Automatic vulnerability scanning template generation method and device based on large language model
By applying an automation method of large language models in the field of network security, the proof of concept is directly converted into a vulnerability scanning template, which solves the problem of complex and inefficient conversion process in the existing technology and achieves efficient automated generation.
Patent Information
- Application Number
- CN202510707210.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-05-29
AI Technical Summary
Prior art When converting proof of concept (PoC) into vulnerability scanning templates, the process is complex and inefficient, requiring manual analysis and conversion by security experts.
Using an automated approach based on a large language model, a step-by-step conversion process is performed through three collaborative large language model agents (requesting agent, judgment agent and extraction agent) to directly convert the proof of concept into a vulnerability scanning template.
The automatic generation of vulnerability scanning templates is realized, which significantly improves the generation efficiency and reduces manual intervention and error occurrence.
Smart Images

Figure CN120223448A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular, to an automated vulnerability scanning template generation method and device based on a large language model. Background Art
[0002] Penetration testing, as a key component of modern network security strategies, identifies and resolves potential security vulnerabilities through simulated attacks to prevent their malicious exploitation. Among them, the vulnerability scanning phase is crucial for detecting possible security weaknesses, and it relies on predefined rules to guide the discovery process.
[0003] However, developing and maintaining these scanning rules pose significant difficulties. Although the network security community has publicly released various Proof-of-Concept (PoC) demonstrations, converting these diverse PoCs into standardized scanning templates is both complex and time-consuming. Security experts must analyze and convert various PoCs, including different programming language codes, natural language descriptions, and various types of structured information, to meet the requirements of vulnerability scanning frameworks such as Nuclei or PocSuite.
[0004] Based on this, there is an urgent need for an automated vulnerability scanning template generation method that directly converts the Proof-of-Concept PoC into a vulnerability scanning template, automates the process, and improves the generation efficiency of vulnerability scanning templates. Summary of the Invention
[0005] The purpose of this application is to provide an automated vulnerability scanning template generation method and device based on a large language model, which uses three collaborative large language model agents to perform a step-by-step conversion process, realizes the automated conversion of Proof-of-Concept to vulnerability scanning templates, and greatly improves the generation efficiency of vulnerability scanning templates.
[0006] This application provides an automated vulnerability scanning template generation method based on a large language model, including: Obtain the Proof-of-Concept corresponding to the target vulnerability, and generate vulnerability interaction overview information based on the Proof-of-Concept; the vulnerability interaction overview information is used to characterize the execution order and dependency relationship of at least one vulnerability interaction process; in any one vulnerability interaction process, use a request agent to generate a request payload according to the vulnerability interaction overview information, use a judgment agent to extract key fragment information in the vulnerability interaction process when judging that the request payload is valid, and use an extraction agent to generate a verification rule according to the key fragment information; based on the request payload and verification rule obtained in each vulnerability interaction process, generate a vulnerability scanning template for the target vulnerability.
[0007] Optionally, generating vulnerability interaction overview information based on the proof of concept includes: generating the vulnerability verification interaction overview information corresponding to the target vulnerability by using a large language model based on the proof of concept; wherein, the vulnerability interaction overview information is text information containing multiple entries, and each entry contains vulnerability trigger association information; the vulnerability trigger association information includes: interaction purpose, dependent steps, and expected response.
[0008] Optionally, using a request proxy to generate a request payload according to the vulnerability interaction overview information includes: using the request proxy to analyze the proof of concept, the vulnerability interaction overview information, and variables in a variable set to generate a request payload and interaction elements corresponding to the current vulnerability interaction process; wherein, the interaction elements include: target address, called method, request header information, and request data; the request payload is used to interact with the vulnerability test environment to trigger the target vulnerability.
[0009] Optionally, the verification rules include: matching rules and extraction rules; using a judgment proxy to extract key fragment information in the vulnerability interaction process when determining that the request payload is valid, and using an extraction proxy to generate verification rules according to the key fragment information includes: generating a vulnerability interaction request containing the request payload corresponding to the current vulnerability interaction process based on the interaction elements; performing a vulnerability interaction with the vulnerability test environment based on the vulnerability interaction request to obtain vulnerability interaction response information, and using the judgment proxy to determine that the request payload is valid when determining that the target vulnerability is triggered based on the vulnerability interaction response information; when determining that the request payload is valid, extracting key fragment information from the request data included in the vulnerability interaction request and the vulnerability interaction response information; using the extraction proxy to analyze the key fragment information in the current vulnerability interaction process to generate the matching rules and extraction rules corresponding to the current vulnerability interaction process; wherein, the matching rules are used to verify whether the target vulnerability is triggered; the extraction rules are used to extract field data required for subsequent vulnerability interaction processes.
[0010] Optionally, the vulnerability interaction request carries a remote control instruction; the step of performing vulnerability interaction with a vulnerability range environment based on the vulnerability interaction request to obtain vulnerability interaction response information, and using the evaluation agent to determine that the request payload is valid when it is determined based on the vulnerability interaction response information that the target vulnerability is triggered, includes: performing vulnerability interaction with a target host in the vulnerability range environment based on the vulnerability interaction request to obtain vulnerability interaction response information; using the evaluation agent to analyze the vulnerability interaction response information, and if the vulnerability interaction response information contains status information feedback by an out-of-band server, determining that the request payload is valid; wherein, the remote control instruction is: a remote command executed by the target host when the vulnerability is triggered; when the target host executes the remote control instruction, it sends any network access request to the out-of-band server; the status information is: information feedback by the out-of-band server after receiving the network access request.
[0011] Optionally, after the extraction agent generates a verification rule according to the key fragment information, the method further includes: using the extraction rule to extract field data required for subsequent vulnerability interaction processes from the vulnerability interaction response information, and adding the extracted field data to the variable set.
[0012] Optionally, generating a vulnerability scanning template for the target vulnerability based on the request payload and verification rule corresponding to each vulnerability interaction process includes: generating a vulnerability scanning template for the target vulnerability based on vulnerability interaction meta-information, the request payload corresponding to each vulnerability interaction process, the matching rule corresponding to each vulnerability interaction process, and the extraction rule corresponding to each vulnerability interaction process; wherein, the vulnerability interaction meta-information is generated based on the proof of concept corresponding to the target vulnerability, and the vulnerability interaction meta-information includes the Common Vulnerability Disclosure number of the target vulnerability.
[0013] This application also provides an automated vulnerability scanning template generation device based on a large language model, including: An information acquisition module, configured to acquire a proof of concept corresponding to a target vulnerability and generate vulnerability interaction overview information based on the proof of concept; the vulnerability interaction overview information is used to characterize the execution order and dependency relationship of at least one vulnerability interaction process; a vulnerability interaction module, configured to, in any one vulnerability interaction process, use a request agent to generate a request payload according to the vulnerability interaction overview information, use an evaluation agent to extract key fragment information in the vulnerability interaction process when it is determined that the request payload is valid, and use an extraction agent to generate a verification rule according to the key fragment information; a template generation module, configured to generate a vulnerability scanning template for the target vulnerability based on the request payload and verification rule obtained in each vulnerability interaction process.
[0014] Optionally, the information acquisition module is specifically configured to generate, based on the proof of concept, the vulnerability verification interaction overview information corresponding to the target vulnerability by using a large language model; wherein, the vulnerability interaction overview information is text information containing multiple entries, and each entry contains vulnerability trigger association information; the vulnerability trigger association information includes: interaction purpose, dependent steps, and expected response.
[0015] Optionally, the vulnerability interaction module is specifically configured to analyze, by using the request proxy, according to the proof of concept, the vulnerability interaction overview information, and variables in the variable set, to generate a request payload and interaction elements corresponding to the current vulnerability interaction process; wherein, the interaction elements include: target address, called method, request header information, and request data; the request payload is used to interact with the vulnerability test environment to trigger the target vulnerability.
[0016] Optionally, the verification rules include: matching rules and extraction rules; the vulnerability interaction module is specifically configured to generate a vulnerability interaction request containing the request payload corresponding to the current vulnerability interaction process based on the interaction elements; the vulnerability interaction module is specifically further configured to interact with the vulnerability test environment based on the vulnerability interaction request to obtain vulnerability interaction response information, and use the judgment proxy to determine that the request payload is valid when it is determined based on the vulnerability interaction response information that the target vulnerability is triggered; the vulnerability interaction module is specifically further configured to extract key fragment information from the request data included in the vulnerability interaction request and the vulnerability interaction response information when it is determined that the request payload is valid; the vulnerability interaction module is specifically further configured to analyze the key fragment information in the current vulnerability interaction process by using the extraction proxy to generate the matching rules and extraction rules corresponding to the current vulnerability interaction process; wherein, the matching rules are used to verify whether the target vulnerability is triggered; the extraction rules are used to extract field data required for subsequent vulnerability interaction processes.
[0017] Optionally, the vulnerability interaction request carries a remote control instruction; the vulnerability interaction module is specifically configured to interact with the target host in the vulnerability test environment based on the vulnerability interaction request to obtain vulnerability interaction response information; the vulnerability interaction module is specifically further configured to analyze the vulnerability interaction response information by using the judgment proxy, and if the vulnerability interaction response information contains status information fed back by an out-of-band server, determine that the request payload is valid; wherein, the remote control instruction is: a remote command executed by the target host when the vulnerability is triggered; when the target host executes the remote control instruction, it sends any network access request to the out-of-band server; the status information is: information fed back by the out-of-band server after receiving the network access request.
[0018] Optionally, the vulnerability interaction module is further configured to extract field data required for subsequent vulnerability interaction processes from the vulnerability interaction response information by using the extraction rule, and add the extracted field data to the variable set.
[0019] Optionally, the template generation module is specifically configured to generate a vulnerability scanning template for the target vulnerability based on vulnerability interaction meta-information, request payloads corresponding to each vulnerability interaction process, matching rules corresponding to each vulnerability interaction process, and extraction rules corresponding to each vulnerability interaction process; wherein the vulnerability interaction meta-information is generated based on the proof of concept corresponding to the target vulnerability, and the vulnerability interaction meta-information includes the common vulnerability disclosure number of the target vulnerability.
[0020] The present application also provides a computer program product, including computer programs / instructions, which when executed by a processor, implement the steps of the method for automatically generating a vulnerability scanning template based on a large language model as described in any one of the above.
[0021] The present application also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps of the method for automatically generating a vulnerability scanning template based on a large language model as described in any one of the above.
[0022] The present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the method for automatically generating a vulnerability scanning template based on a large language model as described in any one of the above.
[0023] The method and apparatus for automatically generating a vulnerability scanning template based on a large language model provided by the present application first obtain a proof of concept corresponding to a target vulnerability, and generate vulnerability interaction overview information based on the proof of concept; the vulnerability interaction overview information is used to represent the execution order and dependency relationship of at least one vulnerability interaction process; then, in any one vulnerability interaction process, use a request proxy to generate a request payload according to the vulnerability interaction overview information, use a judgment proxy to extract key fragment information in the vulnerability interaction process when judging that the request payload is valid, and use an extraction proxy to generate a verification rule according to the key fragment information; finally, based on the request payloads and verification rules obtained in each vulnerability interaction process, generate a vulnerability scanning template for the target vulnerability. By using three collaborative large language model agents to perform a step-by-step conversion process, the automatic conversion from the proof of concept to the vulnerability scanning template is realized, greatly improving the generation efficiency of the vulnerability scanning template. Description of the Drawings
[0024] To more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0025] Figure 1 It is an intermediate representation diagram of vulnerability interaction provided by the present application; Figure 2 It is a schematic diagram of the workflow for deriving vulnerability trigger steps provided by the present application; Figure 3 It is a schematic flowchart of a method for generating an automated vulnerability scanning template based on a large language model provided by the present application; Figure 4 It is a schematic structural diagram of an apparatus for generating an automated vulnerability scanning template based on a large language model provided by the present application; Figure 5 It is a schematic structural diagram of an electronic device provided by the present application. Detailed implementation manners
[0026] To make the objectives, technical solutions, and advantages of the present application clearer, the following will clearly and completely describe the technical solutions in the present application with reference to the drawings in the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0027] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. generally belong to the same category, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally represents an "or" relationship between the associated objects before and after.
[0028] In view of the technical problems of complex process and low efficiency in generating vulnerability scanning templates in the related art, the embodiments of the present application provide an automated vulnerability scanning template generation method based on a large language model. The invention aims to systematically convert various proof-of-concept (PoC) formats into vulnerability scanning templates. To ensure capturing the data and sequential dependencies between PoC steps and integrating the request payloads and verification rules for each step, the embodiments of the present application also introduce a vulnerability interaction intermediate representation graph (PoCGraph) as a platform-independent data storage structure. This graph-based representation helps to uniformly convert PoCs with different structures into a standardized intermediate format, enabling subsequent tasks to generate scanning templates across different vulnerability scanning frameworks.
[0029] As Figure 1 shown, it is the vulnerability interaction intermediate representation graph provided by the embodiments of the present application. Based on the design of the vulnerability interaction intermediate representation graph, the embodiments of the present application first generate vulnerability interaction meta-information (PoCInfo) and vulnerability interaction overview information (PoCOverview) from the proof-of-concept (PoC) provided by the user. Then, the vulnerability interaction overview information is used to guide the generation of each step of the vulnerability interaction process (PoCStep). Subsequently, three collaborative large language model agents are used to execute the step-by-step conversion process.
[0030] As Figure 2 shown, it is a schematic diagram of the vulnerability trigger process derivation workflow. The large language model agents provided by the embodiments of the present application include: a request agent (Request Agent), a judge agent (Judge Agent), and an extractor agent (ExtractorAgent). Each agent independently maintains its own conversation context and coordinates internally, while still allowing the user to interact transparently with the embodiments of the present application. The coordinated efforts of these agents ultimately produce the final conversion output.
[0031] The automated vulnerability scanning template generation method based on a large language model provided by the embodiments of the present application focuses on carefully and systematically converting proof-of-concept demonstrations into vulnerability scanning templates to ensure the accuracy and effectiveness of each step. Given that the failure of a single step may affect the entire process, the embodiments of the present application adopt a fine-grained, step-by-step conversion method to address this challenge. To support this conversion process, the embodiments of the present application design a vulnerability interaction intermediate representation graph (PoCGraph) aiming to meet two key objectives.
[0032] First, the vulnerability interaction intermediate representation graph standardizes the conversion results, making it independent of any specific vulnerability scanning framework, thereby achieving cross-platform compatibility. This standardized design avoids deep integration with specific scanning tools, enabling the converted results to flexibly adapt to various vulnerability scanning template formats. Second, the vulnerability interaction intermediate representation graph retains detailed information in each step, precisely capturing the data and sequential dependencies between steps. This allows the internal large language model agent in the embodiments of this application to utilize the results of previous steps for continuous reasoning and processing during subsequent step conversions, ensuring the logical coherence of the vulnerability proof-of-concept execution process.
[0033] As Figure 2 shown, the vulnerability interaction intermediate representation graph consists of three components: vulnerability interaction meta-information (PoCInfo), vulnerability interaction overview information (PoCOverview), and multiple vulnerability interaction processes (PoCStep). Among them, PoCInfo provides basic information about the PoC, including the Common Vulnerabilities & Exposures (CVE) number of the vulnerability, the author of the proof-of-concept, the severity of the vulnerability, and so on. The vulnerability interaction overview information PocOverview maintains the execution order and dependencies between steps, guiding the orderly execution of the vulnerability proof-of-concept process; each instance in the multiple vulnerability interaction processes PoCStep consists of an interaction request body (PoCRequest) and a response parser (PoCExtractor). The interaction request body is responsible for defining how to construct requests to interact with the target server, while the response parser uses matching rules and extraction rules to parse the response and extract key information for decision-making and operations in subsequent steps.
[0034] The vulnerability interaction intermediate representation graph organizes each vulnerability interaction process and each step in the vulnerability interaction process into a linear relationship, although there may be conditional judgments or loop logic in actual applications. However, considering that the main purpose of the PoC is to verify the existence of vulnerabilities rather than perform complex attack behaviors, this simplified design not only reduces the conversion complexity but also maintains the basic verification ability for the existence of vulnerabilities. For example, when confirming an SQL injection vulnerability, verification can be completed simply by sending malformed payloads and matching error messages, without complex iterative attempts or conditional logic. This method ensures the simplicity and efficiency of the conversion process while not losing its core function of verifying vulnerabilities.
[0035] Next, in combination with the accompanying drawings, the method for generating an automated vulnerability scanning template based on a large language model provided by the embodiments of this application will be described in detail through specific embodiments and their application scenarios.
[0036] As Figure 3As shown in the figure, an automated vulnerability scanning template generation method based on a large language model provided by an embodiment of the present application may include the following steps 301 to 303: Step 301: Obtain a proof of concept for the target vulnerability, and generate vulnerability interaction overview information based on the proof of concept.
[0037] Among them, the vulnerability interaction overview information is used to characterize the execution order and dependency relationship of at least one vulnerability interaction process; the vulnerability proof of concept process includes multiple vulnerability interaction processes, and each vulnerability interaction process includes: generating a request payload, verifying the request payload, and generating a verification rule.
[0038] Exemplarily, in order to convert the proof of concept PoC of the target vulnerability (which can be a Web vulnerability) provided by the user into a vulnerability interaction intermediate representation graph, the embodiment of the present application first utilizes the logical reasoning ability of the large language model to generate vulnerability interaction overview information according to the proof of concept PoC provided by the user, and the vulnerability interaction overview information is used to guide the generation of subsequent vulnerability trigger steps.
[0039] Specifically, in the above step 301, the step of generating vulnerability interaction overview information based on the proof of concept may further include the following step 301a: Step 301a: Based on the proof of concept, use the large language model to generate the vulnerability verification interaction overview information corresponding to the target vulnerability.
[0040] Among them, the vulnerability interaction overview information is text information containing multiple entries, and each entry contains vulnerability trigger association information; the vulnerability trigger association information includes: interaction purpose, dependent steps, and expected response.
[0041] Exemplarily, each entry in the vulnerability interaction overview information contains the basic information of the vulnerability trigger step, including its interaction purpose, dependent steps, expected response, and the contribution of this interaction to vulnerability triggering. The vulnerability interaction overview information maintains the global context and can ensure the coherence between adjacent steps during the generation of vulnerability trigger steps, rather than converting each step in isolation.
[0042] Step 302: In any vulnerability interaction process, use a request proxy to generate a request payload according to the vulnerability interaction overview information, use a judgment proxy to extract key fragment information in the vulnerability interaction process when determining that the request payload is valid, and use an extraction proxy to generate a verification rule according to the key fragment information.
[0043] Among them, the request proxy, the judgment proxy, and the extraction proxy are large language model agents that cooperate with each other.
[0044] Exemplarily, after generating the vulnerability interaction overview information, the vulnerability interaction flow sequence can be generated in sequence. As Figure 2 shown, this process includes three steps: request payload generation, request payload verification, and verification rule generation. These three steps respectively undertake three subtasks: generation, verification, and matching.
[0045] It can be understood that in the embodiment of the present application, the large language model agent can input the data to be analyzed and the corresponding prompt words into the large language model, and the required content output by the large language model can be obtained.
[0046] Specifically, in step 302 above, for the step of request payload generation, the following step 302a may further be included: Step 302a: Use the request agent to analyze according to the proof of concept, the vulnerability interaction overview information, and the variables in the variable set to generate a request payload and interaction elements corresponding to the current vulnerability interaction process.
[0047] Among them, the interaction elements include: target address, called method, request header information, and request data; the request payload is used to interact with the vulnerability test environment to trigger the target vulnerability; when there is no previous vulnerability interaction process before the current vulnerability interaction process, the variable set is empty.
[0048] It should be noted that in the embodiment of the present application, the above vulnerability interaction request is described by taking the hypertext transfer protocol HTTP request as an example. At the beginning of converting specific steps in the proof of concept PoC, the request agent in the embodiment of the present application will analyze the original PoC information and the previously generated vulnerability interaction overview information PocOverview to extract an appropriate request payload PoCRequest. During this process, the request agent will identify four basic HTTP interaction elements from the PoC: uniform resource locator URL, called method, header (i.e., HTTP request header), and POST data. These key elements determine how to communicate with the target server using the HTTP protocol, such as sending a formatted payload to a specified URL.
[0049] Meanwhile, considering that the interaction with the target server may depend on variables obtained from the previous vulnerability interaction process, the request proxy also integrates the set of variables previously extracted during the entire transformation process. This process ensures that the generated request payload can maintain the necessary context and dependencies established in the early interaction steps, thus guaranteeing the consistency and coherence of the operations. Although the request proxy successfully generates the request payload, relying solely on this generation process does not fully guarantee the validity of the payload. The generated request payload may have subtle problems or defects that could hinder the successful triggering of the vulnerability, such as incorrect parameter formats or lack of necessary context-related values. Therefore, to ensure that the request payload can effectively interact with the target environment, a sound verification mechanism must be introduced to evaluate its validity. This verification mechanism is crucial for ensuring the reliability and accuracy of the entire process.
[0050] Exemplarily, in the request payload generation section, the embodiment of the present application introduces a request agent based on a large language model to require the large language model to conduct a detailed analysis of a given proof of concept (PoC) and extract the request payload data that is crucial for the current vulnerability interaction process. The request payload is the data carried in the vulnerability interaction request for triggering the target vulnerability.
[0051] Specifically, in step 302 mentioned above, for the step of request payload verification, it may further include the following steps 302b1 to 302b3: Step 302b1: Generate a vulnerability interaction request containing the request payload corresponding to the current vulnerability interaction process based on the interaction elements.
[0052] Step 302b2: Conduct a vulnerability interaction with the vulnerability test bed environment based on the vulnerability interaction request to obtain vulnerability interaction response information, and use the judgment agent to determine that the request payload is valid when it is determined that the target vulnerability is triggered based on the vulnerability interaction response information.
[0053] Step 302b3: When it is determined that the request payload is valid, extract key fragment information from the request data included in the vulnerability interaction request and the vulnerability interaction response information.
[0054] Among them, when the target vulnerability is triggered, it is determined that the request payload is valid; when the target vulnerability is not triggered, it is determined that the request payload is invalid.
[0055] Exemplarily, in the request payload verification section, the embodiments of the present application introduce a Judge Agent to determine whether the previous request payload is valid, so as to block invalid request payloads caused by problems such as large language model hallucinations in advance. This determination is made based on the interaction between the embodiments of the present application and the vulnerability test bed and the preset change of the out-of-band server information status.
[0056] It should be noted that, in order to verify the validity of the request payload generated in the previous step, the embodiments of the present application deploy a component called Judge Agent to deeply analyze the process of interacting with the target server. After generating the request payload, the embodiments of the present application capture all the traffic in the entire HTTP communication process. The Judge Agent evaluates these interactions by carefully checking specific HTTP status codes and key metrics of the response content to determine whether the request payload has successfully triggered the target vulnerability. If the attempt fails, the Judge Agent will conduct a detailed analysis of the interaction traffic and generate a detailed interaction summary, which enables the Judge Agent to optimize the subsequent request payload based on more accurate information.
[0057] In a possible implementation manner, the analysis ability of the Judge Agent is not limited to standard HTTP response verification. Although many web vulnerabilities can be identified through immediate HTTP response anomalies (such as SQL error messages), in some cases, the execution of a vulnerability does not directly produce distinguishable response metrics.
[0058] Specifically, the vulnerability interaction request carries a remote control instruction, and the above step 302b2 may further include the following steps 302b21 and 302b22: Step 302b21, perform a vulnerability interaction with the target host in the vulnerability test bed environment based on the vulnerability interaction request to obtain vulnerability interaction response information.
[0059] Step 302b22, use the Judge Agent to analyze the vulnerability interaction response information. If the vulnerability interaction response information contains the status information fed back by the out-of-band server, it is determined that the request payload is valid.
[0060] Among them, the remote control instruction is: the remote command executed by the target host when the vulnerability is triggered; when the target host executes the remote control instruction, it sends any network access request to the out-of-band server; the status information is: the information fed back by the out-of-band server after receiving the network access request.
[0061] Exemplarily, such as Figure 2As shown, in the case where it is impossible to determine whether a vulnerability has been triggered based on the information feedback from the target host, the embodiment of the present application also integrates an out-of-band (OOB) server for a secondary detection mechanism. The request proxy can embed a command such as nslookup oobserver.com in the payload to trigger a DNS query. When the HTTP response lacks a clear success identifier, the DNS query received by the OOB server can be used as a basis for confirming the execution of the payload and the existence of the vulnerability, that is, to determine whether the vulnerability on the target host has been triggered by whether the out-of-band server feedbacks status information. This dual-channel detection method enhances the ability of the embodiment of the present application in converting the vulnerability proof of concept, making it go beyond the traditional response-based analysis means. However, for those vulnerabilities that neither provide HTTP response metrics nor initiate network interactions, the current method still has limitations because remote verification is crucial for scan-oriented applications.
[0062] It should be noted that when triggering a vulnerability in the vulnerability test bed, there needs to be a feedback message to indicate whether the trigger is successful this time. For some vulnerabilities (such as sensitive file reading), once these vulnerabilities are triggered, some sensitive information will be included in the vulnerability interaction response message; but for another part of the vulnerabilities without echo (such as silent command injection), whether they are triggered or not will not change the information feedback from the target host. Therefore, it is not enough to simply use the information feedback from the target host to determine whether a vulnerability has been triggered.
[0063] Therefore, an out-of-band server is introduced. There is no vulnerability on the out-of-band server, and its purpose is to detect whether the vulnerability test bed actively accesses the out-of-band server. Generally, the vulnerability test bed will not actively access the out-of-band server. Only by injecting a command such as nslookup into the vulnerability test bed through the vulnerability can the vulnerability test bed access the out-of-band server. Therefore, in addition to the information feedback from the target host, the accessed status of the out-of-band server can also reveal the trigger situation of the vulnerability.
[0064] Exemplarily, to ensure analysis accuracy in various response modes, the Judge Agent tracks all HTTP response redirects to avoid missing any key information. Faced with large-scale HTTP responses that exceed the context window of the large language model, the Judge Agent adopts a response slicing strategy. To avoid the problem of losing the overall context due to excessive focus on a single fragment when treating the HTTP response simply as text, this strategy retains the complete HTTP header as part of the LLM input and only segments the response body. Practice has proven that this method is effective because it uses the HTTP status code and HTTP header information to remind the LLM of the overall context of the response and prevent it from over-focusing on the isolated analysis of a single fragment. Once it is determined that the current vulnerability interaction process has achieved the expected goal, the Judge Agent extracts representative interaction fragments demonstrating success. These key fragments may include parts of the HTTP response containing specific sensitive information or state changes of out-of-band servers (such as receiving DNS requests from the target server). This focused extraction process provides refined input materials for the Extractor Agent, enabling it to develop precise vulnerability detection rules without having to process the entire server response. By providing refined relevant fragments, the Judge Agent enables the Extractor Agent to bypass the need for comprehensive HTTP response analysis and directly utilize pre-filtered information to more efficiently focus on generating matching and extraction rules.
[0065] Exemplarily, in the verification rule generation part, the embodiment of the present application introduces an Extractor Agent to extract and generate a series of matching rules and extraction rules based on information such as the current request payload and the content returned by the vulnerability test server, so as to be able to judge whether the current vulnerability trigger step is successful according to these matching rules during vulnerability scanning, and extract data fields that may be used in subsequent interaction steps according to the information returned by the victim server under the current vulnerability interaction, including but not limited to various login tokens, file upload paths, etc.
[0066] Specifically, in step 302 above, for the step of generating verification rules, the following step 302c may further be included: Step 302c: Analyze the key fragment information in the current vulnerability interaction process by using the Extractor Agent to generate matching rules and extraction rules corresponding to the current vulnerability interaction process.
[0067] Among them, the matching rules are used to verify whether the target vulnerability is triggered; the extraction rules are used to extract the field data required for subsequent vulnerability interaction processes.
[0068] Exemplarily, after the evaluation agent successfully extracts and demonstrates successful interaction fragments, the ExtractorAgent will conduct in-depth analysis on these fragments to formulate precise matching and extraction rules. This process aims to ensure that the scanning tool can accurately identify vulnerabilities in the target server and systematically collect relevant information from the responses. The matching rules enable the scanner to identify vulnerabilities in the target server by detecting expected error messages or determining whether security patches have prevented the leakage of sensitive information. At the same time, the extraction rules focus on collecting relevant fields from the server response when meeting the predetermined goals. The previously generated vulnerability interaction overview information PocOverview provides the necessary context for the extraction agent, ensuring the consistency of the extracted variables with the requirements of subsequent steps.
[0069] Exemplarily, to verify the existence of vulnerabilities, the matching rules adopt multiple pattern types. One verification method is HTTP response code verification, that is, by checking the returned HTTP status code to initially judge the success or failure of the request. In addition, another important verification method involves keyword detection in the HTTP headers and response bodies. This method confirms the existence of expected vulnerability signs by searching for predefined keywords or patterns. There is also a mechanism that relies on the verification of out-of-band server status. In this method, the target server initiates a query (such as a DNS query) to an external out-of-band server as indirect evidence to confirm the success or failure of command execution. For example, when the response to the id command contains the uid= string, or the target server initiates a DNS query to the out-of-band server, the existence of a command injection vulnerability can be confirmed.
[0070] Exemplarily, the extraction rules use complex regular expression techniques, enabling the embodiments of the present application to systematically extract sensitive information from the server response. This method not only improves the accuracy of data extraction but also enhances the automation of the entire process. Through this strategy, it can operate efficiently even in the face of complex and variable response content. The extraction agent uses these refined relevant fragments to directly process the pre-filtered information, thereby more effectively focusing on generating matching and extraction rules and avoiding the need to comprehensively analyze the entire server response. This not only simplifies the processing flow but also ensures the effective extraction and utilization of key information, further supporting the accuracy and efficiency of vulnerability detection. Throughout the process, the operations of the extraction agent are closely centered around the detailed information received from the evaluation agent, ensuring that each step is optimized and executed based on the most accurate data. This rigorous method guarantees the coherence and effectiveness in the conversion process from the proof of concept PoC to the vulnerability interaction intermediate representation graph PocGraph.
[0071] Step 303: Generate a vulnerability scanning template for the target vulnerability based on the request payload and verification rules corresponding to each vulnerability interaction process.
[0072] Exemplarily, after obtaining the request payload, matching rule, and extraction rule for each vulnerability interaction process, a vulnerability scanning template for the target vulnerability can be generated.
[0073] Specifically, step 303 above may further include the following step 303a: Step 303a: Generate a vulnerability scanning template for the target vulnerability based on the vulnerability interaction meta-information, the request payload corresponding to each vulnerability interaction process, the matching rule corresponding to each vulnerability interaction process, and the extraction rule corresponding to each vulnerability interaction process.
[0074] Among them, the vulnerability interaction meta-information is generated based on the proof-of-concept for the target vulnerability, and the vulnerability interaction meta-information includes the Common Vulnerability Disclosure number of the target vulnerability.
[0075] Exemplarily, after obtaining all the relevant data in the vulnerability interaction clock building representation diagram, a corresponding vulnerability scanning template can be generated.
[0076] In a possible implementation manner, it is also necessary to use the extraction rule to extract the field data required for subsequent vulnerability interaction processes from the vulnerability interaction response information, and add the extracted field data to the variable set for subsequent vulnerability interaction processes to use.
[0077] Exemplarily, after step 302c above, the method for generating an automated vulnerability scanning template based on a large language model provided by the embodiments of the present application may further include the following step 305: Step 305: Use the extraction rule to extract the field data required for subsequent vulnerability interaction processes from the vulnerability interaction response information, and add the extracted field data to the variable set.
[0078] Exemplarily, the above field data includes but is not limited to various types of login tokens, file upload paths, etc.
[0079] Exemplarily, in order to comprehensively evaluate the effectiveness of this framework in converting vulnerability proofs-of-concept into scanning templates, the embodiments of the present application designed a series of strict experiments. These experiments not only tested the performance of this method in interaction environments with different complexities, but also compared its performance differences with a benchmark large language model. First, in the experimental design stage, a benchmark dataset containing various types of vulnerability PoCs was collected and constructed from environments such as metasploit, Exploit-DB, and Github. This dataset covers various scenarios from simple to complex, aiming to simulate various situations that may be encountered in actual applications, as shown in Table 1. Each PoC was carefully selected and verified to ensure its representativeness and challenge.
[0080] Table 1
[0081] During the experiment, the automated vulnerability scanning template generation method based on large language models provided by the embodiments of this application demonstrated excellent conversion capabilities. By introducing a deterministic template generation method, this method successfully eliminated the formatting error problems generated by the baseline model. Specifically, this method achieved a success rate of 57.2%, which is significantly better than the success rates of 28.2% and 25.6% achieved by GPT-3.5-turbo and GPT-4o-mini respectively. This indicates that compared with traditional guess-based methods, this method greatly improves the accuracy and reliability of the conversion template by automating the server interaction and verification processes.
[0082] In addition, the performance of this method in dealing with complex interactions is equally impressive. According to statistics, when dealing with PoCs involving multiple interactions, this method consumes approximately 70,000 tokens on average, and the 80th percentile threshold is approximately 100,000 tokens. Considering that the cost of the selected model is less than 1 / M tokens (0.50 / M for GPT-3.5-turbo and 0.15 / M for GPT-4o-mini), this means that the maximum cost per experiment does not exceed 0.1. Therefore, this method not only performs well in terms of performance but also has obvious advantages in terms of cost-effectiveness.
[0083] From the experimental results, it can be seen that by adopting advanced natural language understanding and logical reasoning technologies, this method not only significantly improves the success rate of converting PoCs into scanning templates but also demonstrates superior performance in multiple key tasks. Compared with the baseline model, this method reduces the occurrence of formatting errors, enhances the adaptability to complex vulnerability environments, and reduces costs while maintaining high efficiency.
[0084] The automated vulnerability scanning template generation method based on a large language model provided by an embodiment of the present application first obtains a proof of concept corresponding to a target vulnerability and generates vulnerability interaction overview information based on the proof of concept; the vulnerability interaction overview information is used to represent the execution order and dependency relationships of at least one vulnerability interaction process; then, in any one vulnerability interaction process, a request proxy is used to generate a request payload according to the vulnerability interaction overview information, a judgment proxy is used to extract key fragment information in the vulnerability interaction process when it is determined that the request payload is valid, and an extraction proxy is used to generate a verification rule according to the key fragment information; finally, based on the request payloads and verification rules obtained in each vulnerability interaction process, a vulnerability scanning template for the target vulnerability is generated. By using three collaborative large language model agents to execute the step-by-step conversion process, the automated conversion from the proof of concept to the vulnerability scanning template is realized, greatly improving the generation efficiency of the vulnerability scanning template.
[0085] It should be noted that for the automated vulnerability scanning template generation method based on a large language model provided by an embodiment of the present application, the execution subject can be an automated vulnerability scanning template generation device based on a large language model, or a control module in the automated vulnerability scanning template generation device based on a large language model for executing the automated vulnerability scanning template generation method. In an embodiment of the present application, the case where the automated vulnerability scanning template generation device based on a large language model executes the automated vulnerability scanning template generation method is taken as an example to illustrate the automated vulnerability scanning template generation device provided by an embodiment of the present application.
[0086] It should be noted that in an embodiment of the present application, the automated vulnerability scanning template generation method shown in each of the above method drawings is exemplarily illustrated by taking one drawing in the embodiment of the present application as an example. Specifically, when implemented, the automated vulnerability scanning template generation method shown in each of the above method drawings can also be implemented in combination with any other drawings that can be combined as shown in the above embodiments, which will not be elaborated here.
[0087] The automated vulnerability scanning template generation device provided by the present application will be described below, and the following description can be mutually referred to with the automated vulnerability scanning template generation method described above.
[0088] Figure 4 is a schematic structural diagram of the automated vulnerability scanning template generation device provided by an embodiment of the present application, as Figure 4 shown, specifically including: An information acquisition module 401 is configured to acquire a proof of concept for a target vulnerability and generate vulnerability interaction overview information based on the proof of concept; the vulnerability interaction overview information is used to characterize the execution order and dependency relationship of at least one vulnerability interaction process; a vulnerability interaction module 402 is configured to, in any one vulnerability interaction process, use a request proxy to generate a request payload according to the vulnerability interaction overview information, use a judgment proxy to extract key fragment information in the vulnerability interaction process when determining that the request payload is valid, and use an extraction proxy to generate a verification rule according to the key fragment information; a template generation module 403 is configured to generate a vulnerability scanning template for the target vulnerability based on the request payload and verification rule obtained in each vulnerability interaction process.
[0089] Optionally, the information acquisition module 401 is specifically configured to use a large language model to generate the vulnerability verification interaction overview information corresponding to the target vulnerability based on the proof of concept; wherein, the vulnerability interaction overview information is text information including multiple entries, and each entry includes vulnerability trigger association information; the vulnerability trigger association information includes: interaction purpose, dependency step, and expected response.
[0090] Optionally, the vulnerability interaction module 402 is specifically configured to use the request proxy to analyze according to the proof of concept, the vulnerability interaction overview information, and variables in a variable set to generate a request payload and interaction elements corresponding to the current vulnerability interaction process; wherein, the interaction elements include: target address, called method, request header information, and request data; the request payload is used to interact with a vulnerability test environment to trigger the target vulnerability.
[0091] Optionally, the verification rule includes: a matching rule and an extraction rule; the vulnerability interaction module 402 is specifically configured to generate a vulnerability interaction request including the request payload corresponding to the current vulnerability interaction process based on the interaction elements; the vulnerability interaction module 402 is further specifically configured to interact with a vulnerability test environment based on the vulnerability interaction request to obtain vulnerability interaction response information, and use the judgment proxy to determine that the request payload is valid when determining that the target vulnerability is triggered based on the vulnerability interaction response information; the vulnerability interaction module 402 is further specifically configured to extract key fragment information from the request data included in the vulnerability interaction request and the vulnerability interaction response information when determining that the request payload is valid; the vulnerability interaction module 402 is further specifically configured to use the extraction proxy to analyze the key fragment information in the current vulnerability interaction process to generate a matching rule and an extraction rule corresponding to the current vulnerability interaction process; wherein, the matching rule is used to verify whether the target vulnerability is triggered; the extraction rule is used to extract field data required for subsequent vulnerability interaction processes.
[0092] Optionally, a remote control instruction is carried in the vulnerability interaction request; the vulnerability interaction module 402 is specifically configured to perform vulnerability interaction with a target host in a vulnerability test environment based on the vulnerability interaction request to obtain vulnerability interaction response information; the vulnerability interaction module 402 is further specifically configured to analyze the vulnerability interaction response information by using the judgment agent, and if the vulnerability interaction response information contains status information fed back by an out-of-band server, determine that the request payload is valid; wherein, the remote control instruction is: a remote command executed by the target host when the vulnerability is triggered; when the target host executes the remote control instruction, send any network access request to the out-of-band server; the status information is: information fed back by the out-of-band server after receiving the network access request.
[0093] Optionally, the vulnerability interaction module 402 is further configured to extract field data required for subsequent vulnerability interaction processes from the vulnerability interaction response information by using the extraction rule, and add the extracted field data to the variable set.
[0094] Optionally, the template generation module 403 is specifically configured to generate a vulnerability scanning template for the target vulnerability based on vulnerability interaction meta-information, request payloads corresponding to each vulnerability interaction process, matching rules corresponding to each vulnerability interaction process, and extraction rules corresponding to each vulnerability interaction process; wherein, the vulnerability interaction meta-information is generated based on a proof of concept corresponding to the target vulnerability, and the vulnerability interaction meta-information includes a common vulnerability disclosure number of the target vulnerability.
[0095] The automated vulnerability scanning template generation device based on a large language model provided by the present application first obtains a proof of concept corresponding to a target vulnerability, and generates vulnerability interaction overview information based on the proof of concept; the vulnerability interaction overview information is used to represent the execution order and dependency relationship of at least one vulnerability interaction process; then, in any one vulnerability interaction process, use a request agent to generate a request payload according to the vulnerability interaction overview information, use a judgment agent to extract key fragment information in the vulnerability interaction process when determining that the request payload is valid, and use an extraction agent to generate a verification rule according to the key fragment information; finally, generate a vulnerability scanning template for the target vulnerability based on the request payloads and verification rules obtained in each vulnerability interaction process. Use three collaborative large language model agents to perform a step-by-step conversion process to realize the automated conversion from a proof of concept to a vulnerability scanning template, greatly improving the generation efficiency of the vulnerability scanning template.
[0096] Figure 5 An entity structure diagram of an electronic device is exemplified, as Figure 5As shown in the figure, the electronic device may include: a processor 510, a communications interface 520, a memory 530, and a communication bus 540. Among them, the processor 510, the communications interface 520, and the memory 530 complete communication with each other through the communication bus 540. The processor 510 may call the logical instructions in the memory 530 to execute the method for generating an automated vulnerability scanning template based on a large language model. The method includes: First, obtain a proof of concept corresponding to the target vulnerability, and generate vulnerability interaction overview information based on the proof of concept; the vulnerability interaction overview information is used to characterize the execution order and dependency relationships of at least one vulnerability interaction process; After that, in any one of the vulnerability interaction processes, use a request proxy to generate a request payload according to the vulnerability interaction overview information, use a judgment proxy to extract key fragment information in the vulnerability interaction process when determining that the request payload is valid, and use an extraction proxy to generate a verification rule according to the key fragment information; Finally, based on the request payloads and verification rules obtained in each vulnerability interaction process, generate a vulnerability scanning template for the target vulnerability. Use three collaborative large language model agents to execute the step-by-step conversion process to achieve the automated conversion from the proof of concept to the vulnerability scanning template, greatly improving the generation efficiency of the vulnerability scanning template.
[0097] In addition, when the logical instructions in the above-mentioned memory 530 can be implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0098] On the other hand, the present application also provides a computer program product, which includes a computer program stored on a computer-readable storage medium. The computer program includes program instructions that, when executed by a computer, enable the computer to execute the method for generating an automated vulnerability scanning template based on a large language model provided by each of the above methods. The method includes: First, obtain a proof of concept corresponding to the target vulnerability, and generate vulnerability interaction overview information based on the proof of concept; the vulnerability interaction overview information is used to represent the execution order and dependency relationships of at least one vulnerability interaction process; After that, in any one of the vulnerability interaction processes, use a request agent to generate a request payload according to the vulnerability interaction overview information, use a judgment agent to extract key fragment information in the vulnerability interaction process when judging that the request payload is valid, and use an extraction agent to generate a verification rule according to the key fragment information; Finally, based on the request payloads and verification rules obtained in each vulnerability interaction process, generate a vulnerability scanning template for the target vulnerability. By using three collaborative large language model agents to execute a step-by-step conversion process, the automated conversion from a proof of concept to a vulnerability scanning template is realized, greatly improving the generation efficiency of the vulnerability scanning template.
[0099] On another aspect, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the method for generating an automated vulnerability scanning template based on a large language model provided by each of the above. The method includes: First, obtain a proof of concept corresponding to the target vulnerability, and generate vulnerability interaction overview information based on the proof of concept; the vulnerability interaction overview information is used to represent the execution order and dependency relationships of at least one vulnerability interaction process; After that, in any one of the vulnerability interaction processes, use a request agent to generate a request payload according to the vulnerability interaction overview information, use a judgment agent to extract key fragment information in the vulnerability interaction process when judging that the request payload is valid, and use an extraction agent to generate a verification rule according to the key fragment information; Finally, based on the request payloads and verification rules obtained in each vulnerability interaction process, generate a vulnerability scanning template for the target vulnerability. By using three collaborative large language model agents to execute a step-by-step conversion process, the automated conversion from a proof of concept to a vulnerability scanning template is realized, greatly improving the generation efficiency of the vulnerability scanning template.
[0100] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative effort.
[0101] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0102] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present application.
Claims
1. An automated vulnerability scanning template generation method based on large language models, characterized in that, Including: Obtain a proof-of-concept for the target vulnerability and generate vulnerability interaction overview information based on the proof-of-concept; The vulnerability interaction overview information is used to characterize the execution order and dependency relationships of at least one vulnerability interaction process; In any vulnerability interaction process, use a request proxy to generate a request payload according to the vulnerability interaction overview information, use a judgment proxy to extract key fragment information in the vulnerability interaction process when determining that the request payload is valid, and use an extraction proxy to generate verification rules according to the key fragment information; Generate a vulnerability scanning template for the target vulnerability based on the request payloads and verification rules obtained in each vulnerability interaction process.
2. The method according to claim 1, wherein The generating the vulnerability interaction overview information based on the proof-of-concept includes: Based on the proof-of-concept, use a large language model to generate the vulnerability interaction overview information corresponding to the target vulnerability; Wherein, the vulnerability interaction overview information is text information containing multiple entries, and each entry contains vulnerability trigger association information; the vulnerability trigger association information includes: interaction purpose, dependent steps, and expected response.
3. The method according to claim 1 or 2, characterized in that, The using the request proxy to generate a request payload according to the vulnerability interaction overview information includes: Use the request proxy to analyze according to the proof-of-concept, the vulnerability interaction overview information, and variables in the variable set to generate a request payload and interaction elements corresponding to the current vulnerability interaction process; Wherein, the interaction elements include: target address, called method, request header information, and request data; the request payload is used to interact with the vulnerability target environment to trigger the target vulnerability.
4. The method according to claim 3, wherein The verification rules include: matching rules and extraction rules; The using the judgment proxy to extract key fragment information in the vulnerability interaction process when determining that the request payload is valid, and the using the extraction proxy to generate verification rules according to the key fragment information includes: Generate a vulnerability interaction request including the request payload corresponding to the current vulnerability interaction process based on the interaction elements; Perform a vulnerability interaction with the vulnerability target environment based on the vulnerability interaction request to obtain vulnerability interaction response information, and use the judgment proxy to determine that the request payload is valid when it is determined based on the vulnerability interaction response information that the target vulnerability is triggered; When determining that the request payload is valid, extract key fragment information from the request data included in the vulnerability interaction request and the vulnerability interaction response information; Use the extraction proxy to analyze the key fragment information in the current vulnerability interaction process to generate matching rules and extraction rules corresponding to the current vulnerability interaction process; Wherein, the matching rules are used to verify whether the target vulnerability is triggered; the extraction rules are used to extract field data required for subsequent vulnerability interaction processes.
5. The method according to claim 4, characterized in that The vulnerability interaction request carries a remote control instruction; The performing a vulnerability interaction with the vulnerability target environment based on the vulnerability interaction request to obtain vulnerability interaction response information, and using the judgment proxy to determine that the request payload is valid when it is determined based on the vulnerability interaction response information that the target vulnerability is triggered includes: Perform vulnerability interaction with the target host in the vulnerability testing environment based on the vulnerability interaction request to obtain vulnerability interaction response information; Use the judgment agent to analyze the vulnerability interaction response information. If the status information feedback by the out-of-band server is included in the vulnerability interaction response information, determine that the request payload is valid; Wherein, the remote control instruction is: the remote command executed by the target host when the vulnerability is triggered; when the target host executes the remote control instruction, send any network access request to the out-of-band server; the status information is: the information feedback by the out-of-band server after receiving the network access request.
6. The method according to claim 4 or 5, characterized in that, After the extraction agent generates the verification rule according to the key fragment information, the method further includes: Use the extraction rule to extract the field data required for the subsequent vulnerability interaction process from the vulnerability interaction response information, and add the extracted field data to the variable set.
7. The method according to claim 1, wherein Generating a vulnerability scanning template for the target vulnerability based on the request payload and verification rule corresponding to each vulnerability interaction process, including: Generating a vulnerability scanning template for the target vulnerability based on vulnerability interaction meta-information, the request payload corresponding to each vulnerability interaction process, the matching rule corresponding to each vulnerability interaction process, and the extraction rule corresponding to each vulnerability interaction process; Wherein, the vulnerability interaction meta-information is generated based on the proof of concept corresponding to the target vulnerability, and the vulnerability interaction meta-information includes the common vulnerability disclosure number of the target vulnerability.
8. An automated vulnerability scanning template generation device based on a large language model, characterized in that, The device includes: An information acquisition module, configured to acquire a proof of concept corresponding to a target vulnerability, and generate vulnerability interaction overview information based on the proof of concept; the vulnerability interaction overview information is used to characterize the execution order and dependency relationship of at least one vulnerability interaction process; A vulnerability interaction module, configured to, in any vulnerability interaction process, use a request agent to generate a request payload according to the vulnerability interaction overview information, use a judgment agent to extract key fragment information in the vulnerability interaction process when determining that the request payload is valid, and use an extraction agent to generate a verification rule according to the key fragment information; A template generation module, configured to generate a vulnerability scanning template for the target vulnerability based on the request payload and verification rule corresponding to each vulnerability interaction process.
9. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps of the method for generating an automated vulnerability scanning template based on a large language model according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and when the computer program is executed by a processor, it implements the steps of the method for generating an automated vulnerability scanning template based on a large language model according to any one of claims 1 to 7.
Citation Information
Patent Citations
Honeycomb vulnerability generation method based on large language model
CN117610026A
Vulnerability verification request packet generation method and device, equipment and storage medium
CN118051920A
Automatic generation method of attack graph interaction rule for honey point deployment
CN118101346A
Vulnerability knowledge graph construction method and apparatus, and electronic device
CN118573488A
Network penetration testing method and system based on state feedback
CN119520075A
Cited By
Information processing systems, information processing methods, programs, and storage media
JP7904578B1