Penetration testing method, apparatus, electronic device, and computer storage medium

By constructing a domain knowledge graph using pre-trained network models and large language models, the system automatically extracts and corrects entities and their relationships in penetration testing, solving the problem of low penetration testing quality and achieving more efficient and accurate penetration testing.

CN122197018APending Publication Date: 2026-06-12BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING HONGTENG INTELLIGENT TECH CO LTD
Filing Date
2024-12-11
Publication Date
2026-06-12

AI Technical Summary

Technical Problem

Current penetration testing methods that rely on large language models suffer from poor penetration quality, particularly in terms of illusion and interpretability.

Method used

By extracting entities and their relationships from threat intelligence source data using pre-trained network models and large language models, a domain knowledge graph is constructed. Combined with the large language model, penetration testing is performed on target assets, automatically extracting and correcting entities and their relationships in attack techniques, tactics, and attack implementation processes.

Benefits of technology

It improves the quality and efficiency of penetration testing, reduces the illusions in the reasoning process of large language models, and ensures the comprehensiveness and accuracy of information on attack techniques, tactics, and the attack implementation process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122197018A_ABST
    Figure CN122197018A_ABST
Patent Text Reader

Abstract

The application discloses a penetration testing method and device, electronic equipment and computer storage medium. Wherein, the method comprises: extracting entities and their relationships related to attack techniques and tactics and attack implementation process in threat intelligence source data through a pre-trained network model and a large language model; constructing a domain knowledge graph related to attack techniques and tactics and attack implementation process according to the entities and their relationships; and performing penetration testing on target assets based on the large language model and the domain knowledge graph. Through the above scheme, the large language model can combine the domain knowledge graph to infer more reasonable penetration attack steps, reducing the hallucinations of the large language model in the reasoning process, thereby effectively improving the quality of penetration testing.
Need to check novelty before this filing date? Find Prior Art