Notice: Die Funktion wp_register_script wurde fehlerhaft aufgerufen. Nicht erkannte(r) Schlüssel im Parameter $args: defer. Unterstützte Schlüssel: strategy, in_footer, fetchpriority, module_dependencies Weitere Informationen: Debugging in WordPress (engl.). (Diese Meldung wurde in Version 7.0.0 hinzugefügt.) in /var/www/vhosts/mgm-sp.217-154-231-6.plesk.page/httpdocs/wp-includes/functions.php on line 6170

Notice: Die Funktion wp_register_script wurde fehlerhaft aufgerufen. Nicht erkannte(r) Schlüssel im Parameter $args: defer. Unterstützte Schlüssel: strategy, in_footer, fetchpriority, module_dependencies Weitere Informationen: Debugging in WordPress (engl.). (Diese Meldung wurde in Version 7.0.0 hinzugefügt.) in /var/www/vhosts/mgm-sp.217-154-231-6.plesk.page/httpdocs/wp-includes/functions.php on line 6170
Tool-supported source code analyses powered by LLMs – mgm security partners
Notice: The wp_enqueue_script function was incorrect Called. Unrecognized key(s) in the $args parameter: async. Supported keys: strategy, in_footer, fetchpriority, module_dependencies. For more information: Debugging in WordPress. (This message was added in version 7.0.0.) in /var/www/vhosts/mgm-sp.217-154-231-6.plesk.page/httpdocs/wp-includes/functions.php online 6170

Tool-supported source code analyses powered by LLMs

October 24, 2024 |
Tags: SAST SCA

Talk at the W-JAX

Improving Application Security Analyses Using LLMs

About the talk

Even if current frameworks and libraries make it increasingly difficult for developers to (accidentally) introduce serious security problems into their applications, this topic generally does not lose its importance; in many companies, an opposite "expectation" can even be observed. With the emergence of powerful AI systems, equipped with sometimes impressive programming skills, the idea of improving, accelerating, and automating processes in the security environment through these systems logically arose.

In this session, we would like to present our approach to how classic, mature (closed and open source) scanning software (SAST, SCA…) can be combined with the capabilities of modern Large Language Models (LLM) in order to

  1. effectively get a handle on technologically induced large false-positive quantities
  2. focus attention on the really important findings from the start
  3. obtain support in understanding and evaluating findings
  4. without losing focus, and also being able to fall back on more (specialized) tools in combination

For empirical data, we manually and via LLM evaluated many thousands of findings and compared the results. Based on this, in addition to tips for your own implementation, the presentation will also highlight the (quality) differences when working with free and proprietary LLMs and discuss do's and don'ts for prompting.

Munich or Online, Wednesday, November 06, 2024 – 15:15 – 16:15

The Author

Mirko Richter

Mirko Richter is a Software Security Consultant, Source Code Analysis Specialist and Training Manager for basic training courses up to advanced coding and Secure SDLC training. He has been involved in software development, architecture and security since the mid-90s. He is a speaker at conferences and author of several technical articles.