2608004917
  • Open Access
  • Article

Response-Level Identification of Cloud API Misconfigurations Using Large Language Models

  • Akshay Krishna,   
  • Farzana Zahid *

Received: 21 Jul 2026 | Revised: 13 Aug 2026 | Accepted: 14 Aug 2026 | Published: 20 Aug 2026

Abstract

Application Programming Interfaces (APIs) are a set of rules that enable communication, data exchange, and automated interactions between applications and services. With the rapid advancement of cloud computing, APIs have evolved from simple data-access interfaces into critical components for managing, configuring, and orchestrating cloud resources. Most modern cloud platforms rely on RESTful APIs for provisioning cloud resources, applying configurations, and maintaining services. As a result, APIs misconfigurations have become a critical cloud security threat that can lead to sensitive data exposure, unauthorized access, or operational disruptions. Identifying these misconfigurations is challenging because traditional rule-based and static analysis methods often fail to capture complex, context-dependent configuration issues and system behaviors. In this study, we investigate the use of Large Language Models (LLMs) to detect security misconfigurations directly from cloud API response data. By treating API responses as representations of a system’s configuration state, we assess whether LLMs can effectively identify potential security risks. We evaluate five LLMs using a unified zero-shot prompting approach and compare their performance with and without Retrieval-Augmented Generation (RAG) to understand the impact of external knowledge on misconfiguration detection. The study not only focuses on each model’s ability to identify configuration components and detect misconfigurations, but also evaluates their capability to accurately determine the number of misconfigurations and generate clear, actionable security explanations. Our preliminary results show that Meta Llama Instruct combined with RAG achieves the reliable performance for identifying security misconfigurations in cloud API responses. This study provides new insights into the practicality of LLM-driven API cloud security analysis and paves the way for future research.

References 

  • 1.

    Google Cloud APIs. Available online: https://docs.cloud.google.com/apis/docs/overview (accessed on 15 September 2025).

  • 2.

    Patil, G. Introduction to APIs. In Django REST APIs Demystified: Simplifying API Development with Django; Apress: Berkeley, CA, USA, 2025; pp. 1–4.

  • 3.

    Powell, P.; Smalley, I. What Is a REST API (RESTful API)? Available online: https://www.ibm.com/think/topics/rest-apis (accessed on 24 August 2025).

  • 4.

    Erickson, J. What Is JSON? Available online: https://www.oracle.com/nz/database/what-is-json/ (accessed on 12 October 2025).

  • 5.

    Atlidakis, V.; Godefroid, P.; Polishchuk, M. Checking Security Properties of Cloud Service REST APIs. In Proceedings of the 2020 IEEE 13th International Conference on Software Testing, Validation and Verification (ICST), Porto, Portugal, 24–28 October 2020; pp. 387–397. https://doi.org/10.1109/icst46399.2020.00046.

  • 6.

    van Ede, T.; Khasuntsev, N.; Steen, B.; et al. Detecting Anomalous Misconfigurations in AWS Identity and Access Management Policies. In Proceedings of the 2022 on Cloud Computing Security Workshop, Los Angeles, CA, USA, 7 November 2022; pp. 63–74.

  • 7.

    Xu, W.; Huang, L.; Fox, A.; et al. Detecting Large-Scale System Problems by Mining Console Logs. In Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles, Big Sky, MT, USA, 11–14 October 2009; pp. 117–132.

  • 8.

    National Security Agency. Available online: https://media.defense.gov/2020/Jan/22/2002237484/-1/-1/0/CSI-MITIGATING-CLOUD-VULNERABILITIES 20200121.PDF (accessed on 1 January 2026).

  • 9.

    Xu, H.; Wang, S.; Li, N.; et al. Large Language Models for Cyber Security: A Systematic Literature Review. ACM Trans. Softw. Eng. Methodol. 2025. https://doi.org/10.1145/3769676.

  • 10.

    Hasanov, I.; Virtanen, S.; Hakkala, A. Application of Large Language Models in Cybersecurity: A Systematic Literature Review. IEEE Access 2024, 12, 176751–176778. https://doi.org/10.1109/access.2024.3505983.

  • 11.

    Raiaan, M.A.K.; Mukta, M.S.H.; Fatema, K.; et al. A Review on Large Language Models: Architectures, Applications, Taxonomies, Open Issues and Challenges. IEEE Access 2024, 12, 26839–26874. https://doi.org/10.1109/access.2024.3365742.

  • 12.

    Palo Alto Networks. What Is LLM (Large Language Model) Security? Available online: https://www.paloaltonetworks.com/cyberpedia/what-is-llm-security (accessed on 17 September 2025).

  • 13.

    Bergeman, D. What Is Zero-Shot Learning? Available online: https://www.ibm.com/think/topics/zero-shot-learning (accessed on 31 August 2025).

  • 14.

    Ghanem, M.C. Advancing IoT and Cloud Security through LLMs, Federated Learning, and Reinforcement Learning. In Proceedings of the 7th IEEE Conference on Cloud and Internet of Things, Montreal, QC, Canada, 29–31 October 2024; pp. 1–27.

  • 15.

    Li, H.; Wang, S.X.; Shang, F.; et al. Applications of Large Language Models in Cloud Computing: An Empirical Study Using Real-World Data. Int. J. Innov. Res. Comput. Sci. Technol. 2024, 12, 59–69. https://doi.org/10.55524/ijircst.2024.12.4.10.

  • 16.

    Schwartz, Y.; Ben-Shimol, L.; Mimran, D.; et al. LLMCloudHunter: Harnessing LLMs for Automated Extraction of Detection Rules from Cloud-Based CTI. In Proceedings of the ACM Web Conference 2025, Sydney, NSW, Australia, 28 April–2 May 2025; pp. 1922–1941.

  • 17.

    Kodali, R.K.; Upreti, Y.P.; Boppana, L. Large Language Models in AWS. In Proceedings of the 2024 1st International Conference on Robotics, Engineering, Science, and Technology (RESTCON), Pattaya, Thailand, 16–18 February 2024; pp. 112–117. https://doi.org/10.1109/restcon60981.2024.10463557.

  • 18.

    Wen, J.; Chen, Z.; Zhu, Z.; et al. LLM-Based Misconfiguration Detection for AWS Serverless Computing. ACM Trans. Softw. Eng. Methodol. 2026, 35, 1–28. https://doi.org/10.1145/3745766.

  • 19.

    Goyal, M.K.; Chaturvedi, R. Detecting Cloud Misconfigurations with RAG and Intelligent Agents: A Natural Language Understanding Approach. J. Electr. Syst. 2025, 20, 2558–2570. https://doi.org/10.52783/jes.7882.

  • 20.

    Lewis, P.; Perez, E.; Piktus, A.; et al. Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks. In Proceedings of the Advances in Neural Information Processing Systems 33 (NeurIPS 2020), Virtual Event, 6–12 December 2020; Volume 33, pp. 9459–9474. https://doi.org/10.48550/arxiv.2005.11401.

  • 21.

    Delgado, A.; Saitis, C.; Benetos, E.; et al. Deep Conditional Representation Learning for Drum Sample Retrieval by Vocalisation. arXiv 2022, arXiv:2204.04651.

  • 22.

    Meta Platforms, Inc. Meta LLaMA Documentation. Available online: https://www.llama.com/docs/overview/ (accessed on 30 August 2025).

  • 23.

    OpenAI Platform Documentation. Available online: https://platform.openai.com/docs/overview (accessed on 31 August 2025).

  • 24.

    Gemini API & Model Docs. Available online: https://ai.google.dev/gemini-api/docs (accessed on 31 August 2025).

  • 25.

    DeepSeek. DeepSeek API Documentation. Available online: https://api-docs.deepseek.com/ (accessed on 30 August 2025).

  • 26.

    OpenAI Model & Deployment Documentation. Available online: https://platform.openai.com/docs/models/gpt-oss-20b (accessed on 25 August 2025).

  • 27.

    About Cloud Storage Buckets. Available online: https://docs.cloud.google.com/storage/docs/buckets (accessed on 1 January 2026).

  • 28.

    AnythingLLM Documentation. Available online: https://docs.anythingllm.com/ (accessed on 25 August 2025).

  • 29.

    Gadesha, V. Prompt Engineering Techniques. Available online: https://www.ibm.com/think/topics/prompt-engineering-techniques (accessed on 21 October 2025).

  • 30.

    LM Studio Documentation. Available online: https://lmstudio.ai/docs/app (accessed on 25 August 2025).

  • 31.

    OWASP Top 10 API Security Risks—2023. Available online: https://owasp.org/API-Security/editions/2023/en/0x11-t10/ (accessed on 2 September 2025).

  • 32.

    Google Cloud. Google Cloud Security Best Practices Center. Available online: https://cloud.google.com/security/bestpractices (accessed on 9 August 2025).

  • 33.

    Amazon Web Services. AWS Security Documentation. Available online: https://docs.aws.amazon.com/security/ (accessed on 9 August 2025).

  • 34.

    Azure Security Documentation. Available online: https://learn.microsoft.com/en-us/azure/security/ (accessed on 9 August 2025).

  • 35.

    Chandramouli, R.; Butcher, Z. Guidelines for API Protection for Cloud-Native Systems; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2025. https://doi.org/10.6028/nist.sp.800-228.

  • 36.

    CIS Google Cloud Platform Foundation Benchmark. Available online: https://www.cisecurity.org/insights/blog/cisbenchmarks-april-2024-update#CISGoogleCloudPlatformFoundationBenchmarkv3.0.0 (accessed on 8 August 2025).

  • 37.

    CIS API Security Guide. Available online: https://learn.cisecurity.org/cis-api-security-guide (accessed on 9 August 2026).

Share this article:
How to Cite
Krishna, A.; Zahid, F. Response-Level Identification of Cloud API Misconfigurations Using Large Language Models . Pragmatic Cybersecurity 2026, 1 (2), 12. https://doi.org/10.53941/pc.2026.100012.
RIS
BibTex
Copyright & License
article copyright Image
Copyright (c) 2026 by the authors.