Formal Trust and Threat Modeling Using Large Language Models

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Security modeling, including trust and threat modeling, is a critical process of modern system design and analysis. However, the models are often described in imprecise natural languages, and their inconsistent interpretations and implementations can lead to cybersecurity incidents. In this work, we first introduce an extended Linear Temporal Logic to model the multi-faceted security model of a system to capture its temporal and spatial properties and security guarantees. Then, we manually write 10 security model formulas of real-world systems and attack scenarios. Finally, we fine-Tune a large language model with our manually written models. We evaluate the fine-Tuned model with another set of 9 recent system designs to validate its capability in accurately capturing their security models. Our work provides a formal approach to system security modeling, and it demonstrates the benefits of using large language models in capturing the models of real-world systems.

Original languageEnglish (US)
Title of host publicationProceeding - 2024 Annual Computer Security Applications Conference Workshops, ACSACW 2024
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages232-239
Number of pages8
ISBN (Electronic)9798331532819
DOIs
StatePublished - 2024
Externally publishedYes
Event40th Annual Computer Security Applications Conference Workshops, ACSACW 2024 - Honolulu, United States
Duration: Dec 9 2024Dec 13 2024

Publication series

NameProceeding - 2024 Annual Computer Security Applications Conference Workshops, ACSACW 2024

Conference

Conference40th Annual Computer Security Applications Conference Workshops, ACSACW 2024
Country/TerritoryUnited States
CityHonolulu
Period12/9/2412/13/24

All Science Journal Classification (ASJC) codes

  • Artificial Intelligence
  • Computer Networks and Communications
  • Information Systems
  • Information Systems and Management
  • Safety, Risk, Reliability and Quality

Keywords

  • Formal Methods
  • Large Language Models
  • Threat Modeling
  • Trust Modeling

Fingerprint

Dive into the research topics of 'Formal Trust and Threat Modeling Using Large Language Models'. Together they form a unique fingerprint.

Cite this