D-CIPHER用多智能体协作提升网络安全攻防任务的自动化能力
D-CIPHER: Dynamic Collaborative Intelligent Multi-Agent System with Planner and Heterogeneous Executors for Offensive Security
- 设计规划者与异构执行者协同的多智能体系统,动态分配任务
- 在三个基准上达到22.0%至44.0%准确率,优于之前方法2.5%~8.5%
- 可识别65%更多攻击技术,适合研究自动化渗透测试的开发者
大型语言模型(LLMs)已用于网络安全领域,如自主安全分析或渗透测试。夺旗(CTF)挑战被用作评估LLM智能体任务规划能力的基准。早期尝试使用单智能体系统解决CTF问题,反馈仅限于单一推理-行动循环,难以应对复杂任务。受真实世界CTF竞赛中专家团队协作启发,我们提出D-CIPHER LLM多智能体框架,用于协同解决CTF挑战。D-CIPHER整合具有不同角色的智能体,并通过动态反馈环增强复杂任务推理能力。其核心为规划者-执行者系统:规划者负责整体求解,多个异构执行者负责具体任务,实现职责高效分配。此外,引入自动提示生成器(Auto-prompter)以生成高度相关初始提示,提升求解效率。我们在多个CTF基准和LLM模型上进行综合评估,验证改进效果。同时,手动将NYU CTF Bench中的挑战映射到MITRE ATT&CK技术,全面评估D-CIPHER的进攻能力。D-CIPHER在三个基准上达到最优表现:在NYU CTF Bench上为22.0%,在Cybench上为22.5%,在HackTheBox上为44.0%,比之前工作高出2.5%至8.5%。相比之前工作,能解决65%更多的ATT&CK技术,展现出更强的进攻能力。
原文摘要 · Abstract (English)
Large Language Models (LLMs) have been used in cybersecurity such as autonomous security analysis or penetration testing. Capture the Flag (CTF) challenges serve as benchmarks to assess automated task-planning abilities of LLM agents for cybersecurity. Early attempts to apply LLMs for solving CTF challenges used single-agent systems, where feedback was restricted to a single reasoning-action loop. This approach was inadequate for complex CTF tasks. Inspired by real-world CTF competitions, where teams of experts collaborate, we introduce the D-CIPHER LLM multi-agent framework for collaborative CTF solving. D-CIPHER integrates agents with distinct roles with dynamic feedback loops to enhance reasoning on complex tasks. It introduces the Planner-Executor agent system, consisting of a Planner agent for overall problem-solving along with multiple heterogeneous Executor agents for individual tasks, facilitating efficient allocation of responsibilities among the agents. Additionally, D-CIPHER incorporates an Auto-prompter agent to improve problem-solving by auto-generating a highly relevant initial prompt. We evaluate D-CIPHER on multiple CTF benchmarks and LLM models via comprehensive studies to highlight the impact of our enhancements. Additionally, we manually map the CTFs in NYU CTF Bench to MITRE ATT&CK techniques that apply for a comprehensive evaluation of D-CIPHER's offensive security capability. D-CIPHER achieves state-of-the-art performance on three benchmarks: 22.0% on NYU CTF Bench, 22.5% on Cybench, and 44.0% on HackTheBox, which is 2.5% to 8.5% better than previous work. D-CIPHER solves 65% more ATT&CK techniques compared to previous work, demonstrating stronger offensive capability.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。