Institution profile

University of Southern Mississippi

Academic institutionnorthamerica · us
Official website
Research library37linked papers
Opportunities0open roles
Selected work

Representative Papers

PECR: A Reproducible Specification and Synthetic Stress Test of Telemetry-Informed Vulnerability Prioritization for SD-WAN

Aug 04, 2026

This study addresses the limitations of traditional severity-based vulnerability prioritization in accurately capturing real-world exposure risk and evidence quality within SD-WAN environments. The authors propose the Predictive Exposure and Cryptographic Readiness (PECR) framework, which integrates nine normalized factors to rank vulnerabilities and establishes a dedicated migration queue for cryptographic dependencies, while simultaneously providing confidence and score intervals. PECR constitutes the first actionable vulnerability prioritization specification, augmented by a synthetic stress-testing framework that quantifies ranking robustness under multidimensional perturbations through synthetic data generation, Kendall τ correlation analysis, Dirichlet weight sampling, and interval-based decision boundary detection. Experimental results demonstrate that PECR significantly outperforms baseline metrics such as CVSS and EPSS on synthetic datasets (τ = 0.836–0.924) and identifies 47% of vulnerability records requiring cautious handling due to insufficient evidence.

0 citationsRead paper

Predictive Exposure and Cryptographic Readiness: A Vendor-Neutral Framework, a, Bounded Multivocal Evidence Analysis, and Reproducible Synthetic Evaluation for SD-WAN Environments

Aug 03, 2026

Traditional static scoring systems, such as CVSS, fail to capture real-time exploitability, network exposure, attack paths, business impact, and cryptographic migration risks, limiting their effectiveness in guiding vulnerability remediation priorities within SD-WAN environments. To address this gap, this work proposes PECR—a vendor-neutral framework that uniquely integrates predictive exposure, cryptographic readiness, and organizational context. By normalizing multi-source evidence, applying weighted scoring, and incorporating confidence assessment, PECR enables traceable and auditable vulnerability prioritization. Empirical evaluation demonstrates that PECR consistently produces stable rankings distinct from CVSS (e.g., A-B-E-C-D) across five synthetic scenarios, with 87.5% of weight configurations yielding identical orderings. Furthermore, the framework exhibits robustness under factor ablation and bounded perturbation tests.

0 citationsRead paper
Recent publications

Latest Papers

PECR: A Reproducible Specification and Synthetic Stress Test of Telemetry-Informed Vulnerability Prioritization for SD-WAN

Aug 04, 2026

This study addresses the limitations of traditional severity-based vulnerability prioritization in accurately capturing real-world exposure risk and evidence quality within SD-WAN environments. The authors propose the Predictive Exposure and Cryptographic Readiness (PECR) framework, which integrates nine normalized factors to rank vulnerabilities and establishes a dedicated migration queue for cryptographic dependencies, while simultaneously providing confidence and score intervals. PECR constitutes the first actionable vulnerability prioritization specification, augmented by a synthetic stress-testing framework that quantifies ranking robustness under multidimensional perturbations through synthetic data generation, Kendall τ correlation analysis, Dirichlet weight sampling, and interval-based decision boundary detection. Experimental results demonstrate that PECR significantly outperforms baseline metrics such as CVSS and EPSS on synthetic datasets (τ = 0.836–0.924) and identifies 47% of vulnerability records requiring cautious handling due to insufficient evidence.

0 citationsRead paper

Predictive Exposure and Cryptographic Readiness: A Vendor-Neutral Framework, a, Bounded Multivocal Evidence Analysis, and Reproducible Synthetic Evaluation for SD-WAN Environments

Aug 03, 2026

Traditional static scoring systems, such as CVSS, fail to capture real-time exploitability, network exposure, attack paths, business impact, and cryptographic migration risks, limiting their effectiveness in guiding vulnerability remediation priorities within SD-WAN environments. To address this gap, this work proposes PECR—a vendor-neutral framework that uniquely integrates predictive exposure, cryptographic readiness, and organizational context. By normalizing multi-source evidence, applying weighted scoring, and incorporating confidence assessment, PECR enables traceable and auditable vulnerability prioritization. Empirical evaluation demonstrates that PECR consistently produces stable rankings distinct from CVSS (e.g., A-B-E-C-D) across five synthetic scenarios, with 87.5% of weight configurations yielding identical orderings. Furthermore, the framework exhibits robustness under factor ablation and bounded perturbation tests.

0 citationsRead paper