|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/mitre-tram-mapping-threat-reports-to-attck/
课程评论:没有评论
**课程名称:** MITRE TRAM:将威胁报告映射到 ATT&CK **课程概述:** 本课程将介绍 MITRE TRAM,一个基于网络的开源工具,旨在自动化从网络威胁情报报告中提取对手行为,并将其映射到 MITRE ATT&CK® 框架。TRAM 平台旨在推动自动化将网络威胁情报报告映射到 ATT&CK 的研究,使研究人员能够测试和优化识别 ATT&CK 技术(例如在文本报告中)的机器学习(ML)模型。同时,它也允许威胁情报分析师训练 ML 模型并验证其结果。 **课程目标:** * 降低将 ATT&CK 集成到社区网络威胁情报中的成本。 * 提高将 ATT&CK 集成到社区网络威胁情报的有效性。 * 为威胁情报提供商、威胁情报平台和分析师提供一个更轻松、更一致地将 ATT&CK 集成到其产品中的方法。 * 简化分析报告和提取 ATT&CK 技术的过程。 * 通过自动化映射到 ATT&CK,减少分析师的疲劳,提高 ATT&CK 的覆盖面,并改善威胁情报映射的一致性和准确性。 **TRAM 的工作原理:** 1. **获取数据:** 通过 STIX & TAXII 或威胁情报平台(TIP)。 2. **清理数据。** 3. **训练模型。** 4. **收集报告:** 支持报告上传。 5. **测试数据**(通过 ML 模型)。 6. **接受或审查模型决策**(包括分数和技术)。 7. **反馈循环。** **TRAM 的作用:** 1. **简化 ATT&CK 入门。** 2. **解决记忆大量技术(266+ 且不断增长)的挑战**,因为 MITRE ATT&CK 是一个动态更新的框架。 3. **利用重要的报告信息。** **总结:** 本课程重点介绍 TRAM 工具如何通过自动化手段,协助用户更有效地分析威胁报告,将其中的对手行为准确地映射到 MITRE ATT&CK 框架,从而提升威胁情报工作的效率和质量。TRAM 的公开 Beta 版本现已面向 ATT&CK 社区发布。
TRAM is a web-based tool that automates the extraction of adversary behaviors for the purpose of mapping them to ATT & CK.TRAM is an open-source platform designed to advance research into automating the mapping of cyber threat intelligence reports to MITRE ATT & CK®. TRAM enables researchers to test and refine Machine Learning (ML) models for identifying ATT & CK techniques in prose-based threat intel reports and allows threat intel analysts to train ML models and validate ML results.Through research into automating the mapping of cyber threat intel reports to ATT & CK, TRAM aims to reduce the cost and increase the effectiveness of integrating ATT & CK into cyber threat intelligence across the community. Threat intel providers, threat intel platforms, and analysts should be able to use TRAM to integrate ATT & CK more easily and consistently into their products.Threat Report ATT & CK Mapper (TRAM) aims to provide a streamlined approach for analyzing reports and extracting ATT & CK techniques. Our hope is that automating mapping to ATT & CK can reduce analyst fatigue, increase ATT & CK coverage, and improve consistency and accuracy of threat intelligence mappings. We are excited to now share a public beta of TRAM with the ATT & CK community.TRAM Under the Hood:1. Get Data: STIX & TAXII >> TIP 2. Clean the Data.3. Train Model.4. Collect Reports. >> Report Uploading5. Test Data.(Through ML Models).6. Accept or Review Model Decisions.(Score & Technique).7. Feedback loop.How TRAM is a Enabler:1. Make it easier to get started with ATT & CK.2. Remembering 266+ techniques is hard.>> Not only 266+ but is ever growing..>> MITRE ATT & CK is a Live framework.3. Use Reporting which is important.