自动化构建可扩展的多跳网络攻防环境,验证大模型攻击链持续性。
RangeFactory: Scalable Construction of Multi-Hop Cyber Ranges

- 基于真实攻击数据解析依赖关系,自动编排多跳攻击路径。
- 构建1148个验证过的攻击场景,47%的初始突破未能完成完整攻击链。
- 生成5541条带结果标注的攻击轨迹,助力智能攻防研究。
真实网络攻击常需跨多个主机与网络段持续推进,因此多跳网络攻防环境对评估和提升大模型代理(LLM agents)维持完整攻击链的能力至关重要。现有工作虽能扩展孤立漏洞任务或手动构建多主机场景,但无法自动将不断增长的漏洞环境组合为端到端验证的多跳攻防范围。为此,我们提出RangeFactory——一个自动化网络攻防范围编排框架,可从孤立漏洞环境大规模构建多跳攻防范围。RangeFactory将范围构建建模为依赖关系解析:从代理对真实漏洞的实际攻击中提取依赖信息,通过模板引导的编排解决已知依赖,并利用端到端攻击执行验证组合后出现的运行时依赖。使用RangeFactory,我们构建了包含1,148个验证实例、覆盖287种不同攻击链的RangeBench,评估前沿攻击代理在攻击深度、网络规模和任务信息下的表现。结果显示,在成功攻破入口漏洞的实验中,仍有24.5%-47.0%未能完成后续攻击路径,揭示了建立初始立足点与完成多跳攻击之间存在显著的持续破坏差距。此外,RangeFactory还生成了5,541条带结果标注的多跳攻击轨迹,为攻击过程分析和未来代理训练提供执行数据。
原文摘要 · Abstract (English)
Real-world cyberattacks often require sustained progress across multiple hosts and network segments, making multi-hop cyber ranges essential infrastructure for studying and improving LLM agents' ability to sustain complete attack chains. Prior work has scaled isolated vulnerability tasks and constructed multi-host scenarios from manually specified vulnerability semantics. However, they are still unable to automatically orchestrate the growing supply of vulnerability environments into end-to-end validated multi-hop ranges. To this end, we present RangeFactory, an automated cyber-range orchestration framework that constructs multi-hop cyber ranges at scale from isolated vulnerability environments. RangeFactory formulates range construction as dependency resolution: it extracts dependency information from agents' actual attacks against real vulnerabilities, resolves known dependencies through template-guided orchestration, and uses end-to-end attack execution to validate runtime dependencies that emerge after composition. Using RangeFactory, we construct RangeBench with 1,148 validated range instances spanning 287 distinct attack chains and evaluate frontier attack agents across attack depth, network scale, and task information. Among runs that compromise the entry vulnerability, 24.5-47.0% still fail to complete the remaining attack path, revealing a substantial sustained-compromise gap between establishing an initial foothold and completing a multi-hop attack. RangeFactory further produces a corpus of 5,541 outcome-annotated multi-hop attack trajectories, providing execution data for attack-process analysis and future agent training.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。