Penetration test large model agent based on ATT and CK attack knowledge enhancement
Through penetration testing large-scale agents enhanced by ATT and CK attack knowledge, an attack tactical tree and transfer map are built to realize automated penetration testing, solving the problem of lack of flexibility and systematic integration of existing penetration testing tools and systems, reducing labor costs and improving success rate.
Patent Information
- Application Number
- CN202510466276.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-15
AI Technical Summary
Existing penetration testing tools and systems lack flexibility and systematic integration capabilities, making it difficult to dynamically adjust attack paths and tool combinations, resulting in low efficiency, high cost and low success rate.
The penetration test large-model agent based on ATT and CK attack knowledge enhancement is adopted to achieve automated penetration testing, dynamic planning and decision-making by building attack tactical trees and transfer maps, combining the large-model agent.
It greatly reduces the labor cost of penetration testing, improves work efficiency, effectively reduces the hallucination problem of large models for professional penetration testing, and improves the success rate of penetration testing.
Smart Images

Figure CN119996232A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to artificial intelligence and network security technology, and in particular to an automated penetration testing system. Background Art
[0002] Penetration testing is an important defense method in the field of network security. It simulates the attacker's perspective to identify and exploit security vulnerabilities in the system, thereby evaluating the system's defense capabilities. The purpose of penetration testing is not only to discover potential vulnerabilities, but also to verify whether the system's security configuration and reinforcement measures are effective. With the rapid development of network attack technology, traditional penetration testing has gradually become difficult to meet security needs in complex environments. In particular, in the face of increasingly complex target environments and attack technologies, the efficiency, cost and success rate of manual penetration testing are limited.
[0003] Although existing penetration testing tools and systems can provide a certain degree of automation support, they are mostly based on preset strategies and scripts and lack the ability to flexibly respond to different target environments. This limitation leads to several major problems: First, there is a lack of dynamic adjustment capabilities, and it is impossible to flexibly select attack paths based on real-time information. Second, the integration and coordination between tools is not systematic enough, making it difficult to select the best technology and tool combination, thereby reducing the success rate of penetration testing. Furthermore, existing automated penetration testing systems usually focus on the technical level and lack the ability to coordinate and plan multiple attack technologies from a tactical level, making penetration testing methods relatively limited and single.
[0004] In recent years, the rise of large language models has provided new possibilities for the intelligence of penetration testing. However, large models also face many challenges in penetration testing applications, such as: it is difficult to achieve systematic integration of knowledge bases and attack strategies, it is difficult to dynamically adjust attack paths in real time, and the controllability of calling tools and execution steps is insufficient. In addition, the existing large models lack specific attacks and fail to achieve dynamic generation and adjustment of tactical chains. Therefore, the systematic integration of automated intelligent agents with penetration testing tactical chains and the efficient combination of techniques and tactics based on knowledge bases have become core issues that need to be solved at this stage. Summary of the invention
[0005] In order to overcome the high labor cost in penetration testing and the illusion problem caused by large models on professional penetration testing, the invention proposes a penetration testing large model intelligent agent based on ATT and CK attack knowledge enhancement. The automation of penetration testing is realized based on the large model intelligent agent, which can greatly reduce the labor cost of penetration testing and improve the work efficiency of penetration testing. An attack tactical transfer diagram is constructed based on ATT and CK attack knowledge, and the planning and decision-making of the large model are controlled based on the tactical transfer diagram, which can effectively reduce the illusion problem of large models on professional penetration testing.
[0006] The technical solution adopted by the present invention to solve its technical problem is: A penetration test large model intelligent agent based on ATT and CK attack knowledge enhancement includes the following steps: Step 1: Construction of attack knowledge base: Combine ATT and CK attack knowledge, extract attack tactic sequences and attack cases from a large number of threat intelligence documents, and form an attack tactic tree; Step 2: Construction of attack tactic transfer graph: Analyze the transfer flow and control flow of attack tactics based on the attack tactic tree, and construct the attack tactic transfer graph; Step 3: Automatic penetration testing based on large model agents: Build supervisor agents and tactical agents, and complete automated penetration testing based on large models under the guidance of the attack tactical transfer diagram.
[0007] Furthermore, in step 1, the ATT and CK attack knowledge bases are constructed based on threat intelligence extraction, and the steps are as follows: Step 1-1: Extraction of attack technique and tactical sequences: Based on a large number of threat intelligence documents DS , given DS A threat intelligence document in D k ,according to D k Whether the ATT and CK attack techniques are clearly marked, and whether they are identified using regular expressions or attack technique and tactic recognition algorithms, and then organized into attack tactic sequences after deduplication; Step 1-2, Case description generation: Given DS A threat intelligence document in D k ,reserve D k The title of the D k The rest of the text generates an abstract that does not exceed the specified threshold, and finally concatenates the title and abstract to form D k The case description is denoted as About k ; Step 1-3, Construction of attack tool knowledge base: Establish an attack tool list based on penetration testing requirements. The attack tool list is metasploit or nmap, recorded as TList , where penetration testing requirements can come from the experience of domain experts or knowledge of threat intelligence, and the list of attack tools TList Dynamically scalable; Step 1-4, attack tactic tree construction: given a set of attack tactic sequences extracted from all threat intelligence TASS = { TAS 1, TAS2, …, TAS 5}, and gradually construct the attack tactic tree.
[0008] The steps of step 1-1 are as follows: Step 1-1-1, If D k ATT and CK attack techniques have been clearly marked in the , including the attack techniques listed in the Campaigns threat intelligence library of ATT and CK, so first use the regular expression to identify the ATT&CK attack technique number, the regular expression is T\d{4}, and organize them into attack technique sequences in order. Then, connect the ATT and CK attack tactics corresponding to each ATT and CK attack technique number, remove duplicates, and organize them into attack tactic sequences in order; Step 1-1-2, if D k If ATT and CK attack techniques are not clearly marked in the algorithm, the attack technique and tactic identification algorithms such as EXTRACTOR and TTPDrill are used. D k Extract the attack tactic sequence from the Step 1-1-3: Record the final attack tactic sequence as TAS k = TA 1 TA 2 … TA K ,in TA i For the i ATT and CK attack tactics.
[0009] Steps 1-3, for TList Each attack tool in Tools k ,The specific steps of building the attack tool knowledge base are as follows: Step 1-3-1. Installation Tools k , and write a unified calling interface; Step 1-3-2, Definition Tools k Knowledge items TEntry k = ( api k , function k , context k , tactics k ).in, apii is the interface call format, function i For functional description, context k To call the environment information, including the type of vulnerability targeted and the type of system being worked on, tactics k For the attack tactics.
[0010] The steps of steps 1-4 are as follows: Step 1-4-1: First attack tactical sequence TAS 1= TA 1 TA 2 … TA K , first build a root node, then TA 1. TA 2. … TA K A node sequence is formed in order, which is connected to the root node as a branch. Finally, the initial attack tactic tree is obtained; Step 1-4-2: A new attack tactical sequence TAS k = TA 1 TA 2 … TA K , if there is a prefix and TAS k If a prefix of TAS k The suffix of is linked to the existing branch prefix; Step 1-4-3, traverse TASS , repeat steps 1-2-2, and finally get the attack tactic tree; Step 1-4-4, DS Each threat intelligence document D k , illustrate its case About k Link to its attack tactical sequence TAS k On the leaf node of the corresponding branch.
[0011] Furthermore, in step 2, the attack tactical transition graph is constructed based on the LangGraph framework, and the steps are as follows: Step 2-1, Node definition: Nodes represent subtasks of penetration testing, and define two types of nodes: supervisor nodes and tactical nodes. Each node corresponds to a large model agent; Step 2-2, Edge definition: The edge represents the execution flow of the penetration test task, and defines two types of edges: tactical transfer edge and process control edge; Step 2-3, Attack tactic transfer graph conversion: merge the nodes representing the same ATT and CK attack tactics in the attack tactic tree, convert the root node into the supervisor node, and form an attack tactic transfer graph, recorded as TAG .
[0012] The step 2-1 includes two parts: the supervisor node and the tactical node, and the steps are as follows: Step 2-1-1, Supervisor Node: The corresponding agent is called the supervisor agent, which is responsible for scheduling penetration test tasks; Step 2-1-2, Tactical Node: Each tactical node represents a unique ATT and CK attack tactic TA k The corresponding agent is called a tactical agent, which is responsible for executing the subtasks belonging to the ATT and CK attack tactics in the penetration testing task.
[0013] The step 2-2 includes two parts: the tactical transfer side and the process control side, and the steps are as follows: Step 2-2-1, Tactic transfer edge: If in the attack tactic tree, there are attack tactics from ATT and CK TA i arrive TA j , then in the attack tactical transfer graph, we also define an edge from node TA i arrive TA j The edge of Step 2-2-2, Process Control Edge: There is a bidirectional edge between the supervisor node and each tactical node. The edge from the supervisor node to the tactical node represents the supervisor node scheduling the tactical node to complete the subtask of the penetration test. The edge from the tactical node to the supervisor node represents the fallback mechanism. When the subtask of the current tactical node fails to execute, it returns to the supervisor node and backtracks to the previous tactical node.
[0014] Furthermore, in step 3, given the penetration test task requirements input by the user Q k ,The steps of automatic penetration testing based on large model agents are as follows: Step 3-1, Reconnaissance subtask execution: The first subtask of all penetration testing tasks is reconnaissance, so Q k Enter the reconnaissance tactical agent; Step 3-2, Task initialization: Set the task requirements Q k and reconnaissance results RResult Enter the supervisor agent; Step 3-3, Subtask execution: The supervisor agent calls TAS k Each tactical agent in the game can realize each attack tactic except reconnaissance.
[0015] The steps of step 3-1 are as follows: Step 3-1-1: First, obtain the knowledge base of reconnaissance attack tactics; then obtain the list of attack tools in the knowledge base, recorded as RTools ; Step 3-1-2: Since reconnaissance is the first subtask, its execution process is relatively fixed, so execute it in sequence RTools Each attack tool in RTools Every attack tool in RTool k First, context information such as the operating system and the return result of the previous attack tool are RResult k-1 Organize into prompt words, pay attention k = 1 when Q k replace RResult k-1 , and then input the prompt word into the reconnaissance tactical agent to generate a call RTool k and call RTool k ; Step 3-1-3: Collect the execution results of all attack tools to form the reconnaissance results, recorded as RResult , started and sent to the supervisor agent.
[0016] The steps of step 3-2 are as follows: Step 3-2-1, based on Q k and RResult The most relevant case summaries were retrieved; 3-2-2 Through the leaf nodes of the attack tactics tree associated with the case summary, trace back its branches to obtain the attack tactics sequence TAS k = TA 1 TA 2 … TA K .
[0017] The steps of step 3-3 are as follows: TA k : Step 3-3-1. First, obtain the attack tactics TA k Then, obtain the list of attack tools in the knowledge base, recorded as TTools ; Step 3-3-2: Task requirements Q k , context information, reconnaissance results RResult , the execution result of the previous attack tactic and TA k The description is organized into prompt words, input TA k The corresponding tactical intelligent agent is allowed to gradually determine the attack behavior that should be executed based on the thinking chain mode. TTools Select the most appropriate attack tool, generate code to call the attack tool, and finally call the attack tool to implement the tactic; Step 3-3-3: If step 3-3-2 is executed successfully, the execution result is fed back to the supervisor agent, and the next tactical agent is called to implement the next attack tactic. If step 3-3-2 fails, the next tactical agent is called to implement the next attack tactic. TTools Delete the called attack tool and restart step 3-3-2. If all the attack tools under this tactic are tried, TTools If the tactic is still not successfully implemented, the failure information will be fed back to the supervisor agent to terminate the penetration test in advance; Step 3-3-4, Repeat steps 3-3-1, 3-3-2 and 3-3-3 until TAS k All attack tactics in have been executed and the penetration test is completed.
[0018] The beneficial effects of the present invention are mainly manifested in: (1) Automation of penetration testing based on large model intelligent agents can significantly reduce the labor cost of penetration testing and improve the work efficiency of penetration testing. (2) Based on ATT and CK attack knowledge, an attack tactical transition diagram is constructed, and the planning and decision-making of the large model are controlled based on the tactical transition diagram, which can effectively reduce the illusion problem of professional penetration testing caused by the large model. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 An embodiment of an attack tactics tree construction; Figure 2 An embodiment of the attack tactical transfer diagram conversion; Figure 3This is a flow chart of a large-scale penetration testing agent model based on ATT and CK attack knowledge enhancement. DETAILED DESCRIPTION
[0020] The present invention will be further described below in conjunction with the accompanying drawings.
[0021] Reference Figure 1~Figure 3 , a penetration test large model agent based on ATT and CK attack knowledge enhancement, including the following steps: 1. Construction of attack knowledge base: Combining ATT and CK attack knowledge, extracting attack tactic sequences and attack cases from a large number of threat intelligence documents to form an attack tactic tree; 2 Construction of attack tactic transfer graph: Based on the attack tactic tree, the transfer flow and control flow of the attack tactics are analyzed to construct the attack tactic transfer graph; 3 Automatic penetration testing based on large model agents: Build supervisor agents and tactical agents, and complete automated penetration testing based on large models under the guidance of attack tactical transfer diagrams.
[0022] like Figure 1 As shown, in step 1, the ATT and CK attack knowledge bases are constructed based on threat intelligence extraction to form an attack tactic tree, and the steps are as follows: Step 1-1: Extraction of attack technique and tactical sequences: Based on a large number of threat intelligence documents DS , given DS A threat intelligence document in D k ,The steps of attack tactic sequence extraction are as follows: Step 1-1-1, If D k ATT and CK attack techniques have been clearly marked in the , such as the attack techniques listed in the Campaigns threat intelligence library of ATT and CK, first use a regular expression to identify the ATT&CK attack technique number, the regular expression is T\d{4}, and organize them into an attack technique sequence in order. Then, connect the ATT and CK attack tactics corresponding to each ATT and CK attack technique number, remove duplicates, and organize them into an attack tactic sequence in order; Step 1-1-2, if D k If ATT and CK attack techniques are not clearly marked in the algorithm, the attack technique and tactic identification algorithms such as EXTRACTOR and TTPDrill are used. D k Extract the attack tactic sequence from the Step 1-1-3: Record the final attack tactic sequence as TAS k = TA 1 TA 2 … TA K ,in TA i For the i ATT and CK attack tactics.
[0023] Step 1-2, Case description generation: Given DS A threat intelligence document in D k ,reserve D k The title of the D k The rest of the text generates an abstract that does not exceed the specified threshold, and finally concatenates the title and abstract to form D k The case description is denoted as About k ; Step 1-3, Construction of attack tool knowledge base: Establish a list of attack tools for penetration testing needs, such as metasploit and nmap, recorded as TList Among them, penetration testing requirements can come from the experience of field experts or knowledge of threat intelligence, and the list of attack tools TList Dynamically scalable. TList Each attack tool in Tools k ,The steps to build the attack tool knowledge base are as follows: Step 1-3-1. Installation Tools k , and write a unified calling interface; Step 1-3-2, Definition Tools k Knowledge items TEntry k = ( api k , function k , context k , tactics k ).in, api i is the interface call format, function i For functional description, context k To call environment information, such as the type of vulnerability targeted and the type of system being worked on, tactics k For the attack tactics.
[0024] Steps 1-4: Construction of attack tactics tree: Figure 1 An example of constructing an attack tactic tree is given. Given a set of attack tactic sequences extracted from all threat intelligence, TASS = { TAS 1, TAS 2, …, TAS 5}, the steps to construct the attack tactic tree are as follows: Step 1-4-1: First attack tactical sequence TAS 1= TA 1 TA 2 … TA K First, build a root node root, and then TA 1. TA 2. … TA K (for example Figure 1 The reconnaissance, initial access, ..., lateral movement in (a) form a node sequence in sequence, which is linked to the root node as a branch. Finally, the initial attack tactic tree is obtained (such as Figure 1 ).
[0025] Step 1-4-2: A new attack tactical sequence TAS k = TA 1 TA 2 … TA K , if there is a prefix and TAS k A prefix of Figure 1 (b) TAS 1 and TAS 2 with the same prefix: Reconnaissance Initial access), then TAS k The suffix of the branch is linked to the existing branch prefix (such as Figure 1 ).
[0026] Step 1-4-3, traverse TASS , repeat steps 1-2-2, and finally get the attack tactic tree (such as Figure 1 , as shown in (c) in the figure).
[0027] Step 1-4-4, DSEach threat intelligence document D k , illustrate its case About k Link to its attack tactical sequence TAS k On the leaf node of the corresponding branch.
[0028] like Figure 2 As shown, in step 2, the attack tactical transfer graph is constructed based on the LangGraph framework and is composed of Figure 1 The attack tactic tree is converted from the following steps: Step 2-1, Node definition: Nodes represent subtasks of penetration testing, and define two types of nodes: supervisor nodes and tactical nodes. Each node corresponds to a large model agent. The steps are as follows: Step 2-1-1, Supervisor Node: The corresponding agent is called the supervisor agent, which is responsible for scheduling penetration test tasks.
[0029] Step 2-1-2, Tactical Node: Each tactical node represents a unique ATT and CK attack tactic TA k The corresponding agent is called a tactical agent, which is responsible for executing the subtasks belonging to the ATT and CK attack tactics in the penetration testing task.
[0030] Step 2-2, Edge definition: The edge represents the execution flow of the penetration test task. Two types of edges are defined: tactical transfer edge and process control edge. The steps are as follows: Step 2-2-1, Tactic transfer edge: If in the attack tactic tree, there are attack tactics from ATT and CK TA i arrive TA j , then in the attack tactical transfer graph, we also define an edge from node TA i arrive TA j The edge (such as reconnaissance Initial access).
[0031] Step 2-2-2, Process Control Edge: There is a bidirectional edge between the supervisor node and each tactical node. The edge from the supervisor node to the tactical node represents the supervisor node scheduling the tactical node to complete the subtask of the penetration test. The edge from the tactical node to the supervisor node represents the fallback mechanism. When the subtask of the current tactical node fails to execute, it returns to the supervisor node and backtracks to the previous tactical node.
[0032] Step 2-3, Attack tactic transfer graph conversion: merge the nodes representing the same ATT and CK attack tactics in the attack tactic tree, convert the root node into the supervisor node, and form an attack tactic transfer graph, recorded as TAG . Figure 2 Given based on Figure 1 The attack tactics tree is converted into the attack tactics transfer graph.
[0033] The penetration test process of the present invention is as follows Figure 3 As shown, in step 3, given the penetration test task requirements input by the user Q k The specific steps of automatic penetration testing based on large model agents are as follows: Step 3-1. Enter the task requirements and execute the reconnaissance subtask: The first subtask of all penetration testing tasks is reconnaissance, so Q k Enter the reconnaissance tactical agent, the steps are as follows: Step 3-1-1: First, obtain the knowledge base of reconnaissance attack tactics; then obtain the list of attack tools in the knowledge base, recorded as RTools .
[0034] Step 3-1-2: Since reconnaissance is the first subtask, its execution process is relatively fixed, so execute it in sequence RTools Specifically, RTools Every attack tool in RTool k First, context information such as the operating system and the return result of the previous attack tool are RResult k-1 Organize into prompt words, pay attention k = 1 when Q k replace RResult k-1 Then input the prompt word into the reconnaissance tactical agent to generate the call RTool k and call RTool k ; Step 3-1-3: Collect the execution results of all attack tools to form the reconnaissance results, recorded as RResult , started and sent to the supervisor agent.
[0035] Step 3-2, Task initialization: Set the task requirements Q k and reconnaissance results RResult Send to the supervisor agent, the steps are as follows: Step 3-2-1, based on Qk and RResult The search matches the most relevant case summaries.
[0036] Step 3-2-2: Through the leaf nodes of the attack tactic tree associated with the case summary, trace back its branches to obtain the attack tactic sequence TAS k = TA 1 TA 2 … TA K .
[0037] Step 3-3, Subtask execution: The supervisor agent calls TAS k Each tactical agent in the corresponding tactical agent can realize each attack tactic except reconnaissance. TA k , the steps are as follows: Step 3-3-1. First, obtain the attack tactics TA k Then, we obtain the attack tool set in the knowledge base, which is recorded as TTools .
[0038] Step 3-3-2: Task requirements Q k , context information, reconnaissance results RResult , the execution result of the previous attack tactic and TA k The description is organized into prompt words, input TA k The corresponding tactical intelligent agent is allowed to gradually determine the attack behavior that should be executed based on the thinking chain mode. TTools Select the most appropriate attack tool, generate code to call the attack tool, and finally call the attack tool to implement the tactic; Step 3-3-3: If step 3-3-2 is executed successfully, the execution result is fed back to the supervisor agent, and the next tactical agent is called to implement the next attack tactic. TTools Delete the used attack tool and restart step 3-3-2. TTools If the tactic is still not successfully implemented, the failure information will be fed back to the supervisor agent to terminate the penetration test in advance; Step 3-3-4, Repeat steps 3-3-1, 3-3-2 and 3-3-3 until TAS kAll attack tactics in have been executed and the penetration test is completed.
Claims
1. A penetration test large model agent based on ATT and CK attack knowledge enhancement, characterized in that: The large model agent testing includes the following steps: Step 1: Construction of attack knowledge base: Combine ATT and CK attack knowledge, extract attack tactic sequences and attack cases from a large number of threat intelligence documents, and form an attack tactic tree; Step 2: Construction of attack tactic transfer graph: Analyze the transfer flow and control flow of attack tactics based on the attack tactic tree, and construct the attack tactic transfer graph; Step 3: Automatic penetration testing based on large model agents: Build supervisor agents and tactical agents, and complete automated penetration testing based on large models under the guidance of the attack tactical transfer diagram.
2. A penetration test large model agent based on ATT and CK attack knowledge enhancement as described in claim 1, characterized in that: In step 1, the ATT and CK attack knowledge bases are constructed based on threat intelligence extraction, and the steps are as follows: Step 1-1: Extraction of attack technique and tactical sequences: Based on a large number of threat intelligence documents DS , given DS A threat intelligence document in D k ,according to D k Whether the ATT and CK attack techniques are clearly marked, and whether they are identified using regular expressions or attack technique and tactic recognition algorithms, and then organized into attack tactic sequences after deduplication; Step 1-2, Case description generation: Given DS A threat intelligence document in D k ,reserve D k The title of the D k The rest of the text generates an abstract that does not exceed the specified threshold, and finally concatenates the title and abstract to form D k The case description is denoted as Info k ; Step 1-3, Construction of attack tool knowledge base: Establish an attack tool list based on penetration testing requirements. The attack tool list is metasploit or nmap, recorded as TList , where penetration testing requirements can come from the experience of domain experts or knowledge of threat intelligence, and the list of attack tools TList Dynamically scalable; Step 1-4, attack tactic tree construction: given a set of attack tactic sequences extracted from all threat intelligence TASS = { TAS 1, TAS 2, …, TAS 5}, and gradually construct the attack tactics tree.
3. A penetration test large model agent based on ATT and CK attack knowledge enhancement as described in claim 2, characterized in that: The steps of step 1-1 are as follows: Step 1-1-1, If D k ATT and CK attack techniques have been clearly marked in the , including the attack techniques listed in the Campaigns threat intelligence library of ATT and CK. First, the ATT&CK attack technique number is identified using a regular expression, the regular expression is T\d{4}, and the attack techniques are organized into an attack technique sequence in order. Then, the ATT and CK attack tactics corresponding to each ATT and CK attack technique number are connected, and after deduplication, they are organized into an attack tactic sequence in order. Step 1-1-2, if D k If ATT and CK attack techniques are not clearly marked in the algorithm, the attack technique and tactic identification algorithms such as EXTRACTOR and TTPDrill are used. D k Extract the attack tactic sequence from the Step 1-1-3: Record the final attack tactic sequence as TAS k = TA 1 TA 2 … TA K ,in TA i For the i ATT and CK attack tactics.
4. A penetration test large model agent based on ATT and CK attack knowledge enhancement as described in claim 2, characterized in that: The steps 1-3 are as follows: TList Each attack tool in Tool k : Step 1-3-1. Installation Tool k , and write a unified calling interface; Step 1-3-2, Definition Tool k Knowledge items TEntry k = ( API k , func k , context k , tactic k ),in, API i is the interface call format, func i For functional description, context k To call the environment information, including the type of vulnerability targeted and the type of system being worked on, tactic k For the attack tactics.
5. A penetration test large model agent based on ATT and CK attack knowledge enhancement as described in claim 2, characterized in that: The steps of steps 1-4 are as follows: Step 1-4-1: First attack tactical sequence TAS 1 = TA 1 TA 2 … TA K , first build a root node, then TA 1. TA 2. … TA K A node sequence is formed in order, which is linked to the root node as a branch, and finally the initial attack tactic tree is obtained; Step 1-4-2: A new attack tactical sequence TAS k = TA 1 TA 2 … TA K , if there is a prefix and TAS k If a prefix of TAS k The suffix of is linked to the existing branch prefix; Step 1-4-3, traverse TASS , repeat steps 1-2-2, and finally get the attack tactic tree; Step 1-4-4, DS Each threat intelligence document D k , illustrate its case Info k Link to its attack tactical sequence TAS k On the leaf node of the corresponding branch.
6. A penetration test large model agent based on ATT and CK attack knowledge enhancement as described in claim 1 or 2, characterized in that: In step 2, the attack tactical transition graph is constructed based on the LangGraph framework, and the steps are as follows: Step 2-1, Node definition: Nodes represent subtasks of penetration testing. Two types of nodes are defined: supervisor nodes and tactical nodes. Each node corresponds to a large model agent. Step 2-2, Edge definition: The edge represents the execution flow of the penetration test task, and defines two types of edges: tactical transfer edge and process control edge; Step 2-3, Attack tactic transfer graph conversion: merge the nodes representing the same ATT and CK attack tactics in the attack tactic tree, convert the root node into the supervisor node, and form an attack tactic transfer graph, recorded as TAG .
7. A penetration test large model agent based on ATT and CK attack knowledge enhancement as described in claim 6, characterized in that: The step 2-1 includes two parts: the supervisor node and the tactical node, and the steps are as follows: Step 2-1-1, Supervisor Node: The corresponding agent is called the supervisor agent, which is responsible for scheduling penetration test tasks; Step 2-1-2, Tactical Node: Each tactical node represents a unique ATT and CK attack tactic TA k The corresponding agent is called a tactical agent, which is responsible for executing the subtasks belonging to the ATT and CK attack tactics in the penetration testing task.
8. A penetration test large model agent based on ATT and CK attack knowledge enhancement as described in claim 6, characterized in that: The step 2-2 includes two parts: the tactical transfer side and the process control side, and the steps are as follows: Step 2-2-1, Tactic transfer edge: If in the attack tactic tree, there are attack tactics from ATT and CK TA i arrive TA j , then in the attack tactical transfer graph, we also define an edge from node TA i arrive TA j The edge of Step 2-2-2, Process control edge: There is a bidirectional edge between the supervisor node and each tactical node. The edge from the supervisor node to the tactical node represents that the supervisor node schedules the tactical node to complete the subtask of the penetration test. The edge from the tactical node to the supervisor node represents the fallback mechanism. When the subtask of the current tactical node fails to execute, it returns to the supervisor node and traces back to the previous tactical node.
9. A penetration test large model agent based on ATT and CK attack knowledge enhancement as described in claim 1 or 2, characterized in that: In step 3, given the penetration test task requirements input by the user Q k ,The steps of automatic penetration testing based on large model agents are as follows: Step 3-1, Reconnaissance subtask execution: The first subtask of all penetration testing tasks is reconnaissance, so Q k Enter the reconnaissance tactical agent; Step 3-2, Task initialization: Set the task requirements Q k and reconnaissance results RResult Enter the supervisor agent; Step 3-3, Subtask execution: execute in sequence TAS k Every attack tactic except reconnaissance.
10. A penetration test large model agent based on ATT and CK attack knowledge enhancement as described in claim 9, characterized in that: The steps of step 3-1 are as follows: Step 3-1-1: First, obtain the knowledge base of reconnaissance attack tactics; then obtain the list of attack tools in the knowledge base, recorded as RTools ; Step 3-1-2: Since reconnaissance is the first subtask, its execution process is relatively fixed, so execute it in sequence RTools Each attack tool in RTools Every attack tool in RTool k First, context information such as the operating system and the return result of the previous attack tool are RResult k-1 Organize into prompt words, pay attention k = 1 when Q k replace RResult k-1 , and then input the prompt word into the reconnaissance tactical agent to generate a call RTool k and call RTool k ; Step 3-1-3: Collect the execution results of all attack tools to form the reconnaissance results, recorded as RResult , started and sent to the supervisor agent.
11. A penetration test large model agent based on ATT and CK attack knowledge enhancement as claimed in claim 9, characterized in that: The steps of step 3-2 are as follows: Step 3-2-1, based on Q k and RResult The most relevant case summaries were retrieved; Step 3-2-2: Through the leaf nodes of the attack tactic tree associated with the case summary, trace back its branches to obtain the attack tactic sequence TAS k = TA 1 TA 2 … TA K .
12. A penetration test large model agent based on ATT and CK attack knowledge enhancement as claimed in claim 9, characterized in that: The steps of step 3-3 are as follows: Step 3-3-1. First, obtain the attack tactics TA k Then, obtain the list of attack tools in the knowledge base, recorded as TTools ; Step 3-3-2: Task requirements Q k , context information, reconnaissance results RResult , the execution result of the previous attack tactic and TA k The description is organized into prompt words, input TA k The corresponding tactical intelligent agent is allowed to gradually determine the attack behavior that should be executed based on the thinking chain mode. TTools Select the most appropriate attack tool, generate code to call the attack tool, and finally call the attack tool to implement the tactic; Step 3-3-3: If step 3-3-2 is executed successfully, the execution result is fed back to the supervisor agent, and the next tactical agent is called to implement the next attack tactic. If step 3-3-2 fails, the next tactical agent is called to implement the next attack tactic. TTools Delete the called attack tool and restart step 3-3-2. If all the attack tools under this tactic are tried, TTools If the tactic is still not successfully implemented, the failure information will be fed back to the supervisor agent to terminate the penetration test in advance; Step 3-3-4, Repeat steps 3-3-1, 3-3-2 and 3-3-3 until TAS k All attack tactics in have been executed and the penetration test is completed.
Citation Information
Patent Citations
Automatic penetration testing method and system, electronic equipment and storage medium
CN116566674A
Intelligent report generation method and system based on automatic countermeasure simulation attack
CN116800548A
Penetration test route planning method and device, electronic equipment and storage medium
CN117692252A
Standardized attack path automatic generation and verification method, device and system
CN118300906A
Large language model automatic penetration testing method based on multiple agents
CN119025878A
Cited By
Large model application business risk detection method and cue word generation method and device
CN121145209A
Multi-agent penetration test tool arrangement and unified calling method and computer equipment
CN121233481A