Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
97 tokens/sec
GPT-4o
53 tokens/sec
Gemini 2.5 Pro Pro
44 tokens/sec
o3 Pro
5 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

An Empirical Study on Using Large Language Models to Analyze Software Supply Chain Security Failures (2308.04898v1)

Published 9 Aug 2023 in cs.CR, cs.LG, and cs.SE

Abstract: As we increasingly depend on software systems, the consequences of breaches in the software supply chain become more severe. High-profile cyber attacks like those on SolarWinds and ShadowHammer have resulted in significant financial and data losses, underlining the need for stronger cybersecurity. One way to prevent future breaches is by studying past failures. However, traditional methods of analyzing these failures require manually reading and summarizing reports about them. Automated support could reduce costs and allow analysis of more failures. NLP techniques such as LLMs could be leveraged to assist the analysis of failures. In this study, we assessed the ability of LLMs to analyze historical software supply chain breaches. We used LLMs to replicate the manual analysis of 69 software supply chain security failures performed by members of the Cloud Native Computing Foundation (CNCF). We developed prompts for LLMs to categorize these by four dimensions: type of compromise, intent, nature, and impact. GPT 3.5s categorizations had an average accuracy of 68% and Bard had an accuracy of 58% over these dimensions. We report that LLMs effectively characterize software supply chain failures when the source articles are detailed enough for consensus among manual analysts, but cannot yet replace human analysts. Future work can improve LLM performance in this context, and study a broader range of articles and failures.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (5)
  1. Tanmay Singla (3 papers)
  2. Dharun Anandayuvaraj (5 papers)
  3. Taylor R. Schorlemmer (8 papers)
  4. James C. Davis (60 papers)
  5. Kelechi G. Kalu (7 papers)
Citations (9)

Summary

We haven't generated a summary for this paper yet.