Cisco logo.

Cisco has unveiled Antares, a family of small language models that screens files in code repositories that are likely to contain known security vulnerabilities.

SiliconANGLE reported on Monday that Cisco distributed Antares-350M and Antares-1B as open-weight models on Hugging Face, and plans to release a larger model, Antares-3B.

Antares was developed by Cisco Foundation AI, Cisco's AI research and engineering group focused on security. It aims to narrow down where vulnerabilities are located by linking public vulnerability databases, security advisories and common weakness classification information to specific files in code repositories.

Based on vulnerability descriptions, Antares searches for related code patterns and candidate files. It changes its path as it incorporates clues and presents a ranking of files with higher likelihood. The output also includes the final search path.

All the models can run locally. Security teams can analyze sensitive source code in their own environments without sending it to the cloud. Cisco said the setup could be suitable for universities, the public sector, non-profits and small security teams that lack budgets for commercial models.

Cisco drew a line by saying Antares is only a tool to speed up the first step of vulnerability screening and does not replace it. It said it does not take the place of dependency analysis, software composition analysis, secret scanning, dynamic testing or human review.

Keyword

#Cisco #Antares #Hugging Face #Cisco Foundation AI #Common Weakness Enumeration
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.