Simulation Validation of a Next-Generation Security Architecture for the Adaptive AutoSAR Platform Integrating an AI-Based Intrusion Detection System(AI-IDPS) and Hybrid Access Control(FA-RBAC)
Jul 2026· International Conference on Ubiquitous and Future Networks· pp. 1262-1264· 0 citations· 9 references
Abstract
The rapid evolution of Software-Defined Vehicles (SDVs) and autonomous driving technologies has significantly increased in-vehicle communication complexity and cybersecurity vulnerabilities. While traditional static Role-Based Access Control (RBAC) is incapable of reflecting dynamic driving contexts, independent Attribute-Based Access Control (ABAC) introduces unsustainable computational overhead within AutoSAR environments. To address international regulations such as UNECE WP. 29 R155/156, ISO/SAE 21434, and ISO 24089, this paper proposes a threestage hybrid access control architecture. This framework integrates Flexible Attribute-based RBAC (FA-RBAC) and an AI-based Intrusion Detection System (AI-IDPS) into the Identity and Access Management (IAM) of the AutoSAR Adaptive Platform. Simulations verifying core SDV scenarios—including driving mode transitions, Over-The-Air (OTA) updates, V2X, and diagnostics—were conducted using a SOME/IP bridge between ROS2 and Adaptive AUTOSAR. The proposed model satisfied real-time constraints with a maximum latency of 7.2ms. Quantitative results further demonstrate a 98.5% detection rate for contextual zero-day attacks and a 60% reduction in the number of written policy rules (WPN).
Security Operations Centers (SOCs) increasingly rely on Security Orchestration, Automation, and Response (SOAR) platforms to manage high-volume alerts, enrich telemetry, execute playbooks, and shorten incident-response cycles. However, many deployed SOAR systems remain rule dominated: actions are triggered by static if-then playbooks, threshold scores, and analyst-defined routing logic. Such deterministic automation is auditable and operationally useful for known, repetitive events, but it becomes brittle when adversary behavior shifts, telemetry quality varies, alert streams are noisy, assets have unequal business criticality, and compliance constraints differ across response contexts. This paper proposes an Intelligent Security Operations Automation Algorithm (ISOAA) for AI-enabled SOAR. The algorithm integrates probabilistic alert risk scoring, event-graph representation, constrained response optimization, governance-risk-compliance (GRC) gating, human-in-the-loop validation, and feedback-based policy improvement. The mathematical core models each alert as a feature-bearing security object, transforms heterogeneous telemetry into a state representation, estimates actionable incident probability, and selects response actions by maximizing expected security utility subject to operational cost, false-positive loss, and compliance penalty. A rule-based SOAR baseline, an ML-assisted triage baseline, and a reinforcement-learning cyber-response baseline are used for comparative analysis. Controlled benchmark results indicate that ISOAA achieves lower mean time to detect, lower mean time to respond, higher containment success, improved precision and recall, reduced false-positive automation, and lower compliance-breach rate than rule-based SOAR. The paper contributes a defensible mathematical architecture for intelligent SOC automation and offers practical deployment recommendations for risk-aware, auditable, and GRC-constrained response orchestration.
Ikenna Mbuko, O. Ijiga, L. Enyejo· International Journal of Eng...· 0 citations
A Security-by-Design and risk-based certification framework that combines a six-layer IoT-AI reference architecture with STRIDE-based threat analysis augmented to capture AI-specific threats, including prompt injection and data poisoning is proposed.
Iván Ortiz-Garcés, Roberto O. Andrade· Future Internet· 0 citations
This paper presents an AI-assisted CTI framework tailored to ICS and Industry 4.0 environments, integrating multi-source data ingestion, a Retrieval-Augmented Generation knowledge store, a modular chain-of-agents architecture, and an explicit human-in-the-loop verification gate.
Security Operations Centers (SOCs) rely on Level 1 analysts to triage increasing alert volumes amid alert fatigue and tool fragmentation. LLM-based multi-agent systems using the Model Context Protocol (MCP) are being adopted to automate these tasks, but their autonomy and tool access expose them to attacks such as tool poisoning, indirect prompt injection, and confused deputy exploitation. To address this gap, this work proposes a security framework for MCP-based multi-agent SOC pipelines, implemented as a middleware layer comprising a tool registration validator and five execution layers: access control, rate limiting, input validation, output validation, and audit logging. The framework is applied to a triage-enrichment-response pipeline connected to a Wazuh SIEM through a custom MCP server. Of the 35 attack vectors considered in a threat model derived from different threat taxonomies, including OWASP, MITRE ATLAS, and ATFAA, 29 are addressable at the middleware level and are covered by the framework’s controls. These controls are then validated experimentally using a purpose-built malicious MCP server and targeted test-harness injections, organized into six test suites that together exercise the covered vectors across 600 executions. Every attack instance in the evaluated threat model was blocked, none bypassed the framework, and no legitimate call in the evaluated set was incorrectly rejected; obfuscated variants, however, evade the lexical content-inspection controls, delimiting the scope of this result. A full-pipeline demonstration confirms that the framework preserves benign operational outputs. These results indicate that systematic middleware controls can secure MCP-based agentic SOC deployments without modifying the underlying agents or MCP servers.
R. Simões, Xavier Larriva-Novo, Carmen Sánchez-Zas et al.· Applied Sciences· 0 citations
Results prove the combination of adaptive intelligence, secure virtualization, and dynamic policy enforcement boosts cybersecurity defenses in unique ways for programmable SDN and DCN infrastructures.
Hasan Alkahtani· JOIV: International Journal...· 0 citations
A GenAI-driven adaptive cybersecurity mesh architecture designed for real-time threat detection in distributed intelligent communication environments and demonstrates improved detection accuracy, reduced false positives, and lower response latency compared to baseline signature-based and centralised ML-based IDS models.