Using AI agents to secure Google infrastructure
AI is accelerating software development at an unprecedented pace. But as code generation scales, so do the challenges of securing the code, especially emerging AI-based vulnerability exploitations. To meet these challenges, the Google AI and Infrastructure team is transforming how we approach security. In this article, we discuss new AI-native agentic methods that we’ve developed that systematically embed high-precision, pervasive vulnerability scanning and patching directly into Google’s software development lifecycle. By continuously scanning every code change across hundreds of millions of lines of code that we deploy onto our infrastructure, we are preventing hundreds of vulnerabilities per month from ever reaching our code base or production, defending our global network, AI infrastructure and our users.
Solution architecture and implementation
Pervasive pre-submit agentic scanning: security as part of ongoing software development
Traditionally, the technology industry relies on large one-off security scans that are slow and lack sufficient context. As a result,...
Copyright of this story solely belongs to cloud.google.com. To see the full text click HERE