Barriers to Using Static Application Security Testing (SAST) Tools: A Literature Review
本文通过文献综述探讨了开发人员使用静态应用程序安全测试(SAST)工具时遇到的障碍,指出需从技术和人文两方面入手解决以促进其广泛应用。
本文通过文献综述探讨了开发人员使用静态应用程序安全测试(SAST)工具时遇到的障碍,指出需从技术和人文两方面入手解决以促进其广泛应用。
本文针对软件开发过程中早期识别和修复安全漏洞的问题,提出了一种将静态应用安全测试工具输出集成到CI/CD流水线及问题跟踪软件中的自动化方法。
本文提出了一种基于物理信息的基函数(GDC),用于非线性响应曲线分解,解决了传统方法在解释性和灵活性之间的权衡问题。
This study addresses the high entry barriers and lack of intelligent assistance in MOOSE multiphysics simulations by proposing MOOSEnger-GPT-5.2, a localized AI agent. The system integrates retrieval-augmented generation, environment interaction verification, and persistent memory modules to establish an automated architecture featuring a complete execution chain and an experience accumulation closed loop. Experimental evaluations across eight simulation task categories demonstrate a 90% success rate, significantly outperforming baseline models. By effectively lowering the expertise threshold for domain specialists and enhancing end-to-end workflow efficiency, this work provides a reliable intelligent solution for complex scientific computing, thereby facilitating broader adoption of advanced multiphysics simulation frameworks.
In the context of deep digitalization, large-scale energy internet systems face significant cyber-physical security and resilience challenges due to the tight coupling among power, information, and market layers. This work proposes a comprehensive modeling and decision-making framework that integrates energy storage coordination, multidimensional resilience, and electricity price forecasting. It introduces a graph-computation-based attack-resilient information routing mechanism and, for the first time, incorporates artificial intelligence trustworthiness assurance into the security and resilience research paradigm for energy internet systems. By synergistically combining cyber-physical system modeling, AI security techniques, and multilayer coordinated control strategies, the project establishes a holistic technical framework tailored to the security and resilience needs of large-scale energy internet infrastructures, thereby providing critical support for standardization efforts and regulatory policy development.
本文通过文献综述探讨了开发人员使用静态应用程序安全测试(SAST)工具时遇到的障碍,指出需从技术和人文两方面入手解决以促进其广泛应用。
本文针对软件开发过程中早期识别和修复安全漏洞的问题,提出了一种将静态应用安全测试工具输出集成到CI/CD流水线及问题跟踪软件中的自动化方法。
本文提出了一种基于物理信息的基函数(GDC),用于非线性响应曲线分解,解决了传统方法在解释性和灵活性之间的权衡问题。
This study addresses the high entry barriers and lack of intelligent assistance in MOOSE multiphysics simulations by proposing MOOSEnger-GPT-5.2, a localized AI agent. The system integrates retrieval-augmented generation, environment interaction verification, and persistent memory modules to establish an automated architecture featuring a complete execution chain and an experience accumulation closed loop. Experimental evaluations across eight simulation task categories demonstrate a 90% success rate, significantly outperforming baseline models. By effectively lowering the expertise threshold for domain specialists and enhancing end-to-end workflow efficiency, this work provides a reliable intelligent solution for complex scientific computing, thereby facilitating broader adoption of advanced multiphysics simulation frameworks.
In the context of deep digitalization, large-scale energy internet systems face significant cyber-physical security and resilience challenges due to the tight coupling among power, information, and market layers. This work proposes a comprehensive modeling and decision-making framework that integrates energy storage coordination, multidimensional resilience, and electricity price forecasting. It introduces a graph-computation-based attack-resilient information routing mechanism and, for the first time, incorporates artificial intelligence trustworthiness assurance into the security and resilience research paradigm for energy internet systems. By synergistically combining cyber-physical system modeling, AI security techniques, and multilayer coordinated control strategies, the project establishes a holistic technical framework tailored to the security and resilience needs of large-scale energy internet infrastructures, thereby providing critical support for standardization efforts and regulatory policy development.