LASAA Software

• Software
LASAA uses a large language model (LLM) to adjudicate static-analysis alerts. It also reports a justification along with every verdict.
Publisher

Software Engineering Institute

Abstract

LASAA uses a large language model (LLM) to adjudicate static-analysis alerts (i.e., to decide whether an alert indicates a real flaw). It also reports a justification along with every verdict.

LASAA is analyzer-agnostic: it ingests alerts in a small common format, and the code/conv directory provides converters from SARIF and a few other formats to the LASAA input format, as well as a template for prompting a frontier LLM to create a converter for other formats.

For each alert, LASAA builds a query containing the alert's fields (file, line, CWE, message), the source code of the function that contains the flagged line (located by running ctags over the project), and instructions telling the LLM to classify the alert as true, false, dependent, or uncertain. A verdict of dependent means that the alert would be fixed as a side effect of fixing an earlier line with the same flaw type; pointing a developer at the line that actually needs repair is generally more useful than flagging every downstream symptom. If the LLM needs the definition of a struct or macro that isn't in the supplied function, it can ask for it, and LASAA looks the symbol up (again via ctags), appends the definition to the prompt, and re-issues the query.