AI DRIVEN MISSION AWARE VULNERABILITY PRIORITIZATION FOR CLOUD NATIVE CRITICAL INFRASTRUCTURE

Authors

October 1, 2026

Downloads

Objective: Cloud-native critical infrastructure concentrates operational responsibility in elastic, highly connected systems whose software composition and runtime topology change continuously. Organizations therefore face a prioritization problem rather than a vulnerability-discovery problem: thousands of known vulnerabilities may be present, yet only a subset is reachable, exploitable, attached to mission-essential assets, or capable of producing cascading service disruption. The Common Vulnerability Scoring System (CVSS) remains valuable for describing intrinsic technical severity, but a severity-first queue can misallocate scarce remediation capacity. Method: This article proposes the Mission-Aware Vulnerability Prioritization Framework (MAVPF), an explainable artificial-intelligence architecture that unifies six evidence domains: runtime exposure, exploitability, asset criticality, critical-service dependency, mission impact, and cascading operational impact. MAVPF represents cloud resources, identities, software components, and services as a time-aware dependency graph; fuses scanner, runtime, threat-intelligence, service-catalog, and resilience evidence; produces a constrained remediation ranking; and generates a traceable explanation and recommended action for every vulnerability. Its theoretical foundation integrates risk-based vulnerability management, attack-graph reasoning, socio-technical resilience, graph-based dependency analysis, and explainable AI. Results: A worked scenario shows why an exposed, currently exploitable CVSS 7.5 vulnerability supporting an essential service can rationally outrank an unexposed CVSS 9.8 vulnerability on a low-criticality service. The article does not report empirical performance; instead, it specifies falsifiable evaluation questions, baselines, metrics, and validation procedures for future testbed and field studies. Novelty: The contribution is a generalizable decision architecture that connects technical vulnerability evidence to mission consequences without replacing CVSS or concealing uncertainty.