Understanding the Defence of Operational Technology (OT) Systems: A Comparison of Lockheed Martin’s Cyber Kill Chain, MITRE ATT&CK Framework, and Diamond Model

Kamor Kareem, Nitin Naik, Paul Jenkins, Paul Grace, Jingping Song

Research output: Chapter in Book/Published conference outputConference publication

Abstract

As organisations worldwide strive to optimise processes and digitise systems, Operational Technologies (OT) are increasingly being integrated with Information Technologies (IT). Consequently, this complex amalgamation is challenging cybersecurity professionals to understand and analyse both the attack surfaces and attack vectors that threat actors could potentially exploit. Cybersecurity professionals have been driven to explore different attack models to understand and analyse various cyberattacks and their attack vectors. There are several attack models that have already been developed and are being used in the analysis of different cyberattacks and their mitigations. Each of these attack models has some specific characteristics, strengths and limitations. It is therefore crucial to study the use of the most common attack models for operational technologies in order to comprehend their effectiveness for analysing cyberattacks on OT systems. This paper will analyse the features, strengths, and limitations of three widely recognised attack models: Lockheed Martin’s Cyber Kill Chain, MITRE ATT&CK Framework and Diamond Model for OT systems. It conducts a comparative analysis of these three attack models to provide a complete evaluation of the most suitable model for OT systems.
Original languageEnglish
Title of host publicationContributions Presented at The International Conference on Computing, Communication, Cybersecurity and AI, July 3–4, 2024, London, UK: The C3AI 2024
EditorsNitin Naik, Paul Jenkins, Shaligram Prajapat, Paul Grace
Pages605-624
Number of pages20
Edition1
ISBN (Electronic)9783031744433
DOIs
Publication statusPublished - 19 Dec 2024

Publication series

NameLecture Notes in Networks and Systems
Volume884 LNNS
ISSN (Print)2367-3370
ISSN (Electronic)2367-3389

Keywords

  • Cyber Attack Model
  • Diamond Model
  • Lockheed Martin’s Cyber Kill Chain
  • MITRE ATT&CK Framework
  • OT
  • Operational Technology

Fingerprint

Dive into the research topics of 'Understanding the Defence of Operational Technology (OT) Systems: A Comparison of Lockheed Martin’s Cyber Kill Chain, MITRE ATT&CK Framework, and Diamond Model'. Together they form a unique fingerprint.

Cite this