A source code package vulnerability analysis method, device, terminal and storage medium

By analyzing the jar package information in the source code and judging its introduction method, providing risk warnings, it solves the problem that code auditors find it difficult to detect source code vulnerabilities, and achieves the effect of reducing unpredictable risks.

CN113886823BActive Publication Date: 2025-05-09SECZONE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111137987.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-27
Publication Date
2025-05-09
Estimated Expiration
2041-09-27

AI Technical Summary

Technical Problem

It is difficult for code auditors to intuitively discover vulnerabilities or hazardous information hidden in the source code, resulting in unpredictable risks during the use of the source code.

Method used

Provide a vulnerability analysis method for source code packages, which can obtain jar package information in source code, judge the introduction method of jar packages, and warn of the jar package risk information based on the preset plan.

Benefits of technology

Enable code auditors to intuitively discover the risk information hidden in the source code jar package, thereby urging developers to replace or upgrade the jar package and reduce unpredictable risks in the process of using the source code.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113886823B_ABST
    Figure CN113886823B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of code auditing, and in particular to a vulnerability analysis method, device, terminal and storage medium for a source code package, the method comprising the following steps: obtaining jar package information in the source code; judging the introduction method of the jar package according to the jar package information; and alerting the risk information of the jar package according to a preset scheme based on the introduction method of the jar package. The present application enables code auditors to more intuitively discover the risk information hidden in the jar package of the source code, thereby urging developers to use other jar packages for replacement or upgrade, and reducing the unpredictable risks in the process of using the source code.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of code auditing, and in particular to a source code package vulnerability analysis method, device, terminal and storage medium. Background Art

[0002] Vulnerabilities are weaknesses or defects in the specific implementation of hardware, software, protocols, or system security policies, which can allow attackers to access or damage the system without authorization. Vulnerabilities may come from design defects or coding errors in application software or operating systems, or from design defects or unreasonable logical processes in the interactive processing of services. These defects, errors, or unreasonable places may be exploited intentionally or unintentionally, thereby adversely affecting the assets or operations of an organization, such as information systems being attacked or controlled, important information being stolen, user data being tampered with, and the system being used as a springboard to invade other host systems.

[0003] In related technologies, many developers do not know whether some third-party components (jar packages) have vulnerabilities or hazards when using them, and are prone to mistakenly use third-party components with vulnerabilities or hazards in source code.

[0004] With respect to the above-mentioned related technologies, the inventors believe that code auditors cannot intuitively discover vulnerabilities or harmful information hidden in the source code, which leads to unpredictable risks in the process of using the source code. Summary of the invention

[0005] In order to enable code auditors to more intuitively discover the risk information hidden in the jar package of the source code, the present application provides a vulnerability analysis method, device, terminal and storage medium for a source code package.

[0006] In a first aspect, the present application provides a vulnerability analysis method for a source code package, which adopts the following technical solution:

[0007] A vulnerability analysis method for a source code package includes the following steps:

[0008] Get the jar package information in the source code;

[0009] Determine the method of introducing the jar package according to the jar package information;

[0010] Based on the introduction method of the jar package, a warning is issued for the risk information of the jar package according to a preset plan.

[0011] By adopting the above technical solution, code auditors can more intuitively discover the risk information hidden in the jar package of the source code, thereby urging developers to use other jar packages for replacement or upgrade, thereby reducing the unpredictable risks in the process of using the source code.

[0012] Optionally, the jar package information includes the address coordinates of the jar package or the suffix of the jar package file.

[0013] By adopting the above technical solution, in order to determine the introduction method of the jar package, a source code detection device can be used to scan and analyze the suffix of the jar package file in the source code, so as to improve the detection efficiency and accuracy.

[0014] Optionally, determining the method of introducing the jar package according to the jar package information specifically includes: if the address coordinates of the jar package are recorded in the pom file, the method of introducing the jar package is pom coordinate introduction; if the suffix of the jar package file is .jar, the method of introducing the jar package is direct writing of jar.

[0015] By adopting the above technical solution, in order to determine the introduction method of the jar package, directly judging the suffix of the jar package file or querying the address coordinates of the jar package recorded in the pom file is the simplest and most direct judgment method. This judgment method can greatly improve the judgment speed and accuracy.

[0016] Optionally, when the jar package is introduced by pom coordinates, the preset solution specifically includes:

[0017] Obtain identification content of the jar package, where the identification content includes one or more of an open source organization name, a jar package name, a version number, and a hash value;

[0018] The risk information matching the jar package is searched in the vulnerability information library according to the identification content. If found, the risk information is displayed for warning. If not found, it will be displayed that there is no matching result.

[0019] By adopting the above technical solution, the jar package introduced by the pom coordinates is a project built based on Maven. The pom file can be parsed by the source code detection device to obtain one or more identification contents of the open source organization name, jar package name, version number and hash value of the jar package, and then the risk information matching the identification contents can be searched in the vulnerability information library according to the identification contents.

[0020] Optionally, when the jar package is introduced by directly writing the jar package, the preset solution specifically includes:

[0021] Calculate the hash value of the jar package;

[0022] The risk information matching the jar package is searched in the vulnerability information library according to the hash value. If found, the risk information is displayed for warning. If not found, it will be displayed that there is no matching result.

[0023] By adopting the above technical solution, when the jar package is introduced by directly writing the jar, since the specific content of the jar package is stored in the source program, at this time, a hash value calculation tool can be used to calculate the hash value of the jar package, and then the risk information matching it can be searched in the vulnerability information library according to the hash value.

[0024] Optionally, the risk information includes vulnerabilities and hazards of the jar package and corresponding solutions.

[0025] By adopting the above technical solution, the vulnerability information database stores security vulnerability data information such as the hazard information and corresponding solutions for each discovered vulnerability. These security vulnerability data information corresponding to the current jar package are imported into the risk information and displayed, which enables code auditors to more intuitively discover the risk information hidden in the source code jar package.

[0026] Optionally, the vulnerability information database includes the China National Information Security Vulnerability Database CNNVD and the International Vulnerability Information Database CVE.

[0027] By adopting the above technical solution, China National Information Security Vulnerability Database CNNVD and International Vulnerability Information Database CVE are relatively authoritative vulnerability information databases. Simultaneous searching in the above two vulnerability information databases is conducive to ensuring the authority of the retrieved risk data.

[0028] In a second aspect, the present application also provides a source code package vulnerability analysis device, which adopts the following technical solution:

[0029] A source code package vulnerability analysis device, comprising:

[0030] A memory, used for storing a vulnerability analysis program;

[0031] The processor executes the steps of the vulnerability analysis method of the source code package when running the vulnerability analysis program.

[0032] By adopting the above technical solution, the above vulnerability analysis method is presented in the form of computer-readable code and stored in the memory. When the processor runs the computer-readable code in the memory, the steps of the above vulnerability analysis method are executed, which allows code auditors to more intuitively discover the risk information hidden in the jar package of the source code, thereby urging developers to use other jar packages for replacement or upgrading, thereby reducing the unpredictable risks in the process of using the source code.

[0033] In a third aspect, the present application also provides a vulnerability analysis terminal for a source code package, which adopts the following technical solution:

[0034] A vulnerability analysis terminal for a source code package, comprising:

[0035] Source code detection device, used to scan and analyze jar package information in the source code;

[0036] A risk display device, used to display the risk information of the jar package;

[0037] The above-mentioned vulnerability analysis device has an input end connected to the source code detection device, and an output end connected to the risk display device.

[0038] By adopting the above technical solution, the terminal uses the source code detection device to scan and analyze the jar package information in the source code. Combined with the above-collected signals through its internal program, the code auditor can more intuitively discover the risk information hidden in the jar package of the source code, thereby urging the developer to use other jar packages for replacement or upgrade, reducing the unpredictable risks in the process of using the source code.

[0039] In a fourth aspect, the present application further provides a computer-readable storage medium, which adopts the following technical solution:

[0040] A computer-readable storage medium stores a computer program that can be loaded by a processor and execute the vulnerability analysis method of the source code package.

[0041] In summary, this application enables code auditors to more intuitively discover the risk information hidden in the source code jar package, thereby urging developers to use other jar packages for replacement or upgrade, reducing the unpredictable risks in the process of using the source code. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 It is a principle block diagram of the vulnerability analysis terminal of the source code package of this application.

[0043] Figure 2 It is a flowchart of the vulnerability analysis method of the source code package of this application.

[0044] Description of reference numerals:

[0045] 1. Source code detection device; 2. Vulnerability analysis device; 3. Risk display device. DETAILED DESCRIPTION

[0046] In order to make the purpose, technical solutions and advantages of this application more clear, the following Figure 1-2 It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0047] The following is a further detailed description of an embodiment of the vulnerability analysis terminal of the source code package of the present application in conjunction with the drawings of the specification.

[0048] Code auditing is to check the security defects in the source code, check whether there are security risks in the program source code, or whether there are any irregularities in coding. Through automated tools or manual review, the program source code is checked and analyzed line by line to discover the security vulnerabilities caused by these source code defects and provide code revision measures and suggestions. It is an integral part of the defensive programming paradigm, which attempts to reduce errors before software is released.

[0049] The present application embodiment provides a source code package vulnerability analysis terminal, such as Figure 1 As shown, the terminal includes a source code detection device 1, a vulnerability analysis device 2 and a risk display device 3, the input end of the vulnerability analysis device 2 is connected to the source code detection device 1, and the output end of the vulnerability analysis device 2 is connected to the risk display device 3; the vulnerability analysis device 2 is integrated with a memory and a processor, the memory is used to store the vulnerability analysis program, and the processor is used to execute the steps of the vulnerability analysis method of the above-mentioned source code package when running the vulnerability analysis program; the source code detection device 1 is used to scan and analyze the jar package information in the source code; the risk display device 3 is used to display the risk information of the jar package.

[0050] The following is a detailed description of the implementation of the vulnerability analysis method in conjunction with the vulnerability analysis terminal:

[0051] The present application embodiment discloses a vulnerability analysis method for a source code package. Figure 2 ,The vulnerability analysis method of the source code package includes the following steps:

[0052] S01: Get the jar package information in the source code;

[0053] Specifically, the jar package information includes the address coordinates of the jar package or the suffix of the jar package file. The source code detection device 1 is used to scan and analyze the jar package information in the source code. The source code detection device 1 can use the CodeSecure detection platform, the Fortify SCA detection platform or the Checkmarx Suite detection platform. In the embodiment of the present application, the CodeSecure detection platform can be used to scan and analyze the suffix of the jar package file in the source code to prepare for the next step of determining the introduction method of the jar package.

[0054] S02: Determine the method of introducing the jar package according to the jar package information;

[0055] Specifically, it includes: judging the import method of the jar package according to the address coordinates of the jar package or the suffix of the jar package file; if the address coordinates of the jar package are recorded in the pom file, the import method of the jar package is pom coordinate import; if the suffix of the jar package file is .jar, the import method of the jar package is jar direct writing. By judging the address coordinates of the jar package or the suffix of the jar package file, the import method of the jar package can be obtained, so that it is convenient to use different solutions for different import methods to query the risk information of the jar package.

[0056] S03: Based on the introduction method of the jar package, the risk information of the jar package is warned according to the preset plan.

[0057] When the jar package is imported using pom coordinates, the preset solutions include:

[0058] S31: Obtain the identification content of the jar package, which includes one or more of the open source organization name, jar package name, version number and hash value; the jar package introduced by the pom coordinates is a project built based on Maven, and the pom file can be parsed by the source code detection device 1 to obtain the identification content of the jar package such as the open source organization name, jar package name, version number and hash value.

[0059] S32: searching for risk information matching the jar package in the vulnerability information library according to the identification content. If found, the risk information is displayed for warning. If not found, it is displayed that there is no matching result.

[0060] Vulnerability information repositories include public databases such as the China National Information Security Vulnerability Database CNNVD, the International Information Security Vulnerability Database CVE, or custom information security vulnerability databases; the vulnerability information database stores security vulnerability data information such as the open source organization name, jar package name, version number, hash value, existing hazard information, and corresponding solutions for each discovered vulnerability; the vulnerability information database is used to achieve the sharing of security vulnerability data information, so that security vulnerability data information can be quickly, timely, and accurately transmitted to various organizations and individuals, increasing the interoperability between different network security tools.

[0061] Specifically, the security vulnerability data information matching the current jar package can be searched in the vulnerability information library according to one or more identification contents of the open source organization name, jar package name, version number and hash value; for example, in a pom file that records the address coordinates of the jar package, after parsing using the source code detection device 1, the following results are obtained:

[0062] <dependency>

[0063] <groupid> org.jsoup< / groupid>

[0064] <artifactid> jsoup< / artifactid>

[0065] <version> 1.8.1< / version>

[0066] < / dependency>

[0067] The open source organization name of the jar package recorded in the pom file is org.jsoup, the jar package name is jsoup, and the version number is 1.8.1. Therefore, you can query the vulnerability information of the jar package named jsoup in the vulnerability information library based on the jar package name information alone; because the same jar package name may correspond to multiple different version information, in order to query more accurately, you can also query based on the jar package name, version number and open source organization name; some pom files even specify the hash value of the referenced jar package, and you can also query based on the hash value.

[0068] For example, if you search for vulnerability information of the jar package named jsoup in the China National Information Security Vulnerability Database CNNVD, you can find the following risk information:

[0069] “JSoup cross-site scripting vulnerability;

[0070] CNNVD number: CNNVD-201509-460, Hazard level: Medium, CVE number: CVE-2015-6748, Vulnerability type: Cross-site scripting, Release time: 2015-08-28, Threat type: Remote, Update time: 2020-02-11, Manufacturer: jsoup, Vulnerability source: Florian Weimer.

[0071] Vulnerability Introduction: JSoup is a Java HTML parser developed by American software developer Jonathan Hedley. It can retrieve and manipulate data through DOM, CSS, and JQuery-like operation methods.

[0072] There is a cross-site scripting vulnerability in Jsoup versions prior to 1.8.3. A remote attacker can exploit this vulnerability to execute arbitrary script code in the context of the affected site and steal cookie-based authentication.

[0073] Vulnerability Notice: The manufacturer has released an upgrade patch to fix the vulnerability. The patch acquisition link is: https: / / github.com / jhy / jsoup / pull / 582. ”

[0074] The risk display device 3 displays the above risk information for warning, and the code auditor can intuitively see the identification content and risk information of the current jar package through the risk display device 3. Because it is clearly pointed out in the risk information: "There is a cross-site scripting vulnerability in versions before Jsoup1.8.3. Remote attackers can use this vulnerability to execute arbitrary script code in the context of the affected site and steal cookie-based authentication." The version number of the current jar package is "1.8.1", which is a version before "1.8.3". Therefore, the current jar package has a medium-risk risk, and developers need to follow the corresponding solution measures in the risk information "The manufacturer has released an upgrade patch to fix the vulnerability, patch acquisition link: https: / / github.com / jhy / jsoup / pull / 582", go to the corresponding website to obtain the patch or use other jar packages as a substitute to eliminate the risk.

[0075] When the jar package is introduced by writing directly into the jar, the preset solutions include:

[0076] S41: Calculate the hash value of the jar package;

[0077] When the jar package is introduced by directly writing the jar, since the specific content of the jar package is stored in the source program, a hash value calculation tool can be used to calculate the hash value of the jar package.

[0078] S42: Search for risk information matching the jar package in the vulnerability information library according to the hash value. If found, the risk information will be displayed for warning. If not found, it will be displayed that there is no matching result. The risk information includes the vulnerabilities and hazards of the jar package and the corresponding solutions.

[0079] Vulnerability information repositories include public databases such as the China National Information Security Vulnerability Database CNNVD, the International Information Security Vulnerability Database CVE, or custom information security vulnerability databases; the vulnerability information database stores security vulnerability data information such as the open source organization name, jar package name, version number, hash value, existing hazard information, and corresponding solutions for each discovered vulnerability; the vulnerability information database is used to achieve the sharing of security vulnerability data information, so that security vulnerability data information can be quickly, timely, and accurately transmitted to various organizations and individuals, increasing the interoperability between different network security tools.

[0080] Specifically, the security vulnerability data information that matches the current jar package can be searched in the vulnerability information library according to the hash value of the current jar package; for example, assuming that the source code records the jar package named "NVIDIA Jetson" by directly writing jar, the hash value calculation tool can be used to calculate the hash value of the jar package, and the security vulnerability data information with the same hash value can be searched in the vulnerability information library according to the hash value of the jar package; for example, by querying the vulnerability information of the hash value of the jar package in the China National Information Security Vulnerability Database CNNVD, the following risk information can be found:

[0081] “NVIDIA Jetson Input Validation Error Vulnerability;

[0082] CNNVD number: CNNVD-202106-1473, hazard level: high risk, CVE number: CVE-2021-34372, vulnerability type: input validation error, release time: 2021-06-21, threat type: local, update time: 2021-06-30.

[0083] Vulnerability Introduction: Nvidia NVIDIA Jetson TX2 and NVIDIA Jetson TX1 are both embedded system development modules from Nvidia, an American company.

[0084] NVIDIA Jetson has an input validation error vulnerability. The vulnerability is caused by a vulnerability in the NVIDIA OTE protocol message parsing code of the Trusty (NVIDIA's trusted operating system for Jetson devices) driver, that is, an integer overflow in the malloc() size calculation leads to a buffer overflow on the heap. Attackers can exploit this vulnerability to cause information disclosure, privilege escalation, and denial of service.

[0085] Vulnerability announcement: The manufacturer has released an upgrade patch to fix the vulnerability. The patch acquisition link is: https: / / nvidia.custhelp.com / app / answers / detail / a_id / 5205.

[0086] Patch: Fix for NVIDIA Jetson input validation error vulnerability. ”

[0087] The risk display device 3 displays the above risk information for warning, and the code auditor can intuitively see the identification content and risk information of the current jar package through the risk display device 3. Since it is clearly pointed out in the risk information that the hazard level of the jar package is high risk, and the manufacturer has released an upgrade patch to fix the vulnerability and disclosed the patch acquisition link; therefore, the code auditor can intuitively query whether the above patch has been updated in the source code based on the risk information. If the above patch has not been updated, the developer can be asked to obtain the patch from the corresponding website in time or use other jar packages as a substitute to eliminate the risk.

[0088] Here, no matter whether pom coordinates are used for introduction or jar is written directly, if no risk information matching the current jar package is found, it means that the current jar package is not in the vulnerability information library. At this time, the identification content of the current jar package or the specific content of the current jar package and its hash value can be stored in the custom information security vulnerability library, so as to facilitate further analysis of the current jar package by manual or other methods in the later stage, so as to determine the vulnerabilities, hazards and corresponding solutions of the current jar package. If the above risk information is found to exist, the risk information can be updated to the custom information security vulnerability library in time. Compared with the Chinese National Information Security Vulnerability Library CNNVD and the International Information Security Vulnerability Library CVE, the custom information security vulnerability library can update the newly discovered risk information more timely, and the custom information security vulnerability library is also more flexible and free in terms of editing permissions.

[0089] Based on the same inventive concept mentioned above, an embodiment of the present application provides a computer-readable storage medium, including each step described in the vulnerability analysis method flow of a jar package that can be implemented when loaded and executed by a processor.

[0090] The computer-readable storage medium includes, for example, various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0091] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device and unit described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0092] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0093] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0094] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0095] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) or a processor (processor) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories, random access memories, magnetic disks or optical disks.

[0096] The above are all preferred embodiments of the present application, and are not intended to limit the protection scope of the present application. Any feature disclosed in this specification (including the abstract and drawings), unless otherwise stated, can be replaced by other equivalent or alternative features with similar purposes. That is, unless otherwise stated, each feature is only an example of a series of equivalent or similar features.

Claims

1. A vulnerability analysis method for a source code package, characterized in that: The following steps are involved: Get the jar package information in the source code; Determine the method of introducing the jar package according to the jar package information; Based on the introduction method of the jar package, a warning is issued on the risk information of the jar package according to a preset scheme; The jar package information includes the address coordinates of the jar package or the suffix of the jar package file; The method of introducing the jar package according to the jar package information specifically includes: if the address coordinates of the jar package are recorded in the pom file, the method of introducing the jar package is pom coordinate introduction; if the suffix of the jar package file is .jar, the method of introducing the jar package is jar direct writing; When the jar package is introduced by pom coordinates, the preset solution specifically includes: Obtain identification content of the jar package, where the identification content includes one or more of an open source organization name, a jar package name, a version number, and a hash value; Searching for risk information matching the jar package in the vulnerability information library according to the identification content, and if found, displaying the risk information for warning; if not found, displaying no matching result; When the jar package is introduced by directly writing the jar package, the preset solution specifically includes: Calculate the hash value of the jar package; Search the vulnerability information library for risk information matching the jar package according to the hash value. If found, display the risk information for warning. If not found, display no matching result. The risk information includes the vulnerabilities and hazards of the jar package and the corresponding solutions.

2. The method for analyzing a vulnerability of a source code package according to claim 1, characterized in that: The vulnerability information database includes the China National Information Security Vulnerability Database CNNVD and the International Vulnerability Information Database CVE.

3. A source code package vulnerability analysis device, characterized in that: include: A memory, used for storing a vulnerability analysis program; A processor, when running the vulnerability analysis program, executes the steps of the source code package vulnerability analysis method according to any one of claims 1 to 2.

4. A vulnerability analysis terminal for a source code package, characterized in that: include: A source code detection device (1) is used to scan and analyze jar package information in the source code; A risk display device (3), used for displaying risk information of the jar package; The vulnerability analysis device (2) as claimed in claim 3, wherein the input end is connected to the source code detection device (1), and the output end is connected to the risk display device (3).

5. A computer-readable storage medium, characterized in that: A computer program is stored which can be loaded by a processor and execute the vulnerability analysis method of the source code package according to any one of claims 1 to 2.

Citation Information

Patent Citations

  • Open source software bug analysis method and device and storage medium

    CN108763928A