Component-based directed dual-weight software cascading fault propagation modeling method and system

By building a software cascading fault propagation modeling method of internal and external propagation probability and fault tolerance in the component, the problem of neglecting software fault tolerance and execution path in the existing technology is solved, and more accurate software reliability analysis is achieved.

CN116069623BActive Publication Date: 2025-08-19BEIJING INST OF TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211614384.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-12
Publication Date
2025-08-19
Estimated Expiration
2042-12-12

AI Technical Summary

Technical Problem

The existing software cascade fault propagation modeling methods ignore the change in call frequency, software error tolerance and execution path between functions, resulting in misjudgment of software reliability.

Method used

The directed dual-righted software cascaded fault propagation modeling method is adopted based on components. By building a software network, considering the probability of internal and external transmission and fault tolerance of components, introducing coordination factor quantization uncertainty, and calculating the probability of transmission and infection between components.

Benefits of technology

It improves the simulation effectiveness of software cascade fault propagation modeling, reduces the misjudgment of reliability by software testers, and provides a more comprehensive analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116069623B_ABST
    Figure CN116069623B_ABST
Patent Text Reader

Abstract

The present invention discloses a component-based directed dual-weight software cascade fault propagation modeling method and system, which takes into account the propagation probability within and between components, the propagation limit of the component fault tolerance rate, and the uncertainty during the software operation process. The method includes the following steps: analyzing the software, constructing a software network with functions in the software as nodes and the call relationships between functions as edges; and treating each function node as a component. For faulty component i, if the starting component of the directed edge pointing to the faulty component is a non-faulty component j, the intra-component propagation probability and the inter-component propagation probability of the non-faulty component j are calculated, and the software cascade fault propagation probability is further calculated to obtain the fault infection probability of component j. If the fault infection probability of component j is greater than or equal to its own fault tolerance rate, component j is infected and becomes a new faulty component. The infection probability of the non-faulty components corresponding to the new faulty component is continuously calculated until no new faulty components appear.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software analysis, and is a component-based directed dual-weight software cascade fault propagation modeling method and system. Background Art

[0002] As we all know, software is composed of numerous functions and modules, which are closely interconnected and frequently call each other. When one module or function fails, it can cause other connected modules and functions to fail as well, ultimately leading to partial or complete system crashes—a phenomenon known as a "cascading failure." Software vulnerabilities are a fundamental property of software, and it's impossible to completely eradicate them during the development of complex software. Once a vulnerability is triggered, it can trigger a large-scale cascading failure, causing indelible damage to computers and user information.

[0003] The emergence of complex network theory has significantly boosted research in software engineering. Many researchers have begun to delve into the cascading fault propagation characteristics of complex software from a complex network perspective, incorporating software engineering practices. Typically, complex software is modeled as a topological network. The cascading fault propagation process is then modeled based on the call relationships between functions, and finally, the propagation characteristics of cascading faults are analyzed.

[0004] There are many ways to analyze the cascading fault propagation characteristics of software after modeling it as a network. The following two methods are more common:

[0005] (1) Complex software is modeled as an edge-weighted software network model. Functions are used as nodes and call relationships as edges. Directed edges and edge weights are used to represent the call relationships and closeness between functions. By introducing function fault tolerance and constant fault intensity, a cascading fault propagation model for complex software is established to simulate the fault propagation behavior during software runtime.

[0006] (2) Only the function call frequency is used to quantify the propagation probability of software cascading failures. Based on modeling complex software as an edge-weighted software network, the probability of cascading failure propagation between nodes is defined as the ratio of the number of times node j calls faulty node i to the number of times node j calls all directly callable nodes. A fixed infection threshold is then used to determine the propagation of cascading failures.

[0007] Existing cascading fault propagation modeling methods only consider the call frequency between functions, which has the following four limitations:

[0008] (1) Dynamic analysis is used to obtain the calling frequency between functions, ignoring the possibility that uncalled functions are executed;

[0009] (2) Using a single fault intensity when maliciously triggering software faults ignores the changes in fault intensity during function calls;

[0010] (3) When modeling the propagation of software cascading faults, the software fault tolerance rate is not considered, and the quadratic constraints before and after the propagation of software cascading faults are ignored;

[0011] (4) When modeling the propagation of software cascading faults, the software execution path is not considered, and the propagation probability during software operation is ignored.

[0012] How to improve the above shortcomings and enhance the simulation effectiveness of cascading failures based on the existing software network cascading failure propagation modeling method is an urgent problem to be solved. Summary of the Invention

[0013] In view of this, the present invention provides a component-based directed dual-weight software cascading fault propagation modeling method and system, which can solve the shortcomings of the current software cascading fault propagation modeling method, conduct a more comprehensive analysis of software cascading fault propagation, take into account the propagation probability within and between components, the propagation limit of component fault tolerance and the uncertainty in the software operation process, and can effectively reduce the misjudgment of software reliability by software testers.

[0014] To achieve the above object, the technical solution of the present invention includes the following steps:

[0015] Step 1: Analyze the software, build a software network with functions in the software as nodes and call relationships between functions as edges; treat each function node as a component.

[0016] Step 2: Components with internal defects or malicious attacks are considered faulty components. For faulty component i, if the starting component of the directed edge pointing to the faulty component is a non-faulty component, calculate the fault infection probability of non-faulty component j according to steps 3 to 5.

[0017] Step 3: The probability P(fre) that non-faulty component j receives fault infection from faulty component i ji The ratio of the number of times component i is called for component j to the number of times component j calls all directly callable components;

[0018] The probability of propagation within a component is P(in) ji : is the failure probability of component j itself.

[0019] Step 4: If component i has self-call, the inter-component propagation probability P(mid) ji is 1; otherwise, the probability of propagation between components is P(mid) jiIt is expressed as: the probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j.

[0020] Step 5: Based on the propagation probability P(in) within the component ji Probability of propagation between components P(mid) ji , we can get the software cascade failure propagation probability P ji .

[0021] When the propagation probability P(in) within the component ji Greater than or equal to the component fault tolerance ρ of component j j When the fault infection probability of component j is P j Depends only on the cascade failure propagation probability P between component i and component j ji .

[0022] When the propagation probability P(in) within the component ji Less than the component fault tolerance ρ of component j j When the fault infection probability of component j is P j It depends on the probability P of cascading failure propagation between two components ji , Propagation probability within the component P(in) ji and the component fault tolerance ρ of component j j The combined effect of the ratio.

[0023] If the fault infection probability of component j is greater than or equal to its own fault tolerance rate, component j is infected and becomes a new faulty component. Steps 2 to 5 are repeated until no new faulty components appear.

[0024] Furthermore, the software network is represented as a weighted directed graph G with N nodes and E edges, denoted as G = (V, E, F V , W E ); where V is a node set, each element v in V j Represents a function in the software; E is an edge set, each element in E <v i ,v j > is an ordered pair if and only if v i Call v j hour, <v i ,v j >∈E, that is, v i →v j ; F V represents the set of failure probabilities within the node, W E Represents each element in E <v i ,v j >The call frequency set;

[0025]

[0026] Among them, l j It represents the number of lines of code of function j, FD represents the error density, and FD is the defect rate, which is determined according to the different CMMI maturity levels of the software.

[0027] Furthermore, the probability P(fre) that a non-faulty component j receives a fault infection from a faulty component i is ji The ratio of the number of times component i is called for component j to the number of times component j calls all directly callable components, specifically:

[0028]

[0029] Among them, P(fre) ji represents the probability of component j receiving fault infection from faulty component i, N is the set of components directly called by component j, and W ji represents the weight from component j to component i.

[0030] Furthermore, if component i has self-call, the inter-component propagation probability P(mid) ji is 1; otherwise, the probability of propagation between components is P(mid) ji It is expressed as follows: The probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j, specifically:

[0031] Set the reconciliation factor α, α∈[0,1] to measure the uncertainty of the propagation probability between components;

[0032] Probability of propagation between components P(mid) ji Expressed as:

[0033]

[0034] where R ji represents the number of times component j is executed in all reachable paths of component i, N is the set of components directly called by component j; the probability that component j is infected by the faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j; when k = 0, it means that component i has self-calling.

[0035] Furthermore, the component fault tolerance ρ of component j j, which means that the component j's ability to handle faults is called component fault tolerance; the component fault tolerance is divided into 8 levels, that is, ρ∈[1,8]; two fault tolerance allocation methods are set: random allocation and power law allocation; random allocation means that the fault tolerance of each component conforms to the Poisson distribution with a mean of ρ; power law allocation means that the fault tolerance of each component conforms to the power law distribution with a power exponent of ρ.

[0036] Furthermore, according to the propagation probability P(in) within the component ji Probability of propagation between components P(mid) ji , we can get the software cascade failure propagation probability P ji , specifically:

[0037] P ji =P(in) ji ×P(mid) ji (6)

[0038] When the propagation probability P(in) within the component ji Greater than or equal to the component fault tolerance ρ of component j j When the fault infection probability of component j is P j Depends only on the cascade failure propagation probability P between component i and component j ji ;

[0039] When the propagation probability P(in) within the component ji Less than the component fault tolerance ρ of component j j When the fault infection probability of component j is P j It depends on the probability P of cascading failure propagation between two components ji , Propagation probability within the component P(in) ji and the component fault tolerance ρ of component j j The joint effect of the ratio;

[0040] Specifically:

[0041] P j =P ji ×β ji (7)

[0042] in,

[0043]

[0044] Another embodiment of the present invention further provides a component-based directed dual-weight software cascading fault propagation modeling system, comprising the following modules:

[0045] The software network construction module is used to analyze software, build a software network with functions in the software as nodes and the call relationships between functions as edges; each function node is regarded as a component.

[0046] The fault component search module is used to find the components that have been infected with the fault as the faulty components. For the faulty component i, if the starting component of the directed edge pointing to the faulty component is a non-faulty component, the fault infection probability calculation module is called for the non-faulty component to calculate the fault infection probability of the non-faulty component j.

[0047] The fault infection probability estimation module is used to calculate the fault infection probability of non-faulty component j; this module is divided into an intra-component propagation probability calculation unit, an inter-component propagation probability calculation unit, a cascade fault propagation probability calculation unit, and a fault infection probability calculation unit.

[0048] The intra-component propagation probability calculation unit is used to calculate the intra-component propagation probability, that is, the probability P(fre) that a non-faulty component j receives a fault infection from a faulty component i. ji The ratio of the number of times component i is called for component j to the number of times component j calls all directly callable components; the probability of propagation within a component is P(in) ji : is the failure probability of component j itself.

[0049] The inter-component propagation probability calculation unit is used to calculate the inter-component propagation probability, that is, if component i has self-call, the inter-component propagation probability P(mid) ji is 1; otherwise, the probability of propagation between components is P(mid) ji It is expressed as: the probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j.

[0050] Cascading fault propagation probability calculation unit, used to calculate the propagation probability P(in) within the component ji Probability of propagation between components P(mid) ji , we can get the software cascade failure propagation probability P ji .

[0051] The fault infection probability calculation unit is used to calculate the fault infection probability of component j, specifically when the propagation probability P(in) within the component ji Greater than or equal to the component fault tolerance ρ of component j j When the fault infection probability of component j is P j Depends only on the cascade failure propagation probability P between component i and component j ji ; When the propagation probability P(in) within the component ji Less than the component fault tolerance ρ of component j j When the fault infection probability of component j is P j It depends on the probability P of cascading failure propagation between two components ji , Propagation probability within the component P(in)ji and the component fault tolerance ρ of component j j If the fault infection probability of component j is greater than or equal to its own fault tolerance rate, then component j is infected and becomes a new faulty component. Return to execute the fault infection probability estimation module. If there is no new faulty component, the process ends.

[0052] Furthermore, the software network construction module constructs a software network represented by a weighted directed graph G with N nodes and E edges, denoted as G = (V, E, F V , W E ); where V is a node set, each element v in V j Represents a function in the software; E is an edge set, each element in E <v i ,v j > is an ordered pair if and only if v i Call v j hour, <v i ,v j >∈E, that is, v i →v j ; F V represents the set of failure probabilities within the node, W E Represents each element in E <v i ,v j >The call frequency set;

[0053]

[0054] Among them, l j It represents the number of lines of code of function j, FD represents the error density, and FD is the defect rate, which is determined according to the different CMMI maturity levels of the software.

[0055] Furthermore, the probability P(fre) that a non-faulty component j receives a fault infection from a faulty component i is ji The ratio of the number of times component i is called for component j to the number of times component j calls all directly callable components, specifically:

[0056]

[0057] Among them, P(fre) ji represents the probability of component j receiving fault infection from faulty component i, N is the set of components directly called by component j, and W ji represents the weight from component j to component i.

[0058] Furthermore, if component i has self-call, the inter-component propagation probability P(mid) ji is 1; otherwise, the probability of propagation between components is P(mid) jiIt is expressed as follows: The probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j, specifically:

[0059] Set the reconciliation factor α, α∈[0,1] to measure the uncertainty of the propagation probability between components;

[0060] Probability of propagation between components P(mid) ji Expressed as:

[0061]

[0062] where R ji represents the number of times component j is executed in all reachable paths of component i, N is the set of components directly called by component j; the probability that component j is infected by the faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j; when k = 0, it means that component i has self-calling.

[0063] Furthermore, according to the propagation probability P(in) within the component ji Probability of propagation between components P(mid) ji , we can get the software cascade failure propagation probability P ji , specifically:

[0064] P ji =P(in) ji ×P(mid) ji (6)

[0065] When the propagation probability P(in) within the component ji Greater than or equal to the component fault tolerance ρ of component j j When the fault infection probability of component j is P j Depends only on the cascade failure propagation probability P between component i and component j ji ;

[0066] When the propagation probability P(in) within the component ji Less than the component fault tolerance ρ of component j j When the fault infection probability of component j is P j It depends on the probability P of cascading failure propagation between two components ji , Propagation probability within the component P(in) ji and the component fault tolerance ρ of component j j The joint effect of the ratio;

[0067] Specifically:

[0068] P j =P ji ×βji (7)

[0069] in,

[0070]

[0071] Beneficial effects:

[0072] The present invention proposes a component-based directed dual-weight software cascading fault propagation modeling method: by obtaining attribute information such as the function call frequency and the number of lines of code, and treating each function node as a component, the propagation characteristics of the software cascading fault can be analyzed more comprehensively. The internal failure probability of the component is calculated based on the number of lines of code of each function and the maturity of the software, avoiding the misjudgment of software reliability caused by the use of a constant fault intensity. The ratio of the fault tolerance of each component to the maximum fault tolerance of all components is set as the fault tolerance rate of each component, and propagation constraints are performed before and after the propagation of the fault node, avoiding the misjudgment of software reliability caused by the use of a single fault tolerance. The propagation path probability between components is defined as the ratio of the number of times node j appears in the reachable path of node i to the total number of reachable paths of node j. At the same time, a reconciliation factor is introduced to quantify the uncertainty in the software operation process. In summary, the present invention solves the shortcomings of current software cascading fault propagation modeling methods, conducts a more comprehensive analysis of software cascading fault propagation, takes into account the propagation probability within and between components, the propagation limit of component fault tolerance, and the uncertainty during software operation, and can effectively reduce software testers' misjudgment of software reliability. BRIEF DESCRIPTION OF THE DRAWINGS

[0073] Figure 1 Component-based directed dual-weight software cascading fault propagation model diagram;

[0074] Figure 2 A flow chart of a component-based, directed, dual-weighted software cascading fault propagation modeling method provided by the present invention;

[0075] Figure 3 A block diagram of a component-based directed dual-weight software cascading fault propagation modeling system provided by the present invention. DETAILED DESCRIPTION

[0076] The present invention is described in detail below with reference to the accompanying drawings and embodiments.

[0077] The present invention provides a component-based directed dual-weight software cascading fault propagation modeling method.

[0078] (1) Overall framework

[0079] First, we use reverse analysis to obtain the number of functions, call relationships, call frequency, number of lines of code, and other attributes in the software. This allows us to construct a directed bi-weighted software network without knowing the source code. Secondly, in order to model from a fine-grained perspective, we model each function node as a component to more clearly observe the cascading fault propagation in the software network. Finally, considering the propagation probability within and between components and the propagation limit of the component fault tolerance, we construct a cascading fault propagation model such as Figure 1 The specific steps of the present invention are as shown. Figure 2 As shown, specifically:

[0080] Step 1: Analyze the software, build a software network with functions in the software as nodes and call relationships between functions as edges; treat each function node as a component.

[0081] Specifically, the embodiment of the present invention adopts the following method to construct the network topology:

[0082] The present invention represents the software network as a weighted directed graph G with N nodes and E edges, which is denoted as G=(V, E, F V , W E ). Where V is a node set, each element v in V i Represents a function in the software. E is an edge set, and each element in E <v i ,v j > is an ordered pair if and only if v i Call v j hour, <v i ,v j >∈E, that is, v i →v j . F V represents the set of failure probabilities within the node, F V Each element in The calculation method is shown in formula (1). E Represents each element in E <v i ,v j >The call frequency collection.

[0083] W E Represents each element in E <v i ,v j >The call frequency collection.

[0084]

[0085] Among them, l j It represents the number of lines of code of function j, and FD represents the error density, which is the defect rate mentioned above, and is determined according to the different maturity levels of the software (CMMI).

[0086] Step 2: Components with internal defects or malicious attacks are considered faulty components. For faulty component i, if the starting component of the directed edge pointing to the faulty component is a non-faulty component, calculate the fault infection probability of non-faulty component j according to steps 3 to 5:

[0087] Step 3: Calculate the propagation probability within the component.

[0088] This paper considers an application consisting of C interacting components and assumes that data errors are always propagated through control flow. Only when other components call a component i that has already been infected with a fault can the fault of component i be propagated to other components. The probability of a component propagating a fault to other components is clearly correlated with the frequency with which other components call component i. Therefore, the probability P(fre) that component j may receive a fault propagation from faulty component i is defined based on the edge weights (i.e., function call frequency) in a directed dual-weight software network model. ji , as shown in formula (2):

[0089]

[0090] Among them, P(fre) ji represents the probability of component j receiving fault infection from faulty component i, N is the set of components directly called by component j, and W ji represents the weight from component j to component i. In other words, the probability of component j receiving a fault infection from faulty component i is the ratio of the number of times component j calls component i to the number of times component j calls all directly callable components. Therefore, the probability of propagation within a component can be expressed as:

[0091]

[0092] Step 4: Calculate the propagation probability between components.

[0093] The present invention assumes that the operation process of each component i is known and it follows the Markov property. Therefore, it can be expressed by the probability p(i,j) (1≤i,j≤C). Given an interaction from component i, it is processed to component j with However, since the execution probability between any component and its calling component is less than 1 during real software execution, this paper uses an α reconciliation factor, α∈[0,1], to measure the uncertainty of the propagation probability between components. Therefore, the propagation probability between components can be expressed as:

[0094]

[0095] In the present invention, self-conversion is not prohibited, that is, it may happen that p(i,i)≠0.ji represents the number of times component j is executed in all reachable paths from component i, and N is the set of components directly called by component j. In other words, the probability that component j is infected by a faulty component i via a propagation path is the ratio of the number of times component j appears in reachable paths from component i to the total number of reachable paths from component j. k = 0 indicates that the component has self-calls.

[0096] Step 5: Calculate the probability of cascading fault propagation.

[0097] In the embodiment of the present invention, the component fault tolerance rate is calculated in the following manner:

[0098] During the software operation, if component i fails, such as memory overflow, the fault may be propagated to component j with a certain probability through calls or dependencies between functions, and the strength of the latter's fault tolerance determines whether the fault can cause component j to fail, and then affect other components that call and depend on component j. In the field of software engineering, the ability of each component in a software network to handle faults is called component fault tolerance, denoted as ρ. Referring to the classification method of code vulnerabilities by Fortify Software, component fault tolerance is also divided into 8 levels, that is, ρ∈[1,8]. The higher the level, the stronger the component fault tolerance is, and the less likely it is to be affected by software faults. The present invention sets two fault tolerance distribution methods: random distribution, the fault tolerance of each component conforms to the Poisson distribution with a mean of ρ; power law distribution, the fault tolerance of each component conforms to the power law distribution with a power exponent of ρ. Therefore, the fault tolerance rate of each component can be expressed as:

[0099] ρ j =ρ j / max(ρ) (5)

[0100] In the embodiment of the present invention, the cascading fault propagation probability is calculated as follows:

[0101] There are two ways to trigger a vulnerability: random triggering, where q nodes are randomly selected from the graph G as the initial fault nodes, for example, due to accidental changes in the operating environment causing a function malfunction; and malicious triggering, where the first q nodes with the largest in-degree are selected from the graph G as the initial fault nodes, for example, an attack initiated by a hacker. Based on the intra-component propagation probability and the inter-component propagation probability, the software cascading fault propagation probability can be easily derived as:

[0102] P ji =P(in) ij ×P(mid) ji (6)

[0103] The present invention stipulates that when the propagation probability P(in) within the component ji Greater than or equal to the component fault tolerance rate ρ iWhen , whether component j will be affected by the fault depends only on the cascade fault propagation probability between components i and j; when the propagation probability within the component P(in) ji Less than the component fault tolerance ρ i Whether the fault can infect component j depends on the cascade fault propagation probability between the two components and the propagation probability within the component P(in) ji and component fault tolerance ρ i Therefore, the fault infection probability of component j can be expressed as:

[0104] P j =P ji ×β ji (7)

[0105] in,

[0106]

[0107] A faulty component can only propagate its fault if it is called by other components. Therefore, the single-stage fault propagation rule is defined as follows: traverse all faulty components. If the starting component of the directed edge pointing to the faulty component is a non-faulty component, calculate the infection probability according to formula (7) and infect the component with this probability until all non-faulty neighboring components are calculated. After the single-stage fault propagation is completed, if the fault infection probability of component j is greater than or equal to its own fault tolerance rate, component j is infected and becomes a faulty node. It is then treated as a new faulty component and steps 2 to 5 are repeated until no new faulty components appear.

[0108] Another embodiment of the present invention also provides a component-based directed dual-weight software network cascading fault propagation modeling system, such as Figure 3 As shown, it includes the following modules:

[0109] The software network construction module is used to analyze software, build a software network with functions in the software as nodes and the call relationships between functions as edges; each function node is regarded as a component;

[0110] The fault component search module is used to find the components that have been infected with the fault as the faulty components. For the faulty component i, if the starting component of the directed edge pointing to the faulty component is a non-faulty component, the fault infection probability calculation module is called for the non-faulty component to calculate the fault infection probability of the non-faulty component j:

[0111] The fault infection probability estimation module is used to calculate the fault infection probability of non-faulty component j; this module is divided into an intra-component propagation probability calculation unit, an inter-component propagation probability calculation unit, a cascade fault propagation probability calculation unit, and a fault infection probability calculation unit;

[0112] The intra-component propagation probability calculation unit is used to calculate the intra-component propagation probability, that is, the probability P(fre) that a non-faulty component j receives a fault infection from a faulty component i. ji The ratio of the number of times component i is called for component j to the number of times component j calls all directly callable components; the probability of propagation within a component is P(in) ji : For component v j its own probability of failure;

[0113] The inter-component propagation probability calculation unit is used to calculate the inter-component propagation probability, that is, if component i has self-call, the inter-component propagation probability P(mid) ji is 1; otherwise, the probability of propagation between components is P(mid) ji It is expressed as: the probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j;

[0114] Cascading fault propagation probability calculation unit, used to calculate the propagation probability P(in) within the component ji Probability of propagation between components P(mid) ji , we can get the software cascade failure propagation probability P ji ;;

[0115] The fault infection probability calculation unit is used to calculate the fault infection probability of component j, specifically when the propagation probability P(in) within the component ji Greater than or equal to the component fault tolerance ρ of component j j When the fault infection probability of component j is P j Depends only on the cascade failure propagation probability P between component i and component j ji ; When the propagation probability P(in) within the component ji Less than the component fault tolerance ρ of component j j When the fault infection probability of component j is P j It depends on the probability P of cascading failure propagation between two components ji , Propagation probability within the component P(in) ji and the component fault tolerance ρ of component j j If the fault infection probability of component j is greater than or equal to its own fault tolerance rate, then component j is infected and becomes a new faulty component. Return to execute the fault infection probability estimation module. If there is no new faulty component, the process ends.

[0116] The software network construction module is represented as a weighted directed graph G with N nodes and E edges, denoted as G = (V, E, F V , W E); where V is a node set, each element v in V j Represents a function in the software; E is an edge set, each element in E <v i ,v j > is an ordered pair if and only if v i Call v j hour, <v i ,v j >∈E, that is, v i →v j ; F V represents the set of failure probabilities within the node, W E Represents each element in E <v i ,v j >The call frequency set;

[0117]

[0118] Among them, l j It represents the number of lines of code of function j, FD represents the error density, and FD is the defect rate, which is determined according to the different CMMI maturity levels of the software.

[0119] In the component propagation probability calculation unit, the probability P(fre)ji of non-faulty component j receiving fault infection from faulty component i is the ratio of the number of times component j calls component i to the number of times component j calls all directly callable components, specifically:

[0120]

[0121] Among them, P(fre) ji represents the probability of component j receiving fault infection from faulty component i, N is the set of components directly called by component j, and W ji represents the weight from component j to component i.

[0122] In the inter-component propagation probability calculation unit, if component i has self-call, the inter-component propagation probability P(mid) ji is 1; otherwise, the probability of propagation between components is P(mid) ji It is expressed as follows: The probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j, specifically:

[0123] Set the reconciliation factor α, α∈[0,1] to measure the uncertainty of the propagation probability between components;

[0124] Probability of propagation between components P(mid) ji Expressed as:

[0125]

[0126] where R ji represents the number of times component j is executed in all reachable paths of component i, N is the set of components directly called by component j; the probability that component j is infected by the faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j; when k = 0, it means that component i has self-calling.

[0127] In the joint fault propagation probability calculation unit provided by the embodiment of the present invention, according to the component internal propagation probability P(in) ji Probability of propagation between components P(mid) ji , we can get the software cascade failure propagation probability P ji , specifically:

[0128] P ji =P(in) ji ×P(mid) ji (6)

[0129] When the propagation probability P(in) within the component ji Greater than or equal to the component fault tolerance ρ of component j j When the fault infection probability of component j is P j Depends only on the cascade failure propagation probability P between component i and component j ji ;

[0130] When the propagation probability P(in) within the component ji Less than the component fault tolerance ρ of component j j When the fault infection probability of component j is P j It depends on the probability P of cascading failure propagation between two components ji , Propagation probability within the component P(in) ji and the component fault tolerance ρ of component j j The joint effect of the ratio;

[0131] Specifically:

[0132] P j =P ji ×β ji (7)

[0133] in,

[0134]

[0135] The above system and method can be stored as a software program on a storage medium, which stores computer instructions. The storage medium is computer-readable and can implement the above-mentioned component-based directed bi-weighted software network cascading fault propagation modeling method or system when the instructions are executed by a processor.

[0136] The present invention solves the shortcomings of current software cascading fault propagation modeling methods and conducts a more comprehensive analysis of software cascading fault propagation, taking into account the propagation probability within and between components, the propagation limit of component fault tolerance, and the uncertainty during software operation, which can effectively reduce software testers' misjudgment of software reliability.

[0137] In summary, the above are only preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A component-based, directed, dual-weighted software cascading fault propagation modeling method, characterized by: The steps include: Step 1: Analyze the software, construct a software network using functions in the software as nodes and the call relationships between functions as edges; treat each function node as a component; Step 2: Components with internal defects or malicious attacks are considered faulty components. For faulty component i, if the starting component of the directed edge pointing to the faulty component is a non-faulty component, calculate the fault infection probability of non-faulty component j according to steps 3 to 5: Step 3: The probability P(fre) that non-faulty component j receives fault infection from faulty component i ji The ratio of the number of times component i is called for component j to the number of times component j calls all directly callable components; The probability of propagation within a component is P(in) ji : is the failure probability of component j itself; Step 4: If component i has self-call, the inter-component propagation probability P(mid) ji is 1; otherwise, the probability of propagation between components is P(mid) ji It is expressed as: the probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j; Step 5: Based on the propagation probability P(in) within the component ji Probability of propagation between components P(mid) ji , we can get the software cascade failure propagation probability P ji ; When the propagation probability P(in) within the component ji Greater than or equal to the component fault tolerance ρ of component j j When the fault infection probability of component j is P j Depends only on the cascade failure propagation probability P between component i and component j ji ; When the propagation probability P(in) within the component ji Less than the component fault tolerance ρ of component j j When the fault infection probability of component j is P j It depends on the probability P of cascading failure propagation between two components ji , Propagation probability within the component P(in) ji and the component fault tolerance ρ of component j j The joint effect of the ratio; If the fault infection probability of component j is greater than or equal to its own fault tolerance rate, component j is infected and becomes a new faulty component. Repeat steps 2 to 5 until no new faulty components appear.

2. The component-based directed dual-weight software cascading fault propagation modeling method according to claim 1, characterized in that: The software network is represented as a weighted directed graph G with N' nodes and E edges, denoted as G = (V, E, F V , W E ); where V is a node set, each element v in V j Represents a function in the software; E is an edge set, each element in E <v i ,v j > is an ordered pair if and only if v i Call v j hour, <v i ,v j >∈E, that is, v i →v j ; F V represents the set of failure probabilities within the node, W E Represents each element in E <v i ,v j >The call frequency set; Among them, l j It represents the number of lines of code of function j, FD represents the error density, and FD is the defect rate, which is determined according to the different CMMI maturity levels of the software.

3. The component-based directed dual-weight software cascading fault propagation modeling method according to claim 1, characterized in that: The probability P(fre) that the non-faulty component j receives the fault infection from the faulty component i is ji The ratio of the number of times component i is called for component j to the number of times component j calls all directly callable components, specifically: Among them, P(fre) ji represents the probability of component j receiving fault infection from faulty component i, N is the set of components directly called by component j, and W ji represents the weight from component j to component i.

4. The component-based directed dual-weight software cascading fault propagation modeling method according to claim 1 is characterized in that: If component i has self-call, the inter-component propagation probability P(mid) ji is 1; otherwise, the probability of propagation between components is P(mid) ji It is expressed as follows: The probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j, specifically: Set the reconciliation factor α, α∈[0,1] to measure the uncertainty of the propagation probability between components; Probability of propagation between components P(mid) ji Expressed as: where R ji represents the number of times component j is executed in all reachable paths from component i, and N is the set of components directly called by component j; The probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j; when k=0, it means that component i has self-call.

5. The component-based directed dual-weight software cascading fault propagation modeling method according to claim 1, characterized in that: The component fault tolerance rate ρ of the component j j , which indicates the ability of component j to handle faults is called component fault tolerance; The component fault tolerance is divided into 8 levels, i.e. ρ∈[1,8]; Set two fault tolerance allocation methods: random allocation and power law allocation; The random allocation means that the fault tolerance of each component conforms to a Poisson distribution with a mean of ρ; the power law allocation means that the fault tolerance of each component conforms to a power law distribution with a power exponent of ρ.

6. The component-based directed dual-weight software cascading fault propagation modeling method according to claim 1, characterized in that: The propagation probability P(in) within the component ji Probability of propagation between components P(mid) ji , we can get the software cascade failure propagation probability P ji , specifically: P ji =P(in) ji ×P(mid) ji (6) When the propagation probability P(in) within the component ji Greater than or equal to the component fault tolerance ρ of component j j When the fault infection probability of component j is P j Depends only on the cascade failure propagation probability P between component i and component j ji ; When the propagation probability P(in) within the component ji Less than the component fault tolerance ρ of component j j When the fault infection probability of component j is P j It depends on the probability P of cascading failure propagation between two components ji , Propagation probability within the component P(in) ji and the component fault tolerance ρ of component j j The joint effect of the ratio; Specifically: P j =P ji ×β ji (7) Among them, 7. A component-based directed dual-weight software cascading fault propagation modeling system, characterized by: Includes the following modules: The software network construction module is used to analyze software, build a software network with functions in the software as nodes and the call relationships between functions as edges; each function node is regarded as a component; The fault component search module is used to find the components that have been infected with the fault as the faulty components. For the faulty component i, if the starting component of the directed edge pointing to the faulty component is a non-faulty component, the fault infection probability calculation module is called for the non-faulty component to calculate the fault infection probability of the non-faulty component j: The fault infection probability estimation module is used to calculate the fault infection probability of non-faulty component j; this module is divided into an intra-component propagation probability calculation unit, an inter-component propagation probability calculation unit, a cascade fault propagation probability calculation unit, and a fault infection probability calculation unit; The intra-component propagation probability calculation unit is used to calculate the intra-component propagation probability, that is, the probability P(fre) that a non-faulty component j receives a fault infection from a faulty component i. ji The ratio of the number of times component i is called for component j to the number of times component j calls all directly callable components; the probability of propagation within a component is P(in) ji : is the failure probability of component j itself; The inter-component propagation probability calculation unit is used to calculate the inter-component propagation probability, that is, if component i has self-call, the inter-component propagation probability P(mid) ji is 1; otherwise, the probability of propagation between components is P(mid) ji It is expressed as: the probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j; The cascading fault propagation probability calculation unit is used to calculate the cascading fault propagation probability P(in) according to the component propagation probability P(in) ji Probability of propagation between components P(mid) ji , we can get the software cascade failure propagation probability P ji ; The fault infection probability calculation unit is used to calculate the fault infection probability of component j, specifically when the propagation probability P(in) within the component ji Greater than or equal to the component fault tolerance ρ of component j j When the fault infection probability of component j is P j Depends only on the cascade failure propagation probability P between component i and component j ji ; When the propagation probability P(in) within the component ji Less than the component fault tolerance ρ of component j j When the fault infection probability of component j is P j It depends on the probability P of cascading failure propagation between two components ji , Propagation probability within the component P(in) ji and the component fault tolerance ρ of component j j If the fault infection probability of component j is greater than or equal to its own fault tolerance rate, then component j is infected and becomes a new faulty component. Return to execute the fault infection probability estimation module. If there is no new faulty component, the process ends.

8. The component-based directed dual-weight software cascading fault propagation modeling system according to claim 7, characterized in that: The software network construction module constructs a software network represented by a weighted directed graph G with N' nodes and E edges, denoted as G = (V, E, F V , W E ); where V is a node set, each element v in V j Represents a function in the software; E is an edge set, each element in E <v i ,v j > is an ordered pair if and only if v i Call v j hour, <v i ,v j >∈E, that is, v i →v j ; F V represents the set of failure probabilities within the node, W E Represents each element in E <v i ,v j >The call frequency set; Among them, l j It represents the number of lines of code of function j, FD represents the error density, and FD is the defect rate, which is determined according to the different CMMI maturity levels of the software.

9. The component-based directed dual-weight software cascading fault propagation modeling system according to claim 7 or 8, characterized in that: The probability P(fre) that the non-faulty component j receives the fault infection from the faulty component i is ji The ratio of the number of times component i is called for component j to the number of times component j calls all directly callable components, specifically: Among them, P(fre) ji represents the probability of component j receiving fault infection from faulty component i, N is the set of components directly called by component j, and W ji represents the weight from component j to component i.

10. The component-based directed dual-weight software cascading fault propagation modeling system according to claim 7 or 8, characterized in that: If component i has self-call, the inter-component propagation probability P(mid) ji is 1; otherwise, the probability of propagation between components is P(mid) ji It is expressed as follows: The probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j, specifically: Set the reconciliation factor α, α∈[0,1] to measure the uncertainty of the propagation probability between components; Probability of propagation between components P(mid) ji Expressed as: where R ji represents the number of times component j is executed in all reachable paths of component i, and N is the set of components directly called by component j; The probability that component j is infected by faulty component i through the propagation path is the ratio of the number of times component j appears in the reachable paths of component i to the total number of reachable paths of component j; when k = 0, it means that component i has self-call; The propagation probability P(in) within the component ji Probability of propagation between components P(mid) ji , we can get the software cascade failure propagation probability P ji , specifically: P ji =P(in) ji ×P(mid) ji (6) When the propagation probability P(in) within the component ji Greater than or equal to the component fault tolerance ρ of component j j When the fault infection probability of component j is P j Depends only on the cascade failure propagation probability P between component i and component j ji ; When the propagation probability P(in) within the component ji Less than the component fault tolerance ρ of component j j When the fault infection probability of component j is P j It depends on the probability P of cascading failure propagation between two components ji , Propagation probability within the component P(in) ji and the component fault tolerance ρ of component j j The joint effect of the ratio; Specifically: P j =P ji ×β ji (7) in,

Citation Information

Patent Citations

  • Component software reliability evaluation method based on migration paths and improved Markov chain

    CN104503913A

  • Construction method of software defect evaluation model on the basis of complex network

    CN105808435A