary caveat is that MITRE doesn’t rank or rating vendor outcomes. As an alternative, the uncooked take a look at knowledge is printed together with some primary on-line comparability instruments. Consumers then use that knowledge to judge the distributors primarily based on their group’s distinctive priorities and desires. The taking part distributors’ interpretations of the outcomes are simply that — their interpretations.

So, how do you interpret the outcomes?
That’s an awesome query — one which lots of people are asking themselves proper now. The MITRE Engenuity ATT&CK Evaluations: Enterprise outcomes aren’t introduced in a format that many people are used to digesting ( you, magical graph with quadrants).

And impartial researchers typically declare “winners” to lighten the cognitive load of determining which distributors are the highest performers. On this case, figuring out the “finest” vendor is subjective. Which, if you happen to don’t know what to search for, can really feel like a trouble if you happen to’re already pissed off with making an attempt to evaluate which safety vendor is the appropriate match on your group.

With these disclaimers issued, let’s now assessment the outcomes themselves to match and distinction how taking part distributors carried out in opposition to Turla.

MITRE Engenuity ATT&CK Outcomes Abstract

The next tables current Cynet’s evaluation and calculation of all vendor MITRE Engenuity ATT&CK Evaluations: Enterprise take a look at outcomes for a very powerful measurements: Total Visibility, Detection Accuracy, and Total Efficiency. There are a number of different methods to take a look at the MITRE outcomes, however we take into account these to be most indicative of an answer’s means to detect threats.

Total Visibility is the full variety of assault steps detected throughout all 143 sub-steps. Cynet defines Detection High quality as the share of assault sub-steps that included “Analytic Detections – those who establish the tactic (why an exercise could also be occurring) or method (each why and the way the method is going on).

Moreover, it’s necessary to take a look at how every resolution carried out earlier than the seller adjusted configuration settings resulting from lacking a menace. MITRE permits distributors to reconfigure their methods to aim to detect threats that they missed or to enhance the data they provide for detection. In the true world we don’t have the luxurious of reconfiguring our methods resulting from missed or poor detection, so the extra sensible measure is detections earlier than configuration modifications are carried out.

How’d Cynet do?
Based mostly on Cynet’s evaluation, our staff is happy with our efficiency in opposition to Turla within the 2023 MITRE Engenuity ATT&CK Evaluations: Enterprise, outperforming the vast majority of distributors in a number of key areas. Listed here are our high takeaways:

  • Cynet delivered 100% Detection (19 of 19 assault steps) with NO CONFIGURATION CHANGES
  • Cynet delivered 100% Visibility (143 of 143 assault sub-steps) with NO CONFIGURATION CHANGES
  • Cynet delivered 100% Analytic Protection (143 of 143 detections) with NO CONFIGURATION CHANGES
  • Cynet delivered 100% Actual-time Detections (0 Delays throughout all 143 detections)

Let’s dive a bit of deeper into Cynet’s evaluation of a number of the outcomes.

Cynet’s all-in-one safety resolution was a high performer when evaluating each visibility and detection high quality. This evaluation illustrates how nicely an answer does in detecting threats and offering the context essential to make the detections actionable. Missed detections are an invite for a breach, whereas poor high quality detections create pointless work for safety analysts or probably trigger the alert to be ignored, which once more, is an invite for a breach.

Cynet graphic 0Cynet graphic 0


Cynet delivered 100% visibility and completely detected each one of many 143 assault steps utilizing no configuration modifications.
The next chart reveals the share of detections throughout all 143 assault sub-steps earlier than the distributors carried out configuration modifications. Cynet carried out in addition to two very massive, well-known, safety corporations regardless of being a fraction of their measurement and much better than a number of the greatest names in cybersecurity.

Cynet graphic 1Cynet graphic 1

Cynet offered analytic protection for 100% of the 143 assault steps utilizing no configuration modifications. The next chart reveals the share of detections that contained necessary normal, tactic or method info throughout the 143 assault sub-steps, once more earlier than configuration modifications have been carried out. Cynet carried out in addition to Palo Alto Networks, a $115 billion publicly traded firm with 50 occasions the variety of staff, and much better than many established, publicly traded manufacturers.

Cynet graphic 2Cynet graphic 2

Nonetheless have questions?
On this on-demand webinar, Cynet CTO Aviad Hasnis and ISMG SVP Editorial Tom Subject assessment the latest MITRE ATT&CK outcomes and share knowledgeable recommendation for cybersecurity leaders to seek out the seller that most closely fits the precise wants of their group. Additionally they unpack Cynet’s efficiency in the course of the assessments and establish alternatives ot advance your staff’s targets with the all-in-one safety resolution.


In case you’re curious about sponsoring my website for per week, and reaching an IT-savvy viewers that cares about cybersecurity, you possibly can discover extra info right here.




Supply hyperlink

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles