Distributed Attack Deployment Capability for Modern Automated Penetration Testing

Cybersecurity is an ever-changing landscape. The threats of the future are hard to predict and even harder to prepare for. This paper presents work designed to prepare for the cybersecurity landscape of tomorrow by creating a key support capability for an autonomous cybersecurity testing system. Thi...

Full description

Bibliographic Details
Main Authors: Jack Hance, Jordan Milbrath, Noah Ross, Jeremy Straub
Format: Article
Language:English
Published: MDPI AG 2022-02-01
Series:Computers
Subjects:
Online Access:https://www.mdpi.com/2073-431X/11/3/33
_version_ 1797472158730944512
author Jack Hance
Jordan Milbrath
Noah Ross
Jeremy Straub
author_facet Jack Hance
Jordan Milbrath
Noah Ross
Jeremy Straub
author_sort Jack Hance
collection DOAJ
description Cybersecurity is an ever-changing landscape. The threats of the future are hard to predict and even harder to prepare for. This paper presents work designed to prepare for the cybersecurity landscape of tomorrow by creating a key support capability for an autonomous cybersecurity testing system. This system is designed to test and prepare critical infrastructure for what the future of cyberattacks looks like. It proposes a new type of attack framework that provides precise and granular attack control and higher perception within a set of infected infrastructure. The proposed attack framework is intelligent, supports the fetching and execution of arbitrary attacks, and has a small memory and network footprint. This framework facilitates autonomous rapid penetration testing as well as the evaluation of where detection systems and procedures are underdeveloped and require further improvement in preparation for rapid autonomous cyber-attacks.
first_indexed 2024-03-09T19:59:09Z
format Article
id doaj.art-9482b45938e842cdbd42246510ed43e9
institution Directory Open Access Journal
issn 2073-431X
language English
last_indexed 2024-03-09T19:59:09Z
publishDate 2022-02-01
publisher MDPI AG
record_format Article
series Computers
spelling doaj.art-9482b45938e842cdbd42246510ed43e92023-11-24T00:50:08ZengMDPI AGComputers2073-431X2022-02-011133310.3390/computers11030033Distributed Attack Deployment Capability for Modern Automated Penetration TestingJack Hance0Jordan Milbrath1Noah Ross2Jeremy Straub3Department of Computer Science, North Dakota State University, Fargo, ND 58102, USADepartment of Computer Science, North Dakota State University, Fargo, ND 58102, USADepartment of Computer Science, North Dakota State University, Fargo, ND 58102, USADepartment of Computer Science, North Dakota State University, Fargo, ND 58102, USACybersecurity is an ever-changing landscape. The threats of the future are hard to predict and even harder to prepare for. This paper presents work designed to prepare for the cybersecurity landscape of tomorrow by creating a key support capability for an autonomous cybersecurity testing system. This system is designed to test and prepare critical infrastructure for what the future of cyberattacks looks like. It proposes a new type of attack framework that provides precise and granular attack control and higher perception within a set of infected infrastructure. The proposed attack framework is intelligent, supports the fetching and execution of arbitrary attacks, and has a small memory and network footprint. This framework facilitates autonomous rapid penetration testing as well as the evaluation of where detection systems and procedures are underdeveloped and require further improvement in preparation for rapid autonomous cyber-attacks.https://www.mdpi.com/2073-431X/11/3/33cybersecurityautomate penetration testingattack automationartificial intelligenceBlackboard Architecture
spellingShingle Jack Hance
Jordan Milbrath
Noah Ross
Jeremy Straub
Distributed Attack Deployment Capability for Modern Automated Penetration Testing
Computers
cybersecurity
automate penetration testing
attack automation
artificial intelligence
Blackboard Architecture
title Distributed Attack Deployment Capability for Modern Automated Penetration Testing
title_full Distributed Attack Deployment Capability for Modern Automated Penetration Testing
title_fullStr Distributed Attack Deployment Capability for Modern Automated Penetration Testing
title_full_unstemmed Distributed Attack Deployment Capability for Modern Automated Penetration Testing
title_short Distributed Attack Deployment Capability for Modern Automated Penetration Testing
title_sort distributed attack deployment capability for modern automated penetration testing
topic cybersecurity
automate penetration testing
attack automation
artificial intelligence
Blackboard Architecture
url https://www.mdpi.com/2073-431X/11/3/33
work_keys_str_mv AT jackhance distributedattackdeploymentcapabilityformodernautomatedpenetrationtesting
AT jordanmilbrath distributedattackdeploymentcapabilityformodernautomatedpenetrationtesting
AT noahross distributedattackdeploymentcapabilityformodernautomatedpenetrationtesting
AT jeremystraub distributedattackdeploymentcapabilityformodernautomatedpenetrationtesting