Assured Patching: Can we do it and how can AI help?

Patching is one thing the software industry does all the time, but almost never well and never enough. For some other problems, e.g., memory safety and input validation, we made progress by understanding what the problems were and how to do better based on science. Yet for patching it remains unclear what its core scientific problems are, where they need to be addressed, and what abstractions must be developed or changed. This lack of clarity holds back both traditional computer science research approaches and AI automation---for AI to be effective, it must be told what problems it must solve, and how to check if it actually did.  I will talk about my attempts to define the problems of patching, during my time at DARPA and beyond.

 

About the Presenter: Sergey Bratus

I am the Dartmouth College Distinguished Professor in Cyber Security, Technology, and Society and an Associate Professor of Computer Science. In 2018--2024 I served as a Program Manager at DARPA's Information Innovation Office (I2O), where I created multiple fundamental research programs in cybersecurity, resilience, and sustainment of critical software. You can read about them here.

I am interested in all aspects of cyber security, including Unix and Linux kernel security, software verification and cyber hardening, malware detection and reverse engineering (especially at the kernel and boot-stage firmware levels), wireless networking, digital radio, and visualizations of security-related information. I am interested in identifying and eliminating the root causes of software vulnerabilities, and I believe that this requires connecting state-of-the-art hacking with fundamental concepts of computer science. I believe that edge-of-the-art hacking has developed into a distinct discipline of computer science, even though not formally recognized as such, and that studying it is indispensable for building future computing systems we could finally trust.

Next
Next

Finding 100+ Zero-Days in Open Source with AI Agents