Leveraging Large Language Models for Preliminary Security Risk Analysis: A Mission-Critical Case Study

被引:0
|
作者
Esposito, Matteo [1 ]
Palagiano, Francesco [2 ]
机构
[1] Univ Roma Tor Vergata, Rome, Lazio, Italy
[2] Multitel Lerede Alessandro & Csas, Rome, Lazio, Italy
关键词
Preliminary; Security; Risk; Management; Analysis; Large Language Model; LLM; Generative AI; Standards; Human Experts; Fine-Tuning;
D O I
10.1145/3661167.3661226
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Preliminary security risk analysis (PSRA) provides a quick approach to identify, evaluate, and propose remediation to potential risks in specific scenarios. The extensive expertise required for an effective PSRA and the substantial textual-related tasks hinders quick assessments in mission-critical contexts, where timely and prompt actions are essential. The speed and accuracy of human experts in PSRA significantly impact response time. A large language model can quickly summarise information in less time than a human. To our knowledge, no prior study has explored the capabilities of fine-tuned models (FTM) in PSRA. Our case study investigates the proficiency of FTM in assisting practitioners in PSRA. We manually curated 141 representative samples from over 50 mission-critical analyses archived by the industrial context team in the last five years. We compared the proficiency of the FTM versus seven human experts. Within the industrial context, our approach has proven successful in reducing errors in PSRA, hastening security risk detection, and minimizing false positives and negatives. This translates to cost savings for the company by averting unnecessary expenses associated with implementing unwarranted countermeasures. Therefore, experts can focus on more comprehensive risk analysis, leveraging LLMs for an effective preliminary assessment within a condensed timeframe.
引用
收藏
页码:442 / 445
页数:4
相关论文
共 50 条
  • [1] Risk of adopting mission-critical OSS applications: an interpretive case study
    Poba-Nzaou, Placide
    Raymond, Louis
    Fabi, Bruno
    INTERNATIONAL JOURNAL OF OPERATIONS & PRODUCTION MANAGEMENT, 2014, 34 (04) : 477 - 512
  • [2] Leveraging Large Language Models for Enhanced Classification and Analysis: Fire Incidents Case Study
    Alkhammash, Eman H.
    FIRE-SWITZERLAND, 2025, 8 (01):
  • [3] Migrating mission-critical applications in federated cloud: A case study
    Amato A.
    Aversa R.
    Ficco M.
    Venticinque S.
    International Journal of High Performance Computing and Networking, 2018, 12 (04) : 379 - 390
  • [4] Experimentation for Business-to-Business Mission-Critical Systems: A Case Study
    Mattos, David Issa
    Dakkak, Anas
    Bosch, Jan
    Olsson, Helena Holmstrom
    2020 IEEE/ACM INTERNATIONAL CONFERENCE ON SOFTWARE AND SYSTEM PROCESSES, ICSSP, 2020, : 95 - 104
  • [5] Physical Layer Authentication in Mission-Critical MTC Networks: A Security and Delay Performance Analysis
    Forssell, Henrik
    Thobaben, Ragnar
    Al-Zubaidy, Hussein
    Gross, James
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2019, 37 (04) : 795 - 808
  • [6] Leveraging Large Language Models for Automated Dialogue Analysis
    Finch, Sarah E.
    Paek, Ellie S.
    Choi, Jinho D.
    24TH MEETING OF THE SPECIAL INTEREST GROUP ON DISCOURSE AND DIALOGUE, SIGDIAL 2023, 2023, : 202 - 215
  • [7] Leveraging large language models for data analysis automation
    Jansen, Jacqueline A.
    Manukyan, Artur
    Al Khoury, Nour
    Akalin, Altuna
    PLOS ONE, 2025, 20 (02):
  • [8] Synthesis, Analysis, and Modeling of Large-Scale Mission-Critical Embedded Software Systems
    Selby, Richard W.
    TRUSTWORTHY SOFTWARE DEVELOPMENT PROCESSES, PROCEEDINGS, 2009, 5543 : 3 - +
  • [9] LARGE LANGUAGE MODELS FOR RISK OF BIAS ASSESSMENT: A CASE STUDY
    Edwards, M.
    Bishop, E.
    Reddish, K.
    Carr, E.
    di Ruffano, L. Ferrante
    VALUE IN HEALTH, 2024, 27 (12)
  • [10] Adopting open source for mission-critical applications: A case study on single sign-on
    Ardagna, Claudio Agostino
    Damiani, Ernesto
    Frati, Fulvio
    Reale, Salvatore
    OPEN SOURCE SYSTEMS, 2006, 203 : 209 - +