SCA Detection Method, Device, Equipment and Medium Based on Project Similarity

By using a project similarity-based method in SCA detection and using file fingerprint and attribute information to match, the problem of traditional SCA method being inefficient when changing file contents and adjusting structures is solved, and more efficient and accurate detection is achieved.

CN119690511BActive Publication Date: 2025-06-17BEIJING ANPRO INFORMATION TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510192944.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-06-17
Estimated Expiration
2045-02-21

AI Technical Summary

Technical Problem

Traditional software component analysis (SCA) methods rely on accurate hashing algorithms, which leads to excessive changes in hashing values ​​when the file content of the items to be detected and the file tree structure adjustment, making it easy to miss similar items and components, resulting in low SCA efficiency.

Method used

The SCA detection method based on project similarity is adopted. When the directory fingerprint information of the project to be detected fails to match with the directory fingerprint information of the open source project library, the file fingerprint information and file attribute information are matched, the project similarity is evaluated, and the component version is determined when the preset conditions are met.

Benefits of technology

This method can comprehensively evaluate project similarity from the directory and file level, accurately determine the similar projects and components of the projects to be tested, improve SCA detection efficiency and accuracy, and can still effectively match when the project directory tree structure is adjusted or file content changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119690511B_ABST
    Figure CN119690511B_ABST
Patent Text Reader

Abstract

The present application provides an SCA detection method, device, equipment and medium based on project similarity. When the directory fingerprint information of the project to be detected fails to match the directory fingerprint information of each open-source project in the open-source project library, the similarity between the project to be detected and each target open-source project is evaluated according to the matching results of the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project in the open-source project library, as well as the matching results of the file attribute information of the project to be detected and the file attribute information of each target open-source project. When the similarity between the project to be detected and at least one target open-source project meets the preset project similarity condition, or the directory fingerprint information of the project to be detected matches the directory fingerprint information of at least one open-source project, the component versions corresponding to these known open-source projects are determined as the component versions corresponding to the project to be detected, thereby effectively matching similar projects and components.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to an SCA detection method, device, equipment and medium based on project similarity. Background Art

[0002] Traditional Software Composition Analysis (SCA) methods mainly rely on precise hash algorithms such as MD5 (Message-Digest Algorithm 5) or SHA1 (Secure Hash Algorithm 1) to generate the file hash value and file tree hash value of the project to be detected. By comparing the file hash value and file tree hash value of the project to be detected with those of known open-source projects, one or more known open-source projects similar to the project to be detected are determined, and then the open-source components used by the project to be detected are further determined based on these identified known open-source projects.

[0003] In the actual development process, the code of the open-source components used by the project to be detected often changes. The changes in the file content and the adjustment of the file tree structure of the project to be detected will cause large changes in the hash value, easily missing the matching of similar projects and components, resulting in low SCA efficiency. Summary of the Invention

[0004] The purpose of the embodiments of this application is to provide an SCA detection method, device, equipment and medium based on project similarity, so as to achieve the technical effect of effectively matching similar projects and components and improving the SCA detection efficiency and detection accuracy.

[0005] In a first aspect, the embodiments of this application provide an SCA detection method based on project similarity, including:

[0006] In the case where the directory fingerprint information of the project to be detected fails to match the directory fingerprint information of each open-source project in the open-source project library, evaluate the similarity between the project to be detected and each target open-source project according to the matching result of the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project in the open-source project library, and the matching result of the file attribute information of the project to be detected and the file attribute information of each target open-source project;

[0007] In the case where the similarity between the project to be detected and at least one target open-source project in the open-source project library meets the preset project similarity condition, determine the component version corresponding to the at least one target open-source project as the component version corresponding to the project to be detected;

[0008] In the case where the directory fingerprint information of the item to be detected matches the directory fingerprint information of at least one open-source project in the open-source project library, determine the component version corresponding to the at least one open-source project as the component version corresponding to the item to be detected.

[0009] In the above implementation process, when the directory fingerprint information of the item to be detected fails to match the directory fingerprint information of each open-source project in the open-source project library, evaluate the project similarity between the item to be detected and each target open-source project according to the matching results of the file fingerprint information of the item to be detected and the file fingerprint information of each target open-source project in the open-source project library, and the matching results of the file attribute information of the item to be detected and the file attribute information of each target open-source project. When the project similarity between the item to be detected and at least one target open-source project meets the preset project similarity condition, or the directory fingerprint information of the item to be detected matches the directory fingerprint information of at least one open-source project, determine the component version corresponding to this part of the known open-source projects as the component version corresponding to the item to be detected. It is possible to comprehensively evaluate the similarity between two projects from multiple aspects, such as the similarity of the directory tree structure at the directory level, the similarity of the file content at the file level, and the similarity of the file attributes. Accurately determine the similar projects of the item to be detected, and determine the component version corresponding to the similar projects as the component version corresponding to the item to be detected. Thus, even in the case of project directory tree structure adjustment or file content modification, similar projects and components can be effectively matched, improving the SCA detection efficiency and detection accuracy.

[0010] Further, the similarity between the project fingerprint information of each target open-source project and the project fingerprint information of the item to be detected meets the preset project fingerprint similarity condition.

[0011] In the above implementation process, by screening at least one target open-source project from the open-source project library, and the similarity between the project fingerprint information of each target open-source project and the project fingerprint information of the item to be detected meets the preset project fingerprint similarity condition, it is possible to preselect target open-source projects that may be similar to the item to be detected for project matching at the file level, more quickly and accurately determine the similar projects of the item to be detected, which is beneficial to further improving the SCA detection efficiency.

[0012] Further, the directory fingerprint information of the item to be detected includes the root directory fingerprint information and sub-directory fingerprint information of the item to be detected, and the directory fingerprint information of each open-source project includes the root directory fingerprint information and sub-directory fingerprint information of each open-source project;

[0013] The method further includes:

[0014] Compare the root directory fingerprint information of the item to be detected with the root directory fingerprint information of each open-source project to obtain a first comparison result;

[0015] In the case where the first comparison result is inconsistent, the root directory fingerprint information of the item to be detected is compared with the sub-directory fingerprint information of each open-source project to obtain a second comparison result;

[0016] In the case where the second comparison result is inconsistent, the sub-directory fingerprint information of the item to be detected is compared with the root directory fingerprint information of each open-source project to obtain a third comparison result;

[0017] In the case where the third comparison result is inconsistent, it is determined that the directory fingerprint information of the item to be detected fails to match the directory fingerprint information of each open-source project;

[0018] In the case where the first comparison result, the second comparison result, or the third comparison result is consistent, it is determined that the directory fingerprint information of the item to be detected successfully matches the directory fingerprint information of at least one open-source project.

[0019] In the above implementation process, on the premise that the directory fingerprint information of the project includes root directory fingerprint information and sub-directory fingerprint information, the root directory fingerprint information of the item to be detected is successively compared with the root directory fingerprint information of each open-source project, the root directory fingerprint information of the item to be detected is compared with the sub-directory fingerprint information of each open-source project, and the sub-directory fingerprint information of the item to be detected is compared with the root directory fingerprint information of each open-source project. By comprehensively considering all comparison results to determine the directory-level matching result between the item to be detected and each open-source project, it is possible to effectively judge the complex association relationship between different projects, ensure that the most similar open-source projects and components to the item to be detected are matched, and is conducive to further improving the SCA detection efficiency.

[0020] Further, evaluating the similarity between the item to be detected and each target open-source project according to the matching result of the file fingerprint information of the item to be detected and the file fingerprint information of each target open-source project in the open-source project library, and the matching result of the file attribute information of the item to be detected and the file attribute information of each target open-source project, includes:

[0021] For each target open-source project in the open-source project library, evaluate the first similarity between the item to be detected and the target open-source project according to the matching result of the file fingerprint information of the item to be detected and the file fingerprint information of the target open-source project;

[0022] Evaluate the second similarity between the item to be detected and the target open-source project according to the matching result of the file attribute information of the item to be detected and the file attribute information of the target open-source project;

[0023] Determine the similarity between the project to be detected and the target open-source project according to the first similarity between the project to be detected and the target open-source project and the second similarity between the project to be detected and the target open-source project.

[0024] In the above implementation process, by first separately evaluating the first similarity between the project to be detected and the target open-source project according to the matching result based on the file fingerprint information, and separately evaluating the second similarity between the project to be detected and the target open-source project according to the matching result based on the file attribute information, and then comprehensively evaluating the similarity between the project to be detected and the target open-source project according to the first similarity and the second similarity, it can ensure the accurate evaluation of the similarity between the project to be detected and the target open-source project, which is beneficial to further improving the SCA detection accuracy.

[0025] Furthermore, the file fingerprint information of the project to be detected includes the hash fingerprint and simhash fingerprint of each code file in the project to be detected, and the file fingerprint information of the target open-source project includes the hash fingerprint and simhash fingerprint of each code file in the target open-source project;

[0026] Before evaluating the first similarity between the project to be detected and the target open-source project according to the matching result of the file fingerprint information of the project to be detected and the file fingerprint information of the target open-source project, it further includes:

[0027] Compare the hash fingerprint of each code file in the project to be detected with the hash fingerprints of each code file in the target open-source project respectively to obtain the primary comparison result of the hash fingerprints of each code file in the project to be detected and the hash fingerprints of each code file in the target open-source project;

[0028] Compare the simhash fingerprint of each first target code file in the project to be detected with the simhash fingerprints of each code file in the target open-source project respectively to obtain the secondary comparison result of the simhash fingerprints of each first target code file in the project to be detected and the simhash fingerprints of each code file in the target open-source project; wherein, the hash fingerprint of the first target code file is inconsistent with the hash fingerprints of each code file in the target open-source project;

[0029] Determine the matching result of the file fingerprint information of the project to be detected and the file fingerprint information of the target open-source project according to the primary comparison result and the secondary comparison result.

[0030] In the above implementation process, by comparing the hash fingerprints of each code file in the project to be detected with the hash fingerprints of each code file in the target open-source project respectively, a first comparison result of the hash fingerprints of each code file in the project to be detected and the hash fingerprints of each code file in the target open-source project is obtained. Then, by comparing the simhash fingerprints of each first target code file in the project to be detected with the simhash fingerprints of each code file in the target open-source project respectively, a second comparison result of the simhash fingerprints of each target code file in the project to be detected and the simhash fingerprints of each code file in the target open-source project is obtained. According to the first comparison result and the second comparison result, the matching result based on file fingerprint information is determined. It can utilize the precise matching and approximate matching capabilities of the multi-layer matching strategy to comprehensively and accurately determine the matching result based on file fingerprint information, so as to effectively match similar projects and components even when there are minor changes in the project file content, and improve the SCA detection accuracy.

[0031] Further, the file attribute information of the project to be detected includes the file type, the level in the directory tree, and the file size of each code file in the project to be detected, and the file attribute information of the target open-source project includes the file type, the level in the directory tree, and the file size of each code file in the target open-source project;

[0032] Before evaluating the second similarity between the project to be detected and the target open-source project according to the matching result of the file attribute information of the project to be detected and the file attribute information of the target open-source project, it further includes:

[0033] All code files in the project to be detected with the same file type and the same level in the directory tree are divided into the same code file set to obtain all code file sets in the project to be detected;

[0034] All code files in the target open-source project with the same file type and the same level in the directory tree are divided into the same code file set to obtain all code file sets in the target open-source project;

[0035] Determine the first code file set in the project to be detected and the second code file set in the target open-source project; wherein, the first code file set and the second code file set correspond to the same file type and the same level in the directory tree;

[0036] The file size of each first code file in the first code file set is respectively matched with the file size of each second code file in the second code file set to obtain the matching result of the file attribute information of the project to be detected and the file attribute information of the target open-source project.

[0037] In the above implementation process, by clustering each code file in the project to be detected into each code file set according to the file type and the level of the directory tree where it is located, and clustering each code file in the target open-source project into each code file set according to the file type and the level of the directory tree where it is located, and matching the file sizes of the same type of code files in the project to be detected and the target open-source project, the matching result based on the file attribute information is obtained, which can ensure that the matching result based on the file attribute information accurately reflects the similarity of file attributes between the two projects, so that similar projects and components can be effectively matched even in the case of project structure adjustment, etc., and the SCA detection accuracy is improved.

[0038] Further, the matching the file size of each first code file in the first code file set with the file sizes of each second code file in the second code file set to obtain the matching result of the file attribute information of the project to be detected and the file attribute information of the target open-source project includes:

[0039] Traverse each first code file in the first code file set and each second code file in the second code file set in ascending order of file size;

[0040] Compare the file size of the current first code file with the file size of the current second code file to obtain the difference between the file size of the current first code file and the file size of the current second code file;

[0041] In the case that the difference does not meet the preset difference condition, determine the second target code file with the smaller file size among the current first code file and the current second code file, and update the second target code file to the next code file traversed from the code file set corresponding to the second target code file to re-perform the comparison to obtain a new difference;

[0042] In the case that the difference or the new difference meets the preset difference condition, continue to traverse the next first code file in the first code file set and the next code file in the second code file set for comparison until all the code files in the first code file set and the second code file set have been compared;

[0043] Determine the matching result of the file attribute information of the project to be detected and the file attribute information of the target open-source project according to the comparison result between all the first code file sets in the project to be detected and all the second code file sets in the target open-source project.

[0044] In the above implementation process, by matching the file sizes of the code files of the items to be detected and the target open-source projects of the same type in ascending order of file size one by one, the matching result based on file attribute information is obtained, which can ensure that the most similar open-source projects and components to the item to be detected are matched, and is conducive to further improving the SCA detection accuracy.

[0045] Further, the first similarity between the item to be detected and the target open-source project is determined according to the number of code files in the item to be detected, the number of code files in the target open-source project, and the number of code files with successfully matched file fingerprint information between the item to be detected and the target open-source project;

[0046] The second similarity between the item to be detected and the target open-source project is determined according to the number of code files in the item to be detected, the number of code files in the target open-source project, and the number of code files with successfully matched file attribute information between the item to be detected and the target open-source project.

[0047] In the above implementation process, by determining the first similarity between the item to be detected and the target open-source project according to the number of code files in the item to be detected, the number of code files in the target open-source project, and the number of code files with successfully matched file fingerprint information between the item to be detected and the target open-source project, and determining the second similarity between the item to be detected and the target open-source project according to the number of code files in the item to be detected, the number of code files in the target open-source project, and the number of code files with successfully matched file attribute information between the item to be detected and the target open-source project, the first similarity and the second similarity between the item to be detected and the target open-source project can be quickly and accurately evaluated.

[0048] Further, the preset project similarity condition includes that the similarity between the item to be detected and the target open-source project is greater than a preset project similarity threshold.

[0049] In the above implementation process, by determining whether the similarity between the item to be detected and the target open-source project is greater than the preset project similarity threshold to determine whether the item to be detected and the target open-source project are similar, the open-source projects and components similar to the item to be detected can be quickly and accurately determined.

[0050] In a second aspect, an SCA detection device based on project similarity provided by an embodiment of the present application includes:

[0051] A project matching module, configured to, when the directory fingerprint information of a project to be detected fails to match the directory fingerprint information of each open-source project in an open-source project library, evaluate the similarity between the project to be detected and each target open-source project according to the matching result between the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project in the open-source project library, and the matching result between the file attribute information of the project to be detected and the file attribute information of each target open-source project;

[0052] An SCA detection module, configured to, when the similarity between the project to be detected and at least one target open-source project in the open-source project library meets a preset project similarity condition, determine the component version corresponding to the at least one target open-source project as the component version corresponding to the project to be detected;

[0053] The SCA detection module is further configured to, when the directory fingerprint information of the project to be detected successfully matches the directory fingerprint information of at least one open-source project in the open-source project library, determine the component version corresponding to the at least one open-source project as the component version corresponding to the project to be detected.

[0054] In a third aspect, an embodiment of the present application provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method described above is implemented.

[0055] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the method described above. Description of the Drawings

[0056] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other relevant drawings can be obtained based on these drawings without creative efforts.

[0057] Figure 1 It is a schematic flowchart of an SCA detection method based on project similarity provided by the first embodiment of the present application;

[0058] Figure 2 It is a schematic diagram of the relationship between an open-source project and components exemplified by the first embodiment of the present application;

[0059] Figure 3Data flow diagram of an SCA detection method based on project similarity provided in the first embodiment of this application;

[0060] Figure 4 Structural schematic diagram of an SCA detection device based on project similarity provided in the second embodiment of this application;

[0061] Figure 5 Structural schematic diagram of an electronic device provided in the third embodiment of this application. Detailed implementation manners

[0062] Next, the technical solutions in the embodiments of this application will be described with reference to the accompanying drawings in the embodiments of this application.

[0063] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0064] Software Composition Analysis (SCA) is a technology used to identify and analyze internal components of software and their relationships.

[0065] In the related art, traditional software composition analysis methods mainly rely on precise hash algorithms such as MD5 (Message-Digest Algorithm 5) or SHA1 (Secure Hash Algorithm 1) to generate file hash values and file tree hash values of the project to be detected. By comparing the file hash values and file tree hash values of the project to be detected with the file hash values and file tree hash values of known open-source projects, one or more known open-source projects similar to the project to be detected are determined, and then the open-source components used by the project to be detected are further determined based on these determined known open-source projects.

[0066] In the actual development process, the code of the open-source components used by the project to be detected often changes. Changes in the file content and adjustments to the file tree structure of the project to be detected will cause large changes in the hash values, easily missing the matching of similar projects and components, resulting in low SCA efficiency.

[0067] To this end, the present application proposes an SCA detection method based on project similarity. When the directory fingerprint information of the project to be detected fails to match the directory fingerprint information of each open-source project in the open-source project library, according to the matching results of the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project in the open-source project library, as well as the matching results of the file attribute information of the project to be detected and the file attribute information of each target open-source project, the project similarity between the project to be detected and each target open-source project is evaluated. When the project similarity between the project to be detected and at least one target open-source project meets the preset project similarity condition, or the directory fingerprint information of the project to be detected successfully matches the directory fingerprint information of at least one open-source project, the component versions corresponding to this part of the known open-source projects are determined as the component versions corresponding to the project to be detected. It can comprehensively evaluate the similarity between two projects from multiple aspects, such as the similarity of the directory tree structure at the directory level, the similarity of the file content and the similarity of the file attributes at the file level, accurately determine the similar projects of the project to be detected, and determine the component versions corresponding to the similar projects as the component versions corresponding to the project to be detected, so as to effectively match similar projects and components even in the case of project directory tree structure adjustment or file content modification, improving the SCA detection efficiency and detection accuracy.

[0068] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments.

[0069] Next, in combination with Figure 1 An SCA detection method based on project similarity in an embodiment of the present application is described. The method provided in the embodiment of the present application can be executed by a related terminal device. Hereinafter, the user terminal is taken as an example of the execution subject for description.

[0070] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of an SCA detection method based on project similarity provided in the first embodiment of the present application. The first embodiment of the present application provides an SCA detection method based on project similarity, including steps S101 to S103:

[0071] S101. When the directory fingerprint information of the project to be detected fails to match the directory fingerprint information of each open-source project in the open-source project library, according to the matching results of the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project in the open-source project library, as well as the matching results of the file attribute information of the project to be detected and the file attribute information of each target open-source project, evaluate the similarity between the project to be detected and each target open-source project;

[0072] S102. When the similarity between the project to be detected and at least one target open-source project in the open-source project library meets the preset project similarity condition, determine the component versions corresponding to the at least one target open-source project as the component versions corresponding to the project to be detected;

[0073] S103. When the directory fingerprint information of the project to be detected matches the directory fingerprint information of at least one open-source project in the open-source project library, determine the component versions corresponding to the at least one open-source project as the component versions corresponding to the project to be detected.

[0074] Exemplarily, collect multiple known open-source projects in advance and establish an open-source project library. When it is necessary to perform SCA detection on an unknown open-source project, that is, the project to be detected, obtain the directory fingerprint information, file fingerprint information, and file attribute information of the project to be detected, and obtain the directory fingerprint information, file fingerprint information, and file attribute information of each open-source project in the open-source project library.

[0075] Among them, the directory fingerprint information of the project to be detected is the directory hash value of the directory tree of the project to be detected generated by using a hash algorithm. Specifically, it is to sort the file hash values of all code files under the directory tree of the project to be detected in descending or ascending order of file hash values, and calculate the obtained file hash value sequence by using a hash algorithm. The file fingerprint information of the project to be detected includes the file hash values of each code file in the project to be detected generated by using a hash algorithm. The file attribute information of the project to be detected includes the file attribute information of each code file in the project to be detected, which is used to indicate the file attribute. Similarly, the directory fingerprint information of the open-source project is the directory hash value of the directory tree of the open-source project generated by using a hash algorithm. Specifically, it is to sort the file hash values of all code files under the directory tree of the open-source project in descending or ascending order of file hash values, and calculate the obtained file hash value sequence by using a hash algorithm. The file fingerprint information of the open-source project includes the file hash values of each code file in the open-source project generated by using a hash algorithm. The file attribute information of the open-source project includes the file attribute information of each code file in the open-source project, which is used to indicate the file attribute.

[0076] After obtaining the directory fingerprint information of the project to be detected and the directory fingerprint information of each open-source project, match the directory fingerprint information of the project to be detected with the directory fingerprint information of each open-source project to obtain the matching result of the directory fingerprint information of the project to be detected and the directory fingerprint information of each open-source project.

[0077] In the case where the directory fingerprint information of the project to be detected fails to match the directory fingerprint information of each open-source project, it is considered that the directory tree of the project to be detected is not related to the directory trees of each open-source project, and there is no association relationship between the project to be detected and each open-source project at the directory level. At this time, continue with the project matching at the file level. After obtaining the file fingerprint information and file attribute information of the project to be detected, as well as the file fingerprint information and file attribute information of each target open-source project in the open-source project library, first match the file fingerprint information of the project to be detected with the file fingerprint information of each target open-source project to obtain the matching results of the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project, and match the file attribute information of the project to be detected with the file attribute information of each target open-source project to obtain the matching results of the file attribute information of the project to be detected and the file attribute information of each target open-source project. Then, based on the matching results of the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project in the open-source project library, as well as the matching results of the file attribute information of the project to be detected and the file attribute information of each target open-source project, evaluate the similarity between the project to be detected and each target open-source project. Finally, determine whether the similarity between the project to be detected and each target open-source project meets the preset project similarity condition.

[0078] It should be noted that the target open-source project can be any open-source project in the open-source project library or a specified open-source project in the open-source project library.

[0079] In the case where the similarity between the project to be detected and at least one target open-source project meets the preset project similarity condition, it is considered that although there is no association relationship between the project to be detected and this part of the target open-source projects at the directory level, the project to be detected is similar to this part of the target open-source projects at the file level. At this time, determine the component version corresponding to this part of the target open-source projects, and use the component version corresponding to this part of the target open-source projects as the component version corresponding to the project to be detected, so as to complete the matching of the similar components of the project to be detected.

[0080] In the case where the similarity between the project to be detected and each target open-source project does not meet the preset project similarity condition, it is considered that there is no association relationship between the project to be detected and each target open-source project at the directory level, and the project to be detected is not similar to each target open-source project at the file level. At this time, it can be determined that there are no similar projects and components of the project to be detected in the open-source project library.

[0081] When the directory fingerprint information of the project to be detected matches the directory fingerprint information of at least one open-source project, it is considered that the directory tree of the project to be detected is related to the directory trees of these open-source projects. From the directory level, there is an association between the project to be detected and these open-source projects. At this time, determine the component versions corresponding to these open-source projects, and use the component versions corresponding to these open-source projects as the component versions corresponding to the project to be detected, so as to complete the matching of similar components of the project to be detected.

[0082] By first performing project matching at the directory level for the project to be detected and each open-source project, and then performing project matching at the file level for the project to be detected and each target open-source project when the project matching at the directory level fails, the impact of the adjustment of the directory tree structure and the change of file content of the project to be detected on project matching can be comprehensively considered, and the similarity between the project to be detected and the known open-source projects can be comprehensively and accurately captured. Moreover, during the project matching process at the file level, in addition to performing project matching based on file fingerprint information, file attribute information is also introduced for project matching. According to the matching results based on file fingerprint information and the matching results based on file attribute information, the similarity between the project to be detected and the known open-source projects is comprehensively evaluated. It is possible to accurately capture the similarity between the project to be detected and the known open-source projects even when the content of a large number of files in the project to be detected has changed. Thus, similar projects and components can be effectively matched even in the case of adjustments to the project directory tree structure or changes in file content, improving the SCA detection efficiency and detection accuracy.

[0083] In the embodiment of the present application, when the directory fingerprint information of the project to be detected fails to match the directory fingerprint information of each open-source project in the open-source project library, the project similarity between the project to be detected and each target open-source project is evaluated according to the matching results of the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project in the open-source project library, and the matching results of the file attribute information of the project to be detected and the file attribute information of each target open-source project. When the project similarity between the project to be detected and at least one target open-source project meets the preset project similarity condition, or when the directory fingerprint information of the project to be detected matches the directory fingerprint information of at least one open-source project, determine the component versions corresponding to these known open-source projects as the component versions corresponding to the project to be detected. It is possible to comprehensively evaluate the similarity between two projects from multiple aspects, including the similarity of the directory tree structure at the directory level, the similarity of file content and file attributes at the file level, accurately determine the similar projects of the project to be detected, and determine the component versions corresponding to the similar projects as the component versions corresponding to the project to be detected. Thus, similar projects and components can be effectively matched even in the case of adjustments to the project directory tree structure or changes in file content, improving the SCA detection efficiency and detection accuracy.

[0084] In an alternative embodiment, the similarity between the project fingerprint information of each target open-source project and the project fingerprint information of the project to be detected meets the preset project fingerprint similarity condition.

[0085] Exemplarily, considering the large number of open-source projects in the open-source project library, to further improve the SCA detection efficiency, open-source projects that may be similar to the project to be detected can be preliminarily screened out from the open-source project library as target open-source projects for file-level project matching.

[0086] Determine the preset project fingerprint similarity condition according to the actual application requirements.

[0087] Obtain the project fingerprint information of the project to be detected and the project fingerprint information of each open-source project in the open-source project library.

[0088] Among them, the project fingerprint information of the project to be detected is a vector generated according to the file fingerprint information of the project to be detected. Similarly, the project fingerprint information of the open-source project is a vector generated according to the file fingerprint information of the open-source project.

[0089] For each open-source project in the open-source project library, evaluate the similarity between the project fingerprint information of the project to be detected and the project fingerprint information of this open-source project, and determine whether this similarity meets the preset project fingerprint similarity condition. If this similarity meets the preset project fingerprint similarity condition, it is considered that at least part of the code files in this open-source project are similar to at least part of the code files in the project to be detected, and the possibility that this open-source project is similar to the project to be detected is relatively high. At this time, this open-source project is determined as the target open-source project; if this similarity does not meet the preset project fingerprint similarity condition, it is considered that the possibility that this open-source project is similar to the project to be detected is relatively low, and no processing is done.

[0090] In a preferred implementation manner of this embodiment, the project information of multiple open-source projects is stored in the open-source project library; among them, the project information of the open-source project includes the project fingerprint information, directory fingerprint information, file fingerprint information, and file attribute information of the open-source project, as well as the component version corresponding to the open-source project.

[0091] Exemplarily, to quickly obtain the project information of the open-source project required during the SCA detection process, the project information of multiple open-source projects can be stored in the open-source project library together during the establishment stage of the open-source project library.

[0092] Among them, the project information of the open-source project includes the project fingerprint information, directory fingerprint information, file fingerprint information, and file attribute information of the open-source project, as well as the component version corresponding to the open-source project.

[0093] In practical applications, multiple open-source projects can be crawled from the network. Each open-source project has multiple project versions, and its version information includes information such as directory tree, number of files, and commits, as well as common information such as home_url, doc_url, source_url, repo_url, homepage, forks_count, project description, and license, to obtain all project versions of the open-source project and their version information. For each project version of an open-source project, according to the version information of the project version, determine the components and component versions corresponding to the project version. For example, determine the component version with the same component version number as the project version number of the project version as the component version corresponding to the project version, or, when the information such as home_url, doc_url, and repo_url in the version information of the component version is consistent with the information such as home_url, doc_url, and repo_url in the version information of the project version, determine the component version as the component version corresponding to the project version, and sort out the component versions corresponding to the open-source project according to the component versions corresponding to each project version of the open-source project, so as to obtain the component versions corresponding to multiple open-source projects. For example, the relationship between the open-source project and the component is as Figure 2 shown.

[0094] For each open-source project, preprocess each code file in the open-source project. Among them, the preprocessing includes file filtering. For example, filter out code files with a file size smaller than a preset file size, such as 100 bytes, and special files such as hidden files, generate file hash values of each preprocessed code file in the open-source project using a hash algorithm, determine the file attributes of each preprocessed code file in the open-source project, and generate vectors according to the file hash values of each preprocessed code file in the open-source project, and generate a directory hash value of the directory tree of the open-source project using a hash algorithm, so as to build an open-source project library.

[0095] In an alternative embodiment of this embodiment, the preset project fingerprint similarity condition includes that the similarity between the project fingerprint information of the project to be detected and the project fingerprint information of the open-source project is greater than a preset project fingerprint similarity threshold.

[0096] By screening at least one target open-source project from the open-source project library in the embodiment of the present application, and the similarity between the project fingerprint information of each target open-source project and the project fingerprint information of the project to be detected meets the preset project fingerprint similarity condition, it is possible to preselect target open-source projects that may be similar to the project to be detected for file-level project matching, and more quickly and accurately determine similar projects of the project to be detected, which is beneficial to further improving the SCA detection efficiency.

[0097] In an alternative embodiment, the directory fingerprint information of the item to be detected includes the root directory fingerprint information and sub-directory fingerprint information of the item to be detected, and the directory fingerprint information of each open-source project includes the root directory fingerprint information and sub-directory fingerprint information of each open-source project;

[0098] The method further includes steps S104 to S106:

[0099] S104. Compare the root directory fingerprint information of the item to be detected with the root directory fingerprint information of each open-source project to obtain a first comparison result;

[0100] S105. In the case where the first comparison result is inconsistent, compare the root directory fingerprint information of the item to be detected with the sub-directory fingerprint information of each open-source project to obtain a second comparison result;

[0101] S106. In the case where the second comparison result is inconsistent, compare the sub-directory fingerprint information of the item to be detected with the root directory fingerprint information of each open-source project to obtain a third comparison result;

[0102] S107. In the case where the third comparison result is inconsistent, determine that the directory fingerprint information of the item to be detected fails to match the directory fingerprint information of each open-source project;

[0103] S108. In the case where the first comparison result, the second comparison result, or the third comparison result is consistent, determine that the directory fingerprint information of the item to be detected successfully matches the directory fingerprint information of at least one open-source project.

[0104] Exemplarily, the directory fingerprint information of the item to be detected includes the root directory fingerprint information and sub-directory fingerprint information of the item to be detected. Similarly, the directory fingerprint information of each open-source project in the open-source project library includes the root directory fingerprint information and sub-directory fingerprint information of each respective open-source project.

[0105] On this premise, considering that there may be complex association relationships such as being the same, being included, or including among different open-source projects at the directory level, and the application requirements of matching the same projects and components of the item to be detected need to be prioritized, compare the root directory fingerprint information of the item to be detected with the root directory fingerprint information of each open-source project to obtain a first comparison result. If the root directory fingerprint information of the item to be detected is inconsistent with the root directory fingerprint information of each open-source project, the first comparison result is inconsistent. If the root directory fingerprint information of the item to be detected is consistent with the root directory fingerprint information of at least one open-source project, the first comparison result is consistent.

[0106] In the case where the first comparison result is inconsistent, continue to compare the root directory fingerprint information of the item to be detected with the sub-directory fingerprint information of each open-source project to obtain a second comparison result. If the root directory fingerprint information of the item to be detected is inconsistent with the sub-directory fingerprint information of each open-source project, the second comparison result is inconsistent. If the root directory fingerprint information of the item to be detected is consistent with the sub-directory fingerprint information of at least one open-source project, the second comparison result is consistent.

[0107] In the case where the second comparison result is inconsistent, continue to compare the sub-directory fingerprint information of the item to be detected with the root directory fingerprint information of each open-source project to obtain a third comparison result. If the sub-directory fingerprint information of the item to be detected is inconsistent with the root directory fingerprint information of each open-source project, the third comparison result is inconsistent. If the sub-directory fingerprint information of the item to be detected is consistent with the root directory fingerprint information of at least one open-source project, the third comparison result is consistent.

[0108] In the case where the third comparison result is inconsistent, it is determined that the directory fingerprint information of the item to be detected fails to match the directory fingerprint information of each open-source project.

[0109] In the case where the first comparison result, the second comparison result, or the third comparison result is consistent, it is determined that the directory fingerprint information of the item to be detected successfully matches the directory fingerprint information of at least one open-source project.

[0110] It can be understood that if the first comparison result is consistent, that is, the root directory fingerprint information of the item to be detected is consistent with the root directory fingerprint information of at least one open-source project, it is considered that the item to be detected and this part of the open-source projects are the same project, and the directory fingerprint information of the item to be detected successfully matches the directory fingerprint information of this part of the open-source projects; if the second comparison result is consistent, that is, the root directory fingerprint information of the item to be detected is consistent with the sub-directory fingerprint information of at least one open-source project, it is considered that the item to be detected belongs to each of the open-source projects in this part of the open-source projects, and the directory fingerprint information of the item to be detected successfully matches the directory fingerprint information of this part of the open-source projects; if the third comparison result is consistent, that is, the sub-directory fingerprint information of the item to be detected is the same as the root directory fingerprint information of at least one open-source project, it is considered that the item to be detected contains each of the open-source projects in this part of the open-source projects, and the directory fingerprint information of the item to be detected successfully matches the directory fingerprint information of this part of the open-source projects; if the first comparison result, the second comparison result, and the third comparison result are inconsistent, it is considered that there is no association between the item to be detected and each open-source project at the directory level, and the directory fingerprint information of the item to be detected fails to match the directory fingerprint information of each open-source project.

[0111] In the embodiment of the present application, on the premise that the directory fingerprint information of the project includes the root directory fingerprint information and the sub-directory fingerprint information, the root directory fingerprint information of the project to be detected is compared with the root directory fingerprint information of each open-source project in turn, the root directory fingerprint information of the project to be detected is compared with the sub-directory fingerprint information of each open-source project, and the sub-directory fingerprint information of the project to be detected is compared with the root directory fingerprint information of each open-source project. By comprehensively considering all the comparison results, the directory-level matching results between the project to be detected and each open-source project are determined, which can effectively judge the complex association relationships between different projects, ensure that the most similar open-source projects and components to the project to be detected are matched, and is beneficial to further improving the SCA detection efficiency.

[0112] In an alternative embodiment, evaluating the similarity between the project to be detected and each target open-source project according to the matching results of the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project in the open-source project library, and the matching results of the file attribute information of the project to be detected and the file attribute information of each target open-source project, includes: for each target open-source project in the open-source project library, evaluating the first similarity between the project to be detected and the target open-source project according to the matching results of the file fingerprint information of the project to be detected and the file fingerprint information of the target open-source project; evaluating the second similarity between the project to be detected and the target open-source project according to the matching results of the file attribute information of the project to be detected and the file attribute information of the target open-source project; and determining the similarity between the project to be detected and the target open-source project according to the first similarity between the project to be detected and the target open-source project, and the second similarity between the project to be detected and the target open-source project.

[0113] Exemplarily, after obtaining the matching results of the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project, and the matching results of the file attribute information of the project to be detected and the file attribute information of each target open-source project, for each target open-source project, evaluating the first similarity between the project to be detected and the target open-source project according to the matching results of the file fingerprint information of the project to be detected and the file fingerprint information of the target open-source project, and evaluating the second similarity between the project to be detected and the target open-source project according to the matching results of the file attribute information of the project to be detected and the file attribute information of the target open-source project. Then, according to the first similarity between the project to be detected and the target open-source project, and the second similarity between the project to be detected and the target open-source project, determining the similarity between the project to be detected and the target open-source project, so as to obtain the similarities between the project to be detected and each target open-source project.

[0114] In practical applications, the weights for the first similarity and the weights for the second similarity can be preset. By weighted summing the first similarity and the second similarity according to the weights for the first similarity and the weights for the second similarity, the overall similarity is obtained.

[0115] In the embodiments of the present application, first, the first similarity between the item to be detected and the target open-source project is separately evaluated according to the matching result based on the file fingerprint information, and the second similarity between the item to be detected and the target open-source project is separately evaluated according to the matching result based on the file attribute information. Then, according to the first similarity and the second similarity, the similarity between the item to be detected and the target open-source project is comprehensively evaluated, which can ensure the accurate evaluation of the similarity between the item to be detected and the target open-source project and is beneficial to further improving the SCA detection accuracy.

[0116] In an alternative embodiment, the file fingerprint information of the item to be detected includes the hash fingerprints and simhash fingerprints of each code file in the item to be detected, and the file fingerprint information of the target open-source project includes the hash fingerprints and simhash fingerprints of each code file in the target open-source project; before evaluating the first similarity between the item to be detected and the target open-source project according to the matching result of the file fingerprint information of the item to be detected and the file fingerprint information of the target open-source project, it further includes: respectively comparing the hash fingerprint of each code file in the item to be detected with the hash fingerprints of each code file in the target open-source project to obtain the first comparison result of the hash fingerprints of each code file in the item to be detected and the hash fingerprints of each code file in the target open-source project; respectively comparing the simhash fingerprint of each first target code file in the item to be detected with the simhash fingerprints of each code file in the target open-source project to obtain the second comparison result of the simhash fingerprints of each first target code file in the item to be detected and the simhash fingerprints of each code file in the target open-source project; wherein, the hash fingerprint of the first target code file is inconsistent with the hash fingerprints of each code file in the target open-source project; according to the first comparison result and the second comparison result, the matching result of the file fingerprint information of the item to be detected and the file fingerprint information of the target open-source project is determined.

[0117] Exemplarily, an exact hashing algorithm is used to obtain the hash fingerprints of each code file in the item to be detected, and the simhash algorithm is used to obtain the simhash fingerprints of each code file in the item to be detected, so that the file fingerprint information of the item to be detected includes the respective hash fingerprints and simhash fingerprints of each code file in the item to be detected. Similarly, for each target open-source project, an exact hashing algorithm is used to obtain the hash fingerprints of each code file in the target open-source project, and the simhash algorithm is used to obtain the simhash fingerprints of each code file in the target open-source project, so that the file fingerprint information of the target open-source project includes the respective hash fingerprints and simhash fingerprints of each code file in the target open-source project.

[0118] For each code file in the item to be detected, compare the hash fingerprint of the current code file with the hash fingerprints of each code file in the target open-source project to obtain a comparison result of the hash fingerprint of the current code file and the hash fingerprints of each code file in the target open-source project. Among them, the comparison result of the hash fingerprint of the current code file and the hash fingerprints of each code file in the target open-source project is: consistent comparison or inconsistent comparison.

[0119] If the hash fingerprint of the current code file is consistent with the hash fingerprints of at least one code file in the target open-source project, it is considered that the current code file and these code files are the same files. At this time, it is determined that the file fingerprint information of the current code file matches the file fingerprint information of the target open-source project successfully.

[0120] If the hash fingerprint of the current code file is inconsistent with the hash fingerprints of each code file in the target open-source project, it is considered that the current code file and each code file in the target open-source project are different files. At this time, the current code file is determined as the first target code file, and continue to compare the simhash fingerprint of the first target code file with the simhash fingerprints of each code file in the target open-source project to obtain a secondary comparison result of the simhash fingerprint of the first target code file and the simhash fingerprints of each code file in the target open-source project. Among them, the secondary comparison result of the simhash fingerprint of the first target code file and the simhash fingerprints of each code file in the target open-source project is: whether the Hamming distance between the simhash fingerprint of the first target code file and the simhash fingerprints of each code file in the target open-source project is less than the preset Hamming distance threshold.

[0121] If the Hamming distance between the simhash fingerprint of the first target code file and the simhash fingerprints of at least one code file in the target open-source project is less than the preset Hamming distance threshold, it is considered that the first target code file and these code files are similar files. At this time, it is determined that the file fingerprint information of the first target code file matches the file fingerprint information of the target open-source project successfully.

[0122] If the Hamming distance between the simhash fingerprint of the first target code file and the simhash fingerprints of each code file in the target open-source project is greater than or equal to the preset Hamming distance threshold, it is considered that the current first target code file and each code file in the target open-source project are not similar files. At this time, it is determined that the file fingerprint information of the first target code file does not match the file fingerprint information of the target open-source project.

[0123] Determine the matching result between the file fingerprint information of the item to be detected and the file fingerprint information of the target open-source project according to the primary comparison result and the secondary comparison result obtained in the above comparison process.

[0124] By adopting a multi-layer matching strategy of hash fingerprint and simhash fingerprint for project matching based on file fingerprint information, the accurate matching and approximate matching capabilities of the multi-layer matching strategy can be utilized to comprehensively and accurately determine the matching result based on file fingerprint information, ensuring that the similarity of file fingerprint information between the item to be detected and the known open-source project can still be accurately captured under the condition of minor changes in the project file content, effectively avoiding the detection missing problem caused by minor changes in the project file content, and improving the SCA detection accuracy.

[0125] In the embodiment of the present application, the hash fingerprints of each code file in the item to be detected are respectively compared with the hash fingerprints of each code file in the target open-source project to obtain the primary comparison result of the hash fingerprints of each code file in the item to be detected and the hash fingerprints of each code file in the target open-source project. The simhash fingerprints of each first target code file in the item to be detected are respectively compared with the simhash fingerprints of each code file in the target open-source project to obtain the secondary comparison result of the simhash fingerprints of each target code file in the item to be detected and the simhash fingerprints of each code file in the target open-source project. According to the primary comparison result and the secondary comparison result, the matching result based on file fingerprint information is determined, and the accurate matching and approximate matching capabilities of the multi-layer matching strategy can be utilized to comprehensively and accurately determine the matching result based on file fingerprint information, so as to effectively match similar projects and components even under the condition of minor changes in the project file content, and improve the SCA detection accuracy.

[0126] In an alternative embodiment, the file attribute information of the project to be detected includes the file type, the directory tree level where it is located, and the file size of each code file in the project to be detected, and the file attribute information of the target open-source project includes the file type, the directory tree level where it is located, and the file size of each code file in the target open-source project; before evaluating the second similarity between the project to be detected and the target open-source project according to the matching result of the file attribute information of the project to be detected and the file attribute information of the target open-source project, it further includes: dividing all code files with the same file type and the same directory tree level in the project to be detected into the same code file set to obtain all code file sets in the project to be detected; dividing all code files with the same file type and the same directory tree level in the target open-source project into the same code file set to obtain all code file sets in the target open-source project; determining the first code file set in the project to be detected and the second code file set in the target open-source project; wherein, the first code file set and the second code file set correspond to the same file type and the same directory tree level; respectively matching the file size of each first code file in the first code file set with the file size of each second code file in the second code file set to obtain the matching result of the file attribute information of the project to be detected and the file attribute information of the target open-source project.

[0127] Exemplarily, the file attribute information of the project to be detected includes the file type, the directory tree level where it is located, and the file size of each code file in the project to be detected. Similarly, for each target open-source project, the file attribute information of the target open-source project includes the file type, the directory tree level where it is located, and the file size of each code file in the target open-source project.

[0128] On this premise, cluster each code file in the two projects of the project to be detected and the target open-source project according to the file type and the directory tree level respectively. Specifically, divide all code files with the same file type and the same directory tree level in the project to be detected into the same code file set to obtain all code file sets in the project to be detected, and divide all code files with the same file type and the same directory tree level in the target open-source project into the same code file set to obtain all code file sets in the target open-source project.

[0129] For each combination of file type and directory tree level, select the code file set corresponding to the file type and the directory tree level from the respective code file sets in the project to be detected as the first code file set, and select the code file set corresponding to the file type and the directory tree level from the respective code file sets in the target open-source project as the second code file set. It can be understood that the first code file set and the second code file set correspond to the same file type and the same directory tree level.

[0130] For each first code file in the first set of code files, match the file size of the current first code file with the file sizes of the second code files in the second set of code files. If the file size of the current first code file matches the file size of at least one second code file in the second set of code files, then the current first code file and this part of the second code files are considered similar files. At this time, it is determined that the file attribute information of the current first code file matches the file attribute information of the target open source project. If the file size of the current first code file fails to match the file sizes of the second code files in the second set of code files, then the current first code file and the second code files in the second set of code files are considered different files. At this time, it is determined that the file attribute information of the current first code file does not match the file attribute information of the target open source project, so as to obtain the matching result of the file attribute information of the project to be detected and the file attribute information of the target open source project.

[0131] It should be noted that if there is a first set of code files in the project to be detected corresponding to a certain file type and a certain directory tree level, and there is no second set of code files in the target open source project corresponding to this file type and this directory tree level, then it can be directly determined that the file attribute information of each first code file in the first set of code files does not match the file attribute information of the target open source project.

[0132] By introducing file attribute information such as file type, directory tree level, and file size for project matching, and during the process of project matching based on file attribute information, first cluster the code files in the project into sets of code files according to file type and directory tree level, and then match the file sizes of the same type of code files in the two projects to obtain the matching result based on file attribute information. This can ensure that the matching result based on file attribute information accurately reflects the file attribute similarity between the two projects, enabling the similarity between the project to be detected and the known open source project to be accurately captured even when the structure of the project to be detected is adjusted. Thus, similar projects and components can be effectively matched even in cases such as project structure adjustment, improving the SCA detection accuracy.

[0133] In the embodiments of the present application, by clustering each code file in the project to be detected into each code file set according to the file type and the level in the directory tree, clustering each code file in the target open-source project into each code file set according to the file type and the level in the directory tree, and matching the file sizes of the same type of code files in the project to be detected and the target open-source project, a matching result based on file attribute information is obtained, which can ensure that the matching result based on file attribute information accurately reflects the similarity of file attributes between the two projects, so that similar projects and components can be effectively matched even in the case of project structure adjustment, etc., improving the SCA detection accuracy.

[0134] In an alternative embodiment, the step of respectively matching the file size of each first code file in the first code file set with the file sizes of each second code file in the second code file set to obtain the matching result of the file attribute information of the project to be detected and the file attribute information of the target open-source project includes: traversing each first code file in the first code file set and each second code file in the second code file set in ascending order of file size; comparing the file size of the current first code file with the file size of the current second code file to obtain the difference between the file size of the current first code file and the file size of the current second code file; when the difference does not meet the preset difference condition, determining the second target code file with the smaller file size among the current first code file and the current second code file, and updating the second target code file to the next code file traversed from the code file set corresponding to the second target code file for re-comparison to obtain a new difference; when the difference or the new difference meets the preset difference condition, continuing to traverse the next first code file in the first code file set and the next code file in the second code file set for comparison until all the code files in the first code file set and the second code file set have been compared; and determining the matching result of the file attribute information of the project to be detected and the file attribute information of the target open-source project according to the comparison result between all the first code file sets in the project to be detected and all the second code file sets in the target open-source project.

[0135] Exemplarily, after obtaining the first code file set and the second code file set, traverse each first code file in the first code file set and each second code file in the second code file set in ascending order of file size, that is, from smallest to largest file size, and compare the file size of the current first code file with the file size of the current second code file to obtain the difference between the file size of the current first code file and the file size of the current second code file.

[0136] When the difference does not meet the preset difference condition, it is considered that the two code files participating in the comparison, that is, the current first code file and the current second code file, are different files. At this time, the code file with the smaller file size among the two code files of the current first code file and the current second code file is determined as the second target code file, and the second target code file is updated to the next code file traversed from the code file set corresponding to the second target code file to re - perform the comparison and obtain a new difference.

[0137] For example, assume that the current first code file has a smaller file size and the current second code file has a larger file size. Then, at this time, the current first code file will be updated to the next first code file in the first code file set, and then the file size of the current first code file will be compared with the file size of the current second code file again to obtain a new difference.

[0138] When the difference or the new difference meets the preset difference condition, it is considered that the two code files participating in the comparison are similar files. At this time, it is determined that the file attribute information of the code file participating in the comparison in the item to be detected (that is, the current first code file or the next first code file in the first code file set) matches the file attribute information of the target open - source project. Then, continue to traverse the next first code file in the first code file set and the next code file in the second code file set for comparison until all code files in the first code file set and the second code file set have been compared.

[0139] According to this operation, based on the comparison results between all the first code file sets in the item to be detected and all the second code file sets in the target open - source project, the matching result of the file attribute information of the item to be detected and the file attribute information of the target open - source project is determined.

[0140] In an optional implementation manner of this embodiment, the preset difference condition includes that the difference is less than the preset difference threshold.

[0141] By matching the file sizes of the same - type code files in the item to be detected and the target open - source project one by one in ascending order of file size, the present application embodiment obtains a matching result based on file attribute information, which can ensure that the most similar open - source project and components to the item to be detected are matched, and is beneficial to further improving the SCA detection accuracy.

[0142] In an alternative embodiment, the first similarity between the project to be detected and the target open-source project is determined based on the number of code files in the project to be detected, the number of code files in the target open-source project, and the number of code files in the project to be detected whose file fingerprint information matches the file fingerprint information of the target open-source project; the second similarity between the project to be detected and the target open-source project is determined based on the number of code files in the project to be detected, the number of code files in the target open-source project, and the number of code files in the project to be detected whose file attribute information matches the file attribute information of the target open-source project.

[0143] Exemplarily, for each target open-source project, after obtaining the matching result between the file fingerprint information of the project to be detected and the file fingerprint information of the target open-source project, the number of code files in the project to be detected is counted, the number of code files in the target open-source project is counted, and based on the matching result between the file fingerprint information of the project to be detected and the file fingerprint information of the target open-source project, the number of code files in the project to be detected whose file fingerprint information matches the file fingerprint information of the target open-source project is counted. Then, based on the number of code files in the project to be detected, the number of code files in the target open-source project, and the number of code files in the project to be detected whose file fingerprint information matches the file fingerprint information of the target open-source project, the first similarity between the project to be detected and the target open-source project is determined.

[0144] In an alternative implementation manner of this embodiment, the first similarity between the project to be detected and the target open-source project is equal to the ratio of the number of code files in the project to be detected whose file fingerprint information matches the file fingerprint information of the target open-source project to the number of target code files; wherein, the number of target code files is the minimum value between the number of code files in the project to be detected and the number of code files in the target open-source project.

[0145] For example, assume that the number of code files in the project to be detected is a, the number of code files in the target open-source project is b, and the number of code files in the project to be detected whose file fingerprint information matches the file fingerprint information of the target open-source project is c, where a, b, and c are all positive integers and a ≥ c. Then, the first similarity between the project to be detected and the target open-source project = 。

[0146] After obtaining the matching result of the file attribute information of the item to be detected and the file attribute information of the target open-source project, count the number of code files in the item to be detected, count the number of code files in the target open-source project, and according to the matching result of the file attribute information of the item to be detected and the file attribute information of the target open-source project, count the number of code files in the item to be detected whose file attribute information matches the file attribute information of the target open-source project, and determine the second similarity between the item to be detected and the target open-source project based on the number of code files in the item to be detected, the number of code files in the target open-source project, and the number of code files in the item to be detected whose file attribute information matches the file attribute information of the target open-source project.

[0147] In an alternative implementation of this embodiment, the second similarity between the item to be detected and the target open-source project is equal to the ratio of the number of code files in the item to be detected whose file attribute information matches the file attribute information of the target open-source project to the number of target code files; wherein, the number of target code files is the minimum value between the number of code files in the item to be detected and the number of code files in the target open-source project.

[0148] Assume that the number of code files in the item to be detected is a, the number of code files in the target open-source project is b, and the number of code files in the item to be detected whose file attribute information matches the file attribute information of the target open-source project is d, where a, b, and d are all positive integers, and a ≥ d, then the second similarity between the item to be detected and the target open-source project = .

[0149] In the embodiment of the present application, by determining the first similarity between the item to be detected and the target open-source project according to the number of code files in the item to be detected, the number of code files in the target open-source project, and the number of code files in the item to be detected whose file fingerprint information matches the file fingerprint information of the target open-source project, and determining the second similarity between the item to be detected and the target open-source project according to the number of code files in the item to be detected, the number of code files in the target open-source project, and the number of code files in the item to be detected whose file attribute information matches the file attribute information of the target open-source project, the first similarity and the second similarity between the item to be detected and the target open-source project can be quickly and accurately evaluated.

[0150] In an alternative embodiment, the preset project similarity condition includes that the similarity between the item to be detected and the target open-source project is greater than the preset project similarity threshold.

[0151] Exemplarily, after obtaining the similarity between the project to be detected and each target open-source project, compare the similarity between the project to be detected and each target open-source project with a preset project similarity threshold. If the similarity between the project to be detected and any target open-source project is greater than the preset project similarity threshold, it is considered that the project to be detected is similar to the target open-source project. At this time, determine the component version corresponding to the target open-source project, and use the component version corresponding to the target open-source project as the component version corresponding to the project to be detected, thereby completing the matching of the similar components of the project to be detected; if the similarity between the project to be detected and each target open-source project is less than or equal to the preset project similarity threshold, it is considered that the project to be detected is not similar to each target open-source project. At this time, it can be determined that there are no similar projects and components of the project to be detected in the open-source project library.

[0152] In practical applications, in order to preferentially match the open-source project and components that are most similar to the project to be detected, it can also be determined that the preset project similarity condition includes that the similarity between the project to be detected and the target open-source project is the maximum value in the project similarity set. The project similarity set includes the similarities between the project to be detected and each target open-source project.

[0153] The embodiment of the present application determines whether the project to be detected is similar to the target open-source project by determining whether the similarity between the project to be detected and the target open-source project is greater than the preset project similarity threshold, and can quickly and accurately determine the open-source project and components similar to the project to be detected.

[0154] To more clearly illustrate a SCA detection method based on project similarity provided in the first embodiment of the present application, the data flow diagram of applying the SCA detection method based on project similarity is as Figure 3 shown.

[0155] For a SCA detection method based on project similarity provided in the first embodiment of the present application, for the adjustment of the project directory tree structure, the directory fingerprint information of the two projects is preferentially matched. Since the directory fingerprint information of the project is obtained by sorting and hashing the file hash values of each code file under the project directory tree in order of file hash value size, the interference of the project directory tree structure adjustment on the project relationship matching can be eliminated, and the project relationship independent of the directory tree structure can be obtained, solving the problem of dependency analysis between complex projects. For the case of minor changes in the project file content, the simhash algorithm is additionally used for matching to ensure that even if the file content is slightly changed, the association between the current version and the original version of the project can be accurately captured. For the case of similar project structures, file attribute information is further introduced to calculate the project similarity, thereby improving the reliability of the detection.

[0156] Compared with the traditional SCA solution based on the exact hashing algorithm, the embodiment of the present application provides a robust approximate matching ability for the SCA system, which can effectively match similar projects and components even when the project directory tree structure is adjusted or the file content is changed. At the same time, it significantly enhances the adaptability of the SCA system to the dynamic changes of the directory tree structure and complex file structures, provides high-precision matching for large-scale file changes, and provides strong support for software development and compliance management.

[0157] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of an SCA detection device based on project similarity provided by the second embodiment of the present application. The second embodiment of the present application provides an SCA detection device based on project similarity, including: a project matching module 201, configured to evaluate the similarity between the project to be detected and each target open-source project according to the matching result of the file fingerprint information of the project to be detected and the file fingerprint information of each open-source project in the open-source project library, and the matching result of the file attribute information of the project to be detected and the file attribute information of each target open-source project when the matching between the directory fingerprint information of the project to be detected and the directory fingerprint information of each open-source project in the open-source project library fails; an SCA detection module 202, configured to determine the component version corresponding to the project to be detected as the component version corresponding to at least one target open-source project when the similarity between the project to be detected and at least one target open-source project in the open-source project library meets the preset project similarity condition; the SCA detection module 202 is further configured to determine the component version corresponding to the project to be detected as the component version corresponding to at least one open-source project when the directory fingerprint information of the project to be detected matches the directory fingerprint information of at least one open-source project in the open-source project library.

[0158] In an optional embodiment, the similarity between the project fingerprint information of each target open-source project and the project fingerprint information of the project to be detected meets the preset project fingerprint similarity condition.

[0159] In an alternative embodiment, the directory fingerprint information of the item to be detected includes the root directory fingerprint information and sub-directory fingerprint information of the item to be detected, and the directory fingerprint information of each open-source project includes the root directory fingerprint information and sub-directory fingerprint information of each open-source project; the project matching module 201 is further configured to: compare the root directory fingerprint information of the item to be detected with the root directory fingerprint information of each open-source project to obtain a first comparison result; in the case where the first comparison result is inconsistent, compare the root directory fingerprint information of the item to be detected with the sub-directory fingerprint information of each open-source project to obtain a second comparison result; in the case where the second comparison result is inconsistent, compare the sub-directory fingerprint information of the item to be detected with the root directory fingerprint information of each open-source project to obtain a third comparison result; in the case where the third comparison result is inconsistent, determine that the directory fingerprint information of the item to be detected fails to match the directory fingerprint information of each open-source project; in the case where the first comparison result, the second comparison result, or the third comparison result is consistent, determine that the directory fingerprint information of the item to be detected successfully matches the directory fingerprint information of at least one open-source project.

[0160] In an alternative embodiment, evaluating the similarity between the item to be detected and each target open-source project according to the matching result of the file fingerprint information of the item to be detected and the file fingerprint information of each target open-source project in the open-source project library, and the matching result of the file attribute information of the item to be detected and the file attribute information of each target open-source project includes: for each target open-source project in the open-source project library, evaluating the first similarity between the item to be detected and the target open-source project according to the matching result of the file fingerprint information of the item to be detected and the file fingerprint information of the target open-source project; evaluating the second similarity between the item to be detected and the target open-source project according to the matching result of the file attribute information of the item to be detected and the file attribute information of the target open-source project; determining the similarity between the item to be detected and the target open-source project according to the first similarity between the item to be detected and the target open-source project, and the second similarity between the item to be detected and the target open-source project.

[0161] In an alternative embodiment, the file fingerprint information of the project to be detected includes the hash fingerprints and simhash fingerprints of each code file in the project to be detected, and the file fingerprint information of the target open-source project includes the hash fingerprints and simhash fingerprints of each code file in the target open-source project; the project matching module 201 is further configured to, before evaluating the first similarity between the project to be detected and the target open-source project according to the matching result of the file fingerprint information of the project to be detected and the file fingerprint information of the target open-source project, respectively compare the hash fingerprint of each code file in the project to be detected with the hash fingerprints of each code file in the target open-source project to obtain a primary comparison result of the hash fingerprints of each code file in the project to be detected and the hash fingerprints of each code file in the target open-source project; respectively compare the simhash fingerprint of each first target code file in the project to be detected with the simhash fingerprints of each code file in the target open-source project to obtain a secondary comparison result of the simhash fingerprints of each first target code file in the project to be detected and the simhash fingerprints of each code file in the target open-source project; wherein, the hash fingerprint of the first target code file is inconsistent with the hash fingerprints of each code file in the target open-source project; according to the primary comparison result and the secondary comparison result, determine the matching result of the file fingerprint information of the project to be detected and the file fingerprint information of the target open-source project.

[0162] In an alternative embodiment, the file attribute information of the project to be detected includes the file type, the directory tree level where it is located, and the file size of each code file in the project to be detected, and the file attribute information of the target open-source project includes the file type, the directory tree level where it is located, and the file size of each code file in the target open-source project; the project matching module 201 is further configured to, before evaluating the second similarity between the project to be detected and the target open-source project according to the matching result of the file attribute information of the project to be detected and the file attribute information of the target open-source project, divide all code files with the same file type and directory tree level in the project to be detected into the same code file set to obtain all code file sets in the project to be detected; divide all code files with the same file type and directory tree level in the target open-source project into the same code file set to obtain all code file sets in the target open-source project; determine the first code file set in the project to be detected and the second code file set in the target open-source project; wherein, the first code file set and the second code file set correspond to the same file type and the same directory tree level; respectively match the file size of each first code file in the first code file set with the file sizes of each second code file in the second code file set to obtain the matching result of the file attribute information of the project to be detected and the file attribute information of the target open-source project.

[0163] In an alternative embodiment, matching the file size of each first code file in the first code file set with the file size of each second code file in the second code file set to obtain the matching result of the file attribute information of the item to be detected and the file attribute information of the target open source project includes: traversing each first code file in the first code file set and each second code file in the second code file set in ascending order of file size; comparing the file size of the current first code file with the file size of the current second code file to obtain the difference between the file size of the current first code file and the file size of the current second code file; when the difference does not meet the preset difference condition, determining the second target code file with the smaller file size among the current first code file and the current second code file, and updating the second target code file to the next code file traversed from the code file set corresponding to the second target code file to re-perform the comparison to obtain a new difference; when the difference or the new difference meets the preset difference condition, continuing to traverse the next first code file in the first code file set and the next code file in the second code file set for comparison until all the code files in the first code file set and the second code file set have been compared; determining the matching result of the file attribute information of the item to be detected and the file attribute information of the target open source project according to the comparison result between all the first code file sets in the item to be detected and all the second code file sets in the target open source project.

[0164] In an alternative embodiment, the first similarity between the item to be detected and the target open source project is determined according to the number of code files in the item to be detected, the number of code files in the target open source project, and the number of code files with successfully matched file fingerprint information between the item to be detected and the target open source project; the second similarity between the item to be detected and the target open source project is determined according to the number of code files in the item to be detected, the number of code files in the target open source project, and the number of code files with successfully matched file attribute information between the item to be detected and the target open source project.

[0165] In an alternative embodiment, the preset project similarity condition includes that the similarity between the item to be detected and the target open source project is greater than the preset project similarity threshold.

[0166] The implementation processes of the functions and roles of the various modules in the above device are specifically described in detail in the implementation processes of the corresponding steps in the above method, and will not be elaborated here.

[0167] Please refer to Figure 5 , Figure 5A schematic structural diagram of an electronic device provided by the third embodiment of the present application. The third embodiment of the present application provides an electronic device 30, including a processor 301, a memory 302, and a computer program stored in the memory 302 and configured to be executed by the processor 301; when the processor 301 executes the computer program, it implements the method described in the first embodiment of the present application and can achieve the same beneficial effects.

[0168] Among them, when the processor 301 reads the computer program from the memory 302 through the bus 303 and executes the computer program, it can implement the method described in the first embodiment of the present application.

[0169] The processor 301 can process digital signals and can include various computing architectures. For example, a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, the processor 301 may be a microprocessor.

[0170] The memory 302 can be used to store instructions executed by the processor 301 or data related to the execution of the instructions. These instructions and / or data may include code for implementing some or all of the functions of one or more modules described in the embodiments of the present application. The processor 301 of this embodiment can be used to execute the instructions in the memory 302 to implement the method described in the first embodiment of the present application. The memory 302 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.

[0171] The fourth embodiment of the present application provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the method described in the first embodiment of the present application and can achieve the same beneficial effects.

[0172] In summary, the embodiments of the present application provide an SCA detection method, device, equipment and medium based on project similarity. The SCA detection method based on project similarity includes: when the directory fingerprint information of the project to be detected fails to match the directory fingerprint information of each open-source project in the open-source project library, evaluating the similarity between the project to be detected and each target open-source project according to the matching result of the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project in the open-source project library, and the matching result of the file attribute information of the project to be detected and the file attribute information of each target open-source project; when the similarity between the project to be detected and at least one target open-source project in the open-source project library meets the preset project similarity condition, determining the component version corresponding to at least one target open-source project as the component version corresponding to the project to be detected; when the directory fingerprint information of the project to be detected successfully matches the directory fingerprint information of at least one open-source project in the open-source project library, determining the component version corresponding to at least one open-source project as the component version corresponding to the project to be detected. By evaluating the project similarity between the project to be detected and each target open-source project according to the matching result of the file fingerprint information of the project to be detected and the file fingerprint information of each target open-source project in the open-source project library, and the matching result of the file attribute information of the project to be detected and the file attribute information of each target open-source project when the directory fingerprint information of the project to be detected fails to match the directory fingerprint information of each open-source project in the open-source project library, and determining the component version corresponding to the known open-source project as the component version corresponding to the project to be detected when the project similarity between the project to be detected and at least one target open-source project meets the preset project similarity condition or the directory fingerprint information of the project to be detected successfully matches the directory fingerprint information of at least one open-source project, the embodiments of the present application can comprehensively evaluate the similarity between two projects from multiple aspects, including the similarity of the directory tree structure at the directory level, the similarity of the file content at the file level, and the similarity of the file attributes, accurately determine the similar projects of the project to be detected, and determine the component version corresponding to the similar project as the component version corresponding to the project to be detected, so as to effectively match similar projects and components even when the project directory tree structure is adjusted or the file content is modified, improving the SCA detection efficiency and detection accuracy.

[0173] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0174] In addition, in each embodiment of the present application, the various functional modules may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0175] If the above functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs, etc., which can store program codes.

[0176] The above are only embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various modifications and changes can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0177] As described above, the above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all of them should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0178] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

Claims

1. A SCA detection method based on project similarity, characterized in that: include: In the case that the directory fingerprint information of the project to be detected fails to match the directory fingerprint information of each open source project in the open source project library, for each target open source project in the open source project library, the similarity between the project to be detected and the target open source project is determined according to the first similarity and the second similarity between the project to be detected and the target open source project; the first similarity is evaluated according to the result of matching the file fingerprint information between the project to be detected and the target open source project, and the second similarity is evaluated according to the result of matching the file attribute information between the project to be detected and the target open source project; The file fingerprint information includes the hash fingerprint and simhash fingerprint of each code file; the process of determining the file fingerprint information matching result is as follows: Determine the file fingerprint information matching result according to the first comparison result and the second comparison result of the project to be detected and the target open source project; the first comparison result is obtained by respectively comparing the hash fingerprint of each code file in the project to be detected with the hash fingerprint of each code file in the target open source project, and the second comparison result is obtained by respectively comparing the simhash fingerprint of each first target code file in the project to be detected with the simhash fingerprint of each code file in the target open source project, and the hash fingerprint of the first target code file is inconsistent with the hash fingerprint of each code file in the target open source project; In the case where the similarity between the project to be detected and at least one target open source project in the open source project library meets a preset project similarity condition, determining the component version corresponding to the at least one target open source project as the component version corresponding to the project to be detected; When the directory fingerprint information of the project to be detected successfully matches the directory fingerprint information of at least one open source project in the open source project library, the component version corresponding to the at least one open source project is determined as the component version corresponding to the project to be detected.

2. The method according to claim 1, characterized in that The similarity between the project fingerprint information of each target open source project and the project fingerprint information of the project to be detected meets a preset project fingerprint similarity condition.

3. The method according to claim 1, characterized in that The directory fingerprint information of the project to be detected includes the root directory fingerprint information and sub-directory fingerprint information of the project to be detected, and the directory fingerprint information of each open source project includes the root directory fingerprint information and sub-directory fingerprint information of each open source project; The method further comprises: Compare the root directory fingerprint information of the project to be detected with the root directory fingerprint information of each open source project to obtain a first comparison result; When the first comparison result is inconsistent, the root directory fingerprint information of the project to be detected is compared with the sub-directory fingerprint information of each open source project to obtain a second comparison result; When the second comparison result is inconsistent, the sub-directory fingerprint information of the project to be detected is compared with the root directory fingerprint information of each open source project to obtain a third comparison result; When the third comparison result is inconsistent, it is determined that the directory fingerprint information of the project to be detected fails to match the directory fingerprint information of each open source project; When the first comparison result, the second comparison result, or the third comparison result is consistent, it is determined that the directory fingerprint information of the project to be detected successfully matches the directory fingerprint information of the at least one open source project.

4. The method according to claim 1, characterized in that: The file attribute information of the project to be detected includes the file type, directory tree level and file size of each code file in the project to be detected, and the file attribute information of the target open source project includes the file type, directory tree level and file size of each code file in the target open source project; Before evaluating the second similarity between the project to be detected and the target open source project according to the matching result of the file attribute information of the project to be detected and the file attribute information of the target open source project, the method further includes: Classify all code files with the same file type and directory tree level in the project to be detected into the same code file set to obtain a set of all code files in the project to be detected; Classify all code files in the target open source project that have the same file type and directory tree level into the same code file set, to obtain a set of all code files in the target open source project; Determine a first code file set in the project to be detected and a second code file set in the target open source project; wherein the first code file set and the second code file set correspond to the same file type and are located at the same directory tree level; The file size of each first code file in the first code file set is matched with the file size of each second code file in the second code file set to obtain a matching result between the file attribute information of the project to be detected and the file attribute information of the target open source project.

5. The method according to claim 4, characterized in that The matching of the file size of each first code file in the first code file set with the file size of each second code file in the second code file set to obtain the matching result of the file attribute information of the project to be detected and the file attribute information of the target open source project includes: Traversing each first code file in the first code file set and traversing each second code file in the second code file set in ascending order of file size; Compare the file size of the current first code file with the file size of the current second code file to obtain a difference between the file size of the current first code file and the file size of the current second code file; If the difference does not satisfy a preset difference condition, determining a second target code file having a smaller file size between the current first code file and the current second code file, and updating the second target code file to a next code file traversed from a code file set corresponding to the second target code file, so as to re-compare and obtain a new difference; When the difference or the new difference satisfies the preset difference condition, continue traversing the next first code file in the first code file set and traversing the next code file in the second code file set for comparison until all code files in the first code file set and the second code file set have been compared; According to the comparison result between all the first code file sets in the project to be detected and all the second code file sets in the target open source project, a matching result between the file attribute information of the project to be detected and the file attribute information of the target open source project is determined.

6. The method according to claim 1, characterized in that The first similarity between the project to be detected and the target open source project is determined according to the number of code files in the project to be detected, the number of code files in the target open source project, and the number of code files whose file fingerprint information in the project to be detected successfully matches the file fingerprint information in the target open source project; The second similarity between the project to be detected and the target open source project is determined based on the number of code files in the project to be detected, the number of code files in the target open source project, and the number of code files whose file attribute information in the project to be detected successfully matches the file attribute information of the target open source project.

7. The method according to any one of claims 1 to 6, characterized in that: The preset project similarity condition includes that the similarity between the project to be detected and the target open source project is greater than a preset project similarity threshold.

8. A SCA detection device based on project similarity, characterized in that: include: A project matching module, for determining, for each target open source project in the open source project library, a similarity between the project to be detected and the target open source project according to a first similarity and a second similarity between the project to be detected and the target open source project, when the directory fingerprint information of the project to be detected fails to match the directory fingerprint information of each open source project in the open source project library; the first similarity is evaluated according to a result of matching file fingerprint information between the project to be detected and the target open source project, and the second similarity is evaluated according to a result of matching file attribute information between the project to be detected and the target open source project; The file fingerprint information includes the hash fingerprint and simhash fingerprint of each code file; the project matching module is further used to: determine the file fingerprint information matching result according to the first comparison result and the second comparison result between the project to be detected and the target open source project; the first comparison result is obtained by comparing the hash fingerprint of each code file in the project to be detected with the hash fingerprint of each code file in the target open source project, and the second comparison result is obtained by comparing the simhash fingerprint of each first target code file in the project to be detected with the simhash fingerprint of each code file in the target open source project, and the hash fingerprint of the first target code file is inconsistent with the hash fingerprint of each code file in the target open source project; An SCA detection module, configured to determine the component version corresponding to the at least one target open source project as the component version corresponding to the project to be detected when the similarity between the project to be detected and at least one target open source project in the open source project library meets a preset project similarity condition; The SCA detection module is further configured to determine the component version corresponding to the at least one open source project as the component version corresponding to the project to be detected when the directory fingerprint information of the project to be detected successfully matches the directory fingerprint information of at least one open source project in the open source project library.

9. An electronic device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • SCA-based code homology detection method and device, computer equipment and medium

    CN119377086A