NetHarden: Auditable Attack-Graph Hardening with Multi-Metric and LLM-Reliability Evaluation

Justice Owusu Agyemang, Kwame Agyeman-Prempeh Agyekum, Francisca Adoma Acheampong, Jerry John Kponyo, Michael Agyare, Kwame Opuni-Boachie Obour Agyekum

SSRN Electronic Journal · 2026

Attack-graph-based network hardening evaluations seldom ask whether the reported metric is the right metric or whether the increasingly common LLM reporting layer is reliable. \textsc{NetHarden} pairs a deterministic budgeted coverage-to-cost optimizer over host--vulnerability attack graphs (25 verified real CVEs from NVD) with a structured LLM remediation interface. The optimizer reaches 99.5\% mean weighted risk reduction on 30 synthetic networks and ties an LP-optimal set-cover ILP on all 130 networks (30-net plus 100-net expansion). Beyond the optimizer, a ± 50% coefficient sensitivity sweep yields a 0.012\,pp spread, and two metric-independent attacker models (passive random-walk and adaptive Viterbi-style, the latter plan-aware) find all methods statistically indistinguishable from doing nothing, with the adaptive attacker's best-path probability identical to three decimals across seven methods on both suites.

A six-model dual-judge LLM study with a 3-format prompt ablation finds every model returns a non-empty report on every plan; programmatic CVE- and host-level checks score 0.99--1.00 F1 with zero fabricated identifiers, while LLM-judge faithfulness reaches 6.21/10 with strong ordinal agreement (ρ{=}0.875) but zero agreement on the deployment threshold (κ{=}0). The combined evidence reframes \textsc{NetHarden} as a methodology contribution arguing for harder benchmarks and multi-objective evaluation, not a new optimizer.

📄 이 논문을 인용한 Paperis 글

이 논문이 근거 목록에 올라 있는 Paperis 글입니다.

Paperis - NetHarden: Auditable Attack-Graph Hardening with Multi-Metric and LLM-Reliability Evaluation