Saltzer & Schroeder for 2030: Security engineering principles in a world of AI

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Patnaik, Nikhil, Hallett, Joseph, Rashid, Awais
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914861526548480
author Patnaik, Nikhil
Hallett, Joseph
Rashid, Awais
author_facet Patnaik, Nikhil
Hallett, Joseph
Rashid, Awais
contents Writing secure code is challenging and so it is expected that, following the release of code-generative AI tools, such as ChatGPT and GitHub Copilot, developers will use these tools to perform security tasks and use security APIs. However, is the code generated by ChatGPT secure? How would the everyday software or security engineer be able to tell? As we approach the next decade we expect a greater adoption of code-generative AI tools and to see developers use them to write secure code. In preparation for this, we need to ensure security-by-design. In this paper, we look back in time to Saltzer & Schroeder's security design principles as they will need to evolve and adapt to the challenges that come with a world of AI-generated code.
format Preprint
id arxiv_https___arxiv_org_abs_2407_05710
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Saltzer & Schroeder for 2030: Security engineering principles in a world of AI
Patnaik, Nikhil
Hallett, Joseph
Rashid, Awais
Software Engineering
Writing secure code is challenging and so it is expected that, following the release of code-generative AI tools, such as ChatGPT and GitHub Copilot, developers will use these tools to perform security tasks and use security APIs. However, is the code generated by ChatGPT secure? How would the everyday software or security engineer be able to tell? As we approach the next decade we expect a greater adoption of code-generative AI tools and to see developers use them to write secure code. In preparation for this, we need to ensure security-by-design. In this paper, we look back in time to Saltzer & Schroeder's security design principles as they will need to evolve and adapt to the challenges that come with a world of AI-generated code.
title Saltzer & Schroeder for 2030: Security engineering principles in a world of AI
topic Software Engineering
url https://arxiv.org/abs/2407.05710