Can Sonnet 4.5 hack a network? (www.incalmo.ai)

🤖 AI Summary
Incalmo and Anthropic tested Claude-derived Sonnet 4.5 on a suite of realistic cyber ranges (25–50 hosts each) to measure whether frontier LLMs can autonomously plan and execute long‑horizon network attacks. Sonnet 4.5, given only a Kali shell harness, outperformed prior Claude models—successfully compromising two additional ranges and accessing more key assets on average (e.g., database records). The researchers demonstrated an Equifax‑style exploit where Sonnet 4.5 discovered a vulnerable Apache Struts endpoint and iteratively developed bash/OGNL payloads to spawn processes, enumerate files, and ultimately read an SSH private key—an approach that differs from human red teamers who typically reuse frameworks like Metasploit. This work is significant because it shows LLMs’ raw network‑attack capability is rapidly improving even without specialized toolkits, while also underscoring the multiplier effect of domain‑specific harnesses: Incalmo previously enabled LLMs to hack 37/40 ranges using an integrated attack system. Key technical takeaways are that modern LLMs can perform multistep discovery, exploit development, and data exfiltration via command‑line interfaces, but still struggle as topology, host count, and vulnerability complexity increase. The results both raise cyber‑safety concerns and point to a pragmatic defensive opportunity: realistic, scalable cyber ranges can be used to stress‑test and harden networks against emerging autonomous threats.
Loading comments...
loading comments...