Multi-agent penetration testing tool orchestration and unified invocation methods and computer equipment

By unifying the invocation of a semi-centralized multi-agent system and model context protocol, and combining dynamic knowledge graphs and large language models, the automation and stability issues of penetration testing tools in complex network environments are solved, achieving efficient and measurable penetration testing results.

CN121233481BActive Publication Date: 2026-03-13NANJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-03
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Existing penetration testing tools lack unified invocation and automatic integration when facing complex network structures and diverse attack methods, resulting in low efficiency, instability, and reliability of penetration testing processes.

Method used

It adopts a semi-centralized multi-agent system architecture, realizes unified encapsulation and invocation of penetration testing tools through model context protocol, combines dynamic knowledge graph and large language model for information organization and strategy generation, introduces preference-driven chain thinking mechanism for result denoising and consistency verification, and uses multi-dimensional performance indicators for quantitative evaluation.

Benefits of technology

It improves the automation and strategy stability of penetration testing, increases the success rate of tasks, reduces the average number of training rounds and execution steps, and achieves adaptive optimization and measurable penetration testing for complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121233481B_ABST
    Figure CN121233481B_ABST
Patent Text Reader

Abstract

This invention discloses a method and computer device for orchestrating and uniformly invoking multi-agent penetration testing tools. The method includes: constructing a semi-centralized multi-agent collaborative framework comprising a master agent, a reconnaissance agent, and an attack agent, abstracting the penetration testing process into an interactive task environment; achieving unified invoking and result return of various penetration testing tools through a model context protocol, ensuring scalability and security verifiability among different tools; utilizing dynamic knowledge graphs to model the relationships between target hosts, ports, services, and vulnerabilities in real time, and combining a preference-driven chain thinking mechanism to denoise, correlate, and semantically align the outputs of multiple tools, forming a context-aware knowledge fusion module; using the fused knowledge as decision input to guide the multi-agent to complete task planning, tool selection, and command generation, achieving full-process automation from information gathering to vulnerability exploitation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of network security and artificial intelligence, and more specifically to a method and computer device for orchestrating and uniformly invoking multi-agent penetration testing tools based on the Model Context Protocol. Background Technology

[0002] With the development of large language models, they have shown significant advantages in semantic understanding, contextual association, and task planning. Introducing large language models into penetration testing tasks can enable abstract modeling and knowledge fusion of complex security information, thereby supporting collaborative decision-making among multiple agents.

[0003] In the field of cybersecurity, penetration testing is a key strategy for assessing the security of information systems. Due to the multi-source nature of information in the current network environment, existing penetration testing tools exhibit significant limitations when dealing with complex network structures and diverse attack methods. They also lack unified application and automated integration capabilities, which negatively impacts the efficiency, stability, and reliability of the final penetration testing process. Summary of the Invention

[0004] The present invention provides a method and computer device for orchestrating and unifying the use of multi-agent penetration testing tools, which can improve the automation level, strategy stability and task success rate of penetration testing, and can solve at least one of the above-mentioned technical problems.

[0005] To solve the above-mentioned technical problems, the present invention adopts the following technical solution:

[0006] A method for orchestrating and uniformly invoking multi-agent penetration testing tools includes the following steps:

[0007] S1. Construct a semi-centralized multi-agent system architecture consisting of a master agent, a reconnaissance agent, and an attack agent, with each agent collaborating on tasks and sharing information through message passing.

[0008] S2. Based on the model context protocol, a unified encapsulation and invocation of penetration testing tools is implemented, abstracting different types of penetration testing tools into accessible server interfaces to ensure the security and scalability of penetration testing tool invocation;

[0009] S3. Actively collect information about the target network through semi-centralized multi-agent collaboration, including the acquisition of host, port, service and vulnerability data, and format and store the results output by the penetration testing tool.

[0010] S4. Utilize dynamic knowledge graphs to organize and model the collected information, forming a graph structure containing hosts, ports, services, and vulnerability entities and their relationships, to support task planning and contextual reasoning.

[0011] S5. Combining a preference-driven chain thinking mechanism, the output results from penetration testing tools are denoised, aggregated, and verified for consistency to generate context-aware knowledge fusion results.

[0012] S6. Input the knowledge fusion results into the large language model to generate penetration strategies and execution commands, driving each agent to perform specific tasks.

[0013] S7. Based on the task execution results and feedback information, dynamically update the knowledge graph status to form a cyclical optimization process and gradually improve the task completion rate and strategy stability.

[0014] S8. Use multi-dimensional performance indicators to quantitatively evaluate the penetration strategy in order to determine the stability of the system architecture and the convergence of the strategy.

[0015] Furthermore, in S1, the multi-agent system adopts a semi-centralized collaborative architecture, consisting of a master control agent, a reconnaissance agent, and an attack agent. The master control agent is responsible for global strategic planning and task allocation, while the reconnaissance agent and the attack agent have tactical execution autonomy. They share information and report results through message passing, forming a closed loop of strategic guidance, tactical autonomy, result reporting, and strategic adjustment.

[0016] Furthermore, in step S2, the unified encapsulation and invocation of penetration testing tools based on the Model Context Protocol (MCP) further includes:

[0017] MCP Servers are set up for reconnaissance, attack, and dynamic knowledge graph respectively. The client submits a penetration testing tool request with parameters in JSON-RPC. The server will translate the request into an HTTP / JSON request for the controlled backend and return a structured JSON result.

[0018] The reconnaissance / attack MCP Server does not perform semantic expansion; it only forwards the original structured output from the backend. The dynamic knowledge graph MCP Server supports writing to queues and structured retrieval.

[0019] Furthermore, in S3, the output of the penetration testing tool is standardized and structured and returned for subsequent knowledge fusion and task planning. The reconnaissance MCP Server provides a unified interface for port / directory / HTTP probing, while the attack MCP Server provides a non-interactive unified call to exploit commands and retains verifiable evidentiary fields.

[0020] Furthermore, in S4, a dynamic knowledge graph is used to perform semantic modeling and real-time updates on the collected information. Specifically, entities such as Host, Port, Service, Vulnerability, WebSite, and SensWebPath and their relationships are represented in the form of nodes and edges, and corresponding attributes are maintained to support situational awareness and task planning.

[0021] Furthermore, in S5, a preference-driven chain thinking mechanism is introduced to align and denoise the output results of the penetration testing tool, following a four-step process of strict deduplication, classification and summarization, prohibition of information fabrication, and fact verification, and a unified result report format is enforced for downstream consumption.

[0022] Furthermore, in S6, the system architecture, during the task planning process, performs a two-stage decision based on dynamic knowledge graphs and action history: first, context retrieval is performed, and then strategy generation is performed; the reconnaissance / attack agents generate specific commands accordingly, and execute them by calling penetration testing tools through their respective MCP Servers.

[0023] Furthermore, in S7, the system architecture records the agent's behavior, environmental state, inference chain, and penetration testing tool output results in real time during task execution, dynamically updates the knowledge graph based on the execution results, and sends the final summary back to the master agent.

[0024] The above process is repeated until the scene objective is reached or the stopping condition is met, thus achieving adaptive optimization for complex environments.

[0025] Furthermore, in S8, the following three indicators are introduced to quantitatively evaluate the penetration strategy:

[0026] Penetration Success Rate (PSR) measures the success rate of a system architecture in completing penetration tests across multiple environments. The formula is as follows:

[0027]

[0028] Where p is the number of times this method successfully obtained webshell privileges, and n is the total number of tests;

[0029] The higher the PSR value, the stronger the ability to complete the task;

[0030] Average training epochs (AE) measures the average number of epochs the controlling agent performs across all experiments in multiple environments. The formula is as follows:

[0031]

[0032] Among them, e i This represents the number of training rounds performed in the i-th experiment;

[0033] The lower the AE value, the more accurate the policy decisions of the controlling agent.

[0034] Average number of execution steps (AS) measures the average number of steps required for a reconnaissance agent and an attack agent to complete each reconnaissance or attack mission. The formula for AS is:

[0035]

[0036] Among them, S i,j Let m represent the number of steps performed in the j-th round of the i-th experiment, and m represent the number of rounds in the i-th experiment.

[0037] The lower the AS value, the stronger the ability of the reconnaissance agent and the attack agent to execute tactical decisions.

[0038] A computer device includes a memory and a processor, the memory storing a computer program that, when executed by the processor, causes the processor to perform the steps of the above-described multi-agent penetration testing tool orchestration and unified invocation method.

[0039] The beneficial effects of this invention are reflected in:

[0040] This invention provides a context-aware penetration testing knowledge fusion method based on a large language model. It enables unified invocation and result verification of various penetration testing tools through a model context protocol, and combines dynamic knowledge graphs to dynamically model the relationships between hosts, ports, services and vulnerabilities, thereby supporting the entire process of penetration testing reasoning and planning.

[0041] In addition, a preference-driven chain thinking mechanism is introduced to perform noise reduction, aggregation, and consistency analysis on the results from different penetration testing tools, thereby achieving context-aware multi-source knowledge fusion.

[0042] Furthermore, by constructing inference stability indicators and task performance indicators, the system can quantify the execution effect and inference consistency of different strategies, thereby achieving measurability and stability of the penetration testing process. Attached Figure Description

[0043] The accompanying drawings, which are provided to further illustrate this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application.

[0044] Figure 1 This is a schematic diagram of the overall structure of the method according to an embodiment of the present invention.

[0045] Figure 2This is a schematic diagram of the interaction process between the MCP client, MCP server, and penetration testing tool in the method of this embodiment of the invention.

[0046] Figure 3 This is a schematic diagram of a semi-centralized multi-agent collaborative framework of the method in an embodiment of the present invention.

[0047] Figure 4 This is a comparison chart of PSR indicators under different environments in embodiments of the present invention.

[0048] Figure 5 This is a comparison chart of PSR indices under different models in the embodiments of the present invention.

[0049] Figure 6 This is a comparison chart of the AE index under different environments in the embodiments of the present invention.

[0050] Figure 7 This is a comparison chart of AS index under different environments in the embodiments of the present invention.

[0051] Figure 8 This is a structural block diagram of a computer device according to an embodiment of the present invention. Detailed Implementation

[0052] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Unless otherwise specified, the embodiments and features in the embodiments of this application can be combined with each other. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0053] It should be noted that the meaning of "and / or" throughout the text includes three parallel solutions. Taking "A and / or B" as an example, it includes solution A, solution B, or a solution that simultaneously satisfies A and B. Furthermore, "multiple" refers to two or more. Additionally, the technical solutions of the various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. When the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed by this invention.

[0054] See Figures 1-2 This invention provides a method for orchestrating and uniformly invoking multi-agent penetration testing tools, comprising the following steps:

[0055] S1. Construct a semi-centralized multi-agent system architecture consisting of a master agent, a reconnaissance agent, and an attack agent, with each agent collaborating on tasks and sharing information through message passing.

[0056] In this step, the multi-agent system adopts a semi-centralized collaborative architecture, consisting of a master agent, a reconnaissance agent, and an attack agent. The master agent is responsible for global strategic planning and task allocation, while the reconnaissance agent and the attack agent have tactical execution autonomy. They share information and report results through message passing, forming a closed loop of "strategic guidance - tactical autonomy - result reporting - strategic adjustment".

[0057] S2. Based on the Model Context Protocol (MCP), a unified encapsulation and invocation of penetration testing tools is implemented, abstracting different types of penetration testing tools into accessible server interfaces to ensure the security and scalability of penetration testing tool invocation;

[0058] In this step, a unified encapsulation and invocation of penetration testing tools is implemented based on the Model Context Protocol (MCP), which further includes:

[0059] MCP Servers are set up for reconnaissance, attack, and dynamic knowledge graph respectively. The client submits a penetration testing tool request with parameters in JSON-RPC. The server will translate the request into an HTTP / JSON request for the controlled backend and return a structured JSON result.

[0060] The reconnaissance / attack MCP Server does not perform semantic expansion; it only forwards the original structured output from the backend. The dynamic knowledge graph MCP Server supports writing to queues and structured retrieval.

[0061] In the process of knowledge fusion for penetration testing based on a large language model, MCP implements three types of server interfaces: reconnaissance, attack, and dynamic knowledge graph, which correspond to information collection, attack execution, and knowledge graph management, respectively. The system architecture achieves compatibility and verification of results from different penetration testing tools through a unified input and output format.

[0062] It should be noted that MCP, as an open protocol, is designed to enable secure bidirectional connections between large language models (LLMs) and external data sources and penetration testing tools.

[0063] MCP adopts a client-server architecture, standardizing the interaction between AI models and the external environment. Its core components include:

[0064] 1) MCP Hosts: LLM applications that initiate requests, such as Claude Desktop and AI development IDEs, access the application entry layer through a secure channel.

[0065] 2) MCP Clients: Protocol conversion layer, maintains persistent connection with the server, and acts as a bridge between LLM and MCP servers.

[0066] 3) MCP Servers: Functionality provision layer, standardizing and encapsulating data / penetration testing tool capabilities, such as document parsing services, API gateway services, etc.

[0067] 4) Local Data: Controlled local resources accessed through secure channels, such as enterprise knowledge bases and private databases.

[0068] 5) Remote Services: Cloud-based expansion capabilities, supporting distributed integration, such as SaaS APIs, blockchain nodes, etc.

[0069] The MCP workflow consists of five key steps: context request (the host initiates a standardized request containing semantic intent), intelligent routing (the client automatically selects the optimal combination of servers), secure access (the server accesses resources through an authentication mechanism), context assembly (multi-source data is cleaned to form a structured context), and response delivery (a standardized format is returned as a context packet that LLM can understand).

[0070] The MCP protocol provides four core functional modules, which greatly expand the capabilities of AI models:

[0071] 1) Penetration Testing Tools: Executable functions or operations that the AI ​​Agent can call, such as searching the file system, querying the database, sending emails, or calling specialized APIs.

[0072] 2) Resources: Data sources that the Agent can read, such as document storage or vector databases, supporting structured context management.

[0073] 3) Prompts: Reusable prompt templates or instructions that guide the Agent on how to effectively use penetration testing tools or handle specific tasks.

[0074] 4) Sampling: A request sent by the server to the host to perform a specific operation or calculation, such as chained reasoning or code review, to achieve complex interactions.

[0075] Compared with traditional integration methods, MCP has the following significant advantages:

[0076] 1) Development cost: Traditional methods require writing independent interfaces for each data source, while MCP reduces development costs significantly through protocol abstraction.

[0077] 2) Adapting to complex systems: MCP’s structured context management, dynamic injection and update mechanism make it perform well in complex systems.

[0078] 3) Multi-module collaboration: MCP supports module-level sharing, enabling multiple modules to work together, while traditional integration generally does not support this.

[0079] 4) Long-term memory: MCP strongly supports long-term memory and can better maintain contextual coherence.

[0080] 5) Dynamic updates: MCP supports real-time adjustment of context information, while traditional integration methods are static and inconvenient to update.

[0081] S3. Actively collect information about the target network through semi-centralized multi-agent collaboration, including the acquisition of host, port, service and vulnerability data, and format and store the results output by the penetration testing tool.

[0082] In this step, the output of the penetration testing tool is standardized and structured before being returned for subsequent knowledge integration and task planning. The reconnaissance MCP Server provides a unified interface for port / directory / HTTP probing, while the attack MCP Server provides a unified non-interactive call to exploit commands and retains verifiable evidentiary fields (such as remote write confirmations, exit codes, and key standard outputs).

[0083] S4. Utilize dynamic knowledge graphs to organize and model the collected information, forming a graph structure containing hosts, ports, services, and vulnerability entities and their relationships, to support task planning and contextual reasoning.

[0084] In this step, a dynamic knowledge graph is used to semantically model and update the collected information in real time. Specifically, entities such as Host, Port, Service, Vulnerability, Website, and SensWebPath and their relationships (such as HAS_PORT, RUNS, HAS_VULN, SERVES_PATH, etc.) are represented in the form of nodes and edges, and corresponding attributes (such as host IP / hostname / os, service name / version / banner, path / status_code, etc.) are maintained to support situational awareness and task planning.

[0085] The dynamic knowledge graph includes host nodes, port nodes, service nodes, and vulnerability nodes. The nodes are connected by edges such as "running on", "depending on", "exposed", and "affected by vulnerabilities". The knowledge graph can be updated in real time during the penetration process to reflect changes in the system's cognitive state.

[0086] S5. Combining a preference-driven chain thinking mechanism, the output results from penetration testing tools are denoised, aggregated, and verified for consistency to generate context-aware knowledge fusion results.

[0087] In this step, a preference-driven chain thinking mechanism is introduced to align and denoise the output results of the penetration testing tool, specifically following the four-step process:

[0088] Strict deduplication, such as merging files / paths / services of the same type;

[0089] Categorize and summarize sensitive paths, uploadable directories, form submission points, and other key findings;

[0090] Fabricating information is strictly prohibited, as is making assumptions based on open-source proxy interfaces, etc.

[0091] The principle of fact-checking dictates that only evidence that can be directly traced back to the original output should be reported.

[0092] Subsequently, a standardized results reporting format was mandated for downstream consumption.

[0093] The preference-driven chain thinking mechanism realizes multi-round logical reasoning by constructing reasoning trajectories. In the fusion of multi-source results, it selects reasoning paths based on task objectives and prior preferences, verifies and filters uncertain information, thereby improving the reliability of the fusion results.

[0094] S6. Input the knowledge fusion results into the large language model to generate penetration strategies and execution commands, driving each agent to perform specific tasks.

[0095] In this step, a two-stage decision-making process is executed based on a dynamic knowledge graph and action history: first, context retrieval is performed (high-level objectives and historical actions are input into a large language model (LLM) to generate focused queries and obtain precise context with less noise from the dynamic knowledge graph); then, policy generation is performed (logical reasoning is performed on the precise context to output high-level strategic steps and assign them to sub-agents); the reconnaissance / attack agents generate specific commands based on this and execute them by calling penetration testing tools through their respective MCP Servers.

[0096] During the task planning process, the system architecture uses a large language model to generate a high-level penetration plan in natural language based on dynamic knowledge graph information. This plan is then converted into an executable instruction sequence via a structured command template for execution by the corresponding intelligent agent.

[0097] S7. Based on the task execution results and feedback information, dynamically update the knowledge graph status to form a cyclical optimization process and gradually improve the task completion rate and strategy stability.

[0098] In this step, the system architecture records the agent's behavior, environmental state, inference chain, and penetration testing tool output results in real time during task execution. This data is used for subsequent task performance evaluation and policy convergence analysis. The system also dynamically updates the knowledge graph based on the execution results and sends the final summary back to the master agent.

[0099] The above process is repeated until the scenario goal (such as obtaining webshell privileges) is achieved or the stopping condition is met, thus achieving adaptive optimization for complex environments.

[0100] S8. Use multi-dimensional performance indicators to quantitatively evaluate the penetration strategy in order to determine the stability of the system architecture and the convergence of the strategy.

[0101] In this step, the following three indicators are introduced to quantitatively evaluate the penetration strategy:

[0102] Penetration Success Rate (PSR) measures the success rate of a system architecture in completing penetration tests across multiple environments. The formula is as follows:

[0103]

[0104] Where p is the number of times this method successfully obtained webshell privileges, and n is the total number of tests;

[0105] The higher the PSR value, the stronger the ability to complete the task;

[0106] Average training episodes (AE) measures the average number of training episodes attempted by the controlling agent across all experiments in multiple environments. The formula is as follows:

[0107]

[0108] Among them, e i This represents the number of training rounds performed in the i-th experiment;

[0109] The lower the AE value, the more accurate the policy decisions of the controlling agent.

[0110] Average Steps (AS) measures the average number of steps required for a reconnaissance agent and an attack agent to complete a reconnaissance or attack mission. The formula is as follows:

[0111]

[0112] Among them, S i,j Let m represent the number of steps performed in the j-th round of the i-th experiment, and m represent the number of rounds in the i-th experiment.

[0113] The lower the AS value, the stronger the ability of the reconnaissance agent and the attack agent to execute tactical decisions.

[0114] To further verify the superiority and feasibility of this method, the present invention will provide the following real-world experimental case for illustration and analysis:

[0115] The practical problem discussed in this experiment is: considering the actual engineering implementation and verification of a multi-agent web penetration testing tool orchestration and unified invocation system and method based on the Model Context Protocol (MCP). The goal is to achieve end-to-end automated penetration testing (including obtaining webshell privileges without human intervention) in a real-world test environment, and to evaluate the performance of this invention in terms of task completion rate, strategy stability, and inference consistency. Figure 3 As shown, the specific operation steps are as follows:

[0116] S1. Experimental Environment Setup and Overall Configuration:

[0117] To comprehensively evaluate the applicability and robustness of this method, six target environments from Vulnhub (denoted as env1, env2, ..., env6) were selected as test targets.

[0118] The system architecture adopted is a semi-centralized multi-agent collaborative framework, which includes at least a master control agent, a reconnaissance agent, and an attack agent;

[0119] The large language model used is based on GPT-4.1-mini and compared with GPT-4o-mini and Qwen-72B;

[0120] Each complete run (one experiment) is defined as the entire lifecycle from target machine initialization to task completion (such as establishing a webshell) or timeout;

[0121] Each run consists of several episodes and several steps within each episode, used for subsequent efficiency evaluation and metric calculation.

[0122] S2, MCP, and penetration testing tool orchestration (observation and execution interfaces):

[0123] Each agent invokes the backend penetration testing tool through the Model Context Protocol (MCP). The system abstracts the penetration testing tool into three types of MCP Servers (Reconnaissance MCP Server, Attack MCP Server, and Dynamic Knowledge Graph MCP Server).

[0124] The agent initiates a penetration testing tool call request in JSON-RPC format. The reconnaissance / attack MCP Server returns the structured JSON output of the penetration testing tools (such as nmap, dirb, curl, sqlmap, msfconsole, hydra, etc.) as is (without semantic expansion). The dynamic knowledge graph MCP Server enqueues the write request asynchronously and returns an ack to ensure the traceability of the penetration testing tool output and the orderliness of the knowledge entry into the database.

[0125] S3, Multi-Agent Task Cycle and Short-Term Autonomy (Policy Execution Process):

[0126] In each decision cycle, the master agent retrieves high-level context from the dynamic knowledge graph and action_history and generates high-level task instructions, which are then issued to the reconnaissance agent or the attack agent.

[0127] After receiving a task, the sub-agent enters a short-term autonomous loop: first, it calls the LLM to determine whether the task should continue (tactical feasibility). If it continues, it requests a tactical decision from the LLM and generates specific executable commands. Then, it calls the penetration testing tool through the corresponding MCP Server to execute the command and receive a structured return. Finally, it reports the execution results and the summary of this round to the master agent. At the same time, it writes the execution record to action_history and / or dynamic knowledge graph for subsequent retrieval and planning.

[0128] The aforementioned closed-loop process achieves "strategic guidance - tactical autonomy - results-based rewards - strategic adjustment".

[0129] S4. Preference-Driven Mind Chain and Knowledge Integration:

[0130] After the penetration testing tool output is returned by the reconnaissance / attack MCP Server, it enters the preference-driven thought chain prompt processing module. This module executes a four-step information alignment process: strict deduplication, classification and summarization, prohibition of information fabrication, and fact verification. The structured facts processed and formatted by the thought chain are then written into a dynamic knowledge graph. The dynamic knowledge graph represents entities such as Host, Port, Service, Vulnerability, Website, and SensWebPath and their relationships in a node-edge structure, and maintains entity attributes to support semantic retrieval and temporal reasoning.

[0131] S5. Indicator Definition and Corresponding Calculation (Performance Quantification):

[0132] To objectively evaluate the performance of the method, this experiment uses three metrics: Penetration Success Rate (PSR), Average Episodes (AE), and Average Steps (AS). The relevant formulas and functions of these metrics have been introduced above and will not be repeated here.

[0133] The comparison objects include the complete method, variants without action history, variants without dynamic knowledge graphs, and existing solutions (such as PentestGPT's performance under different operators). Experiments were run repeatedly in six target environments, and PSR, AE, and AS were statistically analyzed. Detailed results are shown in the attached figures in the specification. Figures 4-7 .

[0134] Depend on Figures 4-7 Comparison of various metrics shows that the method of this invention achieves higher PSR in most scenarios and exhibits better convergence and inference consistency in AE and AS metrics. The above experimental results demonstrate that the context-aware knowledge fusion mechanism, MCP penetration testing tool orchestration, and preference-driven thought chain in this method have significant effects on automated penetration testing tasks.

[0135] This invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the steps of the multi-agent penetration testing tool orchestration and unified invocation method described above.

[0136] See Figure 8 The present invention also provides a computer device, including a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, the processor performs the steps of the multi-agent penetration testing tool orchestration and unified invocation method described above.

[0137] This invention also provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the steps of the multi-agent penetration testing tool orchestration and unified invocation method described above.

[0138] It is understood that the systems, devices, and storage media provided in the embodiments of the present invention correspond to the methods provided in the embodiments of the present invention, and the explanations, examples, and beneficial effects of the relevant content can be referred to the corresponding parts of the above-mentioned multi-agent penetration testing tool orchestration and unified invocation method.

[0139] It should be noted that those skilled in the art will understand that all or part of the steps implemented in the embodiments of the present invention can be implemented entirely or partially by software, hardware, firmware, or any combination thereof. When implemented in hardware, it can be implemented entirely or partially by purchasing standard parts or modifications. When implemented in software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid state disks (SSDs)).

[0140] In summary, the method of this invention, by constructing a semi-centralized multi-agent architecture, using MCP to uniformly orchestrate penetration testing tools, using preference-driven thought chains to align and denoise multi-source tool outputs, and leveraging dynamic knowledge graphs and action history for context retrieval and two-stage strategy generation, can achieve end-to-end automated penetration testing in a real-world testing environment. This significantly improves task success rate, reduces average rounds and steps, and enhances the consistency and verifiability of the reasoning process.

[0141] It should be understood that the examples and embodiments described herein are for illustrative purposes only and are not intended to limit the invention. Those skilled in the art can make various modifications or changes based on them. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the invention should be included within the protection scope of the invention.

Claims

1. A multi-agent penetration testing tool orchestration and unified invocation method, characterized in that, The method comprises the following steps: S1, a semi-centralized multi-agent system architecture is built by a master agent, a reconnaissance agent and an attack agent, and task cooperation and information sharing are realized among the agents through message passing; S2, unified packaging and calling of penetration testing tools are realized based on a model context protocol, different types of penetration testing tools are abstracted as accessible server interfaces to ensure the security and scalability of penetration testing tool calling; S3, active information collection of the target network is completed through semi-centralized multi-agent cooperation, including host, port, service and vulnerability data acquisition, and the penetration testing tool output results are formatted and stored; S4, the collected information is organized and modeled using a dynamic knowledge graph, forming a graph structure containing host, port, service and vulnerability entities and their relationships, which is used to support task planning and context reasoning; S5, combined with a preference-driven chain thinking mechanism, the output results from the penetration testing tools are denoised, aggregated and consistency verified to generate context-aware knowledge fusion results; S6, the knowledge fusion results are input into a large language model to generate penetration strategies and execution commands to drive each agent to perform specific tasks; S7, according to the task execution results and feedback information, the knowledge graph state is dynamically updated to form a cyclic optimization process, gradually improving the task completion rate and strategy stability; S8, the penetration strategy is quantitatively evaluated using multi-dimensional performance indicators to judge the stability of the system architecture and the convergence of the strategy.

2. The multi-agent penetration testing tool orchestration and unified invocation method of claim 1, wherein, In S1, the multi-agent adopts a semi-centralized collaborative architecture, which is composed of a master agent, a reconnaissance agent and an attack agent. The master agent is responsible for global strategic planning and task allocation. The reconnaissance agent and the attack agent have autonomous rights of tactical execution and share information and return results through message passing, forming a closed loop of strategic guidance-tactical autonomy-result reporting-strategic adjustment.

3. The method of claim 1, wherein, In S2, the unified packaging and calling of penetration testing tools are realized based on the model context protocol MCP, which further comprises: MCP Server is set for reconnaissance, attack and dynamic knowledge graph respectively. The client submits a named penetration testing tool request with parameters in JSON-RPC mode, the server converts the call into HTTP / JSON request of the controlled backend and returns structured JSON results; The reconnaissance / attack MCP Server does not perform semantic extension and only forwards the original structured output of the backend. The dynamic knowledge graph MCP Server supports write-in queue and structured retrieval.

4. The multi-agent penetration testing tool orchestration and unified invocation method of claim 3, wherein, In S3, the penetration testing tool output is standardized and structured and returned for subsequent knowledge fusion and task planning. The reconnaissance MCP Server provides a unified interface for port / directory / HTTP detection, the attack MCP Server provides non-interactive unified calling of exploit commands, and retains verifiable evidence fields.

5. The method of claim 1, wherein, In S4, dynamic knowledge graph is used to model and update the collected information in real time. Specifically, the entities such as Host, Port, Service, Vulnerability, WebSite, SensWebPath and their relationships are represented in the form of node-edge, and the corresponding attributes are maintained to support situation awareness and task planning.

6. The method of claim 1, wherein, In S5, a preference-driven chain thinking mechanism is introduced to align and denoise the output results of penetration testing tools. The mechanism follows a four-step process of strict deduplication, classification summary, strict information fabrication prohibition, and fact verification, and uses a unified result report format for downstream consumption.

7. The method of claim 1, wherein, In S6, the system architecture makes a two-stage decision based on dynamic knowledge graph and action history execution during task planning: first, context retrieval, then strategy generation. The reconnaissance / attack agent generates specific commands accordingly and calls the penetration testing tools through the respective MCPServer.

8. The method of claim 1, wherein, In S7, the system architecture records the agent behavior, environment state, reasoning chain and penetration testing tool output results in real time during task execution, dynamically updates the knowledge graph according to the execution results, and returns the final summary to the master control agent. The above process is repeated until the scene goal is reached or the stop condition is met, realizing the self-adaptive optimization of complex environment.

9. The method of claim 1, wherein, In S8, the following three indicators are introduced to quantitatively evaluate the penetration strategy: Penetration success rate PSR, used to measure the success rate of the system architecture in completing penetration tasks in multiple environments, calculated as follows: where p is the number of times the method successfully obtains webshell authority, and n is the total number of tests. The higher the PSR value, the stronger the task completion ability. Average training round number AE, used to measure the average number of rounds tried by the master control agent in all experiments in multiple environments, calculated as follows: where e i denotes the number of training epochs performed in the i-th experiment; The lower the AE value, the more accurate the strategy decision of the master control agent. Average execution step number AS, used to measure the average number of steps required by the reconnaissance agent and the attack agent to complete the reconnaissance task and the attack task each time, calculated as follows: where S i,j denotes the number of steps performed in the jth round of the ith experiment, and m denotes the number of rounds in the ith experiment. The lower the AS value, the stronger the ability of the reconnaissance agent and the attack agent in executing tactical decisions.

10. A computer device, comprising: A memory and a processor, the memory stores a computer program, the computer program is executed by the processor, so that the processor executes the multi-agent penetration testing tool scheduling and unified calling method steps of any one of claims 1-9.

Citation Information

Patent Citations

  • Multi-intelligent body-based hierarchical cloud computing model construction method

    CN101719931A

  • Penetration test agent system driven by large language model and test method

    CN119150912A