arXiv:2602.14106cs.CRcs.AI2026-02

用大模型自动生成攻击路径图,提前发现安全漏洞

Anticipating Adversary Behavior in DevSecOps Scenarios through Large Language Models

  • 用大模型分析攻击者行为,生成防御树
  • 实现自动化安全实验,提升防御能力
  • 适合关注主动防御的DevSecOps团队

云环境中的数据是组织最宝贵的资产,正面临日益复杂的网络攻击。过去,许多政府机构和关键国家服务在云上实施安全措施常被视为可选,包括管理敏感信息的系统(如选举或军事行动),这些系统历来是网络犯罪分子的目标。安全措施的抵制往往源于对开发敏捷性的影响,导致漏洞累积风险上升。如今,仅修补软件已不足应对威胁,必须采用由人工智能支持的主动防御策略,以预测并缓解风险。本文提出将安全混沌工程(SCE)与基于大语言模型(LLM)的新流程结合,自动构建反映攻击者行为的防御树,支持基于图形化模型的SCE实验设计,使团队能够提前一步应对攻击,并实施此前未考虑的防御措施。实验详情及复现步骤见:https://github.com/mariomc14/devsecops-adversary-llm.git。

原文摘要 · Abstract (English)

The most valuable asset of any cloud-based organization is data, which is increasingly exposed to sophisticated cyberattacks. Until recently, the implementation of security measures in DevOps environments was often considered optional by many government entities and critical national services operating in the cloud. This includes systems managing sensitive information, such as electoral processes or military operations, which have historically been valuable targets for cybercriminals. Resistance to security implementation is often driven by concerns over losing agility in software development, increasing the risk of accumulated vulnerabilities. Nowadays, patching software is no longer enough; adopting a proactive cyber defense strategy, supported by Artificial Intelligence (AI), is crucial to anticipating and mitigating threats. Thus, this work proposes integrating the Security Chaos Engineering (SCE) methodology with a new LLM-based flow to automate the creation of attack defense trees that represent adversary behavior and facilitate the construction of SCE experiments based on these graphical models, enabling teams to stay one step ahead of attackers and implement previously unconsidered defenses. Further detailed information about the experiment performed, along with the steps to replicate it, can be found in the following repository: https://github.com/mariomc14/devsecops-adversary-llm.git.

安全防御大模型DevSecOps

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。