Uppsats

LLM-based Embedded Penetration Testing

Master-uppsats

Stockholms universitet/Institutionen för data- och systemvetenskap

Publicerad: 2026

Språk: Engelska

Sammanfattning

The rapid adoption of embedded and Internet of Things (IoT) devices has dramatically expanded the cyberattack surface, while their resource constraints, protocol diversity, and architectural heterogeneity make security assessment increasingly difficult. Penetration testing remains the primary validation methodology for these devices, but it is largely manual or constrained by rigid automation. Recent advances in Large Language Models (LLMs) show promise for autonomous penetration testing, yet existing frameworks predominantly target traditional IT environments and do not support heterogeneous embedded systems. Therefore, the central problem addressed in this thesis is the lack of a validated framework for integrating LLMs into the full embedded penetration testing process, and the research question guiding this study is: How can an LLM-driven embedded penetration testing framework be designed to effectively automate the security assessment of embedded systems? Following the Design Science Research (DSR) methodology, this thesis designs, implements, and evaluates an LLM-driven framework that automates embedded penetration testing across heterogeneous interfaces. The artifact combines a hub-and-spoke multi-agent architecture with a centralized Orchestrator that maintains a dynamic Penetration Task Graph (PTG), specialist agents operating in bounded ReAct loops, and a novel pluggable Interface Layer that abstracts physical and logical transport channels (Ethernet, Serial, USB, CAN, Debug) into a uniform containerized execution environment. Firmware images are additionally supported as an alternative input, and a Human-in-the-Loop (HITL) mechanism gates state-modifying actions. The artifact was demonstrated against five emulated targets and a firmware image, and evaluated against a real embedded device using manual penetration testing as a baseline. Results show that the framework reproduces meaningful outcomes, autonomously chains multi-step attacks from reconnaissance to post-exploitation, and substantially reduces engagement time even though coverage remains lower, confirming that intelligent multi-agent orchestration combined with interface abstraction can effectively automate embedded penetration testing.

Information

Lärosäte / institution
Stockholms universitet/Institutionen för data- och systemvetenskap
Publiceringsdatum
2026
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.