LLM-CloudSec: Large Language Model Empowered Automatic and Deep Vulnerability Analysis for Intelligent Clouds

被引:0
|
作者
Cao, Daipeng [1 ]
Wu, Jun [1 ]
机构
[1] Waseda Univ, Grad Sch Informat Prod & Syst, Tokyo, Japan
基金
中国国家自然科学基金;
关键词
Cloud Application; Large Language Model; Vulnerability Detection; Common Weakness Enumeration;
D O I
10.1109/INFOCOMWKSHPS61880.2024.10620804
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The advance of intelligent cloud applications has brought attention to potential security vulnerabilities. Vulnerability detection is a critical step in ensuring the security of cloud applications. However, traditional techniques for vulnerability detection, such as static and dynamic analysis, are challenging to apply in heterogeneous cloud environments. Using data-driven methods such as Machine Learning (ML) to automate vulnerability detection in cloud applications shows promise. However, current ML solutions are limited to coarse-grained vulnerability categorization and function-level analysis. Therefore, we propose LLM-CloudSec, an unsupervised approach to fine-grained vulnerability analysis based on the Large Language Model (LLM). LLM-CloudSec uses Retrieval Augmented Generation (RAG) and the Common Weakness Enumeration (CWE) as an external knowledge base to improve its ability to detect and analyze vulnerabilities. We conduct experiments on the Juliet C++ test suite, and the results show that LLM-CloudSec enables CWE-based vulnerability classification and line-level vulnerability analysis. Additionally, we applied LLM-CloudSec to the D2A dataset, which was collected from real-world scenarios. We obtained 1230 data entries labelled with CWE and detailed vulnerability analysis. To foster related research, we publish our work on https://github.com/DPCa0/LLM-CloudSec.
引用
收藏
页数:6
相关论文
共 14 条
  • [1] Smart Contract Vulnerability Detection: The Role of Large Language Model (LLM)
    Boi, Biagio
    Esposito, Christian
    Lee, Sokjoon
    APPLIED COMPUTING REVIEW, 2024, 24 (02): : 19 - 29
  • [2] LLM-CDM: A Large Language Model Enhanced Cognitive Diagnosis for Intelligent Education
    Chen, Xin
    Zhang, Jin
    Zhou, Tong
    Zhang, Feng
    IEEE ACCESS, 2025, 13 : 47165 - 47180
  • [3] D LLM-in-the-loop: Leveraging Large Language Model for Thematic Analysis
    Dai, Shih-Chieh
    Xiong, Aiping
    Ku, Lun-Wei
    FINDINGS OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (EMNLP 2023), 2023, : 9993 - 10001
  • [4] Large Language Model and Digital Twins Empowered Asynchronous Federated Learning for Secure Data Sharing in Intelligent Labeling
    Sheng, Xuanzhu
    Yu, Chao
    Cui, Xiaolong
    Zhou, Yang
    MATHEMATICS, 2024, 12 (22)
  • [5] VTT-LLM: Advancing Vulnerability-to-Tactic-and-Technique Mapping through Fine-Tuning of Large Language Model
    Zhang, Chenhui
    Wang, Le
    Fan, Dunqiu
    Zhu, Junyi
    Zhou, Tang
    Zeng, Liyi
    Li, Zhaohua
    MATHEMATICS, 2024, 12 (09)
  • [6] Artificially Intelligent Billing in Spine Surgery: An Analysis of a Large Language Model
    Kong, Xiuhua
    Wang, Lingling
    Liu, Changhua
    GLOBAL SPINE JOURNAL, 2024, 14 (05) : 1684 - 1684
  • [7] A Framework for Agricultural Intelligent Analysis Based on a Visual Language Large Model
    Yu, Piaofang
    Lin, Bo
    APPLIED SCIENCES-BASEL, 2024, 14 (18):
  • [8] Artificially Intelligent Billing in Spine Surgery: An Analysis of a Large Language Model
    Zaidat, Bashar
    Lahoti, Yash S.
    Yu, Alexander
    Mohamed, Kareem S.
    Cho, Samuel K.
    Kim, Jun S.
    GLOBAL SPINE JOURNAL, 2023,
  • [9] DLAP: A Deep Learning Augmented Large Language Model Prompting framework for software vulnerability detection
    Yang, Yanjing
    Zhou, Xin
    Mao, Runfeng
    Xu, Jinwei
    Yang, Lanxin
    Zhang, Yu
    Shen, Haifeng
    Zhang, He
    JOURNAL OF SYSTEMS AND SOFTWARE, 2025, 219
  • [10] USE OF LARGE LANGUAGE MODEL (LLM) FOR FULL-TEXT SCREENING IN SYSTEMATIC LITERATURE REVIEWS: A COMPARATIVE ANALYSIS
    Rathi, H.
    Malik, A.
    Behera, D. C.
    Kamboj, G.
    VALUE IN HEALTH, 2024, 27 (06) : S264 - S264