Method and device for analyzing container image dependency vulnerability propagation based on graph neural network
By constructing and updating the dependency graph of container images based on graph neural network, the problems of complex dependencies and inaccurate vulnerability propagation analysis in containerized environments are solved, and more efficient vulnerability propagation risk management and software security improvement are achieved.
Patent Information
- Application Number
- CN202510301774.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-03-14
AI Technical Summary
In containerized deployment environments, the dependencies of container images are complex, and it is difficult for the existing technology to accurately identify the dependencies between containers and effectively analyze vulnerability propagation, resulting in low network security.
Using a graph-based neural network method, a dependency graph is constructed by obtaining the software packages and their dependencies in the container image, and the node characteristics iteratively updates based on the target learning parameters, outputs vulnerability propagation potential scores, and determines high-risk paths for repair.
It improves the accuracy of vulnerability propagation analysis, can better adapt to the dynamic changes of dependencies, timely identify and repair high-risk paths, and improve software security.
Smart Images

Figure CN119808106B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of container security, and in particular, to a method and device for analyzing the propagation of vulnerabilities in container image dependencies based on a graph neural network. Background Art
[0002] With the rapid development of information technology, the complexity and scale of software systems have been continuously expanding. Especially in a containerized deployment environment, containerization is a software deployment process that packages an application program and its dependencies (such as libraries, configuration files, environment variables, etc.) into a standardized, lightweight, and portable independent unit (i.e., a container) through operating system-level virtualization technology. The dependency relationships between software components in containerized deployments have become increasingly complex. For example, in a typical containerized application, there may be multiple open-source and closed-source components, which form direct or indirect dependency chains.
[0003] A container image usually contains multiple layers, each layer may be created by different development teams, and references different external dependencies. These dependencies may directly come from the open-source community, and have the characteristics of dynamic changes and fast version updates, increasing the management difficulty. In addition, in a multi-cloud environment, the base images used by different cloud service providers may also have version inconsistency problems, further exacerbating the complexity of vulnerability propagation.
[0004] To address these challenges, many studies have started to focus on dependency analysis methods based on graph models. However, ordinary graph algorithms (such as the shortest path or topological sorting) have deficiencies in capturing the dynamic changes and non-linear propagation of dependency relationships, resulting in inaccurate identification of the dependency relationships between containers, and thus lower accuracy in vulnerability propagation analysis, which greatly affects network security. Summary of the Invention
[0005] In view of this, embodiments of the present invention provide a method and device for analyzing the propagation of vulnerabilities in container image dependencies based on a graph neural network to improve the accuracy of vulnerability propagation analysis.
[0006] According to one aspect of the present invention, there is provided a method for analyzing the propagation of vulnerabilities in container image dependencies based on a graph neural network, the method comprising:
[0007] Obtain each software package in the container image and the dependency relationships between each of the software packages, and input them into a pre-trained target graph neural network;
[0008] Enable the target graph neural network to construct a dependency graph based on each of the software packages and the dependency relationships between each of the software packages, wherein the dependency graph includes a plurality of nodes, each node corresponds to one of the software packages, and the edges between the nodes are determined based on the dependency relationships between the software packages corresponding to the nodes;
[0009] For each of the nodes in the dependency graph, iteratively update the node features of each of the nodes based on the target learning parameters, the neighbor nodes of the node, and the edge features between the node and the neighbor nodes, where the neighbor nodes are the nodes that have direct or indirect dependencies on the node; wherein, the initial node features of each node are determined based on the identifier, version number, and vulnerability information of the node; wherein, the edge features are determined based on the type of dependency relationship represented by the edge and the dependency strength;
[0010] When the preset iteration stop condition is reached, output the vulnerability propagation potential scores of each of the nodes based on the target learning parameters, the current node features of each of the nodes, and the edge features;
[0011] Determine a preset number of high-risk paths with the highest vulnerability propagation potential scores based on the vulnerability propagation potential scores of each of the nodes and the edge features, so as to repair each of the nodes included in the high-risk paths.
[0012] According to another aspect of the present invention, there is provided a container image dependency vulnerability propagation analysis device based on a graph neural network, the device comprising:
[0013] An acquisition module, configured to acquire each software package in the container image and the dependency relationships between the software packages, and input them into a pre-trained target graph neural network;
[0014] An output module, configured to enable the target graph neural network to construct a dependency graph based on each of the software packages and the dependency relationships between the software packages, wherein the dependency graph includes a plurality of nodes, each node corresponds to one of the software packages, and the edges between the nodes are determined based on the dependency relationships between the software packages corresponding to the nodes;
[0015] For each of the nodes in the dependency graph, iteratively update the node features of each of the nodes based on the target learning parameters, the neighbor nodes of the node, and the edge features between the node and the neighbor nodes, where the neighbor nodes are the nodes that have direct or indirect dependencies on the node; wherein, the initial node features of each node are determined based on the identifier, version number, and vulnerability information of the node; wherein, the edge features are determined based on the type of dependency relationship represented by the edge and the dependency strength;
[0016] When the preset iteration stop condition is reached, output the vulnerability propagation potential scores of each of the nodes based on the target learning parameters, the current node features of each of the nodes, and the edge features;
[0017] A determination module, configured to determine a preset number of high-risk paths with the highest vulnerability propagation potential scores based on the vulnerability propagation potential scores of each of the nodes and each of the edge features, so as to repair each of the nodes included in the high-risk paths.
[0018] According to another aspect of the present invention, there is provided an electronic device, including:
[0019] A processor; and
[0020] A memory storing a program,
[0021] wherein the program includes instructions that, when executed by the processor, cause the processor to execute the container image dependency vulnerability propagation analysis method of any one of the above-mentioned graph neural networks.
[0022] According to another aspect of the present invention, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to execute the container image dependency vulnerability propagation analysis method of any one of the above-mentioned graph neural networks.
[0023] One or more technical solutions provided in the embodiments of the present invention, by using a target neural network to construct a dependency graph based on the software packages in the container image and the dependencies between the software packages, and dynamically updating the node features of each node based on the target learning parameters, the node features of each node in the dependency graph, and the edge features, so that the node features include the features from neighboring nodes. Since the model training and application methods are the same, this enables the target learning parameters in the target neural network to learn the dependencies between nodes at multiple levels, can better adapt to the dynamic changes of the dependencies, and thus can output relatively accurate vulnerability propagation potential score results as the node features and edge features are updated. Further, based on the vulnerability propagation potential scores, high-risk paths are output and repaired, which can more accurately and timely respond to the network vulnerability propagation risk and improve software security. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In the following description of exemplary embodiments with reference to the accompanying drawings, more details, features, and advantages of the present invention are disclosed. In the drawings:
[0025] Figure 1 It is a schematic flowchart of a method for analyzing container image dependency vulnerability propagation based on a graph neural network provided by an embodiment of the present invention;
[0026] Figure 2 It is a schematic flowchart of training a graph neural network in the method for analyzing container image dependency vulnerability propagation based on a graph neural network provided by an embodiment of the present invention;
[0027] Figure 3Schematic diagram of a logical structure of a container image dependency vulnerability propagation analysis device provided by an embodiment of the present invention;
[0028] Figure 4 The block diagram of an exemplary electronic device capable of implementing the embodiments of the present invention is shown. Detailed implementation manners
[0029] Embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not used to limit the protection scope of the present invention.
[0030] It should be understood that the steps recited in the method embodiments of the present invention can be executed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this regard.
[0031] As used herein, the term "including" and its variants are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present invention are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence relationship of the functions performed by these devices, modules or units.
[0032] It should be noted that the modifications of "one" and "plural" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless clearly stated otherwise in the context, it should be understood as "one or more".
[0033] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0034] To improve the accuracy of vulnerability analysis, an embodiment of the present invention provides a method and device for analyzing container image dependency vulnerability propagation based on a graph neural network. The method for analyzing container image dependency vulnerability propagation provided by the embodiment of the present invention can be applied to any electronic device with the function of analyzing vulnerability propagation. The electronic device may include a server, a computer, a mobile terminal, etc. The solution of the present invention will be described below with reference to the accompanying drawings:
[0035] Figure 1 FIG. 4 is a schematic flowchart of a method for analyzing container image dependency vulnerability propagation provided by an embodiment of the present invention. The method may include the following steps:
[0036] S101. Obtain each software package in the container image and the dependency relationships between the software packages, and input them into a pre-trained target graph neural network;
[0037] S102. Enable the target graph neural network to construct a dependency graph based on each software package and the dependency relationships between the software packages. Among them, the dependency graph includes multiple nodes, each node corresponds to a software package, and the edges between the nodes are determined based on the dependency relationships between the software packages corresponding to the nodes;
[0038] For each node in the dependency graph, iteratively update the node features of each node based on the target learning parameters, the neighbor nodes of the node, and the edge features between the node and the neighbor nodes. Among them, the neighbor nodes are the nodes that have direct or indirect dependencies on the node; among them, the initial node features of each node are determined based on the identifier, version number, and vulnerability information of the node; among them, the edge features are determined based on the type of dependency relationship and the dependency strength represented by the edge;
[0039] When the preset iteration stop condition is reached, output the vulnerability propagation potential scores of each node based on the target learning parameters, the current node features of each node, and the edge features;
[0040] S103. Determine a preset number of high-risk paths with the highest vulnerability propagation potential scores based on the vulnerability propagation potential scores of each node and the edge features, so as to repair each node included in the high-risk paths.
[0041] Applying the embodiments of the present invention, by using a target neural network to construct a dependency graph based on the software packages in the container image and the dependencies between the software packages, and dynamically updating the node features of each node based on the target learning parameters, the node features of each node, and the edge features in the dependency graph, so that the node features include the features from neighboring nodes. Since the model training and application methods are the same, this enables the target learning parameters in the target neural network to learn the dependencies between nodes at multiple levels, better adapt to the dynamic changes of dependencies, and then can output relatively accurate vulnerability propagation potential score results as the node features and edge features are updated. Further, based on the vulnerability propagation potential score, high-risk paths are output and repaired, which can more accurately and timely respond to the network vulnerability propagation risk and improve software security.
[0042] The following is an exemplary description of the above S101 - S103:
[0043] In a possible embodiment, each software package can register its software information in the system before going online. The software information may include the identifier of the software package, the version identifier, and the software package dependencies, etc. The identifier of the software package may be the name of the software package, and the version identifier may be the version number. The above software package dependencies may include the identifiers of other software packages that the software package needs to depend on. Here, the dependency may be that the software package needs to use the data generated by other software packages, or needs to use the functions provided by other software packages, etc. Exemplarily, when the software package is generated, it will determine the other software packages it depends on. Therefore, the identifiers of the other software packages that the software package depends on can be used as descriptive information and registered together with the software package.
[0044] The software information of the above software package may further include the vulnerability information of the software package. The vulnerability information may include the CVE (Common Vulnerabilities & Exposures) number of the software package and the vulnerability score, etc. Among them, the CVE number is an identifier for publicly disclosing known defects and security vulnerabilities in computer systems, and can be determined based on the code contained in the software package or the running network environment, etc. The above vulnerability score can be determined based on the exploitability, impact scope, and impact degree of the vulnerability, etc. Exemplarily, the vulnerability score of the software package can be determined by the following formula :
[0045]
[0046] Among them, v represents the current software package or component, The CVSS (Common Vulnerability Scoring System) score for a software package vulnerability, usually between 0 and 10, represents the severity of the vulnerability. The CVSS score is typically calculated by the CVSS scoring system, and the CVSS scoring is divided into three main parts: Base Score: Reflects the basic characteristics of the vulnerability, including factors such as the attack complexity and the scope of impact of the vulnerability, with a score range from 0 to 10. Temporal Score: Reflects the changing impact of the vulnerability over time, usually related to the exploitation situation of the vulnerability. Environmental Score: Considers the impact of a specific environment, such as the harm level of the vulnerability under different application scenarios or configurations.
[0047] Exploitability represents the exploitability of the vulnerability, generally measured by the known vulnerability exploitation situation, and can take a floating value from 0 to 1. The closer it is to 1, the easier it is for the vulnerability to be exploited. ImpactFactor represents the potential impact of the vulnerability on the system, such as data leakage, system crash, etc., and is usually a weight coefficient given according to the nature of the vulnerability. α, β, and γ are all weight coefficients used to adjust the impact of different factors on the final vulnerability score, and can be determined through experiments or domain experience.
[0048] Exemplarily, the CVSS score of a certain software package is 8.5, the exploitability of this vulnerability is 0.9 (indicating that the vulnerability is easy to be exploited), and the impact factor of the vulnerability is 0.8 (indicating that the potential impact of this vulnerability is large). And the weight coefficients are set as: α = 0.7, β = 0.2, γ = 0.1. Then the vulnerability score of this node is calculated according to the following formula:
[0049] VulnerabilityScore(v)=0.7×8.5 + 0.2×0.9 + 0.1×0.8 = 5.95 + 0.18 + 0.08 = 6.21
[0050] As a possible implementation manner, in S101, the software information of each software package can be obtained from the software package registration database, and the identifier, version number, dependency relationship, vulnerability information, etc. of the software package can be extracted from it. The above dependency relationship can include direct dependencies and indirect dependencies. Among them, direct dependency means that a software package directly uses the data of other software packages or calls the functions of other software packages, and indirect dependency means that the data of other software packages on which a software package depends depends on the data or functions generated by another software package. Exemplarily, for nodes A, B, and C, A uses the data b produced by B, and in the process of B producing the data b, it needs to use the data c produced by C. Then there is a direct dependency between A and B, and an indirect dependency between A and C.
[0051] In S102, a dependency graph can be constructed based on the above information of each software package. The dependency graph includes multiple nodes, each node corresponding to one software package, and the edges between the nodes are determined based on the dependencies between the software packages corresponding to the nodes. Specifically, the edges between the nodes can be directed edges, and the directed edges can point from the dependent node to the dependent node.
[0052] Both the nodes and the edges in the above dependency graph have corresponding node features and edge features. Among them, the node features can include the identification, version number, dependency relationship, and vulnerability information determination of the corresponding software package. Exemplarily, the feature vector contains the following content:
[0053] x i =[Package Name,Version,CVE IDs,Vulnerability Score]
[0054] where packagename is the software package name, version is the version number, CVE ID is the CVE number of the node, and Vulnerability Score is the vulnerability score of the node. As a possible implementation, the above information can be encoded according to a preset correspondence relationship, so as to convert data in different dimensions into data in the same dimension and form the node features of the node. The above preset correspondence relationship can include the correspondence relationship between the software package name and the encoding, the correspondence relationship between the version number and the encoding, the correspondence relationship between the CVE ID and the encoding, and the correspondence relationship of the vulnerability score.
[0055] The edge features of the above edges can be determined by the dependency relationship type and the risk level. Among them, the dependency relationship type includes direct dependency and indirect dependency. The above risk level can be determined based on the vulnerability information, node weights, etc. of the two nodes connected by the edge. The above node weights are preset according to the importance of the nodes in the application. Exemplarily, the above risk level can be determined by the following formula:
[0056]
[0057] where, Represents the risk level between node vi and node vj. Direct / Indirect is the type of dependency relationship, and the corresponding values of this dependency relationship type can be set in advance. For example, direct dependency can be set to 1 and indirect dependency can be set to 0.5. CVSSScore is the CVSS score of the node, and ChainLength is the depth of the dependency chain, which can be represented as the number of nodes passed in the dependency path and may affect the breadth of propagation. NodeImportance is the node weight, usually a constant. For example, the node weight of a general node can be set to 1, and the node weight of a core node can be set to 2. The above , , and are all preset weights. Each preset weight can be set according to the actual application scenario. Exemplarily, the above preset weights can be adjusted for different scenarios according to the following table to more accurately evaluate the vulnerability propagation risk in the system.
[0058] Table 1 Schematic Diagram of Preset Weights
[0059]
[0060] The above edge features can be represented by the following formula:
[0061]
[0062] where represents that the type of dependency relationship is direct dependency / indirect dependency, and Risk Level is the risk level of the edge.
[0063] As a possible implementation, after obtaining the node features and edge features of each node, they can be input into a pre-trained target graph neural network. The target graph neural network can construct a dependency relationship graph, and for each node in the dependency relationship graph, the node features of each node are iteratively updated based on the neighbor nodes of the node. As a possible implementation, for each node, the node features of its neighbor nodes and the edge features between the node and the neighbor nodes can be continuously fused to achieve iterative update of the node features of the node.
[0064] When the preset iteration stop condition is reached, the vulnerability propagation potential scores of each node are output based on the node features of each node and the edge features of the edges between each node. The preset iteration stop condition can be that the number of iterations reaches a preset number.
[0065] The above graph neural network can be GCN, GAT, GraphSAGE, etc. The target graph neural network can include an input layer, a propagation layer, and an output layer. Among them, the input layer is used to receive the input of software package information, the propagation layer is used to iteratively update the node features, and the output layer is used to output the final result. Exemplarily, as Figure 2 shown, the target graph neural network can be pre-trained through the following steps:
[0066] S201. Input the training data set into the initial graph neural network. The training data set includes the training node features of the training nodes and the training edge features between the training nodes. Each training node corresponds to an actual vulnerability propagation potential score label.
[0067] The above training data set can be determined according to historical software package information. The specific execution method of this step can refer to the description in parts S101 - S102 and will not be elaborated here.
[0068] S202. For each training node in the initial graph neural network, update the training node features of the training node based on the training node features of the training node, the training node features of the neighbor nodes of the training node, the training edge features of the edges connecting the training node, and a preset weight matrix and a preset bias term. Among them, the preset weight matrix and the preset bias term are trainable parameters.
[0069] This step can be executed by the propagation layer. There can be multiple propagation layers, and the number of propagation layers determines the above preset number of iterations. The number of propagation layers is mainly determined by the depth of the dependency chain between nodes in the dependency graph. If the dependency chain is long, more layers are needed to fully capture the features and propagated information of each node. At the same time, adjustments also need to be made considering the limitations of computing resources and performance requirements to balance accuracy and computational complexity. In practical applications, the number of propagation layers is usually adjusted through experiments to ensure that the network is efficient when converging. Exemplarily, the number of propagation layers can be set for different scenarios according to the following table:
[0070] Table 2 Schematic Table of the Setting of the Number of Propagation Layers
[0071]
[0072] The core mechanism of the propagation layer is message passing. In each layer, the features of a node are iteratively aggregated with the features of its neighbor nodes to update the features of the node. The above neighbor nodes refer to the nodes that have edges with the node. Through the above technical means, the node not only contains its own information but also the information of its neighbor nodes. For example, for a dependency chain: A → B → C, the features of C will gradually include the dependency information propagated from A and B. This mechanism helps to identify the dependency propagation paths across multiple layers and can help the model identify the vulnerability propagation paths in different dependency chains.
[0073] As a possible implementation, for each node in the graph , its updated node features can be calculated by the following formula:
[0074]
[0075] where represents the feature vector of node at the t-th layer, represents the set of neighbor nodes of node , is the edge feature of the edge between node and node . This edge feature can represent the strength of the dependency relationship. W is a learnable weight matrix, and the parameters in this weight matrix can be continuously adjusted during the subsequent training process. σ(·) is an activation function, such as ReLU. b is a bias term, representing the offset in calculating the node features, and this term is also a trainable parameter.
[0076] S203. Output the predicted vulnerability propagation potential scores of each node based on the current node features of each training node and the training edge features of each edge.
[0077] After updating the node features in each propagation layer, the output layer can output the predicted vulnerability propagation potential score (VPS, Vulnerability Propagation Score) based on the updated node features and edge features. This predicted vulnerability propagation potential score is used to represent the probability that this node may trigger communication propagation. Exemplarily, this vulnerability propagation potential score can be calculated by the following formula:
[0078]
[0079] where is the feature vector of node in the last layer during the propagation process of the graph neural network. v' is a learnable parameter vector, obtained through training, representing the weight of the vulnerability propagation potential.
[0080] S204. Adjust the parameters of the graph neural network based on the target difference between the predicted vulnerability propagation potential scores of each training node and the actual vulnerability propagation potential scores of the training nodes until the target difference converges, and obtain the target graph neural network.
[0081] The actual vulnerability propagation probabilities of each node can be determined in advance according to the corresponding code of each node and the running network environment, etc. The above target difference can be obtained through a preset loss function, which can be a cross-entropy loss function, a variance loss function, etc. Specifically, the target difference between the predicted vulnerability propagation potential score and the actual vulnerability propagation probability of the node can be calculated through this loss function, and the parameters of the graph neural network can be adjusted based on this target difference. The parameters can include the above weight matrix W, vector v', and bias term b, etc.
[0082] As a possible implementation, the above parameters can be updated through the backpropagation algorithm, and the above bias term b can also be automatically adjusted according to the gradient descent method to minimize the loss function, thereby improving the prediction accuracy of the graph neural network.
[0083] The convergence of the above target difference can mean that the difference between the target differences obtained twice is less than a preset difference threshold or the target difference is less than a preset difference threshold.
[0084] Traditional graph algorithms (such as the shortest path) assume that information propagation is linear and the propagation path is predefined. However, through deep learning technology, the graph neural network enables the update of node features in each layer to not only depend on direct neighbor nodes, but also processes node features through recursion and non-linear activation functions (such as ReLU). This way can simulate more complex propagation behaviors and can better handle situations of multi-level dependencies and complex path propagation.
[0085] In a possible embodiment, to improve the training efficiency of the graph neural network, the above dependency graph can be converted into a queue data. The time complexity of graph structure data usually increases quadratically with the increase of nodes, while the time complexity of processing queue structure is usually a constant. It can be seen that the time complexity of queue structure data is significantly lower than that of graph structure data.
[0086] In a possible embodiment, the above dependency graph can be converted through the following steps:
[0087] S301. Scan the dependency graph to obtain the leaf nodes that are not dependent on other nodes and access them to a preset processing queue.
[0088] In a possible embodiment, the in-degree of each node in the dependency graph can be calculated. Specifically, for each node , its in-degree indegree(v can be calculated according to the following formula i ):
[0089]
[0090] where A is the adjacency matrix, indicating the dependency relationship from node to node . It can be seen that if a node is not dependent on other nodes, the in-degree of this node is 0.
[0091] In this step, nodes with an in-degree of 0 can be defined as leaf nodes, and these leaf nodes can be added to a preset processing queue, the length of which is greater than the number of nodes included in the dependency graph. After adding a node to the preset processing queue, the node can be marked as processed.
[0092] S302. Decrease the in-degree of the adjacent nodes of the leaf node, and determine whether there is a node with an in-degree of 0; where, the node with an in-degree of 0 refers to a node that is not dependent on other nodes;
[0093] The adjacent nodes of the leaf node refer to, in a directed graph, nodes that have a direct edge connection with the node with an in-degree of 0 and the direction of the connection is from the node with an in-degree of 0 to the node it points to. Exemplarily, the in-degree of the adjacent nodes of the leaf node can be reduced by 1, and it is determined whether there is a node with an in-degree of 0.
[0094] S303. If there is, store the node with an in-degree of 0 into the preset processing queue, and return to the step of decreasing the in-degree of the adjacent nodes of the leaf node and determining whether there is a node with an in-degree of 0;
[0095] S304. If not, return to the step of decreasing the in-degree of the adjacent nodes of the leaf node and determining whether there is a node with an in-degree of 0 until all nodes in the dependency graph are stored in the preset processing queue;
[0096] Correspondingly, each node can be output to the graph neural network in the order in which the nodes are added to the preset processing queue, so that the graph neural network iteratively updates the node features of each node in the dependency graph based on the neighbor nodes of the node in the order in which the nodes are added to the preset processing queue.
[0097] Through the above technical solution, a topological sort is performed on the dependency graph, and the nodes are arranged in descending order of in-degree, that is, the nodes in the graph are arranged in the order of the dependency relationship. This process ensures that each node will only update its own features after all the features of its dependent nodes have been updated, avoiding computational bottlenecks in the training process due to dependency loops or complex multi-layer dependencies.
[0098] Furthermore, the above input order ensures that the node feature updates in each layer of the graph neural network can proceed smoothly during the training process, avoiding computational conflicts or inefficiencies caused by deep dependencies. In the subsequent training process of the graph neural network, through the queue structure, the node features will be propagated in topological order, ensuring the correctness of the computational order and dependency relationship in each layer, thereby reducing the time complexity of training.
[0099] In a possible embodiment, after obtaining the vulnerability propagation potential scores of each node, the vulnerability propagation potential scores of each propagation path can be calculated based on the vulnerability propagation potential scores of the nodes, and a preset number of candidate paths with the highest scores can be selected. A high vulnerability propagation potential score means a higher probability of vulnerability propagation and a higher risk. Therefore, these paths can be further analyzed.
[0100] As a possible implementation, the vulnerability propagation potential scores of each path can be calculated by the following formula: Let the path be a path from node to node , then the propagation risk score R(p) of this path can be calculated by the following formula:
[0101]
[0102] where is the vulnerability propagation potential score of node , and is the edge feature between each pair of adjacent nodes on the path, representing the strength of the dependency relationship.
[0103] Correspondingly, according to the risk score R(p), paths with a higher propagation risk can be selected:
[0104]
[0105] That is, the path with the highest propagation risk score can be selected as the potential vulnerability propagation path for repair or optimization.
[0106] In a possible embodiment, for each of the candidate paths, based on each risk node included in the candidate path and the vulnerability propagation potential scores of each neighbor node of each risk node, and the edge characteristics of the edges between each risk node and each neighbor node of each risk node, the influence range score of each risk node can be calculated.
[0107] The potential impact range (Impact Range) is the potential of each node to spread vulnerabilities to other nodes. Specifically, for each node in the candidate path, first, the depth (number of levels of dependence) and breadth (number of connections with other nodes) of the node's dependence chain need to be analyzed. For example, a certain node A may depend on multiple nodes B, C, and D. If A's vulnerability is attacked, B, C, and D may also be affected. The dependence depth and breadth of each node will affect its potential impact on other nodes. Second, the weight of the edge (strength of the dependence relationship) needs to be analyzed: The weight of each edge represents the strength or importance of the dependence relationship between nodes. For example, there may be a strong dependence (high weight) between certain nodes, which means that if a vulnerability exists in one of the nodes, the spread of the impact may be more extensive. When calculating the potential impact range, the weight of each dependence edge must be considered, which will determine the speed of information spread and the breadth of the impact. VPS (Vulnerability Propagation Potential Score): The VPS score of each node represents its vulnerability propagation potential in the entire dependence chain. If a certain node has a high VPS score, its impact on the entire path will also be greater. Therefore, when calculating the potential impact range, the VPS score plays a weighting role. A node with a high VPS score means that the impact of its vulnerability spread is large, and these nodes may need to be treated as high-priority repair objects.
[0108] Exemplarily, the potential impact range score of a node can be calculated in the following way:
[0109]
[0110] where, is the current node, representing a certain software package or component, represents the set of nodes directly adjacent to node i.e., all other nodes that node depends on, represents the vulnerability propagation potential score of node indicating the potential risk of this node spreading vulnerabilities, is the dependence relationship weight between node and node i.e., the edge characteristic, representing the strength of the dependence relationship. This value can be calculated based on the tightness of the dependence chain, version relationship, or other factors.
[0111] For each node , the potential impact range is all the nodes it depends on is the weighted sum of the VPS scores and the dependency strengths. Nodes with higher VPS scores have a greater impact on vulnerability propagation, so they are given higher weights when calculating the impact range. Weight represents the dependency strength between nodes. If the dependency is strong, this value is large, meaning that a vulnerability in this node is more likely to affect other nodes directly related to it.
[0112] For example, node depends on two nodes and , the weights of its dependencies are 0.8 and 0.5 respectively, and and 's VPSs are 0.7 and 0.9 respectively. Then the potential impact range of node can be calculated as follows:
[0113] ImpactRange(v1)=(0.7×0.8)+(0.9×0.5)=0.56+0.45=1.01
[0114] After that, the impact range scores of each risk node included in each of the candidate paths can be fused to obtain the impact range scores of each of the candidate paths; and based on the impact range scores of each of the candidate paths, a priority order can be set for each of the candidate paths to repair each of the nodes included in each of the high-risk paths according to the priority order.
[0115] According to the potential impact range of the nodes in each path, the paths can be sorted, and the path with the greatest impact can be selected as the key focus. The larger the impact range of a path, the stronger the potential impact of the vulnerabilities in this path on other nodes in the dependency chain, and these paths should be repaired first.
[0116] The calculation of the potential impact range can help the security team conduct risk management when resources are limited. By identifying the vulnerability propagation paths with high impact ranges, the security team can allocate resources more efficiently, concentrate on repairing critical vulnerabilities, and thus maximize the security protection effect.
[0117] Applying the embodiment of the present invention, the dependency relationship modeling based on the graph neural network can capture more complex dependency patterns and potential vulnerability propagation paths. Compared with traditional vulnerability detection methods, this technology mines the hidden patterns in the dependency graph through deep learning, making the prediction of vulnerability propagation paths more accurate. For security analysts, this method can effectively identify potential risks, not just relying on known vulnerability information, and reduce the risk of missed detection.
[0118] Furthermore, in a containerized environment, the security of container images is of utmost importance. By comprehensively analyzing all software packages and dependencies in the image, the system can identify and address potential security risks in advance. Timely patching of vulnerabilities can significantly reduce the security risks in container images, minimize subsequent security incidents, and protect the data and system security of enterprises.
[0119] Moreover, due to the visualization of the dependency graph and its efficient analysis capabilities, developers can quickly locate high-risk vulnerability propagation paths and prioritize patching the vulnerabilities in these paths. This approach can effectively save developers' time and effort, avoid the problem of spending a large amount of time manually analyzing complex dependencies in traditional static analysis methods, and improve the efficiency of vulnerability patching.
[0120] In practical applications, software components in the supply chain are constantly updated and changed, and vulnerabilities may be introduced during the update process. By automatically analyzing the vulnerability propagation paths of each component in the supply chain, enterprises can better assess security risks in supply chain management, issue early warnings, and reduce the likelihood of supply chain disruptions or attacks. Especially in a multi-cloud environment, the complexity of dependencies is higher, and this method can ensure that cross-platform and cross-system dependencies are analyzed in a timely and comprehensive manner.
[0121] It can be seen that the method provided by the embodiments of the present invention improves the automation level of vulnerability detection and patching through graph neural networks and automated dependency analysis. Without manual intervention or excessive manual analysis, most of the work can be automatically completed, thereby reducing the possibility of human errors and making security management more efficient. Through efficient vulnerability propagation path analysis, enterprises can accurately identify which dependency paths pose threats to security and prioritize allocating resources to patch the most critical vulnerabilities. This not only helps reduce resource waste but also maximizes the impact of the patching work, ensuring the best security protection effect for enterprises with limited resources.
[0122] Based on the same inventive concept, the embodiments of the present invention also provide a container image dependency vulnerability propagation analysis device based on graph neural networks, as Figure 3 shown. The device 300 may include:
[0123] An acquisition module 301, configured to acquire each software package in the container image and the dependencies between the software packages, and input them into a pre-trained target graph neural network;
[0124] An output module 302, configured to enable the target graph neural network to construct a dependency graph based on each software package and the dependencies between the software packages, where the dependency graph includes multiple nodes, each node corresponds to a software package, and the edges between the nodes are determined based on the dependencies between the software packages corresponding to the nodes;
[0125] For each of the nodes in the dependency graph, iteratively update the node features of each of the nodes based on the target learning parameters, the neighbor nodes of the node, and the edge features between the node and the neighbor nodes, where the neighbor nodes are the nodes that have direct or indirect dependencies on the node; wherein, the initial node features of each node are determined based on the identifier, version number, and vulnerability information of the node; wherein, the edge features are determined based on the type of dependency relationship represented by the edge and the dependency strength;
[0126] When the preset iteration stop condition is reached, output the vulnerability propagation potential scores of each of the nodes based on the target learning parameters, the current node features of each of the nodes, and the edge features of each of the nodes;
[0127] A determination module 303, configured to determine a preset number of high-risk paths with the highest vulnerability propagation potential scores based on the vulnerability propagation potential scores of each of the nodes and the edge features of each of the nodes, so as to repair each of the nodes included in the high-risk paths.
[0128] In a possible embodiment, the target graph neural network is obtained in advance through the following steps:
[0129] Input the training data set into the initial graph neural network, where the training data set includes the training node features of the training nodes and the training edge features between the training nodes, and each training node corresponds to an actual vulnerability propagation potential score label;
[0130] For each of the training nodes in the initial graph neural network, update the training node features of the training nodes based on the training node features of the training nodes, the training node features of the neighbor nodes of the training nodes, the training edge features of the edges connecting the training nodes, and a preset weight matrix and a preset bias term, where the preset weight matrix and the preset bias term are trainable parameters;
[0131] Output the predicted vulnerability propagation potential scores of each of the nodes based on the current node features of each of the training nodes and the training edge features of each of the edges;
[0132] Adjust the parameters of the graph neural network based on the target difference between the predicted vulnerability propagation potential scores of each of the training nodes and the actual vulnerability propagation potential scores of the training nodes until the target difference converges, to obtain the target graph neural network.
[0133] In a possible embodiment, the device further includes: a storage module,
[0134] The storage module is used for
[0135] Scan the dependency graph to obtain leaf nodes that are not dependent on other nodes and add them to a preset processing queue;
[0136] Reduce the in-degree of the adjacent nodes of the leaf nodes and determine whether there are nodes with an in-degree of 0; wherein, the nodes with an in-degree of 0 refer to nodes that are not dependent on other nodes;
[0137] If there are, store the nodes with an in-degree of 0 in the preset processing queue and return to the step of reducing the in-degree of the adjacent nodes of the leaf nodes and determining whether there are nodes with an in-degree of 0;
[0138] If not, return to the step of reducing the in-degree of the adjacent nodes of the leaf nodes and determining whether there are nodes with an in-degree of 0 until all nodes in the dependency graph are stored in the preset processing queue;
[0139] The iterative update of the node features of each node in the dependency graph based on the target learning parameter, the neighbor nodes of the node, and the edge features between the node and its neighbor nodes includes:
[0140] According to the order in which each node is added to the preset processing queue, for each node in the dependency graph, iteratively update the node features of each node based on the target learning parameter, the neighbor nodes of the node, and the edge features between the node and its neighbor nodes.
[0141] In a possible embodiment, the device further includes:
[0142] An influence range determination module, configured to calculate the influence range score of each risk node for each high-risk path based on the vulnerability propagation potential scores of each risk node included in the high-risk path and the neighbor nodes of each risk node, and the edge features of the edges between each risk node and the neighbor nodes of each risk node;
[0143] Fuse the influence range scores of each risk node included in each high-risk path to obtain the influence range score of each high-risk path;
[0144] Set a priority order for each high-risk path based on the influence range scores of each high-risk path, so as to repair each node included in each high-risk path according to the priority order.
[0145] Wherein, the collection, storage, use, processing, transmission, provision, and disclosure of user personal information involved in the present invention all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0146] An exemplary embodiment of the present invention further provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, it is used to cause the electronic device to execute the method according to the embodiment of the present invention.
[0147] An exemplary embodiment of the present invention further provides a non-transitory computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor of a computer, it is used to cause the computer to execute the method according to the embodiment of the present invention.
[0148] An exemplary embodiment of the present invention further provides a computer program product, including a computer program, wherein when the computer program is executed by a processor of a computer, it is used to cause the computer to execute the method according to the embodiment of the present invention.
[0149] Referring to Figure 4 , a block diagram of an electronic device 400 that can be used as a server or a client of the present invention will now be described. It is an example of a hardware device that can be applied to various aspects of the present invention. The electronic device is intended to represent various forms of digital electronic computer devices, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0150] As Figure 4 shown, the electronic device 400 includes a computing unit 401, which can execute various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 402 or a computer program loaded from a storage unit 408 into a random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the electronic device 400 can also be stored. The computing unit 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.
[0151] Multiple components in the electronic device 400 are connected to the I / O interface 405, including: an input unit 406, an output unit 407, a storage unit 408, and a communication unit 409. The input unit 406 can be any type of device capable of inputting information into the electronic device 400. The input unit 406 can receive input digital or character information and generate key signal inputs related to the user settings and / or function controls of the electronic device. The output unit 407 can be any type of device capable of presenting information and can include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 408 can include, but is not limited to, magnetic disks and optical discs. The communication unit 409 allows the electronic device 400 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks and can include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a Bluetooth™ device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.
[0152] The computing unit 401 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 401 executes the various methods and processes described above. For example, in some embodiments, any of the above-described methods for analyzing the propagation of container image dependency vulnerabilities based on a graph neural network can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 408. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 400 via the ROM 402 and / or the communication unit 409. In some embodiments, the computing unit 401 can be configured to execute any of the above-described methods for analyzing the propagation of container image dependency vulnerabilities based on a graph neural network in any other suitable manner (e.g., by means of firmware).
[0153] The program code for implementing the method of the present invention can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, executed partially on the machine and partially on a remote machine as an independent software package, or executed entirely on a remote machine or server.
[0154] In the context of the present invention, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0155] As used in the present invention, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., a disk, an optical disk, a memory, a programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.
[0156] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0157] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.
[0158] A computer system can include clients and servers. The clients and servers are generally remote from each other and typically interact through a communication network. The client-server relationship is generated by computer programs running on the respective computers and having a client-server relationship with each other.
Claims
1. A container image dependency vulnerability propagation analysis method based on graph neural network, characterized in that: The method comprises: Obtain the software packages in the container image and the dependencies between the software packages, and input them into the pre-trained target graph neural network; So that the target graph neural network constructs a dependency graph based on the software packages and the dependency relationships between the software packages, wherein the dependency graph includes a plurality of nodes, each of the nodes corresponds to a software package, and the edges between the nodes are determined based on the dependency relationships between the software packages corresponding to the nodes; For each of the nodes in the dependency graph, iteratively update the node features of each of the nodes based on the target learning parameters and the neighbor nodes of the node and the edge features between the node and the neighbor nodes, wherein the neighbor nodes are nodes that are directly or indirectly dependent on the node; wherein the initial node features of each of the nodes are determined based on the identification, version number and vulnerability information of the node; wherein the edge features are determined based on the dependency type and dependency strength represented by the edge; When a preset iteration stop condition is reached, outputting a vulnerability propagation potential score of each node based on the target learning parameter, current features of each node, and features of each edge; Determine a preset number of high-risk paths with the highest vulnerability propagation potential scores based on the vulnerability propagation potential scores of each of the nodes and each of the edge features, so as to repair each of the nodes included in the high-risk paths; The target graph neural network is obtained in advance through the following steps: Inputting a training data set into an initial graph neural network, the training data set including training node features of training nodes and training edge features between the training nodes, each training node corresponding to an actual vulnerability propagation potential score label; For each of the training nodes in the initial graph neural network, the training node features of the training nodes are updated based on the training node features of the training nodes, the training node features of the neighboring nodes of the training nodes, the training edge features of the edges connecting the training nodes, and a preset weight matrix and a preset bias item, wherein the preset weight matrix and the preset bias item are trainable parameters; Outputting a predicted vulnerability propagation potential score of each of the nodes based on the current node features of each of the training nodes and the training edge features of each of the edges; Based on the target difference between the predicted vulnerability propagation potential score of each training node and the actual vulnerability propagation potential score of the training node, the parameters of the graph neural network are adjusted until the target difference converges to obtain a target graph neural network.
2. The method according to claim 1, characterized in that The method further comprises: Scan the dependency graph to obtain leaf nodes that are not depended on by other nodes and connect them to a preset processing queue; Lowering the in-degree of the adjacent nodes of the leaf node to determine whether there is a node with an in-degree of 0; wherein the node with an in-degree of 0 refers to a node that is not dependent on other nodes; If so, the node with in-degree 0 is stored in the preset processing queue, and the step of reducing the in-degree of the adjacent node of the leaf node to determine whether there is a node with in-degree 0 is returned; If not, returning to the step of reducing the in-degree of the adjacent nodes of the leaf node to determine whether there is a node with an in-degree of 0, until all nodes in the dependency graph are stored in the preset processing queue; For each of the nodes in the dependency graph, iteratively updating the node features of each of the nodes based on the target learning parameters and the neighbor nodes of the node and the edge features between the node and the neighbor nodes, includes: In the order in which each of the nodes is added to the preset processing queue, for each of the nodes in the dependency graph, the node features of each of the nodes are iteratively updated based on the target learning parameters and the neighboring nodes of the node and the edge features between the node and the neighboring nodes.
3. The method according to claim 1, characterized in that The method further comprises: For each of the high-risk paths, based on the vulnerability propagation potential scores of each risk node and the neighboring nodes of each risk node included in the high-risk path, and the edge features of the edges between each risk node and the neighboring nodes of each risk node, the influence range score of each risk node is calculated; The influence range scores of the risk nodes included in the high-risk paths are merged to obtain the influence range scores of the high-risk paths; A priority order is set for each of the high-risk paths based on the impact range score of each of the high-risk paths, so that each of the nodes included in each of the high-risk paths is repaired according to the priority order.
4. A container image dependency vulnerability propagation analysis device based on graph neural network, characterized in that: The device comprises: An acquisition module is used to acquire the software packages in the container image and the dependencies between the software packages, and input them into a pre-trained target graph neural network; An output module, used for the target graph neural network to construct a dependency graph based on the software packages and the dependency relationships between the software packages, wherein the dependency graph includes a plurality of nodes, each of the nodes corresponds to a software package, and the edges between the nodes are determined based on the dependency relationships between the software packages corresponding to the nodes; For each of the nodes in the dependency graph, iteratively update the node features of each of the nodes based on the target learning parameters and the neighbor nodes of the node and the edge features between the node and the neighbor nodes, wherein the neighbor nodes are nodes that are directly or indirectly dependent on the node; wherein the initial node features of each of the nodes are determined based on the identification, version number and vulnerability information of the node; wherein the edge features are determined based on the dependency type and dependency strength represented by the edge; When a preset iteration stop condition is reached, outputting a vulnerability propagation potential score of each node based on the target learning parameter, current features of each node, and features of each edge; A determination module, configured to determine a preset number of high-risk paths with the highest vulnerability propagation potential scores based on the vulnerability propagation potential scores of the nodes and the edge features, so as to repair the nodes included in the high-risk paths; The target graph neural network is obtained in advance through the following steps: Inputting a training data set into an initial graph neural network, the training data set including training node features of training nodes and training edge features between the training nodes, each training node corresponding to an actual vulnerability propagation potential score label; For each of the training nodes in the initial graph neural network, the training node features of the training nodes are updated based on the training node features of the training nodes, the training node features of the neighboring nodes of the training nodes, the training edge features of the edges connecting the training nodes, and a preset weight matrix and a preset bias item, wherein the preset weight matrix and the preset bias item are trainable parameters; Outputting a predicted vulnerability propagation potential score of each of the nodes based on the current node features of each of the training nodes and the training edge features of each of the edges; Based on the target difference between the predicted vulnerability propagation potential score of each training node and the actual vulnerability propagation potential score of the training node, the parameters of the graph neural network are adjusted until the target difference converges to obtain a target graph neural network.
5. The device according to claim 4, characterized in that The device further comprises: a storage module, The storage module is used Scan the dependency graph to obtain leaf nodes that are not depended on by other nodes and connect them to a preset processing queue; Lowering the in-degree of the adjacent nodes of the leaf node to determine whether there is a node with an in-degree of 0; wherein the node with an in-degree of 0 refers to a node that is not dependent on other nodes; If so, the node with in-degree 0 is stored in the preset processing queue, and the step of reducing the in-degree of the adjacent node of the leaf node to determine whether there is a node with in-degree 0 is returned; If not, returning to the step of reducing the in-degree of the adjacent nodes of the leaf node to determine whether there is a node with an in-degree of 0, until all nodes in the dependency graph are stored in the preset processing queue; For each of the nodes in the dependency graph, iteratively updating the node features of each of the nodes based on the target learning parameters and the neighbor nodes of the node and the edge features between the node and the neighbor nodes, includes: In the order in which each of the nodes is added to the preset processing queue, for each of the nodes in the dependency graph, the node features of each of the nodes are iteratively updated based on the target learning parameters and the neighboring nodes of the node and the edge features between the node and the neighboring nodes.
6. The device according to claim 4, characterized in that The device also includes: Impact Scope Determination Module for For each of the high-risk paths, based on the vulnerability propagation potential scores of each risk node and the neighboring nodes of each risk node included in the high-risk path, and the edge features of the edges between each risk node and the neighboring nodes of each risk node, the influence range score of each risk node is calculated; The influence range scores of the risk nodes included in the high-risk paths are merged to obtain the influence range scores of the high-risk paths; A priority order is set for each of the high-risk paths based on the impact range score of each of the high-risk paths, so that each of the nodes included in each of the high-risk paths is repaired according to the priority order.
7. An electronic device, comprising: processor; as well as Memory for storing programs, The program includes instructions, which, when executed by the processor, cause the processor to perform the method according to any one of claims 1 to 3.
8. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to make a computer execute the method according to any one of claims 1-3.
Citation Information
Patent Citations
Open source component security vulnerability processing method and system
CN119167370A
Integrated security analysis data structure and method for multi-container software projects
US20240411895A1