Loading…
Friday May 30, 2025 10:30am - 11:15am CEST
Static Application Security Testing faces a significant challenge: while current tools excel at identifying potential vulnerabilities in isolation, they struggle to understand the holistic context of how data flows between client and server components. This limitation leads to an overwhelming number of false positives, particularly in detecting Cross-Site Scripting (XSS) vulnerabilities, where the interaction between client and server components is crucial for determining genuine security risks.

In this presentation, we'll demonstrate how Large Language Models (LLMs) can revolutionize vulnerability detection by understanding complete codebases across client and server components. Through a series of practical experiments, we'll show how LLMs can:

- Track data flow paths between different application layers
- Identify genuine vulnerabilities while reducing false positives through context-aware analysis
- Provide detailed reasoning about vulnerability exploitability
- Handle real-world applications at scale

We'll share our findings from extensive research using LLMs, including successes and limitations in analyzing cross-component vulnerabilities. Attendees will learn how this approach could transform security testing and what challenges must be addressed for production implementation.
Speakers
avatar for Jonathan Santilli

Jonathan Santilli

Software Engineer and AI practitioner, Snyk
Jonathan Santilli defines himself as a problem solver, or at least he tries. With over 20 years of experience working for various tech companies, Jonathan has played different roles, from Team lead developer to Product manager and, of course, problem solver. Jonathan is mainly interested... Read More →
avatar for Kirill Efimov

Kirill Efimov

Security R&D Team Lead, Mobb.ai
 As a seasoned security researcher, I've led teams at Snyk and now helm security research at Mobb. With a wealth of publications and speaking engagements, I've delved deep into the intricacies of cybersecurity, unraveling vulnerabilities and crafting solutions. From pioneering research... Read More →
Friday May 30, 2025 10:30am - 11:15am CEST
Room 115
Log in to leave feedback.

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link