logo
        • Who We Are
        • Learn more about MITRE Engenuity’s journey as a hub for transformative innovation.

        • How We Engage
        • We forge innovative partnerships to generate whole-of-nation solutions to complex technological problems.

        • Contact Us
        • Connect with a member of the MITRE Engenuity team and ensure your inquiry gets to the right people.

        • Semiconductors
        • Dive into the revolutionary work that MITRE Engenuity is doing within this critical ecosystem.

        • Circuit Talk
        • Hear directly from the semiconductor experts through our speaker series featuring titans of industry, groundbreaking researchers, and many more.

        • Cybersecurity
        • We are relentlessly advancing the art of threat-informed defense, anchored by a belief that we can improve our defenses with a systemic application of a deep understanding of adversary tradecraft and technology.

        • ATT&CK Evaluations
        • We offer objective analysis of cyber products and features – see our latest results.

        • Center for Threat-Informed Defense
        • Read more about the cutting-edge research and development being done with input from our participant organizations, featuring some of the top security operations centers.

        • MITRE ATT&CK Defender
        • Strengthen your threat-informed defense capabilities with our cybersecurity trainings taught by MITRE ATT&CK subject matter experts.

        • Telecom
        • The transformative power of 5G shifts paradigms across industries and empowers businesses to change the way they interact with people. See how MITRE Engenuity is impacting the next generation of telecommunications. 

        • Open Generation 5G Consortium
        • We are getting to our 5G future faster. Discover how we are accelerating network technology and device-to-device application innovation through use case-focused R&D in the Open Generation 5G Consortium.

        • Health
        • We identify potential health security threats to ensure faster public health pandemic responses and incubate new ideas to ensure national health security.

        • Growing Impact
        • We deliver positive public impact through advanced technological innovation projects.

        • Cyber Risk Model for Mobile Digital Financial Services: Securing Mobile Money Services. Explore Our Cyber Risk Model for Mobile Financial Services product
        • Embedded Capture the Flag: Developing Tomorrow's Cyber Workforce Today. Get Involved with MITRE's Embedded Capture the Flag Competition
        • News & Insights
        • We are leading the leading edge of innovation. Explore the latest news, insights, R&D, and special projects from our advanced tech experts and partners.

MITRE Engenuity Announces ATT&CK Evaluations for ICS Vendors

  • May 5, 2020
Aerial view of industrial plant

Evaluations to Focus on Malware Capable of Physical Damage

McLean, VA, and Bedford, MA, May 5, 2020Â - MITRE's foundation for public good, MITRE Engenuity, will conduct an ATT&CKâ„¢ evaluation to assess industrial control system (ICS) cybersecurity vendors against the threat posed by Triton. This Russian-linked malware is one of the most disruptive and destructive types targeting critical infrastructure.

Triton has been used to compromise industrial systems across the globe, including oil and gas and electrical plants in the Middle East, Europe, and North America. Triton targets safety systems, preventing a response to a failure, hazard, or other unsafe conditions. Triton is one of the few known malware attacks in the ICS space capable of physical destruction.

The evaluations use ATT&CK for ICS, a MITRE-curated knowledge base of adversary tactics, techniques, and procedures based on known threats to industrial control systems. Announced in January 2020, ATT&CK for ICS provides common language to describe the tactics and techniques that cyber adversaries use when attacking the systems that operate some of the nation's most critical infrastructures, including energy transmission and distribution plants, oil refineries, wastewater treatment facilities, and more.

The ICS network detection landscape has changed rapidly in recent years, with the development of new solutions and improving technological approaches, said Otis Alexander, the lead for ATT&CK Evaluations for ICS and an engineer focusing on ICS cybersecurity at MITRE. The new ATT&CK Evaluations for ICS will offer an objective, independent assessment to help vendors improve their products.

To approximate real-life threat conditions, ATT&CK Evaluations for ICS will use a realistic control system testbed. The testbed will represent elements of a Saudi petrochemical facility attacked by the Triton malware in 2017.

"A reliable and realistic test environment is crucial for meaningful evaluations," said Frank Duff, who oversees ATT&CK Evaluations. "We will build a simulated control system, with physical components, to evaluate vendors products."

This latest set of evaluations will be conducted by MITRE Engenuity, a non-profit tech foundation launched last November to collaborate with the private sector on complex public interest challenges, including securing and protecting industrial control systems that help keep America safe.

Cybersecurity vendors may apply for an evaluation via evals@mitre-engenuity.org. The evaluations are paid for by vendors and are intended to help vendors and end users better understand their product's capabilities in relation to MITRE's publicly accessible ATT&CK for ICS knowledge base. Results will be announced in early 2021. ATT&CK Evaluations do not provide scores, ranks, or endorsements.

 

About MITRE Engenuity

MITRE Engenuity is a non-profit tech foundation that collaborates with the private sector on challenges that require a public interest solution, like cybersecurity, infrastructure resilience, healthcare effectiveness, and next generation communications.

 

About MITRE ATT&CK

ATT&CKâ„¢ was created by MITRE's internal research program from its own data and operations. ATT&CK is entirely based on published, open source threat information. Increasingly, ATT&CK is driven by contributions from external sources.

Media contact:

Jordan Graham

media@mitre-engenuity.org

Related Posts

Loading

Load More