LLM-Assisted AHP for Explainable Cyber Range Evaluation
Cyber Ranges (CRs) have emerged as prominent platforms for cybersecurity training and education, especially for Critical Infrastructure (CI) sectors that face rising cyber threats. One way to address these threats is through hands-on exercises that bridge IT and OT domains to improve defensive readiness. However, consistently evaluating whether a CR platform is suitable and effective remains a challenge. This paper proposes an evaluation framework for CRs, emphasizing mission-critical settings by using a multi-criteria decision-making approach. We define a set of evaluation criteria that capture technical fidelity, training and assessment capabilities, scalability, usability, and other relevant factors. To weight and aggregate these criteria, we employ the Analytic Hierarchy Process (AHP), supported by a simulated panel of multidisciplinary experts implemented through a Large Language Model (LLM). This LLM-assisted expert reasoning enables consistent and reproducible pairwise comparisons across criteria without requiring direct expert convening. The framework’s output equals quantitative scores that facilitate objective comparison of CR platforms and highlight areas for improvement. Overall, this work lays the foundation for a standardized and explainable evaluation methodology to guide both providers and end-users of CRs.
Sat 18 AprDisplayed time zone: Brasilia, Distrito Federal, Brazil change
09:00 - 10:30 | |||
09:00 5mDay opening | Workshop Opening EnCyCriS Coralie Esnoul Institute For Energy Technology (IFE) | ||
09:05 15mFull-paper | Towards a Cognitive-Support Tool for Threat Hunters EnCyCriS Alessandra Maciel Paz Milani University of Victoria, Norman Anderson University of Victoria, Margaret-Anne Storey University of Victoria Pre-print | ||
09:20 15mFull-paper | Reflections and Factors in Applying Threat Modelling Tools for Cybersecurity Certification in Critical Infrastructure EnCyCriS Ahmed Amro Norwegian University of Science and Technology (NTNU), Vasileios Gkioulos NTNU, Claudia Lutze Hitachi Rail, Jean-Marie Lauranson Hitachi Rail, Maria I. Maslioukova Catalink, Pavlos Kosmides Catalink, Christina Michailidou Catalink, Pedro-Tito Macías-Roselló Schneider Electric, Evgeny Prokofyev Schneider Electric, Antoliano Davila Schneider Electric, Tanel Kerstna MindChip, Per Myrseth DNV, Meine Van Der Meulen DNV | ||
09:35 15mFull-paper | An Overview of Cyber Security Funding for Open Source Software EnCyCriS Jukka Ruohonen University of Southern Denmark, Gaurav Choudhary Choudhary Technical University of Denmark, Adam Alami University of Southern Denmark | ||
09:50 15mFull-paper | LLM-Assisted AHP for Explainable Cyber Range Evaluation EnCyCriS Vyron Kampourakis Norwegian University of Science and Technology NTNU, Georgios Kavallieratos Norwegian University of Science and Technology NTNU, Georgios Spathoulas Norwegian University of Science and Technology NTNU, Vasileios Gkioulos NTNU, Sokratis Katsikas Norwegian University of Science and Technology (NTNU) | ||
10:05 15mFull-paper | Behind the Quantum Curtain: A practical comparison between SVM and QSVM in OT Anomaly Detection EnCyCriS Alessio Di Santo Università degli Studi dell'Aquila, Nicola Camarda , Walter Tiberti Università degli Studi dell'Aquila, Dajana Cassioli Università degli Studi dell'Aquila | ||
10:20 10mOther | all together : picture EnCyCriS | ||