Uppsats

Enhancing Software Security with AI: Detecting Vulnerabilities in High-Level Programming Languages

Master-uppsats

Lunds universitet/Institutionen för elektro- och informationsteknik

Publicerad: 2024

Språk: Engelska

Nyckelord

klicka för att söka

Sammanfattning

With the rapid growth of software dependencies in critical systems, detecting vulnerabilities early in the development cycle has become a necessity. While extensive research exists on vulnerability detection in low-level languages like C/C++, there is a significant gap in addressing vulnerabilities in higher-level languages, including JavaScript, Python, and PHP. This thesis explores the feasibility of using fine-tuned large language models (LLMs) to detect vulnerabilities in these higher level languages, leveraging data-driven approaches to bridge the existing research gap. In this thesis we work with fine-tuning LLMs on a curated dataset derived from CVEFixes, implementing the model in an API format to facilitate integration into CI/CD pipelines. Key performance metrics, including accuracy, precision, and F1 score, reveal that the model achieved varying effectiveness across different languages, with strong results in JavaScript and Java but weaker results in PHP, highlighting the nuanced challenges of vulnerability detection in diverse programming contexts. To demonstrate real-world applicability, the models proposed in this thesis were deployed through a user-friendly web interface, with API accessibility allowing seamless integration for developers. In our discussion, we address the ethical and security implications of using AIdriven vulnerability detection, including potential misuse by malicious actors and over-reliance on automated findings. The findings suggest that while LLMs are promising for certain languages, further refinement is needed to improve accuracy and reliability across diverse high-level languages. Future work should explore hybrid models that combine traditional and AI-based detection to mitigate current limitations and enhance practical use in software security, and CWE-specific training for higher-level languages.

Information

Författare
Dahlén, Kevin
Lärosäte / institution
Lunds universitet/Institutionen för elektro- och informationsteknik
Publiceringsdatum
2024
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.