{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T19:52:33Z","timestamp":1782762753285,"version":"3.54.5"},"reference-count":56,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/access.2026.3704350","type":"journal-article","created":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T19:44:44Z","timestamp":1781639084000},"page":"94788-94808","source":"Crossref","is-referenced-by-count":0,"title":["Scalability Challenges in Process for Attack Simulation and Threat Analysis (PASTA) Frameworks: A Comprehensive Survey of Current Bottlenecks and Future Directions"],"prefix":"10.1109","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-2595-2273","authenticated-orcid":false,"given":"Abdul","family":"Mohsin","sequence":"first","affiliation":[{"name":"Department of Computer Science, Birla Institute of Technology and Science (BITS) Pilani, Dubai Campus, Dubai, United Arab Emirates"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3992-1109","authenticated-orcid":false,"given":"Sujala D.","family":"Shetty","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Birla Institute of Technology and Science (BITS) Pilani, Dubai Campus, Dubai, United Arab Emirates"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Global Cybersecurity Outlook 2026","year":"2026"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3547932"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3582892"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2021.3125229"},{"key":"ref5","first-page":"88312","article-title":"Comparative analysis of threat modelling methodologies for agile environments","volume":"12","author":"Vijayan","year":"2024","journal-title":"IEEE Access"},{"key":"ref6","first-page":"144567","article-title":"Automated security requirements extraction from user stories using transformer-based NLP","volume":"12","author":"Lopez","year":"2024","journal-title":"IEEE Access"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3550337"},{"key":"ref8","article-title":"An integrity-focused threat model for software development pipelines","author":"Reichert","year":"2022","journal-title":"arXiv:2211.06249"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/s10270-022-00991-5"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-42212-6_7"},{"key":"ref11","first-page":"119843","article-title":"Cloud security posture management using automated SBOM analysis and risk correlation","volume":"12","author":"Liu","year":"2024","journal-title":"IEEE Access"},{"key":"ref12","first-page":"101243","article-title":"Automated STIX\/TAXII ingestion for continuous threat intelligence integration","volume":"12","author":"Al-Shaer","year":"2024","journal-title":"IEEE Access"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3257721"},{"key":"ref14","first-page":"129871","article-title":"CVSS-enhanced risk quantification: Integrating FAIR loss models for DevSecOps","volume":"11","author":"Wurzenberger","year":"2023","journal-title":"IEEE Access"},{"key":"ref15","first-page":"77234","article-title":"Scalable threat modeling for microservices architectures using graph-based decomposition","volume":"11","author":"Aldairi","year":"2023","journal-title":"IEEE Access"},{"key":"ref16","first-page":"21104","article-title":"LLM-augmented threat modelling for software architecture analysis","volume":"13","author":"Doynikova","year":"2025","journal-title":"IEEE Access"},{"key":"ref17","first-page":"48231","article-title":"Scalability challenges in automated threat modeling for large-scale systems","volume":"12","author":"Fang","year":"2024","journal-title":"IEEE Access"},{"key":"ref18","first-page":"113421","article-title":"Automated vulnerability discovery and triage in CI\/CD pipelines using SAST ensemble methods","volume":"11","author":"Aksu","year":"2023","journal-title":"IEEE Access"},{"key":"ref19","first-page":"55312","article-title":"Dynamic risk assessment of IoT supply chains using knowledge graphs and PASTA threat modelling","volume":"12","author":"Radanliev","year":"2024","journal-title":"IEEE Access"},{"key":"ref20","first-page":"11201","article-title":"Federated security assessment for distributed IoT architectures: A PASTA-based approach","volume":"13","author":"Ibarra","year":"2025","journal-title":"IEEE Access"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3603580"},{"key":"ref22","first-page":"29104","article-title":"Graph-based threat detection and analysis in cloud-native DevSecOps environments","volume":"13","author":"Al-Hashimi","year":"2025","journal-title":"IEEE Access"},{"key":"ref23","first-page":"144201","article-title":"Graph neural networks for automated attack path prediction in enterprise security graphs","volume":"12","author":"Polatidis","year":"2024","journal-title":"IEEE Access"},{"key":"ref24","first-page":"133402","article-title":"Reinforcement learning agents for automated attack path discovery in enterprise networks","volume":"12","author":"Nguyen","year":"2024","journal-title":"IEEE Access"},{"key":"ref25","first-page":"98761","article-title":"Predictive threat intelligence: ML approaches for TTP forecasting in enterprise networks","volume":"12","author":"Grigorescu","year":"2024","journal-title":"IEEE Access"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/DASC\/PiCom\/CBDCom\/Cy59711.2023.10361381"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3314629"},{"key":"ref28","first-page":"177801","article-title":"Zero-trust architecture as a dynamic input to threat modelling pipelines","volume":"12","author":"Anderson","year":"2024","journal-title":"IEEE Access"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2022.3227336"},{"key":"ref30","first-page":"87612","article-title":"Data-centric security for GDPR compliance using automated PII flow tracking","volume":"12","author":"Mell","year":"2024","journal-title":"IEEE Access"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3272629"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3133260"},{"key":"ref33","first-page":"21890","article-title":"Effectiveness of security champions programmes in large-scale DevSecOps transformations","volume":"13","author":"Cho","year":"2025","journal-title":"IEEE Access"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3486314"},{"key":"ref35","first-page":"34891","article-title":"Generative AI for threat elicitation: An empirical evaluation in financial services","volume":"13","author":"Ferreira","year":"2025","journal-title":"IEEE Access"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3497011"},{"key":"ref37","first-page":"67123","article-title":"Threat modeling of machine learning systems: A framework for data-driven environments","volume":"11","author":"Xiong","year":"2023","journal-title":"IEEE Access"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/s11219-023-09634-4"},{"key":"ref39","first-page":"120","article-title":"Threat modeling: A rough diamond or fool\u2019s gold?","volume-title":"Proc. Softw. Archit. ECSA","author":"Tran"},{"key":"ref40","article-title":"LINDDUN privacy threat modeling: A tutorial","author":"Wuyts","year":"2022"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3369906"},{"key":"ref42","first-page":"58901","article-title":"Adversarial risk analysis for threat-driven cyber investment decisions","volume":"11","author":"Rios","year":"2023","journal-title":"IEEE Access"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3219063"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3197195"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/s00287-023-01549-5"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev53368.2022.00028"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2021.111138"},{"key":"ref48","article-title":"ThreatKG: An AI-powered system for automated open-source cyber threat intelligence gathering and management","author":"Gao","year":"2022","journal-title":"arXiv:2212.10388"},{"key":"ref49","volume-title":"The STRIDE Threat Model","year":"2024"},{"key":"ref50","volume-title":"2024 Cybersecurity Workforce Study","year":"2024"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3364533"},{"key":"ref52","volume-title":"MITRE ATT&CK Framework","year":"2026"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.6028\/nist.ai.100-1"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-218"},{"key":"ref55","first-page":"1","article-title":"Regulation (EU) 2022\/2554 of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No. 1060\/2009, (EU) No. 648\/2012, (EU) No. 600\/2014, (EU) No. 909\/2014 and (EU) 2016\/1011","volume":"L333","author":"European Parliament","year":"2022","journal-title":"Off. J. Eur. Union"},{"key":"ref56","first-page":"1","volume-title":"ENISA Threat Landscape 2024","year":"2024"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6287639\/11323511\/11568437.pdf?arnumber=11568437","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T19:41:42Z","timestamp":1782762102000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11568437\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":56,"URL":"https:\/\/doi.org\/10.1109\/access.2026.3704350","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}