Add your offcanvas content in here

The Company

Simplifying your IT-security journey.

Knowledge & News

Tool-supported source code analyses powered by LLMs

October 24, 2024 |
Tags: SAST SCA

Talk at the W-JAX

Improving Application Security Analyses Using LLMs

About the talk

Even if current frameworks and libraries make it increasingly difficult for developers to (accidentally) introduce serious security problems into their applications, this topic generally does not lose its importance; in many companies, an opposite "expectation" can even be observed. With the emergence of powerful AI systems, equipped with sometimes impressive programming skills, the idea of improving, accelerating, and automating processes in the security environment through these systems logically arose.

In this session, we would like to present our approach to how classic, mature (closed and open source) scanning software (SAST, SCA…) can be combined with the capabilities of modern Large Language Models (LLM) in order to

  1. effectively get a handle on technologically induced large false-positive quantities
  2. focus attention on the really important findings from the start
  3. obtain support in understanding and evaluating findings
  4. without losing focus, and also being able to fall back on more (specialized) tools in combination

For empirical data, we manually and via LLM evaluated many thousands of findings and compared the results. Based on this, in addition to tips for your own implementation, the presentation will also highlight the (quality) differences when working with free and proprietary LLMs and discuss do's and don'ts for prompting.

Munich or Online, Wednesday, November 06, 2024 – 15:15 – 16:15

The Author

Mirko Richter

Mirko Richter is a Software Security Consultant, Source Code Analysis Specialist and Training Manager for basic training courses up to advanced coding and Secure SDLC training. He has been involved in software development, architecture and security since the mid-90s. He is a speaker at conferences and author of several technical articles.