Big Sleep: Google AI discovers a security bug in SQlite escaped the fuzzing | Large language models tutorial | Llm machine learning | Train llm on own data github | Turtles AI

Big Sleep: Google AI discovers a security bug in SQlite escaped the fuzzing
A new tool developed by Google and Deepmind identifies a vulnerability of memory for the first time in a widely used software, overcoming traditional testing methods
Editorial Team5 November 2024

 

 

Google announced that Big Sleep, its new AI-based tool developed in collaboration with DeepMind, has discovered a security bug in SQLite, an open source database, that had escaped traditional fuzzing methods. This marks a significant step in the use of AI to improve cybersecurity, with a focus on detecting memory vulnerabilities.

Key points:

  • Big Sleep identified a security vulnerability undetected by fuzzing in SQLite.
  • The bug involves a stack buffer underflow, which could lead to crashes or arbitrary code execution.
  • This is the first case in which an AI model has found an exploitable bug in widely used software.
  • The vulnerability was corrected promptly by SQLite developers, thanks to a report by Big Sleep.

Google recently announced a major cyber security milestone with the revelation of an exploitable bug in the code of SQLite, a widely used open source database engine. The discovery came about thanks to Big Sleep, an advanced AI system developed in collaboration between Google’s Project Zero and DeepMind. This tool looks like a significant evolution from previous research initiatives, such as Project Naptime, and appears to represent a real breakthrough in software security. Big Sleep proved capable of detecting a security flaw that eluded traditional approaches, such as fuzzing, that are commonly used to detect vulnerabilities in software.

The vulnerability identified by Big Sleep was a stack buffer underflow, a type of error that, if exploited, could have caused a system crash or even allowed arbitrary code to execute, endangering user security. Specifically, the problem stemmed from the use of a magic value (-1) as an array index, without proper protection against out-of-bounds values. Although there was a check by assert() to detect incorrect use of this index, in release versions of the software this check was disabled, leaving the system vulnerable. The bug was not easy to exploit, but under certain conditions, such as malicious database injection, an attack could have led to remote code execution.

Although the bug was difficult to detect, fuzzing tools, which operate by random data entry to find anomalies in code, failed to detect it. In contrast, Big Sleep, a Large Language Model (LLM)-based model developed by Google, identified the problem with unprecedented speed and accuracy. The model, powered by Gemini 1.5 Pro technology, was tested on a sample of recent commits in the SQLite repository, a process that led to the discovery of the bug quickly. Once the flaw was found, the SQLite team promptly fixed the vulnerability, preventing the flawed code from being released publicly.

This event marks an important step for the use of AI in finding security vulnerabilities, as it demonstrates the ability of AI models to detect complex and exploitable problems that had eluded more traditional methods. The discovery was described by members of the Big Sleep team as an important “milestone,” as it represents the first time an AI system has detected a previously unknown memory security bug in commonly used software. The developers pointed out that although fuzzing remains a key tool in finding vulnerabilities, artificial intelligence could play a complementary role, especially in finding errors that are difficult or impossible to identify through other techniques.

However, the case of Big Sleep is not the only one in which AI has been employed in software security. In October, Protect AI launched Vulnhuntr, an open source tool that uses Anthropic’s Claude AI model to detect zero-day vulnerabilities in Python code. Although the two tools have different goals-with Vulnhuntr focused on Python vulnerabilities and Big Sleep on memory security flaws-both mark the beginning of an era in which artificial intelligence plays an increasingly central role in protecting software infrastructure.

For now, Big Sleep is still in the research phase, and its developers are cautious in declaring definitive conclusions about its potential. The tests carried out so far have mainly concerned small programs with vulnerability already known, and this is the first time that the tool has faced a real and complex application as SQLite. However, despite the enthusiasm for the discovery, Google experts recognized that specialized fuzzing tools could continue to be equally effective, if no longer, in detecting certain types of vulnerability.

While the progress of AI technologies in IT security is indisputable, it is clear that it is a rapidly evolving field, with multiple approaches that are flanked to ensure the protection of the software from increasingly sophisticated attacks.