Leveraging Large Language Models for Preliminary Security Risk Analysis: A Mission-Critical Case Study

被引:0
|
作者
Esposito, Matteo [1 ]
Palagiano, Francesco [2 ]
机构
[1] Univ Roma Tor Vergata, Rome, Lazio, Italy
[2] Multitel Lerede Alessandro & Csas, Rome, Lazio, Italy
关键词
Preliminary; Security; Risk; Management; Analysis; Large Language Model; LLM; Generative AI; Standards; Human Experts; Fine-Tuning;
D O I
10.1145/3661167.3661226
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Preliminary security risk analysis (PSRA) provides a quick approach to identify, evaluate, and propose remediation to potential risks in specific scenarios. The extensive expertise required for an effective PSRA and the substantial textual-related tasks hinders quick assessments in mission-critical contexts, where timely and prompt actions are essential. The speed and accuracy of human experts in PSRA significantly impact response time. A large language model can quickly summarise information in less time than a human. To our knowledge, no prior study has explored the capabilities of fine-tuned models (FTM) in PSRA. Our case study investigates the proficiency of FTM in assisting practitioners in PSRA. We manually curated 141 representative samples from over 50 mission-critical analyses archived by the industrial context team in the last five years. We compared the proficiency of the FTM versus seven human experts. Within the industrial context, our approach has proven successful in reducing errors in PSRA, hastening security risk detection, and minimizing false positives and negatives. This translates to cost savings for the company by averting unnecessary expenses associated with implementing unwarranted countermeasures. Therefore, experts can focus on more comprehensive risk analysis, leveraging LLMs for an effective preliminary assessment within a condensed timeframe.
引用
收藏
页码:442 / 445
页数:4
相关论文
共 50 条
  • [41] Lexical Semantics with Large Language Models: A Case Study of English break
    Petersen, Erika
    Potts, Christopher
    17TH CONFERENCE OF THE EUROPEAN CHAPTER OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, EACL 2023, 2023, : 490 - 511
  • [42] Using Large Language Models to Support Content Analysis: A Case Study of ChatGPT for Adverse Event Detection
    Leas, Eric C.
    Ayers, John W.
    Desai, Nimit
    Dredze, Mark
    Hogarth, Michael
    Smith, Davey M.
    JOURNAL OF MEDICAL INTERNET RESEARCH, 2024, 26
  • [43] Coal Mine Accident Risk Analysis with Large Language Models and Bayesian Networks
    Du, Gu
    Chen, An
    SUSTAINABILITY, 2025, 17 (05)
  • [44] Adopting Pre-trained Large Language Models for Regional Language Tasks: A Case Study
    Gaikwad, Harsha
    Kiwelekar, Arvind
    Laddha, Manjushree
    Shahare, Shashank
    INTELLIGENT HUMAN COMPUTER INTERACTION, IHCI 2023, PT I, 2024, 14531 : 15 - 25
  • [45] Leveraging Large Language Models with Chain-of-Thought and Prompt Engineering for Traffic Crash Severity Analysis and Inference
    Zhen, Hao
    Shi, Yucheng
    Huang, Yongcan
    Yang, Jidong J.
    Liu, Ninghao
    COMPUTERS, 2024, 13 (09)
  • [46] Transforming online learning research: Leveraging GPT large language models for automated content analysis of cognitive presence
    Castellanos-Reyes, Daniela
    Olesova, Larisa
    Sadaf, Ayesha
    INTERNET AND HIGHER EDUCATION, 2025, 65
  • [47] Enhancing Code Security Through Open-Source Large Language Models: A Comparative Study
    Ridley, Norah
    Branca, Enrico
    Kimber, Jadyn
    Stakhanova, Natalia
    FOUNDATIONS AND PRACTICE OF SECURITY, PT I, FPS 2023, 2024, 14551 : 233 - 249
  • [48] An Empirical Study on Using Large Language Models to Analyze Software Supply Chain Security Failures
    Singla, Tanmay
    Anandayuvaraj, Dharun
    Kalu, Kelechi G.
    Schorlemmer, Taylor R.
    Davis, James C.
    PROCEEDINGS OF THE 2023 WORKSHOP ON SOFTWARE SUPPLY CHAIN OFFENSIVE RESEARCH AND ECOSYSTEM DEFENSES, SCORED 2023, 2023, : 5 - 15
  • [49] Security Best Practices: A Critical Analysis Using IoT as a Case Study
    Barrera, David
    Bellman, Christopher
    Van Oorschot, Paul
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2023, 26 (02)
  • [50] From words to wellness: a retrospective study leveraging large language models on conversational data to uncover patient needs
    Ferrand, T.
    Chambost, J.
    Jacques, C.
    He, C.
    HUMAN REPRODUCTION, 2024, 39 : I45 - I45