Automatic penetration testing method and device based on large model driving
The automated penetration testing method driven by a large language model solves the problems of traditional penetration testing being tedious, time-consuming and having a low degree of automation, realizes an efficient penetration testing process and improves work efficiency.
Patent Information
- Application Number
- CN202510810135.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-06-17
AI Technical Summary
Existing penetration testing methods rely on the experience of senior security experts, which makes them cumbersome, time-consuming, difficult to scale, and have a low degree of automation.
An automated penetration testing method driven by a large language model is adopted. The reconnaissance tool is called through the trained large language model to obtain target host information. The key information of vulnerability exploitation is obtained using penetration testing tools and vulnerability databases. The key information of target vulnerability exploitation is filtered out based on environmental information to generate a penetration testing report.
It improves the efficiency of penetration testing and can complete the same task in a shorter time, greatly improving work efficiency and reducing dependence on manual labor.
Smart Images

Figure CN120602171A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to an automated penetration testing method and device driven by a large model. Background Art
[0002] As cyberattack techniques become increasingly diverse and complex, the security risks faced by the Internet and computer systems are gradually increasing. To cope with the increasingly severe security situation, penetration testing has become a key defensive measure.
[0003] Penetration testing methods in related technologies usually rely on the experience of senior security experts, which makes penetration testing cumbersome, time-consuming and extremely dependent on manual labor. Summary of the Invention
[0004] Based on this, it is necessary to provide an automated penetration testing method and device based on large model drive that can improve the efficiency of penetration testing in response to the above technical problems.
[0005] In a first aspect, the present application provides an automated penetration testing method based on a large model drive, the method comprising:
[0006] Based on the received penetration test instruction for the target host, a preset reconnaissance tool is called through the trained large language model to obtain environmental information of the target host; wherein the environmental information includes at least a plurality of service information of the target host, each of the service information is used to represent a service of the target host;
[0007] Obtaining, based on a preset penetration testing tool and the large language model, vulnerabilities of multiple services in the target host and key information on exploitation of each of the vulnerabilities;
[0008] Filtering target vulnerability exploitation key information of each vulnerability from each vulnerability exploitation key information according to the environmental information;
[0009] Perform a penetration test on the target host based on the environmental information and each target vulnerability exploitation key information, and generate a penetration test report.
[0010] In one embodiment, the acquiring of the target host's environment information by calling a preset reconnaissance tool through a trained large language model includes:
[0011] Sending an information collection prompt to the large language model to instruct the large language model to call a preset investigation tool according to a preset role-playing mode and collect port investigation commands and service collection commands from a preset hybrid database;
[0012] Acquire at least one open port number of the target host according to the port detection command;
[0013] A plurality of service information of the target host is obtained according to each of the open port numbers and the service collection command.
[0014] In one embodiment, obtaining vulnerabilities of multiple services in the target host and key information on exploitation of each vulnerability based on a preset penetration testing tool and the large language model includes:
[0015] Determining at least one vulnerability of each of the services from a preset vulnerability database according to a preset penetration testing tool;
[0016] Sending a vulnerability exploitation collection prompt to the large language model to instruct the large language model to use the penetration testing tool to obtain vulnerability exploitation information of each vulnerability from a preset hybrid database; wherein the vulnerability exploitation information includes at least a vulnerability exploitation script and at least one vulnerability exploitation document;
[0017] Sending vulnerability exploitation screening prompt words to the large language model to instruct the large language model to screen out key exploitation information from each vulnerability exploitation document according to a key information extraction rule in the vulnerability exploitation screening prompt words;
[0018] Generate vulnerability exploitation key information according to each vulnerability exploitation script and the corresponding key exploitation information.
[0019] In one embodiment, after determining at least one vulnerability of each of the services from a preset vulnerability database, the method further includes:
[0020] Obtaining the vulnerability type of each vulnerability;
[0021] A potential attack surface of each of the services is generated according to the vulnerability type of each vulnerability; wherein each of the services includes at least one potential attack surface, each of the potential attack surfaces includes at least one vulnerability, and the vulnerabilities in the same potential attack surface have the same vulnerability type.
[0022] In one embodiment, the environmental information further includes system information of the target host, the service information includes at least service identification information of the service; the target vulnerability exploitation key information includes first vulnerability exploitation key information; wherein the first vulnerability exploitation key information of each vulnerability is determined from the vulnerability exploitation key information corresponding to the vulnerability;
[0023] The step of filtering out target vulnerability exploitation key information of each vulnerability from each vulnerability exploitation key information according to the environmental information includes:
[0024] Constructing a judgment instruction for each vulnerability according to the system information, the service name and version number of each service, and the vulnerability type of each vulnerability;
[0025] The judgment instruction is sent to the large language model, so that the large language model filters out the first vulnerability exploitation key information of each vulnerability from the vulnerability exploitation key information corresponding to each vulnerability according to the judgment instruction.
[0026] In one embodiment, the target vulnerability exploitation key information further includes second vulnerability exploitation key information; wherein the second vulnerability exploitation key information of each vulnerability is determined from the vulnerability exploitation key information corresponding to other vulnerabilities in the potential attack surface corresponding to the vulnerability; after filtering out the first vulnerability exploitation key information of each vulnerability, the method further includes:
[0027] determining a first vulnerability and a second vulnerability from a plurality of vulnerabilities based on the potential attack surface;
[0028] The first vulnerability exploitation key information of the second vulnerability is determined as the second vulnerability exploitation key information of the first vulnerability; wherein the first vulnerability and the second vulnerability correspond to the same potential attack surface.
[0029] In one embodiment, performing a penetration test on the target host based on the environmental information and each target vulnerability exploitation key information and generating a penetration test report includes:
[0030] Performing a penetration test on the target host according to the vulnerability of the target host based on the environmental information and the key information of each target vulnerability exploitation, and obtaining an initial test result of each vulnerability;
[0031] In the event that the initial test result for a vulnerability fails, the large language model is trained to collect and analyze error information based on a self-reflection mechanism, so that the large language model performs error analysis and strategy adjustment on the target vulnerability exploitation key information corresponding to the initial test result, and uses the adjusted target vulnerability exploitation key information to perform penetration testing again on the vulnerability for which the initial test result fails, until a preset termination condition is met, and the test result of the last penetration test is used as the penetration test result for the target vulnerability exploitation key information corresponding to the initial test result; wherein the preset termination condition includes a test result being successful, or the number of tests reaching a preset test threshold;
[0032] In the case where the initial test result for a vulnerability is successful, using the initial test result as a penetration test result of the target vulnerability corresponding to the initial test result using key information;
[0033] A penetration test report is generated based on the environmental information, the vulnerabilities, the penetration test results of the target vulnerabilities using key information, and the number of tests of the target vulnerabilities using key information.
[0034] In a second aspect, the present application provides an automated penetration testing device driven by a large model, the device comprising:
[0035] A first execution module is configured to, based on a received penetration test instruction for a target host, invoke a preset reconnaissance tool through a trained large language model to obtain environmental information of the target host; wherein the environmental information includes at least a plurality of service information of the target host, each of the service information representing a service on the target host;
[0036] A second execution module is configured to obtain vulnerabilities of multiple services in the target host and key information on exploitation of each of the vulnerabilities based on a preset penetration testing tool and the large language model;
[0037] A third execution module is configured to filter out target vulnerability exploitation key information of each vulnerability from each vulnerability exploitation key information according to the environmental information;
[0038] The fourth execution module is used to perform a penetration test on the target host according to the environmental information and the key information of each target vulnerability exploitation, and generate a penetration test report.
[0039] In a third aspect, the present application provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method described in any one of the above embodiments when executing the computer program.
[0040] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the method described in any one of the above embodiments when the computer program is executed by a processor.
[0041] The above-mentioned large model-driven automated penetration testing method, device, computer equipment and computer-readable storage medium, when receiving a penetration testing instruction for the target host, the present application first obtains the environmental information of the target host through the trained large language model, the environmental information includes at least multiple service information of the target host, each service information is used to represent a service in the target host, and then, for each service in the target host, the vulnerability of each service and the key information of the vulnerability exploitation of each vulnerability can be obtained by using the pre-established vulnerability database and the large language model. Then, according to the environmental information, the target vulnerability exploitation key information that can actually be used to perform penetration testing on each vulnerability can be further screened from the key information of each vulnerability exploitation. Finally, the target vulnerability exploitation key information that has been screened can be combined with the environmental information of the target host to perform penetration testing on the target host and generate a penetration testing report. The penetration testing method of the present application can send corresponding instructions to the large language model according to the steps of the entire penetration testing process to instruct the large language model to gradually give the information required in the penetration test, and finally complete the penetration test. Compared with traditional manual penetration testing, the present application can complete the same task in a shorter time, greatly improving work efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.
[0043] Figure 1 1 is a flow chart of an automated penetration testing method driven by a large model in one embodiment;
[0044] Figure 2 Schematic diagram of the process of step S101 in one embodiment;
[0045] Figure 3 Schematic diagram of the process of step S102 in one embodiment;
[0046] Figure 4 1 is a flow chart of an automated penetration testing method driven by a large model in another embodiment;
[0047] Figure 5 Schematic diagram of the process of step S103 in one embodiment;
[0048] Figure 6 Schematic diagram of a flow chart of an automated penetration testing method driven by a large model in yet another embodiment;
[0049] Figure 7 A schematic diagram of the structure of an attack tree model in one embodiment;
[0050] Figure 8 Schematic diagram of the process of step S104 in one embodiment;
[0051] Figure 9 A flowchart of a workflow of an automated penetration testing system in one embodiment;
[0052] Figure 10 is a workflow diagram of a reconnaissance module in one embodiment;
[0053] Figure 11 A flowchart of a search module in one embodiment;
[0054] Figure 12 A flowchart of an execution module in one embodiment;
[0055] Figure 13 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0056] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0057] As described in the background technology section, as cyberattack techniques become increasingly diverse and complex, the security risks facing the Internet and computer systems are gradually increasing. To address the increasingly severe security situation, penetration testing has become a key defensive measure. Specifically, penetration testing conducts security assessments by simulating attackers' attacks on networks, systems, and web applications. Currently, this technology is widely used by enterprises and security teams to detect and identify system vulnerabilities, and its effectiveness has been proven in practice. However, traditional penetration testing methods rely on the experience of senior security experts and even require the cooperation of security teams. At the same time, as the scale of computer system software continues to expand, penetration testing has exposed problems such as complex processes and high costs, which have limited the large-scale development and application of penetration testing. Although some automated penetration testing tools are currently available, these tools focus more on local processes in the penetration testing process and lack awareness of the specific vulnerability environment and the contextual association within the penetration testing process, resulting in a low overall level of automation in penetration testing.
[0058] In recent years, large language models have demonstrated strong application potential in code analysis, text understanding and generation, and intelligent question-answering. However, general large language models suffer from insufficient penetration testing knowledge and low automation. Therefore, this invention integrates large language models and corresponding derivative technologies to propose an automated penetration testing system. This automated penetration testing system can be connected to the large language model via an API (Application Programming Interface), enabling the large language model to abstract penetration testing knowledge into an attack tree model. This system automatically utilizes various penetration testing tools and conducts multi-stage collaborative operations to achieve complete, full-process penetration testing tasks, further expanding the knowledge and capabilities of large language models in penetration testing, and focusing on addressing the problems of traditional penetration testing, which is tedious, time-consuming, extremely manual, and difficult to scale and automate.
[0059] In an exemplary embodiment, see Figure 1 This application proposes an automated penetration testing method based on large model driving, and takes the application of this method to the above-mentioned automated penetration testing system as an example for explanation. The automated penetration testing method based on large model driving of this application includes steps S101 to S104.
[0060] S101: Based on the received penetration test instruction for the target host, a preset reconnaissance tool is called through a trained large language model to obtain environmental information of the target host; wherein the environmental information includes at least multiple service information of the target host, and each service information is used to represent a service in the target host.
[0061] In this embodiment, the automated penetration testing system proposed in this application includes a reconnaissance module, a search module, a planning module, an execution module and a report generation module.
[0062] The automated penetration testing system comes pre-loaded with various reconnaissance tools and penetration testing tools. When a user needs to conduct a penetration test on a target host, they can input penetration testing instructions for the target host into the reconnaissance module. The penetration testing instructions include the target host's IP address. After receiving the target host's IP address, the reconnaissance module first calls the large language model, allowing the large language model to directly call the reconnaissance tool and obtain various instructions for collecting the target host's environmental information from the hybrid database configured in the large language model. By pre-downloading the reconnaissance tool, the large language model can avoid downloading the reconnaissance tool from the Internet, which would reduce the efficiency of the penetration test. The hybrid database can include various open source databases that can be queried and used on the Internet. The reconnaissance module then interacts with the target host based on the instructions provided by the large language model to obtain information such as open port numbers and corresponding services, and integrates them into the target host's environmental information. The reconnaissance module also stores this environmental information in a preset environmental database. In subsequent operations, the large language model can retrieve the target host's environmental information from the environmental database at any time, addressing the short-term memory and context loss issues unique to large language models.
[0063] Among them, the large language model used in this application not only processes a hybrid database with the large language model's own configuration, but is also configured with a RAG (Retrieval Augmented Generation) framework, a specialized penetration testing knowledge base, and COT (Chain of Thought). Through COT technology, the large language model can decompose complex tasks into several subtasks to build an effective reconnaissance workflow. By carrying the RAG framework, the large language model can first retrieve various task-related information from the penetration testing knowledge base, and integrate the retrieved information into the instructions of the automated penetration testing system to the large language model, thereby reducing the illusion of the large language model and obtaining more accurate answers.
[0064] S102: According to the preset penetration testing tool and large language model, the vulnerabilities of multiple services in the target host and the key information of vulnerability exploitation of each vulnerability are obtained.
[0065] A vulnerability is a weakness or flaw in a system, its susceptibility to specific threats or dangerous events, or the potential for an attack to occur. Vulnerabilities can arise from design flaws or coding errors in application software or operating systems, or from design flaws or logical inconsistencies in business interactions. These flaws, errors, or inconsistencies can be exploited intentionally or unintentionally, adversely impacting an organization's assets or operations. These flaws, errors, or inconsistencies can lead to information systems being attacked or controlled, important information being stolen, user data being tampered with, or the system being used as a springboard for intrusion into other host systems.
[0066] In this application, a penetration testing tool is used for each service in the target host through the search module to obtain all the vulnerabilities of the service. Furthermore, the search module first calls the large language model, and the large language model calls the penetration testing tool to retrieve comprehensive vulnerability exploitation information of each vulnerability. Then, the vulnerability exploitation screening instruction is input into the large language model, instructing the large model to simplify the comprehensive vulnerability exploitation information based on the carried RAG framework to obtain the key vulnerability exploitation information of each vulnerability.
[0067] S103: Filtering target vulnerability exploitation key information of each vulnerability from each vulnerability exploitation key information according to the environmental information.
[0068] After obtaining the key information of vulnerability exploitation of each vulnerability, the planning module will input the service information of each service in the target host and the key information of vulnerability exploitation of each vulnerability into the large language model, and instruct the large language model to identify the vulnerability exploitation path that can be actually exploited in the current situation based on RAG enhanced retrieval information, that is, to filter out the target vulnerability exploitation key information of each vulnerability.
[0069] S104: Perform a penetration test on the target host based on the environment information and key information of each target vulnerability exploitation, and generate a penetration test report.
[0070] After determining the key information of each target vulnerability exploitation, the execution module will automatically execute the vulnerability exploitation on the target host according to the environmental information and the key information of the target vulnerability exploitation, and finally generate the vulnerability exploitation result.
[0071] Finally, after completing the general process of penetration testing, the report generation module organizes the IP address of the target host, service list, vulnerability list, and records of failures and successes during the iteration of the execution module to generate a penetration test report.
[0072] The above-mentioned automated penetration testing method driven by a large model, when receiving a penetration testing instruction for the target host, the present application first obtains the environmental information of the target host through the trained large language model, the environmental information includes at least multiple service information of the target host, each service information is used to represent a service in the target host, and then, for each service in the target host, the vulnerability of each service and the key information of the vulnerability exploitation of each vulnerability can be obtained by using the pre-established vulnerability database and the large language model. Then, according to the environmental information, the target vulnerability exploitation key information that can actually be used to perform penetration testing on each vulnerability can be further screened out from the key information of each vulnerability exploitation. Finally, the target host can be penetrated and a penetration test report can be generated based on the filtered target vulnerability exploitation key information and the environmental information of the target host. The penetration testing method of the present application can send corresponding instructions to the large language model in accordance with the process of the entire penetration test, so as to instruct the large language model to gradually give the information required in the penetration test, and finally complete the penetration test. Compared with traditional manual penetration testing, the present application can complete the same task in a shorter time, greatly improving work efficiency.
[0073] In an exemplary embodiment, see Figure 2 , step S101, calls the preset reconnaissance tool through the trained large language model to obtain the environmental information of the target host, including steps S201 to S203.
[0074] S201: Sending an information collection prompt to the large language model to instruct the large language model to call a preset investigation tool according to a preset role-playing mode, and collect port investigation commands and service collection commands from a preset hybrid database.
[0075] In one example, the template of the information collection prompt words sent by the detection module to the large language model may be as shown in Table 1 below:
[0076] Table 1 Design template for information collection prompts in the investigation module
[0077]
[0078] Reconnaissance tools may include Nmap. Based on information collection prompts, the large language model can act as a penetration test assistant, effectively circumventing the security policies enforced by the large language model. The reconnaissance module of this application uses appropriately designed prompts to enable the large language model to act as a "penetration test assistant," automatically analyzing targets using reconnaissance tools such as Nmap and outputting executable port reconnaissance commands and service collection commands.
[0079] S202: Obtain at least one open port number of the target host according to the port detection command.
[0080] In the application, in order to reduce the illusion of the large language model, this application also uses COT technology, that is, after obtaining the port detection command and service collection command, the detection module instructs the large language model to use the port detection command based on the information collection prompt word, such as the Namp tool to retrieve the open ports of the target host and obtain all the open port numbers of the target host.
[0081] S203: Acquire multiple service information of the target host according to each open port number and the service collection command.
[0082] Furthermore, based on COT technology, after obtaining all the open port numbers of the target host, the large language model will use the service collection command to scan each open port of the target host in turn, and the services of the target host under each open port. Finally, the large language model will organize the obtained open port numbers and services, obtain the environmental information of the target host, and output it in the specified format.
[0083] In an exemplary embodiment, see Figure 3 , step S102, according to the preset penetration testing tool and the large language model, obtain the vulnerabilities of multiple services in the target host and the key information of vulnerability exploitation of each vulnerability, including steps S301 to S304.
[0084] S301: Determine at least one vulnerability of each service from a preset vulnerability database according to a preset penetration testing tool.
[0085] In one example, the penetration testing tool may be a CVEMAP tool. For each service, the search module calls the CVEMAP tool, obtains vulnerabilities in the service from a vulnerability database configured by the CVEMAP tool, and forms a vulnerability list for the service.
[0086] S302: Sending vulnerability exploitation collection prompt words to the large language model to instruct the large language model to use a penetration testing tool to obtain vulnerability exploitation information of each vulnerability from a preset hybrid database; wherein the vulnerability exploitation information at least includes a vulnerability exploitation script and at least one vulnerability exploitation document.
[0087] Next, the search module will send vulnerability exploitation collection prompts to the large language model, instructing the large language model to use penetration testing tools to collect all vulnerability exploitation information related to each vulnerability from the hybrid database, including various vulnerability exploitation scripts related to the vulnerability, various documents that explain the vulnerability exploitation scripts, and other data.
[0088] S303: Send the vulnerability exploitation screening prompt word to the large language model to instruct the large language model to screen out key exploitation information from each vulnerability exploitation document according to the key information extraction rule in the vulnerability exploitation screening prompt word.
[0089] Next, the search module can send vulnerability exploitation screening prompts to the large language model. The vulnerability exploitation screening prompts include key information extraction rules. The key information extraction rules are used to instruct the large language model to eliminate redundant information from the comprehensive vulnerability exploitation information, leaving only the vulnerability exploitation script, the necessary information that can be used to assist the large language model in understanding the vulnerability exploitation script, and the service version number applicable to the vulnerability exploitation script, etc., that is, key exploitation information.
[0090] S304: Generate vulnerability exploitation key information according to each vulnerability exploitation script and the corresponding key exploitation information.
[0091] Finally, the large language model will organize and filter the vulnerability exploitation scripts and the key exploitation information corresponding to each vulnerability exploitation script, generate vulnerability exploitation key information, and store it in the preset attack knowledge base in the specified format.
[0092] In an exemplary embodiment, see Figure 4 After determining at least one vulnerability of each service from a preset vulnerability database in S301, the method further includes steps S401 and S402.
[0093] S401: Obtain the vulnerability type of each vulnerability.
[0094] Application vulnerabilities come in many different types. Common examples include those caused by coding issues, configuration errors, and environmental issues. Specifically, coding vulnerabilities can be further categorized into SQL injection, cross-site scripting, cross-site request forgery, and buffer overflow vulnerabilities. Environmental vulnerabilities can be further categorized into information leakage and fault injection. SQL injection vulnerabilities allow attackers to insert malicious SQL queries into input fields, allowing them to perform unauthorized database operations. Cross-site scripting vulnerabilities allow attackers to inject malicious scripts into web pages to steal user information or tamper with web page content. Cross-site request forgery vulnerabilities allow attackers to trick users into performing unauthorized operations without their knowledge. Buffer overflow vulnerabilities occur when data overflows into other memory areas due to incorrect memory boundary management. Information leakage vulnerabilities involve the disclosure of sensitive information due to configuration errors or log output. Fault injection vulnerabilities trigger system failures by altering the operating environment (such as temperature or voltage).
[0095] S402: Generate a potential attack surface for each service based on the vulnerability type of each vulnerability; wherein each service includes at least one potential attack surface, each potential attack surface includes at least one vulnerability, and the vulnerabilities in the same potential attack surface have the same vulnerability type.
[0096] For all the vulnerabilities contained in each service, the search module can organize the vulnerabilities of the same type together to form the potential attack surface of the service.
[0097] In an exemplary embodiment, the environment information further includes system information of the target host, the service information includes at least service identification information of the service; and the target vulnerability exploitation key information includes first vulnerability exploitation key information.
[0098] See also Figure 5 , step S103, filtering out target vulnerability exploitation key information of each vulnerability from each vulnerability exploitation key information according to the environmental information, including step S501 and step S502.
[0099] S501: Constructing judgment instructions for each vulnerability based on system information, service names and version numbers of each service, and vulnerability types of each vulnerability.
[0100] In this embodiment, the planning module constructs a judgment instruction based on the system information of the target host, the service identification information (service name, version number, etc.) corresponding to each vulnerability, and the vulnerability type.
[0101] S502: Sending a judgment instruction to the large language model, so that the large language model filters out the first vulnerability exploitation key information of each vulnerability from the vulnerability exploitation key information corresponding to each vulnerability according to the judgment instruction.
[0102] Afterwards, the planning module sends the judgment instructions and the key information of each vulnerability exploitation as context to the large language model. For each vulnerability, the large language model can identify the first key information of the vulnerability exploitation in the current target host environment from the corresponding key information of each vulnerability exploitation.
[0103] In an exemplary embodiment, the target vulnerability exploitation key information further includes second vulnerability exploitation key information; wherein the second vulnerability exploitation key information of each vulnerability is determined from the vulnerability exploitation key information corresponding to other vulnerabilities in the potential attack surface corresponding to the vulnerability. Figure 6 After filtering out the first vulnerability exploitation key information of each vulnerability, the method further includes step S601 and step S602.
[0104] S601: Determine a first vulnerability and a second vulnerability from multiple vulnerabilities based on a potential attack surface.
[0105] In the application, in order to conduct a comprehensive penetration test on each vulnerability in the target host, for each vulnerability, this application will not only filter out the first vulnerability exploitation key information from the vulnerability exploitation key information corresponding to the vulnerability, and use the first vulnerability exploitation key information to test the vulnerability, but also use the first vulnerability exploitation key information corresponding to other vulnerabilities belonging to the same potential attack surface as the vulnerability as the second vulnerability exploitation key information of the vulnerability, and use the second vulnerability exploitation key information to test the vulnerability.
[0106] S602: Determine the first vulnerability exploitation key information of the second vulnerability as the second vulnerability exploitation key information of the first vulnerability; wherein the first vulnerability and the second vulnerability correspond to the same potential attack surface.
[0107] For example, the target host includes service 1, service 1 has potential attack surface 1, potential attack surface 1 includes vulnerability 1 and vulnerability 2. After processing by the search module, it is determined that vulnerability 1 has vulnerability exploitation key information 1 and vulnerability exploitation key information 2, and vulnerability 2 has vulnerability exploitation key information 3 and vulnerability exploitation key information 4.
[0108] Vulnerability exploitation key information 1 includes vulnerability exploitation script 1 and key exploitation information 1 corresponding to vulnerability exploitation script 1, vulnerability exploitation key information 2 includes vulnerability exploitation script 2 and key exploitation information 2 corresponding to vulnerability exploitation script 2, vulnerability exploitation key information 3 includes vulnerability exploitation script 3 and key exploitation information 3 corresponding to the corresponding key exploitation information, and vulnerability exploitation key information 4 includes vulnerability exploitation script 4 and key exploitation information 4 corresponding to the corresponding key exploitation information.
[0109] In this example, the operating system of the target host is Windows system, the version number of service 1 is 4.1.1, key exploitation information 1 indicates that vulnerability exploitation script 1 is suitable for penetration testing vulnerability 1 of service 1 with version number 4.1.3 installed on Windows system, key exploitation information 2 indicates that vulnerability exploitation script 2 is suitable for penetration testing vulnerability 1 of service 1 with version number 4.1.1 installed on Windows system, key exploitation information 3 indicates that vulnerability exploitation script 3 is suitable for penetration testing vulnerability 2 of service 1 with version number 4.1.1 installed on Windows system, and key exploitation information 4 indicates that vulnerability exploitation script 4 is suitable for penetration testing vulnerability 2 of service 1 with version number 4.1.1 installed on Linux system. Therefore, the large model can determine that vulnerability exploitation key information 2 is the first vulnerability exploitation key information of vulnerability 1, and vulnerability exploitation key information 3 is the first vulnerability exploitation key information of vulnerability 2. At the same time, since vulnerability 1 and vulnerability 2 belong to the same potential attack surface, for vulnerability 1, vulnerability 1 is the first vulnerability and vulnerability 2 is the second vulnerability. For vulnerability 1, vulnerability 2 is the first vulnerability and vulnerability 1 is the second vulnerability. Therefore, the execution module can determine that vulnerability exploitation key information 3 is the second vulnerability exploitation key information of vulnerability 1, and determine that vulnerability exploitation key information 2 is the second vulnerability exploitation key information of vulnerability 2.
[0110] In one example, the execution module can also generate Figure 7 The attack tree model shown in the figure represents the association between the target host, each service of the target host, the potential attack surface of each service, the vulnerabilities included in each potential attack surface, and the vulnerability exploitation scripts in the key information of the first vulnerability exploitation of each vulnerability. In this example, the target host has services 1 and 2, service 1 has potential supply surface 1 and potential supply surface 2, service 2 has potential supply surface 3 and potential supply surface 4, potential supply surface 1 includes vulnerability 1, vulnerability 2, and vulnerability 3, potential supply surface 2 includes vulnerability 4 and vulnerability 5, potential supply surface 3 includes vulnerability 6, potential supply surface 4 includes vulnerability 7, the vulnerability exploitation scripts executable on the target host for vulnerability 1 include script 1 and script 2, the vulnerability exploitation scripts executable on the target host for vulnerability 2 include script 3 and script 4, the vulnerability exploitation scripts executable on the target host for vulnerability 3 include script 5, ... By generating an attack tree model, it can be used as an attack plan for the execution module. When performing a penetration test on the target host, the execution module can send the attack tree model, execution phase prompt words, key information on each target vulnerability exploitation, and the requirements for the successful execution of each vulnerability exploitation script determined in the preparation phase to the large language model, which helps the large language model further understand the penetration test process of the target host.
[0111] In an exemplary embodiment, see Figure 8, step S104, performing a penetration test on the target host according to the environmental information and key information of each target vulnerability exploitation, and generating a penetration test report, including steps S801 to S804.
[0112] S801: Based on the environment information and key information of each target vulnerability, a penetration test is performed on the target host according to the vulnerability of the target host, and an initial test result of each vulnerability is obtained.
[0113] In this embodiment, the execution module can instruct the large language model to perform a penetration test on the target host according to the vulnerability of the target host based on the environment information and key information of each target vulnerability. The specific execution process can be divided into two stages.
[0114] First is the preparation stage, in which the execution module inputs the preparation stage prompt words, environmental information, and key information of each target vulnerability exploitation into the large language model, so that the large language model analyzes the key information of the target vulnerability exploitation to determine the requirements for the successful execution of the penetration test, such as the parameters required for each vulnerability exploitation script, and then queries the necessary information from the environmental information, such as the IP address of the target host, the open port number, etc. In order to effectively find the information required for penetration testing of the vulnerability, the present invention adopts COT technology to guide the execution. The large language model first identifies all parameters in the vulnerability exploitation script, and then determines the information required for each parameter. During the analysis process, the execution module retrieves relevant information from the target vulnerability exploitation key information through RAG to generate a context for analysis by the large language model, and the large language model outputs the required information in a structured JSON format. In an example, the template of the preparation stage prompt words sent by the execution module to the large language model can be shown in Table 2 below:
[0115] Table 2. Prompt word design template for the preparation phase of the execution module
[0116]
[0117] S802: When the initial test result of a vulnerability is a failure, the large language model is trained to collect and analyze error information based on a self-reflection mechanism, so that the large language model performs error analysis and instruction adjustment on the target vulnerability exploitation key information corresponding to the initial test result, and uses the adjusted target vulnerability exploitation key information to perform penetration testing again on the vulnerability whose initial test result failed until the preset end condition is met, and the test result of the last penetration test is used as the penetration test result of the target vulnerability exploitation key information corresponding to the initial test result; wherein the preset end condition includes that the test result is successful, or the number of tests reaches a preset test threshold.
[0118] After obtaining a response containing the requested information, the execution module enters the execution phase. In the execution phase, the execution module inputs the execution phase prompt words, key information of each target vulnerability exploitation, and the requirements for the successful execution of each vulnerability exploitation script determined in the preparation phase to the large language model. In addition, the execution module can also input the established attack tree model to the large language model. The large language model uses the attack tree model obtained by RAG analysis to obtain the overall process of penetration test execution, decompose the execution plan, and generate a step-by-step execution guide. If an error is encountered during the execution of the vulnerability exploitation, the present invention uses self-reflection technology to enable the large language model to perform appropriate error handling. The large language model will analyze and adjust the use strategy of the vulnerability attack script based on the vulnerability attack script and the error message, and record the error history for reference by the execution module after iteration to avoid repeated errors. This iterative process ensures the continuous improvement and optimization of the automatic penetration testing system of the present invention. In one example, the template of the execution phase prompt words sent by the execution module to the large language model can be shown in Table 3 below:
[0119] Table 3. Design template for prompt words in the execution phase of the execution module
[0120]
[0121] As described above, the present application adopts a self-reflection mechanism for the large language model. When the initial test result of a vulnerability is failure, the large language model will perform error analysis and strategy adjustment on the target vulnerability exploitation key information whose initial test result is failure based on the instructions of the self-reflection mechanism in the prompt word of the execution phase, and use the adjusted target vulnerability exploitation key information to perform penetration testing on the vulnerability again until the preset end condition is met, and use the test result of the last penetration test as the penetration test result of the target vulnerability exploitation key information corresponding to the initial test result; wherein, the preset end condition includes the test result being successful, or the number of tests reaching the preset test threshold.
[0122] S803: When the initial test result of the vulnerability is successful, the initial test result is used as a penetration test result of the target vulnerability corresponding to the initial test result using key information.
[0123] It can be understood that if the initial test result of the vulnerability is successful, the initial test result can be directly used as the penetration test result of the target vulnerability exploitation key information corresponding to the initial test result.
[0124] S804: Generate a penetration test report based on the environment information, each vulnerability, the penetration test results of each target vulnerability exploitation key information, and the number of tests of each target vulnerability exploitation key information.
[0125] Finally, after completing the general process of penetration testing, a penetration test report needs to be generated. The report generation module can systematically record and present all security vulnerabilities and risks discovered during the penetration test. Specifically, the report generation module will record the IP address of the target host, the service list, the potential attack surface list, the vulnerability list, and the records of failures and successes during the iteration of the execution module. These data provide detailed attack paths and technical details to evaluate the security and protection capabilities of the system. Through the penetration test report, security experts can clearly convey the security issues and severity of the system to management and technical teams, and put forward specific remediation suggestions and protection measures, thereby helping the organization to promptly fix vulnerabilities and improve the overall security protection level. In addition, the penetration test report can also serve as an important basis for compliance audits and security assessments to ensure that the system meets relevant security standards and regulatory requirements.
[0126] For a detailed example, see Figures 9 to 12 , Figure 9 This is a workflow diagram of an automated penetration testing system in an example. Figure 10 The following is a workflow diagram of the reconnaissance module in an example. Figure 11 The following is a workflow diagram of a search module in an example. Figure 12 A workflow diagram for executing modules in an example.
[0127] When the user sends the IP address of the target host to the reconnaissance module, the reconnaissance module can call the large language model, introduce external penetration testing tools through the large language model, and obtain reconnaissance commands such as port reconnaissance commands and service collection commands. The large language model first uses the port reconnaissance command to obtain all open port numbers of the target host, and then uses the service collection command to scan each open port of the target host in turn, and finally organizes the obtained open port numbers and services to obtain the environmental information of the target host, and outputs it in the specified format and in detail in the environmental information database.
[0128] Next, the search module calls the vulnerability library tool for each service, obtains the vulnerabilities in the service from the vulnerability database configured by the vulnerability library tool, and forms a vulnerability list for the service. Based on the type of each vulnerability, the potential attack surface of each service is formed. The search module then sends a vulnerability exploitation collection prompt to the large language model, instructing the large language model to collect all vulnerability exploitation information related to each vulnerability from the hybrid database, including various vulnerability exploitation scripts related to the vulnerability, as well as various documents and other data that explain the vulnerability exploitation scripts. Furthermore, the search module sends a vulnerability exploitation screening prompt including key information extraction rules to the large language model. The key information extraction rules are used to instruct the large language model to eliminate redundant information from the comprehensive vulnerability exploitation information, leaving only key exploitation information. Finally, the large language model will organize the vulnerability exploitation scripts left after screening and the key exploitation information corresponding to each vulnerability exploitation script, generate vulnerability exploitation key information, and store it in a preset attack knowledge base in a specified format.
[0129] Then, the planning module constructs a judgment instruction based on the system information of the target host, the service identification information corresponding to each vulnerability (service name, version number, etc.), and the vulnerability type, and sends the judgment instruction and the key information of each vulnerability exploitation as context to the large language model. For each vulnerability, the large language model can determine the target vulnerability exploitation key information of the vulnerability, and the execution module can also generate an attack tree model of the target host.
[0130] Next, the execution module inputs the preparation phase prompt words, environmental information, and key information about each target vulnerability exploit into the large language model, allowing the large language model to analyze the key information about the target vulnerability exploit to determine the requirements for the successful execution of the penetration test. Furthermore, the execution module inputs the attack tree model, the execution phase prompt words, key information about each target vulnerability exploit, and the requirements for the successful execution of each vulnerability exploit script determined in the preparation phase into the large language model. The large language model uses the attack tree model obtained by RAG analysis to obtain the overall process of penetration test execution, decompose the execution plan, and generate a step-by-step execution guide. If an error is encountered during the execution of the vulnerability exploit, the large language model will perform appropriate error handling. The large language model will analyze the error message based on the vulnerability exploit script and adjust the strategy for using the vulnerability exploit script. At the same time, the error history will be recorded for reference by the execution module after iteration to avoid repeated errors.
[0131] Finally, after completing the general penetration test process, the report generation module will generate a penetration test report. The penetration test report will record the IP address of the target host, a list of services, a list of potential attack surfaces, a list of vulnerabilities, and a record of failures and successes during the execution module iteration.
[0132] This application simplifies the penetration testing process through a structured and automated framework, improving efficiency and reducing the manual work required.
[0133] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0134] Based on the same inventive concept, the embodiments of the present application also provide a large-model-driven automated penetration testing device for implementing the large-model-driven automated penetration testing method involved above. The implementation solution provided by the device is similar to the implementation solution described in the above method. Therefore, the specific limitations of one or more embodiments of the large-model-driven automated penetration testing device provided below can be found in the above-mentioned limitations of the large-model-driven automated penetration testing method, and will not be repeated here.
[0135] In an exemplary embodiment, the present application further proposes an automated penetration testing device driven by a large model, the device comprising:
[0136] A first execution module is configured to, based on a received penetration test instruction for a target host, invoke a preset reconnaissance tool using a trained large language model to obtain environmental information of the target host; wherein the environmental information includes at least a plurality of service information of the target host, each service information representing a service on the target host;
[0137] The second execution module is used to obtain vulnerabilities of multiple services in the target host and key information on the exploitation of each vulnerability based on a preset penetration testing tool and a large language model;
[0138] The third execution module is used to filter out target vulnerability exploitation key information of each vulnerability from each vulnerability exploitation key information according to the environmental information;
[0139] The fourth execution module is used to perform a penetration test on the target host according to the environmental information and key information of each target vulnerability, and generate a penetration test report.
[0140] Each module in the aforementioned large-scale model-driven automated penetration testing device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in hardware form, or can be stored in a memory in the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0141] In an exemplary embodiment, the system includes a memory and a processor, wherein the memory stores a computer program, and is characterized in that when the processor executes the computer program, the steps of the method in any one of the above embodiments are implemented.
[0142] The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 13 As shown. The computer device includes a processor, memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals via wired or wireless means, and the wireless means can be implemented via Wi-Fi, a mobile cellular network, near-field communication (NFC), or other technologies. When executed by the processor, the computer program implements an automated penetration testing method driven by a large model. The display unit of the computer device is used to form a visually visible image, and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse.
[0143] Those skilled in the art will understand that Figure 13 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0144] In an exemplary embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method in any of the above embodiments are implemented.
[0145] In one embodiment, a computer program product is provided, comprising a computer program, which implements the steps of the method in any one of the above embodiments when executed by a processor.
[0146] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0147] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.
[0148] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0149] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. An automated penetration testing method based on large model drive, characterized in that: The method comprises: Based on the received penetration test instruction for the target host, a preset reconnaissance tool is called through the trained large language model to obtain environmental information of the target host; wherein the environmental information includes at least a plurality of service information of the target host, each of the service information is used to represent a service of the target host; Obtaining, based on a preset penetration testing tool and the large language model, vulnerabilities of multiple services in the target host and key information on exploitation of each of the vulnerabilities; Filtering target vulnerability exploitation key information of each vulnerability from each vulnerability exploitation key information according to the environmental information; Perform a penetration test on the target host based on the environmental information and each target vulnerability exploitation key information, and generate a penetration test report.
2. The method according to claim 1, characterized in that The step of acquiring the target host's environment information by calling a preset reconnaissance tool through the trained large language model includes: Sending an information collection prompt to the large language model to instruct the large language model to call a preset investigation tool according to a preset role-playing mode and collect port investigation commands and service collection commands from a preset hybrid database; Acquire at least one open port number of the target host according to the port detection command; A plurality of service information of the target host is obtained according to each of the open port numbers and the service collection command.
3. The method according to claim 1, characterized in that The method of obtaining vulnerabilities of multiple services in the target host and key information on exploitation of each vulnerability based on a preset penetration testing tool and the large language model includes: Determining at least one vulnerability of each of the services from a preset vulnerability database according to a preset penetration testing tool; Sending a vulnerability exploitation collection prompt to the large language model to instruct the large language model to use the penetration testing tool to obtain vulnerability exploitation information of each vulnerability from a preset hybrid database; wherein the vulnerability exploitation information includes at least a vulnerability exploitation script and at least one vulnerability exploitation document; Sending vulnerability exploitation screening prompt words to the large language model to instruct the large language model to screen out key exploitation information from each vulnerability exploitation document according to a key information extraction rule in the vulnerability exploitation screening prompt words; Generate vulnerability exploitation key information according to each vulnerability exploitation script and the corresponding key exploitation information.
4. The method according to claim 3, characterized in that After determining at least one vulnerability of each of the services from a preset vulnerability database, the method further includes: Obtaining the vulnerability type of each vulnerability; A potential attack surface of each of the services is generated according to the vulnerability type of each vulnerability; wherein each of the services includes at least one potential attack surface, each of the potential attack surfaces includes at least one vulnerability, and the vulnerabilities in the same potential attack surface have the same vulnerability type.
5. The method according to claim 4, characterized in that The environment information also includes system information of the target host, and the service information includes at least service identification information of the service; the target vulnerability exploitation key information includes first vulnerability exploitation key information; wherein the first vulnerability exploitation key information of each vulnerability is determined from the vulnerability exploitation key information corresponding to the vulnerability; The step of filtering out target vulnerability exploitation key information of each vulnerability from each vulnerability exploitation key information according to the environmental information includes: Constructing a judgment instruction for each vulnerability according to the system information, the service name and version number of each service, and the vulnerability type of each vulnerability; The judgment instruction is sent to the large language model, so that the large language model filters out the first vulnerability exploitation key information of each vulnerability from the vulnerability exploitation key information corresponding to each vulnerability according to the judgment instruction.
6. The method according to claim 5, characterized in that The target vulnerability exploitation key information further includes second vulnerability exploitation key information; wherein the second vulnerability exploitation key information of each vulnerability is determined from the vulnerability exploitation key information corresponding to other vulnerabilities in the potential attack surface corresponding to the vulnerability; after filtering out the first vulnerability exploitation key information of each vulnerability, the method further includes: determining a first vulnerability and a second vulnerability from a plurality of vulnerabilities based on the potential attack surface; The first vulnerability exploitation key information of the second vulnerability is determined as the second vulnerability exploitation key information of the first vulnerability; wherein the first vulnerability and the second vulnerability correspond to the same potential attack surface.
7. The method according to any one of claims 1 to 6, characterized in that The performing a penetration test on the target host according to the environmental information and each target vulnerability exploitation key information, and generating a penetration test report, includes: Performing a penetration test on the target host according to the vulnerability of the target host based on the environmental information and the key information of each target vulnerability exploitation, and obtaining an initial test result of each vulnerability; In the event that the initial test result for a vulnerability fails, the large language model is trained to collect and analyze error information based on a self-reflection mechanism, so that the large language model performs error analysis and strategy adjustment on the target vulnerability exploitation key information corresponding to the initial test result, and uses the adjusted target vulnerability exploitation key information to perform penetration testing again on the vulnerability for which the initial test result fails, until a preset termination condition is met, and the test result of the last penetration test is used as the penetration test result for the target vulnerability exploitation key information corresponding to the initial test result; wherein the preset termination condition includes a test result being successful, or the number of tests reaching a preset test threshold; In the case where the initial test result for a vulnerability is successful, using the initial test result as a penetration test result of the target vulnerability corresponding to the initial test result using key information; A penetration test report is generated based on the environmental information, the vulnerabilities, the penetration test results of the target vulnerabilities using key information, and the number of tests of the target vulnerabilities using key information.
8. An automated penetration testing device driven by a large model, characterized in that: The device comprises: A first execution module is configured to, based on a received penetration test instruction for a target host, invoke a preset reconnaissance tool through a trained large language model to obtain environmental information of the target host; wherein the environmental information includes at least a plurality of service information of the target host, each of the service information representing a service on the target host; A second execution module is configured to obtain vulnerabilities of multiple services in the target host and key information on exploitation of each of the vulnerabilities based on a preset penetration testing tool and the large language model; A third execution module is configured to filter out target vulnerability exploitation key information of each vulnerability from each vulnerability exploitation key information according to the environmental information; The fourth execution module is used to perform a penetration test on the target host according to the environmental information and the key information of each target vulnerability exploitation, and generate a penetration test report.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Automatic penetration testing method and system based on large language model driving
CN118779883A
Penetration test agent system driven by large language model and test method
CN119150912A
Automatic penetration testing method and system with large language model as kernel
CN119917403A
Penetration testing method and device, electronic equipment and storage medium
CN120017339A
Cited By
Automatic penetration testing system, method and device, intelligent agent and storage medium
CN120781367A
Automated penetration testing systems, methods, apparatuses, agents, and storage media
CN120781367B