An integrated detection method and device for software supply chain security

The method addresses inefficiencies in software supply chain security detection by performing multi-layer analysis and combining results across different layers, ensuring accurate and efficient security evaluation.

CN119903528BActive Publication Date: 2025-07-15NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411994786.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-07-15
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

The security inspection process of the existing software supply chain is complex, time-consuming and laborious, with a high false alarm rate, lacks overall evaluation of the entire supply chain, and lacks detection efficiency, accuracy and comprehensiveness.

Method used

Using a comprehensive detection method for the software supply chain, a comprehensive detection process model of the implantation operation and code comprehensive discrimination is constructed at different levels, and the source code layer, software layer, database layer, configuration file layer and compiler layer are calculated to obtain the comprehensive detection result value.

Benefits of technology

It realizes a rapid and accurate assessment of the security of the software supply chain, improves the efficiency, accuracy and comprehensiveness of the inspection, and ensures the accuracy and comprehensiveness of the inspection results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119903528B_ABST
    Figure CN119903528B_ABST
Patent Text Reader

Abstract

The present invention discloses a comprehensive detection method and device for software supply chain security. The method includes: obtaining a set of software to be implanted and a software supply chain; performing a layer-by-layer analysis and implantation operation on the software supply chain to obtain an implanted software supply chain; performing code comprehensive discrimination processing on the implanted software supply chain and the software supply chain to obtain a comprehensive detection result value of software supply chain security. The present invention improves the efficiency, accuracy, and comprehensiveness of software supply chain security detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of software security and industrial Internet of Things, and particularly to a comprehensive detection method and device for software supply chain security. Background Art

[0002] With the continuous expansion of the complexity and scale of the software supply chain and the rapid development of Internet technology, software supply chain security has become an essential infrastructure in the industrial Internet of Things. Software supply chain security issues are becoming increasingly prominent. How to ensure software supply chain security has become a hot issue in current research. Therefore, the detection and evaluation of software supply chain security are problems that need to be solved urgently.

[0003] Regarding the solutions for industrial software supply chain security detection, there are already some supply chain security detection solutions in the market, but there are still the following limitations and detection defects:

[0004] 1. Currently, software supply chain security detection needs to rely on a large number of security engineers and multiple security tools to achieve. The detection process is complex and time-consuming;

[0005] 2. In current security detection, there is a high false alarm rate in source code detection tools. This is mainly due to reasons such as untimely update of the policy library or incompatibility and mismatch of source code languages, resulting in high false alarm rates and missed alarm rates in source code;

[0006] 3. Currently, security detection is mainly carried out at one level of the software supply chain, and code implantation tools also mainly target one layer, lacking overall implantation and comprehensive evaluation of the entire software supply chain.

[0007] Therefore, how to improve the efficiency, accuracy, and comprehensiveness of software supply chain security detection has become an urgent problem to be solved. Summary of the Invention

[0008] The present invention mainly solves the problem of how to improve the efficiency, accuracy, and comprehensiveness of software supply chain security detection, and discloses a comprehensive detection method and device for software supply chain security.

[0009] In the first aspect of the embodiments of the present invention, a comprehensive detection method for software supply chain security is disclosed, including:

[0010] S1, obtaining a set of software to be implanted and a software supply chain;

[0011] S2, performing layer-by-layer analysis and implantation operations on the software supply chain to obtain an implanted software supply chain;

[0012] S3, performing code comprehensive discrimination processing on the implanted software supply chain and the software supply chain to obtain a comprehensive detection result value of software supply chain security.

[0013] The software supply chain includes a source code layer, a software layer, a database layer, a configuration file layer, and a compiler layer;

[0014] The software set to be implanted includes a source code implantation subset, a software implantation subset, a database implantation subset, a configuration file implantation subset, and a compiler implantation subset;

[0015] The implantation subset includes the implanted software corresponding to all software types at each software supply chain level.

[0016] Performing layer-by-layer analysis and implantation operations on the software supply chain to obtain the post-implantation software supply chain, including:

[0017] S21, obtaining the software type information of each software supply chain level;

[0018] S22, based on all implantation subsets, determining the implanted software corresponding to each software supply chain level according to the software type information;

[0019] S23, implanting the corresponding implanted software into each software supply chain level.

[0020] Performing code comprehensive discrimination processing on the post-implantation software supply chain and the software supply chain to obtain the comprehensive detection result value of software supply chain security, including:

[0021] S31, using the first code discrimination processing model to perform calculation processing on the source code layer and the software layer to obtain the first detection result value;

[0022] S32, using the second code discrimination processing model to perform calculation processing on the database layer and the configuration file layer to obtain the second detection result value;

[0023] S33, using the third code discrimination processing model to perform calculation processing on the compiler layer to obtain the third detection result value;

[0024] S34, performing weighted summation processing on the first detection result value, the second detection result value, and the third detection result value to obtain the comprehensive detection result value of software supply chain security.

[0025] Using the first code discrimination processing model to perform calculation processing on the source code layer and the software layer to obtain the first detection result value, including:

[0026] S311, performing text vector conversion processing on the source code layer and the post-implantation source code layer respectively to obtain the source code vector and the post-implantation source code vector;

[0027] S312. Perform text vector conversion processing on the software layer and the post-implantation software layer respectively to obtain a software vector and a post-implantation software vector;

[0028] S313. Subtract the source code vector from the post-implantation source code vector to obtain a first difference sequence;

[0029] S314. Subtract the software vector from the post-implantation software vector to obtain a second difference sequence;

[0030] S315. Perform high-order cumulant calculation processing on the first difference sequence and the second difference sequence to obtain a high-order cumulant sequence;

[0031] S316. Perform detection calculation processing on the high-order cumulant sequence to obtain a first detection result value.

[0032] The high-order cumulant calculation processing includes:

[0033]

[0034] where x(n) is the nth term of the first difference sequence, y(n) is the nth term of the second difference sequence, RX4, RX6, and RX9 are the fourth-order cumulant, sixth-order cumulant, and ninth-order cumulant of the first difference sequence respectively, RY3, RY5, and RY6 are the third-order cumulant, fifth-order cumulant, and sixth-order cumulant of the second difference sequence respectively, and RXY 34 、RXY 56 、RXY 78 are the third-fourth order joint cumulant, fifth-sixth order joint cumulant, and seventh-eighth order joint cumulant respectively, FFT represents fast Fourier transform processing, and N is the length of the first difference sequence;

[0035] The detection calculation processing includes:

[0036]

[0037] where H1 represents the first detection result value.

[0038] The calculation processing of using the second code discrimination processing model on the database layer and the configuration file layer to obtain a second detection result value includes:

[0039] S321. Perform text vector conversion processing on the post-implantation database and the post-implantation configuration file respectively to obtain a corresponding post-implantation database vector set and a post-implantation configuration file vector set; the post-implantation database vector set includes several post-implantation database vectors; the post-implantation configuration file vector set includes several post-implantation configuration file vectors;

[0040] Represent the post-implantation database vector set and the post-implantation profile vector set as a database matrix and a profile matrix respectively; the row vectors of the database matrix are a post-implantation database vector; the row vectors of the profile matrix are a post-implantation profile vector;

[0041] S322. Perform geometric mean vector calculation processing on the database matrix and the profile matrix respectively to obtain a data geometric vector and a profile geometric vector;

[0042] S323. Perform logarithmic summation processing on the data geometric vector and the profile geometric vector to obtain a second detection result value.

[0043] In the second aspect of the implementation of the present invention, an integrated detection device for software supply chain security is disclosed. The device includes:

[0044] A memory storing executable program code;

[0045] A processor coupled to the memory;

[0046] The processor calls the executable program code stored in the memory to execute the integrated detection method for software supply chain security.

[0047] In the third aspect of the implementation of the present invention, a computer-readable storage medium is disclosed. The computer-readable storage medium stores computer instructions, which are used to execute the integrated detection method for software supply chain security when called by a computer.

[0048] In the fourth aspect of the implementation of the present invention, an information data processing terminal is disclosed. The information data processing terminal is used to implement the integrated detection method for software supply chain security.

[0049] The beneficial effects of the present invention are:

[0050] The present invention discloses an integrated detection method and device for software supply chain security, which mainly solves the problem of how to improve the efficiency, accuracy and comprehensiveness of software supply chain security detection.

[0051] When comprehensively detecting the security of the software supply chain, the present invention first simulates an attack on the software supply chain, implants corresponding codes at each level, and performs code comprehensive discrimination processing on the post-implantation software supply chain and the software supply chain to obtain an integrated detection result value of software supply chain security, ensuring the accuracy and comprehensiveness of the detection result.

[0052] The present invention performs code comprehensive discrimination processing. For different levels and software types, different code discrimination processing models are constructed. Using the first code discrimination processing model, the source code layer and the software layer are calculated and processed to obtain a first detection result value; using the second code discrimination processing model, the database layer and the configuration file layer are calculated and processed to obtain a second detection result value; using the third code discrimination processing model, the compiler layer is calculated and processed to obtain a third detection result value; the first detection result value, the second detection result value, and the third detection result value are weighted and summed to obtain a comprehensive detection result value of software supply chain security. Through the above operations, the accuracy and comprehensiveness of code discrimination processing are ensured, and the rapid and accurate evaluation of software supply chain security is realized. Description of the Drawings

[0053] Figure 1 It is a flowchart of the implementation of the method of the present invention;

[0054] Figure 2 It is a schematic diagram of the composition of a software supply chain attack system. Detailed Embodiment

[0055] To better understand the content of the present invention, an embodiment is given here.

[0056] Figure 1 It is a flowchart of the implementation of the method of the present invention. Figure 2 It is a schematic diagram of the composition of a software supply chain attack system.

[0057] In the first aspect of the embodiment of the present invention, a comprehensive detection method and device for software supply chain security are disclosed, including:

[0058] S1, obtaining a set of software to be implanted and a software supply chain;

[0059] S2, performing a layer-by-layer analysis and implantation operation on the software supply chain to obtain an implanted software supply chain;

[0060] S3, performing code comprehensive discrimination processing on the implanted software supply chain and the software supply chain to obtain a comprehensive detection result value of software supply chain security;

[0061] The software supply chain includes a source code layer, a software layer, a database layer, a configuration file layer, and a compiler layer.

[0062] The set of software to be implanted includes a source code implantation subset, a software implantation subset, a database implantation subset, a configuration file implantation subset, and a compiler implantation subset.

[0063] The implantation subset includes the implanted software corresponding to all software types at each software supply chain level;

[0064] Performing a layer-by-layer analysis and implantation operation on the software supply chain to obtain the implanted software supply chain, including:

[0065] S21, obtaining the software type information of each software supply chain layer;

[0066] S22, based on the implantation subset, determining the implanted software corresponding to each software supply chain layer according to the software type information;

[0067] S23, implanting the corresponding implanted software into each software supply chain layer.

[0068] Performing code comprehensive discrimination processing on the implanted software supply chain and the software supply chain to obtain a comprehensive detection result value of software supply chain security, including:

[0069] S31, using the first code discrimination processing model to perform calculation processing on the source code layer and the software layer to obtain a first detection result value;

[0070] S32, using the second code discrimination processing model to perform calculation processing on the database layer and the configuration file layer to obtain a second detection result value;

[0071] S33, using the third code discrimination processing model to perform calculation processing on the compiler layer to obtain a third detection result value;

[0072] S34, performing weighted summation processing on the first detection result value, the second detection result value, and the third detection result value to obtain a comprehensive detection result value of software supply chain security.

[0073] Using the first code discrimination processing model to perform calculation processing on the source code layer and the software layer to obtain a first detection result value, including:

[0074] Performing text vector conversion processing on the source code layer and the implanted source code layer respectively to obtain a source code vector and an implanted source code vector;

[0075] Performing text vector conversion processing on the software layer and the implanted software layer respectively to obtain a software vector and an implanted software vector;

[0076] Performing subtraction processing on the source code vector and the implanted source code vector to obtain a first difference sequence;

[0077] Performing subtraction processing on the software vector and the implanted software vector to obtain a second difference sequence;

[0078] Performing high-order cumulant calculation processing on the first difference sequence and the second difference sequence to obtain a high-order cumulant sequence;

[0079] Perform detection and calculation processing on the high-order cumulant sequence to obtain a first detection result value.

[0080] The text vector conversion processing for the source code layer and the post-implantation source code layer respectively is to perform text vector conversion on the code of each layer.

[0081] The text vector conversion processing can be implemented by using the function commands str2num or word2vec or a text vector conversion model.

[0082] The high-order cumulant calculation processing includes:

[0083]

[0084]

[0085] where x(n) is the nth term of the first difference sequence, y(n) is the nth term of the second difference sequence, RX4, RX6, and RX9 are the fourth-order cumulant, sixth-order cumulant, and ninth-order cumulant of the first difference sequence respectively, RY3, RY5, and RY6 are the third-order cumulant, fifth-order cumulant, and sixth-order cumulant of the second difference sequence respectively, and RXY 34 、RXY 56 、RXY 78 are the third-fourth order joint cumulant, fifth-sixth order joint cumulant, and seventh-eighth order joint cumulant respectively, FFT represents fast Fourier transform processing, and N is the length of the first difference sequence;

[0086] The detection and calculation processing includes:

[0087]

[0088] where H1 represents the first detection result value.

[0089] The calculation processing of the database layer and the configuration file layer by using the second code discrimination processing model to obtain a second detection result value includes:

[0090] S321, perform text vector conversion processing on the post-implantation database and the post-implantation configuration file respectively to obtain a corresponding post-implantation database vector set and a post-implantation configuration file vector set; the post-implantation database vector set includes several post-implantation database vectors; the post-implantation configuration file vector set includes several post-implantation configuration file vectors;

[0091] Represent the post-implantation database vector set and the post-implantation profile vector set as a database matrix and a profile matrix respectively; the row vector of the database matrix is a post-implantation database vector; the row vector of the profile matrix is a post-implantation profile vector.

[0092] S322. Perform geometric mean vector calculation processing on the database matrix and the profile matrix respectively to obtain a data geometric vector and a profile geometric vector.

[0093] S323. Perform logarithmic summation processing on the data geometric vector and the profile geometric vector to obtain a second detection result value.

[0094] The text vector conversion processing performed on the post-implantation database and the post-implantation profile respectively is to perform text vector conversion processing on the data of the post-implantation database and the post-implantation profile respectively. Convert a data set in the post-implantation database into a corresponding vector, and convert a profile into a corresponding vector. The post-implantation profile includes several profiles.

[0095] The expression for the geometric mean vector calculation is:

[0096]

[0097] where p i is the i-th item of the data geometric vector or the profile geometric vector, a ij is the element in the i-th row and j-th column of the database matrix or the profile matrix, and n is the number of columns of the judgment matrix A.

[0098] The expression for the logarithmic summation processing is:

[0099]

[0100] where R is the second detection result value, M1 is the length of the data geometric vector, is the mean of the i-th item of the data geometric vector and the i-th item of the profile geometric vector.

[0101] The calculation processing of the compiler layer using the third code discrimination processing model to obtain a third detection result value includes:

[0102] Perform text vector conversion processing on the compiler layer and the post-implantation compiler layer respectively to obtain a pre-implantation compiler vector and a post-implantation compiler vector.

[0103] Perform correlation calculation processing on the pre-implantation compiler vector and the post-implantation compiler vector to obtain a correlation vector.

[0104] Perform reverse normalization on the correlation vector to obtain a third detection result value;

[0105] The correlation calculation, its calculation expression is:

[0106]

[0107] where, A1 j is the j-th element of the pre-implant compiler vector, A2 j is the j-th element of the post-implant compiler vector, p j is the j-th element of the correlation vector, and M2 is the length of the pre-implant compiler vector.

[0108] The calculation expression of the reverse normalization process is:

[0109]

[0110] where, H3 is the third detection result value.

[0111] Performing weighted summation on the first detection result value, the second detection result value, and the third detection result value to obtain a comprehensive detection result value for software supply chain security means multiplying the first detection result value, the second detection result value, and the third detection result value by a weighted vector and then accumulating them to obtain a comprehensive detection result value for software supply chain security.

[0112] The weighted vector can be 0.5, 0.4, 0.1.

[0113] In the present invention, when performing comprehensive detection, first, a simulation attack on the software supply chain is required. The software supply chain attack is a system for implanting backdoors into software, and its system architecture is as Figure 2 shown, and it can implement five implantation forms: source code implantation, software implantation, database implantation, configuration file implantation, and compiler implantation.

[0114] Source code implantation means that after an operator puts the obtained software source code into the software supply chain attack, the source code analysis module of the system can automatically analyze the software, judge a series of information such as the language used for software development, the tools used for development, the tools used for code update, and the system platform where the project runs, and implant backdoors into the software according to the obtained information according to the specified implantation strategy, supporting platform automatic deployment and automatically verifying whether the vulnerability is implanted successfully.

[0115] Software implantation means that after an operator puts the obtained software executable file into the software supply chain attack, the software decompilation module of the system can decompile the software, judge the data structure and execution process of the executable file, and implant backdoors in appropriate data blocks.

[0116] Database implantation refers to the way of inserting a "one-sentence" backdoor statement, adding a new backdoor user, and modifying the system security settings in the software database to make it exploitable by attackers.

[0117] Configuration file implantation means tampering with certain configuration files that store sensitive information such as account information and access address control information to achieve the purpose of attack.

[0118] Compiler implantation refers to tampering with a general software compilation platform, adding malicious modules, enabling a large number of developers to obtain the compilation platform and establish a development environment. The software compiled through the tampered software compilation platform will be implanted with a backdoor.

[0119] In the second aspect of the implementation of the present invention, an integrated detection device for software supply chain security is disclosed. The device includes:

[0120] A memory storing executable program code;

[0121] A processor coupled to the memory;

[0122] The processor calls the executable program code stored in the memory and executes the integrated detection method for software supply chain security.

[0123] In the third aspect of the implementation of the present invention, a computer-readable storage medium is disclosed. The computer-readable storage medium stores computer instructions, which are used to execute the integrated detection method for software supply chain security when called by a computer.

[0124] In the fourth aspect of the implementation of the present invention, an information data processing terminal is disclosed. The information data processing terminal is used to implement the integrated detection method for software supply chain security.

[0125] The above are only the embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.

Claims

1. An integrated detection method for software supply chain security, characterized in that, Including: S1. Obtain the software set to be implanted and the software supply chain; S2. Perform layer-by-layer analysis and implantation operations on the software supply chain to obtain the implanted software supply chain; S3. Perform code comprehensive discrimination processing on the implanted software supply chain and the software supply chain to obtain a comprehensive detection result value of the software supply chain security; The software supply chain includes a source code layer, a software layer, a database layer, a configuration file layer, and a compiler layer; The software set to be implanted includes a source code implantation subset, a software implantation subset, a database implantation subset, a configuration file implantation subset, and a compiler implantation subset; Each implantation subset includes the implanted software corresponding to all software types at the corresponding software supply chain level; The performing code comprehensive discrimination processing on the implanted software supply chain and the software supply chain to obtain a comprehensive detection result value of the software supply chain security includes: S31. Use the first code discrimination processing model to perform calculation processing on the source code layer and the software layer to obtain a first detection result value; S32. Use the second code discrimination processing model to perform calculation processing on the database layer and the configuration file layer to obtain a second detection result value; S33. Use the third code discrimination processing model to perform calculation processing on the compiler layer to obtain a third detection result value; S34. Perform weighted summation processing on the first detection result value, the second detection result value, and the third detection result value to obtain a comprehensive detection result value of the software supply chain security; The using the first code discrimination processing model to perform calculation processing on the source code layer and the software layer to obtain a first detection result value includes: S311. Perform text vector conversion processing on the source code layer and the implanted source code layer respectively to obtain a source code vector and an implanted source code vector; S312. Perform text vector conversion processing on the software layer and the implanted software layer respectively to obtain a software vector and an implanted software vector; S313. Perform subtraction processing on the source code vector and the implanted source code vector to obtain a first difference sequence; S314. Perform subtraction processing on the software vector and the implanted software vector to obtain a second difference sequence; S315. Perform high-order cumulant calculation processing on the first difference sequence and the second difference sequence to obtain a high-order cumulant sequence; S316. Perform detection calculation processing on the high-order cumulant sequence to obtain a first detection result value; The high-order cumulant calculation processing includes: Wherein, x(n) is the n-th term of the first difference sequence, y(n) is the n-th term of the second difference sequence, RX4, RX6, and RX9 are the fourth-order cumulant, sixth-order cumulant, and ninth-order cumulant of the first difference sequence respectively, RY3, RY5, and RY6 are the third-order cumulant, fifth-order cumulant, and sixth-order cumulant of the second difference sequence respectively, RXY 34 , RXY 56 , RXY 78 are the third-fourth order joint cumulant, fifth-sixth order joint cumulant, and seventh-eighth order joint cumulant respectively, FFT represents fast Fourier transform processing, and N is the length of the first difference sequence; The detection calculation processing includes: Wherein, H1 represents the first detection result value.

2. The comprehensive detection method for software supply chain security according to claim 1, wherein The performing layer-by-layer analysis and implantation operations on the software supply chain to obtain the implanted software supply chain includes: S21. Obtain the software type information of each software supply chain level; S22. Based on all implantation subsets, determine the implanted software corresponding to each software supply chain level according to the software type information; S23. Implant the corresponding implanted software into each software supply chain level.

3. The comprehensive detection method for software supply chain security according to claim 1, wherein The using the second code discrimination processing model to perform calculation processing on the database layer and the configuration file layer to obtain a second detection result value includes: S321. Perform text vector conversion processing on the post-implantation database and the post-implantation configuration file respectively to obtain the corresponding post-implantation database vector set and the post-implantation configuration file vector set; the post-implantation database vector set includes several post-implantation database vectors; the post-implantation configuration file vector set includes several post-implantation configuration file vectors. Represent the post-implantation database vector set and the post-implantation configuration file vector set as a database matrix and a configuration file matrix respectively; the row vector of the database matrix is a post-implantation database vector; the row vector of the configuration file matrix is a post-implantation configuration file vector. S322. Perform geometric mean vector calculation processing on the database matrix and the configuration file matrix respectively to obtain a data geometric vector and a configuration geometric vector. S323. Perform logarithmic summation processing on the data geometric vector and the configuration geometric vector to obtain a second detection result value.

4. An integrated detection device for software supply chain security, characterized in that, The device includes: A memory storing executable program code; A processor coupled to the memory; The processor calls the executable program code stored in the memory and executes the comprehensive detection method for software supply chain security according to any one of claims 1 to 3.

5. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, which are used to execute the comprehensive detection method for software supply chain security according to any one of claims 1 to 3 when called by a computer.

6. An information data processing terminal, characterized in that, The information data processing terminal is used to implement the comprehensive detection method for software supply chain security according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Detection of supply chain related security threats to software applications

    CN117546164A

  • Demand upgrading information updating method and device, electronic equipment and storage medium

    CN117591156A