KIT | KIT-Bibliothek | Impressum | Datenschutz

Dataset: AVIATOR: A MITRE Emulation Plan-Derived Living Dataset for Advanced Persistent Threat Detection and Investigation

Liu, Qi ORCID iD icon 1
1 Institut für Automation und angewandte Informatik (IAI), Karlsruher Institut für Technologie (KIT)

Abstract:

With the growing trend for developing new detection and investigation systems for Advanced Persistent Threat (APT), the urgent issue of lacking sound and authentic datasets becomes more visible. New datasets for research on APT detection and investigation have been released over the past few years in an accelerated manner. Yet, our examination of the existing datasets yields the finding that the gap between these datasets’ attack scenarios and real-world APT attacks is significant. Recognizing the flaws of prior datasets particularly in terms of attack scenario complexity and authenticity, we develop a novel sound dataset called Aviator, which is backed by MITRE emulation plans. The well-known organization MITRE has released nearly a dozen emulation plans, which closely reproduce APT groups’ real-world attack campaigns observed in the past. However MITRE has not published any datasets. Thus, we resort to stringently implementing these emulation plans. Further, we extend these emulation plans to include an industrial control system and attack steps on it, mimicking APT groups most known for their attacks against critical infrastructures in the past. ... mehr

Zugehörige Institution(en) am KIT Institut für Automation und angewandte Informatik (IAI)
Publikationstyp Forschungsdaten
Publikationsjahr 2025
Identifikator KITopen-ID: 1000179709
HGF-Programm 37.12.01 (POF IV, LK 01) Digitalization & System Technology for Flexibility Solutions
Weitere HGF-Programme 46.23.02 (POF IV, LK 01) Engineering Security for Energy Systems
Lizenz Creative Commons Namensnennung 4.0 International
Schlagwörter Computer Science, Datensatz, Advanced Persistent Threat emulation, data provenance analysis, auditing, logging
Art der Forschungsdaten Dataset
URL https://radar.kit.edu/radar/en/dataset/8s5b0u5yqgfs2y0d
Rechteinhaber Karlsruhe Institute Of Technology

Download
Originalveröffentlichung
DOI: 10.35097/8s5b0u5yqgfs2y0d
Seitenaufrufe: 43
seit 03.03.2025
KIT – Die Forschungsuniversität in der Helmholtz-Gemeinschaft
KITopen Landing Page