arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.03383cs.AI

CVE2AP:通过大型语言模型自动生成PDDL编码的攻击路径

CVE2AP: Automated Generation of PDDL-Encoded Attack Paths via Large Language Models

Lin Cui, Vincenzo Scotti, Raffaela Mirandola

首次发表
浏览论文内容

中文总结 AI 辅助

提出CVE2AP,利用大型语言模型从CVE描述自动生成PDDL编码的攻击路径,通过结构化提示和错误反馈迭代优化,在多个LLM上实现高语法、可解性和语义正确性。

中文摘要 AI 辅助

攻击路径(AP)建模是网络安全分析的基础,其中规划域定义语言(PDDL)已被广泛采用,将攻击路径编码为形式化且机器可验证的表示,用于对漏洞利用、攻击进程及其潜在影响进行自动化推理。然而,现有的攻击路径建模方法主要依赖专家驱动的手动构建,限制了其可扩展性以及跟上快速演变的网络威胁的能力。大型语言模型(LLMs)是有前景的候选方案,因为它们广泛的预训练知识和推理能力使其能够解释威胁情报并将其转换为形式化表示。在本文中,我们提出CVE2AP,一种基于LLM的方法,用于从自然语言的CVE(通用漏洞披露)描述中自动生成PDDL编码的攻击路径。CVE2AP利用结构化提示,并整合了错误反馈机制,该机制使用规划器报告的语法和可解性错误迭代地改进生成的路径。我们跨多个LLM和生成配置进行了系统的实证评估,从语法、可解性和语义维度评估生成质量,同时考虑令牌消耗和生成时间。结果表明,CVE2AP有效地生成了高质量的PDDL编码攻击路径,在LLM作为专家的评估下,实现了高达86.9%的语法正确性、78.6%的可解性和93.1%的语义正确性,而GPT-5.5提供了最佳的质量-成本权衡,错误反馈产生了最一致的质量改进。

英文摘要

Attack Path (AP) modeling is fundamental to cybersecurity analysis, where the Planning Domain Definition Language (PDDL) has been widely adopted to encode APs into formal and machine-verifiable representations for automated reasoning about vulnerability exploitation, attack progression, and their potential impacts. However, existing AP modeling approaches largely rely on expert-driven manual construction, limiting their scalability and ability to keep pace with rapidly evolving cyber threats. Large language models (LLMs) are promising candidates, as their extensive pre-trained knowledge and reasoning capabilities enable them to interpret and transform threat intelligence into formal representations. In this paper, we propose \textbf{CVE2AP}, an LLM-based approach for automatically generating PDDL-encoded attack paths from natural language CVE (Common Vulnerability Exposure) descriptions. CVE2AP leverages structured prompting and incorporates an error-feedback mechanism that iteratively refines the generated paths using planner-reported syntactic and solvability errors. We conduct a systematic empirical evaluation across multiple LLMs and generation configurations, assessing generation quality across syntactic, solvability and semantic dimensions, together with token consumption and generation time. The results demonstrate that CVE2AP effectively generates high-quality PDDL-encoded attack paths, achieving up to 86.9\% syntax correctness, 78.6\% solvability, and 93.1\% semantic correctness under LLM-as-expert evaluation, while \texttt{GPT-5.5} offers the best quality-cost trade-off and error feedback yields the most consistent quality improvement.

发表机构

  • Karlsruhe Institute of Technology(卡尔斯鲁厄理工学院)

机构由 AI 辅助整理,请以论文原文为准。

↑