|
|
using chatgpt as a static application security testing tool
|
|
|
|
|
نویسنده
|
bakhshandeh atieh ,keramatfar abdalsamad ,norouzi amir ,chekidehkhoun mohammad mahdi
|
منبع
|
بيستمين كنفرانس بين المللي انجمن رمز ايران در امنيت اطلاعات و رمزشناسي - 1402 - دوره : 20 - بیستمین کنفرانس بین المللی انجمن رمز ایران در امنیت اطلاعات و رمزشناسی - کد همایش: 02230-87746 - صفحه:0 -0
|
چکیده
|
In recent years, artificial intelligence has had a conspicuous growth in almost every aspect of life. one of the most applicable areas is security code review, in which a lot of ai-based tools and approaches have been proposed. recently,chatgpt has caught a huge amount of attention with its remarkable performance in following instructions and providing a detailed response. regarding the similarities between natural language and code, in this paper, we study the feasibility of using chatgpt for vulnerability detection in python source code. toward this goal, we feed an appropriate prompt along with vulnerable data to chatgpt and compare its results on two datasets with the results of three widely used static application security testing tools (bandit, semgrep and sonarqube). we implement different kinds of experiments with chatgpt and the results indicate that chatgpt reduces the false positive andfalse negative rates and has the potential to be used for python source code vulnerability detection.
|
کلیدواژه
|
artificial intelligence-based code review#chatgpt model# common weakness enumeration# static application security testing#vulnerability detection#
|
آدرس
|
, iran, , iran, , iran, , iran
|
پست الکترونیکی
|
chekidekhoon@rcdat.ir
|
|
|
|
|
|
|
|
|
|
|
|
Authors
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|