Code auditing method and device, electronic equipment, storage medium and program product
By automatically auditing code using large language model (LLM) and small speculative model (SSM), the problems of low efficiency and low coverage in the existing technology are solved, and more efficient and comprehensive code audits are achieved.
Patent Information
- Application Number
- CN202510065054.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-13
AI Technical Summary
In the prior art, code audits rely on manual audits, resulting in low audit efficiency, low coverage and high requirements for auditors.
The large language model (LLM) is used to perform automated auditing of the audit code module. By obtaining and adjusting the parameters of the LLM, SSM is used to audit the code in groups, and the audit results are finally verified by the LLM.
It improves the efficiency and coverage of code audits, reduces the requirements for auditors, and can directly output vulnerability modification suggestions.
Smart Images

Figure CN119989363A_ABST
Abstract
Description
Background Art
[0002] During the development of applications or application systems, the developed codes usually have security vulnerabilities. If they are not discovered in time, they will bring great security risks to the applications or application systems after they are launched.
[0003] In the related art, vulnerabilities in the code are discovered by manually auditing the code. Manual code auditing mainly involves manually reviewing the source code by experienced professional technicians to obtain audit results.
[0004] However, manual code auditing places high demands on auditors, has low efficiency, and the audit results have low coverage of vulnerabilities in the code (it is difficult to discover all vulnerabilities in the code). Summary of the invention
[0005] The present application provides a code auditing method, device, electronic device, storage medium and program product, which at least to a certain extent overcome the problems in the related technology of high requirements for auditors, low efficiency, and low coverage of vulnerabilities in the code by the audit results.
[0006] Other features and advantages of the present application will become apparent from the following detailed description, or may be learned in part by the practice of the present application.
[0007] According to one aspect of the present application, a code auditing method is provided, which is applied to an auditing device, including: obtaining an LLM (Large Language Model); obtaining N code modules to be audited that belong to the same business logic, where N is an integer greater than 1; and auditing the N code modules to be audited according to the LLM to obtain an audit result, which includes the location, type and modification suggestions of the vulnerability.
[0008] In some embodiments, obtaining a large language model LLM includes: obtaining an initial LLM; obtaining a code sample corresponding to the business logic, the code sample having the same compilation style as the N code modules to be audited, the code sample including at least one pair of code snippets, each pair of code snippets including a code snippet with known vulnerabilities and a secure code snippet; adjusting the parameters of the initial LLM according to the code sample to obtain the LLM.
[0009] In some embodiments, the adjusting the parameters of the initial LLM according to the code sample to obtain the LLM includes: obtaining at least one code comment sample, the at least one code comment sample has the same compilation style as the N code modules to be audited, and each code comment sample includes a code segment and a corresponding comment; according to the at least one code comment sample, training the initial LLM's ability to add code comments to obtain an intermediate LLM; obtaining a first prompt content, the first prompt content is used to prompt the intermediate LLM to add comments to the code sample; inputting the code sample and the first prompt content into the intermediate LLM, and generating a code sample with comments through the intermediate LLM; according to the code sample with comments, training the intermediate LLM's ability to audit code to obtain the LLM.
[0010] In some embodiments, the audit device includes M processing cores, each processing core has a corresponding computing frequency, M≤N, M is an integer greater than 1, and each code module to be audited has a corresponding number of code lines; the N code modules to be audited are audited according to the LLM to obtain audit results, including: obtaining M SSMs (small speculation models); dividing the N code modules to be audited into M groups according to the computing frequency of each processing core and the number of code lines of each code module to be audited, to obtain M groups of code modules to be audited; applying an SSM in each processing core to audit a group of code modules to be audited to obtain M intermediate results; verifying the M intermediate results through the LLM, and if the verification passes, using the M intermediate results as the audit results.
[0011] In some embodiments, the method of dividing the N code modules to be audited into M groups according to the calculation frequency of each processing core and the number of code lines of each code module to be audited to obtain M groups of code modules to be audited includes: determining an allocation method for allocating the N code modules to be audited to the M processing cores to obtain C(N+M-1, M-1) allocation methods; determining the ratio of the total number of lines of code modules to be audited corresponding to each processing core to the calculation frequency under each allocation method to obtain C(N+M-1, M-1) ratio groups; determining the maximum value in each ratio group to obtain C(N+M-1, M-1) maximum ratios; taking the allocation method corresponding to the minimum value of the C(N+M-1, M-1) maximum ratios as the target allocation method; and dividing the N code modules to be audited into M groups according to the target allocation method to obtain M groups of code modules to be audited.
[0012] In some embodiments, an SSM is applied in each processing core to audit a group of code modules to be audited and obtain M intermediate results, including: in each processing core, for the group of code modules to be processed corresponding to the processing core, the following processing is performed: the group of code modules to be audited is converted into AST (abstract syntax tree); a second prompt content is obtained, and input content is constructed according to the second prompt content, the AST and the group of code modules to be audited; the input content is input into the SSM, and the SSM audits the group of code modules to be audited according to the input content to obtain an intermediate result.
[0013] According to another aspect of the present application, a code auditing device is also provided, which is applied to an auditing device, including: a first acquisition module, used for LLM; a second acquisition module, used to obtain N code modules to be audited belonging to the same business logic, N is an integer greater than 1; an auditing module, used to audit the N code modules to be audited according to the LLM to obtain an audit result, and the audit result includes the location, type and modification suggestions of the vulnerability.
[0014] In some embodiments, the first acquisition module is used to obtain an initial LLM; obtain a code sample corresponding to the business logic, the code sample has the same compilation style as the N code modules to be audited, and the code sample includes at least one pair of code snippets, each pair of code snippets includes a code snippet with known vulnerabilities and a secure code snippet; adjust the parameters of the initial LLM according to the code sample to obtain the LLM.
[0015] In some embodiments, the first acquisition module is used to acquire at least one code comment sample, at least one code comment sample has the same compilation style as the N code modules to be audited, and each code comment sample includes a code segment and a corresponding comment; according to the at least one code comment sample, the ability of the initial LLM to add code comments is trained to obtain an intermediate LLM; a first prompt content is acquired, and the first prompt content is used to prompt the intermediate LLM to add comments to the code sample; the code sample and the first prompt content are input into the intermediate LLM, and a code sample with comments is generated by the intermediate LLM; according to the code sample with comments, the ability of the intermediate LLM to audit code is trained to obtain the LLM.
[0016] In some embodiments, the audit device includes M processing cores, each processing core has a corresponding computing frequency, M≤N, M is an integer greater than 1, and each code module to be audited has a corresponding number of code lines; the audit module is used to obtain M SSMs; according to the computing frequency of each processing core and the number of code lines of each code module to be audited, the N code modules to be audited are divided into M groups to obtain M groups of code modules to be audited; one SSM is applied to each processing core to audit a group of code modules to be audited to obtain M intermediate results; the M intermediate results are verified by the LLM, and if the verification is passed, the M intermediate results are used as the audit results.
[0017] In some embodiments, the audit module is used to determine an allocation method for allocating the N code modules to be audited to the M processing cores, and obtain C(N+M-1, M-1) allocation methods; determine the ratio of the total number of lines of the code modules to be audited corresponding to each processing core to the calculation frequency under each allocation method, and obtain C(N+M-1, M-1) ratio groups; determine the maximum value in each ratio group, and obtain C(N+M-1, M-1) maximum ratios; take the allocation method corresponding to the minimum value of the C(N+M-1, M-1) maximum ratios as the target allocation method; according to the target allocation method, divide the N code modules to be audited into M groups, and obtain M groups of code modules to be audited.
[0018] In some embodiments, the audit module is used to perform the following processing in each processing core for the code module group to be processed corresponding to the processing core: convert the code module group to be audited into an abstract syntax tree AST; obtain a second prompt content, and construct input content based on the second prompt content, the AST and the code module group to be audited; input the input content into the SSM, and the SSM audits the code group to be audited based on the input content to obtain an intermediate result.
[0019] According to another aspect of the present application, an electronic device is also provided, which includes: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any one of the above-mentioned code auditing methods by executing the executable instructions.
[0020] According to another aspect of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the code auditing method described in any one of the above is implemented.
[0021] According to another aspect of the present application, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the code auditing method described above is implemented.
[0022] The technical solutions provided in the embodiments of the present application include at least the following intended effects:
[0023] The technical solution provided in the embodiments of the present application, by utilizing LLM to audit the code module to be audited, has higher audit efficiency, lower requirements for auditors, and high coverage of vulnerabilities in the code by the audit results compared to manual audit code.
[0024] Furthermore, by using LLM to audit the code, you can also directly output modification suggestions for the audited vulnerabilities, which is conducive to completing the code modification work more quickly. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] The drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present application, and together with the specification are used to explain the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0026] Figure 1 A schematic diagram of a code audit system in one embodiment of the present application is shown;
[0027] Figure 2 A flowchart of a code audit method in one embodiment of the present application is shown;
[0028] Figure 3 A schematic diagram of a code auditing device in one embodiment of the present application is shown;
[0029] Figure 4 A structural block diagram of an electronic device in one embodiment of the present application is shown. DETAILED DESCRIPTION
[0030] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more comprehensive and complete and fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0031] In addition, the accompanying drawings are only schematic illustrations of the present application and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and thus their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.
[0032] It should be noted that the acquisition, storage, use, and processing of data in the technical solution of this application comply with the relevant provisions of national laws and regulations, and various types of data such as personal identity data, operation data, behavioral data, etc. related to individuals, customers, and groups obtained in the embodiments of this application have all been authorized.
[0033] For ease of understanding, before introducing the embodiments of the present application, several terms involved in the embodiments of the present application are first explained as follows:
[0034] Code module to be audited: encapsulated from a piece of code, usually used to implement some functions in a certain business logic;
[0035] Compilation style: Different applications or application systems have requirements for compilation methods and styles. The compilation style includes the logic at compile time.
[0036] Prompt content: used to assist the large model in generating output results. For example, please output the preset content according to the following text (the preset content can be English translation, etc.).
[0037] The specific implementation of the embodiment of the present application is described in detail below in conjunction with the accompanying drawings.
[0038] Figure 1 A schematic diagram of a code audit system in an embodiment of the present application is shown. Figure 1 As shown, the system may include: an audit device 11 and a code providing device 12.
[0039] The code providing device 12 stores code modules to be audited, code samples, and code annotation samples, and the code providing device 12 can send any one of the code modules to be audited, code samples, and code annotation samples to the auditing device 11 .
[0040] The audit device 11 may receive the code module to be audited, the code sample, and the code comment sample sent by the code providing device 12 , or the audit device 11 may actively download the code module to be audited, the code sample, and the code comment sample from the code providing device 12 .
[0041] Alternatively, any one of the code module to be audited, the code sample, and the code comment sample can be directly edited in the audit device 11 .
[0042] The audit device 11 may obtain the service interface of the LLM and apply the LLM through the service interface. Alternatively, the audit device 11 carries the LLM, which is not limited in the present application.
[0043] The audit device 11 may also obtain service interfaces of multiple SSMs and apply the multiple SSMs through the service interfaces.
[0044] The audit device 11 can fine-tune the parameters of the LLM according to the code samples and the code comment samples, so that the LLM can better audit the codes in the audit code module.
[0045] Regarding how the audit device 11 specifically audits the audit code module, please refer to the corresponding embodiment of the audit method, which will not be described here in detail.
[0046] The network is used as a medium to provide a communication link between the audit device 11 and the code providing device 12, and can be a wired network or a wireless network.
[0047] Optionally, the wireless network or wired network described above uses standard communication technology and / or protocol. The network is typically the Internet, but may also be any network, including but not limited to a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a dedicated network or any combination of a virtual private network). In some embodiments, technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged over the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPSec) and the like may be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies may also be used to replace or supplement the above-mentioned data communication technologies.
[0048] The audit device 11 and the code providing device 12 may be various electronic devices, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, etc.
[0049] The audit device 11 and the code providing device 12 can be servers that provide various services. The server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0050] Under the above system architecture, a code audit method is provided in an embodiment of the present application, and the method can be executed by any electronic device with computing and processing capabilities. For example, the electronic device is an audit device.
[0051] Figure 2 A flow chart of a code audit method in an embodiment of the present application is shown as follows: Figure 2 As shown, the code auditing method provided in the embodiment of the present application includes the following S201 to S203.
[0052] S201, obtain LLM.
[0053] Among them, LLM can be any large language model, for example, GTP-4, Wenxinyiyan, etc.
[0054] In one embodiment, obtaining the LLM may be obtaining a service interface of the LLM, so as to apply the LLM through the service interface.
[0055] In another embodiment, obtaining the large language model LLM includes: obtaining an initial LLM; obtaining a code sample corresponding to the business logic, the code sample having the same compilation style as the N code modules to be audited, the code sample including at least one pair of code snippets, each pair of code snippets including a code snippet with known vulnerabilities and a secure code snippet; adjusting the parameters of the initial LLM according to the code sample to obtain the LLM.
[0056] The initial LLM may be obtained by directly downloading the initial LLM, or by obtaining a service interface of the initial LLM so as to apply the initial LLM.
[0057] In one embodiment, the code sample may be compiled by a person who compiles the code module to be audited, or may be automatically generated by other large models, and the embodiments of the present application do not limit this.
[0058] The embodiments of the present application do not limit how to adjust the parameters of the initial LLM according to the code sample. In one embodiment, the code sample can be input into the LLM, and input prompt content can be added to facilitate the LLM to learn the code snippets with known vulnerabilities and safe code snippets in the code sample, so as to be able to identify the vulnerabilities in the code of unknown vulnerabilities.
[0059] The embodiments of the present application do not limit the specific content of the prompt content. For example, the prompt content may be: Please learn how to identify vulnerabilities in the code based on the vulnerable code snippets and safe code snippets in the following code samples.
[0060] By adjusting the parameters of LLM using code samples of the same compilation style, LLM can better identify vulnerabilities in the code module to be audited and better audit the code module to be audited.
[0061] In another embodiment, the parameters of the initial LLM are adjusted according to the code sample to obtain the LLM, including: obtaining at least one code comment sample, the at least one code comment sample has the same compilation style as the N code modules to be audited, and each code comment sample includes a code segment and a corresponding comment; according to the at least one code comment sample, the ability of the initial LLM to add code comments is trained to obtain an intermediate LLM; obtaining a first prompt content, the first prompt content is used to prompt the intermediate LLM to add comments to the code sample; inputting the code sample and the first prompt content into the intermediate LLM, and generating a code sample with comments through the intermediate LLM; according to the code sample with comments, the ability of the intermediate LLM to audit code is trained to obtain the LLM.
[0062] In one embodiment, the code comment sample may be compiled by a person who compiles the code module to be audited.
[0063] The embodiments of the present application do not limit how to train the initial LLM to add code annotations based on the at least one code annotation sample. For example, the at least one code annotation sample can be input into the initial LLM, and corresponding prompt content can be input to facilitate training the initial LLM to add code annotations.
[0064] The embodiments of the present application do not limit the specific content of the prompt content. For example, the prompt content may be: Please learn how to add comments to the code according to the following code comment sample.
[0065] The embodiment of the present application does not limit what the first prompt content is. For example, the first prompt content may be: Please add comments to the following code.
[0066] The embodiments of the present application do not limit how to train the intermediate LLM's code auditing capability based on the annotated code sample.
[0067] For example, an annotated code sample can be input into the intermediate LLM, and input prompt content can be added to facilitate the intermediate LLM to learn code snippets with known vulnerabilities and safe code snippets in the annotated code sample, so as to be able to identify vulnerabilities in code with unknown vulnerabilities.
[0068] By adding comments to code samples, LLM can understand the code samples faster and learn the vulnerabilities in the code samples faster.
[0069] S202, obtaining N code modules to be audited that belong to the same business logic, where N is an integer greater than 1.
[0070] The code modules to be audited that belong to the same business logic have the same compilation style, and the code modules of the same business logic are interrelated, so they need to be audited together to discover vulnerabilities.
[0071] The embodiments of the present application do not limit the specific value of N.
[0072] S203: According to the LLM, the N code modules to be audited are audited to obtain audit results, which include the location, type and modification suggestions of the vulnerabilities.
[0073] In one embodiment, according to the LLM, the N code modules to be audited are audited, including: directly inputting the N code modules to be audited into the LLM, and inputting predetermined prompt content to instruct the LLM to audit the N code modules to be audited, thereby obtaining audit results.
[0074] By using LLM to audit the audit code module, compared with manual audit code, it has higher audit efficiency, lower requirements for auditors, and high coverage of vulnerabilities in the code by audit results.
[0075] Furthermore, by using LLM to audit the code, you can also directly output modification suggestions for the audited vulnerabilities, which is conducive to completing the code modification work more quickly.
[0076] In another embodiment, the audit device includes M processing cores, each processing core has a corresponding computing frequency, M≤N, M is an integer greater than 1, and each code module to be audited has a corresponding number of code lines. In this case, according to the LLM, the N code modules to be audited are audited to obtain audit results, which may include: obtaining M SSMs; dividing the N code modules to be audited into M groups according to the computing frequency of each processing core and the number of code lines of each code module to be audited, to obtain M groups of code modules to be audited; applying one SSM in each processing core to audit a group of code modules to be audited to obtain M intermediate results; verifying the M intermediate results through the LLM, and if the verification passes, using the M intermediate results as the audit results.
[0077] In fact, the number of code lines included in multiple code modules of a business logic may be tens of thousands or hundreds of thousands. By using M processing cores to audit N code modules to be audited through M SSMs respectively, and verifying the intermediate audit results through LLM, the audit efficiency of the code can be greatly improved, and the performance of the audit equipment can be fully utilized to avoid idle computing resources.
[0078] The embodiments of the present application do not limit what specific module the SSM is, and any small inference model corresponding to a large language model can be used here.
[0079] The embodiments of the present application do not limit how to divide N code modules to be audited into M groups.
[0080] In one embodiment, according to the calculation frequency of each processing core and the number of code lines of each code module to be audited, the N code modules to be audited are divided into M groups to obtain M groups of code modules to be audited, including: determining an allocation method for allocating the N code modules to be audited to the M processing cores to obtain C(N+M-1, M-1) allocation methods; determining the ratio of the total number of lines of the code modules to be audited corresponding to each processing core to the calculation frequency under each allocation method to obtain C(N+M-1, M-1) ratio groups; determining the maximum value in each ratio group to obtain C(N+M-1, M-1) maximum ratios; using the allocation method corresponding to the minimum value of the C(N+M-1, M-1) maximum ratios as a target allocation method; and according to the target allocation method, dividing the N code modules to be audited into M groups to obtain M groups of code modules to be audited.
[0081] Among them, C(N+M-1,M-1) is expanded to: C(N+M-1,M-1)=(M+N-1)! / N!(M-1)!
[0082] In one allocation method, a processing core is allocated with two code modules to be audited, the total number of lines of the two code modules to be audited is P, and the calculation frequency of the processing core is Q. Then the ratio of the total number of lines of the code modules to be audited corresponding to the processing core to the calculation frequency is P / Q.
[0083] In one allocation mode, each processing core corresponds to one ratio, that is, one allocation mode corresponds to one ratio group, and one ratio group includes M ratios.
[0084] The C(N+M-1, M-1) allocation methods correspond to C(N+M-1, M-1) ratio groups. From each ratio group, the maximum value in the ratio group is selected to obtain C(N+M-1, M-1) maximum ratios. After that, the minimum value is selected from the C(N+M-1, M-1) maximum ratios. The allocation method corresponding to the minimum value has the shortest total time required to complete the audit. The allocation method corresponding to the minimum value is used as the target allocation method to group the N code modules to be audited.
[0085] Through the grouping method in this embodiment, when M processing cores audit the M groups of code modules to be audited, the audit can be completed more quickly, thereby improving the audit efficiency.
[0086] The embodiments of the present application do not limit how the processing core applies an SSM to audit a set of code modules to be audited and obtain M intermediate results.
[0087] In one embodiment, an SSM is applied in each processing core to audit a group of code modules to be audited and obtain M intermediate results, including: in each processing core, for the group of code modules to be processed corresponding to the processing core, the following processing is performed: the group of code modules to be audited is converted into AST; a second prompt content is obtained, and input content is constructed according to the second prompt content, the AST and the group of code modules to be audited; the input content is input into the SSM, and the SSM audits the group of code modules to be audited according to the input content to obtain an intermediate result.
[0088] The embodiment of the present application does not limit the specific content of the second prompt content. For example, the second prompt content is: please audit the code in the code module group to be audited according to the code module group to be audited and the AST of the code module group to be audited, and output the audit result.
[0089] In one embodiment, the second prompt content, the AST and the code module group to be audited are combined to obtain input content.
[0090] By constructing the AST of the code module group to be audited, SSM can understand the structure and logic of the code module group to be audited more quickly, which is conducive to efficiently and accurately identifying vulnerabilities in the code, accelerating the efficiency of code auditing, and improving the accuracy of audit results.
[0091] Based on the same inventive concept, a code audit device is also provided in the embodiment of the present application, as described in the following embodiment. Since the principle of solving the problem in the embodiment of the device is similar to that in the above method embodiment, the implementation of the embodiment of the device can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.
[0092] Figure 3 A schematic diagram of a code auditing device in an embodiment of the present application is shown as follows: Figure 3 As shown, the device is applied to an auditing device, including: a first acquisition module 31, used for LLM; a second acquisition module 32, used to obtain N code modules to be audited belonging to the same business logic, N is an integer greater than 1; an auditing module 33, used to audit the N code modules to be audited according to the LLM to obtain an audit result, which includes the location, type and modification suggestions of the vulnerability.
[0093] In some embodiments, the first acquisition module 31 is used to obtain an initial LLM; obtain a code sample corresponding to the business logic, the code sample has the same compilation style as the N code modules to be audited, and the code sample includes at least one pair of code snippets, each pair of code snippets includes a code snippet with known vulnerabilities and a secure code snippet; adjust the parameters of the initial LLM according to the code sample to obtain the LLM.
[0094] In some embodiments, the first acquisition module 31 is used to obtain at least one code comment sample, at least one code comment sample has the same compilation style as the N code modules to be audited, and each code comment sample includes a code segment and a corresponding comment; based on the at least one code comment sample, the initial LLM is trained to add code comments to obtain an intermediate LLM; a first prompt content is obtained, and the first prompt content is used to prompt the intermediate LLM to add comments to the code sample; the code sample and the first prompt content are input into the intermediate LLM, and a code sample with comments is generated by the intermediate LLM; based on the code sample with comments, the intermediate LLM is trained to audit code to obtain the LLM.
[0095] In some embodiments, the audit device includes M processing cores, each processing core has a corresponding computing frequency, M≤N, M is an integer greater than 1, and each code module to be audited has a corresponding number of code lines; the audit module 33 is used to obtain M SSMs; according to the computing frequency of each processing core and the number of code lines of each code module to be audited, the N code modules to be audited are divided into M groups to obtain M groups of code modules to be audited; one SSM is applied to each processing core to audit a group of code modules to be audited to obtain M intermediate results; the M intermediate results are verified by the LLM, and if the verification is passed, the M intermediate results are used as the audit results.
[0096] In some embodiments, the audit module 33 is used to determine the allocation method of the N code modules to be audited to the M processing cores, and obtain C (N + M-1, M-1) allocation methods; determine the ratio of the total number of lines of the code modules to be audited corresponding to each processing core to the calculation frequency under each allocation method, and obtain C (N + M-1, M-1) ratio groups; determine the maximum value in each ratio group, and obtain C (N + M-1, M-1) maximum ratios; take the allocation method corresponding to the minimum value of the C (N + M-1, M-1) maximum ratios as the target allocation method; according to the target allocation method, divide the N code modules to be audited into M groups, and obtain M groups of code modules to be audited.
[0097] In some embodiments, the audit module 33 is used to perform the following processing in each processing core for the code module group to be processed corresponding to the processing core: convert the code module group to be audited into an abstract syntax tree AST; obtain a second prompt content, and construct input content based on the second prompt content, the AST and the code module group to be audited; input the input content into the SSM, and the SSM audits the code group to be audited based on the input content to obtain an intermediate result.
[0098] By using LLM to audit the audit code module, compared with manual audit code, it has higher audit efficiency, lower requirements for auditors, and high coverage of vulnerabilities in the code by audit results.
[0099] Furthermore, by using LLM to audit the code, you can also directly output modification suggestions for the audited vulnerabilities, which is conducive to completing the code modification work more quickly.
[0100] It should be noted that the first acquisition module 31, the second acquisition module 32 and the audit module 33 correspond to S201 to S203 in the method embodiment, and the examples and application scenarios implemented by the modules and the corresponding steps are the same, but are not limited to the contents disclosed in the method embodiment. It should be noted that the modules as part of the device can be executed in a computer system such as a set of computer executable instructions.
[0101] Those skilled in the art will appreciate that various aspects of the present application may be implemented as a system, method or program product. Therefore, various aspects of the present application may be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software, which may be collectively referred to as "circuit", "module" or "system" herein.
[0102] Refer to the following Figure 4 The electronic device 400 according to this embodiment of the present application is described. Figure 4 The electronic device 400 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0103] like Figure 4 As shown, the electronic device 400 is in the form of a general computing device. The components of the electronic device 400 may include but are not limited to: at least one processing unit 410, at least one storage unit 420, and a bus 430 connecting different system components (including the storage unit 420 and the processing unit 410).
[0104] The storage unit stores program codes, which can be executed by the processing unit 410, so that the processing unit 410 performs the steps of various exemplary embodiments of the present application described in the above "Exemplary Method" section of this specification. For example, the processing unit 410 can perform the following steps of the above method embodiment: S201-S203.
[0105] The storage unit 420 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 4201 and / or a cache storage unit 4202 , and may further include a read-only storage unit (ROM) 4203 .
[0106] The storage unit 420 may also include a program / utility 4204 having a set (at least one) of program modules 4205, such program modules 4205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.
[0107] Bus 430 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.
[0108] The electronic device 400 may also communicate with one or more external devices 440 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 400, and / or communicate with any device that enables the electronic device 400 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 450. Furthermore, the electronic device 400 may also communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via a network adapter 460. As shown, the network adapter 460 communicates with other modules of the electronic device 400 via a bus 430. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 400, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0109] Through the description of the above implementation methods, it is easy for those skilled in the art to understand that the example implementation methods described here can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the implementation methods of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the implementation methods of the present application.
[0110] In particular, according to an embodiment of the present application, the process described with reference to the flowchart above can be implemented as a computer program product, which includes: a computer program, which implements the above-mentioned code auditing method when executed by a processor.
[0111] In an exemplary embodiment of the present application, a computer-readable storage medium is also provided, which may be a readable signal medium or a readable storage medium. The computer-readable storage medium stores a program product capable of implementing the above method of the present application.
[0112] In some possible implementations, various aspects of the present application may also be implemented in the form of a program product, which includes program code. When the program product is run on a terminal device, the program code is used to enable the terminal device to execute the steps of various exemplary implementations of the present application described in the above “Exemplary Method” section of this specification.
[0113] More specific examples of computer-readable storage media in the present application may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0114] In the present application, a computer readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, wherein a readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A readable signal medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0115] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.
[0116] In specific implementation, the program code for performing the operation of the present application can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also conventional procedural programming languages such as "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, as an independent software package, partially on the user computing device and partially on the remote computing device, or completely on the remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect through the Internet).
[0117] It should be noted that, although several modules or units of the equipment for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into being embodied by multiple modules or units.
[0118] In addition, although the steps of the method in the present application are described in a specific order in the drawings, this does not require or imply that the steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps, etc.
[0119] Through the description of the above implementation modes, it is easy for those skilled in the art to understand that the example implementation modes described here can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the implementation mode of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the implementation mode of the present application.
[0120] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any modification, use or adaptation of the present application, which follows the general principles of the present application and includes common knowledge or customary techniques in the art that are not disclosed in the present application. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the appended claims.
Claims
1. A code audit method, characterized in that: Applied to audit equipment, including: Get the large language model LLM; Get N code modules to be audited that belong to the same business logic, where N is an integer greater than 1; According to the LLM, the N code modules to be audited are audited to obtain audit results, which include the location, type and modification suggestions of the vulnerabilities.
2. The code audit method according to claim 1, characterized in that: The obtaining of the large language model LLM includes: Get initial LLM; Obtain a code sample corresponding to the business logic, wherein the code sample has the same compilation style as the N code modules to be audited, and the code sample includes at least one pair of code snippets, each pair of code snippets including a code snippet with known vulnerabilities and a secure code snippet; The parameters of the initial LLM are adjusted according to the code sample to obtain the LLM.
3. The code audit method according to claim 2, characterized in that: The adjusting the parameters of the initial LLM according to the code sample to obtain the LLM includes: Obtain at least one code comment sample, wherein the at least one code comment sample has the same compilation style as the N code modules to be audited, and each code comment sample includes a code segment and a corresponding comment; According to the at least one code annotation sample, the ability of the initial LLM to add code annotations is trained, Get an intermediate LLM; Obtaining a first prompt content, where the first prompt content is used to prompt the intermediate LLM to add a comment to the code sample; Inputting the code sample and the first prompt content into the intermediate LLM, and generating a code sample with annotations through the intermediate LLM; The code auditing capability of the intermediate LLM is trained according to the annotated code sample to obtain the LLM.
4. The code audit method according to any one of claims 1 to 3, characterized in that: The audit device includes M processing cores, each processing core has a corresponding computing frequency, M≤N, M is an integer greater than 1, and each code module to be audited has a corresponding number of code lines; The auditing of the N code modules to be audited according to the LLM to obtain audit results includes: Obtain M small speculation models SSM; According to the calculation frequency of each processing core and the number of code lines of each code module to be audited, the N code modules to be audited are divided into M groups to obtain M groups of code modules to be audited; Apply one SSM in each processing core to audit a set of code modules to be audited and obtain M intermediate results; The M intermediate results are verified by the LLM, and if the verification passes, the M intermediate results are used as the audit results.
5. The code audit method according to claim 4, characterized in that: According to the calculation frequency of each processing core and the number of code lines of each code module to be audited, the N code modules to be audited are divided into M groups to obtain M groups of code modules to be audited, including: Determine an allocation method for allocating the N code modules to be audited to the M processing cores, and obtain C (N+M-1, M-1) allocation methods; Determine the ratio of the total number of lines of the code module to be audited and the calculation frequency corresponding to each processing core under each allocation mode, and obtain C (N + M-1, M-1) ratio groups; Determine the maximum value in each ratio group and obtain C(N+M-1, M-1) maximum ratios; The allocation method corresponding to the minimum value among the C(N+M-1, M-1) maximum ratios is used as the target allocation method; According to the target allocation method, the N code modules to be audited are divided into M groups to obtain M groups of code modules to be audited.
6. The code audit method according to claim 4, characterized in that: The method applies one SSM in each processing core to audit a group of code modules to be audited, and obtains M intermediate results, including: In each processing core, the following processing is performed for the code module group to be processed corresponding to the processing core: Convert the code module group to be audited into an abstract syntax tree AST; Obtain the second prompt content, and construct input content according to the second prompt content, the AST and the code module group to be audited; The input content is input into SSM, and SSM audits the audit code group according to the input content to obtain an intermediate result.
7. A code auditing device, characterized in that: Applied to audit equipment, including: The first acquisition module is used to acquire a large language model LLM; The second acquisition module is used to acquire N code modules to be audited that belong to the same business logic, where N is an integer greater than 1; The audit module is used to audit the N code modules to be audited according to the LLM to obtain audit results, wherein the audit results include the location, type and modification suggestions of the vulnerabilities.
8. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; Wherein, the processor is configured to execute the code auditing method described in any one of claims 1 to 6 by executing the executable instructions.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the code auditing method described in any one of claims 1 to 6 is implemented.
10. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the code auditing method according to any one of claims 1 to 6 is implemented.
Citation Information
Cited By
Application method of DevOps pipeline business code auditing
CN120315987A