arXiv:2410.05105cs.CRcs.AI2024-10被引 2

用AI提升渗透测试效率,但需人类把关。

AI-Enhanced Ethical Hacking: A Linux-Focused Experiment

  • 用ChatGPT辅助Linux系统渗透各阶段操作。
  • 实验显示AI能显著加速测试流程,提升效率。
  • 适合安全研究人员与红队成员参考实践。

本技术报告通过全面实验与概念分析,研究生成式人工智能(GenAI)——特别是ChatGPT——在伦理黑客攻击中的集成应用。实验在受控虚拟环境中进行,评估了GenAI在针对运行于虚拟局域网(LAN)的Linux目标机进行渗透测试的关键阶段(包括侦察、扫描与枚举、获取访问权限、维持访问及清除痕迹)中的有效性。结果表明,GenAI可显著增强并优化伦理黑客流程,同时强调了人类与AI之间平衡协作的重要性,而非完全替代人工。报告还深入探讨了潜在风险,如滥用、数据偏见、幻觉及对AI的过度依赖。本研究为人工智能在网络安全中伦理使用的讨论提供了贡献,并呼吁持续创新以强化安全防御能力。

原文摘要 · Abstract (English)

This technical report investigates the integration of generative AI (GenAI), specifically ChatGPT, into the practice of ethical hacking through a comprehensive experimental study and conceptual analysis. Conducted in a controlled virtual environment, the study evaluates GenAI's effectiveness across the key stages of penetration testing on Linux-based target machines operating within a virtual local area network (LAN), including reconnaissance, scanning and enumeration, gaining access, maintaining access, and covering tracks. The findings confirm that GenAI can significantly enhance and streamline the ethical hacking process while underscoring the importance of balanced human-AI collaboration rather than the complete replacement of human input. The report also critically examines potential risks such as misuse, data biases, hallucination, and over-reliance on AI. This research contributes to the ongoing discussion on the ethical use of AI in cybersecurity and highlights the need for continued innovation to strengthen security defences.

AI渗透测试生成式AI网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。