Static code analysis method and device based on security defect identification

By building a filter-associated defect list and comparing security defects in the source code, the serious problem of false alarms of static code analysis tools is solved, more accurate code security detection and higher development efficiency are achieved, and the security of the software is enhanced.

CN120068068APending Publication Date: 2025-05-30SECZONE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510003514.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-02
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing static code analysis tools have severe false alarms when detecting security vulnerabilities, and cannot recognize the existence of filters, resulting in false alarms, increasing developer workload, reducing development efficiency, and possibly causing real security vulnerabilities to be ignored.

Method used

By building a list of filter-associated defects, identify and compare the security defects associated with the filter in the source code, eliminate the security defects that the filter has prevented, and generate a more accurate code analysis report.

Benefits of technology

It effectively reduces the false alarm rate of static code analysis, avoids developers spending time checking for false false alarms, improves the accuracy and development efficiency of code security detection, and enhances the overall security of the software.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068068A_ABST
    Figure CN120068068A_ABST
Patent Text Reader

Abstract

The invention discloses a static code analysis method and device based on security defect identification. The method comprises the following steps: constructing a filter associated defect list; performing code defect detection on the source code to obtain a defect analysis result of the source code; identifying the types of all security defects in the defect analysis result; comparing the identified security defects with security defects in a filter associated defect list; and removing security defects existing in the filter associated defect list in the defect analysis result to obtain a code analysis report. According to the static code analysis method based on security defect identification, security defects which are prevented by the filter can be accurately identified, the false alarm rate of static code analysis is effectively reduced, and the situation that developers need to spend time and energy in checking false and false alarms is avoided; and the accuracy of code security detection, the efficiency of code development and the security of software can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of static code analysis, and particularly to a static code analysis method and device based on security defect identification. Background Art

[0002] During the software development process, the security of code is of crucial importance. Usually, static code analysis tools (such as source code scanning tools based on data flow analysis, semantic analysis, lexical analysis, etc.) are used to analyze and detect the source code to discover potential security vulnerabilities. However, existing static code analysis tools have certain limitations. One prominent problem is the serious false positives in security vulnerability detection and analysis.

[0003] When using a white-box tool to perform static analysis on code, although it can perform a relatively detailed inspection of the code based on specific analysis techniques, since it cannot recognize the existence of filters in the project, it is prone to produce misjudged detection results. For example, when filters have been reasonably configured in the project to prevent common security problems such as SQL injection vulnerabilities, cross-site scripting (XSS) vulnerabilities, cross-site request forgery (CSRF) vulnerabilities, file upload vulnerabilities, etc. (assuming that developers have performed strict verification for various vulnerabilities in the filters), the white-box tool may still misreport these security problems that have been protected by the filters as potential security hazards, resulting in developers having to spend time and effort to investigate these false alarms. This will undoubtedly increase the workload of developers, reduce development efficiency, and bring unnecessary troubles to developers.

[0004] In addition, the large number of false positive problems may cause the real security vulnerabilities to be submerged among numerous false alarms, resulting in developers being unable to accurately locate and repair the truly critical security problems in a timely manner, posing a potential threat to the overall security of the software. Summary of the Invention

[0005] The purpose of the present invention is to provide a static code analysis method and device based on security defect identification, which can accurately identify the security defects that have been prevented by filters, effectively reduce the false positive rate of static code analysis, avoid developers having to spend time and effort to investigate false positives, and is conducive to improving the accuracy of code security detection, the efficiency of code development, and the security of the software.

[0006] To achieve the above purpose, the present invention discloses a static code analysis method based on security defect identification, which includes:

[0007] Construct a filter-associated defect list;

[0008] Perform code defect detection on the source code to obtain the defect analysis result of the source code;

[0009] Identify the types of all security defects in the defect analysis result;

[0010] Compare the identified security defects with the security defects in the filter-associated defect list;

[0011] Eliminate the security defects in the defect analysis result that exist in the filter-associated defect list to obtain a code analysis report.

[0012] Further, the "constructing the filter-associated defect list" includes:

[0013] Record multiple filters into the filter-associated defect list;

[0014] Associate and match the recorded filters with the filter class names set in the code project;

[0015] Configure the security defects prevented by the filters according to the filter class names.

[0016] Further, after the "configuring the security defects prevented by the filters according to the filter class names", it further includes:

[0017] Associate each of the filters with the corresponding code project.

[0018] Further, the filters include a first filter for preventing SQL injection, a second filter for preventing cross-site scripting attacks, a third filter for preventing cross-site request forgery, and a fourth filter for preventing file uploads.

[0019] Further, the "performing code defect detection on the source code to obtain a defect analysis result of the source code" includes:

[0020] Detect security defects in the source code according to data flow analysis technology, semantic analysis technology, and lexical analysis technology;

[0021] Summarize the detected security defects to form the defect analysis result.

[0022] To achieve the above object, the present invention discloses a static code analysis device based on security defect identification, which includes:

[0023] A construction module for constructing a filter-associated defect list;

[0024] A detection module for performing code defect detection on the source code to obtain a defect analysis result of the source code;

[0025] An identification module for identifying the types of all security defects in the defect analysis result;

[0026] A comparison module, configured to compare the identified security defects with the security defects in the security defect list associated with the filter;

[0027] An elimination module, configured to eliminate the security defects existing in the security defect list associated with the filter from the defect analysis result to obtain a code analysis report.

[0028] To achieve the above object, the present invention discloses an electronic device, which includes:

[0029] One or more processors;

[0030] One or more memories, configured to store one or more programs, and when one or more of the programs are executed by the processor, the processor implements the static code analysis method based on security defect identification as described above.

[0031] To achieve the above object, the present invention discloses a computer-readable storage medium, on which a program is stored, and when the program is executed by a processor, the static code analysis method based on security defect identification as described above is implemented.

[0032] In the present application, by setting a security defect list associated with the filter to identify the security defects that the filter has prevented, first construct a security defect list associated with the filter, then perform code defect detection on the source code to obtain a defect analysis result of the source code, and identify the types of all security defects therein, then compare the identified security types with the security defects in the security defect list associated with the filter, and finally eliminate the corresponding security defects in the defect analysis result according to the comparison result to obtain a code analysis report. The above accurately identifying the security defects that the filter has prevented can effectively reduce the false alarm rate of static code analysis, avoid developers spending time and energy on troubleshooting false alarms, and is beneficial to improving the accuracy of code security detection, the efficiency of code development, and the security of software. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 It is a flowchart of the static code analysis method based on security defect identification according to an embodiment of the present invention.

[0034] Figure 2 It is a module diagram of the static code analysis device based on security defect identification according to an embodiment of the present invention.

[0035] Figure 3 It is a system diagram of the electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] To describe in detail the technical content, structural features, achieved objects and effects of the present invention, the following is described in detail in conjunction with the embodiments and with reference to the drawings.

[0037] Example 1

[0038] Please refer to Figure 1 , the present invention discloses a static code analysis method based on security defect identification, which includes:

[0039] 101. Build a filter-associated defect list;

[0040] Further, "building a filter-associated defect list" includes:

[0041] 1011. Record multiple filters into the filter-associated defect list;

[0042] Further, the filters include a first filter for preventing SQL injection, a second filter for preventing cross-site scripting attacks, a third filter for preventing cross-site request forgery, and a fourth filter for preventing file uploads.

[0043] It should be noted that when configuring the filter-associated defect list in the static code analysis tool, the information that needs to be configured for each filter includes: filter name, filter class name, associated defect type, and associated code project; where the filter name refers to: each configured filter is given an easily recognizable name to accurately refer to the filter in subsequent operations and management.

[0044] For example, the first filter for preventing SQL injection is named "SQLInjectionFilter", the second filter for preventing cross-site scripting attacks (XSS) is named "XSSFilter", the third filter for preventing cross-site request forgery (CSRF) is named "CSRFFilter", and the fourth filter for preventing file uploads is named "FileUploadFilter", and this is not limited thereto.

[0045] 1012. Associate and match the recorded filters with the filter class names set in the code project;

[0046] It should be noted that the filter class name refers to the filter class name corresponding to the filter actually used in the code project. It has a clear class name definition during the project development process. When configuring the corresponding filter in the static code analysis tool, it is necessary to accurately specify the filter class name corresponding to the filter to ensure that the static code analysis tool can correctly identify and associate with the actually running filter. The filter class name needs to be exactly the same in both. For example, the filter class name of the first filter actually used to prevent SQL injection in the code project is "com.example.security.filters.SQLInjectionPreventionFilter", and this is not the limit.

[0047] 1013. Configure the security defects prevented by the filter according to the filter class name.

[0048] It can be understood that the associated defect type in the filter configuration information of the static code analysis tool refers to: the actual filtering function of the filter in the code project, that is, the specific security vulnerability type prevented by the filter. When configuring filters for different functions in the static code analysis tool, it is necessary to check the security defects it filters to implement the configuration of the associated defect type. This is conducive to the static code analysis tool accurately identifying the security issues each filter is responsible for preventing, so as to accurately handle situations related to the filter in the subsequent comparison process.

[0049] For example, the first filter "SQLInjectionFilter" should check "SQL injection", the second filter "XSSFilter" should check "Cross-Site Scripting (XSS)", the third filter "CSRFFilter" should check "Cross-Site Request Forgery (CSRF)", the fourth filter "FileUploadFilter" should check "File upload", and this is not the limit.

[0050] Furthermore, after "configuring the security defects prevented by the filter according to the filter class name", it includes:

[0051] 1014. Associate each filter with the corresponding code project.

[0052] It can be understood that the associated code project in the filter configuration information of the static code analysis tool refers to the scope of the code project involved in the filter. When configuring filters for different functions in the static code analysis tool, it is necessary to check the detection items associated with the filter (selected from the system's code project list) to clarify the code project involved in the filter. For example, if Web application project A uses the first filter for preventing SQL injection vulnerabilities, then in the static code analysis tool, the first filter needs to be associated with the code related to Web application project A so that the detection items associated with the filter can be accurately identified during the subsequent code analysis process.

[0053] By reasonably configuring filters in the code project and configuring the filter-associated defect list for the filter in the static code analysis tool, the white-box tool can identify and exclude the security vulnerabilities protected by the filter, enabling the final code analysis report to more accurately reflect the true security status of the code project, which helps developers quickly locate the real security vulnerabilities and improve the accuracy of code security detection.

[0054] 102. Perform code defect detection on the source code to obtain the defect analysis result of the source code;

[0055] Furthermore, "performing code defect detection on the source code to obtain the defect analysis result of the source code" includes:

[0056] 1021. Detect security defects in the source code according to data flow analysis technology, semantic analysis technology, and lexical analysis technology;

[0057] 1022. Summarize the detected security defects to form a defect analysis result.

[0058] It can be understood that the white-box tool (static code analysis tool) tracks the source code of the detection items according to its own analysis algorithm to search for security defects existing in the source code as much as possible. For example, security defects such as SQL injection, cross-site scripting attack (XSS), cross-site request forgery (CSRF), and file upload, and it is not limited to this.

[0059] 103. Identify the types of all security defects in the defect analysis result;

[0060] 104. Compare the identified security defects with the security defects in the filter-associated defect list;

[0061] 105. Remove the security defects existing in the filter-associated defect list from the defect analysis result to obtain a code analysis report.

[0062] It is understandable that the defect analysis results obtained after using white box tools to perform static code analysis on the source code may contain security defects that have been prevented by filters, and it is necessary to perform operations such as operations 103 to 105 on them based on the filter configuration information in the filter-associated defect list. Specifically, when performing the comparison, in addition to comparing the type of the identified security defect with the type of the corresponding security defect targeted by the filter, it is also necessary to determine whether the code project corresponding to the identified security defect is consistent with the code project associated with the configured filter, so as to finally determine that the security defect involved in the defect analysis result exists in the filter-associated defect list, and then it can be determined that the corresponding security defect in the filter-associated defect list is a false alarm detection result that can be eliminated, and the present invention is not limited to this.

[0063] For example, in Web application project A, if the SQL injection security vulnerability is found to be of the same type as the SQL injection security vulnerability targeted by the first filter, and the corresponding code projects are consistent, then the security defect can be determined to be a false positive and can be excluded from the final code analysis report.

[0064] Since a large number of unnecessary false alarms are reduced and the problem of high false alarm rate is solved, developers do not need to spend a lot of time and energy to troubleshoot these false alarms, which effectively reduces interference to developers and greatly improves the development efficiency of code projects. In addition, accurate security detection results can also enable developers to discover and fix real security vulnerabilities in a timely manner, avoiding the real security risks from being ignored due to a large number of false alarms, thereby effectively enhancing the overall security of the software.

[0065] In the present application, a filter-associated defect list is set to identify security defects that the filter has prevented. First, a filter-associated defect list is constructed, and then code defect detection is performed on the source code to obtain a defect analysis result of the source code, and the types of all security defects therein are identified. Then, the identified security types are compared with the security defects in the filter-associated defect list. Finally, according to the comparison results, the corresponding security defects in the defect analysis results are eliminated to obtain a code analysis report. The above-mentioned accurate identification of security defects that the filter has prevented can effectively reduce the false alarm rate of static code analysis, avoid developers spending time and energy to troubleshoot false alarms, and is conducive to improving the accuracy of code security detection, the efficiency of code development and the security of software.

[0066] Embodiment 2

[0067] See also Figure 1 and Figure 2 The present invention discloses a static code analysis device based on security defect identification, which includes:

[0068] The construction module 201 is used to construct a filter-associated defect list;

[0069] The detection module 202 is used to detect code defects in the source code to obtain the defect analysis result of the source code;

[0070] The identification module 203 is used to identify the types of all security defects in the defect analysis result;

[0071] The comparison module 204 is used to compare the identified security defects with the security defects in the filter-associated defect list;

[0072] The elimination module 205 is used to eliminate the security defects existing in the filter-associated defect list in the defect analysis result to obtain a code analysis report.

[0073] Embodiment III

[0074] Please refer to Figure 1 and Figure 3 , the present invention discloses an electronic device, which includes:

[0075] One or more processors 301;

[0076] One or more memories 302, used to store one or more programs, when the one or more programs are executed by the processor, the processor implements the static code analysis method based on security defect identification as described above.

[0077] Embodiment IV

[0078] The embodiment of the present application discloses a computer-readable storage medium, on which a program is stored, and when the program is executed by the processor, it implements the static code analysis method based on security defect identification as described above.

[0079] Embodiment V

[0080] The embodiment of the present application discloses a computer program product or a computer program, the computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes the above-mentioned static code analysis method based on security defect identification.

[0081] It should be understood that in the embodiments of the present application, the so-called processor may be a central processing module (Central Processing Unit, CPU), and the processor may also be other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), application-specific integrated circuits (Application Specific Integrated Circuit, ASIC), field-programmable gate arrays (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0082] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by hardware related to computer program instructions. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (Read-Only Memory, ROM) or a random access memory (Random Access Memory, RAM), etc.

[0083] The above-disclosed are only the preferred embodiments of the present invention. Of course, the scope of the rights of the present invention cannot be limited thereby. Therefore, equivalent changes made according to the scope of the patent application of the present invention still fall within the scope covered by the present invention.

Claims

1. A static code analysis method based on security defect identification, characterized in that: include: Build a list of filter-related defects; Perform code defect detection on the source code to obtain defect analysis results of the source code; Identify the types of all security defects in the defect analysis results; comparing the identified security defects with the security defects in the defect list associated with the filter; The security defects in the defect analysis result that are in the filter-associated defect list are removed to obtain a code analysis report.

2. The static code analysis method based on security defect identification according to claim 1 is characterized in that: The "Build Filter Association Defect List" includes: recording a plurality of filters into a list of defects associated with the filters; Associate and match the recorded filters with the filter class names set in the code project; The security flaws that the filter guards against are configured according to the filter class name.

3. The static code analysis method based on security defect identification according to claim 2 is characterized in that: After the "configuring the security flaws that the filter protects against according to the filter class name", it also includes: Each of the filters is associated with a corresponding code item.

4. The static code analysis method based on security defect identification according to claim 2 is characterized in that: The filters include a first filter for preventing SQL injection, a second filter for preventing cross-site scripting attacks, a third filter for preventing cross-site request forgery, and a fourth filter for preventing file upload.

5. The static code analysis method based on security defect identification according to claim 1 is characterized in that: The “detecting code defects on the source code to obtain defect analysis results of the source code” includes: Detect security defects in source code based on data flow analysis, semantic analysis and lexical analysis techniques; The detected security defects are summarized to form the defect analysis result.

6. A static code analysis device based on security defect identification, characterized in that: include: A construction module for building a list of filter-associated defects; A detection module is used to perform code defect detection on the source code to obtain a defect analysis result of the source code; An identification module, used to identify the types of all security defects in the defect analysis results; a comparison module, for comparing the identified security defects with the security defects in the defect list associated with the filter; The elimination module is used to eliminate the security defects in the defect analysis result that exist in the filter-associated defect list to obtain a code analysis report.

7. An electronic device, characterized in that: include: one or more processors; One or more memories are used to store one or more programs. When one or more of the programs are executed by the processor, the processor implements the static code analysis method based on security defect identification as described in any one of claims 1 to 5.

8. A computer-readable storage medium having a program stored thereon, characterized in that: When the program is executed by a processor, the static code analysis method based on security defect identification as described in any one of claims 1 to 5 is implemented.