LLM-CloudSec: Large Language Model Empowered Automatic and Deep Vulnerability Analysis for Intelligent Clouds

被引:0
|
作者
Cao, Daipeng [1 ]
Wu, Jun [1 ]
机构
[1] Waseda Univ, Grad Sch Informat Prod & Syst, Tokyo, Japan
来源
IEEE INFOCOM 2024-IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS, INFOCOM WKSHPS 2024 | 2024年
基金
中国国家自然科学基金;
关键词
Cloud Application; Large Language Model; Vulnerability Detection; Common Weakness Enumeration;
D O I
10.1109/INFOCOMWKSHPS61880.2024.10620804
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The advance of intelligent cloud applications has brought attention to potential security vulnerabilities. Vulnerability detection is a critical step in ensuring the security of cloud applications. However, traditional techniques for vulnerability detection, such as static and dynamic analysis, are challenging to apply in heterogeneous cloud environments. Using data-driven methods such as Machine Learning (ML) to automate vulnerability detection in cloud applications shows promise. However, current ML solutions are limited to coarse-grained vulnerability categorization and function-level analysis. Therefore, we propose LLM-CloudSec, an unsupervised approach to fine-grained vulnerability analysis based on the Large Language Model (LLM). LLM-CloudSec uses Retrieval Augmented Generation (RAG) and the Common Weakness Enumeration (CWE) as an external knowledge base to improve its ability to detect and analyze vulnerabilities. We conduct experiments on the Juliet C++ test suite, and the results show that LLM-CloudSec enables CWE-based vulnerability classification and line-level vulnerability analysis. Additionally, we applied LLM-CloudSec to the D2A dataset, which was collected from real-world scenarios. We obtained 1230 data entries labelled with CWE and detailed vulnerability analysis. To foster related research, we publish our work on https://github.com/DPCa0/LLM-CloudSec.
引用
收藏
页数:6
相关论文
共 5 条
  • [1] DLAP: A Deep Learning Augmented Large Language Model Prompting framework for software vulnerability detection
    Yang, Yanjing
    Zhou, Xin
    Mao, Runfeng
    Xu, Jinwei
    Yang, Lanxin
    Zhang, Yu
    Shen, Haifeng
    Zhang, He
    JOURNAL OF SYSTEMS AND SOFTWARE, 2025, 219
  • [2] Large Language Model and Digital Twins Empowered Asynchronous Federated Learning for Secure Data Sharing in Intelligent Labeling
    Sheng, Xuanzhu
    Yu, Chao
    Cui, Xiaolong
    Zhou, Yang
    MATHEMATICS, 2024, 12 (22)
  • [3] VTT-LLM: Advancing Vulnerability-to-Tactic-and-Technique Mapping through Fine-Tuning of Large Language Model
    Zhang, Chenhui
    Wang, Le
    Fan, Dunqiu
    Zhu, Junyi
    Zhou, Tang
    Zeng, Liyi
    Li, Zhaohua
    MATHEMATICS, 2024, 12 (09)
  • [4] Artificially Intelligent Billing in Spine Surgery: An Analysis of a Large Language Model
    Zaidat, Bashar
    Lahoti, Yash S.
    Yu, Alexander
    Mohamed, Kareem S.
    Cho, Samuel K.
    Kim, Jun S.
    GLOBAL SPINE JOURNAL, 2025, 15 (02) : 1113 - 1120
  • [5] Pixel-level spectral aflatoxin B1 content intelligent prediction via fine-tuning large language model (LLM)
    Zhu, Hongfei
    Zhao, Yifan
    Zhao, Longgang
    Yang, Ranbing
    Han, Zhongzhi
    FOOD CONTROL, 2025, 171