A Penetration Testing Large Model Agent Enhanced by ATT and CK Attack Knowledge
By building a large-scale penetration test agent based on ATT and CK attack knowledge, the problems of flexibility and dynamic adjustment of penetration test tools are solved, and efficient automated penetration tests are achieved, reducing labor costs and improving the success rate of penetration tests.
Patent Information
- Application Number
- CN202510466276.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-04-15
AI Technical Summary
The existing penetration testing tools and systems lack the ability to flexibly respond to different target environments, making it difficult to achieve dynamic adjustments and systematic integration between tools, and large models lack the dynamic generation and adjustment capabilities of tactical chains in penetration testing, resulting in low penetration testing efficiency and success rate.
Build a penetration test large-model agent based on ATT and CK attack knowledge, and use an attack tactical tree and tactical transfer map, and combine it with a large-model agent to achieve automated penetration testing, dynamic planning and decision-making.
Significantly reduce the labor cost of penetration testing, improve penetration testing efficiency, reduce the hallucination problems of large models for professional penetration testing, and realize dynamic generation and adjustment of tactical chains.
Smart Images

Figure CN119996232B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to artificial intelligence and network security technologies, and particularly to an automated penetration testing system. Background Art
[0002] Penetration testing is an important defense means in the field of network security. By simulating the perspective of an attacker, it identifies and exploits security vulnerabilities in a system to evaluate the system's defense capabilities. The purpose of penetration testing is not only to discover potential vulnerabilities but also to verify the effectiveness of the system's security configuration and reinforcement measures. With the rapid development of network attack technologies, traditional penetration testing has gradually become difficult to meet the security requirements in complex environments. Especially in the face of increasingly complex target environments and attack technologies, the efficiency, cost, and success rate of manual penetration testing are all limited.
[0003] Although existing penetration testing tools and systems can provide a certain degree of automated support, most are based on preset strategies and scripts and lack the ability to flexibly adapt to different target environments. This limitation has led to several major problems: First, there is a lack of dynamic adjustment ability and it is unable to flexibly select attack paths based on real-time information. Second, the integration and coordination between tools are not systematic enough, making it difficult to select the best combination of technologies and tools, thus reducing the success rate of penetration testing. Third, existing automated penetration testing systems usually focus on the technical level and lack the ability to overall plan various attack technologies from a tactical level, making the penetration testing methods relatively limited and single.
[0004] In recent years, the rise of large language models has provided new possibilities for the intelligence of penetration testing. However, large models also face many challenges in penetration testing applications. For example, it is difficult to achieve systematic integration of knowledge bases and attack strategies, difficult to dynamically adjust attack paths in real time, and the controllability of tool invocation and execution steps is insufficient. In addition, existing large models lack integration with specific attacks and fail to achieve dynamic generation and adjustment of tactical chains. Therefore, systematically integrating automated agents with penetration testing tactical chains to achieve efficient combination of technologies and tactics based on knowledge bases has become the core problem to be solved urgently at this stage. Summary of the Invention
[0005] In order to overcome the high labor cost in penetration testing and the hallucination problem of large models in professional penetration testing, the invention proposes a penetration testing large model agent enhanced by ATT and CK attack knowledge. Based on the large model agent, the automation of penetration testing can be realized, which can significantly reduce the labor cost of penetration testing and improve the work efficiency of penetration testing. An attack tactical transfer graph is constructed based on ATT and CK attack knowledge, and the planning and decision-making of the large model are controlled based on the tactical transfer graph, which can effectively reduce the hallucination problem of large models in professional penetration testing.
[0006] The technical solution adopted by the present invention to solve its technical problems is as follows:
[0007] A penetration testing large model agent enhanced by ATT and CK attack knowledge, comprising the following steps:
[0008] Step 1, Attack knowledge base construction: Combining ATT and CK attack knowledge, extract attack tactic sequences and attack cases from a large number of threat intelligence documents to form an attack tactic tree;
[0009] Step 2, Attack tactic transfer graph construction: Analyze the transfer flow and control flow of attack tactics based on the attack tactic tree, and construct an attack tactic transfer graph;
[0010] Step 3, Automatic penetration testing based on the large model agent: Construct a supervisor agent and a tactic agent, and complete automatic penetration testing based on the large model under the guidance of the attack tactic transfer graph.
[0011] Furthermore, in the above Step 1, the ATT and CK attack knowledge bases are constructed by extracting based on threat intelligence, and the steps are as follows:
[0012] Step 1-1, Attack technique and tactic sequence extraction: Based on a large number of threat intelligence documents DS , given DS a threat intelligence document in D k , according to D k whether it clearly marks ATT and CK attack techniques, use regular expressions or attack technique and tactic recognition algorithms for recognition, and after removing duplicates, organize them into an attack tactic sequence in order;
[0013] Step 1-2, Case description generation: Given DS a threat intelligence document in D k , retain D k the title, and use a large language model to generate a summary of no more than the specified threshold number of words for D k the rest, and finally splice the title and the summary to form D k the case description of Info k ;
[0014] Step 1-3, Attack tool knowledge base construction: Establish an attack tool list for penetration testing requirements. The attack tool list is metasploit or nmap, denoted as TList , where the penetration testing requirements can come from the experience of domain experts or the knowledge of threat intelligence, and the attack tool list TList can be dynamically expanded;
[0015] Steps 1-4, Attack Tactical Tree Construction: Given a set of attack tactical sequences extracted from all threat intelligence TASS = { TAS 1, TAS 2, …, TAS 5}, construct an attack tactical tree step by step.
[0016] The steps of Step 1-1 are as follows:
[0017] Step 1-1-1, If D k clearly marks ATT and CK attack techniques, including the attack techniques listed in the Campaigns threat intelligence library of ATT and CK, first use regular expressions to identify the ATT&CK attack technique numbers. The regular expression is T\d{4}, and organize them into an attack technique sequence in order. Then, connect the ATT and CK attack tactics corresponding to each ATT and CK attack technique number, remove duplicates, and organize them into an attack tactical sequence in order;
[0018] Step 1-1-2, If D k does not clearly mark ATT and CK attack techniques, use attack technique and tactic identification algorithms such as EXTRACTOR and TTPDrill to extract the attack tactical sequence from D k ;
[0019] Step 1-1-3, Denote the finally obtained attack tactical sequence as TAS k = TA 1 TA 2 … TA K , where TA i is the i th ATT and CK attack tactic.
[0020] For Step 1-3, for each attack tool TList in Tool k , the specific steps for constructing the attack tool knowledge base are as follows:
[0021] Step 1-3-1, Install Tool k , and write a unified form of call interface;
[0022] Step 1-3-2, Define Toolk Knowledge entries TEntry k = ( api k , func k , context k , tactic k ). Among them, api i is the interface call format, func i is the function description, context k is the call environment information, including the vulnerability type targeted and the system type of work, tactic k is the attack tactic to which it belongs.
[0023] The steps of the above-mentioned Steps 1-4 are as follows:
[0024] Step 1-4-1: For the first attack tactic sequence TAS 1= TA 1 TA 2 … TA K , first construct a root node, and then TA 1, TA 2, …, TA K are formed into a node sequence in order and linked to the root node as a branch. Finally, the initial attack tactic tree is obtained;
[0025] Step 1-4-2: For a new attack tactic sequence TAS k = TA 1 TA 2 … TA K , if there is a prefix of an existing branch in the current attack tactic tree that coincides with a prefix of TAS k , then the suffix of TAS k is linked after the existing branch prefix;
[0026] Step 1-4-3: Traverse TASS , and repeatedly execute Step 1-2-2. Finally, the attack tactic tree is obtained;
[0027] Step 1-4-4: ForDS each threat intelligence document in D k and link its case description Info k to the leaf node of the corresponding branch of its attack tactic sequence TAS k on the corresponding branch's leaf node
[0028] Furthermore, in step 2, the attack tactic transfer graph is constructed based on the LangGraph framework, and the steps are as follows:
[0029] Step 2-1, Node Definition: Nodes represent subtasks of penetration testing, and two types of nodes, the supervisor node and the tactic node, are defined. Each node corresponds to a large model agent;
[0030] Step 2-2, Edge Definition: Edges represent the execution flow of penetration testing tasks, and two types of edges, the tactic transfer edge and the process control edge, are defined;
[0031] Step 2-3, Attack Tactic Transfer Graph Transformation: Merge the nodes in the attack tactic tree that represent the same ATT and CK attack tactics, and transform the root node into the supervisor node to form the attack tactic transfer graph, denoted as TAG .
[0032] The above step 2-1 includes two parts, the supervisor node and the tactic node, and the steps are as follows:
[0033] Step 2-1-1, Supervisor Node: The corresponding agent is called the supervisor agent, which is responsible for scheduling penetration testing tasks;
[0034] Step 2-1-2, Tactic Node: Each tactic node represents a unique ATT and CK attack tactic TA k , and the corresponding agent is called the tactic agent, which is responsible for executing the subtasks in the penetration testing task that belong to this ATT and CK attack tactic.
[0035] The above step 2-2 includes two parts, the tactic transfer edge and the process control edge, and the steps are as follows:
[0036] Step 2-2-1, Tactic Transfer Edge: If in the attack tactic tree, there is an edge from the ATT and CK attack tactic TA i to TA j , then in the attack tactic transfer graph, an edge from node TA i to TA j is also defined;
[0037] Step 2-2-2, Process Control Edge: There is a two-way edge between the supervisor node and each tactical node. The edge from the supervisor node to the tactical node represents that the supervisor node schedules the subtask of the tactical node to complete the penetration test. The edge from the tactical node to the supervisor node represents the fallback mechanism. When the subtask of the current tactical node fails to execute, it returns to the supervisor node and backtracks to the previous tactical node.
[0038] Furthermore, in the said Step 3, given the penetration test task requirements input by the user Q k , the automatic penetration test steps based on the large model agent are as follows:
[0039] Step 3-1, Execution of Reconnaissance Subtask: The first subtask of all penetration test tasks is reconnaissance. Therefore, Q k input it into the reconnaissance tactical agent;
[0040] Step 3-2, Task Initialization: Input the task requirements Q k and the reconnaissance results RResult into the supervisor agent;
[0041] Step 3-3, Subtask Execution: The supervisor agent sequentially calls TAS k each corresponding tactical agent in
[0042] to implement each attack tactic except reconnaissance.
[0043] The steps of the said Step 3-1 are as follows: RTools ;
[0044] Step 3-1-1, First, obtain the knowledge base of reconnaissance attack tactics; then, obtain the list of attack tools in the knowledge base, denoted as RTools Since reconnaissance is the first subtask and its execution process is relatively fixed, each attack tool in RTools each attack tool in RTool k , first organize the context information such as the operating system and the return result of the previous attack tool RResult k-1 into a prompt. Note that k when Q k is used instead of RResult k-1 , then input the prompt into the reconnaissance tactical agent to let it generate the code for calling RTool k , and call RTool k;
[0045] Step 3-1-3, Collect the execution results of all attack tools to form a reconnaissance result, denoted as RResult , start and send it to the supervisor agent.
[0046] The steps of the said step 3-2 are as follows:
[0047] Step 3-2-1, Based on Q k and RResult Retrieve the most relevant case summaries;
[0048] 3-2-2 Through the leaf nodes of the attack tactic tree associated with the case summary, trace back its branches to obtain the attack tactic sequence TAS k = TA 1 TA 2 … TA K .
[0049] The steps of the said step 3-3 are as follows, for the current attack tactic TA k :
[0050] Step 3-3-1, First, obtain the knowledge base of the attack tactic TA k ; then, obtain the list of attack tools in the knowledge base, denoted as TTools ;
[0051] Step 3-3-2, Organize the task requirements Q k , context information, reconnaissance results RResult , the execution result of the previous attack tactic and TA k 's description into a prompt, input TA k the corresponding tactical agent, let it gradually determine the current attack behavior to be executed based on the chain-of-thought mode, select the most suitable attack tool from TTools , and generate the code to call the attack tool, and finally call the attack tool to implement the tactic;
[0052] Step 3-3-3, If step 3-3-2 is executed successfully, then feedback the execution result to the supervisor agent, continue to call the next tactical agent to implement the next attack tactic, if step 3-3-2 fails, then delete the called attack tool from TTools , and then restart step 3-3-2, if all theTTools If the tactic still fails to be successfully implemented, the failure information will be fed back to the supervisor agent to terminate the penetration test in advance.
[0053] Step 3-3-4: Repeatedly execute Step 3-3-1, Step 3-3-2, and Step 3-3-3 until TAS k all the attack tactics in it have been executed and the penetration test ends.
[0054] The beneficial effects of the present invention are mainly manifested in: (1) Realizing the automation of penetration testing based on large model agents can significantly reduce the labor cost of penetration testing and improve the work efficiency of penetration testing. (2) Constructing an attack tactic transfer graph based on ATT and CK attack knowledge and controlling the planning and decision-making of the large model based on the tactic transfer graph can effectively reduce the hallucination problem of the large model for professional penetration testing. Description of the Drawings
[0055] Figure 1 An embodiment of constructing an attack tactic tree;
[0056] Figure 2 An embodiment of the conversion of the attack tactic transfer graph;
[0057] Figure 3 A flowchart of a penetration testing large model agent enhanced based on ATT and CK attack knowledge. Detailed Embodiments
[0058] The present invention will be further described below in conjunction with the drawings.
[0059] Referring to Figures 1 - 3 , a penetration testing large model agent enhanced based on ATT and CK attack knowledge includes the following steps:
[0060] 1 Construction of the attack knowledge base: Combining ATT and CK attack knowledge, extracting attack tactic sequences and attack cases from a large number of threat intelligence documents to form an attack tactic tree;
[0061] 2 Construction of the attack tactic transfer graph: Analyzing the transfer flow and control flow of attack tactics based on the attack tactic tree to construct an attack tactic transfer graph;
[0062] 3 Automatic penetration testing based on large model agents: Constructing a supervisor agent and a tactic agent, and completing automatic penetration testing based on the large model under the guidance of the attack tactic transfer graph.
[0063] As Figure 1 shown, in the said Step 1, the ATT and CK attack knowledge bases are constructed by extracting based on threat intelligence to form an attack tactic tree, and the steps are as follows:
[0064] Step 1-1, Attack Technique and Tactics Sequence Extraction: Based on a large number of threat intelligence documents DS , given DS one threat intelligence document in D k , the steps for extracting the attack tactics sequence are as follows:
[0065] Step 1-1-1, If D k has clearly marked ATT and CK attack techniques, such as the attack techniques listed in the Campaigns threat intelligence library of ATT and CK, then first use regular expressions to identify the ATT&CK attack technique numbers. The regular expression is T\d{4}, and organize them into an attack technique sequence in order. Then, connect the ATT and CK attack tactics corresponding to each ATT and CK attack technique number, remove duplicates, and organize them into an attack tactics sequence in order;
[0066] Step 1-1-2, If D k does not clearly mark ATT and CK attack techniques, then use attack technique and tactics identification algorithms such as EXTRACTOR and TTPDrill to extract the attack tactics sequence from D k ;
[0067] Step 1-1-3, Denote the finally obtained attack tactics sequence as TAS k = TA 1 TA 2 … TA K , where TA i is the i th ATT and CK attack tactic.
[0068] Step 1-2, Case Description Generation: Given DS one threat intelligence document in D k , retain D k 's title, and use a large language model to generate a summary of no more than the specified threshold number of words for the remaining part of D k . Finally, concatenate the title and the summary to form D k 's case description, denoted as Info k ;
[0069] Step 1-3, Construction of Attack Tool Knowledge Base: Establish a list of attack tools for penetration testing requirements, such as metasploit and nmap, denoted as TList . Among them, the penetration testing requirements can come from the experience of domain experts or the knowledge of threat intelligence, and the list of attack tools TList can be dynamically expanded. For TList each attack tool in Tool k , the steps for constructing the attack tool knowledge base are as follows:
[0070] Step 1-3-1, Install Tool k , and write a unified form of call interface;
[0071] Step 1-3-2, Define Tool k 's knowledge entries TEntry k = ( api k , func k , context k , tactic k ). Among them, api i is the interface call format, func i is the function description, context k is the call environment information, such as the vulnerability type targeted and the system type of work, tactic k is the attack tactic to which it belongs.
[0072] Step 1-4, Construction of Attack Tactic Tree: Figure 1 shows an example of the construction of an attack tactic tree. Given the set of attack tactic sequences TASS = { TAS 1, TAS 2, …, TAS 5} extracted from all threat intelligence, the steps for constructing the attack tactic tree are as follows:
[0073] Step 1-4-1, For the first attack tactic sequence TAS 1 = TA 1 TA 2 … TA K , first construct a root node root, and then TA 1, TA 2, …,TA K (such as Figure 1 reconnaissance, initial access, …, lateral movement in (a) of Figure 1 ) form a sequence of nodes in order, serving as a branch linked to the root node. Finally, the initial attack tactic tree is obtained (as shown in (a) of
[0074] Step 1-4-2: For a new attack tactic sequence TAS k = TA 1 TA 2 … TA K , if there is a prefix of an existing branch in the current attack tactic tree that coincides with a prefix of TAS k (such as Figure 1 in (b) of TAS 1 and TAS 2 contain the same prefix: reconnaissance initial access), then link the suffix of TAS k after the existing branch prefix (as shown in (b) of Figure 1 ).
[0075] Step 1-4-3: Traverse TASS , repeatedly execute Step 1-2-2, and finally obtain the attack tactic tree (as shown in (c) of Figure 1 ).
[0076] Step 1-4-4: For each threat intelligence document in DS , link its case description D k to the leaf node of the branch corresponding to its attack tactic sequence Info k . TAS k As shown in
[0077] For example, in Step 2, the attack tactic transfer graph is constructed based on the LangGraph framework and is transformed from the attack tactic tree of Figure 2 as follows: Figure 1 The steps are as follows:
[0078] Step 2-1: Node definition: Nodes represent subtasks of penetration testing, and two types of nodes, namely the supervisor node and the tactic node, are defined. Each node corresponds to a large model agent, and the steps are as follows:
[0079] Step 2-1-1, Supervisor Node: The corresponding agent is called the supervisor agent, which is responsible for scheduling penetration testing tasks.
[0080] Step 2-1-2, Tactical Node: Each tactical node represents a unique ATT&CK attack tactic TA k , and the corresponding agent is called the tactical agent, which is responsible for executing the subtasks belonging to this ATT&CK attack tactic in the penetration testing task.
[0081] Step 2-2, Edge Definition: The edge represents the execution flow of the penetration testing task. Two types of edges are defined: tactical transfer edge and process control edge. The steps are as follows:
[0082] Step 2-2-1, Tactical Transfer Edge: If there is an edge from an ATT&CK attack tactic TA i to TA j in the attack tactic tree, then an edge from node TA i to TA j is also defined in the attack tactic transfer graph (for example, reconnaissance Initial Access).
[0083] Step 2-2-2, Process Control Edge: There is a two-way edge between the supervisor node and each tactical node. The edge from the supervisor node to the tactical node represents that the supervisor node schedules the tactical node to complete the subtask of the penetration testing. The edge from the tactical node to the supervisor node represents the fallback mechanism. When the subtask of the current tactical node fails, it returns to the supervisor node and backtracks to the previous tactical node.
[0084] Step 2-3, Attack Tactic Transfer Graph Conversion: Merge the nodes representing the same ATT&CK attack tactic in the attack tactic tree, and convert the root node into the supervisor node to form the attack tactic transfer graph, denoted as TAG . Figure 2 shows the attack tactic transfer graph obtained by converting the attack tactic tree based on Figure 1 .
[0085] The penetration testing process of the present invention is as Figure 3 shown. In step 3, given the penetration testing task requirements input by the user Q k , the specific steps of the automatic penetration testing based on the large model agent are as follows:
[0086] Step 3-1, Input Task Requirements, Execution of Reconnaissance Subtask: The first subtask of all penetration testing tasks is reconnaissance. Therefore, Q kInput the reconnaissance tactical agent, the steps are as follows:
[0087] Step 3-1-1: First, obtain the knowledge base of the reconnaissance and attack tactics; then, obtain the list of attack tools in the knowledge base, denoted as RTools .
[0088] Step 3-1-2: Since reconnaissance is the first subtask and its execution process is relatively fixed, each attack tool in RTools is executed in sequence. Specifically, for each attack tool in RTools , first organize the context information such as the operating system and the return result of the previous attack tool RTool k into a prompt. Note that when RResult k-1 = 1, use k for replacement Q k . Then input the prompt into the reconnaissance tactical agent to let it generate the code for calling RResult k-1 , and call RTool k ; RTool k ;
[0089] Step 3-1-3: Collect the execution results of all attack tools to form the reconnaissance result, denoted as RResult , and start and send it to the supervisor agent.
[0090] Step 3-2: Task initialization: Send the task requirements Q k and the reconnaissance result RResult to the supervisor agent, the steps are as follows:
[0091] Step 3-2-1: Based on Q k and RResult , retrieve and match to obtain the most relevant case summary.
[0092] Step 3-2-2: Through the leaf nodes of the attack tactical tree associated with the case summary, trace back its branches to obtain the attack tactical sequence TAS k = TA 1 TA 2 … TA K .
[0093] Step 3-3: Subtask execution: The supervisor agent calls TAS kEach corresponding tactical agent in it is used to implement each attack tactic except reconnaissance. For the current attack tactic TA k , the steps are as follows:
[0094] Step 3-3-1: First, obtain the knowledge base of the attack tactic TA k . Then, obtain the attack tool set in the knowledge base, denoted as TTools .
[0095] Step 3-3-2: Organize the task requirements Q k , context information, reconnaissance results RResult , the execution result of the previous attack tactic, and TA k 's description into a prompt, and input it TA k 's corresponding tactical agent, and let it gradually determine the attack behavior that should be executed currently based on the chain-of-thought mode, select the most suitable attack tool from TTools , and generate the code to call the attack tool. Finally, call the attack tool to implement the tactic;
[0096] Step 3-3-3: If Step 3-3-2 is executed successfully, feedback the execution result to the supervisor agent and continue to call the next tactical agent to implement the next attack tactic. If Step 3-3-2 fails, delete the called attack tool from TTools , and then restart Step 3-3-2. If all TTools under this tactic have been tried and the tactic still cannot be successfully implemented, feedback the failure information to the supervisor agent and terminate the penetration test in advance;
[0097] Step 3-3-4: Repeatedly execute Step 3-3-1, Step 3-3-2, and Step 3-3-3 until TAS k All attack tactics in have been executed and the penetration test ends.
Claims
1. A penetration testing large model agent enhanced by ATT and CK attack knowledge, characterized in that, The testing of the large model agent includes the following steps: Step 1, Attack knowledge base construction: Combine ATT and CK attack knowledge, extract attack tactic sequences and attack cases from a large number of threat intelligence documents, and form an attack tactic tree; Step 2, Attack tactic transfer graph construction: Analyze the transfer flow and control flow of attack tactics based on the attack tactic tree, and construct an attack tactic transfer graph; Step 3, Automatic penetration testing based on the large model agent: Construct a supervisor agent and tactic agents, and under the guidance of the attack tactic transfer graph, complete automated penetration testing based on the large model. In step 1, the ATT and CK attack knowledge bases are constructed by extracting based on threat intelligence, and the steps are as follows: Step 1-1, Attack Technique and Tactics Sequence Extraction: Based on a large number of threat intelligence documents DS , given DS one threat intelligence document in D k , according to D k whether ATT and CK attack techniques are clearly marked, use regular expressions or attack technique and tactics recognition algorithms for recognition, and after de-duplication, organize them into an attack tactics sequence in order; Step 1-2, Case Description Generation: Given DS one of the threat intelligence documents in D k , retain D k the title, and use a large language model to generate an abstract of no more than the specified threshold number of words for D k the rest, and finally concatenate the title and the abstract to form D k the case description of, denoted as Info k ; Step 1-3, Attack Tool Knowledge Base Construction: Establish an attack tool list according to the penetration testing requirements. The attack tool list is Metasploit or Nmap, denoted as TList , where the penetration testing requirements can come from the experience of domain experts or the knowledge of threat intelligence, and the attack tool list TList can be dynamically expanded; Steps 1-4, Attack Tactical Tree Construction: Given a set of attack tactical sequences extracted from all threat intelligence TASS = { TAS 1, TAS 2, …, TAS 5}, an attack tactical tree is gradually constructed.
2. The intelligent agent of a penetration testing large model enhanced by ATT and CK attack knowledge as claimed in claim 1, wherein The steps of step 1-1 are as follows: Step 1-1-1, if D k clearly mark the ATT and CK attack techniques, including the attack techniques listed in the Campaigns threat intelligence library of ATT and CK. First, use regular expressions to identify the ATT&CK attack technique numbers. The regular expression is T\d{4}, and organize them into an attack technique sequence in order. Then, connect the ATT and CK attack tactics corresponding to each ATT and CK attack technique number, remove duplicates, and organize them into an attack tactic sequence in order; Step 1-1-2, if D k does not clearly label the ATT and CK attack technologies, then use the EXTRACTOR or TTPDrill attack technique and tactic recognition algorithm to extract the attack tactic sequence from D k ; Step 1-1-3: Denote the finally obtained attack tactic sequence as TAS k = TA 1 TA 2 … TA K , where TA i is the i th ATT and CK attack tactic.
3. The intelligent agent of a penetration testing large model enhanced by ATT and CK attack knowledge as claimed in claim 1, wherein The steps of steps 1-3 are as follows. For TList each attack tool in Tool k : Step 1-3-1, Installation Tool k , and write a call interface in a unified form; Step 1-3-2, Define Tool k knowledge item TEntry k = ( api k , func k , context k , tactic k ), where api i is the interface call format, func i is the function description, context k is the call environment information, including the vulnerability type targeted and the system type of work, tactic k is the attack tactic to which it belongs.
4. The intelligent agent of a penetration testing large model enhanced by ATT and CK attack knowledge as claimed in claim 1, wherein, The steps of step 1-4 are as follows: Step 1-4-1: For the first attack tactic sequence TAS 1 = TA 1 TA 2 … TA K , first construct a root node, and then TA 1、 TA 2、…、 TA K form a node sequence in order, which is linked to the root node as a branch, and finally obtain the initial attack tactic tree; Step 1-4-2, for a new attack tactic sequence TAS k = TA 1 TA 2 … TA K , if there is a prefix of an existing branch in the current attack tactic tree that coincides with a prefix of TAS k , then link the suffix of TAS k after the existing branch prefix; Step 1-4-3, traverse TASS , repeatedly execute Step 1-2-2, and finally obtain the attack tactic tree; Step 1-4-4. For DS each threat intelligence document in D k , link its case description Info k to the leaf node of the corresponding branch of its attack tactic sequence TAS k on.
5. The intelligent agent of a penetration testing large model enhanced by ATT and CK attack knowledge as described in claim 1, wherein In step 2, the attack tactic transfer graph is constructed based on the LangGraph framework, and the steps are as follows: Step 2-1, Node definition: Nodes represent sub-tasks of penetration testing. Define two types of nodes, supervisor nodes and tactic nodes, and each node corresponds to a large model agent; Step 2-2, Edge definition: Edges represent the execution flow of penetration testing tasks. Define two types of edges, tactic transfer edges and process control edges; Step 2-3, Conversion of Attack Tactics Transfer Diagram: Merge the nodes representing the same ATT and CK attack tactics in the attack tactics tree, and convert the root node into a supervisor node to form an attack tactics transfer diagram, denoted as TAG .
6. The intelligent agent of a penetration testing large model enhanced by ATT and CK attack knowledge as claimed in claim 5, wherein Step 2-1 includes two parts, supervisor nodes and tactic nodes, and the steps are as follows: Step 2-1-1, Supervisor node: The corresponding agent is called the supervisor agent, which is responsible for scheduling penetration testing tasks; Step 2-1-2, Tactical Node: Each tactical node represents a unique ATT and CK attack tactic TA k , and the corresponding agent is called a tactical agent, which is responsible for executing the subtasks belonging to the ATT and CK attack tactic in the penetration testing task.
7. The intelligent agent of a penetration testing large model enhanced by ATT and CK attack knowledge as described in claim 5, characterized in that, Step 2-2 includes two parts, tactic transfer edges and process control edges, and the steps are as follows: Step 2-2-1, Tactical Transfer Edge: If in the attack tactical tree, there is an edge from the ATT and CK attack tactics TA i to TA j , then in the attack tactical transfer graph, an edge from the node TA i to TA j is also defined; Step 2-2-2, Process control edge: There is a two-way edge between the supervisor node and each tactic node. The edge from the supervisor node to the tactic node represents that the supervisor node schedules the tactic node to complete the sub-task of penetration testing, and the edge from the tactic node to the supervisor node represents the fallback mechanism. When the sub-task of the current tactic node fails, it returns to the supervisor node and backtracks to the previous tactic node.
8. The intelligent agent of a penetration testing large model enhanced by ATT and CK attack knowledge as claimed in claim 1, wherein In step 3, given the penetration testing task requirements input by the user Q k , the automatic penetration testing steps based on the large model agent are as follows: Step 3-1, Reconnaissance Subtask Execution: The first subtask of all penetration testing tasks is reconnaissance. Therefore, Q k input the reconnaissance tactical agent; Step 3-2, Task Initialization: Input the task requirements Q k and the reconnaissance results RResult into the supervisor agent; Step 3-3, Sub-task Execution: Sequentially execute TAS k each attack tactic in except for reconnaissance.
9. The intelligent agent of a penetration testing large model enhanced by ATT and CK attack knowledge as claimed in claim 8, wherein The steps of step 3-1 are as follows: Step 3-1-1: First, obtain the knowledge base of reconnaissance and attack tactics; then, obtain the list of attack tools in the knowledge base, denoted as RTools ; Step 3-1-2: Since reconnaissance is the first subtask and its execution process is relatively fixed, each attack tool in RTools is executed in sequence. Specifically, for each attack tool in RTools RTool k k-1 , first organize the context information of the operating system and the return result of the previous attack tool into a prompt. Note that when RResult k k = 1, use Q k-1 to replace RResult k . Then, input the prompt into the reconnaissance tactical agent to generate the code for calling RTool k and call RTool k k ; Step 3-1-3: Collect the execution results of all attack tools to form reconnaissance results, denoted as RResult , start and send them to the supervisor agent.
10. The intelligent agent of a penetration testing large model enhanced by ATT and CK attack knowledge as claimed in claim 8, wherein The steps of step 3-2 are as follows: Step 3-2-1. Based on Q k and RResult retrieve the most relevant case abstracts; Step 3-2-2: Through the leaf nodes of the attack tactic tree associated with the case summary, trace back its branches to obtain the attack tactic sequence TAS k = TA 1 TA 2 … TA K 。 11. The intelligent agent of a penetration testing large model enhanced by ATT and CK attack knowledge as claimed in claim 8, wherein The steps of step 3-3 are as follows: Step 3-3-1: First, obtain the attack tactics TA k 's knowledge base; then, obtain the list of attack tools in the knowledge base, denoted as TTools ; Step 3-3-2: Organize the task requirements Q k , context information, and reconnaissance results RResult , the execution result of the previous attack tactic, and TA k description into a prompt, and input it TA k to the corresponding tactical agent. Let it gradually determine the attack behavior to be executed currently based on the chain-of-thought pattern, select the most suitable attack tool from TTools , generate the code to call the attack tool, and finally call the attack tool to implement the tactic; Step 3-3-3: If step 3-3-2 is successfully executed, the execution result is fed back to the supervisor agent, and the next tactical agent is called to implement the next attack tactic. If step 3-3-2 fails, the called attack tools are deleted from TTools and then step 3-3-2 is restarted. If all TTools attempts under this tactic still do not succeed in implementing this tactic, the failure information is fed back to the supervisor agent to terminate the penetration test in advance; Step 3-3-4: Repeatedly execute Step 3-3-1, Step 3-3-2, and Step 3-3-3 until TAS k all the attack tactics in
Citation Information
Patent Citations
Penetration test route planning method and device, electronic equipment and storage medium
CN117692252A
Standardized attack path automatic generation and verification method, device and system
CN118300906A