Cyber Mission : Anthropic veut mettre Claude au service de la cybersécurité

Anthropic launches Cyber Mission, an initiative that leverages Claude to detect security vulnerabilities in critical infrastructure and open-source software.

Anthropic announced the Anthropic Cyber Mission, a long-term initiative aimed at strengthening cybersecurity with its artificial intelligence models. The company intends to focus its initial efforts on two particularly sensitive areas: critical infrastructure, such as power grids and water distribution systems, and the open-source software on which much of global computing relies.

For infrastructure, Anthropic is launching the Critical Infrastructure Defense Program (CIDP), which combines Claude's capabilities with the expertise of cybersecurity professionals. Eleven partners are participating in its launch, including Accenture, CrowdStrike, Deloitte, Palo Alto Networks, Hitachi, and Rockwell Automation. The program notably provides for the deployment of engineers on-site, threat analysis, and the identification of vulnerabilities in industrial systems.

The difficulty lies in the very nature of these equipments. Some have been operating for several decades and cannot easily be shut down to perform an update. A poorly prepared intervention can disrupt a factory, a transportation network, or a power facility. Anthropic therefore wishes to use Claude to assist specialized teams in detecting and patching flaws, without replacing their expertise. Several partners are already experimenting with this approach with their clients.

The other component concerns open-source software, often maintained by small teams with limited resources. With OSS Scanner, Anthropic offers maintainers of eligible projects regular and free security scans, performed by its most advanced models. The reports detail potential vulnerabilities, their possible exploitation, and, when feasible, a proposed fix.

These reports are transmitted without prior human verification. Anthropic therefore acknowledges a risk of errors, particularly in assessing the severity of flaws, and announces that it is targeting an accurate detection rate of over 90%. The service is primarily intended for teams capable of reviewing the results and ensuring the follow-up of fixes.

This initiative extends the work of Project Glasswing, during which Anthropic and its partners analyzed hundreds of open-source projects. While many vulnerabilities were discovered, addressing them sometimes stretched over several months. The group also expanded its Cyber Verification Program, designed to give qualified security professionals enhanced access to the capabilities of its models.

Anthropic starts from an observation: the same AI advancements that facilitate the search for vulnerabilities can also be exploited to conduct attacks. The company believes that the technology could, ultimately, further favor defenders, provided that the time between the discovery of a flaw and its fix is reduced. A goal that will depend as much on the reliability of the models as on the ability of teams to intervene on systems that are sometimes impossible to interrupt.