Orchestrated Vulnerability Management for Heterogeneous Networks: Adaptive Two-Stage Vulnerability Assessment, Context-Aware Risk Prioritization, and Automated Mitigation
This study addresses the inefficiencies and delayed response in vulnerability management within heterogeneous networks, stemming from device diversity, environmental fragility, and configuration disparities. To tackle these challenges, the authors propose an automated vulnerability management framework orchestrated via SOAR (Security Orchestration, Automation, and Response). The framework integrates passive asset discovery, an adaptive two-stage vulnerability assessment, context-aware risk prioritization—combining CVSS, EPSS, and asset-specific context—and an SDN-driven mitigation mechanism capable of millisecond-level automated response. Its key innovation lies in significantly reducing scanning-induced disruption to resource-constrained devices while enabling precise risk-based prioritization. Experimental results demonstrate that the system identifies 71% of baseline vulnerabilities, reduces total scanning time by up to 91%, decreases the number of vulnerabilities requiring urgent remediation by approximately 75%, shortens assessment time for 32 hosts by up to 45%, and executes mitigation policies automatically within milliseconds.