Accelerating Threat-Informed Defense: A Collaborative Approach

Richard Struse
MITRE-Engenuity
Published in
3 min readSep 8, 2020

Today’s cybersecurity challenges are bigger and broader than any given organization, industry sector or national government — that’s why MITRE Engenuity created the Center for Threat-Informed Defense. We advance the state of the art and the state of the practice in threat-informed defense through public-interest research, applying a deep technical understanding of cyber adversaries and their tradecraft.

Center R&D projects fill critical gaps in the global community’s knowledge, tools, and methodologies — gaps too large to be filled by any one organization working in isolation. Our research leverages MITRE’s unique insights and deep technical expertise in combination with the best security teams from companies around the world. Together, we identify the common gaps in threat-informed defense and develop innovative solutions that have global impact.

Some Center projects advance the state of the art, creating entirely new approaches to solving critical problems. Others advance the state of the practice, working to ensure that everyone benefits from our insights and collective experience. Some projects advance both. In all cases the Center and its members are committed to ensuring that the work we do benefits all. To achieve this goal, the Center makes the outputs of its completed R&D projects freely available, to all.

Center R&D projects create outputs that vary depending on the specific nature of the problem and the needs of the community. Some projects extend the MITRE ATT&CK® knowledge base, growing our understanding of cyber adversaries, and their tradecraft. Other projects result in the release of open-source software or the publication of methodologies and frameworks. In addition, there are projects that result in the publication of datasets critical to better understanding adversaries and their movements. The common thread is that all Center projects address practical, real-world problems faced by organizations around the world.

This month, we will publish the Center’s first R&D project, followed by a series of research outputs that we believe will relentlessly improve our collective ability to prevent, detect, and respond to cyber-attacks — changing the game on the adversary. Check out the Center’s website and follow our blog for the latest information.

About the Center for Threat-Informed Defense
The Center is a non-profit, privately funded research and development organization operated by MITRE Engenuity. The Center’s mission is to advance the state of the art and the state of the practice in threat-informed defense globally. Currently comprised of 23 Participant organizations from around the globe with highly sophisticated security teams, the Center builds on MITRE ATT&CK®, an important foundation for threat-informed defense used by security teams and vendors in their enterprise security operations. Because the Center operates for the public good, outputs of its research and development are available publicly and for the benefit of all.

© 2020 MITRE Engenuity. Approved for Public Release. Document number CT0004

--

--