arXiv:2505.04265cs.CRcs.AI2025-05中稿 · publication in the…综述

用大模型自动验证漏洞报告,减少误报,提升效率。

Weaponizing Language Models for Cybersecurity Offensive Operations: Automating Vulnerability Assessment Report Validation; A Review Paper

  • 用大模型自动化分析和验证漏洞报告内容
  • 可降低误报率,提高评估效率
  • 适合安全团队与自动化工具开发者参考

随着网络战日益复杂,亟需新解决方案。大型语言模型(LLMs)在网络安全防御中已展现潜力,但在进攻性应用方面研究甚少,尤其在漏洞评估(VA)报告验证领域。本文通过文献综述,提出一种利用LLMs自动化分析与验证VA报告的新方法,有望减少误报并显著提升整体效率。该研究为实现更准确、高效的安全报告验证提供了可行路径,同时揭示了LLM在攻防两端的双重能力,有助于制定更优化的网络安全策略与工具。结果表明,基于LLM的自动化验证对提升安全态势具有重要意义。

原文摘要 · Abstract (English)

This, with the ever-increasing sophistication of cyberwar, calls for novel solutions. In this regard, Large Language Models (LLMs) have emerged as a highly promising tool for defensive and offensive cybersecurity-related strategies. While existing literature has focused much on the defensive use of LLMs, when it comes to their offensive utilization, very little has been reported-namely, concerning Vulnerability Assessment (VA) report validation. Consequentially, this paper tries to fill that gap by investigating the capabilities of LLMs in automating and improving the validation process of the report of the VA. From the critical review of the related literature, this paper hereby proposes a new approach to using the LLMs in the automation of the analysis and within the validation process of the report of the VA that could potentially reduce the number of false positives and generally enhance efficiency. These results are promising for LLM automatization for improving validation on reports coming from VA in order to improve accuracy while reducing human effort and security postures. The contribution of this paper provides further evidence about the offensive and defensive LLM capabilities and therefor helps in devising more appropriate cybersecurity strategies and tools accordingly.

大模型漏洞检测自动化安全攻防

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。