HomeMalware & ThreatsMandiant Launches Agentic Security Harness for the Industry

Mandiant Launches Agentic Security Harness for the Industry

Published on

spot_img

Artificial Intelligence & Machine Learning,
Next-Generation Technologies & Secure Development,
The Future of AI & Cybersecurity

AVDH Scans Enterprise Code at Scale to Find and Validate Exploit Paths

Mandiant Launches Agentic Security Harness for the Industry
Image: Shutterstock

In a groundbreaking move, Google Mandiant has unveiled its innovative approach to agentic security by publishing the underlying architecture of the Agentic Vulnerability Discovery Harness (AVDH). This initiative aims to provide other artificial intelligence (AI) labs and enterprises with valuable insights and methodologies for improving code vulnerability assessments and protection strategies.

The AVDH operates as an advanced tool designed to analyze enterprise code at scale, effectively identifying potential exploit paths during critical activities such as code reviews, penetration testing, and red team operations. As a harness, it integrates a systematic set of capabilities that enhance its effectiveness in automotive vulnerability detection.

In a recent blog post, Mandiant highlighted the significant advancements brought about by the AVDH, noting that its deployment has “greatly accelerated how Mandiant discovers vulnerabilities at scale.” The organization noted that this innovative harness has already addressed “dozens of assignable flaws,” analyzing “tens of millions of lines of code and executing thousands of pipelines” to date.

During an interview with Information Security Media Group (ISMG), Alex Tselevich, a senior consultant at Google Mandiant, expressed the necessity of adopting new methodologies to combat the rapidly evolving agentic risks. “The dramatic increase in the speed at which these risks are rising necessitates newer ways to find and mitigate vulnerabilities,” Tselevich stated. He emphasized that the primary objective of releasing their research was to foster knowledge sharing within the industry, enabling other security teams to benefit from their findings.

The Mandiant team emphasized the pressing need for advanced tooling in the face of growing AI-enabled threats. Tselevich noted that existing traditional source code review tools often fall short in terms of accuracy and tend to generate excessive noise. The limitations of a single-agent model for their specific requirements—due to constraints such as model context sizes and the complexity of workflows—prompted Mandiant to explore harnesses as a viable alternative.

Designed to be vendor agnostic, the AVDH can operate in conjunction with tools such as Google’s CodeMender scanning solution, thereby allowing for greater flexibility in its application across various environments.

According to Tselevich, the harnessing approach proved advantageous as it combined the versatile capabilities of agents with intelligent AI models, enabling programmatic checks that effectively minimize false positives while preventing agent overload. Michael Maturi, a technical manager at Mandiant, further elaborated on the need for custom harnesses, insisting that organizations must first identify their critical assets before implementing such systems. Mandiant centered its deployment on high-priority code, directing the agent toward segments that provide access to sensitive data and critical API endpoints.

The AVDH operates through a comprehensive multi-stage process that includes Threat Modeling, Entry Point Discovery, Context Gathering, Hypotheses Generation, and Hypothesis Validation. A key feature of this process is the involvement of human subject-matter experts who validate the findings of the harness, ensuring the generated insights are accurate before formal disclosure.

The initial phase of the threat modeling pipeline begins with deploying an Explorer agent tasked with identifying the overarching purpose of the codebase. This step is supplemented by other specialized Explorer agents that delve into specifics such as authentication, authorization, routing, and various domain-specific facets. These agents then relay their findings to a Threat Model Synthesis agent for further analysis.

The subsequent stage involves entry point discovery, where dedicated Discovery agents meticulously identify and isolate all user input sources. Once entry points are identified, they are evaluated by Enrichment agents that examine associated components such as permissions and routing conditions, thereby determining if they require additional insights concerning access control or data flow.

Following the entry point evaluation, hypotheses are generated to assess the security measures in place around each entry point. This involves checking whether user access is appropriately restricted or inadvertently exposed to unauthorized entities. The harness performs additional tracking of user inputs and monitors data flow throughout the system.

The final stage of the process entails Hypothesis Validation, where the efficacy of security measures at each entry point is assessed. By the conclusion of the five stages, AVDH aims to ascertain whether vulnerabilities are confirmed, disproved, or dismissed—results that are subsequently presented to human experts for additional validation.

Tselevich noted the existence of red teams dedicated to security, but he acknowledged the challenges associated with scaling these efforts. He emphasized that Mandiant’s experiments with AVDH and the codebases it has analyzed have allowed the harness to evolve, reaching a level of maturity suitable for enterprise-scale deployment. “We are providing a blueprint that we have utilized to scan vast codebases from enterprises of all varieties,” he concluded.

Source link

Latest articles

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

Emergent Cyber Threats: Understanding Week-to-Week Developments In the constantly evolving landscape of cybersecurity, this week...

Deepfake Ads Lure Investors into WhatsApp Groups Managed by Fake Financial Analysts

Investment Fraud: The Rise of Deepfake Scams Investment fraud has become an increasingly sophisticated issue,...

9 Million Facial Images Exposed by ClarityCheck

Unsecured Database Exposes Millions of Facial Images: A Privacy Risk Recent findings by security researcher...

UK Legal Regulator Raises Concerns Over AI Misuse

The Solicitors Regulation Authority (SRA), the regulatory body overseeing the legal sector in the...

More like this

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

Emergent Cyber Threats: Understanding Week-to-Week Developments In the constantly evolving landscape of cybersecurity, this week...

Deepfake Ads Lure Investors into WhatsApp Groups Managed by Fake Financial Analysts

Investment Fraud: The Rise of Deepfake Scams Investment fraud has become an increasingly sophisticated issue,...

9 Million Facial Images Exposed by ClarityCheck

Unsecured Database Exposes Millions of Facial Images: A Privacy Risk Recent findings by security researcher...