Skip to content
Book Open access

Metamodel-Based Generation of Security Models from Structured Cyber Threat Intelligence

Oct 2026 · Proceedings of the ACM/IEEE 29th International Conference on Model Driven Engineering Languages and Systems · 0 citations · 12 references

Abstract

Modern vehicle systems are increasingly exposed to cybersecurity threats due to growing connectivity, software complexity, and the integration of external services. While standards such as ISO/SAE 21434 provide guidance for threat analysis and risk assessment, constructing security models remains a predominantly manual activity that is difficult to scale and maintain. This challenge limits the systematic incorporation of cybersecurity concerns into model-based engineering processes and hinders early assessment of security risks. This paper explores the idea of automatically generating security models from structured cyber threat intelligence. We present a prototype approach that transforms publicly available attack knowledge from sources such as MITRE ATT&CK and MITRE EMB3D into instances of the Security Abstraction Model (SAM), a domain-specific security metamodel. Our vision is to establish an attack-driven modeling workflow that continuously integrates evolving threat knowledge into model-based engineering environments. As an initial proof of concept, we implemented a generator and applied it to publicly available attack datasets, resulting in the automatic creation of valid security model instances. These early results indicate the feasibility of extensive security model generation and suggest potential benefits for improving the efficiency of cybersecurity analyses. We discuss open challenges, including semantic enrichment, model integration, and outline future research directions toward continuous, data-driven cybersecurity engineering.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.