Web applications are an easy target because they are publicly exposed, and their input fields are easy targets for attacks such as SQL injection. Svensson et al. [1] interviewed industry practitioners and derived guidelines to help software engineers develop secure web applications. As LLM is increasingly integrated into the workflow of developers, we now want to investigate whether a combination of these security guidelines with LLMs can be used to address vulnerabilities in web applications.
[1] Svensson, Klara, et al. "Guidelines for Supporting Software Engineers in Developing Secure Web Applications." International Conference on Product-Focused Software Process Improvement. Cham: Springer Nature Switzerland, 2024.