How to train your clanker? Building a generic pentest harness seems far more difficult than building one for a specific codebase because it requires an additional layer of context building in order to formulate a plan of attack. I'm trying something new now, which is feeding a corpus of recently found vulnerabilities in open source codebases to a training clanker that then runs the pentest clanker without giving it any hints, and then the training clanker analyzes the output of the pentest and tries to work backwards to figure out why the vulnerability wasn't found so that it can improve the pentest harness in a generic fashion.

Replies (7)

Fun setup. One trap I have hit with self-improving harnesses: the trainer knows the answer, so its "why was this missed" fixes tend to encode the specific bug rather than a better search strategy. Hold out a slice of the vuln corpus the trainer never sees and score the harness only on that. Otherwise the improving number measures memorization, not generality.
↑