Large model-assisted static code scanning result analysis method, device, electronic device and computer-readable storage medium
Through the analysis method of static code scanning results assisted by large-models, the problems of false positives and difficult-to-understand results of traditional static code scanning tools are solved, and automated analysis and accurate repair suggestions for static code scanning results are realized.
Patent Information
- Application Number
- CN202510206887.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-02-25
AI Technical Summary
Traditional static code scanning tools are prone to false positives when detecting code defects and security vulnerabilities, and the output detection results lack context information, which is difficult for developers to understand and repair.
The analysis method of static code scanning results assisted by large-model is adopted. By obtaining project compilation records and detection reports of static code scanning tools, compilation parameters and basic problem information are extracted, the source code involved is identified and the key information is processed. Based on this, the template is searched in the big model request template library and the request file is generated, triggering the big model analysis to generate the analysis results.
It realizes automated analysis of various problems in the detection report generated by the static code scanning tool, reduces the workload of manual analysis and repairs, and improves the accuracy and automation of result judgment.
Smart Images

Figure CN119690807B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a large model-assisted static code scanning result analysis method, device, electronic device and computer-readable storage medium. Background Art
[0002] As software scale and complexity continue to grow, potential defects and security vulnerabilities in the code have become the main hidden dangers that threaten the safe and stable operation of information systems and applications. Static code scanning tools, as a key code quality assurance tool, have been widely used in various stages of the software development life cycle to detect defects and potential vulnerabilities in the code. By scanning source code or intermediate code, these tools can identify potential problems before the code is executed, thereby providing developers with early warnings and improvement suggestions.
[0003] Traditional static code scanning tools mainly rely on predefined rule bases, model matching, and logical reasoning. Their detection process is characterized by high efficiency and wide coverage. However, due to the imperfection of the rule base or limited adaptability to specific scenarios, or the reduction of analysis accuracy in order to enhance the generalization ability of the analysis rules, these problems often cause a large number of false positives (i.e., false security alarms). The proliferation of false positives not only increases the burden on developers to identify problems, but may also cause real vulnerabilities to be ignored, threatening system security. In addition, the detection results output by the tool often lack sufficient contextual information and are less readable for ordinary developers, resulting in limited support for developers to fix problems, making problem location and the generation of repair suggestions rely on manual intervention. This traditional manual review and analysis method is time-consuming, labor-intensive, and inefficient. At the same time, it relies heavily on the experience level and domain knowledge of the alarm reviewers, making it difficult to promote in large and complex projects.
[0004] With the rapid development of artificial intelligence technology, especially big model technology, new possibilities have been provided for optimization in the field of static code analysis. Analysis methods based on big models can use machine learning and natural language processing technologies to learn code patterns from massive data. Therefore, the introduction of big model-based technologies to assist in analyzing and optimizing the results of static analysis tools can play an important role in improving development analysis efficiency, enhancing vulnerability location accuracy, and reducing security risks. However, if the code snippets involved in the alarms generated by static code scanning tools and the corresponding problem descriptions are directly input into the big model without processing and requesting results, various problems will be encountered that affect the final analysis results returned by the big model. For example, there is a problem of missing code context semantics. For languages such as C or C++ that contain similar macro definition structures, the macro definitions will be dynamically expanded in all locations where they are used when the source code is compiled. Some static code scanning tools perform analysis based on the expanded source code. This results in differences between the code snippets analyzed by the static code scanning tool and the code snippets directly extracted from the source code based on the descriptions of the problems in the scanning results, making it impossible for the large model to perceive the relationship between the alarm description and the code snippet. At the same time, for example, when the code in the alarm involves member functions in a class, extracting only the involved code or function snippets will also result in missing context semantics, affecting the accuracy of subsequent analysis results.
[0005] Therefore, a new static code scanning result analysis method is needed to solve the above problems.
[0006] It should be noted that the information disclosed in the background technology section of the invention is only intended to deepen the understanding of the general background technology of the invention, and should not be regarded as an admission or suggestion in any form that the information constitutes prior art already known to those skilled in the art. Summary of the invention
[0007] The purpose of the present invention is to provide a large-model-assisted static code scanning result analysis method, device, electronic device and computer-readable storage medium, which can quickly and effectively realize automated analysis of various problems in the detection report generated by the static code scanning tool and provide repair suggestions, thereby improving the degree of automation in static analysis result determination, reducing the workload of manual analysis and repair of problems, and improving the accuracy of result determination.
[0008] To achieve the above-mentioned objectives, the present invention provides a large model-assisted static code scanning result analysis method, comprising: obtaining a project compilation record of a target project and a code detection report of the target project output by a static code scanning tool, and extracting project compilation parameters in the project compilation record and basic information of each problem in the code detection report; identifying all source codes involved in the problem based on the basic information of the problem, and processing the project compilation parameters, the source code and the basic information to generate a key information set; searching for a template that meets the characteristics in a large model request template library according to the key information set and generating a corresponding request file; triggering the large model to analyze the problem according to the request file to generate an analysis result of the problem, wherein the analysis result includes a judgment conclusion, a problem analysis description and a repair suggestion.
[0009] Optionally, all source codes involved in the problem are identified based on the basic information of the problem, and the project compilation parameters, the source code and the basic information are processed to generate a key information set, including: identifying the problem description, the problem type, the problem triggering path and the problem triggering path description based on the basic information of the problem; identifying the source code to which each path node contained in the problem triggering path belongs and the position information of the path node in the source code; parsing the source code into an abstract syntax tree based on the project compilation parameters and identifying abstract syntax tree nodes; extracting code snippets and implicit information in the code snippets based on the project compilation parameters, the abstract syntax tree nodes, the position information of the path nodes in the source code and the problem triggering path description; and combining the code snippets, the implicit information in the code snippets, the problem description and the problem type into a key information set.
[0010] Optionally, the extracting of code snippets and implicit information in the code snippets based on the project compilation parameters, the abstract syntax tree nodes, the position information of the path nodes in the source code and the problem triggering path description includes: searching in the abstract syntax tree nodes based on the position information of the path nodes in the source code to find the corresponding statement nodes and the outer definition nodes to which the statement nodes belong; extracting all symbols contained in the statement nodes and identifying the symbol types contained in the statement nodes; performing corresponding processing based on the symbol types and the problem triggering path description to obtain the implicit information in the corresponding code snippets; generating code snippets based on the project compilation parameters, the implicit information in the code snippets and the outer definition nodes.
[0011] Optionally, the corresponding processing is performed based on the symbol type and the problem trigger path description to obtain implicit information in the corresponding code snippet, including: if the symbol type is a replacement type that needs to be expanded during compilation, the definition statement of the replacement type is extracted and the nested replacement type variables in the definition statement of the replacement type are processed in a loop; if the symbol type is a direct function call, the function call is generated into a corresponding control flow jump description statement; if the symbol type is an indirect function call, the description of the corresponding node is extracted based on the problem trigger path description and a corresponding control flow jump description statement is generated; if the symbol type is a variable, the type of the variable and the size of the memory space occupied are extracted to obtain variable information; if the variable type is a user-defined type, the type definition statement of the user-defined type is extracted and recorded, and the type definition statement of the user-defined type contained in the user-defined type is nested and extracted; if the symbol type is an operator, operation information is generated based on the description related to the operator in the problem trigger path description; the definition statement of the replacement type, the control flow jump description statement, the type definition statement, the variable information and the operation information are combined into implicit information in the corresponding code snippet.
[0012] Optionally, the generating of the code snippet based on the project compilation parameters, implicit information in the code snippet and the outer definition node includes: generating the required code snippet based on the type definition statement in the implicit information in the code snippet and the outer definition node; expanding the source code based on the definition statement of the replacement type in the implicit information in the code snippet to obtain a complete source code snippet; processing each conditional compilation statement and internal include statement in the source code snippet based on the project compilation parameters to obtain a valid code snippet.
[0013] Optionally, the generating the required code snippet based on the type definition statement in the implicit information in the code snippet and the outer definition node includes: extracting the code snippet in the corresponding source code based on the outer definition node; if the type of the outer definition node is a local definition type in a user-defined type, then supplementing the outer layer of the code snippet with a definition statement of the upper user-defined type to which the outer definition node belongs; if the outer definition node belongs to any namespace, then supplementing the outer layer of the code snippet with a namespace definition statement; generating the required code snippet based on the type definition statement in the implicit information in the code snippet and the code snippet.
[0014] Optionally, searching for a template that meets the features in the large model request template library based on the key information set and generating a corresponding request file includes: retrieving a template of a corresponding question type in the large model request template library based on the question type in the key information set; generating a corresponding request file based on the template and the code snippet in the key information set, the question description and implicit information in the code snippet.
[0015] To achieve the above-mentioned purpose, the present invention also provides a static code scanning result analysis device assisted by a large model, comprising: an acquisition module, configured to acquire a project compilation record of a target project and a code detection report of the target project output by a static code scanning tool, and extract project compilation parameters in the project compilation record and basic information of each problem in the code detection report; an extraction module, configured to identify all source codes involved in the problem based on the basic information of the problem, and process the project compilation parameters, the source code and the basic information to generate a key information set; a generation module, configured to search for a template that meets the characteristics in a large model request template library according to the key information set and generate a corresponding request file; and an analysis module, configured to trigger the large model to analyze the problem according to the request file to generate an analysis result of the problem, wherein the analysis result includes a judgment conclusion, a problem analysis description and a repair suggestion.
[0016] To achieve the above-mentioned objectives, the present invention also provides an electronic device, comprising at least one processor and at least one storage device, wherein the storage device is suitable for storing multiple program codes, and the program codes are suitable for being loaded and run by the processor to execute the large model-assisted static code scanning result analysis method described in any one of the above items.
[0017] To achieve the above objectives, the present invention also provides a computer-readable storage medium on which a plurality of program codes are stored, wherein the program codes are suitable for being loaded and run by a processor to execute the large model-assisted static code scanning result analysis method described in any one of the above.
[0018] Compared with the prior art, the large model-assisted static code scanning result analysis method, device, electronic device and computer-readable storage medium provided by the present invention have the following beneficial effects: the present invention first obtains the project compilation record of the target project and the code detection report of the target project output by the static code scanning tool, and extracts the project compilation parameters in the project compilation record and the basic information of each problem in the code detection report; then identifies all source codes involved in the problem based on the basic information of the problem, and processes the project compilation parameters, the source code and the basic information to generate a key information set; then searches for a template that meets the characteristics in the large model request template library according to the key information set and generates a corresponding request file; finally, triggers the large model according to the request file to analyze the problem to generate an analysis result of the problem, thereby quickly and effectively realizing the automatic analysis of each problem in the detection report generated by the static code scanning tool and giving repair suggestions, thereby improving the degree of automation of static analysis result determination, reducing the workload of manual analysis and repair of problems, and improving the accuracy of result determination.
[0019] Since the large model-assisted static code scanning result analysis device, electronic device and computer-readable storage medium provided by the present invention belong to the same inventive concept as the large model-assisted static code scanning result analysis method provided by the present invention, the large model-assisted static code scanning result analysis device, electronic device and computer-readable storage medium provided by the present invention at least have all the beneficial effects of the large model-assisted static code scanning result analysis method provided by the present invention. For details, please refer to the relevant description above. Therefore, the beneficial effects of the large model-assisted static code scanning result analysis device, electronic device and computer-readable storage medium provided by the present invention will not be described one by one. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 A flowchart of a large model-assisted static code scanning result analysis method provided in one embodiment of the present invention.
[0021] Figure 2 A flowchart of generating a key information set provided by an embodiment of the present invention.
[0022] Figure 3 A structural block diagram of a large model-assisted static code scanning result analysis device provided in one embodiment of the present invention.
[0023] Figure 4 A structural block diagram of an electronic device provided by an embodiment of the present invention.
[0024] The reference numerals are described as follows: acquisition module-110; extraction module-120; generation module-130; analysis module-140; processor-210; storage device-220. DETAILED DESCRIPTION
[0025] The following is a further detailed description of the static code scanning result analysis method, device, electronic device and computer-readable storage medium assisted by a large model proposed in the present invention in combination with the accompanying drawings and specific embodiments. According to the following description, the advantages and features of the present invention will be clearer. It should be noted that the drawings are in a very simplified form and use non-precise proportions, which are only used to conveniently and clearly assist in explaining the purpose of the present invention. In order to make the purposes, features and advantages of the present invention more obvious and easy to understand, please refer to the accompanying drawings. It should be noted that the structures, proportions, sizes, etc. illustrated in the drawings of this specification are only used to match the contents disclosed in the specification for people familiar with this technology to understand and read, and are not used to limit the limiting conditions for the implementation of the present invention. Any modification of the structure, change in the proportional relationship or adjustment of the size, in the case of the same or similar effects and purposes that can be achieved by the present invention, should still fall within the scope of the technical content disclosed by the present invention.
[0026] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or equipment. In the absence of more restrictions, the elements defined by the statement "comprise one..." do not exclude the existence of other identical elements in the process, method, article or equipment including the elements. The singular forms "a", "an" and "the" include plural objects, the term "or" is generally used in a sense including "and / or", the term "several" is generally used in a sense including "at least one", and the term "at least two" is generally used in a sense including "two or more". In addition, the terms "first", "second" and "third" are used for descriptive purposes only and are not to be understood as indicating or suggesting relative importance or implicitly indicating the number of the indicated technical features.
[0027] In addition, in the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.
[0028] The core idea of the present invention is to provide a large-model-assisted static code scanning result analysis method, device, electronic device and computer-readable storage medium, which can quickly and effectively realize automated analysis of various problems in the detection report generated by the static code scanning tool and provide repair suggestions, thereby improving the degree of automation in static analysis result determination, reducing the workload of manual analysis and repair of problems, and improving the accuracy of result determination.
[0029] It should be noted that the large model-assisted static code scanning result analysis method provided by the present invention can be applied to the large model-assisted static code scanning result analysis device provided by the present invention, and the large model-assisted static code scanning result analysis device can be configured on an electronic device, wherein the electronic device can be a personal computer, a mobile terminal, etc., and the mobile terminal can be a mobile phone, a tablet computer, and other hardware devices with various operating systems.
[0030] To realize the above idea, the present invention provides a large model-assisted static code scanning result analysis method, please refer to Figure 1 , which is a flow chart of a large model-assisted static code scanning result analysis method provided by an embodiment of the present invention, such as Figure 1 As shown, the large model-assisted static code scanning result analysis method provided in this embodiment includes the following steps S100 to S400.
[0031] Step S100: Obtain a project compilation record of a target project and a code detection report of the target project output by a static code scanning tool, and extract project compilation parameters in the project compilation record and basic information of each problem in the code detection report.
[0032] Step S200: identifying all source codes involved in the problem based on the basic information of the problem, and processing the project compilation parameters, the source codes and the basic information to generate a key information set.
[0033] Step S300: Search for a template that meets the characteristics in the large model request template library according to the key information set and generate a corresponding request file.
[0034] Step S400: triggering the big model to analyze the problem according to the request file to generate an analysis result of the problem, wherein the analysis result includes a judgment conclusion, a problem analysis description and a repair suggestion.
[0035] Therefore, the large model-assisted static code scanning result analysis method provided by the present invention can quickly and effectively realize automated analysis of various problems in the detection report generated by the static code scanning tool and provide repair suggestions, thereby improving the degree of automation in static analysis result judgment, reducing the workload of manual analysis and repair of problems, and improving the accuracy of result judgment.
[0036] Specifically, the project compilation record refers to the relevant information of the project compilation process generated by the project construction system or static code scanning tool during the target project compilation process, which can be automatically generated by the compiler or static code scanning tool when the target project is compiled, and is used to record the compilation parameters, dependencies and configuration options of each source file in the target project. For example, when the CMake tool is used to build the target project, a file named compile_commands.json is usually generated as part of the project compilation record. The file adopts a standardized record format and contains the compilation instructions and compilation options corresponding to each source file in the target project. Among them, CMake is an open source cross-platform build system that can generate build scripts suitable for different compilers or platforms by describing the construction process of the project. Based on the compile_commands.json file, each source file involved in the compilation in the target project and its corresponding compilation instructions can be extracted, and the compilation parameters corresponding to each source file can be further extracted.
[0037] The code detection report refers to the analysis output file generated by the static code scanning tool after performing detection on the target project. The report describes the potential code risks and related information identified during the analysis process of the static code scanning tool. In order to achieve a unified expression of the analysis results, it is necessary to preprocess the report files generated by different types of static code scanning tools. Common static code scanning tools include but are not limited to Coverity, Infer, Clang StaticAnalyzer, etc. The static code scanning tool usually generates a static analysis report file stored in the format of HTML, JSON, etc. Through the preprocessing step, the above-mentioned reports in different formats can be converted into a basic information representation of a unified structure, which describes the key features of the potential code problems identified by the static code scanning tool after analysis in the target project. The potential code problem refers to the possible code risks or defects detected by the static code scanning tool in the target project.
[0038] Please continue to refer to Figure 2 , which is a flow chart of generating a key information set provided by an embodiment of the present invention. Figure 2 As shown, the step S200, based on the basic information of the problem, identifies all source codes involved in the problem, and processes the project compilation parameters, the source code and the basic information to generate a key information set, including the following steps S210 to S250.
[0039] Step S210: Identify the problem description, problem type, problem triggering path and problem triggering path description based on the basic information of the problem.
[0040] Step S220: According to the problem triggering path, the source code to which each path node contained in the path belongs and the position information of the path node in the source code are identified.
[0041] Step S230: Parse the source code into an abstract syntax tree based on the project compilation parameters and identify abstract syntax tree nodes.
[0042] Step S240: extracting code snippets and implicit information in the code snippets based on the project compilation parameters, the abstract syntax tree nodes, the location information of the path nodes in the source code, and the problem triggering path description.
[0043] Step S250: Combine the code snippet, the implicit information in the code snippet, the problem description and the problem type into a key information set.
[0044] Therefore, by combining the code snippets extracted from steps S210 to S240, the implicit information in the code snippets, the problem description and the problem type into a key information set, a high-quality input basis can be provided for subsequent large model interaction and problem analysis.
[0045] Specifically, the basic information of the problem is key information extracted from the static code detection report to describe the code problem, including but not limited to the problem description, the potential impact information of the problem, the problem type, the problem triggering path, the problem triggering path description, etc.
[0046] The problem description is a description of the code location where the problem occurs and the potential impact of the problem. The code location where the problem occurs includes the path, line number, and column number of the source file.
[0047] The potential impact of the problem is the actual harm caused by the problem at the current code position, for example, variable A is not released at code position n, resulting in resource leakage.
[0048] The problem type is a classification of the problem, including but not limited to memory leaks, null pointer dereferences, uninitialized variable usage, etc.
[0049] The problem triggering path is a potential code execution path that triggers the problem and is generated by the static code scanning tool analysis. It consists of all program statement sequences involved in the execution path, including but not limited to various source code statement types such as assignment statements and control statements.
[0050] The problem trigger path description is used to further characterize the detailed description of the logical relationship between each node in the path and the problem. Assume that when the code statement corresponding to the path node is "if (varA==varB)", the condition that needs to be met at the node is "varA!=varB", where the symbols varA and varB can be variables or constants.
[0051] Further, for step S220, the problem trigger path provided in the code detection report output by the static code scanning tool can be analyzed to identify each node in the path (path node) and scan it. Each path node represents a specific position in the code execution process, such as a function call, a control flow transfer point, a conditional judgment statement, and the like. Based on the extracted node information, the exact location of each path node is further extracted from the target source code file, including the source file path, line number, and column number.
[0052] Furthermore, the Abstract Syntax Tree (AST) referred to in step S230 is a concept in program analysis. The Abstract Syntax Tree is an intermediate representation of the source code during the processing of the compiler or interpreter. It abstracts the grammatical structure of the code, ignores the specific grammatical details (such as brackets, semicolons, etc.), and only retains the core information that can reflect the logic of the code. Based on the source code and the compilation parameters corresponding to the source code, its complete abstract syntax tree can be obtained. The abstract syntax tree is a rooted tree in which each node (abstract syntax tree node) represents a grammatical unit in the program, such as a function, statement, expression or variable.
[0053] In step S230, the project compilation parameters are used to call the abstract syntax tree parsing tool to parse the identified source code file and generate a corresponding abstract syntax tree. By parsing the abstract syntax tree, the grammatical structure of the source code and the hierarchical relationship between the nodes can be obtained, laying the foundation for subsequent code analysis. Assuming that the node (statement node) corresponding to statement I in the abstract syntax tree is NodeI, statement I belongs to function F, and the node corresponding to function F is NodeF, then NodeF is the outer definition node of NodeI.
[0054] In some exemplary embodiments, the step S240 extracts the code snippet and the implicit information in the code snippet based on the project compilation parameters, the abstract syntax tree nodes, the location information of the path nodes in the source code, and the problem triggering path description, including: searching in the abstract syntax tree nodes based on the location information of the path nodes in the source code to find the corresponding statement nodes and the outer definition nodes to which the statement nodes belong; extracting all symbols contained in the statement nodes and identifying the symbol types contained in the statement nodes; performing corresponding processing based on the symbol types and the problem triggering path description to obtain the implicit information in the corresponding code snippet; generating code snippets based on the project compilation parameters, the implicit information in the code snippet, and the outer definition nodes. Therefore, this method can integrate multi-dimensional information, accurately extract and associate code-related nodes and symbol information (including symbol names and symbol types), perform targeted processing according to specific information, and ensure that the quality and reliability of the generated code snippets are higher.
[0055] Specifically, the outer definition nodes include function definition nodes, user type definition nodes and global variable definition nodes. Furthermore, the processing of the statement nodes in the abstract syntax tree includes extracting all symbols contained in the statement nodes and identifying their types. The symbol is a lexical unit (Token) in the statement. For example, for the source code statement "int x = a + b;", its lexical units include int (keyword), x (variable), = (assignment operator), a (variable), + (addition operator), b (variable), ; (separator), where "assignment operator" is the symbol type of the symbol "=".
[0056] In some exemplary embodiments, the searching in the abstract syntax tree node based on the position information of the path node in the source code to find the corresponding statement node and the outer definition node to which the statement node belongs includes: traversing the abstract syntax tree node based on the position information of the path node in the source code to extract the statement node corresponding to the statement sequence related to the problem triggering path; analyzing the outer definition node to which the statement node belongs, and recording the semantic information contained in the statement node and the outer definition node.
[0057] In some exemplary embodiments, the corresponding processing based on the symbol type and the problem trigger path description to obtain the implicit information in the corresponding code snippet includes: if the symbol type is a replacement type that needs to be expanded at compile time, extracting the definition statement of the replacement type and looping to process the nested replacement type variables in the definition statement of the replacement type; if the symbol type is a direct function call, generating a corresponding control flow jump description statement for the function call; if the symbol type is an indirect function call, extracting the description of the corresponding node based on the problem trigger path description and generating a corresponding control flow jump description statement; if the symbol type is a variable, extracting the type of the variable and the size of the memory space occupied to obtain variable information; if the variable type is a user-defined type, extracting and recording the type definition statement of the user-defined type, and nested extracting the type definition statement of the user-defined type contained in the user-defined type; if the symbol type is an operator, generating operation information based on the description related to the operator in the problem trigger path description; combining the definition statement of the replacement type, the control flow jump description statement, the type definition statement, the variable information and the operation information into the implicit information in the corresponding code snippet.
[0058] Therefore, according to different symbol types and problem trigger path descriptions, targeted processing is performed on elements such as macro definition variables, direct function calls, indirect function calls, variables and operators in the code snippet. Through loop processing of nested replacement type variables, generation of control flow jump description statements, extraction of user-defined type definition statements and variable information, generation of operation information based on operator descriptions and other operations, multiple processing results are finally combined into implicit information in the code snippet, achieving in-depth and refined analysis of the code, ensuring comprehensive and accurate mining of potential code information.
[0059] Specifically, the replacement type includes but is not limited to macro-defined variables, which are identifiers defined by the preprocessor directive #define in programming languages (such as C, C++). These identifiers are replaced by the preprocessor with specified values or code snippets before compilation. Macro-defined variables are not actual variables, but a text replacement mechanism that is often used to improve code readability, reduce duplication, and facilitate the modification of constant values. Furthermore, direct function calls include function pointers, callback functions, and other situations where the function name does not appear directly in the symbol.
[0060] Direct function call means explicitly calling the function by its name in the code. The definition of the function must be visible or declared when calling.
[0061] An indirect function call refers to calling a function through a function pointer, function alias, or other indirect methods, rather than directly calling it through the function name.
[0062] A function pointer is a variable that stores the address of a function. Through a function pointer, you can call a function indirectly and dynamically decide which function to call.
[0063] In some exemplary embodiments, the generating of the code snippet based on the project compilation parameters, the implicit information in the code snippet and the outer definition node includes: generating the required code snippet based on the type definition statement in the implicit information in the code snippet and the outer definition node; expanding the source code based on the definition statement of the replacement type in the implicit information in the code snippet to obtain a complete source code snippet; processing each conditional compilation statement and internal include statement in the source code snippet based on the project compilation parameters to obtain a valid code snippet.
[0064] Specifically, conditional compilation statements are a mechanism that uses preprocessor directives to control the code compilation process, and are used to determine whether to include certain code segments based on specific conditions during compilation. This statement uses conditional judgment to select different code paths to support cross-platform development, debugging function switching, and enabling or disabling functional modules. Conditional compilation relies on preprocessing directives such as #if, #ifdef, #ifndef, #else, #elif, and #endif. These directives are usually used in conjunction with macro definitions to determine whether the code is included in the compilation process by determining whether the macro is defined or its value.
[0065] Furthermore, the processing of each conditional compilation statement and internal include statement in the source code fragment includes: if the condition of the compilation statement does not exist in the project compilation parameter, deleting the compilation statement and the internal include statement from the source code fragment; if the condition of the compilation statement exists in the project compilation parameter, deleting the compilation statement from the source code fragment and retaining the internal include statement in the source code fragment.
[0066] In some exemplary embodiments, the generating of the required code snippet based on the type definition statement in the implicit information in the code snippet and the outer definition node includes: extracting the code snippet in the corresponding source code based on the outer definition node; if the type of the outer definition node is a local definition type in a user-defined type, supplementing the outer layer of the code snippet with a definition statement of the upper user-defined type to which the outer definition node belongs; if the outer definition node belongs to any namespace, supplementing the outer layer of the code snippet with a namespace definition statement; generating the required code snippet based on the type definition statement in the implicit information in the code snippet and the code snippet.
[0067] Therefore, by supplementing the outer layer of the code snippet with a definition statement of the upper-level user-defined type to which the outer definition node belongs, the outer class declaration can be supplemented for the code snippet; by supplementing the outer layer of the code snippet with a namespace definition statement, the namespace declaration can be supplemented for the code snippet, thereby avoiding the problem of missing code context semantics.
[0068] In some exemplary embodiments, the step S300, searching for a template that meets the characteristics in the large model request template library according to the key information set and generating a corresponding request file, includes: retrieving a template of a corresponding question type in the large model request template library based on the question type in the key information set; generating a corresponding request file based on the template and the code snippet in the key information set, the question description and implicit information in the code snippet.
[0069] Therefore, by generating a corresponding request file based on the template of the corresponding problem type retrieved from the big model request template library and the code snippet in the key information set, the problem description and the implicit information in the code snippet, it can be ensured that the big model can achieve more precise operations, so that the big model can better understand the analysis task and reduce the occurrence of big model hallucinations and understanding deviations.
[0070] Specifically, each template in the large model request template library includes: role definition, problem code, key variables and operation information description, similar problem analysis example, control flow description, problem key logic emphasis description, model parameter configuration and other structural entities.
[0071] Furthermore, each template stored in the large model request template library contains structured request information for a specific problem type, thereby ensuring that the generated request file can accurately describe the problem and guide model analysis. The large model request template library is constructed by analyzing common problem types and related code characteristics, specifically including: (1) Designing specific problem descriptions and analysis logic limitations for each problem type, such as resource allocation and release path analysis in resource leakage problems. (2) Expanding the problem type context based on the Chain of Thought (CoT) technology to provide semantic support for logical reasoning for the large model. The problem type context described here includes: problem scenario description: natural language expression and context description of the problem; key code snippets: problem code snippets and comments of the same type as the problem; logical deduction process: problem analysis steps, such as how to identify and locate the problem; solution: code modification examples or best practices. (3) Design template content based on the specific structure of the code snippet for each problem type to make it adaptable to various code scenarios. For example, for resource leakage problems caused by the use of goto statements, it is necessary to add a description of the actual function of the goto statement, the impact of the goto statement on the resource release logic, and the actual impact of the goto statement on the control flow in the current code when designing the template.
[0072] Furthermore, the structure of the template stored in the large model request template library includes the following: (1) Role definition: clarify the role in the interactive request, the capabilities of the role and the conditions that the role needs to meet, such as "security auditor", etc., to guide the tone and logic of the large model's answer. (2) Question code: indicate the specific location and context of the problem through the reference of the code snippet. (3) Key variable and operation information description: clarify the status of the variable and the background information of the related operation to highlight the key points of the problem. (4) Question type context: that is, the extended information of the question type built based on the CoT technology. (5) Control flow description: supplement the jump or logic control information in the question trigger path to provide the large model with a complete code execution logic context. (6) Key logic emphasis description of the question: combine the guidance statements in the template to further highlight the core logic or possible logic defects in the question. (7) Model parameter configuration: adjust the request parameters of the large model, such as temperature, generation length, etc., according to the complexity of the question, the length of the code snippet and other conditions.
[0073] Furthermore, the various parts of information in the retrieved template of the corresponding question type may be filled in according to the code snippet, the question description and the implicit information in the code snippet in the key information set, thereby generating a complete request for a specific question.
[0074] By sending the generated request file to the preset big model service interface, the big model can be triggered to analyze the problem and return the corresponding analysis results (i.e., interact with the big model). The analysis results are provided in a structured or textual form, including the judgment conclusion, problem analysis description, and possible repair suggestions. The final judgment conclusion of the problem can be identified from the analysis results returned by the big model service interface, including but not limited to the following types: real vulnerabilities, false positives, uncertainties, etc.
[0075] In some exemplary embodiments, the large model-assisted static code scanning result analysis method provided by the present invention also includes: if the judgment conclusion is a real vulnerability, parsing the repair suggestions contained in the analysis results, extracting specific executable repair plans, specifically, according to the repair suggestions, marking the code fragments that need to be repaired and their modification directions, forming a problem repair plan (i.e., a specific executable repair plan); if the judgment conclusion is a false alarm, recording the cause of the false alarm, including the triggering conditions of the false alarm of the static code scanning tool and the basis for considering that the problem is not established in the large model analysis results, and exiting the current stage of the interaction process, and archiving the false alarm information to the false alarm database for subsequent optimization templates or static code scanning tool configuration; if the judgment conclusion is uncertain, generating a new request file based on the template related to the uncertain problem in the large model request template library, and sending the new request file to the large model service interface for further supplementary analysis until a clear judgment conclusion is obtained or the preset number of interactions is reached.
[0076] In some exemplary embodiments, the large model-assisted static code scanning result analysis method provided by the present invention further includes: summarizing the problem description, cause of the problem, repair suggestions, and key code locations to generate a structured vulnerability report. When the problem cannot be further determined, the interaction result is marked as an uncertain state and a manual review process is triggered. After completing the corresponding operation according to the processing logic of the determination conclusion, exit the current interaction stage and enter the subsequent processing process.
[0077] Based on the same inventive concept, the present invention also provides a large model-assisted static code scanning result analysis device, please refer to Figure 3 , which is a structural block diagram of a large model-assisted static code scanning result analysis device provided by an embodiment of the present invention. Figure 3As shown, the static code scanning result analysis device provided by the present invention includes: an acquisition module 110, configured to obtain the project compilation record of the target project and the code detection report of the target project output by the static code scanning tool, and extract the project compilation parameters in the project compilation record and the basic information of each problem in the code detection report; an extraction module 120, configured to identify all source codes involved in the problem based on the basic information of the problem, and process the project compilation parameters, the source code and the basic information to generate a key information set; a generation module 130, configured to search for a template that meets the characteristics in the large model request template library according to the key information set and generate a corresponding request file; and an analysis module 140, configured to trigger the large model to analyze the problem according to the request file to generate an analysis result of the problem, the analysis result includes a judgment conclusion, a problem analysis description and a repair suggestion. Therefore, the large model-assisted static code scanning result analysis device provided by the present invention can quickly and effectively realize the automatic analysis of each problem in the detection report generated by the static code scanning tool and give a repair suggestion, improve the automation of static analysis result determination, reduce the workload of manual analysis and repair problems, and improve the accuracy of result determination.
[0078] It should be noted that the large model-assisted static code scanning result analysis device provided by the present invention can be used to execute the large model-assisted static code scanning result analysis method described above. The technical principles, technical problems solved and technical effects produced by the two are similar. Technical personnel in this technical field can clearly understand that for the convenience and conciseness of description, more content about the large model-assisted static code scanning result analysis device provided by the present invention can refer to the content described above about the large model-assisted static code scanning result analysis method provided by the present invention, and will not be repeated here.
[0079] Based on the same inventive concept, the present invention also provides an electronic device, please refer to Figure 4 , which is a structural block diagram of an electronic device provided by an embodiment of the present invention. Figure 4As shown, the electronic device includes at least one processor 210 and at least one storage device 220, and the storage device 220 can be configured to store a program for executing the above-mentioned large model-assisted static code scanning result analysis method, and the processor 210 can be configured to execute the program in the storage device 220, which includes but is not limited to a program for executing the above-mentioned large model-assisted static code scanning result analysis method. Since the electronic device provided by the present invention and the large model-assisted static code scanning result analysis method provided by the present invention belong to the same inventive concept, the electronic device provided by the present invention at least has all the beneficial effects of the large model-assisted static code scanning result analysis method provided by the present invention. Therefore, the beneficial effects of the electronic device provided by the present invention can refer to the relevant description of the beneficial effects of the large model-assisted static code scanning result analysis method provided by the present invention in the above text, and will not be repeated here one by one.
[0080] In an embodiment of the present invention, the electronic device may be a control device device formed by various devices. In some possible implementations, the electronic device may include multiple storage devices 220 and multiple processors 210. The program for executing the above-mentioned large model-assisted static code scanning result analysis method can be divided into multiple subprograms, and each subprogram can be loaded and run by the processor 210 to execute different steps of the above-mentioned large model-assisted static code scanning result analysis method. Specifically, each subprogram can be stored in different storage devices 220 respectively, and each processor 210 can be configured to execute the program in one or more storage devices 220 to jointly implement the above-mentioned large model-assisted static code scanning result analysis method, that is, each processor 210 executes different steps of the above-mentioned large model-assisted static code scanning result analysis method respectively to jointly implement the above-mentioned large model-assisted static code scanning result analysis method.
[0081] The above-mentioned multiple processors 210 may be processors 210 deployed on the same device. For example, the above-mentioned electronic device may be a high-performance device composed of multiple processors 210, and the above-mentioned multiple processors 210 may be processors configured on the high-performance device. In addition, the above-mentioned multiple processors 210 may also be processors deployed on different devices. For example, the above-mentioned electronic device may be a server cluster, and the above-mentioned multiple processors 210 may be processors on different servers in the server cluster.
[0082] The present invention also provides a computer-readable storage medium, which can be configured to store a program for executing the above-mentioned large model-assisted static code scanning result analysis method, and the program can be loaded and run by a processor to implement the above-mentioned large model-assisted static code scanning result analysis method. Since the computer-readable storage medium provided by the present invention and the large model-assisted static code scanning result analysis method provided by the present invention belong to the same inventive concept, the computer-readable storage medium provided by the present invention at least has all the beneficial effects of the large model-assisted static code scanning result analysis method provided by the present invention. Therefore, the beneficial effects of the computer-readable storage medium provided by the present invention can refer to the relevant description of the beneficial effects of the large model-assisted static code scanning result analysis method provided by the present invention in the above text, and will not be repeated here one by one.
[0083] It should be noted that the computer-readable storage medium may be a storage device formed by various electronic devices. Optionally, the computer-readable storage medium in the embodiment of the present invention may be a non-temporary computer-readable storage medium.
[0084] To sum up, compared with the prior art, the large model-assisted static code scanning result analysis method, device, electronic device and computer-readable storage medium provided by the present invention have the following beneficial effects: the present invention can quickly and effectively realize the automated analysis of each problem in the detection report generated by the static code scanning tool and give repair suggestions, thereby improving the degree of automation in the determination of static analysis results, reducing the workload of manual analysis and repair of problems, and at the same time improving the accuracy of result determination.
[0085] It should be noted that the computer program code for performing the operation of the present invention can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, using an Internet service provider to connect through the Internet).
[0086] It should be noted that the devices and methods disclosed in the embodiments of this article can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to the multiple embodiments of this article. In this regard, each box in the flowchart or block diagram can represent a module, a part of a program or a code, and the module, a part of a program segment or a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or the flowchart, and the combination of boxes in the block diagram and / or the flowchart, can be implemented by a dedicated hardware-based system for performing a specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions. In addition, the functional modules in the various embodiments of this document may be integrated together to form an independent part, or each module may exist independently, or two or more modules may be integrated to form an independent part.
[0087] It should also be noted that the above description is only a description of the preferred embodiment of the present invention, and is not any limitation on the scope of the present invention. Any changes and modifications made by a person skilled in the art in the field of the present invention based on the above disclosure are within the scope of protection of the present invention. Obviously, a person skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations fall within the scope of the present invention and its equivalents, the present invention is also intended to include these modifications and variations.
Claims
1. A large model-assisted static code scanning result analysis method, characterized in that: include: Obtaining a project compilation record of a target project and a code detection report of the target project output by a static code scanning tool, and extracting project compilation parameters in the project compilation record and basic information of each problem in the code detection report, wherein the project compilation record refers to relevant information of recording the project compilation process generated by a project build system or a static code scanning tool during the compilation process of the target project, which is automatically generated by a compiler or a static code scanning tool when the target project is compiled, and is used to record compilation parameters, dependencies, and configuration options of each source file in the target project; Based on the basic information of the problem, all source codes involved in the problem are identified, and the project compilation parameters, the source codes and the basic information are processed to generate a key information set; According to the key information set, a template matching the characteristics is searched in the large model request template library and a corresponding request file is generated; Triggering the big model to analyze the problem according to the request file to generate an analysis result of the problem, wherein the analysis result includes a determination conclusion, a problem analysis description, and a repair suggestion; The identifying all source codes involved in the problem based on the basic information of the problem, and processing the project compilation parameters, the source codes and the basic information to generate a key information set includes: Identify the problem description, problem type, problem triggering path and problem triggering path description based on the basic information of the problem; Identify the source code to which each path node included in the problem triggering path belongs and the position information of the path node in the source code; Parsing the source code into an abstract syntax tree based on the project compilation parameters and identifying abstract syntax tree nodes; Extracting code snippets and implicit information in the code snippets based on the project compilation parameters, the abstract syntax tree nodes, the location information of the path nodes in the source code, and the problem triggering path description; The code snippet, the implicit information in the code snippet, the problem description and the problem type are combined into a key information set.
2. The large model-assisted static code scanning result analysis method according to claim 1 is characterized in that: The extracting of code snippets and implicit information in the code snippets based on the project compilation parameters, the abstract syntax tree nodes, the location information of the path nodes in the source code and the problem triggering path description includes: Searching in the abstract syntax tree nodes based on the position information of the path nodes in the source code to find out the corresponding statement nodes and the outer definition nodes to which the statement nodes belong; Extracting all symbols contained in the sentence node and identifying the symbol type contained in the sentence node; Perform corresponding processing based on the symbol type and the problem triggering path description to obtain implicit information in the corresponding code snippet; A code snippet is generated based on the project compilation parameter, implicit information in the code snippet and the outer definition node.
3. The large model-assisted static code scanning result analysis method according to claim 2, characterized in that: The corresponding processing based on the symbol type and the problem triggering path description to obtain the implicit information in the corresponding code snippet includes: If the symbol type is a replacement type that needs to be expanded during compilation, extracting a definition statement of the replacement type and cyclically processing replacement type variables nested in the definition statement of the replacement type; If the symbol type is a direct function call, the direct function call generates a corresponding control flow jump description statement; If the symbol type is an indirect function call, extracting a description of a corresponding node based on the problem trigger path description and generating a corresponding control flow jump description statement; If the symbol type is a variable, extract the type of the variable and the size of the memory space occupied to obtain variable information; if the type of the variable is a user-defined type, extract and record the type definition statement of the user-defined type, and nestedly extract the type definition statement of the user-defined type contained in the user-defined type; If the symbol type is an operator, generating operation information based on a description related to the operator in the problem triggering path description; The definition statement of the replacement type, the control flow jump description statement, the type definition statement, the variable information and the operation information are combined into implicit information in the corresponding code fragment.
4. The large model-assisted static code scanning result analysis method according to claim 3 is characterized in that: The generating of the code snippet based on the project compilation parameter, the implicit information in the code snippet and the outer definition node comprises: Generate a required code snippet based on the type definition statement and the outer definition node in the implicit information in the code snippet; Expanding the source code based on the definition statement of the replacement type in the implicit information in the code snippet to obtain a complete source code snippet; Each conditional compilation statement and internal include statement in the source code snippet is processed based on the project compilation parameter to obtain a valid code snippet.
5. The large model-assisted static code scanning result analysis method according to claim 4 is characterized in that: The generating the required code snippet based on the type definition statement and the outer definition node in the implicit information in the code snippet includes: Extracting a code snippet in a corresponding source code based on the outer definition node; If the type of the outer definition node is a local definition type in a user-defined type, then the outer layer of the code snippet is supplemented with a definition statement of the upper user-defined type to which the outer definition node belongs; If the outer layer definition node belongs to any namespace, then the outer layer of the code snippet is supplemented with a namespace definition statement; A required code snippet is generated based on the type definition statement in the implicit information in the code snippet and the code snippet.
6. The large model-assisted static code scanning result analysis method according to claim 1, characterized in that: The step of searching for a template that meets the characteristics in a large model request template library according to the key information set and generating a corresponding request file includes: Retrieving a template corresponding to the question type in a large model request template library based on the question type in the key information set; A corresponding request file is generated based on the template, the code snippet in the key information set, the problem description and the implicit information in the code snippet.
7. A large model-assisted static code scanning result analysis device, characterized in that: The device comprises: an acquisition module configured to acquire a project compilation record of a target project and a code detection report of the target project output by a static code scanning tool, and extract project compilation parameters in the project compilation record and basic information of each problem in the code detection report, wherein the project compilation record refers to relevant information of recording the project compilation process generated by a project build system or a static code scanning tool during the compilation process of the target project, which is automatically generated by a compiler or a static code scanning tool when the target project is compiled, and is used to record compilation parameters, dependencies, and configuration options of each source file in the target project; An extraction module configured to identify all source codes involved in the problem based on the basic information of the problem, and process the project compilation parameters, the source codes and the basic information to generate a key information set; A generating module configured to search for a template that meets the characteristics in a large model request template library according to the key information set and generate a corresponding request file; and An analysis module, configured to trigger the big model to analyze the problem according to the request file to generate an analysis result of the problem, wherein the analysis result includes a determination conclusion, a problem analysis description, and a repair suggestion; The identifying all source codes involved in the problem based on the basic information of the problem, and processing the project compilation parameters, the source codes and the basic information to generate a key information set includes: Identify the problem description, problem type, problem triggering path and problem triggering path description based on the basic information of the problem; Identify the source code to which each path node included in the problem triggering path belongs and the position information of the path node in the source code; Parsing the source code into an abstract syntax tree based on the project compilation parameters and identifying abstract syntax tree nodes; Extracting code snippets and implicit information in the code snippets based on the project compilation parameters, the abstract syntax tree nodes, the location information of the path nodes in the source code, and the problem triggering path description; The code snippet, the implicit information in the code snippet, the problem description and the problem type are combined into a key information set.
8. An electronic device, characterized in that: The method comprises at least one processor and at least one storage device, wherein the storage device is suitable for storing a plurality of program codes, and the program codes are suitable for being loaded and run by the processor to execute the large model-assisted static code scanning result analysis method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that: A plurality of program codes are stored thereon, and the program codes are suitable for being loaded and run by a processor to execute the large model-assisted static code scanning result analysis method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Source code detection system and method
CN106372511A
Automatic code defect repairing method based on static code analysis tool and artificial intelligence
CN118860864A