Aug 2026· Pragmatic Cybersecurity· 0 citations· 33 references
TL;DR
This study investigates the use of Large Language Models to detect security misconfigurations directly from cloud API response data and evaluates each model’s capability to accurately determine the number of misconfigurations and generate clear, actionable security explanations.
Abstract
Application Programming Interfaces (APIs) are a set of rules that enable communication, data exchange, and automated interactions between applications and services. With the rapid advancement of cloud computing, APIs have evolved from simple data-access interfaces into critical components for managing, configuring, and orchestrating cloud resources. Most modern cloud platforms rely on RESTful APIs for provisioning cloud resources, applying configurations, and maintaining services. As a result, APIs misconfigurations have become a critical cloud security threat that can lead to sensitive data exposure, unauthorized access, or operational disruptions. Identifying these misconfigurations is challenging because traditional rule-based and static analysis methods often fail to capture complex, context-dependent configuration issues and system behaviors. In this study, we investigate the use of Large Language Models (LLMs) to detect security misconfigurations directly from cloud API response data. By treating API responses as representations of a system’s configuration state, we assess whether LLMs can effectively identify potential security risks. We evaluate five LLMs using a unified zero-shot prompting approach and compare their performance with and without Retrieval-Augmented Generation (RAG) to understand the impact of external knowledge on misconfiguration detection. The study not only focuses on each model’s ability to identify configuration components and detect misconfigurations, but also evaluates their capability to accurately determine the number of misconfigurations and generate clear, actionable security explanations. Our preliminary results show that Meta Llama Instruct combined with RAG achieves the reliable performance for identifying security misconfigurations in cloud API responses. This study provides new insights into the practicality of LLM-driven API cloud security analysis and paves the way for future research.
An empirical benchmark evaluating whether LLMs and SLMs can generate security-compliant AWS Terraform configurations suggests that prompt design is a critical factor, highlighting the need for a proper pipeline for developing and validating LLM-assisted secure IaC generation.
Francis Luis Santos Vargas, R. Mansilha, Diego Kreutz· Anais do I Simpósio de Infra...· 0 citations
A comprehensive framework based on Tool-Flow Taint Analysis designed to mitigate data exfiltration in Large Language Model agents is introduced, providing a critical foundation for securing next-generation autonomous agents against sophisticated data-stealing attacks in enterprise environments.
Chun Tian, Hiu-Tung Li, Michelle Yu· Journal of innovative resear...· 0 citations
Function-as-a-Service, actor runtimes, and microservice frameworks have emerged as popular platforms for scalable cloud applications. However, understanding the data management trade-offs of these solutions, not to mention their programming abstractions and architectural design, can be cumbersome for practitioners and...
R. Laigner, Xikun Jiang, Boris Düdder et al.· Proceedings of the VLDB Endo...· 0 citations
Trusted execution environments (TEEs) have emerged as a key technology in cybersecurity, providing isolated environments where sensitive computations can be executed securely. Trusted applications running in a TEE are developed using standardized APIs to which many TEE hardware platforms conform. However, formal execut...
Geunyeol Yu, Seunghyun Chae, Kyungmin Bae et al.· Formal Aspects of Computing· 0 citations
This study conducts a large-scale empirical security analysis of the web-based management interfaces of ten widely used open-source Infrastructure-as-a-Service (IaaS) platforms, identifying 16 vulnerabilities spanning nine classes, including high-severity flaws that enable account takeover.
Alexandros Perrakis, Efstratios Chatzoglou, Vyron Kampourakis et al.· International Journal of Inf...· 0 citations
Java middleware may expose Java Management Extensions (JMX) through Jolokia’s Hypertext Transfer Protocol (HTTP) bridge. In affected ActiveMQ deployments, reachable Log4j 2 configuration managed beans (MBeans) become write capabilities and, with compatible triggers, enable remote code execution (RCE). We ask: in a spec...
A. Caciulescu, Matei Badanoiu, R. Rughinis et al.· Computers· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.