Автоматизація аналізу безпеки коду на основі генеративного штучного інтелекту
Вантажиться...
Файли
Дата
Автори
Назва журналу
Номер ISSN
Назва тому
DOI
Анотація
The paper investigates the application of generative artificial intelligence, specifically large language models, for automating source code security analysis. A comparative analysis of traditional static analysis tools and LLM-based approaches is conducted. The advantages and limitations of generative models in vulnerability identification, threat classification, and remediation recommendation generation are identified. A hybrid approach combining SAST tools with LLM-based analysis using RAG technology is proposed.
Опис
Ключові слова
Тип документа
Мова
ISSN
Бібліографічний опис
Фіглярський І. А., Куперштейн Л. М. Автоматизація аналізу безпеки коду на основі генеративного штучного інтелекту // Матеріали LV Всеукраїнської науково-технічної конференції підрозділів ВНТУ, Вінниця, 24-27 березня 2026 р. Електрон. текст. дані. 2026. Електрон. текст. дані. 2026. URI: https://conferences.vntu.edu.ua/index.php/all-fitki/all-fitki-2026/paper/view/28178.
Схвалення
Рецензія
Доповнено
Цитується в
Список використаної літератури (7)
- McGraw G. Software Security: Building Security In / G. McGraw. – Boston : Addison-Wesley, 2006. – 448 p.
- OWASP Foundation. OWASP Top Ten URL: https://owasp.org/www-project-top-ten.
- Pearce H. Examining Zero-Shot Vulnerability Repair with Large Language Models / H. Pearce, B. Tan, B. Ahmad et al. // IEEE Symposium on Security and Privacy. – 2023. – P. 2339–2356.
- Zhou X. Large Language Model for Vulnerability Detection and Repair: Literature Review and the Road Ahead / X. Zhou, S. Cao, X. Sun, D. Lo // ACM Transactions on Software Engineering and Methodology. – 2024. – Vol. 34. – P. 1–31.
- Howard M. The Security Development Lifecycle / M. Howard, S. Lipner. – Redmond : Microsoft Press, 2006. – 320 p.
- Sheng Z. LLMs in Software Security: A Survey of Vulnerability Detection Techniques and Insights / Z. Sheng, Z. Chen, S. Gu et al. // ACM Computing Surveys. – 2025. – Vol. 57, No. 7. – P. 1–33.
- Ullah S. LLMs Cannot Reliably Identify and Reason About Security Vulnerabilities (Yet?): A