Skip to content
Open access

A model-driven knowledge graph treatment for process-centric cyber threat mitigation

Jul 2026 · Knowledge and Information Systems · Vol 68 · 0 citations · 32 references

TL;DR

A domain-specific modeling method supported by a process-centric visual language to enable a knowledge graph treatment for designing cyber threats mitigations in tandem with business process engineering activities and associated data flows and enhances the system analysis capabilities by streamlining heterogeneous knowledge flows.

Abstract

Cybersecurity analysis touches on diverse interdisciplinary aspects, both technical and business-oriented, and diverse stakeholders from different backgrounds must be supported with a knowledge capture environment that operationalizes the “secure by design” principles while also ensuring semantic traceability of the design decisions, to enable AI-based analysis. This paper introduces a domain-specific modeling method supported by a process-centric visual language (a BPMN extension) to enable a knowledge graph treatment for designing cyber threats mitigations in tandem with business process engineering activities and associated data flows. The treatment is intended to be leveraged by LLM (large language model) services, therefore experimentation leans towards AI integration. The domain-specific modeling language (DSML) hybridizes BPMN and threat modeling, further subjected to model transformations into RDF graphs. A demonstrator is implemented on the ADOxx metamodeling platform and its interoperability/adapters for integration with triplestores and LLMs—this makes possible both SPARQL and natural language queries over the prescriptive diagrammatic designs, as analysis approaches. The proposed method can be used to describe contextualized cybersecurity threats during the design phase of a system or during IT system auditing. The integration bridge with knowledge graphs and large language models enhances the system analysis capabilities by streamlining heterogeneous knowledge flows comprising diagrammatic representation, RDF graphs and generative AI, towards an emerging flavor of model-driven engineering. The method was developed iteratively according to the Design Science framework, with its development activities specialized for the DSML-focused Agile Modeling Method Engineering framework.

Read PDF

Similar papers

Open access Aug 2026

A Five-Layer Reference Architecture for First-Party Enterprise Knowledge Graphs with GraphRAG Integration and Governance Controls

Organizations produce significant amounts of first-party data as part of their day-to-day operations in manufacturing, clinical, and customer experience domains, which are not accessible to generic large language models. The paper discusses the five-layer approach to using this information asset: (1) data ingestion and quality assurance, (2) domain ontology engineering, (3) knowledge graph engineering and population, (4) GraphRAG-enabled AI augmentation, and (5) downstream application enablement. The paper focuses on the design considerations, implementation tactics, and lessons learned from real-world applications in manufacturing, healthcare, and professional networks rather than presenting original research results. The implementation results show up to 70–80% query time reduction and close to 85% fewer hallucinations on average for GraphRAG over the standard RAG for most of the use cases analyzed. The main barriers to adoption are the substantial manual effort involved in ontology engineering, 73–94% entity resolution accuracy across different industries, and 3–5× higher computational costs for GraphRAG compared to RAG. The framework gives practitioners and researchers a reference architecture for designing, evaluating, and governing enterprise knowledge graph deployments built on proprietary organizational data.

Asheesh Pandey · 0 citations
Open access 2026

Designing Efficient Business Processes in the Metaverse with EffABPMN2MV: A Model-Driven Framework for Collaborative Software Design, AI-Driven Documentation, and Stakeholder Rights Management

EffABPMN2MV represents a theoretically grounded and empirically validated contribution to BPM, collaborative software design, and blockchain-enabled information systems.

Masoud Rezaei, Abbas Mirzaei, Babak Nouri-Moghaddam et al. · 0 citations
Preprint Aug 2026

Keeping Models and Code in Sync: Roundtrip Engineering for Tactical Domain-Driven Design

Domain-Driven Design gives teams a shared vocabulary for complex business logic, but that vocabulary only stays useful as long as the model and the code agree with each other. In practice, they drift apart: code changes outpace the model, or model revisions never make it into the codebase. This paper presents JDomInO, a bidirectional synchronization toolchain for tactical DDD that keeps a Java codebase and its domain model connected through a shared metamodel, with the goal of keeping the two in sync as the system evolves. JDomInO generates Java code structure deterministically from a domain model (forward path) and reconstructs a domain model from existing Java code (reverse path). The forward path has been fully validated on a Hotel Management scenario covering all 12 building block types in the metamodel; the reverse path's mapping logic has passed unit testing, with end-to-end validation underway. We also outline how the structured domain model produced by JDomInO could serve as a precision context layer for AI code assistants, helping them respect aggregate boundaries and DDD semantics that raw source code alone does not convey.

Weixing Zhang, Mario Herb, W. Cheng et al. · 0 citations
Preprint Aug 2026

A Security-Oriented Lifecycle Model for Large Language Model Systems

A lifecycle model for LLM systems is proposed that supports security analysis by structuring it around security-relevant boundaries rather than workflow optimisation, and is supported by a 12-stage LLMOps pillar and a 9-category governance pillar.

Eleftherios Batzolis, George Drosatos, V. Katsouros et al. · 0 citations
Book Open access Jul 2026

Lifecycle-Aware GenAI Assistance with MCP via Context Refinement Loops: A Reference Architecture

DevCoach is presented as a reference architecture built on the Model Context Protocol to make GenAI assistance more lifecycle-aware, governable, and inspectable in organizational settings and reframes GenAI integration as a software engineering design and governance problem rather than a prompt-level optimization problem.

Omar Elsisi, Fabio Santos, Glaucia Melo · 0 citations
Jul 2026

Harnessing Process Models and Standards for Change Management Boosted by Industry 4.0

Digitalization and regulatory compliance pose substantial challenges to companies, requiring adjustments to operations and business processes. Smooth transitions can be facilitated by analyzing discrepancies between current and target processes, enabling the identification of necessary organizational changes. Based on these insights, change managers can develop action plans to support effective implementation and ensure return on investment. Although scholars emphasize the importance of data-driven evaluation in change management (CM) and recognize the value of information embedded in business process models, the literature lacks systematic methods for extracting and integrating such information, particularly from text-based sources. In collaboration with industrial partners, we developed a method to address this gap. Our approach integrates semantic business process management, text analytics, and CM to compare process models with industrial standards, align process ontologies, and translate detected deviations into actionable recommendations. The method also resolves terminological inconsistencies across heterogeneous sources. This paper presents an analytics-based framework that delivers practical, context-specific guidance to change managers. To demonstrate applicability, we implemented a proof of concept in an industrial environment to validate process adherence against natural language documents such as industry standards

Domonkos Gáspár, Ildikó Szabó, Katalin Ternai et al. · 0 citations