kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
FreeCAT—Towards a Framework for Resilience and Evolution by Code Analysis Tools
Stockholm University, Stockholm, Sweden.ORCID iD: 0000-0003-0478-9347
KTH, School of Electrical Engineering and Computer Science (EECS), Theoretical Computer Science.ORCID iD: 0000-0002-3656-1614
KTH, School of Electrical Engineering and Computer Science (EECS), Theoretical Computer Science.ORCID iD: 0000-0002-8069-6495
CISPA Helmholtz Center for Information Security, Saarbrücken, Germany.
Show others and affiliations
2026 (English)In: Enterprise Design, Operations, and Computing. EDOC 2025 Workshops - Forum, Doctoral Consortium, EA4AI, iRESEARCH, SoEA4EE, Tool Presentations, Revised Selected Papers, Springer Nature , 2026, Vol. 571 LNBIP, p. 175-188Conference paper, Published paper (Refereed)
Abstract [en]

Cyber attacks are getting smarter every year, yet most security checks still happen late in the project, when fixes are hardest and costliest. To change that, we propose FreeCAT, a step-by-step “security copilot” that works from the first design sketch all the way to day-to-day operation. FreeCAT automatically turns models, documentation, and log files into easy-to-read threat maps that show which parts of a system hackers would target first. It then runs simulations to test different defenses, points human testers to the riskiest spots, and feeds every new finding back into the map so the picture stays up to date. An AI component speeds up chores such as writing audit reports or checking compliance rules. Because these activities repeat in short loops throughout development and after launch, organizations can spot weak points early, use security budgets where they matter most, and keep pace with new attack tactics without hiring an army of specialists. The current paper outlines the concept and planned building blocks; the full platform will be assembled and validated in future work.

Place, publisher, year, edition, pages
Springer Nature , 2026. Vol. 571 LNBIP, p. 175-188
Keywords [en]
Attack Simulations, Cybersecurity Automation, Threat Modeling, Vulnerability Assessment
National Category
Computer Sciences Software Engineering
Identifiers
URN: urn:nbn:se:kth:diva-383421DOI: 10.1007/978-3-032-16234-2_12Scopus ID: 2-s2.0-105040565772OAI: oai:DiVA.org:kth-383421DiVA, id: diva2:2070816
Conference
29th International Workshop on Enterprise Design, Operations, and Computing, EDOC 2025, Lisbon, Portugal, Sep 09 2025 - Sep 12 2025
Note

Part of ISBN 9783032162335

QC 20260612

Available from: 2026-06-12 Created: 2026-06-12 Last updated: 2026-06-12Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Artho, CyrilleGuanciale, RobertoSüren, Emre

Search in DiVA

By author/editor
Hacks, SimonArtho, CyrilleGuanciale, RobertoSüren, Emre
By organisation
Theoretical Computer ScienceNetwork and Systems Engineering
Computer SciencesSoftware Engineering

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 17 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf