NIG-AP: a newmethod for automated penetration testing

Tian-yang ZHOU , Yi-chao ZANG , Jun-hu ZHU , Qing-xian WANG

Front. Inform. Technol. Electron. Eng ›› 2019, Vol. 20 ›› Issue (9) : 1277 -1298.

PDF (821KB)
Front. Inform. Technol. Electron. Eng ›› 2019, Vol. 20 ›› Issue (9) : 1277 -1298. DOI: 10.1631/FITEE.1800532
Orginal Article
Orginal Article

NIG-AP: a newmethod for automated penetration testing

Author information +
History +
PDF (821KB)

Abstract

Penetration testing offers strong advantages in the discovery of hidden vulnerabilities in a network and assessing network security. However, it can be carried out by only security analysts, which costs considerable time and money. The natural way to deal with the above problem is automated penetration testing, the essential part of which is automated attack planning. Although previous studies have explored various ways to discover attack paths, all of them require perfect network information beforehand, which is contradictory to realistic penetration testing scenarios. To vividly mimic intruders to find all possible attack paths hidden in a network from the perspective of hackers, we propose a network information gain based automated attack planning (NIG-AP) algorithm to achieve autonomous attack path discovery. The algorithm formalizes penetration testing as a Markov decision process and uses network information to obtain the reward, which guides an agent to choose the best response actions to discover hidden attack paths from the intruder’s perspective. Experimental results reveal that the proposed algorithm demonstrates substantial improvement in training time and effectiveness when mining attack paths.

Keywords

Penetration testing / Reinforcement learning / Classical planning / Partially observable Markov decision process

Cite this article

Download citation ▾
Tian-yang ZHOU, Yi-chao ZANG, Jun-hu ZHU, Qing-xian WANG. NIG-AP: a newmethod for automated penetration testing. Front. Inform. Technol. Electron. Eng, 2019, 20(9): 1277-1298 DOI:10.1631/FITEE.1800532

登录浏览全文

4963

注册一个新账户 忘记密码

References

RIGHTS & PERMISSIONS

Zhejiang University and Springer-Verlag GmbH Germany, part of Springer Nature

AI Summary AI Mindmap
PDF (821KB)

Supplementary files

Supplementary Material 1

Supplementary Material 2

2507

Accesses

0

Citation

Detail

Sections
Recommended

AI思维导图

/