LLMs to Adjudicate Static Analysis Alerts (LASAA)
• Fact Sheet
This fact sheet describes the LASAA project which uses large language models (LLMs) to adjudicate static analysis alerts. This enables more complete alert adjudication, reducing unknown risk and improving software security.
Publisher
Software Engineering Institute
Abstract
Software vulnerabilities pose a significant risk to critical systems. Static analysis is a standard method for evaluating source code, but it requires significant manual effort and is time consuming and expensive. Large language models (LLMs) are a new technology with promising initial results for automation of alert adjudication and rationales. This has the potential to enable more secure code, support mission effectiveness, and reduce support costs.