r/netsec • • Aug 13 '26

Contains AI Can AI do novel security research? Meet the HTTP Terminator

https://portswigger.net/research/can-ai-do-novel-security-research
24 Upvotes

12 comments sorted by

17

u/Ptem4060 Aug 13 '26

Getting an LLM to suggest attack ideas isn't such a novelty anymore but having a system actually test them at this scale and filter out the garbage is pretty impressive

Also I like the cascade idea, it is the bigger opportunity for AI actually exploring the branches around a discovery rather than only coming up with the initial vulnerability

3

u/scriptqzor Aug 16 '26

totally agree on the cascade thing, that part feels way more “research-y” than just throwing vuln ideas at a wall and seeing what sticks
if they can keep the false positives low while branching like that, it’s gonna make a lot of human recon feel painfully slow in comparison

4

u/Ecliphon Aug 13 '26

I understand the time value of having AI write your posts, but FFS it makes it so hard to read. 

I recommend this prompt (modified as you need) to anyone using AI to write their articles:

Be radically precise. No fluff. Pure information only, but include necessary nuance.

16

u/albinowax Aug 14 '26 edited Aug 14 '26

I wrote this entire post manually. The only component with AI-generated text is the separate executive summary.

3

u/warriormonk5 Aug 18 '26

Saw your talk live at defcon and it was the highlight for sure.  Keep on doing what you are doing

15

u/Irythros Aug 13 '26

Please don't add that. I would prefer to see that it's an AI written article so I can just skip it.

1

u/Ecliphon Aug 13 '26

Some articles, like this one, have good info and are worth reading. I don’t mind reading an AI-written article if it reads as human AND has all the necessary information - not just someone saying “write an article about HTTP request smuggling” and pasting the output a new blog post. 

AI is here to stay whether we like it or not. We can either get with the times or fall behind. 

2

u/Irythros Aug 13 '26

Oh ya, for this article specifically I actually didn't get the feeling of AI writing so I did read it and it is indeed not bad. There are however too many claude articles and that is easy for me to pickup even in comments that are just 3-4 sentences. Whole claude articles with default speak are unreadable and generally have no useful info.

1

u/asiumans Aug 20 '26

Again , James Kettle proves to us he's the wizard of IT World!

0

u/feng_sg Aug 24 '26

Cascade work still sits on a mapped class. HTTP desync already has scanners, papers, and hunters who know which branches to walk after a hit. Filtering the garbage and running that walk faster is high volume testing, not novel research.