PentestAgent: Incorporating LLM Agents to Automated Penetration Testing

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Shen, Xiangmin, Wang, Lingzhi, Li, Zhenyuan, Chen, Yan, Zhao, Wencheng, Sun, Dawei, Wang, Jiashui, Ruan, Wei
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866918038527279104
author Shen, Xiangmin
Wang, Lingzhi
Li, Zhenyuan
Chen, Yan
Zhao, Wencheng
Sun, Dawei
Wang, Jiashui
Ruan, Wei
author_facet Shen, Xiangmin
Wang, Lingzhi
Li, Zhenyuan
Chen, Yan
Zhao, Wencheng
Sun, Dawei
Wang, Jiashui
Ruan, Wei
contents Penetration testing is a critical technique for identifying security vulnerabilities, traditionally performed manually by skilled security specialists. This complex process involves gathering information about the target system, identifying entry points, exploiting the system, and reporting findings. Despite its effectiveness, manual penetration testing is time-consuming and expensive, often requiring significant expertise and resources that many organizations cannot afford. While automated penetration testing methods have been proposed, they often fall short in real-world applications due to limitations in flexibility, adaptability, and implementation. Recent advancements in large language models (LLMs) offer new opportunities for enhancing penetration testing through increased intelligence and automation. However, current LLM-based approaches still face significant challenges, including limited penetration testing knowledge and a lack of comprehensive automation capabilities. To address these gaps, we propose PentestAgent, a novel LLM-based automated penetration testing framework that leverages the power of LLMs and various LLM-based techniques like Retrieval Augmented Generation (RAG) to enhance penetration testing knowledge and automate various tasks. Our framework leverages multi-agent collaboration to automate intelligence gathering, vulnerability analysis, and exploitation stages, reducing manual intervention. We evaluate PentestAgent using a comprehensive benchmark, demonstrating superior performance in task completion and overall efficiency. This work significantly advances the practical applicability of automated penetration testing systems.
format Preprint
id arxiv_https___arxiv_org_abs_2411_05185
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle PentestAgent: Incorporating LLM Agents to Automated Penetration Testing
Shen, Xiangmin
Wang, Lingzhi
Li, Zhenyuan
Chen, Yan
Zhao, Wencheng
Sun, Dawei
Wang, Jiashui
Ruan, Wei
Cryptography and Security
Penetration testing is a critical technique for identifying security vulnerabilities, traditionally performed manually by skilled security specialists. This complex process involves gathering information about the target system, identifying entry points, exploiting the system, and reporting findings. Despite its effectiveness, manual penetration testing is time-consuming and expensive, often requiring significant expertise and resources that many organizations cannot afford. While automated penetration testing methods have been proposed, they often fall short in real-world applications due to limitations in flexibility, adaptability, and implementation. Recent advancements in large language models (LLMs) offer new opportunities for enhancing penetration testing through increased intelligence and automation. However, current LLM-based approaches still face significant challenges, including limited penetration testing knowledge and a lack of comprehensive automation capabilities. To address these gaps, we propose PentestAgent, a novel LLM-based automated penetration testing framework that leverages the power of LLMs and various LLM-based techniques like Retrieval Augmented Generation (RAG) to enhance penetration testing knowledge and automate various tasks. Our framework leverages multi-agent collaboration to automate intelligence gathering, vulnerability analysis, and exploitation stages, reducing manual intervention. We evaluate PentestAgent using a comprehensive benchmark, demonstrating superior performance in task completion and overall efficiency. This work significantly advances the practical applicability of automated penetration testing systems.
title PentestAgent: Incorporating LLM Agents to Automated Penetration Testing
topic Cryptography and Security
url https://arxiv.org/abs/2411.05185