Automating Security Audit Using Large Language Model based Agent: An Exploration Experiment

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Chin, Jia Hui, Zhang, Pu, Cheong, Yu Xin, Pan, Jonathan
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866909612155863040
author Chin, Jia Hui
Zhang, Pu
Cheong, Yu Xin
Pan, Jonathan
author_facet Chin, Jia Hui
Zhang, Pu
Cheong, Yu Xin
Pan, Jonathan
contents In the current rapidly changing digital environment, businesses are under constant stress to ensure that their systems are secured. Security audits help to maintain a strong security posture by ensuring that policies are in place, controls are implemented, gaps are identified for cybersecurity risks mitigation. However, audits are usually manual, requiring much time and costs. This paper looks at the possibility of developing a framework to leverage Large Language Models (LLMs) as an autonomous agent to execute part of the security audit, namely with the field audit. password policy compliance for Windows operating system. Through the conduct of an exploration experiment of using GPT-4 with Langchain, the agent executed the audit tasks by accurately flagging password policy violations and appeared to be more efficient than traditional manual audits. Despite its potential limitations in operational consistency in complex and dynamic environment, the framework suggests possibilities to extend further to real-time threat monitoring and compliance checks.
format Preprint
id arxiv_https___arxiv_org_abs_2505_10732
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Automating Security Audit Using Large Language Model based Agent: An Exploration Experiment
Chin, Jia Hui
Zhang, Pu
Cheong, Yu Xin
Pan, Jonathan
Cryptography and Security
Artificial Intelligence
In the current rapidly changing digital environment, businesses are under constant stress to ensure that their systems are secured. Security audits help to maintain a strong security posture by ensuring that policies are in place, controls are implemented, gaps are identified for cybersecurity risks mitigation. However, audits are usually manual, requiring much time and costs. This paper looks at the possibility of developing a framework to leverage Large Language Models (LLMs) as an autonomous agent to execute part of the security audit, namely with the field audit. password policy compliance for Windows operating system. Through the conduct of an exploration experiment of using GPT-4 with Langchain, the agent executed the audit tasks by accurately flagging password policy violations and appeared to be more efficient than traditional manual audits. Despite its potential limitations in operational consistency in complex and dynamic environment, the framework suggests possibilities to extend further to real-time threat monitoring and compliance checks.
title Automating Security Audit Using Large Language Model based Agent: An Exploration Experiment
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2505.10732