Can Developers rely on LLMs for Secure IaC Development?
We investigated the capabilities of GPT-4o and Gemini 2.0 Flash for secure Infrastructure as Code (IaC) development. On the Stack Overflow dataset, which primarily contains small, simplified code snippets, the models detected at least 71% of security smells when prompted to analyze code from a security perspective (general prompt). With a guided prompt (adding clear, step-by-step instructions), this increased to 78%. In GitHub repositories, which contain complete, real-world project scripts, a general prompt was less effective, leaving more than half of the smells undetected. However, with the guided prompt, the models uncovered at least 67% of security smells and achieved promising F1 scores of 74% or higher. To assess how cautious LLMs are about security risks, we then asked the models to generate code for synthetic scenarios based on 89 insecure patterns identified from GitHub IaC scripts. For both models, only 7% of the generated scripts were secure. Adding an explicit instruction to generate secure code increased GPT-4o’s secure output rate to 17%, while Gemini 2.0 Flash changed little (8%); however, the number of warnings increased. This study highlights the need for further research to improve LLMs’ capabilities in assisting developers with secure IaC development.
Tue 17 MarDisplayed time zone: Athens change
16:00 - 17:30 | |||
16:00 20mTalk | Evaluating Large Language Models for Security Bug Report Prediction Workshops & Tutorials Farnaz Soltaniani Technische Universität Clausthal, Shoaib Razzaq Technical University of Clausthal, Mohammad Ghafari TU Clausthal | ||
16:20 20mTalk | Towards Project-Aware Actionability Detection for Coding Rule Violations Workshops & Tutorials Széles Csoma Lázár University of Szeged, Department of Software Engineering, Gergő Balogh Department of Software Engineering, University of Szeged | ||
16:40 10mTalk | Don’t Mind the Mesh: An Empirical Study of Istio Service Mesh Security in GitHub Workshops & Tutorials Kohsuke Sonoda Aalto university, Jose Luis Martin-Navarro Aalto University, Tuomas Aura Aalto University | ||
16:50 20mTalk | Can Developers rely on LLMs for Secure IaC Development? Workshops & Tutorials | ||
17:10 20mTalk | Persistent Human Feedback, LLMs, and Static Analyzers for Secure Code Generation and Vulnerability Detection Workshops & Tutorials | ||