The invention provides an efficient multi-dimensional network penetration testing method based on RAG, which comprises the following steps: firstly, identifying sub-domain names possibly existing in a target website, and sequentially expanding
attack surfaces of penetration testing to obtain
vulnerability information pairs; secondly, a design model generated based on retrieval enhancement is adopted,
vulnerability information pairs are extracted from the
queue to be utilized, knowledge items related to local
knowledge base retrieval and network intelligent search retrieval are utilized, and finally, a
large model generates
vulnerability utilization information according to the knowledge items; acquiring target
machine permission for the previously acquired vulnerability information pair construction command
injector, and further scanning other hosts of the
intranet accessed by the target skipping
machine; finally, combining vulnerability information obtained by penetration testing, utilizing a
large model to sort vulnerabilities existing in different assets, and outputting penetration testing reports for different assets. According to the method and the
system, comprehensive penetration testing of cross-network and cross-
system is realized, security experts are helped to quickly identify, verify and repair vulnerabilities in a complex and changeable network environment, and high-efficiency and low-cost
network security maintenance is realized.