VulnBot: Autonomous Penetration Testing for A Multi-Agent Collaborative Framework

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kong, He, Hu, Die, Ge, Jingguo, Li, Liangxiong, Li, Tong, Wu, Bingzhen
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913661923098624
author Kong, He
Hu, Die
Ge, Jingguo
Li, Liangxiong
Li, Tong
Wu, Bingzhen
author_facet Kong, He
Hu, Die
Ge, Jingguo
Li, Liangxiong
Li, Tong
Wu, Bingzhen
contents Penetration testing is a vital practice for identifying and mitigating vulnerabilities in cybersecurity systems, but its manual execution is labor-intensive and time-consuming. Existing large language model (LLM)-assisted or automated penetration testing approaches often suffer from inefficiencies, such as a lack of contextual understanding and excessive, unstructured data generation. This paper presents VulnBot, an automated penetration testing framework that leverages LLMs to simulate the collaborative workflow of human penetration testing teams through a multi-agent system. To address the inefficiencies and reliance on manual intervention in traditional penetration testing methods, VulnBot decomposes complex tasks into three specialized phases: reconnaissance, scanning, and exploitation. These phases are guided by a penetration task graph (PTG) to ensure logical task execution. Key design features include role specialization, penetration path planning, inter-agent communication, and generative penetration behavior. Experimental results demonstrate that VulnBot outperforms baseline models such as GPT-4 and Llama3 in automated penetration testing tasks, particularly showcasing its potential in fully autonomous testing on real-world machines.
format Preprint
id arxiv_https___arxiv_org_abs_2501_13411
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle VulnBot: Autonomous Penetration Testing for A Multi-Agent Collaborative Framework
Kong, He
Hu, Die
Ge, Jingguo
Li, Liangxiong
Li, Tong
Wu, Bingzhen
Software Engineering
Penetration testing is a vital practice for identifying and mitigating vulnerabilities in cybersecurity systems, but its manual execution is labor-intensive and time-consuming. Existing large language model (LLM)-assisted or automated penetration testing approaches often suffer from inefficiencies, such as a lack of contextual understanding and excessive, unstructured data generation. This paper presents VulnBot, an automated penetration testing framework that leverages LLMs to simulate the collaborative workflow of human penetration testing teams through a multi-agent system. To address the inefficiencies and reliance on manual intervention in traditional penetration testing methods, VulnBot decomposes complex tasks into three specialized phases: reconnaissance, scanning, and exploitation. These phases are guided by a penetration task graph (PTG) to ensure logical task execution. Key design features include role specialization, penetration path planning, inter-agent communication, and generative penetration behavior. Experimental results demonstrate that VulnBot outperforms baseline models such as GPT-4 and Llama3 in automated penetration testing tasks, particularly showcasing its potential in fully autonomous testing on real-world machines.
title VulnBot: Autonomous Penetration Testing for A Multi-Agent Collaborative Framework
topic Software Engineering
url https://arxiv.org/abs/2501.13411