-

MITRE Engenuity Announces ATT&CK Evaluations for ICS Vendors

Evaluations to Focus on Malware Capable of Physical Damage

MCLEAN, Va. & BEDFORD, Mass.--(BUSINESS WIRE)--MITRE’s foundation for public good, MITRE Engenuity, will conduct an ATT&CK® evaluation to assess industrial control system (ICS) cybersecurity vendors against the threat posed by Triton. This Russian-linked malware is one of the most disruptive and destructive types targeting critical infrastructure.

Triton has been used to compromise industrial systems across the globe, including oil and gas and electrical plants in the Middle East, Europe, and North America. Triton targets safety systems, preventing a response to a failure, hazard, or other unsafe conditions. Triton is one of the few known malware attacks in the ICS space capable of physical destruction.

The evaluations use ATT&CK for ICS, a MITRE-curated knowledge base of adversary tactics, techniques, and procedures based on known threats to industrial control systems. Announced in January 2020, ATT&CK for ICS provides common language to describe the tactics and techniques that cyber adversaries use when attacking the systems that operate some of the nation’s most critical infrastructures, including energy transmission and distribution plants, oil refineries, wastewater treatment facilities, and more.

“The ICS network detection landscape has changed rapidly in recent years, with the development of new solutions and improving technological approaches,” said Otis Alexander, the lead for ATT&CK Evaluations for ICS and an engineer focusing on ICS cybersecurity at MITRE. “The new ATT&CK Evaluations for ICS will offer an objective, independent assessment to help vendors improve their products.”

To approximate real-life threat conditions, ATT&CK Evaluations for ICS will use a realistic control system testbed. The testbed will represent elements of a Saudi petrochemical facility attacked by the Triton malware in 2017.

“A reliable and realistic test environment is crucial for meaningful evaluations,” said Frank Duff, who oversees ATT&CK Evaluations. “We will build a simulated control system, with physical components, to evaluate vendors’ products.”

This latest set of evaluations will be conducted by MITRE Engenuity, a non-profit tech foundation launched last November to collaborate with the private sector on complex public interest challenges, including securing and protecting industrial control systems that help keep America safe.

Cybersecurity vendors may apply for an evaluation via evals@mitre-engenuity.org. The evaluations are paid for by vendors and are intended to help vendors and end users better understand their product’s capabilities in relation to MITRE’s publicly accessible ATT&CK for ICS knowledge base. Results will be announced in early 2021. ATT&CK Evaluations do not provide scores, ranks, or endorsements.

About MITRE Engenuity

MITRE Engenuity is a non-profit tech foundation that collaborates with the private sector on challenges that require a public interest solution, like cybersecurity, infrastructure resilience, healthcare effectiveness, and next generation communications. www.mitre-engenuity.org

About MITRE ATT&CK

ATT&CK® was created by MITRE’s internal research program from its own data and operations. ATT&CK is entirely based on published, open source threat information. Increasingly, ATT&CK is driven by contributions from external sources.

Contacts

Media:
Jordan Graham
media@mitre-engenuity.org

MITRE Engenuity Logo
MITRE Engenuity Logo

MITRE Engenuity


Release Summary
MITRE Engenuity will test cybersecurity vendors' ability to withstand attacks from TRITON, a type of malware that targets industrial control systems
Release Versions

Contacts

Media:
Jordan Graham
media@mitre-engenuity.org

More News From MITRE Engenuity

MITRE and FAA Introduce Novel Aerospace Large Language Model Evaluation Benchmark

MCLEAN, Va.--(BUSINESS WIRE)--The Federal Aviation Administration (FAA) and MITRE are introducing a new benchmark to enable the evaluation and assessment of large language models (LLMs) for aerospace tasks. Given the safety-critical nature of aerospace, it is imperative that LLMs undergo thorough evaluation prior to their integration into systems. The Aerospace Language Understanding Evaluation (ALUE) benchmark provides a crucial tool for guiding the assurance of LLMs tailored to the unique dem...

New Defense Acquisition Framework to Accelerate Technology Transition to Warfighters

MCLEAN, Va., & BEDFORD, Mass.--(BUSINESS WIRE)--The National Security Engineering Center (NSEC), a federally funded research and development center (FFRDC) operated by MITRE, unveiled the Transition Maturity Framework (TMaF) today. TMaF is a comprehensive defense acquisition framework developed to streamline the transition of innovative technologies from research labs to active deployment with U.S. warfighters. The framework addresses persistent challenges by providing a structured acquisition...

Lloyds Banking Group Becomes First U.K. Financial Services Benefactor of MITRE ATT&CK®

MCLEAN, Va. & LONDON--(BUSINESS WIRE)--Lloyds Banking Group has become the first U.K. financial services benefactor of MITRE ATT&CK® to help globally advance threat-informed defense. The MITRE ATT&CK open-source framework enables organizations to understand how adversaries operate so they can better manage cyber risks and strengthen defenses. MITRE ATT&CK is a cornerstone of Lloyds Banking Group’s cyber defense strategy, providing a unified language to describe and analyze adversary...
Back to Newsroom