-

MITRE Launches D3FEND™ 1.0 – A Milestone in Cybersecurity Ontology

MCLEAN, Va. & BEDFORD, Mass.--(BUSINESS WIRE)--MITRE released D3FENDTM 1.0, a cybersecurity ontology and knowledgebase designed to establish a vocabulary and conceptualization of the cyber domain.

Funded by NSA and OUSD, D3FEND 1.0 provides a stable, extensible, and integration-friendly framework for cybersecurity operations and strategic decision-making.

Share

Funded by the National Security Agency, the Cyber Warfare Directorate in the U.S. Office of the Under Secretary of Defense for Acquisition and Sustainment, and the U.S. Office of the Under Secretary of Defense for Research and Engineering, D3FEND 1.0 provides a stable, extensible, and integration-friendly framework for cybersecurity operations and strategic decision-making.

First introduced as a beta-level release in June 2021, D3FEND has steadily grown over three years of consistent development and community contributions, tripling its semantic graph in size since its initial release. The collaboration of experts across government and industry, from security architects to detection engineers, has been shaped into the large and use case-driven model that D3FEND is launching today.

“With D3FEND, we are leaning forward with the greater cybersecurity community,” said Wen Masters, vice president, cyber technologies, MITRE. “D3FEND 1.0 reflects the collective expertise and vision of a diverse cybersecurity community. It's more than just a tool—it's a pathway to smarter, more nuanced defensive strategies. Our goal is to ensure D3FEND is adaptable and valuable across a wide range of cybersecurity domains.”

“D3FEND is effectively a model for what cyber defenders are doing in their day-to-day activities, but it’s trying to establish a common language for those activities and the system components to which they apply,” said Peter Kaloroumakis, principal applied ontologist, MITRE. “Even though D3FEND focuses on technology, it’s really solving a human problem. Getting everyone on the same page with a common language and Rosetta Stone is essential for doing in-depth, strategic analysis on your investments and building secure systems.”

Key Features and Enhancements in D3FEND 1.0

  • Cyber Attack-Defense (CAD) Tool: CAD enables D3FEND users to put the full ontology into action for their specific cybersecurity scenarios. Users can drag, drop, and link nodes on the canvas. Then, users can right-click to explore and incorporate D3FEND’s inference and share their CAD graphs on the internet or private networks.
  • Expanded Defensive Techniques & Taxonomies: With ontology additions for identity and access control concepts, operational technology, and source code hardening, D3FEND 1.0 also includes ontological modeling and incorporation of the Common Weakness Enumeration (CWE™) to support vulnerability modeling use cases.
  • Ontological Precision & Extensibility: Built upon OWL 2 DL, the D3FEND 1.0 release includes an interface, D3FEND Core Classes, which enables alignment to major upper ontologies, ensuring compatibility for broader semantic applications.
  • Transparency in D3FEND Updates: With a new content-lifecycle strategy, D3FEND ensures seamless adaptation as it evolves, offering predictable updates for users and software developers.

“This milestone is not an end—it’s a beginning, and we are just getting started,” said Kaloroumakis. “We’re committed to ongoing engagement with the cybersecurity community to refine and expand the framework, ensuring it meets the demands of an increasingly sophisticated landscape.”

MITRE invites cyber engineers and other industry professionals to explore D3FEND 1.0, as participation in the community is integral to the continued success and utility of the ontology. With D3FEND, MITRE continues its legacy of delivering innovative solutions and open-source tools that push the boundaries of cybersecurity defense.

About MITRE

MITRE’s mission-driven teams are dedicated to solving problems for a safer world. Through our public-private partnerships and federally funded R&D centers, we work across government and in partnership with industry to tackle challenges to the safety, stability, and well-being of our nation. Learn more at mitre.org.

Contacts

Lisa Fasold, media@mitre.org

MITRE


Release Versions
$Cashtags

Contacts

Lisa Fasold, media@mitre.org

Social Media Profiles
More News From MITRE

MITRE and FAA Introduce Novel Aerospace Large Language Model Evaluation Benchmark

MCLEAN, Va.--(BUSINESS WIRE)--The Federal Aviation Administration (FAA) and MITRE are introducing a new benchmark to enable the evaluation and assessment of large language models (LLMs) for aerospace tasks. Given the safety-critical nature of aerospace, it is imperative that LLMs undergo thorough evaluation prior to their integration into systems. The Aerospace Language Understanding Evaluation (ALUE) benchmark provides a crucial tool for guiding the assurance of LLMs tailored to the unique dem...

New Defense Acquisition Framework to Accelerate Technology Transition to Warfighters

MCLEAN, Va., & BEDFORD, Mass.--(BUSINESS WIRE)--The National Security Engineering Center (NSEC), a federally funded research and development center (FFRDC) operated by MITRE, unveiled the Transition Maturity Framework (TMaF) today. TMaF is a comprehensive defense acquisition framework developed to streamline the transition of innovative technologies from research labs to active deployment with U.S. warfighters. The framework addresses persistent challenges by providing a structured acquisition...

Lloyds Banking Group Becomes First U.K. Financial Services Benefactor of MITRE ATT&CK®

MCLEAN, Va. & LONDON--(BUSINESS WIRE)--Lloyds Banking Group has become the first U.K. financial services benefactor of MITRE ATT&CK® to help globally advance threat-informed defense. The MITRE ATT&CK open-source framework enables organizations to understand how adversaries operate so they can better manage cyber risks and strengthen defenses. MITRE ATT&CK is a cornerstone of Lloyds Banking Group’s cyber defense strategy, providing a unified language to describe and analyze adversary...
Back to Newsroom