arrow
Return

An Intelligent Penetration Testing Method Using Human Feedback

delete2024-07-01
delete1
PRE
AI
Q
Qianyu Li
R
Ruipeng Wang
M
Min Zhang
F
Fan Shi *
Y
Yi Shen
M
Miao Hu
B
Bingyang Guo
C
Chengxi Xu
DOI:10.1109/TII.2024.3379633delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Penetration testing is widely acknowledged as the foremost method for evaluating network security. However, three challenges impede the generation of strategies that align with human expectations. In this article, we present, for the first time, a method based on human feedback to enhance strategy generation. Our approach comprises two components: agent training and decision-making. During agent training, we establish a hierarchical framework to decompose tasks and a knowledge base to offer advice for improving data efficiency. We then impose constraints on the action space to mitigate ineffective exploration. Finally, we train a reward model based on human feedback and fine tune the model guided by this reward model. In decision-making, we process the model output to enhance decision accuracy. We crafted scenarios based on real-world networks, and the results demonstrate the effectiveness of our method in generating penetration testing strategies that align more closely with human intentions.
Keywords:
Deep reinforcement learning (DRL)
expert knowledge
human feedback
intelligent penetration testing (PT)
network security assessment

Journal

IEEE Transactions on Industrial Informatics cover
IEEE Transactions on Industrial Informatics
IF:
9.9
Papers:
8.3K
Citations:
6.0W

Organization

N
national university of defense technology - china
Scholars:
1.8W
Papers: 1.4W
Citations: 9