用大模型生成有金融影响的安全部署报告,提升团队响应速度
The potential of LLM-generated reports in DevSecOps
- 用大模型生成强调财务后果的安全报告
- 调查显示可显著提高问题处理意愿
- 适合资源紧张的开发团队应对告警疲劳
DevSecOps中告警疲劳是常见问题。安全扫描工具产生的大量警告,尤其在资源有限的小团队中,导致成员麻木、响应迟缓,可能暴露系统漏洞。本文探索大语言模型(LLM)生成强调未修复安全问题财务后果的可操作报告的潜力,如凭据泄露。对开发者的调查表明,此类报告能显著提升立即处理安全问题的可能性,提供清晰、全面且具有激励性的洞察。将这类报告集成到DevSecOps流程中,有助于缓解注意力过载和告警疲劳,确保关键安全警告得到有效响应。
原文摘要 · Abstract (English)
Alert fatigue is a common issue faced by software teams using the DevSecOps paradigm. The overwhelming number of warnings and alerts generated by security and code scanning tools, particularly in smaller teams where resources are limited, leads to desensitization and diminished responsiveness to security warnings, potentially exposing systems to vulnerabilities. This paper explores the potential of LLMs in generating actionable security reports that emphasize the financial impact and consequences of detected security issues, such as credential leaks, if they remain unaddressed. A survey conducted among developers indicates that LLM-generated reports significantly enhance the likelihood of immediate action on security issues by providing clear, comprehensive, and motivating insights. Integrating these reports into DevSecOps workflows can mitigate attention saturation and alert fatigue, ensuring that critical security warnings are addressed effectively.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。