Multi-Criteria Selection of Network Security Configuration Using NSGA-II
Abstract
1. Introduction
2. Literature Review
3. Research Objectives
4. Proposed Model and Method
4.1. Multi-Criteria Optimization Model
4.2. Applied Solution Method
4.3. Algorithmic Description of the Proposed Optimization Method
- Input:
- Population size (N)
- Maximum generations (G)
- Crossover probability (Pc)
- Mutation probability (Pm)
- Output:
- Pareto-optimal set of NSC
- 1: Initialize population P(0) with N random NSC
- 2: Evaluate objective functions for each individual in P(0)
- 3: Perform non-dominated sorting to determine Pareto ranks
- 4: Compute crowding distance for diversity preservation
- 5: Set generation counter g ← 0
- 6: while g < G do
- 7: Generate offspring population Q(g) using selection, crossover (Pc), and mutation (Pm)
- 8: Evaluate objective functions for each individual in Q(g)
- 9: Merge P(g) and Q(g) into R(g) ← P(g)∪ Q(g)
- 10: Perform non-dominated sorting on R(g)
- 11: Select the best N individuals to form the next generation P(g+1) using Pareto dominance and crowding distance
- 12: g ← g + 1
- 13: end while
- 14: Return the final non-dominated set as the Pareto-optimal configurations of NSTs
4.4. Limitations
5. Computational Experiments and Obtained Results
6. Discussion
7. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Tariq, M.I.; Ahmed, S.; Memon, N.A.; Tayyaba, S.; Ashraf, M.W.; Nazir, M.; Balas, M.M. Prioritization of information security controls through fuzzy AHP for cloud computing networks and wireless sensor networks. Sensors 2020, 20, 1310. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Obayiuwana, E.; Falowo, O.E. Network selection in heterogeneous wireless networks using multi-criteria decision-making algorithms: A review. Wirel. Netw. 2017, 23, 2617–2649. [Google Scholar] [CrossRef] [Scilit]
- Maček, D.; Magdalenić, I.; Ređep, N.B. A systematic literature review on the application of multicriteria decision making methods for information security risk assessment. Int. J. Saf. Secur. Eng. 2020, 10, 161–174. [Google Scholar] [CrossRef] [Scilit]
- Bouramdane, A.A. Cyberattacks in smart grids: Challenges and solving the multi-criteria decision-making for cybersecurity options, including ones that incorporate artificial intelligence, using an analytical hierarchy process. J. Cybersecur. Priv. 2023, 3, 662–705. [Google Scholar] [CrossRef] [Scilit]
- Llansó, T.; McNeil, M.; Noteboom, C. Multi-criteria selection of capability-based cybersecurity solutions. In Proceedings of the 2019 Conference: Hawaii International Conference on System Sciences, Maui, HI, USA, 8–11 January 2019; pp. 7322–7328. [Google Scholar] [CrossRef] [Scilit]
- Khoroshko, V.; Brailovskyi, M.; Kapustia, M. Multi-criteria assessment of the correctness of decision-making in information security tasks. Comput. Syst. Inf. Technol. 2023, 4, 81–86. [Google Scholar]
- ISO/IEC 27001:2022; Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements. International Organization for Standardization: Geneva, Switzerland, 2022.
- ISO/IEC 27002:2022; Information Security, Cybersecurity and Privacy Protection—Information Security Controls. International Organization for Standardization: Geneva, Switzerland, 2022.
- Garg, D.; Sidhu, J.; Rani, S. Improved TOPSIS: A multi-criteria decision making for research productivity in cloud security. Comput. Stand. Interfaces 2019, 65, 61–78. [Google Scholar] [CrossRef] [Scilit]
- Khouzani, M.H.R.; Malacaria, P.; Hankin, C.; Fielder, A.; Smeraldi, F. Efficient numerical frameworks for multi-objective cyber security planning. In Proceedings of the Conference: European Symposium on Research in Computer Security, Heraklion, Crete, Greece, 26–30 September 2016; Lecture Notes in Computer Science 9879; Springer: Berlin/Heidelberg, Germany, 2016; pp. 179–197. [Google Scholar] [CrossRef] [Scilit]
- Khouzani, M.H.R.; Liu, Z.; Malacaria, P. Scalable min-max multi-objective cyber-security optimisation over probabilistic attack graphs. Eur. J. Oper. Res. 2019, 278, 894–903. [Google Scholar] [CrossRef] [Scilit]
- Kumar, R.; Baz, A.; Alhakami, H.; Alhakami, W.; Agrawal, A.; Khan, R.A. A hybrid fuzzy rule-based multi-criteria framework for sustainable-security assessment of web application. Ain Shams Eng. J. 2021, 12, 2227–2240. [Google Scholar] [CrossRef] [Scilit]
- Lakhno, V.; Akhmetov, B.; Mohylnyi, H.; Blozva, A.; Chubaievskyi, V.; Kryvoruchko, O.; Desiatko, A. Multi-criterial optimization composition of cyber security circuits based on genetic algorithm. J. Theor. Appl. Inf. Technol. 2022, 100, 1996–2006. [Google Scholar]
- Torbacki, W. A hybrid MCDM model combining DANP and PROMETHEE II methods for the assessment of cybersecurity in industry 4.0. Sustainability 2021, 13, 8833. [Google Scholar] [CrossRef] [Scilit]
- Akhmetov, B.S.; Lakhno, V.; Akhmetov, B.B.; Zhilkishbayev, A.; Izbasova, N.; Kryvoruchko, O.; Desiatko, A. Application of a Genetic Algorithm for the Selection of the Optimal Composition of Protection Tools of the Information and Educational System of the University. Procedia Comput. Sci. 2022, 215, 598–607. [Google Scholar] [CrossRef] [Scilit]
- Suguna, N.; Thanushkodi, K. Genetic algorithm based feature ranking in multi-criteria optimization. IJCSNS Int. J. Comput. Sci. Netw. Secur. 2009, 9, 132–140. [Google Scholar]
- Ma, H.; Zhang, Y.; Sun, S.; Liu, T.; Shan, Y. A comprehensive survey on NSGA-II for multi-objective optimization and applications. Artif. Intell. Rev. 2023, 56, 15217–15270. [Google Scholar] [CrossRef] [Scilit]
- Kashyap, R.; Vidyarthi, D.P. Security driven scheduling model for computational grid using NSGA-II. J. Grid Comput. 2013, 11, 721–734. [Google Scholar] [CrossRef] [Scilit]
- Lakhan, A.; Mohammed, M.A.; Abdulkareem, K.H.; Deveci, M.; Marhoon, H.A.; Nedoma, J.; Martinek, R. A multi-objectives framework for secure blockchain in fog–cloud network of vehicle-to-infrastructure applications. Knowl. Based Syst. 2024, 290, 111576. [Google Scholar]
- Arisdakessian, S.; Wahab, O.A.; Mourad, A.; Otrok, H.; Kara, N. FoGMatch: An intelligent multi-criteria IoT-fog scheduling approach using game theory. IEEE/ACM Trans. Netw. 2020, 28, 1779–1789. [Google Scholar] [CrossRef] [Scilit]
- Makulov, K.; Chikrii, À.; Lakhno, V.; Yagaliyeva, B.; Malyukov, V.; Malyukova, I.; Lakhno, M. Cloud Platform Selection Model in the Framework of Differential Quality Game with Fuzzy Information. IEEE Access 2025, 13, 22578–22589. [Google Scholar] [CrossRef] [Scilit]
- Zegzhda, D.; Pavlenko, E.; Aleksandrova, E. Modelling artificial immunization processes to counter cyberthreats. Symmetry 2021, 13, 2453. [Google Scholar] [CrossRef] [Scilit]
- Kalinin, M.; Krundyshev, V.; Zegzhda, D. AI methods for neutralizing cyber threats at unmanned vehicular ecosystem of smart city. In The Economics of Digital Transformation: Approaching Non-Stable and Uncertain Digitalized Production Systems; Springer International Publishing: Cham, Switzerland, 2021; pp. 157–171. [Google Scholar]
- Zebouchi, A.; Aklouf, Y. pRTMNSGA-III: A novel multi-objective algorithm for QoS-aware multi-cloud IoT service selection. Ann. Telecommun. 2024, 80, 1–22. [Google Scholar] [CrossRef] [Scilit]
- Li, J.; Chen, M. Multiobjective topology optimization based on mapping matrix and NSGA-II for switched industrial Internet of Things. IEEE Internet Things J. 2016, 3, 1235–1245. [Google Scholar] [CrossRef] [Scilit]
- Chernyavskij, D.S. Zadacha mnogokriterialnogo vybora setevyh sredstv zashity informacii v sootvetstvii s politikami informacionnoj bezopasnosti. Bezop. Inf. Tehnol. 2015, 22, 112–118. [Google Scholar]





| Parameter | Notation | Value | Description |
|---|---|---|---|
| Population Size | 100 | The number of individuals in each population throughout all iterations of the evolutionary process. | |
| Number of Generations | 50 | The number of algorithm iterations after which the set of Pareto-optimal solutions is formed. | |
| Crossover Probability | 0.7 | The proportion of individuals undergoing recombination in each generation to maintain genetic diversity. | |
| Mutation Probability | 0.4 | The initial mutation probability, which adapts dynamically during the evolutionary process. | |
| Chromosome Length | 9 | The number of binary features defining the security system configuration in a single individual. | |
| Minimum Quality Threshold | 3 | The minimum sum of active components in the solution that ensures an acceptable level of protection. | |
| Security Assessment Variability | [0.9, 1.1] | The range of the random variation coefficient in the security rating. | |
| Throughput Assessment Variability | [1.2, 1.8] | The range of variation for the random fluctuation coefficient of throughput capacity. | |
| Certification Level Variability | [0.8, 1.2] | The range of random variation in the security system certification. |
| № | Security Tool (Example) | Type | , Gbit/s | |||
|---|---|---|---|---|---|---|
| 1 | Firewall Cisco ASA | Firewall (FW) | 8.5 | 10 | 150 | 1 |
| 2 | Palo Alto PA-3220 | FW | 9.0 | 12 | 180 | 1 |
| 3 | Fortinet FortiGate 100F | FW | 8.2 | 9 | 140 | 1 |
| 4 | Snort IDS/IPS | Intrusion Detection System (IDS) | 7.5 | 5 | 80 | 0 |
| Suricata IDS/IPS | IDS | 7.8 | 6 | 90 | 0 | |
| 6 | OpenVPN | Virtual Private Network (VPN) | 6.5 | 8 | 50 | 1 |
| 7 | WireGuard | VPN | 7.0 | 10 | 60 | 0 |
| 8 | Squid Proxy | Proxy server | 6.0 | 7 | 40 | 1 |
| 9 | Zscaler Cloud Proxy | Proxy server | 8.0 | 15 | 200 | 1 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Yagaliyeva, B.; Lakhno, V.; Lakhno, M.; Gusev, B.; Makulov, K.; Sundet, T. Multi-Criteria Selection of Network Security Configuration Using NSGA-II. Future Internet 2026, 18, 134. https://doi.org/10.3390/fi18030134
Yagaliyeva B, Lakhno V, Lakhno M, Gusev B, Makulov K, Sundet T. Multi-Criteria Selection of Network Security Configuration Using NSGA-II. Future Internet. 2026; 18(3):134. https://doi.org/10.3390/fi18030134
Chicago/Turabian StyleYagaliyeva, Bagdat, Valery Lakhno, Myroslav Lakhno, Boris Gusev, Kaiyrbek Makulov, and Tomiris Sundet. 2026. "Multi-Criteria Selection of Network Security Configuration Using NSGA-II" Future Internet 18, no. 3: 134. https://doi.org/10.3390/fi18030134
APA StyleYagaliyeva, B., Lakhno, V., Lakhno, M., Gusev, B., Makulov, K., & Sundet, T. (2026). Multi-Criteria Selection of Network Security Configuration Using NSGA-II. Future Internet, 18(3), 134. https://doi.org/10.3390/fi18030134

