Sorry for submitting so late! Feel free to blow me off, love you.
Abstract
Widespread press about the use of agents for security has led to a deluge of vulnerability reports. These reports can be just as good as human-authored reports -- that is, some are great and others are of extremely dubious quality. The sheer volume of these reports begets a further problem: triaging vulnerability reports takes time and effort, especially when such reports lack fully-functional exploit code. In this talk, we discuss how LLM-powered agents do vulnerability discovery, how LLMs can help with triage, and the pitfalls of each. We propose a way forward for both researchers and CNAs to ensure responsible disclosure.
Sorry for submitting so late! Feel free to blow me off, love you.
Abstract
Widespread press about the use of agents for security has led to a deluge of vulnerability reports. These reports can be just as good as human-authored reports -- that is, some are great and others are of extremely dubious quality. The sheer volume of these reports begets a further problem: triaging vulnerability reports takes time and effort, especially when such reports lack fully-functional exploit code. In this talk, we discuss how LLM-powered agents do vulnerability discovery, how LLMs can help with triage, and the pitfalls of each. We propose a way forward for both researchers and CNAs to ensure responsible disclosure.