Open-source software network fingerprint generation method, system, electronic device and storage medium
Through the large-scale model-based method, the network communication characteristics of open source software are extracted and aggregated, and fingerprints are generated and verified, which solves the problem of low fingerprint generation efficiency in the prior art, and realizes automated and highly accurate fingerprint generation.
Patent Information
- Application Number
- CN202510135382.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-02-07
AI Technical Summary
In the prior art, the efficiency of generating open source software fingerprints is not high and it relies heavily on manual investment.
Using a large model-based method, the target open source software is deployed, network protocol features, traffic features and load features are extracted, these features are aggregated to generate initial fingerprints, and the target fingerprint is obtained through verification.
The fingerprint generation process of target open source software can be efficiently and accurately completed without manual intervention, improving the automation level and accuracy of fingerprint generation and saving professional investment.
Smart Images

Figure CN119622644B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence technology, and particularly to an open-source software network fingerprint generation method, system, electronic device, and storage medium. Background Art
[0002] Network mapping fingerprints are a set of features used to identify network assets (such as servers, network devices, and software applications) during network space mapping. These fingerprints can be unique identifiers based on aspects such as network protocols, service ports, application behaviors, certificate information, Hyper Text Markup Language (HTML) tags, etc., which are beneficial for accurately locating and identifying specific network targets in a complex network environment. For example, for a Web server, the Server field in the Hypertext Transfer Protocol (HTTP) response header it returns (such as "Server: Apache / 2.4.56") is a simple fingerprint, which can indicate that the server uses Apache software and the version is 2.4.56.
[0003] In order to effectively identify network assets, it is necessary to obtain various asset fingerprints in the network space, including open-source software fingerprint information. Currently, the generation of open-source software fingerprints is achieved by professional personnel manually operating packet capture tools to capture the network communication data between the software and external servers, extract different features therefrom, and manually write fingerprint detection rules and fill in fingerprint rule descriptions based on these features for identifying the network behavior of the software. Therefore, the current generation of open-source software fingerprints heavily relies on manual input, resulting in low efficiency in generating open-source software fingerprints. Summary of the Invention
[0004] The present invention provides an open-source software network fingerprint generation method, system, electronic device, and storage medium to solve the problem of low efficiency in generating open-source software fingerprints in the prior art.
[0005] In a first aspect, the present invention provides an open-source software network fingerprint generation method, including:
[0006] Deploy a target open-source software to be fingerprinted based on a large model;
[0007] When running the target open-source software, extract various different types of network communication features based on the large model; the various different types of network communication features at least include network protocol features, traffic features, and payload features;
[0008] Aggregate each of the network communication features to generate an initial fingerprint of the target open-source software;
[0009] Verify the initial fingerprint to obtain the target fingerprint of the target open-source software.
[0010] In one embodiment, when running the target open-source software, based on the large model, extract various different types of network communication features, including:
[0011] When running the target open-source software, capture target network packets;
[0012] Convert the target network packets into a format understandable by the large model to obtain data to be processed;
[0013] Generate a first prompt, a second prompt, and a third prompt; the first prompt is used to reflect the requirement information for extracting network protocol data from the target network packets; the second prompt is used to reflect the requirement information for extracting traffic data from the target network packets; the third prompt is used to reflect the requirement information for extracting payload data from the target network packets;
[0014] Based on the large model, according to the first prompt, perform network protocol feature extraction on the data to be processed to obtain the network protocol features in the target network packets;
[0015] Based on the large model, according to the second prompt, perform traffic feature extraction on the data to be processed to obtain the traffic features in the target network packets;
[0016] Based on the large model, according to the third prompt, perform payload feature extraction on the data to be processed to obtain the payload features in the target network packets.
[0017] In one embodiment, the aggregating the network communication features to generate the initial fingerprint of the target open-source software includes:
[0018] Arrange the network communication features in sequence according to a preset sorting rule to obtain a plurality of arranged network communication features;
[0019] Combine the arranged plurality of network communication features into a high-dimensional vector;
[0020] Encode the high-dimensional vector to generate the initial fingerprint of the target open-source software.
[0021] In one embodiment, the verifying the initial fingerprint to obtain the target fingerprint of the target open-source software includes:
[0022] When running the target open-source software, capture sample network packets;
[0023] Generate a sample fingerprint of the target open-source software based on the sample network data packet;
[0024] Match the sample fingerprint with the initial fingerprint;
[0025] If the match is successful, determine the initial fingerprint as the target fingerprint of the target open-source software;
[0026] If the match fails, iteratively execute the step of extracting various different types of network communication features based on the large model when running the target open-source software until the match is successful, and determine the initial fingerprint generated in the latest iteration process as the target fingerprint of the target open-source software.
[0027] In one embodiment, deploying the target open-source software for which a fingerprint is to be generated based on the large model includes:
[0028] Monitor the dynamic information of the software development sharing platform based on the large model;
[0029] If the large model monitors that there is project address change information for the open-source software to be downloaded, then based on the large model, track the latest repository address of the open-source software to be downloaded according to the project information of the open-source software to be downloaded on the software development sharing platform;
[0030] Download the latest version code of the open-source software to be downloaded from the latest repository address;
[0031] Perform a risk assessment on the latest version code based on the large model to obtain a risk assessment result;
[0032] If the risk assessment result is that there is no security risk in the latest version code, determine the latest version code as the target code of the open-source software to be downloaded;
[0033] If the risk assessment result is that there is a security risk in the latest version code, replace the latest version code with a secure dependency version to obtain the target code of the open-source software to be downloaded;
[0034] Deploy the target open-source software for which a fingerprint is to be generated based on the target code.
[0035] In one embodiment, deploying the target open-source software for which a fingerprint is to be generated based on the target code includes:
[0036] Install and run the open-source software to be downloaded according to the target code;
[0037] If an error occurs during the installation and running process, generate an error message;
[0038] Based on the large model, generate a solution according to the error information;
[0039] According to the solution, reinstall and run the open-source software to be downloaded to obtain the initially operable open-source software;
[0040] In the operating environment of the initially operable open-source software, simulate the business process to obtain the target open-source software for which fingerprints are to be generated.
[0041] In one embodiment, the step of simulating the business process in the operating environment of the initially operable open-source software to obtain the target open-source software for which fingerprints are to be generated includes:
[0042] Based on the large model, generate a business process according to the function description of the initially operable open-source software, and generate an automated script according to the business process;
[0043] In the operating environment of the initially operable open-source software, execute the automated script to simulate the business process and obtain the target open-source software for which fingerprints are to be generated.
[0044] In a second aspect, the present invention further provides an open-source software network fingerprint generation system, which includes a large model processing module, a software download module, an installation and debugging module, a configuration interaction module, a fingerprint generation module, and a fingerprint verification module;
[0045] The software download module is used to obtain the target code of the open-source software to be downloaded;
[0046] The installation and debugging module is used to install and run the open-source software to be downloaded according to the target code to obtain the initially operable open-source software;
[0047] The configuration interaction module is used to simulate the business process in the operating environment of the initially operable open-source software to obtain the target open-source software for which fingerprints are to be generated;
[0048] The fingerprint generation module is used to extract various different types of network communication features based on the large model when running the target open-source software; the various different types of network communication features at least include network protocol features, traffic features, and payload features; aggregate the network communication features to generate the initial fingerprint of the target open-source software;
[0049] The fingerprint verification module is used to verify the initial fingerprint to obtain the target fingerprint of the target open-source software;
[0050] The large model processing module is used to provide large model processing capabilities.
[0051] In a third aspect, the present invention provides an electronic device, which includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the open-source software network fingerprint generation method described in any one of the above are implemented.
[0052] In a fourth aspect, the present invention further provides a storage medium, which includes a non-transitory computer-readable storage medium with a computer program stored thereon. When the computer program is executed by a processor, the steps of the open-source software network fingerprint generation method described in any one of the above are implemented.
[0053] The open-source software network fingerprint generation method, system, electronic device, and storage medium provided by the present invention can, when running a target open-source software, extract various different types of network communication features based on a large model, including network protocol features, traffic features, payload features, etc., and aggregate these network communication features to generate an initial fingerprint of the target open-source software. Further verify the initial fingerprint, and finally generate a reliable target fingerprint. With the multi-modal fusion ability of the large model, the fingerprint generation process of the target open-source software can be efficiently and accurately completed without manual intervention, effectively improving the automation level and accuracy of fingerprint generation, saving the input of professionals, and thus quickly increasing the quantity and accuracy of the fingerprint database. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0055] Figure 1 It is a flowchart showing the open-source software network fingerprint generation method provided by the present invention.
[0056] Figure 2 It is a schematic structural diagram of the open-source software network fingerprint generation system provided by the present invention.
[0057] Figure 3 It is a schematic structural diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0058] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the protection scope of the present invention.
[0059] The terms "first", "second", etc. in the present invention are used to distinguish similar objects and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present invention can be implemented in an order other than those illustrated or described herein.
[0060] The following will be combined with Figures 1 - 3 Describe the open-source software network fingerprint generation method, system, electronic device and storage medium provided by the present invention.
[0061] It should be noted that currently, the open-source software fingerprint generation process heavily relies on manual input. From software downloading, malicious code detection, version identification, installation and debugging, configuration and use, feature extraction, fingerprint generation to fingerprint verification, professional personnel are required to participate in the operation. Conventional automated scripts can automate these processes. Although conventional automated scripts can improve the efficiency in some aspects of open-source software fingerprint generation, they cannot effectively solve the following problems: when the download address of open-source software changes, the automated script cannot identify and judge, resulting in the inability to download open-source software; it cannot identify whether open-source software is embedded with malicious code; when an error occurs during the installation of open-source software, the automated script cannot handle this situation; the automated script cannot quickly adapt to the configuration and use of various open-source software and must rely on professional personnel to configure and use open-source software; it cannot automatically identify and extract from the network traffic context the network communication characteristics required in the open-source software operating environment; for the extracted network communication characteristics, it cannot generate corresponding fingerprint information; it cannot effectively verify fingerprint information. That is to say, conventional automated scripts can complete a series of predefined tasks and perform the functions set by professional personnel. When the task requirements change, professional personnel need to modify the original script multiple times, and this processing method has poor flexibility and low accuracy.
[0062] To adapt to the changes in task requirements, large models are introduced. Large models have powerful understanding and generation capabilities. They can understand complex language logic and context relationships, generate natural, fluent, and creative text content, and perform excellently in natural language processing tasks such as text generation, question answering systems, and machine translation. At the same time, they have the ability to fuse multi-modal data and can comprehensively process various types of data such as text, images, and voices, providing strong support for various application scenarios. Therefore, the open-source software network fingerprint generation method provided by the embodiments of the present invention proposes an open-source software network fingerprint generation technology based on the capabilities of large models. This technology is based on the semantic analysis capabilities and multi-modal fusion capabilities of large models, without manual participation. It applies and optimizes large model capabilities in multiple steps to automatically complete open-source software address recognition, malicious embedded code detection, latest version detection, installation error resolution, configuration usage, simulation of business environments, fingerprint generation, and fingerprint verification, realizing the automated extraction of open-source software network mapping fingerprints, greatly reducing personnel input, and quickly improving the quantity and accuracy of the fingerprint database. Among them, the large model can be a locally deployed large model or support interaction with large models on Internet platforms through application programming interfaces, and can implement functions such as large model query instructions, file uploads, response parsing, and data analysis.
[0063] The open-source software network fingerprint generation method provided by the embodiments of the present invention is implemented based on an open-source software network fingerprint generation system. The embodiments of the present invention describe the open-source software network fingerprint generation method by taking the open-source software network fingerprint generation system as the execution subject. The open-source software network fingerprint generation system specifically includes a software download module, an installation and debugging module, a configuration interaction module, a fingerprint generation module, a fingerprint verification module, and a large model processing module. The software download module is used to execute the process of downloading open-source software; the installation and debugging module is used to execute the process of installing and running open-source software; the configuration interaction module is used to execute the process of simulating business processes in the open-source software running environment; the fingerprint generation module is used to execute the process of generating open-source software network fingerprints; the fingerprint verification module is used to execute the process of verifying open-source software network fingerprints; the large model processing module provides large model processing capabilities for the execution processes of each module.
[0064] Refer to Figure 1 , Figure 1 is the flow schematic diagram of the open-source software network fingerprint generation method provided by the present invention.
[0065] As Figure 1 shown, the method includes the following:
[0066] Step 101: Deploy the target open-source software for which fingerprints are to be generated based on a large model;
[0067] Step 102: When running the target open-source software, extract various different types of network communication characteristics based on the large model;
[0068] Step 103: Aggregate each of the network communication features to generate an initial fingerprint of the target open-source software;
[0069] Step 104: Verify the initial fingerprint to obtain the target fingerprint of the target open-source software.
[0070] Specifically, complete the system initialization. Run the local large model, set the local large model access interface and token, and the system can also be configured to select to use the Internet large model. Set the large model configuration prompt document, provide task background information and context, and define the tasks and goals to be executed, so that the large model can clearly complete tasks such as open-source software address tracking, code review, latest version identification, installation and debugging, configuration interaction, feature extraction, fingerprint generation, and fingerprint verification.
[0071] After completing the system initialization, first obtain the target code of the open-source software to be downloaded. Secondly, according to the target code, install and run the open-source software to be downloaded to obtain the initial open-source software that can run normally. Then, in the running environment of the initial open-source software, simulate the business process to obtain the target open-source software for which fingerprints are to be generated, realizing the automatic deployment of the target open-source software under the semantic understanding ability and multi-modal fusion ability of the large model, and using it as the object for generating fingerprints to automatically generate the fingerprint information of the target open-source software.
[0072] After deploying the target open-source software, run the target open-source software. During this running process, capture multiple network packets, use one of them as the target network packet, and use the remaining target network packets as sample network packets. Furthermore, corresponding fingerprint information will be generated for all of them. Match the fingerprint information generated by the target network packet with the fingerprint information generated by the target network packet to achieve fingerprint verification.
[0073] Furthermore, based on the large model, various different types of network communication features are extracted from the captured target network data packets, including network protocol features, traffic features, and payload features. Of course, it is not limited to these network communication features. This article only describes these three network communication features. Network protocol features refer to the attributes and behaviors of network protocols, which define how data is transmitted and exchanged in the network; traffic features describe the behaviors and patterns of data streams in the network; payload features refer to the actual content of data packets or messages, which can be the payloads in network communication. Network communication features such as network protocol features, traffic features, and payload features together constitute the unique behavior pattern of open-source software in network communication. Each software has its specific way of communicating on the network, which can be reflected in the network protocols it uses, the traffic patterns it generates, and the payload content it transmits. Aggregating these features can form a unique fingerprint. Although network conditions may change, the communication features of a specific software usually remain relatively stable, which means that the fingerprint information of the software is consistent within a certain period and can be used to identify the software. Therefore, the fingerprint information generated based on the target network data packets and the fingerprint information generated based on the sample network data packets need to be consistent, which can be used as a fingerprint verification method. If they are consistent, the generated fingerprint is accurate; if they are inconsistent, the generated fingerprint is incorrect.
[0074] Furthermore, the various types of network communication features extracted from the target network data packets are aggregated to generate the initial fingerprint of the target open-source software. At the same time, in the above-mentioned manner, the various types of network communication features extracted from the sample network data packets can also be aggregated to generate the sample fingerprint of the target open-source software.
[0075] Furthermore, the initial fingerprint of the target open-source software is verified for accuracy through the sample fingerprint of the target open-source software, and finally the target fingerprint of the target open-source software after successful verification is obtained.
[0076] The method for generating the network fingerprint of open-source software provided by the present invention can, when running the target open-source software, extract various different types of network communication features based on the large model, including network protocol features, traffic features, and payload features, etc., and aggregate these network communication features to generate the initial fingerprint of the target open-source software. Further verify the initial fingerprint, and finally generate a reliable target fingerprint. With the multi-modal fusion ability of the large model, the fingerprint generation process of the target open-source software can be completed efficiently and accurately without manual intervention, effectively improving the automation level and accuracy of fingerprint generation, saving the input of professional personnel, and thus quickly increasing the quantity and accuracy of the fingerprint database.
[0077] In some embodiments, based on step 101, deploying the target open-source software whose fingerprint is to be generated based on the large model includes:
[0078] Monitor the dynamic information of the software development sharing platform based on a large model;
[0079] If the large model monitors that there is project address change information for the open-source software to be downloaded, then based on the large model, according to the project information of the open-source software to be downloaded on the software development sharing platform, track the latest repository address of the open-source software to be downloaded;
[0080] Download the latest version code of the open-source software to be downloaded from the latest repository address;
[0081] Based on the large model, conduct a risk assessment on the latest version code to obtain a risk assessment result;
[0082] If the risk assessment result is that there is no security risk in the latest version code, then determine the latest version code as the target code of the open-source software to be downloaded;
[0083] If the risk assessment result is that there is a security risk in the latest version code, then replace the latest version code with a secure dependency version to obtain the target code of the open-source software to be downloaded;
[0084] Based on the target code, deploy the target open-source software for which fingerprints are to be generated.
[0085] It should be noted that open-source projects may migrate to new repository addresses for various reasons, such as project reorganization, maintainer change, project update, etc. Therefore, it is necessary to monitor them. It can be configured to use methods such as timing or event triggering, utilize the code and natural language understanding capabilities of the large model, track the new repository addresses of open-source software, establish a prediction model for address changes, anticipate possible address changes, and, after tracking the new repository address, download the latest version code of the open-source software to the local, conduct in-depth review and analysis of the code of the open-source software, identify possible malicious code segments, and take corresponding solutions for the malicious code segments with security risks. This process is executed by the software download module in the system.
[0086] Specifically, based on the large model, monitor the dynamic information of the software development sharing platform. For example, based on the large model, conduct real-time monitoring of the dynamic information of the GitHub community. The dynamic information of the software development sharing platform includes but is not limited to developers' discussions, project update logs, software description information, historical records, etc. When relevant information about project address changes is mentioned in the software development sharing platform, the large model will capture and process it in a timely manner.
[0087] If the large model detects that there is a project address change information for the open-source software to be downloaded (i.e., the open-source software that needs to be obtained currently) on the software development sharing platform, then based on the large model, according to the project information of the open-source software to be downloaded on the software development sharing platform, track the latest repository address of the open-source software to be downloaded, and track the latest version of the open-source software to be downloaded.
[0088] In addition, an alternative solution can be adopted. The large model can generate alternative relevant repository addresses based on the project name or project description, thereby tracking the latest repository address of the open-source software to be downloaded, and tracking the latest version of the open-source software to be downloaded.
[0089] Furthermore, download the latest version code of the open-source software to be downloaded from the latest repository address to the local. Generally speaking, downloading the latest version code of the software can ensure that users obtain the best functions, performance, security, and support. In one embodiment, through file naming: such as v1.0.0 or release-2.1; configuration files: such as files like package.json, setup.py, pom.xml, etc.; documentation records: such as README, CHANGELOG, Issues, or GitHub Releases; combined with the context understanding ability of the large model, identify and download the latest version code of the open-source software.
[0090] Furthermore, based on the multi-dimensional understanding of the code by the large model, such as syntax, semantics, logic, etc., combined with known malware characteristics and patterns, conduct in-depth review and analysis of the latest version code to determine whether there are security risks in the latest version code. Specifically, it can be based on the large model to evaluate the dependency relationship of the open-source software to be downloaded, and check whether there are security hazards in the dependencies in the dependency files, such as whether they have been tampered with or contain the risk of malicious code, and finally generate the corresponding risk assessment result.
[0091] If the risk assessment result is that there are no security risks in the latest version code, then determine the latest version code as the target code of the open-source software to be downloaded.
[0092] If the risk assessment result is that there are security risks in the latest version code, then replace the latest version code with a secure dependency version to obtain the target code of the open-source software to be downloaded.
[0093] Furthermore, based on the target code of the open-source software to be downloaded, deploy the target open-source software to be fingerprinted.
[0094] In an embodiment of the present invention, the dynamic information of the software development and sharing platform is monitored by using a large model, realizing real-time tracking of the address change of the open-source software project, ensuring that the latest version of the code can be downloaded from the latest repository address, and further performing risk assessment on the latest version of the code through the large model, effectively identifying potential security risks, and determining or adjusting the target code accordingly, thereby ensuring the security, reliability, and currency of the download and use of open-source software.
[0095] According to the above content, deploying the target open-source software for which a fingerprint is to be generated based on the target code includes:
[0096] Install and run the open-source software to be downloaded according to the target code;
[0097] If an error occurs during the installation and running process, generate an error message;
[0098] Based on the large model, generate a solution according to the error message;
[0099] Reinstall and run the open-source software to be downloaded according to the solution to obtain the initial open-source software that can run normally;
[0100] In the running environment of the initial open-source software, simulate the business process to obtain the target open-source software for which a fingerprint is to be generated.
[0101] It should be noted that during the installation and debugging process of open-source software, various expected and unexpected problems may be encountered, such as errors like the dependent library not being installed, the version of the dependent library not matching, and the running environment not matching. By applying the semantic analysis and image analysis capabilities of the large model, try various solutions to complete the installation and debugging of the open-source software and obtain the open-source software that can run normally. This process is executed by the installation and debugging module in the system.
[0102] Specifically, according to the target code, automatically start up the virtual machine vm or docker container, and install and run the open-source software to be downloaded.
[0103] If no error occurs during the installation and running process, the initial open-source software that can run normally can be obtained.
[0104] If an error occurs during the installation and running process, an error message is generated, which can be an error message in text format or an error message in the form of a screenshot. Since the large model has both semantic analysis capabilities and image analysis capabilities, whether it is an error message in text format or an error message in the form of a screenshot, the large model can analyze and process it to generate the corresponding solution.
[0105] Furthermore, based on the large model, generate solutions according to the error messages. For example, automatically diagnose and resolve the failure of installing dependency libraries, analyze version conflicts, automatically solve version conflict problems, replace conflicting libraries or downgrade certain dependencies; provide environment configuration suggestions, automatically generate configuration files, and solve environment configuration problems.
[0106] Furthermore, according to the generated solutions, reinstall and run the open-source software to be downloaded. If errors still occur, continue to generate solutions based on the large model according to the error messages. Finally, through multiple solutions, successfully complete the installation and running of the open-source software to be downloaded, and obtain the initial open-source software that can run normally.
[0107] Furthermore, in the running environment of the initial open-source software, simulate the business process to obtain the target open-source software to be fingerprinted.
[0108] In the embodiments of the present invention, when encountering installation and running errors, the large model is used to analyze the error messages and generate solutions to solve the problems generated during installation and running. Finally, an initial open-source software that can run normally is obtained, effectively shortening the problem-solving cycle, ensuring that the open-source software can be successfully installed and run normally, thereby improving the intelligent level of software deployment.
[0109] According to the above content, the step of simulating the business process in the running environment of the initial open-source software to obtain the target open-source software to be fingerprinted includes:
[0110] Based on the large model, generate a business process according to the function description of the initial open-source software, and generate an automated script according to the business process;
[0111] In the running environment of the initial open-source software, execute the automated script to simulate the business process and obtain the target open-source software to be fingerprinted.
[0112] It should be noted that open-source software may need to be quickly adapted to various open-source software configurations during environment configuration. In the past, it had to rely on professional personnel for manual adaptation. However, in the case of complex environment configurations, this method has poor efficiency and poor configuration effects. Based on the semantic analysis ability of the large model, an automated test framework is selected to simulate the remote access of personnel and machines to the open-source software system, generate corresponding automated operation scripts, and simulate the normal business process of the open-source software to generate normal business traffic. This process is executed by the configuration interaction module in the system.
[0113] Specifically, obtain the function description of the initial open-source software, which describes the software usage instructions.
[0114] Further, based on the large model, according to the function description of the initial open-source software, analyze the software usage instructions therein, model the open-source software business process. Specifically, according to the function description of the initial open-source software, analyze the document or interface structure, deduce the possible operation paths of users, generate common business processes, and generate automation scripts (such as Selenium, Playwright) according to the business processes to convert user operations into automation scripts.
[0115] Further, in the running environment of the initial open-source software, execute the automation script to simulate the business process, and then the target open-source software to be fingerprinted can be obtained. This target open-source software can normally generate business traffic pcap data packets. In one embodiment, generate a Locust user behavior script, dynamically adjust the traffic pattern according to the user description, run the initial open-source software, use the large model to dynamically generate test data, optimize the test process according to the real-time feedback, and finally generate business traffic pcap data packets.
[0116] The embodiment of the present invention uses a large model to generate a business process according to the function description of the initial open-source software, and further converts it into an automation script. By executing these scripts in the running environment to simulate the actual business process, it realizes the automatic configuration of the functions and performance of the open-source software, improves the accuracy and efficiency of software testing, and ensures the reliability and stability of the software in real business scenarios.
[0117] In some embodiments, based on step 102, when running the target open-source software, based on the large model, extract various different types of network communication characteristics, including:
[0118] When running the target open-source software, capture the target network data packets;
[0119] Convert the target network data packets into a format understandable by the large model to obtain the data to be processed;
[0120] Generate a first prompt, a second prompt, and a third prompt; the first prompt is used to reflect the requirement information for extracting network protocol data from the target network data packets; the second prompt is used to reflect the requirement information for extracting traffic data from the target network data packets; the third prompt is used to reflect the requirement information for extracting payload data from the target network data packets;
[0121] Based on the large model, according to the first prompt, perform network protocol feature extraction on the data to be processed to obtain the network protocol features in the target network data packets;
[0122] Based on the large model, according to the second prompt, perform traffic feature extraction on the data to be processed to obtain the traffic features in the target network data packets;
[0123] Based on the large model, according to the third prompt, extract the payload features from the data to be processed, and obtain the payload features in the target network packet.
[0124] It should be noted that before generating the fingerprint information of the open-source software, its network communication features are extracted first. If the script execution method is used to automatically extract features, the feature extraction can only be carried out according to the pre-set network communication data. If other network communication data is added as the data source for feature extraction, the script needs to be re-set, and the flexibility is poor. By setting generation prompts, based on the semantic analysis ability of the large model, the corresponding network communication data is obtained according to the user's needs and used as the data source for feature extraction, greatly improving the flexibility. This process is executed by the fingerprint generation module in the system.
[0125] Specifically, when running the target open-source software, network capture tools such as wireshark can be used to collect service traffic to generate multiple network packets. One of them is used as the target network packet, and the remaining target network packets are used as sample network packets for the fingerprint verification process.
[0126] Furthermore, convert the target network packet into a format that can be understood by the large model, usually into a structured data format, to obtain the data to be processed.
[0127] Furthermore, generate the first prompt, the second prompt, and the third prompt. Among them, the first prompt is used to reflect the requirement information of which network protocol data to extract from the target network packet, the second prompt is used to reflect the requirement information of which traffic data to extract from the target network packet, and the third prompt is used to reflect the requirement information of which payload data to extract from the target network packet.
[0128] Furthermore, based on the large model, according to the first prompt, extract the network protocol features from the data to be processed, and obtain the network protocol features in the target network packet.
[0129] In one embodiment, based on a large model, protocol parsing is performed on the data to be processed. From the network layer, transport layer to the application layer, the structure and fields of the target network data packet are parsed layer by layer to determine the protocol type to which the target network data packet belongs. Further, protocol-related parameters and application-related features are extracted. Extract protocol-related parameters: Extract relevant parameters of the TCP connection at the transport layer, such as the establishment time of the TCP connection (three-way handshake time), connection duration, number of bytes of data transmitted, round-trip time (RTT) of data packets, etc. Extract application-related features: Such as request methods (GET, POST, etc.) in the HTTP protocol, HTTP version number, User-Agent field, Cookie field, etc., username, password, operation commands, etc. in the FTP protocol, certificate information, list of cipher suites, handshake data, etc. in the TLS protocol, query domain name, record type, etc. in the DNS protocol.
[0130] At the same time, based on the large model, according to the second prompt word, traffic feature extraction is performed on the data to be processed to obtain the traffic features in the target network data packet.
[0131] In one embodiment, based on a large model, traffic feature extraction is performed on the data to be processed, including extraction of data such as packet size distribution, packet uplink and downlink distribution, packet arrival time interval, traffic rate change, and behavior pattern of session traffic. Packet size distribution: Count the number or proportion of data packets of different sizes; Packet uplink and downlink distribution: Proportion of uplink and downlink data packets; Packet arrival time interval: Calculate the time interval distribution between adjacent data packets; Traffic rate change: Analyze the traffic rate change of the application during the communication process. The traffic rate can be obtained by calculating the number of bytes transmitted per unit time, and observe the peak value, valley value, and change trend of the traffic rate; Behavior pattern of session traffic (such as the interaction structure of requests and responses).
[0132] At the same time, based on the large model, according to the third prompt word, payload feature extraction is performed on the data to be processed to obtain the payload features in the target network data packet.
[0133] In one embodiment, based on a large model, payload features are extracted from the data to be processed, including payload content extraction for text-based applications and payload content extraction for non-text-based applications. For text-based applications, keywords in the text content are extracted, lexical analysis and part-of-speech tagging are performed on the text content, and high-frequency keywords in the text are extracted. These keywords can reflect the functions and uses of the application. Analyze the format and encoding of the text. Different applications may use different text formats (such as HTML format, plain text format) and encoding methods (such as UTF-8, GBK, etc.). This information can also be used to distinguish applications. For non-text-based applications (such as multimedia applications): Extract the format information of the multimedia file. By analyzing the file header in the data packet payload or relevant fields in the protocol, determine the type of the multimedia file (such as video formats like MP4, AVI, etc., audio formats like MP3, WAV, etc.). For encrypted multimedia content, extract features related to the encryption protocol, such as encryption algorithms, key lengths, and other information.
[0134] In the embodiment of the present invention, by capturing network data packets during the runtime of the target open-source software and converting them into a format understandable by the large model, it is convenient for the large model to perform analysis and processing. At the same time, according to the need to extract which network communication data, specific prompt words are generated, and the specific prompt words are used to guide the large model to extract network protocol features, traffic features, and payload features from the data to be processed respectively, realizing the automatic extraction of network communication features and improving the flexibility of network communication feature extraction, providing effective data support for the generation of open-source software network fingerprints.
[0135] In some embodiments, based on step 103, the aggregating of the network communication features to generate the initial fingerprint of the target open-source software includes:
[0136] Arrange the network communication features in sequence according to a preset sorting rule to obtain multiple arranged network communication features;
[0137] Combine the multiple arranged network communication features into a high-dimensional vector;
[0138] Encode the high-dimensional vector to generate the initial fingerprint of the target open-source software.
[0139] Specifically, arrange the network communication features in sequence according to a preset sorting rule to obtain multiple arranged network communication features, and combine the multiple arranged network communication features into a high-dimensional vector. Among them, the preset sorting rule is set according to the actual situation.
[0140] Furthermore, encode the high-dimensional vector to generate a representative string as the initial fingerprint of the target open-source software.
[0141] In one embodiment, a hash function (such as SHA-3, HMAC, etc.) is used to perform a hash operation on the high-dimensional vector to obtain a hash value with a fixed length as the initial fingerprint of the target open-source software.
[0142] In the embodiment of the present invention, the extracted network communication features are sorted and combined into a high-dimensional vector according to a preset rule, and then encoded to generate the initial fingerprint of the target open-source software, realizing the automatic generation of the network fingerprint of the open-source software and greatly improving the efficiency and accuracy of fingerprint generation.
[0143] In some embodiments, based on step 104, the verifying the initial fingerprint to obtain the target fingerprint of the target open-source software includes:
[0144] When the target open-source software is running, capture sample network data packets;
[0145] Generate a sample fingerprint of the target open-source software according to the sample network data packets;
[0146] Match the sample fingerprint with the initial fingerprint;
[0147] If the match is successful, determine the initial fingerprint as the target fingerprint of the target open-source software;
[0148] If the match fails, iterate and execute the step of extracting various different types of network communication features based on the large model when the target open-source software is running until the match is successful, and determine the initial fingerprint generated in the latest iteration process as the target fingerprint of the target open-source software.
[0149] It should be noted that the fingerprint information of the open-source software is generated through feature extraction, feature combination, encoding, etc., and is unique and can be used to identify the network behavior of the software. Then, when the target open-source software is running, the target network data packets and sample network data packets captured are respectively generated into the initial fingerprint and sample fingerprint of the target open-source software through feature extraction, feature combination, encoding, etc. Since the fingerprint is unique, by verifying whether the initial fingerprint and the sample fingerprint are consistent, it can be detected whether the generated fingerprint information is valid. This process is executed by the fingerprint verification module in the system.
[0150] Specifically, when the target open-source software is running, capture sample network data packets, and generate a sample fingerprint of the target open-source software through feature extraction, feature combination, encoding, etc.
[0151] Furthermore, match the sample fingerprint with the initial fingerprint to verify whether they are consistent.
[0152] If the sample fingerprint matches the initial fingerprint successfully, the initial fingerprint is determined as the target fingerprint of the target open-source software.
[0153] If the sample fingerprint fails to match the initial fingerprint, it indicates that the generated initial fingerprint is incorrect or not accurate enough. In this case, the initial fingerprint is marked as the to-be-optimized state, and the step of extracting various different types of network communication features based on the large model when running the target open-source software is returned. The process of fingerprint generation and fingerprint verification is iteratively executed until the match is successful, and the initial fingerprint generated in the latest iteration process is determined as the target fingerprint of the target open-source software.
[0154] In the embodiment of the present invention, the initial fingerprint is verified through the sample fingerprint, and finally a reliable target fingerprint is generated. The fingerprint generation process of the target open-source software can be efficiently and accurately completed without manual intervention, effectively improving the automation level and accuracy of fingerprint generation, saving the investment of professionals, and thus quickly increasing the quantity and accuracy of the fingerprint database.
[0155] Next, the open-source software network fingerprint generation system provided by the present invention will be described. The open-source software network fingerprint generation system described below can be correspondingly referred to the open-source software network fingerprint generation method described above.
[0156] Refer to Figure 2 , Figure 2 which is the structural schematic diagram of the open-source software network fingerprint generation system provided by the present invention.
[0157] The open-source software network fingerprint generation system includes:
[0158] A software download module 210, configured to obtain the target code of the open-source software to be downloaded;
[0159] An installation and debugging module 220, configured to install and run the open-source software to be downloaded according to the target code to obtain the initial open-source software that can run normally;
[0160] A configuration interaction module 230, configured to simulate the business process in the running environment of the initial open-source software to obtain the target open-source software for which fingerprints are to be generated;
[0161] A fingerprint generation module 240, configured to extract various different types of network communication features based on a large model when running the target open-source software; the various different types of network communication features at least include network protocol features, traffic features, and payload features; aggregating the network communication features to generate the initial fingerprint of the target open-source software;
[0162] A fingerprint verification module 250, configured to verify the initial fingerprint to obtain the target fingerprint of the target open-source software;
[0163] The large model processing module 260 is used to provide large model processing capabilities.
[0164] The open-source software network fingerprint generation system provided by the present invention can, when running the target open-source software, extract various different types of network communication features based on a large model, including network protocol features, traffic features, payload features, etc., and aggregate these network communication features to generate an initial fingerprint of the target open-source software. Further verify the initial fingerprint, and finally generate a reliable target fingerprint. Under the multi-modal fusion ability of the large model, the fingerprint generation process of the target open-source software can be efficiently and accurately completed without manual intervention, effectively improving the automation level and accuracy of fingerprint generation, saving the input of professionals, and thus quickly increasing the quantity and accuracy of the fingerprint database.
[0165] Furthermore, the software download module 210 is also used for:
[0166] Monitoring the dynamic information of the software development and sharing platform based on a large model;
[0167] If the large model monitors that there is project address change information for the open-source software to be downloaded, then based on the large model, according to the project information of the open-source software to be downloaded on the software development and sharing platform, track the latest repository address of the open-source software to be downloaded;
[0168] Download the latest version code of the open-source software to be downloaded from the latest repository address;
[0169] Based on the large model, conduct a risk assessment on the latest version code to obtain a risk assessment result;
[0170] If the risk assessment result indicates that there is no security risk in the latest version code, then determine the latest version code as the target code of the open-source software to be downloaded;
[0171] If the risk assessment result indicates that there is a security risk in the latest version code, then replace the latest version code with a safe dependency version to obtain the target code of the open-source software to be downloaded;
[0172] Based on the target code, deploy the target open-source software for which fingerprints are to be generated.
[0173] Furthermore, the installation and debugging module 220 is also used for:
[0174] Install and run the open-source software to be downloaded according to the target code;
[0175] If an error occurs during the installation and running process, generate an error message;
[0176] Based on the large model, generate a solution according to the error information;
[0177] According to the solution, reinstall and run the open source software to be downloaded to obtain the initial open source software that can run normally;
[0178] In the running environment of the initial open source software, simulate the business process to obtain the target open source software to be fingerprinted.
[0179] Furthermore, the configuration interaction module 230 is also used for:
[0180] Based on the large model, generate a business process according to the function description of the initial open source software, and generate an automation script according to the business process;
[0181] In the running environment of the initial open source software, execute the automation script to simulate the business process to obtain the target open source software to be fingerprinted.
[0182] Furthermore, the fingerprint generation module 240 is also used for:
[0183] When running the target open source software, capture the target network packets;
[0184] Convert the target network packets into a format understandable by the large model to obtain the data to be processed;
[0185] Generate a first prompt, a second prompt, and a third prompt; the first prompt is used to reflect the requirement information for extracting network protocol data from the target network packets; the second prompt is used to reflect the requirement information for extracting traffic data from the target network packets; the third prompt is used to reflect the requirement information for extracting payload data from the target network packets;
[0186] Based on the large model, according to the first prompt, perform network protocol feature extraction on the data to be processed to obtain the network protocol features in the target network packets;
[0187] Based on the large model, according to the second prompt, perform traffic feature extraction on the data to be processed to obtain the traffic features in the target network packets;
[0188] Based on the large model, according to the third prompt, perform payload feature extraction on the data to be processed to obtain the payload features in the target network packets;
[0189] Arrange the network communication features in sequence according to a preset sorting rule to obtain multiple arranged network communication features;
[0190] Combine the arranged multiple network communication features into a high-dimensional vector;
[0191] Encode the high-dimensional vector to generate an initial fingerprint of the target open-source software.
[0192] Further, the fingerprint verification module 250 is further configured to:
[0193] Capture sample network data packets when running the target open-source software;
[0194] Generate a sample fingerprint of the target open-source software according to the sample network data packets;
[0195] Match the sample fingerprint with the initial fingerprint;
[0196] If the match is successful, determine the initial fingerprint as the target fingerprint of the target open-source software;
[0197] If the match fails, iteratively execute the step of extracting various different types of network communication features based on the large model when running the target open-source software until the match is successful, and determine the initial fingerprint generated in the latest iteration process as the target fingerprint of the target open-source software.
[0198] Figure 3 It is a schematic structural diagram of an electronic device provided by the present invention. As Figure 3 shown, the electronic device may include: a processor 310, a communication interface 320, a memory 330, and a communication bus 340. Among them, the processor 310, the communication interface 320, and the memory 330 communicate with each other through the communication bus 340. The processor 310 can call the logical instructions in the memory 330 to execute the open-source software network fingerprint generation method, which includes: deploying the target open-source software to be fingerprinted based on a large model; extracting various different types of network communication features based on the large model when running the target open-source software; the various different types of network communication features at least include network protocol features, traffic features, and payload features; aggregating the network communication features to generate an initial fingerprint of the target open-source software; verifying the initial fingerprint to obtain the target fingerprint of the target open-source software.
[0199] In addition, when the logical instructions in the above-mentioned memory 330 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, external hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0200] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the open-source software network fingerprint generation method provided in the above-mentioned various embodiments. The method includes: based on a large model, deploying a target open-source software for which fingerprints are to be generated; when running the target open-source software, based on the large model, extracting various different types of network communication characteristics; the various different types of network communication characteristics at least include network protocol characteristics, traffic characteristics, and payload characteristics; aggregating each of the network communication characteristics to generate an initial fingerprint of the target open-source software; and verifying the initial fingerprint to obtain the target fingerprint of the target open-source software.
[0201] On yet another hand, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the open-source software network fingerprint generation method provided in the above-mentioned various embodiments. The method includes: based on a large model, deploying a target open-source software for which fingerprints are to be generated; when running the target open-source software, based on the large model, extracting various different types of network communication characteristics; the various different types of network communication characteristics at least include network protocol characteristics, traffic characteristics, and payload characteristics; aggregating each of the network communication characteristics to generate an initial fingerprint of the target open-source software; and verifying the initial fingerprint to obtain the target fingerprint of the target open-source software.
[0202] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative effort.
[0203] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0204] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for generating a network fingerprint of an open source software, characterized in that: include: Based on the large model, deploy the target open source software to generate fingerprints, including: Based on the big model, monitor the dynamic information of the software development sharing platform; Based on the semantic analysis capability of the big model, the project address change information can be captured in real time; If the big model detects that there is project address change information of the open source software to be downloaded, then based on the semantic analysis capability of the big model, according to the project information of the open source software to be downloaded on the software development sharing platform, the address information of the open source software to be downloaded is identified, and the latest warehouse address of the open source software to be downloaded is tracked according to the address information; Download the latest version code of the open source software to be downloaded from the latest warehouse address; Based on the understanding of the syntax, semantics, and logic of the code by the large model, and according to known malware features and patterns, a risk assessment is performed on the latest version of the code to obtain a risk assessment result; If the risk assessment result is that the latest version of the code does not have a security risk, then determining the latest version of the code as the target code of the open source software to be downloaded; If the risk assessment result is that the latest version of the code has a security risk, the latest version of the code is replaced with a safe dependent version to obtain the target code of the open source software to be downloaded; Based on the target code, deploy the target open source software to generate the fingerprint, including: According to the target code, install and run the open source software to be downloaded; If errors occur during installation and operation, error messages are generated; Based on the semantic analysis and image analysis capabilities of the large model, the code version conflict is analyzed according to the error information and a solution is generated; According to the solution, reinstall and run the open source software to be downloaded to obtain the initial open source software that can run normally; In the operating environment of the initial open source software, a business process is simulated to obtain the target open source software for which fingerprints are to be generated, including: Based on the semantic analysis capability of the large model, the open source software business process is modeled, the business process is generated, and an automation script is generated according to the business process; In the operating environment of the initial open source software, executing the automation script, simulating the business process, and obtaining the target open source software for which fingerprints are to be generated; When running the target open source software, extracting a plurality of different types of network communication features based on the large model; the plurality of different types of network communication features at least include network protocol features, traffic features and load features; Aggregating the network communication features to generate an initial fingerprint of the target open source software; Verifying the initial fingerprint to obtain a target fingerprint of the target open source software includes: When running the target open source software, capture sample network data packets; Generating a sample fingerprint of the target open source software according to the sample network data packet; Matching the sample fingerprint with the initial fingerprint; If the match is successful, the initial fingerprint is determined as the target fingerprint of the target open source software; If the match fails, the steps of extracting multiple different types of network communication features based on the large model while running the target open source software are iteratively executed until the match is successful, and the initial fingerprint generated in the latest iteration process is determined as the target fingerprint of the target open source software.
2. The open source software network fingerprint generation method according to claim 1, characterized in that: When the target open source software is run, a plurality of different types of network communication features are extracted based on the large model, including: When running the target open source software, capturing target network data packets; Convert the target network data packet into a format understandable by the large model to obtain data to be processed; Generate a first prompt word, a second prompt word and a third prompt word; the first prompt word is used to reflect the demand information for extracting network protocol data from the target network data packet; the second prompt word is used to reflect the demand information for extracting flow data from the target network data packet; the third prompt word is used to reflect the demand information for extracting payload data from the target network data packet; Based on the large model and according to the first prompt word, extracting network protocol features of the data to be processed to obtain network protocol features in the target network data packet; Based on the large model and according to the second prompt word, extracting the flow characteristics of the data to be processed to obtain the flow characteristics in the target network data packet; Based on the large model and according to the third prompt word, load characteristics of the data to be processed are extracted to obtain the load characteristics in the target network data packet.
3. The open source software network fingerprint generation method according to claim 2, characterized in that: The aggregating the network communication features to generate an initial fingerprint of the target open source software includes: Arrange the network communication features in sequence according to a preset sorting rule to obtain a plurality of arranged network communication features; Combining the arranged multiple network communication features into a high-dimensional vector; The high-dimensional vector is encoded to generate an initial fingerprint of the target open source software.
4. An open source software network fingerprint generation system, characterized in that: The open source software network fingerprint generation system includes a software download module, an installation and debugging module, a configuration interaction module, a fingerprint generation module, a fingerprint verification module and a large model processing module; The software download module is used to obtain the target code of the open source software to be downloaded, including: Based on the big model, monitor the dynamic information of the software development sharing platform; Based on the semantic analysis capability of the big model, the project address change information can be captured in real time; If the big model detects that there is project address change information of the open source software to be downloaded, then based on the semantic analysis capability of the big model, according to the project information of the open source software to be downloaded on the software development sharing platform, the address information of the open source software to be downloaded is identified, and the latest warehouse address of the open source software to be downloaded is tracked according to the address information; Download the latest version code of the open source software to be downloaded from the latest warehouse address; Based on the understanding of the syntax, semantics, and logic of the code by the large model, and according to known malware features and patterns, a risk assessment is performed on the latest version of the code to obtain a risk assessment result; If the risk assessment result is that the latest version of the code does not have a security risk, then determining the latest version of the code as the target code of the open source software to be downloaded; If the risk assessment result is that the latest version of the code has a security risk, the latest version of the code is replaced with a safe dependent version to obtain the target code of the open source software to be downloaded; The installation and debugging module is used to install and run the open source software to be downloaded according to the target code to obtain the initial open source software that can run normally, including: According to the target code, install and run the open source software to be downloaded; If errors occur during installation and operation, error messages are generated; Based on the semantic analysis and image analysis capabilities of the large model, the code version conflict is analyzed according to the error information and a solution is generated; According to the solution, reinstall and run the open source software to be downloaded to obtain the initial open source software that can run normally; The configuration interaction module is used to simulate the business process in the running environment of the initial open source software to obtain the target open source software to generate fingerprints, including: Based on the semantic analysis capability of the large model, the open source software business process is modeled, the business process is generated, and an automation script is generated according to the business process; In the operating environment of the initial open source software, executing the automation script, simulating the business process, and obtaining the target open source software for which fingerprints are to be generated; The fingerprint generation module is used to extract multiple different types of network communication features based on the big model when running the target open source software; the multiple different types of network communication features at least include network protocol features, traffic features and load features; aggregate the network communication features to generate the initial fingerprint of the target open source software; The fingerprint verification module is used to verify the initial fingerprint to obtain the target fingerprint of the target open source software, including: When running the target open source software, capture sample network data packets; Generating a sample fingerprint of the target open source software according to the sample network data packet; Matching the sample fingerprint with the initial fingerprint; If the match is successful, the initial fingerprint is determined as the target fingerprint of the target open source software; If the match fails, iteratively executing the step of extracting multiple different types of network communication features based on the large model when running the target open source software until the match succeeds, and determining the initial fingerprint generated in the latest iteration process as the target fingerprint of the target open source software; The large model processing module is used to provide large model processing capabilities.
5. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the open source software network fingerprint generation method according to any one of claims 1 to 3 are implemented.
6. A storage medium, comprising a non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the open source software network fingerprint generation method according to any one of claims 1 to 3 are implemented.
Citation Information
Patent Citations
Butt-joint method for equipment using large language model and Internet of Things platform
CN118509471A
System and method for identifying open source usage
US20200142692A1
Security detection method and apparatus for open source component package
WO2023072002A1