Intelligent Vulnerability Prioritization and Remediation in CI/CD Pipelines Using Large Language Models and Knowledge Graphs
DOI:
https://doi.org/10.63345/wjftcse.v2.i1.2Keywords:
Vulnerability Management, Large Language Models, Knowledge Graphs, DevSecOps, CI/CD Security, Software Supply Chain Security, SBOM, Remediation AutomationAbstract
The exponential growth of software dependencies and the accelerating pace of continuous integration and delivery have created a critical bottleneck in vulnerability management: security teams and developers are overwhelmed by the sheer volume of reported vulnerabilities, most of which are not exploitable in their specific deployment contexts. Traditional vulnerability scanners produce flat lists of Common Vulnerabilities and Exposures (CVEs) without contextual prioritization, leading to alert fatigue, delayed remediation of critical issues, and unnecessary deployment friction. This paper presents an intelligent vulnerability prioritization and remediation framework that combines Large Language Models (LLMs) with knowledge graph reasoning to transform how organizations manage security vulnerabilities in CI/CD pipelines. The proposed architecture integrates: (1) an LLM-based vulnerability intelligence layer that extracts and synthesizes information from CVEs, security advisories, and exploit databases to assess true exploitability; (2) a knowledge graph representation of the application environment that models dependencies, deployment contexts, and security controls; (3) a context-aware risk scoring engine that combines exploitability intelligence with environmental context to produce actionable prioritization; and (4) an automated remediation recommendation system that generates specific, verifiable fixes tailored to the application stack. Experimental validation on production CI/CD pipelines processing over 50,000 vulnerability reports demonstrates that the framework reduces actionable vulnerability volume by 78%, improves critical vulnerability remediation time by 65%, and decreases false-positive driven developer interruptions by 71%. The system generates remediation recommendations with 89% accuracy, with 94% of recommended fixes verified as correct in automated testing. This research demonstrates that combining the reasoning capabilities of LLMs with the structural knowledge of graph-based representations can fundamentally transform vulnerability management from an overwhelming flood of alerts to a targeted, actionable security intelligence system that enables organizations to focus on what truly matters.
Downloads
References
[1] C. Ge, "Optimizing Vulnerability Repair in SBOM Using Maximum Satisfiability Solving," TechRxiv, Feb. 2025. doi: 10.36227/techrxiv.178259266.69611316.
[2] Ö. Kağızmandere and H. Arslan, "Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines," Int. J. Information Security Science, vol. 13, no. 2, pp. 33-42, 2024.
[3] H. Mistry, A. Goswami, and C. Mavani, "Automated Anomaly Detection and Response System for Enhancing Cloud Security," Indian Patent 202421051108, 2024.
[4] K. Bhardwaj, P. K. Dutta, and P. Chintale, "Securing Container Images through Automated Vulnerability Detection in Shift-Left CI/CD Pipelines," 2024.
[5] "AI-Assisted Detection of Malicious Changes in Infrastructure-as-Code," IEEE Xplore, 2026.
[6] R. K. Mahimalur, S. Amgothu, B. Reddy, and S. S. Gadde, "Modern Cloud Security and Automation: A DevSecOps Approach Leveraging AI/ML and Containerization," in 2025 9th Int. Conf. Electronics, Communication and Aerospace Technology (ICECA), 2025, pp. 305-312.
[7] Mittal, "AI-Augmented DevSecOps Pipelines for Secure and Scalable Service-Oriented Architectures in Cloud-Native Systems," IEEE SOSE, 2025.
[8] L. Prates and R. Pereira, "DevSecOps practices and tools," Int. J. Information Security, vol. 24, no. 1, p. 11, 2025.
[9] J. Zhu, K. Li, S. Chen, L. Fan, and X. Xie, "A comprehensive study on static application security testing (SAST) tools for android," IEEE Trans. Software Engineering, 2024.
[10] Singh, "Automating Security Testing in CI/CD Pipelines using DevSecOps Tools: A Comprehensive Study," 2025.
[11] R. Kokku, "Revolutionizing DevOps Security: AI and ML-Enabled Automated Testing Approaches," Int. J. Current Science Research and Review, vol. 7, no. 11, pp. 8140-8144, 2024.
[12] Saboor, M. F. Hassan, R. Akbar, S. N. M. Shah, F. Hassan, S. A. Magsi, and M. A. Siddiqui, "Containerized microservices orchestration and provisioning in cloud computing: A conceptual framework and future perspectives," Applied Sciences, vol. 12, no. 12, p. 5793, 2022.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.







