arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.22664cs.CRcs.AI

从能力到保障:自主渗透测试框架与参考实现

From Capability to Assurance in Autonomous Penetration-Testing Harnesses: A Framework and Reference Implementation

Joas Antonio dos Santos Barbosa

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出自主渗透测试框架的保障属性框架,定义五项可执行保障属性,并通过参考实现NeuroSploit验证其可实现性,发现执行缺口,为安全自主智能体提供审计基础。

中文摘要 AI 辅助

针对渗透测试的大语言模型智能体的研究几乎完全以能力来评估:智能体是否获取了标志或复现了概念验证。该指标适用于基准测试,但对于决定自主智能体能否在授权参与中使用的属性却保持沉默:报告发现是否真实,智能体是否停留在其授权范围内,以及操作员能否审计其行为。我们称这些为保障属性,并认为它们属于框架(即包裹模型的运行时),可以在代码中强制执行。本文做出三项贡献。首先,我们定义了一个包含五项保障属性的框架(证据接地、非破坏性声明缩减、计算严重性、强制授权和防篡改问责),每项属性都有形式化模型和明确的验收测试,并与基于能力的安全、防篡改日志和软件溯源方面的先前工作相关联。其次,我们使用已发布的编码标准将代表性系统(PentestGPT、Cochise参考框架、MAPTA和轨迹评判器PentestJudge)定位于该框架内,并识别出一致的保障缺口。第三,我们研究了一个开源实现NeuroSploit,固定到精确提交,报告其架构、复杂度成本以及针对公开的故意易受攻击目标运行的内容寻址工件包。我们直接执行确定性授权和审计验收测试,发现并报告了一个真实的执行缺口,通过将两项属性评为部分来反映这一点。因此,我们声称存在一个初步的存在性论证,即这些属性可以共同实现,而非比较性能结果,并指定了将框架义务转化为测量所需的多目标、消融和对抗性评估协议。

英文摘要

Research on large language model agents for penetration testing is evaluated almost entirely by capability: whether the agent captures a flag or reproduces a proof of concept. That metric suits a benchmark but is silent on the properties that decide whether an autonomous agent can be used in an authorized engagement: whether a reported finding is true, whether the agent stayed inside its authorized scope, and whether an operator can audit what it did. We call these assurance properties and argue that they belong to the harness, the runtime wrapping the model, and can be enforced in code. This paper makes three contributions. First, we define a framework of five assurance properties (evidence grounding, non destructive claim reduction, computed severity, enforced authorization, and tamper evident accountability), each with a formal model and an explicit acceptance test, connected to prior work in capability based security, tamper evident logging, and software provenance. Second, we position representative systems (PentestGPT, the Cochise reference harness, MAPTA, and the trajectory judge PentestJudge) within the framework using published coding criteria, and identify a consistent assurance gap. Third, we study one open source implementation, NeuroSploit, pinned to an exact commit, reporting its architecture, its complexity cost, and a content addressed artifact bundle from a run against a public deliberately vulnerable target. We execute the deterministic authorization and audit acceptance tests directly and find and report a real enforcement gap, which we reflect by scoring both properties as partial. We therefore claim an initial existence argument that the properties are realizable together, not a comparative performance result, and we specify the multi target, ablation, and adversarial evaluation protocol required to turn the framework obligations into measurements.

发表机构

  • Independent Researcher --- AI

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑