Human Intelligence Guides New AI System to Enhance Web Security
Meet HTTP Terminator, a newly developed AI system that has successfully pinpointed numerous websites susceptible to HTTP request smuggling. In a notable achievement, it conducted live hacks on these sites and uncovered what researchers are terming a “genuinely new class” of vulnerability known as “shared-parser confusion.”
However, the system didn’t operate independently; rather, it was under the strategic guidance of a human researcher throughout its deployment, which is perhaps the most significant aspect of this development.
James Kettle, PortSwigger’s director of research, crafted HTTP Terminator based on his established methodologies. He formulated precise, high-impact questions, excluded less meaningful responses, and applied an anomaly-detection framework to guide the AI’s research efforts. "This inverts the accepted narrative—an expert can significantly amplify an AI research system," Kettle explained in a recent white paper. "A human's involvement can add meaningful value rather than just building the system and stepping away."
Understanding HTTP Smuggling
HTTP desync attacks, commonly referred to as HTTP request smuggling, disrupt how websites handle HTTP requests from users. This attack vector exploits the communication between front-end servers and back-end servers, which often sends multiple requests concurrently over a single network connection to optimize performance.
Kettle pointed out the inherent weaknesses in this architecture: "HTTP requests pile up and the back-end server struggles to discern where one request ends and the next begins." A mismatch in understanding can allow malicious actors to send ambiguous signals that the back-end interprets as two separate requests.
Attackers can engage in response query poisoning (RQP), allowing them to inject misleading information into later requests or alter data flows. This manipulation can expose sensitive user data, including credentials and API keys, by enabling attackers to intercept responses intended for others.
Interestingly, while HTTP smuggling vulnerabilities have traditionally been linked to HTTP/1 requests, exposure persists in setups using HTTP/2, depending upon their architecture.
How HTTP Terminator Operates
Kettle’s design of HTTP Terminator closely mirrored his research methodologies. The process kicks off with ideation, where the AI autonomously generates testable hypotheses for RQP attacks, including potential desynchronization triggers and weaponization techniques.
Next comes the evaluation phase, where these hypotheses are rigorously tested on live websites approved for security assessments through bug-bounty and Vulnerability Disclosure Programs (VDPs). Here, an integrated anomaly detection mechanism scrutinizes unexpected responses.
Following this, a weaponization phase determines the real-world implications of the findings. In its initial trials, HTTP Terminator developed 30,000 unique attack vectors, identifying 700 vulnerable sites, including key financial institutions and government services. It even harvested a live API key from one of the tested banks, with breaches linked to flaws in well-known enterprise products like Apache Traffic Server and Citrix NetScaler.
Kettle introduced a 'cascade' phase, where each finding may reveal additional unexplored targets or detection methods. "Discoveries enable a backward exploration that can uncover previously hidden vulnerabilities," he elaborated. Each finding acts as the seed for subsequent research, creating a feedback loop that promotes further inquiry.
Implications for Security Teams
HTTP Terminator managed to devise and validate multiple new desynchronization triggers and patterns, along with a unique weaponization technique. Among these innovations is the shared-parser confusion approach, which expands an attacker's ability to parse requests and responses, vastly increasing the attack surface.
"This is a monumental discovery," Kettle stated, yet he insisted, "the process wasn’t fully autonomous; while HTTP Terminator proposed the concepts, I confirmed them. We wouldn’t have made this finding in isolation."
To democratize this research, Kettle has open-sourced HTTP Terminator along with his foundational research blueprint, enabling other security experts to transform their own methodologies into powerful autonomous systems.
Kettle suggests a four-step approach: establish clear objectives, devise an evaluation strategy, pinpoint sources for inspiration, and trace potential cascade paths for new discoveries. "Getting the evaluation phase right is essential for both design and implementation; any slip-ups here could undermine the entire initiative," he advised.
It's paramount to aggressively tackle data quality issues early on, as rectifying problems later proves challenging. High-value questions should be targeted without being overly broad, and initial test outputs must be critically assessed to filter out lower-value hypotheses. "Every additional sentence in the prompt carries the risk of context contamination," Kettle remarked.
Kettle acknowledged the reality of fully autonomous research yet underscored the significant role humans play in amplifying AI research efforts. It’s more effective to initiate with an AI-heavy technique and subsequently delegate to deterministic code for enhanced efficiency and accuracy. This balanced methodology maximizes both the speed and precision of security research.