UPDATED 06:00 EDT / JULY 19 2023

SECURITY

Endor Labs report warns AI and LLMs struggle to classify malware risk

A new report from dependency lifecycle management startup Endor Labs Inc. has warned that artificial intelligence and large language models are unable to classify malware risk in most cases accurately.

The “State of Dependency Management 2023” report, compiled by Endor’s Station 9 research team, explores emerging trends that software organizations need to consider as part of their security strategy and risks associated with using existing open-source software in application development. The rise of services such as OpenAI LP’s ChatGPT application programming interface comes in for particular attention, with the report finding that almost half of all applications make no calls to security-sensitive APIs in their code base.

Key findings in the report include that existing LLM technologies can’t be used to assist reliably in malware detection and scale. Instead, the researchers found that LLMs only accurately classify malware risk in barely 5% of all cases.

While it’s noted that AI and LLM models do have value in manual workflows, they will likely never be fully reliable in autonomous workflows as they can’t be trained to recognize novel approaches, such as those derived through LLM recommendations.

The report found that 45% of applications were found to have no calls to security-sensitive APIs in their code base, but the number drops to 5% when dependencies are included. The result indicate that organizations routinely underestimate risk when they don’t analyze their use of such APIs through open-source dependencies.

Java gets a look-in as well. The report finds that even though 71% of typical Java application code is from open-source components, applications use only 12% of imported code. Vulnerabilities in unused code are rarely exploitable, but organizations can eliminate or deprioritize 60% of remediation work with reliable insights into which code is reachable throughout an application.

ChatGPT’s API is already seeing use in 900 Node Package Manager and Python Package Index packages across various problem domains. Three-quarters of these were found to be completely new packages. The report noted that pairing rapid growth with a lack of historical data potentially opens the door for attacks.

“The fact that there’s been such a rapid expansion of new technologies related to artificial intelligence and that these capabilities are being integrated into so many other applications is truly remarkable — but it’s equally important to monitor the risks they bring with them,” Henrik Plate, lead security researcher at Endor Labs Station9, said ahead of the report’s release. “These advances can cause considerable harm if the packages selected introduce malware and other risks to the software supply chain.”

Image: Bing Image Creator

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.