Large Language Model-enabled Vulnerability Investigation: A Review

Zhoujin Pan, Jia Liu, Yifan Dai, Wenjun Fan*

*Corresponding author for this work

Research output: Chapter in Book or Report/Conference proceedingConference Proceedingpeer-review

Abstract

In recent years, the integration of large language models (LLMs) into cybersecurity has demonstrated significant potential in enhancing vulnerability analysis. This paper provides a comprehensive review of current literature, focusing on the applications of LLMs in vulnerability discovery, exploitation, and validation. We examine various LLM-powered frameworks that have automated aspects of vulnerability analysis, reduced the time required for vulnerability identification, and improved the precision of vulnerability assessment. In addition, we discuss LLM-driven advancements in security vulnerability exploitation and validation, which facilitate more efficient and accurate mitigation. The contributions of this review include an extensive synthesis of existing studies, a proposed framework that highlights the role of LLMs across different stages of the vulnerability lifecycle, and an outline of future research directions in LLM-based cybersecurity. Our findings aim to guide researchers and practitioners in developing robust, scalable, and automated cybersecurity solutions powered by LLMs.

Original languageEnglish
Title of host publicationProceedings of the 3rd International Conference on Intelligent Computing and Next Generation Networks, ICNGN 2024
EditorsGyu Myoung Lee, Pavel Loskot, Qinmin Yang, Ruidan Su
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798331529222
DOIs
Publication statusPublished - 23 Nov 2024
Event3rd International Conference on Intelligent Computing and Next Generation Networks, ICNGN 2024 - Bangkok, Thailand
Duration: 23 Nov 202425 Nov 2024

Publication series

NameProceedings of the 3rd International Conference on Intelligent Computing and Next Generation Networks, ICNGN 2024

Conference

Conference3rd International Conference on Intelligent Computing and Next Generation Networks, ICNGN 2024
Country/TerritoryThailand
CityBangkok
Period23/11/2425/11/24

Keywords

  • Large Language Models
  • Vulnerability Discovery
  • Vulnerability Exploitation
  • Vulnerability Validation

Cite this