Jul 2026· International Conference on Ubiquitous and Future Networks· pp. 726-731· 0 citations· 17 references
Abstract
Security review of Infrastructure-as-Code (IaC) in enterprise cloud platforms requires understanding not only configuration diffs, but also how those changes interact with existing architecture and risk controls. In financial-engineering environments, IaC changes can directly affect data perimeter boundaries, model-serving paths, entitlement controls, and operational resilience. Current tools often analyze pull requests in isolation, missing security implications that emerge only from cross-resource context. This paper presents SecReviewAgent, an LLM-powered IaC security review system that maintains persistent architecture memory across pull request reviews. On first encounter with a repository, SecReviewAgent scans IaC files to build an architecture model, persists that model to object storage, and reuses it in subsequent reviews to interpret changes in context. We evaluate the system on 847 pull requests from 23 repositories spanning financial services, healthcare, e-commerce, and developer tooling. Results show a $2.4 \times$ improvement in context-dependent issue detection recall over a no-context LLM baseline, precision of 0.89, F1 of 0.83, and a 73% latency reduction on warm reviews by avoiding full repository rescans. A controlled user study with 42 practitioners indicates reduced median review time and improved finding accuracy. The paper contributes a persistent-memory design for LLM-based code review, algorithms for repository context construction and incremental update, and an empirical evaluation of context-aware IaC security review in realistic settings.
This study investigates the use of Large Language Models to detect security misconfigurations directly from cloud API response data and evaluates each model’s capability to accurately determine the number of misconfigurations and generate clear, actionable security explanations.
A. Krishna, Farzana Zahid· Pragmatic Cybersecurity· 0 citations
The results show that TraceGrant provides a unified governance layer that connects trusted user intent, runtime evidence, concrete tool execution, and verified task completion.
Bohao Liao, Jing-Chao Wang, Qi-Peng Song et al.· 0 citations
This evidence-centered structured survey synthesizes representative work available through May 31, 2026 across software engineering tasks, software security tasks, adaptation mechanisms, artifact granularity, and evaluation design and introduces an assurance framework that separates functional correctness, security, op...
Wei Lin, Tao Zhou, Zhaofei Xie et al.· 0 citations
AEGIS is presented, a policy enforcement component that enables administrators to define fine-grained safeguards against resource abuse across heterogeneous MCP tools and modalities and detects and mitigates abusive behaviors while preserving the flexibility of MCP-based agent ecosystems.
The results show that plan-first execution combined with label-preserving persistence can substantially strengthen persistent LLM agents, while revealing an important security-utility tradeoff introduced by strict integrity enforcement.
Ensuring robust security without compromising performance remains a persistent challenge in microservices architectures. Reactive, non-blocking frameworks are often recommended for high-concurrency workloads, yet the introduction of virtual threads in the Java platform (Project Loom) raises a question of whether reacti...
Kamal Azizov· International Symposium on S...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.