Orchestrace AI agentů pro penetracni testovani

dc.contributor.advisorZelinka, Ivan
dc.contributor.authorNeuwirth, Tomáš
dc.contributor.refereePlucar, Jan
dc.date.accepted2026-06-03
dc.date.accessioned2026-09-02T14:13:57Z
dc.date.available2026-09-02T14:13:57Z
dc.date.issued2026
dc.description.abstractTato diplomová práce se zabývá návrhem, implementací a experimentálním ověřením orchestrátoru pro autonomní penetrační testování založeného na multi-agentních systémech. Cílem je překonat omezení tradičního manuálního testování a monolitických velkých jazykových modelů, které často podléhají halucinacím a ztrátě kontextu. Navržená architektura využívá specializované agenty pro průzkum sítě, analýzu zranitelností, validaci, exploitaci a generování reportů. Řízení systému zajišťuje stavový automat postavený na frameworku LangGraph, který koordinuje asynchronní zpracování událostí a efektivně sdílí kontext napříč agenty prostřednictvím centralizované znalostní báze. Zavedení modulu historických zkušeností (Experience Store) omezilo potřebu opakovaného prohledávání známých stavů a vedlo ke zkrácení času testu o přibližně 44%. Experiment ověřil funkčnost a stabilitu navrženého prototypu v laboratorním prostředí Metasploitable 2. Systém autonomně dokončil 31 iterací za 6 minut a 18 sekund, přičemž identifikoval 74 potenciálních zranitelností na základě mapování na CVE databázi a provedl 6 úspěšných kompromitací při celkových nákladech přibližně 0,061 USD. Práce rovněž analyzuje možnosti integrace kvantových algoritmů pro optimalizaci útokových cest, avšak od jejich implementace bylo z důvodu vysoké chybovosti současného NISQ hardwaru upuštěno.cs
dc.description.abstractThis master's thesis deals with the design, implementation, and experimental verification of an orchestrator for autonomous penetration testing based on multi-agent systems. The primary objective is to overcome the limitations of traditional manual testing and monolithic large language models, which are prone to hallucinations and context loss. The proposed architecture utilizes specialized agents for network reconnaissance, vulnerability analysis, validation, exploitation, and reporting. The system is controlled by a state machine built on the LangGraph framework, coordinating asynchronous event processing and effectively sharing context across agents via a centralized knowledge base. The introduction of a historical experience module (Experience Store) reduced the need for repetitive search of known states and resulted in runtime reduction of around 44%. Experiment verified functionality and stability of the designed prototype in Metasploitable 2 laboratory environment. The system autonomously completed 31 iterations in 6 minutes and 18 seconds, identifying 74 potential vulnerabilities based on CVE database mapping and executing 6 successful compromises at a total cost of approximately $0.061. The thesis also analyzes the potential integration of quantum algorithms for attack path optimization; however, their implementation was omitted due to the high error rates of current NISQ hardware.en
dc.description.department460 - Katedra informatikycs
dc.description.resultvýborněcs
dc.format.extent2137078 bytes
dc.format.mimetypeapplication/pdf
dc.identifier.otherOSD002
dc.identifier.senderS2724
dc.identifier.thesisNEU0093_FEI_N0612A140004_2026
dc.identifier.urihttp://hdl.handle.net/10084/158886
dc.language.isocs
dc.publisherVysoká škola báňská – Technická univerzita Ostravacs
dc.rights.accessopenAccess
dc.subjectautonomní penetrační testovánícs
dc.subjectmulti-agentní systémcs
dc.subjectvelký jazykový modelcs
dc.subjectorchestracecs
dc.subjectLangGraphcs
dc.subjectkybernetická bezpečnostcs
dc.subjectautonomous penetration testingen
dc.subjectmulti-agent systemen
dc.subjectlarge language modelen
dc.subjectorchestrationen
dc.subjectLangGraphen
dc.subjectcybersecurityen
dc.thesis.degree-grantorVysoká škola báňská – Technická univerzita Ostrava. Fakulta elektrotechniky a informatikycs
dc.thesis.degree-levelMagisterský studijní programcs
dc.thesis.degree-nameIng.
dc.thesis.degree-programInformační a komunikační bezpečnostcs
dc.titleOrchestrace AI agentů pro penetracni testovanics
dc.title.alternativeOrchestration of AI agents for penetration testingen
dc.typeDiplomová prácecs
local.files.count6
local.files.size2804379
local.has.filesyes

Files

Original bundle

Now showing 1 - 5 out of 6 results
Loading...
Thumbnail Image
Name:
NEU0093_FEI_N0612A140004_2026.pdf
Size:
2.04 MB
Format:
Adobe Portable Document Format
Description:
Text práce
Loading...
Thumbnail Image
Name:
NEU0093_FEI_N0612A140004_2026_zadani.pdf
Size:
156.7 KB
Format:
Adobe Portable Document Format
Description:
Zadání
Loading...
Thumbnail Image
Name:
NEU0093_FEI_N0612A140004_2026_priloha.zip
Size:
110.34 KB
Format:
ZIP
Description:
Příloha
Loading...
Thumbnail Image
Name:
NEU0093_FEI_N0612A140004_2026_posudek_vedouci_Zelinka_Ivan.pdf
Size:
162.08 KB
Format:
Adobe Portable Document Format
Description:
Posudek vedoucího – Zelinka, Ivan
Loading...
Thumbnail Image
Name:
NEU0093_FEI_N0612A140004_2026_posudek_oponent_Plucar_Jan.pdf
Size:
160.58 KB
Format:
Adobe Portable Document Format
Description:
Posudek oponenta – Plucar, Jan