arXiv:2412.19088cs.CRcs.AI2024-12被引 3

用开源大模型检测代码漏洞和过时代码,提升供应链安全

Integrating Artificial Open Generative Artificial Intelligence into Software Supply Chain Security

  • 将开源大模型用于分析源码错误与过时代码
  • 能发现传统扫描器遗漏的问题,但内存消耗大
  • 适合安全团队持续更新数据以应对新威胁

随着新技术涌现,人为错误始终存在。软件供应链日益复杂且相互关联,服务的安全性已成为保障产品完整性、数据隐私和运营连续性的关键。本文实验了开放的大语言模型(LLMs)在两大软件安全挑战中的应用:源码语言错误与过时代码,并关注其替代依赖预定义规则的静态和动态安全扫描器的潜力。研究发现,尽管大模型展现出一些意外成果,但仍面临显著局限,尤其在内存复杂性和处理新出现的未知数据模式方面。尽管如此,通过结合广泛的安全数据库和持续更新,主动使用大模型有望增强软件供应链(SSC)对新兴威胁的防御能力。

原文摘要 · Abstract (English)

While new technologies emerge, human errors always looming. Software supply chain is increasingly complex and intertwined, the security of a service has become paramount to ensuring the integrity of products, safeguarding data privacy, and maintaining operational continuity. In this work, we conducted experiments on the promising open Large Language Models (LLMs) into two main software security challenges: source code language errors and deprecated code, with a focus on their potential to replace conventional static and dynamic security scanners that rely on predefined rules and patterns. Our findings suggest that while LLMs present some unexpected results, they also encounter significant limitations, particularly in memory complexity and the management of new and unfamiliar data patterns. Despite these challenges, the proactive application of LLMs, coupled with extensive security databases and continuous updates, holds the potential to fortify Software Supply Chain (SSC) processes against emerging threats.

大模型代码安全供应链

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。