Automating Attack Graph Construction for Agentic Pentesting. Towards Neuro-Symbolic Vulnerability Hunting

📅 2026-09-14
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
该研究通过半自动化管道解决神经符号漏洞狩猎中的互操作性问题,将扫描器输出转化为MulVAL谓词,并使用LLM辅助构建领域特定规则,生成结构化攻击路径。
📝 Abstract
Logic attack graphs grounded in scanner output provide explicit and auditable attack path reasoning LLM-based agents lack. Integrating symbolic frameworks such as MulVAL to contemporary security workflows or agentic pipelines, however, requires translating scanner evidence to initial facts, and creating domain-specific rules. We present a semi-automated pipeline that addresses this interoperability problem and depict its feasibility in a web-security case study. Our pipeline parses findings from Trivy, Semgrep, and Nmap into MulVAL predicates and uses an LLM-assisted process to construct domain-specific Datalog rules linking scanner-detectable evidence to attack techniques. MulVAL/XSB then performs symbolic inference to generate structured attack paths. We evaluate the attack-graph construction infrastructure on 54 web Capture-the-Flag tasks from CyBench within an agentic pipeline (Hybrid Reasoner); we do not evaluate the performance of the downstream agent. Every task produced at least one goal-reaching graph, and we achieve mean ground-truth vulnerability coverage of 53.7%, with 51.9% achieving full coverage; mean noise-path rate was 83.9%. With median end-to-end time of 24.9 s (MulVAL reasoning: 2.7 s) the pipeline is feasible and runtime-practical for agentic workflows, but predicate coverage, rule coverage, and path precision remain limiting factors. Next steps include semantic rule validation and agent-level comparison for graph-guided pentesting.
Problem

Research questions and friction points this paper is trying to address.

Attack Graph
Interoperability
Symbolic Frameworks
Scanner Output
Security Workflows
Innovation

Methods, ideas, or system contributions that make the work stand out.

Semi-automated Pipeline
MulVAL Predicates
LLM-assisted Process
Datalog Rules
Symbolic Inference
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
O
Oliver Stevanovic
University of Udine
J
Jasmin Wachter
University of Klagenfurt