Search papers, labs, and topics across Lattice.
This paper introduces GARAGE, a RAG-powered framework designed to transform fragmented Cyber Threat Intelligence (CTI) into a structured knowledge base for automated attack graph generation in vehicle security. By synthesizing a dataset of 12,786 CVEs and 140 incident reports, GARAGE facilitates the formalization of tactical-pattern-level scenarios through detailed kill chain analysis, enabling effective threat generation. The framework's Leave-One-Out experiments demonstrate its ability to accurately apply security knowledge to previously unseen vehicle architectures, highlighting its potential as a scalable tool for Threat Assessment and Risk Analysis (TARA) in human-in-the-loop workflows.
GARAGE can accurately transfer security knowledge to new vehicle architectures, revolutionizing how we approach automotive cybersecurity.
While modern vehicle security depends on effective Cyber Threat Intelligence (CTI) synthesis, current automated tools struggle with unstructured data and automotive-specific architectural nuances. To bridge this gap, we introduce GARAGE, a RAG-powered framework that converts fragmented CTI into an actionable, domain-specific knowledge base for automated attack graph generation. GARAGE synthesizes a dataset of 12,786 CVEs and 140 incident reports into a STIX 2.1 and Auto-ISAC ATM-compliant knowledge base. By formalizing tactical-pattern-level scenarios through granular kill chain analysis, GARAGE achieves threat generation capabilities. Our 320 Leave-One-Out experiments reveal that the framework can accurately transfer security knowledge to entirely unseen vehicle architectures. Furthermore, we position GARAGE as a scalable TARA support tool within human-in-the-loop workflows, offering a comprehensive cost-performance analysis to guide its deployment across various LLM tiers.