A.T.O.M - A Next-Generation Threat Modelling Framework

Introduction

Threat modelling is an art. When done correctly, it is like a superpower that allows you to adjust your defensive behaviours based on what you’re facing in real-world scenarios, not just for applications, systems, networks, or a business but for anything.

The power of threat modelling lies in its ability to systematically evaluate the security posture of a user, system, application or business (an asset) from an attacker's perspective. By understanding the adversary's tactics, techniques, and procedures (TTPs), an organisation can accurately prioritise risks and implement appropriate security controls before real damage occurs.

Threat modelling supports the belief that defence is most effective with an accurate and clear understanding of the offence. This process involves identifying valuable technology and information assets, including data flow through a system, potential vulnerabilities, and the likely threat actors and their objectives.

Following this process, organisations can paint a comprehensive picture (continuing with the art analogy) of their threat landscape by leveraging open-source threat intelligence and mapping this information to valid attack vectors identified within the target environment.

In essence, threat modelling is crucial for any cybersecurity defence strategy as it transitions security from reactive to proactive. It ensures that security measures are aligned with actual business risks and that resources are allocated and prioritised to protect against the most critical threats. 

Common Pain Points

Complexity & Effort

A detailed threat assessment of any significant value will always have an inherent amount of complexity and effort associated with it, which is to be expected. 

Depending on the methodology used, threat modelling can become increasingly complex and time-consuming. With significant technological advances in recent years, the number of systems and applications introduced daily has exploded. The ease of deployment, scalability, and efficiency provided by cloud service providers (CSPs) have also meant a significant change in security is required.

The rapid rate of systems and applications coming online requires a faster, more efficient and scaleable method for assessing our most critical systems and applications hosting sensitive information so that we intimately understand the potential weaknesses and vulnerabilities before malicious adversaries can exploit them. 


Subjectivity

The accuracy and effectiveness of a threat model assessment can vary depending on who is performing the assessment. Certain factors like experience, knowledge, training and cognitive bias can all lead to an inaccurate or incomplete threat model, leaving potential exposures unmitigated and adding several hours or even weeks of wasted effort.  

Subjectivity becomes an even greater challenge in environments where there is a heavy dependency on contingent workers. This is because each person applies their own security lens when performing threat assessments and often uses one or more different frameworks to assess their findings. In real-world scenarios, this often leads to missed exposures and inaccurate assessments.

Unconsidered Stages of Attack

Not considering subsequent stages of attack—most attacks occur in stages, often starting first with reconnaissance, followed by initial access, where the adversary attempts to gain a foothold into the technical environment through a vulnerable attack surface of a system, application, or user. A few different steps in between follow, ultimately ending with a negative impact on the business-critical systems or ‘crown jewels’. 

It is crucial that solution architects and security professionals consider each stage of an attack and not only address the initial threat. This will enable in-depth defence with effective multi-layered controls.


Assets, Techniques, Objectives and Mitigations (A.T.O.M)

Assets, Techniques, Objectives & Mitigations is a four-stage threat modelling process using open-source threat intelligence aligned to the MITRE ATT&CK framework. A.T.O.M is an asset/system-centric methodology and aligns with business security objectives to protect high-value assets.

A.T.O.M brings a modern approach to threat modelling by providing organisations and individuals with a framework to build an effective cyber defence strategy based on the concept of threat-informed defence (TiD).

Using open-source threat intelligence provided by MITRE, the A.T.O.M threat model contains the latest adversarial attack techniques and objectives from the MITRE ATT&CK framework to identify obscure and susceptible attack vectors. From there, the A.T.O.M process continues by mapping the associated attack techniques to one or more objectives (tactics) used to exploit a victim user, system, or application.

The final stage in the A.T.O.M threat modelling framework involves producing a table containing each credible attack vector and mapping it to an effective mitigation or security control to ensure the identified attack techniques and objectives are adequately reduced in line with organisational risk tolerance levels.

Here is a high-level overview of the concept:

A.T.O.M - High-level concept

The A.T.O.M threat modelling process has been built around three major themes, which I referred to earlier as ‘pain points’. By performing threat modelling using this modern approach, the goal is to:

  1. Reduce the complexity and amount of time/effort to produce an accurate exposure assessment and threat analysis.

    • I built a custom tool using PowerBI to quickly identify and map specific attack techniques to related mitigating controls using the MITRE ATT&CK database. The tool removes a lot of manual effort. It enables quick and accurate information gathering by mapping attack objectives to techniques and mitigations across the enterprise, industrial control systems (ICS), and mobile technology domains.

    • Works with generative artificial intelligence (Gen AI) systems and large language models (LLMs). See my custom GPT that generates a threat model using the A.T.O.M framework.

      • I have developed a newer detailed prompt template that instructs a generative AI model to perform threat modelling using this A.T.O.M methodology. This can be used as a baseline for the threat model and generates a first-pass assessment that the analyst refines.

  2. Reduce subjectivity and provide a single lens for identifying attack techniques and reducing risk with standardised mitigating security controls.

    • A.T.O.M uses open-source threat intelligence and well-known industry standards and best practices. The attack techniques, adversarial tactics and mitigations are based on the latest MITRE ATT&CK framework (version 14.0) using their extensive technique and mitigation database.

    • Ability to use different mitigation libraries from other well-established industry bodies such as NIST, CIS, CSA, etc.

  3. Increase accuracy and completeness by considering the various stages of attack that an adversary/malicious user goes through when progressing their attack campaign against a target user, system or organisation.

    • Perform the threat analysis using a hybrid approach with generative AI and open-source threat intelligence to identify all known stages of attack used to compromise an exposed asset.

    • Each stage of attack will have a different set of attack techniques and mitigating controls to provide end-to-end threat coverage.

    • Incorporate your own security standards (bring-your-own-security) into the A.T.O.M framework and identify mitigating controls that align with your unique security requirements.

The below image is a simplified example of the type(s) of information captured for each phase of the A.T.O.M threat model.

A.T.O.M - High-level components

Assets

Like any threat modelling exercise, it begins with something that needs to be protected—an asset or assets. In the context of cybersecurity, this is commonly a mixture of systems, applications, and data.

The asset phase is about capturing the business context and solution overview describing how the asset(s) are used and accessed within the target operating environment. This includes a logical solution architecture diagram from which both technology assets (systems/devices/critical infrastructure) and information assets (data) are extracted and recorded into an asset table.

Below are the fields of information used to complete the asset table:

'assetID'
'assetName'
'type' [technology, information]
'subType' [system, device, application, data]
'eps' [low, medium, high, critical]
'description'

The attribute ‘eps’ needs some further explanation.

  • Environment Protection Score (EPS): This metric enables the analyst to identify the importance of the affected IT asset to a user’s business or organisation, measured in terms of mitigating security controls that are required to be in place.

    Making the EPS part of A.T.O.M was inspired by the common vulnerability scoring system (CVSS) and is calculated in a similar way using four main requirements:

  1. Confidentiality Requirement (CR)

  2. Integrity Requirement (IR)

  3. Availability Requirement (AR)

  4. Possession Requirement (PR)

Possession is an important addition I have made to the EPS.

The possession requirement is about ensuring that the data/information or underlying system(s) is controlled by authorised entities and is not inappropriately or unknowingly transferred to others. Loss of possession could occur without loss of confidentiality, such as when a database backup file is lost or stolen. The data might still be encrypted (confidential) but is no longer in the rightful owner's control.

The possession requirement for cloud-hosted systems will often be ‘low’ due to the shared nature of the infrastructure provided by cloud service providers (CSPs).
Conversely, for cloud-hosted data, the possession requirement will vary and may often be ‘high’ or above based on the level of control the data owner has over the data being stored in the cloud.

A.T.O.M - Asset Table (Example)

Techniques

The second phase of the A.T.O.M framework is focused on the attack techniques used to exploit exposed assets and is mapped to the MITRE ATT&CK framework. Using real-world attack techniques mapped against real assets removes the subjectivity described earlier, providing a threat-informed, single-lens approach. It also improves the accuracy of the A.T.O.M threat model by leveraging open-source threat intelligence to identify real threats and how to detect them.

NOTE: This list has been kept to roughly 5-6 techniques for conciseness.

A.T.O.M - Techniques Table (Example)

Objectives

The third phase of the A.T.O.M framework is the most important. The attack objectives are the pivotal component that provides the mapping of attack techniques to mitigations.

Threat objectives are the key to informing mitigating controls

By analysing the logical solution architecture against valid attack paths, we can identify clear attack objectives where a vulnerable/exposed asset can potentially be exploited by one or more attack techniques from to the MITRE ATT&CK framework.

To help explain this process, I have included a real-world example attack pattern below using a common microservices architecture deployed using Azure Kubernetes Service (AKS). The attack pattern doesn’t include any security controls; the main focus is on identifying how an adversary could exploit the architecture and gain unauthorised access to one or more sensitive information assets using valid attack techniques.

Azure Kubernetes attack pattern using MITRE ATT&CK tactics (objectives)

The attack pattern is completed once all the attack paths have been validated and the objectives have been identified.

With the attack objectives captured, we now have the associated attack techniques. The mapping of techniques and objectives is bi-directional and can be performed either way.

In the objective table below, the attack objectives cover each of the techniques listed from the previous ‘techniques’ phase.
NOTE: This list below is not related to the Kubernetes attack pattern shown above.

A.T.O.M - Objectives Table (Example)

At the time of writing, version 14.0 of the MITRE ATT&CK database contains 507 distinct attack techniques and 31 distinct combinations of attack objectives (tactics).

Mitigations

The final phase of A.T.O.M brings all the key information together in a single view, adding technique-based mitigations derived from the associated attack objectives and techniques captured in the previous stages.

Continuing with the example data I’ve been using so far, the table below shows a complete view of the target assets and the valid attack objectives, techniques, and mitigating controls.

A.T.O.M - Mitigations Table (Example)

The mitigation table provides end-to-end traceability and includes all the critical information captured in the previous stages of the A.T.O.M framework.

Capturing the protected assets, attack techniques, objectives, and finally, the protective mitigations (controls) provides the basis for an effective threat mitigation strategy using technique-based protections mapped to the MITRE ATT&CK framework, reducing the overall technology risk and potential impact of successful attacks.

Conclusion

The A.T.O.M threat modelling framework is designed to be flexible, effective and easy to use. It removes ambiguity and subjectivity by leveraging real-world open-source threat intelligence from the MITRE ATT&CK framework to identify and understand the real threats and techniques used to exploit systems, users, and applications.

A.T.O.M allows you to use industry-standard control libraries (e.g. NIST 800-53) or leverage a custom control library that better aligns with your organisation/industry. By understanding attack objectives, the A.T.O.M methodology provides a way to map security controls to mitigate attack techniques.

A.T.O.M. is designed to remove many common pain points that often arise when performing threat modelling. It uses a defined data structure and tabular format to capture accurate threat information, making it easier and less time-consuming to conduct a detailed cyber threat assessment.

The overall effectiveness of any threat model largely depends on the accuracy of the solution architecture and data-flow diagrams (DFDs) that logically represent your technical environment and the respective systems and information assets within it.

A.T.O.M uses modern threat intelligence to provide accurate threat mitigation strategies that keep up-to-date with new and emerging cyber threats.

Although A.T.O.M threat modelling can be completed without a solution architecture diagram (blind), it is far more valuable (and recommended) to include as much business and technology-specific context as possible to ensure that the attack techniques and mitigating controls are accurate and relevant for a given real-world scenario.

Next Steps

I plan to develop A.T.O.M into a fully-functional and interactive web app that can produce advanced threat models based on customised inputs using the concepts and methodology presented in this article. Stay tuned for updates on this project!

Previous
Previous

Multi-cloud Architecture x SABSA

Next
Next

7 Ways To Avoid Poor Decisions In Cybersecurity