Analysis and Control System for Security Vulnerabilities and Potential Risks of Software Open-Source Components
By analyzing the management and control system to detect and repair security vulnerabilities in software open source components in real time, it solves the complex and time-consuming problem of vulnerability repair after development, and improves security vulnerability handling efficiency and software security.
Patent Information
- Application Number
- CN202411612965.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-13
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-11-13
AI Technical Summary
In the prior art, when security vulnerabilities occur after software development are completed, the repair operation is complex and time-consuming, resulting in large additional losses and many subsequent security vulnerabilities.
Provides an analysis and control system for security vulnerabilities and potential risks of software open source components, including data collection, storage, detection, repair processing and monitoring early warning modules, detect and predict potential risks in real time, provide repair suggestions, and improve the security detection efficiency in the development stage.
Through real-time detection and repair, the impact range of security vulnerabilities is reduced, the security and efficiency in the software development process is improved, and the loss at the source of development is reduced.
Smart Images

Figure CN119538264B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of risk analysis and control, and specifically to an analysis and control system for software open-source component security vulnerabilities and potential risks. Background Art
[0002] With the rapid development of the software industry, the software supply chain has become increasingly complex and diverse. The complex software supply chain introduces a series of security problems, making the overall security protection of information systems more and more difficult. Security attack events against the software supply chain have been growing rapidly, and the resulting harm has become more and more serious. There is an urgent need for security protection against software supply chain risks.
[0003] Referring to the patent with the title: A Method and System for Detecting Vulnerabilities in Open-Source Components (Patent Publication No.: CN117610010A, Patent Publication Date: February 27, 2024), the method for detecting vulnerabilities in open-source components includes: extracting the open-source components to be detected and their corresponding version information; comparing the known vulnerability database with the code data information of the open-source components to obtain known vulnerability information; using a code analysis tool to analyze the code data information of the open-source components for potential vulnerability information to obtain potential vulnerability information; setting a regular detection time interval according to the data information of the known vulnerability information and potential vulnerability information, and performing regular security detection on the open-source components to be detected according to the regular detection time interval.
[0004] Based on the description of the above document, existing software is often released after development. When security vulnerabilities occur later, the technical repair operations are relatively complex, the additional losses caused by the vulnerabilities are relatively large, and there are many subsequent security funnel problems. When performing security vulnerability repair operations based on software projects, each vulnerability requires a new repair operation, which will cause the repair time to become longer. Therefore, the present invention provides an analysis and control system for software open-source component security vulnerabilities and potential risks. Summary of the Invention
[0005] Aiming at the deficiencies of the prior art, the present invention provides an analysis and control system for software open-source component security vulnerabilities and potential risks, which solves the problems that existing software is often released after development, and when security vulnerabilities occur later, the technical repair operations are relatively complex, the additional losses caused by the vulnerabilities are relatively large, and there are many subsequent security funnel problems. When performing security vulnerability repair operations based on software projects, each vulnerability requires a new repair operation, which will cause the repair time to become longer.
[0006] To achieve the above objectives, the present invention is realized through the following technical solutions: An analysis and control system for software open-source component security vulnerabilities and potential risks, including:
[0007] The data acquisition module realizes the acquisition of information data of open-source components in a software project, and acquires and stores the data of known security vulnerabilities with authentication.
[0008] The data repository realizes the storage of the acquired data and the subsequent data for control and processing.
[0009] The security vulnerability detection module performs a preliminary screening operation on the data, constructs a software monitoring model based on the initial open-source component data in the data repository, and performs operations of reducing, increasing, or modifying the data based on the software monitoring model. It detects the occurrence of vulnerabilities during the operation in real time, synchronously predicts potential risks, and feeds back the situation generated by the operation.
[0010] The repair processing module performs corresponding processing on the detected security vulnerability situation, or provides corresponding repair suggestions or solutions.
[0011] The monitoring and warning module realizes the real-time monitoring of the usage of various open-source components in the software project, and warns and notifies the maintenance personnel when security vulnerabilities and potential risks occur.
[0012] The user interface is used for the user to view the information during the operation process and directly feedback the information processing flow.
[0013] Preferably, the operation of preliminarily screening the data in the security vulnerability detection module is as follows:
[0014] A1. After receiving the data, perform a preliminary classification operation according to the required data categories.
[0015] A2. The initial open-source component information used in the software project is summarized into an initial open-source component data set labeled as M, the data used by the software project in real time subsequently is summarized into an updated data set labeled as N, and the data of known security vulnerabilities with authentication is summarized into a known security vulnerability data set labeled as L.
[0016] A3. Perform subsequent use according to the classified data sets.
[0017] Preferably, the operation of evaluating the dependency situation of the initial open-source component data set M is as follows:
[0018] a21. Arbitrarily select an initial open-source component data subset, and find the dependent and dependent open-source component data subsets based on the first initial open-source component data subset.
[0019] a22. Based on the dependent open-source component data subset, continue to find the dependent and dependent open-source component data subsets related to the current subset. Based on the dependent open-source component data subset, continue to find the dependent and dependent open-source component data subsets related to the current subset.
[0020] a23. Extract the starting dependent open source component data subset with the first initial open source component data subset as the node, and at the same time reorder the data subsets in the initial open source component data set M according to the dependency relationship order.
[0021] Preferably, the operation of constructing the software monitoring model based on the data in the data repository in the security vulnerability detection module is as follows:
[0022] B1. Introduce the reordered initial open source component data set M, and perform a compliance audit operation on the licenses of each open source component through the system's inspection tool;
[0023] B2. Induce and construct the open source components that meet the requirements to form a software monitoring model, and then introduce the real-time operation data into the software monitoring model for dynamic preview.
[0024] Preferably, the security vulnerability detection step for performing data reduction, addition, or modification operations based on the software monitoring model in the security vulnerability detection module is as follows:
[0025] C1. Introduce the updated data set N into the software monitoring model, and perform data detection operations on the open source components in sequence according to the dependency relationship;
[0026] C2. Scan the data after the open source components run, and mark the data parts with abnormal changes. At the same time, extract the abnormal change data and compare it with the security vulnerability data set L. The same data after comparison is classified as known abnormal vulnerability data, and the different data after comparison is classified as unknown abnormal vulnerability data;
[0027] C3. Transmit the known abnormal vulnerability data and unknown abnormal vulnerability data to the repair processing module for processing, so as to judge the potential risks of continuing the operation.
[0028] Preferably, the expression for comparing the abnormal change data with the security vulnerability data set L in C2 is:
[0029]
[0030] F represents the judgment result of the abnormal change data, n∩L represents the intersection comparison operation between the abnormal change data and the security vulnerability data set L, n represents the extracted abnormal change data, p is the known abnormal vulnerability data, and q is the unknown abnormal vulnerability data.
[0031] Preferably, the processing of transmitting the abnormal change data and the security vulnerability data set L to the repair processing module in C3 is as follows:
[0032] c21. Extract the subset of security vulnerability data corresponding to the detected open-source component from the security vulnerability dataset L according to the detected open-source component;
[0033] c22. When processing based on the known abnormal vulnerability data p, trace the corresponding repair data according to the security vulnerability dataset L, and introduce the repair data into the software monitoring model for repair operations;
[0034] c23. When processing based on the unknown abnormal vulnerability data q, formulate corresponding repair steps according to the impact of the data for repair operations.
[0035] Preferably, the corresponding repair steps formulated in c23 are as follows:
[0036] D1. Extract the abnormal vulnerability data q and the optimization data y in the corresponding operations, and determine whether to replace the updated data according to the weight ratio of the abnormal vulnerability data q and the optimization data y;
[0037] D2. Then prioritize the impact range of the abnormal vulnerability data q, and perform operations to modify the introduced data corresponding to the abnormal vulnerability data q, and then introduce the modified data into the software monitoring model for re-detection;
[0038] D3. Continuously update and iterate for the operation in D2 until the abnormal vulnerability data is repaired and then subsequent project updates can be performed.
[0039] Preferably, the step of determining whether to replace the updated data according to the weight ratio in D1 is: Determine the weight ratio of the abnormal vulnerability data q and the optimization data y based on the software monitoring model. When the beneficial weight ratio of the optimization data y is greater than the loss weight ratio of the abnormal vulnerability data q, the current data update operation meets the construction requirements of the software project.
[0040] Preferably, the operation of modifying the introduced data corresponding to the abnormal vulnerability data q in D2 is:
[0041] d21. Trace the introduced data part based on the abnormal vulnerability data q, and perform patch insertion or data modification operations on the data part according to the situation of the vulnerability;
[0042] d22. Then perform detection after introducing it into the software monitoring model. After ensuring that the updated model has no security vulnerabilities, introduce the previous abnormal vulnerability data q for repair verification operations, and perform subsequent operations after no problems.
[0043] The present invention provides an analysis and control system for software open-source component security vulnerabilities and potential risks. Compared with the prior art, it has the following beneficial effects:
[0044] (1) The analysis and control system for software open-source component security vulnerabilities and potential risks preliminarily screens data through a security vulnerability detection module, constructs a software monitoring model based on the initial open-source component data in the data repository, performs operations of reducing, adding, or modifying data based on the software monitoring model, detects the occurrence of vulnerabilities during the operation in real time, synchronously predicts potential risks, and feeds back the situations generated by the operation, so as to perform corresponding security detections during the software development stage, promptly handle security vulnerabilities and potential risks, thereby assisting developers to significantly reduce software security problems and improve the analysis and control efficiency of potential risks of security vulnerabilities.
[0045] (2) The analysis and control system for software open-source component security vulnerabilities and potential risks scans the data after the open-source components run by introducing an updated data set into the software monitoring model, marks the data parts with abnormal changes, extracts the abnormal change data and compares it with the security vulnerability data set L at the same time. After comparison, the same data is classified as known abnormal vulnerability data, and the different data is classified as unknown abnormal vulnerability data, and a repair processing module is used for repair operations. Thus, the known abnormal vulnerability data is directly traced back for quick repair operations, and specific repair methods are formulated for the unknown abnormal vulnerability data for processing, so as to improve the efficiency of handling software open-source component security vulnerabilities and the security of the formed software.
[0046] (3) The analysis and control system for software open-source component security vulnerabilities and potential risks traces back the introduced data part based on the abnormal vulnerability data q, inserts patches or modifies the data part according to the situation of the vulnerability, and then performs detection after introducing it into the software monitoring model. After ensuring that the updated model has no security vulnerabilities, the previous abnormal vulnerability data q is introduced for repair verification operations, so as to ensure that staged security vulnerability handling operations are maintained during the development process, and reduce the losses at the development source while improving security. Description of the Drawings
[0047] Figure 1 It is the principle block diagram of the analysis and control system of the present invention;
[0048] Figure 2 It is the preliminary screening operation flowchart of the security vulnerability detection module of the present invention;
[0049] Figure 3 It is the software monitoring model construction operation flowchart of the security vulnerability detection module of the present invention;
[0050] Figure 4 It is the security vulnerability detection operation flowchart of the security vulnerability detection module of the present invention. Detailed Embodiments
[0051] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0052] Please refer to Figures 1 - 4 , the present invention provides two technical solutions:
[0053] Embodiment 1. An analysis and control system for software open-source component security vulnerabilities and potential risks, including:
[0054] A data collection module that realizes the collection of information data of open-source components in a software project, and collects and stores the known security vulnerability data with authentication.
[0055] A data repository that realizes the storage of the collected data and the subsequent controlled processing data.
[0056] A security vulnerability detection module that performs a preliminary screening operation on the data, constructs a software monitoring model based on the initial open-source component data in the data repository, and performs operations of reducing, increasing, or modifying the data based on the software monitoring model, detects the occurrence of vulnerabilities in real time during the operation, synchronously predicts potential risks, and feeds back the situations generated by the operation.
[0057] A repair processing module that correspondingly processes the detected security vulnerability situations or provides corresponding repair suggestions or solutions.
[0058] A monitoring and early warning module that realizes the real-time monitoring of the usage situations of various open-source components in a software project, and issues an early warning notice to the maintenance personnel when security vulnerabilities and potential risks occur.
[0059] A user interface for the user to view the information during the operation process and directly feedback the information processing process.
[0060] The monitoring and early warning module has a real-time monitoring function, can dynamically track the update situations of open-source components, and issue an early warning notice in time when new security vulnerabilities or potential risks are found. This mechanism helps developers respond to security issues in time and reduce the influence scope of security risks.
[0061] Moreover, the user interface provides an intuitive and easy-to-use user interface, which is convenient for users to view security vulnerability and potential risk information, as well as repair suggestions and solutions. This design reduces the learning cost of users and improves the usability and user experience of the system.
[0062] Among them, by setting up a security vulnerability detection module, preliminary screening operations are performed on the data, and based on the initial open-source component data in the data repository, the construction operation of the software monitoring model is implemented. Operations such as data reduction, addition, or modification are performed based on the software monitoring model, and the generation of vulnerabilities during the operations is detected in real time, and potential risks are synchronously predicted. The situations generated by the operations are fed back, so that corresponding security detections are carried out during the development stage of the application software, and security vulnerabilities and potential risks are processed in a timely manner, thereby assisting developers to significantly reduce software security problems and improve the analysis and control efficiency of potential risks of security vulnerabilities.
[0063] In the embodiment of the present invention, the operation of preliminary screening of data in the security vulnerability detection module is as follows:
[0064] A1. After receiving the data, perform preliminary classification operations according to the required data categories;
[0065] A2. The initial open-source component information used in the software project is summarized into the initial open-source component data set labeled as M, the data used in the software project in real time subsequently is summarized into the updated data set labeled as N, and the known security vulnerability data with authentication is summarized into the known security vulnerability data set labeled as L;
[0066] A3. Perform subsequent use according to the classified data sets.
[0067] In the embodiment of the present invention, the operation of evaluating the dependency situation of the initial open-source component data set M is as follows:
[0068] a21. Arbitrarily select an initial open-source component data subset, and find the dependent and dependent open-source component data subsets based on the first initial open-source component data subset;
[0069] a22. Based on the dependent open-source component data subset, continue to find the dependent and dependent open-source component data subsets related to the current subset, and based on the dependent open-source component data subset, continue to find the dependent and dependent open-source component data subsets related to the current subset;
[0070] a23. Extract the starting dependent open-source component data subset with the first initial open-source component data subset as the node, and at the same time reorder the data subsets in the initial open-source component data set M according to the dependency relationship order.
[0071] In the embodiment of the present invention, the operation of implementing the software monitoring model construction based on the data in the data repository in the security vulnerability detection module is as follows:
[0072] B1. Introduce the reordered initial open-source component data set M, and perform compliance audits on the licenses of each open-source component through the system's inspection tools;
[0073] B2. Induce and construct the open-source components that meet the requirements to form a software monitoring model, and then introduce real-time operation data into the software monitoring model for dynamic preview.
[0074] In the embodiment of the present invention, the steps of detecting security vulnerabilities based on the software monitoring model for data reduction, addition, or modification in the security vulnerability detection module are as follows:
[0075] C1. Introduce the updated data set N into the software monitoring model, and perform data detection operations on the open-source components in sequence according to the dependency relationship;
[0076] C2. Scan the data after the open-source components run, and mark the data parts with abnormal changes. At the same time, extract the abnormal change data and compare it with the security vulnerability data set L. After comparison, the same data is classified as known abnormal vulnerability data, and the different data is classified as unknown abnormal vulnerability data;
[0077] C3. Transmit the known abnormal vulnerability data and unknown abnormal vulnerability data to the repair processing module for processing, so as to judge the potential risks of continuing operations.
[0078] Among them, by introducing the updated data set into the software monitoring model, scanning the data after the open-source components run, marking the data parts with abnormal changes, extracting the abnormal change data and comparing it with the security vulnerability data set L. After comparison, the same data is classified as known abnormal vulnerability data, and the different data is classified as unknown abnormal vulnerability data, and using the repair processing module for repair operations, so that the known abnormal vulnerability data can be traced directly to complete the quick repair operation, and the unknown abnormal vulnerability data is processed by formulating specific repair methods, thereby improving the efficiency of handling security vulnerabilities of software open-source components and improving the security of the formed software.
[0079] In the embodiment of the present invention, the expression for comparing the abnormal change data with the security vulnerability data set L in C2 is:
[0080]
[0081] F represents the judgment result of the abnormal change data, n∩L represents the intersection comparison operation between the abnormal change data and the security vulnerability data set L, n represents the extracted abnormal change data, p is the known abnormal vulnerability data, and q is the unknown abnormal vulnerability data.
[0082] In the embodiment of the present invention, the processing of transmitting the abnormal change data and the security vulnerability data set L to the repair processing module in C3 is as follows:
[0083] c21. Extract a subset of security vulnerability data corresponding to the detected open-source component from the security vulnerability dataset L according to the detected open-source component;
[0084] c22. When processing based on the known abnormal vulnerability data p, trace the corresponding repair data according to the security vulnerability dataset L, and introduce the repair data into the software monitoring model for repair operations;
[0085] c23. When processing based on the unknown abnormal vulnerability data q, formulate corresponding repair steps according to the impact of the data for repair operations.
[0086] In the embodiment of the present invention, the corresponding repair steps formulated in c23 are as follows:
[0087] D1. Extract the abnormal vulnerability data q and the optimization data y in the corresponding operations, and determine whether to replace the updated data according to the weight ratio of the abnormal vulnerability data q and the optimization data y;
[0088] D2. Then, prioritize the impact range of the abnormal vulnerability data q, and perform an operation to modify the introduced data corresponding to the abnormal vulnerability data q, and then introduce the modified data into the software monitoring model for re-detection;
[0089] D3. Continuously update and iterate for the operation of D2 until the abnormal vulnerability data is repaired, and then the subsequent project update can be performed.
[0090] In the embodiment of the present invention, the step of determining whether to replace the updated data according to the weight ratio in D1 is: Based on the software monitoring model, determine the weight ratio of the abnormal vulnerability data q and the optimization data y. When the beneficial weight ratio of the optimization data y is greater than the loss weight ratio of the abnormal vulnerability data q, the current data update operation meets the construction requirements of the software project.
[0091] In the embodiment of the present invention, the operation of modifying the introduced data corresponding to the abnormal vulnerability data q in D2 is:
[0092] d21. Trace the introduced data part based on the abnormal vulnerability data q, and perform patch insertion or data modification operations on the data part according to the situation of the vulnerability;
[0093] d22. Then, after introducing it into the software monitoring model for detection, ensure that there are no security vulnerabilities in the updated model, and then introduce the previous abnormal vulnerability data q for repair verification operations. After there are no problems, perform subsequent operations.
[0094] Among them, the data part introduced by tracing the abnormal vulnerability data q is patched or the data part is modified according to the situation of the vulnerability, and then the software monitoring model is introduced for detection. After ensuring that the updated model has no security vulnerabilities, the previous abnormal vulnerability data q is introduced for repair verification operations, so as to ensure that the phased security vulnerability handling operations are maintained during the development process, and reduce the losses at the development source while improving security.
[0095] Embodiment 2: The difference compared with Embodiment 1 is that the existing software open-source component security vulnerability and potential risk analysis and control system and the software open-source component security vulnerability and potential risk analysis and control system of the present invention are applied to the development operations of multiple software projects in an enterprise, and the efficiency of security vulnerability detection and the time for corresponding repair and handling completion are recorded. The specific results are shown in Table 1:
[0096] Table 1 Record situation table
[0097] Vulnerability detection time Vulnerability repair time Vulnerability repair success rate Existing analysis and control system 96s 144s 86% Analysis and control system of the present invention 26s 58s 100%
[0098] In summary, by applying the software open-source component security vulnerability and potential risk analysis and control system of the present invention to the software project development operations of an enterprise, the time for security vulnerability detection and the time for repairing security vulnerabilities are shorter, and the success rate of repairing vulnerabilities is higher, which can be better applied to the software development operations of an enterprise.
[0099] At the same time, the content not described in detail in this specification belongs to the prior art well-known to those skilled in the art.
[0100] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device.
[0101] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. An analysis and control system for software open-source component security vulnerabilities and potential risks, characterized in that: Including: A data collection module that collects information data of open-source components in a software project, and collects and stores data on known security vulnerabilities with certifications; A data repository that stores the collected data and subsequent control and processing data; A security vulnerability detection module that performs preliminary screening operations on the collected data, constructs a software monitoring model based on the initial open-source component data in the data repository, and performs operations to reduce, increase, or modify data based on the software monitoring model, detects the occurrence of vulnerabilities during the operation in real time, synchronously predicts potential risks, and feeds back the situations generated by the operation; A repair processing module that correspondingly processes the detected security vulnerability situations or provides corresponding repair suggestions or solutions; A monitoring and warning module that monitors the usage of various open-source components in a software project in real time, warns of security vulnerability situations and potential risks, and notifies maintenance personnel; A user interface for users to view information during the operation process and directly feedback the information processing flow; The operation of preliminarily screening data in the security vulnerability detection module is as follows: A1. After receiving the data, perform preliminary classification operations according to the required data categories; A2. The initial open-source component information used in the software project is summarized into an initial open-source component data set labeled as M, the data used in the software project in real time subsequently is summarized into an updated data set labeled as N, and the data on known security vulnerabilities with certifications is summarized into a known security vulnerability data set labeled as L; A3. Use the data according to the classified data sets subsequently; The security vulnerability detection steps for performing operations to reduce, increase, or modify data based on the software monitoring model in the security vulnerability detection module are as follows: C1. Introduce the updated data set N into the software monitoring model, and perform data detection operations on the open-source components in sequence according to the dependency relationship; C2. Scan the data after the open-source components run, mark the data parts with abnormal changes, extract the abnormal change data and compare it with the security vulnerability data set L at the same time. After comparison, the same data is classified as known abnormal vulnerability data, and the different data after comparison is classified as unknown abnormal vulnerability data; C3. Transmit the known abnormal vulnerability data and unknown abnormal vulnerability data to the repair processing module for processing, so as to judge the potential risks of continuing the operation; The operation of transmitting the known abnormal vulnerability data and unknown abnormal vulnerability data to the repair processing module for processing in C3 is as follows: c21. Extract the security vulnerability data subset corresponding to the detected open-source component from the security vulnerability data set L; c22. When processing based on the known abnormal vulnerability data p, trace the corresponding repair data according to the security vulnerability data set L, and introduce the repair data into the software monitoring model for repair operations; c23. When processing based on the unknown abnormal vulnerability data q, formulate corresponding repair steps according to the impact of the data for repair operations; The corresponding repair steps formulated in c23 are: D1. Extract the unknown abnormal vulnerability data q and the optimized data y in the corresponding operations, and determine whether to replace the updated data according to the weight ratio of the unknown abnormal vulnerability data q and the optimized data y; D2. Then, prioritize the influence range of the unknown abnormal vulnerability data q, and modify the introduced data corresponding to the unknown abnormal vulnerability data q. Then, introduce the modified data into the software monitoring model for re-detection; D3. Continuously update and iterate the operation in D2 until the abnormal vulnerability data is repaired, and then the subsequent project update can be carried out.
2. The analysis and control system for software open-source component security vulnerabilities and potential risks according to claim 1, wherein: Judge the dependency situation of the initial open-source component dataset M. The specific operation is as follows: a21. Arbitrarily select an initial open-source component data subset, and find the dependent and dependent open-source component data subsets based on the first initial open-source component data subset; a22. Based on the dependent open-source component data subset, continue to find the dependent and dependent open-source component data subsets related to the current subset. Based on the dependent open-source component data subset, continue to find the dependent and dependent open-source component data subsets related to the current subset; a23. Extract the starting dependent open-source component data subset with the first initial open-source component data subset as the node, and re-order the data subsets in the initial open-source component dataset M according to the dependency relationship order.
3. The analysis and control system for software open-source component security vulnerabilities and potential risks according to claim 2, wherein: The operation of constructing the software monitoring model based on the data in the data repository in the security vulnerability detection module is as follows: B1. Introduce the re-ordered initial open-source component dataset M, and perform a compliance audit operation on the licenses of each open-source component through the system's inspection tool; B2. Induce and construct the open-source components that meet the requirements to form a software monitoring model, and then introduce the real-time operation data into the software monitoring model for dynamic preview.
4. The analysis and control system for software open-source component security vulnerabilities and potential risks according to claim 1, wherein: The step of determining whether to replace the updated data by the weight ratio in D1 is as follows: Determine the weight ratio of the unknown abnormal vulnerability data q and the optimized data y based on the software monitoring model. When the beneficial weight ratio of the optimized data y is greater than the loss weight ratio of the unknown abnormal vulnerability data q, the current data update operation meets the construction requirements of the software project.
5. The analysis and control system for software open-source component security vulnerabilities and potential risks according to claim 1, characterized in that: The operation of modifying the introduced data corresponding to the unknown abnormal vulnerability data q in the D2 operation is as follows: d21. Trace the introduced data part based on the unknown abnormal vulnerability data q, and insert patches according to the situation of the vulnerability; d22. Then, after introducing it into the software monitoring model for detection, ensure that there are no security vulnerabilities in the updated model, and then introduce the previous unknown abnormal vulnerability data q for repair verification operation. After there are no problems, perform subsequent operations.
Citation Information
Patent Citations
Open source component vulnerability detection method and system
CN117610010A
Control method and device for use of open source component in software development, equipment and storage medium
CN115422529A
Safety detection and early warning system in open source component
CN118656833A