Automating Penetration Testing with MeTeOr

被引:0
|
作者
Cerreta, Michele [1 ]
Costa, Gabriele [1 ]
机构
[1] IMT Sch Adv Studies, Lucca, Italy
关键词
D O I
10.1109/EuroSPW61312.2024.00088
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Notoriously, penetration testing is an extremely challenging activity that takes a long time and effort from skilled analysts. The reasons behind this complexity are manifold, but a prominent one is the lack of reliable automation strategies. Indeed, human intuition is still irreplaceable despite the abundance of penetration testing tools. In particular, two tasks tend to require human intervention: (i) the strategical prioritization of targets and (ii) the synthesis of novel attack vectors and payloads. Although (ii) may seem reasonable, as vulnerability exploitation may vary from context to context, (i) is often addressed by adopting predefined testing guides and methodologies. Nonetheless, the burden of implementing the testing guide is still on humans' shoulders. In this paper we present MeTeOr, an automated framework designed to alleviate much of the manual effort human analysts expend on the strategic planning and execution of tests. The inspiring principle behind MeTeOr is that human analysts should only focus on the tasks that truly require their skills. The main feature of MeTeOr is that it relies on a knowledge base synthesizing all previous findings. The knowledge base is a cornerstone for two crucial activities: identifying test targets and automating test execution. To assess the benefits of using MeTeOr, we apply it to a case study including real vulnerabilities.
引用
收藏
页码:718 / 725
页数:8
相关论文
共 50 条
  • [1] MASS INFLUX AND PENETRATION RATE OF METEOR STREAMS
    ERICKSON, JE
    [J]. JOURNAL OF GEOPHYSICAL RESEARCH, 1969, 74 (02): : 576 - +
  • [2] THE DEPTH OF PENETRATION UPON IMPACT OF METEOR PARTICLES
    ANDRIANKIN, EI
    STEPANOV, YS
    [J]. PLANETARY AND SPACE SCIENCE, 1963, 11 (11) : 1365 - 1373
  • [3] Automating the Testing of RESTCONF Agents
    Prieto, Alberto Gonzalez
    Leung, Alfred
    Rockwell, Kevin
    [J]. PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 984 - 989
  • [4] Automating PBX system testing
    Weber, B
    [J]. IEEE DESIGN & TEST OF COMPUTERS, 1999, 16 (03): : 44 - 52
  • [5] Automating Bias Testing of LLMs
    Morales, Sergio
    Clariso, Robert
    Cabot, Jordi
    [J]. 2023 38TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE, 2023, : 1705 - 1707
  • [6] Automating fuel injector testing
    Future Technologies Inc, Bay City, United States
    [J]. Sens (Peterborough, NH), 12
  • [7] Automating Distributed Production Testing
    Sleibi, Noura
    Aldaghamin, Areej
    Wolff, Carsten
    [J]. 2022 IEEE 5TH INTERNATIONAL CONFERENCE AND WORKSHOP OBUDA ON ELECTRICAL AND POWER ENGINEERING, CANDO-EPE, 2022, : 147 - 152
  • [8] AUTOMATING THE PRODUCT TESTING FUNCTION
    NAWALINSKI, T
    WATTS, D
    [J]. ELECTRONIC PRODUCTS MAGAZINE, 1981, 24 (02): : 81 - 83
  • [9] Automating BPMN Interchange Testing
    Kurz, Matthias
    [J]. 2016 42ND EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA), 2016, : 331 - 338
  • [10] AUTOMATING ENGINE AND EMISSION TESTING
    不详
    [J]. SAE JOURNAL OF AUTOMOTIVE ENGINEERS, 1973, 81 (12): : 25 - 33