A Threat Modeling Prioritization and Automation Framework for Composable Architectures

Organizations face escalating cyber risk, expanding attack surfaces, increasingly automated adversaries, and constrained security resources. Organizations are looking for practical mechanisms to improve security resilience by transforming threat modeling from a periodic design activity into a continuous, evidence-driven decision process. This paper offers a snapshot of the literature review of the threat modeling for composable architectures, shows why automation is difficult in this context, and proposes an automation framework to allocate scarce resources according to risk exposure to composable architecture components, where applications, services, identities, data flows, and autonomous agents are assembled and reconfigured across distributed environments. Composable architecture shows in an amplified way the gap between the static and dynamic security approaches, and our proposal helps to define the attributes needed for setting automation boundaries at the service level for risk prioritization based on threat modeling for security remediation actions. The conceptual framework integrates Zero Trust principles, control-effectiveness measurement, and human-in-the-loop governance and examines how automation with artificial intelligence changes the threat landscape by introducing risks that are difficult to measure and fast-changing. The results show that automation should be controlled with defined boundaries explained through measurable attributes for transparent decisions. It also proposes that AI should not replace expert judgement; rather, it should augment security teams by improving information quality, revealing hidden dependencies, supporting adaptive prioritization under uncertainty, and enabling resilience-oriented investment decisions for composable, distributed, and increasingly autonomous systems.

Authors

Institutions

Publication Details

Journal
Future Internet
Published
2026-09-22
DOI
https://doi.org/10.3390/fi18100499
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

A Threat Modeling Prioritization and Automation Framework for Composable Architectures

Remus Brad, Liviu-Mihai Popescu
Future Internet
Information and Cyber Security
article

A Threat Modeling Prioritization and Automation Framework for Composable Architectures

Remus Brad, Liviu-Mihai Popescu
article en

Abstract

Organizations face escalating cyber risk, expanding attack surfaces, increasingly automated adversaries, and constrained security resources. Organizations are looking for practical mechanisms to improve security resilience by transforming threat modeling from a periodic design activity into a continuous, evidence-driven decision process. This paper offers a snapshot of the literature review of the threat modeling for composable architectures, shows why automation is difficult in this context, and proposes an automation framework to allocate scarce resources according to risk exposure to composable architecture components, where applications, services, identities, data flows, and autonomous agents are assembled and reconfigured across distributed environments. Composable architecture shows in an amplified way the gap between the static and dynamic security approaches, and our proposal helps to define the attributes needed for setting automation boundaries at the service level for risk prioritization based on threat modeling for security remediation actions. The conceptual framework integrates Zero Trust principles, control-effectiveness measurement, and human-in-the-loop governance and examines how automation with artificial intelligence changes the threat landscape by introducing risks that are difficult to measure and fast-changing. The results show that automation should be controlled with defined boundaries explained through measurable attributes for transparent decisions. It also proposes that AI should not replace expert judgement; rather, it should augment security teams by improving information quality, revealing hidden dependencies, supporting adaptive prioritization under uncertainty, and enabling resilience-oriented investment decisions for composable, distributed, and increasingly autonomous systems.

Future InternetVol. 18(10)
Lucian Blaga University of Sibiu (RO)
Openalex Percentile: Top 4%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

A Threat Modeling Prioritization and Automation Framework for Composable Architectures — Remus Brad, Liviu-Mihai Popescu · Future Internet (2026) | TGRS Research Map | TGRS