Saturday , February 22 2025
D3FENDTM 1.0

MITRE Launches D3FEND 1.0; The Milestone for Cybersecurity Ontology

MITRE launched D3FENDTM 1.0, a cybersecurity framework that provides a vocabulary and understanding of the cyber domain. D3FEND 1.0, funded by the NSA and the U.S. Department of Defense, offers a flexible and user-friendly framework for cybersecurity operations and strategic decision-making.

D3FEND was initially released as a beta in June 2021 and has since developed significantly over three years, tripling its semantic graph. This growth is the result of collaboration among experts from government and industry, including security architects and detection engineers, leading to the launch of a large, use case-driven model.

B1ack’s Stash Releases 1 Million Credit Cards on a Deep Web Forum

On February 19, 2025, the illegal marketplace B1ack's Stash released over 1 million unique stolen credit and debit card details...
Read More
B1ack’s Stash Releases 1 Million Credit Cards on a Deep Web Forum

Cisco Confirms
Salt Typhoon Exploited CVE-2018-0171 to Target U.S. Telecom Networks

Cisco Talos reported that  Salt Typhoon, also known as FamousSparrow and GhostEmperor, has been spying on U.S. telecommunication providers using...
Read More
Cisco Confirms  Salt Typhoon Exploited CVE-2018-0171 to Target U.S. Telecom Networks

AWS Key Hunter
Test this free automated tool to hunt for exposed AWS secrets

A free tool is now available to scan public GitHub repositories for exposed AWS credentials. Security engineer Anmol Singh Yadav created...
Read More
AWS Key Hunter  Test this free automated tool to hunt for exposed AWS secrets

Check Point Flaw Used to Deploy ShadowPad and Ransomware

An unknown threat cluster has targeted European healthcare organizations, deploying PlugX and ShadowPad. In some cases, these intrusions resulted in...
Read More
Check Point Flaw Used to Deploy ShadowPad and Ransomware

CVE-2024-12284
Citrix Issues Security Update for NetScaler Console

Citrix has issued security updates for a serious vulnerability in the NetScaler Console and NetScaler Agent that could allow privilege...
Read More
CVE-2024-12284  Citrix Issues Security Update for NetScaler Console

CISA and FBI ALERT
Ghost ransomware to breach organizations in 70 countries

The FBI and CISA reported on Wednesday that the ransomware group Ghost has been exploiting software and firmware vulnerabilities as...
Read More
CISA and FBI ALERT  Ghost ransomware to breach organizations in 70 countries

Hacker chains multiple vulns to attack Palo Alto Firewall

Palo Alto Networks has issued urgent warnings about threat actors to exploit vulnerabilities in PAN-OS, the operating system powering its...
Read More
Hacker chains multiple vulns to attack Palo Alto Firewall

150 Gov.t Portal affected
Black-Hat SEO Poisoning Indian “.gov.in, .ac.in” domain

Indian government and educational websites, along with reputable financial brands, have experienced SEO poisoning, causing user traffic to be redirected...
Read More
150 Gov.t Portal affected  Black-Hat SEO Poisoning Indian “.gov.in, .ac.in” domain

CVE-2018-19410 Exposes 600 PRTG Instances in Bangladesh

The Cyber Threat Intelligence Unit of BGD e-GOV CIRT has found 600 vulnerable PRTG instances in Bangladesh, affected by the...
Read More
CVE-2018-19410 Exposes 600 PRTG Instances in Bangladesh

Builder claims Rs 150 cr for data loss; AWS faces FIR In Bengaluru

Amazon Web Services (AWS) has been named in an FIR after a builder claimed damages to the tune of Rs...
Read More
Builder claims Rs 150 cr for data loss;  AWS faces FIR In Bengaluru

“With D3FEND, we are leaning forward with the greater cybersecurity community,” said Wen Masters, vice president, cyber technologies, MITRE. “D3FEND 1.0 reflects the collective expertise and vision of a diverse cybersecurity community. It’s more than just a tool—it’s a pathway to smarter, more nuanced defensive strategies. Our goal is to ensure D3FEND is adaptable and valuable across a wide range of cybersecurity domains.”

“D3FEND is effectively a model for what cyber defenders are doing in their day-to-day activities, but it’s trying to establish a common language for those activities and the system components to which they apply,” said Peter Kaloroumakis, principal applied ontologist, MITRE. “Even though D3FEND focuses on technology, it’s really solving a human problem. Getting everyone on the same page with a common language and Rosetta Stone is essential for doing in-depth, strategic analysis on your investments and building secure systems.”

Key Features and Enhancements in D3FEND 1.0

Cyber Attack-Defense (CAD) Tool: CAD allows D3FEND users to apply the entire ontology to their cybersecurity scenarios by dragging, dropping, and linking nodes on a canvas. Users can right-click to explore D3FEND’s inference and share their graphs online or on private networks.

D3FEND 1.0 improves defensive techniques with new additions for identity and access control, operational technology, and source code hardening. It also incorporates the Common Weakness Enumeration (CWE™) for better vulnerability modeling.

Ontological Precision & Extensibility: D3FEND 1.0, built on OWL 2 DL, includes core classes for compatibility with major ontologies, enhancing its semantic applications. It also offers a content-lifecycle strategy for easy updates, helping users and developers adapt to changes.

“This milestone is not an end—it’s a beginning, and we are just getting started,” said Kaloroumakis. “We’re committed to ongoing engagement with the cybersecurity community to refine and expand the framework, ensuring it meets the demands of an increasingly sophisticated landscape.”

MITRE invites cyber engineers and industry professionals to engage with D3FEND 1.0, as community involvement is crucial for its success. D3FEND continues MITRE’s tradition of providing innovative, open-source cybersecurity tools.

Malware Trends Review 2024: Ever Recorded Cyber Threats

Check Also

Zuckerberg

Everything I Say Leaks,’ Zuckerberg Says in Leaked Meeting Audio

At an all-hands meeting at Meta on Thursday, Mark Zuckerberg did not mention the company’s …

Leave a Reply

Your email address will not be published. Required fields are marked *