用大模型自动从IP拿下服务器,全程无需人工介入。
RapidPen: Fully Automated IP-to-Shell Penetration Testing with LLM-based Agents
- 基于LLM的智能代理,自主规划攻击路径并执行
- 200-400秒内拿下目标,单次成本仅0.3-0.6美元
- 适合安全新手快速检测漏洞,也帮专家节省重复劳动
我们提出RapidPen,一个完全自动化的渗透测试框架,旨在无需人工干预即可实现从单一IP地址获取远程控制权(IP-to-Shell)。与以往主要关注后期利用或需人工参与的方法不同,RapidPen利用大语言模型(LLMs)自主发现并利用漏洞。通过结合ReAct式任务规划(Re)与基于成功攻击案例的知识库检索,以及命令生成与直接执行反馈循环(Act),RapidPen系统性地扫描服务、识别可行攻击向量并自动执行针对性利用。在针对Hack The Box平台漏洞靶机的评估中,RapidPen在200-400秒内达成远程访问,单次运行成本约0.3-0.6美元,复用历史成功案例时达到60%成功率。该结果表明,真正自治的渗透测试具备广泛应用潜力,既可帮助缺乏专业团队的企业快速识别关键漏洞,也能让资深渗透测试人员摆脱重复性工作,专注于复杂挑战。本研究致力于提升渗透测试的可及性与效率,从而增强现代软件生态的整体安全性。
原文摘要 · Abstract (English)
We present RapidPen, a fully automated penetration testing (pentesting) framework that addresses the challenge of achieving an initial foothold (IP-to-Shell) without human intervention. Unlike prior approaches that focus primarily on post-exploitation or require a human-in-the-loop, RapidPen leverages large language models (LLMs) to autonomously discover and exploit vulnerabilities, starting from a single IP address. By integrating advanced ReAct-style task planning (Re) with retrieval-augmented knowledge bases of successful exploits, along with a command-generation and direct execution feedback loop (Act), RapidPen systematically scans services, identifies viable attack vectors, and executes targeted exploits in a fully automated manner. In our evaluation against a vulnerable target from the Hack The Box platform, RapidPen achieved shell access within 200-400 seconds at a per-run cost of approximately \$0.3-\$0.6, demonstrating a 60\% success rate when reusing prior "success-case" data. These results underscore the potential of truly autonomous pentesting for both security novices and seasoned professionals. Organizations without dedicated security teams can leverage RapidPen to quickly identify critical vulnerabilities, while expert pentesters can offload repetitive tasks and focus on complex challenges. Ultimately, our work aims to make penetration testing more accessible and cost-efficient, thereby enhancing the overall security posture of modern software ecosystems. Fore more information, visit this link: https://secdevlab.com/rapidpen
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。