A multi-agent based automated penetration testing method and apparatus

By combining a multi-agent architecture and a large language model, intelligent penetration testing is achieved, which solves the problems of low intelligence and high reliance on human labor in existing penetration testing technologies, improves vulnerability discovery rate and testing efficiency, and ensures the security and consistency of the testing process.

CN122412290APending Publication Date: 2026-07-17BEIJING BAIGEFEICHI TECH LLC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING BAIGEFEICHI TECH LLC
Filing Date
2026-04-01
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing penetration testing techniques rely on human experience, cannot intelligently plan attack paths, and are difficult to cover complex business logic vulnerabilities. Furthermore, automated tools lack context awareness and dynamic adjustment capabilities, resulting in high false negative rates, numerous false positives, high labor costs, and long testing cycles.

Method used

A multi-agent architecture is adopted, introducing a root agent and sub-agents to cooperate in a hierarchical manner. A large language model is used for policy generation and task decomposition. Through semantic analysis and closed-loop decision-making, real attack behaviors are simulated to achieve dynamic task orchestration and efficient execution.

Benefits of technology

It significantly reduces reliance on human experts, improves vulnerability discovery rates and testing efficiency, ensures contextual consistency and non-destructiveness, and adapts to the stable execution of complex business logic and long-chain tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122412290A_ABST
    Figure CN122412290A_ABST
Patent Text Reader

Abstract

本申请公开了一种基于多智能体的自动化渗透测试方法和装置。该方法包括:接收渗透测试目标并创建根智能体;所述根智能体请求大语言模型生成测试策略,并根据策略动态创建子智能体执行子任务;所述子智能体从大语言模型接收工具执行步骤,调用安全工具执行扫描;所述子智能体将扫描结果返回给大语言模型进行语义分析,形成执行‑分析‑推进的闭环决策;所述根智能体收集所有子智能体的处理结果,汇总生成渗透测试报告。本申请通过分层协同的多智能体架构,结合大语言模型的推理能力,实现了渗透测试的高度自动化与智能化,提升了测试效率和漏洞覆盖率。
Need to check novelty before this filing date? Find Prior Art