כתבה
arXiv cs.AI ·
בניית גרף התקפה אוטומטית
Automating Attack Graph Construction for Agentic Pentesting. Towards Neuro-Symbolic Vulnerability Hunting
פותחים צינור לבניית גרף התקפה אוטומטי, המשלב מסגרות סמליות ו-LLM. הצינור מפרק ממצאים מ-Trivy, Semgrep ו-Nmap לפרדיקטים ויוצר כללים דומייניים. הוא מאפשר בניית גרף התקפה מובנה.
תקציר מקורי באנגליתarXiv:2609.15523v1 Announce Type: cross Abstract: Logic attack graphs grounded in scanner output provide explicit and auditable attack path reasoning LLM-based agents lack. Integrating symbolic frameworks such as MulVAL to contemporary security workflows or agentic pipelines, however, requires translating scanner evidence to initial facts, and creating domain-specific rules. We present a semi-automated pipeline that addresses this interoperability problem and depict its feasibility in a web-security case study. Our pipeline parses findings from Trivy, Semgrep, and Nmap into MulVAL predicates and uses an LLM-assisted process to construct domain-specific Datalog rules linking scanner-detectable evidence to attack techniques. MulVAL/XSB then performs symbolic inference to generate structured
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית