用AI多智能体自动攻防测试,快速发现并利用本地网络漏洞
BreachSeek: A Multi-Agent Automated Penetration Tester
- 基于LLM的多智能体系统,自主完成漏洞探测与攻击模拟
- 在本地网络中成功利用可被攻击的机器,验证实际有效性
- 适合安全团队用于自动化渗透测试,提升效率与覆盖范围
现代数字环境日益复杂,传统网络安全渗透测试方法耗时费力,难以快速应对新威胁。亟需一种无需大量人工干预的自动化解决方案,以高效识别并利用跨系统漏洞。BreachSeek 提出一个基于大语言模型(LLMs)的多智能体软件平台,通过 LangChain 与 LangGraph 在 Python 中集成,使智能体能自主完成漏洞发现、多种攻击模拟、漏洞利用及生成完整安全报告。初步评估显示,BreachSeek 成功在本地网络中利用可被攻击的机器,证明其实际有效性。未来将扩展功能,目标成为网络安全专业人士不可或缺的工具。
原文摘要 · Abstract (English)
The increasing complexity and scale of modern digital environments have exposed significant gaps in traditional cybersecurity penetration testing methods, which are often time-consuming, labor-intensive, and unable to rapidly adapt to emerging threats. There is a critical need for an automated solution that can efficiently identify and exploit vulnerabilities across diverse systems without extensive human intervention. BreachSeek addresses this challenge by providing an AI-driven multi-agent software platform that leverages Large Language Models (LLMs) integrated through LangChain and LangGraph in Python. This system enables autonomous agents to conduct thorough penetration testing by identifying vulnerabilities, simulating a variety of cyberattacks, executing exploits, and generating comprehensive security reports. In preliminary evaluations, BreachSeek successfully exploited vulnerabilities in exploitable machines within local networks, demonstrating its practical effectiveness. Future developments aim to expand its capabilities, positioning it as an indispensable tool for cybersecurity professionals.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。