LLM-based vulnerability risk repair method, apparatus and device, and storage medium

By applying the large language model (LLM) in vulnerability risk repair, the problem of overly generalized repair suggestions in the existing technology is solved, and efficient and accurate vulnerability repair solutions are achieved, reducing the repair cost.

CN120105424APending Publication Date: 2025-06-06INTEGRITY TECH GRP INC
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510025231.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-08
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Existing vulnerability risk fixation methods are based on rules and cannot fully consider the code context and business logic, resulting in the generated fixing suggestions that are too general to provide directly available code-level fixes.

Method used

Using a method based on the large language model (LLM), repair suggestions and code are generated through the LLM language model, combining the context of the vulnerable code and the characteristics of HTTP request packets and response packets, to accurately identify and provide targeted repair solutions.

Benefits of technology

It significantly improves the efficiency and accuracy of vulnerability risk repair, and the generated fix solutions are highly matched with the actual code scenarios, reducing the repair costs, and providing a more efficient and reliable vulnerability risk management solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105424A_ABST
    Figure CN120105424A_ABST
Patent Text Reader

Abstract

The invention provides an LLM-based vulnerability risk repairing method, device and equipment and a storage medium, the method comprises the steps that scanning data scanned by a vulnerability scanner is processed by a first cue word generator and then input into an LLM language large model, a repairing suggestion is generated, and the scanning data comprises a request packet sent by the vulnerability scanner and a response packet received by the vulnerability scanner; finding a code snippet with the vulnerability according to a code path where the vulnerability is located, processing the code snippet through a second cue word generator, inputting the processed code snippet into the LLM language large model, and generating a repair code; and formatting the repair suggestion and the repair code to generate a vulnerability repair scheme. According to the method, multi-dimensional features of vulnerability codes are deeply analyzed by using an LLM language large model, vulnerability risk points in the codes are accurately positioned, more targeted repair suggestions and repair codes are provided, it is ensured that a generated repair scheme is matched with an actual code scene, the vulnerability risk repair cost is reduced, and the repair efficiency is improved. And a more efficient and reliable vulnerability risk management solution is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software testing, and in particular to a vulnerability risk repair method, device, equipment and storage medium based on LLM. Background Art

[0002] With the continuous expansion of software development scale and the increasing complexity of application scenarios, security vulnerabilities in software systems have become a key factor threatening the security of information systems. Enterprises and organizations invest a lot of resources in vulnerability detection and vulnerability risk remediation every year, but the existing vulnerability risk remediation process still faces many challenges. At present, the vulnerability risk remediation solutions on the market generally adopt rule-based methods. This method usually matches the pre-written remediation template with the detected vulnerability type and then generates corresponding remediation suggestions. Although this method is simple and direct, it has obvious limitations. First, the pre-defined vulnerability risk remediation templates are often too general and cannot fully consider the code context, business logic and other characteristics of the specific project. Secondly, the templated suggestions are usually based on text descriptions. Simple templates are difficult to provide effective remediation guidance and lack targeted remediation code examples, which requires developers to invest extra time and energy to understand and implement remediation solutions. The root cause of these problems is that traditional rule-based detection methods lack the ability to deeply understand code semantics and business scenarios, resulting in overly general remediation suggestions. Due to the limitations of rule templates, it is impossible to generate code-level remediation solutions that can be directly used. Summary of the invention

[0003] In view of the above problems, an embodiment of the present invention provides a vulnerability risk repair method apparatus, device and storage medium based on LLM, which significantly improves the efficiency of vulnerability risk repair and reduces the cost of vulnerability risk repair through the code generation, code understanding and reasoning capabilities of a large language model, thereby providing a more efficient and reliable vulnerability risk management solution to solve existing technical problems.

[0004] In order to achieve the above technical effects, the present invention provides the following technical solutions:

[0005] In a first aspect, the present invention provides a vulnerability risk repair method based on LLM, the method comprising:

[0006] The scan data scanned by the vulnerability scanner is input into the LLM language model after being processed by the first prompt word generator to generate repair suggestions, wherein the scan data includes the request packet sent by the vulnerability scanner and the response packet received;

[0007] Find the vulnerable code snippet according to the code path where the vulnerability is located, process the code snippet through the second prompt word generator, and input it into the LLM language model to generate the repair code;

[0008] Format the repair suggestions and repair codes to generate vulnerability repair solutions.

[0009] In one embodiment, the scanning data scanned by the vulnerability scanner is processed by the first prompt word generator and then input into the LLM language model to obtain the repair suggestion and the code path where the vulnerability is located, including:

[0010] Inputting the scanned data into a first prompt word generator;

[0011] A first prompt word generator generates a first prompt word related to the vulnerability through a first prompt word template;

[0012] The first prompt word is input into the LLM language model to generate a repair suggestion.

[0013] In one embodiment, the method of finding a code snippet with a vulnerability according to the code path where the vulnerability is located, inputting the code snippet into the LLM language model after being processed by the second prompt word generator, and generating a repair code includes:

[0014] Infer the code path where the vulnerability is located based on the request path information in the request packet;

[0015] Find the corresponding code snippet according to the code path where the vulnerability is located as the vulnerable code snippet;

[0016] Enter the vulnerable code snippet into the second prompt word generator;

[0017] The second prompt word generator generates a second prompt word related to the code vulnerability through a second prompt word template;

[0018] The second prompt word is input into the LLM language model to generate the repair code.

[0019] In one embodiment, formatting the repair suggestion and the repair code to generate a vulnerability repair solution includes:

[0020] Formatting the repair suggestions to generate vulnerability repair content guidance, wherein the vulnerability repair content guidance includes repair principles, precautions, and potential impacts;

[0021] Formatting the repair code to generate a repair code example, wherein the repair code example includes a comparison of codes before and after modification, a code modification position, and comments on the modification points;

[0022] Use vulnerability repair content guidance and repair code examples as vulnerability repair solutions.

[0023] In a second aspect, the present invention provides a vulnerability risk repair device based on LLM, the device comprising:

[0024] The first LLM interaction module is used to input the scan data scanned by the vulnerability scanner into the LLM language model after being processed by the first prompt word generator to generate repair suggestions, wherein the scan data includes the request packet sent by the vulnerability scanner and the response packet received;

[0025] The second LLM interaction module is used to find the vulnerable code snippet according to the code path where the vulnerability is located, and input the code snippet into the LLM language model after being processed by the second prompt word generator to generate the repair code;

[0026] Repair plan output module: formats the repair suggestions and repair codes to generate vulnerability repair plans.

[0027] In one embodiment, the first LLM interaction module is specifically used for:

[0028] Inputting the scanned data into a first prompt word generator;

[0029] A first prompt word generator generates a first prompt word related to the vulnerability through a first prompt word template;

[0030] The first prompt word is input into the LLM language model to generate a repair suggestion.

[0031] In one embodiment, the first LLM interaction module is specifically used for:

[0032] Infer the code path where the vulnerability is located based on the request path information in the request packet;

[0033] Find the corresponding code snippet according to the code path where the vulnerability is located as the vulnerable code snippet;

[0034] Enter the vulnerable code snippet into the second prompt word generator;

[0035] The second prompt word generator generates a second prompt word related to the code vulnerability through a second prompt word template;

[0036] The second prompt word is input into the LLM language model to generate the repair code.

[0037] In one embodiment, the repair solution output module is specifically used to:

[0038] Formatting the repair suggestions to generate vulnerability repair content guidance, wherein the vulnerability repair content guidance includes repair principles, precautions, and potential impacts;

[0039] Formatting the repair code to generate a repair code example, wherein the repair code example includes a comparison of codes before and after modification, a code modification position, and comments on the modification points;

[0040] Use vulnerability repair content guidance and repair code examples as vulnerability repair solutions.

[0041] In a third aspect, the present invention provides an electronic device, comprising: a processor and a memory;

[0042] The memory is used to store computer programs;

[0043] The processor is used to execute a vulnerability risk repair method based on LLM provided in any one of the first aspects by calling the computer program.

[0044] In a fourth aspect, the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium includes a program, and when the program is executed by a processor, the program is used to implement an LLM-based vulnerability risk repair method provided in any one of the first aspects.

[0045] The beneficial effects of the present invention are as follows: the scan data obtained by the vulnerability scanner, including the request packets sent and the response packets received, are input into the LLM language model to generate repair suggestions after being processed by the first prompt word generator. Then, according to the code path where the vulnerability is located, the code fragment containing the vulnerability is located, and after being processed by the second prompt word generator, it is input into the LLM language model again to generate the repair code. After that, the repair suggestions and repair codes are formatted to form a complete vulnerability repair solution. Using the LLM language model, in-depth analysis is performed in combination with the context of the vulnerability code and the characteristics of the HTTP request packet, response packet, etc., to accurately identify the vulnerability risk points in the code, and provide targeted repair suggestions and executable repair codes. This ensures that the generated repair solution is highly matched with the actual code scenario, thereby reducing the cost of vulnerability risk repair and providing a more efficient and reliable vulnerability risk management solution. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 The figure is a schematic flow chart of a vulnerability risk repair method based on LLM provided by an embodiment of the present invention;

[0047] Figure 2 FIG. 1 is a schematic diagram of the structure of a vulnerability risk repair device based on LLM provided by an embodiment of the present invention;

[0048] Figure 3 FIG. 1 is a schematic structural diagram of an electronic device in an embodiment of the present invention. DETAILED DESCRIPTION

[0049] In order to make the purpose, technical solution and advantages of the present invention clearer and more understandable, the present invention is further described below in conjunction with the accompanying drawings and specific implementation methods. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0050] Based on the shortcomings of the prior art, the embodiment of the present invention provides a specific implementation of a vulnerability risk repair method based on LLM, such as Figure 1 As shown, the method comprises the following steps:

[0051] S110: The scan data scanned by the vulnerability scanner is input into the LLM language model after being processed by the first prompt word generator to generate repair suggestions, wherein the scan data includes the request packet sent by the vulnerability scanner and the response packet received.

[0052] During the working process, the vulnerability scanner sends test requests in the form of request packets, receives returned response packets, analyzes the request packets (such as the request method, URL, request parameters, and request header information, etc.) and response codes (such as status codes, error information in the response body, and returned data format, etc.) to find out anomalies that may be related to vulnerabilities.

[0053] When the vulnerability scanner finds a vulnerability, it will input the scanning data (i.e., the request packet and the response packet) into the first prompt word generator, which will generate the first prompt word related to the vulnerability through the first prompt word template. First, the first prompt word template describes the contextual basic information of the request packet and the response code, such as "Currently analyzing the vulnerability repair problem of (system name / application name), the known request packet information is as follows: List the key contents of the request packet in detail (such as the request method, URL, and the specific configuration of the request parameters)" and "The corresponding response packet information is: (list the key of the response packet in detail, such as the specific status code and the specific response body content)"; secondly, the first prompt word template analyzes the vulnerability characteristics from the dimensions of the request packet and the response packet, such as "From the request packet point of view (point out the suspected problem in the request packet)" and "The error code and error message presented in the response packet suggest that there may be a guess about the type of vulnerability"; finally, the first prompt word template generates a demand guide, such as "Please provide repair suggestions for the above suspected vulnerabilities, including but not limited to how to verify the code layer, how to adjust the server configuration, and how to prevent vulnerability exploitation." Taking SQL injection vulnerability as an example, the first prompt word generated is as follows: "Currently analyzing the vulnerability repair problem of XX management system, the known request package information is as follows: the request method is GET, the URL is / orders / search?order_id=123'OR 1=1--, and the request header contains common browser logos and other general information. The corresponding response package information is: status code 500Internal Server Error, and the response body contains 'You have an error in yourSQL syntax'. From the request package, the input of the parameter 'order_id' contains a SQL injection attack feature string, which is suspected to use single quotes to close the original query conditions and inject malicious logic. The SQL syntax error presented in the response package suggests that there may be a SQL injection vulnerability. Please provide repair suggestions for the above suspected vulnerabilities, including but not limited to how to strictly check and filter the 'order_id' parameter in the backend code (using Java language, based on the Spring Boot framework), how to configure the database connection pool and related SQL query execution components to prevent SQL injection attacks, and whether it is necessary to introduce professional SQL anti-injection middleware. If necessary, please explain the selection and configuration details."

[0054] The first prompt word is input into the LLM language model, and the LLM language model uses its own understanding and reasoning ability of the vulnerability to output repair suggestions.

[0055] During the pre-training phase, the LLM language model is exposed to a large amount of text data, including knowledge about computer security, programming, software systems, etc. When the first prompt word is input, this knowledge can be used to generate repair suggestions.

[0056] S120: Find the code snippet with the vulnerability according to the code path where the vulnerability is located, input the code snippet into the LLM language model after being processed by the second prompt word generator, and generate the repair code.

[0057] The code path where the vulnerability is located can be inferred based on the request path information in the request package by understanding the request path structure, combining the application technology stack, checking the routing configuration file, tracking code resource references and call relationships, and using logs and debugging information.

[0058] Developers can find the corresponding code snippet as the vulnerable code snippet based on the code path where the vulnerability is located.

[0059] The code snippet with the vulnerability is input into the second prompt word generator. First, the second prompt word template describes the basic information of the code snippet, such as "the function implemented by the code snippet and its implementation principle, focusing on the interactive part of the code snippet, especially the security risks of the code"; secondly, the second prompt word template points out the details of the vulnerability, such as "the specific line of code in the code snippet that causes the vulnerability, and explain why this line of code is vulnerable to attack"; finally, the second prompt word template generates a repair guide, such as "based on the vulnerability pointed out in the code snippet, please give at least one feasible repair suggestion, and explain in detail the specific implementation steps of the repair method at the code level, and compare the code logic before and after the repair, and explain how the repair code effectively prevents the vulnerability." The generated second prompt word example is as follows: "Please describe the main function of this code and point out the possible types of vulnerabilities. The code is as follows: {code snippet} or for (code language) code (code snippet), analyze its purpose and identify potential security vulnerabilities in the device, such as SQL injection."

[0060] The second prompt word is input into the LLM language model to generate the repair code.

[0061] The LLM language model has been trained with a large amount of text (including code-related content) and can understand the grammatical rules and programming patterns of programming languages. When the second prompt word is entered, it can generate repair code based on the understanding of correct programming practices.

[0062] S130: Formatting the repair suggestion and the repair code to generate a vulnerability repair plan.

[0063] The repair suggestions are formatted to generate vulnerability repair content guidance, which includes repair principles, precautions and potential impacts. The repair principle refers to explaining the relationship between the root cause of the vulnerability and the repair method, the precautions refer to listing the key points of the repair method, and the potential impact refers to analyzing the scope that the repair operation may affect.

[0064] The repair code is formatted to generate a repair code example, which includes a code comparison before and after modification, a code modification location, and comments on the modification points.

[0065] Receive the fixed code and add comments next to the modified parts of the fixed code relative to the original code, explaining what changes were made and why the changes were made. Use a table to show the code comparison before and after the modification or use comments in the code block to distinguish the parts before and after the modification.

[0066] Finally, the vulnerability repair content guidance and repair code examples are used as the vulnerability repair plan, so that the vulnerability repair plan is presented to users in a clear and easy-to-read form, helping them to quickly understand and implement the repair work.

[0067] In the present invention, the scanning data obtained by the vulnerability scanner, including the request packets sent and the response packets received, are input into the LLM language model after being processed by the first prompt word generator to generate repair suggestions. Subsequently, based on the code path where the vulnerability is located, the code fragment containing the vulnerability is accurately located, and after being processed by the second prompt word generator, it is input into the LLM language model again to generate repair code. Afterwards, the repair suggestions and repair codes are formatted to form a complete vulnerability repair solution. Using the LLM language model, in-depth analysis is performed in combination with the context of the vulnerability code and the characteristics of the HTTP request packet, response packet, etc., to accurately identify the vulnerability risk points in the code, and provide targeted repair suggestions and executable repair codes. This ensures that the generated repair solution is highly matched with the actual code scenario, thereby reducing the cost of vulnerability risk repair and providing a more efficient and reliable vulnerability risk management solution.

[0068] Based on the same inventive concept, the embodiment of the present application also provides a vulnerability risk repair device based on LLM, which can be used to implement a vulnerability risk repair method based on LLM described in the above embodiment, as described in the following embodiment. Since the principle of solving the problem by a vulnerability risk repair device based on LLM is similar to that of a vulnerability risk repair method based on LLM, the implementation of a vulnerability risk repair device based on LLM can refer to the implementation of a vulnerability risk repair method based on LLM, and the repeated parts will not be repeated. As used below, the term "unit" or "module" can be a combination of software and / or hardware that implements a predetermined function. Although the system described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceived.

[0069] The present invention provides a vulnerability risk repair device based on LLM, such as Figure 2 The device shown comprises:

[0070] The first LLM interaction module 210 is used to input the scan data scanned by the vulnerability scanner into the LLM language model after being processed by the first prompt word generator to generate repair suggestions. The scan data includes the request packet sent by the vulnerability scanner and the response packet received;

[0071] The second LLM interaction module 220 is used to find the vulnerable code fragment according to the code path where the vulnerability is located, and input the code fragment into the LLM language model after being processed by the second prompt word generator to generate a repair code;

[0072] Repair solution output module 230: formats the repair suggestion and the repair code to generate a vulnerability repair solution.

[0073] In one embodiment of the present invention, the first LLM interaction module 210 is specifically used for:

[0074] Inputting the scanned data into a first prompt word generator;

[0075] A first prompt word generator generates a first prompt word related to the vulnerability through a first prompt word template;

[0076] The first prompt word is input into the LLM language model to generate a repair suggestion.

[0077] In an embodiment of the present invention, the first LLM interaction module 220 is specifically used for:

[0078] Infer the code path where the vulnerability is located based on the request path information in the request packet;

[0079] Find the corresponding code snippet according to the code path where the vulnerability is located as the vulnerable code snippet;

[0080] Enter the vulnerable code snippet into the second prompt word generator;

[0081] The second prompt word generator generates a second prompt word related to the code vulnerability through a second prompt word template;

[0082] The second prompt word is input into the LLM language model to generate the repair code.

[0083] In one embodiment of the present invention, the repair solution output module 230 is specifically used to:

[0084] Format the repair suggestions and generate vulnerability repair content guidance, which includes repair principles, precautions and potential impacts;

[0085] Format the repair code and generate a repair code example, which includes a code comparison before and after the modification, the code modification location, and comments on the modification points;

[0086] Use vulnerability repair content guidance and repair code examples as vulnerability repair solutions.

[0087] The embodiment of the present application also provides a specific implementation of an electronic device that can implement all the steps in the vulnerability risk repair method based on LLM in the above embodiment, see Figure 3 , the electronic device 300 specifically includes the following contents:

[0088] Processor 310, memory 320, communication unit 330 and bus 340;

[0089] The processor 310 , the memory 320 , and the communication unit 330 communicate with each other via the bus 340 ; the communication unit 330 is used to implement information transmission between server-side devices and terminal devices and other related devices.

[0090] The processor 310 is used to call the computer program in the memory 320. When the processor executes the computer program, all steps of the vulnerability risk repair method based on LLM in the above embodiment are implemented.

[0091] Those skilled in the art should understand that the memory may be, but is not limited to, a random access memory (RAM), a read only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), etc. The memory is used to store programs, and the processor executes the programs after receiving the execution instruction. Furthermore, the software programs and modules in the above-mentioned memory may also include an operating system, which may include various software components and / or drivers for managing system tasks (such as memory management, storage device control, power management, etc.), and may communicate with various hardware or software components to provide an operating environment for other software components.

[0092] The processor may be an integrated circuit chip having the ability to process signals. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc. The methods, steps, and logic block diagrams disclosed in the embodiments of the present application may be implemented or executed. The general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc.

[0093] The present application also provides a computer-readable storage medium, which includes a program. When the program is executed by a processor, it is used to execute an LLM-based vulnerability risk repair method provided by any of the aforementioned method embodiments.

[0094] Those skilled in the art should understand that all or part of the steps of implementing the above-mentioned method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the steps of the above-mentioned method embodiments are executed; and the aforementioned storage medium includes: ROM, RAM, magnetic disk or optical disk, etc., various media that can store program codes, and the specific media type is not limited in this application.

[0095] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed by the present invention should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.

Claims

1. A vulnerability risk repair method based on LLM, characterized in that: The method comprises: The scan data scanned by the vulnerability scanner is input into the LLM language model after being processed by the first prompt word generator to generate repair suggestions, wherein the scan data includes the request packet sent by the vulnerability scanner and the response packet received; Find the vulnerable code snippet according to the code path where the vulnerability is located, process the code snippet through the second prompt word generator, and input it into the LLM language model to generate the repair code; Format the repair suggestions and repair codes to generate vulnerability repair solutions.

2. The LLM-based vulnerability risk repair method according to claim 1, characterized in that: The scanning data scanned by the vulnerability scanner is processed by the first prompt word generator and then input into the LLM language model to obtain the repair suggestion and the code path where the vulnerability is located, including: Inputting the scanned data into a first prompt word generator; A first prompt word generator generates a first prompt word related to the vulnerability through a first prompt word template; The first prompt word is input into the LLM language model to generate a repair suggestion.

3. The LLM-based vulnerability risk repair method according to claim 1, characterized in that: The method of finding a code snippet with a vulnerability according to the code path where the vulnerability is located, inputting the code snippet into the LLM language model after being processed by the second prompt word generator, and generating a repair code includes: Infer the code path where the vulnerability is located based on the request path information in the request packet; Find the corresponding code snippet according to the code path where the vulnerability is located as the vulnerable code snippet; Enter the vulnerable code snippet into the second prompt word generator; The second prompt word generator generates a second prompt word related to the code vulnerability through a second prompt word template; The second prompt word is input into the LLM language model to generate the repair code.

4. The LLM-based vulnerability risk repair method according to claim 1, characterized in that: The formatting of the repair suggestions and repair codes to generate the vulnerability repair solution includes: Formatting the repair suggestions to generate vulnerability repair content guidance, wherein the vulnerability repair content guidance includes repair principles, precautions, and potential impacts; Formatting the repair code to generate a repair code example, wherein the repair code example includes a comparison of codes before and after modification, a code modification position, and comments on the modification points; Use vulnerability repair content guidance and repair code examples as vulnerability repair solutions.

5. A vulnerability risk repair device based on LLM, characterized in that: The device comprises: The first LLM interaction module is used to input the scan data scanned by the vulnerability scanner into the LLM language model after being processed by the first prompt word generator to generate repair suggestions, wherein the scan data includes the request packet sent by the vulnerability scanner and the response packet received; The second LLM interaction module is used to find the vulnerable code snippet according to the code path where the vulnerability is located, and input the code snippet into the LLM language model after being processed by the second prompt word generator to generate the repair code; Repair plan output module: formats the repair suggestions and repair codes to generate vulnerability repair plans.

6. The LLM-based vulnerability risk repair device according to claim 5, characterized in that: The first LLM interaction module is specifically used for: Inputting the scanned data into a first prompt word generator; A first prompt word generator generates a first prompt word related to the vulnerability through a first prompt word template; The first prompt word is input into the LLM language model to generate a repair suggestion.

7. The LLM-based vulnerability risk repair device according to claim 5, characterized in that: The first LLM interaction module is specifically used for: Infer the code path where the vulnerability is located based on the request path information in the request packet; Find the corresponding code snippet according to the code path where the vulnerability is located as the vulnerable code snippet; Enter the vulnerable code snippet into the second prompt word generator; The second prompt word generator generates a second prompt word related to the code vulnerability through a second prompt word template; The second prompt word is input into the LLM language model to generate the repair code.

8. The LLM-based vulnerability risk repair device according to claim 5, characterized in that: The repair solution output module is specifically used for: Formatting the repair suggestions to generate vulnerability repair content guidance, wherein the vulnerability repair content guidance includes repair principles, precautions, and potential impacts; Formatting the repair code to generate a repair code example, wherein the repair code example includes a comparison of codes before and after modification, a code modification position, and comments on the modification points; Use vulnerability repair content guidance and repair code examples as vulnerability repair solutions.

9. An electronic device, characterized in that: include: Processor and memory; The memory is used to store computer programs; The processor is used to execute the LLM-based vulnerability risk repair method according to any one of claims 1 to 4 by calling the computer program.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a program, which, when executed by a processor, is used to implement a vulnerability risk repair method based on LLM as described in any one of claims 1 to 4.

Citation Information

Cited By

  • Code scanning analysis method and system based on large model

    CN120893046A