Enhancing RMF and ATT&CK Mapping Accuracy through Sentence-BERT and Mitigation Parameters Integration
preprint
OA: closed
CC-BY-4.0
Abstract
To minimize cybersecurity risks in weapon systems, the implementation of the Ko-rean Risk Management Framework (K-RMF) has become essential. However, a significant 'strategic gap' exists between high-level RMF controls and technical MITRE ATT&CK techniques, rendering manual mapping labor-intensive. This study proposes an automated mitigation-driven pipeline that integrates Sentence-BERT (SBERT) with the struc-tural defense relationships of the ATT&CK knowledge graph. To address the data cover-age limitations of the CTID silver standard, we introduce Recall@restricted as a calibrated performance metric. Experimental evaluation demonstrated that the proposed ensemble framework achieves a Recall@restricted of 0.74, significantly outperforming baseline SBERT-only models. These findings suggest that deterministic mitigation relationships effectively complement semantic representations, providing a robust framework for aligning RMF controls with adversarial behaviors.
My notes (saved in your browser only)
Citation neighborhood (no data yet)
We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2026) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.
Source provenance
- europepmc
- last seen: 2026-05-20T01:45:00.602351+00:00
- unpaywall
- last seen: 2026-06-04T02:00:05.705006+00:00
License: CC-BY-4.0