Skip to content
Open access

Prioritization of security controls for critical infrastructure using the analytic network process and large language models

Jun 2026 · Collection Information technology and security · Vol 14, pp. 235-252 · 0 citations

Abstract

This paper addresses the applied problem of prioritizing security controls for national critical infrastructure under state‑level threats and severe resource constraints. We use the Analytic Network Process (ANP) to explicitly model nonlinear interdependencies and feedback loops in the system “controls–evaluation criteria–threat vectors–constraints”. A 20‑node ANP model is constructed with four clusters: security controls (7 alternatives), evaluation criteria (5), threat vectors (5), and constraints (3). The main novelty is an expert‑elicitation workflow based on “virtual experts”. Seven role personas (e.g., ICS engineer, SOC lead, CISO) are instantiated using large language models (LLMs) and used to produce the pairwise judgments required by ANP. The judgments are aggregated with the geometric mean. The resulting inputs demonstrate high consistency (mean Saaty consistency ratio ≈0.006; mean Koczkodaj index ≈0.034), enabling reliable synthesis of the limit supermatrix and global priorities. The final ranking assigns the highest priorities to Network Monitoring and Anomaly Detection (0.1948) and Network Segmentation / Unidirectional Gateways (0.1832), followed by Identity & Privileged Access Management (0.1623), Supply‑Chain Security with SBOM and code signing (0.1354), and Incident Response readiness (0.1342). The lowest priority in the considered scenario is Physical Hardening (0.0659). Robustness is confirmed by a leave‑one‑expert‑out (LOEO) analysis and by Monte‑Carlo perturbation (1000 trials), which yield stable rankings. Practical usefulness is illustrated with a portfolio selection model under a $10.2M budget, where a submodular knapsack heuristic selects {Monitoring, Identity, Incident Response, Supply Chain} as the highest‑value bundle for threat coverage.

Read PDF

Similar papers

2026

Integration of Vulnerability Databases into ISMS: A Path to Enhancing Cyber Resilience of Critical Systems

A conceptual model and methodological framework are proposed for embedding data from vulnerability databases into ISMS processes in alignment with ISO/IEC 27001/27002 and NIST recommendations, and provides methodological and architectural foundations for implementing integrated vulnerability management and enhancing cyber resilience in critical infrastructure environments.

V. Yashchuk, A. Ivanusa, N. Maslova et al. · 1 citation
Conference Open access 2026

A Hierarchical Evaluation Framework for LLM-driven Threat Modelling Tools

A systematic evaluation framework for LLM-driven threat modelling tools to support tool selection, observing the general LLM-integration, governance risks, and allowing for comparison of tool output is introduced.

Josephine Bakka, A. Brandhøj, T. Bøgedal et al. · 0 citations
Preprint Aug 2026

A Security-Oriented Lifecycle Model for Large Language Model Systems

A lifecycle model for LLM systems is proposed that supports security analysis by structuring it around security-relevant boundaries rather than workflow optimisation, and is supported by a 12-stage LLMOps pillar and a 9-category governance pillar.

Eleftherios Batzolis, George Drosatos, V. Katsouros et al. · 0 citations
Preprint Jul 2026

Determinants and Limits of LLM Security-Tool Orchestration: A Study with HexStrike-AI

Large language model agents driving security tool suites over the Model Context Protocol are increasingly common. Yet the factors that bound their capability remain poorly characterized: how much depends on the model versus the client that drives it, whether constraining the agent to the orchestrator's own tools helps, and where capability is limited by reasoning rather than by missing tools. Using HexStrikeAI, an open-source orchestrator that exposes 150+ tools, as a testbed, we follow a methodology that evaluates the system, diagnoses its failures, and applies targeted improvements. We run 86 picoCTF challenges across seven categories and three difficulty tiers, under three tool-access regimes and three model/client configurations (774 trials). We then apply corrections to existing tools, agent-behavior changes, and eleven new capability tools, and re-run the previously-unsuccessful trials. The diagnosis isolates the driving client as a first-order factor for a fixed model (a 2.1 * gap between two DeepSeek clients) and a monotonic difficulty gradient, with the largest gains in the mid tier. The overall solve rate rises from 55.4% to 72.0%, and every configuration improves significantly (paired McNemar p<0.001, non-overlapping 95% confidence intervals). The residual failures are reasoning- or environment-bound rather than missing-tool. A 60-run stability sub-study finds single-run verdicts reproducible (17/20 unanimous). We discuss what the results imply for how such orchestrators should be evaluated, and we are explicit about the limits: the study uses a single benchmark, the fixes were tuned on the same challenges they were evaluated on, and the client effect is demonstrated for one model only, so its generality to other models remains a hypothesis.

Romain Gerard, Assmaa Zeghaider, Yan Guo · 0 citations
Conference Jul 2026

A Comparative Analysis of Security Vulnerabilities and Defense Mechanisms in Large Language Models

Large Language Models (LLMs) are now deployed at an unprecedented scale across many critical sectors, rapidly transitioning from experimental AI tools to embedded components of production software systems. This accelerated adoption, often enabled by low-code integrations, has lowered technical barriers while simultaneously expanding the attack surface of modern applications, particularly when deployments occur without sufficient domain-specific security expertise. In many cases, security maturity has not progressed at the same pace as capability expansion, creating systemic exposure across confidentiality, integrity, and availability dimensions. To provide structured clarity amid this rapid growth, this paper presents a comparative and standards-aligned analysis of LLM security risks and defense mechanisms grounded in the OWASP GenAI Top-10 (2025). We systematically examine each vulnerability class, map representative attack patterns to primary mitigation strategies, evaluate their security property impact, and analyze practical limitations and implementation trade-offs. In addition, we introduce a severity-based assessment to prioritize risks according to operational and systemic impact, offering a quantitative perspective on defensive readiness. Our findings indicate that current mitigation strategies are predominantly reactive, concentrated at inference time, and unevenly distributed across the LLM lifecycle. Controls addressing training pipelines, supplychain dependencies, and autonomous system behaviors remain comparatively less mature and less standardized. By integrating vulnerability classification, defense mapping, severity prioritization, and trade-off analysis within a unified framework, this study provides actionable guidance for strengthening secure, resilient, and standards-driven LLM deployment in high-stakes environments.

Md Abdul Barek, Md Bajlur Rashid, A. K. I. Riad et al. · 0 citations