Using Generative AI Models to Support Cybersecurity Analysts

Štefan Balogh,Marek Mlynček,Oliver Vraňák,Pavol Zajac
DOI: https://doi.org/10.3390/electronics13234718
IF: 2.9
2024-11-30
Electronics
Abstract:One of the tasks of security analysts is to detect security vulnerabilities and ongoing attacks. There is already a large number of software tools that can help to collect security-relevant data, such as event logs, security settings, application manifests, and even the (decompiled) source code of potentially malicious applications. The analyst must study these data, evaluate them, and properly identify and classify suspicious activities and applications. Fast advances in the area of Artificial Intelligence have produced large language models that can perform a variety of tasks, including generating text summaries and reports. In this article, we study the potential black-box use of LLM chatbots as a support tool for security analysts. We provide two case studies: the first is concerned with the identification of vulnerabilities in Android applications, and the second one is concerned with the analysis of security logs. We show how LLM chatbots can help security analysts in their work, but point out specific limitations and security concerns related to this approach.
engineering, electrical & electronic,computer science, information systems,physics, applied
What problem does this paper attempt to address?