Anthropic Claude Sonnet 4.5 オープンソースツールのみを使用して自律的なマルチステージ攻撃を実証
TL;DR
Claude Sonnet 4.5 は、Kali Linux ホスト上の標準的な Bash コマンドのみを使用して、マルチステージのネットワーク攻撃を実行し、Equifax スタイルの侵害からシミュレートされた個人データを流出させることが可能になりました。これは、AI モデルが現実的なサイバーレンジ環境で成功するために、もはやカスタムのサイバーツールキットを必要としないことを示しています。
1. 発表の概要
Anthropic は 2026 年 1 月 16 日に、Claude Sonnet 4.5 モデルの新しい能力について説明するアップデートをリリースしました。
"In a recent evaluation of AI models’ cyber capabilities, current Claude models can now succeed at multistage attacks on networks with dozens of hosts using only standard, open-source tools, instead of the custom tools needed by previous generations."
この発表は、典型的な capture‑the‑flag 環境よりも高度な Carnegie Mellon University の CyLab サイバーレンジで Claude を評価した 2025 年の論文に基づいています。主な進歩は、Sonnet 4.5 が、以前のモデルが必要としたカスタム サイバーツールキット なし で成功できるようになったことです。
2. 前回評価からの技術的進歩
| Model | Release | Need for Custom Toolkit | Success on Equifax Simulation |
|---|---|---|---|
| Claude Sonnet 3.5 | 2024‑2025 | Required | 0 / 5 trials |
| Claude Sonnet 4.5 | 2026 | Not required for a minority of networks; still needed on 5 / 9 networks | 2 / 5 trials (autonomous) |
この軌跡は、他の AI の進歩の傾向を反映しています。モデルは、まず専門的なスキャフォールディングに依存し、その後、公開されているツールのみで動作することが可能になります。
3. Equifax スタイルの侵害シミュレーションの詳細
評価では、まだパッチが適用されていない公開 CVE を悪用した 2017 年の Equifax 侵害を再現しました。Sonnet 4.5 は、Kali Linux ホスト上の Bash シェルのみを使用して、以下のステップを実行しました。
- Vulnerability Recognition – 公開された CVE を外部検索なしですぐに特定。
- Exploit Generation – エクスプロイト コードを即座に作成。
- Data Exfiltration – ターゲットシステムからすべてのシミュレートされた個人情報を取得。
"Sonnet 4.5 can now exfiltrate all of the (simulated) personal information in a high‑fidelity simulation of the Equifax data breach… using only a Bash shell on a widely‑available Kali Linux host (standard, open‑source tools for penetration testing; not a custom toolkit)."
このモデルは 5 回中 2 回の試行で自律的に成功し、現在の AI 駆動型攻撃の自動化における可能性と変動性(variability)の両方を示しました。
4. 制限事項と成功率
- Partial Success – Sonnet 4.5 は Equifax の試行の 5 回中 2 回で自律的に成功しましたが、5 / 9 の他のネットワークでカスタムツールキットなしでは進展できませんでした。
- Dependence on Network Conditions – モデルは、到達可能な脆弱なサービスと適切な資格情報(credentials)を必要とします。すべてのターゲットに対して成功を保証するものではありません。
- Tool Availability – デモンストレーションでは Bash と Kali ユーティリティのみが使用されましたが、より複雑な環境では、追加のツールが必要になる可能性があります。
Anthropic は、これらの注意点を明示的に認めています。
"It’s important not to overstate the status quo. Claude does not succeed every time in these tests; Sonnet 4.5 succeeded autonomously on the Equifax cyber range in two of five trials. Also, for five of the nine networks it could not make progress without the custom cyber toolkit."
5. Broader Implications (より広い範囲への影響)
5.1 AI 駆動型サイバー攻撃の障壁の低下
標準的なオープンソースツールのみを使用して高度な攻撃を実行できる能力は、非技術的なアクターが AI モデルを活用して大規模な搾取を自動化できる ことを意味します。モデルが公開 CVE を認識し、エクスプロイトを生成する速度は、既知の脆弱性を迅速かつ自動的に武器化するリスクをハイライトしています。
5.2 基本的なセキュリティ・ハイジーンの重要性
Anthropic は、Equifax スタイルのシナリオが、時代を超えた防御の原則を強調していると述べています。
"The prospect of highly competent and fast AI agents leveraging this approach underscores the pressing need for security best practices like prompt updates and patches."
AI が脆弱性を即座に発見し、悪用することが可能になったため、システムをパッチ適用済みに保つことは、かつてて以上に重要になっています。
5.3 防御的 AI 研究の必要性
Anthropic は、 AI 駆動型サイバー防御者のための Anthropic 自身の研究についても言及しています。
"...real‑world examples like the recent AI‑orchestrated cyber espionage campaign... show the need for substantial research into how best to equip cyber defenders with the AI‑enabled tools they will need to keep pace."
AI 駆動型攻撃を検知、封じ込め、および修復するための防御的 AI を開発することは、優先事項です。
6. 実務家への推奨事項
- Patch Management – AI エージェントが脆弱性を悪用する前に、既知の CVE を閉じるために、パッチ適用パイプラインを加速させる。
- Network Segmentation – 重要な資産(例:データベース)を分離し、ラテラル・ムーブメント(横方向の移動)の機会を限る。
- Monitoring for Anomalous Tool Use – 予期期外のホストから、典型的なペネトレーション・テスト・ユーティリティ(例:
curlと疑わしいペイロード)が使用されている場合の検知ルールを限る。 - Invest in Defensive AI – 攻撃的な AI の速度にマッチングする、 AI 駆動型スレット・ハンティングや自動応答プラットフォームを展開する。
- Red‑Team Exercises with AI – ペネトレーション・テスト業務において、 AI 補完的な adversaries (攻撃者) を組み込み、新たな攻撃パスをサーフェス(surface)として抽出する。
7. Where to Find More Information
Incalmo’s detailed blog post – https://://www.incalmo.ai/blog/2025/10/01/sonnet_eval/
Claude Sonnet 4.5 system card (Section 5.3) – https://assets.anthropic.com/m/12f214efcc2f457a/original/Claude-Sonnet-4-5-System-Card.pdf
Anthropic’s prior 2025 cyber-toolkits paper – https://red.anthropic.com/2025/cyber-toolkits/
Anthropic’s AI-for-cyber-defenders post – https://red.anthropic.com/2025/ai-for-cyber-defenders/
Anthropic’s recent AI-orchestrated espionage campaign announcement – https://www.anthropic.com/news/disrupting-AI-espionage
8. Conclusion
Anthropic の最新の評価は、Claude Sonnet 4.5 が Kali Linux 上の標準的な Bash コマンドのみを使用して、現実的な Equifax スタイルの侵害を自律的に実行し、データを流出させることができることを示しています。これは、 AI 駆動型攻撃能力の技術的な進歩を、示しており、堅牢的なパッチ・マネジメント、パッチ適用、および AI 駆動型防御ツールの開発の緊急性を再確認させています。
SUMMARY: Anthropic は、 Claude Sonnet 4.5 が Kali Linux 上の標準的な Bash コマンドのみを使用して、現実的なサイバーレンジにおいて、 Equifax スタイルの完全なデータ流出を含むマルチステージ攻撃を自律的に実行できることを発表しました。これは、 AI 駆動型サイバー作戦の障壁が急速に低下していることを示しています。
TITLE: Anthropic Claude Sonnet 4.5 オープンソースツールのみを使用して自律的なマルチステージ攻撃を実証
Sources
関連
- Dispatch
- Dispatch
- Dispatch
- Dispatch
- Dispatch