Show simple item record

Αυτοματοποίηση ελέγχου διείσδυσης μέσω αρχιτεκτονικής πολλαπλών AI agents

dc.contributor.advisorΚαραντζιάς, Αθανάσιος
dc.contributor.authorΜπαλτζής, Δημήτριος
dc.date.accessioned2026-09-08T08:37:02Z
dc.date.available2026-09-08T08:37:02Z
dc.date.issued2026-07
dc.identifier.urihttps://dione.lib.unipi.gr/xmlui/handle/unipi/19726
dc.description.abstractΣτο πλαίσιο της παρούσας διπλωματικής εργασίας προτείνεται, σχεδιάζεται και υλοποιείται ένα αυτοματοποιημένο σύστημα ελέγχου διείσδυσης (penetration testing) βασισμένο σε αρχιτεκτονική πολλαπλών AI agents. Το σύστημα αξιοποιεί το Model Context Protocol (MCP) και το μοντέλο DeepSeek για τον συντονισμό δύο εξειδικευμένων agents: τον Agent Ανάλυσης, ο οποίος εκτελεί παθητική αναγνώριση και παράγει δομημένο πλάνο επίθεσης, και τον Pentester Agent, ο οποίος αναλαμβάνει την εκτέλεση και επιβεβαίωση των ευπαθειών. Η φάση αναγνώρισης υλοποιείται μέσω της αλυσίδας Wappalyzer, FastCVE και ExploitDB, ενώ η εκτέλεση βασίζεται κυρίως σε templates του Nuclei με εναλλακτικό μονοπάτι μέσω ExploitDB. Το σύστημα αξιολογήθηκε σε δύο ελεγχόμενα περιβάλλοντα Docker, επιβεβαιώνοντας ευπάθειες τύπου path traversal (CVE-2021-41773) και απομακρυσμένης εκτέλεσης κώδικα μέσω reverse shell (CVE-2017-5638). Τα αποτελέσματα έδειξαν ότι το σύστημα μπορεί να αυτοματοποιήσει αξιόπιστα το πλήρες pipeline ενός penetration test με ελάχιστη ανθρώπινη παρέμβαση.el
dc.format.extent41el
dc.language.isoelel
dc.publisherΠανεπιστήμιο Πειραιώςel
dc.rightsΑναφορά Δημιουργού-Μη Εμπορική Χρήση-Όχι Παράγωγα Έργα 3.0 Ελλάδα*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/3.0/gr/*
dc.titleΑυτοματοποίηση ελέγχου διείσδυσης μέσω αρχιτεκτονικής πολλαπλών AI agentsel
dc.title.alternativePenetration testing automation through multi-agent AI architectureel
dc.typeMaster Thesisel
dc.contributor.departmentΣχολή Τεχνολογιών Πληροφορικής και Επικοινωνιών. Τμήμα Πληροφορικήςel
dc.description.abstractENThis thesis proposes, designs, and implements an automated penetration testing system based on a multi-agent AI architecture, which is subsequently evaluated in a controlled environment. The system leverages the Model Context Protocol (MCP) and the DeepSeek language model to coordinate two specialized agents: an Analyst Agent, responsible for passive reconnaissance and generating a structured attack plan, and a Pentester Agent, which handles exploit execution and vulnerability confirmation. The reconnaissance phase is implemented through a pipeline consisting of Wappalyzer, FastCVE, and ExploitDB, while execution relies primarily on Nuclei templates with a fallback path via ExploitDB. The system was evaluated in two controlled Docker environments, successfully confirming a path traversal vulnerability (CVE-2021-41773) and a remote code execution vulnerability via reverse shell (CVE-2017-5638). Results demonstrate that the system can reliably automate the full penetration testing pipeline with minimal human intervention, validating the effectiveness of the multi-agent role separation approach.el
dc.contributor.masterΚυβερνοασφάλεια και Τεχνολογίες Τεχνητής Νοημοσύνης / MSc Cybersecurity & AI Technologiesel
dc.subject.keywordΈλεγχος διείσδυσηςel
dc.subject.keywordΑυτοματοποίηση ασφάλειαςel
dc.subject.keywordΠολλαπλοί AI agentsel
dc.subject.keywordModel Context Protocol (MCP)el
dc.subject.keywordΜεγάλα γλωσσικά μοντέλαel
dc.subject.keywordDeepSeekel
dc.subject.keywordPenetration testingel
dc.subject.keywordMulti-agent systemsel
dc.subject.keywordLLMsel
dc.date.defense2026-07


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record

Αναφορά Δημιουργού-Μη Εμπορική Χρήση-Όχι Παράγωγα Έργα 3.0 Ελλάδα
Except where otherwise noted, this item's license is described as
Αναφορά Δημιουργού-Μη Εμπορική Χρήση-Όχι Παράγωγα Έργα 3.0 Ελλάδα

Βιβλιοθήκη Πανεπιστημίου Πειραιώς
Contact Us
Send Feedback
Created by ELiDOC
Η δημιουργία κι ο εμπλουτισμός του Ιδρυματικού Αποθετηρίου "Διώνη", έγιναν στο πλαίσιο του Έργου «Υπηρεσία Ιδρυματικού Αποθετηρίου και Ψηφιακής Βιβλιοθήκης» της πράξης «Ψηφιακές υπηρεσίες ανοιχτής πρόσβασης της βιβλιοθήκης του Πανεπιστημίου Πειραιώς»