arXiv:2501.16466cs.CRcs.AI2025-01被引 24

用大模型自动攻破多主机网络,成功率超90%且成本极低。

Incalmo: An Autonomous LLM-assisted System for Red Teaming Multi-Host Networks

  • 通过声明式任务+专用代理,让大模型自主规划跨主机攻击路径。
  • 在40个模拟环境中成功获取关键资产37次,远超现有系统(仅3次)。
  • 适合安全研究者和自动化渗透测试团队快速验证防御短板。

安全团队常通过红队演练模拟真实攻击以发现防御漏洞。在企业级场景中,此类攻击需跨越多个跳板主机,但传统红队成本高、依赖专家经验。尽管大模型在夺旗赛中表现亮眼,我们发现当前最先进的LLM辅助攻防系统(如PentestGPT、CyberSecEval3)仍无法自主完成多主机攻击。基于对失败模式的分析,我们提出Incalmo——一个专为多主机网络红队设计的LLM辅助系统。Incalmo采用高阶声明式任务,由领域特定代理执行,并借助辅助服务管理上下文与已获取资产。我们构建了新的多主机攻击基准MHBench,包含40个真实感模拟网络(每网22至50台主机)。实验显示,Incalmo在37个环境中成功获取关键资产,而现有系统仅在3个中成功。高效性方面,成功攻击耗时12–54分钟,成本低于15美元(以LLM调用计费)。

原文摘要 · Abstract (English)

Security operators use red teams to simulate real attackers and proactively find defense gaps. In realistic enterprise settings, this involves executing multi-host network attacks spanning many "stepping stone" hosts. Unfortunately, red teams are expensive and entail significant expertise and effort. Given the promise of LLMs in CTF challenges, we first analyze if LLMs can autonomously execute multi-host red team exercises. We find that state-of-the-art LLM-assisted offense systems (e.g., PentestGPT, CyberSecEval3) with leading LLMs (e.g., Sonnet 4, Gemini 2.5 Pro) are unable to do so. Building on our observations in understanding the failure modes of state-of-the-art systems, we argue the need to improve the abstractions and interfaces for LLM-assisted red teaming. Based on this insight, we present the design and implementation of Incalmo, an LLM-assisted system for autonomously red teaming multi-host networks. Incalmo uses LLMs to plan red team exercises in terms of high-level declarative tasks that are executed by domain-specific task agents. Incalmo also uses auxiliary services to manage context and acquired assets. For our evaluation, we develop MHBench, a novel multi-host attack benchmark with 40 realistic emulated networks (from 22 to 50 hosts). We find that Incalmo successfully acquires critical assets (i.e., key hosts or data) in 37 out of 40 MHBench environments. In contrast, state-of-the-art LLM-assisted systems succeed in only 3 out of 40 environments. We show that Incalmo is efficient-successful attacks took 12-54 minutes and cost <$15 in LLM credits.

红队演练大模型攻防自动化渗透网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。