МОДЕЛЬ КЛАСИФІКАЦІЇ ВРАЗЛИВОСТЕЙ ТА МЕТОДИ ОЦІНЮВАННЯ ЗАХИЩЕНОСТІ МОДУЛІВ АВТЕНТИФІКАЦІЇ ТА АВТОРИЗАЦІЇ ВЕБЗАСТОСУНКІВ, ЗГЕНЕРОВАНИХ ВЕЛИКИМИ МОВНИМИ МОДЕЛЯМИ

Topicality. Large language models are widely used for program code generation, and empirical studies show that generated code systematically contains security vulnerabilities, with authentication and authorization modules being the most critical, since a defect in them compromises the whole application. Existing security classifications systematize vulnerabilities by weakness type or threat category and do not distinguish in which artifact of the generated code a defect arises, which limits their applicability. The subject of study in the article is the vulnerability classification model and the security assessment methods for authentication and authorization modules of web applications generated by large language models. The purpose of the article is to develop a classification model and assessment methods that form the theoretical basis for a future information technology for security assessment of generated code. The following results were obtained. A three-level classification model was formalized that distinguishes algorithmic, configuration and architectural levels of defect origin by the criterion of defect locus, with a structural scheme and an application example. The model was empirically validated on a curated corpus of 64 real vulnerabilities of the Spring ecosystem selected from 235 NVD records, where the configuration level covered 45% of vulnerabilities, the architectural level 28% and the algorithmic level 27%. A method for constructing a reference annotated dataset of generated modules based on consensus annotation and an integral risk assessment method with empirically calibrated level criticality weights were developed, and the interaction of the model and the methods was described by a data flow scheme per ISO 5807. Conclusion. The proposed model and methods form the theoretical basis for the further development of an information technology for security assessment of generated authentication modules.

Authors

Institutions

Publication Details

Journal
Scientific periodicals of Ukraine
Published
2026-09-20
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

МОДЕЛЬ КЛАСИФІКАЦІЇ ВРАЗЛИВОСТЕЙ ТА МЕТОДИ ОЦІНЮВАННЯ ЗАХИЩЕНОСТІ МОДУЛІВ АВТЕНТИФІКАЦІЇ ТА АВТОРИЗАЦІЇ ВЕБЗАСТОСУНКІВ, ЗГЕНЕРОВАНИХ ВЕЛИКИМИ МОВНИМИ МОДЕЛЯМИ

Володимир ЛЮБЧАК, Віталій Савостян
Scientific periodicals of Ukraine
Information and Cyber Security
article

МОДЕЛЬ КЛАСИФІКАЦІЇ ВРАЗЛИВОСТЕЙ ТА МЕТОДИ ОЦІНЮВАННЯ ЗАХИЩЕНОСТІ МОДУЛІВ АВТЕНТИФІКАЦІЇ ТА АВТОРИЗАЦІЇ ВЕБЗАСТОСУНКІВ, ЗГЕНЕРОВАНИХ ВЕЛИКИМИ МОВНИМИ МОДЕЛЯМИ

Володимир ЛЮБЧАК, Віталій Савостян
article en

Abstract

Topicality. Large language models are widely used for program code generation, and empirical studies show that generated code systematically contains security vulnerabilities, with authentication and authorization modules being the most critical, since a defect in them compromises the whole application. Existing security classifications systematize vulnerabilities by weakness type or threat category and do not distinguish in which artifact of the generated code a defect arises, which limits their applicability. The subject of study in the article is the vulnerability classification model and the security assessment methods for authentication and authorization modules of web applications generated by large language models. The purpose of the article is to develop a classification model and assessment methods that form the theoretical basis for a future information technology for security assessment of generated code. The following results were obtained. A three-level classification model was formalized that distinguishes algorithmic, configuration and architectural levels of defect origin by the criterion of defect locus, with a structural scheme and an application example. The model was empirically validated on a curated corpus of 64 real vulnerabilities of the Spring ecosystem selected from 235 NVD records, where the configuration level covered 45% of vulnerabilities, the architectural level 28% and the algorithmic level 27%. A method for constructing a reference annotated dataset of generated modules based on consensus annotation and an integral risk assessment method with empirically calibrated level criticality weights were developed, and the interaction of the model and the methods was described by a data flow scheme per ISO 5807. Conclusion. The proposed model and methods form the theoretical basis for the further development of an information technology for security assessment of generated authentication modules.

Scientific periodicals of Ukraine
Sumy State University (UA)
Openalex Percentile: Top 4%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.