MITRE D3FEND
Defensive countermeasure ontologyMITRE D3FEND (Detection, Denial, and Disruption Framework Empowering Network Defense) · The MITRE Corporation
D3FEND supplies a seven-tactic ontology of general defensive countermeasures. Ontology 1.5.0 is the current release; this AITBM-authored crosswalk remains explicitly pinned to D3FEND 1.0 and routes measured implementation evidence from that declared basis and the independent, AI-specialized AIDEFEND catalogue, while counting overlapping evidence only once.
| D3FEND Tactic | Primary AITBM Sub-Metrics | Evidence Use / Notes |
|---|---|---|
| Model (Asset Inventory, System Mapping) | Tr-4Cn-1 | Inventory and topology evidence may support Tr-4, Cn-1, ACI provenance, and the SDG; no automatic score |
| Harden (Message/App Hardening, Agent Authentication) | Ro-1Cn-3Cn-5Cn-4Ro-4 | Measured hardening effectiveness may support the listed rubrics; no fixed anchor or ERS change |
| Detect (Process/User Behavior Analysis, Monitoring) | Tr-3Ro-3Cn-1Cn-2 | Telemetry may support Tr-3 and monitoring/freshness evidence when coverage and health rules are met |
| Isolate (Execution Isolation, Network Isolation) | Cn-1Cn-4 | Isolation evidence informs Cn-1/Cn-4, As, and SDG reachability; Cp remains graph-derived |
| Deceive (Decoy Environment, Decoy Object) | Tr-3Cn-2 | Decoy evidence may support detection, audit, and remediation testing; no fixed ERS change |
| Evict (Process/Credential Eviction) | Cn-2 | Measured eviction and quarantine performance may inform Cn-2 and Rf |
| Restore (Restore Object/rollback, Restore Access) | ORP Rf | Measured rollback and recovery evidence may inform Rf; no fixed ERS change |
| Harden :: Agent Authentication (1.x) [standout] | Cn-5 | ISSR and attestation-coverage evidence may support Cn-5; no automatic anchor |
Key findings
- A D3FEND countermeasure is an implementable control, not a score. Measured implementation evidence may support an AITBM rubric; no fixed anchor or ERS reduction is inherent to the control.
- D3FEND (general cyber defense) and AIDEFEND (AI-specialized, modeled on D3FEND's same seven tactics) are concentric, not redundant; a D3FEND control and its AIDEFEND twin targeting the same sub-metric are scored once, never double-counted.
- Harden and Isolate carry the most IVP-moving weight (especially Agent Authentication -> Cn-5), while Detect/Deceive/Evict/Restore act largely through the ORP layer (Rf, As, Cp) and by sustaining ACI freshness.
- The D3FEND worked example is retained on its dated 21-sub-metric, pre-GDCP basis. A current assessment must derive Cn-6, Cp, ACI, and ERS under the current specification.