Skip to content
#explainable ai Review Open access

A Threat Modeling Prioritization and Automation Framework for Composable Architectures

Sep 2026 · Future Internet · 0 citations · 41 references
Information and Cyber Security

TL;DR

A snapshot of the literature review of the threat modeling for composable architectures is offered, why automation is difficult in this context is shown, and an automation framework to allocate scarce resources according to risk exposure to composable architecture components is proposed.

Abstract

Organizations face escalating cyber risk, expanding attack surfaces, increasingly automated adversaries, and constrained security resources. Organizations are looking for practical mechanisms to improve security resilience by transforming threat modeling from a periodic design activity into a continuous, evidence-driven decision process. This paper offers a snapshot of the literature review of the threat modeling for composable architectures, shows why automation is difficult in this context, and proposes an automation framework to allocate scarce resources according to risk exposure to composable architecture components, where applications, services, identities, data flows, and autonomous agents are assembled and reconfigured across distributed environments. Composable architecture shows in an amplified way the gap between the static and dynamic security approaches, and our proposal helps to define the attributes needed for setting automation boundaries at the service level for risk prioritization based on threat modeling for security remediation actions. The conceptual framework integrates Zero Trust principles, control-effectiveness measurement, and human-in-the-loop governance and examines how automation with artificial intelligence changes the threat landscape by introducing risks that are difficult to measure and fast-changing. The results show that automation should be controlled with defined boundaries explained through measurable attributes for transparent decisions. It also proposes that AI should not replace expert judgement; rather, it should augment security teams by improving information quality, revealing hidden dependencies, supporting adaptive prioritization under uncertainty, and enabling resilience-oriented investment decisions for composable, distributed, and increasingly autonomous systems.

Read PDF

Similar papers

Book Open access Oct 2026

Metamodel-Based Generation of Security Models from Structured Cyber Threat Intelligence

This paper presents a prototype approach that transforms publicly available attack knowledge from sources such as MITRE ATT&CK and MITRE EMB3D into instances of the Security Abstraction Model (SAM), a domain-specific security metamodel, and outlines future research directions toward continuous, data-driven cybersecurit...

Alexander Fischer, Ramin Tavakoli Kolagari · 0 citations
#artificial intelligence Review Sep 2026

Trustworthy Agentic AI: A Comprehensive Cybersecurity and Systems Survey on Threat Landscapes, Defense Architectures, and Open Challenges

This survey systematically analyze threat surfaces across intra-execution loops and interaction planes, formulate a multi-layered zero-trust defense-in-depth architecture integrating Dual-LLM isolation, Capability-Based Access Control, kernel eBPF probes, and sandboxed runtimes, and map technical controls to internatio...

Seyedakbar Mostafavi · 0 citations
Preprint Aug 2026

Agentic AI Cybersecurity Framework

The increasing scale, complexity, and dynamism of modern cyber threats have rendered traditional reactive cybersecurity mechanisms insufficient. This paper introduces an Agentic AI Cybersecurity Framework (AACF) designed to enable autonomous, goal-driven, and adaptive cyber defense operations. Unlike conventional syste...

Victor R. Kebande · 0 citations
Open access Aug 2026

DISTRIBUTED AI-ASSISTED RISK ASSESSMENT FOR ZERO-TRUST MICROSERVICES: A TAXONOMY AND CONCEPTUAL FRAMEWORK

Microservice and cloud-native architectures have expanded the software attack surface at a pace that outstrips the adaptation of traditional risk assessment methods. Conventional vulnerability management remains centralized, static, severity-oriented, and disconnected from access control—characteristics that are ill-su...

Daoquan Zhou, Xiong-Sheng Yi · 0 citations
#artificial intelligence Review Sep 2026

Connecting the Dots in Agentic AI Security: A Cross-Dimensional Threat Taxonomy, Evaluation Maturity, and Open Challenges

Agentic AI extends LLM security beyond generated content to persistent state, autonomous actions, tool use, and interactions with humans and other agents. Existing threat classifications often emphasize individual dimensions, obscuring connections among entry points, affected components, and security consequences. The...

Heewon Baek, Alsharif Abuadbba, Kristen Moore et al. · 0 citations
Open access Aug 2026

TOWARD SDN-NATIVE CYBERSECURITY: UNIFIED THREAT MODELING, FORMAL ASSURANCE, BEHAVIORAL DETECTION, AND MULTI-CONTROLLER RESILIENCE

This study designs and analytically evaluates an SDN-native cybersecurity integration contract that unifies: a multidimensional threat model; invariant-based preventive assurance; governed hybrid detection; security-aware multi-controller resilience; ATT&CK informed traceability; and controlled learning.

Oumar Y. Maïga, Moussa Koita, I. Traoré et al. · 0 citations

Related blog posts

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.