MARATTO

article · Symmetry

Temporal MITRE ATT&CK Modelling for Residual Time-to-Compromise Estimation in Multi-Stage Attacks

Abstract

Security operations can detect that an intrusion is under way, yet they cannot say how long an ongoing attack still needs to reach a critical objective such as data exfiltration. Prior work on multi-stage attacks identifies the active stage or predicts the next step, but does not estimate the residual time to compromise from real traffic using survival models. This paper addresses that gap through a temporal framework built on empirically measured stage durations, with three contributions. First, the MITRE ATT&CK taxonomy is given a temporal layer, in which each stage carries a duration distribution estimated empirically from the observed episodes of that stage. Second, a probability-weighted multi-path formulation combines these durations with stage-transition probabilities to estimate the time remaining before the objective. Third, the framework is validated on a real multi-stage campaign rather than on synthetic traffic, and three survival models are compared under a matched protocol as a benchmark of how learnable the durations are. Random Survival Forest, DeepSurv, and DeepHit are compared on DAPT 2020, a public advanced-persistent-threat dataset of 82,577 real network flows collected across five days. Random Survival Forest reaches a stable concordance index of 0.92, with a standard deviation of 0.006 across twenty repeated stratified splits on leakage-free features, and it retains a concordance of 0.79 when benign traffic is excluded entirely. When the three models are placed on a single concordance scale and trained on an identical subsample of 40,000 flows, DeepSurv reaches 0.955 and DeepHit 0.879, so the neural models are competitive at that scale. DeepSurv nevertheless fails to converge on the full flow set, returning no survival estimates in any of five seeds, whereas the forest fits successfully at every training size examined. A stage-transition graph recovered from the data, built from 25 observed transitions across ten multi-stage sessions, shows branching progression, and the residual time, reported at the entry to each stage, falls along the campaign, from about 139 min at reconnaissance to about 31 min at lateral movement, conditional on reaching the objective. All stage-level estimates rest on 74 episodes from a single campaign, of which 43 carry a positive duration, so cross-environment generalisation remains to be confirmed. The framework gives a security operations centre a data-driven estimate of the active attack effort that remains before compromise, supporting informed containment decisions.

Research topics

  • Network Security and Intrusion Detection
  • Software-Defined Networks and 5G
  • Information and Cyber Security

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.3390/sym18091439

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.