A Survey on Penetration Path Planning in Automated Penetration Testing

被引:0
|
作者
Chen, Ziyang [1 ]
Kang, Fei [1 ]
Xiong, Xiaobing [1 ]
Shu, Hui [1 ]
机构
[1] Informat Engn Univ, Key Lab Cyberspace Secur, Minist Educ, Zhengzhou 450001, Peoples R China
来源
APPLIED SCIENCES-BASEL | 2024年 / 14卷 / 18期
关键词
automated penetration testing; penetration path planning; planning models; planning methods; cybersecurity threats; ATTACK; INTELLIGENT; MODEL; FF;
D O I
10.3390/app14188355
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Penetration Testing (PT) is an effective proactive security technique that simulates hacker attacks to identify vulnerabilities in networks or systems. However, traditional PT relies on specialized experience and costs extraordinary time and effort. With the advancement of artificial intelligence technologies, automated PT has emerged as a promising solution, attracting attention from researchers increasingly. In automated PT, penetration path planning is a core task that involves selecting the optimal attack paths to maximize the overall efficiency and success rate of the testing process. Recent years have seen significant progress in the field of penetration path planning, with diverse methods being proposed. This survey aims to comprehensively examine and summarize the research findings in this domain. Our work first outlines the background and challenges of penetration path planning and establishes the framework for research methods. It then provides a detailed analysis of existing studies from three key aspects: penetration path planning models, penetration path planning methods, and simulation environments. Finally, this survey offers insights into the future development trends of penetration path planning in PT. This paper aims to provide comprehensive references for academia and industry, promoting further research and application of automated PT path planning methods.
引用
收藏
页数:27
相关论文
共 50 条
  • [1] AUTOMATED PLANNING FOR REMOTE PENETRATION TESTING
    Greenwald, Lloyd
    Shanley, Robert
    MILCOM 2009 - 2009 IEEE MILITARY COMMUNICATIONS CONFERENCE, VOLS 1-4, 2009, : 2099 - 2105
  • [2] Survey on Automated Penetration Testing Technology Research
    Chen K.
    Lu H.
    Fang B.-X.
    Sun Y.-B.
    Su S.
    Tian Z.-H.
    Ruan Jian Xue Bao/Journal of Software, 2024, 35 (05): : 2235 - 2267
  • [3] Application Research of Knowledge Graph in Automated Penetration Testing Path Planning in the Digital Era
    Liang, Rufeng
    Chen, Junhan
    Chen, Xingchi
    Huang, Xun
    Peng, Jin
    Zheng, Chencong
    Zhang, Haonan
    Hu, Wenguang
    Xu, Gengchen
    COMPUTATIONAL AND EXPERIMENTAL SIMULATIONS IN ENGINEERING, ICCES 2024-VOL 2, 2025, 173 : 321 - 330
  • [4] An automated method of penetration testing
    Qiu, Xue
    Xia, Chunhe
    Wang, Shuguang
    Xia, Qingxin
    Jia, Qiong
    2014 IEEE COMPUTING, COMMUNICATIONS AND IT APPLICATIONS CONFERENCE (COMCOMAP), 2014, : 211 - 216
  • [5] Domain-Independent Intelligent Planning Technology and Its Application to Automated Penetration Testing Oriented Attack Path Discovery
    Zhang Y.
    Zhou T.
    Zhu J.
    Wang Q.
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2020, 42 (09): : 2095 - 2107
  • [6] Domain-Independent Intelligent Planning Technology and Its Application to Automated Penetration Testing Oriented Attack Path Discovery
    Zhang Yichao
    Zhou Tianyang
    Zhu Junhu
    Wang Qingxian
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2020, 42 (09) : 2095 - 2107
  • [7] Efficient Penetration Testing Path Planning Based on Reinforcement Learning with Episodic Memory
    Zhou, Ziqiao
    Zhou, Tianyang
    Xu, Jinghao
    Zhu, Junhu
    CMES-COMPUTER MODELING IN ENGINEERING & SCIENCES, 2024, 140 (03): : 2613 - 2634
  • [8] Simulated Penetration Testing as Contingent Planning
    Shmaryahu, Dorin
    Shani, Guy
    Hoffmann, Joerg
    Steinmetz, Marcel
    TWENTY-EIGHTH INTERNATIONAL CONFERENCE ON AUTOMATED PLANNING AND SCHEDULING (ICAPS 2018), 2018, : 241 - 249
  • [9] Robot path planning with penetration growth distance
    Ong, CJ
    Gilbert, EG
    JOURNAL OF ROBOTIC SYSTEMS, 1998, 15 (02): : 57 - 74
  • [10] A Survey on Web Application Penetration Testing
    Altulaihan, Esra Abdullatif
    Alismail, Abrar
    Frikha, Mounir
    ELECTRONICS, 2023, 12 (05)