用大模型自动分析文献,快速发现研究空白
CEKER: A Generalizable LLM Framework for Literature Analysis with a Case Study in Unikernel Security
- 三步流程:收集、提取、总结文献关键信息
- 发现无地址随机化等三大安全漏洞,验证有效
- 适合需要高效文献综述的研究者和安全领域
文献综述是提出新研究的核心环节,但传统方法依赖人工,耗时费力。本文提出通用型文献分析框架CEKER,通过三步流程实现文献收集、关键洞察提取与趋势总结的自动化。基于大语言模型(LLM),该方法具备可扩展性、灵活性和重复性,适用于多领域研究。以微内核安全为例,验证了其生成新见解的能力。分析揭示‘攻击面缩小’为最显著主题,关键安全缺口包括缺乏地址空间布局随机化、缺少调试工具及熵生成不足。研究还发现对虚拟机管理器的依赖可能成为攻击入口,并强调需动态调整安全策略以应对实时威胁。
原文摘要 · Abstract (English)
Literature reviews are a critical component of formulating and justifying new research, but are a manual and often time-consuming process. This research introduces a novel, generalizable approach to literature analysis called CEKER which uses a three-step process to streamline the collection of literature, the extraction of key insights, and the summarized analysis of key trends and gaps. Leveraging Large Language Models (LLMs), this methodology represents a significant shift from traditional manual literature reviews, offering a scalable, flexible, and repeatable approach that can be applied across diverse research domains. A case study on unikernel security illustrates CEKER's ability to generate novel insights validated against previous manual methods. CEKER's analysis highlighted reduced attack surface as the most prominent theme. Key security gaps included the absence of Address Space Layout Randomization, missing debugging tools, and limited entropy generation, all of which represent important challenges to unikernel security. The study also revealed a reliance on hypervisors as a potential attack vector and emphasized the need for dynamic security adjustments to address real-time threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。