A method and device for constructing an information security risk detection system

By replacing the strings in the detection logic code of the built system to adapt to the new encoding rules, the problem of inefficiency in the existing technology is solved, and the target logic code of the information security hazard detection system is effectively implemented.

CN115934108BActive Publication Date: 2025-07-25BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211693880.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-28
Publication Date
2025-07-25
Estimated Expiration
2042-12-28

AI Technical Summary

Technical Problem

When building an information security risk detection system, the existing technology requires manual writing of detection logic code, which leads to inefficiency and is unable to efficiently build a system suitable for different coding rules.

Method used

By obtaining the detection logic code and encoding rules of the built system, replacing the string to be converted into a replacement string that complies with the new encoding rules, and generating the object detection logic code for building a new system.

Benefits of technology

It improves the efficiency of building an information security risk detection system, reduces the need for manual code writing, and improves accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115934108B_ABST
    Figure CN115934108B_ABST
Patent Text Reader

Abstract

The present disclosure relates to the field of information security, and particularly to a method and apparatus for constructing an information security hidden danger detection system. The method includes: obtaining the detection logic code of a first information security hidden danger detection system and a first coding rule corresponding to the detection logic code; the first information security hidden danger detection system is used to execute the detection logic code to perform information security hidden danger detection; according to the first coding rule, each string to be converted in the detection logic code is replaced with a corresponding replacement string that conforms to a second coding rule to obtain a target detection logic code; a second information security hidden danger detection system is constructed based on the target detection logic code. Thus, the target detection logic code corresponding to the second information security hidden danger detection system is obtained by replacing the string to be converted in the detection logic code with the replacement string, which can improve the efficiency of constructing the second information security hidden danger detection system based on the already constructed first information security hidden danger detection system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of information security, and in particular, to a method and apparatus for constructing an information security hidden danger detection system. Background Art

[0002] As an information security hidden danger detection system, a Network Intrusion Detection System (NIDS) is used to detect behaviors that endanger the security of computer systems, such as collecting vulnerability information, causing denial of access, and obtaining system control rights beyond the legal scope. By combining a network intrusion detection system with a firewall, malicious intrusion actions from external or internal networks can be effectively prevented.

[0003] Currently, when constructing an information security hidden danger detection system, first, developers need to manually write detection logic code for information security hidden danger detection, and then an information security hidden danger detection system can be constructed based on this detection logic code.

[0004] However, on the premise that an information security hidden danger detection system corresponding to a computer system has been constructed, when constructing an information security hidden danger detection system corresponding to another computer system, since the encoding rules applicable to the two computer systems are different, developers will manually write the detection logic code corresponding to the to-be-constructed information security hidden danger detection system according to the logic of the detection logic code corresponding to the already constructed information security hidden danger detection system using new encoding rules. Therefore, the efficiency of constructing another information security hidden danger detection system based on the already constructed information security hidden danger detection system is low. Summary of the Invention

[0005] In view of the above technical problem of low efficiency in constructing another information security hidden danger detection system based on the already constructed information security hidden danger detection system, the technical solution adopted by the present disclosure is as follows:

[0006] According to one aspect of the present disclosure, there is provided a method for constructing an information security hidden danger detection system, including:

[0007] Obtain the detection logic code of a first information security hidden danger detection system and a first encoding rule corresponding to the detection logic code; the first information security hidden danger detection system is used to execute the detection logic code to perform information security hidden danger detection.

[0008] According to the first encoding rule, replace each string to be converted in the detection logic code with a corresponding replacement string that conforms to a second encoding rule to obtain a target detection logic code.

[0009] Construct a second information security hidden danger detection system based on the target detection logic code.

[0010] According to another aspect of the present disclosure, there is also provided an apparatus for constructing an information security hazard detection system, including:

[0011] An acquisition module, configured to acquire the detection logic code of the first information security hazard detection system and the first coding rule corresponding to the detection logic code; the first information security hazard detection system is used to execute the detection logic code to perform information security hazard detection.

[0012] A replacement module, configured to replace each string to be converted in the detection logic code with a corresponding replacement string that conforms to the second coding rule according to the first coding rule, so as to obtain a target detection logic code.

[0013] A construction module, configured to construct a second information security hazard detection system based on the target detection logic code.

[0014] According to another aspect of the present disclosure, there is also provided a non-transitory computer-readable storage medium, in which at least one instruction or at least one program segment is stored, and at least one instruction or at least one program segment is loaded and executed by a processor to implement the method for constructing the information security hazard detection system as described above.

[0015] According to another aspect of the present disclosure, there is also provided an electronic device, including a processor and the above-mentioned non-transitory computer-readable storage medium.

[0016] The technical solutions provided by the embodiments of the present disclosure may include the following beneficial effects:

[0017] In the present disclosure, each string to be converted in the detection logic code of the first information security hazard detection system that has been constructed can be replaced with a corresponding replacement string that conforms to the second coding rule to obtain a target detection code, and then a second information security hazard detection system is constructed based on the target detection logic code. Compared with constructing the second information security hazard detection system by manually writing the target detection logic code after the first information security hazard detection system is constructed based on the detection logic code, the target detection logic code corresponding to the second information security hazard detection system in the present disclosure is obtained by replacing each string to be converted in the detection logic code with a replacement string, without the need for developers to manually write character by character, which can improve the efficiency of constructing the second information security hazard detection system based on the first information security hazard detection system that has been constructed.

[0018] It should be understood that the above general description and the following detailed description are only exemplary and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] To more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings; the accompanying drawings here are incorporated into the specification and form a part of this specification, showing the embodiments in line with the present disclosure, and are used together with the specification to explain the principles of the present disclosure.

[0020] Figure 1 It is a flowchart of a method for constructing an information security hidden danger detection system shown according to an exemplary embodiment.

[0021] Figure 2 It is a schematic block diagram of a device for constructing an information security hidden danger detection system shown according to an exemplary embodiment. Detailed implementation manners

[0022] The following will clearly and completely describe the technical solutions in the embodiments of the present disclosure with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only some embodiments of the present disclosure, rather than all embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present disclosure.

[0023] The embodiments of the present disclosure provide a method for constructing an information security hidden danger detection system. Among them, the method can be completed by any one of the following or any combination thereof: a terminal, a server, and other devices with processing capabilities. The embodiments of the present disclosure do not limit this.

[0024] The embodiments of the present disclosure take the server as an example. The following will refer to Figure 1 the flowchart of the method for constructing an information security hidden danger detection system shown, and introduce the method for constructing an information security hidden danger detection system.

[0025] The method includes the following steps:

[0026] S100, obtain the detection logic code of the first information security hidden danger detection system and the first coding rule corresponding to the detection logic code.

[0027] Among them, the first information security hidden danger detection system is used to execute the detection logic code for information security hidden danger detection.

[0028] Specifically, the first information security hidden danger detection system is an information security hidden danger detection system that has been constructed.

[0029] S200. According to the first encoding rule, replace each string to be converted in the detection logic code with a corresponding replacement string that conforms to the second encoding rule, to obtain the target detection logic code.

[0030] A specific implementation manner of the above step S200 may be as follows: According to the first encoding rule, determine each string to be converted in the detection logic code, and according to the second encoding rule, replace each string to be converted in the detection logic code with a corresponding replacement string, so as to obtain the target detection code.

[0031] S300. Build a second information security hazard detection system based on the target detection logic code.

[0032] Among them, the first information security hazard detection system and the second information security detection system are of the same type of information security detection system. For example, both the first information security hazard detection system and the second information security detection system are network intrusion detection systems. For example, the first information security hazard detection system is a network intrusion detection system used by Company A, and the second information security detection system is a network intrusion detection system to be built by Company B.

[0033] It can be seen therefrom that in the present disclosure, according to the first encoding rule, each string to be converted in the detection logic code of the already built first information security hazard detection system can be replaced with a corresponding replacement string that conforms to the second encoding rule, so as to obtain the target detection code, and then a second information security hazard detection system is built based on the target detection logic code. Compared with the method of manually writing the target detection logic code to build the second information security hazard detection system after the first information security hazard detection system is built based on the detection logic code, the target detection logic code corresponding to the second information security hazard detection system in the present disclosure is obtained by replacing each string to be converted in the detection logic code with a replacement string, without the need for developers to manually write character by character, which can improve the efficiency of building the second information security hazard detection system based on the already built first information security hazard detection system.

[0034] Optionally, the first encoding rule includes a number of first strings and the first interpretation corresponding to each first string, and the second encoding rule includes a number of second strings and the second interpretation corresponding to each second string.

[0035] Specifically, the first encoding rule is a rule that records the association relationship between each first string and the corresponding first interpretation. The first encoding rule includes a number of first strings and the first interpretation corresponding to each first string. For example, the number of first strings are respectively "http", "&&", and "to_server", and the corresponding first interpretations are respectively "HTTP protocol keyword", "AND operator", and "symbol indicating the data transmission direction".

[0036] The second coding rule is a rule that records the association relationship between each second string and the corresponding second interpretation. The second coding rule includes a number of second strings and the second interpretation corresponding to each second string. For example, the number of second strings are "webServer", "and", and "=>", and the corresponding second interpretations are "HTTP protocol keyword", "AND operator", and "symbol indicating the data transmission direction", respectively.

[0037] Based on this, the above step S200 includes the following steps:

[0038] S203, determine each first string in the detection logic code as a string to be converted.

[0039] S206, regard the first interpretation corresponding to each string to be converted as the target interpretation.

[0040] S209, if there is a second interpretation that meets the preset matching condition for each target interpretation in the second coding rule, then for each string to be converted, use the second string corresponding to the second interpretation that meets the preset matching condition and exists for the first interpretation corresponding to it as the replacement string corresponding to the string to be converted.

[0041] A specific implementation manner of the above step S209 may be that if there is the same second interpretation for each target interpretation in the second coding rule, then for each string to be converted, use the second string corresponding to the second interpretation that is the same as the first interpretation corresponding to it as the replacement string corresponding to the string to be converted.

[0042] Another specific implementation manner of the above step S209 may be that if there is a second interpretation with a similarity greater than the preset threshold for each target interpretation in the second coding rule, then for each string to be converted, use the second string corresponding to the second interpretation with a similarity greater than the preset threshold to the first interpretation corresponding to it as the replacement string corresponding to the string to be converted. Optionally, the preset threshold may be 80%-100%, and the embodiments of the present disclosure do not limit this.

[0043] S212, replace each string to be converted in the detection logic code with the corresponding replacement string to obtain the target detection logic code.

[0044] Optionally, some of the number of first strings are advanced strings; each advanced string has a synonymous string; the synonymous string is composed of at least some first strings that are not advanced strings.

[0045] For example, ">", "or", or "=" etc. are first strings that are not advanced strings, and "≥" is an advanced string.

[0046] The synonymous string of “≥” is “> or =”, that is, the synonymous string of “≥” is composed of these 3 first strings: “>”, “or”, and “=”. The first interpretation corresponding to “≥” or “> or =” is both “greater than or equal to”.

[0047] For example, “~”, “A”, or etc. are first strings that are not high-level strings. “A|R-con” is a high-level string, and the synonymous string of “A|R-con” is That is, the synonymous string of “A|R-con” is composed of these 3 first strings: “~”, “A”, and. The first interpretation corresponding to “A|R-con” or is both “included after A is negated”.

[0048] For example, “x”, “y”, or etc. are first strings that are not high-level strings. “con-x-y” is a high-level string, and the synonymous string of “con-x-y” is That is, the synonymous string of “con-x-y” is composed of these 3 first strings: “x”, “y”, and. The first interpretation corresponding to “con-x-y” or is both “include x and include y”.

[0049] Specifically, the first strings that are high-level strings are generally more complex than the first strings that are not high-level strings.

[0050] Based on this, before the above step S212, the above step S200 further includes the following steps:

[0051] S210, if any target interpretation does not have a second interpretation that meets the preset matching condition in the second coding rule, then use the string to be converted corresponding to each target interpretation that does not have a second interpretation that meets the preset matching condition in the second coding rule as the string to be processed.

[0052] A specific implementation manner of the above step S210 may be that if any target interpretation does not have the same second interpretation in the second coding rule, then use the string to be converted corresponding to each target interpretation that does not have the same second interpretation in the second coding rule as the string to be processed.

[0053] Another specific implementation manner of the above step S210 may be that if any target interpretation does not have a second interpretation with a similarity greater than the preset threshold in the second coding rule, then use the string to be converted corresponding to each target interpretation that does not have a second interpretation with a similarity greater than the preset threshold in the second coding rule as the string to be processed.

[0054] S211. If each string to be processed is a high-level string, determine the replacement string corresponding to each string to be processed according to the synonymous string corresponding to each string to be processed.

[0055] It can be seen from this that for the detection of high-level strings in the detection logic code in the present disclosure, if the corresponding first interpretation does not have a second interpretation that meets the preset matching conditions in the second coding rule, the replacement string corresponding to each high-level string can be determined according to the synonymous string corresponding to each high-level string, so as to reduce the possibility that any string to be converted in the detection logic code is not successfully replaced, achieving the purpose of improving the accuracy of the target detection logic code.

[0056] Optionally, the determining the replacement string corresponding to each string to be processed according to the synonymous string corresponding to each string to be processed includes the following steps:

[0057] S2111. Take the synonymous string corresponding to each string to be processed as the target string.

[0058] S2112. For each target string, replace each first string therein with a second string corresponding to a second interpretation that exists in the second coding rule and meets the preset matching conditions for the corresponding first interpretation, to obtain the replaced target string corresponding to the target string.

[0059] S2113. Take each replaced target string as the replacement string corresponding to the corresponding string to be processed.

[0060] Optionally, after the above step S210, the above step S200 further includes the following steps:

[0061] S213. If any string to be processed is not a high-level string, display an error prompt.

[0062] A specific implementation manner of the above step S213 may be that if any string to be processed is not a high-level string, it means that there is a string to be processed in the detection logic code that cannot be directly and successfully replaced and is not a high-level string. At this time, an error prompt box can be popped up, and the replacement string corresponding to the string to be processed can be obtained by manual input by the developer. Therefore, the possibility that any string to be converted in the detection logic code is not successfully replaced can be further reduced, achieving the purpose of further improving the accuracy of the target detection logic code.

[0063] Optionally, the above step S203 includes the following steps:

[0064] S2031. In the order from the largest to the smallest of the lengths of the first strings, according to each first string in turn, in the part of the detection logic code that has not been determined as the string to be converted, determine the string that is the same as the first string as the string to be converted.

[0065] Specifically, the length of the first string is the number of characters.

[0066] For example, if there are 2 first strings, and the 2 first strings are "==" and "=" respectively, then first determine "==" in the detection logic code as the string to be converted, and then determine "=" in the part other than "==" in the detection logic code as the string to be converted.

[0067] It can be seen therefrom that in the present disclosure, the possibility of incorrect determination of the string to be converted caused by the fact that the first string with a larger number of characters includes the first string with a smaller number of characters can be minimized, and further, the possibility of the string to be converted in the detection logic code being mis-replaced can be reduced, achieving the purpose of improving the accuracy of the target detection logic code.

[0068] Optionally, both the first string and the second string are used to represent communication protocol type identifiers, left operands, operators, right operands or special symbols.

[0069] Specifically, several first strings can be several communication protocol type identifiers, several left operands, several operators, several right operands and / or several special symbols respectively. Several second strings can be several communication protocol type identifiers, several left operands, several operators, several right operands and / or several special symbols respectively.

[0070] Among them, the communication protocol type identifier can be HTTP, TCP, UDP, DNS, etc.; the left operand can be Agent, Host, Port, Payload, Name, etc.; the operator can be AND, OR, NOT, EQUALS, CONTAINS or REGULAR MATCH, etc.; the right operand can be port number, string, hexadecimal array, data length or regular content, etc.; the special symbol can be =>, etc.

[0071] The embodiment of the present disclosure also provides a device for constructing an information security hazard detection system, and this device is used to implement the method for constructing an information security hazard detection system described above. Refer to Figure 2 As shown in the schematic block diagram of the device for constructing an information security hazard detection system, the device 400 for constructing an information security hazard detection system includes: an acquisition module 401, a replacement module 402, and a construction module 403.

[0072] An acquisition module 401, configured to acquire the detection logic code of the first information security hazard detection system and the first coding rule corresponding to the detection logic code; the first information security hazard detection system is configured to execute the detection logic code to perform information security hazard detection;

[0073] A replacement module 402, configured to replace each string to be converted in the detection logic code with a corresponding replacement string that conforms to the second coding rule according to the first coding rule, to obtain a target detection logic code;

[0074] A construction module 403, configured to construct a second information security hazard detection system based on the target detection logic code.

[0075] Optionally, the first coding rule includes a number of first strings and the first interpretation corresponding to each first string, and the second coding rule includes a number of second strings and the second interpretation corresponding to each second string;

[0076] Based on this, the replacement module 402 is further configured to:

[0077] Determine each first string in the detection logic code as a string to be converted;

[0078] Use the first interpretation corresponding to each string to be converted as the target interpretation;

[0079] If there is a second interpretation that meets the preset matching condition for each target interpretation in the second coding rule, then for each string to be converted, use the second string corresponding to the second interpretation that meets the preset matching condition for the first interpretation corresponding to it as the replacement string corresponding to the string to be converted;

[0080] Replace each string to be converted in the detection logic code with the corresponding replacement string to obtain the target detection logic code.

[0081] Optionally, some of the first strings among the number of first strings are advanced strings; each advanced string has a synonymous string; the synonymous string is composed of at least some first strings that are not advanced strings;

[0082] Based on this, the replacement module 402 is further configured to:

[0083] Before replacing each string to be converted in the detection logic code with the corresponding replacement string to obtain the target detection logic code, if there is no second interpretation that meets the preset matching condition for any target interpretation in the second coding rule, then use the string to be converted corresponding to each target interpretation that has no second interpretation that meets the preset matching condition in the second coding rule as the string to be processed;

[0084] If each string to be processed is an advanced string, a replacement string corresponding to the string to be processed is determined according to the synonymous string corresponding to each string to be processed.

[0085] Optionally, determining a replacement string corresponding to the string to be processed according to the synonymous string corresponding to each string to be processed includes:

[0086] Taking the synonymous string corresponding to each string to be processed as the target string;

[0087] For each target string, replacing each first string therein with a second string corresponding to a second paraphrase that conforms to a preset matching condition and exists in the second coding rule for the corresponding first paraphrase, to obtain a replacement target string corresponding to the target string;

[0088] Taking each replacement target string as the replacement string for the corresponding string to be processed.

[0089] Optionally, the replacement module 402 is further configured to:

[0090] If any string to be processed is not an advanced string, an error prompt is displayed.

[0091] Optionally, the replacement module 402 is further configured to:

[0092] In the order of the lengths of the first strings from largest to smallest, for each first string in turn, in the part of the detection logic code that has not been determined as the string to be converted, determining the string identical to the first string as the string to be converted.

[0093] Optionally, both the first string and the second string are used to represent a communication protocol type identifier, a left operand, an operator, a right operand, or a special symbol.

[0094] Embodiments of the present disclosure further provide a non-transitory computer-readable storage medium, which can be disposed in an electronic device to store at least one instruction or at least one program related to a method in method embodiments, and the at least one instruction or the at least one program is loaded and executed by the processor to implement the method provided in the above embodiments.

[0095] Embodiments of the present disclosure further provide an electronic device, including a processor and the foregoing non-transitory computer-readable storage medium.

[0096] Although some specific embodiments of the present disclosure have been described in detail by way of examples, those skilled in the art should understand that the above examples are for illustrative purposes only and not for limiting the scope of the present disclosure. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the present disclosure. The scope of the present disclosure is defined by the appended claims.

Claims

1. A method for constructing an information security risk detection system, characterized in that The method includes: Obtaining the detection logic code of the first information security hazard detection system and the first coding rule corresponding to the detection logic code; According to the first coding rule, replacing each string to be converted in the detection logic code with a corresponding replacement string that conforms to the second coding rule to obtain a target detection logic code; Constructing a second information security hazard detection system based on the target detection logic code; The first coding rule includes a number of first strings and the first interpretation corresponding to each first string, and the second coding rule includes a number of second strings and the second interpretation corresponding to each second string; The step of, according to the first coding rule, replacing each string to be converted in the detection logic code with a corresponding replacement string that conforms to the second coding rule to obtain a target detection logic code includes: Determining each of the first strings in the detection logic code as the string to be converted; Regarding the first interpretation corresponding to each string to be converted as the target interpretation; If there is a second interpretation that conforms to the preset matching condition for each of the target interpretations in the second coding rule, then for each string to be converted, using the second string corresponding to the second interpretation that conforms to the preset matching condition and exists for the first interpretation corresponding to it in the second coding rule as the replacement string corresponding to the string to be converted; Replacing each string to be converted in the detection logic code with the corresponding replacement string to obtain a target detection logic code; Some of the first strings among the number of first strings are high-level strings; each high-level string has a synonymous string; the synonymous string is composed of at least some first strings that are not high-level strings; Before replacing each string to be converted in the detection logic code with the corresponding replacement string to obtain a target detection logic code, the step of, according to the first coding rule, replacing each string to be converted in the detection logic code with a corresponding replacement string that conforms to the second coding rule to obtain a target detection logic code further includes: If there is no second interpretation that conforms to the preset matching condition for any of the target interpretations in the second coding rule, then regarding the string to be converted corresponding to each target interpretation that has no second interpretation conforming to the preset matching condition in the second coding rule as a string to be processed; If each string to be processed is the high-level string, determining the replacement string corresponding to the string to be processed according to the synonymous string corresponding to each string to be processed; The step of determining the replacement string corresponding to each string to be processed according to the synonymous string corresponding to each string to be processed includes: Regarding the synonymous string corresponding to each string to be processed as the target string; For each target string, replacing each first string therein with the second string corresponding to the second interpretation that conforms to the preset matching condition and exists for the corresponding first interpretation in the second coding rule to obtain the replacement target string corresponding to the target string; Use each of the replaced target strings as the replacement string for the corresponding string to be processed.

2. The method according to claim 1, wherein The step of, according to the first encoding rule, replacing each string to be converted in the detection logic code with a corresponding replacement string that conforms to the second encoding rule to obtain a target detection logic code further includes: If any of the strings to be processed is not the high-level string, display an error prompt.

3. The method according to claim 1, wherein The step of determining each of the first strings in the detection logic code as the string to be converted includes: In the order of the lengths of the first strings from largest to smallest, successively determine, according to each first string, in the part of the detection logic code that has not been determined as the string to be converted, the string that is the same as the first string as the string to be converted.

4. The method according to any one of claims 1 to 3, characterized in that, Both the first string and the second string are used to represent a communication protocol type identifier, a left operand, an operator, or a right operand.

5. A device for constructing an information security hidden danger detection system, characterized in that, The device includes: An acquisition module, configured to acquire the detection logic code of the first information security risk detection system and the first encoding rule corresponding to the detection logic code; A replacement module, configured to, according to the first encoding rule, replace each string to be converted in the detection logic code with a corresponding replacement string that conforms to the second encoding rule to obtain a target detection logic code; A construction module, configured to construct a second information security risk detection system based on the target detection logic code; The first encoding rule includes a plurality of first strings and the first interpretation corresponding to each first string, and the second encoding rule includes a plurality of second strings and the second interpretation corresponding to each second string; The step of, according to the first encoding rule, replacing each string to be converted in the detection logic code with a corresponding replacement string that conforms to the second encoding rule to obtain a target detection logic code includes: The replacement module is further configured to: Determine each of the first strings in the detection logic code as the string to be converted; Use the first interpretation corresponding to each string to be converted as the target interpretation; If there is a second interpretation that meets the preset matching condition for each target interpretation in the second encoding rule, then for each string to be converted, use the second string corresponding to the second interpretation that meets the preset matching condition for the first interpretation corresponding to it in the second encoding rule as the replacement string corresponding to the string to be converted; Replace each string to be converted in the detection logic code with the corresponding replacement string to obtain a target detection logic code; Some of the plurality of first strings are high-level strings; each high-level string has a synonymous string; the synonymous string is composed of at least some first strings that are not high-level strings; Before replacing each string to be converted in the detection logic code with the corresponding replacement string to obtain a target detection logic code, the step of, according to the first encoding rule, replacing each string to be converted in the detection logic code with a corresponding replacement string that conforms to the second encoding rule to obtain a target detection logic code further includes: If any of the target interpretations does not have a second interpretation that meets the preset matching conditions in the second coding rule, then each string to be converted corresponding to the target interpretation that does not have a second interpretation meeting the preset matching conditions in the second coding rule is used as a string to be processed; If each of the strings to be processed is the advanced string, then a replacement string corresponding to the string to be processed is determined according to the synonymous string corresponding to each of the strings to be processed; The determining the replacement string corresponding to the string to be processed according to the synonymous string corresponding to each of the strings to be processed includes: Using the synonymous string corresponding to each of the strings to be processed as the target string; For each of the target strings, replacing each first string therein with a second string corresponding to a second interpretation that exists in the second coding rule and meets the preset matching conditions corresponding to the corresponding first interpretation, to obtain a replacement target string corresponding to the target string; Using each of the replacement target strings as the replacement string for the corresponding string to be processed.

6. A non-transitory computer-readable storage medium, in which at least one instruction or at least one program segment is stored, and the at least one instruction or the at least one program segment is loaded and executed by a processor to implement the method according to any one of claims 1-4.

7. An electronic device, characterized in that, Comprising a processor and the non-transitory computer-readable storage medium according to claim 6.

Citation Information

Patent Citations

  • Code migration method and device, computer equipment and storage medium

    CN112181489A

  • Code generation method and device

    CN114879964A