Full-process intelligent software detection method and system based on large language model

By constructing a full-process intelligent software detection method using a large language model, the problem of low efficiency in traditional software detection is solved. This method enables efficient detection of security risks related to complex software and artificial intelligence, and generates comprehensive and standardized test reports.

CN120930147APending Publication Date: 2025-11-11ANHUI JIYUAN TESTING TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511060326.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Traditional software testing technologies are inefficient and have insufficient coverage, making it difficult to address security risks related to complex software and artificial intelligence. Existing security testing capabilities are inadequate.

Method used

We employ a large language model to construct a full-process intelligent software detection method. By learning industry standards and historical documents, we perform comprehensive scanning and consistency checks, automatically extract requirement features and build a knowledge graph, generate test cases covering all test scenarios, identify software vulnerabilities and generate remediation suggestions, and combine traditional scanning tools to identify code vulnerabilities and generate detection reports.

Benefits of technology

It enables full-process software testing, improving testing efficiency and coverage, and can identify security risks related to complex software and artificial intelligence, generating standardized test reports.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120930147A_ABST
    Figure CN120930147A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a full-process intelligent software detection method and system based on a large language model, and belongs to the technical field of software testing. Comprising the following steps: based on a large language model learning industry standard and a historical document, carrying out comprehensive scanning and consistency checking on tested data; automatically extracting demand features and constructing a knowledge graph in the process of learning industry standards and historical documents by the large language model; analyzing the demand document through the natural language processing capability of the large language model; performing security testing on the software application API and the host according to the test case; identifying software code vulnerabilities according to a traditional scanning tool and a large model reasoning capability; and generating a standard test report based on the repair suggestion and the detection report. According to the full-process intelligent software detection method, a linked and synergistic detection system is built through a large language model, all links of software detection are comprehensively enabled, and full-process detection of software is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of software testing technology, and specifically to a full-process intelligent software testing method and system based on a large language model. Background Technology

[0002] With the rapid development of artificial intelligence technology, software systems are becoming increasingly complex, software development models are constantly evolving, and customers' demands for software quality are gradually increasing. However, traditional software testing techniques rely too heavily on manual testing and experience-based testing, resulting in inefficiency and insufficient coverage. Meanwhile, the cybersecurity situation is becoming increasingly severe, and existing security testing technologies are relatively less effective at detecting the ever-emerging and evolving security vulnerabilities, especially those related to artificial intelligence. Therefore, a comprehensive intelligent software testing method based on large language models is needed. Summary of the Invention

[0003] The purpose of this invention is to provide a full-process intelligent software detection method and system based on a large language model. This full-process intelligent software detection method constructs an interconnected and synergistic detection system through a large language model, fully empowering all aspects of software detection and realizing full-process software detection.

[0004] To achieve the above objectives, embodiments of the present invention provide a full-process intelligent software detection method based on a large language model, comprising: Based on the large language model, we learn industry standards and historical documents to conduct a comprehensive scan and consistency check on the test materials to ensure document integrity. During the process of learning industry standards and historical documents by the large language model, demand features are automatically extracted and a knowledge graph is constructed. The requirements document is parsed using the natural language processing capabilities of the large language model, and the functional points in the requirements document are extracted by combining the knowledge graph to generate test cases that cover a comprehensive test scenario. Security testing is performed on the software application API and host based on test cases to identify vulnerabilities and generate remediation recommendations; Based on traditional scanning tools and the reasoning capabilities of large models, software code vulnerabilities are identified and detection reports are generated. Based on the repair recommendations and test reports, a standardized test report is generated.

[0005] Optionally, based on the large language model, industry standards and historical documents are learned to perform a comprehensive scan and consistency check on the test submission materials to ensure document integrity, including: Collect test data consisting of historical research, preliminary design, and environmental verification forms, and label them with compliance tags; Structured training data is generated by labeling to pre-train the large language model and improve its ability to understand the test data. The text parsing tool extracts readable text from the PDF, Word, and Excel files in the test data, and the natural language processing capabilities of the large language model are used to identify key fields in the readable text. The test submission materials are matched against key fields and historical review cases. If the matching degree is greater than a preset threshold, the test submission materials are deemed to have passed the consistency check.

[0006] Optionally, during the process of learning industry standards and historical documents by the large language model, demand features are automatically extracted and a knowledge graph is constructed, including: The large language model extracts entities from the industry standards and historical documents as nodes, and uses the relationships between entities as edges to construct an initial knowledge graph. Based on the constructed initial knowledge graph, the degree centrality of each node in the initial knowledge graph is calculated using formula (1): Formula (1), in, Represents a node Degree centrality, Represents nodes The number of directly connected nodes represents the total number of nodes; Nodes whose degree centrality is greater than a preset threshold are selected as priority candidate nodes. Obtain the number of edges between the remaining nodes (excluding the priority candidate nodes) and the priority candidate nodes; The final knowledge graph is constructed by using the number of edges as the weights of the edges between nodes that have an edge relationship with the priority candidate node, where the weights serve as a specific measure of the association between two nodes.

[0007] Optionally, the requirements document can be parsed using the natural language processing capabilities of the large language model, and the functional points in the requirements document can be extracted by combining the knowledge graph to generate test cases that cover all test scenarios. The requirement document is processed by the large language model to obtain the functional description words in the requirement document; The functional description terms are analyzed to obtain the functional points to be tested within the functional description terms; The function point to be tested is matched with the nodes in the priority candidate nodes in order to obtain the node in the knowledge graph corresponding to the function point to be tested. Detect whether there is a semantic conflict between the relevant detection items corresponding to the function point to be tested and the edges and nodes associated with the corresponding node; In the absence of conflicts, a test item table is generated based on the function to be tested and related test items to obtain test cases.

[0008] Optionally, based on traditional scanning tools and the reasoning capabilities of large models, software code vulnerabilities can be identified, and a detection report can be generated, including: Collect and organize various vulnerabilities and defects in existing documents, as well as corresponding detection methods and solutions, to build a code vulnerability knowledge base; The software code is scanned using traditional scanning tools, and the scan results are extracted and processed in a structured manner. The large model performs contextual logic parsing on the structured code based on the code vulnerability knowledge base to analyze code semantics, function call chains and data flow, thereby locating deep vulnerabilities. Output the location, type, and remediation recommendations for each vulnerability in a report with a specific format.

[0009] On the other hand, the present invention also provides a full-process intelligent software detection system based on a large language model, comprising: The intelligent document review module is used to learn industry standards and historical documents based on a large language model, and to perform a comprehensive scan and consistency check on the submitted test materials to ensure document integrity. The knowledge graph construction module is used to automatically extract demand features and construct a knowledge graph during the learning process of the large language model on industry standards and historical documents; The test case generation module is used to parse the requirements document using the natural language processing capabilities of the large language model, and extract the functional points in the requirements document by combining the knowledge graph to generate test cases that cover all test scenarios. The penetration testing module is used to perform security testing on software application APIs and hosts based on test cases in order to identify vulnerabilities and generate remediation suggestions. The auxiliary code auditing module is used to identify software code vulnerabilities and generate detection reports based on the reasoning capabilities of traditional scanning tools and large models. The test report generation module is used to generate standardized test reports based on repair suggestions and test reports.

[0010] Optionally, based on the large language model, industry standards and historical documents are learned to perform a comprehensive scan and consistency check on the test submission materials to ensure document integrity, including: Collect test data consisting of historical research, preliminary design, and environmental verification forms, and label them with compliance tags; Structured training data is generated by labeling to pre-train the large language model and improve its ability to understand the test data. The text parsing tool extracts readable text from the PDF, Word, and Excel files in the test data, and the natural language processing capabilities of the large language model are used to identify key fields in the readable text. The test submission materials are matched against key fields and historical review cases. If the matching degree is greater than a preset threshold, the test submission materials are deemed to have passed the consistency check.

[0011] Optionally, during the process of learning industry standards and historical documents by the large language model, demand features are automatically extracted and a knowledge graph is constructed, including: The large language model extracts entities from the industry standards and historical documents as nodes, and uses the relationships between entities as edges to construct an initial knowledge graph. Based on the constructed initial knowledge graph, the degree centrality of each node in the initial knowledge graph is calculated using formula (1): Formula (1), in, Represents a node Degree centrality, Represents nodes The number of directly connected nodes represents the total number of nodes; Nodes whose degree centrality is greater than a preset threshold are selected as priority candidate nodes. Obtain the number of edges between the remaining nodes (excluding the priority candidate nodes) and the priority candidate nodes; The final knowledge graph is constructed by using the number of edges as the weights of the edges between nodes that have an edge relationship with the priority candidate node, where the weights serve as a specific measure of the association between two nodes.

[0012] Optionally, the requirements document can be parsed using the natural language processing capabilities of the large language model, and the functional points in the requirements document can be extracted by combining the knowledge graph to generate test cases that cover all test scenarios. The requirement document is processed by the large language model to obtain the functional description words in the requirement document; The functional description terms are analyzed to obtain the functional points to be tested within the functional description terms; The function point to be tested is matched with the nodes in the priority candidate nodes in order to obtain the node in the knowledge graph corresponding to the function point to be tested. Detect whether there is a semantic conflict between the relevant detection items corresponding to the function point to be tested and the edges and nodes associated with the corresponding node; In the absence of conflicts, a test item table is generated based on the function to be tested and related test items to obtain test cases.

[0013] Optionally, based on traditional scanning tools and the reasoning capabilities of large models, software code vulnerabilities can be identified, and a detection report can be generated, including: Collect and organize various vulnerabilities and defects in existing documents, along with corresponding detection methods and solutions, to build a code vulnerability knowledge base; The scanning results are extracted and structured using traditional scanning tools and software. The large model performs contextual logic parsing on the structured code based on the code vulnerability knowledge base to analyze code semantics, function call chains and data flow, thereby locating deep vulnerabilities. Output the location, type, and remediation recommendations for each vulnerability in a report with a specific format.

[0014] Through the above technical solution, this invention provides a full-process intelligent software testing method and system based on a large language model. This method learns industry standards and historical documents using a large language model, and performs comprehensive scanning and consistency checks on the submitted test materials, thereby ensuring document integrity. During the learning process of the large language model on industry standards and historical documents, it can automatically extract requirement features and construct a knowledge graph based on these features. These requirement features can be entities extracted from the documents. The natural language processing capabilities of the large language model can parse the requirement documents, and then, combined with knowledge topology, extract functional points from the requirement documents, thereby generating test cases covering comprehensive testing scenarios. After obtaining the test cases, security testing can be performed on the software application API and host based on these test cases, thereby identifying vulnerabilities and generating remediation suggestions. Based on traditional scanning tools and the reasoning capabilities of the large model, software code vulnerabilities can be identified, and a detection report can be generated based on these vulnerabilities. A standardized test report can be generated based on the remediation suggestions and the detection report. This full-process intelligent software testing method constructs an interconnected and synergistic testing system through a large language model, comprehensively empowering all aspects of software testing and achieving full-process software testing.

[0015] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description

[0016] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart of a full-process intelligent software detection method based on a large language model according to an embodiment of the present invention; Figure 2This is a flowchart of document review for a full-process intelligent software detection method based on a large language model according to an embodiment of the present invention; Figure 3 This is a flowchart of the construction of a knowledge graph in a full-process intelligent software detection method based on a large language model according to an embodiment of the present invention; Figure 4 This is a flowchart illustrating the generation of test cases for a full-process intelligent software detection method based on a large language model according to an embodiment of the present invention. Figure 5 This is a flowchart illustrating the detection of code vulnerabilities in a full-process intelligent software detection method based on a large language model, according to an embodiment of the present invention. Detailed Implementation

[0017] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the scope of the present invention.

[0018] In the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, they do not mean that the applicant has used or necessarily used the solution.

[0019] Figure 1 This is a flowchart of a full-process intelligent software detection method based on a large language model according to an embodiment of the present invention. In this invention, the detection process may include: In step S1, based on the large language model, industry standards and historical documents are learned, and a comprehensive scan and consistency check is performed on the test data to ensure the integrity of the documents.

[0020] In step S2, during the process of the large language model learning from industry standards and historical documents, demand features are automatically extracted and a knowledge graph is constructed.

[0021] In step S3, the requirements document is parsed using the natural language processing capabilities of the large language model, and the functional points in the requirements document are extracted by combining the knowledge graph to generate test cases that cover all test scenarios.

[0022] In step S4, security tests are performed on the software application API and the host according to the test cases to identify vulnerabilities and generate remediation suggestions.

[0023] In step S5, software code vulnerabilities are identified based on traditional scanning tools and the reasoning capabilities of large models, and a detection report is generated.

[0024] In step S6, a standardized test report is generated based on the repair recommendations and the test report.

[0025] In this invention, during testing, industry standards and historical documents can be learned based on a large language model, and a comprehensive scan and consistency check can be performed on the submitted test materials to ensure document integrity. During the learning process of the large language model on industry standards and historical documents, requirement features can be automatically extracted and a knowledge graph can be constructed based on the extracted features. These requirement features can be entities extracted from the documents. The natural language processing capabilities of the large language model can parse the requirement documents, and then, combined with the knowledge topology, functional points can be extracted from the requirement documents, thereby generating test cases covering a comprehensive testing scenario. After obtaining the test cases, security testing can be performed on the software application API and host based on these test cases, thereby identifying vulnerabilities and generating remediation suggestions. Based on traditional scanning tools and the reasoning capabilities of the large model, software code vulnerabilities can be identified, and a detection report can be generated based on these vulnerabilities. A standardized test report can be generated based on the remediation suggestions and the detection report. This end-to-end intelligent software testing method constructs an interconnected and synergistic testing system through a large language model, comprehensively empowering all aspects of software testing and achieving end-to-end software testing.

[0026] In one embodiment of the present invention, such as Figure 2 As shown, the document review process may include: In step S7, test data consisting of historical research, preliminary design, and environmental verification forms are collected and labeled with compliance tags.

[0027] In step S8, structured training data is generated by labeling to pre-train the large language model and improve its ability to understand the test data.

[0028] In step S9, readable text is extracted from the PDF, Word, and Excel files in the test data using a text parsing tool, and the natural language processing capabilities of the large language model are used to identify key fields in the readable text.

[0029] In step S10, the key fields for testing are matched with historical review cases, and if the matching degree is greater than a preset threshold, the testing data is determined to pass the consistency check.

[0030] In this invention, when performing consistency checks on documents, test data consisting of historical research materials, preliminary design materials, and environmental confirmation forms can be collected first, and compliance labels can be added to these materials. After labeling, structured training data can be generated through tagging, allowing the large language model to be pre-trained to improve its ability to understand the test materials. A text parsing tool can extract readable text from the PDF, Word, and Excel files in the test materials, and then the natural language processing capabilities of the large language model can be used to identify key fields in this readable text. Based on the identified key fields, historical review cases can be matched. If the matching degree is greater than a preset threshold, the test material is considered to have passed the consistency check, and the corresponding document is complete. If the matching degree is not greater than the preset threshold, the test material is considered to have failed the consistency check, and the corresponding document is incomplete.

[0031] In one embodiment of the present invention, such as Figure 3 As shown, the process of constructing a knowledge graph may include: In step S11, the large language model extracts entities from industry standards and historical documents as nodes, and uses the relationships between entities as edges to construct an initial knowledge graph.

[0032] In step S12, based on the constructed initial knowledge graph, the degree centrality of each node in the initial knowledge graph is calculated using formula (1): Formula (1), in, Represents a node Degree centrality, Represents nodes The number of directly connected nodes represents the total number of nodes.

[0033] In step S13, nodes with a degree centrality greater than a preset threshold are selected as priority candidate nodes.

[0034] In step S14, the number of edges between the remaining nodes (excluding the priority candidate nodes) and the priority candidate nodes is obtained.

[0035] In step S15, the weights of edges between nodes that have an edge relationship with the priority candidate node are determined based on the number of edges, in order to construct the final knowledge graph, where the weights serve as a specific measure of the association between two nodes.

[0036] In this invention, when constructing a knowledge graph, the large language model can extract entities from industry standards and historical documents as nodes, and use the relationships between entities as edges, thereby constructing an initial knowledge graph. After constructing the initial knowledge graph, the degree centrality of each node in the initial knowledge graph can be calculated using formula (1). Based on the degree centrality, it can be determined which nodes in the initial knowledge graph are more important. Nodes with a degree centrality greater than a preset threshold can be selected as priority candidate nodes. In the subsequent node matching process, nodes with a degree centrality greater than the preset threshold can be matched first. Because the frequency of nodes in the priority candidate nodes may be higher than that of general nodes, when matching, matching the nodes in the priority candidate nodes first can find the corresponding matching nodes more quickly. After obtaining the priority candidate nodes, the number of edges between the other nodes and the priority candidate nodes can be obtained. The number of edges obtained can be used as the weight of the edges between nodes that have an edge relationship with the priority candidate nodes, thereby constructing the final knowledge graph. This weight can be a specific measure of the correlation between two nodes. The greater the weight, the closer the relationship between the two nodes. When one of the nodes is matched later, the node with the greater weight associated with it is more likely to be selected as a candidate node to form a complete case.

[0037] In one embodiment of the present invention, such as Figure 4 As shown, the process for generating test cases may include: In step S16, the requirement document is processed by a large language model to obtain the functional description words in the requirement document.

[0038] In step S17, word parsing is performed on the functional description words to obtain the functional points to be tested in the functional description words.

[0039] In step S18, the function point to be tested is matched with the nodes in the priority candidate nodes to obtain the node in the knowledge graph corresponding to the function point to be tested.

[0040] In step S19, it is detected whether there is a semantic conflict between the relevant detection items corresponding to the function point to be tested and the edges and nodes associated with the corresponding nodes.

[0041] In step S20, if there are no conflicts, a test item table is generated based on the function point to be tested and the relevant test items to obtain test cases.

[0042] In this invention, when generating test cases, the requirement document can be processed first using a large language model to obtain the functional description statements within it. Based on the word analysis of these functional description statements, the functional points to be tested can be identified. These functional points are then matched with nodes in the priority candidate nodes to obtain the corresponding nodes in the knowledge graph. After obtaining the corresponding nodes, it is possible to check for semantic conflicts between the relevant detection items corresponding to the functional point and the edges and nodes associated with those nodes. In other words, based on the location and relationships of the matched nodes in the knowledge graph, it is determined whether the relevant detection items conflict with the relationships in the knowledge graph. If no conflict exists, a detection table can be generated based on the functional point and relevant detection items, thus obtaining test cases. If a conflict exists, it indicates an error in the relevant detection item, requiring the corresponding relevant detection item to be regenerated based on the functional point.

[0043] In one embodiment of the present invention, such as Figure 5 As shown, the process for detecting code vulnerabilities may include: In step S21, various vulnerabilities and defects in existing documents, as well as corresponding detection methods and solutions, are collected and organized to build a code vulnerability knowledge base.

[0044] In step S22, the software code is scanned using a traditional scanning tool, the scan results are extracted, and then structured.

[0045] In step S23, the large model performs contextual logic parsing on the structured code based on the code vulnerability knowledge base to analyze code semantics, function call chains, and data flow, thereby locating deep vulnerabilities.

[0046] In step S24, the location, type, and remediation recommendations for each vulnerability are output to form a report in a specific format.

[0047] In this invention, when detecting code vulnerabilities, various vulnerabilities and defects from existing documentation, along with corresponding detection methods and solutions, can be collected and organized to construct a code vulnerability knowledge base. After constructing the vulnerability knowledge base, software code can be scanned using traditional scanning tools, and the scan results can be extracted and structured. A large model can then perform contextual logic parsing on the structured code based on the vulnerability knowledge base, thereby analyzing code semantics, function call chains, and data flow. Based on the analyzed code semantics, function call chains, and data flow, deep vulnerabilities can be located. After identifying deep vulnerabilities, the location, type, and remediation suggestions for each vulnerability can be output, resulting in a report in a characteristic format.

[0048] On the other hand, this invention can also provide a full-process intelligent software detection system based on a large language model. This system may include: an intelligent document review module, a knowledge graph construction module, a test case generation module, an auxiliary penetration testing module, an auxiliary code auditing module, and a test report generation module. The intelligent document review module can be used to learn industry standards and historical documents based on the large language model, performing a comprehensive scan and consistency check on the submitted test materials to ensure document integrity. The knowledge graph construction module can be used to automatically extract requirement features and construct a knowledge graph during the large language model's learning process of industry standards and historical documents. The test case generation module can be used to parse requirement documents using the natural language processing capabilities of the large language model, and combine the knowledge graph to extract functional points from the requirement documents, generating test cases covering comprehensive testing scenarios. The auxiliary penetration testing module can be used to perform security testing on software application APIs and hosts based on the test cases to identify vulnerabilities and generate remediation suggestions. The auxiliary code auditing module can be used to identify software code vulnerabilities based on traditional scanning tools and the large model's reasoning capabilities, and generate a detection report. The test report generation module can be used to generate a standardized test report based on the remediation suggestions and the detection report.

[0049] In this invention, when performing consistency checks on documents, test data consisting of historical research materials, preliminary design materials, and environmental confirmation forms can be collected first, and compliance labels can be added to these materials. After labeling, structured training data can be generated through tagging, allowing the large language model to be pre-trained to improve its ability to understand the test materials. A text parsing tool can extract readable text from the PDF, Word, and Excel files in the test materials, and then the natural language processing capabilities of the large language model can be used to identify key fields in this readable text. Based on the identified key fields, historical review cases can be matched. If the matching degree is greater than a preset threshold, the test material is considered to have passed the consistency check, and the corresponding document is complete. If the matching degree is not greater than the preset threshold, the test material is considered to have failed the consistency check, and the corresponding document is incomplete.

[0050] In this invention, when constructing a knowledge graph, the large language model can extract entities from industry standards and historical documents as nodes, and use the relationships between entities as edges, thereby constructing an initial knowledge graph. After constructing the initial knowledge graph, the degree centrality of each node in the initial knowledge graph can be calculated using formula (1). Based on the degree centrality, it can be determined which nodes in the initial knowledge graph are more important. Nodes with a degree centrality greater than a preset threshold can be selected as priority candidate nodes. In the subsequent node matching process, nodes with a degree centrality greater than the preset threshold can be matched first. Because the frequency of nodes in the priority candidate nodes may be higher than that of general nodes, when matching, matching the nodes in the priority candidate nodes first can find the corresponding matching nodes more quickly. After obtaining the priority candidate nodes, the number of edges between the other nodes and the priority candidate nodes can be obtained. The number of edges obtained can be used as the weight of the edges between nodes that have an edge relationship with the priority candidate nodes, thereby constructing the final knowledge graph. This weight can be a specific measure of the correlation between two nodes. The greater the weight, the closer the relationship between the two nodes. When one of the nodes is matched later, the node with the greater weight associated with it is more likely to be selected as a candidate node to form a complete case.

[0051] In this invention, when generating test cases, the requirement document can be processed first using a large language model to obtain the functional description statements within it. Based on the word analysis of these functional description statements, the functional points to be tested can be identified. These functional points are then matched with nodes in the priority candidate nodes to obtain the corresponding nodes in the knowledge graph. After obtaining the corresponding nodes, it is possible to check for semantic conflicts between the relevant detection items corresponding to the functional point and the edges and nodes associated with those nodes. In other words, based on the location and relationships of the matched nodes in the knowledge graph, it is determined whether the relevant detection items conflict with the relationships in the knowledge graph. If no conflict exists, a detection table can be generated based on the functional point and relevant detection items, thus obtaining test cases. If a conflict exists, it indicates an error in the relevant detection item, requiring the corresponding relevant detection item to be regenerated based on the functional point.

[0052] In this invention, when detecting code vulnerabilities, various vulnerabilities and defects from existing documentation, along with corresponding detection methods and solutions, can be collected and organized to construct a code vulnerability knowledge base. After constructing the vulnerability knowledge base, software code can be scanned using traditional scanning tools, and the scan results can be extracted and structured. A large model can then perform contextual logic parsing on the structured code based on the vulnerability knowledge base, thereby analyzing code semantics, function call chains, and data flow. Based on the analyzed code semantics, function call chains, and data flow, deep vulnerabilities can be located. After identifying deep vulnerabilities, the location, type, and remediation suggestions for each vulnerability can be output, resulting in a report in a characteristic format.

[0053] Through the above technical solution, this invention provides a full-process intelligent software testing method and system based on a large language model. This method learns industry standards and historical documents using a large language model, and performs comprehensive scanning and consistency checks on the submitted test materials, thereby ensuring document integrity. During the learning process of the large language model on industry standards and historical documents, it can automatically extract requirement features and construct a knowledge graph based on these features. These requirement features can be entities extracted from the documents. The natural language processing capabilities of the large language model can parse the requirement documents, and then, combined with knowledge topology, extract functional points from the requirement documents, thereby generating test cases covering comprehensive testing scenarios. After obtaining the test cases, security testing can be performed on the software application API and host based on these test cases, thereby identifying vulnerabilities and generating remediation suggestions. Based on traditional scanning tools and the reasoning capabilities of the large model, software code vulnerabilities can be identified, and a detection report can be generated based on these vulnerabilities. A standardized test report can be generated based on the remediation suggestions and the detection report. This full-process intelligent software testing method constructs an interconnected and synergistic testing system through a large language model, comprehensively empowering all aspects of software testing and achieving full-process software testing.

[0054] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0055] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0056] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0057] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0058] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0059] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0060] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0061] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0062] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A full-process intelligent software detection method based on a large language model, characterized in that, include: Based on the large language model, we learn industry standards and historical documents to conduct a comprehensive scan and consistency check on the test materials to ensure document integrity. During the process of learning industry standards and historical documents by the large language model, demand features are automatically extracted and a knowledge graph is constructed. The requirements document is parsed using the natural language processing capabilities of the large language model, and the functional points in the requirements document are extracted by combining the knowledge graph to generate test cases that cover a comprehensive test scenario. Security testing is performed on the software application API and host based on test cases to identify vulnerabilities and generate remediation recommendations; Based on traditional scanning tools and the reasoning capabilities of large models, software code vulnerabilities are identified and detection reports are generated. Based on the repair recommendations and test reports, a standardized test report is generated.

2. The end-to-end intelligent software testing method according to claim 1, characterized in that, Based on large language models, industry standards and historical documents are learned, and a comprehensive scan and consistency check is performed on the test submission materials to ensure document integrity, including: Collect test data consisting of historical research, preliminary design, and environmental verification forms, and label them with compliance tags; Structured training data is generated by labeling to pre-train the large language model and improve its ability to understand the test data. The text parsing tool extracts readable text from the PDF, Word, and Excel files in the test data, and the natural language processing capabilities of the large language model are used to identify key fields in the readable text. The test submission materials are matched against key fields and historical review cases. If the matching degree is greater than a preset threshold, the test submission materials are deemed to have passed the consistency check.

3. The end-to-end intelligent software testing method according to claim 1, characterized in that, During the learning process of the large language model on industry standards and historical documents, it automatically extracts demand features and constructs a knowledge graph, including: The large language model extracts entities from the industry standards and historical documents as nodes, and uses the relationships between entities as edges to construct an initial knowledge graph. Based on the constructed initial knowledge graph, the degree centrality of each node in the initial knowledge graph is calculated using formula (1): Formula (1), in, Represents a node Degree centrality, Represents nodes The number of directly connected nodes represents the total number of nodes; Nodes whose degree centrality is greater than a preset threshold are selected as priority candidate nodes. Obtain the number of edges between the remaining nodes (excluding the priority candidate nodes) and the priority candidate nodes; The final knowledge graph is constructed by using the number of edges as the weights of the edges between nodes that have an edge relationship with the priority candidate node, where the weights serve as a specific measure of the association between two nodes.

4. The end-to-end intelligent software testing method according to claim 3, characterized in that, The requirements document is parsed using the natural language processing capabilities of the large language model, and the functional points in the requirements document are extracted by combining the knowledge graph to generate test cases that cover a comprehensive test scenario. The requirement document is processed by the large language model to obtain the functional description words in the requirement document; The functional description terms are analyzed to obtain the functional points to be tested within the functional description terms; The function point to be tested is matched with the nodes in the priority candidate nodes in order to obtain the node in the knowledge graph corresponding to the function point to be tested. Detect whether there is a semantic conflict between the relevant detection items corresponding to the function point to be tested and the edges and nodes associated with the corresponding node; In the absence of conflicts, a test item table is generated based on the function to be tested and related test items to obtain test cases.

5. The end-to-end intelligent software testing method according to claim 1, characterized in that, Based on traditional scanning tools and large-scale model inference capabilities, software code vulnerabilities are identified, and a detection report is generated, including: Collect and organize various vulnerabilities and defects in existing documents, as well as corresponding detection methods and solutions, to build a code vulnerability knowledge base; The software code is scanned using traditional scanning tools, and the scan results are extracted and processed in a structured manner. The large model performs contextual logic parsing on the structured code based on the code vulnerability knowledge base to analyze code semantics, function call chains and data flow, thereby locating deep vulnerabilities. Output the location, type, and remediation recommendations for each vulnerability in a report with a specific format.

6. A full-process intelligent software detection system based on a large language model, characterized in that, include: The intelligent document review module is used to learn industry standards and historical documents based on a large language model, and to perform a comprehensive scan and consistency check on the submitted test materials to ensure document integrity. The knowledge graph construction module is used to automatically extract demand features and construct a knowledge graph during the learning process of the large language model on industry standards and historical documents; The test case generation module is used to parse the requirements document using the natural language processing capabilities of the large language model, and extract the functional points in the requirements document by combining the knowledge graph to generate test cases that cover all test scenarios. The penetration testing module is used to perform security testing on software application APIs and hosts based on test cases in order to identify vulnerabilities and generate remediation suggestions. The auxiliary code auditing module is used to identify software code vulnerabilities and generate detection reports based on the reasoning capabilities of traditional scanning tools and large models. The test report generation module is used to generate standardized test reports based on repair suggestions and test reports.

7. The end-to-end intelligent software testing system according to claim 6, characterized in that, Based on large language models, industry standards and historical documents are learned, and a comprehensive scan and consistency check is performed on the test submission materials to ensure document integrity, including: Collect test data consisting of historical research, preliminary design, and environmental verification forms, and label them with compliance tags; Structured training data is generated by labeling to pre-train the large language model and improve its ability to understand the test data. The text parsing tool extracts readable text from the PDF, Word, and Excel files in the test data, and the natural language processing capabilities of the large language model are used to identify key fields in the readable text. The test submission materials are matched against key fields and historical review cases. If the matching degree is greater than a preset threshold, the test submission materials are deemed to have passed the consistency check.

8. The end-to-end intelligent software testing system according to claim 6, characterized in that, During the learning process of the large language model on industry standards and historical documents, it automatically extracts demand features and constructs a knowledge graph, including: The large language model extracts entities from the industry standards and historical documents as nodes, and uses the relationships between entities as edges to construct an initial knowledge graph. Based on the constructed initial knowledge graph, the degree centrality of each node in the initial knowledge graph is calculated using formula (1): Formula (1), in, Represents a node Degree centrality, Represents nodes The number of directly connected nodes represents the total number of nodes; Nodes whose degree centrality is greater than a preset threshold are selected as priority candidate nodes. Obtain the number of edges between the remaining nodes (excluding the priority candidate nodes) and the priority candidate nodes; The final knowledge graph is constructed by using the number of edges as the weights of the edges between nodes that have an edge relationship with the priority candidate node, where the weights serve as a specific measure of the association between two nodes.

9. The end-to-end intelligent software testing system according to claim 8, characterized in that, The requirements document is parsed using the natural language processing capabilities of the large language model, and the functional points in the requirements document are extracted by combining the knowledge graph to generate test cases that cover a comprehensive test scenario. The requirement document is processed by the large language model to obtain the functional description words in the requirement document; The functional description terms are analyzed to obtain the functional points to be tested within the functional description terms; The function point to be tested is matched with the nodes in the priority candidate nodes in order to obtain the node in the knowledge graph corresponding to the function point to be tested. Detect whether there is a semantic conflict between the relevant detection items corresponding to the function point to be tested and the edges and nodes associated with the corresponding node; In the absence of conflicts, a test item table is generated based on the function to be tested and related test items to obtain test cases.

10. The end-to-end intelligent software testing system according to claim 6, characterized in that, Based on traditional scanning tools and large-scale model inference capabilities, software code vulnerabilities are identified, and a detection report is generated, including: Collect and organize various vulnerabilities and defects in existing documents, as well as corresponding detection methods and solutions, to build a code vulnerability knowledge base; The software code is scanned using traditional scanning tools, and the scan results are extracted and processed in a structured manner. The large model performs contextual logic parsing on the structured code based on the code vulnerability knowledge base to analyze code semantics, function call chains and data flow, thereby locating deep vulnerabilities. Output the location, type, and remediation recommendations for each vulnerability in a report with a specific format.