Predictive Exposure and Cryptographic Readiness: A Vendor-Neutral Framework, a, Bounded Multivocal Evidence Analysis, and Reproducible Synthetic Evaluation for SD-WAN Environments

2026-08-03Networking and Internet Architecture

Networking and Internet Architecture
AI summary

The authors looked at how current SD-WAN security teams pick which vulnerabilities to fix first, usually by using a fixed severity score (CVSS). They studied a new framework called PECR that uses multiple factors like live attacks, business impact, and confidence levels to rank issues. When they tested PECR against CVSS on five example cases, the rankings were different but stable even when changing weights or removing factors. The authors say PECR offers a more traceable ranking but do not claim it is better in real-world use yet, as more evidence is needed.

SD-WANCVSSPECR frameworkseverity scoringvulnerability rankingattack pathsKendall's taumean absolute rank shiftJaccard overlappost-quantum cryptography (PQC)
Authors
Saeed Alam
Abstract
SD-WAN teams often use static severity scores to decide what to fix first. These scores do not show live exploitation, network exposure, attack paths, business impact, or cryptographic migration risk. This study asks whether a vendor-neutral PECR framework can produce a different and more traceable ranking than CVSS alone. We reviewed 19 DOI-verified publications from 2020-2026 and five current NIST documents. The review supported ten normalized factors, one weighted score, and a separate confidence measure. We then compared equal-weight PECR with CVSS in five synthetic cases. The tests used Kendall's $τ_b$, mean absolute rank shift (MARS), top-three Jaccard overlap ($J_3$), factor removal, and bounded weight changes. CVSS ranked the cases A-D-B-E-C. PECR ranked them A-B-E-C-D. The results were $τ_b = 0.40$, MARS = 1.2, and $J_3 = 0.50$. The exact $τ$ test was not significant ($p = 0.483$) because the sample had only five cases. The PECR order remained unchanged in 87.5% of 1,024 weight combinations. It also remained unchanged in eight of ten single-factor removal tests. The evidence supports separate measures for severity, exploitation, and organizational context. Evidence for live SD-WAN attack paths and daily PQC triage is still limited. PECR can produce a different and auditable ranking. This synthetic test does not prove better operational results or better human understanding.