This paper explores ways to improve the effectiveness of penetration testing amidst the increasing complexity of cyber threats. The focus is placed on leveraging artificial intelligence (AI) technologies to enhance the efficiency of pentesting processes. A review of conventional testing methods and relevant international frameworks, such as OWASP, NIST, and PTES, is conducted. The limitations of manual techniques are identified, and the use of AI is justified for automating information gathering, vulnerability analysis, attack simulation, and reporting. Based on the analysis, an intelligent penetration testing approach is proposed, which includes the development of a knowledge base, mapping of vulnerabilities to MITRE ATT&CK techniques, and automated generation of attack scenarios based on input parameters. This methodology improves the accuracy of vulnerability detection, accelerates analysis, and adapts to modern IT environments, confirming its relevance and practical significance for cybersecurity tasks.
Paper
Full text
The Methodology of Penetration Testing using Artificial Intelligence Technology
Semantic Scholar · 2025
Abstract
This paper explores ways to improve the effectiveness of penetration testing amidst the increasing complexity of cyber threats. The focus is placed on leveraging artificial intelligence (AI) technologies to enhance the efficiency of pentesting processes. A review of conventional testing methods and relevant international frameworks, such as OWASP, NIST, and PTES, is conducted. The limitations of manual techniques are identified, and the use of AI is justified for automating information gathering, vulnerability analysis, attack simulation, and reporting. Based on the analysis, an intelligent penetration testing approach is proposed, which includes the development of a knowledge base, mapping of vulnerabilities to MITRE ATT&CK techniques, and automated generation of attack scenarios based on input parameters. This methodology improves the accuracy of vulnerability detection, accelerates analysis, and adapts to modern IT environments, confirming its relevance and practical significance for cybersecurity tasks.