Cyber Reasoning Systems for the Next Generation
Can higher order descriptive metadata alone aid automated exploitation of code repositories? Or are we stuck waiting for more sophisticated language models?
A Cyber Reasoning System (CRS) is a program that can use threat information and source code to find and patch vulnerabilities in a code repository automatically. These systems increasingly use large language models for search with great effect, and the solution space for these systems has become very diverse. In this talk I will argue that while there is a very valid space for using a cyber reasoning system to protect key libraries, the solution space it often produces is narrower than desired.
To explore this notion of implementation versus algorithmic flaws in code, we will walk through a cyber security harness that produces code for the Lean 4 proof assistant as an intermediate representation language. The demo will explore this in practice with the Anthropic Glasswing demo harness, displaying the trade offs of using proof metadata as part of a cyber reasoning system. We'll contrast this with a larger parallel system that operates proof metadata in the context of an implementation of OSS-CRS.
About the Presenter: Jonathan Reiter
Jonathan is a Member of Technical Staff at VulnCheck, specializing in canary development. He has presented at CYBERWARCON and DEF CON on the topics of cyber threat intelligence related to state actors, undocumented industrial protocols, and incident response simulation on AI-enabled architecture.

