arXiv:2604.23905cs.CRcs.AI2026-04

自动为物联网系统生成安全威胁清单,提升防护效率。

SMSI: System Model Security Inference: Automated Threat Modeling for Cyber-Physical Systems

论文配图:SMSI: System Model Security Inference: Automated Threat Modeling for Cyber-Physical Systems
图 1 · 摘自论文原文
  • 从系统架构模型出发,用符号与神经网络结合方式识别漏洞。
  • 在医疗物联网网关上验证,准确推荐符合标准的安全控制措施。
  • 适合安全工程师快速构建威胁模型,降低人工成本。

针对工业物联网等信息物理系统(CPS)的威胁建模仍依赖人工,本文提出SMSI(系统模型安全推断)框架,通过混合神经-符号流程,从SysML架构模型自动推导出优先级排序的NIST 800-53安全控制项。该原型包含三个阶段:基于NVD的确定性解析器将组件映射至漏洞;一系列检索与分类模型将漏洞关联至MITRE ATT&CK攻击技术;最终由控制推荐模块输出安全策略。在九个软件组件的医疗物联网网关案例中评估,使用微调后的SecureBERT+在CVE到ATT&CK映射中表现最佳,且预训练的SecureBERT在控制检索任务中得分最高,表明密集嵌入可有效支撑自动化推荐。

原文摘要 · Abstract (English)

Threat modeling for cyber-physical systems (CPS) remains a largely manual exercise. This project presents SMSI (System Model Security Inference), a hybrid neuro-symbolic pipeline that starts from a SysML architecture model and produces a prioritized list of NIST 800-53 security controls. The prototype has three main stages: a deterministic parser mapping system components to vulnerabilities via the NVD; a family of retrieval and classification models linking vulnerabilities to MITRE ATT&CK techniques; and a control recommender. We explore three approaches for CVE-to-ATT&CK mapping: a supervised classifier using fine-tuned SecureBERT+, retrieval-based dense encoders, and a zero-shot LLM approach using Gemma-4 26B. We validate the pipeline on a healthcare IoT gateway with nine software components. For the ATT&CK-to-NIST stage, pretrained SecureBERT achieves the highest control retrieval scores, demonstrating that dense embeddings provide a strong basis for automated control recommendation.

威胁建模系统安全自动化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。