Software vulnerability detection method, system and product based on bidirectional gating graph neural network

Through the method based on the bidirectional gated graph neural network, the source code is analyzed to generate code attribute graphs, extract and fuse node features, the problem of limited context information propagation in the existing technology is solved, and the accuracy and robustness of software vulnerability detection are significantly improved.

CN120030550APending Publication Date: 2025-05-23ANHUI UNIV
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510120148.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-25
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Existing machine learning-based software vulnerability detection methods have the problem that context information is lost or limited during the propagation process, resulting in reduced vulnerability detection accuracy.

Method used

Using a method based on a bidirectional gated graph neural network, a code attribute graph (CPG) is generated by analyzing the source code, the type and semantic features of the node are extracted, and the K-wheel forward and backward propagation are performed, the characteristics are fused for graph-level embedding, and finally input into a multi-layer perceptron for binary classification.

Benefits of technology

It enhances the understanding of code context and global dependencies, avoids context information loss, and improves the accuracy, robustness and detection accuracy of vulnerability detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030550A_ABST
    Figure CN120030550A_ABST
Patent Text Reader

Abstract

The invention relates to a software vulnerability detection method, system and product based on a bidirectional gating graph neural network. The software vulnerability detection method based on the bidirectional gating graph neural network comprises the following steps: S1, analyzing a source code into a code attribute graph (CPG); and S2, extracting a type feature of the mth v, obtaining a type feature vector # imgabs0 #, extracting a semantic feature of the mth v, obtaining a semantic feature vector # imgabs1 #, splicing # imgabs2 # and # imgabs3 #, and obtaining an initial feature vector # imgabs4 # of the mth v. According to the method, a bidirectional gating graph neural network structure is introduced, and through a bidirectional message passing mechanism, both a forward dependency relationship and a backward dependency relationship can be captured. Compared with a traditional one-way graph neural network, the method has the advantages that the ability of understanding dependency on code context and global dependency is enhanced, it is ensured that information is fully shared and updated, context information is prevented from being lost or limited in the propagation process, and therefore the accuracy, robustness and detection precision of vulnerability detection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software vulnerability detection, and in particular to a software vulnerability detection method, system and product based on a bidirectional gated graph neural network. Background Art

[0002] In the field of software vulnerability detection, traditional methods rely on static analysis tools and pattern matching algorithms. Although these methods can identify known types of vulnerabilities to a certain extent, they are powerless when faced with increasingly complex new types of vulnerabilities. Although existing machine learning-based methods have improved, they still have significant limitations. For example, traditional vulnerability detection methods usually use unidirectional gated graph neural networks for processing, which only support unidirectional edge information transmission mechanisms. However, many logical relationships and potential vulnerabilities in the code often span multiple functions, modules or classes and rely on the understanding of the global context. Therefore, traditional vulnerability detection methods cannot effectively utilize the input (incoming edge) and output (outgoing edge) information of the node, which may cause the context information to be lost or limited during the propagation process, especially when dealing with complex dependencies in the code, resulting in a decrease in the accuracy of software vulnerability detection. Summary of the invention

[0003] Based on this, it is necessary to provide a software vulnerability detection method, system and product based on a bidirectional gated graph neural network to address the problem that existing machine learning-based vulnerability detection methods may cause context information to be lost or limited during the propagation process.

[0004] In a first aspect, the present invention proposes a software vulnerability detection method based on a bidirectional gated graph neural network, which comprises the following steps:

[0005] S1. Parse the source code into a code property graph CPG; wherein the CPG includes M nodes v, and the mth v represents the mth syntax unit of the source code; m∈[1,M];

[0006] S2. Extract the type feature of the mth v and obtain the type feature vector

[0007] Extract the semantic features of the mth v and obtain the semantic feature vector

[0008] Will and Splice and get the initial eigenvector of the mth v

[0009] S3, first According to the connection relationship of the edges in CPG, K rounds of forward propagation and K rounds of backward propagation are performed to obtain Forward message of round k and backward messages K is the maximum number of rounds;

[0010] Then and Fusion gets fusion features Perform the k+1th round of forward propagation and backward propagation;

[0011] After iterating to the Kth round, Update to the final fusion feature

[0012] Traverse M v and get M final fusion features

[0013] Will Add dimension by dimension to get the graph vector h graph To characterize the global features of the source code;

[0014] S4, h graph The input is processed in the trained multi-layer perceptron to obtain a binary classification result of 0 or 1; 0 means no vulnerability and 1 means there is a vulnerability.

[0015] In a second aspect, the present invention further proposes a software vulnerability detection system based on a bidirectional gated graph neural network, which uses the software vulnerability detection method based on a bidirectional gated graph neural network in the first aspect. The software vulnerability detection system based on a bidirectional gated graph neural network includes a generation module, a feature extraction module, a propagation module and a neural network module.

[0016] Among them, a generation module is used to parse the source code into a code property graph CPG.

[0017] Feature extraction module, which is used to extract the type feature vector of CPG node v and semantic feature vector and will and Splice to get the initial eigenvector of v

[0018] The propagation module is used to According to the connection relationship of the edges in CPG, K rounds of forward propagation and K rounds of backward propagation are performed to obtain Forward message of round k and backward messages Then and Fusion gets fusion features Perform the k+1th round of forward propagation and backward propagation; after iterating to the Kth round, Update to the final fusion feature It is also used to traverse M v to obtain M final fusion features Will Add dimension by dimension to get the graph vector h graph .

[0019] Neural network module, which is used to graph After processing, a binary classification result of 0 or 1 is obtained; 0 means no vulnerability and 1 means there is a vulnerability.

[0020] In a third aspect, the present invention further proposes a software program product, which includes program instructions, and when the software program product is run on an electronic device, it enables the electronic device to execute the steps of the software vulnerability detection method based on a bidirectional gated graph neural network in the first aspect.

[0021] The beneficial effects of the present invention include:

[0022] 1. The present invention introduces a bidirectional gated graph neural network structure, which can capture both forward and backward dependencies through a bidirectional message passing mechanism. Compared with traditional unidirectional graph neural networks, the present invention enhances the ability to understand code context and global dependencies, ensures that information is fully shared and updated, and avoids the loss or limitation of context information during the propagation process, thereby improving the accuracy, robustness and detection precision of vulnerability detection.

[0023] 2. The present invention can identify key samples in minority class samples by resampling the training sample set of the adopted model, and generate synthetic samples based on these groups, thereby avoiding the generation of redundancy and noise, so as to address the problem of imbalance in the number of vulnerability samples and non-vulnerability samples, and generate a high-quality training data set with balanced category distribution. Compared with traditional resampling techniques such as SMOTE, the present invention can effectively balance the ratio of vulnerability code to non-vulnerability code in the data set, improve the learning ability of the model when processing unbalanced data, and significantly improve the model's ability to identify vulnerability code (minority class samples).

[0024] 3. Traditional vulnerability detection methods usually use low-dimensional embedding models, such as Word2Vec, to represent code features. However, low-dimensional models can only capture the more superficial semantic information of the code, and it is difficult to effectively capture the detailed logic and deep dependencies in the code. The present invention uses the GraphCodeBERT model to perform deep semantic embedding of code nodes, which can map each code node into an 837-dimensional feature vector, and can fully capture the complex logic and dependencies in the code. By using high-dimensional feature representation, the present invention significantly improves the feature expression ability of the model and shows significant advantages in complex vulnerability detection tasks. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0026] Figure 1 Flow chart of a software vulnerability detection method based on a bidirectional gated graph neural network in an embodiment;

[0027] Figure 2 Flow chart of data resampling in the embodiment. DETAILED DESCRIPTION

[0028] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0029] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which the present invention belongs. The terms used herein in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "or / and" used herein includes any and all combinations of one or more of the related listed items.

[0030] Please refer to Figure 1 , this embodiment provides a software vulnerability detection method based on a bidirectional gated graph neural network, which includes the following steps:

[0031] S1. Parse the source code into a code property graph CPG, where CPG includes M nodes v, and the mth v represents the mth syntax unit of the source code; m∈[1,M].

[0032] Specifically, the Joern-cli tool is first used to generate an abstract syntax tree AST, a control flow graph CFG, and a program dependency graph PDG based on the source code, and then AST, CFG, and PDG are merged to form a CPG to achieve unified modeling of source code syntax, execution logic, and dependencies. The definition of CPG is expressed in mathematical form as follows:

[0033] CPG=(V,E,λ,μ)

[0034] V=V A

[0035] E=E A ∪E C ∪E P

[0036] λ=λ A ∪λ C ∪λ P

[0037] μ=μ A ∪μ C ∪μ P

[0038] Where V represents the node set of CPG. A represents the node set of AST, each of which represents a grammatical unit in the source code (such as variables, operators, function calls, etc.). E represents the edge set of CPG; E A 、E C 、E P are the edge sets of AST, CFG, and PDG respectively. λ represents the set of labeling functions of the edges of CPG; A , C , P They represent the label function sets of AST, CFG, and PDG respectively. μ represents the attribute function set of the nodes of CPG; μ A , μ C , μ P Represents the attribute function sets of AST, CFG, and PDG respectively.

[0039] The resulting CPG integrates the static structure and dynamic execution logic of the source code, and can simultaneously capture the syntax elements, control dependencies, and data dependency features of the source code, enabling CPG to more comprehensively express the source code features and provide high-quality input features for subsequent vulnerability detection tasks.

[0040] S2. Extract the type feature of the mth v and obtain the type feature vector Extract the semantic features of the mth v and obtain the semantic feature vector Will and Splice and get the initial eigenvector of the mth v

[0041] In this step, the node v in the CPG needs to be converted into a compact feature vector with consistent length, while maintaining semantic and grammatical information, and generating an initial embedding representation for each node. The features of each v include two parts: type features and semantic features.

[0042] Among them, the node type (such as variables, operators, function calls, etc.) is converted into a fixed-length type feature vector T through One-Hot Encoding. v For example, the "if" conditional node is encoded as [1, 0, 0, ..., 0], and the "+" operator node is encoded as [0, 1, 0, ..., 0].

[0043] The semantics of the nodes are extracted using the GraphCodeBERT model. In this embodiment, the pre-trained GraphCodeBERT model can be used directly, so there is no need to train from scratch, saving a lot of time. And compared to the traditional vulnerability detection model that usually uses Word2Vec to generate semantic vectors (the dimension is only more than 100), the use of the GraphCodeBERT model in this step can extract higher-dimensional semantic vectors, thereby more comprehensively capturing the logic and complex information in the source code. Due to the complexity of the code logic and the large amount of information, a higher vector dimension helps to more completely extract the detailed information contained in the code and improve the vulnerability detection performance of the model. The extracted The dimension is set to 837 dimensions to strike a balance between extracting detailed information and optimizing model performance.

[0044] The dimension is The sum of the dimensions of . Through the combination of type features and semantic features, the spliced It can capture the structure information and code snippet information of v. Take a source code as an example: The source code is as follows:

[0045] if(x>0){

[0046] y=x+1;

[0047] }

[0048] The corresponding nodes are: conditional node if and operator node +. For the conditional node if, its type feature vector T if =[1,0,0,…] indicates if type. Semantic feature vector C if The GraphcodeBERT model is used to represent the contextual semantics of if. So the initial feature vector of the if node is represented as x if =[T if ; C if ]. For the operator node +, the type feature vector T + =[0,1,0,…] represents operator + type. Semantic feature vector C + The contextual semantics of + is represented by the GraphcodeBERT model. So the initial feature vector of the operator node + is x + =[T+ ; C + ].

[0049] S3, initial feature vector Represents the static characteristics of the mth node v, that is, the information has not been updated by neighboring nodes.

[0050] Step 1: Exploitation And the connection relationship of the edges in CPG is carried out through K rounds of forward propagation and K rounds of backward propagation, and we get Forward message of round k and backward messages K is the maximum number of rounds.

[0051] For the forward propagation, By all its forward neighbor nodes μ n →The feature aggregation is obtained, and its calculation formula is:

[0052]

[0053] Where N →(ν) For all forward neighbor nodes μ of v n →Collection. is the nth forward neighbor node μ n →Forward information in the k-1th round of propagation, n∈[1,N →(ν) ]. → represents the direction of forward propagation, that is, from the forward neighbor node μ n → passed to v. SUM represents the summation operation. The so-called forward neighbor node μ n → refers to the node whose edge points to v, that is, the parent node of v. This calculation formula describes the calculation of v from its forward neighbor node μ in the kth iteration. n → The information aggregation process received. The goal of the forward propagation is to capture the positive dependencies in the CPG, which starts from the input edge of the target node and forwards the neighboring node μ n →The feature information of the target node is passed to the target node to capture the positive dependency. This process can effectively integrate the information of the positive dependency into the embedding vector of the target node, providing input for subsequent steps.

[0054] For the backward propagation, it is similar to the forward propagation. By all its backward neighbor nodes μ n ←The feature aggregation is obtained, and its calculation formula is:

[0055]

[0056] Where N ←(ν) is the number of all backward neighbor nodes μ of v n ← collection. is the nth backward neighbor node μ n ←The embedding vector in the k-1th round of propagation. ←Indicates the direction of backward propagation. Backward neighbor node μ n ← refers to the node pointed to by the edge of v, that is, the child node of v. The goal of backward propagation is to capture the reverse dependency in CPG, which starts from the output edge of the target node and propagates the information along the reverse path from the back to the neighbor node μ n ←Backtrack to the target node to capture the reverse dependencies. This process can integrate the information of these reverse dependencies into the embedding representation of the target node, providing more comprehensive contextual information for the features of the target node and further improving the expressiveness of the target node embedding.

[0057] Step 2: and Fusion gets fusion features Perform the k+1th round of forward propagation and backward propagation. After iterating to the Kth round, Update to the final fusion feature.

[0058] Specifically, in this embodiment, a gating mechanism is used for fusion. The fusion method includes the following steps:

[0059] First fuse through the Fuse function and Get the middle vector The fusion formula is:

[0060]

[0061] z=σ(W z [a; b; a⊙b; ab]+b z )

[0062] In the formula, Fuse represents the Fuse function. a represents b means ⊙ represents element-by-element multiplication. z represents the gate vector. σ represents the sigmoid activation function. W Z and b z denote weight and bias respectively.

[0063] Then according to and the k-1th round Updated by the gated recurrent unit, we get Its update expression is:

[0064]

[0065] Where GRU stands for gated recurrent unit.

[0066] The final result It contains the information of the target node itself and the context information of its neighbor nodes (including forward neighbor nodes and backward neighbor nodes). After integration through two-way message passing, the characteristics of the target node are enriched.

[0067] Step 3: Traverse M v to obtain M final fusion features Will Add dimension by dimension to get the graph vector h graph To characterize the global features of source code.

[0068] In this step, we need to convert the node-level embedding vector into a graph-level embedding vector. This process involves aggregating all node embeddings. Specifically, Perform a sum operation to generate a unified, fixed-dimensional graph vector h graph This summation operation is By adding dimension by dimension, the generated h graph It is always a fixed-dimensional vector of the same size, which ensures the consistency of the subsequent input dimension and facilitates subsequent processing. For example, there is a CPG that contains 3 nodes, and the embedding vector of each node is as follows:

[0069] Embedding vector h of node 1 1 =[0.2,0.3];

[0070] Embedding vector h of node 2 2 =[0.4,0.5];

[0071] Embedding vector h of node 3 3 =[0.1,0.2];

[0072] Then, through the final graph vector h graph will be:

[0073] h graph =h 1 +h 2 +h 3 =[0.2,0.3]+[0.4,0.5]+[0.1,0.2]=[0.7,1.0].

[0074] The final result is a vector of fixed dimension, which represents the characteristics of the entire CPG.

[0075] S4, h graph The input is processed in the trained multi-layer perceptron to obtain a binary classification result of 0 or 1. Among them, 0 means no vulnerability and 1 means there is a vulnerability.

[0076] The multilayer perceptron in this step includes an input layer, a hidden layer, and an output layer. The input layer is used to receive h graph The hidden layer is used to connect h graph The output layer is used to generate binary classification probabilities using the Sigmoid activation function and output results of 0 or 1.

[0077] The multi-layer perceptron used in the above steps needs to be trained before it can be used. However, a key issue is the imbalance of the training sample set. In reality, the number of vulnerable codes is far less than that of non-vulnerable codes, which leads to a serious imbalance in the ratio of positive and negative samples in the training sample set. In order to solve this problem, some studies have tried to use resampling techniques such as SMOTE, but in practical applications, these methods are prone to generate under-sampled or over-sampled samples, especially on data sets with complex distributions or noise problems. The performance is unstable, reducing the ability to recognize vulnerable code samples. To this end, we use a new method to construct a training sample set for a multi-layer perceptron to balance the number of vulnerable codes and non-vulnerable codes. In this embodiment, a data resampling method based on MWMOTE is used to enhance the diversity and coverage of minority class samples, generate new graph vectors, and thus balance the data distribution, providing high-quality input for the last step of multi-layer perceptron training.

[0078] Specifically, Figure 2 As shown, the data resampling method includes the following steps:

[0079] S11. The training sample set includes a minority class sample set D used to characterize vulnerability data. min and the majority class sample set D used to represent non-vulnerability data maj .

[0080] The first step is to identify and extract D min Medium close to D maj The boundary samples are the minority class samples near the decision boundary. The identification and extraction method includes the following steps:

[0081] First calculate the i-th minority class sample x i ∈D min To D maj The minimum Euclidean distance d(x i ,D maj ), and its calculation formula is:

[0082]

[0083] In the formula, sample x j ∈D maj , indicating D maj The jth majority class sample in .

[0084] Then judge d(x i ,D maj ) is less than the set threshold. If it is, the corresponding x i Extracted as boundary samples.

[0085] The second step is to assign weights w(x i ), the boundary samples with higher weights have higher priorities when generating synthetic samples later, and the allocation formula is:

[0086]

[0087] Then randomly select S w(x i ) is greater than the set threshold as the boundary sample x s .

[0088] S12, at the sth x s The x closest to it i Generate a synthetic sample x by linear interpolation new ; s∈[1,S]; its interpolation formula is:

[0089] x new =x i +λ·(x j -x i )

[0090] Where λ∈[0,1] is a randomly generated interpolation coefficient.

[0091] Traverse Q x s After x new Construct synthetic sample set D synthetic In this way, the generated x new Distributed in D min In the spatial range, x new It maintains the characteristics of minority samples and enhances x new diversity.

[0092] S13, D synthetic , D min , D maj Combination, we can get a new training sample set D new .

[0093] In another embodiment, for x obtained in S12 new The purpose is to optimize the sample distribution and avoid x new Too dense or deviate from the actual distribution of minority class samples. Specifically, clustering optimization includes the following steps:

[0094] S121, Dsynthetic and D min To cluster the elements in , the K-means algorithm can be used to generate T clusters.

[0095] S122. Calculate the element density ρ in the tth cluster t and the overall density of all elements ρ total ; t∈[1,T].

[0096] S123, according to ρ t and ρ total Calculate the optimized x new The number of Q opt , and its calculation formula is:

[0097]

[0098] In the formula, Q opt For each cluster, x needs to be generated new α is the adjustment factor used to control the overall x new The number of opt Then, according to the boundary conditions in the K-means algorithm, x new Perform deduplication and boundary constraints to form a new D new , ensure that x new Distribution coverage D min key areas.

[0099] The D generated by the above steps new Before inputting into the multi-layer perceptron training, the data set needs to be randomly divided into training set: validation set: test set = 8:1:1 ratio, and the training set is used as the training data of the multi-layer perceptron. The test results on the validation set are used as the basis for adjusting the parameters of the multi-layer perceptron. The test set is used to test the performance of the multi-layer perceptron in terms of accuracy, precision, recall rate and F1 score, and the results of the test set are used as the final performance of the multi-layer perceptron.

[0100] In summary, the innovation of the present invention mainly includes two parts. First: the present invention parses the source code and constructs CPG to form a unified code representation structure, which integrates the grammatical information, execution path and data dependencies in the code. Next, this performs feature extraction on each node in the CPG to generate a type feature vector and a semantic feature vector, and splices the two into the initial feature vector of the node. Subsequently, global semantic information is captured through forward propagation and backward propagation to generate updated node feature embeddings. Finally, all node embeddings are integrated into a graph-level embedding vector by a fusion method as a high-quality feature input for subsequent analysis and processing.

[0101] Second: The present invention addresses the imbalance between the number of vulnerability samples and non-vulnerability samples by resampling the training sample set of the adopted model, generating a high-quality training data set with balanced category distribution, which can significantly improve the model's ability to recognize vulnerability codes (minority class samples).

[0102] In some other embodiments, a software vulnerability detection system based on a bidirectional gated graph neural network is also proposed, which uses the software vulnerability detection method based on a bidirectional gated graph neural network in the above embodiment. The software vulnerability detection system based on a bidirectional gated graph neural network includes: a generation module, a feature extraction module, a propagation module and a neural network module. Among them, the generation module is used to parse the source code into a code property graph CPG.

[0103] The feature extraction module is used to extract the type feature vector of CPG node v and semantic feature vector and will and Splice to get the initial eigenvector of v

[0104] The propagation module is used to According to the connection relationship of the edges in CPG, K rounds of forward propagation and K rounds of backward propagation are performed to obtain Forward message of round k and backward messages Then and Fusion gets fusion features Perform the k+1th round of forward propagation and backward propagation; after iterating to the Kth round, Update to the final fusion feature It is also used to traverse M v to obtain M final fusion features Will Add dimension by dimension to get the graph vector h graph .

[0105] The neural network module is used to graph After processing, a binary classification result of 0 or 1 is obtained; 0 means no vulnerability and 1 means there is a vulnerability.

[0106] In some other embodiments, an electronic device is also proposed. The electronic device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the steps of the software vulnerability detection method based on a bidirectional gated graph neural network in the above embodiment are implemented.

[0107] Some other embodiments also provide a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps of the software vulnerability detection method based on a bidirectional gated graph neural network in the above embodiment are implemented.

[0108] Some other embodiments also provide a software program product, which includes program instructions, and when the software program product is run on an electronic device, the electronic device executes the steps of the software vulnerability detection method based on a bidirectional gated graph neural network in the above embodiment.

[0109] The technical features of the above-described embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0110] The above-mentioned embodiments only express several implementation methods of the present invention, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.

Claims

1. A software vulnerability detection method based on a bidirectional gated graph neural network, characterized in that: It includes the following steps: S1. Parse the source code into a code property graph CPG; wherein the CPG includes M nodes v, and the mth v represents the mth syntax unit of the source code; m∈[1,M]; S2. Extract the type feature of the mth v and obtain the type feature vector Extract the semantic features of the mth v and obtain the semantic feature vector Will and Splice and get the initial eigenvector of the mth v S3, first According to the connection relationship of the edges in CPG, K rounds of forward propagation and K rounds of backward propagation are performed to obtain Forward message of round k and backward messages k∈[1,K]; K is the maximum number of rounds; Then and Fusion gets fusion features Perform the k+1th round of forward propagation and backward propagation; After iterating to the Kth round, Update to the final fusion feature Traverse M v and get M final fusion features Will Add dimension by dimension to get the graph vector h graph To characterize the global features of the source code; S4, h graph The input is processed in the trained multi-layer perceptron to obtain a binary classification result of 0 or 1; 0 means no vulnerability and 1 means there is a vulnerability.

2. The software vulnerability detection method based on bidirectional gated graph neural network according to claim 1 is characterized in that: In S1, CPG is a fusion of the abstract syntax tree, control flow graph, and program dependency graph; Wherein, v in CPG is a node of the abstract syntax tree; The edges in CPG are the union of the edges in the abstract syntax tree, control flow graph, and program dependency graph.

3. The software vulnerability detection method based on bidirectional gated graph neural network according to claim 1 is characterized in that: In S2, one-hot encoding is used to obtain Use the GraphCodeBERT model to generate a dimension greater than 500 The dimension is The sum of the dimensions.

4. The software vulnerability detection method based on bidirectional gated graph neural network according to claim 1 is characterized in that: In S3, during the kth round of forward propagation, By all its forward neighbor nodes μ n →The feature aggregation is obtained, and its calculation formula is: Where N →(ν) For all forward neighbor nodes μ of v n → collection; is the nth forward neighbor node μ n →The embedding vector in the k-1th round of propagation; n∈[1,N →(ν) ]; SUM represents the sum operation; During the kth round of backpropagation, By all its backward neighbor nodes μ n ←The features are aggregated; Among them, the forward neighbor node μ n →The node whose edge points to the mth v; the backward neighbor node μ n ← is the node pointed to by the mth edge of v.

5. The software vulnerability detection method based on bidirectional gated graph neural network according to claim 1 is characterized in that: In S3, fusion is achieved through a gating mechanism and get The fusion method includes the following steps: First fuse through the Fuse function and Get the middle vector According to and the k-1th round Updated by the gated recurrent unit, we get 6. The software vulnerability detection method based on bidirectional gated graph neural network according to claim 1 is characterized in that: In S4, the training sample set of the multilayer perceptron includes the minority class sample set D used to characterize vulnerability data. min and the majority class sample set D used to represent non-vulnerability data maj ; The training sample set is processed by data resampling to generate a new training sample set D new , so that D min and D maj The sample size in is balanced.

7. The software vulnerability detection method based on bidirectional gated graph neural network according to claim 6 is characterized in that: The data resampling method includes the following steps: S11. According to the minority class sample x i ∈D min With the majority class sample x j ∈D maj The distance, D min Extract multiple boundary samples; First, assign weights w(x i ), and then randomly select S w(x i ) is greater than the set threshold as the boundary sample x s ; S12, at the sth x s The x closest to it i Generate a synthetic sample x by linear interpolation new ; s∈[1,S]; Traverse Q x s After x new Construct synthetic sample set D synthetic ; S13, D synthetic , D min , D maj Combine to get D new .

8. The software vulnerability detection method based on bidirectional gated graph neural network according to claim 7 is characterized in that: In S12, for x new The number of generated clusters is optimized, which includes the following steps: S121, D synthetic and D min Cluster the elements in to generate T clusters; S122. Calculate the element density ρ in the tth cluster t and the overall density of all elements ρ total ; t∈[1,T]; S123, according to ρ t and ρ total Calculate the optimized x new The number of Q opt , and its calculation formula is: In the formula, α is the adjustment factor.

9. A software vulnerability detection system based on a bidirectional gated graph neural network, characterized in that: It uses the software vulnerability detection method based on a bidirectional gated graph neural network as described in any one of claims 1 to 8; The software vulnerability detection system based on bidirectional gated graph neural network includes: A generation module, which is used to parse the source code into a code property graph CPG; Feature extraction module, which is used to extract the type feature vector of CPG node v and semantic feature vector and will and Splice to get the initial eigenvector of v The propagation module is used to According to the connection relationship of the edges in CPG, K rounds of forward propagation and K rounds of backward propagation are performed to obtain Forward message of round k and backward messages Then and Fusion gets fusion features Perform the k+1th round of forward propagation and backward propagation; after iterating to the Kth round, Update to the final fusion feature It is also used to traverse M v to obtain M final fusion features Will Add dimension by dimension to get the graph vector h graph ; Neural network module, which is used to h graph After processing, a binary classification result of 0 or 1 is obtained; 0 means no vulnerability and 1 means there is a vulnerability.

10. A software program product, characterized in that The software program product includes program instructions, which, when run on an electronic device, enable the electronic device to execute the steps of the software vulnerability detection method based on a bidirectional gated graph neural network as described in any one of claims 1 to 8.

Citation Information

Cited By

  • Code-level security vulnerability intelligent verification method, electronic equipment and storage medium

    CN120671152A