arXiv:2508.03882cs.CRcs.AI2025-08被引 3

用混沌工程提升攻防演练,自动模拟真实黑客攻击路径。

Simulating Cyberattacks through a Breach Attack Simulation (BAS) Platform empowered by Security Chaos Engineering (SCE)

  • 将混沌工程融入攻防模拟平台,自动生成攻击链路。
  • 基于MITRE Caldera实现自动化攻击序列,构建推断攻击树。
  • 适合安全团队用于发现隐藏漏洞,提升防御韧性。

在当今数字环境中,组织面临持续演进的网络威胁,亟需通过安全混沌工程(SCE)等新方法识别隐蔽攻击路径,有效测试防御体系并发现漏洞。本文提出将SCE集成至漏洞攻击模拟(BAS)平台,利用现有威胁情报数据库中的攻击者画像与能力。该方案采用三层结构:SCE编排器、连接器与BAS层。在BAS层使用MITRE Caldera执行自动化攻击序列,基于攻击者画像生成推断攻击树。评估表明,SCE与BAS融合可显著提升攻击模拟的覆盖深度与真实性,超越传统静态场景,是构建有效网络安全防御策略的重要组成部分。

原文摘要 · Abstract (English)

In today digital landscape, organizations face constantly evolving cyber threats, making it essential to discover slippery attack vectors through novel techniques like Security Chaos Engineering (SCE), which allows teams to test defenses and identify vulnerabilities effectively. This paper proposes to integrate SCE into Breach Attack Simulation (BAS) platforms, leveraging adversary profiles and abilities from existing threat intelligence databases. This innovative proposal for cyberattack simulation employs a structured architecture composed of three layers: SCE Orchestrator, Connector, and BAS layers. Utilizing MITRE Caldera in the BAS layer, our proposal executes automated attack sequences, creating inferred attack trees from adversary profiles. Our proposal evaluation illustrates how integrating SCE with BAS can enhance the effectiveness of attack simulations beyond traditional scenarios, and be a useful component of a cyber defense strategy.

攻防演练混沌工程安全模拟

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。