Open source component multi-mode dependence risk tracing method and device

By combining static and dynamic analysis, BAP binary analysis, natural language processing, and knowledge graphs, the problem of the inability to identify dynamic dependencies in existing technologies has been solved, enabling comprehensive detection and risk assessment of software component dependencies and improving supply chain security.

CN121365402APending Publication Date: 2026-01-20FUJIAN YIRONG INFORMATION TECH +1
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202511531485.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-24
Publication Date
2026-01-20

AI Technical Summary

Technical Problem

Existing technologies cannot effectively identify dynamically loaded or indirect dependencies when detecting software component dependencies, and lack cross-modal fusion analysis, resulting in insufficient supply chain security.

Method used

A combination of static and dynamic analysis is employed. Component dependencies are extracted through AST analysis and script parsing. Combined with the BAP binary analysis platform and machine learning models, hidden dependencies and malicious code are detected. Natural language processing technology is used to parse license files, construct component dependency graphs, and combine them with knowledge graphs for risk assessment.

Benefits of technology

It improves the comprehensiveness and accuracy of dependency detection, can identify potential supply chain attack points, provides a comprehensive risk score, supports time-backtracking queries, and enhances the security and reliability of software components.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121365402A_ABST
    Figure CN121365402A_ABST
Patent Text Reader

Abstract

The invention relates to an open source component multi-modal dependency risk tracing method and device, and the method comprises the steps: employing a mode of combining static analysis and dynamic analysis to analyze a component dependency relationship of software, and combining AST analysis and construction script analysis; function-level features are extracted, a binary fingerprint database is constructed, the similarity between different versions is analyzed through LSH, behavior patterns in binary codes are analyzed, and hidden dependencies or malicious code injection is detected; the version updating history of the dependent component is analyzed and monitored by using a time sequence, and the vulnerability security of the component is evaluated in combination with attack graph analysis; high-risk components on the path are calculated, potential supply chain attack points are identified, and risk points are subjected to cross validation; a time sequence diagram database is used for recording the component dependency relationship, and time backtracking query is supported. According to the method, a multi-mode dependency analysis method is adopted, potential dependency risks are rapidly identified, and potential supply chain attack risks are timely warned.
Need to check novelty before this filing date? Find Prior Art

Citation Information

Cited By

  • Security intelligent monitoring and risk assessment method for open source software supply chain

    CN121580391A

  • Multi-source heterogeneous data intelligent analysis method and system

    CN121786820A

  • Sensitive data circulation risk assessment and detection system and method based on AI

    CN122204560A