An Alignment Between the CRA's Essential Requirements and the ATT&CK's Mitigations
Fuente:
arXiv
Saved in:
| Main Authors: | Ruohonen, Jukka, Kang, Eun-Young, Ramadan, Qusai |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
A Mapping Analysis of Requirements Between the CRA and the GDPR
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
An Empirical Study of Vulnerability Handling Times in CPython
by: Ruohonen, Jukka
Published: (2024)
by: Ruohonen, Jukka
Published: (2024)
A Time Series Analysis of Malware Uploads to Programming Language Ecosystems
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
by: Hamer, Sivana, et al.
Published: (2025)
by: Hamer, Sivana, et al.
Published: (2025)
SoK: The Design Paradigm of Safe and Secure Defaults
by: Ruohonen, Jukka
Published: (2024)
by: Ruohonen, Jukka
Published: (2024)
Snaps: Bloated and Outdated?
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Vulnerability Patching Across Software Products and Software Components: A Case Study of Red Hat's Product Portfolio
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
A Static Analysis of Popular C Packages in Linux
by: Ruohonen, Jukka, et al.
Published: (2024)
by: Ruohonen, Jukka, et al.
Published: (2024)
Vulnerability Coordination Under the Cyber Resilience Act
by: Ruohonen, Jukka, et al.
Published: (2024)
by: Ruohonen, Jukka, et al.
Published: (2024)
Compliance as Code: A Study of Linux Distributions and Beyond
by: Ruohonen, Jukka, et al.
Published: (2026)
by: Ruohonen, Jukka, et al.
Published: (2026)
An Overview of Cyber Security Funding for Open Source Software
by: Ruohonen, Jukka, et al.
Published: (2024)
by: Ruohonen, Jukka, et al.
Published: (2024)
Risks and Compliance with the EU's Core Cyber Security Legislation
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Towards Systematic Specification and Verification of Fairness Requirements: A Position Paper
by: Ramadan, Qusai, et al.
Published: (2025)
by: Ramadan, Qusai, et al.
Published: (2025)
A Rapid Review Regarding the Concept of Legal Requirements in Requirements Engineering
by: Ruohonen, Jukka
Published: (2025)
by: Ruohonen, Jukka
Published: (2025)
Privacy and Confidentiality Requirements Engineering for Process Data
by: Haertel, Fabian, et al.
Published: (2025)
by: Haertel, Fabian, et al.
Published: (2025)
Developments in Connected Vehicles and the Requirement for Increased Cybersecurity
by: Garrad, Phillip, et al.
Published: (2021)
by: Garrad, Phillip, et al.
Published: (2021)
A Requirement-Based Framework for Engineering Adaptive Authentication
by: Hassan, Alzubair, et al.
Published: (2026)
by: Hassan, Alzubair, et al.
Published: (2026)
Usability as a Weapon: Attacking the Safety of LLM-Based Code Generation via Usability Requirements
by: Li, Yue, et al.
Published: (2026)
by: Li, Yue, et al.
Published: (2026)
How Reliable Are FOSS Popularity Metrics? Analyzing the Effort Required for Spoofing Common Software Popularity Metrics
by: Swierzy, Ben, et al.
Published: (2025)
by: Swierzy, Ben, et al.
Published: (2025)
When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation
by: Zhao, Weibo, et al.
Published: (2025)
by: Zhao, Weibo, et al.
Published: (2025)
Automatic Selection of Protections to Mitigate Risks Against Software Applications
by: Canavese, Daniele, et al.
Published: (2025)
by: Canavese, Daniele, et al.
Published: (2025)
Centralized Defense: Logging and Mitigation of Kubernetes Misconfigurations with Open Source Tools
by: Russell, Eoghan, et al.
Published: (2024)
by: Russell, Eoghan, et al.
Published: (2024)
LLM-Driven Adaptive Source-Sink Identification and False Positive Mitigation for Static Analysis
by: Lin, Shiyin
Published: (2025)
by: Lin, Shiyin
Published: (2025)
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
by: Cesarano, Carmine, et al.
Published: (2025)
by: Cesarano, Carmine, et al.
Published: (2025)
A Data-Mining Based Study of Security Vulnerability Types and Their Mitigation in Different Languages
by: Antal, Gábor, et al.
Published: (2024)
by: Antal, Gábor, et al.
Published: (2024)
How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
by: Zhang, Ying, et al.
Published: (2023)
by: Zhang, Ying, et al.
Published: (2023)
HarnessAgent: Scaling Automatic Fuzzing Harness Construction with Tool-Augmented LLM Pipelines
by: Yang, Kang, et al.
Published: (2025)
by: Yang, Kang, et al.
Published: (2025)
FASR: Automated Identification of Unsafe Control Actions in STPA
by: Dardik, Ian, et al.
Published: (2026)
by: Dardik, Ian, et al.
Published: (2026)
LLM-enabled Applications Require System-Level Threat Monitoring
by: Zhang, Yedi, et al.
Published: (2026)
by: Zhang, Yedi, et al.
Published: (2026)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
zkCraft: Prompt-Guided LLM as a Zero-Shot Mutation Pattern Oracle for TCCT-Powered ZK Fuzzing
by: Fu, Rong, et al.
Published: (2026)
by: Fu, Rong, et al.
Published: (2026)
Revisiting Vulnerability Patch Identification on Data in the Wild
by: Irsan, Ivana Clairine, et al.
Published: (2026)
by: Irsan, Ivana Clairine, et al.
Published: (2026)
Mapping NVD Records to Their Vulnerability-fixing Commits: How Hard is It?
by: Nguyen, Huu Hung, et al.
Published: (2025)
by: Nguyen, Huu Hung, et al.
Published: (2025)
CleanVul: Automatic Function-Level Vulnerability Detection in Code Commits Using LLM Heuristics
by: Li, Yikun, et al.
Published: (2024)
by: Li, Yikun, et al.
Published: (2024)
Containment Verification: AI Safety Guarantees Independent of Alignment
by: Moon, Royce, et al.
Published: (2026)
by: Moon, Royce, et al.
Published: (2026)
ProSec: Fortifying Code LLMs with Proactive Security Alignment
by: Xu, Xiangzhe, et al.
Published: (2024)
by: Xu, Xiangzhe, et al.
Published: (2024)
Symbolic Execution Meets Multi-LLM Orchestration: Detecting Memory Vulnerabilities in Incomplete Rust CVE Snippets
by: Abdelrazek, Zeyad, et al.
Published: (2026)
by: Abdelrazek, Zeyad, et al.
Published: (2026)
Mitigating Sensitive Information Leakage in LLMs4Code through Machine Unlearning
by: Gu, Shanzhi, et al.
Published: (2025)
by: Gu, Shanzhi, et al.
Published: (2025)
Similar Items
-
A Mapping Analysis of Requirements Between the CRA and the GDPR
by: Ruohonen, Jukka, et al.
Published: (2025) -
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
by: Ruohonen, Jukka, et al.
Published: (2025) -
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
by: Ruohonen, Jukka, et al.
Published: (2025) -
An Empirical Study of Vulnerability Handling Times in CPython
by: Ruohonen, Jukka
Published: (2024) -
A Time Series Analysis of Malware Uploads to Programming Language Ecosystems
by: Ruohonen, Jukka, et al.
Published: (2025)