基于大语言模型的渗透测试在蜜罐存在场景下的研究
LLM-Based Penetration Testing in the Presence of Honeypots
- The Pennsylvania State University(宾夕法尼亚州立大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本研究系统研究蜜罐存在下LLM攻击智能体的预算分配问题,提出检测器引导策略,使攻击者能有效分配预算攻陷主机,并讨论了对未来自适应蜜罐设计的影响。
AI中文摘要:
大语言模型(LLM)智能体正越来越多地被用于进攻性网络安全任务,如自动化漏洞发现、侦察和渗透测试。这一新能力也威胁到了防御者最有价值的工具之一:欺骗。传统蜜罐依赖真实性和隐蔽性来诱使人类或脚本驱动的攻击者暴露战术、技术和程序(TTPs),但由LLM驱动的攻击者能够对异构工件进行推理,并利用对蜜罐的怀疑来指导目标选择决策。我们针对LLM攻击智能体提出了一项关于蜜罐感知预算分配的系统性研究。我们将攻击者的问题形式化为一个预算决策过程:智能体与潜在目标交互,在侦察和利用阶段消耗LLM执行预算,并且当出现蜜罐怀疑时,必须决定是(继续利用)还是(跳过)。我们的研究结果表明,借助所提出的检测器引导策略,LLM智能体攻击者能够有效地分配预算以攻陷主机池中的主机,这凸显了在受控混合主机测试平台中动态分配预算的重要性。虽然防御措施超出了当前的研究范围,但我们讨论了对未来具有对抗韧性和自适应性的蜜罐设计的影响。
英文摘要:
Large language model (LLM) agents are increasingly employed for offensive cybersecurity tasks such as automated vulnerability discovery, reconnaissance, and penetration testing. This new capability also threatens one of the defender's most valuable tools: deception. Traditional honeypots rely on realism and obscurity to lure human or script-driven attackers into revealing tactics, techniques, and procedures (TTPs), but LLM-driven attackers can reason about heterogeneous artifacts and use the honeypot suspicion to guide target-selection decisions. We present a systematic study of honeypot-aware budget allocation for LLM attack agents. We formalize the attacker's problem as a budgeted decision process: an agent interacts with potential targets, consuming LLM execution budget during reconnaissance and exploitation, and must decide whether to (continue exploitation) or (skip) when honeypot suspicion arises. Our findings show that with the proposed detector-guided policy, LLM agent attackers can effectively allocate budget to compromise hosts in a host pool, highlighting the importance of dynamically allocating budget in a controlled mixed-host testbed. While defenses are beyond our present scope, we discuss implications for future adversarially resilient and adaptive honeypot design.