Automatic Update Method, Device, Equipment and Storage Medium of Software Function Package
By comprehensively evaluating the dependencies and update importance of software function packages, calculating update priority scores, and automatically updating using priority queues and dynamic programming, the problems of insufficient update management and insufficient strategy in the existing technology are solved, and the update efficiency and reliability are improved.
Patent Information
- Application Number
- CN202411739251.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-29
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2044-11-29
AI Technical Summary
The existing technology lacks comprehensive evaluation and dynamic adjustment of update strategies in the update management of software function packages, resulting in insufficient update efficiency and reliability.
By scanning the software warehouse to obtain the function package dependency table and update description, calculate dependency, impact range, functionality and security metrics, calculate update priority scores based on these metrics, and automatically update in combination with priority queues and dynamic programming.
The optimization of the automatic update process of software function packages is achieved, which significantly improves the efficiency and reliability of updates, and ensures priority updates of key function packages and system stability.
Smart Images

Figure CN119396440B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of software updating, and in particular to a method, device, equipment and storage medium for automatically updating a software function package. Background Art
[0002] As software systems become increasingly complex and modular, the update management of software feature packages has become an important challenge. A software feature package usually refers to a collection of software components or modules that can be deployed and updated independently. In modern software development and maintenance, timely and secure updates of these feature packages are essential to maintaining system stability. Especially in the context of the rapid development of Industry 4.0 and the Internet of Things, software systems are often composed of multiple interdependent components that may come from different development teams or third-party suppliers. At the same time, in order to quickly respond to market demand and deal with security threats, software release cycles are constantly shortening and update frequency is constantly increasing. These trends make the automatic update of software feature packages a key issue that needs to be addressed.
[0003] At present, there are some technical solutions in the industry that are used to update software feature packages. For example, the package manager provides automatic dependency resolution and update functions, which can automatically handle the dependencies between software packages. Containerization technology simplifies the software packaging and deployment process, making update operations more standardized and controllable. Configuration management tools provide automated software configuration and deployment capabilities, which can perform update operations on multiple systems simultaneously. In addition, some continuous integration / continuous deployment platforms integrate automated testing and deployment functions, which can automatically perform tests during the update process to reduce the risk of introducing bugs during updates.
[0004] However, these existing technologies still have limitations. Most of them only focus on the execution process of the update, lack a comprehensive evaluation of the update, and adopt a fixed update strategy, which cannot dynamically adjust the update plan according to the system status and update importance.
[0005] To this end, a method, device, equipment and storage medium for automatically updating a software function package are proposed. Summary of the invention
[0006] The purpose of the present invention is to provide a method, device, equipment and storage medium for automatically updating software function packages. First, by scanning the software repository, an installed function package dependency table and an update description of the software function packages to be updated are obtained, and the latest function package dependency table is obtained by analyzing the installed function package dependency table and the update description. Then, according to the latest function package dependency table, a dependency degree index is calculated, a function package dependency graph is constructed, an influence scope index is calculated, and at the same time, a functionality index and a security index are calculated according to the update description, and an update priority score is calculated based on all the indexes. Finally, the best update time window is determined through the historical load data of the software system, and in the best update time window, automatic update is performed according to the update priority score, in combination with a priority queue and dynamic programming. The present invention optimizes the process of automatically updating software function packages by comprehensively evaluating the impact of the update, and can significantly improve the efficiency and reliability of the update.
[0007] To achieve the above object, the present invention provides the following technical solutions:
[0008] A method for automatically updating software function packages, comprising:
[0009] Set an update period, and scan the software repository at the beginning of each update period to obtain an installed function package dependency table and a list of packages to be updated;
[0010] Extract the update description of the software function packages to be updated according to the list of packages to be updated;
[0011] Analyze the update description, and extract dependency change information, new function information and defect repair information;
[0012] Update the installed function package dependency table according to the dependency change information to obtain the latest function package dependency table and calculate the dependency degree index of the software function packages to be updated;
[0013] Construct a function package dependency graph according to the latest function package dependency table, and calculate the influence scope index of the software function packages to be updated;
[0014] Calculate the functionality index and security index of the software function packages to be updated according to the new function information and defect repair information;
[0015] Calculate the update priority score of the software function packages to be updated according to the dependency degree index, the influence scope index, the functionality index and the security index;
[0016] Determine the best update time window according to the historical load data of the software system;
[0017] In the best update time window, construct an update priority queue according to the update priority score for automatic update;
[0018] Record the update log and the running status of the updated software system, and adjust subsequent automatic updates.
[0019] Preferably, constructing the functional package dependency graph specifically includes: representing each software functional package as a node in the graph to obtain a graph node set V = {v1, v2, …, v n}, where v n represents the nth node in the graph node set; when the ith software functional package directly depends on the jth software functional package, it is represented as a directed edge from node v i to node v j ; representing the direct dependency relationship between every two different software functional packages as a directed edge to obtain a graph edge set where represents the mth edge in the graph edge set; creating a directed graph according to the graph node set and the graph edge set to obtain the functional package dependency graph G(V, E).
[0020] Preferably, the specific steps for calculating the influence range index of the software functional package to be updated include:
[0021] Defining an influence function between two nodes in the dependency graph and calculating the influence probability; the influence function is as follows:
[0022]
[0023] where P(v j , v i ) represents the influence probability of node v j on node v i ; E(v i , v j ) represents the path edge set corresponding to a path from node v i to node v j in the dependency graph. When node v i is inaccessible to node v j represents an empty set; represents the directed edge in the path edge set that points to node v q ; λ represents a weight coefficient; frequency(v q ) represents the average historical update frequency of node v q ;
[0024] Extracting the critical path between two nodes; the critical path is the path with the largest number of edges among all paths from node v i to node v j ;
[0025] Calculate the influence range index of each software function package to be updated according to the influence function and the critical path:
[0026]
[0027] where W(u) represents the influence range index of node u; u represents the node corresponding to the software function package to be updated; represents the influence probability corresponding to the critical path from node a to node u; A represents the set of nodes that node u can reach,
[0028] Preferably, the calculation methods of the dependency index, the functionality index, and the security index of the software function package to be updated are as follows:
[0029] The dependency index D = N d / N total ; where N d represents the number of software function packages directly dependent on the software function package to be updated; N total represents the total number of software function packages in the software system;
[0030] The functionality index F = (N f +N b ) / N max ; where N f represents the number of new functions of the software function package to be updated; N b represents the number of fixed defects of the software function package to be updated; N max represents the predefined maximum reference value;
[0031] The security index S = CVSS_Score / 10; where CVSS_Score represents the severity level of the security vulnerability in the fixed defects of the software function package to be updated.
[0032] Preferably, the specific steps for determining the optimal update time window according to the historical load data of the software system include:
[0033] Collect the historical load data of the software system in the N update cycles before the current update cycle and perform preprocessing to obtain N historical load time series data;
[0034] Construct a comprehensive load index based on the historical load time series data and set a threshold for the comprehensive load index;
[0035] Divide each historical load time series data into m time windows and calculate the comprehensive load index of each time window;
[0036] Identify the time window where the comprehensive load index is lower than the comprehensive load index threshold, traverse N historical load time series data, retain the time window with an occurrence frequency greater than h, and obtain a low utilization time window set; h represents the occurrence frequency threshold;
[0037] Merging consecutive time windows in the low-usage time window set to obtain M candidate optimal update time windows;
[0038] Constructing a load data prediction model and training it using the historical load time series data;
[0039] Generate predicted load time series data of the current update period by using the trained load data prediction model;
[0040] According to the predicted load time series data, the comprehensive load index of each candidate optimal update time window is calculated, and the candidate optimal update time window with the lowest comprehensive load index is selected as the optimal update time window of the current update cycle.
[0041] Preferably, the specific steps of constructing the update priority queue for automatic updating according to the update priority score include:
[0042] S1. Calculate the update priority scores of all current software function packages to be updated, and create the update priority queue Q of the software function packages to be updated in descending order;
[0043] The update priority score calculation formula is as follows:
[0044] PS(k)=w1*I1(k)+w2*I2(k)+w3*I3(k)+w4*I4(k);
[0045] Wherein, I1(k), I2(k), I3(k) and I4(k) respectively represent the normalized values of the dependency index, the impact range index, the functional index and the security index of the kth software function package to be updated; w1, w2, w3 and w4 represent the weights of each index;
[0046] S2. Collect the current system resource status, determine the total available resources R, and estimate the required resources r(k) for each software function package to be updated;
[0047] S3. Construct constraints based on the total available resources and the required resources, apply a dynamic programming algorithm to maximize the objective function under the constraints, and divide the update priority queue into a selected priority queue and an unselected priority queue; the constraints are ∑ k∈Q (r(k)*x(k))≤R; the objective function is ∑ k∈Q(PS(k)*x(k)); where x(k) represents an indicator function, and the values of x(k) are 1 and 0, indicating the selection and non-selection of the k-th software function package to be updated; the selected priority queue consists of the software function packages to be updated with x(k) having a value of 1; the unselected priority queue consists of the software function packages to be updated with x(k) having a value of 0;
[0048] S4. Update the software function packages to be updated in the selected priority queue in sequence;
[0049] S5. When the best update time window has not ended and the unselected priority queue is not empty, replace the priority queue with the unselected priority queue and return to step S2; when the best update time window has ended and the unselected priority queue is not empty, the unupdated software function packages to be updated are automatically updated in the best update time window of the next update cycle.
[0050] Preferably, the weights of the indicators in the update priority score are adaptively adjusted weights, and the adjustment steps are as follows:
[0051] Assign initial weight values to the dependency indicator, the influence scope indicator, the functionality indicator, and the security indicator;
[0052] After each update cycle ends, calculate the update effect score; the update effect score is calculated based on the update log and the running state of the software system after the update;
[0053] After every C update cycles end, calculate the difference between the current update effect score and the historical update effect score to obtain the update effect score difference; the historical update effect score is the average of the update effect scores of all ended update cycles;
[0054] Adjust the weights of the indicators according to the update effect score difference;
[0055] Apply the adjusted weights to the calculation of the update priority score in subsequent update cycles.
[0056] An automatic update device for software function packages, comprising:
[0057] An information collection module that scans the software repository, obtains a list of dependencies of installed function packages and a list of packages to be updated, extracts the update descriptions of the software function packages to be updated according to the list of packages to be updated, and analyzes the update descriptions to extract dependency change information, new function information, and defect repair information;
[0058] A dependency analysis module, based on the dependency relationship change information and the installed functional package dependency list, obtains the latest functional package dependency list and calculates the dependency index; constructs a functional package dependency graph according to the latest functional package dependency list, and calculates the influence range index of the functional packages to be updated;
[0059] A function analysis module, calculates the function index according to the new function information and the defect repair information;
[0060] A security analysis module, calculates the security index according to the defect repair information;
[0061] An update planning module, including an update time planning unit and an update priority planning unit; the update time planning unit determines the best update time window according to the historical load data of the software system; the update priority planning unit calculates the update priority score according to the dependency index, the influence range index, the function index and the security index, and constructs an update priority queue according to the update priority score;
[0062] An update execution module, in the best update time window, performs automatic update based on the update priority queue by applying dynamic programming.
[0063] A computer device, including a memory and a processor, wherein the memory stores a computer program that can run on the processor, and the steps in the automatic update method of the software functional package are implemented when the program is executed on the processor.
[0064] A storage medium, on which computer program instructions are stored, and the steps in the automatic update method of the software functional package are implemented when the computer program is executed by the processor.
[0065] Compared with the prior art, the beneficial effects of the present invention are:
[0066] 1. Evaluate the update priority of software function packages based on multiple metrics, including dependency metrics, impact scope metrics, functionality metrics, and security metrics. The dependency metrics consider direct dependencies and help identify critical software function packages; the impact scope metrics are calculated by constructing a function package dependency graph and defining an impact function, which can accurately evaluate the potential impact of each software function package to be updated on the overall software system; the functionality metrics combine the number of new features and defect fixes to evaluate the impact of the software function package to be updated on function improvement and stability; the security metrics focus on the severity of the security vulnerabilities fixed in the software function package to be updated, which can evaluate the impact of the software function package to be updated on improving system security; calculate the update priority score based on these metrics, comprehensively considering all aspects of the update, which can effectively identify and prioritize the update of critical function packages, providing a data basis for the automatic update of dynamically adjusted function packages.
[0067] 2. Propose a method for intelligently selecting the best update time window. First, collect and preprocess the system load data of multiple historical update cycles to construct a comprehensive load metric; then, identify low-usage time windows by setting thresholds and analyzing frequencies, and then obtain candidate best update time windows to avoid updating when the software system is busy and reduce the impact of the update on the software system; next, use a load data prediction model to generate the predicted load data for the current update cycle; finally, calculate the comprehensive load metric for each candidate best update time window based on the predicted load data to determine the best update time window for the current update cycle, improving the effectiveness of update time selection; this method can select the optimal time for updating, realize the dynamic adjustment of the update time, and can improve the efficiency and success rate of the update while ensuring the stability of the software system.
[0068] 3. Propose an automatic update execution strategy based on dynamic programming and update priority queue. First, construct an update priority queue according to the update priority score; then, collect the current system resource status, estimate the resources required for each package to be updated, and under the constraint of the total available resources, apply the dynamic programming algorithm to maximize the objective function, dividing the update queue into a selected priority queue and an unselected priority queue; finally, the system updates the function packages in the selected priority queue in order; the automatic update execution strategy based on dynamic programming and update priority queue not only ensures the orderly progress of the update, but also improves the utilization rate of system resources, realizes the global and local dynamic adjustment of the update, thus enhancing the stability and efficiency of the entire update process. Brief Description of the Drawings
[0069] Figure 1 It is a schematic flow chart of the automatic update method for the software function package provided by the embodiment of the present invention;
[0070] Figure 2Partial structural schematic diagram of the function package dependency graph provided by an embodiment of the present invention;
[0071] Figure 3 Structural schematic diagram of the automatic update device for software function packages provided by an embodiment of the present invention;
[0072] Figure 4 Structural schematic diagram of the computer device for automatic update of software function packages provided by an embodiment of the present invention.
[0073] In the figure: 1. Computer device; 11. Communication bus; 12. Receiver; 13. Processor; 14. Memory; 15. Computer program. Detailed implementation manners
[0074] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0075] The automatic update of software function packages is crucial for maintaining the security and stability of the system. However, the complex dependency relationships between software function packages pose great challenges to the automatic update process. The update of one function package may affect other packages that depend on it, triggering a chain reaction and resulting in system instability or abnormal functions. Therefore, before performing an update, it is particularly necessary to accurately evaluate the importance of each function package update. The evaluation needs to consider not only the content of the update itself but also weigh its potential impact scope in the entire dependency table. Through comprehensive evaluation, the update order of software function packages can be optimized to ensure that critical updates are processed first, thereby achieving continuous improvement and optimization of the software while ensuring system stability.
[0076] The present invention proposes an automatic update method, device, equipment, and storage medium for software function packages, which can calculate the update priority, automatically select the best update time, and reliably execute the update process, thereby improving the security, stability, and maintenance efficiency of the software system. To illustrate the role of the present invention, the effectiveness of the present invention will be described from the following embodiments.
[0077] Embodiment 1
[0078] As Figure 1 shown, an automatic update method for software function packages applied to the backend system of an e-commerce platform includes:
[0079] Set an update period, and scan the software repository at the beginning of each update period to obtain the installed function package dependency table and the list of packages to be updated;
[0080] Extract the update description of the software function package to be updated according to the to-be-updated list;
[0081] Analyze the update description, and extract the dependency change information, new function information, and defect repair information;
[0082] Update the installed function package dependency table according to the dependency change information to obtain the latest function package dependency table and calculate the dependency index of the software function package to be updated;
[0083] Construct a function package dependency graph according to the latest function package dependency table, and calculate the influence scope index of the software function package to be updated;
[0084] Calculate the functionality index and security index of the software function package to be updated according to the new function information and defect repair information;
[0085] Calculate the update priority score of the software function package to be updated according to the dependency index, the influence scope index, the functionality index, and the security index;
[0086] Determine the optimal update time window according to the historical load data of the software system;
[0087] In the optimal update time window, construct an update priority queue according to the update priority score for automatic update;
[0088] Record the update log and the running status of the updated software system, and adjust subsequent automatic updates.
[0089] The automatic update method of the software function package. First, set the update period and scan the software repository to obtain the installed function package dependency table and the to-be-updated list, which ensures the periodicity and systematicness of the update and reduces the risk of missing important updates; then, extract and analyze the update description of the software function package to be updated, which can accurately extract the key information of the update to calculate the dependency index, the influence scope index, the functionality index, and the security index, providing a basis for subsequent decision-making. Calculate the update priority score according to these indexes, making the update process more orderly and efficient, and ensuring the priority update of key function packages; in addition, automatically determine the optimal update time window, which can minimize the impact of the update on the normal operation of the system; in the optimal update time window, construct an update priority queue according to the update priority score for automatic update, realizing the automation of the update process and improving the efficiency; finally, record the update log and the running status of the software system, which helps to trace the details of the update process and achieve self-optimization, continuously improving the update quality.
[0090] Further, constructing the functional package dependency graph specifically includes: representing each software functional package as a node in the graph to obtain a graph node set V = {v1, v2, …, v n}, where v n represents the nth node in the graph node set; when the ith software functional package directly depends on the jth software functional package, it is represented as a directed edge from node v i to node v j ; representing the direct dependency relationship between every two different software functional packages as a directed edge to obtain a graph edge set where represents the mth edge in the graph edge set; creating a directed graph according to the graph node set and the graph edge set to obtain the functional package dependency graph G(V, E).
[0091] Representing the dependency relationship between software functional packages through a graph data structure intuitively shows the software system structure, facilitating understanding and analysis, more clearly reflecting the dependency direction between functional packages, helping to identify key software functional packages, and providing a basis for subsequent impact scope analysis and update decision-making.
[0092] Table 1 Functional Package Dependency Table
[0093] Function Package Name Dependent Function Package Name Authentication Encryption Library, Database Connector User Management Authentication, Notification Service Product Catalog Database Connector, Classification Manager Order Processing Product Catalog, Payment System, Inventory Management, Notification Service Payment System Encryption Library, Bank Interface, Payment Gateway Inventory Management Product Catalog, Database Connector Notification Service Message Queue, Email Sender, SMS Sender Recommendation Engine User Management, Product Catalog, Machine Learning Library
[0094] In the embodiment of the present application, in the current update cycle, part of the dependency relationships in the latest functional package dependency table of the e-commerce platform backend system are shown in Table 1. Figure 2Shows a partial structural schematic diagram of the corresponding functional package dependency graph. There is an edge respectively from the recommended engine functional package node to the user management functional package node, the product catalog functional package node, and the machine learning library functional package node, and there is a path respectively to the classification manager functional package node, the database connector functional package node, the notification service functional package node, the message queue functional package node, the SMS sender functional package node, and the email sender functional package node. There is a path respectively from the product catalog functional package node to the database connector functional package node and the classification manager functional package node. There is an edge respectively from the inventory management functional package node to the product catalog functional package node and the database connector functional package node, and there is a path to the classification manager functional package node. There is an edge respectively from the user management functional package node to the authentication functional package node and the notification service functional package node, and there is a path respectively between it and the encryption library functional package node, the database connector functional package node, the message queue functional package node, the SMS sender functional package node, and the email sender functional package node. There is an edge respectively from the authentication functional package node to the encryption library functional package node and the database connector functional package node. There is an edge respectively from the payment system functional package node to the encryption library functional package node, the bank interface functional package node, and the payment gateway functional package node. There is an edge respectively from the order processing functional package node to the product catalog functional package node, the payment system functional package node, the inventory management functional package node, and the notification service functional package node, and there is a path respectively to the encryption library functional package node, the payment gateway functional package node, the bank interface functional package node, the message queue functional package node, the SMS sender functional package node, and the email sender functional package node, there are two paths to the classification manager functional package node, and there are three paths to the database connector functional package node. There is an edge respectively from the notification service functional package node to the message queue functional package node, the SMS sender functional package node, and the email sender functional package node.
[0095] Further, the specific steps for calculating the influence scope index of the software functional package to be updated include:
[0096] Define an influence function between two nodes in the dependency graph and calculate the influence probability; the influence function is as follows:
[0097]
[0098] Wherein, P(v j , v i ) represents the influence probability of node v j on node v i ; E(v i , v j ) represents the set of path edges corresponding to a path from node v i to node v j in the dependency graph. When node vi To node v j When it is unreachable Indicates an empty set; Indicates the directed edge in the set of path edges that points to node v q ; λ represents the weight coefficient; frequency(v q ) represents the average historical update frequency of node v q ;
[0099] Extract the critical path between two nodes; the critical path is the path with the largest number of edges among all paths from node v i to node v j ;
[0100] According to the influence function and the critical path, calculate the influence range index of each software function package to be updated:
[0101]
[0102] Among them, W(u) represents the influence range index of node u; u represents the node corresponding to the software function package to be updated; represents the influence probability corresponding to the critical path from node a to node u; A represents the set of nodes that node u can reach,
[0103] The influence relationship between software function packages is quantified through the influence function, and the influence range of software function package updates is evaluated more accurately; by extracting the concept of the critical path, it helps to discover the software function package with the widest influence; calculating the influence range index provides a more comprehensive influence assessment and helps to optimize the update order.
[0104] Furthermore, the calculation methods of the dependency index, the functionality index, and the security index of the software function package to be updated are as follows:
[0105] The dependency index D = N d / N total ; where N d represents the number of software function packages that directly depend on the software function package to be updated; N total represents the total number of software function packages in the software system;
[0106] The functionality index F = (N f +N b ) / N max ; where N f represents the number of new functions of the software function package to be updated; N b represents the number of defects fixed in the software function package to be updated; N maxRepresents a predefined maximum reference value;
[0107] The security index S = CVSS_Score / 10; where CVSS_Score represents the severity level of the security vulnerabilities in the fixed defects of the software package to be updated.
[0108] The severity level of the fixed vulnerability is at least 0 and at most 10, which is calculated through a vulnerability scoring system based on the detailed information of the security vulnerability; if the update of the software package does not fix the security vulnerability, the security index is 0.
[0109] Methods for calculating the dependency degree, functionality, and security index are provided, quantifying each index, and the multi-dimensional update evaluation can comprehensively measure the necessity of the update; the dependency index reflects the importance of the package, which helps to prioritize the update of critical packages; the functionality index helps to evaluate the actual value of the update; the security index can evaluate the improvement of the overall system security by the update.
[0110] Further, the specific steps for determining the optimal update time window according to the historical load data of the software system include:
[0111] Collect the historical load data of the software system in the N update cycles before the current update cycle and perform preprocessing to obtain N historical load time series data;
[0112] Construct a comprehensive load index based on the historical load time series data and set a threshold for the comprehensive load index;
[0113] Divide each historical load time series data into m time windows and calculate the comprehensive load index of each time window;
[0114] Identify the time windows where the comprehensive load index is lower than the threshold of the comprehensive load index, traverse the N historical load time series data, and retain the time windows with a frequency of occurrence greater than h to obtain a set of low-usage time windows; h represents the frequency threshold;
[0115] Merge the consecutive time windows in the set of low-usage time windows to obtain M candidate optimal update time windows;
[0116] Construct a load data prediction model and train it with the historical load time series data;
[0117] Generate the predicted load time series data for the current update cycle through the trained load data prediction model;
[0118] Based on the predicted load time series data, calculate the comprehensive load metrics for each of the candidate best update time windows, and select the candidate best update time window with the lowest comprehensive load metric as the best update time window for the current update cycle.
[0119] In the embodiments of the present application, the comprehensive load metric is the normalized weighted sum of the key load data of the software system; the key load data includes the number of active users, CPU usage rate, memory usage rate, and network bandwidth usage rate.
[0120] Considering the historical data of multiple update cycles, the accuracy of the selection of the best update time window is improved based on the historical data and the load data prediction model; identifying low-usage time windows is selected to minimize the impact on the system; in addition, the load data prediction model considers future load changes, making the selection of the best update time window forward-looking.
[0121] Further, the specific steps for constructing the update priority queue according to the update priority score for automatic update include:
[0122] S1. Calculate the update priority scores of all currently pending software function packages to be updated, and create the update priority queue Q of the software function packages to be updated in descending order;
[0123] The calculation formula for the update priority score is as follows:
[0124] PS(k) = w1 * I1(k) + w2 * I2(k) + w3 * I3(k) + w4 * I4(k);
[0125] Wherein, I1(k), I2(k), I3(k), and I4(k) respectively represent the normalized values of the dependency metric, the influence range metric, the functionality metric, and the security metric of the k-th software function package to be updated; w1, w2, w3, and w4 represent the weights of each metric;
[0126] S2. Collect the current system resource status, determine the total available resources R, and estimate the required resources r(k) for each software function package to be updated;
[0127] S3. Construct a constraint condition based on the total available resources and the required resources, and apply a dynamic programming algorithm under the constraint condition to maximize the objective function, and divide the update priority queue into a selected priority queue and an unselected priority queue; the constraint condition is ∑ k∈Q (r(k) * x(k)) ≤ R; the objective function is ∑ k∈Q(PS(k)*x(k)); where x(k) represents an indicator function, and the values of x(k) are 1 and 0, indicating the selection and non-selection of the k-th software function package to be updated; the selected priority queue consists of the software function packages to be updated with x(k) having a value of 1; the unselected priority queue consists of the software function packages to be updated with x(k) having a value of 0;
[0128] S4. Update the software function packages to be updated in the selected priority queue in sequence;
[0129] S5. When the best update time window has not ended and the unselected priority queue is not empty, replace the update priority queue with the unselected priority queue and return to step S2; when the best update time window has ended and the unselected priority queue is not empty, the software function packages to be updated that have not been updated are automatically updated in the best update time window of the next update cycle.
[0130] The calculation of the update priority score comprehensively considers multiple factors and can achieve a more scientific priority ranking of software function packages; the dynamic programming algorithm is used to maximize the update benefit under resource constraints; through dynamic programming and the update priority queue, the update process is made intelligent and automated, which not only ensures the orderly progress of the update but also improves the utilization efficiency of system resources, thereby enhancing the stability and efficiency of the entire update process.
[0131] Further, the weights of the indicators in the update priority score are adaptively adjusted weights, and the adjustment steps are as follows:
[0132] Assign initial weight values to the dependency indicator, the influence scope indicator, the functionality indicator, and the security indicator;
[0133] After each update cycle ends, calculate the update effect score; the update effect score is calculated based on the update log and the running state of the software system after the update;
[0134] After every C update cycles end, calculate the difference between the current update effect score and the historical update effect score to obtain the update effect score difference; the historical update effect score is the average of the update effect scores of all completed update cycles;
[0135] According to the update effect score difference, adjust the weights of the indicators, and the formula is as follows:
[0136] w′ i =w i +α*(|γ i | / ∑|γ i |-w i )*sign(ΔES);
[0137] Among them, w′ i and w i are the adjusted i-th weight and the i-th weight before adjustment respectively, where i = 1, 2, 3, 4, corresponding to 4 indicators used for updating priority calculation; α is the learning rate, used to control the adjustment amplitude; γ i is the Pearson correlation coefficient between the indicator corresponding to the weight w i in the updated priority score and the update effect score; ΔES represents the update effect score difference; sign represents the sign function, which is 1 when ΔES > 0, -1 when ΔES < 0, and 0 when ΔES = 0;
[0138] Apply the adjusted weight to the calculation of the updated priority score in the subsequent update cycle.
[0139] Furthermore, the calculation steps of the Pearson correlation coefficient are as follows:
[0140] Obtain the C indicators I i corresponding to the C weights w i in C update cycles, and calculate the average value
[0141] Obtain the C update effect scores ES in C update cycles and calculate the average value
[0142] Calculate the covariance of I i and ES where, I i,c represents the indicator corresponding to the weight w i in the c-th update cycle; ES c represents the update effect score in the c-th update cycle;
[0143] Calculate the standard deviation of I i and the standard deviation of ES and
[0144] Calculate the Pearson correlation coefficient
[0145] By continuously adjusting the weights, the calculation of the updated priority score can better adapt to the dynamic changes of the system, which helps to improve the long-term effect of automatic updates; adjusting the weights according to the actual update effect makes the update process more in line with the actual operation requirements, enhancing the stability and reliability of the system; adjusting the weights according to the update effect score difference can achieve self-optimization of the update process; moreover, the Pearson correlation coefficient can reflect the linear correlation degree between each indicator and the update effect score, and can accurately adjust the weights targeted.
[0146] Embodiment 2
[0147] As shown Figure 3 in the figure, the present invention also provides an automatic update device for software function packages, including:
[0148] An information collection module scans the software repository, obtains a list of dependencies of installed function packages and a list of packages to be updated, extracts update descriptions of software function packages to be updated according to the list of packages to be updated, and analyzes the update descriptions to extract dependency change information, new function information, and defect repair information;
[0149] A dependency analysis module obtains a list of dependencies of the latest function packages and calculates a dependency index according to the dependency change information and the list of dependencies of installed function packages; constructs a function package dependency graph according to the list of dependencies of the latest function packages, and calculates the influence range index of the function packages to be updated;
[0150] A function analysis module calculates a functionality index according to the new function information and the defect repair information;
[0151] A security analysis module calculates a security index according to the defect repair information;
[0152] An update planning module includes an update time planning unit and an update priority planning unit; the update time planning unit determines the best update time window according to the historical load data of the software system; the update priority planning unit calculates an update priority score according to the dependency index, the influence range index, the functionality index, and the security index, and constructs an update priority queue according to the update priority score;
[0153] An update execution module performs automatic updates based on the update priority queue using dynamic programming during the best update time window.
[0154] Further, constructing the function package dependency graph specifically includes: representing each software function package as a node in the graph to obtain a graph node set V = {v1, v2,..., v n}, v n represents the nth node in the graph node set; when the ith software function package directly depends on the jth software function package, it is represented as a directed edge from node v i to node v j ; representing the direct dependency relationship between every two different software function packages as a directed edge to obtain a graph edge set represents the mth edge in the graph edge set; creating a directed graph according to the graph node set and the graph edge set to obtain the function package dependency graph G(V, E).
[0155] Further, the specific steps for calculating the influence scope index of the software function package to be updated include:
[0156] Define the influence function between two nodes in the dependency graph and calculate the influence probability; the influence function is as follows:
[0157]
[0158] where P(v j , v i ) represents the influence probability of node v j on node v i ; E(v i , v j ) represents the set of path edges corresponding to a path from node v i to node v j in the dependency graph. When node v i is inaccessible to node v j , it represents an empty set; represents the directed edge pointing to node v q in the set of path edges; λ represents the weight coefficient; frequency(v q ) represents the average historical update frequency of node v q .
[0159] Extract the critical path between two nodes; the critical path is the path with the largest number of edges among all paths from node v i to node v j .
[0160] According to the influence function and the critical path, calculate the influence scope index of each software function package to be updated:
[0161]
[0162] where W(u) represents the influence scope index of node u; u represents the node corresponding to the software function package to be updated; represents the influence probability corresponding to the critical path from node a to node u; A represents the set of nodes that node u can reach,
[0163] Further, the calculation method of the dependency index of the software function package to be updated is: the dependency index D = N d / N total ; where N d represents the number of software function packages directly dependent on the software function package to be updated; N total represents the total number of software function packages in the software system.
[0164] Further, the calculation method of the functional index of the software function package to be updated is: the functional index F = (N f + N b ) / N max ; where N f represents the number of new functions in the function package to be updated; N b represents the number of fixed defects in the software function package to be updated; N max represents a predefined maximum reference value.
[0165] Further, the calculation method of the security index of the software function package to be updated is: the security index S = CVSS_Score / 10; where CVSS_Score represents the severity level of security vulnerabilities in the fixed defects of the software function package to be updated.
[0166] Further, the specific steps for determining the optimal update time window according to the historical load data of the software system include:
[0167] Collect the historical load data of the software system for N update cycles before the current update cycle and perform preprocessing to obtain N historical load time series data;
[0168] Construct a comprehensive load index based on the historical load time series data and set a comprehensive load index threshold;
[0169] Divide each historical load time series data into m time windows and calculate the comprehensive load index of each time window;
[0170] Identify the time windows where the comprehensive load index is lower than the comprehensive load index threshold, traverse the N historical load time series data, and retain the time windows with a frequency of occurrence greater than h to obtain a set of low-usage time windows; h represents the frequency threshold;
[0171] Merge the consecutive time windows in the set of low-usage time windows to obtain M candidate optimal update time windows;
[0172] Construct a load data prediction model and train it with the historical load time series data;
[0173] Generate the predicted load time series data for the current update cycle through the trained load data prediction model;
[0174] According to the predicted load time series data, calculate the comprehensive load index of each candidate optimal update time window, and select the candidate optimal update time window with the lowest comprehensive load index as the optimal update time window for the current update cycle.
[0175] Further, calculating the update priority score and constructing an update priority queue according to the update priority score specifically includes: calculating the update priority scores of all currently to-be-updated software function packages, and creating the update priority queue Q of the to-be-updated software function packages in descending order; the calculation formula of the update priority score is as follows:
[0176] PS(k) = w1·I1(k) + w2·I2(k) + w3·I3(k) + w4·I4(k);
[0177] Wherein, I1(k), I2(k), I3(k), and I4(k) respectively represent the normalized values of the dependency index, the influence range index, the functionality index, and the security index of the k-th to-be-updated software function package; w1, w2, w3, and w4 represent the weights of each index.
[0178] Further, the specific steps of applying dynamic programming for automatic update based on the update priority queue include:
[0179] Collect the current system resource status, determine the total available resources R, and estimate the required resources r(k) for each to-be-updated software function package;
[0180] Construct a constraint condition according to the total available resources and the required resources, and apply the dynamic programming algorithm to maximize the objective function under the constraint condition, dividing the update priority queue into a selected priority queue and an unselected priority queue; the constraint condition is ∑ k∈Q (r(k)*x(k)) ≤ R; the objective function is ∑ k∈Q (PS(k)*x(k)); wherein, x(k) represents an indicator function, and the value of x(k) is 1 and 0, indicating whether to select or not select the k-th to-be-updated software function package; the selected priority queue consists of the to-be-updated software function packages with x(k) taking the value of 1; the unselected priority queue consists of the to-be-updated software function packages with x(k) taking the value of 0;
[0181] Update the to-be-updated function packages in the selected priority queue in sequence;
[0182] When the best update time window has not ended and the unselected priority queue is not empty, replace the update priority queue with the unselected priority queue and repeat all steps; when the best update time window ends and the unselected priority queue is not empty, the unupdated to-be-updated software function packages are automatically updated in the best update time window of the next update cycle.
[0183] Embodiment III
[0184] AsFigure 4 As shown in the figure, the present invention further provides a computer device 1, including a receiver 12, a processor 13 and a memory 14; the receiver 12, the processor 13 and the memory 14 complete communication with each other through a communication bus 11; the receiver 12 is used to execute the commands of the processor 13, the memory 14 is used to store computer programs, and when the processor 13 executes the computer programs, it realizes the automatic update method of the software function package according to any one of the first embodiment.
[0185] The receiver 12 obtains the installed function package dependency table and the list to be updated, and calculates the update priority score of the software function package to be updated by executing the computer program in the memory 14 through the processor 13; the receiver 12 obtains the historical load data of the software system, and determines the optimal update time window by executing the computer program in the memory 14 through the processor 13; at the optimal update time window, the receiver 12 obtains the update priority score through the communication bus 11, and performs automatic update of the software function package by executing the computer program in the memory 14 through the processor 13; the receiver 12 obtains the update log and the running state of the updated software system, and adjusts subsequent updates by executing the computer program in the memory 14 through the processor 13.
[0186] The communication bus 11 mentioned in the computer device 1 may be an external component interconnect standard (Peripheral Component-Interconnect, abbreviated as PCI) bus or an extended industry standard architecture (Extended Indistry Standard-Architecture, abbreviated as EISA) bus, etc. This communication bus 11 can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation Figure 4 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus;
[0187] The communication bus 11 is used for communication between the above-mentioned computer device 1 and other devices.
[0188] The memory 14 may be a read-only memory (Read Only Memory, abbreviated as ROM) or other types of static storage devices that can store static information and instructions, or a random access memory (Random Access Memory, abbreviated as RAM) or other types of dynamic storage devices that can store information and instructions, or other media that can be used to carry or store desired program codes in the form of instructions or data structures and can be stored by a computer, but is not limited thereto.
[0189] The processor 13 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0190] The computer device 1 includes, but is not limited to, mobile terminals such as laptop computers and tablet computers (referred to as PADs), and also includes fixed terminals such as desktop computers, and also includes servers in data centers, etc. Figure 4 This is only an example and should not impose any restrictions on the functions and usage scope of this common embodiment.
[0191] Embodiment 4
[0192] The present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the automatic update method of the software function package in the above Embodiment 1; as Figure 4 shown, the computer-readable storage medium is the memory 14, which is used to store the computer program 15 and is executed by the processor 13.
[0193] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present invention are generated in whole or in part. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, or data center to another website, computer, or data center in a wired manner (such as, but not limited to, optical fiber, etc.) or a wireless manner (such as, but not limited to, infrared, wireless, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as, but not limited to, a floppy disk, a hard disk, etc.), an optical medium (such as, but not limited to, a DVD), etc.
[0194] Although embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for automatically updating a software function package, characterized in that: include: Set an update cycle, scan the software repository at the beginning of each update cycle, and obtain the dependency table of installed function packages and the list to be updated; Extract the update description of the software function package to be updated according to the list to be updated; Analyze the update notes to extract dependency change information, new feature information, and bug fix information; Update the dependency table of the installed function package according to the dependency change information, obtain the latest function package dependency table and calculate the dependency index D=N of the software function package to be updated d / N total ; Among them, N d Indicates the number of software function packages that directly depend on the software function package to be updated; N total Indicates the total number of software function packages in the software system; According to the latest function package dependency table, a function package dependency graph is constructed, and the impact range index of the software function package to be updated is calculated. The specific steps include: defining the impact function between two nodes in the dependency graph and calculating the impact probability; the impact function is: Among them, P(v j ,v i ) represents node v j For node v i The probability of influence; E(v i ,v j ) represents the node v in the dependency graph i To node v j The path edge set corresponding to a path of i To node v j When unreachable represents the empty set; Indicates the path edge set pointing to node v q The directed edge of q ) represents node v q The average historical update frequency; extract the key path between two nodes; the key path is node v i To node v j Among all the paths, the one with the largest number of edges; according to the impact function and the key path, calculate the impact range index of each function package to be updated: Wherein, W(u) represents the influence range index of node u; u represents the node corresponding to the software function package to be updated; represents the impact probability corresponding to the critical path from node a to node u; A represents the set of nodes that node u can reach, According to the new function information and defect repair information, calculate the functional index F of the software function package to be updated = (N f +N b ) / N max And security index S = CVSS_Score / 10; where N f and N b Respectively represent the number of new functions and the number of defects fixed in the software function package to be updated; N max Indicates the predefined maximum reference value; CVSS_Score indicates the severity level of the security vulnerability in the fixed defect of the software function package to be updated; Calculate the update priority score of the software function package to be updated based on the dependency index, impact scope index, functionality index and security index; Determine the optimal update time window based on the historical load data of the software system; In the optimal update time window, an update priority queue is built according to the update priority score for automatic update; Record the update log and the running status of the updated software system, and adjust subsequent automatic updates.
2. The automatic updating method of a software function package according to claim 1, characterized in that: Constructing the function package dependency graph specifically includes: representing each software function package as a node in the graph, obtaining a graph node set V = {v1, v2, ..., v n },v n represents the nth node in the graph node set; when the i-th software function package directly depends on the j-th software function package, it is represented as node v i Points to node v j A directed edge; the direct dependency relationship between each two different software function packages is represented as a directed edge, and the graph edge set is obtained Represents the mth edge in the graph edge set; creates a directed graph based on the graph node set and the graph edge set to obtain the function package dependency graph G(V,E).
3. The automatic updating method of a software function package according to claim 1, characterized in that: The specific steps of determining the optimal update time window according to the historical load data of the software system include: Collect and pre-process the software system historical load data of N update cycles before the current update cycle to obtain N historical load time series data; Constructing a comprehensive load index based on the historical load time series data and setting a comprehensive load index threshold; Divide each of the historical load time series data into m time windows, and calculate the comprehensive load index of each time window; Identify the time window where the comprehensive load index is lower than the comprehensive load index threshold, traverse N historical load time series data, retain the time window with an occurrence frequency greater than h, and obtain a low utilization time window set; h represents the occurrence frequency threshold; Merging consecutive time windows in the low-usage time window set to obtain M candidate optimal update time windows; Constructing a load data prediction model and training it using the historical load time series data; Generate predicted load time series data of the current update period by using the trained load data prediction model; According to the predicted load time series data, the comprehensive load index of each candidate optimal update time window is calculated, and the candidate optimal update time window with the lowest comprehensive load index is selected as the optimal update time window of the current update cycle.
4. The automatic updating method of a software function package according to claim 1, characterized in that: The specific steps of constructing the update priority queue for automatic updating according to the update priority score include: S1. Calculate the update priority scores of all current software function packages to be updated, and create the update priority queue Q of the software function packages to be updated in descending order; The update priority score calculation formula is as follows: PS(k)=w1*I1(k)+w2*I2(k)+w3*I3(k)+w4*I4(k); Wherein, PS(k) represents the update priority score; I1(k), I2(k), I3(k) and I4(k) respectively represent the normalized values of the dependency index, the impact range index, the functional index and the security index of the kth software function package to be updated; w1, w2, w3 and w4 represent the weights of each index; S2. Collect the current system resource status, determine the total available resources R, and estimate the required resources r(k) for each software function package to be updated; S3. Construct constraints based on the total available resources and the required resources, apply a dynamic programming algorithm to maximize the objective function under the constraints, and divide the update priority queue into a selected priority queue and an unselected priority queue; the constraints are ∑ k∈Q (r(k)*x(k))≤R; the objective function is ∑ k∈Q (PS(k)*x(k)); wherein x(k) represents an indicator function, and the values of x(k) are 1 and 0, indicating the selection and non-selection of the kth software function package to be updated; the selected priority queue is composed of the software function packages to be updated whose values of x(k) are 1; the unselected priority queue is composed of the software function packages to be updated whose values of x(k) are 0; S4. Update the function packages to be updated in the selected priority queue in order; S5. When the optimal update time window has not ended and the unselected priority queue is not empty, replace the update priority queue with the unselected priority queue and return to step S2; when the optimal update time window has ended and the unselected priority queue is not empty, the unupdated software function package to be updated is automatically updated in the optimal update time window of the next update cycle.
5. The automatic updating method of the software function package according to claim 4, characterized in that: The weight of each indicator in the update priority score is the weight of adaptive adjustment, and the adjustment steps are as follows: Assigning initial weight values to the dependency index, the impact range index, the functionality index, and the security index; After each update cycle, calculate the update effect score; The update effect score is calculated based on the update log and the running status of the software system after the update; After each of the C update cycles, the difference between the current update effect score and the historical update effect score is calculated to obtain the update effect score difference; the historical update effect score is the average update effect score of all the completed update cycles; According to the difference in the update effect scores, the weight of each indicator is adjusted; The adjusted weight is applied to the calculation of the update priority score in subsequent update cycles.
6. An automatic updating device for a software function package, characterized in that: include: The information collection module scans the software warehouse to obtain the dependency table of installed function packages and the list to be updated, extracts the update instructions of the software function packages to be updated according to the list to be updated, and analyzes the update instructions to extract dependency change information, new function information and defect repair information; The dependency analysis module obtains the latest function package dependency table and calculates the dependency index D=N according to the dependency change information and the installed function package dependency table. d / N total ; Among them, N d Indicates the number of software function packages that directly depend on the software function package to be updated; N total Represents the total number of software function packages in the software system; constructs a function package dependency graph based on the latest function package dependency table, and calculates the impact range index of the function package to be updated. The specific steps include: defining the impact function between two nodes in the dependency graph and calculating the impact probability; the impact function is: Among them, P(v j ,v i ) represents node v j For node v i The probability of influence; E(v i ,v j ) represents the node v in the dependency graph i To node v j The path edge set corresponding to a path of i To node v j When unreachable represents the empty set; Indicates the path edge set pointing to node v q The directed edge of q ) represents node v q The average historical update frequency; extract the key path between two nodes; the key path is node v i To node v j Among all the paths, the one with the largest number of edges; according to the impact function and the key path, calculate the impact range index of each function package to be updated: Where W(u) represents the influence range index of node u; u represents the node corresponding to the software function package to be updated; represents the impact probability corresponding to the critical path from node a to node u; A represents the set of nodes that node u can reach, Functional analysis module, calculates the functional index F=(N f +N b ) / N max ; Among them, N f and N b Respectively represent the number of new functions and the number of defects fixed in the software function package to be updated; N max Indicates a predefined maximum reference value; The security analysis module calculates the security index S=CVSS_Score / 10 according to the defect repair information; wherein CVSS_Score represents the severity level of the security vulnerability in the repair defect of the software function package to be updated; The update planning module includes an update time planning unit and an update priority planning unit. The update time planning unit determines the optimal update time window based on the historical load data of the software system. The update priority planning unit calculates the update priority score based on the dependency index, impact range index, functional index and security index, and builds an update priority queue based on the update priority score. The update execution module automatically updates in the optimal update time window based on the update priority queue using dynamic programming.
7. A computer device comprising a memory and a processor, characterized in that: The memory stores a computer program that can be run on the processor, and when the program is executed on the processor, the steps in the automatic update method of the software function package as claimed in any one of claims 1 to 5 are implemented.
8. A storage medium having computer program instructions stored thereon, characterized in that: When the computer program is executed by a processor, the steps in the method for automatically updating the software function package according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Running program remote dynamic updating method
CN117971271A
Method and system for automatically upgrading operating system patch
CN118963779A