Leveraging Large Language Models for Preliminary Security Risk Analysis: A Mission-Critical Case Study

被引:0
|
作者
Esposito, Matteo [1 ]
Palagiano, Francesco [2 ]
机构
[1] Univ Roma Tor Vergata, Rome, Lazio, Italy
[2] Multitel Lerede Alessandro & Csas, Rome, Lazio, Italy
关键词
Preliminary; Security; Risk; Management; Analysis; Large Language Model; LLM; Generative AI; Standards; Human Experts; Fine-Tuning;
D O I
10.1145/3661167.3661226
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Preliminary security risk analysis (PSRA) provides a quick approach to identify, evaluate, and propose remediation to potential risks in specific scenarios. The extensive expertise required for an effective PSRA and the substantial textual-related tasks hinders quick assessments in mission-critical contexts, where timely and prompt actions are essential. The speed and accuracy of human experts in PSRA significantly impact response time. A large language model can quickly summarise information in less time than a human. To our knowledge, no prior study has explored the capabilities of fine-tuned models (FTM) in PSRA. Our case study investigates the proficiency of FTM in assisting practitioners in PSRA. We manually curated 141 representative samples from over 50 mission-critical analyses archived by the industrial context team in the last five years. We compared the proficiency of the FTM versus seven human experts. Within the industrial context, our approach has proven successful in reducing errors in PSRA, hastening security risk detection, and minimizing false positives and negatives. This translates to cost savings for the company by averting unnecessary expenses associated with implementing unwarranted countermeasures. Therefore, experts can focus on more comprehensive risk analysis, leveraging LLMs for an effective preliminary assessment within a condensed timeframe.
引用
收藏
页码:442 / 445
页数:4
相关论文
共 50 条
  • [21] Enhancing Software Sustainability: Leveraging Large Language Models to Evaluate Security Requirements Fulfillment in Requirements Engineering
    Subahi, Ahmad F.
    SYSTEMS, 2025, 13 (02):
  • [22] Leveraging large language models for medical text classification: a hospital readmission prediction case
    Nazyrova, Nodira
    Chahed, Salma
    Chausalet, Thierry
    Dwek, Miriam
    2024 14TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION SYSTEMS, ICPRS, 2024,
  • [23] A Security Risk Taxonomy for Prompt-Based Interaction With Large Language Models
    Derner, Erik
    Batistic, Kristina
    Zahalka, Jan
    Babuska, Robert
    IEEE ACCESS, 2024, 12 : 126176 - 126187
  • [24] Security Analysis of Large Language Models on API Misuse Programming Repair
    Zhang, Rui
    Qiao, Ziyue
    Yu, Yong
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2024, 2024
  • [25] Leveraging large language models for generating responses to patient messages-a subjective analysis
    Liu, Siru
    Mccoy, Allison B.
    Wright, Aileen P.
    Carew, Babatunde
    Genkins, Julian Z.
    Huang, Sean S.
    Peterson, Josh F.
    Steitz, Bryan
    Wright, Adam
    JOURNAL OF THE AMERICAN MEDICAL INFORMATICS ASSOCIATION, 2024, 31 (06) : 1367 - 1379
  • [26] Leveraging Large Language Models for QA Dialogue Dataset Construction and Analysis in Public Services
    Wu, Chaomin
    Wu, Di
    Pan, Yushan
    Wang, Hao
    NATURAL LANGUAGE PROCESSING AND CHINESE COMPUTING, PT I, NLPCC 2024, 2025, 15359 : 56 - 68
  • [27] Leveraging Large Language Models for the Auto-remediation of Microservice Applications: An Experimental Study
    Sarda, Komal
    Namrud, Zakeya
    Litoiu, Marin
    Shwartz, Larisa
    Watts, Ian
    COMPANION PROCEEDINGS OF THE 32ND ACM INTERNATIONAL CONFERENCE ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, FSE COMPANION 2024, 2024, : 358 - 369
  • [28] Safety analysis in the era of large language models: A case study of STPA using ChatGPT
    Qi, Yi
    Zhao, Xingyu
    Khastgir, Siddartha
    Huang, Xiaowei
    MACHINE LEARNING WITH APPLICATIONS, 2025, 19
  • [29] Large Language Models and Sentiment Analysis in Financial Markets: A Review, Datasets, and Case Study
    Liu, Chenghao
    Arulappan, Arunkumar
    Naha, Ranesh
    Mahanti, Aniket
    Kamruzzaman, Joarder
    Ra, In-Ho
    IEEE ACCESS, 2024, 12 : 134041 - 134061
  • [30] Sentiment and Emotion Analysis with Large Language Models for Political Security Prediction Framework
    Zaabar, Liyana Safra
    Yacob, Adriana Arul
    Isa, Mohd Rizal Mohd
    Wook, Muslihah
    Abdullah, Nor Asiakin
    Ramli, Suzaimah
    Razali, Noor Afiza Mat
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2025, 16 (01) : 954 - 960