Abstract: Context-aware authorization verification for Application Programming Interface (API) endpoints using large language models (LLMs) is disclosed herein. A system receives source code including an implementation file and at least one service definition file. The service definition file(s) include metadata and a service interface definition. The system determines that the source code implements an API handler by determining that the implementation file includes a reference to the service interface definition. The metadata is used to determine that the API handler is associated with a public endpoint. An LLM is used to determine that the source code lacks an authorization check by determining absence of a direct call to an authorization function, and determining absence of an indirect authorization check. An alert is generated indicating that the source code implements an API handler associated with a public endpoint and that the source code lacks an authorization check.
Abstract: AI-powered security analysis platforms with modular scanning architectures are disclosed herein. A system scans a codebase stored in a software repository to generate a scan snapshot. The system analyzes, using one or more code analyzers, the scan snapshot across corresponding security domains, where each code analyzer is associated with a different security domain and type of security vulnerability. The system identifies, using one or more large language models, a security vulnerability based on context of the software repository. The system determines, using a call graph, components through which the security vulnerability propagates. The system stores a timestamped record and compares it to a prior record. The system generates a corrective action and sends a report indicating the security vulnerability to the computer device.
Abstract: The disclosed technology pertains to the detection of security vulnerabilities in proposed changes to a codebase. Upon receiving a proposed change, the system determines a code context based on the data and metadata of the changed files. The proposed change is then divided into code segments processed by multiple code analyzers in parallel, each focusing on specific security concerns. The system can utilize large language models (LLMs) to enhance the analysis, providing more accurate and comprehensive detection of vulnerabilities. Furthermore, the system can present to a user a user interface comprising security information and answers to one or more natural-language security questions.