DSL (Digital Subscriber Line) rule modification method and device and computing equipment cluster

By modifying DSL rules and filtering out rules with shorter execution time and the same query results, the problem of low efficiency in querying DSL rules is solved, and efficient query of static code inspection is realized.

CN120067145APending Publication Date: 2025-05-30HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311644189.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In static code inspection based on DSL, DSL rules are more flexible, which leads to a longer time for the upper inspector to query the database by running DSL rules and low query efficiency.

Method used

By modifying the DSL rules and comparing them with the original DSL rules, we filter out modified DSL rules with less execution time and the same query results from the database, and apply the modified DSL rules to reduce the time to execute the DSL rules to query the database and improve query efficiency.

Benefits of technology

By filtering and applying more efficient DSL rules, the time to query the database is significantly reduced and the query efficiency of static code inspection is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120067145A_ABST
    Figure CN120067145A_ABST
Patent Text Reader

Abstract

The invention provides a DSL (Digital Subscriber Line) rule modification method and device and a computing equipment cluster. In an embodiment, a method includes: determining a domain specific language (DSL) rule; the DSL rule is used for querying data in a database; conditions in the DSL rule are modified, and the modified DSL rule is determined; performing a first test on the modified DSL rule based on a query engine and a database; the query engine is used for executing the DSL rule to query data in the database; screening a target DSL rule from the modified DSL rules based on a result of the first test; the query engine executes the target DSL rule and the DSL rule, the data queried from the database is the same, and the execution time of the query engine executing the target DSL rule is shorter than the execution time of the query engine executing the DSL rule. By applying the modified DSL rule, the time for executing the DSL rule to query the database can be shortened, and the query efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technologies, and in particular, to a method, an apparatus, and a cluster of computing devices for modifying DSL rules. Background Art

[0002] With the continuous development of Internet-related technologies, the scale and complexity of software have been continuously expanding, and the pressure faced by software security has also been gradually increasing. Since static code analysis technology can analyze code without running the software and identify potential security risks in the code in advance through relevant rules, it has been widely used. Among them, the analysis technology based on DSL is highly praised due to the flexibility of its customized rules.

[0003] Using DSL technology for static code inspection usually consists of two parts: the underlying framework parses the input code, uses specific data structures such as abstract syntax trees and control flow graphs to save the code and generate a database; the upper-layer checker queries the database through DSL rules and finally locates the code positions suspected of having risks.

[0004] However, due to the flexibility of DSL rules, the time for the upper-layer checker to query the database by running DSL rules may be relatively long, resulting in low query efficiency.

[0005] The information disclosed in this background art section is only intended to enhance the overall understanding of the present application and should not be regarded as an admission or any form of suggestion that this information constitutes prior art already known to those of ordinary skill in the art. Summary of the Invention

[0006] Embodiments of the present application provide a method, an apparatus, and a cluster of computing devices for modifying DSL rules, which can modify DSL rules, and then, by comparing with the original DSL rules, screen out the modified DSL rules with less execution time and the same query results from the database. Subsequently, using the modified DSL rules can reduce the time for querying the database by executing DSL rules and improve the query efficiency.

[0007] In a first aspect, an embodiment of the present application provides a method for modifying DSL rules, including: determining a domain-specific language (DSL) rule, where the DSL rule is used to query data in a database; modifying the conditions in the DSL rule to determine a modified DSL rule; based on a query engine and the database, performing a first test on the modified DSL rule, where the query engine is used to execute the DSL rule to query data in the database; based on the result of the first test, screening a target DSL rule from the modified DSL rules, where the data queried from the database by the query engine executing the target DSL rule is the same as that queried by the query engine executing the DSL rule, and the execution time of the query engine executing the target DSL rule is less than the execution time of the query engine executing the DSL rule.

[0008] In this solution, the DSL rules can be modified. Then, by comparing with the original DSL rules, the modified DSL rules with less execution time and the same query results from the database are screened out. Subsequently, by using the modified DSL rules, the time for the query engine to execute the DSL rule to query the database can be reduced, and the query efficiency can be improved.

[0009] In a possible implementation manner, modifying the conditions in the DSL rule includes performing at least one of the following modifications to the conditions in the DSL rule: changing the order relationship of the conditions, condition replacement, and condition addition.

[0010] In an example of this implementation manner, changing the order relationship of the conditions is implemented by a first optimizer, and the first optimizer is used to disassemble and adjust the structure of the conditions in the DSL rule according to the syntax analysis of the DSL rule by the query engine.

[0011] In this solution, based on the logic of the syntax analysis of the DSL rule by the query engine, the conditions in the DSL rule can be disassembled and structurally adjusted to improve the query efficiency.

[0012] In an example of this implementation manner, condition replacement is implemented by a second optimizer, and the second optimizer is used to replace the conditions in the DSL rule according to the query logic of the query engine executing the DSL rule.

[0013] In this solution, according to the query logic of the query engine executing the DSL rule, the conditions in the DSL rule are replaced to reduce the query time, thereby improving the query efficiency.

[0014] In an example of this implementation manner, condition addition is implemented by a third optimizer, and the third optimizer is used to understand the DSL rule and add restrictive conditions to the conditions in the DSL rule to narrow the query scope.

[0015] In this solution, based on the checking logic of the DSL rule, the query scope is narrowed by adding some condition restrictions to improve the query efficiency.

[0016] In an example of this example, the method further includes: using the DSL rule as the input of a third optimizer, including adding the processed DSL rule as the output of the third optimizer, and training the third optimizer.

[0017] In this solution, by training the third optimizer with new samples, the performance of the third optimizer can be improved.

[0018] In a possible implementation manner, the method further includes: performing a second test on the DSL rule based on a query engine and a database; screening target DSL rules from the modified DSL rules based on the result of the first test, including: screening target DSL rules from the modified DSL rules based on the results of the first test and the second test.

[0019] In this solution, through the test results of the DSL rule and the modified DSL rule, the target DSL rule can be screened out more accurately.

[0020] In a possible implementation manner, screening target DSL rules from the modified DSL rules includes: screening candidate DSL rules from the modified DSL rules; the query engine executes the candidate DSL rule and the data queried from the database by the DSL rule is the same; displaying the execution times of the candidate DSL rule and the DSL rule; determining the DSL rule selected from the candidate DSL rules as the target DSL rule.

[0021] In a possible example, the execution times of the candidate DSL rule and the DSL rule can be displayed in a pop-up window; the user operates the pop-up window to select the target DSL rule from the candidate DSL rules.

[0022] In a possible implementation manner, the database is the call relationship between codes in the software to be tested; the DSL rule is used to query software codes with security vulnerabilities.

[0023] In a second aspect, an embodiment of the present application provides a device for modifying a DSL rule. The device for modifying a DSL rule includes several modules, and each module is used to execute each step in the method for modifying a DSL rule provided in the first aspect of the embodiment of the present application. The division of the modules is not limited here. For the specific functions executed by each module of the device for modifying a DSL rule and the beneficial effects achieved, please refer to the functions of each step in the method for modifying a DSL rule provided in the first aspect of the embodiment of the present application, which will not be elaborated here.

[0024] Exemplarily, the device for modifying a DSL rule includes:

[0025] A rule determination module for determining domain-specific language (DSL) rules; the DSL rules are used to query data in a database;

[0026] A modification module for modifying the conditions in the DSL rules to determine the modified DSL rules;

[0027] A testing module for performing a first test on the modified DSL rules based on a query engine and a database; the query engine is used to execute the DSL rules to query data in the database;

[0028] A filtering module for filtering target DSL rules from the modified DSL rules based on the results of the first test; the query engine executes the target DSL rules and the data queried from the database by the DSL rules is the same, and the execution time of the query engine executing the target DSL rules is less than the execution time of executing the DSL rules.

[0029] In this solution, the modification of the DSL rules can be performed, and the modified DSL rules with less query time and the same query results from the database can be filtered out through the query engine. Subsequently, by using the modified DSL rules, the time for the query engine to execute the DSL rules to query the database can be reduced, and the query efficiency can be improved.

[0030] In a possible implementation, the modification module is used to perform at least one of the following modifications to the conditions in the DSL rules: changing the order relationship of the conditions, condition replacement, and condition addition.

[0031] In an example of this implementation, changing the order relationship of the conditions is implemented by a first optimizer, and the first optimizer is used to disassemble and adjust the structure of the conditions in the DSL rules according to the syntax analysis of the DSL rules by the query engine.

[0032] In an example of this implementation, condition replacement is implemented by a second optimizer, and the second optimizer is used to replace the conditions in the DSL rules according to the query logic of the query engine executing the DSL rules.

[0033] In an example of this implementation, condition addition is implemented by a third optimizer, and the third optimizer is used to understand the DSL rules and add restrictive conditions to the conditions in the DSL rules to narrow the query scope.

[0034] In an example of this example, the device further includes: a training module for using the DSL rules as the input of the third optimizer and the DSL rules including the processed condition addition as the output of the third optimizer to train the third optimizer.

[0035] In a possible implementation, the testing module is further configured to perform a second test on the DSL rules based on the query engine and the database; and screen for target DSL rules from the modified DSL rules based on the results of the first test and the second test.

[0036] In a possible implementation, the screening module is configured to screen for candidate DSL rules from the modified DSL rules; ensure that the query engine executes the same data queried from the database for the candidate DSL rules and the DSL rules; display the execution times of the candidate DSL rules and the DSL rules; and determine the DSL rules selected from the candidate DSL rules as the target DSL rules.

[0037] In a possible example, the execution times of the candidate DSL rules and the DSL rules can be displayed in a pop-up window; the user operates the pop-up window to select the target DSL rules from the candidate DSL rules.

[0038] In a possible implementation, the database is the call relationship between the codes in the software to be tested; the DSL rules are used to query software codes with security vulnerabilities.

[0039] In a third aspect, an embodiment of the present application provides an apparatus for modifying DSL rules, including: at least one memory for storing programs; at least one processor for executing the programs stored in the memory, and when the programs stored in the memory are executed, the processor is configured to execute the method provided in the first aspect.

[0040] In a fourth aspect, an embodiment of the present application provides an apparatus for modifying DSL rules, characterized in that the apparatus runs computer program instructions to execute the method provided in the first aspect. Exemplarily, the apparatus can be a chip or a processor.

[0041] In an example, the apparatus may include a processor, which can be coupled to a memory, read instructions from the memory, and execute the method provided in the first aspect according to the instructions. Wherein, the memory can be integrated in the chip or the processor, or can be independent of the chip or the processor.

[0042] In a fifth aspect, an embodiment of the present application provides a computer storage medium, in which instructions are stored, and when the instructions run on a computer, the computer is caused to execute the method provided in the first aspect.

[0043] In a sixth aspect, an embodiment of the present application provides a computer program product containing instructions, and when the instructions run on a computer, the computer is caused to execute the method provided in the first aspect. Description of the Drawings

[0044] Figure 1It is the system architecture diagram of the rule optimization system provided by the embodiments of the present application;

[0045] Figure 2 It is the schematic flowchart of the method for modifying DSL rules provided by the embodiments of the present application;

[0046] Figure 3a It is the schematic diagram of the scenario for changing the sequential relationship of conditions provided by the embodiments of the present application;

[0047] Figure 3b It is the schematic diagram of the scenario for condition replacement provided by the embodiments of the present application;

[0048] Figure 3c It is the schematic diagram of the scenario for condition addition provided by the embodiments of the present application;

[0049] Figure 3d It is the schematic diagram of the scenario for condition replacement and changing the sequential relationship of conditions provided by the embodiments of the present application;

[0050] Figure 4 It is the schematic diagram of the scenario for the modification scheme provided by the embodiments of the present application;

[0051] Figure 5 It is the display schematic diagram of the UI interface provided by the embodiments of the present application;

[0052] Figure 6a It is the schematic illustration of the scenario for modifying DSL rules provided by the embodiments of the present application Figure 1 ;

[0053] Figure 6b It is the schematic illustration of the scenario for modifying DSL rules provided by the embodiments of the present application Figure 2 ;

[0054] Figure 7 It is the structural schematic diagram of the device for modifying DSL rules provided by the embodiments of the present application;

[0055] Figure 8 It is the structural schematic diagram of the computing device provided by the embodiments of the present application;

[0056] Figure 9 It is the structural schematic diagram of the computing device cluster provided by the embodiments of the present application;

[0057] Figure 10 It is the schematic diagram of the interaction scenario of computing devices provided by the embodiments of the present application. Detailed implementation manners

[0058] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings.

[0059] In the description of the embodiments of this application, words such as "exemplary", "for example", or "for illustration" are used to give examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary", "for example", or "for illustration" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary", "for example", or "for illustration" is intended to present relevant concepts in a specific manner.

[0060] In the description of the embodiments of this application, the term "and / or" is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, B exists alone, and A and B exist simultaneously. In addition, unless otherwise specified, the meaning of the term "plural" refers to two or more. For example, multiple systems refer to two or more systems, and multiple terminals refer to two or more terminals.

[0061] In addition, the terms "first" and "second" are only used for descriptive purposes and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. The terms "include", "comprise", "have" and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0062] Hereinafter, some terms in this embodiment will be explained. It should be noted that these explanations are for the convenience of those skilled in the art and do not constitute a limitation on the scope of protection required by this application.

[0063] Domain Specific Language (DSL): A computer language specifically for a particular application domain. For example: HTML for displaying web pages, Maven for compilation configuration.

[0064] DSL rule: A DSL query statement for querying a certain code scenario. For example: Want to query a method call named test (functionCall fc where fc.name == "test";)

[0065] Optimizer: An algorithm implementation for performance optimization of DSL rules.

[0066] Test project: A local project for validating a written DSL rule, usually including various scenarios that the DSL rule should cover and similar scenarios that should not be covered.

[0067] Abstract Syntax Tree: It is an abstract representation of the syntax structure of source code. It represents the syntax structure of a programming language in a tree-like form, and each node on the tree represents a structure in the source code.

[0068] Control Flow Graph: It is used to illustrate the control flow of a program.

[0069] With the continuous development of Internet-related technologies, the scale and complexity of software have been continuously expanding, and the pressure faced by software security has also been gradually increasing. Static code analysis technology can analyze code without running the software and identify potential security risks in the code in advance through relevant rules, so it has been widely used. Among them, the analysis technology based on DSL is highly praised for the flexibility of its customized rules.

[0070] Using DSL technology for static code inspection usually consists of two parts: the underlying framework parses the input code, uses specific data structures such as abstract syntax trees and control flow graphs to save the code and generate a database; the upper-layer checker constructs query statements through DSL to query the database and finally locates the code positions suspected of having risks. Due to the flexibility of DSL, there are often multiple different DSL rules to achieve the same purpose of code inspection. These different DSL rules will show different scanning efficiencies during the scanning process. Through statistics in actual projects, it is found that the efficiency gap between DSL rules with the same query ability can reach a factor of 3.

[0071] Currently, the inspection efficiency of DSL rules customized by security personnel in code inspection completely depends on the capabilities of the security personnel themselves. In the same inspection scenario, DSL rules with low execution efficiency will be significantly slower than those with high execution efficiency. For this scenario, this application mainly solves two technical problems: First, automatically optimize the performance of DSL rules developed by security personnel; Second, use test projects to test the feasibility of DSL rules after performance modification, and finally feedback to the automated performance optimization process to improve the optimization effect.

[0072] Therefore, how to determine high-performance DSL rules is particularly important for security personnel.

[0073] Based on this, the embodiments of this application propose a method for modifying DSL rules.

[0074] This method constructs optimization rules based on the goal of reducing query efficiency, and automatically optimizes DSL rules through pre-set optimization rules, reduces the time for querying using DSL rules, and improves the query efficiency of DSL rules. Here is just a brief description of the method, and for the detailed content of this method, please refer to the following description.

[0075] Next, the rule optimization system to which the DSL rule modification method provided by the embodiments of the present application may be applied will be introduced. Figure 1 FIG. shows an architectural example diagram of a rule optimization system provided by an embodiment of the present application. The DSL rule modification method provided by the embodiments of the present application can be applied to a Figure 1 system architecture diagram as shown. As Figure 1 shown, the rule optimization system includes a terminal 101 and a performance optimization system 102.

[0076] Among them, the terminal 101 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, and portable wearable devices. Exemplary embodiments of the terminal devices involved in this solution include, but are not limited to, electronic devices equipped with iOS, android, Windows, Harmony OS, or other operating systems. The embodiments of the present application do not specifically limit the type of electronic device.

[0077] Among them, the performance optimization system 102 may include a device cluster and application software deployed on the device cluster. The device cluster can be implemented by an independent electronic device or a device cluster composed of multiple electronic devices. In some possible implementation manners, the electronic devices in the device cluster can be terminals, computers, or servers. In one example, the server involved in this solution can be used to provide cloud services, and it can be a server or a super terminal that can establish a communication connection with other devices and provide computing functions and / or storage functions for other devices. Among them, the server involved in this solution can be a hardware server or can be implanted into a virtualized environment. For example, the server involved in this solution can be a virtual machine running on a hardware server including one or more other virtual machines. The application software is used to implement the DSL rule modification method provided by the embodiments of the present application. For the detailed content, see the description of Figure 2 below, and no detailed description will be given here.

[0078] Among them, the terminal 101 communicates with the performance optimization system 102 via a network. The network can be a wired network or a wireless network. Exemplarily, the wired network can be a cable network, an optical fiber network, a Digital Data Network (DDN), etc., and the wireless network can be a telecommunication network, an internal network, the Internet, a Local Area Network (LAN), a Wide Area Network (WAN), a Wireless Local Area Network (WLAN), a Metropolitan Area Network (MAN), a Public Service Telephone Network (PSTN), a Bluetooth network, a ZigBee network, a Global System for Mobile Communications (GSM), a Code Division Multiple Access (CDMA) network, a General Packet Radio Service (GPRS) network, etc. or any combination thereof. It can be understood that the network can use any known network communication protocol to implement communication between different client layers and gateways. The above network communication protocols can be various wired or wireless communication protocols, such as Ethernet, universal serial bus (USB), firewire, global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), new radio (NR), Bluetooth, wireless fidelity (Wi-Fi), etc.

[0079] In the embodiment of the present application, the terminal 101 can determine DSL rules; the performance optimization system 102 can optimize the DSL rules.

[0080] Next, in combination with the rules provided above to optimize the system, a method for modifying DSL rules provided in an embodiment of the present application will be introduced in detail. Figure 2 It is a schematic flowchart of the method for modifying DSL rules provided in an embodiment of the present application. This embodiment can be applied to a rule optimization system, specifically on a server or a general computer.

[0081] As Figure 2 shown, the method for modifying DSL rules provided in an embodiment of the present application at least includes the following steps:

[0082] Step 201, the terminal 101 determines a DSL rule, and the DSL rule is used to query data in the database.

[0083] In a specific implementation, a tester can input a DSL rule by operating the terminal 101.

[0084] In a possible scenario, if the software needs to be analyzed for security through the terminal 101, then the software needs to be parsed to determine the abstract syntax tree and the control flow graph. The abstract syntax tree and the control flow graph can show the call relationship between the codes in the software, and then the call relationship between the codes in the software reflected by the abstract syntax tree and the control flow graph is stored in the database in a specific form. Exemplarily, the database can be a graph database.

[0085] Step 202, the terminal 101 sends the DSL rule to the performance optimization system 102.

[0086] Step 203, the performance optimization system 102 modifies the conditions in the DSL rule to determine the modified DSL rule.

[0087] It should be noted that in an embodiment of the present application, the performance optimization system 102 may include a query engine and a database. The query engine is used to execute the DSL rule, query data in the database such as codes in the software, so as to perform risk analysis.

[0088] In an embodiment of the present application, in the process of optimizing the performance of the DSL rule by the performance optimization system 102, at least one of the following modifications needs to be performed: changing the conditional order relationship, conditional replacement, and conditional addition.

[0089] Among them, changing the conditional order relationship can be understood as an optimization based on the structure of the DSL rule. Specifically, changing the conditional result requires disassembling the conditions in the DSL rule and adjusting the sequential structure according to the syntax analysis of the DSL rule by the query engine.

[0090] In specific implementation, changing the conditional order relationship can be achieved through a first optimizer, which is used to disassemble the conditions in the DSL rule and adjust the structure. Herein, the first optimizer can be understood as a model, which can be directly used after being pre-trained; when specifically constructing the first optimizer, it is necessary to consider the abstract syntax tree obtained by the query engine through parsing the DSL rule (which can be the DSL rule that has been used before), conduct structural analysis through the abstract syntax tree, determine the structural adjustment method that can improve the query efficiency, and thus construct the first optimizer. Therefore, based on the syntax analysis (such as the abstract syntax tree) of the DSL rule by the query engine, the first optimizer can know the execution sequence of different conditions in the DSL rule, and, the query logic of each condition (such as the method of finding data from the database), so as to disassemble the conditions in the DSL rule and adjust the sequential structure. It can be seen that in the embodiment of the present application, the first optimizer disassembles the conditions in the DSL rule and adjusts the sequential structure through the determined knowledge (syntax knowledge such as the abstract syntax tree), thereby improving the query efficiency.

[0091] Exemplarily, the structural adjustment may include bringing the simple query condition in the series of conditions to the beginning of the series of conditions, so as to short-circuit the query of some complex conditions; wherein, the series of conditions can be understood as conditions containing multiple condition combinations, such as multiple conditions in parallel with and or or; exemplarily, the simple query condition can be understood as a condition that does not contain nested conditions, or a condition for confirming whether it is a certain piece of information; the complex condition can be understood as a condition that contains nested conditions.

[0092] As Figure 3a shown, condition 2 is: fc.function.name match “geturl” (used to check whether the name of the function is geturl), and condition 1 is: fc.enclosingClass contain functionDeclaration fd where fd contain variableDeclaration vd where vd.name == “url” (this is a nested condition, used to find that the name of the variable declared in the function description in the class is url); condition 2 does not involve nesting and is only used to determine the function name, which is a simple condition, and condition 1 involves nesting and is a complex condition; since the complex condition 1 takes more query time and the relationship between the simple condition 2 and the complex condition 1 is and, at this time, the simple condition 2 can be changed to the front of the complex condition 1. During actual query, the simple condition 2 can be queried first. When the simple condition 2 is not satisfied, there is no need to query the complex condition 1, thereby reducing the query time and improving the query efficiency.

[0093] Among them, conditional replacement can be understood as the use of an optimization node for the inspection logic based on DSL rules. It should be noted that with the continuous update and iteration of the code inspection engine, the query engine will add some new nodes and attributes to establish special edge relationships between some nodes in the DSL rules. These edge relationships can often replace some original complex query logics and improve the query efficiency of the DSL rules. Conditional replacement needs to replace the conditions in the DSL rules according to the query logic of the query engine executing the DSL rules, reducing the query time and thus improving the query efficiency.

[0094] In specific implementation, conditional replacement can be achieved through a second optimizer. The second optimizer is used to replace conditions based on the query logic of the query engine executing the DSL rules (which can be understood as the process of querying from the database when the query engine executes the DSL rules) and through the relationships between the conditions in the DSL rules. Among them, the second optimizer can be understood as a model that can be directly used after being trained in advance; in the embodiments of the present application, the second optimizer can understand the DSL rules and use the corresponding special edge relationship nodes to replace the complex logic therein, and finally can achieve the same performance improvement with a high probability. In a possible implementation manner, the second optimizer can analyze the abstract syntax tree after parsing the DSL rules based on the database and the query engine to obtain the query logic, so as to perform conditional replacement. Specifically, the abstract syntax tree after the query engine parses the DSL rules and the database are input into the second optimizer, so that the second optimizer analyzes according to the description of the abstract syntax tree and the database, understands the DSL rules, and thus uses the corresponding special edge relationship nodes to replace the complex logic therein, and finally can achieve the same performance improvement with a high probability.

[0095] For example, as Figure 3b shown, condition 1 is: va.enclosingClass contain functionCallfcc where, and the second optimizer can replace condition 1 with condition 1': va.enclosingClass.functionCallscontain fcc where; when querying using condition 1, it is necessary to traverse the class and then find the function calls in the class, while when querying using condition 1', the function calls can be directly found without traversing the class, thus saving query time.

[0096] Among them, condition addition can be understood as the inspection logic based on DSL rules, and by adding some condition restrictions to narrow the query range. For example, the type of the node queried by a certain rule is confirmable, and by adding a restriction on its type, access to non - this - type nodes can be excluded, improving the query efficiency.

[0097] The condition addition can be achieved through a third optimizer, which is used to understand DSL rules and add restrictive conditions to the conditions in the DSL rules.

[0098] The third optimizer automatically adds restrictive conditions to the DSL rules based on the model. In specific implementation, a rule optimization instance pair can be constructed, which consists of an unmodified DSL rule and a modified DSL rule (optimized by adding restrictive conditions). Then, the DSL-related grammar description and the rule optimization instance pair are given to the model for learning, enabling the model to analyze the unmodified DSL rule and add restrictive conditions to improve performance. The trained model can be used as the third optimizer.

[0099] Exemplarily, as Figure 3c shown, for the condition: fc.name match “contains|startswith|indexOf”, a new parallel condition: va.type.name == “java.lang.String” is added, and this condition is used to restrict the content contained in contains in the condition: fc.name match “contains|startswith|indexOf”.

[0100] It should be noted that in specific implementation, the performance optimization system 102 determines at least one processing scheme based on at least one modification: changing the order relationship of conditions, condition replacement, and conditions. Each processing scheme is formed by at least one modification method; for each processing scheme, the conditions in the DSL rule are modified according to the modification methods in the processing scheme to determine the modified DSL rule. Exemplarily, the modified DSL rule can be obtained after sequential processing by any one or more of the first optimizer, the second optimizer, or the third optimizer. For example, as Figure 4As shown, the output of the third optimizer is connected to the first optimizer, and the output of the second optimizer is connected to the third optimizer and the first optimizer. There are a total of 4 paths for processing DSL rules, denoted as R1, R2, R3, and R4. Among them, R1 represents DSL rule → the first optimizer, R2 represents DSL rule → the second optimizer → the third optimizer → the first optimizer, R3 represents DSL rule → the second optimizer → the first optimizer, and R4 represents DSL rule → the third optimizer → the first optimizer. It should be noted that each path can be understood as a modification scheme. In practical applications, the performance optimization system 102 can input the DSL rules into the second optimizer, the second optimizer, and the third optimizer respectively, and process them according to the above 4 paths R1, R2, R3, and R4. Correspondingly, there are 4 modified DSL rules. For path R1, the first optimizer can output the modified DSL rule of the DSL rule. For path R2, the output of the second optimizer is input to the third optimizer for modification, the output of the third optimizer is input to the first optimizer, and the first optimizer outputs the modified DSL rule of the output of the third optimizer. For path R3, the output of the second optimizer is input to the first optimizer for modification, and the first optimizer outputs the modified DSL rule of the output of the second optimizer. For path R4, the output of the third optimizer is input to the first optimizer for modification, and the first optimizer outputs the modified DSL rule of the third optimizer.

[0101] Exemplarily, as Figure 3d shown, Condition 1:

[0102]

[0103] Condition 2:

[0104]

[0105] During the modification process, Condition 1 is adjusted to below Condition 2. In Condition 2, Condition 2.1: fc.function contain variableAccess va1 where is replaced with Condition 2’.1: fc.function.variableAccess contain va1 where to obtain Condition 2’. And the structure of Condition 1 can be adjusted to Condition 1’ to reduce the execution time of the condition. Condition 1’ is as follows:

[0106]

[0107] It should be noted that the above three processing methods (changing the conditional order relationship, condition replacement, and condition addition) are only examples and do not constitute specific limitations. Specifically, the processing methods that can improve the query efficiency can be determined in combination with actual requirements.

[0108] Step 204: Based on the query engine and the database, the performance optimization system 102 performs a first test on the modified DSL rule.

[0109] It should be noted that the first test can be understood as executing the modified DSL rule based on the query engine to query data from the database.

[0110] It is worth noting that in the embodiments of the present application, there may be multiple modified DSL rules, and a first test needs to be performed on each modified DSL rule.

[0111] Step 205: Based on the results of the first test, the performance optimization system 102 filters out the target DSL rule from the modified DSL rules. The data queried from the database by the query engine executing the target DSL rule is the same as that by executing the DSL rule, and the execution time of the query engine executing the target DSL rule is less than the execution time of executing the DSL rule.

[0112] Among them, the results of the first test may include the data queried from the database by the query engine executing the modified DSL rule (which can be understood as the query result), and the performance of executing the modified DSL rule, such as the execution time (which can also be understood as the query time). In some possible scenarios, the database stores the call relationships between codes in the software. The data queried from the database by the query engine executing the DSL rule can be considered as risky codes. Subsequently, by analyzing the call relationships between codes in the software, the analysis of software security vulnerabilities can be realized.

[0113] In the embodiments of the present application, in order to ensure that the query results are the same, it is necessary to select the modified DSL rule with the same query result as the DSL rule. In addition, in order to reduce the execution time, it is also necessary to select the modified DSL rule with less execution time, so as to improve the query efficiency. Specifically, the performance optimization system 102 needs to select, from the multiple modified DSL rules, the modified DSL rule that has the same query result as the DSL rule and whose execution time is less than that of the DSL rule as the target DSL rule.

[0114] In some possible implementation manners, the performance optimization system 102 performs a second test on the unmodified DSL rule through the query engine and the database to obtain the result of the second test. The result of the second test may include the data queried from the database by the query engine executing the unmodified DSL rule (which can be understood as the query result), and the performance of executing the unmodified DSL rule, such as the execution time (which can also be understood as the query time). Correspondingly, for each modified DSL rule, the performance optimization system 102 compares whether the query result of the modified DSL rule is the same as that of the unmodified DSL rule. If they are the same, it further compares whether the execution time is reduced. If so, the modified DSL rule can be used as the target DSL rule.

[0115] In some other possible implementation manners, the performance optimization system 102 performs a second test on the unmodified DSL rule through the query engine and the database to obtain the result of the second test. The result of the second test may include the data queried from the database by the query engine executing the unmodified DSL rule (which can be understood as the query result), and the performance of executing the unmodified DSL rule, such as the execution time (which can also be understood as the query time). Correspondingly, the performance optimization system 102 filters out candidate DSL rules from the modified DSL rules; the data queried from the database by the query engine executing the candidate DSL rules is the same as that of the DSL rule; then, the execution times of the candidate DSL rules and the DSL rule are displayed, for example, it can be displayed in the user interface (User Interface, UI), or for another example, the execution times of the candidate DSL rules and the DSL rule can be displayed in a pop-up window on the UI page; exemplarily, as Figure 5 shown, the terminal 101 displays the original DSL rule, two modified DSL rules (with the same query result as the original DSL rule), the optimized execution times of the two modified DSL rules, and the selection boxes for the two modified DSL rules in the UI interface; finally, the DSL rule selected from the candidate DSL rules is determined as the target DSL rule; for example, the user can view the execution times of the candidate DSL rules and the DSL rule through the UI interface, and then select the candidate DSL rule whose execution time is less than that of the DSL rule. The performance optimization system 102 uses the candidate DSL rule selected by the user as the target DSL rule; in specific implementation, as Figure 5 shown, the user can select the modified DSL rule by clicking the selection box.

[0116] In this solution, the DSL rule can be modified, and then, by comparing with the original DSL rule, the modified DSL rule with less execution time and the same query result from the database can be filtered out. Subsequently, by using the modified DSL rule, the time for querying the database by executing the DSL rule can be reduced, and the query efficiency can be improved.

[0117] Further, it should be noted that for the target DSL rule, the performance optimization system 102 can use the target DSL rule and its corresponding unmodified DSL rule as a rule optimization instance pair to continue training the third optimizer to improve the optimization ability of the third optimizer.

[0118] In specific implementation, the performance optimization system 102 combines the DSL rule and the target DSL rule modified by the third optimizer to construct a rule optimization instance pair and trains the third optimizer.

[0119] Based on the above-provided method for modifying the DSL rule, the specific application of the method for modifying the DSL rule is described.

[0120] Figure 6a It is a schematic diagram of a specific application of a method for modifying a DSL rule provided for the implementation of this application. As Figure 6a shown, the specific content includes: The tester can input the DSL rule through the operation terminal 101 and send the DSL rule to the performance optimization system 102. The performance optimization system 102 inputs the DSL rule into the third optimizer, the second optimizer, and the first optimizer (used to split, reconstruct, and sort the DSL query statement in the DSL rule, that is, the rule) respectively for modification to obtain a modified rule set; among them, the third optimizer is connected to the first optimizer, and the second optimizer is connected to the first optimizer and the third optimizer; correspondingly, the modified rule set includes the following 4 modified DSL rules:

[0121] The DSL rule passes through the first optimizer, and the modified DSL rule output by the first optimizer

[0122] After the DSL rule passes through the third optimizer and the first optimizer, the modified DSL rule output by the first optimizer;

[0123] The DSL rule passes through the second optimizer, the third optimizer, and the first optimizer, and the modified DSL rule output by the first optimizer;

[0124] The DSL rule passes through the second optimizer and the first optimizer, and the modified DSL rule output by the first optimizer.

[0125] Then, the performance optimization system 102 tests the DSL rules in the DSL rule set and the modified rule set through a query engine and a database to obtain a test result set. The test result set includes the results after testing each DSL rule in the modified rule set and the results of testing the DSL rules. The results after testing include query results (indicating the data queried from the database) and execution times (indicating the time taken to execute the DSL rules). The performance optimization system 102 selects the modified DSL rules in the modified rule set that have the same query results as the DSL rules to obtain an available rule set. The performance optimization system 102 feeds back the modified DSL rules in the available rule set and the execution times of the modified DSL rules to the terminal 101. The terminal 101 can select the modified DSL rules as the finally used DSL rules. The performance optimization system 102 combines the DSL rules and the DSL rules processed by the third optimizer in the available rule set as a rule optimization instance pair, and continues to train the third optimizer through the newly added rule optimization instance pair to improve the optimization function of the third optimizer.

[0126] Figure 6b A schematic diagram of a specific application of a method for modifying DSL rules provided for the implementation of this application. As Figure 6b shown, the specific content includes: testers can write DSL rules in the page provided by the IDE (Integrated Development Environment) by operating the terminal 101. After completing the writing of the DSL rules, the performance optimization system 102 runs the rule performance optimization function, which is used to implement the functions described in steps 203 and 204 above. Finally, the actual execution times of the DSL rules and the modified DSL rules are obtained, and a pop-up window asks the user whether to apply the modified rules. The terminal 101 displays the original DSL rules, two modified DSL rules (with the same query results as the original DSL rules), the optimized execution times of the two modified DSL rules, and selection boxes for the two modified DSL rules in the IDE WebView (a control for displaying Web pages in the integrated switch environment). The terminal 101 can select one of the modified DSL rules through the selection box, so as to select the modified DSL rule actually used in the actual business.

[0127] This application also provides a device for modifying DSL rules, as Figure 7 shown, including:

[0128] A rule determination module, used to determine a domain-specific language (DSL) rule; the DSL rule is used to query data in a database;

[0129] A modification module, used to modify the conditions in the DSL rule to determine a modified DSL rule;

[0130] A test module, configured to perform a first test on the modified DSL rule based on a query engine and the database; the query engine is configured to execute a DSL rule to query data in the database;

[0131] A screening module, configured to screen a target DSL rule from the modified DSL rules based on the result of the first test; the query engine executes the target DSL rule and the data queried from the database by the DSL rule is the same, and the execution time of the query engine executing the target DSL rule is less than the execution time of executing the DSL rule.

[0132] Among them, the rule determination module, the modification module, the test module, and the screening module can all be implemented by software or by hardware. Exemplarily, next, taking the rule determination module as an example, the implementation manner of the rule determination module will be introduced. Similarly, the implementation manners of the modification module, the test module, and the screening module can refer to the implementation manner of the rule determination module.

[0133] As an example of a software functional unit, the rule determination module may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance may be one or more. For example, the rule determination module may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running this code may be distributed in the same region, or may be distributed in different regions. Further, the multiple hosts / virtual machines / containers for running this code may be distributed in the same availability zone (AZ), or may be distributed in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Among them, generally one region may include multiple AZs.

[0134] Similarly, the multiple hosts / virtual machines / containers for running this code may be distributed in the same virtual private cloud (VPC), or may be distributed in multiple VPCs. Among them, generally one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is achieved through the communication gateway.

[0135] As an example of a hardware functional unit, the rule determination module may include at least one computing device, such as a server or the like. Alternatively, the rule determination module may also be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0136] The multiple computing devices included in the rule determination module may be distributed in the same region or in different regions. The multiple computing devices included in the rule determination module may be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the rule determination module may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0137] It should be noted that in other embodiments, the rule determination module may be used to execute any step in the method for modifying DSL rules, the modification module may be used to execute any step in the method for modifying DSL rules, the test module may be used to execute any step in the method for modifying DSL rules, and the screening module may be used to execute any step in the method for modifying DSL rules. The steps to be implemented by the rule determination module, the modification module, the test module, and the screening module can be specified as needed. The entire function of the YY device is realized by the rule determination module, the modification module, the test module, and the screening module respectively implementing different steps in the method for modifying DSL rules.

[0138] This application also provides a computing device 800. As Figure 8 shown, the computing device 800 includes: a bus 802, a processor 804, a memory 806, and a communication interface 808. The processor 804, the memory 806, and the communication interface 808 communicate with each other through the bus 802. The computing device 800 may be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 800.

[0139] The bus 802 can be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 only one line is used in Figure 8 , but it does not mean that there is only one bus or one type of bus. The bus 802 can include a path for transmitting information between various components of the computing device 800 (e.g., the memory 806, the processor 804, the communication interface 808).

[0140] The processor 804 can include any one or more of processors such as a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), a Micro Processor (MP), or a Digital Signal Processor (DSP).

[0141] The memory 806 can include volatile memory, such as Random Access Memory (RAM). The processor 804 can also include non-volatile memory, such as Read-Only Memory (ROM), flash memory, a Hard Disk Drive (HDD), or a Solid State Drive (SSD).

[0142] The memory 806 stores executable program code, and the processor 804 executes the executable program code to respectively implement the functions of the aforementioned rule determination module, modification module, test module, and screening module, thereby implementing the method for modifying DSL rules. That is, the memory 806 stores instructions for executing the method for modifying DSL rules.

[0143] The communication interface 808 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 800 and other devices or a communication network.

[0144] Embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.

[0145] As Figure 9 shown, the computing device cluster includes at least one computing device 800. Instructions for executing the method for modifying DSL rules can be stored in the same manner in the memory 806 of one or more of the computing devices 800 in the computing device cluster.

[0146] In some possible implementation manners, partial instructions for executing the method for modifying DSL rules can also be stored separately in the memory 806 of one or more of the computing devices 800 in the computing device cluster. In other words, a combination of one or more computing devices 800 can jointly execute the instructions for executing the method for modifying DSL rules.

[0147] It should be noted that the memories 806 in different computing devices 800 in the computing device cluster can store different instructions, respectively for executing partial functions of the DSL rule modification device. That is, the instructions stored in the memories 806 of different computing devices 800 can implement the functions of one or more of the rule determination module, the modification module, the test module, and the screening module.

[0148] In some possible implementation manners, one or more computing devices in the computing device cluster can be connected through a network. Among them, the network can be a wide area network or a local area network, etc. Figure 10 Illustrates a possible implementation manner. As Figure 10 shown, two computing devices 800A and 800B are connected through a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this type of possible implementation manner, instructions for executing the function of the rule determination module are stored in the memory 806 of the computing device 800A. At the same time, instructions for executing the functions of the modification module, the test module, and the screening module are stored in the memory 806 of the computing device 800B.

[0149] Figure 10 The connection manner between the computing device clusters shown can be considered because the method for modifying DSL rules provided in the present application needs to provide DSL rules. Therefore, it is considered to hand over the functions implemented by the modification module, the test module, and the screening module to the computing device 800B for execution.

[0150] It should be understood that Figure 10The functions of the computing device 800A shown can also be completed by multiple computing devices 800. Similarly, the functions of the computing device 800B can also be completed by multiple computing devices 800.

[0151] Embodiments of the present application also provide a computer program product containing instructions. The computer program product can be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute the method for modifying DSL rules.

[0152] Embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc. The computer-readable storage medium includes instructions that direct the computing device to execute the method for modifying DSL rules, or direct the computing device to execute the method for modifying DSL rules.

[0153] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0154] The basic principles of the present application have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present application are only examples and not limitations. It cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. Additionally, the specific details disclosed above are only for illustrative and easy-to-understand purposes, and not for limitation. The above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.

[0155] The block diagrams of the devices, apparatuses, equipment, and systems involved in the present disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended words, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the word "and / or" and can be used interchangeably with each other, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with each other.

[0156] It should also be noted that in the devices, equipment and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations shall be regarded as equivalent solutions of the present disclosure.

[0157] The foregoing description has been presented for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present disclosure to the form disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize some of their variations, modifications, alterations, additions, and subcombinations.

[0158] It can be understood that the various numerical numbers involved in the embodiments of the present application are only for the convenience of description and are not used to limit the scope of the embodiments of the present application.

Claims

1. A method for modifying DSL rules, characterized in that, it includes: Determine domain-specific language (DSL) rules; the DSL rules are used to query data in a database; Modify the conditions in the DSL rules to determine the modified DSL rules; Based on a query engine and the database, perform a first test on the modified DSL rules; The query engine is used to execute DSL rules to query data in the database; Based on the results of the first test, screen target DSL rules from the modified DSL rules; The data queried from the database by the query engine executing the target DSL rules is the same as that by executing the DSL rules, and the execution time of the query engine executing the target DSL rules is less than the execution time of executing the DSL rules.

2. The method according to claim 1, characterized in that, The modification of the conditions in the DSL rules includes: performing at least one of the following modifications on the conditions in the DSL rules: changing the order relationship of conditions, condition replacement, and condition addition.

3. The method according to claim 2, characterized in that, The change of the condition order relationship is implemented by a first optimizer, and the first optimizer is used to disassemble and adjust the structure of the conditions in the DSL rules according to the syntax analysis of the DSL rules by the query engine; The condition replacement is implemented by a second optimizer, and the second optimizer is used to replace the conditions in the DSL rules according to the query logic of the query engine executing the DSL rules; The condition addition is implemented by a third optimizer, and the third optimizer is used to understand the DSL rules and add restrictive conditions to the conditions in the DSL rules to narrow the query scope.

4. The method according to claim 3, characterized in that, The method further includes: using the DSL rules as the input of the third optimizer, and using the DSL rules after the condition addition processing as the output of the third optimizer to train the third optimizer.

5. The method according to claim 1, characterized in that, The method further includes: Based on a query engine and the database, perform a second test on the DSL rules; The screening of the target DSL rules from the modified DSL rules based on the results of the first test includes: Based on the results of the first test and the second test, screen the target DSL rules from the modified DSL rules.

6. The method according to any one of claims 1 to 5, characterized in that, The screening of the target DSL rules from the modified DSL rules includes: Screen candidate DSL rules from the modified DSL rules; the data queried from the database by the query engine executing the candidate DSL rules is the same as that by executing the DSL rules; Display the execution times of the candidate DSL rules and the DSL rules; Determine the DSL rules selected from the candidate DSL rules as the target DSL rules.

7. The method according to any one of claims 1 to 5, characterized in that, The database is the call relationship between codes in the software to be tested; the DSL rules are used to query software codes with security vulnerabilities.

8. An optimization device for DSL rules, characterized in that, the device includes: a rule determination module, configured to determine domain-specific language (DSL) rules; the DSL rules are used to query data in the database; an optimization module, configured to modify the conditions in the DSL rules to determine the modified DSL rules; a test module, configured to perform a first test on the modified DSL rules based on a query engine and the database; the query engine is used to execute the DSL rules to query data in the database; a screening module, configured to screen target DSL rules from the modified DSL rules based on the results of the first test; the data queried from the database by the query engine executing the target DSL rules is the same as that by the query engine executing the DSL rules, and the execution time of the query engine executing the target DSL rules is less than the execution time of the query engine executing the DSL rules.

9. A computing device cluster, characterized in that, it includes at least one computing device, and each computing device includes a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 7.

10. A computer program product containing instructions, characterized in that, when the instructions are run by a computing device cluster, the computing device cluster is caused to execute the method according to any one of claims 1 to 7.

11. A computer-readable storage medium, characterized in that, it includes computer program instructions, and when the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method according to any one of claims 1 to 7.