The field of software security testing, more specifically penetration testing, is an activity that requires high levels of expertise and involves many manual testing and analysis steps. This paper explores the potential usage of large-language models, such as GPT3.5, to augment penetration testers with AI sparring partners. We explore the feasibility of supplementing penetration testers with AI models for two distinct use cases: high-level task planning for security testing assignments and low-level vulnerability hunting within a vulnerable virtual machine. For the latter, we implemented a closed-feedback loop between LLM-generated low-level actions with a vulnerable virtual machine (connected through SSH) and allowed the LLM to analyze the machine state for vulnerabilities and suggest concrete attack vectors which were automatically executed within the virtual machine. We discuss promising initial results, detail avenues for improvement, and close deliberating on the ethics of providing AI-based sparring partners.
翻译:软件安全测试领域,尤其是渗透测试,是一项需要高水平专业知识且涉及大量手动测试与分析步骤的活动。本文探索了大语言模型(如GPT3.5)作为AI陪练伙伴增强渗透测试人员的潜在应用。我们针对两种不同用例,研究了利用AI模型辅助渗透测试的可行性:安全测试任务的高层规划,以及易受攻击虚拟机内的低层漏洞挖掘。针对后者,我们构建了LLM生成的底层操作与易受攻击虚拟机(通过SSH连接)之间的闭环反馈机制,允许LLM分析机器状态以发现漏洞,并自动执行虚拟机内的具体攻击向量。本文讨论了初步成果,详述了改进方向,并最终探讨了提供基于AI的陪练伙伴的伦理问题。