Business code auditing method and device, electronic equipment, medium and program product

By combining a large language model with a multi-source labeled dataset and a multimodal feature fusion method for business code auditing, the problems of high false positive rate and false negative rate of traditional auditing methods are solved, and efficient and accurate business logic vulnerability identification and real-time response are achieved.

CN121326727APending Publication Date: 2026-01-13INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510719991.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

Traditional business code auditing methods have a high false alarm rate, fail to report business logic vulnerabilities, cannot understand complex contexts, lack multimodal information fusion capabilities, and are difficult to identify complex business logic vulnerabilities.

Method used

A business code auditing method based on a large language model is adopted. The first analysis result is obtained through preliminary scanning. The business logic analysis is carried out using the business code auditing model. The parameters are fine-tuned by combining multi-source labeled datasets. Code dependency graph and control flow graph are constructed. Feature extraction and multimodal feature fusion are performed to generate the second analysis result, and the first analysis result is verified.

Benefits of technology

Significantly reduce computing resource requirements, increase processing throughput, shorten feedback cycles, improve the real-time responsiveness and accuracy of audit results, and identify vulnerabilities in complex business logic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121326727A_ABST
    Figure CN121326727A_ABST
Patent Text Reader

Abstract

The invention provides a business code auditing method, belongs to the field of large model application, and can be used in the field of information security, the field of big data and the technical field of artificial intelligence. The method comprises the following steps: acquiring target business information and a target business code; performing preliminary scanning on the target business code to obtain a first analysis result; based on the first analysis result and the target service information, performing service logic analysis by using a service code auditing model to obtain a second analysis result; and verifying the first analysis result based on the second analysis result, and generating a business code auditing result based on the second analysis result and a verification result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the fields of large model application, information security, big data and artificial intelligence, and more specifically to a business code auditing method, apparatus, equipment, medium and program product. Background Technology

[0002] With the increasing complexity of financial information systems and the widespread deployment of business systems, software code security issues are becoming increasingly prominent. Traditional business code auditing methods rely heavily on manual inspection or rule-based static analysis tools, which suffer from high false positive rates, missed detection of business logic vulnerabilities, and inability to understand complex contexts. Especially in actual business scenarios, such as promotional systems and financial payment systems, complex business processes and cross-module logic are often involved. Traditional tools struggle to effectively identify hidden business logic vulnerabilities and lack the ability to comprehensively analyze multimodal information such as natural language rule documents and interface logic. Summary of the Invention

[0003] In view of the above issues, this disclosure provides business code auditing methods, apparatus, equipment, media, and program products.

[0004] According to a first aspect of this disclosure, a business code auditing method is provided, the method comprising: acquiring target business information and target business code; performing a preliminary scan of the target business code to obtain a first analysis result; performing business logic analysis using a business code auditing model based on the first analysis result and the target business information to obtain a second analysis result; and verifying the first analysis result based on the second analysis result, and generating a business code auditing result based on the second analysis result and the verification result.

[0005] According to embodiments of this disclosure, the code auditing model is obtained by fine-tuning the parameters of a pre-trained large language model. The fine-tuning of the parameters of the pre-trained large language model is based on a multi-source labeled dataset, which includes code auditing scenarios, business logic information, and vulnerability tags.

[0006] According to embodiments of this disclosure, the first analysis result includes a first vulnerability list, which includes first vulnerability information and corresponding code snippets; the second analysis result includes a second vulnerability list and vulnerability analysis information, which includes second vulnerability information and corresponding code snippets.

[0007] According to embodiments of this disclosure, the step of performing business logic analysis using a business code auditing model based on the first analysis result and the target business information to obtain a second analysis result specifically includes: constructing a code dependency graph based on the code fragment corresponding to the first vulnerability information; extracting features from the code dependency graph to generate a context vector representation; and fusing the context vector representation with features extracted from the target business information using multimodal features as input to the business code auditing model.

[0008] According to embodiments of this disclosure, the step of performing business logic analysis using a business code auditing model based on the first analysis result and the target business information to obtain a second analysis result specifically includes: constructing a control flow graph and a data flow graph based on the code fragment corresponding to the first vulnerability information; performing vectorization processing on the control flow graph and the data flow graph to generate execution path features and data transmission features; and using the execution path features and the data transmission features as input to the business code auditing model.

[0009] According to embodiments of this disclosure, the target business information includes graphical interface information, and the method further includes: performing structured recognition on the graphical interface information to extract visual element features; and jointly encoding the visual element features and the context vector representation as input to the business code audit model.

[0010] According to embodiments of this disclosure, the step of verifying the first analysis result based on the second analysis result, and generating a business code audit result based on the second analysis result and the verification result, specifically includes: comparing the second vulnerability list and the first vulnerability list to obtain vulnerability supplementary items; verifying the first vulnerability list based on the vulnerability analysis information to obtain vulnerability false positive items and vulnerability true items; performing structured annotation on the vulnerability true items to obtain structured vulnerability information; and generating the business code audit result based on the vulnerability supplementary items, vulnerability false positive items, and the structured vulnerability information.

[0011] According to embodiments of this disclosure, the method further includes: in response to modifications to the business code, re-executing a preliminary scan and business logic analysis process on the modified business code to obtain repair effect information; and updating the code audit model based on the repair suggestions and the repair effect information.

[0012] A second aspect of this disclosure provides a business code auditing apparatus, the apparatus comprising: a data acquisition module, configured to: acquire target business information and target business code; an initial scanning module, configured to: perform a preliminary scan of the target business code to obtain a first analysis result; a business logic analysis module, configured to: perform business logic analysis using a business code auditing model based on the first analysis result and the target business information to obtain a second analysis result; and a business code auditing module, configured to: verify the first analysis result based on the second analysis result, and generate a business code auditing result based on the second analysis result and the verification result.

[0013] According to embodiments of this disclosure, the business logic analysis module can also be used to construct a code dependency graph based on the code fragment corresponding to the first vulnerability information; extract features from the code dependency graph to generate a context vector representation; and fuse the context vector representation with features extracted from the target business information in a multimodal manner as input to the business code audit model.

[0014] According to embodiments of this disclosure, the business logic analysis module can also be used to construct a control flow graph and a data flow graph based on the code fragment corresponding to the first vulnerability information; perform vectorization processing on the control flow graph and the data flow graph to generate execution path features and data transmission features; and use the execution path features and the data transmission features as input to the business code auditing model.

[0015] According to embodiments of this disclosure, the business logic analysis module can also be used to perform structured recognition of the graphical interface information, extract visual element features, and jointly encode the visual element features and the context vector representation as input to the business code audit model.

[0016] According to embodiments of this disclosure, the business code auditing module can also be used to compare the second vulnerability list and the first vulnerability list to obtain vulnerability supplementary items; verify the first vulnerability list based on the vulnerability analysis information to obtain vulnerability false alarm items and vulnerability true items; perform structured annotation on the vulnerability true items to obtain structured vulnerability information; and generate the business code auditing result based on the vulnerability supplementary items, vulnerability false alarm items, and the structured vulnerability information.

[0017] According to embodiments of this disclosure, the business code auditing module can also be used to respond to modifications to the business code by re-executing a preliminary scan and business logic analysis process on the modified business code to obtain repair effect information; and to update the code auditing model based on the repair suggestions and the repair effect information.

[0018] A third aspect of this disclosure provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method described above.

[0019] A fourth aspect of this disclosure also provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the above-described method.

[0020] The fifth aspect of this disclosure also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described method.

[0021] According to embodiments of this disclosure, by performing rapid rule matching on the business code during the initial scanning phase, potentially risky code regions can be pre-screened, significantly reducing the amount of data and model inference computational resources required for subsequent in-depth analysis, thereby lowering overall computational costs and increasing processing throughput. Furthermore, leveraging the semantic modeling and context awareness of the business code auditing model, targeted audit judgments can be made on key logic points without requiring a full code traversal, avoiding redundant analysis paths, reducing system waiting time, and improving the real-time responsiveness of audit result generation. Simultaneously, by using the second analysis result to verify the first analysis result, the transmission chain of false alarm information can be further compressed, shortening the feedback cycle required for manual intervention and achieving more efficient risk assessment and closed-loop processing. Attached Figure Description

[0022] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0023] Figure 1 The illustration shows an application scenario diagram of the business code auditing method, apparatus, device, medium, and program product according to embodiments of the present disclosure;

[0024] Figure 2 A flowchart illustrating a business code auditing method according to an embodiment of this disclosure is shown schematically;

[0025] Figure 3 A flowchart illustrating a method for processing a first analysis result and target business information according to an embodiment of the present disclosure is shown schematically.

[0026] Figure 4 A flowchart illustrating a method for processing first analysis results and target business information according to another embodiment of the present disclosure is shown schematically.

[0027] Figure 5A schematic diagram illustrating the structure of a business code auditing apparatus according to an embodiment of the present disclosure is shown; and

[0028] Figure 6 A block diagram of an electronic device suitable for implementing a business code auditing method according to an embodiment of the present disclosure is shown schematically. Detailed Implementation

[0029] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0030] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0031] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0032] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).

[0033] First, the technical terms used in this article are explained and clarified as follows.

[0034] Code Dependency Graph: A graph structure built with code elements such as classes, functions, and variables as nodes and relationships such as calls, inheritance, and references as edges, used to show the static structure of code and the coupling relationship between modules.

[0035] Control-Flow Graph (CFG): A directed graph that describes the execution order of a program. Its nodes represent basic blocks and edges represent possible control flow transitions. It is used to analyze conditional branches, loops, and abnormal paths.

[0036] Data-Flow Graph (DFG): A graph structure that reflects the relationships between the definition, propagation, and use of data in a program. It can help identify problems such as uninitialized variables and sensitive data leakage.

[0037] Adapter Injection (Adapter Layers): A fine-tuning method that inserts small trainable modules between layers of a pre-trained model, avoiding modification of the original model weights and enabling rapid transfer learning.

[0038] LoRA (Low-Rank Adaptation): A lightweight fine-tuning strategy that efficiently completes task customization by injecting low-rank decomposition components into the model weight matrix and updating only a small number of parameters.

[0039] With the continuous evolution of financial information systems, modern business systems are showing a trend towards increased functional complexity, diversified processes, and decoupled modules. In industries such as banking, securities, insurance, e-commerce, and payment, a large amount of business logic is encoded into the business code of the enterprise's core systems, carrying critical functions such as user authentication, transaction processing, discount calculation, and fund settlement. However, with the increase in system complexity, the security of the business code faces some challenges.

[0040] Traditional business code auditing primarily relies on security personnel manually reading source code or using rule-driven static code analysis tools to check for common types of vulnerabilities such as SQL injection and unreleased resources. While this approach is efficient in identifying syntax-level issues, it has significant limitations in practical engineering applications.

[0041] First, the false positive rate is high. Static rules often rely on fixed pattern matching and lack awareness of variable lifecycles, call chain relationships, and dynamic contexts, resulting in a large number of "suspected vulnerabilities" requiring manual investigation one by one, which seriously affects audit efficiency.

[0042] Secondly, there is the issue of unreported business logic vulnerabilities. Business logic vulnerabilities refer to situations where program behavior does not violate syntax rules but deviates from business expectations, potentially leading to consequences such as authorization bypass, incorrect amounts, overlapping discounts, and abnormal inventory. Because these vulnerabilities heavily rely on the combination of specific business rules, process states, and user roles, existing tools lack the ability to understand "business intent" and struggle to identify non-structured security risks such as "incorrect deduction order under concurrent conditions" and "missing state transitions."

[0043] Secondly, it struggles to understand complex contexts. With the development of service modularization and microservices, business logic often spans multiple classes, functions, files, and even interfaces between different languages. Traditional auditing tools, based on files as the basic unit, struggle to trace the actual path of call chains and data flow throughout the system.

[0044] Furthermore, existing technologies generally neglect the integration of multimodal information during the auditing process. In many systems, the correctness of code needs to be judged by combining multiple types of information, such as requirements documents, design documents, test documents, and interface prototypes. For example, a document might stipulate that "new customers do not enjoy additional discounts on their first order," but if the code does not reflect this restriction, it may logically constitute a security flaw. Traditional auditing methods typically cannot parse natural language documents, nor can they effectively align document information with code semantics, thus failing to achieve "specification-process consistency" verification.

[0045] In systems with complex user interaction logic (such as e-commerce platforms, online banking systems, and credit platforms), the front-end interface behavior is tightly coupled with the back-end business processes. If the interface fields lack constraints or the user operation path is not updated in sync with the code logic, "input bypass" vulnerabilities may occur. However, traditional tools lack the ability to process visual interaction logic, interface design specifications, and graphical prototypes, and do not have the ability to identify cross-modal vulnerabilities.

[0046] Based on this, embodiments of this disclosure provide a business code auditing method, including: acquiring target business information and target business code; performing a preliminary scan of the target business code to obtain a first analysis result; performing business logic analysis using a business code auditing model based on the first analysis result and the target business information to obtain a second analysis result; verifying the first analysis result based on the second analysis result, and generating a business code auditing result based on the second analysis result and the verification result. By performing rapid rule matching on the business code during the preliminary scan stage, potentially risky code areas can be pre-screened, significantly reducing the amount of data and model inference computation resources required for subsequent in-depth analysis, thereby reducing overall computational costs and increasing processing throughput. Furthermore, by leveraging the semantic modeling and context awareness of the business code auditing model, targeted audit judgments can be made on key logic points without traversing the entire code, avoiding redundant analysis paths, reducing system waiting time, and improving the real-time responsiveness of audit result generation. Simultaneously, by using the second analysis result to verify the first analysis result, the transmission chain of false alarm information can be further compressed, shortening the feedback cycle required for manual intervention and judgment, and achieving more efficient risk assessment and closed-loop processing.

[0047] It should be noted that the business code auditing methods, apparatus, devices, media, and program products specified in this disclosure belong to the field of large-scale model applications and can be used in the fields of information security, big data, artificial intelligence, and fintech. They can also be used in various other fields besides large-scale model applications, information security, big data, artificial intelligence, and fintech. The application fields of the business code auditing methods, apparatus, devices, media, and program products provided in the embodiments of this disclosure are not limited.

[0048] In the technical solution disclosed herein, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, necessary confidentiality measures have been taken, and they do not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse.

[0049] In scenarios involving automated decision-making using personal information, the methods, devices, and systems provided in this disclosure all offer users corresponding entry points for choosing to agree to or reject the automated decision-making results. If the user chooses to reject, the process proceeds to the expert decision-making stage. Here, "automated decision-making" refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, or economic, health, and credit status through computer programs, and then making a decision. Here, "expert decision-making" refers to the activity of making decisions by personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise.

[0050] Figure 1 The illustration schematically depicts application scenarios of the business code auditing method, apparatus, device, medium, and program product according to embodiments of this disclosure.

[0051] like Figure 1 As shown, application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.

[0052] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).

[0053] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0054] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.

[0055] It should be noted that the business code auditing method provided in this embodiment can generally be executed by server 105. Correspondingly, the business code auditing device provided in this embodiment can generally be located in server 105. The business code auditing method provided in this embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the business code auditing device provided in this embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.

[0056] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0057] The following will be based on Figure 1 The described scene, through Figures 2-4 The business code auditing method of the disclosed embodiments is described in detail.

[0058] Figure 2 A flowchart illustrating a business code auditing method according to an embodiment of this disclosure is shown schematically.

[0059] like Figure 2 As shown, the business code auditing method 200 of this embodiment includes operations S210 to S240, and the business code auditing method can be executed by server 105.

[0060] In operation S210, obtain target business information and target business code.

[0061] In the embodiments of this disclosure, the target business code can be a collection of source code constituting the functional logic of a business system, covering backend service code, middleware logic code, and some frontend interaction logic tightly coupled with business implementation, and organized in the form of a project structure, containing multiple modules, classes, functions, and configuration files. The acquired business code can come from a source code management platform or be loaded into a code auditing system in the form of a local directory structure.

[0062] Furthermore, it can selectively support multi-version code comparison, focusing on analyzing the differences before and after branch iterations or patch fixes.

[0063] In the embodiments of this disclosure, the target business information may include structured or semi-structured documents such as business requirements specifications, process design documents, interface specification documents, database structure descriptions, test cases, rule configuration tables, and access control matrices. It may also include non-code information such as business system interface prototype diagrams, operation manuals, event logs, and operation trajectory data. The target business information can be automatically extracted from project management systems, enterprise architecture tools, interface management platforms, and design prototyping tools, or provided by business personnel through manual upload. To improve information usability, preprocessing operations such as format standardization, OCR text recognition, and file structure parsing can be performed on the raw data during the acquisition phase to ensure readability and consistency in subsequent analysis.

[0064] Taking a promotion system as an example, the target business code can include the logic implementation part responsible for discount calculation, order price verification and promotion rule matching, while the target business information includes various promotion strategy description documents, promotion activity configuration tables (such as discounts for purchases over a certain amount, gifts for purchases over a certain amount, limited-time discounts, etc.), product application scope rules, user segmentation standards, and description information of the user selection path in the front-end interface.

[0065] Taking a credit system as an example, the target business code may include functional modules such as credit limit calculation, repayment plan generation, and default judgment. The corresponding business information includes loan product parameter definition table, repayment rule description, approval process configuration, and customer credit scoring rules.

[0066] In operation S220, a preliminary scan of the target business code is performed to obtain the first analysis result.

[0067] In the embodiments of this disclosure, the preliminary scan can employ existing static code analysis techniques. By constructing intermediate representations such as abstract syntax trees and combining them with a pre-defined detection rule base, it can quickly identify potential basic security vulnerabilities, coding style issues, and potential business risks in the code. For example, the scan content can include common issues such as SQL injection, command injection, hard-coded passwords, null pointer references, unauthorized access, resource leaks, and improper exception handling, as well as issues that are easily overlooked in business implementations, such as lack of boundary checks, missing null value checks, and repetitive logic.

[0068] In the embodiments of this disclosure, the initial scan can be performed based on static analysis tools, or it can be combined with a self-developed rule engine to implement industry-customized detection strategies. During the scan, the system can automatically select the corresponding parser and rule set according to the language type of the code to support the auditing needs of multi-language mixed projects. For structured rule hits, meta-information including file path, line number, rule type, hit code segment, and preliminary risk level can be recorded to form the first analysis result, which is used for subsequent comparison and verification with semantic analysis results.

[0069] The initial analysis results may include a first vulnerability list, which records potential risks initially identified in the target business code. Each item in the first vulnerability list is first vulnerability information, which may include vulnerability type, vulnerability level, hit rule number, detection location, etc., and be associated with a specific code snippet to facilitate semantic judgment and contextual analysis by auditors or subsequent models.

[0070] The corresponding code snippet can point to the direct triggering location of the vulnerability, including the source file path, function name, start and end line numbers, and several lines of context code, which helps the subsequent model identify the vulnerability context structure, call relationships, and potential dependency paths.

[0071] In embodiments of this disclosure, the system can support the simultaneous recording of multiple hit locations or variant paths, ensuring coverage analysis of conditional branches or repetitive implementations in the code structure.

[0072] In operation S230, based on the first analysis result and the target business information, business logic analysis is performed using the business code audit model to obtain the second analysis result.

[0073] In the embodiments of this disclosure, the business code auditing model can be built based on a domain-fine-tuned large language model, and has the ability to jointly model multi-source heterogeneous data such as code structure, natural language description, and graph structure information.

[0074] Specifically, the fine-tuning process can be based on a specially constructed multi-source labeled dataset. This dataset covers various real or simulated code audit scenarios, integrating structured code snippets, corresponding business logic documentation, and manually reviewed vulnerability tags. For example, each sample in the multi-source labeled dataset may include: code segments with audit significance, such as order amount verification, approval status transitions, and user permission verification; business descriptions related to the code's function, such as the limiting clauses for discount logic in the requirements specification and the constraints on status transitions in the flowchart; and one or more labeled vulnerability tags that clearly indicate potential problems in the current code regarding business rule coverage, exception handling, and access control.

[0075] During model fine-tuning, supervised learning can be employed, inputting multi-source data samples into the model and training it with pre-defined labels to identify complex logical defects such as violations of business rules, gaps in contextual logic, and omissions in control conditions. To improve training efficiency and transfer adaptability, lightweight methods such as low-rank adaptation (LoRA) and adapter injection can be used in the fine-tuning process. These methods can significantly improve model performance by updating only a small number of parameter modules, avoiding damage to the weights of the original large language model and preserving its original language and programming knowledge.

[0076] Specifically, the LoRA method can optimize only a small number of weights by introducing trainable parameter modules of low-rank matrix factorization into the linear transformation layer of the pre-trained model, thus avoiding the computational overhead and overfitting risk of updating all parameters. This method, while keeping the original weights frozen, enables the model to effectively capture new semantic patterns relevant to code auditing tasks even with limited samples.

[0077] For example, when identifying logical vulnerabilities with significant business characteristics, such as "approval status not synchronized" or "conflict in preferential rules" during the audit process, LoRA can quickly adjust the model's attention distribution in terms of judgment conditions, state transitions, and variable dependencies, thereby improving the identification accuracy.

[0078] Adapter injection methods introduce flexible feature transformation channels between different task domains by inserting small, trainable adapter modules between model layers. This approach is suitable for multi-task, cross-domain model sharing scenarios, injecting the logical feature representation capabilities required for specific tasks without interfering with the semantic structure of the backbone model. In business code auditing, adapters can be used to guide models to identify business process language patterns and common logical norms in specific industries (such as finance, government affairs, and e-commerce), enhancing the model's sensitivity to industry-specific vulnerabilities.

[0079] The input received by the business code auditing model can include high-risk code snippets extracted from the first vulnerability list, as well as related semantic information such as business rule descriptions, process roles, parameter constraints, and abnormal scenario descriptions. By encoding and fusing the input content, the model can understand the behavioral logic of the business code in context and determine whether there are problems such as violation of business intent, omission of process state jumps, permission verification errors, and missing exception handling paths.

[0080] Taking a credit system as an example, if the first analysis result marks that a certain approval function has a missing permission judgment logic, while the business rules clearly stipulate that "high-amount approvals require double review", then the business code auditing model can identify that the missing information is a typical business authorization bypass vulnerability by comparing the code implementation with the rule description.

[0081] Taking e-commerce scenarios as an example, if the front-end promotion logic does not set restrictions on fresh produce, but the back-end rule document states that "fresh produce is not eligible for discounts," the business code audit model can also determine that there is a rule adaptation omission in the code, and thus output the logic risk as part of the second analysis result.

[0082] In the embodiments of this disclosure, the second analysis result may include a second vulnerability list and vulnerability analysis information. This is a deep semantic analysis output generated using a business code auditing model after combining the first analysis result with target business information. The second vulnerability list is a set of vulnerabilities discovered based on the initial scan, through the business code auditing model's understanding of code context, alignment with business rules, and judgment of logical consistency. It may include confirmed items and corrective items from the original first vulnerability list, as well as newly identified business logic vulnerabilities by the model.

[0083] Specifically, each item in the second vulnerability list is second vulnerability information, encompassing richer semantic tags and contextual reasoning. Unlike traditional rule scanning, second vulnerability information not only includes basic attributes such as vulnerability type, severity level, and hit location, but also further includes business dimension information such as descriptions of business rule conflicts related to the vulnerability, call paths, role and permission impact analysis, and abnormal scenario coverage, enhancing the interpretability and business relevance of vulnerability identification. The corresponding code snippet is directly associated with the point where the vulnerability occurs and can be extended to include auxiliary judgment areas such as upstream and downstream call logic, judgment conditions, loop bodies, and abnormal branches, facilitating further tracing and analysis by auditors and subsequent tools.

[0084] Vulnerability analysis information is a semantic interpretation and judgment basis automatically generated by the audit model based on the second vulnerability list. It includes the model's judgment of the main triggering cause of the vulnerability, potential attack paths, differences from business rules, and the data objects or process nodes affected by the vulnerability. Vulnerability analysis information can be presented in the form of structured data, natural language descriptions, or visual graphs, providing direct basis for subsequent vulnerability verification, remediation suggestion generation, and audit report construction.

[0085] For example, in an order processing system, the model might identify a logical flaw where "the discount amount is not capped." The second vulnerability information would include the code location corresponding to this judgment logic, while the vulnerability analysis would indicate that this defect could lead to platform financial losses after additional discounts are applied, and list conflicting promotional strategy rules and clauses. Similarly, in a credit approval system, if it finds that a certain state in the approval process has not been correctly transferred to the pending review node, the model will output the relevant missing code path from the state machine and indicate in the analysis information that it may lead to the business consequence of "unauthorized loan disbursement."

[0086] In operation S240, the first analysis result is verified based on the second analysis result, and a business code audit result is generated based on the second analysis result and the verification result.

[0087] During the verification phase, the second vulnerability list output by the business code audit model can be compared item by item with the first vulnerability list obtained in the preliminary scanning phase. By using the vulnerability confidence score, semantic interpretation information, and business rule correlation output by the model, false alarms generated in the static analysis phase can be identified and eliminated. Vulnerabilities not covered by the preliminary scan but confirmed by the model can be supplemented to form a comprehensive and reliable business code audit result.

[0088] For example, if the model finds during business logic analysis that the input parameter has been validated according to business specifications in a higher-level function and that the validation conforms to the business documentation description, the system will mark the vulnerability as a false alarm, thereby avoiding unnecessary manual review workload.

[0089] For example, vulnerabilities that were not discovered in the initial scanning phase but were newly identified in the business logic analysis phase (such as omissions in state machine transitions in specific scenarios or bypassing of approval rules) can be automatically included in the final vulnerability list, and their discovery source and corresponding business scenario information can be clearly marked.

[0090] The preferred embodiments of this disclosure will be described below. It should be noted that the solutions listed below are not intended to limit the scope of this disclosure.

[0091] Figure 3A flowchart illustrating a method for processing a first analysis result and target business information according to an embodiment of the present disclosure is shown schematically.

[0092] like Figure 3 As shown, the method for processing the first analysis result and target business information in this embodiment includes operations S310 to S330.

[0093] When operating S310, a code dependency graph is constructed based on the code snippet corresponding to the first vulnerability information.

[0094] In the embodiments of this disclosure, a code dependency graph can be used to capture static features such as call relationships, data dependencies, and inheritance structures in the code segment corresponding to a vulnerability. For example, it can use code elements such as classes, functions, and variables as nodes in the graph, and relationships such as function calls, parameter passing, member access, and control jumps as edges, forming a structured input that can be used for graph modeling. The code dependency graph can be automatically generated by a static analysis engine or compiler front-end module, forming an input foundation that helps capture contextual behavior patterns.

[0095] In operation S320, feature extraction is performed on the code dependency graph to generate a context vector representation.

[0096] For example, a graph neural network model can be used for encoding to propagate and aggregate information about nodes and edges in the code dependency graph. For instance, the system can construct an initial embedding vector by combining semantic attributes such as the node's syntax type (e.g., class, method, variable), naming information, call frequency, dependency path depth, and the module level where the code resides, and then use a graph neural network model to perform multi-layer feature aggregation to further capture potential dependencies between functions and modules.

[0097] According to embodiments of this disclosure, context vectors can not only express the direct semantics of code fragments, but also supplement behavioral patterns that are missed or misjudged due to missing context in static scanning, providing semantic enhancement and reasoning support for subsequent vulnerability identification.

[0098] In operation S330, the context vector representation is fused with the features extracted from the target business information using multimodal feature fusion, and used as the input to the business code audit model.

[0099] Specifically, text semantic features and code context vectors can be fused using methods such as concatenation, attention mechanisms, or co-representation learning to form a unified input vector, which can be used to guide the model to conduct in-depth analysis on aspects such as business logic consistency, process coverage completeness, and rule implementation correctness.

[0100] Figure 4 A flowchart illustrating a method for processing a first analysis result and target business information according to another embodiment of the present disclosure is shown.

[0101] like Figure 4 As shown, the method for processing the first analysis result and target business information in this embodiment may include operations S410 to S430.

[0102] When operating S410, a control flow graph and a data flow graph are constructed based on the code snippet corresponding to the first vulnerability information. The control flow graph describes the relationships between logical branches, loop structures, and jump paths during program execution, reflecting the possible execution paths of the code under different conditions. The data flow graph represents the lifecycle of variables or objects in the program, including their definition, assignment, passing, and usage processes, focusing on capturing data propagation paths across statements, functions, and even modules.

[0103] For example, in financial lending systems, approval processes often involve multi-level state transitions and role controls. If a piece of code has incomplete state transition paths or fails to cover abnormal paths, it is difficult to identify this using static rules alone. However, by constructing a control flow graph of this code, all possible paths from initial approval to final approval can be clearly depicted, and logical gaps where a certain approval role lacks necessary review nodes can be identified.

[0104] For example, in an e-commerce promotion system, if a variable such as "final amount payable" is found to have inconsistent values ​​or not processed with a unified upper limit judgment in different branches when calculating the combined "discount and coupon", a data flow diagram can be constructed to trace the entire process of the variable from initialization to final output, and to find vulnerabilities such as rule bypass or incorrect discount amount caused by inconsistent logical branches.

[0105] In operation S420, the control flow graph and the data flow graph are vectorized to generate execution path features and data transfer features. Vectorization is a key step in converting the program structure and dependencies contained in the control flow graph and data flow graph into a high-dimensional feature representation acceptable to the model. It can be achieved through techniques such as graph neural networks, path embedding, and structural attention mechanisms.

[0106] Taking an e-commerce promotion system as an example, in the code-level implementation, product discount strategies may involve multiple conditional statements and function call logic, such as "whether it is a first-time user," "whether to combine products," and "whether the minimum purchase threshold is met." The control flow graph formed by these conditional branches can reflect the judgment path of the promotion logic. After vectorization, the path information between "user identity judgment - order amount calculation - promotion activity matching - final settlement" can be extracted for the model to understand whether the logic coverage is complete. At the same time, the system constructs a data flow graph for the reading, calculation, and writing paths of key data variables such as discount amount, product type, and user identifier, and extracts the data transmission chain of "user type, discount calculation, order generation" for the model to judge whether there is a risk of missing, duplicate application, or conflicting writing of cross-process parameters.

[0107] Specifically, each node in the control flow graph and data flow graph can be encoded with a combination of features such as its syntax type, scope, variable attributes, and whether it is a key decision point. Dependencies between nodes are established through edge-based information propagation. Conditional branch nodes in the control flow graph can capture the complexity of the decision logic, while write and read dependency paths in the data flow graph can identify the validity of variable usage. Subsequently, multi-layer graph neural networks or attention networks can be used to aggregate features of the graph structure, ultimately generating vector results representing the behavioral characteristics of the execution path and data transmission patterns. These vector results serve as input for subsequent models to judge the completeness of business logic and the correctness of data processing.

[0108] In operation S430, the execution path characteristics and the data transmission characteristics are used as inputs to the business code audit model.

[0109] Furthermore, the target business information includes not only textual descriptions of business rules and process documents, but also graphical interface information, such as user interface prototypes, UI design diagrams, front-end page structure diagrams, and mobile layout files. To enhance the model's ability to understand the consistency between interface behavior and back-end business logic, the system introduces a structured recognition mechanism for graphical interface information during processing.

[0110] Specifically, the graphical interface information can first be structurally analyzed. For example, technologies such as image recognition, OCR text extraction, DOM structure analysis, and interface element recognition can be used to automatically identify and classify visual elements such as buttons, input boxes, drop-down menus, navigation paths, and label prompts. The identified interface elements will be mapped to a set of structured visual features, such as interface hierarchy, control type, input constraints, interaction logic, visible state, and hidden state.

[0111] For example, in the product order interface, the system can identify interface controls such as "coupon input box", "payment method option" and "submit order button" and extract their associated interaction logic and display conditions.

[0112] Subsequently, the extracted visual element features can be jointly encoded with the previously generated code context vector representation, serving as the multimodal input to the business code auditing model. In practice, the joint encoding process can be achieved by concatenating feature vectors, introducing cross-modal attention mechanisms, or constructing a joint embedding space, enabling the business code auditing model to perform deeper logical consistency judgments based on the fusion of front-end interface semantics and back-end logical semantics.

[0113] For example, in a credit approval system, if the front-end page allows users to select "no guarantor required," but the back-end code does not verify whether the user's qualifications meet this condition, the model can identify the business logic vulnerability of "inconsistency between the front-end and back-end logic" through joint analysis of the interface and code semantics.

[0114] By introducing structured recognition and fusion modeling of graphical interface information, the embodiments of this disclosure enhance the business code audit model's ability to understand the mapping relationship between front-end behavior and back-end logic. It can discover interface guidance risks, interaction process vulnerabilities, and hidden bypass paths that are difficult to detect by traditional auditing methods, thereby enhancing the system's business audit adaptability and vulnerability identification breadth.

[0115] In the embodiments of this disclosure, during the verification phase, the differences between the first vulnerability list and the second vulnerability list can be analyzed to identify the intersection, complement, and exclusion items in the static analysis and semantic analysis results, thereby achieving accurate screening and supplementation of the preliminary detection results and improving the reliability and coverage of the audit conclusions.

[0116] Specifically, the second vulnerability list included in the second analysis results can be compared with the first vulnerability list in the first analysis results to identify newly added vulnerability items that exist in the second vulnerability list but are not included in the first vulnerability list. These are recorded as vulnerability supplementary items. Vulnerability supplementary items can represent business logic vulnerabilities discovered by the business code audit model during semantic analysis.

[0117] Simultaneously, based on the vulnerability analysis information in the second analysis results, each record in the first vulnerability list can be verified. Vulnerability analysis information can include vulnerability type, confidence score, triggering context, call path, and explanation of business rules. The system can use this information to determine whether the vulnerability is real or a false alarm due to context coverage, pre-verification, rule adaptation, or other reasons. Specifically, mechanisms such as rule matching enhancement, context clustering comparison, or model confidence threshold judgment can be used to divide the first vulnerability list into two subsets: "false alarm vulnerabilities" and "real vulnerability vulnerabilities."

[0118] For identified vulnerabilities, further structured annotations can be generated to form structured vulnerability information. This structured information can include vulnerability location (file, function, line of code), vulnerability cause description, call chain context, associated business rules, affected data objects, risk level classification, and remediation suggestion templates. This facilitates subsequent report generation, remediation prioritization, and allows developers to quickly locate the problem.

[0119] According to embodiments of this disclosure, the system can generate comprehensive business code audit results based on vulnerability supplementary items, false positives, and structured vulnerability information. These audit results not only reflect a real list of vulnerabilities in the current code implementation but also reduce manual intervention costs by filtering false positives and enhance the business semantic depth and coverage of vulnerability identification through the introduction of model analysis results. Output can include various formats such as structured reports, audit dashboards, and interactive visual analysis charts, adapting to the audit needs of multiple roles and stages. This method effectively integrates the high coverage of static analysis with the deep semantic capabilities of large-scale model analysis, achieving a synergistic improvement in accuracy and breadth. It is suitable for security auditing tasks of enterprise-level business systems with complex processes, dense rules, and frequent iterations.

[0120] In the embodiments disclosed herein, a closed-loop mechanism of audit-repair-re-audit can also be constructed based on the continuous audit capability after the business code is modified, so as to realize the automatic verification of the vulnerability repair effect and the continuous optimization of the code audit model.

[0121] Specifically, after developers modify the business code based on the remediation suggestions provided in the audit report, the system can automatically re-execute the initial scan and business logic analysis process on the modified business code to obtain information on the remediation effect.

[0122] Re-running the initial scan can quickly confirm whether the code location corresponding to the original vulnerability has been modified and whether the original hit rules are still triggered, which is suitable for verifying whether structural defects have been explicitly fixed. Re-running the business logic analysis further evaluates whether the modified business logic meets the original business rules or context constraints, preventing new logical jump omissions and state overriding conflicts caused by patch fixes.

[0123] For example, in an e-commerce order system, if the original vulnerability was "discount calculation did not handle exclusive logic", after the developers added a judgment branch, the system will remodel the control flow and data flow path during the semantic analysis stage to confirm whether the added logic meets the business rule that "same type of discounts cannot be stacked".

[0124] According to embodiments of this disclosure, the system can generate remediation effect information, which may include, for example, whether the original vulnerability still exists after modification, whether the corresponding location has been overwritten and repaired, whether the repaired business logic meets the expected rules, and whether new risk paths have been introduced. The remediation effect information can be used to retrospectively verify the effectiveness of the remediation, and can also be used to measure operational metrics such as vulnerability closure cycle and development response efficiency.

[0125] Building upon this foundation, repair suggestions and their effectiveness can be used as feedback data to update the business code audit model. By incorporating information such as successful repair cases, differences before and after repair, and deviations between model predictions and actual results into the model training sample set, fine-tuning of model weights or enhancement of static rules can be achieved, continuously improving the model's adaptability to similar scenarios and its recognition accuracy.

[0126] According to embodiments of this disclosure, by constructing code dependency graphs, control flow graphs, and data flow graphs, and combining business rules, documents, and graphical interface information to achieve multimodal feature fusion input, the system's ability to identify vulnerabilities in complex business logic is significantly improved. This method not only effectively reduces the problems of high false positive rates and insufficient understanding of business context in traditional static analysis, but also has the ability to automatically identify deep-seated vulnerabilities such as business process deviations, rule omissions, and missing state transitions. Simultaneously, the audit model supports fine-tuning and continuous learning mechanisms, and can be dynamically optimized based on remediation effect information, forming an audit-remediation-feedback closed loop, improving the system's adaptability and continuous evolution capabilities.

[0127] Corresponding to the above-described business code auditing method, embodiments of this disclosure also provide a business code auditing apparatus.

[0128] Figure 5 A schematic block diagram of a business code auditing apparatus according to an embodiment of the present disclosure is shown.

[0129] like Figure 5 As shown, the business code auditing device 500 of this embodiment includes a data acquisition module 510, an initial scanning module 520, a business logic analysis module 530, and a business code auditing module 540.

[0130] The data acquisition module 510 can be used to acquire target business information and target business code. In one embodiment, the data acquisition module 510 can be used to perform the operation S210 described above, which will not be repeated here.

[0131] The initial scanning module 520 can be used to perform a preliminary scan of the target business code to obtain a first analysis result. In one embodiment, the initial scanning module 520 can be used to perform the operation S220 described above, which will not be repeated here.

[0132] The business logic analysis module 530 can be used to perform business logic analysis based on the first analysis result and the target business information, using a business code auditing model, to obtain a second analysis result. In one embodiment, the business logic analysis module 530 can be used to execute the operation S230 described above, which will not be repeated here.

[0133] The business code audit module 540 can be used to verify the first analysis result based on the second analysis result, and generate a business code audit result based on the second analysis result and the verification result. In one embodiment, the business code audit module 540 can be used to perform the operation S240 described above, which will not be repeated here.

[0134] According to embodiments of this disclosure, the business logic analysis module 530 can also be used to construct a code dependency graph based on the code fragment corresponding to the first vulnerability information; extract features from the code dependency graph to generate a context vector representation; and fuse the context vector representation with features extracted from the target business information in a multimodal manner as input to the business code audit model.

[0135] According to embodiments of this disclosure, the business logic analysis module 530 can also be used to construct a control flow graph and a data flow graph based on the code fragment corresponding to the first vulnerability information; perform vectorization processing on the control flow graph and the data flow graph to generate execution path features and data transmission features; and use the execution path features and the data transmission features as input to the business code audit model.

[0136] According to embodiments of this disclosure, the business logic analysis module 530 can also be used to perform structured recognition of the graphical interface information, extract visual element features, and jointly encode the visual element features and the context vector representation as input to the business code audit model.

[0137] According to embodiments of this disclosure, the business code audit module 540 can also be used to compare the second vulnerability list and the first vulnerability list to obtain vulnerability supplementary items; verify the first vulnerability list based on the vulnerability analysis information to obtain vulnerability false alarm items and vulnerability true items; perform structured annotation on the vulnerability true items to obtain structured vulnerability information; and generate the business code audit result based on the vulnerability supplementary items, vulnerability false alarm items and the structured vulnerability information.

[0138] According to embodiments of this disclosure, the business code audit module 540 can also be used to respond to modifications to the business code by re-executing a preliminary scan and business logic analysis process on the modified business code to obtain repair effect information; and to update the code audit model based on the repair suggestions and the repair effect information.

[0139] According to embodiments of this disclosure, any multiple modules among the data acquisition module 510, initial scanning module 520, business logic analysis module 530, and business code auditing module 540 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least some of the functions of one or more of these modules can be combined with at least some of the functions of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the data acquisition module 510, initial scanning module 520, business logic analysis module 530, and business code auditing module 540 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging the circuitry, or implemented in any one of the three implementation methods of software, hardware, and firmware, or in a suitable combination of any of these. Alternatively, at least one of the data acquisition module 510, the initial scanning module 520, the business logic analysis module 530, and the business code auditing module 540 can be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.

[0140] Figure 6 A block diagram of an electronic device suitable for implementing a business code auditing method according to an embodiment of the present disclosure is shown schematically.

[0141] like Figure 6 As shown, an electronic device 600 according to an embodiment of the present disclosure includes a processor 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage portion 606 into a random access memory (RAM) 603. The processor 601 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 601 may also include onboard memory for caching purposes. The processor 601 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0142] RAM 603 stores various programs and data required for the operation of electronic device 600. Processor 601, ROM 602, and RAM 603 are interconnected via bus 604. Processor 601 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 602 and / or RAM 603. It should be noted that the programs may also be stored in one or more memories other than ROM 602 and RAM 603. Processor 601 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.

[0143] According to embodiments of this disclosure, the electronic device 600 may further include an input / output (I / O) interface 605, which is also connected to a bus 604. The electronic device 600 may also include one or more of the following components connected to the input / output (I / O) interface 605: an input section 606 including a keyboard, mouse, etc.; an output section 607 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the input / output (I / O) interface 605 as needed. A removable medium 611, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 610 as needed so that computer programs read from it can be installed into the storage section 608 as needed.

[0144] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.

[0145] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 602 and / or RAM 603 and / or one or more memories other than ROM 602 and RAM 603 described above.

[0146] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to enable the computer system to implement the business code auditing method provided in the embodiments of this disclosure.

[0147] When the computer program is executed by the processor 601, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0148] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and downloaded and installed via the communication section 609, and / or installed from the removable medium 611. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0149] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 609, and / or installed from the removable medium 611. When the computer program is executed by the processor 601, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0150] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on a user's computing device, partially on a user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0151] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0152] Those skilled in the art will understand that the features described in the various embodiments of this disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments of this disclosure can be combined and / or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0153] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A method for auditing business code, characterized in that, The method includes: Obtain target business information and target business code; A preliminary scan of the target business code was performed to obtain the first analysis result; Based on the first analysis result and the target business information, a business logic analysis is performed using a business code auditing model to obtain a second analysis result; and The first analysis result is verified based on the second analysis result, and a business code audit result is generated based on the second analysis result and the verification result.

2. The method according to claim 1, characterized in that, The code auditing model is obtained by fine-tuning the parameters of a pre-trained large language model. The fine-tuning is based on a multi-source labeled dataset, which includes code auditing scenarios, business logic information, and vulnerability labels.

3. The method according to claim 1 or 2, characterized in that, The first analysis result includes a first vulnerability list, which includes first vulnerability information and corresponding code snippets; the second analysis result includes a second vulnerability list and vulnerability analysis information, which includes second vulnerability information and corresponding code snippets.

4. The method according to claim 3, characterized in that, The step of performing business logic analysis using a business code auditing model based on the first analysis result and the target business information to obtain the second analysis result specifically includes: Based on the code snippets corresponding to the first vulnerability information, construct a code dependency graph; Feature extraction is performed on the code dependency graph to generate a context vector representation; and The context vector representation is fused with features extracted from the target business information using multimodal feature fusion, and used as input to the business code audit model.

5. The method according to claim 3, characterized in that, The step of performing business logic analysis using a business code auditing model based on the first analysis result and the target business information to obtain the second analysis result specifically includes: Based on the code snippet corresponding to the first vulnerability information, construct a control flow graph and a data flow graph; The control flow graph and the data flow graph are vectorized to generate execution path features and data transfer features; and The execution path characteristics and the data transmission characteristics are used as inputs to the business code audit model.

6. The method according to claim 4, characterized in that, The target business information includes graphical interface information, and the method further includes: The graphical interface information is subjected to structured recognition to extract visual element features; and The visual element features and the context vector representation are jointly encoded and used as input to the business code audit model.

7. The method according to claim 3, characterized in that, The step of verifying the first analysis result based on the second analysis result, and generating a business code audit result based on the second analysis result and the verification result, specifically includes: The second vulnerability list is compared with the first vulnerability list to obtain additional vulnerability items; The first vulnerability list is verified based on the vulnerability analysis information to obtain false vulnerability reports and actual vulnerability reports. The actual vulnerability items are structurally annotated to obtain structured vulnerability information; and Based on the vulnerability supplement items, false vulnerability items, and the structured vulnerability information, the audit results of the business code are generated.

8. The method according to any one of claims 1, 2, 4 to 7, characterized in that, The method further includes: In response to modifications to the business code, a preliminary scan and business logic analysis process are re-executed on the modified business code to obtain information on the repair effect; and The code audit model is updated based on the repair suggestions and the repair effect information.

9. A business code auditing device, characterized in that, The device includes: The data acquisition module is used to: acquire target business information and target business code; The initial scanning module is used to: perform a preliminary scan of the target business code and obtain a first analysis result; The business logic analysis module is used to: perform business logic analysis based on the first analysis result and the target business information using a business code auditing model to obtain a second analysis result; and The business code audit module is used to: verify the first analysis result based on the second analysis result, and generate a business code audit result based on the second analysis result and the verification result.

10. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 8.

11. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 8.

12. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 8.

Citation Information

Cited By

  • Task deployment and control method, system and device based on artificial intelligence and storage medium

    CN122285228A