Тhis study examines the impact of automating the threat modeling process in conjunction with dynamic application security testing, aiming to reduce the time required to complete the full cycle—from creating a threat model to identifying vulnerabilities within web applications. The proposed automation method utilizes scripts to streamline both threat modeling and dynamic application security testing, eliminating the need for manual interventions. This automation ensures a consistent process that can be seamlessly integrated into CI/CD pipelines. The findings reveal that script-driven automated threat modeling can decrease analysis time by over 95% when compared to traditional manual methods. This approach aligns well with the requirements of contemporary DevSecOps practices, facilitating ongoing security monitoring and swift responses to emerging threats.
Nikolov et al. (Fri,) studied this question.