Inicio  /  Future Internet  /  Vol: 15 Par: 10 (2023)  /  Artículo
ARTÍCULO
TITULO

A New Approach to Web Application Security: Utilizing GPT Language Models for Source Code Inspection

Zoltán Szabó and Vilmos Bilicki    

Resumen

Due to the proliferation of large language models (LLMs) and their widespread use in applications such as ChatGPT, there has been a significant increase in interest in AI over the past year. Multiple researchers have raised the question: how will AI be applied and in what areas? Programming, including the generation, interpretation, analysis, and documentation of static program code based on promptsis one of the most promising fields. With the GPT API, we have explored a new aspect of this: static analysis of the source code of front-end applications at the endpoints of the data path. Our focus was the detection of the CWE-653 vulnerability?inadequately isolated sensitive code segments that could lead to unauthorized access or data leakage. This type of vulnerability detection consists of the detection of code segments dealing with sensitive data and the categorization of the isolation and protection levels of those segments that were previously not feasible without human intervention. However, we believed that the interpretive capabilities of GPT models could be explored to create a set of prompts to detect these cases on a file-by-file basis for the applications under study, and the efficiency of the method could pave the way for additional analysis tasks that were previously unavailable for automation. In the introduction to our paper, we characterize in detail the problem space of vulnerability and weakness detection, the challenges of the domain, and the advances that have been achieved in similarly complex areas using GPT or other LLMs. Then, we present our methodology, which includes our classification of sensitive data and protection levels. This is followed by the process of preprocessing, analyzing, and evaluating static code. This was achieved through a series of GPT prompts containing parts of static source code, utilizing few-shot examples and chain-of-thought techniques that detected sensitive code segments and mapped the complex code base into manageable JSON structures.Finally, we present our findings and evaluation of the open source project analysis, comparing the results of the GPT-based pipelines with manual evaluations, highlighting that the field yields a high research value. The results show a vulnerability detection rate for this particular type of model of 88.76%, among others.

 Artículos similares

       
 
Dilanka Chandrasiri, Perampalam Gatheeshgar, Hadi Monsef Ahmadi and Lenganji Simwanda    
In the construction domain, there is a growing emphasis on sustainability, resource efficiency, and energy optimisation. Light-gauge steel panels (LGSPs) stand out for their inherent advantages including lightweight construction and energy efficiency. Ho... ver más
Revista: Buildings

 
Yalin Yang, Yanan Wu and May Yuan    
In-person social events bring people to places, while people and places influence where and what social events occur. Knowing what people do and where they build social relationships gives insights into the distribution and availability of places for soc... ver más

 
Gholamreza Eslamifar, Hamid Balali and Alexander Fernald    
Enhancing the comprehension of alterations in land use holds paramount importance for water management in semi-arid regions due to its effects on hydrology and agricultural economics. Allowing agricultural land to lie fallow has emerged as a technique to... ver más
Revista: Water

 
Guangxi Sun, Gang Zhang, Jianrong Huang, Qiaoli Shi, Xiaocheng Tang and Salamat Ullah    
In the present paper, a modified Fourier series approach is developed for new precise flexural analysis of three different types of concrete plates in a rectangular sewage tank. The bending problems of the bottom plate, side-plate, and the fluid-guiding ... ver más
Revista: Buildings

 
Dario Bottino-Leone, Dagmar Elisabet Exner, Jennifer Adami, Alexandra Troi and Jessica Balest    
The abandonment and deterioration of historic rural buildings in Europe raise significant issues, including hydrogeological risks, the loss of productive land, and cultural heritage decline. Despite being underestimated, these structures hold significant... ver más
Revista: Buildings