Orchestrated Vulnerability Management for Heterogeneous Networks: Adaptive Two-Stage Vulnerability Assessment, Context-Aware Risk Prioritization, and Automated Mitigation

📅 2026-08-08
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the inefficiencies and delayed response in vulnerability management within heterogeneous networks, stemming from device diversity, environmental fragility, and configuration disparities. To tackle these challenges, the authors propose an automated vulnerability management framework orchestrated via SOAR (Security Orchestration, Automation, and Response). The framework integrates passive asset discovery, an adaptive two-stage vulnerability assessment, context-aware risk prioritization—combining CVSS, EPSS, and asset-specific context—and an SDN-driven mitigation mechanism capable of millisecond-level automated response. Its key innovation lies in significantly reducing scanning-induced disruption to resource-constrained devices while enabling precise risk-based prioritization. Experimental results demonstrate that the system identifies 71% of baseline vulnerabilities, reduces total scanning time by up to 91%, decreases the number of vulnerabilities requiring urgent remediation by approximately 75%, shortens assessment time for 32 hosts by up to 45%, and executes mitigation policies automatically within milliseconds.
📝 Abstract
Heterogeneous networks pose significant security challenges due to device diversity, fragile operating conditions, and heterogeneous firmware and service configurations. Traditional vulnerability management often relies on static scanning and severity-based prioritization, overlooking exploitation likelihood and asset context. This can delay mitigation and increase operational overhead. This paper proposes a SOAR-orchestrated vulnerability management framework integrating passive asset discovery, adaptive two-stage vulnerability assessment, context-aware risk assessment, and automated SDN-based mitigation. The detection engine progressively characterizes device attack surfaces using assessment strategies tailored to device capabilities, minimizing disruption to resource-constrained IoT assets. Risk assessment combines CVSS severity, EPSS exploitation probability, and contextual attributes to prioritize vulnerabilities by operational risk. Based on risk bands, mitigation is automatically enforced through coordinated OpenFlow and IDS policies, ranging from monitoring and selective service isolation to complete host quarantine. Experimental results demonstrate the framework's effectiveness. Adaptive two-stage assessment reduces scan time by up to 91% while identifying 71% of baseline vulnerabilities during the initial stage before selectively triggering further analysis. The context-aware risk model reduces vulnerabilities requiring immediate mitigation by approximately 75% without missing any vulnerability with verified exploitation. Compared with conventional assessment, the framework reduces assessment time for 32 physical hosts by up to 45% and enforces mitigation within milliseconds, enabling efficient and scalable vulnerability management through adaptive assessment, context-aware prioritization, and automated mitigation.
Problem

Research questions and friction points this paper is trying to address.

heterogeneous networks
vulnerability management
context-aware risk prioritization
adaptive assessment
automated mitigation
Innovation

Methods, ideas, or system contributions that make the work stand out.

adaptive vulnerability assessment
context-aware risk prioritization
automated mitigation
SOAR-orchestrated security
heterogeneous networks
🔎 Similar Papers
No similar papers found.
Ricardo Lopes
Ricardo Lopes
ISCTE – Instituto Universitário de Lisboa, Lisbon, Portugal
J
Jose Moura
ISCTE – Instituto Universitário de Lisboa, Lisbon, Portugal; Instituto de Telecomunicações, Lisbon, Portugal
R
Rui Neto Marinheiro
ISCTE – Instituto Universitário de Lisboa, Lisbon, Portugal; Instituto de Telecomunicações, Lisbon, Portugal