Code audit security enhancement method and system based on external camera assistance
Through the combination of plug-in cameras and object detection algorithms, video streaming data and historical modification records in the developer's code audit process are obtained and analyzed in real time, and the risk index of the code area is evaluated, which solves the problems of high false alarm rate and limited vulnerability coverage of traditional code audit methods, achieving more efficient and accurate code audits.
Patent Information
- Application Number
- CN202510169821.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2045-02-17
AI Technical Summary
Traditional code auditing methods have problems such as high false positive rate, limited vulnerability coverage and inability to detect real-time, and cannot flexibly capture dynamic changes in the system operation environment.
The video stream data during the developer's code audit process is obtained in real time through an external camera, combined with object detection algorithms, historical modification record analysis and audit security feature extraction, evaluate the data sensitivity and risk exposure of the code area, obtain the code audit risk index, and judge the risk level of the code area based on the risk index, and mark and visualize the display.
Effectively identify code areas that developers are concerned about, have an in-depth understanding of changes in code areas, identify potential security issues and review omissions, improve the comprehensiveness and accuracy of code audits, improve audit efficiency, and ensure that high-risk issues are discovered and dealt with in a timely manner.
Smart Images

Figure CN119625621B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a code audit security enhancement method and system based on the assistance of an external camera. Background Art
[0002] With the rapid development of information technology, network security has become a global focus. Especially for enterprises and organizations, the security of software systems is directly related to data security and business stability. Code auditing, as an effective security detection method, can help developers and security experts discover potential security vulnerabilities and programming errors, and prevent systems from being attacked or abused. In the process of digital transformation, more and more companies use automated tools for code auditing to improve audit efficiency and reduce the cost of manual auditing. However, with the continuous evolution of code complexity and attack methods, traditional code auditing methods face technical challenges, and there is an urgent need for more intelligent, flexible and efficient solutions.
[0003] At present, the mainstream code auditing methods mainly include static analysis and dynamic analysis. Static analysis scans the source code to identify potential security vulnerabilities and bad programming practices, which is suitable for the early development stage; while dynamic analysis runs the program to capture security vulnerabilities that may appear during the execution process. Although these two methods can effectively identify certain types of vulnerabilities, they still have the disadvantages of high false positive rate, limited vulnerability coverage and inability to detect in real time. In addition, most of the existing code auditing tools are software-level scanning tools that cannot flexibly capture dynamic changes in the system operating environment. In order to improve the accuracy and real-time performance of the audit, the audit scheme based on the assistance of external cameras has begun to attract attention. This method combines the external monitoring perspective of the camera to record and analyze the behavior patterns, interaction records and system status changes in the development process in real time, thereby providing a more comprehensive security enhancement method. Summary of the invention
[0004] In view of the deficiencies in the prior art, the present invention provides a code audit security enhancement method and system based on the assistance of an external camera, which solves the problems of the above-mentioned background technology.
[0005] To achieve the above objectives, the present invention is implemented through the following technical solutions: a code audit security enhancement method based on the assistance of an external camera, comprising the following steps: S1. Real-time acquisition of video stream data during the developer's code audit process through an external camera, capturing the code area operated by the developer in the video stream data through a target detection algorithm, and extracting the audit security features of the code area; S2. According to the code area operated by the developer in the video stream data, analyzing the historical modification records and developer behavior patterns of the code area, and extracting the historical audit security features of the code area; S3. According to the audit security features and historical audit security features of the code area, evaluating the data sensitivity and risk exposure of the code area, and obtaining the code audit risk index; S4. Based on the code audit risk index, judging the risk level of the code area, marking the code area and assigning risk levels, identifying key review code segments and displaying them visually.
[0006] Furthermore, the code area operated by developers in the video stream data is captured by the target detection algorithm, and the specific process of extracting the audit security features of the code area is as follows: convert the real-time video stream data into an image frame sequence, process each frame of the image through the target detection algorithm, and identify the code area where the developer is operating; accurately locate the code area through image segmentation technology, and extract the code lines that the developer focuses on; extract the complexity indicators of the code through static code analysis, including cyclomatic complexity, number of code lines, and function length, scan the code through the security rule library, mark the security vulnerability area, match the code according to the preset security keywords, identify the risky code fragments, and extract the audit security features of the code area, including code complexity features, security vulnerability features, and dangerous operation features; convert the extracted audit security features of the code area into numerical indicators, and normalize the numerical features.
[0007] Furthermore, the specific process of analyzing the historical modification records and developer behavior patterns of the code area and extracting the historical audit security features of the code area is as follows: according to the code area operated by the developer in the video stream data, the historical modification records of the code area are extracted from the version control system, and the modification frequency and modification pattern of the area are analyzed; according to the frequency of code modification, modification content and modification time, the code segments that have not been fully reviewed are identified, the frequently modified code areas are marked, and the historical audit security features of the code area are extracted, including the code modification frequency feature and the review omission feature; the extracted historical audit security features of the code area are converted into numerical indicators, and the numerical features are normalized.
[0008] Furthermore, based on the audit security features and historical audit security features of the code area, the specific process of evaluating the data sensitivity and risk exposure of the code area is as follows: based on the audit security features of the code area, analyze the types of sensitive data in the code area, judge the sensitivity of the code area, and identify code areas that have not been fully reviewed; based on and historical audit security features, evaluate the risk exposure of the code area.
[0009] Furthermore, the specific process of obtaining the code audit risk index is as follows: perform weighted calculation on the normalized audit security features and historical audit security features of the code area, assign weights to the audit security features and historical audit security features of each extracted code area, perform comprehensive calculations on the normalized value of each feature and its corresponding weight value, and obtain the code audit risk index.
[0010] Furthermore, based on the code audit risk index, the specific process of judging the risk level of the code area is as follows: perform a risk assessment on each code area according to the code audit risk index; compare the code audit risk index with the preset risk level threshold; when the code audit risk index is greater than the preset high risk threshold, it indicates that the code area is a high risk area; when the code audit risk index is greater than the preset medium risk threshold and less than the preset high risk threshold, it indicates that the code area is a medium risk area; when the code audit risk index is less than the preset medium risk threshold, it indicates that the code area is a low risk area.
[0011] Furthermore, the specific process of marking code areas and assigning risk levels, identifying key code segments for review and visually displaying them is as follows: color-marking each code area according to the risk level of the code area, including marking high-risk areas with red, medium-risk areas with orange, and low-risk areas with gray; identifying and listing high-risk areas as key code segments for review, and visually displaying the risk level markings of the code areas in the code editing interface.
[0012] The code audit security enhancement system based on the assistance of an external camera includes the following modules: a video stream acquisition module, a historical audit analysis module, a risk assessment module, and a risk marking and visualization module; the video stream acquisition module is used to acquire the video stream data of the developer's code audit process in real time through the external camera, capture the code area operated by the developer in the video stream data through the target detection algorithm, and extract the audit security features of the code area; the historical audit analysis module is used to analyze the historical modification records and developer behavior patterns of the code area according to the code area operated by the developer in the video stream data, and extract the historical audit security features of the code area; the risk assessment module is used to evaluate the data sensitivity and risk exposure of the code area according to the audit security features and historical audit security features of the code area, and obtain the code audit risk index; the risk marking and visualization module is used to judge the risk level of the code area based on the code audit risk index, mark the code area and assign risk levels, identify key review code segments and display them visually.
[0013] The present invention has the following beneficial effects:
[0014] (1) This code audit security enhancement method based on the assistance of an external camera can effectively identify the code areas that developers are concerned about during the audit process by acquiring the developer's operation video stream in real time and analyzing the historical modification records of the code area. The target detection algorithm accurately extracts the audit security features of the operation code area, and combines the historical modification and developer behavior patterns to gain an in-depth understanding of the changes in the code area, thereby identifying potential security issues and omissions in the review. This helps to discover potential hidden dangers in the code, especially those areas that are frequently modified and not fully reviewed, thereby improving the comprehensiveness and accuracy of the code audit.
[0015] (2) The code audit security enhancement system based on the assistance of an external camera can evaluate the sensitivity and risk exposure of the code area and quantify the audit risk index of each code segment by setting up a video stream acquisition module, a historical audit analysis module, a risk assessment module, and a risk marking and visualization module. This process can not only identify high-risk code areas, but also mark them according to risk levels and provide developers and auditors with clear review focuses. By visually displaying the key review code segments, auditors can more efficiently concentrate resources on conducting in-depth reviews of high-risk codes, thereby improving audit results and reducing potential security vulnerabilities.
[0016] Of course, any product implementing the present invention does not necessarily need to achieve all of the advantages described above at the same time. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 The present invention is a flow chart of the code audit security enhancement method based on the assistance of an external camera.
[0018] Figure 2 This is a flow chart of the code audit security enhancement system based on the assistance of an external camera of the present invention. DETAILED DESCRIPTION
[0019] The embodiment of the present application solves the problems of the difficulty of manual auditing in fully monitoring the operations of developers, the difficulty of identifying frequently modified and insufficiently reviewed code areas, and the low audit efficiency in the traditional code audit process through a code audit security enhancement method and system assisted by an external camera. This method obtains video stream data in real time, combines target detection algorithms, historical modification record analysis, and audit security feature extraction, which not only improves the accuracy and comprehensiveness of code audits, but also effectively improves audit efficiency, ensuring that high-risk issues in key code areas are discovered and handled in a timely manner.
[0020] The overall idea of the solution in the embodiments of this application is as follows:
[0021] The video stream data of the developer's code audit process is obtained in real time through an external camera. The code area operated by the developer in the video stream data is captured through the target detection algorithm, and the audit security features of the code area are extracted.
[0022] According to the code area operated by developers in the video stream data, the historical modification records and developer behavior patterns of the code area are analyzed, and the historical audit security features of the code area are extracted.
[0023] Based on the audit security features and historical audit security features of the code area, the data sensitivity and risk exposure of the code area are evaluated to obtain the code audit risk index.
[0024] Based on the code audit risk index, the risk level of the code area is determined, the code area is marked and assigned a risk level, and the key code segments for review are identified and displayed visually.
[0025] See also Figure 1The embodiment of the present invention provides a technical solution: a code audit security enhancement method based on the assistance of an external camera, comprising the following steps: S1. Real-time acquisition of video stream data during the developer's code audit process through an external camera, capturing the code area operated by the developer in the video stream data through a target detection algorithm, and extracting the audit security features of the code area; S2. According to the code area operated by the developer in the video stream data, analyzing the historical modification records and developer behavior patterns of the code area, and extracting the historical audit security features of the code area; S3. According to the audit security features and historical audit security features of the code area, evaluating the data sensitivity and risk exposure of the code area, and obtaining the code audit risk index; S4. Based on the code audit risk index, judging the risk level of the code area, marking the code area and assigning risk levels, identifying the key review code segments and displaying them visually.
[0026] In this implementation scheme, step S1: real-time acquisition of video stream data and extraction of audit security features of code areas. In this step, the system uses an external camera to capture video stream data in real time during the code audit process of developers. Through the target detection algorithm, the system can identify and locate the code area where the developer is operating. Then, the system extracts relevant audit security features from these identified code areas. These features may include code complexity, security vulnerabilities, dangerous operations, etc. Through these features, the system can monitor the operations of developers in real time during the code audit process and identify potential security issues in a timely manner. Step S2: Analyze the historical modification records of the code area and the developer's behavior pattern. In the second step, the system combines the code area identified in the video stream data to further analyze the historical modification records of the code area. This step obtains the modification history of the code by querying the version control system (such as Git), analyzing the modification frequency, modification content and behavior patterns of the developer during the modification process. This information helps to extract historical audit security features and identify code areas that may not have been fully reviewed. By understanding the historical modification records, it is possible to find out which code areas are frequently modified, which helps to determine whether these areas need to be audited in a focused manner. Step S3: Evaluate the risk exposure of the code area. According to the audit security features and historical audit security features extracted in steps S1 and S2, the system will further evaluate the data sensitivity and risk exposure of the code area. This step is achieved by calculating the risk index of the code area. The system will convert the feature values into numerical indicators according to the weights and importance of different features, and perform normalization. Through the comprehensive evaluation of these indicators, the system can assign a risk value to each code area to represent the potential security risk of the area. Step S4: Determine the risk of the code area based on the risk index and display it visually. Finally, according to the code audit risk index obtained in step S3, the system determines the risk level of each code area. If the risk index is high, it means that there are major security risks in the code area and it needs to be reviewed in detail. The system will divide the code area into different risk levels, such as high risk, medium risk and low risk, according to the preset risk level threshold, and display them in a visual way. In this way, auditors can more clearly identify the code segments that need to be focused on and conduct targeted reviews, thereby improving audit efficiency and reducing omissions. An external camera refers to an externally mounted camera device that is used to capture the developer's operation process in real time when conducting a code audit. Unlike fixed cameras integrated into the device, external cameras are usually movable and have greater flexibility. They can be placed in different locations to obtain the best viewing angle. The object detection algorithm is a computer vision technology used to identify and locate specific target objects from images or videos. In this solution, the object detection algorithm is used to analyze video stream data, identify the code area where the developer operates, and thus extract the audit security features of the area.The version control system (VCS) is a software tool used to track and manage the modification history of source code. Common version control systems include Git, SVN, etc. In this implementation scheme, the version control system is used to extract the historical modification records of the code area to help analyze the frequency, content and behavior patterns of code modifications. Developer behavior patterns refer to the behavioral characteristics of developers when writing and modifying code. For example, the frequency of developers modifying code, the time period of modification, the type of modified code segments, etc. These behavior patterns can reflect the developer's review habits, review depth, etc. The code audit risk index is a comprehensive score that indicates the security risks that may exist in the code area during the audit process. The index is calculated by analyzing multi-dimensional data such as the audit security features of the code area and the historical audit security features. The higher the risk index, the greater the security risks in the area.
[0027] Specifically, the code area operated by developers in the video stream data is captured by the target detection algorithm, and the specific process of extracting the audit security features of the code area is as follows: convert the real-time video stream data into an image frame sequence, process each frame of the image through the target detection algorithm, and identify the code area where the developer is operating; accurately locate the code area through image segmentation technology, and extract the code lines that the developer focuses on; extract the complexity indicators of the code through static code analysis, including cyclomatic complexity, number of lines of code, and function length, scan the code through the security rule library, mark the security vulnerability area, match the code according to the preset security keywords, identify the risky code fragments, and extract the audit security features of the code area, including code complexity features, security vulnerability features, and dangerous operation features; convert the extracted audit security features of the code area into numerical indicators, and normalize the numerical features.
[0028] In this implementation, by analyzing the real-time video stream, an object detection algorithm (such as YOLO) is used to identify the specific code area that the developer is operating. The algorithm processes each frame of the image, locates the developer's hand or mouse pointer, and marks the screen area where they are operating. Image segmentation technology accurately separates the lines of code that the developer is focusing on by processing the image. This helps to accurately locate the code snippet that the developer is reviewing and provide a precise target for subsequent analysis. Static code analysis extracts code complexity indicators such as cyclomatic complexity (a measure of the complexity of the code path), number of lines of code, and function length by parsing the source code. These indicators are used to evaluate the maintainability of the code and the potential risk of errors. The potential vulnerabilities in the code are automatically scanned through the preset security rule base. For example, the rule base will identify common security vulnerabilities such as SQL injection and XSS. The scanning results will mark the risky parts of the code. The system searches for risky operations in the code based on preset security keywords. For example, in the parts such as sensitive data processing and encryption algorithms, the code snippets that match the keywords are identified as potential high-risk areas. The extracted features such as code complexity, security vulnerabilities, and dangerous operations are converted into numerical data. This allows each feature to be quantified, facilitating subsequent risk analysis and assessment. All digitized features are normalized to unify features of different dimensions into a standard range (such as between 0 and 1) to ensure that the weight and influence of each feature in risk assessment is fair.
[0029] Specifically, the specific process of analyzing the historical modification records and developer behavior patterns of code areas and extracting the historical audit security features of code areas is as follows: according to the code areas operated by developers in the video stream data, the historical modification records of the code areas are extracted from the version control system, and the modification frequency and modification pattern of the area are analyzed; according to the frequency of code modifications, modification content and modification time, the code segments that have not been fully reviewed are identified, and the frequently modified code areas are marked, and the historical audit security features of the code areas are extracted, including code modification frequency features and review omission features; the extracted historical audit security features of the code areas are converted into numerical indicators, and the numerical features are normalized.
[0030] In this embodiment, according to the code area operated by the developer in the video stream data, the system extracts the historical modification record of the code area from the version control system (such as Git). The version control system records the modification history of each code file, and the extracted records include the modification time, modifier, modification content, and modification frequency. By analyzing the historical modification records of the code area, the system can calculate the frequency of code modification (for example, the number of times the code is modified within a certain time range). The modification mode refers to whether a specific area is frequently modified, or whether the modifications are concentrated in certain specific time periods or specific developers. This information helps to identify the maintenance status and potential problems of the code. Based on the modification frequency, modification content, and modification time, the system can identify which code segments may not have been fully reviewed. Frequently modified code areas may mean that there are potential design defects, logical errors, or security issues in the area, so more reviews are required. By comparing the modification time, the system can also identify those code segments that have not been fully reviewed or verified after modification. The system marks these code areas as areas that need to be focused on through high-frequency modifications and unreviewed modification history. These areas usually indicate potential security vulnerabilities or parts that need further verification. The extracted historical audit security features include: Code modification frequency feature: Indicates the number of times a code area has been modified within a certain period of time. Frequently modified areas may indicate high risk. Review omission feature: By comparing modification records and review records, the system can identify which code modifications have not been reviewed or tested, thereby marking areas where reviews have been missed. The extracted features (such as modification frequency, review omissions, etc.) are converted into numerical indicators so that they can be used for further analysis. Normalization is to convert these numerical features to a uniform range (for example, between 0 and 1) so that different features can be reasonably compared and weighted in subsequent risk assessment and analysis.
[0031] Specifically, the specific process of evaluating the data sensitivity and risk exposure of a code area based on the audit security features and historical audit security features of a code area is as follows: Based on the audit security features of a code area, analyze the types of sensitive data in the code area, determine the sensitivity of the code area, and identify code areas that have not been fully reviewed; Based on and historical audit security features, evaluate the risk exposure of the code area.
[0032] In this implementation scheme, the audit security features include features such as code complexity, security vulnerabilities, and dangerous operations, which can help identify the type of sensitive data involved in the code area. For example, if the code processes user privacy information, payment data, personal identity information, etc., then these data are sensitive data. By analyzing these security features of the code area, the system can determine whether the area involves sensitive data. Once sensitive data is identified in the code, the system will further determine the sensitivity of the code area. This step is to evaluate whether there are operations in the code area that process sensitive data, such as encryption and decryption, user authentication, data transmission, etc. Highly sensitive code areas usually require higher review and protection standards. Based on historical audit security features, the system can identify code areas that are frequently modified and not fully reviewed. For example, some code areas may be frequently modified, but no corresponding code review or security audit has been performed. The sensitive data in these areas may be at risk of being abused or leaked, so they need to be reviewed first. Historical audit security features (such as modification frequency, review omissions, etc.) and current audit security features (such as vulnerability features, complexity, etc.) are used together to assess the risk exposure of code areas. The basis for the assessment includes: the frequency of code modification and the comprehensiveness of the review. Code areas that are frequently modified and under-reviewed may have more undiscovered risks. Security vulnerabilities and dangerous operation characteristics. Code areas involving potential attack points are at higher risk. Data sensitivity. Code areas that process sensitive data have higher risk exposure.
[0033] Specifically, the specific process of obtaining the code audit risk index is as follows: perform weighted calculations on the normalized audit security features and historical audit security features of the code area, assign weights to the audit security features and historical audit security features of each extracted code area, perform comprehensive calculations on the normalized value of each feature and its corresponding weight value, and obtain the code audit risk index.
[0034] In this embodiment, set Audit security features ( )and Historical Audit Security Features ( , and their normalized values are and , the weights are and , the normalized features: and The normalized audit security features and the normalized formula for historical audit security features are: ;in, and Characteristics The minimum and maximum values of It is in the range [0,1]. Assign a weight to each feature and , indicating the importance of this feature to risk assessment. Weight value and It is usually determined based on the importance of the feature. The weighted value calculation formula is: ; Weight and sum all features to get a comprehensive code audit risk index , the formula is: ;in, and The impact index is adjusted according to the characteristics of the feature. Index value and If it is greater than 1, it means that the impact of this feature on the risk index increases exponentially.
[0035] Specifically, based on the code audit risk index, the specific process of judging the risk level of a code area is as follows: perform a risk assessment on each code area based on the code audit risk index; compare the code audit risk index with a preset risk level threshold; when the code audit risk index is greater than the preset high-risk threshold, it indicates that the code area is a high-risk area; when the code audit risk index is greater than the preset medium-risk threshold and less than the preset high-risk threshold, it indicates that the code area is a medium-risk area; when the code audit risk index is less than the preset medium-risk threshold, it indicates that the code area is a low-risk area.
[0036] In this implementation scheme, risk assessment is performed on each code area based on the calculated code audit risk index. The risk index reflects the overall security risk of the code area, which includes multiple factors such as the complexity of the code, potential security vulnerabilities, and historical modification records. By evaluating these factors, a quantitative risk index is obtained. In order to determine the risk level of the code area, the code audit risk index needs to be compared with the preset risk level threshold. The preset threshold divides the risk index into different risk levels. These thresholds are usually set based on security requirements or historical data and are divided into three levels: high, medium, and low: High risk threshold: indicates that the risk is high, usually involving major security vulnerabilities or complex issues, and requires priority review. Medium risk threshold: indicates that there is a certain risk, although it is not as urgent as the high-risk area, it should also be handled in a timely manner. Low risk threshold: indicates that the risk of the code area is low, usually stable code that has been fully reviewed. High risk area: If the code audit risk index exceeds the preset high risk threshold, it means that the risk of the area is very high. This usually means that the code in the area may have serious security vulnerabilities or other high-risk factors, and must be reviewed and repaired in detail as soon as possible. Medium-risk areas: If the code audit risk index is greater than the medium-risk threshold but less than the high-risk threshold, this indicates that the code area is at medium risk. Although these code areas are not as urgent as high-risk areas, they still need to be reviewed and addressed. Low-risk areas: If the code audit risk index is less than the medium-risk threshold, this indicates that the code area is at low risk. This means that the code is relatively stable and has fewer problems, and other high-risk areas can be given priority, but they should also be checked regularly.
[0037] Specifically, the specific process of marking code areas and assigning risk levels, identifying key review code segments and visually displaying them is as follows: color-marking each code area according to the risk level of the code area, including marking high-risk areas with red, medium-risk areas with orange, and low-risk areas with gray; identifying and listing high-risk areas as key review code segments, and visually displaying the risk level markings of the code areas in the code editing interface.
[0038] In this implementation scheme, color marking: different colors are used to mark the code area according to the risk level, so as to clearly identify the risk level of each code area. Color marking is an intuitive and easy-to-understand way to help developers quickly understand which areas need special attention. The specific marking rules are as follows: High-risk area: Use red marking to indicate that the risk in this area is high, and there may be serious security vulnerabilities or other critical issues that need to be dealt with immediately. Medium-risk area: Use orange marking to indicate that there are certain security risks in this area. Although it is not as urgent as the high-risk area, it still needs to be paid attention to and reviewed in time. Low-risk area: Use gray marking to indicate that the risk in this area is low, and it has usually been reviewed or its problems are relatively simple and can be dealt with later. Identify key review code segments: After marking the risk level, the system will automatically identify and list high-risk areas as key review code segments. These high-risk areas are usually due to security vulnerabilities, high complexity or frequent historical modifications, and may have greater security risks and need to be reviewed first. The key review code segments are usually key parts or external interaction parts of the system, and developers should check potential security issues more carefully in these areas. Visual display: Through visual display in the code editing interface, the risk level mark of the code area is intuitively presented to the developer. This allows developers to quickly locate code areas with high, medium, and low risks when conducting code reviews, and optimize the review process. For example, when developers are editing code, the system displays the corresponding color mark next to each code segment, helping developers to quickly understand the risk level of each area, ensuring that high-risk areas are given priority and avoiding security issues from being ignored. This approach not only improves the efficiency of code review, but also enhances the accuracy of the review, ensuring that developers can discover and fix potential security issues in a timely manner.
[0039] See also Figure 2The code audit security enhancement system based on the assistance of an external camera includes the following modules: a video stream acquisition module, a historical audit analysis module, a risk assessment module, and a risk marking and visualization module; the video stream acquisition module is used to obtain the video stream data of the developer's code audit process in real time through an external camera, capture the code area operated by the developer in the video stream data through the target detection algorithm, and extract the audit security features of the code area; the historical audit analysis module is used to analyze the historical modification records and developer behavior patterns of the code area according to the code area operated by the developer in the video stream data, and extract the historical audit security features of the code area; the risk assessment module is used to evaluate the data sensitivity and risk exposure of the code area according to the audit security features and historical audit security features of the code area, and obtain the code audit risk index; the risk marking and visualization module is used to judge the risk level of the code area based on the code audit risk index, mark the code area and assign risk levels, identify the key review code segments and display them visually.
[0040] In this implementation scheme, the video stream acquisition module: obtains real-time video data during the developer's code audit process through an external camera, uses the target detection algorithm to identify the code area where the developer is operating, and extracts the security features of the area. Historical audit analysis module: According to the code area in the video stream data, analyze the historical modification records of the area and the developer's behavior patterns, extract the audit security features related to the history, so as to evaluate the modification frequency of the code and potential review vulnerabilities. Risk assessment module: Combines the audit security features and historical audit security features of the code area, evaluates the data sensitivity and risk exposure of the code area, and calculates a comprehensive code audit risk index. Risk marking and visualization module: According to the risk index calculated by the risk assessment module, judges the risk level of the code area, and marks it with different colors to help developers identify high-risk areas. This module also visualizes the high-risk code segments that are reviewed, so that developers can review and repair them in priority. .
[0041] In summary, this application has at least the following effects:
[0042] The code audit security enhancement method and system based on the assistance of external cameras can capture the developer's operation process in real time with the assistance of external cameras. Combined with historical audit data, the system can comprehensively analyze the security features of the code area, help developers quickly identify potential risk areas, and improve the efficiency and accuracy of code audits. Combining video stream data with historical modification records, the system can not only capture the security features of the current code, but also infer the potential risks of the code from the modification frequency and developer behavior patterns, making the audit more comprehensive and in-depth. Through risk assessment and color marking, developers can see the risk level of the code area at a glance, focus on reviewing high-risk code segments, reduce the probability of human judgment errors, and ensure that high-risk areas are handled in a timely manner. The system automatically assesses the risk exposure of the code and marks high-risk areas through visualization, helping the development team to better manage code security and reduce potential security vulnerabilities and defects.
[0043] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0044] The present invention is described with reference to flowcharts and / or block diagrams of systems, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0045] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0046] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0047] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0048] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.
Claims
1. A code audit security enhancement method based on external camera assistance, characterized in that: The following steps are involved: S1. Use an external camera to obtain real-time video stream data during the developer code audit process, use a target detection algorithm to capture the code area operated by the developer in the video stream data, and extract the audit security features of the code area; S2. Analyze the historical modification records and developer behavior patterns of the code area operated by the developer in the video stream data, and extract the historical audit security features of the code area; S3. Evaluate the data sensitivity and risk exposure of the code area based on the audit security features and historical audit security features of the code area, and obtain the code audit risk index; S4. Based on the code audit risk index, determine the risk level of the code area, mark the code area and assign risk levels, identify the key code segments for review and display them visually; The specific process of capturing the code area operated by developers in the video stream data through the target detection algorithm and extracting the audit security features of the code area is as follows: Convert real-time video stream data into a sequence of image frames, process each frame through an object detection algorithm, and identify the code area where the developer is working; Use image segmentation technology to accurately locate code areas and extract the code lines that developers focus on; Extract code complexity indicators through static code analysis, including cyclomatic complexity, number of lines of code, and function length. Scan the code through the security rule library, mark the security vulnerability area, match the code according to the preset security keywords, identify the risky code fragments, and extract the audit security features of the code area, including code complexity features, security vulnerability features, and dangerous operation features. The audit security features of the extracted code area are converted into numerical indicators, and the numerical features are normalized.
2. The code audit security enhancement method based on the assistance of an external camera according to claim 1 is characterized in that: The specific process of analyzing the historical modification records and developer behavior patterns of the code area and extracting the historical audit security features of the code area is as follows: According to the code area operated by the developer in the video stream data, the historical modification records of the code area are extracted from the version control system, and the modification frequency and modification pattern of the area are analyzed; According to the frequency, content and time of code modification, we can identify the code segments that have not been fully reviewed, mark the frequently modified code areas, and extract the historical audit security features of the code areas, including the code modification frequency features and the review omission features; The historical audit security features of the extracted code area are converted into numerical indicators, and the numerical features are normalized.
3. The code audit security enhancement method based on the assistance of an external camera according to claim 2 is characterized in that: Based on the audit security features and historical audit security features of the code area, the specific process of evaluating the data sensitivity and risk exposure of the code area is as follows: Analyze the sensitive data types in the code area based on the audit security features of the code area, determine the sensitivity of the code area, and identify the code areas that have not been fully reviewed; Assess the risk exposure of code areas based on historical audit security features.
4. The code audit security enhancement method based on the assistance of an external camera according to claim 3 is characterized in that: The specific process of obtaining the code audit risk index is as follows: The normalized audit security features and historical audit security features of the code area are weightedly calculated, weights are assigned to the audit security features and historical audit security features of each extracted code area, the normalized value of each feature and its corresponding weight value are comprehensively calculated to obtain the code audit risk index.
5. The code audit security enhancement method based on the assistance of an external camera according to claim 4 is characterized in that: Based on the code audit risk index, the specific process of judging the risk level of the code area is as follows: Conduct risk assessment on each code area based on the code audit risk index; Compare the code audit risk index with the preset risk level threshold. When the code audit risk index is greater than the preset high risk threshold, it means that the code area is a high risk area. When the code audit risk index is greater than the preset medium risk threshold and less than the preset high risk threshold, it means that the code area is a medium risk area; When the code audit risk index is less than the preset medium risk threshold, it means that the code area is a low risk area.
6. The code audit security enhancement method based on the assistance of an external camera according to claim 5 is characterized in that: The specific process of marking code areas and assigning risk levels, identifying key code sections for review, and visualizing them is as follows: Color-code each code area according to its risk level, including marking high-risk areas with red, medium-risk areas with orange, and low-risk areas with gray; Identify and list high-risk areas as key code segments for review, and visually display the risk level markers of the code areas in the code editing interface.
7. A code audit security enhancement system based on the assistance of an external camera, applying the code audit security enhancement method based on the assistance of an external camera as described in any one of claims 1 to 6, characterized in that: It includes the following modules: video stream acquisition module, historical audit analysis module, risk assessment module, risk marking and visualization module; The video stream acquisition module is used to acquire video stream data in the developer code audit process in real time through an external camera, capture the code area operated by the developer in the video stream data through a target detection algorithm, and extract the audit security features of the code area; The historical audit analysis module is used to analyze the historical modification records and developer behavior patterns of the code area according to the code area operated by the developer in the video stream data, and extract the historical audit security features of the code area; The risk assessment module is used to assess the data sensitivity and risk exposure of the code area according to the audit security features and historical audit security features of the code area, and obtain the code audit risk index; The risk marking and visualization module is used to determine the risk level of the code area based on the code audit risk index, mark the code area and assign risk levels, identify key review code segments and perform visual display.
Citation Information
Patent Citations
Image code and method and apparatus for recognizingthereof
KR1020060016430A
Risky code pre-detection method and apparatus, electronic device, computer readable storage medium, and computer program product
WO2023236538A1