Risk propagation path identification method based on Rust supply chain structure diagram
By analyzing the package manager configuration file, building a Rust software supply chain structure chart, and using the breadth priority method to identify the risk transmission path, the problem of lack of effective identification and visualization of the risk transmission path of the Rust software supply chain in the existing technology is solved, and rapid and accurate risk management and visual display are achieved.
Patent Information
- Application Number
- CN202510042320.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-05-13
AI Technical Summary
The existing technology lacks effective methods to identify and visualize risk transmission paths in the Rust software supply chain, making it difficult for developers to quickly confirm the maintenance status and supply chain structure of third-party libraries.
By analyzing the package manager configuration file, a Rust-based supply chain structure diagram is built, the maintenance status of nodes is identified, and the dependencies in the structure diagram are used to identify the risk propagation path and visually display it.
It realizes the rapid and accurate construction of the software supply chain structure chart, effectively identify the maintenance status of the library, clearly visualize the risk transmission path, and helps developers quickly understand and manage risks in the software supply chain.
Smart Images

Figure CN119989358A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a risk propagation path identification method based on a Rust supply chain structure diagram, belongs to the technical field of software security, and is applied to Rust software supply chain dependency management. Background Art
[0002] Using third-party libraries for software development can speed up the speed and quality of software development, but these libraries may stop being maintained due to lack of development time, shifting interests, etc. These unmaintained third-party libraries will not only affect their users, but also their indirect users. Cargo, the package manager for the Rust language, does not provide a formal way to abandon a library, so library users need to spend a lot of time manually collecting information to confirm the maintenance status of the library. At the same time, a project often uses a certain number of third-party libraries, which will cost developers a lot of time.
[0003] At present, there is still a lack of relevant products and technologies to help developers understand the maintenance status of each software in the software supply chain. In order to help Rust developers quickly confirm the maintenance status of third-party libraries used in the project and clearly understand the supply chain structure of these libraries, a targeted solution for identifying risk propagation paths can be developed.
[0004] Therefore, how to identify and visualize the existing Rust supply chain risk propagation path has become an urgent problem to be solved. Summary of the invention
[0005] The purpose of the present invention is to solve the technical problem of visualizing the existing Rust supply chain risk propagation path identification, and propose a risk propagation path identification method based on the Rust supply chain structure diagram.
[0006] The present invention constructs a Rust-based supply chain structure diagram by parsing the package manager configuration file, determines the maintenance status of the nodes in the structure diagram to obtain risk nodes, and utilizes the dependency relationship of the nodes in the structure diagram to further identify the risk propagation path.
[0007] The objective of the present invention is achieved through the following technical solutions:
[0008] A risk propagation path identification method based on a Rust supply chain structure diagram of the present invention is applied to a Rust third-party library dependency management scenario, and includes the following steps:
[0009] Step 1: Parse the Rust software supply chain using the content of the package manager configuration file Cargo.toml as input;
[0010] Step 1.1: Get the contents of the Rust project's package manager configuration file Cargo.toml;
[0011] Step 1.2: Create the directory structure of the package manager; place the configuration file in the corresponding location of the directory structure;
[0012] Step 1.3: Use the package manager to build and generate the package manager Cargo.lock file corresponding to the directory structure;
[0013] Step 1.4: Get the library name, version, and dependencies between libraries from the Cargo.lock file;
[0014] Step 2: Perform Rust software supply chain analysis on the name of the uploaded software package in crates.io, the Rust package storage center;
[0015] Step 2.1: Create the package manager configuration file Cargo.toml;
[0016] Step 2.2: Put the uploaded software package in crates.io, the Rust package storage center, as the only dependency into the dependencies area of Cargo.toml to form the Cargo.toml content containing the dependency on the software package;
[0017] Step 2.3: Execute step 1 to obtain the name, version and dependency relationship between the dependent libraries of the input software package;
[0018] Step 3: Screen and identify the active status of the dependent libraries obtained in steps 1 and 2;
[0019] Step 3.1: Use the open source repository commit time, version release time, and the time interval between adjacent version releases to filter out inactive dependent libraries;
[0020] Step 3.2: Use active declaration to filter out the abandoned dependency libraries from the inactive dependency libraries;
[0021] Step 3.3: Treat the dependent libraries that are not marked as inactive or abandoned as normal dependent libraries;
[0022] Step 4: Use the interactive method of web applications to visualize the dependencies between libraries and the active status of libraries;
[0023] Step 4.1: Use dependent libraries as nodes and the dependency relationships between libraries as edges to construct a directed graph of the supply chain;
[0024] Step 4.2: Color-code the nodes of the directed graph of the supply chain according to the active status of the library;
[0025] Step 4.3: Display the library name and version on the node in a visual way;
[0026] Step 5: Use the breadth-first method to obtain the Rust supply chain risk propagation path and visualize it;
[0027] Step 5.1: Take the input package as the root node;
[0028] Step 5.2: Use the breadth-first method to construct the path from the root node to the inactive state and abandoned state nodes, thereby forming the supply chain risk propagation path;
[0029] Step 5.3: Visualize the supply chain risk propagation path;
[0030] Beneficial effects:
[0031] Compared with the prior art, the present invention has the following effects:
[0032] 1. The present invention adopts the technical means of generating parsing results by the package manager's own construction mechanism, so as to achieve the effect of quickly and accurately constructing the software supply chain structure diagram;
[0033] 2. The present invention realizes effective identification of the maintenance status of a library by collecting the development indicators of the library and identifying the technical means that the developer actively declares to be abandoned. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 It is a schematic diagram of the process of the present invention;
[0035] Figure 2 It is a schematic diagram of the web application of the present invention after the configuration file content is input on the home page;
[0036] Figure 3 It is a schematic diagram of the home page of the Web application of the present invention;
[0037] Figure 4 is a schematic diagram of a software package search result interface of a Web application of the present invention;
[0038] Figure 5 It is a schematic diagram of the present invention analyzing the supply chain structure and displaying the maintenance status of each library;
[0039] Figure 6 It is a schematic diagram showing the risk propagation path of Web applications of the present invention. DETAILED DESCRIPTION
[0040] In order to better illustrate the purpose and advantages of the present invention, the invention is further described below in conjunction with the accompanying drawings and examples. It should be noted that the implementation of the present invention is not limited to the following embodiments, and any form of modification or change made to the present invention will fall within the protection scope of the present invention.
[0041] Example
[0042] like Figure 1 As shown, a risk propagation path identification method based on the Rust supply chain structure diagram of this embodiment is specifically implemented in the following steps:
[0043] Step 1: Parse the Rust software supply chain using the content of the package manager configuration file Cargo.toml as input;
[0044] Step 1.1: Get the contents of the Rust project's package manager configuration file Cargo.toml;
[0045] In the embodiment, Figure 2 As shown, enter the content of the Cargo.toml file of the Rust project to be parsed in the text input box at the bottom of the two input boxes. After clicking the Submit button, you can jump to the software supply chain structure diagram generation interface.
[0046] Step 1.2: Create the directory structure of the package manager; place the configuration file in the corresponding location of the directory structure;
[0047] Step 1.3: Use the package manager to build and generate the package manager Cargo.lock file corresponding to the directory structure;
[0048] Step 1.4: Get the library name, version, and dependencies between libraries from the Cargo.lock file;
[0049] Step 2: Perform Rust software supply chain analysis on the name of the uploaded software package in crates.io, the Rust package storage center;
[0050] Step 2.1: Create the package manager configuration file Cargo.toml;
[0051] Step 2.2: Put the uploaded software package in crates.io, the Rust package storage center, as the only dependency into the dependencies area of Cargo.toml to form the Cargo.toml content containing the dependency on the software package;
[0052] In the embodiment, Figure 3As shown in the figure, enter the software name you want to search in the text input box on the upper side of the two input boxes, such as ffp. After clicking the search button, the page will jump to the software package selection page, such as Figure 4 After selecting the version 1.3.0 of the software package you want to query, the system places the software package name and version number under the dependencies area of Cargo.toml, indicating the library and corresponding version that need to be parsed.
[0053] Step 2.3: Execute step 1 to obtain the name, version and dependency relationship between the dependent libraries of the input software package;
[0054] In the embodiment, the system will generate a temporary folder to form the project structure required by the package manager. After the Cargo.lock file is generated using the Cargo build command, the Cargo.lock file content is read to obtain the dependent library name, version and the dependency relationship between them, and finally the temporarily generated folder is deleted.
[0055] Step 3: Screen and identify the active status of the dependent libraries obtained in steps 1 and 2;
[0056] Step 3.1: Use the open source repository commit time, version release time, and the time interval between adjacent version releases to filter out inactive dependent libraries;
[0057] In the embodiment, when a library meets the following three conditions at the same time, the library will be judged as inactive: 1) the corresponding open source repository has not been committed for more than one year; 2) the project has not released a new version for more than one year; 3) the time when the project stopped releasing new versions exceeds the maximum interval between the release times of any two adjacent versions of the project.
[0058] Step 3.2: Use active declaration to filter out the abandoned dependency libraries from the inactive dependency libraries;
[0059] In the embodiment, the following seven methods are used to determine whether a project has stopped maintenance. If a library meets at least one of the conditions, the library is determined to be an abandoned library: 1) All versions of the project are marked as abandoned (yanked); 2) The open source repository corresponding to the project in GitHub is already in an archived state (archived); 3) The project has used an abandoned badge on crates.io; 4) The project has been declared abandoned in the introduction document (README) on the crates.io homepage; 5) The description content of the project on the crates.io homepage uses text to declare abandonment; 6) The project has been declared abandoned in the introduction document (README) on the GitHub homepage; 7) The description content of the project on the GitHub homepage uses text to declare abandonment;
[0060] Step 3.3: Treat the dependent libraries that are not marked as inactive or abandoned as normal dependent libraries;
[0061] Step 4: Use the interactive method of web applications to visualize the dependencies between libraries and the active status of libraries;
[0062] Step 4.1: Use dependent libraries as nodes and the dependency relationships between libraries as edges to construct a directed graph of the supply chain;
[0063] Step 4.2: Color-code the nodes of the directed graph of the supply chain according to the active status of the library;
[0064] Step 4.3: Display the library name and version on the node in a visual way;
[0065] In the embodiment, Figure 5 As shown in the figure, the software supply chain structure diagram page shows the dependency relationship between all upstream dependent libraries of the 1.3.0 version of the library ffp. The nodes corresponding to inactive libraries are marked in orange, the abandoned library nodes are marked in red, and the other nodes are marked in green. This system uses D3.js to visualize the parsed dependency graph and uses the Flask framework to build the web page.
[0066] Step 5: Use the breadth-first method to obtain the Rust supply chain risk propagation path and visualize it;
[0067] Step 5.1: Take the input package as the root node;
[0068] Step 5.2: Use the breadth-first method to construct the path from the root node to the inactive state and abandoned state nodes, thereby forming the supply chain risk propagation path;
[0069] Step 5.3: Visualize the supply chain risk propagation path;
[0070] In the embodiment, Figure 6 As shown in the figure, after clicking the library named winapi-i686-pc-windows-gnu in the inactive library list, the system will use the breadth-first algorithm to obtain all paths from the root node to the selected library and present them in a visual way, thereby helping developers understand how libraries with maintenance risks are introduced into the project.
[0071] The specific description above further illustrates the purpose, technical solutions and beneficial effects of the invention in detail. It should be understood that the above is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A risk propagation path identification method based on Rust supply chain structure diagram, characterized by: The following steps are included: Step 1: Parse the Rust software supply chain using the content of the package manager configuration file Cargo.toml as input; Step 2: Perform Rust software supply chain analysis on the name of the uploaded software package in crates.io, the Rust package storage center; Step 3: Screen and identify the active status of the dependent libraries obtained in steps 1 and 2; Step 3.1: Use the open source repository commit time, version release time, and the time interval between adjacent version releases to filter out inactive dependent libraries; Step 3.2: Use active declaration to filter out the abandoned dependency libraries from the inactive dependency libraries; Step 3.3: Treat the dependent libraries that are not marked as inactive or abandoned as normal dependent libraries; Step 4: Use the interactive method of web applications to visualize the dependencies between libraries and the active status of libraries; Step 4.1: Use dependent libraries as nodes and the dependency relationships between libraries as edges to construct a directed graph of the supply chain; Step 4.2: Color-code the nodes of the directed graph of the supply chain according to the active status of the library; Step 4.3: Display the library name and version on the node in a visual way; Step 5: Use the breadth-first method to obtain the Rust supply chain risk propagation path and visualize it; Step 5.1: Take the input package as the root node; Step 5.2: Use the breadth-first method to construct the path from the root node to the inactive and abandoned nodes, thereby forming the supply chain risk propagation path; Step 5.3: Visualize the supply chain risk propagation path.
2. A risk propagation path identification method based on Rust supply chain structure diagram as claimed in claim 1, characterized in that: Step 1 is implemented as follows: Step 1.1: Get the contents of the Rust project's package manager configuration file Cargo.toml; Step 1.2: Create the directory structure of the package manager; place the configuration file in the corresponding location of the directory structure; Step 1.3: Use the package manager to build and generate the package manager Cargo.lock file corresponding to the directory structure; Step 1.4: Get the library name, version, and dependencies between libraries from the Cargo.lock file.
3. The risk propagation path identification method based on the Rust supply chain structure diagram according to claim 1 is characterized in that: Step 2 is implemented as follows: Step 2.1: Create the package manager configuration file Cargo.toml; Step 2.2: Put the uploaded software package in crates.io, the Rust package storage center, as the only dependency into the dependencies area of Cargo.toml to form the Cargo.toml content containing the dependency on the software package; Step 2.3: Execute step 1 to obtain the name and version of the dependent library of the input software package and the dependency relationship between the libraries.