Data processing method, device, storage medium and electronic device

By using code generation models to generate and evaluate vulnerable codes in the automatic file processing scenario, the problem of building high-quality vulnerable code data sets is solved, and the diversity and quality improvement of vulnerable codes is achieved.

CN119322734BActive Publication Date: 2025-05-16BEIJING QIHOOD TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411822985.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-11
Publication Date
2025-05-16
Estimated Expiration
2044-12-11

AI Technical Summary

Technical Problem

It is difficult to build high-quality vulnerability code datasets in prior art, especially when software system complexity increases and security vulnerabilities increase.

Method used

In the automatic file processing scenario, the specified code vulnerability mode is obtained, the vulnerability mode description information and code scenario description information are determined, the code generation prompt words are generated based on this information, the code generation model is used to generate reference vulnerability code, and the target vulnerability code is obtained through code evaluation and processing, and the vulnerability code data set is finally built.

Benefits of technology

It realizes the generation of code that meets the code scenario and has specified vulnerabilities, ensuring the diversity and quality of vulnerable codes and improving the richness of vulnerable code data sets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119322734B_ABST
    Figure CN119322734B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses a data processing method, device, storage medium and electronic device, the method comprising: in a file automatic processing scenario, obtaining a specified code vulnerability pattern for a file automatic processing function code, determining vulnerability pattern description information and code scenario description information for the specified code vulnerability pattern, determining a code generation prompt word based on the vulnerability pattern description information and the code scenario description information, performing code generation processing using a code generation large model based on the code generation prompt word, obtaining a reference vulnerability code, performing code evaluation processing on the reference vulnerability code to obtain a target vulnerability code, and constructing a vulnerability code data set based on the target vulnerability code. Thus, the code generation large model automatically generates code that conforms to the code scenario and has a specified vulnerability according to the vulnerability pattern description information and the code scenario description information, and constructs a vulnerability code data set through the vulnerability code, thereby ensuring the quality and richness of the vulnerability code data set.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a data processing method, device, storage medium and electronic device. Background Art

[0002] In related technologies, vulnerability code datasets are an important resource in the field of information security, which aims to provide examples and related information of known software vulnerabilities. Vulnerability code datasets usually contain different types of vulnerability codes, including buffer overflow, SQL injection, cross-site scripting, etc., to help researchers and developers understand the characteristics and exploitation methods of vulnerabilities. As the complexity of software systems continues to increase, the number of security vulnerabilities is also increasing, so it is particularly important to build a high-quality vulnerability code dataset. Summary of the invention

[0003] The embodiments of the present application provide a data processing method, device, computer storage medium and electronic device. The technical solution is as follows:

[0004] In a first aspect, an embodiment of the present application provides a data processing method, the method comprising:

[0005] In the file automatic processing scenario, obtaining a specified code vulnerability pattern for the file automatic processing function code, and determining vulnerability pattern description information and code scenario description information for the specified code vulnerability pattern;

[0006] Determine a code generation prompt word based on the vulnerability pattern description information and the code scenario description information, and perform code generation processing using a code generation macro model based on the code generation prompt word to obtain a reference vulnerability code;

[0007] Code evaluation is performed on the reference vulnerability code to obtain a target vulnerability code, and a vulnerability code dataset is constructed based on the target vulnerability code.

[0008] In a possible implementation manner, determining the code scenario description information for the specified code vulnerability pattern includes:

[0009] Obtaining a real code database for the specified code vulnerability pattern, performing similar pattern code selection processing based on the real code database to obtain real scenario code fragments, and generating code scenario description information including the real scenario code fragments; or,

[0010] Obtain code scenario type information corresponding to the specified code vulnerability pattern, and generate code scenario description information including the code scenario type information.

[0011] In a possible implementation manner, the performing similar pattern code selection processing based on the real code database to obtain the real scenario code fragment includes:

[0012] Determine the vulnerability code keyword corresponding to the specified code vulnerability pattern, and use the vulnerability code keyword to perform similar pattern code matching processing in the real code database to obtain a real scenario code fragment.

[0013] In a possible implementation manner, the determining vulnerability pattern description information for the specified code vulnerability pattern includes:

[0014] Acquire vulnerability pattern definition information for the designated code vulnerability pattern, and generate vulnerability pattern description information including the vulnerability pattern definition information; or,

[0015] Vulnerability pattern definition information and a synthetic vulnerability code fragment for the designated code vulnerability pattern are obtained, and vulnerability pattern description information including the vulnerability pattern definition information and the synthetic vulnerability code fragment is generated.

[0016] In a possible implementation, the code generation process is performed based on the code generation prompt word using a code generation model to obtain a reference vulnerability code, including:

[0017] Inputting the code generation prompt word into the code generation model, performing code merging processing based on vulnerability pattern definition information, synthetic vulnerability code snippets and real scenario code snippets through the code generation model to obtain a first reference vulnerability code; and / or,

[0018] Inputting the code generation prompt word into a code generation macromodel, generating a first vulnerability code snippet based on vulnerability pattern definition information and a real scenario code snippet through the code generation macromodel, and performing code merging processing based on the first vulnerability code snippet and the real scenario code snippet to obtain a second reference vulnerability code; and / or,

[0019] Inputting the code generation prompt word into the code generation big model, performing vulnerability code generation processing based on vulnerability pattern definition information, synthetic vulnerability code snippets and code scenario type information through the code generation big model to obtain a third reference vulnerability code; and / or,

[0020] The code generation prompt word is input into the code generation big model, and the code generation big model is used to perform vulnerability code generation processing based on vulnerability pattern definition information and code scenario type information to obtain a fourth reference vulnerability code.

[0021] In a possible implementation manner, the performing code evaluation processing on the reference vulnerability code to obtain the target vulnerability code includes:

[0022] Performing similarity calculation on the plurality of reference vulnerability codes to obtain code similarity of at least one vulnerability code pair;

[0023] Based on the code similarity, a similarity threshold is used to perform code deduplication processing on the at least one vulnerability code pair to obtain a candidate vulnerability code;

[0024] Determine a raw code segment from the vulnerability pattern description information and the code scenario description information, and use the raw code segment to perform code consistency verification on the candidate vulnerability code to obtain a code verification result corresponding to the candidate vulnerability code;

[0025] If the code verification result is a verification success type, the candidate vulnerability code corresponding to the code verification result is used as the target vulnerability code;

[0026] If the code verification result is a verification failure type, the candidate vulnerability code corresponding to the code verification result is removed.

[0027] In a possible implementation manner, the using the raw code fragment to perform code consistency verification processing on the candidate vulnerability code to obtain a code verification result corresponding to the candidate vulnerability code includes:

[0028] If the raw code fragment includes a vulnerability code fragment, a first code verification prompt word is generated based on the vulnerability code fragment and the candidate vulnerability code, the first code verification prompt word is input into a code verification macro model, and a code consistency verification process is performed based on the vulnerability code fragment and the candidate vulnerability code by the code verification macro model to obtain a first code verification result corresponding to the candidate vulnerability code;

[0029] If the raw code fragment includes a real-scene code fragment, a second code verification prompt word is generated based on the real-scene code fragment and the candidate vulnerability code, and the second code verification prompt word is input into the code verification big model. The code verification big model is used to perform code consistency verification processing based on the real-scene code fragment and the candidate vulnerability code to obtain a second code verification result corresponding to the candidate vulnerability code.

[0030] In a second aspect, an embodiment of the present application provides a data processing device, the device comprising:

[0031] An information acquisition module, used to acquire a specified code vulnerability pattern for the file automatic processing function code in a file automatic processing scenario, and determine vulnerability pattern description information and code scenario description information for the specified code vulnerability pattern;

[0032] A code generation module, used to determine a code generation prompt word based on the vulnerability pattern description information and the code scenario description information, and perform code generation processing using a code generation macro model based on the code generation prompt word to obtain a reference vulnerability code;

[0033] The code evaluation module is used to perform code evaluation processing on the reference vulnerability code to obtain a target vulnerability code, and to construct a vulnerability code data set based on the target vulnerability code.

[0034] Optionally, the information acquisition module includes:

[0035] A first information generating unit is configured to obtain a real code database for the specified code vulnerability pattern, perform similar pattern code selection processing based on the real code database to obtain a real scenario code fragment, and generate code scenario description information including the real scenario code fragment; or

[0036] The second information generating unit is used to obtain the code scenario type information corresponding to the specified code vulnerability pattern, and generate code scenario description information including the code scenario type information.

[0037] Optionally, the first information generating unit is specifically configured to:

[0038] Determine the vulnerability code keyword corresponding to the specified code vulnerability pattern, and use the vulnerability code keyword to perform similar pattern code matching processing in the real code database to obtain a real scenario code fragment.

[0039] Optionally, the information acquisition module includes:

[0040] A third information generating unit is configured to obtain vulnerability pattern definition information for the designated code vulnerability pattern and generate vulnerability pattern description information including the vulnerability pattern definition information; or

[0041] The fourth information generating unit is used to obtain vulnerability pattern definition information and synthetic vulnerability code fragments for the designated code vulnerability pattern, and generate vulnerability pattern description information including the vulnerability pattern definition information and the synthetic vulnerability code fragment.

[0042] Optionally, the code generation module includes:

[0043] A first code generation unit is configured to input the code generation prompt word into a code generation model, and perform code merging processing based on vulnerability pattern definition information, synthetic vulnerability code snippets, and real scenario code snippets through the code generation model to obtain a first reference vulnerability code; and / or,

[0044] a second code generation unit, configured to input the code generation prompt word into a code generation macromodel, generate a first vulnerability code snippet based on vulnerability pattern definition information and a real scenario code snippet through the code generation macromodel, and perform code merging processing based on the first vulnerability code snippet and the real scenario code snippet to obtain a second reference vulnerability code; and / or,

[0045] A third code generation unit is configured to input the code generation prompt word into a code generation macro model, and perform vulnerability code generation processing based on vulnerability pattern definition information, synthetic vulnerability code snippets, and code scenario type information through the code generation macro model to obtain a third reference vulnerability code; and / or,

[0046] The fourth code generation unit is used to input the code generation prompt word into the code generation model, and perform vulnerability code generation processing based on vulnerability pattern definition information and code scenario type information through the code generation model to obtain a fourth reference vulnerability code.

[0047] Optionally, the code evaluation module is specifically used to:

[0048] A first code evaluation unit is used to perform similarity calculation on the plurality of reference vulnerability codes to obtain code similarity of at least one vulnerability code pair;

[0049] A second code evaluation unit is used to perform code deduplication processing on the at least one vulnerability code pair based on the code similarity and adopt a similarity threshold to obtain a candidate vulnerability code;

[0050] A third code evaluation unit is used to determine a raw code segment from the vulnerability pattern description information and the code scenario description information, and use the raw code segment to perform code consistency verification processing on the candidate vulnerability code to obtain a code verification result corresponding to the candidate vulnerability code;

[0051] a fourth code evaluation unit, configured to use the candidate vulnerability code corresponding to the code verification result as the target vulnerability code if the code verification result is a verification success type;

[0052] The fifth code evaluation unit is used to remove the candidate vulnerability code corresponding to the code verification result if the code verification result is a verification failure type.

[0053] Optionally, the third code evaluation unit is specifically used to:

[0054] If the raw code fragment includes a synthetic vulnerability code fragment, a first code verification prompt word is generated based on the synthetic vulnerability code fragment and the candidate vulnerability code, the first code verification prompt word is input into a code verification macro model, and a code consistency verification process is performed based on the vulnerability code fragment and the candidate vulnerability code by the code verification macro model to obtain a first code verification result corresponding to the candidate vulnerability code;

[0055] If the raw code fragment includes a real-scene code fragment, a second code verification prompt word is generated based on the real-scene code fragment and the candidate vulnerability code, and the second code verification prompt word is input into the code verification big model. The code verification big model is used to perform code consistency verification processing based on the real-scene code fragment and the candidate vulnerability code to obtain a second code verification result corresponding to the candidate vulnerability code.

[0056] In a third aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium has a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the above-mentioned method.

[0057] In a fourth aspect, an embodiment of the present application provides an electronic device, which may include: a memory and a processor; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the memory and executing the above method.

[0058] The beneficial effects brought by the technical solution provided by the embodiment of the present application include at least:

[0059] The data processing method provided by the embodiment of the present application, in the file automatic processing scenario, obtains the specified code vulnerability pattern for the file automatic processing function code, determines the vulnerability pattern description information and code scenario description information for the specified code vulnerability pattern, determines the code generation prompt word based on the vulnerability pattern description information and the code scenario description information, uses the code generation big model to perform code generation processing based on the code generation prompt word, obtains the reference vulnerability code, performs code evaluation processing on the reference vulnerability code to obtain the target vulnerability code, and constructs the vulnerability code data set based on the target vulnerability code. Thus, the code generation big model automatically generates the code that meets the code scenario and has the specified vulnerability according to the vulnerability pattern description information and the code scenario description information, thereby ensuring the diversity of the generated vulnerability code, and constructing the vulnerability code data set after evaluating the vulnerability code, thereby ensuring the quality and richness of the vulnerability code in the vulnerability code data set. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.

[0061] Figure 1 It is a flowchart of a data processing method provided in an embodiment of the present application;

[0062] Figure 2 It is a flowchart of another data processing method provided in an embodiment of the present application;

[0063] Figure 3 is a structural schematic diagram of a data processing device provided in an embodiment of the present application;

[0064] Figure 4 It is a structural diagram of a code evaluation module provided in an embodiment of the present application;

[0065] Figure 5 It is a structural schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0066] In order to make the purpose, features, and advantages of the embodiments of the present application more obvious and understandable, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.

[0067] In the description of the present application, it should be understood that the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance. In the description of the present application, it should be noted that, unless otherwise clearly specified and limited, "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device comprising a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units that are not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood in specific circumstances. In addition, in the description of the present application, unless otherwise specified, "multiple" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the associated objects before and after are a kind of "or" relationship.

[0068] In related technologies, vulnerability code datasets for vulnerability analysis can not only be used for vulnerability detection and repair, but also as a training basis for machine learning models, deep learning models, and large language models to improve the effectiveness of automated security detection tools. By analyzing vulnerability codes, researchers can extract features, identify patterns, and develop more advanced security protection mechanisms. Therefore, how to build a high-quality vulnerability code dataset is a technical problem that needs to be solved urgently.

[0069] In order to solve the above technical problems, the present application is described in detail below in conjunction with specific embodiments.

[0070] In one embodiment, Figure 1 As shown, a data processing method is proposed, which can be implemented by a computer program and can be run on a data processing device based on the von Neumann system. The computer program can be integrated into an application or run as an independent tool application.

[0071] Specifically, the data processing method includes:

[0072] S101, in a file automatic processing scenario, obtaining a specified code vulnerability pattern for a file automatic processing function code, and determining vulnerability pattern description information and code scenario description information for the specified code vulnerability pattern.

[0073] The automatic file processing scenario refers to the automatic file processing scenario based on the Large Language Model (LLM). For example, the automatic file processing scenario can specifically be the automatic file processing scenario in an artificial intelligence office product that relies on the function of processing files using a large language model.

[0074] The file automatic processing function code refers to the program code that can realize the function of automatically processing files.

[0075] The specified code vulnerability mode refers to at least one code vulnerability mode specified in all code vulnerability modes involved in the file automatic processing function code. The code vulnerability modes involved in the file automatic processing function code may include but are not limited to buffer overflow, SQL injection, cross-site scripting, command injection, privilege escalation, information leakage, etc. The specified code vulnerability mode may include one or more of the above-mentioned vulnerability modes.

[0076] Vulnerability pattern description information refers to specific information used to describe a specified code vulnerability pattern. The vulnerability pattern description information may include other information such as the pattern name, cause, and exploitation method of the code vulnerability pattern.

[0077] The code scenario description information refers to specific information used to describe the code scenario to which the specified code vulnerability pattern is applied. The code scenario description information may include at least one of the following information: application environment, user interaction, business logic, workflow, and specific examples.

[0078] In some embodiments, in a file automatic processing scenario, in response to a code vulnerability configuration operation for a file automatic processing function code input by a user, a specified code vulnerability pattern for the file automatic processing function code is obtained from the code vulnerability pattern configuration operation, and then the vulnerability pattern definition information corresponding to the specified code vulnerability pattern is obtained, and vulnerability pattern description information including the vulnerability pattern definition information is generated, or the vulnerability pattern definition information and a synthetic vulnerability code fragment corresponding to the specified code vulnerability pattern information are obtained, and vulnerability pattern description information including the vulnerability pattern definition information and the synthetic vulnerability code fragment is generated, and then a real scenario code fragment is selected from a real code database for the specified code vulnerability pattern, and code scenario description information including the real scenario code fragment is generated, or the code scenario type information corresponding to the specified code vulnerability pattern is obtained, and code scenario description information including the code scenario type information is generated.

[0079] S102, determining a code generation prompt word based on the vulnerability pattern description information and the code scenario description information, and performing code generation processing using a code generation macro model based on the code generation prompt word to obtain a reference vulnerability code.

[0080] The code generation prompt refers to task description information that instructs the code generation model to generate reference vulnerability code based on the vulnerability pattern description information and the code scenario description information.

[0081] Among them, the code generation big model refers to a big language model with strong programming capabilities, which can understand, generate and process code. The programming capabilities of the code generation big model are reflected in the ability to understand the syntax and structure of multiple programming languages ​​(such as Python, Java, JavaScript, etc.), to understand the intent of the code, and to automatically generate corresponding code based on the description of natural language. The code generation big model can be fine-tuned based on the basic programming big model, or the code generation big model can directly use the basic programming big model. The programming big model is a big model with strong programming capabilities.

[0082] The reference vulnerability code refers to the code with a vulnerability, and the type of the vulnerability is the specified code vulnerability mode.

[0083] In some embodiments, a preset prompt word template is obtained, a first prompt feature word including vulnerability pattern description information is generated, a second prompt feature word including code scene description information is generated, and the first prompt feature word and the second prompt feature word are filled in the preset prompt word template to obtain a code generation prompt word. Further, the code generation prompt word is input into a code generation big model, and a reference vulnerability code is generated by the code generation big model according to the vulnerability pattern definition information in the vulnerability pattern description information and the real scene code snippet in the code scene description information, and / or, a reference vulnerability code is generated by the code generation big model according to the vulnerability pattern definition information in the vulnerability pattern description information, the synthetic vulnerability code snippet, and the real scene code snippet in the code scene description information, and / or, a reference vulnerability code is generated by the code generation big model according to the vulnerability pattern definition information in the vulnerability pattern description information and the code scene type information in the code scene description information, and / or, a reference vulnerability code is generated by the code generation big model according to the vulnerability pattern definition information in the vulnerability pattern description information, the synthetic vulnerability code snippet, and the code scene type information in the code scene description information.

[0084] S103, performing code evaluation processing on the reference vulnerability code to obtain a target vulnerability code, and constructing a vulnerability code dataset based on the target vulnerability code.

[0085] In some embodiments, code verification prompt words can be generated based on reference vulnerability codes and raw code snippets, wherein the raw code snippets can include at least one of the synthetic vulnerability code snippets in the vulnerability pattern description information and the real scenario code snippets in the code scenario description information, and the code verification prompt words are input into the code verification big model, and the code consistency verification process is performed on the reference vulnerability code and the raw code snippet through the code verification big model. If the consistency check between the reference vulnerability code and the raw code snippet passes, the reference vulnerability code is used as the target vulnerability code, and if the consistency check between the reference vulnerability code and the raw code snippet fails, the reference vulnerability code is removed. Furthermore, a corresponding relationship between the target vulnerability code and the vulnerability pattern definition information corresponding to the target vulnerability code is established, and a vulnerability code data set is generated, and the vulnerability code data set includes all target vulnerability codes and the vulnerability pattern definition information corresponding to each target vulnerability code.

[0086] The data processing method provided by the embodiment of the present application, in the file automatic processing scenario, obtains the specified code vulnerability pattern for the file automatic processing function code, determines the vulnerability pattern description information and code scenario description information for the specified code vulnerability pattern, determines the code generation prompt word based on the vulnerability pattern description information and the code scenario description information, uses the code generation big model to perform code generation processing based on the code generation prompt word, obtains the reference vulnerability code, performs code evaluation processing on the reference vulnerability code to obtain the target vulnerability code, and constructs the vulnerability code data set based on the target vulnerability code. Thus, the code generation big model automatically generates the code that meets the code scenario and has the specified vulnerability according to the vulnerability pattern description information and the code scenario description information, thereby ensuring the diversity of the generated vulnerability code, and constructing the vulnerability code data set after evaluating the vulnerability code, thereby ensuring the quality and richness of the vulnerability code in the vulnerability code data set.

[0087] See also Figure 2 , Figure 2 It is a flowchart of another embodiment of a data processing method proposed in this application.

[0088] Specifically, the data processing method includes:

[0089] S201, in a file automatic processing scenario, obtaining a specified code vulnerability pattern for a file automatic processing function code.

[0090] Specifically, see Figure 1 The description of the relevant parts in the illustrated embodiment will not be repeated here.

[0091] S202, obtaining vulnerability pattern definition information for a designated code vulnerability pattern, and generating vulnerability pattern description information including the vulnerability pattern definition information.

[0092] In some embodiments, after determining the specified code vulnerability pattern, vulnerability pattern definition information for the specified code vulnerability pattern can be obtained from the security database, and then vulnerability pattern description information including the vulnerability pattern definition information is generated. Specifically, the vulnerability pattern definition information may include the vulnerability pattern name, the cause of the vulnerability, the vulnerability exploitation method, etc., wherein the vulnerability pattern name may be a common vulnerability name, and the vulnerability exploitation method may be used to summarize how the attacker exploits the vulnerability. Through the vulnerability pattern definition information, the specified code vulnerability pattern can be quickly understood.

[0093] Optionally, the security database may be a dedicated vulnerability database such as the National Vulnerability Database (NVD) of the United States, Common Vulnerabilities and Exposures (CVE), etc.

[0094] In parallel with S203 , vulnerability pattern definition information and synthetic vulnerability code snippets for the designated code vulnerability pattern are obtained, and vulnerability pattern description information including the vulnerability pattern definition information and the synthetic vulnerability code snippets is generated.

[0095] Among them, synthetic vulnerability code snippets refer to manually constructed or automatically generated code snippets used to simulate known code vulnerabilities. Synthetic vulnerability code snippets can be generated through specific methods and rules. Synthetic vulnerability code snippets are designed to demonstrate specific vulnerability characteristics (synthetic vulnerability codes lack the complexity and diversity of real projects).

[0096] In some embodiments, after determining the specified code vulnerability pattern, vulnerability pattern definition information for the specified code vulnerability pattern can be obtained from the security database, and synthetic vulnerability code snippets for the specified code vulnerability pattern can be found from the open source project or sample code library, or, a synthetic vulnerability code snippet for the specified code vulnerability pattern can be generated using a vulnerability generation tool, and then, vulnerability pattern description information including vulnerability pattern definition information and synthetic vulnerability code snippets is generated. Among them, the description of the vulnerability pattern definition information can refer to the interpretation in step S202. Through the vulnerability pattern definition information and the exemplary synthetic vulnerability code snippet, the specified code vulnerability pattern and its utilization method can be quickly understood.

[0097] It should be noted that in the data processing method provided in the embodiment of the present application, after executing step S201, you can choose to execute any one of step S202 and step S203 to generate vulnerability pattern description information.

[0098] S204, obtaining a real code database for a specified code vulnerability pattern, performing similar pattern code selection processing based on the real code database to obtain real scenario code snippets, and generating code scenario description information including the real scenario code snippets.

[0099] The real code database refers to a database used to store real code snippets extracted from real development environments. Real-scenario code snippets are code snippets that exist in real project scenarios and meet specified vulnerability requirements. Specified vulnerability requirements refer to requirements that may cause vulnerabilities in specified code vulnerability patterns. Specified vulnerability requirements may include specific conditions corresponding to specified code vulnerability patterns, contextual conditions for the occurrence of specified code vulnerability patterns, attack paths for specified code vulnerability patterns, and so on.

[0100] For example, taking SQL injection as an example, some real codes involving database operations may have the risk of SQL injection, which means that these real codes involving database operations are codes that meet the requirements of SQL injection. Then, these real codes involving database operations can be used as real-scenario code snippets.

[0101] In some embodiments, the real code database can be created in advance by developers based on codes in various real development environments. The real code database can include code snippets that meet different specified vulnerability requirements. Different specified vulnerability requirements are requirements for vulnerabilities that may cause different code vulnerability patterns. The association relationship between the real code database and these code vulnerability patterns can also be established in advance. Therefore, when executing this step, a real code database that has an association relationship with the specified code vulnerability pattern can be obtained.

[0102] Furthermore, based on the real code database, similar pattern code selection is performed to obtain real scenario code fragments. The implementation of this step can be: A2: determine the vulnerability code keyword corresponding to the specified code vulnerability pattern; A4: use the vulnerability code keyword in the real code database to perform similar pattern code matching processing to obtain real scenario code fragments.

[0103] In step A2, feature analysis is performed on the vulnerability code with the specified code vulnerability pattern to determine the vulnerability code keyword corresponding to the specified code vulnerability pattern, wherein the vulnerability code keyword refers to the keyword in the code used to characterize the specified vulnerability requirement, and the specified vulnerability requirement is the requirement that may trigger the vulnerability of the specified code vulnerability pattern.

[0104] In step A4, a first real-scenario code snippet with a vulnerability code keyword is matched in a real code database, a specified vulnerability requirement verification process is performed on the first real-scenario code snippet, and the first real-scenario code snippet that meets the specified vulnerability requirement is selected as the real-scenario code snippet, wherein the specified vulnerability requirement is a requirement for a code that may trigger a specified code vulnerability pattern.

[0105] In parallel with S205, code scenario type information corresponding to the specified code vulnerability pattern is obtained, and code scenario description information including the code scenario type information is generated.

[0106] Among them, code scenario type information refers to information used to limit the type of code application scenario. Code scenario type information may include but is not limited to application environment, user interaction, business logic or workflow; application environment refers to the specific application environment where the specified code vulnerability pattern may occur, such as Web applications, mobile applications, embedded systems, etc.; user interaction is used to describe how users interact with the system and under what circumstances attackers may exploit the specified code vulnerability pattern, such as user input, file upload, etc.; business logic or workflow is used to describe the links that may expose vulnerabilities of the specified code vulnerability pattern.

[0107] In some embodiments, a code scenario configuration operation input by a user can be obtained, and code scenario type information corresponding to a specified code vulnerability mode can be obtained from the code scenario configuration operation, wherein the user refers to a project-related person in a file automatic processing scenario. Specifically, when a user inputs a code scenario configuration operation, the code scenario of the specified code vulnerability mode can be configured from the aspects of application environment, user interaction, business logic, or workflow, and thus code scenario type information including application environment, user interaction, business logic, or workflow can be obtained from the code configuration operation.

[0108] It should be noted that in the data processing method provided in the embodiment of the present application, after executing step S202 or S203, you can choose to execute any one of step S204 and step S205 to generate code scenario description information.

[0109] S206, determining a code generation prompt word based on the vulnerability pattern description information and the code scenario description information, and performing code generation processing using a code generation macro model based on the code generation prompt word to obtain a reference vulnerability code.

[0110] In some embodiments, a preset prompt word template is obtained, a first prompt feature word including vulnerability pattern description information is generated, a second prompt feature word including code scenario description information is generated, the first prompt feature word and the second prompt feature word are filled in the preset prompt word template to obtain a code generation prompt word.

[0111] Further, the code generation prompt word is input into the code generation big model, and the code generation big model performs code merging processing based on the vulnerability pattern definition information, the synthetic vulnerability code snippet and the real scenario code snippet to obtain a first reference vulnerability code; and / or,

[0112] Inputting the code generation prompt word into the code generation big model, generating a first vulnerability code snippet based on the vulnerability pattern definition information and the real scenario code snippet through the code generation big model, and performing code merging processing based on the first vulnerability code snippet and the real scenario code snippet to obtain a second reference vulnerability code; and / or,

[0113] Inputting the code generation prompt word into the code generation big model, performing vulnerability code generation processing based on the vulnerability pattern definition information, the synthetic vulnerability code snippet and the code scenario type information through the code generation big model, and obtaining a third reference vulnerability code; and / or,

[0114] The code generation prompt word is input into the code generation big model, and the code generation big model performs vulnerability code generation processing based on the vulnerability pattern definition information and the code scenario type information to obtain the fourth reference vulnerability code.

[0115] It is understandable that if the vulnerability pattern description information includes vulnerability pattern definition information and synthetic vulnerability code snippets, and the code scenario description information includes real scenario code snippets, the code generation model combines the vulnerability pattern definition information and the synthetic vulnerability code snippet to determine the code to be modified in the real scenario code snippet, and modifies the code to be modified to the target vulnerability code in the real scenario code snippet to obtain the first reference vulnerability code. Among them, the target vulnerability code includes a code statement with a vulnerability, and the type of the vulnerability is a specified code vulnerability pattern. Among them, the target vulnerability code can directly use the corresponding code in the synthetic vulnerability code snippet, and the target vulnerability code can also be a code obtained after corresponding adjustments based on the synthetic vulnerability code snippet.

[0116] If the vulnerability pattern description information includes vulnerability pattern definition information, and the code scenario description information includes a real scenario code snippet, the code generation model generates a first vulnerability code snippet based on the vulnerability pattern definition information and the real scenario code snippet, determines the code to be modified in the real scenario code snippet, and replaces the code to be modified with the first vulnerability code snippet in the real scenario code snippet to obtain a second reference vulnerability code, wherein the first vulnerability code snippet includes a code statement with a vulnerability, and the type of the vulnerability is a specified code vulnerability pattern.

[0117] If the vulnerability pattern description information includes vulnerability pattern definition information and synthetic vulnerability code snippets, and the code scenario description information includes code scenario type information, then the code generation model generates a third reference vulnerability code for the code scenario that conforms to the code scenario type information according to the vulnerability pattern definition information and the synthetic vulnerability code snippet, wherein the third reference vulnerability code includes a code statement with a vulnerability, the type of the vulnerability is a specified code vulnerability pattern, the code statement with a vulnerability may be a code obtained after corresponding adjustments are made to the synthetic vulnerability code snippet, and the code statement with a vulnerability may also be a code statement imitated by referring to the synthetic vulnerability code snippet.

[0118] If the vulnerability pattern description information includes vulnerability pattern definition information, and the code scenario description information includes code scenario type information, the code generation model determines the vulnerability code template corresponding to the vulnerability pattern definition information, determines the code parameters in the vulnerability code template according to the code scenario type, determines the context environment code of the vulnerability code template, and performs code splicing processing on the vulnerability code template, the code parameters, and the context environment code to obtain a fourth reference vulnerability code, wherein the fourth reference vulnerability code is a code that conforms to the code scenario indicated by the code scenario type information, and the fourth reference vulnerability code includes a code statement with a vulnerability, and the type of the vulnerability is a specified code vulnerability pattern.

[0119] Therefore, the code generation model can generate vulnerability code snippets that have specified vulnerabilities, conform to specified code scenarios, and conform to real-world code styles based on vulnerability pattern description information and code generation scenario description information. Therefore, a variety of complex vulnerability code snippets can be generated through the code generation model.

[0120] S207, performing code evaluation processing on the reference vulnerability code to obtain a target vulnerability code, and constructing a vulnerability code dataset based on the target vulnerability code.

[0121] In some embodiments, the step of performing code evaluation processing on a reference vulnerability code to obtain a target vulnerability code may specifically include: B2: performing similarity calculation on multiple reference vulnerability codes to obtain code similarity of at least one vulnerability code pair; B4: performing code deduplication processing on at least one vulnerability code pair based on code similarity using a similarity threshold to obtain a candidate vulnerability code; B6: determining a raw code fragment in the vulnerability pattern description information and the code scenario description information, and performing code consistency verification processing on the candidate vulnerability code using the raw code fragment to obtain a code verification result corresponding to the candidate vulnerability code; B8: if the code verification result is a verification success type, the candidate vulnerability code corresponding to the code verification result is used as the target vulnerability code; B10: if the code verification result is a verification failure type, the candidate vulnerability code corresponding to the code verification result is removed.

[0122] In step B2, similarity calculation can be performed on any two reference vulnerability codes to obtain code similarity of at least one vulnerability code pair (composed of any two reference vulnerability codes). Optionally, the code similarity of at least one vulnerability code pair can be calculated using the Levenshtein distance.

[0123] In step B4, when the Levenshtein distance is used to represent the code similarity, the similarity threshold is represented by a preset Levenshtein distance threshold. The preset Levenshtein distance threshold can be set according to the code length. A longer code segment needs to set a larger distance threshold, and a shorter code segment needs to set a smaller distance threshold. When the Levenshtein distance between a vulnerability code pair is less than the preset Levenshtein distance threshold, it means that the two reference vulnerability codes in the vulnerability code pair are similar codes, and any one of the codes in the vulnerability code pair needs to be removed. After removing the duplicate codes in all reference vulnerability codes, a candidate vulnerability code is obtained.

[0124] In step B6, when the vulnerability pattern description information includes synthetic vulnerability code snippets and the code scenario description information includes real scenario code snippets, the raw code snippets include synthetic vulnerability code snippets and real scenario code snippets; when the vulnerability pattern description information does not include synthetic vulnerability code snippets and the code scenario description information includes real scenario code snippets, the raw code snippets include real scenario code snippets; when the vulnerability pattern description information includes synthetic vulnerability code snippets and the code scenario description information includes code scenario description information, the raw code snippets include synthetic vulnerability code snippets.

[0125] In step B6, the step of performing code consistency verification processing on the candidate vulnerability code using the raw code fragment to obtain the code verification result corresponding to the candidate vulnerability code may specifically include:

[0126] b2: if the raw code fragment includes a synthetic vulnerability code fragment, a first code verification prompt word is generated based on the synthetic vulnerability code fragment and the candidate vulnerability code, the first code verification prompt word is input into the code verification big model, and the code verification big model performs code consistency verification processing based on the synthetic vulnerability code fragment and the candidate vulnerability code to obtain a first code verification result corresponding to the candidate vulnerability code;

[0127] b4: If the raw code fragment includes a real-scene code fragment, a second code verification prompt word is generated based on the real-scene code fragment and the candidate vulnerability code, and the second code verification prompt word is input into the code verification large model. The code verification large model is used to perform code consistency verification processing based on the real-scene code fragment and the candidate vulnerability code to obtain a second code verification result corresponding to the candidate vulnerability code.

[0128] Among them, the code verification big model can adopt the above-mentioned code generation big model, and can also adopt a big language model that is different from the code generation big model and has strong programming capabilities.

[0129] In step b2, a first preset code verification prompt template is obtained, and the synthetic vulnerability code fragment and the candidate vulnerability code are filled in the first preset code verification prompt template to obtain a first code verification prompt word, where the first code verification prompt word is task description information for indicating that the code verification big model verifies the consistency between the synthetic vulnerability code fragment and the candidate vulnerability code. The code verification big model analyzes whether the code structure and code behavior of the synthetic vulnerability code fragment appear in the candidate vulnerability code. If the code verification big model analyzes the code structure and code behavior of the synthetic vulnerability code fragment in the candidate vulnerability code, a first code verification result of a verification success type is generated. If the code verification big model analyzes the code result and / or code behavior of the synthetic vulnerability code in the candidate vulnerability code, a first code verification result of a verification failure type is generated.

[0130] In step b4, a second preset code verification prompt template is obtained, and the real scenario code snippet and the candidate vulnerability code are filled in the second preset code verification prompt template to obtain a second code verification prompt word, where the second code verification prompt word is task description information for indicating that the code verification large model verifies the consistency between the real scenario code snippet and the candidate vulnerability code. The code verification large model analyzes whether the code structure and code behavior of the real scenario code snippet appear in the candidate vulnerability code, and analyzes whether the non-real scenario code snippet in the candidate vulnerability code and the real scenario code snippet in the candidate vulnerability code have data flow consistency and code style consistency. If the code verification large model analyzes the code structure and code behavior of the real scenario code snippet in the candidate vulnerability code, and analyzes whether the non-real scenario code snippet in the candidate vulnerability code and the real scenario code snippet in the candidate vulnerability code have data flow consistency and code style consistency, then a second code verification result of a verification success type is generated; otherwise, the code verification large model generates a second code verification result of a verification failure type.

[0131] In step B8, if both the first code verification result and the second code verification result are verification success types, the code verification result is determined to be a verification success type, and the candidate vulnerability code corresponding to the code verification result is used as the target vulnerability code.

[0132] In step B10, if the first code verification result is a verification failure type, and / or the second code verification result is a verification failure type, the code verification result is determined to be a verification failure type, and the candidate vulnerability code corresponding to the code verification result is removed.

[0133] Furthermore, in S207, a step of constructing a vulnerability code dataset based on the target vulnerability code is performed, which can specifically be: establishing a correspondence between the target vulnerability code and the vulnerability pattern definition information corresponding to the target vulnerability code, generating a vulnerability code dataset, and the vulnerability code dataset includes all target vulnerability codes and the vulnerability pattern definition information corresponding to each target vulnerability code.

[0134] In the data processing method provided in the embodiment of the present application, in the file automatic processing scenario, a specified code vulnerability pattern for the file automatic processing function code is obtained, vulnerability pattern definition information for the specified code vulnerability pattern is obtained, and vulnerability pattern description information including the vulnerability pattern definition information is generated, or vulnerability pattern definition information and a synthetic vulnerability code fragment for the specified code vulnerability pattern are obtained, and vulnerability pattern description information including the vulnerability pattern definition information and the synthetic vulnerability code fragment is generated. Thus, a variety of methods for generating vulnerability pattern description information are provided, and the generated vulnerability pattern description information can help the code generation large model to quickly understand the specified code vulnerability pattern; thereafter, a real code database for the specified code vulnerability pattern is obtained, and similar pattern code selection processing is performed based on the real code database to obtain a real scenario code fragment, and code scenario description information including the real scenario code fragment is generated, or code scenario type information corresponding to the specified code vulnerability pattern is obtained. , generate code scenario description information including code scenario type information, thereby providing a variety of ways to generate code scenario description information, and the generated code scenario description information helps the code generation big model to understand the code application scenario; then, determine the code generation prompt words based on the vulnerability pattern description information and the code scenario description information, and use the code generation big model to perform code generation processing based on the code generation prompt words to obtain reference vulnerability code, perform code evaluation processing on the reference vulnerability code to obtain target vulnerability code, and build a vulnerability code data set based on the target vulnerability code. Therefore, the code generation big model is used to automatically generate vulnerability code according to the vulnerability pattern description information and the code scenario description information, which can ensure the generation of diverse vulnerability codes that meet the code application scenarios, and also evaluate the generated vulnerability code to ensure the consistency between the target vulnerability code and the raw material code used, thereby improving the richness and code quality of the vulnerability code in the code vulnerability data set.

[0135] The following will be combined Figure 3 , the data processing device provided in the embodiment of the present application is introduced in detail. It should be noted that, Figure 3 The data processing device shown is used to execute the application Figure 1~Figure 2 For the convenience of explanation, only the part related to the embodiment of the present application is shown. For the specific technical details not disclosed, please refer to the present application. Figure 1~Figure 2 The embodiment shown.

[0136] See also Figure 3 , which shows a schematic diagram of the structure of the data processing device of an embodiment of the present application. The data processing device 1 can be implemented as all or part of the device through software, hardware or a combination of both. According to some embodiments, the data processing device 1 includes an information acquisition module 11, a code generation module 12, and a code evaluation module 13, which are specifically used to:

[0137] The information acquisition module 11 is used to acquire a specified code vulnerability pattern for the file automatic processing function code in the file automatic processing scenario, and determine vulnerability pattern description information and code scenario description information for the specified code vulnerability pattern;

[0138] A code generation module 12, configured to determine a code generation prompt word based on the vulnerability pattern description information and the code scenario description information, and perform code generation processing using a code generation macro model based on the code generation prompt word to obtain a reference vulnerability code;

[0139] The code evaluation module 13 is used to perform code evaluation processing on the reference vulnerability code to obtain a target vulnerability code, and to construct a vulnerability code data set based on the target vulnerability code.

[0140] Optionally, the information acquisition module 11 includes:

[0141] A first information generating unit is configured to obtain a real code database for the specified code vulnerability pattern, perform similar pattern code selection processing based on the real code database to obtain a real scenario code fragment, and generate code scenario description information including the real scenario code fragment; or

[0142] The second information generating unit is used to obtain the code scenario type information corresponding to the specified code vulnerability pattern, and generate code scenario description information including the code scenario type information.

[0143] Optionally, the first information generating unit is specifically configured to:

[0144] Determine the vulnerability code keyword corresponding to the specified code vulnerability pattern, and use the vulnerability code keyword to perform similar pattern code matching processing in the real code database to obtain a real scenario code fragment.

[0145] Optionally, the information acquisition module 11 includes:

[0146] A third information generating unit is configured to obtain vulnerability pattern definition information for the designated code vulnerability pattern and generate vulnerability pattern description information including the vulnerability pattern definition information; or

[0147] The fourth information generating unit is used to obtain vulnerability pattern definition information and synthetic vulnerability code fragments for the designated code vulnerability pattern, and generate vulnerability pattern description information including the vulnerability pattern definition information and the synthetic vulnerability code fragment.

[0148] Optionally, the code generation module 12 includes:

[0149] A first code generation unit is configured to input the code generation prompt word into a code generation model, and perform code merging processing based on vulnerability pattern definition information, synthetic vulnerability code snippets, and real scenario code snippets through the code generation model to obtain a first reference vulnerability code; and / or,

[0150] a second code generation unit, configured to input the code generation prompt word into a code generation macromodel, generate a first vulnerability code snippet based on vulnerability pattern definition information and a real scenario code snippet through the code generation macromodel, and perform code merging processing based on the first vulnerability code snippet and the real scenario code snippet to obtain a second reference vulnerability code; and / or,

[0151] A third code generation unit is configured to input the code generation prompt word into a code generation macro model, and perform vulnerability code generation processing based on vulnerability pattern definition information, synthetic vulnerability code snippets, and code scenario type information through the code generation macro model to obtain a third reference vulnerability code; and / or,

[0152] The fourth code generation unit is used to input the code generation prompt word into the code generation model, and perform vulnerability code generation processing based on vulnerability pattern definition information and code scenario type information through the code generation model to obtain a fourth reference vulnerability code.

[0153] Optionally, see Figure 4 , is a schematic diagram of the structure of a code evaluation module 13 provided in an embodiment of the present application. The code evaluation module 13 may include a first code evaluation unit 131, a second code evaluation unit 132, a third code evaluation unit 133, a fourth code evaluation unit 134, and a fifth code evaluation unit 135, which are specifically used for:

[0154] A first code evaluation unit 131 is used to perform similarity calculation on the plurality of reference vulnerability codes to obtain code similarity of at least one vulnerability code pair;

[0155] A second code evaluation unit 132 is configured to perform code deduplication processing on the at least one vulnerability code pair based on the code similarity and adopt a similarity threshold to obtain a candidate vulnerability code;

[0156] The third code evaluation unit 133 is used to determine a raw code segment from the vulnerability pattern description information and the code scenario description information, and use the raw code segment to perform code consistency verification on the candidate vulnerability code to obtain a code verification result corresponding to the candidate vulnerability code;

[0157] The fourth code evaluation unit 134 is used to use the candidate vulnerability code corresponding to the code verification result as the target vulnerability code if the code verification result is a verification success type;

[0158] The fifth code evaluation unit 135 is configured to remove the candidate vulnerability code corresponding to the code verification result if the code verification result is a verification failure type.

[0159] Optionally, the third code evaluation unit 133 is specifically used for:

[0160] If the raw code fragment includes a synthetic vulnerability code fragment, a first code verification prompt word is generated based on the synthetic vulnerability code fragment and the candidate vulnerability code, the first code verification prompt word is input into a code verification macro model, and a code consistency verification process is performed based on the vulnerability code fragment and the candidate vulnerability code by the code verification macro model to obtain a first code verification result corresponding to the candidate vulnerability code;

[0161] If the raw code fragment includes a real-scene code fragment, a second code verification prompt word is generated based on the real-scene code fragment and the candidate vulnerability code, and the second code verification prompt word is input into the code verification big model. The code verification big model is used to perform code consistency verification processing based on the real-scene code fragment and the candidate vulnerability code to obtain a second code verification result corresponding to the candidate vulnerability code.

[0162] The data processing device provided by the embodiment of the present application obtains the specified code vulnerability pattern for the file automatic processing function code in the file automatic processing scenario, determines the vulnerability pattern description information and code scenario description information for the specified code vulnerability pattern, determines the code generation prompt word based on the vulnerability pattern description information and the code scenario description information, uses the code generation big model to perform code generation processing based on the code generation prompt word, obtains the reference vulnerability code, performs code evaluation processing on the reference vulnerability code to obtain the target vulnerability code, and constructs the vulnerability code data set based on the target vulnerability code. Thus, the code generation big model automatically generates the code that meets the code scenario and has the specified vulnerability according to the vulnerability pattern description information and the code scenario description information, thereby ensuring the diversity of the generated vulnerability code, and constructing the vulnerability code data set after evaluating the vulnerability code, thereby ensuring the quality and richness of the vulnerability code in the vulnerability code data set.

[0163] Please refer to Figure 5 , Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Exemplarily, the electronic device in the embodiment of the present application may be a server, and the electronic device may include one or more of the following components: a processor 110, a memory 120, an input device 130, an output device 140, and a bus 150. The processor 110, the memory 120, the input device 130, and the output device 140 may be connected via the bus 150.

[0164] The processor 110 may include one or more processing cores. The processor 110 uses various interfaces and lines to connect various parts of the entire electronic device, and executes various functions of the electronic device and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory 120, and calling data stored in the memory 120. Optionally, the processor 110 can be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), and programmable logic array (PLA). The processor 110 can integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. Among them, the CPU mainly processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing display content; and the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 110, but may be implemented separately through a communication chip.

[0165] The memory 120 may include a random access memory (RAM) or a read-only memory (ROM). Optionally, the memory 120 includes a non-transitory computer-readable storage medium. The memory 120 may be used to store instructions, programs, codes, code sets or instruction sets. The memory 120 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the following various method embodiments, etc. The operating system may be an Android system, including a system deeply developed based on the Android system, an iOS system developed by Apple, including a system deeply developed based on the iOS system, or other systems.

[0166] In order for the operating system to distinguish the specific application scenarios of third-party applications, it is necessary to open up data communication between third-party applications and the operating system so that the operating system can obtain the current scenario information of third-party applications at any time, and then perform targeted system resource adaptation based on the current scenario.

[0167] The input device 130 is used to receive input commands or data, and includes but is not limited to a keyboard, a mouse, a camera, a microphone, or a touch device. The output device 140 is used to output commands or data, and includes but is not limited to a display device and a speaker. In one example, the input device 130 and the output device 140 can be combined, and the input device 130 and the output device 140 are touch screen displays.

[0168] The touch display screen can be designed as a full screen, a curved screen or a special-shaped screen. The touch display screen can also be designed as a combination of a full screen and a curved screen, or a combination of a special-shaped screen and a curved screen, which is not limited in the embodiments of the present application.

[0169] In addition, those skilled in the art can understand that the structure of the electronic device shown in the above drawings does not constitute a limitation on the electronic device, and the electronic device may include more or fewer components than shown in the drawings, or combine certain components, or arrange the components differently. For example, the electronic device also includes radio frequency circuits, input units, sensors, audio circuits, wireless fidelity (WiFi) modules, power supplies, Bluetooth modules and other components, which will not be described in detail here.

[0170] exist Figure 5In the electronic device shown, the processor 110 can be used to call the program of the data processing method stored in the memory 120, and specifically perform the following operations:

[0171] In the file automatic processing scenario, obtaining a specified code vulnerability pattern for the file automatic processing function code, and determining vulnerability pattern description information and code scenario description information for the specified code vulnerability pattern;

[0172] Determine a code generation prompt word based on the vulnerability pattern description information and the code scenario description information, and perform code generation processing using a code generation macro model based on the code generation prompt word to obtain a reference vulnerability code;

[0173] Code evaluation is performed on the reference vulnerability code to obtain a target vulnerability code, and a vulnerability code dataset is constructed based on the target vulnerability code.

[0174] In some embodiments, when the processor 110 executes the step of determining the code scenario description information for the specified code vulnerability pattern, the processor 110 specifically performs the following operations:

[0175] Obtaining a real code database for the specified code vulnerability pattern, performing similar pattern code selection processing based on the real code database to obtain real scenario code fragments, and generating code scenario description information including the real scenario code fragments; or,

[0176] Obtain code scenario type information corresponding to the specified code vulnerability pattern, and generate code scenario description information including the code scenario type information.

[0177] In some embodiments, when the processor 110 performs the step of performing similar pattern code selection processing based on the real code database to obtain the real scene code fragment, the following operations are specifically performed:

[0178] Determine the vulnerability code keyword corresponding to the specified code vulnerability pattern, and use the vulnerability code keyword to perform similar pattern code matching processing in the real code database to obtain a real scenario code fragment.

[0179] In one embodiment, when the processor 110 executes the step of determining the vulnerability pattern description information for the specified code vulnerability pattern, the processor 110 specifically performs the following operations:

[0180] Acquire vulnerability pattern definition information for the designated code vulnerability pattern, and generate vulnerability pattern description information including the vulnerability pattern definition information; or,

[0181] Vulnerability pattern definition information and a synthetic vulnerability code fragment for the designated code vulnerability pattern are obtained, and vulnerability pattern description information including the vulnerability pattern definition information and the synthetic vulnerability code fragment is generated.

[0182] In some embodiments, when the processor 110 performs the step of performing code generation processing based on the code generation prompt word using the code generation large model to obtain the reference vulnerability code, the processor 110 specifically performs the following operations:

[0183] Inputting the code generation prompt word into the code generation model, performing code merging processing based on vulnerability pattern definition information, synthetic vulnerability code snippets and real scenario code snippets through the code generation model to obtain a first reference vulnerability code; and / or,

[0184] Inputting the code generation prompt word into the code generation big model, generating a first vulnerability code snippet based on the vulnerability pattern definition information and the real scenario code snippet through the code generation big model, and performing code merging processing based on the first vulnerability code snippet and the real scenario code snippet to obtain a second reference vulnerability code; and / or,

[0185] Inputting the code generation prompt word into the code generation big model, performing vulnerability code generation processing based on vulnerability pattern definition information, synthetic vulnerability code snippets and code scenario type information through the code generation big model to obtain a third reference vulnerability code; and / or,

[0186] The code generation prompt word is input into the code generation big model, and the code generation big model is used to perform vulnerability code generation processing based on vulnerability pattern definition information and code scenario type information to obtain a fourth reference vulnerability code.

[0187] In some embodiments, when the processor 110 performs the step of performing code evaluation processing on the reference vulnerability code to obtain the target vulnerability code, the following operations are specifically performed:

[0188] Performing similarity calculation on the plurality of reference vulnerability codes to obtain code similarity of at least one vulnerability code pair;

[0189] Based on the code similarity, a similarity threshold is used to perform code deduplication processing on the at least one vulnerability code pair to obtain a candidate vulnerability code;

[0190] Determine a raw code segment from the vulnerability pattern description information and the code scenario description information, and use the raw code segment to perform code consistency verification on the candidate vulnerability code to obtain a code verification result corresponding to the candidate vulnerability code;

[0191] If the code verification result is a verification success type, the candidate vulnerability code corresponding to the code verification result is used as the target vulnerability code;

[0192] If the code verification result is a verification failure type, the candidate vulnerability code corresponding to the code verification result is removed.

[0193] In some embodiments, when the processor 110 executes the step of performing code consistency verification processing on the candidate vulnerability code using the raw code fragment to obtain a code verification result corresponding to the candidate vulnerability code, the following operations are specifically performed:

[0194] If the raw code fragment includes a synthetic vulnerability code fragment, a first code verification prompt word is generated based on the synthetic vulnerability code fragment and the candidate vulnerability code, the first code verification prompt word is input into a code verification macro model, and a code consistency verification process is performed based on the vulnerability code fragment and the candidate vulnerability code by the code verification macro model to obtain a first code verification result corresponding to the candidate vulnerability code;

[0195] If the raw code fragment includes a real-scene code fragment, a second code verification prompt word is generated based on the real-scene code fragment and the candidate vulnerability code, and the second code verification prompt word is input into the code verification big model. The code verification big model is used to perform code consistency verification processing based on the real-scene code fragment and the candidate vulnerability code to obtain a second code verification result corresponding to the candidate vulnerability code.

[0196] An embodiment of the present application further provides a computer-readable storage medium, which stores at least one instruction, and the at least one instruction is used to be executed by a processor to implement the data processing method described in the above embodiments.

[0197] An embodiment of the present application further provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the data processing method described in the above embodiments.

[0198] Those skilled in the art should be aware that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented with hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein the communication media include any media that facilitates the transmission of a computer program from one place to another. The storage medium can be any available medium that a general or special-purpose computer can access.

[0199] The above description is only an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A data processing method, characterized in that: The method comprises: In the file automatic processing scenario, obtaining a specified code vulnerability pattern for the file automatic processing function code, and determining vulnerability pattern description information and code scenario description information for the specified code vulnerability pattern; Determine a code generation prompt word based on the vulnerability pattern description information and the code scenario description information, and perform code generation processing using a code generation macro model based on the code generation prompt word to obtain a reference vulnerability code; Performing code evaluation processing on the reference vulnerability code to obtain a target vulnerability code, and constructing a vulnerability code dataset based on the target vulnerability code; Wherein, the determining of the vulnerability pattern description information for the specified code vulnerability pattern includes: obtaining the vulnerability pattern definition information for the specified code vulnerability pattern, and generating the vulnerability pattern description information including the vulnerability pattern definition information; or, obtaining the vulnerability pattern definition information and the synthetic vulnerability code fragment for the specified code vulnerability pattern, and generating the vulnerability pattern description information including the vulnerability pattern definition information and the synthetic vulnerability code fragment; The determining of the code scenario description information for the specified code vulnerability pattern includes: obtaining a real code database for the specified code vulnerability pattern, performing similar pattern code selection processing based on the real code database to obtain a real scenario code fragment, and generating code scenario description information including the real scenario code fragment; or obtaining code scenario type information corresponding to the specified code vulnerability pattern, and generating code scenario description information including the code scenario type information; The code evaluation processing of the reference vulnerability code to obtain the target vulnerability code includes: performing similarity calculation on multiple reference vulnerability codes to obtain the code similarity of at least one vulnerability code pair; performing code deduplication processing on the at least one vulnerability code pair based on the code similarity using a similarity threshold to obtain a candidate vulnerability code; determining a raw code fragment in the vulnerability pattern description information and the code scenario description information, and performing code consistency verification processing on the candidate vulnerability code using the raw code fragment to obtain a code verification result corresponding to the candidate vulnerability code; if the code verification result is a verification success type, then using the candidate vulnerability code corresponding to the code verification result as the target vulnerability code; if the code verification result is a verification failure type, then removing the candidate vulnerability code corresponding to the code verification result.

2. The method according to claim 1, characterized in that The method of performing similar pattern code selection processing based on the real code database to obtain real scene code fragments includes: Determine the vulnerability code keyword corresponding to the specified code vulnerability pattern, and use the vulnerability code keyword to perform similar pattern code matching processing in the real code database to obtain a real scenario code fragment.

3. The method according to claim 1, characterized in that The code generation process is performed based on the code generation prompt word using a code generation model to obtain a reference vulnerability code, including: Inputting the code generation prompt word into the code generation model, performing code merging processing based on vulnerability pattern definition information, synthetic vulnerability code snippets and real scenario code snippets through the code generation model to obtain a first reference vulnerability code; and / or, Inputting the code generation prompt word into a code generation macromodel, generating a first vulnerability code snippet based on vulnerability pattern definition information and a real scenario code snippet through the code generation macromodel, and performing code merging processing based on the first vulnerability code snippet and the real scenario code snippet to obtain a second reference vulnerability code; and / or, Inputting the code generation prompt word into the code generation big model, performing vulnerability code generation processing based on vulnerability pattern definition information, synthetic vulnerability code snippets and code scenario type information through the code generation big model to obtain a third reference vulnerability code; and / or, The code generation prompt word is input into the code generation big model, and the code generation big model is used to perform vulnerability code generation processing based on vulnerability pattern definition information and code scenario type information to obtain a fourth reference vulnerability code.

4. The method according to claim 1, characterized in that: The using the raw code fragment to perform code consistency verification processing on the candidate vulnerability code to obtain a code verification result corresponding to the candidate vulnerability code includes: If the raw code fragment includes a synthetic vulnerability code fragment, a first code verification prompt word is generated based on the synthetic vulnerability code fragment and the candidate vulnerability code, the first code verification prompt word is input into a code verification macro model, and a code consistency verification process is performed based on the vulnerability code fragment and the candidate vulnerability code by the code verification macro model to obtain a first code verification result corresponding to the candidate vulnerability code; If the raw code fragment includes a real-scene code fragment, a second code verification prompt word is generated based on the real-scene code fragment and the candidate vulnerability code, and the second code verification prompt word is input into the code verification big model. The code verification big model is used to perform code consistency verification processing based on the real-scene code fragment and the candidate vulnerability code to obtain a second code verification result corresponding to the candidate vulnerability code.

5. A data processing device, characterized in that: The device comprises: An information acquisition module, used to acquire a specified code vulnerability pattern for the file automatic processing function code in a file automatic processing scenario, and determine vulnerability pattern description information and code scenario description information for the specified code vulnerability pattern; A code generation module, used to determine a code generation prompt word based on the vulnerability pattern description information and the code scenario description information, and perform code generation processing using a code generation macro model based on the code generation prompt word to obtain a reference vulnerability code; A code evaluation module, used to perform code evaluation processing on the reference vulnerability code to obtain a target vulnerability code, and to construct a vulnerability code data set based on the target vulnerability code; The information acquisition module includes: a third information generation unit, which is used to obtain vulnerability pattern definition information for the specified code vulnerability pattern and generate vulnerability pattern description information including the vulnerability pattern definition information; or a fourth information generation unit, which is used to obtain vulnerability pattern definition information and a synthetic vulnerability code fragment for the specified code vulnerability pattern and generate vulnerability pattern description information including the vulnerability pattern definition information and the synthetic vulnerability code fragment; The information acquisition module includes: a first information generation unit, which is used to obtain a real code database for the specified code vulnerability pattern, perform similar pattern code selection processing based on the real code database to obtain a real scenario code fragment, and generate code scenario description information including the real scenario code fragment; or a second information generation unit, which is used to obtain code scenario type information corresponding to the specified code vulnerability pattern, and generate code scenario description information including the code scenario type information; The code evaluation module includes: a first code evaluation unit, which is used to perform similarity calculation on multiple reference vulnerability codes to obtain code similarity of at least one vulnerability code pair; a second code evaluation unit, which is used to perform code deduplication processing on the at least one vulnerability code pair based on the code similarity using a similarity threshold to obtain candidate vulnerability code; a third code evaluation unit, which is used to determine a raw code fragment in the vulnerability pattern description information and the code scenario description information, and use the raw code fragment to perform code consistency verification processing on the candidate vulnerability code to obtain a code verification result corresponding to the candidate vulnerability code; a fourth code evaluation unit, which is used to use the candidate vulnerability code corresponding to the code verification result as the target vulnerability code if the code verification result is a verification success type; and a fifth code evaluation unit, which is used to remove the candidate vulnerability code corresponding to the code verification result if the code verification result is a verification failure type.

6. A computer storage medium, characterized in that: The computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the method according to any one of claims 1 to 4.

7. An electronic device, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Code vulnerability detection large model construction method and device and electronic equipment

    CN118171291A

  • Source code vulnerability detection method and system based on large model

    CN118332557A