Skip to main content

DARPA prize-winning bot Mayhem deploys to seek flaws, shut out botnets

darpa mayhem bot cyber grand challenge winners
DARPA
In a riff on Hitchcock’s To Catch a Thief, a powerful software bot is being used to defeat botnets. Carnegie Mellon spinoff ForAllSecure’s Mayhem software won $2 million in a Defense Advanced Research Projects Agency (DARPA) Pentagon hacking contest in Las Vegas last August, according to MIT Technology Review.

Mayhem is the creation of Carnegie Mellon professor David Brumley and two of his graduate students. In the DARPA contest, called the Cyber Grand Challenge, the competitors had two tasks: Fix and defend assigned server software and hack the server code assigned to other teams. The purpose of the contest, which awarded a total of $4 million in prizes, was to encourage the automating computer security tasks. DARPA states the primary focus is the development of defensive software, MIT Technology Review reports.

Fresh from the bot battle, Brumley and his company are adopting Mayhem for commercial applications, intended to find flaws in internet firmware, starting with, but not limited to, routers. In 2016 the group tested some parts of Mayhem’s code with nearly 2,000 router firmware images. In the course of testing, the code found that more than 40 percent of the routers had at least one vulnerability including 14 that had never before been detected and were involved in 69 separate software builds.

One of the biggest challenges with internet device vulnerabilities is chasing down and updating products from past product cycles. The promise of Mayhem is its potential to both detect and repair or defend against vulnerabilities quickly. One example is a botnet — a large number of computers or devices, often in the tens and hundreds of thousands, that are unknowingly recruited for malicious purposes by computer malware. When each of the multitude of devices is directed to make multiple, rapid requests of a single website in order to overwhelm servers and effectively shut down the site, it’s called a “distributed denial of service” (DDoS) attack.

After last October’s massive DDoS attack using vulnerability in smart home web cameras, the need for better screening and protection was underscored, particularly in devices purchased by less-knowledgeable users.

Mayhem’s job will be to find and patch immediately. “Now when a machine is compromised it takes days or weeks for someone to notice and then days or weeks — or never — until a patch is put out,” Brumley said. “Imagine a world where the first-time a hacker exploits a vulnerability he can only exploit one machine and then it’s patched.”

Answering concerns that human security experts will still want to check the work of defensive bots, according to Brumley even the United States government still wants to have a “human in the loop.”

“I’m not against that, but I feel that it slows down the process,” Brumley said.

Bruce Brown
Digital Trends Contributing Editor Bruce Brown is a member of the Smart Homes and Commerce teams. Bruce uses smart devices…
These Razer Blade discounts for Amazon Gaming Week are rogue-like
Razer Blade 15 lifestyle image on desk

Ahead of Amazon Gaming Week in May, Razer is offering some incredible deals on its Blade series of gaming laptops. Amazon's Gaming Week celebration, if you're not familiar with it, is filled with deals and promotions for all types of gamers, from the avid streamer and competitive PC gamer to console aficionados and beyond. Razer's deals, specifically, are some of the best for PC gamers looking to upgrade their gaming setups for the latest titles. Take , for instance, that drops the price by $700 to $2,300. It has a 15-inch QHD+ 240Hz display, an Intel Core i7 13800H processor, 32GB of DDR5 RAM, an NVIDIA GeForce RTX 4070, and a 2TB solid-state drive. That's plenty of power packed inside to play the latest games on high or above with stable framerates, plenty of storage to download and install a few big titles, and a price that won't empty your bank account. I highly recommend browsing to see what deals Razer has available, you won't regret it.

 
What else is discounted for Razer's Gaming Week sale
Okay, so I know it's technically Amazon Gaming Week, but these Razer deals are firmly in the category of "best in class" for discounts on PC gaming laptops, so I'm giving them a call out. You can expect to save anywhere from $400 to $700 on these powerful laptops in the Razer Blade series, from the Blade 14 to the Blade 18. Also, they all feature the NVIDIA GeForce RTX 40 series GPUs, offering a ton of power to play the latest titles like Helldivers 2, Baldur's Gate 3, Dragon's Dogma 2, and more.

Read more
Here’s everything to consider when buying a CPU in 2024
AMD Ryzen 9 3900x pins.

Searching for a new CPU in 2024 presents you with excellent options for powerful processors, budget chips that punch well above their weight, and some incredibly efficient options that are perfect for small builds. That's what makes the modern CPU landscape so exciting: You don't just need to buy the best processor you can afford.

The right CPU for you is one that can do everything you need right now, and do it well, while also providing some future-proofing, and ideally, a clear upgrade path for the future. Here's how to buy a CPU in 2024.
CPU specs, explained

Read more
Apple has backed itself into a corner
Apple iPad Pro 11 with Apple Magic Keyboard.

Apple is rumored to finally be updating its new iPads at its forthcoming May 7 event. While this may come as a relief to anyone who’s been patiently waiting to upgrade their iPad Pro or iPad Air, a new report has thrown the whole situation into confusion.

That’s because the latest Power On newsletter from Bloomberg reporter Mark Gurman claims that the upcoming iPad Pro will contain an Apple M4 chip. On first blush, that doesn’t seem all that unusual -- the iPad Pro has come with an Apple silicon chip for years, after all. But here’s the wrinkle: this launch plan would mean the iPad will get an M4 chip before the Mac, and that has all kinds of weird implications. By delaying the iPad for so long, it looks like Apple has left itself with a very odd update cycle for its chips this time around.
The end of the M3 Ultra?

Read more