变异规避:基于知识驱动多智能体编排的自主端点规避
Mutate to Bypass: Autonomous Endpoint Evasion via Knowledge-Driven Multi-Agent Orchestration
浏览论文内容
中文总结 AI 辅助
研究针对商用EDR系统的自动化弹性评估难题,提出AutoBypass多智能体框架,经实验可高比例绕过多款商用EDR,还能提升开源模型的规避成功率。
中文摘要 AI 辅助
公开报告和开源资源披露了许多端点检测与响应(EDR)规避技术,但目前尚不清楚商用EDR系统能否抵御这些已记录的攻击。评估此类系统需要将碎片化的安全知识转化为可运行的有效载荷,并从模糊警报中优化这些有效载荷,现有自动化工具尚未解决这些任务。我们提出AutoBypass,一个基于知识的闭环多智能体框架,用于自动化EDR弹性评估。感知检测知识库将威胁情报、专家分析和开源概念验证构建为规避技术与操作约束。智能体利用该知识规划攻击、生成多态代码并编译二进制文件,而遥测驱动的推理引擎诊断故障并将纠正证据反馈至策略。在7个商用端点安全平台上,AutoBypass绕过了所有目标,对Windows Defender的规避率达90%,对趋势科技(Trend Micro)杀毒软件的规避率达86.7%。消融实验显示,该知识库将8B开源权重模型的成功率从27%–53%提升至43%–83%,使其接近大型专有模型。这些结果证明了一种将公共安全知识落地用于EDR弹性的持续自动化评估的系统方法。
英文摘要
Public reports and open-source resources expose many EDR evasion techniques, but it remains unclear whether commercial Endpoint Detection and Response (EDR) systems can withstand these documented attacks. Evaluating them requires turning fragmented security knowledge into working payloads and refining those payloads from opaque alerts, tasks that existing automation does not address. We present AutoBypass, a knowledge-grounded, closed-loop multi-agent framework for automated EDR resilience assessment. A Detection-Aware Knowledge Base structures threat intelligence, expert analyses, and open-source proofs of concept into evasion techniques and operational constraints. Agents use this knowledge to plan attacks, generate polymorphic code, and compile binaries, while a telemetry-driven reasoning engine diagnoses failures and feeds corrective evidence back into the strategy. Across seven commercial endpoint security platforms, AutoBypass bypassed every target, reaching 90% evasion against Windows Defender and 86.7% against Trend Micro AV. Ablations show that the knowledge base raises the success rates of 8B open-weight models from 27--53% to 43--83%, bringing them close to large proprietary models. These results demonstrate a systematic way to operationalize public security knowledge for continuous, automated assessment of EDR resilience.