Please use this identifier to cite or link to this item: http://repository.iiitd.edu.in/xmlui/handle/123456789/1922
Title: Identification and patch generation of security vulnerabilities in web applications using LLMs and static analysis tools
Authors: Kaushik, Manit
Gupta, Pranav
Jalote, Pankaj (Advisor)
Kumar, Dhruv (Advisor)
Keywords: Cybersecurity
Vulnerability
Detection
Static Analysis
Web Applications
Path Traversal
Issue Date: 27-Nov-2024
Publisher: IIIT-Delhi
Abstract: Web application vulnerabilities, such as Cross-Site Scripting (XSS) and Code Injections, pose significant security risks, often leading to data breaches and privacy issues. Traditional Static Application Security Testing (SAST) tools, while effective, are limited in their ability to un- derstand code semantics and context, leading to potential missed vulnerabilities. This project investigates the integration of Large Language Models (LLMs) with SAST tools to enhance vul- nerability detection in web applications, specifically in JavaScript and PHP environments. By appending SASTs findings to LLM prompts, we explore whether this combined approach can provide more accurate and comprehensive security analysis. The research demonstrates that leveraging LLMs alongside existing static analysis tools can improve the detection of common vulnerabilities and streamline the security auditing process.
URI: http://repository.iiitd.edu.in/xmlui/handle/123456789/1922
Appears in Collections:Year-2024

Files in This Item:
File Description SizeFormat 
2022277_BTP_Report - Manit Kaushik.pdf
  Restricted Access
417.72 kBAdobe PDFView/Open Request a copy
2022364_BTP_Report - Pranav Gupta.pdf
  Restricted Access
417.48 kBAdobe PDFView/Open Request a copy


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.