Automated Security Penetration Testing Based on Machine Learning

Peng Zhang, Wenhui Wang, Daojuan Zhang, Hongbin Wu, Longxi Han, Qi Zhao · 2024

Penetration testing is a crucial measure for preventing cyberspace attacks. Typically, penetration testing is conducted manually, which presents challenges such as reliance on experience, high costs, and low efficiency. This study proposes an automated penetration testing method that integrates machine learning algorithms with Metasploit to achieve low-code generation and execution of penetration testing cases. This approach enhances testing efficiency, reduces costs, and mitigates dependence on experience. The study introduces a decision-making algorithm to facilitate the selection of exploit files during the generation of penetration testing cases and leverages Metasploit to implement basic penetration testing functionalities. Experimental results show that the algorithm achieves an accuracy of 73.16%, and the method successfully meets the objective of automated penetration testing.

Read the paper · More papers on PaperTik