Program processing method, computing device, storage medium and program product
By collecting and decompiling the static and dynamic codes of the target program, the problem of inaccurate code features in the prior art is solved, and more accurate program verification is achieved.
Patent Information
- Application Number
- PCT/IB2025/052163
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-13
- Filing Date
- 2025-02-28
- Publication Date
- 2025-09-18
AI Technical Summary
In the existing technology, the code features obtained through white box analysis are not accurate enough and cannot fully characterize the features of the program during runtime, resulting in inaccurate verification methods.
A non-invasive injection method is used to collect static and dynamic code of the target program during runtime, and decompile to obtain the target source code, and perform semantic analysis to obtain more comprehensive code features.
By collecting static and dynamic codes simultaneously, more comprehensive and accurate code features are obtained, which improves the accuracy of program verification without affecting the application operation of the target program.
Smart Images

Figure IB2025052163_18092025_PF_FP_ABST
Abstract
Description
[0001] PROGRAM PROCESSING METHOD, COMPUTING DEVICE, STORAGE MEDIUM, AND PROGRAM PRODUCT TECHNICAL FIELD
[0002]
[0001] The present disclosure relates to the field of computer technology, and more particularly to a program processing method, a computing device, a storage medium, and a program product.
[0003] To improve program security, stability, or compatibility, code analysis can be performed on the program to obtain code features, which can then be used to verify the program. For example, in a microservice scenario, individual microservice applications can be designed and developed based on a microservice framework, splitting the service program into multiple microservice applications. Each microservice application can correspond to a function provided by the service program. The microservice framework can provide multiple APIs (Application Programming Interfaces) for developers to use. Therefore, understanding the APIs used by the service program can ensure the compatibility and stability of the service program when the microservice framework is upgraded.
[0004]
[0003] Currently, white box analysis is usually used to perform semantic analysis on static code generated during the program compilation phase to obtain code features. However, static code cannot fully represent the program runtime features, resulting in inaccurate code features.
[0005]
[0004] The embodiments of the present disclosure provide a program processing method, a computing device, a storage medium, and a program product to solve the problem of low accuracy of code features in related technologies.
[0006]
[0005] In a first aspect, an embodiment of the present disclosure provides a program processing method, comprising: using a collection program to collect static code and dynamic code of a target program during its execution; wherein the collection program is non-invasively injected into the target program; decompiling the static code and the dynamic code to obtain a target source code; wherein the target source code is used to perform semantic analysis to obtain code features.
[0007]
[0006] Optionally, the method further includes: sending the target source code to a control terminal, so that the control terminal performs semantic analysis on the target source code to obtain code features, and performs verification processing on the target program based on the code features.
[0008]
[0007] Optionally, the method further includes: performing semantic analysis on the target source code to obtain code features; and sending the code features to the control end so that the control end can perform verification processing on the target program based on the code features.
[0009]
[0008] In a second aspect, an embodiment of the present disclosure provides a program processing method, comprising: determining a target source code of a target program; decompiling the target source code to obtain static code and dynamic code collected when the target program is running; collecting the static code and the dynamic code by a collection program that is non-invasively injected into the target program; and performing semantic analysis on the target source code to obtain code features.
[0010]
[0009] Optionally, the method further includes: performing verification processing on the target program based on the code features.
[0011]
[0010] Optionally, performing semantic analysis on the target source code to obtain code features includes: detecting target information that meets sensitivity requirements in the target source code; deleting the target information or replacing the target information with preset information to update the target source code; and performing semantic analysis on the updated target source code to obtain code features.
[0012]
[0011] Optionally, the target program is a microservice application; and the verifying the target program based on the code features includes: determining code features corresponding to a plurality of microservice applications divided into the service program; archiving the code features corresponding to the plurality of microservice applications to obtain code features corresponding to the service program; and verifying the service program based on the code features corresponding to the service program.
[0013]
[0012] Optionally, the code features include usage information of the application program interface provided by the microservice framework; the verification processing of the service program based on the code features corresponding to the service program includes: providing the usage information to the framework provider of the microservice framework, so that the framework provider verifies the usage information, and receiving the verification result provided by the framework provider, and sending a prompt message to the developer corresponding to the service program based on the verification result; or, based on the usage information and upgrade requirements, building a test case for the microservice framework; or, based on the usage information, if it is determined that there is a risk of misuse of the application program interface, sending a risk notification to the developer corresponding to the service program.
[0014]
[0013] In a third aspect, an embodiment of the present disclosure provides a program processing method, comprising: obtaining a collection program; non-invasively injecting the collection program into the target program; running the collection program to use the collection program to collect static code and dynamic code of the target program during runtime, and decompiling the static code and the dynamic code to obtain target source code; wherein the target source code is used to perform semantic analysis to obtain code features.
[0015]
[0014] Optionally, the non-invasively injecting the acquisition program into the target program includes: loading an agent tool; and non-invasively injecting the acquisition program into the target program using the agent tool.
[0016]
[0015] Optionally, obtaining the acquisition program includes: obtaining the acquisition program issued by the scheduling end; the acquisition program is provided by the user to the scheduling end.
[0016] In a fourth aspect, embodiments of the present disclosure provide a program processing method, comprising: determining a user-provided acquisition program in response to an acquisition instruction; sending the acquisition program to at least one server, so that the server non-invasively injects the acquisition program into a target program to acquire static code and dynamic code of the target program, and decompiling the static code and the dynamic code to obtain target source code; wherein the target source code is used to perform semantic analysis to obtain code features.
[0017]
[0017] In a fifth aspect, an embodiment of the present disclosure provides a computing device, comprising a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement the program processing method described in the first aspect above, or the program processing method described in the second aspect above, or the program processing method described in the third aspect above, or the program processing method described in the fourth aspect above.
[0018]
[0018] In a sixth aspect, an embodiment of the present disclosure provides a computer storage medium storing a computer program. When the computer program is executed by a computer, the program processing method described in the first aspect, the program processing method described in the second aspect, the program processing method described in the third aspect, or the program processing method described in the fourth aspect is implemented.
[0019]
[0019] In a seventh aspect, an embodiment of the present disclosure provides a computer program product, including a computer program / instruction. When the computer program / instruction is executed by a computer, it implements the program processing method described in the first aspect, the program processing method described in the second aspect, the program processing method described in the third aspect, or the program processing method described in the fourth aspect.
[0020] The disclosed embodiments utilize a collection program to collect static and dynamic code during the runtime of a target program. The collection program non-invasively injects the code into the target program, decompiles the static and dynamic code, and obtains target source code. The target source code is then used for semantic analysis to obtain code features. Simultaneously collecting both static and dynamic code allows for more comprehensive code analysis, resulting in more comprehensive and accurate code features, thereby improving the accuracy of target program verification using code features. Furthermore, using non-invasive injection to collect code allows for comprehensive and accurate collection of required data without affecting the operation of the target program application, thereby improving collection efficiency and quality.
[0021]
[0021] These and other aspects of the present disclosure will become more readily apparent in the following description of the embodiments.
[0022]
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technology descriptions. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0023] FIG1 shows a flow chart of an embodiment of a program processing method provided by the present disclosure;
[0024] FIG2 shows a flow chart of an embodiment of a program processing method provided by the present disclosure;
[0025] FIG3 shows a flow chart of an embodiment of a program processing method provided by the present disclosure;
[0026] FIG4 shows a flow chart of an embodiment of a program processing method provided by the present disclosure;
[0027] FIG5 shows a schematic diagram of scene interaction in an actual application of an embodiment of the present disclosure;
[0028] FIG6 shows a schematic structural diagram of an embodiment of a program processing device provided by the present disclosure;
[0029] FIG7 shows a schematic structural diagram of an embodiment of a program processing device provided by the present disclosure;
[0030] FIG8 is a schematic structural diagram of an embodiment of a program processing device provided by the present disclosure;
[0031] FIG9 is a schematic diagram showing the structure of an embodiment of a program processing device provided by the present disclosure;
[0032]
[0032] FIG10 shows a schematic diagram of a structure of an embodiment of a computing device provided by the present disclosure.
[0033]
[0033] In order to enable people skilled in the art to better understand the solution of the present disclosure, the technical solution in the embodiment of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiment of the present disclosure.
[0034] Some of the processes described in the specification and claims of this disclosure and the accompanying drawings include multiple operations that appear in a specific order. However, it should be understood that these operations may be executed in a different order than the order in which they appear herein or in parallel. Operation sequence numbers, such as 101 and 102, are merely used to distinguish between different operations and do not represent any specific order of execution. Furthermore, these processes may include more or fewer operations, and these operations may be executed sequentially or in parallel. It should be noted that terms such as "first" and "second" herein are used to distinguish between different messages, devices, modules, etc., and do not represent a sequential order, nor do they limit "first" and "second" to different types.
[0035] As described in the background art, a traditional white-box analysis method involves performing semantic analysis on the static code generated during the program compilation phase to obtain code features, and then verifying the program based on the code features. However, during the implementation of the present disclosure, the inventors discovered that because programs involve a large number of external dependencies, especially in large-scale programs, these external dependencies are often in other source code libraries, and these dependencies cannot be obtained based on the code features of the static code. In addition, some programs may use a dynamic loading mode at runtime, which may add some new functions to the program, and these functions cannot be reflected in the static code. Therefore, the white-box analysis method results in less accurate verification.
[0036] To improve verification accuracy, the inventors, after a series of studies, have proposed the technical solution disclosed herein. In an embodiment of the present disclosure, a collection program is used to collect static and dynamic code during the runtime of a target program. The collection program is non-invasively injected into the target program, and then decompiles the static and dynamic code to obtain target source code. The target source code is then used for semantic analysis to obtain code features. Simultaneously collecting both static and dynamic code allows for more comprehensive code analysis, resulting in more comprehensive and accurate code features, thereby improving the accuracy of target program verification using code features. Furthermore, using non-invasive injection to collect code allows for comprehensive and accurate collection of required data without affecting the operation of the target program application, thereby improving collection efficiency and quality.
[0037] The technical solutions in the embodiments of the present disclosure will be described clearly and completely below with reference to the accompanying drawings. It is apparent that the described embodiments are only a portion of the embodiments of the present disclosure, and are not intended to be exhaustive. All other embodiments derived by those skilled in the art based on the embodiments of the present disclosure without inventive effort are intended to fall within the scope of protection of the present disclosure.
[0038]
[0038] It should be noted that the embodiments of the present disclosure may involve the use of user data. In actual applications, user-specific personal data can be used in the solutions described herein within the scope permitted by applicable laws and regulations of the country where the use occurs (for example, with the user's explicit consent, effective notification to the user, etc.).
[0039]
[0039] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.
[0040]
[0040] It should be noted that the technical solution of the embodiment of the present disclosure is applicable to a network virtual environment. The users, framework providers, developers, etc. described are generally referred to as "virtual users". Real users can register a user account in the server through registration to obtain a user identity in the network environment.
[0041]
[0041] The following describes in detail the implementation details of the technical solution of the embodiment of the present disclosure.
[0042]
[0042] FIG1 is a flow chart of an embodiment of a program processing method provided by the present disclosure. The technical solution of this embodiment can be executed by an acquisition program. The method may include the following steps.
[0043]
[0043] 101: Utilize an acquisition program to acquire static codes and dynamic codes when a target program is running.
[0044] The target program can refer to any program, including backend service programs, front-end applications, or scripts. In one practical application of the present disclosure, the target program can be a microservice application. A microservice application is a software architecture that decomposes a large, monolithic program into a set of small, independent microservice applications. Each microservice application runs in its own process. Developers can use a microservice framework to build and run microservice applications.
[0044]
[0045] Static code is determined and fixed during the compilation phase, meaning it exists before the target program runs and does not change during runtime. Dynamic code is code that is created, modified, or executed during the runtime of the target program. This can include code generated in real time as needed and / or remote code pulled from external sources. In practical applications, in scripting languages like Python and JavaScript, code can be constructed from strings at runtime and converted into executable objects or modules using built-in functions or API calls. Remote code can refer to code stored in an external source outside the local program and downloaded over the network for local execution. For example, a program with hot-update capabilities can pull the latest code version from a remote code repository and replace some or all of the local logic. Alternatively, in some open platform frameworks, a program can pull verified, secure scripts or plug-in code from a remote server to extend its functionality.
[0045]
[0046] Among them, the acquisition program can be injected into the target program without intrusion when the target program is running, and the acquisition program can be injected into the runtime environment of the program.
[0046]
[0047] Of course, the acquisition program can also be injected into the target program without intrusion before the target program runs.
[0047]
[0048] The acquisition program can be a specific code snippet or function that can be dynamically added to the target program's running process without modifying the target program's source code. It can collect data without changing the target program's logic and without significantly affecting the target program's performance.
[0048]
[0049] Agent technology, such as eBPF (Extended Berkeley Packet Filter), can be used to non-invasively inject the collection program into the target program while it is running. eBPF is a lower-level non-invasive injection technology that can dynamically insert and execute code in the kernel and user space applications. Agent tools, such as Java (a programming language) Agent and Python Agent, are standalone programs that can inject required functionality into the target program by modifying the bytecode or adding new classes and methods at runtime without modifying the source code. For example, if the target program is a Java program, the JVM can
[0049] The Java Agent provided by the Java Virtual Machine (Java Virtual Machine) inserts the acquisition program into the program runtime environment by loading the specified Agent class when the target program is running.
[0050]
[0050] The acquisition program can collect static code and dynamic code when the program is running. The acquisition program can realize the acquisition of static code and dynamic code through the API provided by the underlying system such as JVM.
[0051]
[0051] The target program and the acquisition program may be run in a computing device. When the target program is a backend service program, the computing device may be a server, etc.
[0052]
[0052] 102: Decompile the static code and the dynamic code to obtain the target source code.
[0053] The target source code is a code written in a programming language that contains all the instructions and logic of the target program and is used to instruct the computer to perform a specific task. The target source code needs to be converted into binary code or bytecode by a compiler or interpreter so that the computer can execute it.
[0054]
[0054] The static code and the dynamic code may be binary codes or byte codes converted by the compiler from the target source code. The static code and the dynamic code may be decompiled using a decompilation tool to obtain the target source code.
[0055]
[0055] The target source code can be used to perform semantic analysis to obtain code features. The code features can be used to verify the target program.
[0056] The target source code can be converted into an AST (Abstract Syntax Tree). The AST can represent the grammatical structure of the target source code in the form of a tree, where each node in the tree represents a structure in the target source code. Furthermore, a semantic analyzer can be used to perform in-depth analysis on the AST to obtain code features.
[0057] Code features may include, for example, features of the code structure, syntax, semantics, control flow, data flow, type, and exception handling. Based on code features, the behavior, intent, and potential problems of the target source code can be identified, facilitating code optimization, reconstruction, error detection, and quality improvement operations on the target source code.
[0058] In this embodiment, a collection program is used to collect static code and dynamic code during the runtime of a target program. The collection program is non-invasively injected into the target program, and then decompiles the static code and dynamic code to obtain target source code. The target source code is used for semantic analysis to obtain code features. Since both static and dynamic code are collected simultaneously, a more comprehensive code analysis can be performed, resulting in more comprehensive and accurate code features, thereby improving the accuracy of verifying the target program using code features. Furthermore, by collecting code using a non-invasive injection method, required data can be comprehensively and accurately collected without affecting the operation of the target program application, thereby improving the efficiency and quality of the collection.
[0059]
[0059] As an optional method, the acquisition program can directly perform semantic analysis on the target source code to obtain code features. Therefore, the method can also include: performing semantic analysis on the target source code to obtain code features; and sending the code features to the control terminal so that the control terminal can verify the target program based on the code features.
[0060] Since semantic analysis of the target source code typically requires a significant amount of resources, as another alternative, the target source code can be sent to a control terminal through a mechanism such as event notification. The control terminal can then perform semantic analysis on the target source code to obtain code features, thereby avoiding consuming significant resources on the server running the target program. The control terminal can be a centralized server cluster, which has more powerful computing capabilities than the server running the target program. Therefore, the method can further include: sending the target source code to the control terminal, for the control terminal to perform semantic analysis on the target source code to obtain code features, and verifying the target program based on the code features.
[0061]
[0061] FIG2 is a flow chart of an embodiment of a program processing method provided by the present disclosure. The technical solution of this embodiment can be executed by an acquisition program or a control terminal. The method may include the following steps.
[0062]
[0062] 201: Determine the target source code of the target program.
[0063]
[0063] As an optional method, the technical solution of this embodiment can be executed by the control end, and the target source code of the target program can be sent to the control end by the acquisition program.
[0064]
[0064] The control terminal may be implemented as a distributed server cluster consisting of multiple servers, or as a single server. The server may also be a server of a distributed system, or a server integrated with a blockchain. The server may also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms, or an intelligent cloud computing server or intelligent cloud host with artificial intelligence technology.
[0065]
[0065] The target source code decompiles the static code and dynamic code collected when the target program is running. The static code and dynamic code are collected by a collection program that is injected into the target program without intrusion.
[0066]
[0066] 202: Perform semantic analysis on the target source code to obtain code features.
[0067] In this embodiment, the target source code of the target program is determined, and semantic analysis is performed on the target source code to obtain code features. The target source code is obtained by decompiling static code and dynamic code collected during the runtime of the target program; the static code and dynamic code are collected by a collection program that is non-invasively injected into the target program. Since both static and dynamic code are collected simultaneously, a more comprehensive code analysis can be performed, resulting in more comprehensive and accurate code features, thereby improving the accuracy of verifying the target program using code features. Furthermore, using non-invasive injection to collect code allows for comprehensive and accurate collection of required data without affecting the operation of the target program application, thereby improving the efficiency and quality of collection.
[0068]
[0068] In some embodiments, performing semantic analysis on the target source code to obtain code features may include: detecting target information in the target source code that meets sensitivity requirements; deleting the target information or replacing the target information with preset information to update the target source code; and performing semantic analysis on the updated target source code to obtain code features.
[0069] For example, target information can include private data such as usernames, passwords, and encryption keys. Deleting target information or replacing it with pre-set information can prevent sensitive information leaks and reduce security risks.
[0069]
[0070] In some embodiments, the method may further include: performing verification processing on the target program based on code features.
[0070]
[0071] In some embodiments, the target program may be a microservice application.
[0071]
[0072] A microservice application is a software architecture style that breaks down a large, monolithic program into a set of small, independent microservice applications. Each microservice application runs in its own process, and developers can use a microservice framework to build and run these applications. For example, an e-commerce service might independently develop and design microservice applications for different functions, such as product management, order processing, user authentication, and payment processing. Each microservice application focuses on completing a specific function and can be independently deployed, scaled, and maintained. These microservice applications interact and integrate using lightweight protocols, collaborating to achieve the functionality of the entire service.
[0072]
[0073] Since a service program may involve multiple microservice applications, the above-mentioned verification of the target program based on code features may include: determining the code features corresponding to the multiple microservice applications divided by the service program; archiving the code features corresponding to the multiple microservice applications to obtain the code features corresponding to the service program; and verifying the service program based on the code features corresponding to the service program.
[0073]
[0074] Archiving code features corresponding to multiple microservice applications may include, for example, merging code features that meet similar conditions, then archiving them to obtain code features corresponding to the service program. For example, similar conditions may include variable and function names with identical semantics, similar control flows and logical structures, and code blocks and functions with identical functionality or behavior. This simplifies code feature representation, reduces redundancy and noise, and helps users better understand the source code.
[0074]
[0075] In actual applications, microservice frameworks provide numerous flexible APIs for developers of service programs. Consequently, the code of the programs developed by these developers is deeply integrated with the microservice framework. Consequently, when upgrading a microservice framework, the framework provider cannot determine which APIs are being used due to the wide variety of API usage. Consequently, they are unable to specifically verify the upgrade compatibility of the microservice framework, posing significant stability risks. Furthermore, framework providers often set API usage rules to regulate how developers use them. Promptly notifying developers of potential misuse risks is also crucial. Therefore, in some embodiments, the aforementioned code features may include API usage information provided by the microservice framework.
[0075]
[0076] The usage information may include, for example, the API name, the number of times the API is used, the API usage method such as in which functional modules it is used, etc. The archiving of the code features may include statistics on the number of times the API is used, etc.
[0076]
[0077] As an optional implementation, verifying a service program based on its corresponding code features can include: providing usage information to the microservice framework provider for verification; receiving verification results from the framework provider, and sending a prompt to the developer of the service program based on the verification results. This implementation allows the framework provider to fully understand the usage of the application program interface and conduct targeted verification of the compatibility and stability of the microservice framework.
[0077]
[0078] As another optional implementation, based on the code features corresponding to the service program, verifying the service program may include: building test cases for the micro-service framework based on usage information and upgrade requirements.
[0078]
[0079] For example, if a microservice framework requires an upgrade, to ensure the compatibility and stability of the service program, test cases can be built based on the service program's API usage information and upgrade requirements. This ensures that the test cases ensure that the service program's API usage information remains unchanged. Once the test cases are verified and used to upgrade the microservice framework, the upgraded microservice framework remains compatible with the service program, ensuring the stability of the service program. Building test cases based on usage information ensures that the functionality and performance of important APIs are not affected. Furthermore, microservice framework upgrades may add, modify, or deprecate certain APIs. Corresponding test cases can be planned to ensure that all uses of deprecated or modified APIs are correctly handled.
[0079]
[0080] As another optional implementation, verifying the service program based on code features corresponding to the service program may include: sending a risk notification to the developer of the service program if, based on usage information, it is determined that there is a risk of misuse of the application program interface.
[0080]
[0081] Alternatively, it is possible to determine whether the application has an interface misuse risk by judging whether the usage information meets the risk condition.
[0081]
[0082] For example, the risk condition may be application program interface failure, call error, input parameter error, and / or call sequence error. Application program interface failure may mean, for example, that the application program has been deprecated or is not recommended for use. If a service program is determined to have a misuse risk, a corresponding risk notification is sent to the developer of the service program. The developer can improve the use of the application program interface based on the risk notification to reduce the risk of misuse.
[0082]
[0083] Optionally, code collection for the target program can be performed multiple times, thereby combining the current usage information and historical usage information of the service program to determine whether there is an API misuse risk. The service program may be considered to have a misuse risk if the usage information meets the risk condition multiple times or if the usage information meets the risk condition a specified number of times.
[0083]
[0084] FIG3 is a flowchart of an embodiment of a program processing method provided by the present disclosure. The technical solution of this embodiment can be executed by a computing device. When the target program is a Java program, the technical solution of this embodiment can be specifically executed by a JVM running in the computing device. The method may include the following steps.
[0084]
[0085] 301: Get the acquisition program.
[0085]
[0086] 302: Inject the acquisition program into the target program without intrusion.
[0086]
[0087] The acquisition program may be injected non-invasively while the target program is running. Of course, the acquisition program may also be injected non-invasively before the target program is running.
[0087]
[0088] 303: Run the acquisition program to use the acquisition program to acquire static code and dynamic code of the target program when it is running, and decompile the static code and dynamic code to obtain the target source code.
[0088]
[0089] The target source code is used for semantic analysis to obtain code features; the code features can be used to verify the target program.
[0089]
[0090] In this embodiment, a collection program is obtained and non-invasively injected into the target program. The collection program is then run to collect static and dynamic code from the target program during runtime. The static and dynamic code are then decompiled to obtain the target source code. The target source code is then used for semantic analysis to obtain code features. The simultaneous collection of static and dynamic code allows for more comprehensive code analysis, resulting in more comprehensive and accurate code features, thereby improving the accuracy of target program verification using code features. Furthermore, using non-invasive injection to collect code allows for comprehensive and accurate collection of required data without affecting the operation of the target program application, thereby improving collection efficiency and quality.
[0090]
[0091] In some embodiments, obtaining the collection program may include obtaining the collection program issued by the scheduling end. The collection program may be provided to the scheduling end by a user. The user may be, for example, a framework provider, a specific operation and maintenance personnel, or a testing personnel.
[0091]
[0092] In some embodiments, non-invasively injecting the acquisition program into the target program may include: loading an agent tool; and non-invasively injecting the acquisition program into the target program using the agent tool.
[0092]
[0093] The agent tool may be an agent tool such as a Java Agent or a Python Agent. The agent tool can be used to insert a collection program into the program runtime environment by loading a specified Agent class when the target program is running.
[0093]
[0094] FIG4 is a flowchart of an embodiment of a program processing method provided by the present disclosure. The technical solution of this embodiment can be executed by the scheduling end.
[0094]
[0095] 401: In response to a collection instruction, determine a collection program provided by a user.
[0095]
[0096] 402: Sending a collection program to at least one server so that the server non-invasively injects the collection program into the target program to collect static code and dynamic code of the target program, and decompiles the static code and dynamic code to obtain target source code.
[0096]
[0097] The target source code is used for semantic analysis to obtain code features; the code features are used to verify the target program.
[0097]
[0098] In this embodiment, in response to a collection instruction, a user-provided collection program is determined and sent to at least one server. The server then non-invasively injects the collection program into the target program to collect the target program's static and dynamic code. The server then decompiles the static and dynamic code to obtain target source code, which is then used for semantic analysis to obtain code features. Simultaneously collecting both static and dynamic code allows for more comprehensive code analysis, resulting in more comprehensive and accurate code features, thereby improving the accuracy of target program verification using code features. Furthermore, using non-invasive injection to collect code allows for comprehensive and accurate collection of required data without affecting the operation of the target program application, thereby improving collection efficiency and quality.
[0098]
[0099] To facilitate understanding, the following uses a microservice application as an example. This microservice application can be derived from a service program developed based on a microservice framework. The technical solution of the present disclosure will be introduced with reference to the interactive scenario diagram of a practical application of the present disclosure shown in FIG5 . A user 501 can issue a collection instruction to multiple servers 503 via a dispatch terminal 502. Each server 503 can run a microservice application 504 corresponding to the service program. In response to the collection instruction, the server 503 can load an agent tool and use the agent tool to inject the collection program 505 in the collection instruction into the runtime environment of the microservice application 504.
[0099]
[0100] Taking the microservice application 504 as a Java program as an example, the server running the microservice application 504 can execute the collection instruction, load the Java Agent provided by the JVM, and use the Java Agent to non-invasively inject the collection program 505 issued by the scheduling end into the microservice application 504 when the microservice application 504 is running.
[0100]
[0101] When microservice application 504 is running, collection program 505 can collect the static and dynamic code corresponding to microservice application 504 based on the API provided by the JVM. Collection program 505 can decompile the static and dynamic code to obtain the target source code, and can provide the target source code to control terminal 506 through, for example, an event notification mechanism.
[0101]
[0102] The control terminal 506 can obtain the target source code corresponding to each of the multiple microservice applications corresponding to the service program, perform semantic analysis on each of the target source code, detect target information in the target source code that meets sensitivity requirements, delete the target information or replace it with preset information, and update the target source code corresponding to each of the multiple microservice applications to achieve desensitization. Subsequently, semantic analysis can be performed on the desensitized target source code to obtain code features corresponding to each of the multiple microservice applications. The code features corresponding to the multiple microservice applications are archived, for example, by merging code features that meet similar requirements to obtain code features corresponding to the service program.
[0103] The code features may include usage information of the application program interface provided by the micro-service framework. The control terminal 506 may provide this usage information to the framework provider 507 of the micro-service framework, for verification by the framework provider 507. The framework provider 507 may be the same as the user 501. The control terminal 506 may also receive the verification result provided by the framework provider 507 and send a prompt message to the developer 508 of the service program based on the verification result.
[0102]
[0104] Of course, the control terminal 506 can also build test cases for the micro-service framework based on usage information and upgrade requirements. In addition, the control terminal 506 can also send a risk notification to the developer 508 of the service program if it determines that there is a risk of misuse of the application program interface based on usage information and risk conditions.
[0103]
[0105] In this embodiment, a server running a micro-service application can execute a collection instruction sent by a user via a scheduling terminal, non-invasively injecting the collection program issued by the scheduling terminal into the micro-service application while it is running. Furthermore, the collection program is run to collect static and dynamic code from the micro-service application during runtime. The static and dynamic code are then decompiled to obtain target source code. The control terminal then performs semantic analysis on the target source code to obtain code features, and verifies the target program based on these features. Since both static and dynamic code are collected simultaneously, more comprehensive code analysis can be performed, resulting in more comprehensive and accurate code features, thereby improving the accuracy of verification of the target program using code features. Furthermore, using non-invasive injection to collect code allows for comprehensive and accurate collection of required data without disrupting the operation of the micro-service application, thereby improving collection efficiency and quality.
[0104]
[0106] Furthermore, framework providers can comprehensively monitor API usage based on code characteristics, enabling targeted verification of the microservice framework's compatibility and stability. Service program developers can also use risk notifications to improve API usage and reduce the risk of misuse. The control side can also build test cases to further ensure the compatibility and stability of the microservice framework.
[0105]
[0107] FIG6 is a schematic diagram of the structure of an embodiment of a program processing device provided by an embodiment of the present disclosure. The program processing device includes: a collection module 601, which is used to use a collection program to collect static code and dynamic code of a target program during runtime; and a decompilation module 602, which is used to decompile the static code and dynamic code to obtain a target source code.
[0106]
[0108] The target source code can be used for semantic analysis to obtain code features, which can be used to verify the target program.
[0107]
[0109] In some embodiments, as an optional method, the device can perform semantic analysis on the target source code to obtain code features; and send the code features to the control end so that the control end can verify the target program based on the code features.
[0108]
[0110] Since semantic analysis of the target source code usually takes up a lot of resources, as another optional method, the device can send the target source code to the control end, so that the control end can perform semantic analysis on the target source code to obtain code features and verify the target program based on the code features.
[0109]
[0111] The program processing device shown in FIG6 can execute the program processing method described in the embodiment shown in FIG1 . Its implementation principles and technical effects are not further described. The specific manner in which the various modules and units of the program processing device in the above embodiment perform operations has been described in detail in the embodiment related to the method and will not be elaborated upon here.
[0110]
[0112] FIG7 is a schematic diagram of the structure of an embodiment of a program processing device provided by an embodiment of the present disclosure. The program processing device includes: a determination module 701 for determining the target source code of a target program; and an analysis module 702 for performing semantic analysis on the target source code to obtain code features.
[0111]
[0113] In some embodiments, the apparatus may further include a verification processing module, which may be configured to perform verification processing on the target program based on code features.
[0112]
[0114] In some embodiments, the analysis module performs semantic analysis on the target source code to obtain code features, which may include: detecting target information in the target source code that meets sensitivity requirements; deleting the target information or replacing the target information with preset information to update the target source code; and performing semantic analysis on the updated target source code to obtain code features.
[0113]
[0115] In some embodiments, the target program may be a microservice application.
[0114]
[0116] Because a service program can involve multiple microservice applications, the verification processing module verifies the target program based on code features, which may include: determining the code features corresponding to the multiple microservice applications divided into the service program; archiving the code features corresponding to the multiple microservice applications to obtain the code features corresponding to the service program; and verifying the service program based on the code features corresponding to the service program.
[0115]
[0117] Archiving code features corresponding to multiple microservice applications can, for example, include merging code features that meet similar conditions and then archiving them to obtain code features corresponding to the service programs. For example, similar conditions can include variable and function names with identical semantics, similar control flows and logical structures, and code blocks and functions with identical functionality or behavior. This simplifies code feature representation, reduces redundancy and noise, and helps users better understand the source code.
[0116]
[0118] In actual applications, microservice frameworks provide numerous flexible APIs for user use, and the code of user-developed programs is also deeply integrated with the microservice framework. Consequently, when upgrading a microservice framework, due to the wide variety of API usage, framework providers have no way of knowing which APIs are being used. Consequently, they are unable to specifically verify the upgrade compatibility of the microservice framework, posing significant stability risks. Furthermore, framework providers often set API usage rules to regulate user usage, making it crucial to promptly notify users of potential misuse risks. Therefore, in some embodiments, the aforementioned code features may include API usage information provided by the microservice framework.
[0117]
[0119] The usage information may include, for example, the API name, the number of times the API is used, the API usage method such as in which functional modules it is used, etc. The archiving of the code features may include statistics on the number of times the API is used, etc.
[0118]
[0120] As an optional implementation, the verification module can verify the service program based on the corresponding code features. This may include: providing usage information to the microservice framework provider for verification; receiving verification results from the framework provider; and sending a prompt message to the developer of the service program based on the verification results. This implementation allows the framework provider to fully understand the usage of the application program interface and conduct targeted verification of the compatibility and stability of the microservice framework.
[0119]
[0121] As another optional implementation, the verification processing module may verify the service program based on the code features corresponding to the service program, and may include: building test cases for the microservice framework based on usage information and upgrade requirements.
[0120]
[0122] As another optional implementation, the verification processing module may verify the service program based on code features corresponding to the service program, and may include: sending a risk notification to the developer of the service program if it is determined based on usage information that there is a risk of misuse of the application program interface.
[0121]
[0123] Optionally, whether the application has an interface misuse risk may be determined by judging whether the usage information satisfies a risk condition.
[0122]
[0124] Optionally, the device can perform code collection on the target program multiple times, thereby combining the current usage information and historical usage information of the service program to determine whether there is a risk of API misuse. The service program may be considered to have a misuse risk if the usage information meets the risk condition multiple times or if the usage information meets the risk condition a specified number of times.
[0123]
[0125] The program processing device shown in FIG. 7 can execute the program processing method described in the embodiment shown in FIG. 2 , and its implementation principles and technical effects are not further described. The specific manner in which the various modules and units of the program processing device in the above embodiment perform operations has been described in detail in the embodiment related to the method and will not be further elaborated here.
[0124]
[0126] FIG8 is a schematic diagram of the structure of an embodiment of a program processing device provided by an embodiment of the present disclosure. The program processing device includes: an acquisition module 801 for acquiring a collection program; an injection module 802 for non-invasively injecting the collection program into a target program; and a running module 803 for running the collection program to use the collection program to collect static code and dynamic code of the target program at runtime, and decompile the static code and dynamic code to obtain target source code. The target source code is used for semantic analysis to obtain code features; and the code features are used to verify the target program.
[0125]
[0127] In some embodiments, the acquisition module acquiring the acquisition program may include: acquiring the acquisition program issued by the scheduling end. The acquisition program is provided by the user to the scheduling end.
[0126]
[0128] In some embodiments, the injecting module non-invasively injecting the acquisition program into the target program may include: loading an agent tool; and injecting the acquisition program non-invasively into the target program using the agent tool.
[0127]
[0129] The program processing device shown in FIG8 can execute the program processing method described in the embodiment shown in FIG3 . Its implementation principles and technical effects are not further described. The specific manner in which the various modules and units of the program processing device in the above embodiment perform operations has been described in detail in the embodiment related to the method and will not be elaborated upon here.
[0128]
[0130] FIG9 is a schematic structural diagram of an embodiment of a program processing device provided by an embodiment of the present disclosure. The program processing device includes a response module 901 and a sending module 902 .
[0129]
[0131] The response module 901 is configured to determine a collection program provided by a user in response to a collection instruction.
[0130]
[0132] A sending module 902 is configured to send a collection program to at least one server, so that the server non-invasively injects the collection program into a target program to collect static and dynamic code from the target program, and decompile the static and dynamic code to obtain target source code. The target source code is used for semantic analysis to obtain code features, and the code features are used to verify the target program.
[0131]
[0133] The program processing device shown in FIG. 9 can execute the program processing method described in the embodiment shown in FIG. 4 , and its implementation principles and technical effects are not further described. The specific manner in which the various modules and units of the program processing device in the above embodiment perform operations has been described in detail in the embodiment related to the method and will not be further elaborated here.
[0132]
[0134] An embodiment of the present disclosure further provides a computing device, as shown in FIG10 , which may include a storage component 1001 and a processing component 1002; the storage component 1001 stores one or more computer instructions, wherein the one or more computer instructions are invoked and executed by the processing component to implement the program processing method described in the embodiment shown in FIG1 , FIG2 , FIG3 , or FIG4 .
[0133]
[0135] Of course, the computing device may also include other components, such as input / output interfaces, display components, communication components, etc.
[0134]
[0136] The input / output interface provides an interface between the processing component and the peripheral interface module, which may be an output device, an input device, etc. The communication component is configured to facilitate wired or wireless communication between the computing device and other devices.
[0135]
[0137] The processing component 1002 may include one or more processors to execute computer instructions to complete all or part of the steps in the above method. Of course, the processing component may also be one or more application-specific integrated circuits.
[0136] (ASIC), digital signal processor (DSP), digital signal processing device (DSPD), programmable logic device (PLD), field programmable gate array (FPGA), controller, microcontroller, microprocessor or other electronic components are used to perform the above method.
[0137]
[0138] The storage component 1001 is configured to store various types of data to support operations in the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM) or a combination thereof.
[0138] (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.
[0139]
[0139] The display component can be an electroluminescent (EL) element, a liquid crystal display or a micro display having a similar structure, or a retinal direct display or a similar laser scanning display.
[0140]
[0140] It should be noted that the computing device may be a physical device or an elastic computing host provided by a cloud computing platform. It may be implemented as a distributed cluster consisting of multiple servers or terminal devices, or as a single server or a single terminal device.
[0141]
[0141] It should be noted that when the computing device implements the program processing method described in the embodiment shown in FIG. 1 , FIG. 2 , FIG. 3 , or FIG. 4 , it can be a physical device or an elastic computing host provided by a cloud computing platform. It can be implemented as a distributed cluster consisting of multiple servers or terminal devices, or as a single server or a single terminal device.
[0142]
[0142] The present disclosure also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a computer, it can implement the program processing method described in the embodiment shown in FIG. 1 , FIG. 2 , FIG. 3 , or FIG. 4 . The computer-readable medium can be included in the electronic device described in the above embodiment; or it can exist independently and not be incorporated into the electronic device.
[0143]
[0143] The present disclosure also provides a computer program product, comprising a computer program carried on a computer-readable storage medium. When the computer program is executed by a computer, it can implement the program processing method described in the embodiments shown in FIG. 1 , FIG. 2 , FIG. 3 , or FIG. 4 . In such an embodiment, the computer program can be downloaded and installed from a network and / or installed from a removable medium. When the computer program is executed by a processor, it performs various functions defined in the system of the present disclosure.
[0144]
[0144] In the above corresponding embodiments, the computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or component.
[0145]
[0145] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0146] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. Persons of ordinary skill in the art can understand and implement the present invention without inventive effort.
[0147] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by means of hardware. Based on this understanding, the above technical solution, in essence, or the portion that contributes to the relevant art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.
[0148]
[0148] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present disclosure, rather than to limit them. Although the present disclosure has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present disclosure.
Claims
Claims 1. A program processing method, comprising: A collection program is used to collect static code and dynamic code of a target program during its runtime; wherein the collection program is non-invasively injected into the target program; the static code and the dynamic code are decompiled to obtain target source code; wherein the target source code is used to perform semantic analysis to obtain code features.
2. The method according to claim 1, further comprising: The target source code is sent to a control terminal, so that the control terminal performs semantic analysis on the target source code to obtain code features, and performs verification processing on the target program based on the code features.
3. The method according to claim 2, further comprising: Performing semantic analysis on the target source code to obtain code features; The code features are sent to a control terminal, so that the control terminal can perform verification processing on the target program based on the code features.
4. A program processing method, comprising: Determine the target source code of the target program; The target source code is obtained by decompiling static code and dynamic code collected when the target program is running; The static code and the dynamic code are collected by a collection program that is non-invasively injected into the target program; semantic analysis is performed on the target source code to obtain code features.
5. The method according to claim 4, further comprising: Based on the code features, verification processing is performed on the target program.
6. The method according to claim 4, wherein: The performing semantic analysis on the target source code to obtain code features includes: detecting target information in the target source code that meets sensitivity requirements; deleting the target information or replacing the target information with preset information to update the target source code; and performing semantic analysis on the updated target source code to obtain code features.
7. The method according to claim 5, wherein: The target program is a microservice application; the verification processing of the target program based on the code features includes: determining the code features corresponding to multiple microservice applications divided by the service program; archiving the code features corresponding to the multiple microservice applications to obtain the code features corresponding to the service program; and verifying the service program based on the code features corresponding to the service program.
8. The method according to claim 7, wherein: The code features include usage information of the application program interface provided by the micro-service framework; the verification processing of the service program based on the code features corresponding to the service program includes: providing the usage information to the framework provider of the micro-service framework, so that the framework provider verifies the usage information, and receiving the verification result provided by the framework provider, and sending a prompt message to the developer corresponding to the service program based on the verification result; or, based on the usage information and upgrade requirements, building a test case for the micro-service framework; or, based on the usage information, if it is determined that there is a risk of misuse of the application program interface, sending a risk notification to the developer corresponding to the service program.
9. A program processing method, comprising: Obtain acquisition procedures; Injecting the acquisition program into the target program without intrusion; The acquisition program is run to acquire static code and dynamic code of the target program during its operation, and the static code and the dynamic code are decompiled to obtain target source code; wherein the target source code is used for semantic analysis to obtain code features.
10. The method according to claim 9, wherein: The non-invasively injecting the acquisition program into the target program includes: loading an agent tool; and non-invasively injecting the acquisition program into the target program using the agent tool.
11. The method according to claim 9, wherein: The acquiring of the collection program includes: acquiring the collection program sent by the scheduling end; and providing the collection program to the scheduling end by the user.
12. A program processing method, comprising: In response to the collection instruction, determining a collection program provided by the user; The acquisition program is sent to at least one server so that the server non-invasively injects the acquisition program into a target program to acquire static code and dynamic code of the target program, and decompiles the static code and the dynamic code to obtain target source code; wherein the target source code is used for semantic analysis to obtain code features.
13. A computing device comprising a processing component and a storage component; wherein: The storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement the following The program processing method according to any one of claims 1 to 3, or the program processing method according to any one of claims 4 to 8, or the program processing method according to any one of claims 9 to 11, or the program processing method according to claim 12.
14. A computer storage medium storing a computer program, wherein: When the computer program is executed by a computer, the program processing method according to any one of claims 1 to 3, the program processing method according to any one of claims 4 to 8, the program processing method according to any one of claims 9 to 11, or the program processing method according to claim 12 is implemented.
15. A computer program product comprising a computer program / instructions, wherein: When the computer program / instruction is executed by a computer, the program processing method according to any one of claims 1 to 3, the program processing method according to any one of claims 4 to 8, the program processing method according to any one of claims 9 to 11, or the program processing method according to claim 12 is implemented.
Citation Information
Patent Citations
Automatic application bug mining system and method under Android platform
CN107832619A
Securing Code Execution in a Network Environment
US20180060584A1
Time Travel Source Code Debugger Incorporating Redaction Of Sensitive Information
US20190213355A1