LLMs as a “Virtual Security Copilot”: Supporting the Generation of Security Requirements, Evil User Stories, and Test Cases
Security Engineering; Software Security; Threat Modeling; LLM; STRIDE; Automation; Security Tests; Agile; DevSecOps
This work investigates the use of Large Language Models (LLMs) as virtual security copilots to support software development teams, QA professionals, and security practitioners throughout the software development lifecycle. It proposes an artifact composed of three chained microservices that support threat identification, security requirements elicitation, generation of evil user stories, and construction of conceptual security test scenarios from functional requirements, business rules, and user stories. The approach is grounded in Gary McGraw’s Software Security Touchpoints and uses STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege) as the structuring mechanism for threat modeling, positioning AI as support for reasoning and decision-making rather than as a replacement for human experts. The research follows the Design Science Research methodology, covering the design, development, demonstration, and evaluation of the artifact in the context of systems maintained by STI/UFRN. The evaluation combines a pilot application with QA professionals and a comparison between generated scenarios and consolidated vulnerability bases derived from penetration testing reports for the SIGAA and SIGEventos systems. The results indicate potential for cognitive support and for generating scenarios semantically related to real vulnerabilities, although with limited coverage and continued dependence on human validation. Thus, the dissertation positions LLMs as complementary mechanisms to scale, trace, and organize secure development practices in teams with limited security expertise