Static code analysis method and device based on function white list
By introducing a function whitelist mechanism into the static code analysis tool to identify and filter false positives, the problem that existing tools cannot accurately analyze custom security logic is solved, and the accuracy and efficiency of static code analysis are improved.
Patent Information
- Application Number
- CN202411986445.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-30
AI Technical Summary
Existing static code analysis tools cannot accurately analyze the custom security logic set by users in software code, resulting in high false positive rates and reducing the accuracy and efficiency of analysis.
The static code analysis method based on the function whitelist is adopted. By configuring the attribute information of the function to be analyzed into the function whitelist, the function nodes that meet the conditions are identified and identified, and the false positives in the static code analysis report are filtered.
It significantly reduces the false positive rate of static code analysis, improves the accuracy and efficiency of analysis, reduces the troubleshooting of developers, and saves time and energy.
Smart Images

Figure CN120066928A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of static code analysis, and in particular to a static code analysis method and device based on a function whitelist. Background Art
[0002] In the current software development field, static code analysis technology has been widely applied and has become an indispensable part of the software development process. It can analyze code without running the code, and then discover code problems at the code writing stage to help developers find potential defects in the code at an early stage, such as security vulnerabilities, code quality problems, etc., and reduce the cost of later debugging and repair. With the continuous increase in software scale and complexity, the importance of static code analysis has become increasingly prominent. Many software development teams and enterprises will incorporate static code analysis tools into their development processes to improve the reliability and security of the code.
[0003] Existing static code analysis tools can detect problems in code according to a series of set rules and patterns. For example, some code analysis tools can detect common defects such as buffer overflows, SQL injections, uninitialized variables, null pointer references, resource leaks, etc. in the code.
[0004] However, during the software development process, users often set some custom security logics in the code according to specific business requirements and security requirements. These security logics may be complex, diverse, and closely combined with specific business scenarios;
[0005] However, the existing static code analysis technology cannot directly and accurately analyze the custom security logics set by users in software code, resulting in a high false alarm rate during the detection process of static code analysis tools, greatly reducing the accuracy of static code analysis of software code, and causing developers to spend a lot of time and effort to troubleshoot the problems. This undoubtedly reduces the efficiency of the entire software development and maintenance. In the software development process, time cost is crucial. Especially with the expansion of project scale and the shortening of delivery cycle, the reduction of efficiency will have a greater negative impact on the progress of the project; moreover, when developers need to spend extra time and effort to identify and eliminate these false alarm problems, it is easy for real code problems to be covered up by false alarms, thus affecting the accurate assessment of code security and the effective discovery of security defects.
[0006] Therefore, the existing static code analysis tools cannot meet the requirements of related specific businesses. Summary of the Invention
[0007] The object of the present invention is to provide a static code analysis method and device based on a function whitelist, which can accurately identify and filter false positives generated by static code analysis tools, so as to improve the quality and effect of static code analysis, reduce the false positive rate, and further reduce unnecessary troubleshooting work caused by false positives, effectively saving the time and energy of developers and significantly improving the overall efficiency of static code analysis.
[0008] To achieve the above object, the present invention discloses a static code analysis method based on a function whitelist, which includes:
[0009] Configuring the function to be configured in the function whitelist;
[0010] Performing static code analysis on the source code to obtain a static code analysis report;
[0011] Scanning and parsing all function nodes in the source code to obtain function detection results;
[0012] Identifying function nodes in the function detection results according to the function whitelist, and marking function nodes belonging to the function whitelist;
[0013] Filtering function defects in the static code analysis report according to the marked function nodes to obtain a code detection report.
[0014] Further, the step of "configuring the function to be configured in the function whitelist" includes:
[0015] Reading the attribute information of the function to be configured;
[0016] Writing the read attribute information into the function whitelist.
[0017] Further, the attribute information includes function name, adapted programming language, matching detection rules, code namespace, data structure, and project effective scope.
[0018] Further, the step of "scanning and parsing all function nodes in the source code to obtain function detection results" includes:
[0019] Obtaining the source code file of the function node;
[0020] Performing defect type analysis on the obtained source code file to obtain an analysis result;
[0021] Generating node information of the function by using the source code file and the analysis result;
[0022] Saving the generated node information into the function detection results.
[0023] Further, the function whitelist includes the attribute information of functions, and the function detection result includes the node information of function nodes. The "identifying the function nodes in the function detection result according to the function whitelist and marking the function nodes belonging to the function whitelist" includes:
[0024] Comparing the node information of function nodes with the attribute information of functions in the function whitelist one by one;
[0025] Generating identification information by using the node information of function nodes belonging to the function whitelist.
[0026] To achieve the above object, the present invention discloses a static code analysis device based on a function whitelist, which includes:
[0027] A configuration module for configuring functions to be configured in the function whitelist;
[0028] An analysis module for performing static code analysis on the source code to obtain a static code analysis report;
[0029] A parsing module for scanning and parsing all function nodes in the source code to obtain a function detection result;
[0030] An identification module for identifying the function nodes in the function detection result according to the function whitelist and marking the function nodes belonging to the function whitelist;
[0031] A filtering module for filtering function defects in the static code analysis report according to the marked function nodes to obtain a code detection report.
[0032] In this application, by setting a function whitelist to reduce false positives in static code analysis, first configure the functions to be configured in the function whitelist, then still perform static code analysis on the source code to obtain a static code analysis report, then scan and parse all function nodes in the source code, identify them according to the function whitelist, mark the function nodes belonging to the function whitelist, and finally filter function defects in the static code analysis report according to the marked function nodes to obtain a code detection report. The setting of the above function whitelist can assist the static code analysis tool to accurately identify and filter the false positives generated by it, so as to improve the quality and effect of static code analysis, reduce the false positive rate, and further reduce unnecessary troubleshooting work caused by false positives, effectively saving the time and energy of developers and significantly improving the overall efficiency of static code analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 It is a flowchart of the static code analysis method based on the function whitelist according to the embodiment of the present invention.
[0034] Figure 2 This is a module diagram of the static code analysis device based on the function whitelist according to an embodiment of the present invention.
[0035] Figure 3 This is a system diagram of the electronic device according to an embodiment of the present invention. Detailed implementation manners
[0036] To describe in detail the technical content, structural features, achieved objectives and effects of the present invention, the following is described in detail in conjunction with the embodiments and with reference to the drawings.
[0037] Embodiment 1
[0038] Please refer to Figure 1 , the present invention discloses a static code analysis method based on a function whitelist, which includes:
[0039] 101. Configure the function to be configured in the function whitelist;
[0040] Further, "configuring the function to be configured in the function whitelist" includes:
[0041] 1011. Read the attribute information of the function to be configured;
[0042] 1012. Write the read attribute information into the function whitelist.
[0043] Further, the attribute information includes function name, adapted programming language, matching detection rules, code namespace, data structure, and project effective scope.
[0044] It can be understood that developers or relevant personnel need to first add functions recognized as safe or functions that conform to specific security logics to the function whitelist according to the specific requirements of the project and security policies. And when configuring the function into the function whitelist, multiple key attribute information of the function whitelist needs to be clearly recorded, including but not limited to function name, adapted programming language, specific matching detection rules, namespace (package name), structure (class name), and effective scope definition (whether it is effective for all projects or specified projects). Specifically, the attribute information of the configured function will be stored in the function whitelist of the database in a standardized Json format to ensure that the function whitelist has good readability and compatibility, facilitating the static code scanning tool to quickly and accurately read the data therein in subsequent operations, providing solid preliminary data support for the entire static code analysis process.
[0045] It should be noted that the function whitelist supports subsequent dynamic updates and expansions according to actual needs, can adapt to the needs of project development and external environment changes, is beneficial to maintaining the continuous effectiveness of the static code analysis tool, and has very good flexibility and scalability.
[0046] 102. Perform static code analysis on the source code to obtain a static code analysis report;
[0047] 103. Scan and parse all function nodes in the source code to obtain function detection results;
[0048] Further, "scan and parse all function nodes in the source code to obtain function detection results" includes:
[0049] 1031. Obtain the source code file of the function node;
[0050] 1032. Perform defect type analysis on the obtained source code file to obtain analysis results;
[0051] 1033. Generate node information of the function using the source code file and analysis results;
[0052] 1034. Save the generated node information to the function detection results.
[0053] It can be understood that on the basis of traditional static code analysis tools, the function whitelist recognition function is added to realize the operation of identifying function nodes in the source code, which is convenient for subsequent accurate matching with the function whitelist. Specifically, in the static code analysis process, the function whitelist recognition function is used to comprehensively scan and parse the source code to obtain node information of all functions therein. The node information includes the source code file related to the function node and the possible defect types of the function node, but is not limited thereto.
[0054] 104. Identify the function nodes in the function detection results according to the function whitelist, and mark the function nodes belonging to the function whitelist;
[0055] Further, the function whitelist includes attribute information of the function, and the function detection results include node information of the function node. "Identify the function nodes in the function detection results according to the function whitelist, and mark the function nodes belonging to the function whitelist" includes:
[0056] 1041. Compare the node information of the function node with the attribute information of the functions in the function whitelist one by one;
[0057] 1042. Generate identification information using the node information of the function nodes belonging to the function whitelist.
[0058] It can be understood that identifying the functions that meet the function whitelist conditions in the code by comparing the node information with the attribute information is conducive to accurately screening out the function data for subsequent function filtering from a large amount of code information, providing effective data support for subsequent operations, and is not limited thereto.
[0059] 105. Filter function defects in the static code analysis report according to the identified function nodes to obtain a code detection report.
[0060] Based on the original static code analysis tool, set the rules for function whitelist configuration, so that the static code analysis tool can accurately identify and process the security logic set by users. Furthermore, it can automatically identify and filter defects related to the security functions of the user-defined security logic during the static code analysis process, effectively reducing the false positive rate of the static code analysis tool, facilitating the accurate identification of actual problems in the code, and thus improving the accuracy of static code analysis; at the same time, it is beneficial to improve the fluency of software development, so as to more quickly discover and solve the real problems in the code, and is conducive to accelerating the development progress of the project.
[0061] It can be understood that the automatic filtering of the defect results detected by static code analysis is achieved by receiving the original detection results (static code analysis report) from the static code analysis tool and the identification information generated based on the function whitelist. For example, when a certain defect in the static code analysis report is related to a certain function in the function whitelist, this defect can be directly excluded from the final code detection report. The above efficient filtering mechanism can effectively reduce the false positive phenomenon of static code analysis, provide accurate and valuable code analysis results for developers, and is beneficial to improving the efficiency and quality of code development.
[0062] In this application, to reduce the false positives of static code analysis by setting a function whitelist, first configure the functions to be configured in the function whitelist, then still perform the static code analysis of the source code to obtain a static code analysis report, then scan and parse all function nodes in the source code, identify them according to the function whitelist, mark the function nodes belonging to the function whitelist, and finally filter the function defects in the static code analysis report according to the marked function nodes to obtain a code detection report. The setting of the above function whitelist can assist the static code analysis tool to accurately identify and filter the false positives it generates, improve the quality and effect of static code analysis, reduce the false positive rate, and thus reduce the unnecessary troubleshooting work caused by false positives, effectively saving the time and energy of developers and significantly improving the overall efficiency of static code analysis.
[0063] Embodiment 2
[0064] Please refer to Figure 1 and Figure 2 , the present invention discloses a static code analysis device based on a function whitelist, which includes:
[0065] A configuration module 201, configured to configure a function to be configured into a function whitelist;
[0066] An analysis module 202, configured to perform static code analysis on source code to obtain a static code analysis report;
[0067] A parsing module 203, configured to scan and parse all function nodes in the source code to obtain a function detection result;
[0068] An identification module 204, configured to identify function nodes in the function detection result according to the function whitelist, and identify function nodes belonging to the function whitelist;
[0069] A filtering module 205, configured to filter function defects in the static code analysis report according to the identified function nodes to obtain a code detection report.
[0070] Embodiment III
[0071] Please refer to Figure 1 and Figure 3 , the present invention discloses an electronic device, which includes:
[0072] One or more processors 301;
[0073] One or more memories 302, configured to store one or more programs, and when the one or more programs are executed by the processor, the processor implements the static code analysis method based on the function whitelist as described above.
[0074] Embodiment IV
[0075] An embodiment of the present application discloses a computer-readable storage medium, on which a program is stored, and when the program is executed by a processor, the static code analysis method based on the function whitelist as described above is implemented.
[0076] Embodiment V
[0077] An embodiment of the present application discloses a computer program product or a computer program, the computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes the above-mentioned static code analysis method based on the function whitelist.
[0078] It should be understood that in the embodiments of this application, the so-called processor may be a central processing module (Central Processing Unit, CPU), and this processor may also be other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), application-specific integrated circuits (Application Specific Integrated Circuit, ASIC), field-programmable gate arrays (Field-Programmable Gate Array, FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or this processor may also be any conventional processor, etc.
[0079] Those of ordinary skill in the art can understand that all or part of the processes in the above-described method embodiments can be completed by hardware related to computer program instructions. The program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the above-described method embodiments. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (Read-Only Memory, ROM), or a random access memory (Random Access Memory, RAM), etc.
[0080] The above-disclosed are only the preferred embodiments of the present invention, and of course, the scope of rights of the present invention cannot be limited thereby. Therefore, equivalent changes made according to the scope of the patent application of the present invention still fall within the scope covered by the present invention.
Claims
1. A static code analysis method based on function whitelist, characterized in that: include: Configure the function to be configured in the function whitelist; Perform static code analysis on the source code to obtain a static code analysis report; Scan and parse all function nodes in the source code to obtain function detection results; Identifying function nodes in the function detection result according to the function whitelist, and marking the function nodes belonging to the function whitelist; The function defects in the static code analysis report are filtered according to the identified function nodes to obtain a code detection report.
2. The static code analysis method based on function whitelist according to claim 1 is characterized in that: The "configuring the function to be configured in the function whitelist" includes: Read the property information of the function to be configured; The read attribute information is written into the function whitelist.
3. The static code analysis method based on function whitelist according to claim 2 is characterized in that: The attribute information includes function name, adapted programming language, matching detection rule, code namespace, data structure and project effective scope.
4. The static code analysis method based on function whitelist according to claim 1, characterized in that: The "scanning and parsing all function nodes in the source code to obtain function detection results" includes: Get the source code file of the function node; Perform defect type analysis on the acquired source code files to obtain analysis results; Generate function node information using source code files and analysis results; The generated node information is saved in the function detection result.
5. The static code analysis method based on function whitelist according to claim 1, characterized in that: The function whitelist includes attribute information of the function, the function detection result includes node information of the function node, and the "identifying the function nodes in the function detection result according to the function whitelist, and marking the function nodes belonging to the function whitelist" includes: Compare the node information of the function node with the attribute information of the functions in the function whitelist one by one; The identification information is generated using the node information of the function nodes belonging to the function whitelist.
6. A static code analysis device based on function whitelist, characterized in that: include: A configuration module is used to configure the function to be configured in the function whitelist; An analysis module, used for performing static code analysis on source code to obtain a static code analysis report; The parsing module is used to scan and parse all function nodes in the source code to obtain function detection results; An identification module, used to identify the function nodes in the function detection result according to the function whitelist, and identify the function nodes belonging to the function whitelist; The filtering module is used to filter the function defects in the static code analysis report according to the identified function nodes to obtain a code detection report.
7. An electronic device, characterized in that: include: one or more processors; One or more memories are used to store one or more programs. When one or more of the programs are executed by the processor, the processor implements the static code analysis method based on function whitelist as described in any one of claims 1 to 5.
8. A computer-readable storage medium having a program stored thereon, characterized in that: When the program is executed by a processor, the static code analysis method based on a function whitelist as described in any one of claims 1 to 5 is implemented.