Ana gezinime geç Aramaya geç Ana içeriğe geç

Friends, Not Foes: Enhancing Attack Surface Metrics of Web Applications with Large Language Models

  • Istanbul Technical University

Araştırma sonucu: Kitap/Rapor/Konferans Bildirisinde BölümKonferans katkısıbilirkişi

Özet

The attack surface refers to all potential points of entry in a system that an attacker could exploit. In this work, we present an advanced metric for calculating the attack surface of web applications by leveraging the capabilities of large language models (LLMs) and introducing new features based on recent evaluations of the OWASP Top 10 security risks. Incorporating 28 parameters across 9 main categories and drawing on past studies to address previously identified limitations, this metric provides a comprehensive assessment of the attack surface. The Euclidean norm of the metric allows for quantitative comparisons, enabling precise evaluation and monitoring of security risks. Additionally, we develop a tool to facilitate the calculation of attack surface parameters, with the source code available as open source. The tool features an interface that visualizes the attack surface vector, presenting the metrics of web applications in graphical form. Among its many uses, web security analysts can employ our metric and tool to monitor changes in an application's attack surface across different versions. We also provide recommendations for further improving attack surface metric calculations using LLMs.

Orijinal dilİngilizce
Ana bilgisayar yayını başlığı17th International Conference on Information Security and Cryptology, ISCTurkiye 2024 - Proceedings
EditörlerAli Aydin Selcuk, Seref Sagiroglu, Oguz Yayla, Cihangir Tezcan
YayınlayanInstitute of Electrical and Electronics Engineers Inc.
ISBN (Elektronik)9798331533649
DOI'lar
Yayın durumuYayınlandı - 2024
Etkinlik17th International Conference on Information Security and Cryptology, ISCTurkiye 2024 - Ankara, Türkiye
Süre: 16 Eki 202417 Eki 2024

Yayın serisi

Adı17th International Conference on Information Security and Cryptology, ISCTurkiye 2024 - Proceedings

???event.eventtypes.event.conference???

???event.eventtypes.event.conference???17th International Conference on Information Security and Cryptology, ISCTurkiye 2024
Ülke/BölgeTürkiye
ŞehirAnkara
Periyot16/10/2417/10/24

Bibliyografik not

Publisher Copyright:
© 2024 IEEE.

Parmak izi

Friends, Not Foes: Enhancing Attack Surface Metrics of Web Applications with Large Language Models' araştırma başlıklarına git. Birlikte benzersiz bir parmak izi oluştururlar.

Alıntı Yap