高级检索

    ValidPoC:基于大语言模型的PoC-Nuclei模板生成与漏洞复现验证方法

    ValidPoC: LLM-Based Generation and Verification Method of PoC-Nuclei Templates for Vulnerability Reproduction

    • 摘要: 外部漏洞知识是支撑大语言模型开展自动化渗透测试与漏洞复现的重要信息来源。然而,公开漏洞利用材料通常来源复杂、表示形式异构,广泛存在于脚本代码、HTTP请求片段、命令行示例以及自然语言说明文档中,缺乏统一的描述规范与明确的语义边界。现有方法虽然能够通过漏洞知识检索、利用代码生成等方式辅助漏洞利用,但仍面临漏洞利用语义提取困难、环境适配能力不足以及模型幻觉等问题,导致自动化漏洞复现成功率受限。针对上述问题,提出一种基于大语言模型的自动化漏洞复现方法ValidPoC。该方法以公开漏洞利用材料为输入,通过构建PoC语义解析、PoC中间表示建模以及PoC-Nuclei模板生成流程,实现异构漏洞利用材料向标准化漏洞利用模板的自动转换。其中,定义了面向漏洞复现的PoC语义模型,统一描述请求构造、载荷生成、执行依赖与验证判据等关键利用逻辑;设计了基于Semgrep辅助的PoC语义解析机制,从代码脚本与自然语言材料中抽取漏洞触发相关语义;构建了基于Nuclei模板的漏洞复现载体,实现漏洞利用逻辑的结构化表达与自动执行。为提高漏洞复现结果的可靠性,进一步提出基于“执行—评估—修复”闭环反馈优化机制,并建立L1(可解析执行)、L2(条件匹配成功)和L3(漏洞真实复现)三级验证模型,对漏洞触发结果进行多源证据交叉验证。在67个真实漏洞复现任务上的实验结果表明,ValidPoC能够有效提升自动化漏洞复现能力。与现有自动化渗透测试方法相比,ValidPoC取得76.12%的Pass@3漏洞复现成功率,较PentestAgent提升4.48个百分点,较PentestGPT提升43.28个百分点;同时,在Token消耗和运行时间方面均表现出较好的效率优势。实验结果验证了所提方法在异构漏洞利用材料理解、PoC模板生成以及漏洞复现验证方面的有效性。

       

      Abstract:
      External vulnerability knowledge is increasingly important for large language models (LLMs) to understand vulnerability targets, craft exploit payloads, and interpret verification evidence. Recent approaches incorporate external vulnerability knowledge via prompt, task planning and multi-agent collaboration, to improve automated penetration testing. However, automated vulnerability reproduction remains challenging because public exploit materials are often heterogeneous and loosely structured, spanning scripts, HTTP requests, command-line snippets, and walkthrough in natural language. Prior work has leveraged retrieval-augmented generation, PoC semantic repair, and exploit code generation to better utilize external vulnerability knowledge, but still constrained by environment dependencies, exploit semantic extraction and model hallucinations, weakening the trustworthiness of automated reproduction.
      To address these issues, we propose ValidPoC, an LLM-driven framework for automated vulnerability reproduction that can convert heterogeneous exploit walkthrough or scripts into structured and reliable PoC-Nuclei templates. Specifically, ValidPoC defines a PoC semantic model that provides a unified representation of exploit logic, including request construction, payload generation, execution dependencies, and verification criteria. We develop a Semgrep-assisted semantic parsing mechanism to extract PoC Semantic IR from public exploit materials, including exploit scripts and natural-language descriptions, and construct structured Nuclei YAML templates for automated vulnerability reproduction. To improve reproduction reliability, we establish a closed-loop execution–evaluation–repair framework and a three-level validation model (L1–L3) for cross-validation across multiple execution evidence.We evaluate ValidPoC on 67 real-world vulnerability reproduction tasks. ValidPoC achieves a Pass@3 reproduction rate of 76.12% and consistently surpasses existing automated penetration testing frameworks, including PentestAgent and PentestGPT. In addition, it maintains competitive efficiency with respect to both execution time and token usage. These results demonstrate the effectiveness of ValidPoC in understanding heterogeneous exploit materials, generating PoC templates, and vulnerability reproduction.

       

    /

    返回文章
    返回