Banca de QUALIFICAÇÃO: ANDRE VICTOR RIBEIRO DE CARVALHO

Uma banca de QUALIFICAÇÃO de MESTRADO foi cadastrada pelo programa.
STUDENT : ANDRE VICTOR RIBEIRO DE CARVALHO
DATE: 12/03/2026
TIME: 08:30
LOCAL: Google Meet
TITLE:

LLMs as a “Virtual Security Consultant”: Supporting the Generation of Security Requirements, Evil User Stories, and Test Cases for Teams with Low Security Proficiency

 


KEY WORDS:

Security Engineering; Software Security; Threat Modeling; LLM; STRIDE; Automation; Security Tests; Agile; DevSecOps.

 


PAGES: 50
BIG AREA: Ciências Exatas e da Terra
AREA: Ciência da Computação
SUBÁREA: Metodologia e Técnicas da Computação
SPECIALTY: Engenharia de Software
SUMMARY:

This work investigates the use of Large Language Models (LLMs) as security assistants to
support software development teams with loy security proficiency throughout the software
development lifecycle. It proposes an artifact composed of microservices that assist in the
identification and structurinf of threats, as well as in the elicitation of security requirements,
business rules, and user stories provided by the developers or QA members. The approach
is based on Gary McGraw’s Touchpoints, focusing specifically on automating the Security
Requirements and Architectural Risk Analysis points, using the STRIDE methodology as
an analysis engine to identify threats. It uses a structured process that integrates LLMs
as a mechanism to support reasoning and decision-making, and not as a substitute for
human experts. The goal is to reduce cognitive effort, support security reasoning, and
improve security awareness and maturity in teams with limited expertise. The research
follows the Design Science Research methodology, encompassing the design, development,
demonstration, and evaluation of the artifact through a controlled study conducted in
the context of systems maintained by STI/UFRN. The expected results aim to assess to
what extent an LLM-based artifact improves quantity, diversity, and quality of identified
threats and security requirements when compared to predominantly manual approaches,
positioning LLM as “virtual security consultant” for low-proficiency teams

 


COMMITTEE MEMBERS:
Presidente - 2274774 - EIJI ADACHI MEDEIROS BARBOSA
Interno - 1874895 - RAMON DOS REIS FONTES
Interno - 1644456 - UIRA KULESZA
Notícia cadastrada em: 26/02/2026 10:39
SIGAA | Superintendência de Tecnologia da Informação - (84) 3342 2210 | Copyright © 2006-2026 - UFRN - sigaa08-producao.info.ufrn.br.sigaa08-producao