Leveraging Large Language Models for Preliminary Security Risk Analysis: A Mission-Critical Case Study

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Esposito, Matteo, Palagiano, Francesco
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929635715973120
author Esposito, Matteo
Palagiano, Francesco
author_facet Esposito, Matteo
Palagiano, Francesco
contents Preliminary security risk analysis (PSRA) provides a quick approach to identify, evaluate and propose remeditation to potential risks in specific scenarios. The extensive expertise required for an effective PSRA and the substantial ammount of textual-related tasks hinder quick assessments in mission-critical contexts, where timely and prompt actions are essential. The speed and accuracy of human experts in PSRA significantly impact response time. A large language model can quickly summarise information in less time than a human. To our knowledge, no prior study has explored the capabilities of fine-tuned models (FTM) in PSRA. Our case study investigates the proficiency of FTM to assist practitioners in PSRA. We manually curated 141 representative samples from over 50 mission-critical analyses archived by the industrial context team in the last five years.We compared the proficiency of the FTM versus seven human experts. Within the industrial context, our approach has proven successful in reducing errors in PSRA, hastening security risk detection, and minimizing false positives and negatives. This translates to cost savings for the company by averting unnecessary expenses associated with implementing unwarranted countermeasures. Therefore, experts can focus on more comprehensive risk analysis, leveraging LLMs for an effective preliminary assessment within a condensed timeframe.
format Preprint
id arxiv_https___arxiv_org_abs_2403_15756
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Leveraging Large Language Models for Preliminary Security Risk Analysis: A Mission-Critical Case Study
Esposito, Matteo
Palagiano, Francesco
Software Engineering
Artificial Intelligence
Computation and Language
Cryptography and Security
Computers and Society
Preliminary security risk analysis (PSRA) provides a quick approach to identify, evaluate and propose remeditation to potential risks in specific scenarios. The extensive expertise required for an effective PSRA and the substantial ammount of textual-related tasks hinder quick assessments in mission-critical contexts, where timely and prompt actions are essential. The speed and accuracy of human experts in PSRA significantly impact response time. A large language model can quickly summarise information in less time than a human. To our knowledge, no prior study has explored the capabilities of fine-tuned models (FTM) in PSRA. Our case study investigates the proficiency of FTM to assist practitioners in PSRA. We manually curated 141 representative samples from over 50 mission-critical analyses archived by the industrial context team in the last five years.We compared the proficiency of the FTM versus seven human experts. Within the industrial context, our approach has proven successful in reducing errors in PSRA, hastening security risk detection, and minimizing false positives and negatives. This translates to cost savings for the company by averting unnecessary expenses associated with implementing unwarranted countermeasures. Therefore, experts can focus on more comprehensive risk analysis, leveraging LLMs for an effective preliminary assessment within a condensed timeframe.
title Leveraging Large Language Models for Preliminary Security Risk Analysis: A Mission-Critical Case Study
topic Software Engineering
Artificial Intelligence
Computation and Language
Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2403.15756