Digitala Vetenskapliga Arkivet

Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
FreeCAT—Towards a Framework for Resilience and Evolution by Code Analysis Tools
Stockholm University, Faculty of Social Sciences, Department of Computer and Systems Sciences.ORCID iD: 0000-0003-0478-9347
KTH Royal Institute of Technology, Stockholm, Sweden.
KTH Royal Institute of Technology, Stockholm, Sweden.
CISPA Helmholtz Center for Information Security, Saarbrücken, Germany.
Show others and affiliations
Number of Authors: 62026 (English)In: Enterprise Design, Operations, and Computing. EDOC 2025 Workshops: Forum, Doctoral Consortium, EA4AI, iRESEARCH, SoEA4EE, Tool Presentations, Lisbon, Portugal, September 9–12, 2025, Revised Selected Papers / [ed] José Barateiro; Andrey Rivkin; Jelena Zdravkovic; José Borbinha; Miguel Mira da Silva, Springer , 2026, p. 175-188Conference paper, Published paper (Refereed)
Abstract [en]

Cyber attacks are getting smarter every year, yet most security checks still happen late in the project, when fixes are hardest and costliest. To change that, we propose FreeCAT, a step-by-step “security copilot” that works from the first design sketch all the way to day-to-day operation. FreeCAT automatically turns models, documentation, and log files into easy-to-read threat maps that show which parts of a system hackers would target first. It then runs simulations to test different defenses, points human testers to the riskiest spots, and feeds every new finding back into the map so the picture stays up to date. An AI component speeds up chores such as writing audit reports or checking compliance rules. Because these activities repeat in short loops throughout development and after launch, organizations can spot weak points early, use security budgets where they matter most, and keep pace with new attack tactics without hiring an army of specialists. The current paper outlines the concept and planned building blocks; the full platform will be assembled and validated in future work.

Place, publisher, year, edition, pages
Springer , 2026. p. 175-188
Series
Lecture Notes in Business Information Processing, ISSN 1865-1348, E-ISSN 1865-1356 ; 571
Keywords [en]
Cybersecurity Automation, Threat Modeling, Attack Simulations, Vulnerability Assessment
National Category
Information Systems
Research subject
Computer and Systems Sciences
Identifiers
URN: urn:nbn:se:su:diva-256194DOI: 10.1007/978-3-032-16234-2_12Scopus ID: 2-s2.0-105040565772ISBN: 978-3-032-16233-5 (print)OAI: oai:DiVA.org:su-256194DiVA, id: diva2:2065519
Conference
EDOC 2025, 9-12 September, 2025, Lisbon, Portugal.
Available from: 2026-06-03 Created: 2026-06-03 Last updated: 2026-06-18Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Search in DiVA

By author/editor
Hacks, SimonMalakhova, Diana
By organisation
Department of Computer and Systems Sciences
Information Systems

Search outside of DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 30 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf