Uma Abordagem Baseada em LLMs Open-Weight para Detecção e Classificação de Vulnerabilidades em Relatórios OSINT

Resumo


A pesquisa proposta tem como objetivo avaliar Modelos de Linguagem de Grande Porte (LLMs) na tarefa de análise de resultados obtidos a partir de testes de segurança em ambientes online. O foco central está relacionado à interpretação automatizada de relatórios de exploração gerados por ferramentas OSINT, utilizados para identificar vulnerabilidades e, assim, reduzir a dependência de análises manuais exaustivas. O estudo aborda a lacuna associada à complexidade da inspeção desses relatórios, cuja natureza altamente técnica dificulta a identificação, a classificação e a priorização de falhas de segurança. A proposta também é motivada por diretrizes recentes da OWASP Foundation, que destacam a necessidade do uso de LLMs confiáveis e seguros em aplicações críticas. Para a realização da classificação de vulnerabilidades nos ambientes online analisados, é proposta uma taxonomia de integração unificada composta por cinco categorias Macro, construída a partir da integração de metodologias consolidadas dos frameworks OWASP Top 10 e FIRST CVSS. Os resultados demonstraram que modelos como qwen3.6-35b-a3b e gemma-4-26b-a4b apresentaram os melhores desempenhos gerais na avaliação, destacando-se nas métricas de F1-Score, Recall e Precision. Além disso, modelos compactos como o gemma-4-e2b também obtiveram resultados competitivos, indicando que LLMs menores podem representar alternativas viáveis em cenários com restrições computacionais.

Referências

Anderson, R. (2010). Security engineering: a guide to building dependable distributed systems. John Wiley & Sons.

Barros, D. R., Cabral, L., Oliveira, J. V., Castro, F. M., Soares, L. L., Monteiro, J. M., Bento, J., and Rocha, L. S. (2024). Web xkaliburr: uma plataforma online para levantamento de informaçoes em pentest em aplicaçoes na internet. In Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 177–184. SBC.

Barros, D. R., Cabral, L., Oliveira, J. V., Castro, F. M., Soares, L. L., Monteiro, J. M., Bento, J., and Rocha, L. S. (2026). Web xkaliburr: An online platform for information gathering in pentest for internet applications. Journal of the Brazilian Computer Society, 32(1):700–714.

Bell, D. E. and LaPadula, L. J. (1973). Secure computer systems: Mathematical foundations. Technical Report MTR-2547, MITRE Corporation, Bedford, MA, USA.

Caminha, C., Silva, M. d. L. M., Chaves, I. C., Brito, F. T., Farias, V. A., and Machado, J. C. (2025). DiagHW: A compact LLM for hardware failure diagnosis via a novel knowledge distillation pipeline. In Brazilian Conference on Intelligent Systems, pages 393–407. Springer.

Carvalho, R., editor (2023). OSINT: do zero à investigação profissional. [s.n.], [S.l.]. eBook Kindle.

Chopra, S., Ahmad, H., Goel, D., and Szabo, C. (2026). Chatnvd: Advancing cybersecurity vulnerability assessment with large language models. IEEE Access.

Cuong Nguyen, H., Tariq, S., Baruwal Chhetri, M., and Quoc Vo, B. (2025). Towards effective identification of attack techniques in cyber threat intelligence reports using large language models. In Companion Proceedings of the ACM on Web Conference 2025, pages 942–946.

Dettmers, T. and Zettlemoyer, L. (2023). The case for 4-bit precision: k-bit inference scaling laws. In Proceedings of the 40th International Conference on Machine Learning, ICML’23. JMLR.org.

Fielding, R. T. and Reschke, J. (2014). Hypertext transfer protocol (HTTP/1.1): Semantics and content. Technical Report RFC 7231, Internet Engineering Task Force (IETF).

FIRST (2019). Common vulnerability scoring system (CVSS). Acesso em: 01 ago. 2026.

GitHub Security Lab (2025). GitHub security advisories (GHSA). Acesso em: 01 ago. 2026.

Hugging Face (2023). The tokenizer playground. Acesso em: 01 ago. 2026.

Kaplan, J., McCandlish, S., Henighan, T., Brown, T. B., Chess, B., Child, R., et al. (2020). Scaling laws for neural language models. arXiv preprint arXiv:2001.08361.

Lampson, B. W. (1974). Protection. ACM SIGOPS Operating Systems Review, 8(1):18–24.

Li, F., Jiang, J., Chen, D., and Xiong, Y. (2026). LLM-based vulnerability detection at project scale: An empirical study. arXiv preprint arXiv:2601.19239.

Lima, J. V., Pinheiro, V., and Caminha, C. (2026). Portuguese sentiment analysis with open-source LLMs: Models, prompts, and efficient deployment. In Proceedings of the 17th International Conference on Computational Processing of Portuguese (PROPOR 2026)-Vol. 1, pages 212–221.

MITRE Corporation (2025). Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE). [link]; [link]. Acesso em: 01 ago. 2026.

National Institute of Standards and Technology (1995). An introduction to computer security: The nist handbook. Technical Report Special Publication 800-12, NIST.

National Security Agency (2012). Defense in depth: A practical strategy for achieving information assurance in today’s highly networked environments. Technical report, National Security Agency (NSA).

OWASP Foundation (2025). OWASP top 10: 2025. Acesso em: 01 ago. 2026.

OWASP LLMs Risk (2025). OWASP Top 10 for Large Language Model Applications. Acesso em: 01 ago. 2026.

Roy, S., Sharmin, N., Acosta, J. C., Kiekintveld, C., and Laszka, A. (2022). Survey and taxonomy of adversarial reconnaissance techniques. ACM Computing Surveys, 55(6):1–38.

Theisen, C., Munaiah, N., Al-Zyoud, M., Carver, J. C., Meneely, A., and Williams, L. (2018). Attack surface definitions: A systematic literature review. Information and Software Technology, 104:94–103.

Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A. N., Kaiser, Ł., and Polosukhin, I. (2017). Attention is all you need. arXiv preprint arXiv:1706.03762.

World Economic Forum (2025). Global cybersecurity outlook 2025. Technical report, World Economic Forum. Acesso em: 01 ago. 2026.
Publicado
01/09/2026
BARROS, Daniel R.; LIMA, João P.; CAMINHA, Carlos; MONTEIRO, José M.; MACHADO, Javam. Uma Abordagem Baseada em LLMs Open-Weight para Detecção e Classificação de Vulnerabilidades em Relatórios OSINT. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1228-1243. DOI: https://doi.org/10.5753/sbseg.2026.26950.

Artigos mais lidos do(s) mesmo(s) autor(es)

1 2 > >>