AI让漏洞发现变便宜,但修复能力成新瓶颈。
Demystifying the Mythos or Disrupting Bugonomics? From Zero-Day Asymmetry to Defender Remediation Throughput
- 用经济学视角分析AI生成漏洞的全流程成本与收益。
- 漏洞报告量激增,但修复、验证和发布能力跟不上。
- 开源项目尤其面临维护者资源不足的挑战。
近期大语言模型在生产软件中生成候选及确认漏洞的演示,重燃了关于AI将重塑攻防安全的叙事。然而,主流报道强调能力,却很少审视成本与激励机制。本文从漏洞经济学(bugonomics)角度,分析LLM驱动漏洞发现的运营经济性:包括缺陷的生成、验证、优先级排序和修复全过程。历史上,高价值零日漏洞因需政府、中间商和攻击方投入大量资源而价格高昂;防御端已有漏洞研究、奖励计划和厂商修复工作,但LLM使候选生成、代码理解、利用构造、影响证明撰写和报告准备的成本大幅降低。尽管漏洞利用和概念验证依然重要,但在防御流程中主要承担证明影响、指导优先级和推动修复的作用。当前瓶颈不再是发现更多漏洞,而是处理更庞大的报告流——包括吸收、验证、分类、打补丁和发布。基于Anthropic Mythos Preview与Mozilla Firefox合作的公开数据,结合漏洞市场定价和漏洞奖励计划,我们指出,短期变化并非更多零日漏洞,而是防御方修复吞吐量的提升:低信号候选更廉价,证据丰富的修复更重要,稀缺资源转向维护者评审与发布工作。该效应在开源领域尤为明显,因为LLM辅助发现虽提升报告量,但维护者侧的验证、分类、资助和发布能力并未同步扩展。
原文摘要 · Abstract (English)
Recent demonstrations of large language models producing candidate and confirmed vulnerabilities in production software have renewed the narrative that AI will reshape offensive and defensive security. Headlines emphasize capability; they rarely interrogate costs and incentives. This paper examines LLM-driven vulnerability discovery through a bugonomics lens: the operational economics of producing, proving, prioritizing, and fixing security-relevant defects. Historically, the most visible high-end bugonomics was offense-priced because production-grade zero-days and exploit chains were expensive specialist outputs for governments, brokers, and offensive vendors. Defender-side bugonomics already existed in vulnerability research, reward programs, and vendor remediation work; LLM-assisted systems change its scale and distribution. They make candidate generation, code comprehension, harness construction, proof-of-impact drafting, and report preparation cheaper at codebase scale. Exploits and proofs of concept remain important, but in defender workflows they primarily prove impact, guide prioritization, and justify remediation. The resulting bottleneck is not only finding more bugs; it is absorbing, validating, triaging, patching, and shipping a larger stream of reports. Using public data from Anthropic's Mythos Preview and Mozilla Firefox collaborations, along with public exploit-market price anchors and vulnerability reward programs, we argue that the near-term shift is not simply more zero-days. It is a move toward broader defender remediation throughput: low-signal candidates become cheaper, evidence-rich remediation become more important, and scarce capacity shifts toward maintainer review and release work. The effect is acute in open source, where LLM-assisted discovery can increase report volume while maintainer-side validation, triage, funding, and release capacity may not scale.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。