{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,14]],"date-time":"2026-08-14T16:11:48Z","timestamp":1786723908880,"version":"3.56.0"},"reference-count":59,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2025,5,27]],"date-time":"2025-05-27T00:00:00Z","timestamp":1748304000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"University Research Scholarship Program of the Ministry for Culture and Innovation from the source of the National Research, Development, and Innovation Fund","award":["2024-2.1.1"],"award-info":[{"award-number":["2024-2.1.1"]}]},{"name":"University Research Scholarship Program of the Ministry for Culture and Innovation from the source of the National Research, Development, and Innovation Fund","award":["2019-1.3.1-KK-2019-00007"],"award-info":[{"award-number":["2019-1.3.1-KK-2019-00007"]}]},{"name":"Innov\u00e1ci\u00f3s szolg\u00e1ltat\u00f3 b\u00e1zis l\u00e9trehoz\u00e1sa diagnosztikai, ter\u00e1pi\u00e1s \u00e9s kutat\u00e1si c\u00e9l\u00fa kiberorvosi rendszerek fejleszt\u00e9s\u00e9re","award":["2024-2.1.1"],"award-info":[{"award-number":["2024-2.1.1"]}]},{"name":"Innov\u00e1ci\u00f3s szolg\u00e1ltat\u00f3 b\u00e1zis l\u00e9trehoz\u00e1sa diagnosztikai, ter\u00e1pi\u00e1s \u00e9s kutat\u00e1si c\u00e9l\u00fa kiberorvosi rendszerek fejleszt\u00e9s\u00e9re","award":["2019-1.3.1-KK-2019-00007"],"award-info":[{"award-number":["2019-1.3.1-KK-2019-00007"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>The proliferation of cyber\u2013physical systems in modern vehicles, characterized by densely interconnected Electronic Control Units (ECUs) and heterogeneous communication networks, has significantly expanded the automotive attack surface. Traditional Threat Analysis and Risk Assessment (TARA) methodologies remain predominantly manual processes that exhibit limitations in scalability, and comprehensive threat identification. This research addresses these limitations by developing a formalized framework for automating attack path analysis within the automotive architecture. While attack graph methodologies have demonstrated efficacy in conventional information technology domains, their application within automotive cybersecurity contexts presents unique challenges stemming from domain-specific architectural constraints. We propose a novel Graph-based Attack Path Prioritization (GAPP) methodology that integrates Extended Finite State Machine (EFSM) modeling. Our implementation employs the Neo4j property graph database architecture to establish the mappings between architectural components, security states, and exploitation vectors. This research contributes a systematic approach to automotive security assessment, enhancing vulnerability identification capabilities while reducing analytical complexity.<\/jats:p>","DOI":"10.3390\/info16060449","type":"journal-article","created":{"date-parts":[[2025,5,27]],"date-time":"2025-05-27T11:12:57Z","timestamp":1748344377000},"page":"449","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Graph-Based Automation of Threat Analysis and Risk Assessment for Automotive Security"],"prefix":"10.3390","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9265-2273","authenticated-orcid":false,"given":"Mera Nizam-Edden","family":"Saulaiman","sequence":"first","affiliation":[{"name":"BioTech Research Center, Doctoral School of Applied Informatics and Applied Mathematics, \u00d3buda University, 1034 Budapest, Hungary"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8096-9628","authenticated-orcid":false,"given":"Miklos","family":"Kozlovszky","sequence":"additional","affiliation":[{"name":"John Von Neumann Faculty of Informatics, Institute of Biomatics, \u00d3buda University, 1034 Budapest, Hungary"},{"name":"Applied Cyber-Medical Systems Research Team, Laboratory of Parallel and Distributed Systems, Institute for Computer Science and Control (SZTAKI), Hungarian Research Network (HUN-REN), 1518 Budapest, Hungary"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Akos","family":"Csilling","sequence":"additional","affiliation":[{"name":"Academic Relations, Robert Bosch Kft., 1103 Budapest, Hungary"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,5,27]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"830","DOI":"10.3897\/jucs.72367","article-title":"Cybersecurity Threat Analysis, Risk Assessment and Design Patterns for Automotive Networked Embedded Systems: A Case Study","volume":"27","author":"Dobaj","year":"2021","journal-title":"J. Univers. Comput. Sci. (JUCS)"},{"key":"ref_2","unstructured":"Mundhenk, P. (2017). Security for Automotive Electrical\/Electronic (E\/E) Architectures, Cuvillier Verlag."},{"key":"ref_3","unstructured":"Boban, M., Kousaridas, A., Manolakis, K., Eichinger, J., and Xu, W. (2017). Use cases, requirements, and design considerations for 5G V2X. arXiv."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"373","DOI":"10.1109\/JPROC.2019.2948302","article-title":"5G vehicle-to-everything services: Gearing up for security and privacy","volume":"108","author":"Lu","year":"2019","journal-title":"Proc. IEEE"},{"key":"ref_5","unstructured":"(2021). Road Vehicles\u2014Cybersecurity Engineering (Standard No. ISO\/SAE 21434:2021). Available online: https:\/\/www.iso.org\/standard\/70918.html."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"149","DOI":"10.12700\/APH.22.2.2025.2.8","article-title":"Integrated Automation for Threat Analysis and Risk Assessment in Automotive Cybersecurity Through Attack Graphs","volume":"22","author":"Saulaiman","year":"2025","journal-title":"Acta Polytech. Hung."},{"key":"ref_7","unstructured":"(2021). Road Vehicles\u2014Functional Safety (Standard No. ISO 26262-1:2018). Available online: https:\/\/www.iso.org\/standard\/68383.html."},{"key":"ref_8","unstructured":"(2025, May 24). UN Regulation No. 155\u2014Cyber Security and Cyber Security Management System|UNECE. Available online: https:\/\/unece.org\/transport\/documents\/2021\/03\/standards\/un-regulation-no-155-cyber-security-and-cyber-security."},{"key":"ref_9","unstructured":"(2025, May 24). Common Vulnerability Scoring System Version 4.0 Calculator. Available online: https:\/\/www.first.org\/cvss\/calculator\/4-0."},{"key":"ref_10","unstructured":"(2021). Road Vehicles\u2014Controller Area Network (CAN), Part 1: Data Link Layer and Physical Coding Sublayer (Standard No. ISO 11898-1:2024). Available online: https:\/\/www.iso.org\/standard\/86384.html."},{"key":"ref_11","unstructured":"(2021). Road Vehicles\u2014Controller Area Network (CAN), Part 2: High-Speed Physical Medium Attachment (PMA) Sublayer (Standard No. ISO 11898-2:2024). Available online: https:\/\/www.iso.org\/standard\/85120.html."},{"key":"ref_12","first-page":"5209","article-title":"Automotive Ethernet architecture and security: Challenges and technologies","volume":"13","author":"Toghuj","year":"2023","journal-title":"Int. J. Power Electron. Drive Syst.\/Int. J. Electr. Comput. Eng."},{"key":"ref_13","unstructured":"ENISA (2016). Cyber Security and Resilience of Smart Cars, ENISA."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Koscher, K., Czeskis, A., Roesner, F., Patel, S., Kohno, T., Checkoway, S., McCoy, D., Kantor, B., Anderson, D., and Shacham, H. (2010, January 16\u201319). Experimental Security Analysis of a Modern Automobile. Proceedings of the 2010 IEEE Symposium on Security and Privacy, Oakland, CA, USA.","DOI":"10.1109\/SP.2010.34"},{"key":"ref_15","unstructured":"Chartrand, G., and Zhang, P. (2013). A First Course in Graph Theory, Courier Corporation."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Gross, J.L., Yellen, J., and Anderson, M. (2018). Graph Theory and Its Applications, Chapman and Hall\/CRC.","DOI":"10.1201\/9780429425134"},{"key":"ref_17","first-page":"751","article-title":"An overview applications of graph theory in real field","volume":"2","author":"Mondal","year":"2017","journal-title":"Int. J. Sci. Res. Comput. Sci. Eng. Inf. Technol."},{"key":"ref_18","unstructured":"Dickson, A. (2006). Introduction to Graph Theory, CRC Press."},{"key":"ref_19","unstructured":"Grinberg, D. (2024). An introduction to graph theory. arXiv."},{"key":"ref_20","unstructured":"Wilson, R.J. (1979). Introduction to Graph Theory, Pearson Education India."},{"key":"ref_21","unstructured":"Jungnickel, D., and Jungnickel, D. (2005). Graphs, Networks and Algorithms, Springer."},{"key":"ref_22","unstructured":"Baier, C., and Katoen, J.P. (2008). Principles of Model Checking, The MIT Press. The MIT Press Ser."},{"key":"ref_23","unstructured":"Rich, E. (2008). Automata, Computability and Complexity: Theory and Applications, Pearson Prentice Hall."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Salfer, M. (2024). Automotive Security Analyzer for Exploitability Risks: An Automated and Attack Graph-Based Evaluation of On-Board Networks, Springer Fachmedien.","DOI":"10.1007\/978-3-658-43506-6"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.cosrev.2017.09.001","article-title":"A survey on the usability and practical applications of graphical security models","volume":"26","author":"Hong","year":"2017","journal-title":"Comput. Sci. Rev."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.cosrev.2014.07.001","article-title":"DAG-based attack and defense modeling: Don\u2019t miss the forest for the attack trees","volume":"13","author":"Kordy","year":"2014","journal-title":"Comput. Sci. Rev."},{"key":"ref_27","unstructured":"Sheyner, O., Haines, J., Jha, S., Lippmann, R., and Wing, J.M. (2002, January 12\u201315). Automated generation and analysis of attack graphs. Proceedings of the 2002 IEEE Symposium on Security and Privacy, Berkeley, CA, USA."},{"key":"ref_28","first-page":"21","article-title":"Attack trees","volume":"24","author":"Schneier","year":"1999","journal-title":"Dr. Dobb\u2019s J."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Ingols, K., Lippmann, R., and Piwowarski, K. (2006, January 11\u201315). Practical attack graph generation for network defense. Proceedings of the 2006 22nd Annual Computer Security Applications Conference (ACSAC\u201906), Miami Beach, FL, USA.","DOI":"10.1109\/ACSAC.2006.39"},{"key":"ref_30","unstructured":"Ou, X., Boyer, W.F., and McQueen, M.A. (November, January 30). A scalable approach to attack graph generation. Proceedings of the 13th ACM Conference on Computer and Communications Security, Alexandria, VA, USA."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Saulaiman, M.N.E., Kozlovszky, M., Csilling, \u00c1., Banati, A., and Benhamida, A. (2022, January 6\u20139). Overview of Attack Graph Generation For Automotive Systems. Proceedings of the 2022 IEEE 10th Jubilee International Conference on Computational Cybernetics and Cyber-Medical Systems (ICCC), Reykjav\u00edk, Iceland.","DOI":"10.1109\/ICCC202255925.2022.9922866"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"27974","DOI":"10.1109\/ACCESS.2023.3257721","article-title":"A Survey of MulVAL Extensions and Their Attack Scenarios Coverage","volume":"11","author":"Tayouri","year":"2023","journal-title":"IEEE Access"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Salfer, M., and Eckert, C. (2018, January 27\u201330). Attack graph-based assessment of exploitability risks in automotive on-board networks. Proceedings of the 13th International Conference on Availability, Reliability and Security, Hamburg, Germany.","DOI":"10.1145\/3230833.3230851"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"109730","DOI":"10.1016\/j.comnet.2023.109730","article-title":"Dynamic logic-based attack graph for risk assessment in complex computer systems","volume":"228","author":"Boudermine","year":"2023","journal-title":"Comput. Netw."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"559","DOI":"10.14429\/dsj.66.10795","article-title":"Attack graph generation and analysis techniques","volume":"66","author":"Barik","year":"2016","journal-title":"Def. Sci. J."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Yekta, A.R., Spychalski, D., Yekta, E., Yekta, C., and Katzenbeisser, S. (2023, January 5). VATT&EK: Formalization of Cyber Attacks on Intelligent Transport Systems\u2014A TTP based approach for Automotive and Rail. Proceedings of the 7th ACM Computer Science in Cars Symposium, Darmstadt, Germany.","DOI":"10.1145\/3631204.3631867"},{"key":"ref_37","unstructured":"Henniger, O., Ruddle, A., Seudi\u00e9, H., Weyl, B., Wolf, M., and Wollinger, T. (2009, January 27\u201328). Securing vehicular on-board it systems: The evita project. Proceedings of the VDI\/VW Automotive Security Conference, Ingolstadt, Germany."},{"key":"ref_38","unstructured":"(2022). Information Security, Cybersecurity and Privacy Protection\u2014Evaluation Criteria for IT Security (Standard No. ISO\/IEC 15408-1:2022). Available online: https:\/\/www.iso.org\/standard\/72891.html."},{"key":"ref_39","unstructured":"Ruddle, A., Ward, D., Weyl, B., Idrees, S., Roudier, Y., Friedewald, M., Leimbach, T., Fuchs, A., G\u00fcrgens, S., and Henniger, O. (2009). Deliverable D2. 3: Security requirements for automotive on-board networks based on dark-side scenarios. EVITA Proj., Available online: https:\/\/evita-project.org\/deliverables.html."},{"key":"ref_40","unstructured":"D\u00fcrrwang, J., Sommer, F., and Kriesten, R. (2021, January 10\u201311). Automation in automotive security by using attacker privileges. Proceedings of the 19th Escar Europe\u2014The World\u2019s Leading Automotive Cyber Security Conference, Escar Europe, Frankfurt, Germany."},{"key":"ref_41","unstructured":"Abouelnaga, M., and Jakobs, C. (2023). Security Risk Analysis Methodologies for Automotive Systems. arXiv."},{"key":"ref_42","unstructured":"Sommer, F. (2024). Automatic Attack Path Generation in Automotive Model-Based Security Testing. [Ph.D. Thesis, Institute of Distributed Systems Faculty of Engineering, Computer Science and Psychology, Ulm University]."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Alberts, C.J., Behrens, S.G., Pethia, R.D., and Wilson, W.R. (1999). Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) Framework, Version 1.0, Carnegie Mellon University. Technical Report.","DOI":"10.21236\/ADA367718"},{"key":"ref_44","unstructured":"Karahasanovic, A., Kleberger, P., and Almgren, M. (2017, January 7\u20138). Adapting threat modeling methods for the automotive industry. Proceedings of the 15th ESCAR Conference, Berlin, Germany."},{"key":"ref_45","unstructured":"Saulaiman, M., Csilling, A., and Kozlovszky, M. (2023, January 25\u201329). Leveraging Attack Graphs in Automotive Threat Analysis and Risk Assessment. Proceedings of the SECURWARE 2023: The Seventeenth International Conference on Emerging Security Information, Systems and Technologies, Porto, Portugal."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Alagar, V., and Periyasamy, K. (2011). Specification of Software Systems, Springer. Texts in Computer Science.","DOI":"10.1007\/978-0-85729-277-3"},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"55474","DOI":"10.1109\/ACCESS.2023.3282176","article-title":"Survey of Model-Based Security Testing Approaches in the Automotive Domain","volume":"11","author":"Sommer","year":"2023","journal-title":"IEEE Access"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Luo, F., Jiang, Y., Wang, J., Li, Z., and Zhang, X. (2023). A framework for cybersecurity requirements management in the automotive domain. Sensors, 23.","DOI":"10.3390\/s23104979"},{"key":"ref_49","unstructured":"(2025, January 14). National Vulnerability Database (NVD), Available online: https:\/\/nvd.nist.gov\/."},{"key":"ref_50","unstructured":"Checkoway, S., McCoy, D., Kantor, B., Anderson, D., Shacham, H., Savage, S., Koscher, K., Czeskis, A., Roesner, F., and Kohno, T. (2011, January 8\u201312). Comprehensive experimental analyses of automotive attack surfaces. Proceedings of the 20th USENIX Security Symposium (USENIX Security 11), San Francisco, CA, USA."},{"key":"ref_51","unstructured":"D\u00fcrrwang, J. (2022). Steigerung der Betriebssicherheit von Personenkraftwagen Durch Bedrohungsanalysen f\u00fcr die Informationssicherheit. [Ph.D. Thesis, Technische Universit\u00e4t M\u00fcnchen]."},{"key":"ref_52","unstructured":"Miller, C., and Valasek, C. (2014, January 2\u20137). A Survey of Remote Automotive Attack Surfaces. Proceedings of the Black Hat USA, Las Vegas, NV, USA."},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3569458","article-title":"Security risk assessments: Modeling and risk level propagation","volume":"7","author":"Angermeier","year":"2023","journal-title":"ACM Trans. Cyber-Phys. Syst."},{"key":"ref_54","unstructured":"Robinson, I., Webber, J., and Eifrem, E. (2015). Graph Databases: New Opportunities for Connected Data, O\u2019Reilly Media, Inc."},{"key":"ref_55","unstructured":"Anuyah, S., Bolade, V., and Agbaakin, O. (2024). Understanding graph databases: A comprehensive tutorial and survey. arXiv."},{"key":"ref_56","unstructured":"Vukotic, A., Watt, N., Abedrabbo, T., Fox, D., and Partner, J. (2014). Neo4j in Action, Manning Publications Co."},{"key":"ref_57","unstructured":"Pelofske, E., Liebrock, L.M., and Urias, V. (2023). Cybersecurity threat hunting and vulnerability analysis using a Neo4j graph database of open source intelligence. arXiv."},{"key":"ref_58","unstructured":"Noel, S., Harley, E., Tam, K.H., and Gyor, G. (2015, January 14\u201316). Big-data architecture for cyber attack graphs: Representing security relationships in NoSQL graph databases. Proceedings of the IEEE Symposium on Technologies for Homeland Security (HST), Waltham, MA, USA."},{"key":"ref_59","doi-asserted-by":"crossref","unstructured":"Wang, Y., Ren, Y., Cui, Z., and Yu, H. (2024). Proactive security defense: Cyber threat intelligence modeling for connected autonomous vehicles. arXiv.","DOI":"10.1038\/s41597-025-04439-5"}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/16\/6\/449\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:41:26Z","timestamp":1760031686000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/16\/6\/449"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,27]]},"references-count":59,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2025,6]]}},"alternative-id":["info16060449"],"URL":"https:\/\/doi.org\/10.3390\/info16060449","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,27]]}}}