Google has a new AI-powered security kit that should give human researchers a break
Project Naptime uses AI to help identify vulnerabilities
Google’s Project Zero, a team of security analysts, has introduced a new framework aimed at enhancing automated vulnerability research using large language models.
Project Naptime uses AI to replicate the systematic methods used by human security researchers to reduce some of the pressure on the already strained workforce.
The initiative gets its name from its potential to allow human workers to “take regular naps” while AI handles complex vulnerability research tasks.
Google reveals details of Project Naptime
Google Project Zero’s Sergei Glazunov and Mark Brand, noted, “Naptime uses a specialised architecture to enhance an LLM's ability to perform vulnerability research.”
Key components of the Naptime architecture include a Code Browser Tool which allows the AI agent to navigate the target codebase, similar to how engineers use Chromium Code Search; a Python Tool that enables running Python scripts in a sandboxed environments, a Debugger Tool that observes program behavior with different inputs; and a Reporter Tool that monitors the task progress and verifies success conditions.
Glazunov and Brand added: “Naptime enables an LLM to perform vulnerability research that closely mimics the iterative, hypothesis-driven approach of human security experts.”
In tests using the CyberSecEval 2 benchmark suite, released by rival tech company Meta, Naptime demonstrated significant improvements in identifying buffer overflow and advanced memory corruption flaws in C and C++ code.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Though in its early stages, Google’s Project Naptime marks a significant step forward in automated vulnerability research, potentially helping to reduce gaps left by traditional methods while addressing the ongoing skills shortage.
More from TechRadar Pro
- Cybersecurity workers are increasingly working over the weekends — and many are ready to quit
- Check out the best AI tools and best AI writers you can use in your business
- Enhance your security with the best endpoint protection software
With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!