What is it about?
Security testing tools help identify weaknesses in web applications, but their alerts can be lengthy, technical, and difficult to understand. This study investigates whether AI language models can turn these alerts into clearer, shorter summaries. We used five language models to summarize two security alerts, one from Burp Suite and one from ZAP, and asked 48 software practitioners to evaluate them alongside the original alerts. Participants generally rated the summaries as clearer and reported that they were easier to understand. Around 81% preferred receiving security information in summarized form. The findings suggest that AI-generated summaries could make security information more accessible, while retaining access to the original technical details.
Featured Image
Photo by FlyD on Unsplash
Why is it important?
Identifying a security weakness is only useful if the people responsible for addressing it understand the warning. Lengthy or confusing alerts can make this difficult, particularly for people without specialist security expertise. This research provides preliminary evidence that AI-generated summaries can improve how security information is communicated. It also offers guidance for designing reports that give readers a concise overview while preserving detailed information when needed. Such an approach could help developers and other stakeholders engage more effectively with security findings.
Perspectives
In this study, we focused on the people who need to interpret security alerts, rather than on vulnerability detection alone. Our findings suggest that presenting security information clearly deserves attention alongside the technical capabilities of security tools. We see concise summaries as a complement to detailed reports, not a replacement for them. Further research should examine summary correctness and whether these benefits translate into better decisions and faster responses in real development settings.
Arpit Thool
Virginia Polytechnic Institute and State University
Read the Original
This page is a summary of: Harnessing the Power of LLMs: LLM Summarization for Human-Centric DAST Reports, September 2024, Institute of Electrical & Electronics Engineers (IEEE),
DOI: 10.1109/vl/hcc60511.2024.00014.
You can read the full text:
Contributors
The following have contributed to this page







