МОДЕЛЬ КЛАСИФІКАЦІЇ ВРАЗЛИВОСТЕЙ ТА МЕТОДИ ОЦІНЮВАННЯ ЗАХИЩЕНОСТІ МОДУЛІВ АВТЕНТИФІКАЦІЇ ТА АВТОРИЗАЦІЇ ВЕБЗАСТОСУНКІВ, ЗГЕНЕРОВАНИХ ВЕЛИКИМИ МОВНИМИ МОДЕЛЯМИ
Topicality. Large language models are widely used for program code generation, and empirical studies show that generated code systematically contains security vulnerabilities, with authentication and authorization modules being the most critical, since a defect in them compromises the whole application. Existing security classifications systematize vulnerabilities by weakness type or threat category and do not distinguish in which artifact of the generated code a defect arises, which limits their applicability. The subject of study in the article is the vulnerability classification model and the security assessment methods for authentication and authorization modules of web applications generated by large language models. The purpose of the article is to develop a classification model and assessment methods that form the theoretical basis for a future information technology for security assessment of generated code. The following results were obtained. A three-level classification model was formalized that distinguishes algorithmic, configuration and architectural levels of defect origin by the criterion of defect locus, with a structural scheme and an application example. The model was empirically validated on a curated corpus of 64 real vulnerabilities of the Spring ecosystem selected from 235 NVD records, where the configuration level covered 45% of vulnerabilities, the architectural level 28% and the algorithmic level 27%. A method for constructing a reference annotated dataset of generated modules based on consensus annotation and an integral risk assessment method with empirically calibrated level criticality weights were developed, and the interaction of the model and the methods was described by a data flow scheme per ISO 5807. Conclusion. The proposed model and methods form the theoretical basis for the further development of an information technology for security assessment of generated authentication modules.
Authors
- Володимир ЛЮБЧАК
- Віталій Савостян
Institutions
- Sumy State University (UA)
Publication Details
- Journal
- Scientific periodicals of Ukraine
- Published
- 2026-09-20
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00