周天阳1,,,
朱俊虎1, 2,
王清贤1
1.数学工程与先进计算国家重点实验室(信息工程大学) 郑州 450001
2.国家数字交换系统工程技术研究中心 郑州 450001
基金项目:国家自然科学基金(61502528)
详细信息
作者简介:臧艺超:男,1991年生,博士生,研究方向为路径规划,强化学习,效果评估
周天阳:男,1979年生,副教授,研究方向为网络安全,强化学习,效果评估
朱俊虎:男,1971年生,教授,研究方向为网络安全,网络模拟与效果评估
王清贤:男,1960年生,教授,研究方向为网络安全,计算复杂度,网络模拟与效果评估
通讯作者:周天阳 aipteamzhouty@aliyun.com
中图分类号:TN915.08; TP309计量
文章访问数:1055
HTML全文浏览量:396
PDF下载量:118
被引次数:0
出版历程
收稿日期:2019-12-31
修回日期:2020-03-17
网络出版日期:2020-07-21
刊出日期:2020-09-27
Domain-Independent Intelligent Planning Technology and Its Application to Automated Penetration Testing Oriented Attack Path Discovery
Yichao ZHANG1,Tianyang ZHOU1,,,
Junhu ZHU1, 2,
Qingxian WANG1
1. State Key Laboratory of Mathematical Engineering and Advanced Computing, Information & Engineering University, Zhengzhou 450001, China
2. National Engineering Technology Research Center of the National Digital Switching System, Zhengzhou 450001, China
Funds:The National Natural Science Foundation of China (61502528)
摘要
摘要:攻击路径发现是自动化渗透测试领域的重要研究方向。该文综合论述了领域独立智能规划技术在面向自动化渗透测试的攻击路径发现上的研究进展及应用前景。首先介绍了攻击路径发现的基本概念并按照技术原理将其划分为基于领域相关和领域独立规划技术的攻击路径发现方法。然后介绍了领域独立智能规划算法,包括确定性规划算法、非确定性规划算法和博弈规划的技术原理和发展状况并就各类方法在攻击路径发现中的应用进行了综述。接着分析总结了渗透测试过程的特点,对比了领域独立智能规划算法应用在面向自动化渗透测试的攻击路径发现时的优缺点。最后对攻击路径发现将来的发展方向进行了总结和展望,希望对未来进一步的研究工作有一定的参考价值。
关键词:领域独立智能规划技术/
自动化渗透测试/
攻击路径发现
Abstract:Attack path discovery is an important research direction in automated penetration testing area. This paper introduces the research progress of domain independent intelligent planning technology and its application to the field of automated penetration testing oriented attack paths discovery. Firstly, the basic concept of attack path discovery is introduced and the related algorithms are divided into domain-specific and domain-independent intelligent planning based attack path discovery algorithms separately. Secondly, the domain-independent planning algorithms are classified into deterministic planning, uncertain planning and game planning, where each of which is described from principle, development and application aspect in detail. Thirdly, this paper summarizes the characteristics of automated penetration testing and compares the advantages and disadvantages of domain independent intelligent planning algorithms adopted in automated penetration testing. Lastly, the development of automated penetration testing oriented attack path discovery is prospected. It is hoped that this paper could contribute future research works on attack path discovery.
Key words:Domain independent intelligent planning technology/
Automated penetration testing/
Attack path discovery
PDF全文下载地址:
https://jeit.ac.cn/article/exportPdf?id=e363775d-69c5-4e40-8c4e-2a9e51d1d954