arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

RangeFactory:可扩展多跳网络靶场构建框架

RangeFactory: Scalable Construction of Multi-Hop Cyber Ranges

Hanlin Jiang, Puyi Wang, Jiandong Jin, Shaofei Li, Zhan Shen, Pengli Wang, Ziming Wang, Yifeng Cai, Ning Jia, Yuxin Ren, Peng Jiang, Yao Guo, Ding Li

arXiv 2608.09526首次发表:更新:

发表机构

Peking University; Huawei Technologies Co., Ltd.; Southeast University(北京大学; 华为技术有限公司; 东南大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

RangeFactory是自动化网络靶场编排框架,可规模化构建多跳靶场;其构建的RangeBench含1148个靶场实例,发现智能体存在持续入侵差距,还生成了攻击轨迹语料库。

AI 中文摘要

现实世界中的网络攻击往往需要在多个主机和网络段间持续推进,因此多跳网络靶场成为研究和提升大语言模型(LLM)智能体维持完整攻击链能力的关键基础设施。现有研究虽已扩展孤立漏洞任务,并通过手动指定漏洞语义构建多主机场景,但仍无法自动将日益增多的漏洞环境编排为端到端验证的多跳靶场。为此,本文提出RangeFactory,一种自动化网络靶场编排框架,可从孤立漏洞环境规模化构建多跳网络靶场。RangeFactory将靶场构建建模为依赖关系解析:从智能体针对真实漏洞的实际攻击中提取依赖信息,通过模板引导的编排解析已知依赖,并利用端到端攻击执行验证组合后出现的运行时依赖。借助RangeFactory,本文构建了RangeBench,包含1148个经验证的靶场实例,覆盖287条不同攻击链,并从攻击深度、网络规模和任务信息维度评估前沿攻击智能体。在成功入侵入口漏洞的运行中,24.5%至47.0%的智能体仍无法完成剩余攻击路径,揭示了建立初始立足点与完成多跳攻击间存在显著的持续入侵差距。RangeFactory还生成了包含5541条带结果标注的多跳攻击轨迹语料库,为攻击过程分析和未来智能体训练提供执行数据。

英文摘要

Real-world cyberattacks often require sustained progress across multiple hosts and network segments, making multi-hop cyber ranges essential infrastructure for studying and improving LLM agents' ability to sustain complete attack chains. Prior work has scaled isolated vulnerability tasks and constructed multi-host scenarios from manually specified vulnerability semantics. However, they are still unable to automatically orchestrate the growing supply of vulnerability environments into end-to-end validated multi-hop ranges. To this end, we present RangeFactory, an automated cyber-range orchestration framework that constructs multi-hop cyber ranges at scale from isolated vulnerability environments. RangeFactory formulates range construction as dependency resolution: it extracts dependency information from agents' actual attacks against real vulnerabilities, resolves known dependencies through template-guided orchestration, and uses end-to-end attack execution to validate runtime dependencies that emerge after composition. Using RangeFactory, we construct RangeBench with 1,148 validated range instances spanning 287 distinct attack chains and evaluate frontier attack agents across attack depth, network scale, and task information. Among runs that compromise the entry vulnerability, 24.5-47.0% still fail to complete the remaining attack path, revealing a substantial sustained-compromise gap between establishing an initial foothold and completing a multi-hop attack. RangeFactory further produces a corpus of 5,541 outcome-annotated multi-hop attack trajectories, providing execution data for attack-process analysis and future agent training.

Comments16 pages, 2 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑