Penetration testing method and device, electronic equipment and storage medium
By using pre-trained large language models to automate the penetration testing process, the problems of low accuracy and low efficiency of traditional manual penetration testing are solved, and efficient identification and utilization of vulnerabilities in complex network environments are achieved, and the accuracy and efficiency of testing are improved.
Patent Information
- Application Number
- CN202510102861.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-16
AI Technical Summary
Traditional manual penetration testing has problems of low accuracy and low efficiency, especially in complex network environments, where critical vulnerabilities are easily missed and it is difficult to quickly adapt to new secondary vulnerability exploit attacks.
Using a pre-trained large language model, it automatically receives penetration test requests, obtains vulnerability information from the target host, selects the highest priority vulnerability for attack, obtains credential information, and conducts post-penetration tests until the end of the test instruction is received.
Through the automated identification and utilization of vulnerability chains of large language models, the accuracy and efficiency of penetration testing are improved, the dependence on manual experience is reduced, and new vulnerability attacks can be quickly adapted to new vulnerability attacks.
Smart Images

Figure CN120017339A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a penetration testing method, device, electronic device and storage medium. Background Art
[0002] With the rapid development of information technology, network penetration has become an important part of the field of network security technology. With the rapid development of information technology, network penetration has become an important part of the field of network security. Network penetration not only concerns the information security of enterprises and organizations, but also directly affects the privacy and data security of users. In the context of the current digital transformation, the network systems of various enterprises and organizations are facing increasingly complex and frequent network attacks, and network security issues are becoming more prominent. The frequent occurrence of data leaks caused by network attacks around the world has made the importance of penetration testing more and more obvious.
[0003] Penetration testing is a method of evaluating the security of network systems by simulating the attack methods of malicious hackers and finding security vulnerabilities in the IT infrastructure of an enterprise or organization. Penetration testers will try to exploit these vulnerabilities to evaluate the ability of network systems to resist attacks and make improvement suggestions to strengthen security measures. Penetration testing is an important part of information security management and risk assessment.
[0004] However, although traditional manual penetration testing is flexible in some aspects, it also has many shortcomings. First, the process of manual penetration testing is usually time-consuming and laborious. Penetration testers need to spend a lot of time on tasks such as information collection, vulnerability scanning, manual analysis, vulnerability verification, vulnerability exploitation, and lateral movement, resulting in a long penetration test cycle. Especially in complex network environments, manual processing methods are less efficient and it is easy to miss critical vulnerabilities. Secondly, manual penetration testing is highly dependent on the experience and expertise of testers, and this dependence is more prominent when performing vulnerability chain exploitation. The subjective differences in vulnerability identification and analysis among different testers may lead to inconsistent results, which in turn affects the accuracy and effectiveness of the test. In addition, with the continuous evolution of network attack technology, traditional manual penetration methods often find it difficult to quickly adapt to new secondary vulnerability exploitation attacks and cannot identify new vulnerabilities in a timely manner, resulting in increased security risks. Summary of the invention
[0005] In order to solve the problems of low accuracy and low efficiency of traditional penetration testing, the embodiments of the present application provide a penetration testing method, device, electronic device and storage medium.
[0006] In a first aspect, an embodiment of the present application provides a penetration testing method, comprising:
[0007] Receive a penetration test request sent by a client, wherein the penetration test request carries the IP address information of the target host;
[0008] Acquire vulnerability information of the target host according to the IP address information of the target host and the pre-trained large language model;
[0009] Selecting a first vulnerability from the vulnerability information of the target host;
[0010] Performing a vulnerability attack on the target host according to the first vulnerability and the large language model to obtain credential information of the target host;
[0011] A post-penetration test is performed on other hosts in the target network system to which the target host belongs according to the credential information of the target host and the large language model to obtain a test result.
[0012] In one implementation, obtaining vulnerability information of the target host according to the IP address information of the target host and a pre-trained large language model specifically includes:
[0013] The IP address information of the target host is input into the large language model, and a preset vulnerability scanning tool is called through the large language model to scan the vulnerability information of the target host.
[0014] In one embodiment, each vulnerability information of the target host includes at least proof-of-concept (POC) script information of the vulnerability and description information of the vulnerability, wherein the POC script of the vulnerability is a code showing how to exploit the vulnerability;
[0015] Selecting a first vulnerability from the vulnerability information of the target host specifically includes:
[0016] For each vulnerability of the target host, determine a risk level score of the vulnerability according to the possibility of exploitation of the vulnerability, whether the vulnerability is in the wild, and the activity of the vulnerability;
[0017] Determine the priority of each vulnerability according to its risk level score, and sort the vulnerabilities in descending order of priority;
[0018] The vulnerability with the highest priority is selected as the first vulnerability.
[0019] In one implementation, performing a vulnerability attack on the target host according to the first vulnerability and the large language model to obtain credential information of the target host specifically includes:
[0020] The POC script information of the first vulnerability and the description information of the first vulnerability are input into the large language model, and the vulnerability exploitation script corresponding to the POC script of the first vulnerability is called by the large language model to perform a vulnerability attack on the target host to obtain the credential information of the target host, wherein the vulnerability exploitation script is used to execute malicious operations corresponding to the first vulnerability.
[0021] In one embodiment, a post-penetration test is performed on other hosts in the target network system to which the target host belongs according to the credential information of the target host and the large language model to obtain a test result, which specifically includes:
[0022] Acquiring control authority of the target host according to the credential information of the target host, and invoking a preset tunnel establishment rule through the large language model to establish a tunnel between the target host and a designated host in the target network system;
[0023] Move laterally toward the designated host through the tunnel, and obtain vulnerability information of the designated host according to the large language model;
[0024] Selecting a second vulnerability from the vulnerability information of the designated host;
[0025] Performing a vulnerability attack on the designated host according to the second vulnerability and the large language model to obtain credential information of the designated host;
[0026] Performing a post-penetration test on the next host in the target network system according to the credential information of the designated host and the large language model until receiving an end-test instruction sent by the client to obtain a test result; and
[0027] Return a penetration test report to the client.
[0028] In a second aspect, an embodiment of the present application provides a penetration testing device, comprising:
[0029] A receiving module is used to receive a penetration test request sent by a client, wherein the penetration test request carries the IP address information of the target host;
[0030] A vulnerability scanning module, used to obtain vulnerability information of the target host according to the IP address information of the target host and a pre-trained large language model;
[0031] A selection module, configured to select a first vulnerability from the vulnerability information of the target host;
[0032] A vulnerability exploitation module, used to perform a vulnerability attack on the target host according to the first vulnerability and the large language model, and obtain credential information of the target host;
[0033] The chain exploitation module is used to perform a post-penetration test on other hosts in the target network system to which the target host belongs according to the credential information of the target host and the large language model to obtain a test result.
[0034] In one implementation, the vulnerability scanning module is specifically configured to input the IP address information of the target host into the large language model, and call a preset vulnerability scanning tool through the large language model to scan the vulnerability information of the target host.
[0035] In one embodiment, each vulnerability information of the target host includes at least proof-of-concept (POC) script information of the vulnerability and description information of the vulnerability, wherein the POC script of the vulnerability is a code showing how to exploit the vulnerability;
[0036] The selection module is specifically used to determine the risk level score of each vulnerability of the target host according to the possibility of exploitation of the vulnerability, whether the vulnerability is in the wild, and the activity of the vulnerability; determine the respective priorities of each vulnerability according to the risk level score, and sort the vulnerabilities in descending order of priority; and select the vulnerability with the highest priority as the first vulnerability.
[0037] In one embodiment, the vulnerability exploitation module is specifically used to input the POC script information of the first vulnerability and the description information of the first vulnerability into the large language model, and call the vulnerability exploitation script corresponding to the POC script of the first vulnerability through the large language model to perform a vulnerability attack on the target host, and obtain the credential information of the target host, wherein the vulnerability exploitation script is used to execute malicious operations corresponding to the first vulnerability.
[0038] In one embodiment, the chain exploit module is specifically used to obtain the control authority of the target host according to the credential information of the target host, and to establish a tunnel between the target host and a designated host in the target network system by calling a preset tunnel establishment rule through the large language model; to move laterally toward the designated host through the tunnel, and to obtain the vulnerability information of the designated host according to the large language model; to select a second vulnerability from the vulnerability information of the designated host; to perform a vulnerability attack on the designated host according to the second vulnerability and the large language model, and to obtain the credential information of the designated host; to perform a post-penetration test on the next host in the target network system according to the credential information of the designated host and the large language model, until an end-test instruction sent by the client is received to obtain a test result; and to return a penetration test report to the client.
[0039] In a third aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the penetration testing method described in the present application is implemented when the processor executes the program.
[0040] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, the steps in the penetration testing method described in the present application are implemented.
[0041] The beneficial effects of this application are as follows:
[0042] The penetration testing method, device, electronic device and storage medium provided by the embodiments of the present application, the server receives a penetration testing request sent by a client, the penetration testing request carries the IP address information of the target host, obtains the vulnerability information of the target host according to the IP (Internet Protocol) address information of the target host and a pre-trained large language model, selects a first vulnerability from the vulnerability information of the target host, performs a vulnerability attack on the target host according to the first vulnerability and the large language model, obtains the credential information of the target host, and performs a post-penetration test on other hosts in the target network system to which the target host belongs according to the credential information of the target host and the large language model to obtain a test result. In an embodiment of the present application, when the server performs a penetration test on a host in a target network system, it automatically obtains vulnerability information of the target host according to a pre-trained large language model, and after selecting a first vulnerability in the vulnerability information of the target host, it automatically performs vulnerability exploitation on the first vulnerability according to the large language model to launch a vulnerability attack on the target host and obtain the credential information of the target host. After obtaining the credential information of the target host, it automatically performs a post-penetration test on other hosts in the target network system based on the large language model. Thus, based on the understanding ability of the large language model, it realizes the automatic identification of potential vulnerability chains in the target network system, avoids reliance on manual experience, and improves the accuracy of the test while improving the attack efficiency and test efficiency.
[0043] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or be understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0045] Figure 1 A schematic diagram of an application scenario provided for an embodiment of the present application;
[0046] Figure 2 A schematic diagram of a penetration testing method provided in an embodiment of the present application;
[0047] Figure 3 A schematic diagram of a process for selecting a first vulnerability from vulnerability information of a target host provided in an embodiment of the present application;
[0048] Figure 4 A schematic diagram of a process for performing a post-penetration test on other hosts in a target network system provided in an embodiment of the present application;
[0049] Figure 5 A schematic diagram of the structure of a penetration testing device provided in an embodiment of the present application;
[0050] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0051] In order to solve the problems of low accuracy and low efficiency of traditional penetration testing, the embodiments of the present application provide a penetration testing method, device, electronic device and storage medium.
[0052] The preferred embodiments of the present application are described below in conjunction with the drawings in the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application. In addition, the embodiments and features in the embodiments of the present application may be combined with each other if there is no conflict.
[0053] In this article, it is necessary to understand that the technical terms involved in this application are:
[0054] 1. Large Language Model (LLM): It is a deep learning model with a large number of parameters and complex structure. These models can handle tasks such as natural language, text generation, image recognition, etc., and have strong learning and generation capabilities. In the field of network security, in this application, large language models are used for automated information collection, vulnerability identification and vulnerability exploitation.
[0055] 2. POC (Proof of Concept): refers to an experimental implementation that demonstrates or proves the effectiveness of a security vulnerability, attack method or protection technology. In the field of network security, POC is usually used to verify the existence of vulnerabilities, prove the feasibility of a new attack technology or defense method, and help security teams verify and understand network security risks. In the field of network security, POC usually refers to a short code or script that demonstrates how to exploit a specific vulnerability. Proof of concept is particularly important in the field of network security because it can be used to verify the existence of a vulnerability and the possibility of its exploitation. Security researchers will write POC scripts to demonstrate how to exploit a vulnerability, thereby prompting manufacturers to fix these vulnerabilities. This type of POC usually includes: (1) A short code or script that can trigger and exploit a vulnerability in the target network system. (2) A detailed description of the vulnerability, the affected system version, the conditions for exploitation, etc. (3) Possible mitigation measures or repair solutions, etc.
[0056] 3. Exploit (EXP): refers to code or tools written for a specific vulnerability, designed to exploit the vulnerability to perform malicious operations or obtain unauthorized access. EXP is often used in penetration testing and attack simulation to evaluate the security of the system. Therefore, EXP is also called a vulnerability exploitation tool and is one of the means of network attack.
[0057] Common types of vulnerability exploits include:
[0058] Remote Code Execution (RCE): An attacker can remotely execute arbitrary code.
[0059] Denial of Service (Denial of Service / Distributed Denial of Service DoS / DDoS): Making system or network resources unavailable.
[0060] Privilege Escalation: Elevating the privileges of a normal user to an administrator or other high-privilege user.
[0061] SQL (Structured Query Language) injection: Manipulating the database by inserting malicious SQL code into the input.
[0062] Cross-site scripting (XSS): Injecting malicious scripts into web pages to attack other users.
[0063] Buffer overflow: Writing more data than the capacity of a fixed-length buffer overwrites other data in memory, leading to the execution of malicious code.
[0064] 4. Chained vulnerability exploitation: This means that attackers use a series of different types of vulnerabilities to gradually penetrate the network system and eventually achieve their attack goals. This attack method is more complex than single vulnerability exploitation because it requires attackers to discover and combine multiple vulnerabilities, but it is also more difficult to defend because even if a single vulnerability is patched, attackers may still achieve their goals through other paths.
[0065] 5. Lateral movement in the intranet: This refers to the process whereby an attacker starts from the initial entry point of the network and spreads to other parts of the network through various means to infect more devices and servers. This process usually starts with the discovery of an entry point, such as an infected machine, stolen user credentials, or vulnerability exploits. The goal of the attacker is to move laterally without being detected, and even if they are detected on one device, they can maintain their presence in the network by infecting more devices.
[0066] 6. Vulnerabilities in the wild: refers to vulnerabilities that have been actually used by attackers in attacks. Unlike laboratory environments or theoretical vulnerabilities, vulnerabilities in the wild have already appeared in real-world attack activities and may have been widely exploited. This type of vulnerability poses a direct threat to enterprises and individuals because attackers are already actively using them to hack into systems, steal data, or perform other malicious activities.
[0067] 7. Vulnerability Activity: refers to the frequency and extent to which a particular vulnerability is exploited over a period of time. Vulnerability activity can help security teams prioritize those vulnerabilities that are most likely to be exploited by attackers, thereby allocating resources more effectively for repairs.
[0068] 8. Exploitability of vulnerabilities: refers to the extent to which vulnerabilities in existing network systems can be exploited by attackers, that is, the probability that the vulnerabilities can be exploited. To exploit a vulnerability, specific environmental or operating conditions are often required. For example, a network attack may require network connectivity between the target host and the attacker, while a physical access attack may require the attacker to directly access the target device.
[0069] 9. EPSS (Exploit Prediction Scoring System): Provides a new efficient, data-driven vulnerability management capability. EPSS is a data-driven effort that uses current threat information from CVE (Common Vulnerabilities and Exposures) and real-world vulnerability data. The EPSS model produces a probability score between 0 and 1 (0 to 100%), where the higher the score, the greater the probability that the vulnerability is exploited.
[0070] 10. Reverse Shell: This is a technique for sending shell commands to a remote machine. This technique is very useful when the remote machine is behind a firewall or something else. The way a reverse shell works is that the remote computer sends its shell to a specific user, rather than binding the shell to a port. The latter is inaccessible in many environments. In this way, root commands can be executed on the remote server. Reverse shells are often used by hackers to do some illegal activities. For example, after hacking into a server, they will set up a reverse shell, and in the future they will be able to easily access the remote computer through this shell.
[0071] 11. Backdoor: It is a malicious program or code that bypasses normal access control mechanisms and allows attackers to maintain persistent access and control rights in the target network system. Common types include:
[0072] In penetration testing, discovering and analyzing backdoors is crucial to assessing the security of target network systems. Penetration testers simulate hacker behavior to find backdoors in the system, identify potential security vulnerabilities, and provide repair suggestions. Detecting backdoors can help organizations discover and repair system risks and improve system security and defense capabilities.
[0073] Hackers use a variety of methods to leave backdoors, including exploiting known security vulnerabilities, obtaining credentials through social engineering, hiding malicious code in the system, etc. They use strategies such as remote access tools, modifying configuration files, manipulating services, or implanting code to provide a persistent channel for intrusion into the system.
[0074] In order to evade detection, hackers use encryption and obfuscation techniques to hide the intentions of malicious code. They exploit vulnerabilities to bypass security software and ensure that backdoors exist for a long time without being discovered. Identifying and removing backdoors is a key task in protecting system security. Penetration testers need to master different backdoor types, detection techniques and defense strategies.
[0075] First reference Figure 1, which is a schematic diagram of an application scenario of the penetration testing method provided in an embodiment of the present application, and may include a client 101, a server 102, and a target network system 103. The client 101 and the server 102 are connected via a communication network, and the server 102 and the target network system 103 are connected via a communication network. The server 102 includes a vulnerability verification module 1021, a path planning module 1022, a vulnerability exploitation module 1023, and a chain exploitation module 1024. The chain exploitation module may also be referred to as a post-penetration testing module. When the server 102 receives a penetration testing request for the target network system sent by the client 101, the vulnerability verification module 1021 obtains the service information, port information, and vulnerability information of the target host according to the IP address information of the target host carried in the penetration testing request and the pre-trained large language model, and sends the obtained service information, port information, and vulnerability information of the target host to the path planning module 1022. The path planning module 1022 determines the risk level score of each vulnerability of the target host according to the possibility of exploitation of the vulnerability, whether the vulnerability is in the wild, and the activity of the vulnerability, and then, according to the vulnerability level score, the vulnerability level score is calculated. Determine the priority of each vulnerability according to the risk level score of each vulnerability, and sort the vulnerabilities in descending order of priority, select the vulnerability with the highest priority, which can be recorded as the first vulnerability, and send the first vulnerability to the vulnerability exploitation module 1023. The vulnerability exploitation module 1023 performs a vulnerability attack on the target host according to the first vulnerability and the large language model, obtains the credential information of the target host, and then sends the obtained credential information of the target host to the chain exploitation module 1024. The chain exploitation module 1024 performs a post-penetration test on other hosts in the target network system to which the target host belongs according to the credential information of the target host and the large language model to obtain the test results. Thus, based on the understanding ability of the large language model, the potential vulnerability chain in the target network system is automatically identified, avoiding dependence on manual experience, and improving the accuracy of the test while improving the attack efficiency and test efficiency.
[0076] The server 102 may be an independent physical server or a cloud server that provides basic cloud computing services such as cloud servers, cloud databases, and cloud storage, which is not limited in the present embodiment. The target network system 103 may be a network system of any enterprise or organization, such as an intranet or local area network of an enterprise, and the host included in the target network system 103 may be any type of electronic device, such as a server, a terminal, a network device, etc., which is not limited in the present embodiment.
[0077] Based on the above application scenarios, the following will refer to the attached Figures 2 to 5The exemplary embodiments of the present application are described in more detail. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principle of the present application, and the implementation of the present application is not limited in any way. On the contrary, the implementation of the present application can be applied to any applicable scenario.
[0078] like Figure 2 As shown, it is a schematic diagram of the implementation process of the penetration testing method provided in the embodiment of the present application. The penetration testing method can be applied to the above-mentioned server 102, and specifically may include the following steps:
[0079] S21. The server receives a penetration test request sent by the client, where the penetration test request carries the IP address information of the target host.
[0080] In specific implementation, the client sends a penetration test request for the target network system to the server, and the penetration test request carries the IP address information of the target host, wherein the target host can be any host in the target network system, which is the starting device for the client to request the server to perform a penetration test on the target network system. The server receives the penetration test request sent by the client.
[0081] S22. Obtain vulnerability information of the target host based on the IP address information of the target host and the pre-trained large language model.
[0082] During specific implementation, the server may pre-train a large language model using large-scale natural text data. The large language model can understand and generate natural language text. The large language model can, but is not limited to, use any of the following series of models: Qwen series models, GLM series models, DeepSeek series models, etc., which are not limited in the embodiments of the present application. The server pre-packages various information collection tools and vulnerability scanning tools APIs (Application Programming Interface), wherein the information collection tools include: port scanning tools, subdomain collection tools, fingerprint recognition tools, etc., and the vulnerability scanning tools include: Web vulnerability scanning tools, service blasting tools, host vulnerability scanning tools, etc.
[0083] When the server receives the penetration test request sent by the client, it can obtain the service information and port information of the target host, as well as the vulnerability information of the target host, based on the IP address information of the target host and the pre-trained large language model. Among them, the service information of the target host may include: the service type and version information, operating system information, etc. included in the target host, and the port information of the target host is the port information opened by the target host. The vulnerability information of the target host may at least include: the POC script information of the vulnerability and the description information of the vulnerability. The POC script of the vulnerability is the code that shows how to exploit the vulnerability. Each vulnerability has its corresponding POC script, and may also include other vulnerability-related information, which is not limited in the embodiments of the present application.
[0084] Specifically, the server can input the IP address information of the target host into the large language model, and call the preset information collection tool through the large language model to collect the service information and port information of the target host, and can also collect other information related to the target host, such as domain name information. At the same time, the server can call the preset vulnerability scanning tool through the large language model to scan the vulnerability information of the target host. When collecting information related to the target host, multi-threading and parallel processing can be used to improve the efficiency of information collection.
[0085] During implementation, when a user sends a penetration test request to a server through a client, an operation instruction can also be input into the client, which is then sent to the server. When the server receives the penetration test request and operation instruction sent by the client, the IP address information and operation instruction of the target host carried in the penetration test request are input into the large language model to obtain information related to the target host and vulnerability information of the target host. The operation instruction is used to inform the large language model of the operation to be performed. For example, the operation instruction input into the large language model includes: "collect the service information, port information and subdomain information of the domain name 'XXX' of the target host", and "scan the vulnerability information of the target host". After receiving the above operation instructions and the IP address information of the target host, the large language model has a preliminary understanding of the current penetration environment, which includes: Web vulnerability environment, host vulnerability environment, weak password environment, etc., and can automatically call the corresponding tools to obtain corresponding information, including: known system information, obtained access rights and existing vulnerability exploitation. For example, the vulnerability scanning tool is called through the large language model to collect service information such as the service type and version information contained in the target host, the operating system information of the target host, etc. according to the IP address information of the target host. The port scanning tool is called through the large language model to perform port scanning on the target host according to the IP address information of the target host, and the port information developed by the target host is collected. The subdomain collection tool is called through the large language model to collect the subdomain information corresponding to the domain name 'XXX' according to the IP address information of the target host. The host vulnerability scanning tool is called through the large language model to scan the vulnerability information existing in the target host according to the IP address information of the target host, including the POC script information of the vulnerability and the description information of the vulnerability.
[0086] In an embodiment of the present application, the vulnerability verification module in the server uses a large language model to implement information collection and vulnerability detection involving a variety of complex subtasks, which may include: subdomain collection, port scanning, fingerprint recognition, URL (Uniform Resource Location) crawler, Web vulnerability scanning, service blasting, host vulnerability scanning, etc. During implementation, the operation instructions of the tasks to be performed can be input into the large language model according to actual needs, and the large language model can intelligently call the corresponding information collection tools and vulnerability scanning tools to obtain the corresponding information.
[0087] In the embodiment of the present application, in addition to information collection and vulnerability scanning, the large language model can also call other pre-packaged tools, such as Base encoding and decoding tools, URL encoding and decoding tools, hexadecimal encoding and decoding tools, etc., involving string processing, encoding conversion, and data query tasks. The large language model can use its text processing and algorithm implementation capabilities to perform these functions by calling the API of the corresponding tool.
[0088] S23. Select a first vulnerability from the vulnerability information of the target host.
[0089] When implementing it specifically, you can follow the following steps: Figure 3 The process shown selects the first vulnerability from the vulnerability information of the target host, including the following steps:
[0090] S31. For each vulnerability of the target host, determine the risk level score of the vulnerability based on the possibility of exploitation of the vulnerability, whether the vulnerability is in the wild, and the activity of the vulnerability.
[0091] In specific implementation, the path planning module in the server can determine the respective priorities according to the risk level scores of the vulnerabilities of the target host, and sort the vulnerabilities of the target host in order of priority.
[0092] Specifically, for each vulnerability of the target host, the probability score of the vulnerability being exploited is queried from the Vulnerability Exploitation Prediction Scoring System (EPSS), and the corresponding status score is determined according to whether the vulnerability is in the wild, and the activity score of the vulnerability is determined according to the preset correspondence between the vulnerability and the vulnerability activity score. The probability score of the vulnerability being exploited, the status score corresponding to the vulnerability, and the activity score of the vulnerability are weighted and summed to obtain the risk level score of the vulnerability. The risk level of the vulnerability represents the degree of vulnerability risk.
[0093] During implementation, if the vulnerability status is "in the wild", the status score corresponding to the vulnerability can be set to 70 points, and if the vulnerability status is "not in the wild", the status score corresponding to the vulnerability can be set to 30 points. This embodiment of the present application does not limit this. The higher the activity of the vulnerability, the higher the activity score of the vulnerability, and the lower the activity of the vulnerability, the lower the activity score of the vulnerability. For example, the activity score of a vulnerability with high activity can be set to 80 points, the activity score of a vulnerability with average activity can be set to 50 points, and the activity score of a vulnerability with low activity can be set to 20 points. This embodiment of the present application does not determine this.
[0094] Specifically, the risk level score of the vulnerability can be calculated by the following formula:
[0095] T=αA+βB+γC
[0096] Where T represents the risk level score of the vulnerability;
[0097] A represents the probability score of the vulnerability being exploited, and α represents the weight of the probability score of the vulnerability being exploited;
[0098] B represents the status score corresponding to the vulnerability, and β represents the weight of the status score corresponding to the vulnerability;
[0099] C represents the activity score of the vulnerability, and γ represents the weight of the activity score of the vulnerability.
[0100] Among them, α+β+γ=1. During implementation, the values of α, β, and γ can be set according to the probability score of the vulnerability being exploited, the status score corresponding to the vulnerability, and the importance of the vulnerability's activity score.
[0101] Thus, the risk level score corresponding to each vulnerability of the target host can be obtained.
[0102] S32. Determine the priority of each vulnerability according to the risk level score of each vulnerability, and sort the vulnerabilities in descending order of priority.
[0103] During specific implementation, the path planning module in the server can determine the priority of each vulnerability according to the risk level score of each vulnerability. The vulnerability with a higher risk level score has a higher priority. The vulnerabilities are sorted in order from high to low priority, that is, the vulnerabilities are sorted in order from large to small according to the risk level score. During implementation, the vulnerabilities can also be sorted in order from small to large priority, and the embodiments of the present application are not limited to this.
[0104] S33. Select the vulnerability with the highest priority as the first vulnerability.
[0105] During specific implementation, the path planning module in the server selects the vulnerability with the highest priority, that is, the vulnerability with the highest risk level score, as the first vulnerability.
[0106] S24: Perform a vulnerability attack on the target host according to the first vulnerability and the large language model to obtain credential information of the target host.
[0107] In specific implementation, the server pre-stores the corresponding relationship between the vulnerability POC script and the vulnerability exploitation script (ie, EXP script). The vulnerability POC script is the code showing how to exploit the vulnerability, and the vulnerability exploitation script is used to perform the malicious operation corresponding to the vulnerability. The server pre-packages the APIs of various vulnerability exploitation tools (ie, vulnerability exploitation scripts).
[0108] Specifically, the vulnerability exploitation module in the server inputs the POC script information of the first vulnerability and the description information of the first vulnerability into the large language model, and calls the vulnerability exploitation script corresponding to the POC script of the first vulnerability through the large language model to attack the target host, obtain the credential information of the target host, thereby obtaining the control authority of the target host and completing the initial penetration of the target host. Among them, the vulnerability exploitation script is used to execute the malicious operation corresponding to the first vulnerability. The credential information of the target host includes: the username and password information of the target host, and may also include sensitive information such as user identity information, mobile phone number, name, password, password, certificate, etc. when logging into the web page. Once the vulnerability is successfully exploited, these sensitive information will be leaked. In this step, LLM automatically collects credential information (such as username, password, API key, etc.) from the target system. Through semantic analysis, it can effectively filter redundant information and find the most critical authentication credentials. Through credential collection, the attacker can obtain more access rights in the subsequent process, thereby conducting further penetration and attack.
[0109] S25. Perform a post-penetration test on other hosts in the target network system to which the target host belongs according to the credential information of the target host and the large language model to obtain a test result.
[0110] When implementing it specifically, you can follow the following steps: Figure 4 The process shown performs post-penetration testing on other hosts in the target network system to which the target host belongs, and includes the following steps:
[0111] S41. Obtain control authority of the target host according to the credential information of the target host, and establish a tunnel between the target host and a designated host in the target network system by calling a preset tunnel establishment rule through a large language model.
[0112] In the specific implementation, in the post-penetration test, after the attacker obtains the control authority of a target host in the target network system, he attacks other hosts in the target network system by establishing tunnels with other hosts in the target network system. In the embodiment of the present application, the post-penetration test process is automated by a large language model to improve the efficiency and accuracy of lateral movement. The server pre-packages an API for preset tunnel establishment rules. The tunnel establishment rules may include but are not limited to: reverse shell establishment process, VPN tunnel establishment process and SSL tunnel establishment process, etc., which are not limited in the embodiment of the present application.
[0113] During implementation, after the vulnerability exploitation module in the server obtains the control authority of the target host according to the credential information of the target host, it can return preliminary penetration result information to the client, that is: for the success information of the first vulnerability exploitation, the user inputs the IP address information of the designated host in the target network system to the client, and inputs the operation instruction, the client sends the IP address information and operation instruction of the designated host to the chain exploitation module in the server, and the chain exploitation module inputs the IP address information and operation instruction of the designated host into the large language model, wherein the operation instruction can be "execute the secondary chain exploitation of the vulnerability", and the large language model calls the preset tunnel establishment rule through the large language model to establish a tunnel between the target host and the designated host, wherein the preset tunnel establishment rule can be any one of the aforementioned tunnel establishment rules, and the large language model can automatically select intelligently. In the process of intelligently establishing a tunnel, the large language model can identify the user's specific needs and intentions according to the operation instruction input by the user, and the user can also specify the type of tunnel establishment to be adopted. The large language model calls the tunnel establishment tool specified by the user to establish the tunnel, and automatically executes the tunnel establishment process according to the characteristics of the current penetration test environment. The embodiment of the present application does not limit this.
[0114] S42. Move laterally to the designated host through the tunnel, and obtain vulnerability information of the designated host according to the large language model.
[0115] In specific implementation, after the tunnel between the target host and the designated host is successfully established, the established tunnel is used to move laterally toward the designated host to perform secondary chain exploitation of the vulnerability. The chain exploitation module obtains the vulnerability information of the designated host based on the IP address information and the large language model of the designated host. The implementation process can refer to the implementation of step S22 and will not be repeated here.
[0116] S43. Select a second vulnerability from the vulnerability information of the designated host.
[0117] In specific implementation, the server selects the vulnerability with the highest priority as the second vulnerability according to the risk level of each vulnerability of the designated host. The implementation of this step can refer to the implementation of step S23, which will not be described in detail here.
[0118] S44. Perform a vulnerability attack on the designated host according to the second vulnerability and the large language model to obtain credential information of the designated host.
[0119] In specific implementation, the chain exploitation module inputs the POC script information of the second vulnerability and the description information of the second vulnerability into the large language model, and calls the vulnerability exploitation script corresponding to the POC script of the second vulnerability through the large language model to attack the designated host, obtain the credential information of the designated host, and thus obtain the control authority of the designated host, and complete the secondary chain exploitation of the designated host, that is, the post-penetration of the designated host. The implementation of this step can refer to the implementation of step S24, which will not be repeated here.
[0120] S45. Perform a post-penetration test on the next host in the target network system according to the credential information and the large language model of the designated host, until receiving an end-test instruction sent by the client, and obtaining a test result.
[0121] In specific implementation, after the secondary chain exploitation is successful, the vulnerability exploitation module obtains the control authority of the designated host according to the credential information of the designated target host, and then returns the successful secondary vulnerability chain exploitation information to the client. If it is necessary to continue to execute the next level of vulnerability chain exploitation process, the user can input the IP address information of the next host in the target network system to the client, and input the operation instruction. The client sends the IP address information and the operation instruction of the next host to the chain exploitation module in the server, and the chain exploitation module inputs the IP address information and the operation instruction of the next host into the large language model, wherein the operation instruction can be "execute the third level chain exploitation of the vulnerability", and the large language model calls the preset tunnel establishment rule through the large language model to establish a tunnel between the designated host and the next host for post-penetration testing, until receiving the end test instruction sent by the client, and obtaining the test result. If the end test instruction of the client is not received, the server can also automatically end the penetration test process when the test termination condition is met, wherein the test termination condition can include but is not limited to: when the vulnerability scanning tool called by the large language model does not scan the vulnerability information in other hosts in the target network system, it can be determined that the test termination condition is met. The implementation process of post-infiltration can refer to the implementation of steps S42 to S44, which will not be described in detail here.
[0122] In the post-penetration process, the large language model can call the vulnerability scanning tool again based on the obtained credential information and the operation instructions entered by the user and discover new attacked targets (other hosts in the target network system), that is, to achieve intelligent lateral movement through the existing credential information. In addition, the large language model can give priority to the most vulnerable hosts and dynamically adjust the attack strategy. After obtaining the information of the next host for lateral movement, the large language model can intelligently call the API interface information of the post-penetration tool (such as the vulnerability exploitation tool) according to the status of the current penetration test environment, the exploited vulnerabilities, the historical penetration test data, and the user's needs, and complete the post-penetration process.
[0123] In order to ensure a continuous penetration process, the server pre-packages the API of the backdoor tool or persistence tool. When executing the post-penetration process, the server can intelligently select the appropriate backdoor tool or persistence tool based on the defense situation of the current penetration test environment through a large language model, and install it on the host selected for vulnerability exploitation, thereby ensuring that the attack and control of the target network system can be maintained for a long time.
[0124] In the embodiment of the present application, the intelligent tool call based on the large language model mainly relies on natural language processing and context understanding capabilities. First, the information input by the user is parsed to identify its intentions and needs, and then the most appropriate tool is automatically selected for call based on the predefined tool library. During the execution process, the large language model can adjust the call strategy in real time. For example, if the EXP tool call corresponding to the selected vulnerability to be exploited fails, the next vulnerability with the highest priority can be selected to execute the subsequent vulnerability exploitation process, thereby optimizing the operation process and improving the efficiency of penetration testing. In this way, not only is manual intervention reduced, but the accuracy and response speed of tool selection can also be continuously improved through data analysis and learning.
[0125] S46. Return the penetration test report to the client.
[0126] In specific implementation, when the penetration test is completed, the large language model can generate a detailed attack report of the entire penetration test process (also known as the penetration test report), which records each step of the operation, the permissions obtained, the vulnerabilities exploited, the recommended repair and defense solutions, etc. The penetration test report is automatically produced by the large language model, reducing the time for manual analysis. The server returns the penetration test report to the client.
[0127] In the embodiment of the present application, the large language model learns new penetration strategies and vulnerability exploitation techniques from each penetration test, improves the efficiency and accuracy of its subsequent penetration, and continuously optimizes the large language model by continuously updating the vulnerability library and attack mode, making the next penetration test more accurate and efficient. During the entire post-penetration process, the large language model can automatically select suitable tools according to user needs, and automatically execute corresponding penetration commands according to the input context to reduce the manual intervention of testers. Through the implementation of this intelligent chain-based exploitation module, the large language model can effectively exploit weaknesses and loopholes in the network, further penetrate the target network system and implement higher-level attacks.
[0128] The penetration testing method provided by the embodiment of the present application comprises the following steps: a server receives a penetration testing request sent by a client, the penetration testing request carries the IP address information of the target host, obtains the vulnerability information of the target host according to the IP address information of the target host and a pre-trained large language model, selects a first vulnerability from the vulnerability information of the target host, performs a vulnerability attack on the target host according to the first vulnerability and the large language model, obtains the credential information of the target host, performs a post-penetration test on other hosts in the target network system to which the target host belongs according to the credential information of the target host and the large language model, and obtains a test result. In an embodiment of the present application, when the server performs a penetration test on a host in a target network system, it automatically obtains vulnerability information of the target host according to a pre-trained large language model, and after selecting a first vulnerability in the vulnerability information of the target host, it automatically performs vulnerability exploitation on the first vulnerability according to the large language model to launch a vulnerability attack on the target host and obtain the credential information of the target host. After obtaining the credential information of the target host, it automatically performs a post-penetration test on other hosts in the target network system based on the large language model. Thus, based on the understanding ability of the large language model, it realizes the automatic identification of potential vulnerability chains in the target network system, avoids reliance on manual experience, and improves the accuracy of the test while improving the attack efficiency and test efficiency.
[0129] Based on the same inventive concept, an embodiment of the present application also provides a penetration testing device. Since the principle of solving the problem by the above-mentioned penetration testing device is similar to that of the above-mentioned penetration testing method, the implementation of the above-mentioned device can refer to the implementation of the method, and the repeated parts will not be repeated.
[0130] like Figure 5 As shown, it is a schematic diagram of the structure of the penetration testing device provided in the embodiment of the present application, and the penetration testing device can be applied to Figure 1 In the server 102 shown, the device may include:
[0131] The receiving module 51 is used to receive a penetration test request sent by a client, wherein the penetration test request carries the IP address information of the target host;
[0132] A vulnerability scanning module 52, used to obtain vulnerability information of the target host according to the IP address information of the target host and a pre-trained large language model;
[0133] A selection module 53, configured to select a first vulnerability from the vulnerability information of the target host;
[0134] A vulnerability exploitation module 54, configured to perform a vulnerability attack on the target host according to the first vulnerability and the large language model, and obtain credential information of the target host;
[0135] The chain exploitation module 55 is used to perform a post-penetration test on other hosts in the target network system to which the target host belongs according to the credential information of the target host and the large language model to obtain a test result.
[0136] In one implementation, the vulnerability scanning module 52 is specifically configured to input the IP address information of the target host into the large language model, and call a preset vulnerability scanning tool through the large language model to scan the vulnerability information of the target host.
[0137] In one embodiment, each vulnerability information of the target host includes at least proof-of-concept (POC) script information of the vulnerability and description information of the vulnerability, wherein the POC script of the vulnerability is a code showing how to exploit the vulnerability;
[0138] The selection module 53 is specifically used to determine the risk level score of each vulnerability of the target host according to the possibility of exploitation of the vulnerability, whether the vulnerability is in the wild, and the activity of the vulnerability; determine the respective priorities of each vulnerability according to the risk level score, and sort the vulnerabilities in descending order of priority; and select the vulnerability with the highest priority as the first vulnerability.
[0139] In one embodiment, the vulnerability exploitation module 54 is specifically used to input the POC script information of the first vulnerability and the description information of the first vulnerability into the large language model, and call the vulnerability exploitation script corresponding to the POC script of the first vulnerability through the large language model to perform a vulnerability attack on the target host, and obtain the credential information of the target host, wherein the vulnerability exploitation script is used to execute malicious operations corresponding to the first vulnerability.
[0140] In one embodiment, the chain exploit module 55 is specifically used to obtain the control authority of the target host according to the credential information of the target host, and to establish a tunnel between the target host and a designated host in the target network system by calling a preset tunnel establishment rule through the large language model; to move laterally toward the designated host through the tunnel, and to obtain the vulnerability information of the designated host according to the large language model; to select a second vulnerability from the vulnerability information of the designated host; to perform a vulnerability attack on the designated host according to the second vulnerability and the large language model, and to obtain the credential information of the designated host; to perform a post-penetration test on the next host in the target network system according to the credential information of the designated host and the large language model, until receiving an end test instruction sent by the client to obtain a test result; and to return a penetration test report to the client.
[0141] Based on the same technical concept, the present application embodiment also provides an electronic device 600, referring to Figure 6 As shown, the electronic device 600 is used to implement the penetration testing method described in the above method embodiment. The electronic device 600 of this embodiment may include: a memory 601, a processor 602, and a computer program stored in the memory and executable on the processor, such as a penetration testing program. When the processor executes the computer program, the steps in the above penetration testing method embodiments are implemented.
[0142] The specific connection medium between the memory 601 and the processor 602 is not limited in the embodiment of the present application. Figure 6 In the embodiment, the memory 601 and the processor 602 are connected via a bus 603. The bus 603 is Figure 6 The connection between other components is shown by bold lines, which is only for schematic illustration and is not intended to be limiting. The bus 603 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0143] The memory 601 may be a volatile memory, such as a random-access memory (RAM); the memory 601 may also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD), or the memory 601 may be any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 601 may be a combination of the above memories.
[0144] Processor 602 is used to implement the penetration testing method provided in the embodiment of the present application.
[0145] An embodiment of the present application also provides a computer-readable storage medium that stores computer-executable instructions required to execute the above-mentioned processor, which includes a program required to execute the above-mentioned processor.
[0146] In some possible implementations, various aspects of the penetration testing method provided by the present application may also be implemented in the form of a program product, which includes a program code. When the program product is run on an electronic device, the program code is used to enable the electronic device to execute the steps of the penetration testing method according to various exemplary embodiments of the present application described above in this specification.
[0147] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, devices, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0148] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (apparatus), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0149] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0150] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0151] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.
[0152] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. A penetration testing method, characterized in that: include: Receive a penetration test request sent by a client, wherein the penetration test request carries the IP address information of the target host; Acquire vulnerability information of the target host according to the IP address information of the target host and the pre-trained large language model; Selecting a first vulnerability from the vulnerability information of the target host; Performing a vulnerability attack on the target host according to the first vulnerability and the large language model to obtain credential information of the target host; A post-penetration test is performed on other hosts in the target network system to which the target host belongs according to the credential information of the target host and the large language model to obtain a test result.
2. The method according to claim 1, characterized in that According to the IP address information of the target host and the pre-trained large language model, the vulnerability information of the target host is obtained, specifically including: The IP address information of the target host is input into the large language model, and a preset vulnerability scanning tool is called through the large language model to scan the vulnerability information of the target host.
3. The method according to claim 1, characterized in that Each vulnerability information of the target host includes at least proof-of-concept (POC) script information of the vulnerability and description information of the vulnerability, wherein the POC script of the vulnerability is a code showing how to exploit the vulnerability; Selecting a first vulnerability from the vulnerability information of the target host specifically includes: For each vulnerability of the target host, determine a risk level score of the vulnerability according to the possibility of exploitation of the vulnerability, whether the vulnerability is in the wild, and the activity of the vulnerability; Determine the priority of each vulnerability according to its risk level score, and sort the vulnerabilities in descending order of priority; The vulnerability with the highest priority is selected as the first vulnerability.
4. The method according to claim 3, characterized in that Performing a vulnerability attack on the target host according to the first vulnerability and the large language model to obtain credential information of the target host specifically includes: The POC script information of the first vulnerability and the description information of the first vulnerability are input into the large language model, and the vulnerability exploitation script corresponding to the POC script of the first vulnerability is called by the large language model to perform a vulnerability attack on the target host to obtain the credential information of the target host, wherein the vulnerability exploitation script is used to execute malicious operations corresponding to the first vulnerability.
5. The method according to any one of claims 1 to 4, characterized in that: Performing a post-penetration test on other hosts in the target network system to which the target host belongs according to the credential information of the target host and the large language model, and obtaining a test result, specifically including: Acquiring control authority of the target host according to the credential information of the target host, and invoking a preset tunnel establishment rule through the large language model to establish a tunnel between the target host and a designated host in the target network system; Move laterally toward the designated host through the tunnel, and obtain vulnerability information of the designated host according to the large language model; Selecting a second vulnerability from the vulnerability information of the designated host; Performing a vulnerability attack on the designated host according to the second vulnerability and the large language model to obtain credential information of the designated host; Performing a post-penetration test on the next host in the target network system according to the credential information of the designated host and the large language model until receiving an end-test instruction sent by the client to obtain a test result; and A penetration test report is returned to the client.
6. A penetration testing device, characterized in that: include: A receiving module is used to receive a penetration test request sent by a client, wherein the penetration test request carries the IP address information of the target host; A vulnerability scanning module, used to obtain vulnerability information of the target host according to the IP address information of the target host and a pre-trained large language model; A selection module, configured to select a first vulnerability from the vulnerability information of the target host; A vulnerability exploitation module, used to perform a vulnerability attack on the target host according to the first vulnerability and the large language model, and obtain credential information of the target host; The chain exploitation module is used to perform a post-penetration test on other hosts in the target network system to which the target host belongs according to the credential information of the target host and the large language model to obtain a test result.
7. The device according to claim 6, characterized in that The vulnerability scanning module is specifically used to input the IP address information of the target host into the large language model, and call a preset vulnerability scanning tool through the large language model to scan the vulnerability information of the target host.
8. The device according to claim 6, characterized in that Each vulnerability information of the target host includes at least proof-of-concept (POC) script information of the vulnerability and description information of the vulnerability, wherein the POC script of the vulnerability is a code showing how to exploit the vulnerability; The selection module is specifically used to determine, for each vulnerability of the target host, a risk level score of the vulnerability according to the possibility of exploitation of the vulnerability, whether the vulnerability is in the wild, and the activity of the vulnerability; Determine the respective priorities of the vulnerabilities according to their risk level scores, and sort the vulnerabilities in descending order of priority; and select the vulnerability with the highest priority as the first vulnerability.
9. The device according to claim 8, characterized in that The vulnerability exploitation module is specifically used to input the POC script information of the first vulnerability and the description information of the first vulnerability into the large language model, and call the vulnerability exploitation script corresponding to the POC script of the first vulnerability through the large language model to attack the target host and obtain the credential information of the target host, wherein the vulnerability exploitation script is used to execute the malicious operation corresponding to the first vulnerability.
10. The device according to any one of claims 6 to 9, characterized in that: The chain exploitation module is specifically used to obtain the control authority of the target host according to the credential information of the target host, and to establish a tunnel between the target host and a designated host in the target network system by calling a preset tunnel establishment rule through the large language model; Move laterally toward the designated host through the tunnel, and obtain vulnerability information of the designated host according to the large language model; A second vulnerability is selected from the vulnerability information of the designated host; a vulnerability attack is performed on the designated host according to the second vulnerability and the large language model to obtain the credential information of the designated host; a post-penetration test is performed on the next host in the target network system according to the credential information of the designated host and the large language model until an end-test instruction sent by the client is received to obtain a test result; and a penetration test report is returned to the client.
11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the penetration testing method according to any one of claims 1 to 5 is implemented.
12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the penetration testing method as described in any one of claims 1 to 5 are implemented.
Citation Information
Cited By
Automatic penetration testing method and device based on large model driving
CN120602171A
Penetration test method and device for security evaluation of network information system
CN121283773A