邮电设计技术2024,Issue(8) :1-7.DOI:10.12045/j.issn.1007-3043.2024.08.001

基于AI的智能化渗透测试技术研究

Research on Intelligent Penetration Testing Technology Based on AI

张小梅 郑涛 李长连 刘兵 熊琛 王昭顺
邮电设计技术2024,Issue(8) :1-7.DOI:10.12045/j.issn.1007-3043.2024.08.001

基于AI的智能化渗透测试技术研究

Research on Intelligent Penetration Testing Technology Based on AI

张小梅 1郑涛 1李长连 2刘兵 3熊琛 4王昭顺4
扫码查看

作者信息

  • 1. 中国联合网络通信集团有限公司,北京 100033
  • 2. 中讯邮电咨询设计院有限公司,北京 100048
  • 3. 北京墨云科技有限公司,北京 100094
  • 4. 北京科技大学,北京 100083
  • 折叠

摘要

传统的渗透测试方式依赖测试人员的经验,而自动化测试通常基于已知的攻击模式和漏洞库,因此在面对复杂的网络场景时,难以实施灵活高效的渗透测试.针对上述问题,利用人工智能技术赋能自动化渗透测试,提出了基于强化认知决策的智能化渗透测试方案,通过拆解渗透攻击的各个阶段并提取攻击单元,设计迭代运行的系统架构,动态生成攻击行为,针对复杂的网络环境,利用强化学习实现攻击决策智能体的自进化学习,实现高效的智能化渗透测试.

Abstract

Traditional penetration testing relies on the expertise of engineers,while automatic testing based on known attack patterns and vulnerability databases lacks the flexibility and efficiency to address complex network scenarios.To address these challenges,it proposes an intelligent penetration testing approach empowered by artificial intelligence techniques,based on reinforcement cognition decision-making.By decomposing the penetration attack into various stages and extracting attack units,an iterative system architecture is designed to dynamically generate attack behaviors.To tackle complex network environments,a reinforcement learning-based approach is employed to enable self-evolution capabilities of the attack decision-making agent,achieving efficient intelligent penetration testing.

关键词

渗透测试/强化认知决策/攻击决策智能体/自进化学习/智能化渗透测试

Key words

Penetration test/Reinforcement cognition and decision-making/Attack decision-making agent/Self-evolution learning/Intelligent penetration testing

引用本文复制引用

出版年

2024
邮电设计技术
中讯邮电咨询设计院有限公司

邮电设计技术

影响因子:0.647
ISSN:1007-3043
段落导航相关论文