Oct 2026· Proceedings of the ACM/IEEE 29th International Conference on Model Driven Engineering Languages and Systems· 0 citations· 12 references
TL;DR
This paper presents a prototype approach that transforms publicly available attack knowledge from sources such as MITRE ATT&CK and MITRE EMB3D into instances of the Security Abstraction Model (SAM), a domain-specific security metamodel, and outlines future research directions toward continuous, data-driven cybersecurity engineering.
Abstract
Modern vehicle systems are increasingly exposed to cybersecurity threats due to growing connectivity, software complexity, and the integration of external services. While standards such as ISO/SAE 21434 provide guidance for threat analysis and risk assessment, constructing security models remains a predominantly manual activity that is difficult to scale and maintain. This challenge limits the systematic incorporation of cybersecurity concerns into model-based engineering processes and hinders early assessment of security risks. This paper explores the idea of automatically generating security models from structured cyber threat intelligence. We present a prototype approach that transforms publicly available attack knowledge from sources such as MITRE ATT&CK and MITRE EMB3D into instances of the Security Abstraction Model (SAM), a domain-specific security metamodel. Our vision is to establish an attack-driven modeling workflow that continuously integrates evolving threat knowledge into model-based engineering environments. As an initial proof of concept, we implemented a generator and applied it to publicly available attack datasets, resulting in the automatic creation of valid security model instances. These early results indicate the feasibility of extensive security model generation and suggest potential benefits for improving the efficiency of cybersecurity analyses. We discuss open challenges, including semantic enrichment, model integration, and outline future research directions toward continuous, data-driven cybersecurity engineering.
Organizations face escalating cyber risk, expanding attack surfaces, increasingly automated adversaries, and constrained security resources. Organizations are looking for practical mechanisms to improve security resilience by transforming threat modeling from a periodic design activity into a continuous, evidence-drive...
Liviu-Mihai Popescu, R. Brad· Future Internet· 0 citations
Electric Vehicle Charging Systems (EVCSs) have become a critical component of the global transition toward sustainable and intelligent transportation. However, their tight integration with heterogeneous cyber–physical, vehicular, and cloud-based infrastructures exposes them to an expanding attack surface, including dat...
Talea Huraysi, Ohud Alsadi, T. Pamulapati et al.· Electronics· 0 citations
The proposed Large Language Model-Assisted Threat-Driven Testing System enables security teams, particularly resource-constrained organizations lacking dedicated red-team capabilities, to conduct high-fidelity threat simulation exercises aligned with current adversarial TTPs, without specialized AI expertise, thereby s...
Praise Emeka Nze, A. Ademuwagun, Muktar Bello et al.· Journal of Cyber Security· 0 citations
The use of generative AI technologies in architectural threat modeling automation seems to be a promising alternative to ‘traditional’ formal approaches (e.g., attack-defense trees, domain-specific languages, knowledge graphs, etc.). The main advantage of Large Language Models (LLMs) is that they can work with system a...
Unknown authors· Journal of Superintelligence...· 0 citations
This report encompasses the cutting-edge implementation of advanced Large Language Models (LLMs) for cybersecurity and digital forensics applications at the intersection of cybersecurity and AI. The project brings together innovative research on AI-based security solutions in four major areas: threat detection and inte...
Harsh Dankhara· International Journal of Art...· 0 citations
Modern Artificial Intelligence (AI) infrastructures and Model Context Protocol (MCP) deployments face systemic security exposures as a result of autonomous agents interacting directly with external databases and tools. Protocol-level weaknesses, permissive access rights, and unverified third-party repositories allow at...
Upendra Kanuru, Alexa Schmitt· The Pinnacle: A Journal by S...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.