A Software Supply Chain Risk Detection and Protection Method and System

Through Bayesian network, differential execution sandbox, deep learning and graph neural network, comprehensive monitoring and risk assessment of third-party component behavior is achieved, the problem of low risk behavior identification and prediction capabilities in the existing technology is solved, and the security and response efficiency of the software supply chain are improved.

CN119808082BActive Publication Date: 2025-06-13HUAQING WEIYANG (BEIJING) TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510294796.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-06-13
Estimated Expiration
2045-03-13

AI Technical Summary

Technical Problem

The prior art has shortcomings in comprehensive monitoring and intelligent evaluation of third-party component behavior, making it difficult to effectively identify and predict potential risk behavior.

Method used

Bayesian network algorithm is used to predict the risk behavior patterns of third-party components, and combine differential sandboxing technology and deep learning time series anomaly detection algorithm to monitor and evaluate the behavioral data flow of components in real time. Graph neural network algorithm is used to evaluate the risk level of abnormal behavior, and to dynamically adjust security control measures through adaptive strategy selection algorithms.

Benefits of technology

It realizes comprehensive and accurate monitoring and risk assessment of third-party component behaviors, improves the accuracy of identification and prediction of potential risk behaviors, and enhances the security and response efficiency of the software supply chain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119808082B_ABST
    Figure CN119808082B_ABST
Patent Text Reader

Abstract

This application provides a method and system for detecting and protecting software supply chain risks. Among them, third-party components are obtained from the software supply chain, and their multi-level dynamic behaviors are analyzed; the Bayesian network algorithm is used to predict risk behavior patterns and construct a behavior pattern library; the behaviors during the runtime of third-party components are monitored, and the behavior data stream is recorded; the time series anomaly detection algorithm of deep learning is applied to identify abnormal behaviors that deviate from the normal behavior pattern; the graph neural network is used to evaluate the risk level of abnormal behaviors, and combined with the relevance and propagation path between behaviors, an abnormal behavior list is generated; according to the list, through the adaptive policy selection algorithm, the response policies in the security control measure library are dynamically adjusted to formulate security control measures for third-party components. This application improves the ability to identify and predict potential risk behaviors.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of software supply chain, and in particular, to a method and system for detecting and protecting software supply chain risks. Background Art

[0002] In modern software development and deployment, third-party components are widely used in various applications, greatly improving development efficiency. However, these third-party components may contain unknown vulnerabilities or malicious code, thereby introducing potential security risks. To address this challenge, existing software supply chain security solutions mainly rely on static analysis, sandbox isolation, and rule-based detection methods. Static analysis identifies potential risks through code review and dependency analysis, and can detect problems at the pre-compilation stage; sandbox isolation runs third-party components in an isolated environment, restricting their access to system resources to reduce risks; rule-based detection uses a predefined rule set to detect known abnormal behaviors. Although these methods ensure the security of the software supply chain to a certain extent, they each have limitations and are difficult to comprehensively capture and evaluate the complex behaviors of third-party components in the actual operating environment.

[0003] The prior art usually combines static analysis, sandbox isolation, and rule-based detection to achieve risk assessment and protection of third-party components. The static analysis method scans the source code and dependency graph to identify potential security vulnerabilities and non-compliant code segments. However, static analysis is limited to the code level and cannot capture the behavioral characteristics of third-party components during actual operation. The sandbox isolation technology creates a controlled execution environment to restrict the access of third-party components to system resources, thereby reducing the impact of potential threats. However, traditional sandbox technologies only provide basic isolation functions and lack fine-grained monitoring and in-depth analysis of component behaviors. In addition, the rule-based detection method uses a predefined rule set to match known abnormal behavior patterns. Although this method is simple and direct, its detection ability for new attacks and complex behavior patterns is limited. Generally speaking, the prior art can discover and mitigate some security problems to a certain extent, but there are still deficiencies in comprehensiveness and intelligence.

[0004] Although existing technologies provide effective protection measures in some aspects, there are still significant deficiencies, especially in comprehensive monitoring and intelligent evaluation. Static analysis methods cannot capture runtime behavior and are powerless against dynamically loaded code or changing dependencies; while sandbox isolation technology can provide basic isolation, it lacks fine-grained monitoring and in-depth analysis of component behavior and is difficult to detect hidden malicious behavior. Rule-based detection methods can only detect known threats and have poor adaptability to new attacks and complex behavior patterns, prone to false positives or false negatives. In addition, existing methods usually focus on single-dimensional risk assessment and fail to combine advanced technologies such as multi-level behavior analysis, time series anomaly detection, and graph neural networks, resulting in incomplete and inaccurate risk assessment. Therefore, there is an urgent need for a more intelligent and comprehensive method to comprehensively monitor and evaluate the behavior of third-party components and improve the security and response efficiency of the software supply chain. Summary of the Invention

[0005] An embodiment of the present application provides a software supply chain risk detection and protection method and system to solve the problem of low ability to identify and predict potential risk behaviors in the prior art.

[0006] In a first aspect, an embodiment of the present application provides a software supply chain risk detection and protection method, including:

[0007] Obtain third-party components in the software supply chain and analyze multi-level dynamic behaviors from the third-party components;

[0008] Based on the multi-level dynamic behaviors, use the Bayesian network algorithm to predict risk behavior patterns in the third-party components and generate a behavior pattern library;

[0009] According to the behavior pattern library, use the differential execution sandbox technology to monitor the behavior of the third-party components during runtime, so as to obtain and record the behavior data stream of the third-party components during runtime by using a fine-grained resource access tracking mechanism;

[0010] Based on the behavior data stream, apply the time series anomaly detection algorithm of deep learning to identify abnormal behaviors that deviate from the normal behavior pattern in the behavior pattern library, and use the graph neural network algorithm to evaluate the risk level of the abnormal behaviors, and combine the relevance and propagation path between the abnormal behaviors to generate a list of abnormal behaviors;

[0011] According to the list of abnormal behaviors, dynamically adjust the response strategy from a pre-defined security control measure library through an adaptive policy selection algorithm to formulate security control measures for the third-party components.

[0012] Optionally, based on the behavior data stream, a time series anomaly detection algorithm applying deep learning is used to identify abnormal behaviors deviating from the normal behavior patterns in the behavior pattern library, and a graph neural network algorithm is used to evaluate the risk levels of the abnormal behaviors. Combining the relevance and propagation paths among the abnormal behaviors, an abnormal behavior list is generated, including:

[0013] Using a deep learning model of long short-term memory network or gated recurrent unit to perform modeling processing on the behavior data stream, and extracting local and global features in the behavior data stream through a multi-scale sliding window, extracting time series features from the behavior data stream, and constructing a time series prediction model based on the time series features;

[0014] According to the historical behavior data stream records of the normal behavior patterns in the behavior pattern library, the time series prediction model is trained and verified to obtain an anomaly detection model;

[0015] Inputting the data in the behavior data stream into the anomaly detection model, and judging whether the specific behaviors during the operation of the third-party component deviate from the normal behavior patterns in the behavior pattern library through the probability distribution output by the anomaly detection model. When the anomaly detection model identifies behaviors deviating from the normal behavior patterns, record the occurrence time, involved system resources and specific operation types of the behaviors, and at the same time capture the context environment information of the abnormal behaviors to obtain behavior records identified as abnormal;

[0016] Using the behavior records, by analyzing the temporal relationship and resource dependency relationship among the abnormal behaviors, constructing a behavior graph representing the relevance among the abnormal behaviors, introducing node weights and edge weights to quantify the influence scope and severity of the abnormal behaviors, applying a graph neural network algorithm, evaluating the risk levels of the abnormal behaviors from the behavior graph, and combining the relevance among the abnormal behaviors and the propagation paths of the abnormal behaviors in the network, and optimizing the risk scores through multiple rounds of iteration to generate the risk levels of each abnormal behavior;

[0017] Based on the risk levels, performing clustering analysis on the abnormal behaviors to identify potential attack patterns, and summarizing the specific information of the abnormal behaviors to generate an abnormal behavior list including abnormal behavior classification, risk scores and disposal suggestions.

[0018] Optionally, using the behavior records, by analyzing the temporal relationship and resource dependency relationship between abnormal behaviors, construct a behavior graph representing the correlation between abnormal behaviors, introduce node weights and edge weights to quantify the influence scope and severity of abnormal behaviors, apply the graph neural network algorithm, evaluate the risk level of the abnormal behaviors from the behavior graph, and combine the correlation between the abnormal behaviors and the propagation path of the abnormal behaviors in the network, and generate the risk level of each abnormal behavior through multiple rounds of iterative optimization of the risk score, including:

[0019] Extract the key information in the behavior records, where the key information includes the occurrence time, the system resources involved, the type of operation executed, and the context information of the behavior occurrence. At the same time, extract the execution subject, target object, and operation result information of the abnormal behavior to construct a more comprehensive behavior feature representation;

[0020] By analyzing the temporal relationship between abnormal behaviors, calculate the time interval and sequential dependency relationship of behavior occurrence, and determine the correlation of abnormal behaviors in the time dimension; by analyzing the resource dependency relationship between abnormal behaviors, calculate the access overlap degree and dependency intensity of behaviors on system resources, and determine the correlation of abnormal behaviors in the resource dimension;

[0021] According to the key information and the correlation analysis results, create a node for each abnormal behavior, and assign a weight to each node. The weight value is dynamically calculated according to the influence scope and severity of the abnormal behavior. At the same time, create an edge between nodes according to the logical relationship between abnormal behaviors, and assign a weight to each edge. The weight value is dynamically calculated according to the correlation strength between abnormal behaviors, and obtain a behavior graph representing the interaction between abnormal behaviors;

[0022] Using graph embedding technology, convert the behavior graph into a representation form in a low-dimensional vector space, and optimize the vector representations of nodes and edges through multiple rounds of iteration, retaining the structural information and semantic information in the graph, and obtaining an optimized graph representation;

[0023] Use the graph neural network algorithm to perform deep learning processing on the graph representation. Dynamically adjust the importance of neighbor node information by introducing an attention mechanism, update the representation of each node in the behavior graph by aggregating the neighbor node information of the nodes in the behavior graph in multiple layers, combine the propagation path of abnormal behaviors and the dependency relationship of system resources, construct a multi-dimensional risk assessment model, and combine the correlation between abnormal behaviors and the propagation mode of abnormal behaviors in the network to obtain the behavior risk information evaluated by the graph neural network;

[0024] Based on the behavioral risk information, comprehensively considering the direct harm and potential propagation risk of abnormal behaviors, calculate a comprehensive risk score for each of the abnormal behaviors, optimize the risk score through multiple rounds of iteration, dynamically adjust the scoring parameters to reflect the real-time impact of abnormal behaviors, map the scores to a unified risk interval through normalization, and adopt a dynamic grading strategy to assign corresponding risk levels to each of the abnormal behaviors according to predefined risk thresholds or distribution conditions. At the same time, generate an explanatory note for the risk level, including the risk source and scope of influence.

[0025] Optionally, perform deep learning processing on the graph representation using the graph neural network algorithm, dynamically adjust the importance of neighbor node information by introducing an attention mechanism, update the representation of each node in the behavior graph by aggregating the neighbor node information of the nodes in the behavior graph through multiple layers, combine the propagation path of the abnormal behavior and the dependency relationship of system resources, construct a multi-dimensional risk assessment model, and combine the relevance between the abnormal behaviors and the propagation mode of the abnormal behaviors in the network to obtain the behavioral risk information evaluated by the graph neural network, including:

[0026] Initialize the vector representation of each node in the behavior graph to obtain the initial vector representation of each node. Based on the occurrence time, resource dependency relationship, and operation type of the abnormal behavior, enhance the features of the initial vector representation. Based on the connection relationship between the nodes in the behavior graph, collect the information of the neighbor nodes directly connected to each node. By introducing an attention mechanism, dynamically calculate the importance weight of each neighbor node for the current node, and perform weighted aggregation on the neighbor node information according to the weight to obtain the comprehensive information about the surrounding environment where the node is located;

[0027] Based on the initial vector representation of the node, use an aggregation function to integrate the aggregated comprehensive information of the relevance between the nodes from the comprehensive information, combine the propagation path of the abnormal behavior, analyze the propagation intensity and scope of influence between the nodes, and according to the aggregated comprehensive information, through a trainable transformation function, convert the initial vector representation of the node into a target vector representation that combines the characteristics of the node itself and the neighborhood information of the node, while retaining the temporal dependency relationship and resource dependency relationship between the nodes;

[0028] Through the iterative message passing mechanism, repeatedly perform aggregation and transformation on the target representation of the node at different levels. In each layer of iteration, dynamically update the attention weights to reflect the changes in the relevance between the nodes, obtain a global view of the complex relevance between the abnormal behaviors, and capture the propagation mode of the abnormal behaviors in the network;

[0029] Based on the graph structure characteristics in the behavior graph and in combination with the global view, by analyzing the centrality of nodes in the network and the strength of resource dependencies, the main source or high-risk area of the abnormal behavior is analyzed from the network structure characteristics of the abnormal behavior. In combination with the dependency relationship of system resources, key resource nodes and high-risk propagation paths are identified, and an enhanced node representation of the network structure characteristics is generated;

[0030] Using the enhanced node representation as input, a multi-dimensional risk assessment model is constructed. Considering comprehensively the influence range, propagation path and resource dependency relationship of nodes, prediction processing is performed on the risk level of nodes in each behavior graph. And in combination with the characteristics of nodes themselves in the behavior graph and the position and role of nodes in the entire network, the risk degree of nodes is calculated through a multi-dimensional scoring mechanism, and a score representing the risk degree of the abnormal behavior is output;

[0031] The scores are aggregated, and in combination with the propagation path of the abnormal behavior and the dependency relationship of system resources, behavior risk information including the risk source, propagation path and influence range is generated.

[0032] Optionally, according to the list of abnormal behaviors, the response strategy from a pre-defined security control measure library is dynamically adjusted through an adaptive strategy selection algorithm to formulate security control measures for the third-party component, including:

[0033] The third-party components involved in the list of abnormal behaviors are evaluated. By analyzing the upstream and downstream dependency relationships, call frequencies and permission scopes of the components in the software supply chain, the position, function of the third-party components in the software supply chain and the impact of the third-party components on the overall security and stability of the system are determined. At the same time, the historical behavior pattern of the components and the deviation degree of the current abnormal behavior are evaluated to obtain a security status assessment report of the affected components;

[0034] Monitor data of the current system is obtained from the behavior data stream, and the monitor data is cleaned and feature-extracted in real time. Based on the security status assessment report, the adaptive strategy selection algorithm is applied to analyze the security status of the current system. The relevance between system load, network traffic pattern and the effectiveness of existing security measures is evaluated through a dynamic weight allocation mechanism. And in combination with the system load, network traffic pattern of the current system and the effectiveness of existing security measures, a real-time risk assessment portrait of the system environment is generated to obtain the potential risk and response ability assessment results in the environment where the current system is located;

[0035] Extract the evolution rules of attack behaviors through time series analysis and pattern matching techniques based on historical attack data and known security incidents, combine machine learning models to predict the types and impact scopes of potential security threats in the future, and simultaneously identify potential attack paths and key resources affected, so as to identify new attack vectors against the affected components in advance;

[0036] Based on the potential risks and response ability assessment results in the current system environment and the new attack vectors, balance the implementation cost and expected benefits of security control measures through a multi-objective optimization algorithm, and combine the security state, historical attack patterns and expected losses of the current system to dynamically generate a set of candidate response strategies, adaptively adjust the strategy priorities according to real-time environmental changes and risk evolution trends, and dynamically adjust and formulate optimal security control measures.

[0037] Optionally, obtain the monitoring data of the current system from the behavior data stream, perform real-time cleaning and feature extraction on the monitoring data, based on the security state assessment report, apply an adaptive strategy selection algorithm to analyze and process the security state of the current system, evaluate the correlation between system load, network traffic patterns and the effectiveness of existing security measures through a dynamic weight allocation mechanism, and combine the load, network traffic patterns and the effectiveness of existing security measures of the current system to generate a real-time risk assessment portrait of the system environment, and obtain the potential risks and response ability assessment results in the current system environment, including:

[0038] Obtain the monitoring data of the current system from the behavior data stream, perform real-time cleaning on the monitoring data through data filtering and outlier processing, extract key features related to system load, network traffic and security measures, use the location and function information of third-party components in the software supply chain provided in the security state assessment report to analyze the load situation of the current system, and evaluate the correlation between load peaks, resource utilization rates and task priorities through a dynamic weight allocation mechanism to obtain an evaluation result of the current system load;

[0039] Based on the security state assessment report, combine the network traffic data collected by network monitoring tools, analyze abnormal traffic patterns from the network traffic patterns of the current system through traffic clustering and pattern recognition techniques, dynamically adjust the sensitivity of abnormal traffic detection in combination with historical traffic data and real-time traffic trends, and evaluate the communication security of the current system based on the abnormal traffic patterns to generate a network traffic security assessment report including traffic anomaly scores and risk hotspots;

[0040] Based on the security status assessment report, review the security control measures deployed in the current system, evaluate the impact of different security measures on system load and network traffic through a dynamic weight allocation mechanism to determine whether the security control measures can effectively respond to the threats in the environment where the current system is located, and verify the actual protection effect of the security control measures through simulated attack tests or vulnerability scans. Record the effectiveness score and coverage of the security measures to obtain the security measure effectiveness assessment result;

[0041] Input the evaluation result, the security assessment report, and the security measure effectiveness assessment result into an adaptive policy selection algorithm. Integrate the effectiveness information of system load, network traffic, and security measures through multi-dimensional data fusion technology to output multi-dimensional information, dynamically adjust the weight allocation of each dimension in combination with real-time environmental changes, analyze the multi-dimensional information through a machine learning model, construct a real-time risk assessment portrait of the system environment, including a risk distribution map, threat evolution trend, and response ability score, and obtain the potential risk and response ability assessment result in the environment where the current system is located in combination with the mutual influence between various factors in the multi-dimensional information.

[0042] Optionally, according to the behavior pattern library, use differential execution sandbox technology to monitor the behavior of the third-party component during runtime, and use a fine-grained resource access tracking mechanism to obtain and record the behavior data stream of the third-party component during runtime, including:

[0043] Use the behavior pattern library to configure and deploy a differential execution sandbox environment, create an independent runtime environment through virtualization technology and resource isolation mechanism to isolate and monitor the behavior of the third-party component during runtime, and at the same time configure the behavior monitoring policy of the sandbox environment to match the normal and abnormal behavior patterns in the behavior pattern library;

[0044] Use differential execution sandbox technology to monitor the behavior of the third-party component during runtime, and ensure that the monitoring mechanism identifies and matches the normal and abnormal behavior patterns in the behavior pattern library by executing the third-party component in the sandbox environment and synchronously comparing its differences with the normal behavior pattern, and at the same time record the execution trajectory and resource access behavior of the component in the sandbox environment;

[0045] For the monitoring mechanism, deploy a fine-grained resource access tracking mechanism, capture the access requests of the third-party component to system resources through hook technology and system call interception mechanism, track all access operations of the third-party component to system resources during runtime, including file reading and writing, network communication, memory access, and process creation operations, etc., to obtain and record the behavior data stream of the third-party component during runtime, and at the same time mark each access operation with a timestamp and context label to generate a complete behavior log.

[0046] In a second aspect, an embodiment of the present application provides a software supply chain risk detection and protection system, including:

[0047] An acquisition module, configured to acquire third-party components in the software supply chain and analyze multi-level dynamic behaviors from the third-party components;

[0048] A prediction module, configured to, based on the multi-level dynamic behaviors, use the Bayesian network algorithm to predict risk behavior patterns in the third-party components and generate a behavior pattern library;

[0049] A monitoring module, configured to, according to the behavior pattern library, use the differential execution sandbox technology to monitor the behaviors of the third-party components during operation, so as to acquire and record the behavior data stream of the third-party components during operation by using a fine-grained resource access tracking mechanism;

[0050] An identification module, configured to, based on the behavior data stream, apply a time series anomaly detection algorithm of deep learning to identify abnormal behaviors that deviate from the normal behavior patterns in the behavior pattern library, use a graph neural network algorithm to evaluate the risk levels of the abnormal behaviors, and generate an abnormal behavior list in combination with the relevance and propagation paths between the abnormal behaviors;

[0051] An adjustment module, configured to, according to the abnormal behavior list, dynamically adjust response policies from a predefined security control measure library through an adaptive policy selection algorithm and formulate security control measures for the third-party components.

[0052] In a third aspect, an embodiment of the present application provides a computing device, including a processor and a memory. A computer program is stored in the memory, and the processor is configured to run the computer program to execute a software supply chain risk detection and protection method according to any one of the first aspect.

[0053] In a fourth aspect, an embodiment of the present application provides a computer storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processor, a software supply chain risk detection and protection method according to any one of the first aspect is implemented.

[0054] In the embodiments of the present application, a third-party component in the software supply chain is obtained, and multi-level dynamic behaviors are analyzed from the third-party component; based on the multi-level dynamic behaviors, a Bayesian network algorithm is used to predict risk behavior patterns in the third-party component, and a behavior pattern library is generated; according to the behavior pattern library, the differential execution sandbox technology is used to monitor the behaviors of the third-party component during operation, so as to obtain and record the behavior data stream of the third-party component during operation by using a fine-grained resource access tracking mechanism; based on the behavior data stream, a time series anomaly detection algorithm of deep learning is applied to identify abnormal behaviors that deviate from the normal behavior patterns in the behavior pattern library, and a graph neural network algorithm is used to evaluate the risk levels of the abnormal behaviors, and in combination with the correlation and propagation paths between the abnormal behaviors, an abnormal behavior list is generated; according to the abnormal behavior list, a response strategy from a pre-defined security control measure library is dynamically adjusted through an adaptive policy selection algorithm, and a security control measure is formulated for the third-party component.

[0055] The technical solution of the present application has the following beneficial effects:

[0056] By deeply analyzing the multi-level dynamic behaviors of third-party components, the present application can comprehensively capture the behavior characteristics of these components in different operating environments and conditions, ensuring more accurate identification of potential risk behaviors. The Bayesian network algorithm is used to predict risk behavior patterns in third-party components, and a behavior pattern library including normal behavior patterns, abnormal behavior patterns and risk behavior patterns is generated. This method not only improves the prediction accuracy of risk behaviors, but also provides data support for subsequent risk assessments. The differential execution sandbox technology is used to monitor the behaviors of third-party components during operation, and in combination with a fine-grained resource access tracking mechanism, a detailed runtime behavior data stream is obtained and recorded. This combination ensures real-time and accurate monitoring of the behaviors of third-party components, reducing the false alarm rate and missed alarm rate. A time series anomaly detection algorithm of deep learning is applied to identify abnormal behaviors that deviate from the normal behavior patterns. This algorithm can automatically adapt to complex and changeable behavior patterns, improving the sensitivity and accuracy of anomaly detection. The graph neural network algorithm is used to evaluate the risk levels of abnormal behaviors, and in combination with the correlation and propagation paths between the abnormal behaviors, an abnormal behavior list is generated. This method not only considers the impact of individual abnormal behaviors, but also evaluates their chain reactions in the network, providing a more comprehensive risk view. According to the abnormal behavior list, a response strategy from a pre-defined security control measure library is dynamically adjusted through an adaptive policy selection algorithm, and a security control measure is formulated for the third-party component. This enables the system to flexibly adjust defense measures according to the actual threat situation, enhancing the self-adaptability and response ability of the system.

[0057] Furthermore, by using a deep learning model of long short-term memory network or gated recurrent unit to model the behavioral data stream and extract time series features from it, the system can capture the time-dependency and long-term relational features of the runtime behavior of third-party components. By aggregating node information at multiple levels and combining the relevance and propagation paths between abnormal behaviors, comprehensive behavioral risk information is generated. This method not only considers the impact of individual abnormal behaviors but also evaluates their chain reactions in the network, providing a more comprehensive risk view and enhancing the accuracy and reliability of risk assessment.

[0058] Furthermore, by extracting key information from behavioral records, creating nodes for each abnormal behavior, and creating edges between nodes based on logical relationships, this refined construction method ensures that the behavioral graph can accurately reflect the interactions between abnormal behaviors, laying a solid foundation for subsequent deep learning processing. Based on the behavioral risk information, a comprehensive risk score is calculated for each abnormal behavior, and corresponding risk levels are assigned according to predefined risk thresholds or distribution situations. This method not only provides a quantitative risk assessment but also realizes hierarchical risk management, enabling the security team to adopt appropriate response strategies according to different risk levels. The introduction of the comprehensive risk score makes risk assessment more intuitive and operable, enhancing the system's decision-making support ability.

[0059] These aspects or other aspects of the present application will be more clearly understood in the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0061] Figure 1 It is a flowchart of a software supply chain risk detection and protection method provided by an embodiment of the present application;

[0062] Figure 2 It is a schematic structural diagram of a software supply chain risk detection and protection system provided by an embodiment of the present application;

[0063] Figure 3 It is a schematic structural diagram of a computing device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0064] To enable those skilled in the art to better understand the solution of this application, the following will clearly and completely describe the technical solution in the embodiments of this application in conjunction with the accompanying drawings in the embodiments of this application.

[0065] In some processes described in the specification, claims and above-mentioned accompanying drawings of this application, there are multiple operations that appear in a specific order. However, it should be clearly understood that these operations can be executed not in the order in which they appear in this article or in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations can be executed sequentially or in parallel. It should be noted that the descriptions such as "first", "second", etc. in this article are used to distinguish different messages, devices, modules, etc., and do not represent a sequence, nor do they limit that "first" and "second" are of different types.

[0066] The following will clearly and completely describe the technical solution in the embodiments of this application in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, rather than all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of this application.

[0067] Figure 1 The following is a flowchart of a software supply chain risk detection and protection method provided for the embodiments of this application. As Figure 1 shown, the method includes:

[0068] Step 101: Obtain third-party components in the software supply chain, and analyze multi-level dynamic behaviors from the third-party components;

[0069] In this step, the third-party components include software libraries, frameworks, plugins, and tools introduced from external sources; the multi-level dynamic behaviors refer to behavioral characteristics under different environments and conditions, including but not limited to behaviors at startup, resource access patterns during runtime, interaction methods with other components, etc. These behavioral characteristics are captured and analyzed through dynamic analysis tools.

[0070] In the embodiments of this application, in an enterprise-level application development environment, the development team uses multiple open-source libraries and commercial plugins to accelerate the project progress. To ensure the security of these third-party components, the security team first collected a list of all introduced third-party components and performed static analysis and dynamic analysis on each component through automated tools. The dynamic analysis includes executing the component in an isolated environment and recording its behavior, so as to identify initialization behaviors at startup, API call patterns during runtime, file system access behaviors, etc. These multi-level dynamic behavior data are used for subsequent risk assessment.

[0071] The embodiments of the present application ensure a comprehensive understanding of the behaviors of third - party components, provide a detailed data basis for subsequent risk prediction, and improve the accuracy and reliability of risk assessment.

[0072] Step 102: Based on the multi - level dynamic behaviors, use the Bayesian network algorithm to predict the risk behavior patterns in the third - party components and generate a behavior pattern library.

[0073] In this step, the behavior pattern library includes normal behavior patterns, abnormal behavior patterns, and risk behavior patterns; the Bayesian network algorithm refers to a probabilistic graphical model used to represent the dependencies between variables. By learning historical data, the Bayesian network can predict the likelihood of future events.

[0074] In the embodiments of the present application, continuing from the above - mentioned embodiments, the security team used the Bayesian network algorithm to model the collected multi - level dynamic behavior data. By learning a large amount of historical data of known normal and abnormal behaviors, the algorithm generated a detailed behavior pattern library. This library not only includes common normal behavior patterns, such as normal API call sequences, but also covers known abnormal behavior patterns, such as unauthorized file access, and potential risk behavior patterns, such as unusual network connection attempts. This behavior pattern library serves as the basis for subsequent real - time monitoring and anomaly detection.

[0075] Through the Bayesian network algorithm, the system in the embodiments of the present application can more accurately predict the possible risk behavior patterns of third - party components, improve the forward - looking nature of risk identification, and reduce the security risks brought by unknown threats.

[0076] Step 103: According to the behavior pattern library, use the differential execution sandbox technology to monitor the behaviors of the third - party components during runtime, so as to obtain and record the behavior data stream of the third - party components during runtime by using the fine - grained resource access tracking mechanism.

[0077] In this step, the differential execution sandbox technology refers to creating an execution environment that is similar to the actual production environment but isolated, in order to observe and analyze the real - time running behaviors of third - party components; the fine - grained resource access tracking mechanism refers to recording all access operations of third - party components to system resources during runtime, providing detailed log information.

[0078] In the embodiment of the present application, during the actual deployment phase, the security team runs third-party components in a differential execution sandbox. The sandbox environment simulates a real production environment but restricts direct access to external systems. At the same time, a fine-grained resource access tracking mechanism is enabled to record all resource access behaviors of each third-party component during runtime. For example, the specific path and content of the configuration file loaded by an open-source library each time it starts, as well as the requests it sends during network communication, are recorded. These behavioral data streams are transmitted to the central monitoring system in real time and compared with the patterns in the behavior pattern library.

[0079] The differential execution sandbox technology in the embodiment of the present application combined with the fine-grained resource access tracking mechanism ensures real-time and accurate monitoring of the behaviors of third-party components, reduces the false alarm rate and missed alarm rate, and enhances the security of the system.

[0080] Step 104: Based on the behavioral data stream, apply the time series anomaly detection algorithm of deep learning to identify the abnormal behaviors that deviate from the normal behavior patterns in the behavior pattern library, and use the graph neural network algorithm to evaluate the risk levels of the abnormal behaviors. Combine the correlation and propagation paths between the abnormal behaviors to generate a list of abnormal behaviors.

[0081] In this step, the time series anomaly detection algorithm refers to using deep learning models such as Long Short-Term Memory (LSTM) or gated recurrent units to model the behavioral data stream, extract time series features, and identify abnormal behaviors that deviate from the normal behavior patterns. The graph neural network algorithm refers to evaluating the risk levels of abnormal behaviors by aggregating node information in multiple layers and combining the correlation and propagation paths between abnormal behaviors.

[0082] In the embodiment of the present application, during the monitoring process, the central monitoring system receives a large amount of behavioral data streams. The system first applies the LSTM model to perform time series modeling on these data streams, extracts key time series features, and constructs a time series prediction model. By comparing with the normal behavior patterns in the behavior pattern library, the model identifies the abnormal behaviors of some third-party components, such as a certain plugin suddenly increasing a large number of unauthorized file reading operations. Subsequently, the system uses the graph neural network algorithm to further evaluate these abnormal behaviors, combines their correlation and propagation paths, and generates a detailed list of abnormal behaviors. For example, it is found that the abnormal behavior of one plugin may be a chain reaction caused by the update of another framework.

[0083] The application of the time series anomaly detection algorithm and graph neural network algorithm of deep learning in the embodiment of the present application significantly improves the sensitivity and accuracy of abnormal behavior recognition, enables the system to detect and evaluate complex behavior patterns in a timely manner, and enhances the comprehensiveness and accuracy of risk assessment.

[0084] Step 105: According to the abnormal behavior list, dynamically adjust the response policy from a predefined security control measure library through an adaptive policy selection algorithm, and formulate security control measures for the third-party component;

[0085] In this step, the adaptive policy selection algorithm refers to dynamically selecting the most appropriate response policy according to the currently detected abnormal behavior and its risk level to cope with different security threats; the security control measure library refers to a predefined series of security control measures, including but not limited to isolation, disabling, warning, etc., for coping with different types of abnormal behaviors.

[0086] In the embodiment of the present application, according to the abnormal behavior list, the security team dynamically adjusts the security control measures through the adaptive policy selection algorithm. For example, for high-risk abnormal behaviors, such as malicious code injection, isolation measures are immediately taken to prevent it from further affecting other system components; for medium-risk behaviors, such as unauthorized file access, an alarm is sent to notify the relevant responsible person and the relevant function is temporarily disabled. This dynamic adjustment mechanism ensures that the system can quickly respond to various security threats and minimize potential losses to the greatest extent.

[0087] In the embodiment of the present application, through the adaptive policy selection algorithm, the system can flexibly adjust the security control measures according to the actual situation, realizing intelligent security protection and improving the adaptability and response efficiency of the system.

[0088] Through the comprehensive application of the above five steps, not only can the behavior of the third-party component be comprehensively monitored and evaluated, but also potential security threats can be discovered and addressed in a timely manner, significantly enhancing the security and stability of the software supply chain.

[0089] To solve the problem of accurate monitoring and risk assessment of the behavior of third-party components, in some embodiments, based on the behavior data stream, a time series anomaly detection algorithm of deep learning is applied to identify abnormal behaviors that deviate from the normal behavior pattern in the behavior pattern library, and a graph neural network algorithm is used to evaluate the risk level of the abnormal behaviors. Combining the relevance and propagation path between the abnormal behaviors, an abnormal behavior list is generated, including:

[0090] Using a deep learning model with long short-term memory network or gated recurrent unit to model the behavior data stream, extracting local and global features in the behavior data stream through a multi-scale sliding window, extracting time series features from the behavior data stream, and constructing a time series prediction model based on the time series features; training and validating the time series prediction model according to the historical behavior data stream records of normal behavior patterns in the behavior pattern library to obtain an anomaly detection model; inputting the data in the behavior data stream into the anomaly detection model, and judging whether the specific behavior during the operation of the third-party component deviates from the normal behavior pattern in the behavior pattern library through the probability distribution output by the anomaly detection model. When the anomaly detection model identifies a behavior that deviates from the normal behavior pattern, record the occurrence time of the behavior, the system resources involved, and the specific operation type, and at the same time capture the context information of the abnormal behavior to obtain a behavior record identified as abnormal; using the behavior record, constructing a behavior map representing the correlation between the abnormal behaviors by analyzing the temporal relationship and resource dependency relationship between the abnormal behaviors, introducing node weights and edge weights to quantify the influence range and severity of the abnormal behaviors, applying a graph neural network algorithm, evaluating the risk level of the abnormal behaviors from the behavior map, combining the correlation between the abnormal behaviors and the propagation path of the abnormal behaviors in the network, and generating the risk level of each abnormal behavior through multiple rounds of iterative optimization of the risk score; based on the risk level, performing cluster analysis on the abnormal behaviors to identify potential attack patterns, and summarizing the specific information of the abnormal behaviors to generate an abnormal behavior list including abnormal behavior classification, risk score, and handling suggestions.

[0091] In this embodiment, the long short-term memory network (LSTM) or gated recurrent unit (GRU) are two deep learning models that are good at processing and predicting time series data. The multi-scale sliding window technique allows capturing feature information at different time scales from the behavior data stream, which is crucial for understanding complex behavior patterns. The constructed behavior map is a graphical representation method, where nodes represent abnormal behaviors, edges represent the correlation between these behaviors, and weights reflect the influence range and severity.

[0092] In the embodiment of this application, first, preprocess and extract features from the behavior data stream through a deep learning model to identify possible abnormal behaviors; second, train a time series prediction model based on historical data that can distinguish normal and abnormal behaviors; third, use this model to monitor the behavior of the third-party component during actual operation and record all behaviors marked as abnormal; finally, based on the recorded behavior data, construct a behavior map and evaluate the risk level of each abnormal behavior through a graph neural network algorithm to generate a detailed abnormal behavior list.

[0093] The following is a specific example:

[0094] Deploy the above solution in an enterprise-level software system. First, use the LSTM model to model the operation logs of third-party components, and at the same time capture the key features in the log data of the past three months through the multi-scale sliding window technology; second, establish a time series prediction model based on these features, and use the data without abnormal behavior in the past year to train and verify this model; third, collect the operation data of the current system in real time and input it into the anomaly detection model. When it is found that a certain operation significantly deviates from the normal behavior, record its occurrence time, involved resources and specific types, and collect context information; then, based on all the abnormal behavior records collected, construct a detailed behavior graph, and use the graph neural network algorithm to calculate the risk scores of each abnormal behavior; finally, conduct a clustering analysis on all abnormal behaviors based on the risk scores, determine potential security threats, and generate a list of abnormal behaviors including classification, scoring and handling suggestions; through the above steps, the enterprise not only improves its monitoring ability of the software supply chain security, but also can quickly respond to and mitigate potential security threats.

[0095] In order to further improve the recognition accuracy of abnormal behaviors and the accuracy of their risk assessment, in some embodiments, using the behavior records, by analyzing the temporal relationship and resource dependence relationship between abnormal behaviors, construct a behavior graph representing the relevance between abnormal behaviors, introduce node weights and edge weights to quantify the influence range and severity of abnormal behaviors, apply the graph neural network algorithm, evaluate the risk level of the abnormal behaviors from the behavior graph, and combine the relevance between the abnormal behaviors and the propagation path of the abnormal behaviors in the network, and optimize the risk score through multiple rounds of iteration to generate the risk level of each abnormal behavior, including:

[0096] Extract the key information from the behavior records, where the key information includes the occurrence time, the system resources involved, the type of operation executed, and the context information of the behavior occurrence. At the same time, extract the execution subject, target object, and operation result information of the abnormal behavior to construct a more comprehensive representation of the behavior characteristics; by analyzing the temporal relationship between abnormal behaviors, calculate the time interval and sequential dependence relationship of behavior occurrence, and determine the relevance of abnormal behaviors in the time dimension; by analyzing the resource dependence relationship between abnormal behaviors, calculate the access overlap degree and dependence strength of behaviors on system resources, and determine the relevance of abnormal behaviors in the resource dimension; according to the key information and the results of the relevance analysis, create a node for each abnormal behavior, and assign a weight to each node. The weight value is dynamically calculated according to the influence range and severity of the abnormal behavior. At the same time, create edges between nodes according to the logical relationship between abnormal behaviors, and assign a weight to each edge. The weight value is dynamically calculated according to the association strength between abnormal behaviors, and obtain a behavior graph representing the interaction between the abnormal behaviors; use graph embedding technology to convert the behavior graph into a representation form in a low-dimensional vector space, and optimize the vector representation of nodes and edges through multiple rounds of iteration, retaining the structural information and semantic information in the graph to obtain an optimized graph representation; use the graph neural network algorithm to perform deep learning processing on the graph representation, dynamically adjust the importance of neighbor node information by introducing an attention mechanism, update the representation of each node in the behavior graph by aggregating the neighbor node information of the nodes in the behavior graph through multiple layers, combine the propagation path of the abnormal behavior and the dependence relationship of the system resources, construct a multi-dimensional risk assessment model, and combine the relevance between the abnormal behaviors and the propagation mode of the abnormal behaviors in the network to obtain the behavior risk information evaluated by the graph neural network; based on the behavior risk information, comprehensively consider the direct harm and potential propagation risk of the abnormal behavior, calculate a comprehensive risk score for each abnormal behavior, optimize the risk score through multiple rounds of iteration, dynamically adjust the scoring parameters to reflect the real-time impact of the abnormal behavior, map the score to a unified risk interval through normalization processing, and adopt a dynamic grading strategy to assign corresponding risk levels to each abnormal behavior according to the predefined risk threshold or distribution, and at the same time generate an explanatory description of the risk level, including the risk source and the influence range.

[0097] In this embodiment, the behavior graph is a graphical model, where nodes represent abnormal behaviors and edges represent the associations between these behaviors. The node weight reflects the influence range and severity of the behavior, while the edge weight is calculated based on the association strength between behaviors. The graph neural network (GNN) is a deep learning model specifically designed for processing graph-structured data, which can effectively capture the complex dependence relationships between nodes and is suitable for scenarios such as risk assessment.

[0098] In the embodiments of the present application, first, key information including timestamps, involved resources, operation types, etc. is extracted from the behavior logs of third-party components for constructing behavior feature representations; second, by analyzing the time intervals and sequential dependencies of abnormal behaviors as well as the resource access overlap and dependency strength, the temporal and resource correlations between behaviors are determined; third, based on the above analysis results, a behavior graph is constructed, where each abnormal behavior serves as a node and the connections between nodes represent their logical relationships; finally, graph embedding technology is used to convert the behavior graph into a low-dimensional vector representation, and these representations are optimized through graph neural network algorithms to evaluate the risk levels of each abnormal behavior.

[0099] The following is a specific example:

[0100] Deploying this solution in a cloud computing environment, first, key information of all abnormal behaviors in the past week is extracted from the cloud service operation logs, including the occurrence time, involved server resources, executed operation types, and context information; second, by analyzing the time intervals and resource access patterns between these abnormal behaviors, their correlations in the time and resource dimensions are determined; third, based on the above analysis results, a behavior graph with 20 nodes is constructed, each node representing an abnormal behavior, with different weight values assigned according to its influence range and severity, and corresponding weights are assigned to each edge according to the association strength between abnormal behaviors; then, graph embedding technology is used to transform the graph into a representation form in a low-dimensional vector space, and multiple iterations of optimization are performed through graph neural network algorithms to obtain the final risk scores of each abnormal behavior; finally, according to predefined risk thresholds, all abnormal behaviors are classified, and a detailed risk level explanation including the source and influence range is provided for each behavior; through the above steps, not only the detection ability of potential threats in the cloud environment is improved, but also the accurate risk assessment of abnormal behaviors is achieved, thereby enhancing the security of the system.

[0101] To further improve the understanding of the propagation patterns of abnormal behaviors in the network and the accuracy of their risk assessment, in some embodiments, the graph neural network algorithm is used to perform deep learning processing on the graph representation. By introducing an attention mechanism, the importance of neighbor node information is dynamically adjusted, and the neighbor node information of nodes in the behavior graph is aggregated through multiple layers to update the representation of each node in the behavior graph. Combining the propagation paths of abnormal behaviors and the dependency relationships of system resources, a multi-dimensional risk assessment model is constructed. Combining the correlations between the abnormal behaviors and the propagation patterns of the abnormal behaviors in the network, the behavior risk information evaluated by the graph neural network is obtained, including:

[0102] Initialize the vector representation of each node in the behavior graph to obtain the initial vector representation of each node. Based on the occurrence time, resource dependency relationship, and operation type of the abnormal behavior, enhance the features of the initial vector representation. Based on the connection relationship between nodes in the behavior graph, collect the information of neighbor nodes directly connected to each node. By introducing an attention mechanism, dynamically calculate the importance weight of each neighbor node for the current node, and weighted aggregate the neighbor node information according to the weight to obtain the comprehensive information about the surrounding environment where the node is located. Based on the initial vector representation of the node, use an aggregation function to integrate the aggregated comprehensive information about the relevance between nodes from the comprehensive information, combine the propagation path of the abnormal behavior, analyze the propagation intensity and influence range between nodes, and according to the aggregated comprehensive information, through a trainable transformation function, convert the initial vector representation of the node into a target vector representation that combines the characteristics of the node itself and the neighborhood information of the node, while preserving the temporal and resource dependency relationships between nodes. Through the iterative message passing mechanism, repeatedly perform aggregation and transformation on the target representation of the node at different levels. In each layer of iteration, dynamically update the attention weights to reflect the changes in the relevance between nodes, obtain the global view of the complex relevance between the abnormal behaviors, and capture the propagation pattern of the abnormal behavior in the network. Based on the graph structure characteristics in the behavior graph and the global view, by analyzing the centrality and resource dependency intensity of nodes in the network, analyze the main source or high-risk area of the abnormal behavior from the network structure characteristics of the abnormal behavior, combine the dependency relationship of system resources, identify key resource nodes and high-risk propagation paths, and generate an enhanced node representation of the network structure characteristics. Use the enhanced node representation as input to construct a multi-dimensional risk assessment model, comprehensively consider the influence range, propagation path, and resource dependency relationship of the node, perform prediction processing on the risk level of each node in the behavior graph, and combine the characteristics of the node itself in the behavior graph and the position and role of the node in the entire network, calculate the risk degree of the node through a multi-dimensional scoring mechanism, and output the score representing the risk degree of the abnormal behavior. Summarize the scores, combine the propagation path of the abnormal behavior and the dependency relationship of system resources, and generate behavior risk information including the risk source, propagation path, and influence range.

[0103] In this embodiment, the graph neural network (GNN) is a deep learning model capable of processing graph-structured data, and is particularly suitable for capturing complex dependency relationships between nodes. The attention mechanism allows the model to dynamically adjust the importance weights according to the relevance of neighbor nodes, thereby more accurately reflecting the actual influence. The aggregation function is used to integrate the information of neighbor nodes, and the transformation function helps to update the vector representation of the node to better reflect its role and influence in the network.

[0104] In the embodiments of the present application, first, vector representations are initialized for each node in the behavior graph, and feature enhancement is performed based on the specific attributes of abnormal behaviors; second, the importance weights of neighbor nodes are calculated through the attention mechanism, and the information of neighbor nodes is aggregated accordingly; third, the target vector representations of the nodes are updated using the aggregated information, while considering the temporal and resource dependency relationships between nodes; finally, the node representations are optimized through multiple iterations to identify key nodes and propagation paths in the network, construct a multi-dimensional risk assessment model, and finally generate behavior risk information including the risk source, propagation path, and scope of influence.

[0105] The following is a specific example:

[0106] This solution is deployed in an enterprise internal network security monitoring system. First, initial vector representations are created for all abnormal behaviors recorded in the past month, and feature enhancement is performed according to their occurrence time, involved resources, and operation types; second, for each node, information of all its directly connected neighbor nodes is collected, and the importance weights of neighbor nodes are calculated using the attention mechanism to obtain comprehensive information about the environment around each node; third, based on this comprehensive information, the target vector representations of each node are updated through a trainable transformation function, while preserving the temporal and resource dependency relationships between nodes; then, through the message passing mechanism of multiple iterations, the aggregation and transformation processes are repeatedly executed at different levels to analyze the entire network structure and identify several main abnormal behavior sources and high-risk propagation paths; based on the above analysis results, a multi-dimensional risk assessment model is constructed to perform risk scoring for each abnormal behavior; after summarizing all the scores, a detailed behavior risk report is generated, which includes the risk source, propagation path, and scope of influence of each abnormal behavior; through the above steps, not only the ability to identify enterprise internal network security threats is improved, but also the effective management and control of potential risks are achieved.

[0107] In order to further improve the dynamic assessment and response capabilities for the security of third-party components, in some embodiments, dynamically adjusting the response strategy from a pre-defined security control measure library through an adaptive policy selection algorithm according to the abnormal behavior list to formulate security control measures for the third-party components includes:

[0108] Evaluate and process the third-party components involved in the abnormal behavior list. By analyzing the upstream and downstream dependencies, call frequencies, and permission scopes of the components in the software supply chain, determine the positions, functions of the third-party components in the software supply chain, and the impacts of the third-party components on the overall security and stability of the system. At the same time, evaluate the historical behavior patterns of the components and the deviation degree of the current abnormal behavior to obtain a security status assessment report of the affected components; Obtain the monitoring data of the current system from the behavior data stream, perform real-time cleaning and feature extraction on the monitoring data. Based on the security status assessment report, apply an adaptive strategy selection algorithm to analyze and process the security status of the current system. Through a dynamic weight allocation mechanism, evaluate the correlation between system load, network traffic patterns, and the effectiveness of existing security measures, and combine the system load, network traffic patterns, and the effectiveness of existing security measures of the current system to generate a real-time risk assessment portrait of the system environment, and obtain the potential risk and response ability assessment results of the current system environment; According to historical attack data and known security events, extract the evolution laws of attack behaviors through time series analysis and pattern matching techniques, combine machine learning models to predict the types and impact ranges of possible future security threats, and at the same time identify potential attack paths and key resources affected to identify new attack vectors against the affected components in advance; Based on the potential risk and response ability assessment results of the current system environment and the new attack vectors, balance the implementation cost and expected benefits of security control measures through a multi-objective optimization algorithm, and combine the security status, historical attack patterns, and expected losses of the current system to dynamically generate a set of candidate response strategies, adaptively adjust the strategy priorities according to real-time environmental changes and risk evolution trends, and dynamically adjust and formulate optimal security control measures.

[0109] In this embodiment, the adaptive strategy selection algorithm is a method that can dynamically adjust security policies according to the real-time state and historical data of the current system. It comprehensively evaluates the system load, network traffic patterns, and the effectiveness of existing security measures to determine the most appropriate response strategy. In addition, the multi-objective optimization algorithm aims to balance the implementation cost of security measures and their expected benefits to ensure that the measures taken are both effective and economical.

[0110] In the embodiments of the present application, first, a comprehensive assessment is conducted on the third-party components involved in the abnormal behavior list to determine their roles in the software supply chain and their impacts on system security and stability; second, the real-time monitoring data of the system is collected and processed, and an adaptive strategy selection algorithm is used to generate a risk assessment portrait reflecting the current system security status; third, historical attack data and machine learning models are utilized to predict future security threats and identify potential attack paths and critical resources; finally, a multi-objective optimization algorithm is employed to generate the best response strategies for these threats, and the strategies are continuously adjusted according to real-time environmental changes to maintain the optimal protection state.

[0111] The following is a specific example:

[0112] Some abnormal behaviors were discovered in an enterprise's in-house deployed application. First, a comprehensive security assessment was carried out on the third-party components used by the application, analyzing their upstream and downstream dependencies, call frequencies, and permission scopes in the software supply chain, and a security status report for each component was obtained; second, the running data of the application was collected in real time. After cleaning and feature extraction, an adaptive strategy selection algorithm was used to analyze the security status of the current system, considering system load, network traffic patterns, and the effectiveness of existing security measures, and a real-time risk assessment portrait of the system was formed; third, based on past security events and known attack patterns, future possible security threats were predicted through time series analysis and pattern matching techniques, and potential attack paths and affected critical resources were identified; then, a multi-objective optimization algorithm was used to evaluate the costs and benefits of various security control measures, and combined with the real-time state of the system and historical attack patterns, a set of candidate response strategies was dynamically generated, and the priorities of these strategies were continuously adjusted according to changes in the real-time environment; through the above steps, not only was the enterprise effectively protected from unknown security threats, but it was also ensured that the security measures taken were the most cost-effective.

[0113] To further improve the accuracy of the assessment of potential risks and response capabilities in the current system environment, in some embodiments, the monitoring data of the current system is obtained from the behavior data stream, the monitoring data is cleaned and feature-extracted in real time, and based on the security status assessment report, an adaptive strategy selection algorithm is applied to analyze and process the security status of the current system. The relevance between system load, network traffic patterns, and the effectiveness of existing security measures is evaluated through a dynamic weight allocation mechanism, and combined with the load of the current system, network traffic patterns, and the effectiveness of existing security measures, a real-time risk assessment portrait of the system environment is generated, and the assessment results of potential risks and response capabilities in the environment where the current system is located are obtained, including:

[0114] Obtain the monitoring data of the current system from the behavioral data stream, perform real-time cleaning on the monitoring data through data filtering and outlier processing, extract key features related to system load, network traffic, and security measures, utilize the location and function information of third-party components provided in the security status assessment report in the software supply chain to analyze the load situation of the current system, evaluate the correlation between load peaks, resource utilization, and task priorities through a dynamic weight allocation mechanism to obtain an evaluation result regarding the load of the current system; based on the security status assessment report, combined with the network traffic data collected by network monitoring tools, through traffic clustering and pattern recognition techniques, analyze abnormal traffic patterns from the network traffic patterns of the current system, dynamically adjust the sensitivity of abnormal traffic detection in combination with historical traffic data and real-time traffic trends, and based on the abnormal traffic patterns, evaluate the communication security of the current system to generate a network traffic security assessment report containing traffic anomaly scores and risk hotspots; based on the security status assessment report, review the security control measures deployed in the current system, evaluate the impact of different security measures on system load and network traffic through a dynamic weight allocation mechanism to determine whether the security control measures can effectively respond to the threats in the environment where the current system is located, and verify the actual protection effect of the security control measures through simulated attack tests or vulnerability scans, record the effectiveness scores and coverage of the security measures to obtain an evaluation result of the effectiveness of the security measures; input the evaluation result, the security assessment report, and the evaluation result of the effectiveness of the security measures into an adaptive policy selection algorithm, integrate the effectiveness information of system load, network traffic, and security measures through multi-dimensional data fusion technology to output multi-dimensional information, dynamically adjust the weight allocation of each dimension in combination with real-time environmental changes, analyze the multi-dimensional information through a machine learning model, construct a real-time risk assessment portrait of the system environment, including a risk distribution map, threat evolution trend, and response ability score, and obtain the potential risk and response ability evaluation result in the environment where the current system is located in combination with the mutual influence between various factors in the multi-dimensional information.

[0115] In this embodiment, real-time cleaning refers to removing outliers by filtering and processing the original monitoring data to ensure the quality of the data. The dynamic weight allocation mechanism is a method of adjusting the weights of different indicators according to the operating conditions of the system to more accurately reflect the true state of the system. Traffic clustering and pattern recognition techniques are used to identify abnormal patterns in network traffic to help quickly locate potential threats. The adaptive policy selection algorithm comprehensively considers the system load, network traffic, and the effectiveness of existing security measures to provide the optimal security protection strategy for the system.

[0116] In the embodiments of the present application, first, key monitoring data is extracted from the behavior data stream, and high-quality input data is obtained after real-time cleaning; second, using this data in combination with the location and function information of third-party components, the load status of the current system is evaluated through a dynamic weight allocation mechanism; third, based on network monitoring data, traffic clustering and pattern recognition techniques are used to analyze the current network traffic pattern, identify any abnormal traffic, and evaluate the communication security of the system accordingly; then, the effectiveness of existing security measures is reviewed, and their scores and coverage are recorded; finally, all evaluation results are input into an adaptive policy selection algorithm, and a multi-dimensional information is integrated through a machine learning model to construct a real-time risk assessment profile of the system and evaluate the potential risks and response capabilities of the system.

[0117] The following is a specific example:

[0118] In an enterprise-level data center environment, first, monitoring data within the past 24 hours is extracted from server logs and network monitoring tools, and real-time cleaning is performed through data filtering and outlier handling to extract key features related to system load, network traffic, and security measures; second, based on the function and location information of each third-party component within the data center, the load situation of the system is analyzed, and the relationship between the load peak, resource utilization rate, and task priority is calculated through a dynamic weight allocation mechanism to obtain a preliminary evaluation of the system load; third, in combination with network traffic data, several abnormal traffic patterns are discovered using traffic clustering and pattern recognition techniques, and the detection sensitivity is dynamically adjusted in combination with historical data to form a network traffic security assessment report including abnormal scores and risk hotspots; then, existing security measures such as firewalls and intrusion detection systems are reviewed, and their actual effects are verified through simulated attack tests, and the effectiveness scores and coverage of each measure are recorded; finally, all evaluation results are input into an adaptive policy selection algorithm, and these multi-dimensional information is integrated using a machine learning model to construct a detailed real-time risk assessment profile of the system environment, including a risk distribution map, threat evolution trend, and response capability score; through the above steps, not only the security monitoring ability of the enterprise data center environment is improved, but also the accurate assessment and rapid response to potential threats are achieved.

[0119] To further improve the monitoring and risk identification capabilities for the runtime behavior of third-party components, in some embodiments, according to the behavior pattern library, the differential execution sandbox technology is used to monitor the runtime behavior of the third-party components, so as to obtain and record the behavior data stream of the third-party components during runtime using a fine-grained resource access tracking mechanism, including:

[0120] Using the behavior pattern library, configure and deploy a differential execution sandbox environment, create an independent runtime environment through virtualization technology and resource isolation mechanisms for isolating and monitoring the behavior of the third-party component during runtime. At the same time, configure the behavior monitoring policy of the sandbox environment to match the normal and abnormal behavior patterns in the behavior pattern library; use differential execution sandbox technology to monitor the behavior of the third-party component during runtime, by executing the third-party component in the sandbox environment and synchronously comparing its differences with the normal behavior pattern to ensure that the monitoring mechanism identifies and matches the normal and abnormal behavior patterns in the behavior pattern library, and at the same time record the execution trace and resource access behavior of the component in the sandbox environment; for the monitoring mechanism, deploy a fine-grained resource access tracking mechanism, capture the access requests of the third-party component to system resources through hook technology and system call interception mechanism, track all access operations of the third-party component to system resources during runtime, including file reading and writing, network communication, memory access, and process creation, etc., to obtain and record the behavior data stream of the third-party component during runtime, and at the same time mark each access operation with a timestamp and context label to generate a complete behavior log.

[0121] In this embodiment, the differential execution sandbox is a technology that creates a secure and independent runtime environment through virtualization technology and resource isolation mechanisms, which can effectively isolate and monitor the behavior of third-party components. The fine-grained resource access tracking mechanism involves using hook technology and system call interception technology to capture all access operations of the component to system resources, including file reading and writing, network communication, etc., and mark each operation with a timestamp and context label to ensure that the behavior trace of the component can be comprehensively recorded.

[0122] In the embodiment of the present application, first, configure the differential execution sandbox environment according to the behavior pattern library to ensure that it can accurately match the normal and abnormal behavior patterns; second, execute the third-party component in the sandbox environment and monitor the deviation of its behavior from the normal pattern in real time; third, adopt a fine-grained resource access tracking mechanism to accurately capture the access requests of the third-party component to various system resources, and detailedly record the timestamps and context information of these requests, so as to construct a detailed behavior log for subsequent analysis and review.

[0123] The following is a specific example:

[0124] In an enterprise-level application system, first, a differential execution sandbox environment is configured according to a known security behavior pattern library, and virtualization technology is used to create an independent running environment specifically for monitoring newly integrated third-party payment components. Second, the payment component is launched in this sandbox environment, and its behavior is monitored in real time. The actual behavior is compared with the predefined normal behavior patterns to ensure that any deviation is captured in a timely manner. At the same time, a fine-grained resource access tracking mechanism is deployed. Through hook technology and system call interception mechanism, access requests of the component to all resources within the system are tracked and recorded, including but not limited to read and write operations of the file system, network communication activities, and memory access, etc. Each operation is accompanied by a timestamp and a context label. Then, all the collected behavior data is integrated into a complete behavior log. Through the above steps, not only the monitoring accuracy of the behavior of the third-party component is improved, but also the protection of the security of the enterprise internal system is enhanced, enabling rapid response and handling even in the face of potential risks.

[0125] Graph Neural Networks (GNNs) are deep learning models specifically designed for processing graph-structured data and are widely used in fields such as social network analysis, recommendation systems, and anomaly detection. In the field of software supply chain security, GNNs can effectively capture the complex relationships between third-party components and evaluate their risk levels. This solution uses GNNs to perform multi-layer aggregation and transformation on the nodes in the behavior graph to generate enhanced node representations, and then predicts the risk scores of each node.

[0126] Optionally, the deep learning processing of the graph representation using the graph neural network algorithm updates the representation of each node in the behavior graph by multi-layer aggregating the neighbor node information of the nodes in the behavior graph. Combining the relevance between the abnormal behaviors and the propagation pattern of the abnormal behaviors in the network, the behavior risk information evaluated by the graph neural network is obtained, including:

[0127] Initialize the vector representation of each node in the graph representation to obtain the initial vector representation of each node. Based on the connection relationship between the nodes in the graph representation, collect the information of the neighbor nodes directly connected to each node to obtain the comprehensive information about the surrounding environment where the node is located, including:

[0128] Generate the initial vector representation of each node in the behavior graph according to the initialization strategy of each node , in each layer , collect the neighbor nodes directly connected to the node 's information, and integrate the information of the neighbor nodes through an aggregation function to form comprehensive information ; Among them, the calculation formula for the comprehensive information is:

[0129] ;

[0130] Among them, represents the comprehensive information aggregated by node in the -th layer of the graph neural network; represents the set of neighbor nodes of node ; represents the size of the set of neighbor nodes of node , that is, the number of neighbor nodes, which is used as the denominator when calculating the average value; represents the vector representation of node in the -th layer of the graph neural network; represents the summation operation on all neighbor nodes belonging to , is the index for traversing all neighbor nodes; ;

[0131] In the calculation formula of the comprehensive information , the purpose of this formula design is to integrate the information of neighbor nodes through an aggregation function, enabling each node to reflect the environmental characteristics around it and enhancing the node representation ability.

[0132] The following briefly introduces the design reasons for each item of this formula:

[0133] The design reason for is to gradually accumulate the information of the node and its neighbors, so as to better capture the context features of the node. The design reason for is to ensure that the contributions of each neighbor node are of equal weight and avoid the scale difference problem caused by different nodes having different numbers of neighbors.

[0134] The design reason for

[0135] is to directly obtain it from the adjacency matrix or edge list of the behavior graph. For each node is the set of all nodes directly connected to it. During the training process, these representations are gradually updated through a multi-layer aggregation mechanism. The initial representation can be the original feature vector of the node, and the representations of subsequent layers are iteratively calculated through the formula and other update mechanisms. is directly calculated from the size of the set of neighbor nodes .

[0136] According to the comprehensive information, through a trainable transformation function, converting the initial vector representation of the node into a target vector representation that combines the characteristics of the node itself and the neighborhood information of the node includes:

[0137] According to the comprehensive information and the node in the layer of the graph neural network vector representation update the node in the layer of the graph neural network target vector representation through the transformation function, and is calculated through the following formula:

[0138] ;

[0139] Among them, represents the updated target vector representation of the node in the layer of the graph neural network; Activation function, used to introduce non-linearity; The weight matrix of the layer, used to map the input features to the output feature space; represents the concatenation operation, that is, concatenating the representation vector of the node itself in the layer and the aggregated neighbor information into a new vector, and using the new vector as the input of the transformation function; represents the bias vector of the layer, used to adjust the threshold of the activation function;

[0140] In the calculation formula of the target vector representation , the purpose of this formula design is to update the node representation through the transformation function, introduce non-linearity, so that the model can capture more complex feature relationships.

[0141] The following briefly introduces the design reasons for each item of this formula:

[0142] Introducing the non-linear activation function refers to the activation function is introduced to break the limitations of linear transformation, enabling the model to capture complex non-linear relationships between input features. Using the weight matrix refers to the weight matrix enables the model to better capture the complex relationships between nodes and their neighbors by learning to adjust the importance of different input features. Concatenating the node's own representation and aggregating neighbor information is achieved by concatenating the previous layer representation of the node itself and the aggregated neighbor information By doing so, the model not only considers the features of the node itself but also incorporates the influence of its surrounding environment. It ensures that the representation of each node reflects not only its own attributes but also contains important information from neighboring nodes, providing a more comprehensive understanding of the context. Introducing the bias term is the bias term is introduced to ensure a non-zero output even when the input is zero, increasing the flexibility of the model. This helps the model better fit the data under different input conditions and avoids the problem of constant output due to all-zero inputs.

[0143] The following briefly introduces the methods for obtaining the parameters of this formula:

[0144] Activation function is selected according to the specific task requirements. The weight matrix is the weight matrix is learned from a large amount of labeled data through the training process. is the representation of the node at the layer, which is calculated step by step by recursively applying the formula. The initial representation can be the original feature vector of the node, such as the features extracted from the behavior records. is calculated by aggregating the representations of neighboring nodes The bias term is the bias term is also learned from the labeled data through the training process and is optimized together with the weight matrix The initial bias term can be randomly initialized or set to zero.

[0145] Using the enhanced node representation as the input, predicting the risk level of each node in the behavior graph, and combining the features of the node itself in the behavior graph and the position and role of the node in the entire network, outputting a score representing the degree of abnormal behavior risk, including:

[0146] Using the enhanced node representation​ As input, the risk score of each node is predicted through a prediction model , and the formula is:

[0147] ;

[0148] Among them, represents the risk score of node ; represents the weight matrix of the first - layer prediction layer, which defines the linear relationship between the input enhanced node representation and the output risk score ; : the weight matrix of the second - layer prediction layer, used for linear transformation after further non - linear transformation; represents the enhanced node representation generated after introducing the graph structure characteristics; represents the bias vector of the first - layer prediction layer; represents the bias vector of the second - layer prediction layer; represents the feature representation of node after high - order feature interaction processing; represents the hidden representation of node containing residual connections and adaptive normalization. ReLU represents the activation function, used to introduce non - linearity.

[0149] In the calculation formula for predicting the risk score of each node by the prediction model , the design purpose of this formula is to use the enhanced node representation to predict the risk score of each node, combining node features and network positions to comprehensively evaluate risks.

[0150] The following briefly introduces the design reasons for each item of this formula:

[0151] Introducing the non - linear activation function ReLU is to enhance the expression ability of the model. The non - saturation property of ReLU helps to accelerate the training convergence and prevent the gradient vanishing problem, making the training of deep networks more stable and efficient. Using the weight matrices and is that the weight matrices and are introduced to achieve linear combination of features, enabling the model to learn complex relationships between input features. By applying different weight matrices layer by layer, the model can extract different feature abstractions at different levels, gradually enhancing the understanding of graph - structured data. This not only increases the learning depth of the model but also improves its generalization ability and adaptability. Residual connection Introducing residual connections allows information to be directly passed from shallower layers to deeper layers, ensuring that the model can still effectively learn useful features at deeper levels. This approach can significantly improve the performance of the model, especially when dealing with complex graph-structured data. Node feature representation is the node feature representation contains the original feature information of the node itself, such as the time in the behavior record, the resource access pattern, etc. These features provide the model with basic information about the node and are the basis for risk assessment. By combining with the representation after multiple aggregations, the model can more comprehensively understand the behavior pattern of the node and thus make more accurate risk predictions. Bias term and are the bias terms and are introduced to ensure that non-zero outputs can be generated even when the input is zero, increasing the flexibility of the model. The bias terms enable the model to still have reasonable outputs without input, improving the adaptability and robustness of the model.

[0152] The following briefly introduces the ways to obtain the parameters of this formula:

[0153] The activation function ReLU selects an appropriate activation function according to the specific task requirements. ReLU is one of the most commonly used activation functions in deep learning and is usually directly provided in deep learning frameworks. Weight matrix and are the weight matrices and are learned from a large amount of labeled data through the training process. Usually, the backpropagation algorithm is used to minimize a predefined loss function to optimize these parameters. The initial weights can be randomly initialized or loaded from a pre-trained model. Residual connection is to aggregate the information of neighboring nodes and update the node representation through a transformation function. Residual connections can be extracted from specific hidden layers to ensure the effective transmission of information. Node feature representation is the node feature representation can be extracted from the behavior record, including but not limited to the occurrence time, the system resources involved, the type of operation executed, and the context information. These features can be generated through data preprocessing steps and used as the input of the model. Bias term and are the bias terms and are also learned from the labeled data through the training process and are optimized together with the weight matrices and The initial bias terms can be randomly initialized or set to zero.

[0154] ​Summarize the above scores to generate behavioral risk information.

[0155] Suppose we have a behavioral graph containing 5 nodes, numbered to , and the initial vector representations of each node are known and their sets of neighbor nodes :

[0156] ;

[0157] Set of neighbor nodes: ;

[0158] Weight matrix and bias vector: ;

[0159] Activation function: ;

[0160] Calculation process:

[0161] First step: Initialize the node vector representation. According to the given initial vector representations , directly use these values as the initial vector representations of the 0th layer.

[0162] Second step: Aggregate neighbor node information. For each layer , calculate the comprehensive information : Take as an example:

[0163] ;

[0164] Similarly, calculate the comprehensive information of other nodes:

[0165] ;

[0166] Third step: Update the node vector representation. Use the transformation function to update the node vector representation : Take as an example:

[0167] ;

[0168] Similarly, calculate the updated vector representations of other nodes .

[0169] Fourth step: Predict the risk score. Use the enhanced node representation as the input to predict the risk score of each node : Take as an example:

[0170] ;

[0171] Hypothesis and :

[0172] ;

[0173] Similarly, calculate the risk scores of other nodes .

[0174] By calculating the risk scores of each node , we obtain the risk level scores of each abnormal behavior. For example, the risk score of node is 0.832, indicating that this abnormal behavior has a high risk level. The security team can take corresponding measures based on these scores, such as isolating high-risk plugins, strengthening monitoring, or updating security policies. This method not only improves the ability to identify potential threats but also enhances the system's adaptability and response efficiency, ensuring the security of the software supply chain.

[0175] Optionally, according to the abnormal behavior list in step 105, the response policy from a predefined security control measure library is dynamically adjusted through an adaptive policy selection algorithm to formulate security control measures for the third-party component, including: evaluating and processing the third-party components involved in the abnormal behavior list to determine the location, function of the third-party component in the software supply chain, and the impact of the third-party component on the overall security and stability of the system, so as to obtain a security status evaluation report of the affected component; obtaining the monitoring data of the current system from the behavior data stream, analyzing and processing the security status of the current system by applying the adaptive policy selection algorithm based on the security status evaluation report, and combining the load of the current system, the network traffic pattern, and the effectiveness of the existing security measures to obtain the evaluation results of potential risks and response capabilities in the environment where the current system is located; predicting the types and scopes of security threats that may occur in the future according to historical attack data and known security events by combining with a machine learning model to identify new attack vectors against the affected component in advance; based on the evaluation results of potential risks and response capabilities in the environment where the current system is located and the new attack vectors, and combining the security status of the current system, historical attack patterns, and expected losses, dynamically adjust and formulate optimal security control measures.Optionally, obtain the monitoring data of the current system from the behavior data stream, based on the security status assessment report, apply an adaptive policy selection algorithm to analyze and process the security status of the current system, and combine the load of the current system, the network traffic pattern, and the effectiveness of the existing security measures to obtain the potential risk and response ability assessment results in the environment where the current system is located, including: obtaining the monitoring data of the current system from the behavior data stream, using the location and function information of the third-party components in the software supply chain provided in the security status assessment report to analyze the load situation of the current system, and obtaining the assessment result of the load of the current system; based on the security status assessment report, combining the network traffic data collected by the network monitoring tool, analyzing the abnormal traffic pattern from the network traffic pattern of the current system, and based on the abnormal traffic pattern, evaluating the communication security of the current system, and generating a security assessment report of the network traffic pattern; based on the security status assessment report, reviewing the security control measures deployed in the current system to determine whether the security control measures can effectively respond to the threats in the environment where the current system is located, and verifying the actual protection effect of the security control measures through simulation attack tests or vulnerability scans to obtain the security measure effectiveness assessment result; inputting the assessment result, the security assessment report, and the security measure effectiveness assessment result into the adaptive policy selection algorithm to output multi-dimensional information, analyzing the multi-dimensional information through a machine learning model, and combining the mutual influence between the factors in the multi-dimensional information to obtain the potential risk and response ability assessment results in the environment where the current system is located.

[0176] In this step, the security status assessment report includes a detailed assessment of the location, function of the third-party components in the software supply chain and their impact on the overall security and stability of the system. This information is used to determine the security status of the affected components and provide a basis for subsequent security policy adjustments. The monitoring data comes from the behavior data stream and covers multi-dimensional information such as the load situation of the current system, the network traffic pattern, and the effectiveness of the existing security measures. The potential risk and response ability assessment results are obtained by analyzing and processing the above monitoring data through an adaptive policy selection algorithm, and combining the load of the current system, the network traffic pattern, and the actual protection effect of the existing security measures, the potential risk and response ability in the environment where the system is located are evaluated. The new attack vector is based on historical attack data and known security events, combined with a machine learning model to predict the possible types and impact ranges of future security threats, and to identify in advance the new attack paths against the affected components. The optimal security control measures are dynamically adjusted and formulated according to the potential risk of the current system, the response ability assessment result, the historical attack pattern, and the expected loss, and are the most effective security policies.

[0177] In the embodiments of the present application, in this alternative solution, the third-party components involved in the abnormal behavior list are first comprehensively evaluated to determine their positions, functions in the software supply chain, and their impacts on the overall security and stability of the system, and a security status evaluation report is generated. Next, the monitoring data of the current system is obtained from the behavioral data stream, and the load condition of the current system is analyzed by using the position and function information provided in the security status evaluation report to obtain an evaluation result regarding the system load. Meanwhile, by combining the network traffic data collected by the network monitoring tool, an abnormal traffic pattern is analyzed, the communication security of the current system is evaluated, and a security evaluation report of the network traffic pattern is generated. In addition, the security control measures deployed in the current system are reviewed to verify their actual protection effects, and an evaluation result of the effectiveness of the security measures is obtained. Finally, these evaluation results are input into the adaptive policy selection algorithm, and through the machine learning model, multi-dimensional information is analyzed, and combined with the mutual influences between various factors, an evaluation result of the potential risks and response capabilities in the environment where the current system is located is obtained. Based on these evaluation results and the new attack vectors, combined with the security status of the current system, historical attack patterns, and expected losses, the optimal security control measures are dynamically adjusted and formulated to ensure the security and stability of the system.

[0178] In an enterprise-level software supply chain environment, the security team is committed to dynamically adjusting security control measures to address potential threats. They first conduct a comprehensive assessment of third-party components involved in the list of abnormal behaviors, not only paying attention to the positions and functions of these components in the supply chain, but also deeply analyzing their impacts on the overall security and stability of the system, thus generating a detailed security status assessment report. For example, for the behavior of a certain plugin frequently accessing unauthorized files, which may affect the integrity of system files, the team detailedly records and evaluates the risk level of this behavior. Then, the monitoring data of the current system is obtained from the real-time behavior data stream, and the information provided by the previous security status assessment report is used to analyze the current system load situation, especially the phenomenon that the system load is significantly increased during a specific period. At the same time, combining with the network traffic data collected by network monitoring tools, the team identifies abnormal traffic patterns, evaluates that there are vulnerabilities in the communication security of the current system, and generates a security assessment report of the network traffic pattern accordingly. In addition, the team also reviews the effectiveness of the security control measures already deployed in the current system, verifies the actual protection effects of these measures through simulated attack tests and vulnerability scans, and obtains specific evaluation results on the effectiveness of security measures. Finally, all the above evaluation results are input into the adaptive strategy selection algorithm, and a machine learning model is used to comprehensively analyze multi-dimensional information, considering the interactions between various factors, and the evaluation results of potential risks and response capabilities in the current environment are obtained. Based on this, combining factors such as predicted new attack vectors, the current security status of the system, historical attack patterns, and expected losses, the security team dynamically adjusts and formulates optimal security control measures, such as isolating high-risk plugins, enhancing network traffic monitoring, updating firewall rules, etc. Throughout the process, the application of the adaptive strategy selection algorithm greatly improves the security and response efficiency of the system, ensures that threats can be timely and effectively addressed, and significantly enhances the overall security protection level of the enterprise. For example, immediately isolating a specific plugin after detecting its abnormal behavior to prevent it from further endangering the system security; or quickly adjusting firewall rules according to changes in network traffic patterns to block potential malicious traffic from entering the enterprise internal network. This series of highly targeted and rapid-response measures effectively guarantees the secure and stable operation of the enterprise software supply chain.Optionally, according to the behavior pattern library in step 103, the differential execution sandbox technology is used to monitor the behavior of the third-party component during runtime, so as to obtain and record the behavior data stream of the third-party component during runtime by using the fine-grained resource access tracking mechanism, including: configuring and deploying a differential execution sandbox environment by using the behavior pattern library for isolating and monitoring the behavior of the third-party component during runtime; using the differential execution sandbox technology to monitor the behavior of the third-party component during runtime to ensure that the monitoring mechanism identifies and matches the normal and abnormal behavior patterns in the behavior pattern library; for the monitoring mechanism, deploying a fine-grained resource access tracking mechanism to track all access operations of the third-party component to system resources during runtime to obtain and record the behavior data stream of the third-party component during runtime.

[0179] In this step, the differential execution sandbox environment is an execution environment similar to but isolated from the actual production environment, which can observe and analyze the real running behavior of the third-party component without affecting the production system. The fine-grained resource access tracking mechanism is used to record all access operations of the third-party component to system resources during runtime, providing detailed log information to ensure that each resource access is accurately captured and recorded, providing detailed data support for subsequent behavior analysis.

[0180] In the embodiment of the present application, this optional solution first configures and deploys a differential execution sandbox environment by using the behavior pattern library to isolate and monitor the behavior of the third-party component during runtime. The differential execution sandbox technology ensures that the monitoring mechanism can identify and match the normal and abnormal behavior patterns in the behavior pattern library, thereby improving the accuracy of behavior recognition. Then, a fine-grained resource access tracking mechanism is deployed in the sandbox environment to track all access operations of the third-party component to system resources during runtime, and obtain and record the detailed behavior data stream during runtime. In this way, not only can the behavior of the third-party component be monitored in real time, but also all resource access operations can be detailedly recorded, providing a solid data basis for subsequent risk assessment and anomaly detection.

[0181] In an enterprise-level software development environment, to ensure that the introduced third-party components do not introduce potential security threats, the security team first configured and deployed a differential execution sandbox environment based on a pre-built behavior pattern library. This environment not only simulates the real production environment to ensure that the third-party components can exhibit their real behaviors, but also is completely isolated from the actual business environment, thus avoiding any potential risks from affecting the existing system. For example, when a certain plugin is launched in the sandbox environment, the built-in monitoring mechanism immediately starts to work. By identifying and matching the normal and abnormal behavior patterns in the behavior pattern library, any behavior deviating from the standard can be detected in a timely manner, such as attempting to access unauthorized resources or performing abnormal operations. At the same time, to further enhance the monitoring ability, the team also deployed a fine-grained resource access tracking mechanism to record in detail all the system resource access operations of the plugin, including the specific paths and contents of each configuration file read and the details of each data packet of each request sent during network communication. These detailed runtime behavior data streams are then transmitted to the central monitoring system in real time, where in-depth analysis is carried out to identify potential security threats and take corresponding countermeasures. Throughout the process, the combined application of the differential execution sandbox technology and the fine-grained resource access tracking mechanism significantly enhances the transparency and controllability of the third-party component behaviors, ensuring that even in a complex enterprise-level software development environment, the overall security of the system can be effectively improved and the enterprise can be protected from potential security hazards brought by external components. In this way, the security team can not only quickly respond to and handle abnormal behaviors, but also continuously optimize the behavior pattern library based on the collected data to enhance the long-term security protection ability. Figure 2 The following is a schematic structural diagram of a software supply chain risk detection and protection system provided by an embodiment of the present application, as Figure 2 shown, the system includes:

[0182] An acquisition module 21, configured to acquire third-party components in the software supply chain and analyze multi-level dynamic behaviors from the third-party components;

[0183] A prediction module 22, configured to predict risk behavior patterns in the third-party components based on the multi-level dynamic behaviors using a Bayesian network algorithm and generate a behavior pattern library;

[0184] A monitoring module 23, configured to monitor the behaviors of the third-party components during runtime according to the behavior pattern library by using differential execution sandbox technology, and acquire and record the behavior data streams of the third-party components during runtime by using a fine-grained resource access tracking mechanism;

[0185] An identification module 24, configured to identify, based on the behavior data stream, abnormal behaviors that deviate from the normal behavior patterns in the behavior pattern library by applying a time series anomaly detection algorithm of deep learning, and use a graph neural network algorithm to evaluate the risk levels of the abnormal behaviors, and generate an abnormal behavior list by combining the relevance and propagation paths among the abnormal behaviors;

[0186] An adjustment module 25, configured to dynamically adjust, according to the abnormal behavior list, a response strategy from a predefined security control measure library through an adaptive policy selection algorithm, and formulate a security control measure for the third-party component.

[0187] Figure 2 The described software supply chain risk detection and protection system can execute Figure 1 The described software supply chain risk detection and protection method in the illustrated embodiment, and its implementation principle and technical effects will not be elaborated further. For each module and unit in the above-described software supply chain risk detection and protection system, the specific manners of performing operations have been described in detail in the embodiments related to the method, and will not be elaborated here.

[0188] In a possible design, Figure 2 The software supply chain risk detection and protection system in the illustrated embodiment can be implemented as a computing device, such as Figure 3 shown, and this computing device can include a storage component 31 and a processing component 32;

[0189] The storage component 31 stores one or more computer instructions, and among them, the one or more computer instructions are called and executed by the processing component 32.

[0190] The processing component 32 is configured to: obtain a third-party component in the software supply chain, and analyze multi-level dynamic behaviors from the third-party component; based on the multi-level dynamic behaviors, use a Bayesian network algorithm to predict risk behavior patterns in the third-party component, and generate a behavior pattern library; according to the behavior pattern library, use differential execution sandbox technology to monitor the behaviors of the third-party component during runtime, so as to obtain and record the behavior data stream of the third-party component during runtime by using a fine-grained resource access tracking mechanism; based on the behavior data stream, apply a time series anomaly detection algorithm of deep learning to identify abnormal behaviors that deviate from the normal behavior patterns in the behavior pattern library, and use a graph neural network algorithm to evaluate the risk levels of the abnormal behaviors, and generate an abnormal behavior list by combining the relevance and propagation paths among the abnormal behaviors; according to the abnormal behavior list, dynamically adjust a response strategy from a predefined security control measure library through an adaptive policy selection algorithm, and formulate a security control measure for the third-party component.

[0191] Among them, the processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above methods. Of course, the processing component may also be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components for executing the above methods.

[0192] The storage component 31 is configured to store various types of data to support the operation of the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0193] Of course, the computing device may also necessarily include other components, such as input / output interfaces, display components, communication components, etc.

[0194] The input / output interface provides an interface between the processing component and the peripheral interface module, and the above peripheral interface module may be an output device, an input device, etc.

[0195] The communication component is configured to facilitate communication between the computing device and other devices in a wired or wireless manner, etc.

[0196] Among them, the computing device may be a physical device or an elastic computing host provided by a cloud computing platform, etc. At this time, the computing device may refer to a cloud server, and the above processing component, storage component, etc. may be basic server resources leased or purchased from a cloud computing platform.

[0197] The embodiment of the present application also provides a computer storage medium storing a computer program, and when the computer program is executed by a computer, it can implement the above Figure 1 software supply chain risk detection and protection method shown in the embodiment.

[0198] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again.

[0199] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative work.

[0200] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0201] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present application.

Claims

1. A software supply chain risk detection and protection method, characterized in that: include: Obtain third-party components in the software supply chain and analyze multi-level dynamic behaviors from the third-party components; Based on the multi-level dynamic behavior, using a Bayesian network algorithm to predict risk behavior patterns in the third-party components and generate a behavior pattern library; According to the behavior pattern library, the behavior of the third-party component during runtime is monitored using differential execution sandbox technology, so as to obtain and record the behavior data flow of the third-party component during runtime using a fine-grained resource access tracking mechanism; Based on the behavior data stream, a deep learning time series anomaly detection algorithm is applied to identify abnormal behaviors that deviate from normal behavior patterns in the behavior pattern library, and a graph neural network algorithm is used to evaluate the risk level of the abnormal behaviors, and a list of abnormal behaviors is generated by combining the correlation and propagation path between the abnormal behaviors; According to the abnormal behavior list, dynamically adjust the response strategy from the predefined security control measure library through an adaptive strategy selection algorithm to formulate security control measures for the third-party component; Based on the behavior data stream, the deep learning time series anomaly detection algorithm is applied to identify abnormal behaviors that deviate from normal behavior patterns in the behavior pattern library, and the graph neural network algorithm is used to evaluate the risk level of the abnormal behaviors, and the abnormal behavior list is generated by combining the correlation and propagation path between the abnormal behaviors, including: The behavior data stream is modeled using a long short-term memory network or a deep learning model of a gated recurrent unit, and local and global features in the behavior data stream are extracted through a multi-scale sliding window, time series features are extracted from the behavior data stream, and a time series prediction model is constructed based on the time series features; According to the historical behavior data stream records of normal behavior patterns in the behavior pattern library, the time series prediction model is trained and verified to obtain an anomaly detection model; Inputting the data in the behavior data stream into the anomaly detection model, judging whether the specific behavior of the third-party component during operation deviates from the normal behavior pattern in the behavior pattern library through the probability distribution output by the anomaly detection model, and when the anomaly detection model identifies a behavior that deviates from the normal behavior pattern, recording the occurrence time of the behavior, the system resources involved and the specific operation type, and capturing the contextual environment information of the abnormal behavior, to obtain a record of the behavior identified as abnormal; By using the behavior records, by analyzing the temporal relationship and resource dependency relationship between the abnormal behaviors, a behavior graph representing the correlation between the abnormal behaviors is constructed, and node weights and edge weights are introduced to quantify the impact scope and severity of the abnormal behaviors. A graph neural network algorithm is applied to evaluate the risk level of the abnormal behaviors from the behavior graph. In combination with the correlation between the abnormal behaviors and the propagation path of the abnormal behaviors in the network, the risk score is optimized through multiple rounds of iterations to generate the risk level of each abnormal behavior. Based on the risk level, cluster analysis is performed on the abnormal behaviors to identify potential attack patterns, and specific information of the abnormal behaviors is summarized to generate an abnormal behavior list including abnormal behavior classification, risk score and disposal suggestions.

2. The method according to claim 1, characterized in that The behavior records are used to analyze the temporal relationship and resource dependency relationship between abnormal behaviors, to construct a behavior graph representing the correlation between the abnormal behaviors, to introduce node weights and edge weights to quantify the impact scope and severity of abnormal behaviors, to apply a graph neural network algorithm to evaluate the risk level of the abnormal behaviors from the behavior graph, and to optimize the risk score through multiple rounds of iterations to generate the risk level of each abnormal behavior, including: Extract key information from the behavior record, wherein the key information includes the time of occurrence, the system resources involved, the type of operation performed, and the context information of the behavior, and extract the execution subject, target object, and operation result information of the abnormal behavior to construct a more comprehensive behavior feature representation; By analyzing the temporal relationship between abnormal behaviors, the time interval and sequential dependency of the behaviors are calculated to determine the relevance of abnormal behaviors in the time dimension; by analyzing the resource dependency between abnormal behaviors, the access overlap and dependency intensity of the behaviors on system resources are calculated to determine the relevance of abnormal behaviors in the resource dimension; According to the key information and the correlation analysis results, a node is created for each abnormal behavior, and a weight is assigned to each node. The weight value is dynamically calculated according to the impact scope and severity of the abnormal behavior. At the same time, according to the logical relationship between the abnormal behaviors, edges between the nodes are created, and a weight is assigned to each edge. The weight value is dynamically calculated according to the correlation strength between the abnormal behaviors, so as to obtain a behavior map representing the interaction between the abnormal behaviors; Using graph embedding technology, the behavior graph is converted into a representation in a low-dimensional vector space, and the vector representations of nodes and edges are optimized through multiple rounds of iterations to retain the structural information and semantic information in the graph, thereby obtaining an optimized graph representation; The graph representation is deep-learned using a graph neural network algorithm. The importance of neighbor node information is dynamically adjusted by introducing an attention mechanism. The representation of each node in the behavior graph is updated by multi-layer aggregation of neighbor node information of nodes in the behavior graph. A multi-dimensional risk assessment model is constructed by combining the propagation path of abnormal behaviors and the dependency of system resources. The behavioral risk information evaluated by the graph neural network is obtained by combining the correlation between the abnormal behaviors and the propagation mode of the abnormal behaviors in the network. Based on the behavioral risk information, a comprehensive risk score is calculated for each abnormal behavior taking into account the direct harm and potential transmission risk of the abnormal behavior. The risk score is optimized through multiple rounds of iterations, and the scoring parameters are dynamically adjusted to reflect the real-time impact of the abnormal behavior. The score is mapped to a unified risk interval through normalization processing. According to the predefined risk threshold or distribution, a dynamic grading strategy is used to assign a corresponding risk level to each abnormal behavior, and an explanatory description of the risk level is generated at the same time, including the source of the risk and the scope of impact.

3. The method according to claim 2, characterized in that The graph representation is deep-learned using a graph neural network algorithm, the importance of neighbor node information is dynamically adjusted by introducing an attention mechanism, the representation of each node in the behavior graph is updated by multi-layer aggregation of neighbor node information of nodes in the behavior graph, a multi-dimensional risk assessment model is constructed in combination with the propagation path of abnormal behaviors and the dependency of system resources, and the behavior risk information evaluated by the graph neural network is obtained in combination with the correlation between the abnormal behaviors and the propagation mode of the abnormal behaviors in the network, including: Initialize the vector representation of each node in the behavior graph to obtain the initial vector representation of each node, enhance the features of the initial vector representation based on the occurrence time, resource dependency and operation type of the abnormal behavior, collect information of neighboring nodes directly connected to each node based on the connection relationship between nodes in the behavior graph, dynamically calculate the importance weight of each neighboring node to the current node by introducing an attention mechanism, and perform weighted aggregation on the neighboring node information according to the weight to obtain comprehensive information about the surrounding environment of the node; Based on the initial vector representation of the node, the aggregated comprehensive information of the association between the nodes is integrated from the comprehensive information by using an aggregation function, and the propagation intensity and influence range between the nodes are analyzed in combination with the propagation path of the abnormal behavior. According to the aggregated comprehensive information, the initial vector representation of the node is converted into a target vector representation that combines the node's own characteristics and the node's neighborhood information through a trainable conversion function, while retaining the temporal dependency and resource dependency between the nodes; Through the iterative message passing mechanism, the target representation of the node is repeatedly aggregated and transformed at different levels. In each layer iteration, the attention weight is dynamically updated to reflect the changes in the correlation between nodes, so as to obtain a global view of the complex correlation between the abnormal behaviors and capture the propagation mode of abnormal behaviors in the network. Based on the graph structure characteristics in the behavior graph combined with the global view, by analyzing the centrality and resource dependency strength of the nodes in the network, the main source or high-risk area of ​​the abnormal behavior is analyzed from the network structure characteristics in the abnormal behavior, and the key resource nodes and high-risk propagation paths are identified in combination with the dependency relationship of system resources, and an enhanced node representation of the network structure characteristics is generated; Using the enhanced node representation as input, a multi-dimensional risk assessment model is constructed, the influence range, propagation path and resource dependency of the node are comprehensively considered, the risk level of each node in the behavior graph is predicted, and the risk level of the node is calculated through a multi-dimensional scoring mechanism in combination with the characteristics of the node itself in the behavior graph and the position and role of the node in the behavior graph in the entire network, and a score representing the risk level of the abnormal behavior is output; The scores are aggregated, combined with the propagation path of the abnormal behavior and the dependency of system resources, to generate behavioral risk information including the risk source, propagation path, and impact range.

4. The method according to claim 1, characterized in that: The step of dynamically adjusting the response strategy from the predefined security control measures library through an adaptive strategy selection algorithm according to the abnormal behavior list to formulate security control measures for the third-party component includes: Evaluate and process the third-party components involved in the abnormal behavior list, and determine the position and function of the third-party components in the software supply chain and the impact of the third-party components on the overall security and stability of the system by analyzing the upstream and downstream dependencies, call frequency, and permission scope of the components in the software supply chain. At the same time, evaluate the historical behavior patterns of the components and the degree of deviation of the current abnormal behavior to obtain a security status assessment report of the affected components. Acquire monitoring data of the current system from the behavior data stream, perform real-time cleaning and feature extraction on the monitoring data, analyze and process the security status of the current system based on the security status assessment report, evaluate the correlation between system load, network traffic pattern and the effectiveness of existing security measures through a dynamic weight allocation mechanism, and generate a real-time risk assessment portrait of the system environment in combination with the load of the current system, network traffic pattern and the effectiveness of existing security measures, and obtain potential risk and response capability assessment results in the environment where the current system is located; Based on historical attack data and known security events, the evolution of attack behaviors is extracted through time series analysis and pattern matching technology, and the types and scope of security threats that may appear in the future are predicted in combination with machine learning models. At the same time, potential attack paths and affected key resources are identified to identify new attack vectors against the affected components in advance. Based on the potential risks and response capability assessment results in the environment of the current system and the new attack vector, a multi-objective optimization algorithm is used to balance the implementation cost and expected benefits of security control measures. In combination with the security status of the current system, historical attack patterns and expected losses, a set of candidate response strategies is dynamically generated. According to real-time environmental changes and risk evolution trends, strategy priorities are adaptively adjusted, and optimal security control measures are dynamically adjusted and formulated.

5. The method according to claim 4, characterized in that The monitoring data of the current system is obtained from the behavior data stream, and the monitoring data is cleaned and feature extracted in real time. Based on the security status assessment report, the security status of the current system is analyzed and processed by applying an adaptive strategy selection algorithm. The correlation between the system load, network traffic pattern and the effectiveness of existing security measures is evaluated through a dynamic weight allocation mechanism. In combination with the load of the current system, the network traffic pattern and the effectiveness of existing security measures, a real-time risk assessment portrait of the system environment is generated, and the potential risk and response capability assessment results in the environment where the current system is located are obtained, including: Acquire monitoring data of the current system from the behavior data stream, clean the monitoring data in real time through data filtering and outlier processing, extract key features related to system load, network traffic and security measures, analyze the load of the current system using the location and function information of third-party components in the software supply chain provided in the security status assessment report, evaluate the correlation between load peak, resource utilization and task priority through a dynamic weight allocation mechanism, and obtain an assessment result on the load of the current system; Based on the security status assessment report, combined with the network traffic data collected by the network monitoring tool, the abnormal traffic pattern is analyzed from the network traffic pattern of the current system through traffic clustering and pattern recognition technology, and the sensitivity of abnormal traffic detection is dynamically adjusted in combination with historical traffic data and real-time traffic trends. Based on the abnormal traffic pattern, the communication security of the current system is assessed, and a network traffic security assessment report containing traffic anomaly scores and risk hotspots is generated; Based on the security status assessment report, review the security control measures deployed in the current system, evaluate the impact of different security measures on system load and network traffic through a dynamic weight allocation mechanism to determine whether the security control measures are effective in responding to threats in the environment of the current system, and verify the actual protection effect of the security control measures through simulated attack tests or vulnerability scans, record the effectiveness scores and coverage of the security measures, and obtain the effectiveness assessment results of the security measures; The assessment result, the security assessment report and the security measure effectiveness assessment result are input into an adaptive strategy selection algorithm, and the system load, network traffic and security measure effectiveness information are integrated through multi-dimensional data fusion technology to output multi-dimensional information. The weight distribution of each dimension is dynamically adjusted in combination with real-time environmental changes. The multi-dimensional information is analyzed through a machine learning model to construct a real-time risk assessment portrait of the system environment, including a risk distribution map, a threat evolution trend and a response capability score. In combination with the mutual influence between the factors in the multi-dimensional information, the potential risk and response capability assessment results in the environment where the current system is located are obtained.

6. The method according to claim 1, characterized in that The method of monitoring the behavior of the third-party component at runtime by using the differential execution sandbox technology according to the behavior pattern library, and obtaining and recording the behavior data flow of the third-party component at runtime by using a fine-grained resource access tracking mechanism, includes: Using the behavior pattern library, configuring and deploying a differential execution sandbox environment, creating an independent runtime environment through virtualization technology and resource isolation mechanism to isolate and monitor the runtime behavior of the third-party component, and configuring the behavior monitoring strategy of the sandbox environment to match the normal and abnormal behavior patterns in the behavior pattern library; The behavior of the third-party component at runtime is monitored using differential execution sandbox technology, by executing the third-party component in the sandbox environment and synchronously comparing the difference between the third-party component and the normal behavior pattern, so as to ensure that the monitoring mechanism identifies and matches the normal and abnormal behavior patterns in the behavior pattern library, and records the execution track and resource access behavior of the component in the sandbox environment; For the monitoring mechanism, a fine-grained resource access tracking mechanism is deployed to capture the access requests of third-party components to system resources through hook technology and system call interception mechanism, and track all access operations of the third-party components to system resources during runtime, including file reading and writing, network communication, memory access and process creation, so as to obtain and record the behavioral data flow of the third-party components during runtime, and at the same time, timestamp and context label each access operation to generate a complete behavior log.

7. A software supply chain risk detection and protection system, characterized in that: include: An acquisition module, used to acquire third-party components in the software supply chain and analyze multi-level dynamic behaviors from the third-party components; A prediction module, used to predict risk behavior patterns in the third-party component based on the multi-level dynamic behavior using a Bayesian network algorithm to generate a behavior pattern library; A monitoring module, used to monitor the behavior of the third-party component at runtime by using the differential execution sandbox technology according to the behavior pattern library, so as to obtain and record the behavior data flow of the third-party component at runtime by using a fine-grained resource access tracking mechanism; An identification module is used to identify abnormal behaviors that deviate from normal behavior patterns in the behavior pattern library based on the behavior data stream and apply a deep learning time series anomaly detection algorithm, and use a graph neural network algorithm to evaluate the risk level of the abnormal behaviors, and generate an abnormal behavior list by combining the correlation and propagation path between the abnormal behaviors; An adjustment module, configured to dynamically adjust a response strategy from a predefined security control measure library through an adaptive strategy selection algorithm according to the abnormal behavior list, and formulate security control measures for the third-party component; Based on the behavior data stream, the deep learning time series anomaly detection algorithm is applied to identify abnormal behaviors that deviate from normal behavior patterns in the behavior pattern library, and the graph neural network algorithm is used to evaluate the risk level of the abnormal behaviors, and the abnormal behavior list is generated by combining the correlation and propagation path between the abnormal behaviors, including: The behavior data stream is modeled using a long short-term memory network or a deep learning model of a gated recurrent unit, and local and global features in the behavior data stream are extracted through a multi-scale sliding window, time series features are extracted from the behavior data stream, and a time series prediction model is constructed based on the time series features; According to the historical behavior data stream records of normal behavior patterns in the behavior pattern library, the time series prediction model is trained and verified to obtain an anomaly detection model; Inputting the data in the behavior data stream into the anomaly detection model, judging whether the specific behavior of the third-party component during operation deviates from the normal behavior pattern in the behavior pattern library through the probability distribution output by the anomaly detection model, and when the anomaly detection model identifies a behavior that deviates from the normal behavior pattern, recording the occurrence time of the behavior, the system resources involved and the specific operation type, and capturing the contextual environment information of the abnormal behavior, to obtain a record of the behavior identified as abnormal; By using the behavior records, by analyzing the temporal relationship and resource dependency relationship between the abnormal behaviors, a behavior graph representing the correlation between the abnormal behaviors is constructed, and node weights and edge weights are introduced to quantify the impact scope and severity of the abnormal behaviors. A graph neural network algorithm is applied to evaluate the risk level of the abnormal behaviors from the behavior graph. In combination with the correlation between the abnormal behaviors and the propagation path of the abnormal behaviors in the network, the risk score is optimized through multiple rounds of iterations to generate the risk level of each abnormal behavior. Based on the risk level, cluster analysis is performed on the abnormal behaviors to identify potential attack patterns, and specific information of the abnormal behaviors is summarized to generate an abnormal behavior list including abnormal behavior classification, risk score and disposal suggestions.

8. A computing device, characterized in that It comprises a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a software supply chain risk detection and protection method as described in any one of claims 1 to 6.

9. A computer storage medium, characterized in that: A computer program is stored, and when the computer program is executed by a computer, a software supply chain risk detection and protection method as described in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Intrusion detection system and method based on intelligent network

    CN118413406A

  • Software risk assessment system and method based on stage problem set

    CN119475327A

Cited By

  • Intelligent agent service platform based on real-time supply chain situation risk awareness

    CN120975557A