Open source component multi-mode dependence risk tracing method and device
By combining static and dynamic analysis, BAP binary analysis, natural language processing, and knowledge graphs, the problem of the inability to identify dynamic dependencies in existing technologies has been solved, enabling comprehensive detection and risk assessment of software component dependencies and improving supply chain security.
Patent Information
- Application Number
- CN202511531485.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-24
- Publication Date
- 2026-01-20
AI Technical Summary
Existing technologies cannot effectively identify dynamically loaded or indirect dependencies when detecting software component dependencies, and lack cross-modal fusion analysis, resulting in insufficient supply chain security.
A combination of static and dynamic analysis is employed. Component dependencies are extracted through AST analysis and script parsing. Combined with the BAP binary analysis platform and machine learning models, hidden dependencies and malicious code are detected. Natural language processing technology is used to parse license files, construct component dependency graphs, and combine them with knowledge graphs for risk assessment.
It improves the comprehensiveness and accuracy of dependency detection, can identify potential supply chain attack points, provides a comprehensive risk score, supports time-backtracking queries, and enhances the security and reliability of software components.
Smart Images

Figure CN121365402A_ABST
Abstract
Citation Information
Cited By
Security intelligent monitoring and risk assessment method for open source software supply chain
CN121580391A
Multi-source heterogeneous data intelligent analysis method and system
CN121786820A
Sensitive data circulation risk assessment and detection system and method based on AI
CN122204560A