一种面向Rust语言的漏洞自动化定位及分析方法
By automating the collection and analysis of vulnerability data in the Rust ecosystem and locating vulnerable code, this technology solves the problems of low efficiency and high cost in existing technologies, and achieves efficient and automated vulnerability location and security risk analysis in the Rust ecosystem.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ZHEJIANG UNIV
- Filing Date
- 2023-04-03
- Publication Date
- 2026-07-17
AI Technical Summary
Existing technologies cannot automate the collection and location of vulnerabilities and vulnerable code in the Rust ecosystem, resulting in low location efficiency and high manual costs, and making it impossible to effectively analyze security risks in the Rust ecosystem.
By automating the collection of vulnerability data in the Rust open-source ecosystem, we analyze whether vulnerable code is located in insecure code blocks. This includes crawling vulnerability databases, cleaning and integrating data, locating remediation commits, obtaining insecure code blocks and vulnerable code locations, and using Rust compiler plugins and Gitdiff tools for automated analysis.
It automates the collection and location of vulnerabilities in the Rust ecosystem, improves the efficiency of location, reduces manual costs, provides analysis and development trends of security risks in the Rust ecosystem, and reveals the growth trend and impact scope of vulnerabilities.
Smart Images

Figure CN116305163B_ABST