Security management method and system for open source software supply chain

By building a supply chain knowledge graph for the open source software supply chain and extracting and analyzing related information, the problem of high security risks in the open source software supply chain is solved, and timely warning and response to potential security threats is achieved.

CN120012118AActive Publication Date: 2025-05-16ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510480875.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-05-16
Estimated Expiration
2045-04-17

AI Technical Summary

Technical Problem

The security risks of the open source software supply chain are high, and malicious attackers may pretend to publish malicious code packages, resulting in the user's system being damaged.

Method used

By collecting related information from open source software, extracting various entities in the supply chain, software events related to security risks, and the relationship between entities, building a supply chain knowledge graph, and issuing early warning information and emergency response strategies when there are risk events.

Benefits of technology

It effectively reduces the security risks of the open source software supply chain and prevents potential security threats through timely warning and emergency response strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012118A_ABST
    Figure CN120012118A_ABST
Patent Text Reader

Abstract

The invention relates to a security management method and system for an open source software supply chain, and relates to the technical field of software security. The method comprises the following steps: collecting associated information of open source software; extracting entities in an open source software supply chain of the open source software, software events associated with the security risk of the open source software in the open source software supply chain and an association relationship among the entities from the association information as supply chain knowledge of the open source software supply chain; obtaining a supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge; on the basis of the supply chain knowledge graph, under the condition that it is determined that the risk event exists in the open source software supply chain, early warning information and an emergency response strategy for the risk event are sent out. By adopting the method, the security risk of the open source software supply chain can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of software security technology, and in particular to a security management method, system, computer device, computer-readable storage medium and computer program product for an open source software supply chain. Background Art

[0002] Open source software refers to software whose source code is open to the public, allowing anyone to view, use, modify and distribute it; the open source software supply chain refers to the supply network composed of open source components and their dependencies in the open source software, covering multiple aspects such as the development, maintenance, management and distribution of open source software packages.

[0003] In the related art, since open source software allows anyone to view, use, modify and distribute it, the security risk of the open source software supply chain is relatively high. For example, malicious attackers may disguise the release of software packages containing malicious code and publish them on software package distribution platforms to trick users into downloading them, thereby destroying the user's system that uses the software package. Summary of the invention

[0004] Based on this, it is necessary to provide a security management method, system, computer device and computer-readable storage medium for an open source software supply chain that can reduce security risks in order to address the technical issues of the high security risks of the above-mentioned open source software supply chain.

[0005] In a first aspect, the present application provides a method for secure management of an open source software supply chain, including:

[0006] Collect relevant information about open source software;

[0007] Extracting from the association information entities in the open source software supply chain of the open source software, software events in the open source software supply chain that are associated with the security risk of the open source software, and association relationships between the entities as supply chain knowledge of the open source software supply chain; the entities at least include components, vulnerabilities, and patches corresponding to the open source software, and the software events at least include a first software event that increases the security risk and a second software event that reduces the security risk;

[0008] Based on the supply chain knowledge, a supply chain knowledge graph of the open source software supply chain is obtained;

[0009] When it is determined that there is a risk event in the open source software supply chain based on the supply chain knowledge graph, early warning information and emergency response strategies for the risk event are issued.

[0010] In one embodiment, extracting from the association information entities in the open source software supply chain of the open source software, software events in the open source software supply chain associated with the security risk of the open source software, and association relationships between the entities includes:

[0011] Based on the pre-trained knowledge extraction model, extract the components, vulnerabilities and patches corresponding to the open source software from the associated information to obtain the entities;

[0012] Based on the knowledge extraction model and the entities, extracting from the association information the first software events that increase the security risk and the second software events that reduce the security risk in the open source software supply chain to obtain the software events;

[0013] Based on the knowledge extraction model, extracting from the association information and the software events a first association relationship between the components, a second association relationship between the components and the vulnerabilities, a third association relationship between the patches and the vulnerabilities, and a fourth association relationship between the components and the patches, to obtain association relationships between the entities;

[0014] Determine the entities, the associations between the entities, and the software events as supply chain knowledge of the open source software supply chain;

[0015] Among them, the first association relationship between two components represents whether there is a dependency relationship between the two components; the second association relationship between each component and each vulnerability represents whether the vulnerability exists in the component; the third association relationship between each patch and each vulnerability represents whether the patch is a patch released for the vulnerability; the fourth association relationship between each component and each patch represents whether the patch is applied to the component.

[0016] In one embodiment, obtaining a supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge includes:

[0017] Construct the node corresponding to each entity;

[0018] Based on the association relationship between the entities, determining the connection edges between the nodes;

[0019] Based on the software events, determining the weights of the connecting edges between the nodes;

[0020] The supply chain knowledge graph is constructed based on the nodes, the connecting edges between the nodes, and the weights of the connecting edges between the nodes.

[0021] In one of the embodiments, the nodes in the supply chain knowledge graph include at least a component node corresponding to each component, a vulnerability node corresponding to each vulnerability, and a patch node corresponding to each patch;

[0022] When it is determined that there is a risk event in the open source software supply chain based on the supply chain knowledge graph, issuing warning information and emergency response strategies for the risk event includes:

[0023] For each vulnerability node in the supply chain knowledge graph, based on the connection relationship between the vulnerability node and other nodes in the supply chain knowledge graph, determine the risk information of the vulnerability node;

[0024] In the case where the risk information is greater than or equal to the preset risk information, determining that a risk event corresponding to the vulnerability node exists in the open source software supply chain;

[0025] Generate early warning information for risk events, and determine an emergency response strategy for the risk events based on the connection relationship between the vulnerability node and the remaining nodes;

[0026] The warning information and the emergency response strategy are issued.

[0027] In one embodiment, determining the risk information of the vulnerability node based on the connection relationship between the vulnerability node and other nodes in the supply chain knowledge graph includes:

[0028] Determine the impact area of ​​the vulnerability node in the supply chain knowledge graph based on the connection relationship between the vulnerability node and the component node in the supply chain knowledge graph;

[0029] Determining risk information of the vulnerable node based on the component nodes in the impact area and the connection relationship between the vulnerable node and the component nodes in the impact area;

[0030] The determining, based on the connection relationship between the vulnerable node and the remaining nodes, an emergency response strategy for the first software event corresponding to the vulnerable node includes:

[0031] Based on the connection relationship between the vulnerability node and the patch nodes in the affected area, a target patch node for repairing the vulnerability node is determined among the patch nodes in the affected area; based on the connection relationship between the vulnerability node and the component nodes in the affected area, a target component node to which the target patch node is to be applied is determined among the component nodes in the affected area;

[0032] An emergency response strategy for the risk event is determined based on the target patch node and the target component node.

[0033] In one embodiment, after obtaining the supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge, the method further includes:

[0034] Receiving a query request for the open source software supply chain;

[0035] Among the nodes in the supply chain knowledge graph, locate a target node associated with the query request;

[0036] Generate a query result corresponding to the query request based on the connection relationship between the target node and the remaining nodes in the supply chain knowledge graph;

[0037] The query result is displayed.

[0038] In one embodiment, after obtaining the supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge, the method further includes:

[0039] Determine an index value of the open source software supply chain under at least one security risk index based on a connection relationship between nodes in the supply chain knowledge graph;

[0040] The supply chain knowledge graph and the indicator values ​​of the open source software supply chain under various security risk indicators are displayed.

[0041] In a second aspect, the present application also provides a security management system for an open source software supply chain, including:

[0042] Information collection layer, used to collect relevant information of open source software;

[0043] A knowledge extraction layer, for extracting entities in the open source software supply chain of the open source software, software events in the open source software supply chain associated with the security risk of the open source software, and associations between the entities, as supply chain knowledge of the open source software supply chain; the entities at least include components, vulnerabilities and patches corresponding to the open source software, and the software events at least include a first software event that increases the security risk and a second software event that reduces the security risk;

[0044] A knowledge representation layer, used to obtain a supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge;

[0045] The risk warning layer is used to issue warning information and emergency response strategies for risk events when it is determined that there are risk events in the open source software supply chain based on the supply chain knowledge graph.

[0046] In a third aspect, the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0047] Collect relevant information about open source software;

[0048] Extracting from the association information entities in the open source software supply chain of the open source software, software events in the open source software supply chain that are associated with the security risk of the open source software, and association relationships between the entities as supply chain knowledge of the open source software supply chain; the entities at least include components, vulnerabilities, and patches corresponding to the open source software, and the software events at least include a first software event that increases the security risk and a second software event that reduces the security risk;

[0049] Based on the supply chain knowledge, a supply chain knowledge graph of the open source software supply chain is obtained;

[0050] When it is determined that there is a risk event in the open source software supply chain based on the supply chain knowledge graph, early warning information and emergency response strategies for the risk event are issued.

[0051] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:

[0052] Collect relevant information about open source software;

[0053] Extracting from the association information entities in the open source software supply chain of the open source software, software events in the open source software supply chain that are associated with the security risk of the open source software, and association relationships between the entities as supply chain knowledge of the open source software supply chain; the entities at least include components, vulnerabilities, and patches corresponding to the open source software, and the software events at least include a first software event that increases the security risk and a second software event that reduces the security risk;

[0054] Based on the supply chain knowledge, a supply chain knowledge graph of the open source software supply chain is obtained;

[0055] When it is determined that there is a risk event in the open source software supply chain based on the supply chain knowledge graph, early warning information and emergency response strategies for the risk event are issued.

[0056] The above-mentioned open source software supply chain security management method, system, computer device and computer-readable storage medium first collect the associated information of the open source software; then, from the associated information, extract the entities in the open source software supply chain of the open source software, the software events associated with the security risks of the open source software in the open source software supply chain, and the association relationship between the entities as the supply chain knowledge of the open source software supply chain; each entity includes at least the components, vulnerabilities and patches corresponding to the open source software, and the software events include at least the first software event that increases the security risk and the second software event that reduces the security risk; then, based on the supply chain knowledge, a supply chain knowledge graph of the open source software supply chain is obtained; then, when it is determined that there is a risk event in the open source software supply chain based on the supply chain knowledge graph, early warning information and emergency response strategies for the risk event are issued. In this way, through information extraction, entities such as components, vulnerabilities and patches in the open source software supply chain, the first software event that increases the security risk of the open source software, the second software event that reduces the security risk of the open source software, and the association between the entities can be extracted from the associated information of the open source software, thereby obtaining the supply chain knowledge of the open source software supply chain; based on the supply chain knowledge, the corresponding supply chain knowledge graph can be obtained; based on the supply chain knowledge graph, the existence of risk events in the open source software supply chain can be analyzed, and in the event of risk events, corresponding warning information and emergency response strategies can be issued; the security management method of the open source software supply chain based on the above process can provide timely warnings for risk events in the open source software supply chain and provide emergency response strategies, thereby reducing the security risks of the open source software supply chain. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the drawings required for use in the embodiments of the present application or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0058] Figure 1 A schematic diagram of a process for a security management method for an open source software supply chain in one embodiment;

[0059] Figure 2 A flowchart of steps for extracting entities in an open source software supply chain of open source software, software events in the open source software supply chain associated with security risks of the open source software, and association relationships between entities from association information in one embodiment;

[0060] Figure 3A flowchart of steps for obtaining a supply chain knowledge graph of an open source software supply chain based on supply chain knowledge in one embodiment;

[0061] Figure 4 A flowchart of the steps of issuing early warning information and emergency response strategies for risk events when a risk event is determined to exist in an open source software supply chain based on a supply chain knowledge graph in an embodiment;

[0062] Figure 5 is a schematic diagram of an open source software supply chain security knowledge management system based on a large language model in one embodiment;

[0063] Figure 6 is a structural block diagram of a security management system for an open source software supply chain in one embodiment;

[0064] Figure 7 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0065] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0066] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0067] In one embodiment, Figure 1 As shown, a security management method for an open source software supply chain is provided. This embodiment uses the method applied to a server as an example for illustration. It is understandable that the method can also be applied to a terminal, and can also be applied to a system including a server and a terminal, and is implemented through the interaction between the server and the terminal; wherein the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services; the terminal can be, but is not limited to, various personal computers, laptops, smart phones, tablet computers, etc. In this embodiment, the method includes the following steps S102 to S108:

[0068] Step S102: Collect relevant information of open source software.

[0069] Among them, open source software refers to software whose source code is open to the public, allowing anyone to view, use, modify and distribute it.

[0070] Among them, an open source software includes at least one open source project, and an open source project includes at least one open source component.

[0071] The associated information of the open source software includes at least first open source software information on the open source software platform and second open source software information on an Internet page related to the open source software.

[0072] In specific applications, the first open source software information includes at least the basic information of the open source software (project name, description, developer information, license type, etc.), version information (code snapshots of different versions, release time, update logs, etc.), code repository content (source code files, submission records, branch information, tags, etc.), project documents (README files (a text file used to introduce the basic information of a project, software or program to users, developers or other relevant personnel), wiki pages, contribution guidelines, etc.), Issue and Pull Request information (problem description, solution status, comments), dependency information (dependent libraries, dependent versions, etc.) and security relevance information (code scanning results, vulnerability reports, etc.).

[0073] In specific applications, the second open source software information at least includes vulnerability libraries and threat intelligence (such as vulnerability databases such as CVE (Common Vulnerabilities and Exposures), NVD (National Vulnerability Database)), technical forums and community discussions (such as discussions related to open source software on open source software platforms), security research reports and white papers (such as research reports released by major security vendors), and other relevant information (such as news reports, social media discussions, etc.).

[0074] Specifically, the server obtains first open source software information related to the open source software from the open source software platform, and obtains second open source software information related to the open source software from an Internet page related to the open source software, to obtain associated information of the open source software.

[0075] In a specific application, the server is associated with a database for storing associated information; the server performs incremental updates or full updates to the database based on the information difference between the associated information obtained this time and the historical associated information in the database. For example, when the information difference between the associated information obtained this time and the historical associated information is less than or equal to the preset information difference, the server performs incremental updates to the database based on the information difference; when the information difference is greater than the preset information difference, the server performs full updates to the database based on the associated information obtained this time. This can reduce unnecessary data transmission and processing and improve the efficiency of data synchronization.

[0076] In actual applications, for related information, the server can obtain the related information based on the interface of the page or platform where the related information is located, or dynamically adjust the crawler strategy by identifying the structure of different pages or platforms to obtain the related information through the crawler.

[0077] In practical applications, the server can perform data preprocessing on the collected related information, such as data format unification, data cleaning and standardization, and duplicate data detection and merging.

[0078] In actual applications, the server collects related information every certain period of time.

[0079] Step S104, extracting from the associated information the entities in the open source software supply chain of the open source software, the software events in the open source software supply chain associated with the security risks of the open source software, and the association relationships between the entities as the supply chain knowledge of the open source software supply chain.

[0080] Among them, the open source software supply chain refers to the supply network composed of open source components and their dependencies in open source software, covering multiple links such as open source software development, maintenance, software package management and distribution.

[0081] Each entity includes at least components, vulnerabilities and patches corresponding to the open source software. In specific applications, the server can also extract entity attributes of the entity from the associated information, such as the name, publisher, developer, release time, release version, etc. of the entity.

[0082] Among them, software events include at least a first software event that increases security risks and a second software event that reduces security risks. In specific applications, the first software event includes but is not limited to vulnerability exposure events, vulnerability exploitation events, malicious attack events, data security events, supply chain attack events, etc.; the second software event includes but is not limited to vulnerability repair events, patch release events, patch application events, component update events, component release events, etc.

[0083] Specifically, the server extracts knowledge from the associated information, extracts entities such as components, vulnerabilities and patches in the open source software supply chain of the open source software, and extracts software events such as the first software event and the second software event that have occurred in the open source software supply chain; then, based on the extracted entities and software events, the server further extracts the association relationships between the entities from the associated information, thereby obtaining the supply chain knowledge of the open source software supply chain composed of the entities, the association relationships between the entities and the software events.

[0084] Step S106, based on the supply chain knowledge, obtain the supply chain knowledge graph of the open source software supply chain.

[0085] Specifically, the server obtains the supply chain knowledge graph of the open source software supply chain by constructing or updating the supply chain knowledge based on the supply chain knowledge. In a specific application, the server determines the knowledge difference between the supply chain knowledge and the historical supply chain knowledge. When the knowledge difference is less than or equal to the preset knowledge difference, the server updates the historical supply chain knowledge graph based on the knowledge difference to obtain the supply chain knowledge graph, wherein the historical supply chain knowledge graph is obtained through the historical supply chain knowledge; when the knowledge difference is greater than the preset knowledge difference, the server constructs a new supply chain knowledge graph based on the supply chain knowledge.

[0086] Step S108, when it is determined that there is a risk event in the open source software supply chain based on the supply chain knowledge graph, early warning information and emergency response strategies for the risk event are issued.

[0087] Among them, risk events refer to the first software events that may occur and, after their occurrence, will pose a serious threat to the security of the open source software supply chain.

[0088] Among them, emergency response strategies are used to characterize solutions to risk events.

[0089] Specifically, based on the supply chain knowledge graph, the server can predict through reasoning the first software event that may occur in the open source software supply chain; based on the supply chain knowledge graph, the server determines that the possible first software event will cause a serious threat and determines the possible first software event as a risk event; then, the server generates early warning information for the risk event, and generates an emergency response strategy for the risk event based on the supply chain knowledge graph, and then issues the early warning information and the emergency response strategy.

[0090] In a specific application, the server can send warning information and emergency response strategies to the security management terminal associated with the server.

[0091] In specific applications, the server displays warning information and emergency response strategies through the server front end or the security management terminal front end.

[0092] In this embodiment, there are one or more open source software, that is, the user can build an independent supply chain knowledge graph for each open source software separately, or represent the open source software supply chain of each open source software in the same knowledge graph.

[0093] In the above-mentioned security management method for the open source software supply chain, first, the server collects the associated information of the open source software; then, the server extracts the entities in the open source software supply chain of the open source software, the software events associated with the security risks of the open source software in the open source software supply chain, and the association relationship between the entities from the associated information as the supply chain knowledge of the open source software supply chain; each entity includes at least the components, vulnerabilities and patches corresponding to the open source software, and the software events include at least the first software events that increase the security risks and the second software events that reduce the security risks; then, the server obtains the supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge; then, when the server determines that there are risk events in the open source software supply chain based on the supply chain knowledge graph, it issues early warning information and emergency response strategies for the risk events. In this way, through information extraction, the server can extract entities such as components, vulnerabilities and patches in the open source software supply chain, the first software event that increases the security risk of the open source software and the second software event that reduces the security risk of the open source software, as well as the association between the entities from the associated information of the open source software, thereby obtaining the supply chain knowledge of the open source software supply chain; based on the supply chain knowledge, the server can obtain the corresponding supply chain knowledge graph; based on the supply chain knowledge graph, the server can detect the existence of risk events in the open source software supply chain, and in the event of risk events, issue corresponding warning information and emergency response strategies; the security management method of the open source software supply chain based on the above process can provide timely warnings for risk events in the open source software supply chain and provide emergency response strategies, thereby reducing the security risks of the open source software supply chain.

[0094] In an exemplary embodiment, Figure 2 As shown, the above step S104 extracts, from the association information, entities in the open source software supply chain of the open source software, software events in the open source software supply chain associated with the security risks of the open source software, and the association relationship between the entities, and specifically includes the following steps:

[0095] Step S202 , based on the pre-trained knowledge extraction model, extract the components, vulnerabilities and patches corresponding to the open source software from the associated information to obtain the entities.

[0096] Step S204, based on the knowledge extraction model and each entity, extract each first software event that increases security risk and each second software event that reduces security risk in the open source software supply chain from the associated information to obtain each software event.

[0097] Step S206, based on the knowledge extraction model, extract the first association relationship between components, the second association relationship between components and vulnerabilities, the third association relationship between patches and vulnerabilities, and the fourth association relationship between components and patches from the association information and software events to obtain the association relationship between entities.

[0098] Step S208: Determine each entity, the relationship between entities, and each software event as supply chain knowledge of the open source software supply chain.

[0099] The first association relationship between two components indicates whether there is a dependency relationship between the two components; for example, the first association relationship between component A and component B indicates whether the application of component A depends on the application of component B.

[0100] The second association relationship between each component and each vulnerability represents whether there is a vulnerability in the component; for example, the second association relationship between component A and vulnerability A represents whether there is vulnerability A in component A.

[0101] Among them, the third association relationship between each patch and each vulnerability represents whether the patch is a patch released for the vulnerability; for example, the third association relationship between patch A and vulnerability A represents whether patch A is a patch released for vulnerability A, that is, whether patch A can fix vulnerability A.

[0102] The fourth association relationship between each component and each patch represents whether the patch is applied to the component; for example, the fourth association relationship between component A and patch A represents whether patch A is applied to component A.

[0103] Among them, the pre-trained knowledge extraction model is implemented based on the large language model; the knowledge extraction model can be obtained by fine-tuning the general large language model based on the open source software supply chain fine-tuning dataset.

[0104] Specifically, the server inputs the associated information into the knowledge extraction model, and through the semantic understanding ability and text generation ability of the knowledge extraction model, first extracts the components, vulnerabilities and patches corresponding to the open source software from the associated information, then, based on the components, vulnerabilities and patches, extracts the first software events that increase the security risk and the second software events that reduce the security risk from the associated information, and finally, based on the components, vulnerabilities, patches, first software events and second software events, extracts the association relationship between the components, vulnerabilities and patches from the associated information. Based on the extracted components, vulnerabilities, patches, first software events, second software events and the association relationship between the components, vulnerabilities and patches, the server obtains the supply chain knowledge of the open source software.

[0105] In specific applications, after obtaining supply chain knowledge such as each component, each vulnerability, each patch, each first software event, each second software event, and the relationship between each component, each vulnerability and each patch, since the sources and expressions of each supply chain knowledge are different, the server can integrate the supply chain knowledge based on entity alignment and conflict detection strategies to ensure the accuracy and consistency of the supply chain knowledge.

[0106] In practical applications, the server measures the knowledge processing efficiency of the knowledge extraction model through the following formula 1:

[0107] (Formula 1)

[0108] in, For knowledge processing efficiency, is the total number of knowledge categories, For the Class knowledge, For the The weight of class knowledge, For the The quality score of class knowledge, For processing time, For resource consumption.

[0109] The classification of knowledge includes, but is not limited to, classification according to its source, classification according to its entity type, association relationship and software event, etc.

[0110] Among them, the quality score of knowledge can be obtained through user scoring or through artificial intelligence scoring.

[0111] In this embodiment, the server uses the capabilities of a large language model to quickly and accurately extract supply chain knowledge from the open source software supply chain, avoiding the time and labor costs of manual aggregation and improving the efficiency of acquiring supply chain knowledge.

[0112] In an exemplary embodiment, Figure 3 As shown, the above step S106, based on the supply chain knowledge, obtains the supply chain knowledge graph of the open source software supply chain, which specifically includes the following steps:

[0113] Step S302: construct a node corresponding to each entity.

[0114] Step S304: determining the connection edges between the nodes based on the association relationship between the entities.

[0115] Step S306: Determine the weight of the connection edge between each node based on each software event.

[0116] Step S308, constructing a supply chain knowledge graph based on each node, the connecting edges between each node, and the weights of the connecting edges between each node.

[0117] The weight of the connection edge is used to represent the degree of association between the entities corresponding to the two nodes connected by the connection edge.

[0118] Specifically, the process of the server building the supply chain knowledge graph is as follows:

[0119] First, the server builds a corresponding node for each entity; for example, a corresponding component node is built for each component, a corresponding vulnerability node is built for each vulnerability, and a corresponding patch node is built for each patch. The node attributes of the node include the entity attributes of the entity corresponding to the node and the update time of the node.

[0120] Then, the server determines the connection edges between the nodes based on the association relationships between the entities; for example, connecting the component node corresponding to the component with a first association relationship, connecting the component node and the vulnerability node corresponding to the component and the vulnerability with a second association relationship, connecting the patch node and the vulnerability node corresponding to the patch and the vulnerability with a third association relationship, and connecting the component node and the patch node corresponding to the component and the patch with a fourth association relationship.

[0121] Next, the server determines the weight of the connection edge between the nodes corresponding to the entities involved in each software event based on the event attributes such as the number of occurrences, severity, and importance of each software event. For example, the weight of the connection edge between the nodes corresponding to the entities involved in the software event with more occurrences is higher. For example, the more times vulnerability A occurs in component A, the higher the weight of the connection edge between the component node corresponding to component A and the vulnerability node corresponding to vulnerability A; for another example, the weight of the connection edge between the nodes corresponding to the entities involved in the first software event with more serious security threats is higher. For example, the more serious the threat caused by vulnerability A to component A, the higher the weight of the connection edge between the component node corresponding to component A and the component node corresponding to vulnerability A; for another example, the weight of the connection edge between the nodes corresponding to the entities involved in the second software event with higher importance is higher. For example, the more important patch A is to repair vulnerability A, the higher the weight of the connection edge between the patch node corresponding to patch A and the vulnerability node corresponding to vulnerability A.

[0122] Finally, the server constructs a supply chain knowledge graph based on the above-mentioned nodes, the connecting edges between the nodes, and the weights of the connecting edges between the nodes.

[0123] It is easy to understand that based on the nodes in the supply chain knowledge graph, the node attributes of each node, the connecting edges between the nodes, and the weights of the connecting edges between the nodes, it is possible to characterize the mutual influence between the components, vulnerabilities, and patches in the open source software supply chain, and then to characterize and predict the security development trend of the open source software supply chain based on the supply chain knowledge graph.

[0124] In this embodiment, the server can construct a supply chain knowledge graph by determining the nodes, the connecting edges between the nodes, and the weights of the connecting edges. Based on the supply chain knowledge graph, the mutual influence between the components, vulnerabilities, and patches in the open source software supply chain can be represented, and the security development trend of the open source software supply chain can be represented and predicted based on the supply chain knowledge graph, thereby achieving timely early warning of risk events and providing emergency response strategies, thereby reducing the security risks of the open source software supply chain.

[0125] In an exemplary embodiment, the nodes in the supply chain knowledge graph include at least a component node corresponding to each component, a vulnerability node corresponding to each vulnerability, and a patch node corresponding to each patch.

[0126] like Figure 4 As shown, the above step S108, when it is determined based on the supply chain knowledge graph that there is a risk event in the open source software supply chain, issues warning information and emergency response strategies for the risk event, specifically including the following steps:

[0127] Step S402, for each vulnerability node in the supply chain knowledge graph, determine the risk information of the vulnerability node based on the connection relationship between the vulnerability node and the remaining nodes in the supply chain knowledge graph.

[0128] Step S404: When the risk information is greater than or equal to the preset risk information, a risk event corresponding to a vulnerability node in the open source software supply chain is determined.

[0129] Step S406, generating early warning information for risk events, and determining an emergency response strategy for risk events based on the connection relationship between the vulnerability node and the remaining nodes.

[0130] Step S408: issuing warning information and emergency response strategies.

[0131] Among them, risk information is used to characterize the degree of harm to the open source software supply chain after the vulnerability corresponding to the vulnerability node occurs. The risk information is related to the probability of occurrence, scope of impact and difficulty of repair of the vulnerability.

[0132] Among them, the connection relationship between nodes is represented by the connection edges between the node relationships and the weights of the connection edges; in specific applications, the connection relationship between two nodes can be divided into primary connection, secondary connection, tertiary connection...etc. according to whether there are other nodes between the two nodes.

[0133] Specifically, for each vulnerability node in the supply chain knowledge graph, the server uses the risk warning model, based on the rule reasoning ability and deep learning ability of the risk warning model, and based on the remaining nodes that are connected to the vulnerability node, to predict the probability of occurrence, scope of impact and difficulty of repair of the vulnerability corresponding to the vulnerability node, and then evaluates the risk information corresponding to the vulnerability node; then, when the risk information is greater than or equal to the preset risk information, the server determines that the vulnerability corresponding to the vulnerability node may occur, and after occurrence, it will pose a serious threat to the security of the open source software supply chain, that is, there is a risk event corresponding to the vulnerability node in the open source software supply chain; then, the server generates warning information for the risk event, and determines the emergency response strategy for the risk event based on the remaining nodes that are connected to the vulnerability node; finally, the server issues warning information and emergency response strategy.

[0134] Among them, the risk warning model is a pre-trained machine learning model or deep learning model. In specific applications, users can configure corresponding risk warning rules and emergency response strategy generation rules for the risk warning model based on the actual situation of the enterprise, so that the risk warning and emergency response strategy provided can better meet the actual needs of the enterprise.

[0135] For example, assuming that the server predicts the probability of occurrence and impact range of vulnerability A based on the supply chain knowledge graph, and then evaluates that the degree of harm to the open source software supply chain after the occurrence of vulnerability A is high, then the server further provides a repair strategy for vulnerability A based on the supply chain knowledge graph, such as using patch B to repair components A and component B to prevent the occurrence of vulnerability A from causing harm to components A and component B, or component C can replace component A, and vulnerability A will not occur in component C. Therefore, component C is used to replace component A to avoid the harm caused by the occurrence of vulnerability A, etc.

[0136] In this embodiment, the server can evaluate the hazards of vulnerabilities in the open source software supply chain through the supply chain knowledge graph and generate targeted countermeasures, thereby improving the security of the open source software supply chain.

[0137] In an exemplary embodiment, the above step S402 determines the risk information of the vulnerability node based on the connection relationship between the vulnerability node and the remaining nodes in the supply chain knowledge graph, and specifically includes the following contents: based on the connection relationship between the vulnerability node and the component nodes in the supply chain knowledge graph, determining the impact area of ​​the vulnerability node in the supply chain knowledge graph; based on the component nodes in the impact area, and the connection relationship between the vulnerability node and the component nodes in the impact area, determining the risk information of the vulnerability node.

[0138] Among them, the impact area is used to characterize the impact range of the vulnerability corresponding to the vulnerability node.

[0139] Among them, the component nodes in the impact area are used to represent the components that will be affected after the vulnerability corresponding to the vulnerability node occurs.

[0140] Specifically, the server determines the impact range of the vulnerability corresponding to the vulnerability node based on the connection relationship between the vulnerability node and the component node in the supply chain knowledge graph, and obtains the impact area of ​​the vulnerability node in the supply chain knowledge graph; then, the server determines the risk information of the vulnerability node based on the importance of the components corresponding to the component nodes in the impact area in the open source software supply chain, and the weights of the connecting edges between these component nodes and the vulnerability nodes, for example, the importance of the components is weighted and summed according to the weights of the corresponding connecting edges to obtain the risk information of the vulnerability node; further, in the process of determining the risk information, the number of component nodes in the impact area can also be considered, that is, the risk information is determined in combination with the number of components affected by the vulnerability corresponding to the vulnerability node.

[0141] In a specific application, the server determines the impact range based on the attenuation effect of the impact. For example, the server determines the impact area of ​​the vulnerable node based on the component nodes whose connection relationship with the vulnerable node is within the third level of connection.

[0142] The above-mentioned step S406 determines the emergency response strategy for the risk event based on the connection relationship between the vulnerability node and the remaining nodes, and specifically includes the following contents: based on the connection relationship between the vulnerability node and the patch nodes in the affected area, the target patch node for repairing the vulnerability node is determined among the patch nodes in the affected area; based on the connection relationship between the vulnerability node and the component nodes in the affected area, the target component node for the target patch node to be applied is determined among the component nodes in the affected area; based on the target patch node and the target component node, the emergency response strategy for the risk event is determined.

[0143] Specifically, the server determines, among the patch nodes in the impact area, a target patch node for repairing the vulnerability node based on the connection relationship between the vulnerability node and the patch nodes in the impact area; for example, among the patch nodes in the impact area, the server determines, based on the connection edges and weights between the vulnerability node and the patch nodes in the impact area, a patch node that is connected to the vulnerability node and has the largest weight of the corresponding connection edge (among the vulnerability node and each patch node in the impact area) as the target patch node.

[0144] At the same time, the server determines the target component node of the target patch node to be applied among the component nodes in the impact area based on the connection relationship between the vulnerability node and the component nodes in the impact area; for example, the server determines the component node that can block the spread of the vulnerability corresponding to the vulnerability node as the target component node among the component nodes in the impact area based on the connection edges and their weights between the vulnerability node and the component nodes in the impact area.

[0145] Then, the server generates an emergency response strategy based on the target patch node and the target component node to provide users with solutions to the risk events corresponding to the vulnerability node.

[0146] In this embodiment, the server can determine the propagation path and propagation range of the vulnerability based on the connection relationship between the vulnerability node and the component node in the supply chain knowledge graph, and then evaluate the impact caused by the vulnerability. Based on the connection relationship between the vulnerability node and the patch node, and the vulnerability node and the component node in the impact area, the server can provide corresponding solutions for the vulnerability corresponding to the vulnerability node, avoid the threat to the open source software supply chain after the vulnerability occurs, and ensure the security of the open source software supply chain.

[0147] In an exemplary embodiment, in the above step S106, after obtaining the supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge, the following contents are specifically included: receiving a query request for the open source software supply chain; locating the target node associated with the query request in each node in the supply chain knowledge graph; generating a query result corresponding to the query request based on the connection relationship between the target node and the remaining nodes in the supply chain knowledge graph; and displaying the query result.

[0148] Specifically, the server also provides a query function based on the large language model; the server receives the query request input by the user, and locates at least one target node associated with the query request in each node in the supply chain knowledge graph, and based on the connection relationship between the target node and the remaining nodes in the supply chain knowledge graph, generates a query result corresponding to the query request and returns it to the user.

[0149] For example, when a user needs to query the dependency relationship between component A and other components, the server can search for component nodes that have a connection relationship with the component node corresponding to component A in the supply chain knowledge graph, and return the components corresponding to these component nodes to the user. For another example, when a user needs to query the impact of vulnerability B on the open source software supply chain, the server can locate the vulnerability node corresponding to vulnerability B based on the supply chain knowledge graph, and based on the connection relationship between the vulnerability node and the other nodes, evaluate the risk information corresponding to the vulnerability node, and then obtain the risk information of vulnerability B and return it to the user.

[0150] In specific applications, the query results can be text or a partial area in the supply chain knowledge graph; that is, the server can generate and return the result text corresponding to the query request based on the connection relationship between the target node and the remaining nodes in the supply chain knowledge graph, or it can intercept and return the sub-graph corresponding to the query request in the supply chain knowledge graph based on the connection relationship between the target node and the remaining nodes in the supply chain knowledge graph.

[0151] In specific applications, the server can display the query results through the server front end or the security management terminal front end.

[0152] In this embodiment, the server provides a query function. Based on the query function, the user can quickly obtain the information he needs to know, which is convenient for the user to manage the open source software supply chain.

[0153] In an exemplary embodiment, the server provides a multi-level storage engine: first, the server stores the associated information in the database and provides a full-text query function based on Elasticsearch (a distributed search and analysis engine) for the database; second, the server stores the supply chain knowledge graph in the Neo4j (a high-performance NOSQL graph database) database, thereby improving the graph query function; third, for query requests initiated by users more frequently, the server caches the query results in the Redis (a distributed cache database) database.

[0154] Based on the above multi-level storage engine, when a user enters a query request, the server first searches for the corresponding query result in Redis. If it exists, it is returned directly. If it does not exist, it is searched based on Neo4j. When the user chooses to use Elasticsearch for full-text query, the query result is obtained from the database.

[0155] In an exemplary embodiment, in the above step S106, after obtaining the supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge, the following contents are specifically included: based on the connection relationship between each node in the supply chain knowledge graph, determining the indicator value of the open source software supply chain under at least one security risk indicator; displaying the supply chain knowledge graph and the indicator value of the open source software supply chain under each security risk indicator.

[0156] Specifically, the server determines the index value of the open source software supply chain under at least one security risk index based on the connection relationship between each node in the supply chain knowledge graph, such as the component security index, vulnerability risk index, and overall security index of the open source software supply chain.

[0157] Then, the server displays the supply chain knowledge graph and the indicator values ​​of the open source software supply chain under each security risk indicator, so that users can view the open source software supply chain at any time and grasp the real-time security risk situation of the open source software supply chain in a timely manner.

[0158] In specific applications, the server can display the supply chain knowledge graph and the indicator values ​​of the open source software supply chain under various security risk indicators through the server front end or the security management terminal front end.

[0159] In specific applications, users can interact with the displayed supply chain knowledge graph, such as zooming in, zooming out, and filtering, to view some information in the open source software supply chain.

[0160] In specific applications, the server can display indicator values ​​in the form of charts to help users promptly identify potential security issues and provide strong support for the security management of the open source software supply chain.

[0161] In this embodiment, the security risk index at least includes a risk propagation index between components in the open source software supply chain. The risk propagation index between components can be expressed by the following formula 2:

[0162] (Formula 2)

[0163] in, For each component The risk spread index at the moment, that is, the scope of risk impact, is the initial risk impact range, is the risk diffusion coefficient, is the risk attenuation coefficient. This formula reflects the diffusion and attenuation process of security risks in the supply chain network and provides an important reference for analyzing the risk propagation mechanism.

[0164] In this embodiment, the server can display the real-time security risk situation of the open source software supply chain by displaying the supply chain knowledge graph and indicator values, so that users can promptly discover potential security issues and provide strong support for the security management of the open source software supply chain.

[0165] In order to more clearly illustrate the open source software supply chain security management method provided by the embodiment of the present application, the open source software supply chain security management method is specifically described below with a specific embodiment, but it should be understood that the embodiment of the present application is not limited to this. In one of the exemplary embodiments, the present application also provides an open source software supply chain security knowledge management method and system based on a large language model, which specifically includes the following contents:

[0166] like Figure 5 As shown, this embodiment provides an open source software supply chain security knowledge management system based on a large language model; the system includes at least a data acquisition layer, a knowledge extraction and fusion layer, a knowledge representation and storage layer, an intelligent reasoning and decision-making layer, and a visualization interaction layer.

[0167] Among them, the data collection layer includes a data collection module and a data preprocessing module; the data collection module is used to collect related information related to open source software from the Internet; the data preprocessing module is used to preprocess the related information for subsequent knowledge extraction.

[0168] Among them, the knowledge extraction and fusion layer is implemented based on a large language model, including an entity recognition module, an event extraction module, a relationship extraction module and a knowledge fusion module; the entity recognition module is used to identify named entities from associated information; the event extraction module is used to extract events containing named entities from associated information; the relationship extraction module is used to extract the relationship between entities from associated information and events; the knowledge fusion module is used to fuse the above-extracted knowledge to eliminate its redundancy and repetition.

[0169] Among them, the knowledge representation and storage layer includes a knowledge graph construction module, a graph database, a distributed cache database, a global database and a search engine; the knowledge graph construction module is used to construct a knowledge graph based on the knowledge extracted by the knowledge extraction and fusion layer; the graph database is used to store the knowledge graph; the distributed cache database is used to store knowledge that is frequently accessed by users; the global database is used to store related information, and the search engine is used to support searches in the global database.

[0170] Among them, the intelligent reasoning and decision-making layer is implemented based on the reasoning engine, including the reasoning module and the decision-making module; the reasoning module is used to infer the security risks in the open source software supply chain; the decision module is used to generate response strategies for the inferred security risks that need to be handled.

[0171] Among them, the visual interaction layer is used to display the knowledge graph and the real-time security risk situation of the open source software supply chain based on the knowledge graph to users.

[0172] In this embodiment, the system also provides an identity authentication function, and all users using the system need to pass identity authentication.

[0173] In this real-time, the system also limits the request frequency of the system interface based on the token bucket algorithm to ensure the stability and reliability of the system under high concurrency conditions.

[0174] In this embodiment, the method and system provided in this embodiment have brought about a qualitative leap in the open source software supply chain security knowledge management based on a large language model in terms of specific business functions such as information acquisition, knowledge management, and decision support.

[0175] First, the efficiency of information acquisition has been greatly improved. Under the existing technology, a large number of links in the information acquisition process rely on manual intervention, such as data screening and preliminary sorting, which not only consumes a lot of time and human resources, but also easily introduces errors and omissions due to human factors. However, this embodiment has achieved a high degree of automation in the information acquisition process by introducing advanced intelligent automation technology. From the automatic identification and connection of data sources to the automatic collection, classification and preliminary analysis of data, this embodiment can complete most of the work independently, requiring only a small amount of manual supervision and correction. This highly automated operation mode greatly improves the efficiency and stability of information acquisition, reduces the burden of manual operation, and makes the information acquisition process smoother and more reliable.

[0176] Second, the data accuracy has been greatly improved. Since the data sources of open source software are extensive and complex, there are problems such as inconsistent data formats and uneven data quality. The existing technology has deficiencies in data cleaning, integration and verification, resulting in low data accuracy. This embodiment can more accurately identify and process abnormal data, duplicate data and incomplete data by designing data cleaning and verification algorithms and combining machine learning and data mining technologies.

[0177] Third, the efficiency of knowledge management has been greatly improved. In the prior art, first, the update cycle of knowledge management is long, which affects the ability to identify and analyze the latest security risks. Secondly, there is a lack of comprehensive coverage of the complex and diverse knowledge structure and extensive knowledge fields of open source software, resulting in a low knowledge coverage rate. This embodiment achieves rapid updates of knowledge management by establishing a real-time data monitoring mechanism and an automated knowledge update process. At the same time, through an in-depth understanding and analysis of the open source software supply chain, a comprehensive and detailed knowledge graph structure is constructed, covering all aspects of open source software. In addition, in the process of data collection and knowledge fusion, multi-source data fusion technology and semantic analysis technology are introduced, which can extract and analyze relevant information from various data sources to fill knowledge gaps, thereby improving the ability to respond to security risks in the open source software supply chain.

[0178] Fourth, the decision-making knowledge ability has been greatly enhanced. The existing technology is difficult to accurately identify complex security risks in the risk identification process, and lacks comprehensive consideration and personalized analysis of the actual situation, resulting in low applicability of decision-making recommendations. This embodiment introduces advanced machine learning and deep learning algorithms, combined with big data analysis and data mining technology, to build a more complex and accurate risk identification model. The model can learn patterns and rules in historical security data, automatically mine potential security risk factors, and perform real-time analysis and prediction of new data; at the same time, this embodiment introduces an intelligent decision-making support system, combined with domain expert knowledge and actual case data, to build a more flexible and intelligent decision-making recommendation generation mechanism. This mechanism can automatically generate personalized decision recommendations based on different risk scenarios and user needs, and adjust and optimize decision plans in real time.

[0179] It should be understood that, although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0180] Based on the same inventive concept, the embodiment of the present application also provides a security management system for an open source software supply chain for implementing the security management method for an open source software supply chain involved above. The implementation scheme for solving the problem provided by the system is similar to the implementation scheme recorded in the above method, so the specific limitations in the embodiments of the security management system for one or more open source software supply chains provided below can refer to the limitations of the security management method for an open source software supply chain above, and will not be repeated here.

[0181] In an exemplary embodiment, Figure 6 As shown, a security management system for an open source software supply chain is provided, including: an information collection layer 602, a knowledge extraction layer 604, a knowledge representation layer 606 and a risk warning layer 608, wherein:

[0182] The information collection layer 602 is used to collect relevant information of open source software.

[0183] The knowledge extraction layer 604 is used to extract the entities in the open source software supply chain of the open source software, the software events associated with the security risks of the open source software in the open source software supply chain, and the association relationships between the entities as the supply chain knowledge of the open source software supply chain; each entity includes at least the components, vulnerabilities and patches corresponding to the open source software, and the software events include at least a first software event that increases the security risk and a second software event that reduces the security risk.

[0184] The knowledge representation layer 606 is used to obtain a supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge.

[0185] The risk warning layer 608 is used to issue warning information and emergency response strategies for risk events when it is determined that there are risk events in the open source software supply chain based on the supply chain knowledge graph.

[0186] In an exemplary embodiment, the knowledge extraction layer 604 is further used to extract the components, vulnerabilities and patches corresponding to the open source software from the association information based on the pre-trained knowledge extraction model to obtain the entities; based on the knowledge extraction model and the entities, extract the first software events that increase the security risk and the second software events that reduce the security risk in the open source software supply chain from the association information to obtain the software events; based on the knowledge extraction model, extract the first association relationship between the components, the second association relationship between the components and the vulnerabilities, the third association relationship between the patches and the vulnerabilities, and the fourth association relationship between the components and the patches from the association information and the software events to obtain the association relationship between the entities; determine the entities, the association relationship between the entities, and the software events as the supply chain knowledge of the open source software supply chain; wherein the first association relationship between two components represents whether there is a dependency relationship between the two components; the second association relationship between each component and each vulnerability represents whether there is a vulnerability in the component; the third association relationship between each patch and each vulnerability represents whether the patch is a patch released for the vulnerability; the fourth association relationship between each component and each patch represents whether the patch is applied to the component.

[0187] In an exemplary embodiment, the knowledge representation layer 606 is also used to construct a node corresponding to each entity; determine the connection edges between each node based on the association relationship between each entity; determine the weight of the connection edges between each node based on each software event; and construct a supply chain knowledge graph based on each node, the connection edges between each node, and the weight of the connection edges between each node.

[0188] In an exemplary embodiment, the nodes in the supply chain knowledge graph include at least a component node corresponding to each component, a vulnerability node corresponding to each vulnerability, and a patch node corresponding to each patch.

[0189] The risk warning layer 608 is also used to determine the risk information of each vulnerability node in the supply chain knowledge graph based on the connection relationship between the vulnerability node and the remaining nodes in the supply chain knowledge graph; when the risk information is greater than or equal to the preset risk information, determine the risk event corresponding to the vulnerability node in the open source software supply chain; generate warning information for the risk event, and determine the emergency response strategy for the risk event based on the connection relationship between the vulnerability node and the remaining nodes; and issue warning information and emergency response strategy.

[0190] In an exemplary embodiment, the risk warning layer 608 is further used to determine the impact area of ​​the vulnerability node in the supply chain knowledge graph based on the connection relationship between the vulnerability node and the component nodes in the supply chain knowledge graph; determine the risk information of the vulnerability node based on the component nodes in the impact area and the connection relationship between the vulnerability node and the component nodes in the impact area;

[0191] The risk warning layer 608 is also used to determine, among the patch nodes in the impact area, a target patch node for repairing the vulnerability node based on the connection relationship between the vulnerability node and the patch nodes in the impact area; and to determine, among the component nodes in the impact area, a target component node for applying the target patch node based on the connection relationship between the vulnerability node and the component nodes in the impact area; and to determine an emergency response strategy for risk events based on the target patch node and the target component node.

[0192] In an exemplary embodiment, the security management system of the open source software supply chain also includes a query layer for receiving query requests for the open source software supply chain; locating the target node associated with the query request in each node in the supply chain knowledge graph; generating query results corresponding to the query request based on the connection relationship between the target node and the remaining nodes in the supply chain knowledge graph; and displaying the query results.

[0193] In an exemplary embodiment, the security management system of the open source software supply chain also includes a visualization interaction layer for determining the indicator value of the open source software supply chain under at least one security risk indicator based on the connection relationship between each node in the supply chain knowledge graph; and displaying the supply chain knowledge graph and the indicator value of the open source software supply chain under each security risk indicator.

[0194] Each module in the above-mentioned open source software supply chain security management system can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.

[0195] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 7As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store associated information of open source software. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a method for secure management of an open source software supply chain is implemented.

[0196] Those skilled in the art will understand that Figure 7 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0197] In an exemplary embodiment, a computer device is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above-mentioned method embodiments when executing the computer program.

[0198] In an exemplary embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0199] In an exemplary embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0200] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., but are not limited to this.

[0201] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0202] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A security management method for an open source software supply chain, characterized in that: The method comprises: Collect relevant information about open source software; Extracting from the association information entities in the open source software supply chain of the open source software, software events in the open source software supply chain that are associated with the security risk of the open source software, and association relationships between the entities as supply chain knowledge of the open source software supply chain; the entities at least include components, vulnerabilities, and patches corresponding to the open source software, and the software events at least include a first software event that increases the security risk and a second software event that reduces the security risk; Based on the supply chain knowledge, a supply chain knowledge graph of the open source software supply chain is obtained; When it is determined that there is a risk event in the open source software supply chain based on the supply chain knowledge graph, early warning information and emergency response strategies for the risk event are issued.

2. The method according to claim 1, characterized in that Extracting from the association information entities in the open source software supply chain of the open source software, software events in the open source software supply chain associated with the security risk of the open source software, and association relationships between the entities, includes: Based on the pre-trained knowledge extraction model, extract the components, vulnerabilities and patches corresponding to the open source software from the associated information to obtain the entities; Based on the knowledge extraction model and the entities, extracting from the association information the first software events that increase the security risk and the second software events that reduce the security risk in the open source software supply chain to obtain the software events; Based on the knowledge extraction model, extracting from the association information and the software events a first association relationship between the components, a second association relationship between the components and the vulnerabilities, a third association relationship between the patches and the vulnerabilities, and a fourth association relationship between the components and the patches, to obtain association relationships between the entities; Determine the entities, the associations between the entities, and the software events as supply chain knowledge of the open source software supply chain; Among them, the first association relationship between two components represents whether there is a dependency relationship between the two components; the second association relationship between each component and each vulnerability represents whether the vulnerability exists in the component; the third association relationship between each patch and each vulnerability represents whether the patch is a patch released for the vulnerability; the fourth association relationship between each component and each patch represents whether the patch is applied to the component.

3. The method according to claim 1, characterized in that The step of obtaining a supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge includes: Construct the node corresponding to each entity; Based on the association relationship between the entities, determining the connection edges between the nodes; Based on the software events, determining the weights of the connecting edges between the nodes; The supply chain knowledge graph is constructed based on the nodes, the connecting edges between the nodes, and the weights of the connecting edges between the nodes.

4. The method according to claim 1, characterized in that The nodes in the supply chain knowledge graph include at least a component node corresponding to each component, a vulnerability node corresponding to each vulnerability, and a patch node corresponding to each patch; When it is determined that there is a risk event in the open source software supply chain based on the supply chain knowledge graph, issuing warning information and emergency response strategies for the risk event includes: For each vulnerability node in the supply chain knowledge graph, based on the connection relationship between the vulnerability node and other nodes in the supply chain knowledge graph, determine the risk information of the vulnerability node; In the case where the risk information is greater than or equal to the preset risk information, determining that a risk event corresponding to the vulnerability node exists in the open source software supply chain; Generate early warning information for risk events, and determine an emergency response strategy for the risk events based on the connection relationship between the vulnerability node and the remaining nodes; The warning information and the emergency response strategy are issued.

5. The method according to claim 4, characterized in that The determining the risk information of the vulnerability node based on the connection relationship between the vulnerability node and other nodes in the supply chain knowledge graph includes: Determine the impact area of ​​the vulnerability node in the supply chain knowledge graph based on the connection relationship between the vulnerability node and the component node in the supply chain knowledge graph; Determining risk information of the vulnerable node based on the component nodes in the impact area and the connection relationship between the vulnerable node and the component nodes in the impact area; The determining of an emergency response strategy for the risk event based on the connection relationship between the vulnerability node and the remaining nodes includes: Based on the connection relationship between the vulnerability node and the patch nodes in the affected area, a target patch node for repairing the vulnerability node is determined among the patch nodes in the affected area; based on the connection relationship between the vulnerability node and the component nodes in the affected area, a target component node to which the target patch node is to be applied is determined among the component nodes in the affected area; An emergency response strategy for the risk event is determined based on the target patch node and the target component node.

6. The method according to any one of claims 1 to 5, characterized in that: After obtaining the supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge, the method further includes: Receiving a query request for the open source software supply chain; Among the nodes in the supply chain knowledge graph, locate a target node associated with the query request; Generate a query result corresponding to the query request based on the connection relationship between the target node and the remaining nodes in the supply chain knowledge graph; The query result is displayed.

7. The method according to any one of claims 1 to 5, characterized in that: After obtaining the supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge, the method further includes: Determine an index value of the open source software supply chain under at least one security risk index based on a connection relationship between nodes in the supply chain knowledge graph; The supply chain knowledge graph and the indicator values ​​of the open source software supply chain under various security risk indicators are displayed.

8. A security management system for an open source software supply chain, characterized in that: The system comprises: Information collection layer, used to collect relevant information of open source software; A knowledge extraction layer, for extracting entities in the open source software supply chain of the open source software, software events in the open source software supply chain associated with the security risk of the open source software, and associations between the entities, as supply chain knowledge of the open source software supply chain; the entities at least include components, vulnerabilities and patches corresponding to the open source software, and the software events at least include a first software event that increases the security risk and a second software event that reduces the security risk; A knowledge representation layer, used to obtain a supply chain knowledge graph of the open source software supply chain based on the supply chain knowledge; The risk warning layer is used to issue warning information and emergency response strategies for risk events when it is determined that there are risk events in the open source software supply chain based on the supply chain knowledge graph.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Software component supply chain security detection method and device based on knowledge graph

    CN115033894A

  • Early warning method based on knowledge graph, electronic equipment and readable storage medium

    CN115687633A

  • Security detection method and device for supply chain management system

    CN115987570A

  • Multi-source software supply chain intelligent analysis method and system

    CN119720225A

  • Software risk detection method and device, electronic equipment and medium

    CN119830297A