Cloud Security AI Infrastructure Threat Modeling MITRE ATLAS AWS

BlastMap

An identity-centric threat mapping framework for cloud AI infrastructure, mapping MITRE ATLAS attack tactics to machine identity over-privilege in AWS environments.

Status
Active Research
Venue
CMU Scholar Showcase '26
Environment
AWS Cloud / IAM
Framework
MITRE ATLAS

BlastMap addresses a growing blind spot in cloud AI security: machine identities IAM roles, service accounts, and instance profiles are consistently over-privileged in AWS environments hosting AI workloads, creating a wide blast radius when compromised.

The framework systematically maps MITRE ATLAS adversarial ML tactics to specific IAM misconfiguration patterns, enabling security teams to prioritize identity remediation based on realistic attack paths rather than theoretical vulnerability scores.

"Most cloud AI security frameworks focus on model protection. BlastMap focuses on what attackers actually target first: the identity layer that gives them access to everything else."

NIST 800-53 AC, IA, SC families
SOC 2 CC6, CC7 criteria
EU AI Act High-risk systems
MITRE ATLAS Full tactic coverage
AWS IAM
MITRE ATLAS
AWS SageMaker
Python
AWS Policy Sim
NIST 800-53