Skip to content
Book Open access

Metamodel-Based Generation of Security Models from Structured Cyber Threat Intelligence

Oct 2026 · Proceedings of the ACM/IEEE 29th International Conference on Model Driven Engineering Languages and Systems · 0 citations · 12 references

TL;DR

This paper presents a prototype approach that transforms publicly available attack knowledge from sources such as MITRE ATT&CK and MITRE EMB3D into instances of the Security Abstraction Model (SAM), a domain-specific security metamodel, and outlines future research directions toward continuous, data-driven cybersecurity engineering.

Abstract

Modern vehicle systems are increasingly exposed to cybersecurity threats due to growing connectivity, software complexity, and the integration of external services. While standards such as ISO/SAE 21434 provide guidance for threat analysis and risk assessment, constructing security models remains a predominantly manual activity that is difficult to scale and maintain. This challenge limits the systematic incorporation of cybersecurity concerns into model-based engineering processes and hinders early assessment of security risks. This paper explores the idea of automatically generating security models from structured cyber threat intelligence. We present a prototype approach that transforms publicly available attack knowledge from sources such as MITRE ATT&CK and MITRE EMB3D into instances of the Security Abstraction Model (SAM), a domain-specific security metamodel. Our vision is to establish an attack-driven modeling workflow that continuously integrates evolving threat knowledge into model-based engineering environments. As an initial proof of concept, we implemented a generator and applied it to publicly available attack datasets, resulting in the automatic creation of valid security model instances. These early results indicate the feasibility of extensive security model generation and suggest potential benefits for improving the efficiency of cybersecurity analyses. We discuss open challenges, including semantic enrichment, model integration, and outline future research directions toward continuous, data-driven cybersecurity engineering.

Read PDF

Similar papers

#explainable ai Review Open access Sep 2026

A Threat Modeling Prioritization and Automation Framework for Composable Architectures

Organizations face escalating cyber risk, expanding attack surfaces, increasingly automated adversaries, and constrained security resources. Organizations are looking for practical mechanisms to improve security resilience by transforming threat modeling from a periodic design activity into a continuous, evidence-drive...

Liviu-Mihai Popescu, R. Brad · 0 citations
Open access Aug 2026

Ontology-Driven Modeling and Semantic Integration of Attack, Protection, and Risk Domains in Electric Vehicle Charging Systems

Electric Vehicle Charging Systems (EVCSs) have become a critical component of the global transition toward sustainable and intelligent transportation. However, their tight integration with heterogeneous cyber–physical, vehicular, and cloud-based infrastructures exposes them to an expanding attack surface, including dat...

Talea Huraysi, Ohud Alsadi, T. Pamulapati et al. · 0 citations
Review Open access 2026

Large Language Model-Assisted Threat-Driven Testing System for Enhanced Cybersecurity Readiness

The proposed Large Language Model-Assisted Threat-Driven Testing System enables security teams, particularly resource-constrained organizations lacking dedicated red-team capabilities, to conduct high-fidelity threat simulation exercises aligned with current adversarial TTPs, without specialized AI expertise, thereby s...

Praise Emeka Nze, A. Ademuwagun, Muktar Bello et al. · 0 citations
Open access Sep 2026

A Case Study on Using Local LLMs for Automated Cybersecurity Analysis

The use of generative AI technologies in architectural threat modeling automation seems to be a promising alternative to ‘traditional’ formal approaches (e.g., attack-defense trees, domain-specific languages, knowledge graphs, etc.). The main advantage of Large Language Models (LLMs) is that they can work with system a...

Unknown authors · 0 citations
Open access Sep 2026

Cybersecurity and AI: A Comprehensive Implementation of Advanced Large Language Models for Threat Detection, Digital Forensics, SOC Automation, and Security Vulnerability Mitigation

This report encompasses the cutting-edge implementation of advanced Large Language Models (LLMs) for cybersecurity and digital forensics applications at the intersection of cybersecurity and AI. The project brings together innovative research on AI-based security solutions in four major areas: threat detection and inte...

Harsh Dankhara · 0 citations
Review Open access Sep 2026

Artificial Intelligence - Model Context Protocol - Review of Real-World Security Threats

Modern Artificial Intelligence (AI) infrastructures and Model Context Protocol (MCP) deployments face systemic security exposures as a result of autonomous agents interacting directly with external databases and tools. Protocol-level weaknesses, permissive access rights, and unverified third-party repositories allow at...

Upendra Kanuru, Alexa Schmitt · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.