Device and method for retrieving standardized requirements of software codes
By designing a device and method including a search configuration module, a search matching logic, a code correction analysis module, and a historical data storage module, the existing code static walk-through tool has been solved, and efficient code standardization detection and error correction have been achieved, and software development and maintenance efficiency has been improved.
Patent Information
- Application Number
- CN202411972713.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-16
AI Technical Summary
The existing static code walk-in tools have shortcomings in configuration and detection efficiency. For example, Fortify's configuration is complex, Checkmarx's vulnerability library is small, and CoBOT-SAST relies on external documents and subjective explanations, making it difficult to conduct secondary development of defect patterns in specific fields.
Design a device and method, including a search configuration module, a search matching logic and code correction analysis module, and a historical data storage module, supporting independent configuration of search items, providing correction solutions, completing multi-file batch search and historical data storage.
By independently configuring search items and providing correction solutions, the problem of excessive cumbersome initialization configuration is solved, and multi-file batch search and multiple programming language files are supported, code search efficiency is improved, large file scanning time is reduced, historical data analysis function is provided, and software error correction and iteration efficiency is improved.
Smart Images

Figure CN120011196A_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the field of software, and in particular relates to a code standardization detection method for compensating for the function of a code static walkthrough tool. Background Art
[0002] Code static walkthrough tools can quickly retrieve code logic vulnerabilities. The software code walkthrough tools used daily include Fortify, Checkmarx, CoBOT-SAST and other tools. The relevant introductions are as follows:
[0003] Fortify software can detect more than 900 types of security holes and defects in the code. It automatically detects security holes and defects by statically analyzing the source code of the application. In terms of use, the configuration of Fortify is very complicated. Many configuration options need to be set before using the tool and when creating a detection project. In addition, there are many false positives in the Fortify detection results, which requires users to spend a lot of time and energy to analyze and confirm the false positives.
[0004] Checkmarx software uses static code analysis technology to detect security vulnerabilities in applications. The Checkmarx vulnerability library is relatively small, which may result in failure to detect specific types of vulnerabilities that users are concerned about. Checkmarx's performance is limited by the scope and scale of the scan. If the code base to be scanned is large, it will take a lot of time and computing resources to complete the scan.
[0005] In addition to the security vulnerabilities and defects that Fortify and Checkmarx can detect, CoBOT-SAST source code static analysis tool also supports the detection of coding rules. However, CoBOT-SAST relies on external software documentation and subjective interpretation, and is subject to customization restrictions, making it difficult to carry out secondary development for defect patterns in specific fields. Summary of the invention
[0006] In view of this, the present invention proposes a device and method for retrieving software code standardization based on the shortcomings of the above-mentioned static walkthrough tool in the process of code walkthrough. The present invention can independently configure search items, provide correction solutions, and complete functions such as multi-file batch retrieval and historical data storage. The specific technical solution is as follows:
[0007] A device for retrieving software code standardization includes a retrieval configuration module, a retrieval matching logic and code correction analysis module, and a historical data storage module, wherein the retrieval configuration module is used to configure retrieval objects, and the objects refer to functions used in pairs. The retrieval matching logic and code correction analysis module are used to perform retrieval matching in files to be retrieved according to the retrieval matching logic, and provide change measures and suggestions. The historical data storage module is used to store retrieval information as well as change measures and suggestions, wherein retrieval matching refers to all situations where retrieval objects are used in pairs in the code, including checking return, break, and continue branches.
[0008] Furthermore, the retrieval configuration module supports the synchronous configuration of multiple retrieval objects.
[0009] Furthermore, the search and matching logic is divided into two categories: fuzzy error correction and precise error correction: the fuzzy error correction: for functions that are used flexibly, it locates possible errors, including locating folders and lines; the precise error correction: for functions that are used strictly, it locates error situations, including locating folders and lines.
[0010] Furthermore, the retrieved information includes the program file name, function name, and code line number where the object match is lost.
[0011] Furthermore, a multi-file batch retrieval module may be configured to perform batch retrieval of files in a directory folder, including retrieval of source files.
[0012] A method for retrieving software code standardization, configuring a search object, and performing search matching in files to be retrieved according to a search matching logic, wherein the search matching logic is divided into two categories: fuzzy error correction and precise error correction, wherein the fuzzy error correction is used to locate possible errors for functions that are used flexibly, including locating folders and lines; the precise error correction is used to locate error conditions for functions that are used strictly, including locating folders and lines; after locating, if the current search information is not in a database, the search information and corresponding change measures and suggestions are written into the database; in addition, batch search matching of multiple files of different file types can also be performed, and the file types include C language: .c source code file; C++ language: .cpp and .cc source files; Java: .java source file; assembly language: .asm source file; Python: .py source file.
[0013] Beneficial Effects
[0014] 1. The items to be checked of conventional walkthrough software are configured through configuration files in the configuration library, with customized restrictions. In order to break away from the conventional search logic and get rid of the restrictions of the configuration library, the present invention solves the problem of overly cumbersome initialization configuration by setting up a search configuration module and flexibly configuring it according to actual search requirements;
[0015] 2. The present invention supports batch retrieval of multiple files and files in multiple programming languages, and solves the time-consuming problem of scanning large files through batch retrieval of multiple files;
[0016] 3. The present invention sets up a historical data storage module for the purpose of saving the retrieved data. If the part is retrieved for the second time, the data that has been retrieved will not be retrieved again through comparison, and only the changed data part will be retrieved to improve the retrieval efficiency. The module provides a subsequent historical data analysis function, which makes up for the disadvantage of low adaptability of conventional software retrieval tools and improves software error correction and iteration efficiency. The present invention is a method for in-depth analysis of code logic for many programming languages on the market.
[0017] 4. The present invention helps to improve the efficiency of code checking and make up for the inadequate coverage of software evaluation by third-party evaluation agencies. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 Configuring the module graph for retrieval
[0019] Figure 2 Analyze module diagrams for searching matching logic and code correction
[0020] Figure 3 Module diagram for batch retrieval of multiple files
[0021] Figure 4 Module diagram for storing historical data
[0022] Figure 5 Design a general diagram for the implementation scheme DETAILED DESCRIPTION
[0023] The device of the present invention comprises a retrieval configuration module, a retrieval matching logic and code correction analysis module, a multi-file batch retrieval module, and a historical data storage module.
[0024] Among them, the retrieval configuration module: In the software design process, some functions that are adapted to the software system are usually used in pairs. Taking the coding under the VxWorks system as an example: taskLock() and taskunlock(), tasksafe() and taskunsafe(), binary semaphores SemGive and SemTake, and the paired use and timely release of malloc and realloc, etc. The retrieval configuration module can configure the objects that need to be retrieved, and supports simultaneous retrieval configuration of multiple targets.
[0025] Search matching logic and code correction analysis module: After configuring the search items in the search matching module, submit and check all paired usages in the code, including branches such as return, break, and continue. The search mode and results are shown below:
[0026] Fuzzy error correction: for the functions that are used flexibly, possible errors can be located (locating folders and rows), and search problems and change opinions can be exported and filled into Excel tables;
[0027] Accurate error correction: For strictly matched functions, locate the error situation (locate the folder and number of rows), export the search problems and change suggestions and fill them into Excel tables.
[0028] Batch retrieval of multiple files: adopts multi-threaded calling mode, first evaluates the retrieval time of the files to be retrieved, sorts them according to the time consumption, gives priority to searching the files with low time consumption, reduces the search file items within the same search time, and focuses on searching large files. Supported file types:
[0029] C language: .c source code file;
[0030] C++ language: .cpp and .cc source files;
[0031] Java: .java source files;
[0032] Assembly language: .asm source file;
[0033] Python: .py source files.
[0034] Historical data storage module: This module records the search information of previous searches in the database. When performing batch searches of multiple files, by comparing the historical search files in the database, the search for the searched files will not be repeated, and the search for the unsearched files will be performed according to the search matching logic, and the database files will be updated to improve the search efficiency.
[0035] Figure 5 It is the general diagram of the scheme of the present invention. After starting the search software, it is configured according to the required search items, the software to be searched is selected, the code file is searched according to fuzzy error correction or precise error correction, and its pairing situation in branches such as return, break, and continue is matched, and the program file name, function name, number of code lines and other information of the missing matches are recorded, and the search result information is recorded in the database in real time.
[0036] When it is the first search, the error location and change plan will be written into the Excel table and database file after the search is completed. When the file is a second search, the database data will be compared first, and the changed items will be searched. After the search is completed, the database information and Excel table information will be updated.
[0037] This solution is based on the design defects of the current retrieval software, improves the software retrieval efficiency and modification efficiency, optimizes the design and shortens the code maintenance cycle.
Claims
1. A device for retrieving software code standardization, characterized in that: It includes a retrieval configuration module, a retrieval matching logic and code correction analysis module, and a historical data storage module, wherein the retrieval configuration module is used to configure the retrieval object, and the object refers to a function used in pairs; the retrieval matching logic and code correction analysis module is used to perform retrieval matching in the files to be retrieved according to the retrieval matching logic, and provide change measures and suggestions; the historical data storage module is used to store retrieval information as well as change measures and suggestions, wherein retrieval matching refers to all situations where the retrieval object is used in pairs in the code, including checking return, break, and continue branches.
2. A device for retrieving software code standardization according to claim 1, characterized in that: The retrieval configuration module supports the simultaneous configuration of multiple retrieval objects.
3. A device for retrieving software code standardization according to claim 1, characterized in that: The search and matching logic is divided into two categories: fuzzy error correction and precise error correction: The fuzzy error correction described above can locate possible errors in functions that are used flexibly, including locating folders and lines. The precise error correction described above can locate error situations in functions that are used strictly, including locating folders and lines.
4. The device for retrieving software code standardization according to claim 1, characterized in that: The retrieved information includes the program file name, function name, and code line number where the object match was lost.
5. A device for retrieving software code standardization according to any one of claims 1 to 4, characterized in that: You can also configure a multi-file batch retrieval module to perform batch retrieval of files in a directory folder, including retrieval of source files.
6. A method for retrieving software code standardization, characterized in that: Configure the search object, and perform search and matching in the files to be searched according to the search and matching logic. The search and matching logic is divided into two categories: fuzzy error correction and precise error correction. The fuzzy error correction is used to locate possible errors for functions that are used flexibly, including locating folders and lines; the precise error correction is used to locate errors for functions that are used strictly, including locating folders and lines; after locating, if the current search information is not in the database, the search information and corresponding change measures and suggestions are written into the database; in addition, batch search and matching of multiple files of different file types can also be performed, including C language: .c source code files; C++ language: .cpp and .cc source files; Java: .java source file; Assembly language: .asm source file; Python: .py source files.