{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T16:48:32Z","timestamp":1783183712487,"version":"3.54.6"},"reference-count":35,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2025,7,22]],"date-time":"2025-07-22T00:00:00Z","timestamp":1753142400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Comput. Sci."],"abstract":"<jats:sec><jats:title>Introduction<\/jats:title><jats:p>With the rise of digital transformation, the concept of the smart city has emerged as a key pillar of modern urban development. However, as smart cities increasingly rely on the Internet of Things (IoT), cloud computing, and real-time data processing, they also face an expanded attack surface and growing cybersecurity threats.<\/jats:p><\/jats:sec><jats:sec><jats:title>Methods<\/jats:title><jats:p>This paper presents a comprehensive threat modeling and risk assessment approach tailored to smart city environments. It begins by identifying the core components and data flows within a typical smart city architecture covering domains such as surveillance, transportation, and healthcare. A Data Flow Diagram (DFD) is constructed to visualize the interactions and pinpoint critical assets. The STRIDE methodology, supported by the Microsoft Threat Modeling (MTM) tool, is employed to systematically uncover threats including spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. To enrich the analysis and align with real-world adversarial behavior, the MITRE ATT&amp;amp;CK framework is also utilized to map identified threats to known tactics and techniques. Each discovered threat is evaluated through a detailed risk assessment using the Common Vulnerability Scoring System (CVSS) and a 5 by 5 risk matrix, allowing a quantifiable estimation of impact and likelihood.<\/jats:p><\/jats:sec><jats:sec><jats:title>Results<\/jats:title><jats:p>The analysis revealed 21 threats across smart city domains, with spoofing, tampering, and denial of service being the most frequent. Five threats were rated as critical based on CVSS, particularly targeting cloud services and web applications.<\/jats:p><\/jats:sec><jats:sec><jats:title>Discussion<\/jats:title><jats:p>Furthermore, the paper introduces a dedicated case study involving the Internet of Vehicles (IoV), applying the Cyber Kill Chain model to demonstrate the progression of a cyber-attack targeting connected vehicle systems, with a focus on identifying less common yet critical ATT&amp;amp;CK techniques at each phase. The study concludes by proposing targeted mitigation strategies and architectural recommendations aimed at enhancing the cyber resilience of smart city infrastructures.<\/jats:p><\/jats:sec>","DOI":"10.3389\/fcomp.2025.1647179","type":"journal-article","created":{"date-parts":[[2025,7,22]],"date-time":"2025-07-22T05:30:00Z","timestamp":1753162200000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["A framework for cyber threat modeling and risk assessment in smart city environments"],"prefix":"10.3389","volume":"7","author":[{"given":"Mariya","family":"Ouaissa","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mariyam","family":"Ouaissa","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zineb","family":"Nadifi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sarah","family":"El Himer","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yassine","family":"Al Masmoudi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ali","family":"Kartit","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1965","published-online":{"date-parts":[[2025,7,22]]},"reference":[{"key":"ref1","doi-asserted-by":"publisher","first-page":"103949","DOI":"10.1016\/j.scs.2022.103949","article-title":"A systematic survey of internet of things frameworks for smart city applications","volume":"83","author":"Abad\u00eda","year":"2022","journal-title":"Sustain. Cities Soc."},{"key":"ref2","author":"Al-Ani","year":"2019"},{"key":"ref3","doi-asserted-by":"publisher","first-page":"101019","DOI":"10.1016\/j.suscom.2024.101019","article-title":"Optimizing risk mitigation: a simulation-based model for detecting fake IoT clients in smart city environments","volume":"43","author":"AlJamal","year":"2024","journal-title":"Sustain. Comput."},{"key":"ref4","doi-asserted-by":"publisher","first-page":"1217","DOI":"10.1109\/ACCESS.2023.3344680","article-title":"Analysis and characterization of cyber threats leveraging the MITRE ATT&CK database","volume":"12","author":"Al-Sada","year":"2023","journal-title":"IEEE Access"},{"key":"ref5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3687300","article-title":"Mitre att&ck: state of the art and way forward","volume":"57","author":"Al-Sada","year":"2024","journal-title":"ACM Comput. Surv."},{"key":"ref6","first-page":"387","article-title":"Modeling security threats for smart cities: a stride-based approach","author":"Anwar","year":"2020"},{"key":"ref7","doi-asserted-by":"publisher","first-page":"7823","DOI":"10.3390\/app14177823","article-title":"A comprehensive survey on the societal aspects of smart cities","volume":"14","author":"Bastos","year":"2024","journal-title":"Appl. Sci."},{"key":"ref8","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/s43926-024-00076-3","article-title":"Smart cities and the IoT: an in-depth analysis of global research trends and future directions","volume":"4","author":"Bhardwaj","year":"2024","journal-title":"Discov. Internet Things"},{"key":"ref9","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1016\/j.iotcps.2023.12.002","article-title":"Metaverse for smart cities: a survey","volume":"4","author":"Chen","year":"2024","journal-title":"Int. Things Cyber-Phys. Syst."},{"key":"ref10","doi-asserted-by":"publisher","first-page":"1140","DOI":"10.3390\/vehicles6030054","article-title":"Stride-based cybersecurity threat modeling, risk assessment and treatment of an in-vehicle infotainment system","volume":"6","author":"Das","year":"2024","journal-title":"Vehicles"},{"key":"ref11","author":"Debnath","year":"2022"},{"key":"ref12","author":"Fadzil","year":"2023"},{"key":"ref13","author":"Hossain","year":"2023"},{"key":"ref14","doi-asserted-by":"publisher","first-page":"393","DOI":"10.1007\/s10796-020-10044-1","article-title":"Security, privacy and risks within smart cities: literature review and development of a smart city interaction framework","volume":"24","author":"Ismagilova","year":"2022","journal-title":"Inf. Syst. Front."},{"key":"ref15","author":"Koban","year":"2022"},{"key":"ref16","author":"Kumar","year":"2024"},{"key":"ref17","doi-asserted-by":"publisher","first-page":"102023","DOI":"10.1016\/j.scs.2020.102023","article-title":"Security and the smart city: a systematic review","volume":"55","author":"Laufs","year":"2020","journal-title":"Sustain. Cities Soc."},{"key":"ref18","doi-asserted-by":"publisher","first-page":"51","DOI":"10.31449\/inf.v47i1.4526","article-title":"Threat model and risk management for a smart home IoT system","volume":"47","author":"Mahlous","year":"2023","journal-title":"Informatica"},{"key":"ref19","doi-asserted-by":"publisher","first-page":"103985","DOI":"10.1016\/j.cose.2024.103985","article-title":"Adopting security practices in software development process: security testing framework for sustainable smart cities","volume":"144","author":"Mothanna","year":"2024","journal-title":"Comput. Secur."},{"key":"ref20","author":"Naik","year":"2024"},{"key":"ref21","author":"Okai","year":"2018"},{"key":"ref22","doi-asserted-by":"publisher","first-page":"126","DOI":"10.3991\/ijim.v19i02.52377","article-title":"Analyzing and mitigating attacks in IoT smart home using a threat modeling approach-based STRIDE","volume":"19","author":"Ouaissa","year":"2025","journal-title":"Int. J. Interact. Mob. Technol."},{"key":"ref23","doi-asserted-by":"publisher","first-page":"393","DOI":"10.3390\/fi15120393","article-title":"Information security applications in smart cities: a bibliometric analysis of emerging research","volume":"15","author":"Poleto","year":"2023","journal-title":"Future Internet"},{"key":"ref24","doi-asserted-by":"publisher","first-page":"1514040","DOI":"10.3389\/frsc.2024.1514040","article-title":"Social smart city research: interconnections between participatory governance, data privacy, artificial intelligence and ethical sustainable development","volume":"6","author":"Rasoulzadeh Aghdam","year":"2025","journal-title":"Front. Sustain. Cities"},{"key":"ref25","doi-asserted-by":"crossref","first-page":"95","DOI":"10.1007\/978-981-97-8483-7_5","article-title":"Building resilient smart cities: the role of digital twins and generative AI in disaster management strategy","volume-title":"Digital twin computing for urban intelligence","author":"Razavi","year":"2024"},{"key":"ref26","doi-asserted-by":"publisher","first-page":"1550147719853984","DOI":"10.1177\/1550147719853984","article-title":"Smart cities survey: technologies, application domains and challenges for the cities of the future","volume":"15","author":"S\u00e1nchez-Corcuera","year":"2019","journal-title":"Int. J. Distrib. Sens. Networks"},{"key":"ref27","doi-asserted-by":"publisher","first-page":"68319","DOI":"10.1109\/ACCESS.2022.3184710","article-title":"A decade review on smart cities: paradigms, challenges and opportunities","volume":"10","author":"Singh","year":"2022","journal-title":"IEEE Access"},{"key":"ref28","doi-asserted-by":"publisher","first-page":"100809","DOI":"10.1016\/j.iot.2023.100809","article-title":"Security issues in internet of vehicles (IoV): a comprehensive survey","volume":"22","author":"Taslimasa","year":"2023","journal-title":"Internet of Things"},{"key":"ref29","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1049\/iet-smc.2020.0001","article-title":"Security for smart cities","volume":"2","author":"Toh","year":"2020","journal-title":"IET Smart Cities"},{"key":"ref30","doi-asserted-by":"publisher","first-page":"301540","DOI":"10.1016\/j.fsidi.2023.301540","article-title":"Identifying threats, cybercrime and digital forensic opportunities in smart city infrastructure via threat modeling","volume":"45","author":"Tok","year":"2023","journal-title":"Forensic Sci. Int. Digit. Investig."},{"key":"ref31","doi-asserted-by":"publisher","first-page":"252","DOI":"10.54560\/jracr.v13i4.411","article-title":"Integrating resilience into risk matrices: a practical approach to risk assessment with empirical analysis","volume":"13","author":"Vaezi","year":"2023","journal-title":"J. Risk Anal. Crisis Response"},{"key":"ref32","author":"Wang","year":"2015"},{"key":"ref33","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1016\/j.cose.2019.03.010","article-title":"Threat modeling\u2013a systematic literature review","volume":"84","author":"Xiong","year":"2019","journal-title":"Comput. Secur."},{"key":"ref34","doi-asserted-by":"publisher","first-page":"100766","DOI":"10.1016\/j.iot.2023.100766","article-title":"Threat modeling in smart firefighting systems: aligning MITRE ATT&CK matrix and NIST security controls","volume":"22","author":"Zahid","year":"2023","journal-title":"Int. Things"},{"key":"ref35","doi-asserted-by":"publisher","first-page":"170","DOI":"10.54254\/2755-2721\/38\/20230549","article-title":"Navigating the cyber kill chain: a modern approach to pentesting","volume":"38","author":"Zhao","year":"2024","journal-title":"Appl. Comput. Eng."}],"container-title":["Frontiers in Computer Science"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2025.1647179\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,22]],"date-time":"2025-07-22T05:30:01Z","timestamp":1753162201000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2025.1647179\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,22]]},"references-count":35,"alternative-id":["10.3389\/fcomp.2025.1647179"],"URL":"https:\/\/doi.org\/10.3389\/fcomp.2025.1647179","relation":{},"ISSN":["2624-9898"],"issn-type":[{"value":"2624-9898","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,22]]},"article-number":"1647179"}}