A Java vulnerability repair method, device, medium and program product

Through the Java vulnerability automatic repair method based on the large language model, the problem of low code quality and low efficiency in the existing technology is solved, and high-quality vulnerability repair and automation processes are realized, which significantly reduces the workload of developers.

CN119377972BActive Publication Date: 2025-05-09CHANGCHUN IDEAL S&T INFORMATION LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411959318.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-09
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

The repair code generated by existing Java vulnerability repair methods is low in quality, low in vulnerability repair efficiency, and poor in vulnerability repair effect.

Method used

The Java vulnerability automatic repair method based on the large language model is adopted. The target code blocks of vulnerability locations are extracted, the queues to be analyzed are generated, and the vulnerability analysis and repair processing is carried out, including syntax analysis, data capture, vulnerability repair and review, and finally the repaired code is put back to the source code.

Benefits of technology

It improves the quality and efficiency of repairing code, realizes the full process automation of vulnerability location, code repair, compilation and submission, and significantly reduces the workload of developers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119377972B_ABST
    Figure CN119377972B_ABST
Patent Text Reader

Abstract

The present invention discloses a Java vulnerability repair method, device, medium and program product, the method comprising: firstly, extracting the target code block corresponding to the Java vulnerability according to the location of the Java vulnerability; then, based on a preset large language model, extracting the elements to be analyzed from the target code block to generate a queue to be analyzed; performing vulnerability analysis processing according to the queue to be analyzed, analyzing and obtaining the code block to be repaired; performing repair processing on the code block to be repaired to obtain a repaired code block; then performing repair review processing on the repaired code block to obtain a code block that has passed the review; and finally, putting the code block that has passed the review back into the source code. The present invention realizes automatic repair of Java vulnerabilities based on the AutoGen framework and the large language model, effectively improving the accuracy and efficiency of Java vulnerability repair.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of large model technology, and in particular to a Java vulnerability repair method, device, medium and program product. Background Art

[0002] In today's software development field, Java is a widely used programming language, and its security is of vital importance. In order to enhance the security of Java programs, researchers have proposed many automated means to help developers discover, detect and locate vulnerabilities, but developers still need to spend a lot of effort to manually fix the vulnerabilities.

[0003] As Java projects continue to expand in size and complexity, traditional manual vulnerability repair techniques can no longer meet the needs of modern software development. Existing methods are not only inefficient but also prone to errors, which brings tremendous work pressure to developers. In order to reduce the burden on developers, it is necessary to use automatic vulnerability repair technology.

[0004] Automatic vulnerability repair technology is designed to assist developers in repairing vulnerabilities, covering functions such as vulnerability root cause location, code generation, and code verification.

[0005] The existing technology only reduces the software vulnerability repair specification to a general text generation problem, without locating the defect repair location, resulting in a large generation space for the repair code and low quality of the generated repair code, which affects the efficiency and effectiveness of vulnerability repair.

[0006] Therefore, it is urgent to invent a Java vulnerability automatic repair method based on a large model to solve the problems of low quality of repair code generated by existing vulnerability repair methods, low vulnerability repair efficiency and poor vulnerability repair effect. Summary of the invention

[0007] In view of this, embodiments of the present invention provide a Java vulnerability repair method, device, medium and program product, which at least partially solve the problems existing in the prior art.

[0008] Other features and advantages of the present invention will become apparent from the following detailed description, or may be learned in part by practice of the present invention.

[0009] In order to achieve the above purpose, the embodiment of the present invention provides the following technical solutions:

[0010] According to a first aspect of an embodiment of the present invention, a Java vulnerability repair method is provided, the method comprising:

[0011] According to the location of the Java vulnerability, extract the target code block corresponding to the Java vulnerability;

[0012] Based on a preset large language model, extract elements to be analyzed from the target code block to generate a queue to be analyzed;

[0013] Perform vulnerability analysis according to the queue to be analyzed, and obtain code blocks to be repaired;

[0014] Performing repair processing on the code block to be repaired to obtain a repaired code block;

[0015] Performing a repair review process on the repaired code block to obtain a code block that has passed the review;

[0016] Put the reviewed code block back into the source code.

[0017] Furthermore, according to the location of the Java vulnerability, the target code block corresponding to the Java vulnerability is extracted, including:

[0018] Locate the target code block where the Java vulnerability exists based on the URL corresponding to the Java vulnerability or the number of code lines where the vulnerability occurs.

[0019] Further, based on the preset large language model, extracting the elements to be analyzed from the target code block and generating a queue to be analyzed includes:

[0020] Performing syntax analysis on the target code block using a Tree-sitter parser to obtain a syntax analysis result;

[0021] Determine capture parameters corresponding to the target code block based on a preset large language model and a preset Java knowledge base, wherein the capture parameters include a class name, a method name, and a return type of a method parameter;

[0022] Using the capture parameter to perform data capture processing on the syntax analysis result to obtain a capture result;

[0023] The Java classes and methods in the captured results are stored as elements to be analyzed in a queue to be analyzed in a preset format.

[0024] Further, vulnerability analysis is performed according to the queue to be analyzed to obtain code blocks to be repaired, including:

[0025] For the first element to be analyzed in the queue to be analyzed, input the code block corresponding to the first element to be analyzed into the AutoGen group chat session;

[0026] Using the Analyst Agent customized in the AutoGen framework, determine whether the code block corresponding to the element to be analyzed contains content that directly causes the vulnerability based on the vulnerability description;

[0027] If the code block corresponding to the element to be analyzed contains content that directly causes the vulnerability, the code block containing the content that directly causes the vulnerability is used as the code block to be repaired;

[0028] If the code block corresponding to the element to be analyzed does not contain the content that directly causes the vulnerability, then the first element to be analyzed is deleted from the queue to be analyzed;

[0029] Determine whether the current queue to be analyzed is empty;

[0030] If the current queue to be analyzed is empty, the vulnerability analysis is completed;

[0031] If the current queue to be analyzed is not empty, the preset large language model is used to determine whether there is an element to be analyzed in the queue to be analyzed that contains the Java method that needs to be checked the most, where the Java method that needs to be checked the most is the Java method that is most likely to cause a vulnerability;

[0032] If there is an element to be analyzed that contains the Java method that needs to be checked most in the queue to be analyzed, locate the corresponding method code block according to the file path where the Java method corresponding to the element to be analyzed that contains the Java method that needs to be checked most is located, and use the method code block as the code block to be repaired;

[0033] If there is no element to be analyzed in the queue to be analyzed that contains the Java method that needs to be viewed most, the key and value of the first element to be analyzed in the current queue to be analyzed are replaced with the method path and method code block corresponding to the element;

[0034] The loop is executed until the first element to be analyzed in the queue to be analyzed is executed, and the code block corresponding to the first element to be analyzed is input into the AutoGen group chat session.

[0035] Further, the code block to be repaired is repaired to obtain a repaired code block, including:

[0036] Using vector embedding technology, a preset vulnerability knowledge base in text form is stored in a vulnerability vector database, wherein the preset vulnerability knowledge base stores vulnerabilities in vulnerability scenarios according to preset fields, and the preset fields include vulnerability name, vulnerability description, vulnerability appearance mode, vulnerability repair method, code block before repair, and code block after repair;

[0037] For each of the code blocks to be repaired in the AutoGen group chat session, judging, based on cosine similarity, whether there is content in the vulnerability vector database that matches the vulnerability description corresponding to the code block to be repaired;

[0038] If there is content in the vulnerability vector database that matches the vulnerability description corresponding to the code block to be repaired, obtaining the vulnerability repair prompt word corresponding to the code block to be repaired according to the matching result;

[0039] Based on the customized Engineer Agent in the Autogen framework, the vulnerability repair prompt word is used to perform vulnerability repair processing on the code block to be repaired, so as to obtain a repaired code block;

[0040] If there is no content matching the vulnerability description corresponding to the code block to be repaired in the vulnerability vector database, based on the customized Engineer Agent in the Autogen framework, the code block to be repaired is repaired using the preset default prompt words to obtain a repaired code block;

[0041] The repaired code block is output in the AutoGen group chat session.

[0042] Further, the repaired code block is subjected to repair review processing to obtain a code block that passes the review, including:

[0043] For the repaired code block in the AutoGen group chat session, based on the Reviewer Agent customized in the AutoGen framework, determine whether the repaired code block is completely repaired;

[0044] If the repaired code block is not completely repaired, the repaired code block is used as the code block to be repaired, and the Engineer Agent is used to repair the code block to be repaired. After the repair is completed, the process loops to determine whether the repaired code block is completely repaired.

[0045] If the repaired code block is completely repaired, the repaired code block is used as the first review code block;

[0046] Determine whether there are any Java methods that need to be repaired in the first review code block;

[0047] If there are still Java methods that need to be repaired in the first review code block, the EngineerAgent is used to repair the code corresponding to the Java method that needs to be repaired, and after the repair is completed, the process is looped to determine whether there are still Java methods that need to be repaired in the first review code block;

[0048] If there is no Java method that needs to be repaired in the first review code block, use the first review code block as the second review code block;

[0049] Determine whether the Java method call in the second review code block is correct;

[0050] If the Java method in the second review code block is called correctly, output the second review code block as a review-passed code block in the AutoGen group chat session;

[0051] If the Java method in the second review code block is called incorrectly, the Engineer Agent is used to repair the code corresponding to the incorrectly called Java method. After the repair is completed, the process loops to determine whether the Java method in the second review code block is called correctly.

[0052] Furthermore, the code blocks that have passed the review are put back into the source code, including:

[0053] Obtain the approved code block in the AutoGen group chat session, and according to the location of the Java vulnerability, put the approved code block back to the corresponding location of the source code to obtain the repaired source code;

[0054] Compiling the repaired source code to obtain a compilation result;

[0055] Determine whether the compilation result is passed;

[0056] If the compilation result is not passed, the code is repaired using the compilation error information based on the preset large language model, and after the repair is completed, the code is compiled in a loop to process the repaired source code;

[0057] If the compilation result is passed, a Git merge request is automatically submitted based on the repaired source code.

[0058] According to a second aspect of an embodiment of the present invention, a device is provided, the device comprising: a processor and a memory;

[0059] The memory is used to store one or more program instructions;

[0060] The processor is used to run one or more program instructions to execute the steps of a Java vulnerability repair method as described in any one of the above items.

[0061] According to a third aspect of an embodiment of the present invention, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of a Java vulnerability repair method as described in any one of the above items are implemented.

[0062] According to a fourth aspect of an embodiment of the present invention, a computer program product is provided, the computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising program instructions, and when the program instructions are executed by a computer, the computer implements the steps of a Java vulnerability repair method as described in any one of the above items.

[0063] The embodiments of the present invention provide a Java vulnerability repair method, device, medium and program product, which can automatically repair Java vulnerabilities through a large language model based on the AutoGen framework, realize full-process automation of vulnerability location, code repair, compilation and submission, and at the same time combine with a custom knowledge base to ensure the quality of the generated code, thereby solving the problems of low quality of repair code generated by the prior art and heavy workload for developers. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] In order to more clearly illustrate the implementation methods of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the implementation methods or the description of the prior art. Obviously, the drawings in the following description are only exemplary, and for ordinary technicians in this field, other implementation drawings can be derived from the provided drawings without creative work.

[0065] Figure 1 A schematic diagram of a Java vulnerability repair method provided by an embodiment of the present invention;

[0066] Figure 2 A schematic diagram of a Java vulnerability analysis process provided by an embodiment of the present invention;

[0067] Figure 3 A schematic diagram of a process for repairing a code block to be repaired provided by an embodiment of the present invention;

[0068] Figure 4 A schematic diagram of a process for reviewing a repaired code block provided by an embodiment of the present invention;

[0069] Figure 5 A schematic diagram of a source code repair process provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0070] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0071] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0072] Figure 1 The figure shows a flow chart of a Java vulnerability repairing method according to an embodiment of the present invention.

[0073] like Figure 1 As shown, the Java vulnerability repair method according to the embodiment of the present invention may include step S100, step S200, step S300, step S400, step S500 and step S600.

[0074] In step S100, according to the location of the Java vulnerability, the target code block corresponding to the Java vulnerability is extracted.

[0075] Specifically, the above steps include:

[0076] Locate the target code block where the Java vulnerability exists based on the URL corresponding to the Java vulnerability or the number of code lines where the vulnerability occurs.

[0077] Next, in step S200, based on the preset large language model, elements to be analyzed are extracted from the target code block to generate a queue to be analyzed.

[0078] Specifically, the above steps include:

[0079] Firstly, the Tree-sitter parser is used to perform syntax analysis on the target code block and the file where the target code block is located to obtain the syntax analysis result.

[0080] Then, based on the preset large language model and the preset Java knowledge base, the capture parameters corresponding to the target code block are determined, wherein the above-mentioned capture parameters include the class name, method name and the return type of the method parameter, and the above-mentioned preset Java knowledge base contains the class names, method names and the return types of the method parameters of all Java standard libraries.

[0081] Then, the capture parameters are used to perform data capture processing on the above syntax analysis results to obtain capture results, and the Java classes and methods in the capture results are stored as elements to be analyzed in a queue to be analyzed in a preset format. The preset format is "deque(("class name java(initial line, end line)"], ("method name": path of the file where the method is located}...)".

[0082] It should be noted that the above-mentioned preset large language model is an existing general large language model.

[0083] The embodiment of the present invention extracts the referenced method from the target code block, finds the class where the method is defined, and generates a queue to be analyzed together with the target code block and its path.

[0084] In step S300, vulnerability analysis is performed according to the queue to be analyzed to obtain code blocks to be repaired.

[0085] Specifically, refer to Figure 2 , the above steps include:

[0086] In step S301, for the first element to be analyzed in the queue to be analyzed, a code block corresponding to the first element to be analyzed is input into the AutoGen group chat session.

[0087] In step S302, the Analyst Agent customized in the AutoGen framework is used to determine whether the code block corresponding to the element to be analyzed contains content that directly causes the vulnerability based on the vulnerability description.

[0088] If the code block corresponding to the element to be analyzed contains content that directly causes the vulnerability, step S303 is executed to take the code block containing the content that directly causes the vulnerability as the code block to be repaired.

[0089] If the target code block corresponding to the element to be analyzed does not contain the content that directly causes the vulnerability, step S304 is executed to delete the first element to be analyzed from the queue to be analyzed.

[0090] In step S305, it is determined whether the current queue to be analyzed is empty.

[0091] If the current queue to be analyzed is empty, it means that there is no vulnerability that needs to be repaired in the code, and step S306 is executed to complete the vulnerability analysis.

[0092] If the current queue to be analyzed is not empty, execute step S307, and use the preset large language model to determine whether there is an element to be analyzed in the queue to be analyzed that contains the Java method that most needs to be reviewed. The above-mentioned Java method that most needs to be reviewed is the Java method that the preset large language model believes is most likely to cause a vulnerability. Use method_choose Agent to determine whether the Java method is the Java method that is most likely to cause a vulnerability.

[0093] If there is an element to be analyzed that contains the Java method that most needs to be checked in the queue to be analyzed, step S308 is executed to locate the corresponding method code block according to the file path of the Java method corresponding to the element to be analyzed that contains the Java method that most needs to be checked, and use the method code block as the code block to be repaired.

[0094] If there is no to-be-analyzed element in the to-be-analyzed queue that contains the Java method that needs to be viewed most, step S309 is executed to place the method path and method code block corresponding to the first to-be-analyzed element in the current to-be-analyzed queue at the head of the queue in the format of "{"class name java (initial line, end line)": source code}", and the corresponding to-be-analyzed element in the queue is deleted.

[0095] The loop is executed until the first element to be analyzed in the queue to be analyzed is executed, and the code block corresponding to the first element to be analyzed is input into the AutoGen group chat session.

[0096] The embodiment of the present invention automatically analyzes the factors that directly cause vulnerabilities in the code block and the Java methods that need to be checked most through a traversal algorithm, and determines that the vulnerability analysis has been completed by judging that the queue is empty. During the traversal process, it is judged whether the code block currently being accessed contains content that directly causes the vulnerability. Once the code block contains content that directly causes the vulnerability, the code block is taken out and input into the AutoGen group chat session as a code block to be repaired. The code blocks to be repaired in the group chat session are waiting to be repaired in the order of input time. If the code block does not contain content that directly causes the vulnerability, the large model continues to traverse the remaining code blocks in the queue until the queue is empty.

[0097] Next, in step S400, the code block to be repaired is repaired to obtain a repaired code block.

[0098] Specifically, refer to Figure 3 , the above steps include:

[0099] In step S401, the preset vulnerability knowledge base in text form is stored in a vulnerability vector database using vector embedding technology, wherein the preset vulnerability knowledge base stores vulnerabilities in vulnerability scenarios according to preset fields, and the preset fields include vulnerability name, vulnerability description, vulnerability occurrence method, vulnerability repair method, code block before repair, and code block after repair.

[0100] In step S402, for each code block to be repaired in the AutoGen group chat session, it is determined based on cosine similarity whether there is content matching the vulnerability description corresponding to the code block to be repaired in the vulnerability vector database.

[0101] If there is content matching the vulnerability description corresponding to the code block to be repaired in the vulnerability vector database, step S403 is executed to obtain a matching result, and the matching result is further screened using the vulnerability name as a keyword, and the part that meets the requirements is output as a vulnerability repair prompt word.

[0102] In step S404, based on the customized Engineer Agent in the Autogen framework, vulnerability repair prompt words are used to perform vulnerability repair processing on the code block to be repaired, so as to obtain a repaired code block.

[0103] If there is no content matching the vulnerability description corresponding to the code block to be repaired in the vulnerability vector database, step S405 is executed to perform vulnerability repair processing on the code block to be repaired using preset default prompt words based on the customized Engineer Agent in the Autogen framework to obtain a repaired code block.

[0104] In step S406, the repaired code block is output in the AutoGen group chat session.

[0105] Next, in step S500, the repaired code block is subjected to a repair review process to obtain a code block that has passed the review.

[0106] Specifically, refer to Figure 4 , the above steps include:

[0107] In steps S501 to S502, for the repaired code block in the AutoGen group chat session, based on the Reviewer Agent customized in the AutoGen framework, it is determined whether the repaired code block is completely repaired.

[0108] If the repaired code block is not completely repaired, step S503 is executed to use the repaired code block as the code block to be repaired, and the Engineer Agent is used to repair the code block to be repaired. After the repair is completed, the process loops to determine whether the repaired code block is completely repaired.

[0109] If the repaired code block is completely repaired, step S504 is executed to use the repaired code block as the first review code block.

[0110] In step S505, it is determined whether there are any Java methods that need to be repaired in the first review code block.

[0111] If there are still Java methods that need to be repaired in the first review code block, execute step S506, use Engineer Agent to repair the code corresponding to the Java method that needs to be repaired, and after the repair is completed, loop to determine whether there are still Java methods that need to be repaired in the first review code block.

[0112] If there is no Java method that needs to be repaired in the first review code block, step S507 is executed to use the first review code block as the second review code block.

[0113] In step S508, determine whether the Java method call in the second review code block is correct.

[0114] If the Java method call in the second review code block is correct, step S509 is executed to output the second review code block as a review-passed code block in the AutoGen group chat session.

[0115] If the Java method in the second review code block is called incorrectly, execute step S510, use EngineerAgent to repair the code corresponding to the incorrectly called Java method, and after the repair is completed, loop to determine whether the Java method in the second review code block is correct.

[0116] Finally, in step S600, the code blocks that have passed the review are put back into the source code.

[0117] Specifically, refer to Figure 5 , the above steps include:

[0118] In step S601, the code blocks that have passed the review in the AutoGen group chat session are obtained, and according to the location of the Java vulnerability, the code blocks that have passed the review are placed back to the corresponding position of the source code to obtain the repaired source code.

[0119] In step S602, the repaired source code is compiled to obtain a compilation result.

[0120] In step S603, it is determined whether the compilation result is passed.

[0121] If the compilation result is not passed, step S604 is executed, and the code is repaired based on the preset large language model using the compilation error information. After the repair is completed, the code is looped to compile the repaired source code.

[0122] If the compilation result is passed, step S605 is executed to automatically submit a Git merge request based on the repaired source code.

[0123] The embodiment of the present invention can realize automatic repair of Java vulnerabilities based on the AutoGen framework through a large language model, realize the automation of the entire process of vulnerability location, code repair, compilation, and submission, and at the same time combine with a custom knowledge base to ensure the quality of the generated code, thereby solving the problems of low quality of repair code generated by the prior art and heavy workload for developers.

[0124] In addition, an embodiment of the present invention further provides a device, which includes: a processor and a memory; the memory is used to store one or more program instructions; the processor is used to run one or more program instructions to execute the steps of a Java vulnerability repair method as described above.

[0125] In addition, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the Java vulnerability repair method described above are implemented.

[0126] In addition, an embodiment of the present invention further provides a computer program product, which includes computer program instructions. When the computer program instructions are executed by a processor, the steps of the Java vulnerability repair method described above are implemented.

[0127] The embodiment of the present invention uses a large language model combined with a custom knowledge base to parse and repair the code blocks that cause the vulnerability. The repair code generated by the present invention is highly accurate. The present invention automatically completes the entire process of vulnerability location, code repair, compilation, and submission, significantly reducing the workload of operation and maintenance personnel and greatly improving the efficiency of repairing Java vulnerabilities.

[0128] In the embodiment of the present invention, the processor may be an integrated circuit chip having the ability to process signals. The processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gates or transistor logic devices, or discrete hardware components. The methods, steps, and logic block diagrams disclosed in the embodiments of the present invention may be implemented or executed. The general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc. The steps of the method disclosed in the embodiment of the present invention may be directly embodied as being executed by a hardware decoding processor, or may be executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The processor reads the information in the storage medium and completes the steps of the above method in combination with its hardware. The storage medium may be a memory, for example, a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM) and direct RAM bus random access memory (DRRAM).The storage medium described in the embodiment of the present invention is intended to include but is not limited to these and any other suitable types of memory. Those skilled in the art should be aware that in one or more of the above examples, the functions described in the present invention can be implemented by a combination of hardware and software. When the application software is used, the corresponding function can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein the communication medium includes any medium that is convenient for transmitting a computer program from one place to another. The storage medium can be any available medium that a general or special-purpose computer can access. Although the present invention has been described in detail above with general descriptions and specific embodiments, it is obvious to those skilled in the art that some modifications or improvements can be made to it on the basis of the present invention. Therefore, these modifications or improvements made on the basis of not departing from the spirit of the present invention all belong to the scope of protection claimed in the present invention.

[0129] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any form. Those skilled in the art may make some simple modifications, equivalent changes or modifications using the technical contents disclosed above, which all fall within the protection scope of the present invention.

Claims

1. A Java vulnerability repair method, characterized in that: The method comprises: According to the location of the Java vulnerability, extract the target code block corresponding to the Java vulnerability; Based on a preset large language model, extract elements to be analyzed from the target code block to generate a queue to be analyzed; Vulnerability analysis is performed according to the queue to be analyzed, and code blocks to be repaired are obtained through analysis, including: For the first element to be analyzed in the queue to be analyzed, input the code block corresponding to the first element to be analyzed into the AutoGen group chat session; Using the Analyst Agent customized in the AutoGen framework, determine whether the code block corresponding to the element to be analyzed contains content that directly causes the vulnerability based on the vulnerability description; If the code block corresponding to the element to be analyzed contains content that directly causes the vulnerability, the code block containing the content that directly causes the vulnerability is used as the code block to be repaired; If the code block corresponding to the element to be analyzed does not contain the content that directly causes the vulnerability, then the first element to be analyzed is deleted from the queue to be analyzed; Determine whether the current queue to be analyzed is empty; If the current queue to be analyzed is empty, the vulnerability analysis is completed; If the current queue to be analyzed is not empty, the preset large language model is used to determine whether there is an element to be analyzed in the queue to be analyzed that contains the Java method that needs to be checked the most, where the Java method that needs to be checked the most is the Java method that is most likely to cause a vulnerability; If there is an element to be analyzed that contains the Java method that needs to be checked most in the queue to be analyzed, locate the corresponding method code block according to the file path where the Java method corresponding to the element to be analyzed that contains the Java method that needs to be checked most is located, and use the method code block as the code block to be repaired; If there is no element to be analyzed in the queue to be analyzed that contains the Java method that needs to be viewed most, the key and value of the first element to be analyzed in the current queue to be analyzed are replaced with the method path and method code block corresponding to the element; Looping until the first element to be analyzed in the queue to be analyzed is executed, and inputting the code block corresponding to the first element to be analyzed into the AutoGen group chat session; Performing repair processing on the code block to be repaired to obtain a repaired code block; Performing a repair review process on the repaired code block to obtain a code block that has passed the review; Put the reviewed code block back into the source code.

2. A Java vulnerability repair method according to claim 1, characterized in that: According to the location of the Java vulnerability, extract the target code block corresponding to the Java vulnerability, including: Locate the target code block where the Java vulnerability exists based on the URL corresponding to the Java vulnerability or the number of code lines where the vulnerability occurs.

3. A Java vulnerability repair method according to claim 1, characterized in that: Based on the preset large language model, extracting elements to be analyzed from the target code block and generating a queue to be analyzed include: Performing syntax analysis on the target code block using a Tree-sitter parser to obtain a syntax analysis result; Determine capture parameters corresponding to the target code block based on a preset large language model and a preset Java knowledge base, wherein the capture parameters include a class name, a method name, and a return type of a method parameter; Using the capture parameter to perform data capture processing on the syntax analysis result to obtain a capture result; The Java classes and methods in the captured results are stored as elements to be analyzed in a queue to be analyzed in a preset format.

4. A Java vulnerability repair method according to claim 1, characterized in that: Performing repair processing on the code block to be repaired to obtain a repaired code block, including: Using vector embedding technology, a preset vulnerability knowledge base in text form is stored in a vulnerability vector database, wherein the preset vulnerability knowledge base stores vulnerabilities in vulnerability scenarios according to preset fields, and the preset fields include vulnerability name, vulnerability description, vulnerability appearance mode, vulnerability repair method, code block before repair, and code block after repair; For each of the code blocks to be repaired in the AutoGen group chat session, judging, based on cosine similarity, whether there is content in the vulnerability vector database that matches the vulnerability description corresponding to the code block to be repaired; If there is content in the vulnerability vector database that matches the vulnerability description corresponding to the code block to be repaired, obtaining the vulnerability repair prompt word corresponding to the code block to be repaired according to the matching result; Based on the customized Engineer Agent in the Autogen framework, the vulnerability repair prompt word is used to perform vulnerability repair processing on the code block to be repaired, so as to obtain a repaired code block; If there is no content matching the vulnerability description corresponding to the code block to be repaired in the vulnerability vector database, based on the customized Engineer Agent in the Autogen framework, the code block to be repaired is repaired using the preset default prompt words to obtain a repaired code block; The repaired code block is output in the AutoGen group chat session.

5. A Java vulnerability repair method according to claim 1, characterized in that: Performing a repair review process on the repaired code block to obtain a code block that passes the review, including: For the repaired code block in the AutoGen group chat session, based on the ReviewerAgent customized in the AutoGen framework, determine whether the repaired code block is completely repaired; If the repaired code block is not completely repaired, the repaired code block is used as the code block to be repaired, and the Engineer Agent is used to repair the code block to be repaired. After the repair is completed, the process loops to determine whether the repaired code block is completely repaired. If the repaired code block is completely repaired, the repaired code block is used as the first review code block; Determine whether there are any Java methods that need to be repaired in the first review code block; If there are still Java methods that need to be repaired in the first review code block, the Engineer Agent is used to repair the code corresponding to the Java method that needs to be repaired, and after the repair is completed, the process loops to determine whether there are still Java methods that need to be repaired in the first review code block; If there is no Java method that needs to be repaired in the first review code block, use the first review code block as the second review code block; Determine whether the Java method call in the second review code block is correct; If the Java method in the second review code block is called correctly, output the second review code block as a review-passed code block in the AutoGen group chat session; If the Java method in the second review code block is called incorrectly, the Engineer Agent is used to repair the code corresponding to the incorrectly called Java method. After the repair is completed, the process loops to determine whether the Java method in the second review code block is called correctly.

6. A Java vulnerability repair method according to claim 1, characterized in that: Put the reviewed code blocks back into the source code, including: Obtain the approved code block in the AutoGen group chat session, and according to the location of the Java vulnerability, put the approved code block back to the corresponding location of the source code to obtain the repaired source code; Compiling the repaired source code to obtain a compilation result; Determine whether the compilation result is passed; If the compilation result is not passed, the code is repaired using the compilation error information based on the preset large language model, and after the repair is completed, the code is compiled in a loop to process the repaired source code; If the compilation result is passed, a Git merge request is automatically submitted based on the repaired source code.

7. A Java vulnerability repair device, characterized in that: The device comprises: a processor and a memory; The memory is used to store one or more program instructions; The processor is used to run one or more program instructions to execute the steps of a Java vulnerability repair method according to any one of claims 1 to 6.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of a Java vulnerability repair method according to any one of claims 1 to 6 are implemented.

9. A computer program product, characterized in that The computer program product comprises computer program instructions, which, when executed by a processor, implement the steps of a Java vulnerability repair method as claimed in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method and device for processing security vulnerabilities and electronic equipment

    CN118036009A

  • Advanced vulnerability mining and automatic testing method and testing system based on large language model

    CN118171288A

  • Hyperledger Fabric-oriented intelligent contract vulnerability detection method and system

    CN118626379A