By analyzing the structural and contextual layers of code logs relative to the surrounding codebase, this paper proposes alternative strategies to treat logs as highly prioritized dimensional constructs and allows for the automated detection of latent vulnerabilities that currently evade standard security controls.
Abstract
Software code logs are the primary lens for software system observability, yet they represent a significant, overlooked security blind spot. While essential for intrusion detection and tracking anomalous behavior, code logs create a security paradox since the more data we record for monitoring, the greater the degree for data exfiltration. As modern software systems scale, manual verification becomes impractical, transforming code logs into an unmanaged liability where sensitive information such as PIIs, database credentials, API and private keys is inadvertently captured. Current tools rely on brittle pattern-matching and lexical signatures, rendering them context-blind. Because they focus exclusively on the surface-level syntax, such tools miss the core and intent that define actual security risks. In this paper, we argue that such paradigms are fundamentally insufficient for modern software complexity and propose a shift from standard pattern matching models to semantic security models. By analyzing the structural and contextual layers of code logs relative to the surrounding codebase, we propose alternative strategies to treat logs as highly prioritized dimensional constructs. This approach allows for the automated detection of latent vulnerabilities that currently evade standard security controls.
Security vulnerabilities in software systems remain a major concern in modern computing,
especially as applications grow in complexity and are increasingly integrated into critical
infrastructures. Traditional vulnerability detection methods such as static code analysis tools and
manual inspection face limitations i...
D. Sako· International Journal of Com...· 0 citations
A defensive capability analysis for JavaScript libraries that soundly reports every exercised capability for code executed under a lightweight protected runtime, complementing the static analysis with a lightweight runtime enforcement mechanism that blocks those patterns.
A defensive capability analysis for JavaScript libraries that soundly reports every exercised capability for code executed under a lightweight protected runtime, complementing the static analysis with a lightweight runtime enforcement mechanism that blocks those patterns.
D-RELLM is presented, a defensive reverse-engineering framework for black-box security assessment of deployed LLM applications that treats the deployed application as a socio-technical system whose risk depends on instruction hierarchy, retrieval trust, authorization, tool agency, output handling, monitoring, and opera...
Bhavesh B. Prajapati, Bhavya Shah· International journal of com...· 0 citations
Experimental results show that AST-based structural features substantially improve recall compared with the TF-IDF baseline, while the combined TF-IDF and AST representation maintains this improved performance.
Vani Pasupula, M. N. V. Manikanth, Nagaraju Vassey· International Journal of Cre...· 0 citations
The adoption of Large Language Models (LLMs) is changing how code is written, but the security implications of using LLMs to generate complete web API backends remain insufficiently characterized. Prior studies have assessed the security of LLM-generated code by detecting vulnerabilities in isolated code snippets; howe...
Abdul Ali Khan, S. Rauti, T. Mäkilä· IEEE Access· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.