A method and device for constructing a 0DAY vulnerability detection model based on an AI large model

By building a multi-level 0DAY vulnerability detection dataset and combining AI large models, the dataset imbalance and insufficient understanding of complex code logic faced by AI models in 0DAY vulnerability detection are solved, and more efficient and accurate vulnerability detection and positioning are achieved.

CN119961941BActive Publication Date: 2025-06-24FUJIAN BAMIN YUNAN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510453571.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-06-24
Estimated Expiration
2045-04-11

AI Technical Summary

Technical Problem

In the detection of 0DAY vulnerability, existing AI models face data set imbalance, scarcity of samples and insufficient understanding of complex code logic, and it is difficult to adopt different analytical strategies for different levels of code, resulting in difficulty in problem positioning and performance optimization.

Method used

By collecting code from open source projects, building a vulnerability detection dataset in combination with the disclosed vulnerability database, generating adversarial samples using AST abstract syntax tree replacement technology and GAN, extracting code features in layered, and combining Transformer model and convolutional neural network algorithm, 0DAY vulnerability detection models of different levels of code were trained respectively.

Benefits of technology

It improves the generalization ability and efficiency of AI models in 0DAY vulnerability detection, can more accurately identify and locate 0DAY vulnerabilities, improves code quality and security, and reduces the risk of system crashes and data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961941B_ABST
    Figure CN119961941B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for constructing a 0DAY vulnerability detection model based on an AI large model, which relates to the field of network security technology, and solves the technical problems that it is difficult to adopt different analysis strategies for codes at different levels, difficult to locate problems and optimize performance targeted, and also difficult to combine the advantages of multiple models to fully analyze different analysis parameters; by adding adversarial samples to the vulnerability detection dataset, the AI large model can learn more diverse vulnerability features during the training process, thereby enhancing the generalization ability of the model and enabling it to better adapt to vulnerability detection tasks in different scenarios. Through the AST abstract syntax tree replacement technology, it is convenient to quickly locate and replace non-system code functions in the dataset, reducing the dependence on the original code, thereby improving the efficiency of vulnerability detection. Adopting different analysis strategies for codes at different levels facilitates more targeted problem location.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security, and specifically relates to a method and device for constructing a 0DAY vulnerability detection model based on an AI large model. Background Art

[0002] With the rapid development of information technology, the complexity and scale of software systems have been continuously increasing, and security vulnerabilities have become a major hidden danger in the field of network security. In particular, 0DAY vulnerabilities (Zero-Day Vulnerabilities), which refer to vulnerabilities that have not been discovered or fixed by developers after the software is released. Such vulnerabilities are usually exploited by hackers for attacks, causing serious security threats. Traditional vulnerability detection methods often rely on static and dynamic analysis, but these methods often lack detection efficiency and accuracy when facing newly emerging 0DAY vulnerabilities. In recent years, the development of artificial intelligence technology has provided new ideas for vulnerability detection. Through machine learning and deep learning models, potential security risks can be automatically identified from a large amount of code. However, existing AI models still face many challenges when dealing with 0DAY vulnerabilities, including unbalanced datasets, scarce samples, and insufficient understanding of complex code logic. Therefore, a new method is needed to improve the effectiveness of AI models in 0DAY vulnerability detection.

[0003] Most 0DAY vulnerability detection solutions uniformly analyze the code, making it difficult to adopt different analysis strategies for different levels of code, difficult to target problem location and performance optimization, and also difficult to combine the advantages of multiple models to fully analyze different analysis parameters. Summary of the Invention

[0004] The present invention aims to at least solve one of the technical problems existing in the prior art; for this purpose, the present invention proposes a method and device for constructing a 0DAY vulnerability detection model based on an AI large model, which is used to solve the technical problems that it is difficult to adopt different analysis strategies for different levels of code, difficult to target problem location and performance optimization, and also difficult to combine the advantages of multiple models to fully analyze different analysis parameters.

[0005] To solve the above problems, the first aspect of the present invention provides a method for constructing a 0DAY vulnerability detection model based on an AI large model, including the following steps:

[0006] Collect codes that are normally running with various functions and implementations from open-source projects, obtain known vulnerability instances and their contexts through a public vulnerability database, mark the vulnerability locations, and form a vulnerability detection dataset together with the normally running codes;

[0007] Replace non-system code functions in the dataset with kernel APIs through the AST (Abstract Syntax Tree) replacement technique, and insert simulated vulnerability patterns into the legitimate code;

[0008] Screen the source code with 0DAY vulnerabilities in the legitimate code, generate adversarial samples containing "effective verification but the vulnerability still exists" for the screened source code through GAN, and add them to the vulnerability detection dataset;

[0009] Divide the dataset into multiple levels according to the function and structure of the code, and extract the syntax features, execution path features, and function relationship features of the code at each level;

[0010] Adopt different dynamic analysis strategies and static analysis strategies for the code at different levels, and analyze the corresponding dynamic analysis results and static analysis results;

[0011] According to the dynamic analysis results and static analysis results, as well as the syntax features, execution path features, and function relationship features of the code at each level, train 0DAY vulnerability detection models for the code at different levels by combining the Transformer model and the convolutional neural network algorithm respectively.

[0012] Optionally, in an example of the above aspect, replacing non-system code functions in the dataset with kernel APIs through the AST replacement technique and inserting simulated vulnerability patterns into the legitimate code includes the following steps:

[0013] Convert the source code into a tree representation of the source code through a parser of the programming language; for example, the ast module in Python converts the source code into an AST, which is a tree representation of the source code; among them, in the tree representation of the source code, each node represents a syntax element; such as variables, functions, control structures, etc.

[0014] Traverse the tree representation of the source code, identify non-system functions according to the function name, parameters, and return value features, regard the identified non-system functions as function nodes to be replaced, and randomly select a certain number of non-system functions among them. By randomly combining non-system functions, modifying the input format or content, allowing more input conditions to trigger, and by renaming variables, functions, and classes, replace the non-system functions with non-system functions with 0DAY vulnerabilities, and mark the vulnerability positions; identify non-system functions according to the function name, parameters, and return value features, for example, exclude function names starting with a specific prefix (such as "_").

[0015] Determine the non-system functions of all function nodes to be replaced and their corresponding kernel APIs, and replace them with the corresponding kernel API nodes; for example, replace a certain custom input validation function with a security API provided by the kernel;

[0016] Re - convert the tree representation of the replaced source code back into executable code. Use existing tools, such as the astor library, to convert the modified AST back into executable code.

[0017] In this embodiment, through the AST abstract syntax tree replacement technology, functions in non - system code, such as user - mode programs, are replaced with kernel APIs; for example, kmalloc → vmalloc.

[0018] Optionally, in an example of the above aspect, screening the source code with 0DAY vulnerabilities in the legal code includes the following steps:

[0019] Screen the source code in the legal code that is marked with vulnerabilities but not marked with 0DAY vulnerabilities;

[0020] Trigger the vulnerability location in the code by modifying the input format or content, allowing more input conditions, and convert the code at the vulnerability location into 0DAY vulnerability code by renaming variables, functions, and classes, and perform 0DAY vulnerability marking;

[0021] Screen out the source code marked with 0DAY vulnerabilities.

[0022] Optionally, in an example of the above aspect, generating adversarial samples with "effective verification but the vulnerability still exists" from the screened source code through GAN and adding them to the vulnerability detection dataset includes the following steps:

[0023] For the source code screened and marked with 0DAY vulnerabilities, insert a simulated vulnerability pattern at an appropriate position in the source code;

[0024] Use the code with the inserted simulated vulnerability pattern as the training set, and combine it with normal code and known vulnerability samples to form an adversarial training set;

[0025] Train the GAN model generator through the adversarial training set to create new samples that behave like real samples in front of the discriminator, and train the GAN model discriminator to learn to distinguish real samples from generated samples, and feedback to the generator to improve its output;

[0026] Add the obtained new samples to the vulnerability detection dataset.

[0027] Optionally, in an example of the above aspect, divide the dataset into multiple levels according to the function and structure of the code, and extract the syntax features, execution path features, and function - to - function relationship features of the code at each level, including the following steps:

[0028] According to the function and structure of the code, the vulnerability detection dataset is divided into multiple levels, including: the application layer, the service layer, the data access layer, and the system layer; the application layer is the user interaction logic and input processing code, the service layer is the API calls and business logic processing, the data access layer is the database operations and data transmission, and the system layer is the system calls and underlying implementation;

[0029] For the code of each level, syntax features are extracted through AST, execution path features are extracted through the CFG control flow graph, and function - to - function relationship features are extracted through the Call Graph function call graph.

[0030] Optionally, in an example of the above aspect, different dynamic analysis strategies and static analysis strategies are adopted for codes of different levels, including the following steps:

[0031] For the code of the application layer in the vulnerability detection dataset, the dynamic analysis strategy includes:

[0032] Simulate user interactions through the Selenium tool, test the responses of the application under various regular inputs, and attack the application through the OWASP ZAP fuzz testing tool to identify potential security vulnerabilities;

[0033] Obtain error information and security vulnerability data of the application - layer code under simulated user behavior;

[0034] The static analysis strategy for the code of the application layer includes:

[0035] Check the code quality through the SonarQube static code analysis tool, identify security vulnerabilities and labeled 0DAY vulnerabilities in the code;

[0036] Generate a report, including the code quality score and the list of security vulnerabilities;

[0037] For the code of the service layer in the vulnerability detection dataset, the dynamic analysis strategy includes:

[0038] Conduct load testing and security testing through RESTful or SOAP APIs, as well as the return results of regular requests, and monitor service requests and responses in real - time;

[0039] Collect API response time, error rate, and security vulnerability information;

[0040] The static analysis strategy for the code of the service layer includes:

[0041] Verify the consistency between the service interface definition and implementation, and check the service - layer code quality through static analysis tools;

[0042] Generate an interface contract consistency report and a code quality assessment report;

[0043] For the code of the data access layer in the vulnerability detection dataset, the dynamic analysis strategy includes:

[0044] Detect the transaction processing performance by simulating concurrent database query operations, and identify potential performance anomaly data or SQL injection by monitoring the execution plan and performance of SQL queries;

[0045] Record database query performance metrics and SQL injection anomalies;

[0046] The static analysis strategy for the code of the access layer includes:

[0047] Detect potential injection risks in SQL query construction through static code analysis tools, and check the configuration of the ORM object-relational mapping;

[0048] Generate an SQL injection risk assessment report and an ORM usage review report;

[0049] For the code of the system layer in the vulnerability detection dataset, the dynamic analysis strategy includes:

[0050] Real-time monitor the usage of system layer resources, obtain the occupancy data of CPU, memory, and disk I / O, system performance metrics, and at the same time conduct a comprehensive penetration test on the system to identify vulnerabilities in the code of the system layer;

[0051] Collect system performance data and vulnerability information discovered by penetration testing;

[0052] The static analysis strategy for the code of the system layer includes:

[0053] Conduct a source code audit on the underlying system components, and generate a configuration review report and a source code audit report.

[0054] Analyze the corresponding dynamic analysis results and static analysis results.

[0055] Optionally, in an example of the above aspects, for different levels of code, combine the Transformer model and the convolutional neural network algorithm to train 0DAY vulnerability detection models for different levels of code, including the following steps:

[0056] Obtain the dynamic analysis results and static analysis results extracted from the code in the vulnerability detection dataset, as well as the syntax features, execution path features, and function relationship features of each level of code;

[0057] Add a fusion input layer before the input layer of the Transformer model and the convolutional neural network model, and add an analysis output layer after the output layer of the Transformer model and the convolutional neural network model;

[0058] The fusion input layer inputs the dynamic analysis results and static analysis results of the corresponding level, as well as the syntactic features of the code, into the Transformer model, and inputs the execution path features and inter-function relationship features into the convolutional neural network model;

[0059] The analysis output layer obtains the output results of the Transformer model and the convolutional neural network model for weighted fusion to obtain the final 0DAY vulnerability detection result;

[0060] For codes at different levels, the data extracted from the vulnerability detection dataset is input into the fusion input layer for model training to obtain 0DAY vulnerability detection models for codes at different levels, and 0DAY vulnerabilities in the code are detected.

[0061] According to another aspect of the present disclosure, there is provided a 0DAY vulnerability detection model construction device based on an AI large model, including:

[0062] Dataset generation module: Collect the normally running codes of various functions and implementations from open-source projects, obtain known vulnerability instances and their contexts through a public vulnerability database, mark the vulnerability locations, and form a vulnerability detection dataset with the normally running codes;

[0063] Dataset expansion module: Through the AST abstract syntax tree replacement technology, replace the non-system code functions in the dataset with kernel APIs, and insert simulated vulnerability patterns into the legal codes; Screen the source codes with 0DAY vulnerabilities in the legal codes, generate adversarial samples with "effective verification but the vulnerability still exists" from the screened source codes through GAN, and add them to the vulnerability detection dataset;

[0064] Data analysis module: Divide the dataset into multiple levels according to the functions and structures of the codes, and extract the syntactic features, execution path features and inter-function relationship features of the codes at each level; Adopt different dynamic analysis strategies and static analysis strategies for codes at different levels to analyze the corresponding dynamic analysis results and static analysis results;

[0065] Vulnerability detection model construction module: According to the dynamic analysis results and static analysis results, as well as the syntactic features, execution path features and inter-function relationship features of the codes at each level, for codes at different levels, combine the Transformer model and the convolutional neural network algorithm to train 0DAY vulnerability detection models for codes at different levels respectively.

[0066] According to another aspect of the present disclosure, there is provided a computing device, including:

[0067] A memory and a processor;

[0068] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the above-mentioned method for constructing a 0DAY vulnerability detection model based on an AI large model are implemented.

[0069] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0070] By adding adversarial samples to the vulnerability detection dataset, the AI large model can learn more diverse vulnerability features during the training process, thereby enhancing the generalization ability of the model and enabling it to better adapt to vulnerability detection tasks in different scenarios. Through the AST abstract syntax tree replacement technology, it is convenient to quickly locate and replace non-system code functions in the dataset, reducing the dependence on the original code and thus improving the efficiency of vulnerability detection.

[0071] The present invention adopts different analysis strategies for codes at different levels, which is convenient for more targeted problem location and performance optimization. By combining dynamic analysis and static analysis, it is convenient to timely discover and repair vulnerabilities and defects in the code, which helps to improve the overall quality and security of the code, and reduce the risks of system crashes and data leaks; according to the results of dynamic analysis and static analysis, as well as the syntax features, execution path features, and function relationship features of each level of code, for codes at different levels, combining the Transformer model and the convolutional neural network algorithm, the 0DAY vulnerability detection models for different levels of code are trained respectively. BRIEF DESCRIPTION OF THE DRAWINGS

[0072] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0073] Figure 1 It is a schematic diagram of the method flow of the present invention;

[0074] Figure 2 It is a schematic diagram of the system framework of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0075] The following will clearly and completely describe the technical solutions of the present invention in conjunction with the embodiments. Obviously, the described embodiments are only some of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments of the present invention belong to the scope of protection of the present invention. Embodiment 1

[0076] Please refer to Figure 1 , an embodiment of the first aspect of the present invention provides a method for constructing a 0DAY vulnerability detection model based on an AI large model, including the following steps:

[0077] Collect the codes that run normally for various functions and implementations from open-source projects, obtain known vulnerability instances and their contexts through a public vulnerability database (such as CVE), mark the vulnerability locations, and form a vulnerability detection dataset with the codes that run normally;

[0078] Through the AST abstract syntax tree replacement technology, replace the non-system code functions in the dataset with kernel APIs, and insert simulated vulnerability patterns into the legitimate codes;

[0079] Screen the source codes with 0DAY vulnerabilities in the legitimate codes, generate adversarial samples containing "effective verification but the vulnerability still exists" from the screened source codes through GAN, and add them to the vulnerability detection dataset;

[0080] According to the functions and structures of the codes, divide the dataset into multiple levels, and extract the syntax features, execution path features, and function relationship features of the codes at each level;

[0081] Adopt different dynamic analysis strategies and static analysis strategies for the codes at different levels, and analyze the corresponding dynamic analysis results and static analysis results;

[0082] According to the dynamic analysis results and static analysis results, as well as the syntax features, execution path features, and function relationship features of the codes at each level, for the codes at different levels, combine the Transformer model and the convolutional neural network algorithm to train the 0DAY vulnerability detection models for the codes at different levels respectively.

[0083] Specifically, through the AST abstract syntax tree replacement technology, replace the non-system code functions in the dataset with kernel APIs, and insert simulated vulnerability patterns into the legitimate codes; screen the source codes with 0DAY vulnerabilities in the legitimate codes, generate adversarial samples containing "effective verification but the vulnerability still exists" from the screened source codes through GAN, and add them to the vulnerability detection dataset;

[0084] By adding the adversarial samples to the vulnerability detection dataset, the AI large model can learn more diverse vulnerability features during the training process, thereby enhancing the generalization ability of the model and enabling it to better adapt to the vulnerability detection tasks in different scenarios.

[0085] Through the AST abstract syntax tree replacement technology, it is convenient to quickly locate and replace the non-system code functions in the dataset, reduce the dependence on the original code, and thus improve the efficiency of vulnerability detection.

[0086] Replace non-system code functions with kernel APIs and insert a simulated vulnerability mode into the legitimate code to facilitate simulating a vulnerability scenario closer to the real environment, which helps the AI large model to more accurately learn and identify the characteristics of 0DAY vulnerabilities.

[0087] According to the function and structure of the code, divide the dataset into multiple levels, and extract the syntax features, execution path features, and function relationship features of the code at each level; adopt different dynamic analysis strategies and static analysis strategies for the code at different levels, and analyze the corresponding dynamic analysis results and static analysis results.

[0088] The stratification of the dataset helps to decompose the complex code system into more manageable parts. Each level has its specific scope and responsibilities, making it more convenient to locate and understand the code. By extracting the syntax features, execution path features, and function relationship features, it is easier to comprehensively understand the behavior and logic of the code. By focusing on the runtime behavior of the code through dynamic analysis, problems and performance bottlenecks in the actual execution of the code can be revealed. Static analysis checks the syntax, semantics, and structure of the code without running the code, which helps to discover potential defects and security issues. Combining the two can achieve a comprehensive analysis of the code and improve the accuracy of the analysis.

[0089] Adopting different analysis strategies for the code at different levels facilitates more targeted problem location and performance optimization. By combining dynamic analysis and static analysis, it is easy to discover and fix vulnerabilities and defects in the code in a timely manner, which helps to improve the overall quality and security of the code and reduce the risk of system crashes and data leaks.

[0090] According to the dynamic analysis results and static analysis results, as well as the syntax features, execution path features, and function relationship features of the code at each level, for the code at different levels, combine the Transformer model and the convolutional neural network algorithm to train the 0DAY vulnerability detection models for the code at different levels respectively.

[0091] The Transformer model is good at handling global dependencies and long-distance dependency relationships, has a stronger ability to capture complex logic and function call relationships in the code, and can effectively analyze the function relationship features, thus more accurately identifying potential 0DAY vulnerabilities. The CNN model performs well in local feature extraction and is particularly suitable for extracting the syntax features and execution path features of the code. Through convolutional operations, the CNN can capture subtle changes in the code, which may be clues to 0DAY vulnerabilities.

[0092] Train models for different levels of code respectively, enabling the models to focus more on the code features of specific levels, thereby improving the generalization ability of the models. When new code appears, the models can adapt more quickly and accurately detect vulnerabilities. By combining the dynamic analysis results and static analysis results, as well as various features of the code for training, the models can learn richer code representations. This representation method helps the models better understand and analyze the code, improving the accuracy of vulnerability detection.

[0093] The Transformer model has the ability of parallel computing, processing information at multiple positions simultaneously, thus accelerating the training speed. This is particularly important for the training of large-scale code datasets. The CNN model efficiently extracts local features through convolutional operations, reducing unnecessary computational amounts and improving the training efficiency; by combining the outputs of the Transformer model and the CNN model, complementarity between the models can be achieved, further improving the accuracy of vulnerability detection; during the training process, the models can be optimized and adjusted specifically according to the characteristics of different levels of code and the requirements of vulnerability detection to improve the performance and accuracy of the models.

[0094] In one embodiment of the present invention, through the AST abstract syntax tree replacement technology, non-system code functions in the dataset are replaced with kernel APIs, and simulated vulnerability patterns are inserted into the legal code, including the following steps:

[0095] Convert the source code into a tree representation of the source code through a parser of the programming language; for example, the ast module of Python converts the source code into an AST, and the AST is a tree representation of the source code; among them, in the tree representation of the source code, each node represents a syntactic element; such as variables, functions, control structures, etc.

[0096] Traverse the tree representation of the source code, identify non-system functions according to function names, parameters, and return value features, regard the identified non-system functions as function nodes to be replaced, and randomly select a certain number of non-system functions among them. By randomly combining non-system functions, modifying the input format or content, allowing more input conditions to trigger, and by renaming variables, functions, and classes, replace the non-system functions with non-system functions with 0DAY vulnerabilities, and mark the vulnerability positions; identify non-system functions according to function names, parameters, and return value features, for example, exclude function names starting with a specific prefix (such as "_").

[0097] Determine the non-system functions of all function nodes to be replaced and their corresponding kernel APIs, and replace them with the corresponding kernel API nodes. For example, replace a certain custom input validation function with a security API provided by the kernel;

[0098] Re - convert the tree representation of the replaced source code back into executable code. Use existing tools, such as the astor library, to convert the modified AST back into executable code.

[0099] In this embodiment, through the AST abstract syntax tree replacement technology, functions in non - system code, such as user - mode programs, are replaced with kernel APIs; for example, kmalloc → vmalloc.

[0100] In one embodiment of the present invention, screening the source code with 0DAY vulnerabilities in legal code includes the following steps:

[0101] Screen the source code in legal code that is marked with vulnerabilities but not marked with 0DAY vulnerabilities;

[0102] Trigger the vulnerability location in the code by modifying the input format or content, allowing more input conditions, and convert the code at the vulnerability location into 0DAY vulnerability code by renaming variables, functions, and classes, and perform 0DAY vulnerability marking;

[0103] Screen out the source code marked with 0DAY vulnerabilities.

[0104] In one embodiment of the present invention, generating adversarial samples with "effective verification but the vulnerability still exists" from the screened source code through GAN and adding them to the vulnerability detection dataset includes the following steps:

[0105] For the source code marked with 0DAY vulnerabilities screened out, insert a simulated vulnerability pattern at an appropriate position in the source code;

[0106] Use the code with the inserted simulated vulnerability pattern as the training set, and combine it with normal code and known vulnerability samples to form an adversarial training set;

[0107] Train the GAN model generator with the adversarial training set to create new samples that behave like real samples in front of the discriminator, and train the GAN model discriminator to learn to distinguish real samples from generated samples, and feedback to the generator to improve its output;

[0108] Add the obtained new samples to the vulnerability detection dataset.

[0109] In one embodiment of the present invention, according to the function and structure of the code, divide the dataset into multiple levels, and extract the syntax features, execution path features, and function - to - function relationship features of the code at each level, including the following steps:

[0110] According to the function and structure of the code, the vulnerability detection dataset is divided into multiple levels, including: the application layer, the service layer, the data access layer, and the system layer; the application layer is the user interaction logic and input processing code, the service layer is the API calls and business logic processing, the data access layer is the database operations and data transmission, and the system layer is the system calls and underlying implementation;

[0111] For the code of each level, extract syntax features through AST, extract execution path features through CFG (Control Flow Graph), and extract function - to - function relationship features through Call Graph.

[0112] In one embodiment of the present invention, different dynamic analysis strategies and static analysis strategies are adopted for codes of different levels, including the following steps:

[0113] For the code in the application layer of the vulnerability detection dataset, the dynamic analysis strategy includes:

[0114] Simulate user interaction through the Selenium tool, test the response of the application under various regular inputs, and attack the application through the OWASP ZAP fuzz testing tool to identify potential security vulnerabilities;

[0115] Obtain error information and security vulnerability data of the application - layer code under simulated user behavior;

[0116] The static analysis strategy for the code in the application layer includes:

[0117] Check the code quality through the SonarQube static code analysis tool, identify security vulnerabilities and labeled 0DAY vulnerabilities in the code;

[0118] Generate a report, including code quality scores and a list of security vulnerabilities;

[0119] For the code in the service layer of the vulnerability detection dataset, the dynamic analysis strategy includes:

[0120] Conduct load testing and security testing through RESTful or SOAP APIs, as well as the return results of regular requests, and monitor service requests and responses in real - time;

[0121] Collect API response time, error rate, and security vulnerability information;

[0122] The static analysis strategy for the code in the service layer includes:

[0123] Verify the consistency between the service interface definition and implementation, and check the code quality of the service layer through static analysis tools;

[0124] Generate an interface contract consistency report and a code quality evaluation report;

[0125] For the code of the data access layer in the vulnerability detection dataset, the dynamic analysis strategy includes:

[0126] Detect the transaction processing performance by simulating concurrent database query operations, and identify potential performance anomaly data or SQL injection by monitoring the execution plan and performance of SQL queries;

[0127] Record the database query performance metrics and SQL injection anomalies;

[0128] The static analysis strategy for the code of the access layer includes:

[0129] Detect potential injection risks in SQL query construction through static code analysis tools, and check the configuration of the ORM object-relational mapping;

[0130] Generate a SQL injection risk assessment report and an ORM usage review report;

[0131] For the code of the system layer in the vulnerability detection dataset, the dynamic analysis strategy includes:

[0132] Real-time monitor the usage of system layer resources, obtain the occupancy data of CPU, memory, and disk I / O, system performance metrics, and conduct a comprehensive penetration test on the system to identify vulnerabilities in the code of the system layer;

[0133] Collect system performance data and vulnerability information discovered during the penetration test;

[0134] The static analysis strategy for the code of the system layer includes:

[0135] Conduct a source code audit on the underlying system components, and generate a configuration review report and a source code audit report.

[0136] In one embodiment of the present invention, analyzing the corresponding dynamic analysis results and static analysis results includes the following steps:

[0137] For the code of the application layer in the vulnerability detection dataset, extract the error ratio and the number of security vulnerability data in the error information and security vulnerability data of the dynamic analysis;

[0138] By calculating the dynamic analysis evaluation value V1 = a1 * error ratio + a2 * (number of security vulnerability data / 100), where a1 and a2 are the corresponding weights, use the extracted data and the dynamic analysis evaluation value together as the dynamic analysis result;

[0139] Extract the code quality score and the security vulnerability list in the static analysis result of the code of the application layer;

[0140] Evaluate the static analysis value E1 = b1 * (the number of 0DAY vulnerabilities marked in security vulnerabilities / the total number of security vulnerabilities) + b2 * [(100 - code quality score) / 100], where b1 and b2 are the corresponding weights. Use the extracted data and the static analysis value together as the static analysis result;

[0141] For the code in the service layer of the vulnerability detection dataset, extract the API response time and error rate of dynamic analysis, as well as the number of security vulnerabilities and the number of 0DAY vulnerabilities marked in security vulnerabilities;

[0142] Evaluate the dynamic analysis value V2 = a3 * (API response time / 100 + error rate) + a4 * (the number of 0DAY vulnerabilities marked in security vulnerabilities / the total number of security vulnerabilities), where a3 and a4 are the corresponding weights. Use the extracted data and the dynamic analysis value together as the dynamic analysis result;

[0143] Extract the code quality score and security vulnerability list from the static analysis result of the code in the service layer;

[0144] Evaluate the static analysis value E2 = b3 * (the number of interface contract consistency compliance / the total number of interface contract detections) + b4 * [(100 - code quality score) / 100], where b3 and b4 are the corresponding weights. Use the extracted data and the static analysis value together as the static analysis result;

[0145] For the code in the data access layer of the vulnerability detection dataset, extract the database query response time and error rate of dynamic analysis, as well as the number of SQL injection exceptions;

[0146] Evaluate the dynamic analysis value V3 = a5 * (database query response time / 100 + error rate) + a6 * (the number of SQL injection exceptions / the total number of security vulnerabilities), where a5 and a6 are the corresponding weights. Use the extracted data and the dynamic analysis value together as the dynamic analysis result;

[0147] Extract the number of potential SQL injection points and the list of potential vulnerabilities in the ORM configuration from the static analysis result of the code in the data access layer;

[0148] Evaluate the static analysis value E3 = b5 * (the number of potential SQL injection points / 100) + b6 * [the number of potential vulnerabilities in the ORM configuration / 100], where b5 and b6 are the corresponding weights. Use the extracted data and the static analysis value together as the static analysis result;

[0149] For the system layer code in the vulnerability detection dataset, extract the number of abnormal occupancy data of CPU, memory, and disk I / O in dynamic analysis and the vulnerability data detected by penetration testing;

[0150] Evaluate the dynamic analysis evaluation value V4 = a7 * (proportion of 0DAY vulnerabilities marked among the vulnerabilities detected by penetration testing) + a8 * (number of abnormal occupancy data of CPU, memory, and disk I / O / 100), where a7 and a8 are the corresponding weights, and use the extracted data and the dynamic analysis evaluation value together as the dynamic analysis result;

[0151] Extract the number of underlying system component vulnerabilities and security risk factors in the static analysis result of the system layer code, as well as the number of non-compliant codes in the source code audit;

[0152] Evaluate the static analysis evaluation value E4 = b7 * (percentage of non-compliant codes in the source code audit among the audited codes) + b8 * [number of underlying system component vulnerabilities / sum of the number of underlying system component vulnerabilities and security risk factors], where b7 and b8 are the corresponding weights, and use the extracted data and the static analysis evaluation value together as the static analysis result.

[0153] In one embodiment of the present invention, for different levels of code, combine the Transformer model and the convolutional neural network algorithm to train 0DAY vulnerability detection models for different levels of code respectively, including the following steps:

[0154] Obtain the dynamic analysis results and static analysis results extracted from the code in the vulnerability detection dataset, as well as the syntax features, execution path features, and inter-function relationship features of each level of code;

[0155] Add a fusion input layer before the input layer of the Transformer model and the convolutional neural network model, and add an analysis output layer after the output layer of the Transformer model and the convolutional neural network model;

[0156] The fusion input layer inputs the dynamic analysis results and static analysis results of the corresponding level, as well as the syntax features of the code, into the Transformer model, and inputs the execution path features and inter-function relationship features into the convolutional neural network model;

[0157] The analysis output layer obtains the output results of the Transformer model and the convolutional neural network model, performs weighted fusion, and obtains the final 0DAY vulnerability detection result;

[0158] For different levels of code, input the extracted data in the vulnerability detection dataset into the fusion input layer, perform model training, obtain 0DAY vulnerability detection models for different levels of code, and detect 0DAY vulnerabilities in the code. Embodiment 2

[0159] Please refer to Figure 2, according to the embodiments of the present application, there is also provided an apparatus for constructing a 0DAY vulnerability detection model based on an AI large model, including:

[0160] Dataset generation module: Collect the normally running codes of various functions and implementations from open-source projects, obtain known vulnerability instances and their contexts through a publicly available vulnerability database, annotate the vulnerability locations, and form a vulnerability detection dataset with the normally running codes;

[0161] Dataset expansion module: Through the AST (Abstract Syntax Tree) replacement technology, replace the non-system code functions in the dataset with kernel APIs, and insert simulated vulnerability patterns into the legitimate codes; Screen the source codes with 0DAY vulnerabilities in the legitimate codes, generate adversarial samples with "effective verification but the vulnerability still exists" from the screened source codes through GAN (Generative Adversarial Network), and add them to the vulnerability detection dataset;

[0162] Data analysis module: According to the functions and structures of the codes, divide the dataset into multiple levels, and extract the syntax features, execution path features, and function relationship features of the codes at each level; Adopt different dynamic analysis strategies and static analysis strategies for the codes at different levels, and analyze the corresponding dynamic analysis results and static analysis results;

[0163] Vulnerability detection model construction module: According to the dynamic analysis results and static analysis results, as well as the syntax features, execution path features, and function relationship features of the codes at each level, for the codes at different levels, combine the Transformer model and the convolutional neural network algorithm to train the 0DAY vulnerability detection models for the codes at different levels respectively. Embodiment 3

[0164] According to the embodiments of the present application, there is also provided a computing device, including:

[0165] A memory and a processor;

[0166] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the above-mentioned method for constructing a 0DAY vulnerability detection model based on an AI large model are implemented.

[0167] The above embodiments are only used to illustrate the technical method of the present invention and not to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A method for constructing a 0DAY vulnerability detection model based on an AI big model, characterized in that: The following steps are involved: Collect normal running codes of various functions and implementations from open source projects, obtain known vulnerability instances and their contexts through public vulnerability databases, annotate the vulnerability locations, and form a vulnerability detection dataset with normal running codes; Through AST abstract syntax tree replacement technology, non-system code functions in the dataset are replaced with kernel APIs, and simulated vulnerability patterns are inserted into legitimate code; Filter the source code with 0DAY vulnerabilities in the legitimate code, generate adversarial samples containing "valid verification but vulnerabilities still exist" through GAN, and add them to the vulnerability detection dataset; According to the function and structure of the code, the data set is divided into multiple levels, and the syntax features, execution path features, and inter-function relationship features of the code at each level are extracted; Use different dynamic analysis strategies and static analysis strategies for different levels of code, and analyze the corresponding dynamic analysis results and static analysis results; Based on the results of dynamic and static analysis, as well as the syntax features, execution path features, and inter-function relationship features of each level of code, we train 0DAY vulnerability detection models for different levels of code by combining the Transformer model and convolutional neural network algorithm. Analyzing the corresponding dynamic analysis results and static analysis results includes the following steps: For the application layer code in the vulnerability detection dataset, extract the error information of dynamic analysis and the error ratio and security vulnerability quantity data in the security vulnerability data; By calculating the dynamic analysis evaluation value V1 = a1*error ratio + a2*(security vulnerability quantity data / 100), a1 and a2 are corresponding weights, and the extracted data and the dynamic analysis evaluation value are taken together as the dynamic analysis result; Extract code quality scores and security vulnerability lists from static analysis results of application layer codes; By calculating the static analysis evaluation value E1 = b1*(the number of 0DAY vulnerabilities marked as security vulnerabilities / the total number of security vulnerabilities)+b2*[(100-code quality score) / 100], b1 and b2 are the corresponding weights, and the extracted data and the static analysis evaluation value are taken together as the static analysis result; For the service layer code in the vulnerability detection dataset, extract the API response time and error rate of dynamic analysis, as well as the number of security vulnerabilities and the number of 0DAY vulnerabilities annotated by security vulnerabilities; By calculating the dynamic analysis evaluation value V2 = a3*(API response time / 100+error rate)+a4*(number of 0DAY vulnerabilities marked as security vulnerabilities / total number of security vulnerabilities), a3 and a4 are corresponding weights, and the extracted data and dynamic analysis evaluation value are taken together as the dynamic analysis result; Extract the code quality score and security vulnerability list from the static analysis results of the service layer code; By calculating the static analysis evaluation value E2 = b3*(number of interface contract consistency standards / total number of interface contract tests)+b4*[(100-code quality score) / 100], b3 and b4 are corresponding weights, and the extracted data and static analysis evaluation value are taken together as the static analysis result; For the data access layer code in the vulnerability detection dataset, extract the database query response time and error rate for dynamic analysis, as well as the number of SQL injection anomalies; By calculating the dynamic analysis evaluation value V3 = a5*(database query response time / 100+error rate)+a6*(number of SQL injection anomalies / total number of security vulnerabilities), a5 and a6 are corresponding weights, and the extracted data and the dynamic analysis evaluation value are taken together as the dynamic analysis result; Extract the number of potential SQL injection points from the static analysis results of the data access layer code and the list of potential vulnerabilities in the ORM configuration; By calculating the static analysis evaluation value E3 = b5*(number of potential SQL injection points / 100)+b6*[number of potential vulnerabilities in ORM configuration / 100], b5 and b6 are corresponding weights, the extracted data and the static analysis evaluation value are taken together as the static analysis result; For the system-level code in the vulnerability detection dataset, extract the abnormal times of CPU, memory and disk I / O usage data for dynamic analysis and the vulnerability data detected by penetration testing; By calculating the dynamic analysis evaluation value V4 = a7* (the proportion of 0DAY vulnerabilities marked in the vulnerabilities detected by the penetration test) + a8* (the number of abnormal CPU, memory and disk I / O usage data / 100), a7 and a8 are the corresponding weights, and the extracted data and the dynamic analysis evaluation value are taken together as the dynamic analysis result; Extract the number of vulnerabilities and security risk factors of underlying system components from the static analysis results of system-level code, as well as the number of non-compliant codes in source code audits; By calculating the static analysis evaluation value E4=b7*(the percentage of non-compliant code in the source code audit)+b8*[the number of vulnerabilities in the underlying system components / the sum of the number of vulnerabilities in the underlying system components and the number of security risk factors], b7 and b8 are the corresponding weights, and the extracted data and the static analysis evaluation value are taken together as the static analysis results.

2. According to the method for constructing a 0DAY vulnerability detection model based on an AI large model according to claim 1, it is characterized in that: Through the AST abstract syntax tree replacement technology, the non-system code functions in the dataset are replaced with kernel APIs, and the simulated vulnerability patterns are inserted into the legitimate code, including the following steps: The source code is converted into a tree representation of the source code by a parser of the programming language; in the tree representation of the source code, each node represents a syntax element; Traverse the tree representation of the source code, identify non-system functions according to the function name, parameter and return value characteristics, identify the non-system functions as function nodes that need to be replaced, and randomly select a number of non-system functions from them. Replace the non-system functions with non-system functions with 0DAY vulnerabilities by randomly combining the non-system functions, modifying the input format or content, allowing input conditional triggering, and renaming variables, functions and classes, and mark the vulnerability locations; Determine all non-system functions of function nodes that need to be replaced and their corresponding kernel APIs, and replace them with corresponding kernel API nodes; The tree representation of the replaced source code is converted back into executable code.

3. According to the method for constructing a 0DAY vulnerability detection model based on an AI large model according to claim 1, it is characterized in that: Screening legitimate code for source code with 0DAY vulnerabilities includes the following steps: Filter legitimate code that has vulnerabilities marked and source code that does not have 0DAY vulnerabilities marked; The vulnerability location of the code is converted into 0DAY vulnerability code by modifying the input format or content, allowing input condition triggering, and renaming variables, functions, and classes, and 0DAY vulnerability is marked; Filter out the source code marked with 0DAY vulnerability.

4. According to the method for constructing a 0DAY vulnerability detection model based on an AI big model according to claim 1, it is characterized in that: The screened source code is used to generate adversarial samples containing "valid verification but vulnerabilities still exist" through GAN, and added to the vulnerability detection dataset, including the following steps: For the source code marked with 0DAY vulnerabilities, insert the simulated vulnerability pattern at a selected position in the source code; Use the code with simulated vulnerability patterns inserted as the training set, and combine normal code and known vulnerability samples to form an adversarial training set; The GAN model generator is trained through the adversarial training set to create new samples so that the discriminator can identify them as real samples, and the GAN model discriminator is trained to learn to distinguish between real samples and generated samples, and feedback is given to the generator to improve its output; Add the obtained new samples to the vulnerability detection dataset.

5. According to the method for constructing a 0DAY vulnerability detection model based on an AI big model according to claim 1, it is characterized in that: According to the function and structure of the code, the dataset is divided into multiple levels, and the syntax features, execution path features, and inter-function relationship features of the code at each level are extracted, including the following steps: According to the function and structure of the code, the vulnerability detection data set is divided into multiple layers, including: application layer, service layer, data access layer and system layer; the application layer is user interaction logic and input processing code, the service layer is API call and business logic processing, the data access layer is database operation and data transmission, and the system layer is system call and underlying implementation; For each level of code, syntactic features are extracted through AST, execution path features are extracted through CFG control flow graph, and relationship features between functions are extracted through Call Graph function call graph.

6. According to the method for constructing a 0DAY vulnerability detection model based on an AI big model according to claim 1, it is characterized in that: Different dynamic analysis strategies and static analysis strategies are used for different levels of code, including the following steps: For the application layer code in the vulnerability detection dataset, the dynamic analysis strategy includes: Use the Selenium tool to simulate user interactions, test the application's response to various common inputs, and use the OWASP ZAP fuzz testing tool to attack the application and identify potential security vulnerabilities; Obtain error information and security vulnerability data of application layer code under simulated user behavior; Static analysis strategies for application layer code include: Check code quality through SonarQube static code analysis tool, identify security vulnerabilities in the code and annotate zero-day vulnerabilities; Generate reports, including code quality scores and security vulnerability lists; For the service layer code in the vulnerability detection dataset, the dynamic analysis strategy includes: Perform load testing and security testing through RESTful or SOAP APIs, as well as the return results of regular requests, and monitor service requests and responses in real time; Collect API response time, error rate, and security vulnerability information; The static analysis strategy for the service layer code includes: Verify the consistency between service interface definition and implementation, and check the quality of service layer code through static analysis tools; Generate interface contract consistency report and code quality assessment report; For the code of the data access layer in the vulnerability detection dataset, the dynamic analysis strategy includes: Detect transaction processing performance by simulating concurrent database query operations, and identify potential performance anomalies or SQL injections by monitoring SQL query execution plans and performance; Record database query performance indicators and SQL injection anomalies; The static analysis strategy for the access layer code includes: Detect potential injection risks in SQL query construction through static code analysis tools and check the configuration of ORM object-relational mapping; Generate SQL injection risk assessment report and ORM usage review report; For the system-level code in the vulnerability detection dataset, the dynamic analysis strategy includes: Monitor the usage of system-level resources in real time, obtain CPU, memory and disk I / O usage data, system performance indicators, and conduct comprehensive penetration testing on the system to identify system-level code vulnerabilities; Collect system performance data and vulnerability information discovered by penetration testing; System-level code, static analysis strategy, including: Perform source code audit on underlying system components and generate configuration review reports and source code audit reports.

7. According to the method for constructing a 0DAY vulnerability detection model based on an AI big model according to claim 1, it is characterized in that: For different levels of code, the Transformer model and convolutional neural network algorithm are combined to train the 0DAY vulnerability detection model for different levels of code, including the following steps: Obtain the dynamic analysis results and static analysis results of code extraction in the vulnerability detection dataset, as well as the syntax features, execution path features, and inter-function relationship features of each level of code; Add a fusion input layer before the input layer of the Transformer model and the convolutional neural network model, and add an analysis output layer after the output layer of the Transformer model and the convolutional neural network model; The fusion input layer inputs the dynamic analysis results and static analysis results of the corresponding layers, as well as the syntax features of the code, into the Transformer model, and inputs the execution path features and inter-function relationship features into the convolutional neural network model; Analyze the output layer to obtain the output results of the Transformer model and the output results of the convolutional neural network model for weighted fusion to obtain the final 0DAY vulnerability detection results; For codes at different levels, the vulnerability detection dataset is concentrated, the extracted data is input into the fusion input layer for model training, and the 0DAY vulnerability detection model of codes at different levels is obtained to detect 0DAY vulnerabilities in the code.

8. A 0DAY vulnerability detection model construction device based on AI big model, characterized in that: The system adopts a 0DAY vulnerability detection model construction method based on an AI large model as described in any one of claims 1 to 7 to realize the construction of a 0DAY vulnerability detection model, including: Dataset generation module: collects normal running codes of various functions and implementations from open source projects, obtains known vulnerability instances and their contexts through public vulnerability databases, annotates the vulnerability locations, and forms a vulnerability detection dataset with normal running codes; Dataset expansion module: Use AST abstract syntax tree replacement technology to replace non-system code functions in the dataset with kernel APIs, and insert simulated vulnerability patterns into legitimate code; filter source code with 0DAY vulnerabilities in legitimate code, and generate adversarial samples containing "valid verification but vulnerabilities still exist" through GAN from the filtered source code, and add them to the vulnerability detection dataset; Data analysis module: divides the data set into multiple levels according to the function and structure of the code, and extracts the syntax features, execution path features, and inter-function relationship features of the code at each level; adopts different dynamic analysis strategies and static analysis strategies for codes at different levels, and analyzes the corresponding dynamic analysis results and static analysis results; Vulnerability detection model building module: Based on the dynamic analysis results and static analysis results, as well as the syntax features, execution path features, and inter-function relationship features of each level of code, the Transformer model and convolutional neural network algorithm are combined to train 0DAY vulnerability detection models for different levels of code.

9. A computing device comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of a method for constructing a 0DAY vulnerability detection model based on an AI large model as described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Software vulnerability detection method and device based on graph convolution network

    CN111611586A

  • Intelligent contract vulnerability detection method and system based on improved PGD adversarial network

    CN119416222A