Code Processing Method, Device, Electronic Device and Storage Medium
By calling the conversion model to convert object code statements in code processing and integrating security components, the problem of low efficiency of static code security testing in the prior art is solved, and efficient integration of security function design in code is achieved.
Patent Information
- Application Number
- CN202111293276.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-03
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2041-11-03
AI Technical Summary
In the prior art, the security functions in the code are improved through static code security testing methods, and the efficiency is low.
By receiving code processing requests, calling the preset conversion model to identify the target code statement, and converting it into the call code statement corresponding to the security component, obtaining the security component from the component library, integrating it with the converted program code, and generating a code file including the security component.
It realizes automatic integration of security components in code files, improves the efficiency of designing security functions in code, and avoids the inefficiency of improving security functions through static code security testing methods.
Smart Images

Figure CN114021133B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a code processing method, apparatus, electronic device, and storage medium. Background Art
[0002] In some scenarios such as writing input data into a database, on the basis of writing the input data into the database, it is also necessary to ensure the security of the input data. Therefore, when developing the corresponding code, for security considerations, it is necessary to design the function of ensuring data security in the developed code. In the prior art, usually, after the code development is completed, the security function in the code is improved by means of static code security testing to ensure the security of the input data when the code runs, but the efficiency of this method is relatively low. Summary of the Invention
[0003] In view of this, embodiments of the present invention provide a code processing method, apparatus, electronic device, and storage medium, which can solve the problem of low efficiency in improving the security function in the code by means of static code security testing.
[0004] To achieve the above object, according to one aspect of the embodiments of the present invention, a code processing method is provided.
[0005] A code processing method according to an embodiment of the present invention includes: receiving a code processing request, obtaining a code identifier in the code processing request, so as to query the corresponding program code from a code library; calling a preset conversion model to identify a target code statement in the program code, and converting the target code statement into a call code statement corresponding to a security component; obtaining a security component from a component library, and integrating the security component with the converted program code to obtain a code file including the security component.
[0006] In one embodiment, before calling the preset conversion model, it further includes:
[0007] identifying a string in a preset format in the program code;
[0008] querying a replacement character corresponding to the preset format to replace the string with the replacement character;
[0009] Integrating the security component with the converted program code includes:
[0010] replacing the replacement character in the converted program code with the string, and integrating the replaced program code with the security component.
[0011] In yet another embodiment, before calling the preset conversion model, it further includes:
[0012] Collect historical program code segments, where the historical program code segments include the code before the conversion call code statement and the code after the conversion of the call code statement;
[0013] Train a preset machine learning model based on the code segments to obtain the conversion model.
[0014] In another embodiment, integrating the security component with the converted program code includes:
[0015] Obtain the identifier of the security component to update the identifier of the security component to the configuration file corresponding to the program code;
[0016] Based on the configuration file, the security component and the converted program code combination, obtain a code file including the security component.
[0017] In another embodiment, the obtaining the security component includes:
[0018] Query the version identifier of the security component from a preset knowledge base, obtain the component identifier of the security component with the highest version, and obtain the security component from a preset component library based on the component identifier.
[0019] In another embodiment, the method further includes:
[0020] Receive an update message of the security component, and obtain the component identifier and the updated version identifier of the security component after the update in the update message;
[0021] Store the component identifier and the updated version identifier of the security component after the update in the knowledge base.
[0022] In another embodiment, before calling the preset conversion model, it further includes:
[0023] Call a preset code error recognition model to identify the program code to determine whether it includes error codes;
[0024] If so, send a prompt message corresponding to the error code to prompt to correct the error code in the program code; if not, call the preset conversion model.
[0025] To achieve the above object, according to another aspect of the embodiments of the present invention, there is provided a code processing device.
[0026] A code processing device according to an embodiment of the present invention includes: a receiving unit, configured to receive a code processing request, obtain a code identifier in the code processing request, and query corresponding program code from a code library; a conversion unit, configured to call a preset conversion model to identify target code statements in the program code and convert the target code statements into call code statements corresponding to security components; an integration unit, configured to obtain security components from a component library, integrate the security components with the converted program code, and obtain a code file including the security components.
[0027] In one embodiment, the device further includes:
[0028] an identification unit, configured to identify a string in a preset format in the program code;
[0029] a replacement unit, configured to query a replacement symbol corresponding to the preset format and replace the string with the replacement symbol;
[0030] The integration unit is specifically configured to replace the replacement symbol in the converted program code with the string, and integrate the replaced program code with the security components.
[0031] In yet another embodiment, the device further includes:
[0032] a collection unit, configured to collect historical program code segments, where the historical program code segments include the code before converting the call code statements and the code after converting the call code statements;
[0033] a training unit, configured to train a preset machine learning model based on the code segments to obtain the conversion model.
[0034] In yet another embodiment, the integration unit is specifically configured to:
[0035] obtain an identifier of the security component to update the identifier of the security component to a configuration file corresponding to the program code;
[0036] Based on the configuration file, the security component and the converted program code combination, obtain a code file including the security component.
[0037] In yet another embodiment, the integration unit is specifically configured to:
[0038] query a version identifier of a security component from a preset knowledge base, obtain a component identifier of the security component with the highest version, and obtain the security component from a preset component library based on the component identifier.
[0039] In yet another embodiment, the receiving unit is further configured to receive an update message of a security component, and obtain a component identifier of the updated security component and an updated version identifier in the update message;
[0040] The device further includes:
[0041] Store the component identifier of the updated security component and the updated version identifier into the knowledge base.
[0042] In yet another embodiment, the identifying unit is further configured to call a preset code error identification model to identify the program code to determine whether it includes an error code; if so, send a prompt message corresponding to the error code to prompt to correct the error code in the program code; if not, call a preset conversion model.
[0043] To achieve the above object, according to another aspect of the embodiments of the present invention, there is provided an electronic device.
[0044] An electronic device according to an embodiment of the present invention includes: one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors implement the code processing method provided by the embodiments of the present invention.
[0045] To achieve the above object, according to yet another aspect of the embodiments of the present invention, there is provided a computer-readable medium.
[0046] A computer-readable medium according to an embodiment of the present invention has a computer program stored thereon, and when the program is executed by a processor, it implements the code processing method provided by the embodiments of the present invention.
[0047] One embodiment of the above invention has the following advantages or beneficial effects: In the embodiment of the present invention, after receiving a code processing request, the corresponding program code, that is, the code program to be processed, can be queried based on the code identifier in the code processing request; the conversion model is preset, and by calling the conversion model, the target code statements in the program code, that is, the code statements to be converted, can be identified, and then the target code statements are converted into call code statements corresponding to the security components, so that when the program code runs and reaches the call code statements, the call of the security components can be realized; after obtaining the security components from the component library, the security components are integrated with the converted program code to obtain a code file including the security components, that is, a code file with guaranteed input data security. In the embodiment of the present invention, the program code can be converted through the conversion model, and then the security components are integrated with the converted program code to obtain a code file including the security components. Since the security components are integrated in the code file, during the code running process, the security components can be called through the call code statements to implement the verification of the input data security and ensure its security. Thus, in the embodiment of the present invention, the security components can be automatically integrated into the code file, thereby realizing the functional design of security in the code, avoiding improving the security functions in the code by means of static code security testing, and improving the efficiency of designing security functions in the code.
[0048] The further effects of the above non-conventional optional methods will be described below in combination with specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] The drawings are used to better understand the present invention and do not constitute an improper limitation to the present invention. Among them:
[0050] Figure 1 is a schematic diagram of a system architecture of a code processing system according to an embodiment of the present invention;
[0051] Figure 2 is a schematic diagram of a main process of a code processing method according to an embodiment of the present invention;
[0052] Figure 3 is another schematic diagram of a main process of a code processing method according to an embodiment of the present invention;
[0053] Figure 4 is a schematic diagram of the main units of a code processing device according to an embodiment of the present invention;
[0054] Figure 5 is another exemplary system architecture diagram to which the embodiment of the present invention can be applied;
[0055] Figure 6It is a schematic structural diagram of a computer system suitable for implementing the embodiments of the present invention. Detailed implementation manners
[0056] The exemplary embodiments of the present invention will be described below with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0057] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.
[0058] The embodiments of the present invention provide a code processing system, which can be used in scenarios for designing the security of program code, specifically in scenarios for integrating security components into program code.
[0059] In the embodiments of the present invention, as Figure 1 shown, it is a schematic system architecture diagram of the code processing system in the embodiments of the present invention. The code processing system may include a security component automatic integration system, a code repository, and a security component library. The security component automatic integration system can be used to integrate security components and program code, and it can include two parts, namely an integration engine and a knowledge base. Among them, the integration engine can perform the function of integrating security components and program code, and the knowledge base can store the parameters required for integrating security components and program code, that is, provide the required parameters for the operation of the integration engine, such as the version information and component information of security components, etc. The code repository can be used to store various codes, such as program codes for integrating security components and code files that have already integrated security components, etc. The code repository can interact with the integration engine so that the integration engine can obtain codes that have not yet integrated security components from the code repository or send the code files that have already integrated security components to the code repository for storage. Usually, the engineering files corresponding to the codes are stored in the code repository, so the integration engine can obtain or send codes from the code repository in the form of engineering files. The security component library is a pre-set component library, which can store security components of various versions and can interact with the integration engine to facilitate the integration engine to obtain security components from the security component library.
[0060] It should be noted that, in the embodiments of the present invention, the code processing system can run on a general hardware platform such as x86. The API corresponding to the code repository and the security component library can be pre-stored in the integration engine, and then data interaction with the code repository and the security component library can be realized by calling the corresponding API. Specifically, the integration engine can obtain the code engineering file from the code repository through tools such as Git to obtain the program code to be processed.
[0061] Embodiments of the present invention provide a code processing method, which can be executed by Figure 1 the security component automatic integration system shown, as Figure 2 shown, the method includes:
[0062] S201: Receive a code processing request, obtain the code identifier in the code processing request, and query the corresponding program code from the code library.
[0063] Among them, the code processing request is triggered when security components need to be integrated into the code, and it can be triggered manually or automatically by the running environment. After receiving the code processing request, the code processing request can be responded to, and the code identifier in the code processing request can be obtained. The code identifier represents the program code that needs to integrate security components. Therefore, the integration engine can query the corresponding program code from the code repository based on the code identifier, that is, read the program code corresponding to the code identifier from the code repository. Specifically, the integration engine can query the corresponding code engineering file from the code repository based on the code identifier, and then the program code can be obtained from the code engineering file. The following code shows part of the program code in the code engineering file.
[0064]
[0065] S202: Call a preset conversion model to identify the target code statements in the program code and convert the target code statements into call code statements corresponding to the security components.
[0066] Among them, the conversion model is pre-set and can be used for the conversion of code in program code. In the design of security functions in program code, in the embodiments of the present invention, a security component is integrated with the program code, so that the security component can be directly called during the running process of the integrated code file to perform security detection on input data, thereby ensuring the security of the input data. To enable the direct call of the security component during the running process of the code file, some code in the program code needs to be rewritten, that is, at the position where the security component needs to be called in the program code, the original code statement (target code statement) is converted into a call code statement for calling the security component. When the converted program code runs, when it executes to the converted call code statement, the call of the security component can be automatically triggered. Therefore, in this step, the conversion model can first identify the target code statement in the program code, that is, the code statement that needs to be converted, and then convert the target code statement into a call code statement corresponding to the security component.
[0067] It should be noted that in the embodiments of the present invention, the conversion model can adopt a machine learning model. For example, it can be a Transformer model of the TensorFlow (a symbolic mathematics system based on data flow programming) machine learning platform. Before this step, historical program code segments can be collected in advance. The historical program code segments include the code before the conversion call code statement and the code after the conversion of the call code statement, that is, the code before the target code statement is converted into a call code statement and the program code after the target code statement is converted into a call code statement; then, based on the code segments, the preset machine learning model is trained to obtain the conversion model. Specifically, the code after the conversion of the call code statement (source) and the code before the conversion of the call code statement (target) can be input into the preset machine learning model for training, so that the machine learning model can learn the mapping relationship between source and target, and then realize the conversion of the program code. In the embodiments of the present invention, if the code segments used for model training are not sufficient to support model training, the code conversion rules between the target code statement in the program code and the call code statement corresponding to the security component can also be extracted to generate a conversion model corresponding to the code conversion rules.
[0068] In the embodiments of the present invention, after the program code is developed, there may be errors in the program code. To avoid these errors from affecting the accuracy of the code conversion in this step, before executing this step, the program code can also be error-identified. Specifically, it can be executed as follows: call a preset code error identification model to identify the program code and obtain the error code in the program code; send a prompt message of the error code to prompt the correction of the error code in the program code.
[0069] The code error recognition model can be pre-trained, specifically, it can be an LSTM model. After identifying the error code in the program code, a prompt message corresponding to the error code can be sent to prompt developers, etc. to correct the program code in a timely manner, that is, to prompt the correction of the error code in the program code.
[0070] S203: Obtain a security component from the component library, integrate the security component with the converted program code, and obtain a code file including the security component.
[0071] Among them, the integration engine can obtain the security component from the component library (security component library). For example, it can obtain the Jar package of the security component, and then integrate the security component with the converted program code.
[0072] In the embodiment of the present invention, the program code usually includes various formats of strings, such as variable names, etc. Since these strings may be defined by developers, they may interfere with the conversion model to identify the target code statement. Therefore, before performing step S202, these strings that may cause interference can be replaced with preset replacement characters, and after performing this step, they can be replaced back, and then integrated with the security component. Specifically, before step S202, it can be performed as follows: identify the strings in the program code in a preset format; query the replacement character corresponding to the preset format to replace the string with the replacement character; the integration operation in step S203 can be specifically performed as: replace the replacement character in the converted program code with the string, and integrate the replaced program code with the security component.
[0073] The format of the string to be replaced can be set in advance, specifically, it can be set based on the format of each string included in the program code. The replacement character can also be set based on requirements. Usually, it is necessary not to affect the conversion of the calling code statement, and different strings need to be set with different replacement characters to avoid confusing the replaced strings and causing errors in the program code. Taking the code in step S201 as an example, the replaced code can be as follows, where the variable name and string are replaced with preset numbers: $v0, $v1, $v2, $s0.
[0074]
[0075] Based on the above replaced program code, step S202 can be performed, and then the converted code is as follows, where the target code statement is converted into a calling code statement of the security component, and "ESAPI" represents the identifier of the security component.
[0076]
[0077] For the converted program code above, the replacement symbols can be replaced with the variable names in the program code of step S201, and the result after replacement can be as follows.
[0078]
[0079]
[0080] It should be noted that in this step, integrating the security component and the converted program code may include adding the security component to the code project file of the program code and updating the corresponding configuration file of the program code. Specifically, it can be executed as follows: obtain the identifier of the security component to update the identifier of the security component to the corresponding configuration file of the program code; based on the combination of the configuration file, the security component and the converted program code, obtain a code file including the security component. Combining the updated configuration file, the security component and the converted program code can be executed by updating the updated configuration file, the security component and the converted program code to the project file of the program code, and then a code file including the security component can be obtained. After obtaining the code file in this step, the code file can be sent to the code repository for storage.
[0081] In the embodiment of the present invention, the versions and component identifiers of each security component are stored in the knowledge base. In order to improve the security function in the program code, usually the security component with the highest version will be selected in this step to be integrated into the code file. Therefore, obtaining the security component in this step can be specifically executed as follows: query the version identifier of the security component from the preset knowledge base, obtain the component identifier of the security component with the highest version, and obtain the security component from the preset component library based on the component identifier.
[0082] The version identifiers of each security component can be queried from the knowledge base, and then the security component with the highest version can be filtered out, and then the component identifier of the security component with the highest version can be obtained. After obtaining the component identifier in this way, the corresponding security component can be obtained from the component library.
[0083] It should be noted that in the embodiment of the present invention, when the version of the security component is updated, the knowledge base also needs to be updated in time so that the integration engine can query the security component with the highest version. Specifically, it can be executed as follows: receive the update message of the security component, obtain the component identifier and the updated version identifier of the security component after the update in the update message; store the component identifier and the updated version identifier of the security component after the update in the knowledge base. The update message may include the component identifier of the updated security component and the version identifier of the security component after the update, and then store them in the knowledge base for subsequent use.
[0084] In an embodiment of the present invention, after receiving a code processing request, the corresponding program code can be queried based on the code identifier in the code processing request, that is, the code program to be processed; the conversion model is preset, and by calling the conversion model, the target code statements in the program code can be identified, that is, the code statements to be converted, and then the target code statements are converted into call code statements corresponding to the security components, so that when the program code runs and reaches the call code statements, the security components can be called; after obtaining the security components from the component library, the security components are integrated with the converted program code to obtain a code file including the security components, that is, a code file with guaranteed input data security. In an embodiment of the present invention, the program code can be converted through the conversion model, and then the security components are integrated with the converted program code to obtain a code file including the security components. Since the security components are integrated in the code file, during the code running process, the security components can be called through the call code statements to implement the verification of the security of the input data and ensure its security. Thus, in an embodiment of the present invention, the security components can be automatically integrated into the code file, thereby realizing the functional design of security in the code, avoiding improving the security functions in the code by means of static code security testing, and improving the efficiency of designing security functions in the code.
[0085] The following combines Figure 1 the system architecture shown in Figure 2 and the embodiments shown in Figure 3 to specifically illustrate the code processing method in an embodiment of the present invention. As Figure 3 shown, the method includes:
[0086] S301: Receive a code processing request, obtain the code identifier in the code processing request, and query the corresponding program code from the code library.
[0087] S302: Identify the strings in the program code in a preset format; query the replacement characters corresponding to the preset format to replace the strings with the replacement characters.
[0088] S303: Call a preset conversion model to identify the target code statements in the program code and convert the target code statements into call code statements corresponding to the security components.
[0089] S304: Query the version identifier of the security component from a preset knowledge base, obtain the component identifier of the security component with the highest version, and obtain the security component from a preset component library based on the component identifier.
[0090] S305: Update the identifier of the security component to the configuration file corresponding to the program code; combine the configuration file, the security component, and the converted program code to obtain a code file including the security component.
[0091] S306: Send the code file to the code repository.
[0092] It should be noted that the data processing principle in the embodiments of the present invention is the same as the corresponding data processing principle in the Figure 2 illustrated embodiment, and will not be elaborated herein.
[0093] In the embodiments of the present invention, the program code can be converted by a conversion model, and then the security component is integrated with the converted program code to obtain a code file including the security component. Since the security component is integrated in the code file, during the code running process, the security component can be called by invoking code statements to implement the verification of the security of the input data and ensure its security. In this way, in the embodiments of the present invention, the security component can be automatically integrated into the code file, thereby realizing the functional design of security in the code, avoiding improving the security function in the code by means of static code security testing, and improving the efficiency of designing the security function in the code.
[0094] To solve the problems existing in the prior art, an embodiment of the present invention provides a code processing device 400, as Figure 4 shown, the device 400 includes:
[0095] A receiving unit 401, configured to receive a code processing request, obtain a code identifier in the code processing request, and query the corresponding program code from a code library;
[0096] A conversion unit 402, configured to call a preset conversion model to identify target code statements in the program code and convert the target code statements into call code statements corresponding to security components;
[0097] An integration unit 403, configured to obtain a security component from a component library, integrate the security component with the converted program code, and obtain a code file including the security component.
[0098] It should be understood that the implementation manner of the embodiments of the present invention is the same as that of the Figure 2 illustrated embodiment, and will not be elaborated herein.
[0099] In an implementation manner of the embodiments of the present invention, the device 400 further includes:
[0100] An identification unit, configured to identify a string in a preset format in the program code;
[0101] A replacement unit, configured to query a replacement character corresponding to the preset format and replace the string with the replacement character;
[0102] The integration unit is specifically configured to replace the replacement character in the converted program code with the string, and integrate the replaced program code with the security component.
[0103] In another implementation manner of the embodiment of the present invention, the apparatus 400 further includes:
[0104] An acquisition unit, configured to acquire a historical program code segment, where the historical program code segment includes the code before the conversion call code statement and the code after the conversion of the call code statement;
[0105] A training unit, configured to train a preset machine learning model based on the code segment to obtain the conversion model.
[0106] In another implementation manner of the embodiment of the present invention, the integration unit 402 is specifically configured to:
[0107] Obtain the identifier of the security component to update the identifier of the security component to the configuration file corresponding to the program code;
[0108] Based on the configuration file, the security component and the combined converted program code, obtain a code file including the security component.
[0109] In another implementation manner of the embodiment of the present invention, the integration unit 402 is specifically configured to:
[0110] Query the version identifier of the security component from a preset knowledge base, obtain the component identifier of the security component with the highest version, and obtain the security component from a preset component library based on the component identifier.
[0111] In another implementation manner of the embodiment of the present invention, the receiving unit 401 is further configured to receive an update message of the security component, and obtain the component identifier of the updated security component and the updated version identifier in the update message;
[0112] The apparatus 400 further includes:
[0113] Store the component identifier of the updated security component and the updated version identifier in the knowledge base.
[0114] In another implementation manner of the embodiment of the present invention, the recognition unit is further configured to call a preset code error recognition model to recognize the program code to determine whether it includes error code; if so, send a prompt message corresponding to the error code to prompt to correct the error code in the program code; if not, call a preset conversion model.
[0115] It should be understood that the implementation manner of implementing the embodiment of the present invention is the same as the implementation manner of the embodiment shown Figure 2 or Figure 3 and will not be described in detail herein.
[0116] In the embodiments of the present invention, the program code can be converted by a conversion model, and then a security component is integrated with the converted program code to obtain a code file including the security component. Since the security component is integrated in the code file, during the running of the code, the security component can be called by invoking code statements to implement the verification of the security of the input data and ensure its security. Thus, in the embodiments of the present invention, the security component can be automatically integrated into the code file, thereby realizing the design of security functions in the code, avoiding improving the security functions in the code by means of static code security testing, and improving the efficiency of designing security functions in the code.
[0117] According to an embodiment of the present invention, the embodiments of the present invention also provide an electronic device and a readable storage medium.
[0118] The electronic device according to the embodiment of the present invention includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the code processing method provided by the embodiment of the present invention.
[0119] Figure 5 An exemplary system architecture 500 is shown to which the code processing method or the code processing device according to the embodiment of the present invention can be applied.
[0120] As Figure 5 shown, the system architecture 500 may include terminal devices 501, 502, 503, a network 504, and a server 505. The network 504 is used to provide a medium for communication links between the terminal devices 501, 502, 503 and the server 505. The network 504 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0121] Users can use the terminal devices 501, 502, 503 to interact with the server 505 through the network 504 to receive or send messages, etc. Various client applications may be installed on the terminal devices 501, 502, 503.
[0122] The terminal devices 501, 502, 503 may be, but are not limited to, smart phones, tablet computers, laptop portable computers, desktop computers, etc.
[0123] The server 505 may be a server providing various services. The server may analyze and process data such as code processing requests received, and feedback the processing results (such as a code file - only an example) to the terminal devices.
[0124] It should be noted that the code processing method provided by the embodiments of the present invention is generally executed by the server 505. Correspondingly, the code processing device is generally provided in the server 505.
[0125] It should be understood that Figure 5 the number of terminal devices, networks, and servers in
[0126] Reference will now be made to Figure 6 FIG. [FIGURE NUMBER NOT PROVIDED], which shows a schematic structural diagram of a computer system 600 suitable for implementing the embodiments of the present invention. Figure 6 The computer system shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present invention.
[0127] As Figure 6 shown, the computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage section 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the system 600 are also stored. The CPU 601, ROM 602, and RAM 603 are connected to each other via a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.
[0128] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed so that a computer program read from it can be installed into the storage section 608 as needed.
[0129] In particular, according to the embodiments disclosed by the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed by the present invention include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 609, and / or installed from the removable medium 611. When the computer program is executed by the central processing unit (CPU) 601, the above functions defined in the system of the present invention are performed.
[0130] It should be noted that the computer-readable medium shown in the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or combined with an instruction execution system, apparatus, or device. In the present invention, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable medium can send, propagate, or transmit a program for use by or combined with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0131] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a unit, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0132] The units involved in the embodiments of the present invention can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor includes a receiving unit, a conversion unit, and an integration unit. Among them, the names of these units do not constitute a limitation to the unit itself in some cases. For example, the receiving unit can also be described as "a unit for receiving code processing requests".
[0133] On the other hand, the present invention also provides a computer-readable medium, which can be included in the devices described in the above embodiments; or can exist separately without being assembled into the devices. The above computer-readable medium carries one or more programs. When the one or more programs are executed by one of the devices, the device is caused to execute the code processing method provided by the present invention.
[0134] The above specific embodiments do not constitute a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A code processing method, characterized in that, it includes: Receiving a code processing request, obtaining the code identifier in the code processing request, and querying the corresponding program code from a code library; Invoking a preset conversion model to identify target code statements in the program code and convert the target code statements into call code statements corresponding to security components; Obtaining security components from a component library, integrating the security components with the converted program code, and obtaining a code file including the security components; Among them, integrating the security components with the converted program code includes: obtaining the identifier of the security component to update the identifier of the security component to the configuration file corresponding to the program code; based on the configuration file, the security component and the converted program code combination, obtaining a code file including the security component.
2. The method according to claim 1, characterized in that, before invoking the preset conversion model, it further includes: Identifying strings in a preset format in the program code; Querying the replacement character corresponding to the preset format to replace the string with the replacement character; Integrating the security components with the converted program code includes: Replacing the replacement character in the converted program code with the string, and integrating the replaced program code with the security component.
3. The method according to claim 1, characterized in that, before invoking the preset conversion model, it further includes: Collecting historical program code segments, where the historical program code segments include the code before converting the call code statement and the code after converting the call code statement; Training a preset machine learning model based on the historical program code segments to obtain the conversion model.
4. The method according to claim 1, characterized in that, obtaining the security component includes: Querying the version identifier of the security component from a preset knowledge base, obtaining the component identifier of the security component with the highest version, and obtaining the security component from a preset component library based on the component identifier.
5. The method according to claim 4, characterized in that, the method further includes: Receiving an update message of the security component, obtaining the component identifier of the updated security component and the updated version identifier in the update message; Storing the component identifier of the updated security component and the updated version identifier in the knowledge base.
6. The method according to claim 1, characterized in that, before invoking the preset conversion model, it further includes: Invoking a preset code error identification model to identify the program code to determine whether it includes error codes; If so, sending a prompt message corresponding to the error code to prompt to correct the error code in the program code; if not, invoking a preset conversion model.
7. A code processing device, characterized in that, it includes: A receiving unit, configured to receive a code processing request, obtain the code identifier in the code processing request, and query the corresponding program code from a code library; A conversion unit, configured to call a preset conversion model to identify target code statements in the program code and convert the target code statements into call code statements corresponding to security components; An integration unit, configured to obtain security components from a component library and integrate the security components with the converted program code to obtain a code file including the security components; wherein, integrating the security components with the converted program code includes: obtaining an identifier of the security component to update the identifier of the security component to a configuration file corresponding to the program code; and combining the configuration file, the security component and the converted program code to obtain a code file including the security components.
8. An electronic device characterized in that it includes one or more processors; a storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, enabling the one or more processors to implement the method according to any one of claims 1-6.
9. A computer-readable medium, having a computer program stored thereon, characterized in that when the program is executed by a processor, it implements the method according to any one of claims 1-6.
Citation Information
Patent Citations
Method for modifying function of software installation package, and terminal
CN107305495A
Code error identification method and device based on block chain, equipment and storage medium
CN109977014A
Data processing method and device, computer equipment and storage medium
CN111290801A
Industrial software vulnerability detection method based on self-attention mechanism
CN113591093A