Software supply chain security analysis method
By collecting and analyzing the historical security risks and real-time behavioral data of the software supply chain, combining machine learning and knowledge graph technology, the problem of running-time threats in the existing technology is solved, and comprehensive security guarantees for the software supply chain are achieved.
Patent Information
- Application Number
- CN202510319551.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-03-18
AI Technical Summary
The existing technology is difficult to detect runtime threats in the software supply chain such as zero-day vulnerabilities and hidden backdoors, and fails to effectively quantify historical security risks, resulting in incomplete risk assessment and undynamic adjustment of defense strategies.
By collecting data from components of the software supply chain, calculating historical security risk weights, combining real-time behavioral data for correlation analysis, using machine learning and knowledge graph technology for abnormal detection and threat tracing, generating security situation awareness reports, and dynamically adjusting defense strategies.
It significantly improves the coverage and accuracy of threat detection, can detect dynamic threats that cannot be detected by static analysis, realizes intelligent risk assessment and dynamic defense, and improves the system's adaptability.
Smart Images

Figure CN120234808A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of software security, and particularly to a method for analyzing software supply chain security. Background Art
[0002] With the globalization and complexity of the software supply chain, there are more and more third-party components, open-source libraries, suppliers, etc. involved in the software development and delivery process. The supply chain security problem is becoming increasingly prominent. Attackers may implant malicious code, exploit unpatched vulnerabilities or introduce non-compliant components through a certain link in the supply chain, thus posing a serious threat to the entire system. Traditional supply chain security analysis methods mainly rely on static code analysis, vulnerability scanning and compliance checking;
[0003] However, although the existing methods can discover known security problems, the existing technologies are often static analysis and are difficult to discover threats that are only exposed during runtime, such as zero-day vulnerabilities, hidden backdoors, etc. At the same time, historical security risks are also ignored. The historical security problems of the components of the supply chain, such as vulnerabilities and malicious code records, are not quantified or incorporated into the analysis model, resulting in incomplete risk assessment;
[0004] In addition, the existing methods usually rely on manual analysis or simple log correlation, and it is difficult to accurately identify the attack paths in the supply chain. Moreover, traditional defense strategies are usually static and cannot be dynamically adjusted according to real-time threats.
[0005] Therefore, it is necessary to propose a method for analyzing software supply chain security to solve the above problems. Summary of the Invention
[0006] The main object of the present invention is to provide a method for analyzing software supply chain security, which can effectively solve the problems in the background art.
[0007] To achieve the above object, the technical solution adopted by the present invention is as follows:
[0008] A method for analyzing software supply chain security includes the following steps:
[0009] S1: Collect data on the components of the software supply chain, and calculate the historical security risk weights for each component in the supply chain. If a security problem has occurred in a certain component of the supply chain, calculate its weight value according to the severity and frequency of the security problem;
[0010] S2: Collect the behavior data of the software during runtime, and perform correlation analysis in combination with the supply chain data;
[0011] S3: Preprocess the collected behavior data and supply chain data, and extract key features;
[0012] S4: Use machine learning algorithms, combined with historical security risk weights, to detect abnormal behaviors during software operation;
[0013] The specific implementation steps are as follows. S41: Use historical normal behavior data to train a machine learning model;
[0014] S42: Input the behavior characteristics collected in real time into the trained model for anomaly detection;
[0015] S43: Combine the historical security risk weights of the components of the supply chain to adjust the sensitivity of anomaly detection. For components with higher historical security risk weights, increase the sensitivity of anomaly detection. For components with lower historical security risk weights, reduce the sensitivity of anomaly detection;
[0016] S44: The model outputs the probability value of abnormal behavior. If it exceeds the set threshold, it is determined as abnormal behavior;
[0017] S5: Through knowledge graph technology, conduct traceability analysis on the detected abnormal behaviors, and combine historical security risk weights to identify potential supply chain attack paths;
[0018] S6: Based on the results of abnormal behavior detection and threat traceability, generate a security situation awareness report for the software supply chain and conduct real-time early warning;
[0019] S7: Dynamically adjust the defense strategy according to the results of security situation awareness and conduct emergency response.
[0020] Preferably, in step S1, the components of the software supply chain include third-party suppliers, dependencies, intellectual property structures, and vulnerability information. The specific data collected for each component are as follows:
[0021] Third-party supplier information: the name of the supplier, historical security records, and compliance;
[0022] Dependencies: the dependencies between software components, including open-source components and third-party libraries;
[0023] Intellectual property structure: the intellectual property information of the software, including licenses and copyrights;
[0024] Vulnerability information: known vulnerability information, including CVE numbers and vulnerability severity;
[0025] The weight value calculation formula is: H i = α·S i + β·F i , where H i is the historical security risk weight of the i-th supply chain component, S i is the severity of the historical security event of the i-th supply chain component, Fi The occurrence frequency of historical security events for the i-th supply chain component, where α and β are weight coefficients used to adjust the impacts of severity and frequency, and α + β = 1.
[0026] Preferably, in step S2, the specific implementation steps for collecting the behavioral data of the software during operation and conducting correlation analysis in combination with the supply chain data are as follows:
[0027] S21: Deploy a lightweight monitoring agent in the target system to capture the runtime behavior of the software in real time;
[0028] S22: The monitoring agent captures the system calls, network communications, and file operation behaviors of the software through system hook technology;
[0029] S23: Correlate the captured behavioral data with the supply chain data to analyze the relationship between the runtime behavior of the software and the supply chain components;
[0030] The formula for collecting behavioral data is:
[0031] D runtime ={d1, d2, …, d n}, where D runtime is the runtime behavior data set, and d i is the i-th behavioral data point, including timestamp, behavior type, and behavior parameter information.
[0032] Preferably, in step S3, the specific implementation steps for preprocessing the collected behavioral data and supply chain data and extracting key features are as follows:
[0033] S31: Clean the original behavioral data and supply chain data to remove noise and redundant information;
[0034] S32: Use feature engineering methods to extract the features of the behavioral data;
[0035] S33: Combine the supply chain data to extract the features related to the supply chain components;
[0036] S34: Vectorize the extracted features to form a feature matrix;
[0037] The formula for feature extraction is: F = {f1, f2, …, f m}, where F is the feature matrix and f i is the i-th feature vector, including behavioral features and supply chain features.
[0038] Preferably, the features extracted from the behavioral data include system call frequency, network communication patterns, and file operation sequences;
[0039] Extracting features related to supply chain components includes relying on the usage frequency of components and the historical security records of suppliers.
[0040] Preferably, in step S4, the anomaly detection formula is:
[0041] Where P(y = 1|F, H) is the probability that the behavior data F and the historical security risk weight H belong to abnormal behavior, θ and b are model parameters, and γ is the influence coefficient of the historical security risk weight.
[0042] Preferably, the implementation steps of step S5 include:
[0043] S51: Construct a software supply chain knowledge graph;
[0044] S52: Associate the detected abnormal behavior with the nodes in the knowledge graph and analyze possible attack paths;
[0045] S53: Reason about the knowledge graph through a graph neural network, and combine with the historical security risk weight to identify potential sources of supply chain attacks;
[0046] S54: Conduct more in-depth analysis and detection for supply chain components with higher historical security risk weights;
[0047] The knowledge graph reasoning formula is: Where H graph (l) is the node feature matrix of the l-th layer, A~ is the adjacency matrix, D~ is the degree matrix, W (l) is the weight matrix, and σ is the activation function.
[0048] Preferably, the implementation steps of step S6 include:
[0049] S61: Conduct a comprehensive analysis of the abnormal behavior detection results and threat tracing results to generate a security situation awareness report;
[0050] S62: Trigger different levels of warning mechanisms according to the severity of the threat and the historical security risk weight;
[0051] S63: Push the warning information to relevant security management personnel in real time and provide countermeasure suggestions;
[0052] The security situation scoring formula is: Where S is the security situation score, w i is the weight of the i-th threat, s i is the severity score of the i-th threat, H j is the historical security risk weight of the j-th supply chain component, h jThe historical security issue score for the j-th supply chain component.
[0053] Preferably, the implementation steps of step S7 include:
[0054] S71: Dynamically adjust the security policy of the system according to the security posture score;
[0055] S72: Trigger the emergency response mechanism for detected severe threats, especially for supply chain components with a relatively high historical security risk weight, isolate the affected software components, and perform repairs;
[0056] S73: Record the processing process of the entire security incident to form a security incident report for subsequent analysis;
[0057] The dynamic defense strategy adjustment formula is: R = α·S + β·T + λ·H, where R is the adjustment intensity of the defense strategy, S is the security posture score, T is the urgency of the threat, H is the historical security risk weight, and α, β, γ are weight coefficients.
[0058] Preferably, in step S51, constructing the software supply chain knowledge graph includes software components, dependency relationships, supplier information, and historical security risk weights.
[0059] Compared with the prior art, the present invention provides a software supply chain security analysis method, which has the following beneficial effects:
[0060] This software supply chain security analysis method can discover runtime threats that cannot be detected by static analysis, such as zero-day vulnerabilities and hidden backdoor threats, through dynamic behavior analysis, significantly improving the coverage rate of threat detection. At the same time, it introduces the historical security risk weight to quantify the historical security issues of supply chain components, combines knowledge graph and graph neural network technologies to achieve intelligent risk assessment and threat traceability, dynamically adjusts the defense strategy based on the security posture score and historical security risk weight, and improves the adaptive ability of the system. In addition, by adjusting the sensitivity of the anomaly detection model in combination with the historical security risk weight, it can effectively reduce the false alarm and missed alarm rates and improve the detection accuracy. It covers all aspects of supply chain security from data collection, anomaly detection, threat traceability to dynamic defense, forming a complete solution, and can comprehensively ensure the security of the software supply chain. BRIEF DESCRIPTION OF THE DRAWINGS
[0061] Figure 1 It is the flowchart of the steps of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0062] To make the technical means, creative features, achieved purposes and effects of the present invention easy to understand, the present invention will be further described below in conjunction with specific embodiments.
[0063] As Figure 1 shown, a software supply chain security analysis method includes the following steps:
[0064] Step 1: Collect data on the components of the software supply chain. The components of the software supply chain include third-party suppliers, dependencies, intellectual property structures, vulnerability information, etc. Specifically, the data collected from the software supply chain is as follows:
[0065] Third-party supplier information: the name of the supplier, historical security records, compliance;
[0066] Dependencies: the dependencies between software components, including open-source components and third-party libraries;
[0067] Intellectual property structure: the intellectual property information of the software, including licenses, copyrights, etc.;
[0068] Vulnerability information: known vulnerability information, including CVE numbers, vulnerability severity, etc.
[0069] The data collection formula is: D supply ={d1, d2, …, d n} where D supply is the supply chain dataset, and d i is the data of the i-th supply chain component, including supplier information, dependencies, intellectual property structure, and vulnerability information;
[0070] Then calculate the historical security risk weight H for each component. If a security problem (such as a vulnerability or malicious code implantation) has occurred in a component of a supply chain, calculate its weight value according to the severity and frequency of the security problem;
[0071] The calculation formula is: H i =α·S i +β·F i where H i is the historical security risk weight of the i-th supply chain component, S i is the severity of the historical security event of the i-th supply chain component, F i is the frequency of the historical security event of the i-th supply chain component, and α and β are weight coefficients used to adjust the influence of severity and frequency, and α + β = 1;
[0072] Specifically, for vulnerability severity: for known vulnerabilities (CVE vulnerabilities), directly use the CVSS score as a measure of severity. The CVSS score ranges from 0 to 10, and the higher the score, the higher the severity of the vulnerability;
[0073] Regarding the severity of malicious code incidents: For malicious code implantation incidents, a score can be assigned based on their scope of impact, degree of damage, and difficulty of repair.
[0074] Specifically:
[0075] Scope of impact: Whether it affects multiple systems or users.
[0076] Degree of damage: Whether it results in serious consequences such as data leakage or system crashes.
[0077] Difficulty of repair: Whether a large amount of resources or time is required for repair.
[0078] Regarding the severity of compliance issues: For compliance issues (license conflicts, intellectual property disputes), a score can be assigned based on their legal risks and economic losses.
[0079] Specifically:
[0080] Legal risk: Whether it may lead to litigation or fines.
[0081] Economic loss: Whether it may result in significant financial losses.
[0082] Finally, if a component is involved in multiple types of security incidents (vulnerabilities, malicious code, compliance issues), its severity can be weighted and summed to obtain a comprehensive score.
[0083] Step 2: Collect the behavioral data of the software during runtime and perform correlation analysis in combination with supply chain data;
[0084] The specific implementation steps are as follows: Step 21: Deploy a lightweight monitoring agent in the target system to capture the runtime behavior of the software in real-time;
[0085] Step 22: The monitoring agent captures the system calls, network communications, and file operation behaviors of the software through system hook technology;
[0086] Step 23: Correlate the captured behavioral data with the supply chain data to analyze the relationship between the runtime behavior of the software and the components of the supply chain;
[0087] The formula for collecting behavioral data is: D runtime ={d1, d2, …, d n}, where D runtime is the dataset of runtime behavior, and d i is the i-th behavioral data point, which includes timestamp, behavior type, and behavior parameter information.
[0088] Step 3: Preprocess the collected behavioral data and supply chain data and extract key features;
[0089] The specific implementation steps are as follows:
[0090] Step 31: Clean the original behavior data and supply chain data to remove noise and redundant information;
[0091] Step 32: Use feature engineering methods to extract features of the behavior data. The features of the behavior data include system call frequency, network communication pattern, and file operation sequence;
[0092] Step 33: Combine the supply chain data to extract features related to the components of the supply chain. The features related to the components of the supply chain include the usage frequency of dependent components and the historical security records of suppliers;
[0093] Step 34: Vectorize the extracted features to form a feature matrix;
[0094] The feature extraction formula is: F = {f1, f2,..., f m}, where F is the feature matrix, and f i is the i-th feature vector, which includes behavior features and supply chain features.
[0095] Step 4: Use machine learning algorithms and combine historical security risk weights to detect abnormal behaviors during software operation;
[0096] The specific implementation steps are as follows:
[0097] Step 41: Use historical normal behavior data to train a machine learning model, preferably an isolation forest, support vector machine, or deep learning model;
[0098] Step 42: Input the behavior features collected in real-time into the trained model for anomaly detection;
[0099] Step 43: Combine the historical security risk weights of the components of the supply chain to adjust the sensitivity of anomaly detection. For components with higher historical security risk weights, increase the sensitivity of anomaly detection (i.e., lower the detection threshold), and for components with lower historical security risk weights, decrease the sensitivity of anomaly detection (i.e., raise the detection threshold);
[0100] Step 44: The model outputs the probability value of abnormal behavior, and those exceeding the set threshold are determined to be abnormal behaviors;
[0101] The anomaly detection formula is: where P(y = 1|F, H) is the probability that the behavior data F and the historical security risk weight H belong to abnormal behaviors, θ and b are model parameters, and γ is the influence coefficient of the historical security risk weight.
[0102] Step 5: Through knowledge graph technology, conduct traceability analysis on the detected abnormal behaviors, and combine historical security risk weights to identify potential supply chain attack paths;
[0103] The implementation steps include:
[0104] Step 51: Construct a software supply chain knowledge graph, including software components, dependency relationships, supplier information, and historical security risk weights;
[0105] Step 52: Associate the detected abnormal behaviors with the nodes in the knowledge graph and analyze possible attack paths;
[0106] Step 53: Reason about the knowledge graph through a graph neural network, and combine historical security risk weights to identify potential supply chain attack sources;
[0107] Step 54: Conduct more in-depth analysis and detection on the supply chain components with higher historical security risk weights;
[0108] The knowledge graph reasoning formula is: where \(H\) graph (l) is the node feature matrix of the \(l\)-th layer, is the adjacency matrix, is the degree matrix, \(W\) (l) is the weight matrix, and \(\sigma\) is the activation function.
[0109] Step 6: Based on the abnormal behavior detection and threat traceability results, generate a security situation awareness report for the software supply chain and conduct real-time early warning;
[0110] The implementation steps include:
[0111] Step 61: Conduct comprehensive analysis on the abnormal behavior detection results and threat traceability results to generate a security situation awareness report;
[0112] Step 62: Trigger different levels of early warning mechanisms (low, medium, high) according to the severity of the threat and historical security risk weights;
[0113] Step 63: Push the early warning information to relevant security management personnel in real time and provide coping suggestions;
[0114] The security situation scoring formula is: where \(S\) is the security situation score, \(w\) i is the weight of the \(i\)-th threat, \(s\) i is the severity score of the \(i\)-th threat, \(H\) j is the historical security risk weight of the \(j\)-th supply chain component, \(h\) j is the historical security problem score of the \(j\)-th supply chain component.
[0115] Step 7: Dynamically adjust the defense strategy according to the results of security situation awareness and conduct emergency response;
[0116] The implementation steps include:
[0117] Step 71: Dynamically adjust the security policies (firewall rules, access control policies) of the system according to the security situation score;
[0118] Step 72: Trigger the emergency response mechanism for the detected serious threats, especially for the components of the supply chain with a relatively high weight of historical security risks, isolate the affected software components and perform repairs;
[0119] Step 73: Record the processing process of the entire security incident to form a security incident report for subsequent analysis;
[0120] The formula for dynamically adjusting the defense strategy is: R = α·S + β·T + λ·H, where R is the adjustment intensity of the defense strategy, S is the security situation score, T is the urgency of the threat, H is the weight of historical security risks, and α, β, γ are weight coefficients.
[0121] This solution realizes the real-time security situation awareness of the software supply chain by introducing the weight of historical security risks and combining technologies such as dynamic behavior analysis, knowledge graph, and graph neural network;
[0122] Introduction of the weight of historical security risks: It can more intelligently analyze and detect potential threats in the supply chain, especially those components that have had security problems.
[0123] Dynamic behavior analysis and intelligent threat tracing: It can discover dynamic threats that cannot be detected by static analysis and perform intelligent threat tracing through the knowledge graph.
[0124] Dynamic defense and adaptive ability: Based on the security situation score and the weight of historical security risks, it can dynamically adjust the defense strategy and improve the adaptive ability of the system.
[0125] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification only illustrates the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed.
Claims
1. A software supply chain security analysis method, characterized in that: The steps include: S1: Collect data on the components of the software supply chain and calculate the historical security risk weight for each component in the supply chain. If a component of a supply chain has experienced security issues, calculate its weight value based on the severity and frequency of the security issue. S2: Collect the behavior data of the software during operation and combine it with the supply chain data for correlation analysis; S3: Preprocess the collected behavioral data and supply chain data and extract key features; S4: Use machine learning algorithms combined with historical security risk weights to detect abnormal behavior during software runtime; The specific implementation steps are: S41: using historical normal behavior data to train a machine learning model; S42: inputting the behavioral features collected in real time into the trained model to perform anomaly detection; S43: Adjust the sensitivity of anomaly detection based on the historical security risk weights of the supply chain components. For components with high historical security risk weights, increase the sensitivity of anomaly detection, and for components with low historical security risk weights, reduce the sensitivity of anomaly detection. S44: The model outputs a probability value of abnormal behavior, and if it exceeds a set threshold, it is determined to be an abnormal behavior; S5: Through knowledge graph technology, trace the source of detected abnormal behaviors and identify potential supply chain attack paths in combination with historical security risk weights; S6: Generate a security situation awareness report of the software supply chain based on abnormal behavior detection and threat tracing results, and provide real-time warnings; S7: Dynamically adjust defense strategies and conduct emergency responses based on security situation awareness results.
2. A software supply chain security analysis method according to claim 1, characterized in that: In step S1, the components of the software supply chain include third-party suppliers, dependencies, intellectual property structure, and vulnerability information, and the specific data collected for each component is: Third-party supplier information: supplier’s name, historical safety record, and compliance; Dependencies: Dependencies between software components, including open source components and third-party libraries; Intellectual property structure: intellectual property information of the software, including licenses and copyrights; Vulnerability information: known vulnerability information, including CVE number and vulnerability severity; The weight value calculation formula is: H i =α·S i +β·F i , where H i is the historical security risk weight of the i-th supply chain component, S i is the severity of the historical security incidents of the i-th supply chain component, F i is the frequency of historical security incidents of the i-th supply chain component, α and β are weight coefficients used to adjust the impact of severity and frequency, α+β=1.
3. A software supply chain security analysis method according to claim 1, characterized in that: In step S2, the specific implementation steps of collecting the behavior data of the software at runtime and combining it with the supply chain data for correlation analysis are as follows: S21: Deploy a lightweight monitoring agent in the target system to capture the runtime behavior of the software in real time; S22: The monitoring agent uses system hook technology to capture the software's system calls, network communications, and file operations; S23: Correlate the captured behavior data with the supply chain data to analyze the relationship between the software runtime behavior and the supply chain components; The behavioral data collection formula is: D runtime ={d1,d2,…,d n }, where D runtime is the runtime behavior dataset, d i is the i-th behavior data point, including timestamp, behavior type, and behavior parameter information.
4. A software supply chain security analysis method according to claim 3, characterized in that: In step S3, the collected behavior data and supply chain data are preprocessed and the specific implementation steps of extracting key features are as follows: S31: Clean the original behavior data and supply chain data to remove noise and redundant information; S32: Use feature engineering methods to extract features of behavioral data; S33: Combine supply chain data to extract features related to supply chain components; S34: quantizing the extracted features to form a feature matrix; The feature extraction formula is: F = {f1, f2, ..., f m }, where F is the feature matrix, f i is the i-th feature vector, which contains behavioral features and supply chain features.
5. A software supply chain security analysis method according to claim 4, characterized in that: The features of extracted behavioral data include system call frequency, network communication patterns, and file operation sequences; The features extracted related to the supply chain components include the usage frequency of dependent components and the historical safety record of the suppliers.
6. A software supply chain security analysis method according to claim 4, characterized in that: In step S4, the anomaly detection formula is: Where P(y=1|F,H) is the probability that the behavior data F and the historical safety risk weight H belong to abnormal behavior, θ and b are model parameters, and γ is the influence coefficient of the historical safety risk weight.
7. A software supply chain security analysis method according to claim 1, characterized in that: The implementation steps of step S5 include: S51: Constructing software supply chain knowledge graph; S52: Associating the detected abnormal behavior with the nodes in the knowledge graph and analyzing possible attack paths; S53: Use graph neural networks to reason about knowledge graphs and combine historical security risk weights to identify potential sources of supply chain attacks; S54: Conduct more in-depth analysis and testing of supply chain components with higher historical security risk weights; The knowledge graph reasoning formula is: Among them, H graph (l) is the node feature matrix of the lth layer, is the adjacency matrix, is the degree matrix, W (l) is the weight matrix and σ is the activation function.
8. A software supply chain security analysis method according to claim 1, characterized in that: The implementation steps of step S6 include: S61: Comprehensively analyze the abnormal behavior detection results and threat tracing results to generate a security situation awareness report; S62: Trigger different levels of early warning mechanisms based on the severity of the threat and historical security risk weights; S63: Push warning information to relevant safety managers in real time and provide response suggestions; The security posture scoring formula is: Where S is the security situation score, w i is the weight of the ith threat, s i Score the severity of the ith threat, H j is the historical security risk weight of the jth supply chain component, h j Score the historical security issues of the jth supply chain component.
9. A software supply chain security analysis method according to claim 8, characterized in that: The implementation steps of step S7 include: S71: Dynamically adjust the system's security policy based on the security situation score; S72: For detected serious threats, trigger the emergency response mechanism, isolate the affected software components, and perform repairs; S73: Record the entire security incident handling process and form a security incident report; The dynamic defense strategy adjustment formula is: R = α·S + β·T + λ·H, where R is the adjustment strength of the defense strategy, S is the security situation score, T is the urgency of the threat, H is the historical security risk weight, and α, β, and γ are weight coefficients.
10. A software supply chain security analysis method according to claim 7, characterized in that: In step S51, a software supply chain knowledge graph is constructed including software components, dependencies, supplier information, and historical security risk weights.
Citation Information
Patent Citations
Method capable of analyzing health degree of software supply chain
CN118400283A
Supply chain risk prediction method and system based on information fusion analysis
CN118411017A
Malicious software package detection method, system and device and storage medium
CN118520459A
Software supply chain security detection and situation analysis system
CN119272283A
Software supply chain threat monitoring method and device based on large model
CN119557881A
Cited By
Supply chain security information push early warning method and device
CN121037440A
A supply chain security intelligence push early warning method and device
CN121037440B
Software security hidden danger detection method and system based on knowledge graph
CN121479783A
A knowledge graph-based software security hazard detection method and system
CN121479783B