Prioritization of security controls for critical infrastructure using the analytic network process and large language models
Abstract
This paper addresses the applied problem of prioritizing security controls for national critical infrastructure under state‑level threats and severe resource constraints. We use the Analytic Network Process (ANP) to explicitly model nonlinear interdependencies and feedback loops in the system “controls–evaluation criteria–threat vectors–constraints”. A 20‑node ANP model is constructed with four clusters: security controls (7 alternatives), evaluation criteria (5), threat vectors (5), and constraints (3). The main novelty is an expert‑elicitation workflow based on “virtual experts”. Seven role personas (e.g., ICS engineer, SOC lead, CISO) are instantiated using large language models (LLMs) and used to produce the pairwise judgments required by ANP. The judgments are aggregated with the geometric mean. The resulting inputs demonstrate high consistency (mean Saaty consistency ratio ≈0.006; mean Koczkodaj index ≈0.034), enabling reliable synthesis of the limit supermatrix and global priorities. The final ranking assigns the highest priorities to Network Monitoring and Anomaly Detection (0.1948) and Network Segmentation / Unidirectional Gateways (0.1832), followed by Identity & Privileged Access Management (0.1623), Supply‑Chain Security with SBOM and code signing (0.1354), and Incident Response readiness (0.1342). The lowest priority in the considered scenario is Physical Hardening (0.0659). Robustness is confirmed by a leave‑one‑expert‑out (LOEO) analysis and by Monte‑Carlo perturbation (1000 trials), which yield stable rankings. Practical usefulness is illustrated with a portfolio selection model under a $10.2M budget, where a submodular knapsack heuristic selects {Monitoring, Identity, Incident Response, Supply Chain} as the highest‑value bundle for threat coverage.