Integrating Artificial Open Generative Artificial Intelligence into Software Supply Chain Security

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Alevizos, Vasileios, Papakostas, George A, Simasiku, Akebu, Malliarou, Dimitra, Messinis, Antonis, Edralin, Sabrina, Xu, Clark, Yue, Zongliang
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913655397810176
author Alevizos, Vasileios
Papakostas, George A
Simasiku, Akebu
Malliarou, Dimitra
Messinis, Antonis
Edralin, Sabrina
Xu, Clark
Yue, Zongliang
author_facet Alevizos, Vasileios
Papakostas, George A
Simasiku, Akebu
Malliarou, Dimitra
Messinis, Antonis
Edralin, Sabrina
Xu, Clark
Yue, Zongliang
contents While new technologies emerge, human errors always looming. Software supply chain is increasingly complex and intertwined, the security of a service has become paramount to ensuring the integrity of products, safeguarding data privacy, and maintaining operational continuity. In this work, we conducted experiments on the promising open Large Language Models (LLMs) into two main software security challenges: source code language errors and deprecated code, with a focus on their potential to replace conventional static and dynamic security scanners that rely on predefined rules and patterns. Our findings suggest that while LLMs present some unexpected results, they also encounter significant limitations, particularly in memory complexity and the management of new and unfamiliar data patterns. Despite these challenges, the proactive application of LLMs, coupled with extensive security databases and continuous updates, holds the potential to fortify Software Supply Chain (SSC) processes against emerging threats.
format Preprint
id arxiv_https___arxiv_org_abs_2412_19088
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Integrating Artificial Open Generative Artificial Intelligence into Software Supply Chain Security
Alevizos, Vasileios
Papakostas, George A
Simasiku, Akebu
Malliarou, Dimitra
Messinis, Antonis
Edralin, Sabrina
Xu, Clark
Yue, Zongliang
Cryptography and Security
Artificial Intelligence
Emerging Technologies
While new technologies emerge, human errors always looming. Software supply chain is increasingly complex and intertwined, the security of a service has become paramount to ensuring the integrity of products, safeguarding data privacy, and maintaining operational continuity. In this work, we conducted experiments on the promising open Large Language Models (LLMs) into two main software security challenges: source code language errors and deprecated code, with a focus on their potential to replace conventional static and dynamic security scanners that rely on predefined rules and patterns. Our findings suggest that while LLMs present some unexpected results, they also encounter significant limitations, particularly in memory complexity and the management of new and unfamiliar data patterns. Despite these challenges, the proactive application of LLMs, coupled with extensive security databases and continuous updates, holds the potential to fortify Software Supply Chain (SSC) processes against emerging threats.
title Integrating Artificial Open Generative Artificial Intelligence into Software Supply Chain Security
topic Cryptography and Security
Artificial Intelligence
Emerging Technologies
url https://arxiv.org/abs/2412.19088