Enterprise product verification processing method and device, equipment and storage medium
By parsing and scheduling scanning programs to verify product files and catalog information during the product development and production process of financial IT companies, the problem of low product verification efficiency has been solved, and unified registration and scheduling of product inspection have been achieved, thereby improving the overall verification efficiency.
Patent Information
- Application Number
- CN202411116372.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-14
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2044-08-14
AI Technical Summary
In the product development and production process of financial IT companies, each target stage, such as document review, vulnerability scanning, and virus scanning, is completely independent, resulting in data isolation. Versions and asset levels lack effective reuse, requiring coordination among departments to execute. This makes unified planning and scheduling difficult and verification efficiency low.
By responding to product submission events, the system determines the relevant information of the target product submission, parses the standard files under the directory structure, schedules preset programs of different scanning types to verify and scan the product files and directory information, and outputs multi-dimensional verification and scanning reports. This breaks down siloed processes, enables unified registration and scheduling of product inspection, and reuses existing work results.
It improves the overall efficiency of product verification for enterprises. By integrating the entire process and merging repetitive steps, it achieves multi-dimensional control and reuse, solving the problem of low product verification efficiency and optimizing resource utilization.
Smart Images

Figure CN119167365B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of resource management, and particularly relates to a verification processing method and device for enterprise products, equipment and a storage medium. BACKGROUND
[0002] At present, in some large financial enterprises, based on the leading architecture perspective and concept of the industry, we will scientifically divide the enterprise architecture in order based on the enterprise strategic goal, obtain the divided enterprise product, and the enterprise product can effectively guide the business and IT team to convert the enterprise strategic goal and enterprise business knowledge into enterprise IT capability and business operation capability, and integrate the business operation and the IT system.
[0003] In the prior art, the product scanning process of a financial IT enterprise is usually based on a vertical independent process of a unified pipeline or a product library. In the entire development and production process, various target links such as document checking, vulnerability scanning and virus scanning are completely independently executed.
[0004] However, in the prior art, in the entire development and production process of the product, various target links such as document checking, vulnerability scanning and virus scanning are completely independent, data isolation, based on dependence, version and asset level lack effective reuse, and a series of verification scanning can be executed only when each department is coordinated and consistent. It is difficult to uniformly and overall schedule, resulting in low verification efficiency of the enterprise product. SUMMARY
[0005] The present application provides a verification processing method and device for enterprise products, equipment and a storage medium to solve the problem of low verification efficiency of enterprise products.
[0006] In a first aspect, the present application provides a verification processing method for enterprise products, comprising:
[0007] In response to a product submission event, determining submission-related information of a target product in the product submission event; wherein the product submission event is used to indicate that the target product is subjected to verification processing, and the submission-related information includes a directory structure of the target product and standard files under the directory structure;
[0008] Performing analysis processing on the standard files under the directory structure in the submission-related information to obtain analysis result information; wherein the analysis result information includes product file and product directory information of the target product;
[0009] According to a preset scanning type, a preset scanning program corresponding to the scanning type is dispatched to perform verification scanning on the product file and the product directory information in the analysis result information, verification scanning information is determined and a verification scanning report is output; wherein the scanning report includes scanning results of the target product in multiple scanning dimensions.
[0010] In a possible design, the analysis of the standard file under the directory structure in the submission-related information includes:
[0011] The standard file under the directory structure in the submission-related information is decompressed to obtain a decompressed product file under the directory structure.
[0012] According to the decompressed product file, analysis result information is generated; wherein the analysis result information includes the target product in the directory structure before decompression and the standard file under the directory structure, and the product file and product directory information of the target product after decompression.
[0013] In a possible design, the verification scanning according to the preset scanning type includes:
[0014] According to the current preset scanning type, a preset scanning program corresponding to the current scanning type is dispatched to perform verification scanning on the product file and the product directory information in the analysis result information, and verification scanning information is determined; wherein the verification scanning information includes information of multiple verification targets.
[0015] According to a preset other scanning type, a preset scanning program corresponding to the other scanning type is dispatched to perform verification scanning on the product file and the product directory information, if it is determined that the verification target is repeated, the information of the repeated verification target is determined as the verification scanning information, and other targets are scanned to obtain verification scanning information.
[0016] According to the verification scanning information, verification scanning information is determined and a verification scanning report is output.
[0017] In a possible design, the preset scanning type includes any one or more of the following:
[0018] The analysis result information includes difference comparison, technical component scanning, document verification, vulnerability scanning and virus scanning.
[0019] In a possible design, the preset scanning program corresponding to the current scanning type is dispatched according to the current scanning type, and the product file and the product directory information in the analysis result information are scanned to determine the verification scanning information, including:
[0020] If the current scanning type is the difference comparison type, the preset scanning program corresponding to the difference comparison type is dispatched according to the difference comparison type, and the product file and the product directory information in the analysis result information are compared with the product file and the product directory information of the previous historical version to determine the range change list of the target product.
[0021] The verification scanning information is determined according to the range change list.
[0022] In a possible design, after the standard file under the directory structure in the submission information is parsed to obtain the analysis result information, the method further includes:
[0023] The analysis result information is sent to a product file management module, and the analysis result information is used to be associated with the version information of the target product.
[0024] In a second aspect, the application provides a verification processing device for enterprise products, including:
[0025] A determination module is configured to determine submission information of a target product in a product submission event in response to the product submission event, wherein the product submission event is used to indicate that the target product is subjected to verification processing, and the submission information includes a directory structure of the target product and a standard file under the directory structure.
[0026] An analysis module is configured to parse the standard file under the directory structure in the submission information to obtain analysis result information, wherein the analysis result information includes a product file and product directory information of the target product.
[0027] A verification module is configured to dispatch a preset scanning program corresponding to a scanning type according to the preset scanning type, and scan the product file and the product directory information in the analysis result information to determine and output a verification scanning report, wherein the scanning report includes scanning results of the target product in multiple scanning dimensions.
[0028] In a possible design, the analysis module includes:
[0029] a decompression unit, configured to perform decompression processing on the standard file under the directory structure in the submission-related information, to obtain a decompressed product file under the directory structure;
[0030] a generation unit, configured to generate parsing result information according to the decompressed product file; wherein the parsing result information comprises a directory structure of the target product before decompression, the standard file under the directory structure, the product file after decompression of the target product, and product directory information.
[0031] In a possible design, the verification module comprises:
[0032] a first verification unit, configured to, according to a current preset scanning type, dispatch a preset scanning program corresponding to the current scanning type, to perform verification scanning on the product file and the product directory information in the parsing result information, to determine verification scanning information; wherein the verification scanning information comprises information of a plurality of verification targets;
[0033] a second verification unit, configured to, according to a preset other scanning type, dispatch a preset scanning program corresponding to the other scanning type, to perform verification scanning on the product file and the product directory information, to determine, if a duplicate verification target is determined to exist, information of the duplicate verification target as the verification scanning information, and to perform verification scanning on other targets to obtain verification scanning information;
[0034] an output unit, configured to determine and output a verification scanning report according to the verification scanning information.
[0035] In a possible design, the preset scanning type comprises any one or more of the following:
[0036] differential comparison, technical component scanning, document verification, vulnerability scanning, and virus scanning of the parsing result information.
[0037] In a possible design, the first verification unit comprises:
[0038] a comparison subunit, configured to, if the current scanning type is a differential comparison type, according to the differential comparison type, dispatch a preset scanning program corresponding to the differential comparison type, to perform differential comparison on the product file and the product directory information in the parsing result information and a product file and product directory information of a previous historical version, to determine a range change list of the target product;
[0039] a determination subunit, configured to determine verification scanning information according to the range change list.
[0040] In a possible design, the apparatus further comprises:
[0041] The sending module is configured to send the analysis result information to the product file management module after the standard file under the directory structure in the submission-related information is parsed to obtain the analysis result information, wherein the analysis result information is used to be associated with the version information of the target product.
[0042] In a third aspect, an electronic device is provided, which comprises at least one processor and a memory. The memory stores computer-executable instructions. The at least one processor executes the computer-executable instructions stored in the memory, so that the at least one processor performs the enterprise product verification processing method as described in the first aspect and various possible designs of the first aspect.
[0043] In a fourth aspect, a computer-readable storage medium is provided, which stores computer-executable instructions. When a processor executes the computer-executable instructions, the enterprise product verification processing method as described in the first aspect and various possible designs of the first aspect is implemented.
[0044] In a fifth aspect, a computer program product is provided, which comprises a computer program. When the computer program is executed by a processor, the enterprise product verification processing method as described in the first aspect and various possible designs of the first aspect is implemented.
[0045] This application provides a method, apparatus, equipment, and storage medium for verifying enterprise products. In response to a product submission event, it determines the relevant information of the target product submission in the product submission event. The product submission event is used to instruct verification processing of the target product, and the relevant information includes the target product's directory structure and standard files within that directory structure. The standard files within the directory structure of the submission information are parsed to obtain parsing result information, which includes the target product's product file and product directory information. Based on a preset scan type, a preset scan program corresponding to that scan type is scheduled to perform verification scans on the product file and product directory information in the parsing result information, determining and outputting a verification scan report. The scan report includes scan results of the target product across multiple scan dimensions. In this solution, scan programs corresponding to each scan type can be scheduled to perform verification scans on the product file and product directory information in the parsing result information, determining and outputting verification scan reports. Therefore, the enterprise-level overall product verification method proposed in this application breaks the siloed process of the original enterprise-level production line. In the existing process, each link is based on the principle of process independence, and each link independently completes the downloading, decompression, directory structure parsing, directory structure uploading, and autonomous task splitting of products, which consumes a large amount of repetitive storage and computing resources. This application can integrate the entire process from an enterprise-level perspective, merge repetitive links in multiple processes, and perform enterprise-level global control of products in production from the management perspectives of products, documents, components, processes, and documents. It breaks data isolation, coordinates and schedules scanning programs of various scanning types to verify products, realizes unified registration and unified scheduling of product verification, reuses existing work results, improves the efficiency of enterprise integrated process, and provides a product verification system based on multi-dimensional control and reuse, solving the problem of low product verification efficiency in enterprises. Attached Figure Description
[0046] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0047] Figure 1 A flowchart illustrating a verification process for enterprise products provided in this application embodiment;
[0048] Figure 2 A flowchart illustrating another verification method for enterprise products provided in this application embodiment;
[0049] Figure 3 A schematic diagram of the structure of a verification and processing device for enterprise products provided in this application embodiment;
[0050] Figure 4Another enterprise product verification processing device structure schematic view provided by the embodiment of the application is shown in the figure;
[0051] Figure 5 An electronic device structure schematic view provided by the embodiment of the application is shown in the figure.
[0052] The specific embodiments of the application have been shown in the above figures, and will be described in more detail hereinafter. These figures and the written description are not intended to limit the scope of the inventive concept in any way, but to illustrate the inventive concept by reference to specific embodiments. DETAILED DESCRIPTION
[0053] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The following description is made with reference to the accompanying drawings in which like reference numerals refer to like elements, and the term "exemplary" is used herein to mean "serving as an example, instance, or illustration." The following description is not intended to limit the scope of the present application in any way, but rather is intended to provide what is considered to be a practical demonstration of the application. As such, the application is likely to have other embodiments and / or applications and that the scope of the application should not be limited by this description.
[0054] It should be noted that the collection, storage, use, processing, transmission, provision and disclosure of the financial data or user data and other information involved in the technical solutions of the application comply with relevant laws and regulations and do not violate public order and good customs. The user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of the relevant data need to comply with relevant laws, regulations and standards, and provide corresponding operation portal for user to choose authorization or refusal. In addition, in the embodiments of the application, some existing industry solutions such as software, components, models, etc. may be mentioned, which should be considered as exemplary, and the purpose is only to illustrate the feasibility of the implementation of the technical solutions of the application, but it does not mean that the applicant has or will necessarily use the solution.
[0055] At present, based on the leading architecture perspective and concept in the industry, we will scientifically and orderly divide the enterprise architecture based on the strategic goals of the enterprise, and obtain the divided enterprise products. The enterprise products can effectively guide the business and IT team to transform the enterprise strategic goals and enterprise business knowledge into enterprise IT capabilities and business operation capabilities, and integrate the business operation and IT system.
[0056] In one example, the product scanning process of a financial IT enterprise is usually a vertical independent process based on a unified pipeline or product library. In the entire development and production process, each target link such as document review, vulnerability scanning, and virus scanning is completely independently executed. However, in the prior art, in the entire development and production process of the product, each target link such as document review, vulnerability scanning, and virus scanning is completely independent, data is isolated, effective reuse of dependencies, versions, and asset levels is lacking, a series of verification scans need to be executed in coordination with each department, unified scheduling is difficult, and the verification efficiency of the enterprise product is low.
[0057] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below with specific examples. The following specific examples can be combined with each other, and the same or similar concepts or processes may not be described again in some examples. The embodiments of the present application will be described below with reference to the accompanying drawings.
[0058] Figure 1 A flowchart of an enterprise product verification processing method according to an embodiment of the present application is shown in FIG. 1. The method includes the following steps. Figure 1
[0059] In step 101, in response to a product submission event, determine the submission-related information of the target product in the product submission event. The product submission event is used to indicate that the target product is subjected to verification processing, and the submission-related information includes the directory structure of the target product and the standard files under the directory structure.
[0060] By way of example, the execution subject of the present embodiment can be an electronic device, or a terminal device, or an enterprise product verification processing device or equipment, or other devices or equipment that can execute the present embodiment, and no limitation is made thereto. In the present embodiment, the execution subject is introduced as an electronic device.
[0061] First, the electronic device communicates with a plurality of subsystems, and the electronic device and the plurality of subsystems together constitute a total verification system. The electronic device is deployed with a product analysis platform, and the subsystems include an enterprise IT management platform, an enterprise-level product library, an enterprise-level global technical component management subsystem, and an enterprise-level product file management IT subsystem.
[0062] Specifically, the product analysis platform is a unified management tool for dissection of enterprise-level products based on enterprise-level product specifications and general file compression and decompression technology, and the decompression result is used for document checking, vulnerability scanning and product scanning and other specific processes; wherein, the specific process tools include document indexing tools, product component scanning tools, virus scanning tools, vulnerability scanning tools, etc. Enterprise IT management platform: used for IT product and process related information management, online flow of development process, linking various systems, realizing information sharing and publishing. Enterprise product library: used for unified management of enterprise released products, with product directory and product specifications defined by enterprise-level specifications, unified management of enterprise-level global delivery products, that is, products include file sets stored according to product directory and product specifications, mainly managing file sets. Enterprise-level global technical component management subsystem: used for managing technical components used by products, from the perspective of enterprise-level, managing all products in terms of technical component dependency and technical component version. Enterprise product file management IT subsystem: used for extracting and indexing versions, keywords, abstracts, etc. of components and documents in submitted products, and managing details of products at certain level, wherein, the components include non-standard components and standard components.
[0063] In this step, first, according to the enterprise-level project management regulations and application management regulations, the application information, project management information, etc. related to the target product are initialized on the IT management platform according to the product directory and product specifications defined by the enterprise-level specifications, for example, the product name and the archived product directory are defined. According to the product directory and product specifications defined by the enterprise-level specifications, the structure of the standard submission under the product standard internal file directory and the product internal file directory structure of the target product is determined in the enterprise product file management IT subsystem, wherein, the product standard internal file directory includes the global storage structure of the target product and the internal directory structure of the target product. According to the enterprise-level project process, the user opens and submits the target product to the enterprise product library, at this time, the enterprise product library generates a product submission event, which indicates that the target product is subjected to verification processing, and the product analysis platform receives the product submission event and initiates the product verification process according to the product submission event. Specifically, the submission related information of the target product in the product submission event is determined, including the directory structure of the target product and the standard files under the directory structure.
[0064] Step 102, the standard files under the directory structure in the submission related information are analyzed to obtain analysis result information; wherein, the analysis result information includes product file and product directory information of the target product.
[0065] Exemplarily, the standard file under the directory structure in the submission-related information is decompressed to obtain a decompressed product file under the directory structure, and the decompressed product directory information is generated according to the decompressed product file. The directory structure of the target product before decompression, the standard file under the directory structure, and the product file and the product directory information of the target product after decompression are all analysis result information.
[0066] In step 103, according to the preset scanning type, the preset scanning program corresponding to the scanning type is dispatched to verify and scan the product file and the product directory information in the analysis result information, and a verification scanning report is determined and output. The scanning report includes the scanning results of the target product in multiple scanning dimensions.
[0067] Exemplarily, the preset scanning type refers to the verification manner performed on each aspect of the business function of the target product, for example, the scanning types include difference comparison of the analysis result information, technical component scanning, document verification, vulnerability scanning, and virus scanning, etc., which are not limited. Each scanning type corresponds to a preset scanning program, for example, the scanning program corresponding to the document verification type is the document verification program in the enterprise IT management platform. If the document verification is performed on the target product, the electronic device directly dispatches the document verification program in the enterprise IT management platform to perform the document verification.
[0068] In this step, according to the preset scanning type, the electronic device dispatches the preset scanning program corresponding to the scanning type from any subsystem, and according to the dispatched scanning program, the product file and the product directory information in the analysis result information are verified and scanned, and a verification scanning report is determined and output. The scanning report includes the scanning results of the target product in multiple scanning dimensions, for example, the scanning report includes the scanning results of the target product in technical component scanning, document verification, vulnerability scanning, and virus scanning, etc.
[0069] In the embodiment of the present application, in response to the product submission event, the submission-related information of the target product in the product submission event is determined; wherein the product submission event is used to indicate the verification processing of the target product, and the submission-related information includes the directory structure of the target product and the standard files under the directory structure. The standard files under the directory structure in the submission-related information are parsed and processed to obtain parsing result information; wherein the parsing result information includes product files and product directory information of the target product. According to the preset scanning type, the preset scanning program corresponding to the scanning type is dispatched to perform verification scanning on the product files and product directory information in the parsing result information, and a verification scanning report is determined and output; wherein the scanning report includes the scanning results of the target product in multiple scanning dimensions. In the scheme, the scanning program corresponding to each scanning type can be dispatched to perform verification scanning on the product files and product directory information in the parsing result information, and a verification scanning report is determined and output. Therefore, the enterprise-level product overall checking method of the present application breaks the original vertical process in the enterprise-level assembly line. In the existing process, each process is based on the process independence principle, and each process independently completes the download, decompression, directory structure parsing, directory structure uploading, and autonomous task splitting of the product, which occupies a large amount of repeated storage resources and computing resources. The present application can integrate the process from the enterprise-level perspective, combine the repeated links in multiple processes, manage the production products from the perspectives of product, file, component, process, and document, break the data isolation, schedule the scanning programs of various scanning types to verify the product, realize unified registration and unified scheduling of product checking, reuse existing work results, improve the efficiency of enterprise integrated process, provide a product checking system based on multi-dimensional management and reuse, and solve the problem of low verification efficiency of enterprise products.
[0070] Figure 2 The flowchart of another enterprise product verification processing method provided in the embodiment of the present application is shown in Figure 2 The method comprises the following steps.
[0071] Step 201, in response to the product submission event, the submission-related information of the target product in the product submission event is determined; wherein the product submission event is used to indicate the verification processing of the target product, and the submission-related information includes the directory structure of the target product and the standard files under the directory structure.
[0072] For example, this step can refer to step 101 in Figure 1 , and will not be repeated here.
[0073] Step 202, the standard files under the directory structure in the submission-related information are decompressed to obtain the decompressed product files under the directory structure.
[0074] Exemplarily, the submission-related information includes a directory structure of the target artifact, standard files under the directory structure, and file types and standard artifact analysis and parsing rules corresponding to the file types. Formats of the standard files under the directory structure in the submission-related information are determined, and standard artifact parsing rules corresponding to each format are determined. According to the standard artifact parsing rules, the standard files of the corresponding formats under the directory structure in the submission-related information are decompressed to obtain decompressed artifact files under the directory structure. For example, the decompression processing is equivalent to dissection processing, and the standard files are decompressed to obtain a plurality of decompressed artifact files of the next level.
[0075] In step 203, the analysis result information is generated according to the decompressed artifact files. The analysis result information includes the directory structure and the standard files under the directory structure of the target artifact before decompression, and the artifact files and the artifact directory information of the target artifact after decompression.
[0076] Exemplarily, after the artifact analysis is completed, the electronic device extracts the file and directory information of the target artifact before and after decompression based on the artifact analysis result. The file and directory information before decompression includes the directory structure and the standard files under the directory structure of the target artifact before decompression, and the file and directory information after decompression includes the artifact files and the artifact directory information of the target artifact after decompression. The file before and after decompression includes full-text abstract and other artifact identification information, and the directory information before and after decompression includes other artifact identification information.
[0077] In step 204, the analysis result information is sent to an artifact file management module. The analysis result information is used to associate with the version information of the target artifact.
[0078] Exemplarily, the electronic device submits the file and directory information extracted from the analysis result information to an enterprise-level artifact file management IT subsystem. The enterprise-level artifact file management IT subsystem associates the file and directory information with the version information of the target artifact submitted this time.
[0079] In step 205, according to the current preset first scanning type, a preset scanning program corresponding to the current scanning type is dispatched to verify and scan the artifact files and the artifact directory information in the analysis result information to determine verification and scanning information. The verification and scanning information includes information of a plurality of verification targets.
[0080] In one example, the preset scanning type includes any one or more of the following: difference comparison of the analysis result information, technical component scanning, document verification, vulnerability scanning, and virus scanning.
[0081] In one example, if the current scan type is a difference comparison type, then according to the difference comparison type, a preset scan program corresponding to the difference comparison type is dispatched to perform a difference comparison between the product file and the product directory information in the analysis result information and the product file and the product directory information of the previous historical version, so as to determine a range change list of the target product; and according to the range change list, verification scan information is determined.
[0082] By way of example, the preset scan type refers to a verification manner performed on each aspect of the business function of the target product, for example, the scan type includes a difference comparison of the analysis result information, a technical component scan, a document verification, a vulnerability scan, a virus scan, and the like, without limitation. Each scan type corresponds to a preset scan program, for example, a scan program corresponding to the document verification type is a document verification program in the enterprise IT management platform, and if the document verification is performed on the target product, the electronic device directly dispatches the document verification program in the enterprise IT management platform to perform the document verification.
[0083] For example, if the current scan type is a difference comparison type, then according to the difference comparison type, a preset scan program corresponding to the difference comparison type is dispatched to perform a difference comparison between the product file and the product directory information in the analysis result information and the product file and the product directory information of the previous historical version of the same specification and definition, so as to determine a range change list of the target product; and according to the range change list, verification scan information is determined. At the same time, key information of a non-standard specification supplement file and change information should also be recorded. In particular, when the target product belongs to an incremental deployment form, the current submission information can be partial information, therefore, the product comparison should not perform a full difference comparison, but a local comparison between the incremental part and the product directory structure corresponding to the historical version to form version difference information. The product file and the product directory information in the analysis result information can also be compared and analyzed with a preset submission standard, and an analysis result is submitted, wherein the preset submission standard refers to a standard content specification to which the product should be submitted.
[0084] If the scanning type is the technical component scanning type, further product technical component scanning is performed according to the product specification and the product analysis result. Specifically, a preset scanning program corresponding to the technical component scanning type is dispatched to further analyze the internal files of the target product by using the preset component technical rules and features of the product. The preset scanning program corresponding to the technical component scanning type includes a product component scanning tool, and the internal files include the decompressed product files in the product analysis result, such as a WAR format deployment package. The dependent component information is obtained by analyzing the WAR format deployment package. Then, the dependent component information is listed in the enterprise-level global technical component management subsystem and matched with the preset global component library, component dependency relationship library, component version library, and the like to obtain the dependent component version list of the specific files of the target product. The dependent component version list is uploaded to the enterprise-level global technical component management subsystem, and the dependent component version list is the verification scanning information. The enterprise-level global technical component management subsystem synchronously updates the global list range, product version dependency relationship, and corresponding system release component information according to the dependent component version list of the product.
[0085] If the current scanning type is the document verification type, a preset scanning program corresponding to the document verification type is dispatched to perform document verification on the target product in a standard format according to the product specification, and the preset scanning program corresponding to the document verification type includes a document indexing tool. Specifically, the document content is analyzed according to the document format, the keywords are extracted, the abstract is extracted, the formatted data in an online format is formed, and the formatted data is uploaded to the enterprise-level product file management IT subsystem for checking, approving, and the like.
[0086] If the current scanning type is the vulnerability scanning type and the virus scanning type, a preset scanning program corresponding to the vulnerability scanning type and a preset scanning program corresponding to the virus scanning type are dispatched to perform vulnerability scanning and virus scanning. Specifically, the preset virus scanning tool and the vulnerability scanning tool are used to perform special virus verification and vulnerability verification based on the product analysis result to obtain the verification scanning information.
[0087] Therefore, based on the horizontal scanning result reuse of the unified enterprise-level product library and the enterprise-level component dependency management, document range management, and document version change control, the vertical global scheduling, including product document verification, vulnerability scanning, virus scanning, and the like, can be performed to comprehensively verify the target product, which facilitates centralized management of the product.
[0088] In step 206, according to the preset other scanning type, the preset scanning program corresponding to the other scanning type is dispatched to perform verification scanning on the product file and the product directory information. If it is determined that there is a repeated verification target, the information of the repeated verification target is determined as the verification scanning information, and the other targets are verified and scanned to obtain the verification scanning information.
[0089] For example, the electronic device can dispatch the preset scanning program corresponding to the other scanning type according to the preset other scanning type to perform verification scanning on the product file and the product directory information. If it is determined that there is a repeated verification target that has been verified and scanned to obtain the verification scanning information, the repeated verification target does not need to be repeatedly verified and scanned, and the information of the repeated verification target is directly determined as the verification scanning information of the current verification. Verification scanning is performed on the other targets except the repeated verification target to obtain the verification scanning information. Therefore, data interworking and multiplexing can be realized under the verification of multiple scanning types, so that the data in the verification scanning report remains consistent. The existing product analysis result can be used to avoid repeated analysis of the same product multiple times, and the existing result can be used to split and schedule according to the scanning performance of the tool.
[0090] In step 207, the verification scanning information is determined and a verification scanning report is output according to the verification scanning information. The scanning report includes the scanning results of the target product in multiple scanning dimensions.
[0091] For example, the electronic device can determine and output the verification scanning report according to the verification scanning information of each scanning type. The scanning report includes the scanning results of the target product in multiple scanning dimensions.
[0092] In the embodiments of the present application, in response to the product submission event, the submission-related information of the target product in the product submission event is determined; wherein the product submission event is used to indicate that the target product is subjected to verification processing, and the submission-related information includes the directory structure of the target product and the standard files under the directory structure. The standard files under the directory structure in the submission-related information are decompressed to obtain the decompressed product files under the directory structure. According to the decompressed product files, the analysis result information is generated; wherein the analysis result information includes the directory structure and the standard files under the directory structure of the target product before decompression, and the product files and the product directory information of the target product after decompression. The analysis result information is sent to the product file management module; wherein the analysis result information is used to be associated with the version information of the target product. According to the current preset first scanning type, the preset scanning program corresponding to the current scanning type is dispatched to perform verification scanning on the product files and the product directory information in the analysis result information to determine the verification scanning information; wherein the verification scanning information includes the information of multiple verification targets. According to the preset other scanning type, the preset scanning program corresponding to the other scanning type is dispatched to perform verification scanning on the product files and the product directory information, and if it is determined that there is a repeated verification target, the information of the repeated verification target is determined as the verification scanning information, and other targets are subjected to verification scanning to obtain the verification scanning information. According to the verification scanning information, the verification scanning report is determined and output; wherein the scanning report includes the scanning results of the target product in multiple scanning dimensions. Therefore, the enterprise-level product overall checking method of the present application breaks the vertical process in the original enterprise-level assembly line. In the existing process, each link is based on the process independence principle, and each process independently completes the download, decompression, directory structure analysis, directory structure upload, and independent task splitting of the product, which occupies a large amount of repeated storage resources and computing resources. The present application can integrate the process from the enterprise-level perspective, combine the repeated links in multiple processes, manage the products, files, components, processes, and documents from the perspective of enterprise-level overall control, break the data isolation, schedule the scanning programs of various scanning types to verify the products, realize the unified registration and unified scheduling of product checking, reuse the existing work results, improve the enterprise integration process efficiency, provide a product checking system based on multi-dimensional control and reuse, and solve the problem of low product verification efficiency.
[0093] In one example, the embodiment of the present application provides a verification processing system of enterprise products, which comprises an electronic device and a plurality of subsystems, wherein the electronic device is deployed with a product analysis platform, and the subsystems comprise an enterprise IT management platform, an enterprise product library, an enterprise global technical component management subsystem, and an enterprise product file management IT subsystem. The electronic device is configured to dispatch a scanning program in the subsystem to perform verification scanning on a target product according to a preset scanning type, and obtain a verification scanning report.
[0094] Figure 3 A structural schematic diagram of a verification processing device of enterprise products provided by the embodiment of the present application is shown in Figure 3 , which comprises:
[0095] A determination module 31 is configured to determine submission-related information of a target product in a product submission event in response to the product submission event, wherein the product submission event is used to indicate that the target product is subjected to verification processing, and the submission-related information comprises a directory structure of the target product and standard files under the directory structure.
[0096] An analysis module 32 is configured to perform analysis processing on the standard files under the directory structure in the submission-related information, and obtain analysis result information, wherein the analysis result information comprises product file and product directory information of the target product.
[0097] A verification module 33 is configured to dispatch a preset scanning program corresponding to a scanning type according to the preset scanning type, and perform verification scanning on the product file and the product directory information in the analysis result information, determine and output a verification scanning report, wherein the scanning report comprises scanning results of the target product in a plurality of scanning dimensions.
[0098] The device of the embodiment can execute the technical solutions in the above method, and the specific implementation process and technical principles are the same, which will not be repeated here.
[0099] Figure 4 A structural schematic diagram of another verification processing device of enterprise products provided by the embodiment of the present application is shown in Figure 3 , which is based on the embodiment shown in Figure 4 , wherein the analysis module 32 comprises:
[0100] A decompression unit 321 is configured to perform decompression processing on the standard files under the directory structure in the submission-related information, and obtain decompressed product files under the directory structure.
[0101] The generating unit 322 is configured to generate parsing result information according to the decompressed product file; the parsing result information comprises the directory structure and the standard file under the directory structure of the target product before decompression, and the product file and the product directory information of the target product after decompression.
[0102] In one example, the verification module 33 comprises:
[0103] The first verification unit 331 is configured to, according to the current preset scanning type, schedule a preset scanning program corresponding to the current scanning type, perform verification scanning on the product file and the product directory information in the parsing result information, and determine verification scanning information; the verification scanning information comprises information of a plurality of verification targets.
[0104] The second verification unit 332 is configured to, according to a preset other scanning type, schedule a preset scanning program corresponding to the other scanning type, perform verification scanning on the product file and the product directory information, and if it is determined that a repeated verification target exists, determine information of the repeated verification target as the verification scanning information, and perform verification scanning on other targets to obtain the verification scanning information.
[0105] The output unit 333 is configured to determine and output a verification scanning report according to the verification scanning information.
[0106] In one example, the preset scanning type comprises any one or more of the following:
[0107] Difference comparison of the parsing result information, technology component scanning, document verification, vulnerability scanning, and virus scanning.
[0108] In one example, the first verification unit 331 comprises:
[0109] The comparison sub-unit 3311 is configured to, if the current scanning type is a difference comparison type, according to the difference comparison type, schedule a preset scanning program corresponding to the difference comparison type, perform difference comparison on the product file and the product directory information in the parsing result information and the product file and the product directory information of the last historical version, and determine a range change list of the target product.
[0110] The determination sub-unit 3312 is configured to determine the verification scanning information according to the range change list.
[0111] In one example, the apparatus further comprises:
[0112] The sending module 41 is configured to, after performing parsing processing on the standard file under the directory structure in the submission-related information to obtain the parsing result information, send the parsing result information to the product file management module; the parsing result information is used to be associated with the version information of the target product.
[0113] The device of the embodiment can execute the technical solutions in the above method, and the specific implementation process and technical principles are the same, which will not be repeated here.
[0114] It should be noted that the division of each module of the above device is only a logical division of functions, and all or part of the physical entity can be integrated or physically separated when actually implemented. The modules can all be implemented in the form of software called by the processing element; all can be implemented in the form of hardware; some modules can be implemented in the form of software called by the processing element, and some modules can be implemented in the form of hardware. Each module can be a separately established processing element, or can be integrated in a chip of the above device, in addition, the functions of each module can also be stored in the memory of the above device in the form of program code, and called and executed by a processing element of the above device. In addition, all or part of the modules can be integrated together, or can be independently implemented. The processing element here can be an integrated circuit with signal processing capability. In the implementation process, each step of the above method or each module can be completed by the integrated logic circuit of hardware or the instruction of software in the processing element.
[0115] Figure 5 The structure schematic diagram of the electronic device provided by the embodiment of the present application is shown in FIG. 1. As shown in the figure, the electronic device can include a transceiver 121, a processor 122, and a memory 123. Figure 5
[0116] The processor 122 executes the computer execution instructions stored in the memory, so that the processor 122 executes the schemes in the above embodiments. The processor 122 can be a general-purpose processor, including a central processing unit CPU, a network processor NP, etc.; it can also be a digital signal processor DSP, an application-specific integrated circuit ASIC, a field programmable gate array FPGA or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component.
[0117] The memory 123 is connected with the processor 122 through a system bus and completes mutual communication, and the memory 123 is used for storing computer program instructions.
[0118] The transceiver 121 can be used to obtain a to-be-run task and configuration information of the to-be-run task.
[0119] The system bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The system bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is shown in the figure, but it does not mean that there is only one bus or only one type of bus. The transceiver is used to realize the communication between the database access device and other computers (such as clients, read-write libraries and read-only libraries). The memory can include random access memory (RAM) and can also include non-volatile memory.
[0120] The electronic device provided by the embodiment of the present application can be the terminal device of the above embodiment.
[0121] The embodiment of the present application further provides a chip for running instructions, which is used to execute the technical solutions of the enterprise product verification processing method in the above embodiment.
[0122] The embodiment of the present application further provides a computer readable storage medium, which stores computer instructions, and when the computer instructions are run on a computer, the computer executes the technical solutions of the enterprise product verification processing method in the above embodiment.
[0123] The embodiment of the present application further provides a computer program product, which includes a computer program stored in a computer readable storage medium, at least one processor can read the computer program from the computer readable storage medium, and when the at least one processor executes the computer program, the technical solutions of the enterprise product verification processing method in the above embodiment can be realized.
[0124] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the modules is only a logical function division, and actual implementation can have another division manner, for example, a plurality of modules can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed each other can be indirect coupling or communication connection through some interfaces, devices or modules, and can be electrical, mechanical or other forms.
[0125] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical units, i.e., may be located in one place, or may be distributed to multiple network units. Part or all of the modules can be selected according to actual needs to implement the embodiments of the present application.
[0126] In addition, the functional modules in each embodiment of the present application can be integrated in one processing unit, or each module can be physically present alone, or two or more modules can be integrated in one unit. The above-mentioned modules can be realized in the form of hardware or in the form of hardware plus software function modules.
[0127] The integrated modules realized in the form of software function modules can be stored in a computer readable storage medium. The software function modules stored in a storage medium include a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute part of the steps of the method of each embodiment of the present application.
[0128] It should be understood that the above-mentioned processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the application can be directly embodied as hardware processor execution or executed by a combination of hardware and software modules in the processor.
[0129] The memory can include a high-speed RAM memory, and can also include a non-volatile storage NVM, for example at least one disk memory, and can also be a U disk, a mobile hard disk, a read-only memory, a magnetic disk or an optical disk, etc.
[0130] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of the present application does not limit to only one bus or one type of bus.
[0131] The storage medium described above can be realized by any type of volatile or nonvolatile storage devices or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic storage, a flash memory, a magnetic disk or an optical disk. The storage medium can be any available medium that can be accessed by a general or special purpose computer.
[0132] An exemplary storage medium is coupled to the processor so that the processor can read information from, and write information to, the storage medium. Of course, the storage medium can be part of the processor. The processor and the storage medium can be located in an application specific integrated circuits (ASIC). Of course, the processor and the storage medium can exist as discrete components in an electronic control unit or a host device.
[0133] Those of ordinary skill in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by relevant hardware instructed by programs. The foregoing programs can be stored in a computer readable storage medium. When the programs are executed, the steps of the above-mentioned method embodiments are executed; and the foregoing storage medium includes various storage media that can store program codes, such as ROM, RAM, magnetic disks or optical disks.
[0134] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A method of verifying a business artifact, the method comprising: The method comprises the following steps: In response to an article submission event, determine submission-related information of a target article in the article submission event; wherein the article submission event is used to indicate that the target article is subjected to verification processing, and the submission-related information includes a directory structure of the target article and standard files under the directory structure; Perform parsing processing on the standard files under the directory structure in the submission-related information to obtain parsing result information; wherein the parsing result information includes article files and article directory information of the target article; According to a preset scanning type, dispatch a preset scanning program corresponding to the scanning type to perform verification scanning on the article files and the article directory information in the parsing result information, and determine and output a verification scanning report; wherein the scanning report includes scanning results of the target article in multiple scanning dimensions.
2. The method of claim 1, wherein, The parsing processing on the standard files under the directory structure in the submission-related information to obtain parsing result information comprises: Perform decompression processing on the standard files under the directory structure in the submission-related information to obtain decompressed article files under the directory structure; Generate parsing result information according to the decompressed article files; wherein the parsing result information includes the directory structure and the standard files under the directory structure of the target article before decompression, and the article files and the article directory information of the target article after decompression.
3. The method of claim 2, wherein, The verification scanning according to the preset scanning type to determine and output the verification scanning report comprises: According to a current preset scanning type, dispatch a preset scanning program corresponding to the current scanning type to perform verification scanning on the article files and the article directory information in the parsing result information to determine verification scanning information; wherein the verification scanning information includes information of multiple verification targets; According to a preset other scanning type, dispatch a preset scanning program corresponding to the other scanning type to perform verification scanning on the article files and the article directory information, and if it is determined that a repeated verification target exists, determine information of the repeated verification target as the verification scanning information, and perform verification scanning on other targets to obtain verification scanning information; Determine and output the verification scanning report according to the verification scanning information.
4. The method of claim 3, wherein, The preset scanning type includes any one or more of the following: Difference comparison of the parsing result information, technology component scanning, document verification, vulnerability scanning, and virus scanning.
5. The method of claim 4, wherein, The verification scanning according to the current preset scanning type to determine the verification scanning information comprises: If the current scan type is a difference comparison type, a preset scan program corresponding to the difference comparison type is dispatched according to the difference comparison type, and the product file and the product directory information in the analysis result information are compared with the product file and the product directory information of a previous historical version to determine a range change list of the target product. According to the range change list, verification scan information is determined.
6. The method according to any one of claims 1 to 5, characterized in that, After the standard files under the directory structure in the submission-related information are parsed to obtain analysis result information, the method further includes: The analysis result information is sent to a product file management module; wherein the analysis result information is used to be associated with version information of the target product.
7. An enterprise artifact verification processing apparatus, characterized by comprising: Comprise: A determination module is configured to determine submission-related information of a target product in a product submission event in response to the product submission event; wherein the product submission event is used to indicate that the target product is subjected to verification processing, and the submission-related information comprises a directory structure of the target product and standard files under the directory structure; An analysis module is configured to parse the standard files under the directory structure in the submission-related information to obtain analysis result information; wherein the analysis result information comprises product file and product directory information of the target product; A verification module is configured to dispatch a preset scan program corresponding to a preset scan type according to the scan type, and perform verification scanning on the product file and the product directory information in the analysis result information to determine and output a verification scan report; wherein the scan report comprises scan results of the target product in multiple scan dimensions.
8. An electronic device, comprising: Comprise: A processor, and a memory in communication connection with the processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory to implement the method in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method in any one of claims 1-6.
10. A computer program product, characterised in that, A computer program is executed by the processor to implement the method in any one of claims 1-6.
Citation Information
Patent Citations
Vulnerability scanning engine implementation method and device, vulnerability scanning method and electronic equipment
CN115544518A
File scanning method, file scanning apparatus, and terminal device
WO2020087356A1