Task-specific dataset for Structural Leakage in Host Intrusion Alert Corpora: A Grouped Evaluation Framework for ATT&CK-Aligned Cyber Risk Mapping
收藏资源简介:
Effective cyber risk management requires not only detecting malicious activity but also interpreting host intrusion detection system alerts as evidence of adversary behaviour and defensive priorities. This study demonstrates how to transform alerts from the Wazuh platform, generated in a Cyber Range, into operational cyber risk intelligence by mapping the alerts to MITRE ATT&CK techniques and linking them to relevant CIS Controls and metrics. Using primary alert data, the methodology applies structured pre-processing, exact-text deduplication, leakage diagnostics, and grouped cross-validation by Wazuh's rule identifier to reduce over-optimistic evaluation caused by repeated alert templates. The results show that naïve evaluation substantially overestimates predictive performance, whereas leakage-aware analysis still identifies meaningful ATT&CK signal, with tactic-level mapping proving more stable than fine-grained technique-level mapping. Overall, the study demonstrates a reproducible pathway for converting Wazuh telemetry into control-aware and metrics-driven cyber risk decision support.



