A method and system for automatically constructing an adaptive penetration testing attack path based on a large language model

The penetration testing system driven by a large language model collects and infers test status in real time and dynamically decides attack paths, solving the problems of rigid execution logic and invalid operations in traditional penetration testing, and realizing efficient and interpretable adaptive penetration testing.

CN122419980APending Publication Date: 2026-07-17
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Filing Date
2026-06-11
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing automated penetration testing technologies suffer from rigid execution logic, numerous invalid operations, lack of contextual semantic reasoning capabilities, and no failure path backtracking mechanism. They are unable to dynamically and adaptively construct attack paths, resulting in low testing efficiency, severe resource waste, and uninterpretable test results.

Method used

It adopts a large language model as the penetration testing decision engine, collects test status in real time, and dynamically decides the optimal attack action through semantic understanding and logical reasoning of the large language model, constructs an adaptive attack path, and is equipped with an intelligent backtracking mechanism for failed paths to generate an interpretable attack path chain.

Benefits of technology

Significantly improves the intelligence and efficiency of penetration testing, reduces invalid operations, adapts to diverse target assets, enables intelligent decision-making and path optimization throughout the entire process, and generates interpretable test reports.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122419980A_ABST
    Figure CN122419980A_ABST
Patent Text Reader

Abstract

本发明公开了一种基于大语言模型的自适应渗透测试攻击路径自动构建方法及系统,属于网络安全测试技术领域。本发明旨在解决现有自动化渗透测试工具采用固定流水线、缺乏上下文推理、无法动态调整攻击策略导致效率低下与适应性差的问题。本发明将大语言模型作为渗透测试的决策引擎,通过实时接收、语义关联并分析不同安全工具的阶段性输出结果,由大语言模型自主推理并动态决策下一步攻击动作,构建出非固定的、自适应的攻击路径。系统主要包括LLM决策引擎、工具执行器、状态管理器和结果解析器。本发明实现了攻击路径的智能化动态生成与失效路径的自动回溯,显著减少了无效操作,提升了对未知场景的适应性和渗透测试的整体效率。
Need to check novelty before this filing date? Find Prior Art