Skip to content
Open access

Response-Level Identification of Cloud API Misconfigurations Using Large Language Models †

Aug 2026 · Pragmatic Cybersecurity · 0 citations · 33 references

TL;DR

This study investigates the use of Large Language Models to detect security misconfigurations directly from cloud API response data and evaluates each model’s capability to accurately determine the number of misconfigurations and generate clear, actionable security explanations.

Abstract

Application Programming Interfaces (APIs) are a set of rules that enable communication, data exchange, and automated interactions between applications and services. With the rapid advancement of cloud computing, APIs have evolved from simple data-access interfaces into critical components for managing, configuring, and orchestrating cloud resources. Most modern cloud platforms rely on RESTful APIs for provisioning cloud resources, applying configurations, and maintaining services. As a result, APIs misconfigurations have become a critical cloud security threat that can lead to sensitive data exposure, unauthorized access, or operational disruptions. Identifying these misconfigurations is challenging because traditional rule-based and static analysis methods often fail to capture complex, context-dependent configuration issues and system behaviors. In this study, we investigate the use of Large Language Models (LLMs) to detect security misconfigurations directly from cloud API response data. By treating API responses as representations of a system’s configuration state, we assess whether LLMs can effectively identify potential security risks. We evaluate five LLMs using a unified zero-shot prompting approach and compare their performance with and without Retrieval-Augmented Generation (RAG) to understand the impact of external knowledge on misconfiguration detection. The study not only focuses on each model’s ability to identify configuration components and detect misconfigurations, but also evaluates their capability to accurately determine the number of misconfigurations and generate clear, actionable security explanations. Our preliminary results show that Meta Llama Instruct combined with RAG achieves the reliable performance for identifying security misconfigurations in cloud API responses. This study provides new insights into the practicality of LLM-driven API cloud security analysis and paves the way for future research.

Read PDF

Similar papers

Open access Jul 2026

Can Language Models Generate Secure Terraform Code? A Security-Focused Benchmark Using Static Analysis

An empirical benchmark evaluating whether LLMs and SLMs can generate security-compliant AWS Terraform configurations suggests that prompt design is a critical factor, highlighting the need for a proper pipeline for developing and validating LLM-assisted secure IaC generation.

Francis Luis Santos Vargas, R. Mansilha, Diego Kreutz · 0 citations
Open access Jul 2026

Tool-Flow Taint Analysis for Data Exfiltration Defense in Large Language Model Agents

A comprehensive framework based on Tool-Flow Taint Analysis designed to mitigate data exfiltration in Large Language Model agents is introduced, providing a critical foundation for securing next-generation autonomous agents against sophisticated data-stealing attacks in enterprise environments.

Chun Tian, Hiu-Tung Li, Michelle Yu · 0 citations
Aug 2026

OMBench: Taming Data Management Requirements in Cloud-Native Applications

Function-as-a-Service, actor runtimes, and microservice frameworks have emerged as popular platforms for scalable cloud applications. However, understanding the data management trade-offs of these solutions, not to mention their programming abstractions and architectural design, can be cumbersome for practitioners and...

R. Laigner, Xikun Jiang, Boris Düdder et al. · 0 citations
Open access Aug 2026

Formal Specification of Trusted Execution Environment APIs and Model Checking of Trusted Applications

Trusted execution environments (TEEs) have emerged as a key technology in cybersecurity, providing isolated environments where sensitive computations can be executed securely. Trusted applications running in a TEE are developed using standardized APIs to which many TEE hardware platforms conform. However, formal execut...

Geunyeol Yu, Seunghyun Chae, Kyungmin Bae et al. · 0 citations
Open access Aug 2026

Cloud in the crosshairs: exposing vulnerabilities in web-based management interfaces of open-source IaaS platforms

This study conducts a large-scale empirical security analysis of the web-based management interfaces of ten widely used open-source Infrastructure-as-a-Service (IaaS) platforms, identifying 16 vulnerabilities spanning nine classes, including high-severity flaws that enable account takeover.

Alexandros Perrakis, Efstratios Chatzoglou, Vyron Kampourakis et al. · 0 citations
Open access Aug 2026

From Logging Configuration to Code Execution: A Systematization of Log4j 2 File-Write Primitives in HTTP-Exposed JMX

Java middleware may expose Java Management Extensions (JMX) through Jolokia’s Hypertext Transfer Protocol (HTTP) bridge. In affected ActiveMQ deployments, reachable Log4j 2 configuration managed beans (MBeans) become write capabilities and, with compatible triggers, enable remote code execution (RCE). We ask: in a spec...

A. Caciulescu, Matei Badanoiu, R. Rughinis et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.