• Mi Re-Unir
    Búsqueda Avanzada
    JavaScript is disabled for your browser. Some features of this site may not work without it.
    Ver ítem 
    •   Inicio
    • RESULTADOS DE INVESTIGACIÓN
    • Otras Publicaciones: artículos, libros...
    • Ver ítem
    •   Inicio
    • RESULTADOS DE INVESTIGACIÓN
    • Otras Publicaciones: artículos, libros...
    • Ver ítem

    Integration of Large Language Models (LLMs) and Static Analysis for Improving the Efficacy of Security Vulnerability Detection in Source Code.

    Autor: 
    Santas Ciavatta, José Armando
    ;
    Bermejo Higuera, Juan Ramón
    ;
    Bermejo Higuera, Javier
    ;
    Sicilia Moltalvo, Juan Antonio
    ;
    Sureda Riera, Tomás
    ;
    Pérez Melero, Jesús
    Fecha: 
    2026
    Palabra clave: 
    AI + SAST; secure code; LLM; benchmarking LLM; vulnerability detection
    Revista / editorial: 
    Tech Science Press, Computers, Materials & Continua
    Citación: 
    Santas Ciavatta, J.A., Bermejo Higuera, J.R., Bermejo Higuera, J., Montalvo, J.A.S., Riera, T.S. et al. (2026). Integration of Large Language Models (LLMs) and Static Analysis for Improving the Efficacy of Security Vulnerability Detection in Source Code. Computers, Materials & Continua, 86(3), 11. https://doi.org/10.32604/cmc.2025.074566
    Tipo de Ítem: 
    article
    URI: 
    https://reunir.unir.net/handle/123456789/19503
    DOI: 
    https://doi.org/10.32604/cmc.2025.074566
    Dirección web: 
    https://www.techscience.com/cmc/v86n3/65509
    Open Access
    Resumen:
    As artificial Intelligence (AI) continues to expand exponentially, particularly with the emergence of generative pre-trained transformers (GPT) based on a transformer’s architecture, which has revolutionized data processing and enabled significant improvements in various applications. This document seeks to investigate the security vulnerabilities detection in the source code using a range of large language models (LLM). Our primary objective is to evaluate the effectiveness of Static Application Security Testing (SAST) by applying various techniques such as prompt persona, structure outputs and zero-shot. To the selection of the LLMs (CodeLlama 7B, DeepSeek coder 7B, Gemini 1.5 Flash, Gemini 2.0 Flash, Mistral 7b Instruct, Phi 3 8b Mini 128K instruct, Qwen 2.5 coder, StartCoder 2 7B) with comparison and combination with Find Security Bugs. The evaluation method will involve using a selected dataset containing vulnerabilities, and the results to provide insights for different scenarios according to the software criticality (Business critical, non-critical, minimum effort, best effort) In detail, the main objectives of this study are to investigate if large language models outperform or exceed the capabilities of traditional static analysis tools, if the combining LLMs with Static Application Security Testing (SAST) tools lead to an improvement and the possibility that local machine learning models on a normal computer produce reliable results. Summarizing the most important conclusions of the research, it can be said that while it is true that the results have improved depending on the size of the LLM for business-critical software, the best results have been obtained by SAST analysis. This differs in “Non-Critical,” “Best Effort,” and “Minimum Effort” scenarios, where the combination of LLM (Gemini) + SAST has obtained better results.
    Mostrar el registro completo del ítem
    Ficheros en el ítem
    icon
    Nombre: TSP_CMC_74566 (1).pdf
    Tamaño: 16.94Mb
    Formato: application/pdf
    Ver/Abrir
    Este ítem aparece en la(s) siguiente(s) colección(es)
    • Otras Publicaciones: artículos, libros...

    Estadísticas de uso

    Año
    2012
    2013
    2014
    2015
    2016
    2017
    2018
    2019
    2020
    2021
    2022
    2023
    2024
    2025
    2026
    Vistas
    0
    0
    0
    0
    0
    0
    0
    0
    0
    0
    0
    0
    0
    0
    7
    Descargas
    0
    0
    0
    0
    0
    0
    0
    0
    0
    0
    0
    0
    0
    0
    4

    Ítems relacionados

    Mostrando ítems relacionados por Título, autor o materia.

    • Benchmarking Android Malware Analysis Tools 

      Bermejo Higuera, Javier; Morales Moreno, Javier; Bermejo Higuera, Juan Ramón; Sicilia Moltalvo, Juan Antonio; Barreiro Martillo, Gustavo Javier; Sureda Riera, Tomas Miguel (Electronics, 2024)
      Today, malware is arguably one of the biggest challenges organisations face from a cybersecurity standpoint, regardless of the types of devices used in the organisation. One of the most malware-attacked mobile operating ...
    • Prevention and fighting against web attacks through anomaly detection technology. A systematic review 

      Sureda Riera, Tomás; Bermejo Higuera, Juan Ramón ; Bermejo-Higuera, Javier ; Martínez Herraiz, José-Javier; Sicilia, Juan Antonio (Sustainability (Switzerland), 01/06/2020)
      Numerous techniques have been developed in order to prevent attacks on web servers. Anomaly detection techniques are based on models of normal user and application behavior, interpreting deviations from the established ...
    • A new multi-label dataset for Web attacks CAPEC classification using machine learning techniques 

      Sureda Riera, Tomás; Bermejo Higuera, Juan Ramón ; Bermejo-Higuera, Javier ; Martínez Herraiz, José-Javier; Sicilia, Juan Antonio (Computers & Security, 2022)
      Context: There are many datasets for training and evaluating models to detect web attacks, labeling each request as normal or attack. Web attack protection tools must provide additional information on the type of attack ...

    Mi cuenta

    AccederRegistrar

    ¿necesitas ayuda?

    Manual de UsuarioContacto: reunir@unir.net

    Listar

    todo Re-UnirComunidades y coleccionesPor fecha de publicaciónAutoresTítulosPalabras claveTipo documentoTipo de accesoEsta colecciónPor fecha de publicaciónAutoresTítulosPalabras claveTipo documentoTipo de acceso






    Aviso Legal Política de Privacidad Política de Cookies Cláusulas legales RGPD
    © UNIR - Universidad Internacional de La Rioja
     
    Aviso Legal Política de Privacidad Política de Cookies Cláusulas legales RGPD
    © UNIR - Universidad Internacional de La Rioja