- Article
A Business-Oriented Approach to Automated Threat Analysis for Large-Scale Infrastructure Systems
- Chiaki Otahara,
- Hiroki Uchiyama and
- Makoto Kayashima
Security design for large-scale infrastructure systems requires substantial effort and often causes development delays. In line with NIST guidance, such systems should consider security design throughout a system development lifecycle. Nevertheless, performing security design in early phases of the lifecycle is difficult due to frequent specification changes and variability in analyst expertise, which causes repeated rework. The workload is particularly critical in threat analysis, the key activity of security design, because rework can inflate the workload. To address this challenge, we propose an automated threat-analysis method. Specifically, (i) we systematize past security design cases and develop “templates” that organize the system-configuration and security information required for threat analysis into a reusable 5W-based format (When, Where, Who, Why, What); (ii) we define dependencies among the templates and design an algorithm that automatically generates threat-analysis results; and (iii) observing that threat analysis of large-scale systems often yield overlaps, we introduce “business operations” as an analytical asset, which includes encompassing information, function, and physical resources. We apply our method to an actual large-scale operational system and confirm that it reduces the workload by up to 84% relative to conventional manual analysis, while maintaining both the coverage and the accuracy of the analysis.
16 January 2026


![Example of Business Process [Production Monitoring Business Process].](https://mdpi-res.com/computers/computers-15-00066/article_deploy/html/images/computers-15-00066-ag-550.jpg)

![The Climate Control Task from PISA 2012, retrieved from Eichmann et al. [50].](https://mdpi-res.com/computers/computers-15-00064/article_deploy/html/images/computers-15-00064-g001-550.jpg)


