AI helped Google identify 26 open source software vulnerabilities, including a twenty-year-old

Google has used artificial intelligence to identify 26 new vulnerabilities in open source projects, including a bug in OpenSSL that went undetected for two decades. The bug, dubbed CVE-2024-9143, was an out-of-bounds memory issue that caused program crashes and, in rare cases, launched malicious code.

Image source: AI generation

To search for vulnerabilities and automate the process, Google developers used the fuzz testing method, in which random data is loaded into the code to identify possible failures. The company’s blog notes that the approach was to use the power of large language models (LLMs) to generate more fuzzing targets.

As it turned out, LLMs were “highly effective in emulating the entire workflow of a typical developer to write, test, and triage detected faults.” As a result, artificial intelligence was used to test 272 software projects, where 26 vulnerabilities were discovered, including an “ancient” bug in OpenSSL.

According to the researchers, the reason the bug went undetected for 20 years was because it was difficult to test individual scripts of the code, and because the code was considered to have already been thoroughly tested and therefore did not attract much attention. “Tests are not capable of measuring all possible paths through which a program can be executed. Different settings, flags and configurations can also activate different behaviors that reveal new vulnerabilities,” the experts explained. Fortunately, the error is of low severity due to the minimal risk of operating the process.

Previously, developers manually wrote code for fuzzing tests, but now Google plans to teach AI not only to find vulnerabilities, but also to automatically suggest fixes, minimizing human intervention. “Our goal is to reach a point where we are confident that we can do without manual verification,” the company said.

admin

Share
Published by
admin

Recent Posts

The potential US Secretary of Transportation promised to deal with SpaceX fines and eliminate the space bureaucracy

This week, Congress held confirmation hearings for new ministers nominated by new US President Donald…

19 minutes ago

Vast Space has built the world’s first private space station; it will go into orbit this year

California-based startup Vast Space has announced the completion of the world's first commercial space station,…

19 minutes ago

Qualcomm began releasing defective Snapdragon 8 Elite

In October, Qualcomm introduced the flagship processor Snapdragon 8 Elite, which received two powerful cores…

4 hours ago

Samsung TVs will receive useful AI functions thanks to integration with OpenAI neural networks

Samsung has previously announced the development of functions based on Vision AI artificial intelligence that…

4 hours ago

Astronomers have obtained the most detailed infrared image of an active galactic nucleus yet

US scientists have used an innovative method of combining images from two optical telescopes to…

7 hours ago