Penetration testing is a method of assessing the security of a system, application, or network by simulating the actions of an attacker. With the continuous development of the digital economy, the data protection and offensive and defensive confrontation of digital economic infrastructure are becoming increasingly fierce. How to improve the efficiency and accuracy of penetration testing through automation has become increasingly important. As an important part of artificial intelligence technology, knowledge graph provides new ideas for automated penetration testing with its efficient semantic understanding and reasoning capabilities. This paper can be divided into three parts according to the main content. First, it reviews and analyzes the current research status of automated penetration testing path planning. Secondly, it introduces the related construction methods of cyber security knowledge graph and ontology. Finally, it analyzed and compared attack path generation technology from multiple perspectives and looked forward to future research directions.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Application Research of Knowledge Graph in Automated Penetration Testing Path Planning in the Digital Era

  • Rufeng Liang,
  • Junhan Chen,
  • Xingchi Chen,
  • Xun Huang,
  • Jin Peng,
  • Chencong Zheng,
  • Haonan Zhang,
  • Wenguang Hu,
  • Gengchen Xu

摘要

Penetration testing is a method of assessing the security of a system, application, or network by simulating the actions of an attacker. With the continuous development of the digital economy, the data protection and offensive and defensive confrontation of digital economic infrastructure are becoming increasingly fierce. How to improve the efficiency and accuracy of penetration testing through automation has become increasingly important. As an important part of artificial intelligence technology, knowledge graph provides new ideas for automated penetration testing with its efficient semantic understanding and reasoning capabilities. This paper can be divided into three parts according to the main content. First, it reviews and analyzes the current research status of automated penetration testing path planning. Secondly, it introduces the related construction methods of cyber security knowledge graph and ontology. Finally, it analyzed and compared attack path generation technology from multiple perspectives and looked forward to future research directions.