Modern software development paradigms, particularly Agile and DevOps methodologies, have compressed development timelines while simultaneously increasing the complexity of security threat landscapes. Traditional threat modeling approaches, notably attack scenario analysis, demand substantial security expertise and extensive time investments that are incompatible with accelerated development cycles. Furthermore, the expanding demand for secure systems has necessitated threat analysis implementation by practitioners lacking comprehensive security backgrounds. This research presents COTTAGE, an automated tool that generates Attack Defense Trees (ADTrees) by leveraging CAPEC and CWE security knowledge repositories, specifically designed to enable effective threat modeling by security non-specialists. Experimental validation involving six participants with limited security expertise revealed that COTTAGE facilitated threat analysis outcomes comparable to expert-level assessment within 30-minute sessions, contrasting with the approximately two-day timeframe typically required by security professionals. Additional validation through DevOps environment case studies confirmed COTTAGE's capability to support continuous security assessment via automatically generated reference tree structures.
YAMAMOTO et al. (Thu,) studied this question.