Site navigation

UN Introduces New Cyber-attack Assessment Framework

Elizabeth Greenberg

,

UN cyber-attack framework
The UNIDIR Intrusion Path model builds on and compliments two well-established tools – MITRE ATT&CK and the Kill Chain Frameworks – for analysing malicious ICT activities.

The UN Institute for Disarmament Research (UNIDR) has introduced a new cyber-attack assessment framework to build on existing frameworks.

“The international community and non-technical stakeholders often face several challenges in understanding malicious [information communication technology] activities, either due to the complex language used by the technical community or the frequently simplistic language used by media to portray ICT incidents,” the UN wrote.

The new UNIDR Intrusion Path Framework is an accessible framework to analyse both malicious and security activities in the information communication technologies (ICT) environment, built around the concept of the network perimeter, which categorises the ICT environment into the dichotomy of outside and inside according to an organisation’s network.

With this spatial understanding of the ICT environment, it aims to help visualise the different layers where ICT activities can take place, thus offering a tool to make cyber diplomacy more inclusive and better informed.

A network perimeter refers to those systems that delimit a specific network from the broader internet, mostly by managing security of and access to internal networks.

This then creates three key layers of analysis, outside, on, and inside the perimeter.

Outside the perimeter encompasses all systems, networks, and data sources that exist beyond an organisation’s direct control.

On the perimeter represents the boundary between an organisation’s internal systems and the external world: a boundary that is protected by layers of security meant to filter, monitor, and control access.


Recommended reading


Inside the perimeter is the internal, private part of an organisation’s network, often characterised by a series of segmented and monitored subnetworks and devices that house sensitive data and operational systems.

The UNIDIR Intrusion Path model builds on and compliments two well-established tools – MITRE ATT&CK and the Kill Chain Frameworks – for analysing malicious ICT activities.

The UN says that its elements are compatible and include each to these framework’s categorisations.

“As malicious activities in the ICT environment increase and pose growing threats to international peace and stability, it is essential to equip policymakers, practitioners and other stakeholders with tools to understand, inform and act for a more transparent, stable and peaceful digital space,” the UN wrote. “We hope that the UNIDIR Intrusion Path will contribute to this end.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data