{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:TNOBZ4O6KQG5K5W6MI3YV45DBW","short_pith_number":"pith:TNOBZ4O6","schema_version":"1.0","canonical_sha256":"9b5c1cf1de540dd576de62378af3a30d9b9e5e8a430536968003db0fed465f98","source":{"kind":"arxiv","id":"2010.00533","version":2},"attestation_state":"computed","paper":{"title":"Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Bryn Reinstadler, Erik Hemberg, Jonathan Kelly, Katherine Xu, Michal Shlapentokh-Rothman, Nick Rutar, Una-May O'Reilly","submitted_at":"2020-10-01T16:31:46Z","abstract_excerpt":"Many public sources of cyber threat and vulnerability information exist to help defend cyber systems. This paper links MITRE's ATT&CK MATRIX of Tactics and Techniques, NIST's Common Weakness Enumerations (CWE), Common Vulnerabilities and Exposures (CVE), and Common Attack Pattern Enumeration and Classification list (CAPEC), to gain further insight from alerts, threats and vulnerabilities. We preserve all entries and relations of the sources, while enabling bi-directional, relational path tracing within an aggregate data graph called BRON. In one example, we use BRON to enhance the information "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2010.00533","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-10-01T16:31:46Z","cross_cats_sorted":[],"title_canon_sha256":"2eaeefe944bceb23c2415a630bf1b776ce0e1c7445a77934bbafdb6cdc6d26a9","abstract_canon_sha256":"598f52852285a7a5923b406c663d9b479a692880652048a20f5c01fb110666b5"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T02:14:11.316493Z","signature_b64":"dKBkwsqMkJZFq5j15Myhdg/PP3dJ8vkUPDdR+Yghgp/maydKeAU1RJZ6nbZ+i7M1smjsaVDT4uK2Vb8kKdLKAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9b5c1cf1de540dd576de62378af3a30d9b9e5e8a430536968003db0fed465f98","last_reissued_at":"2026-07-05T02:14:11.316090Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T02:14:11.316090Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Bryn Reinstadler, Erik Hemberg, Jonathan Kelly, Katherine Xu, Michal Shlapentokh-Rothman, Nick Rutar, Una-May O'Reilly","submitted_at":"2020-10-01T16:31:46Z","abstract_excerpt":"Many public sources of cyber threat and vulnerability information exist to help defend cyber systems. This paper links MITRE's ATT&CK MATRIX of Tactics and Techniques, NIST's Common Weakness Enumerations (CWE), Common Vulnerabilities and Exposures (CVE), and Common Attack Pattern Enumeration and Classification list (CAPEC), to gain further insight from alerts, threats and vulnerabilities. We preserve all entries and relations of the sources, while enabling bi-directional, relational path tracing within an aggregate data graph called BRON. In one example, we use BRON to enhance the information "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2010.00533","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2010.00533/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2010.00533","created_at":"2026-07-05T02:14:11.316147+00:00"},{"alias_kind":"arxiv_version","alias_value":"2010.00533v2","created_at":"2026-07-05T02:14:11.316147+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2010.00533","created_at":"2026-07-05T02:14:11.316147+00:00"},{"alias_kind":"pith_short_12","alias_value":"TNOBZ4O6KQG5","created_at":"2026-07-05T02:14:11.316147+00:00"},{"alias_kind":"pith_short_16","alias_value":"TNOBZ4O6KQG5K5W6","created_at":"2026-07-05T02:14:11.316147+00:00"},{"alias_kind":"pith_short_8","alias_value":"TNOBZ4O6","created_at":"2026-07-05T02:14:11.316147+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2604.23905","citing_title":"SMSI: System Model Security Inference: Automated Threat Modeling for Cyber-Physical Systems","ref_index":11,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/TNOBZ4O6KQG5K5W6MI3YV45DBW","json":"https://pith.science/pith/TNOBZ4O6KQG5K5W6MI3YV45DBW.json","graph_json":"https://pith.science/api/pith-number/TNOBZ4O6KQG5K5W6MI3YV45DBW/graph.json","events_json":"https://pith.science/api/pith-number/TNOBZ4O6KQG5K5W6MI3YV45DBW/events.json","paper":"https://pith.science/paper/TNOBZ4O6"},"agent_actions":{"view_html":"https://pith.science/pith/TNOBZ4O6KQG5K5W6MI3YV45DBW","download_json":"https://pith.science/pith/TNOBZ4O6KQG5K5W6MI3YV45DBW.json","view_paper":"https://pith.science/paper/TNOBZ4O6","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2010.00533&json=true","fetch_graph":"https://pith.science/api/pith-number/TNOBZ4O6KQG5K5W6MI3YV45DBW/graph.json","fetch_events":"https://pith.science/api/pith-number/TNOBZ4O6KQG5K5W6MI3YV45DBW/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/TNOBZ4O6KQG5K5W6MI3YV45DBW/action/timestamp_anchor","attest_storage":"https://pith.science/pith/TNOBZ4O6KQG5K5W6MI3YV45DBW/action/storage_attestation","attest_author":"https://pith.science/pith/TNOBZ4O6KQG5K5W6MI3YV45DBW/action/author_attestation","sign_citation":"https://pith.science/pith/TNOBZ4O6KQG5K5W6MI3YV45DBW/action/citation_signature","submit_replication":"https://pith.science/pith/TNOBZ4O6KQG5K5W6MI3YV45DBW/action/replication_record"}},"created_at":"2026-07-05T02:14:11.316147+00:00","updated_at":"2026-07-05T02:14:11.316147+00:00"}