When you complete this material, you will be able to:
Prepare to find and fix vulnerabilities. This includes how to prepare the AI and its sandbox, as well as how to prepare the software threat model, code/documentation, and CI/CD processes to make this more effective.
Find & fix vulnerabilities using AI. This includes:
Knowing the value of separating the process of identifying findings from the process of validating them.
How to identify findings (potential vulnerabilities), including mechanisms for increasing the likelihood of finding potential vulnerabilities such as using past vulnerability reports.
How to deduplicate, validate, and triage findings.
How to fix vulnerabilities and verify the fixes, including the importance of ensuring that a defect is fully fixed.
Knowing important aspects of reporting, releasing, and deploying the fixes.
Understanding the need for repeatedly looking for vulnerabilities when using AI, given the non-deterministic nature of modern AI, where a single application may miss important issues.
Prevent longer-term problems. This includes evaluating merge/pull requests, the need for secure-by-design and secure-by-default, and the importance of larger-scale hardening.