Open source component vulnerability detection method and device and electronic equipment
By analyzing and sub-graphing the open source component dependency configuration files and vulnerability detection files, an open source component vulnerability knowledge graph is built, and the problem of being unable to effectively analyze the open source component dependency chain and vulnerability impact scope in the existing technology is solved, and accurate vulnerability identification and management is achieved.
Patent Information
- Application Number
- CN202510550118.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-29
AI Technical Summary
It is difficult for the existing technology to effectively analyze and accurately quantify the impact of open source component dependency chains and vulnerabilities in the software supply chain, especially due to the large number of open source components and complex dependencies, it is impossible to effectively present the propagation characteristics of vulnerabilities in the open source component dependency chain.
By parsing the open source component dependency configuration files and vulnerability detection files to be detected, multiple triples are built, including head entities, tail entities and entity relationships, and a sub-graph is built based on these triples, and sub-graphs are merged to determine whether the triples are included in the open source component vulnerability knowledge graph, and find the dependency chains of open source components and the scope of impact of vulnerabilities.
It realizes accurate analysis and quantification of the impact range of open source component dependency chain and vulnerabilities, and can effectively identify and manage vulnerabilities in the software supply chain and improve information security.
Smart Images

Figure CN120068096A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular, to a method, device, and electronic device for detecting vulnerabilities in open-source components. Background Art
[0002] Currently, the open-source component-based development model has been widely introduced into the software R & D process. Developers use a large number of open-source components with relevant tools, forming a software supply chain. With the introduction of open-source components, vulnerabilities will inevitably be introduced into the dependency chain of open-source components, projects, and even the entire software supply chain, resulting in the expansion of vulnerabilities. Therefore, it is necessary to comprehensively analyze the entire software supply chain ecosystem and effectively obtain the open-source component dependency chain and the scope of vulnerability propagation.
[0003] However, the existing technologies have problems such as a large number of open-source components, complex dependencies of open-source components, and the inability to effectively present the propagation characteristics of vulnerabilities in the open-source component dependency chain, resulting in the inability to comprehensively analyze and accurately quantify the open-source component dependency chain and the scope of vulnerability impact in the software supply chain. Summary of the Invention
[0004] The present invention provides a method, device, and electronic device for detecting vulnerabilities in open-source components, which can solve at least one of the above technical problems.
[0005] According to an aspect of the present invention, a method for detecting vulnerabilities in open-source components is provided, including: Parsing an open-source component dependency configuration file and an open-source component vulnerability detection file to be detected to obtain a corresponding plurality of triples, where the triple includes a head entity, a tail entity, and an entity relationship between the head entity and the tail entity, the head entity includes an open-source component or a vulnerability, and the tail entity includes an open-source component, a vulnerability, or vulnerability information; Based on the entity relationships provided by the plurality of triples, constructing at least one relationship subgraph for each of the triples, where the at least one relationship subgraph includes a relationship subgraph centered on an open-source component and / or a relationship subgraph centered on a vulnerability; Performing subgraph fusion on at least one relationship subgraph corresponding to each of the triples to obtain a fused relationship subgraph for each of the triples; Based on the similarity between the fused relationship subgraph of each triple and the fused relationship subgraph of each reference triple in the open-source component vulnerability knowledge graph, determining whether each triple is included in the open-source component vulnerability knowledge graph; In the case where it is determined that a first triple among the plurality of triples is included in the open-source component vulnerability knowledge graph, searching for the dependency chain of the open-source component in the first triple and / or the scope of influence of the vulnerability in the open-source component vulnerability knowledge graph.
[0006] According to another aspect of the present invention, there is provided an open-source component vulnerability detection device, including: A configuration file parsing module, configured to parse the open-source component dependency configuration file and the open-source component vulnerability detection file to be detected, and obtain a corresponding plurality of triples, where the triple includes a head entity, a tail entity, and an entity relationship between the head entity and the tail entity, the head entity includes an open-source component or a vulnerability, and the tail entity includes an open-source component, a vulnerability, or vulnerability information; A relationship subgraph construction module, configured to construct at least one relationship subgraph for each of the triples based on the entity relationships provided by the plurality of triples, where the at least one relationship subgraph includes a relationship subgraph centered on an open-source component and / or a relationship subgraph centered on a vulnerability; A subgraph fusion module, configured to perform subgraph fusion on at least one relationship subgraph corresponding to each of the triples to obtain a fused relationship subgraph for each of the triples; An inclusion relationship determination module, configured to determine whether each of the triples is included in the open-source component vulnerability knowledge graph based on the similarity between the fused relationship subgraph of each of the triples and the fused relationship subgraph of each reference triple in the open-source component vulnerability knowledge graph; A graph search module, configured to, when it is determined that a first triple among the plurality of triples is included in the open-source component vulnerability knowledge graph, search for a dependency chain of the open-source component in the first triple and / or the influence scope of the vulnerability in the open-source component vulnerability knowledge graph.
[0007] By adopting the technical solution of the present invention, the open-source component dependency configuration file and the open-source component vulnerability detection file to be detected are parsed to obtain a corresponding plurality of triples, where the triple includes a head entity, a tail entity, and an entity relationship between the head entity and the tail entity, the head entity includes an open-source component or a vulnerability, and the tail entity includes an open-source component, a vulnerability, or vulnerability information. Based on the entity relationships provided by the above-mentioned plurality of triples, at least one relationship subgraph centered on an open-source component and / or a relationship subgraph centered on a vulnerability is constructed for each triple, and then subgraph fusion is performed on at least one relationship subgraph corresponding to each triple to obtain a fused relationship subgraph for each triple. In this way, a relationship subgraph describing the relationship between the open-source component and the vulnerability in the open-source component dependency configuration file and the open-source component vulnerability detection file can be accurately obtained. In this way, by using the fused relationship subgraph, it can be accurately determined whether the triple to be detected is included in the open-source component vulnerability knowledge graph. If so, the open-source component vulnerability knowledge graph can be used to search for the dependency chain of the open-source component in the triple and / or the influence scope of the vulnerability.
[0008] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Description of the Drawings
[0009] The drawings are used to better understand the present solution and do not constitute a limitation to the present invention. Among them: Figure 1 is a flowchart of a method for detecting vulnerabilities in open-source components according to an embodiment of the present invention; Figure 2 is a structural block diagram of a device for detecting vulnerabilities in open-source components according to an embodiment of the present invention; Figure 3 is a block diagram of an electronic device for implementing the method according to an embodiment of the present invention. Detailed Embodiments
[0010] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of the present invention. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0011] Figure 1 is a flowchart of a method for detecting vulnerabilities in open-source components according to an embodiment of the present invention.
[0012] As Figure 1 shown, the method for detecting vulnerabilities in open-source components may include: S110. Parse the open-source component dependency configuration file and the open-source component vulnerability detection file to be detected to obtain a corresponding plurality of triples. Among them, a triple includes a head entity, a tail entity, and an entity relationship between the head entity and the tail entity. The head entity includes an open-source component or a vulnerability, and the tail entity includes an open-source component, a vulnerability, or vulnerability information; S120. Based on the entity relationships provided by the plurality of triples, construct at least one relationship subgraph for each triple. Among them, at least one relationship subgraph includes a relationship subgraph centered on an open-source component and / or a relationship subgraph centered on a vulnerability; S130. Perform subgraph fusion on at least one relationship subgraph corresponding to each triple to obtain a fused relationship subgraph for each triple; S140. Based on the similarity between the fused relationship subgraph of each triple and the fused relationship subgraph of each reference triple in the open-source component vulnerability knowledge graph, determine whether each triple is included in the open-source component vulnerability knowledge graph; S150. When it is determined that the first triple among multiple triples is included in the open-source component vulnerability knowledge graph, in the open-source component vulnerability knowledge graph, search for the dependency chain of the open-source component in the first triple and / or the scope of influence of the vulnerability.
[0013] It can be understood that in the embodiments of the present invention, the triple, the relationship sub-graph of the triple, and the fusion relationship sub-graph can all be expressed by corresponding embedding representations. In the above sub-graph fusion and similarity calculation, the corresponding results are also calculated using the embedding representation.
[0014] Exemplarily, the open-source component vulnerability detection file can be an open-source component vulnerability scan report.
[0015] Exemplarily, for the open-source component vulnerability knowledge graph, it can be pre-collected and constructed from data. The specific construction process can be as follows: Collect the basic information of various open-source components and vulnerabilities, the dependency configuration files of open-source components, etc. from platforms such as open-source project hosting platforms (such as GitHub, GitLab), vulnerability databases (such as NVD - National Vulnerability Database, CVE Details), and Maven Central component libraries. Among them, the basic information of the open-source component can include the component name, component version, component dependency relationship, and the basic information of the vulnerability can include the vulnerability name, vulnerability type, vulnerability description, affected components, etc. The dependency configuration files of open-source components can include component index files, component dependency storage files pom, etc.
[0016] For the collected data, remove duplicate, irregular, and incomplete data.
[0017] Through the above-collected basic information of open-source components, basic information of vulnerabilities, and dependency configuration files of open-source components, it can be determined the dependency relationship between open-source components, the inclusion relationship between open-source components and vulnerabilities, the inclusion relationship between vulnerabilities and vulnerability information, and the influence relationship between vulnerabilities and open-source components. Using these entity relationships, multiple triples can be constructed, and thus, the open-source component vulnerability knowledge graph can be constructed.
[0018] For example, by parsing the dependency configuration file of the open-source component, it can be obtained that if open-source component 1 directly uses open-source component 2, then open-source component 2 is defined as the parent component of open-source component 1, and the dependency relationship is a direct dependency; if open-source component 1 indirectly introduces open-source component 2, then open-source component 2 is defined as the indirect parent component of open-source component 1, and the dependency relationship is an indirect dependency.
[0019] Exemplarily, when parsing the collected data to obtain multiple reference triples, the same steps as those in step S120 and step S130 above can be adopted to obtain the relationship subgraphs of each entity node in the multiple reference triples, and the relationship subgraphs of each entity node are used to construct an open-source component vulnerability knowledge graph. In this way, the open-source component vulnerability knowledge graph integrates open-source components and vulnerability information, and can deeply analyze the open-source components and vulnerabilities of the data to be detected.
[0020] Exemplarily, the knowledge graph of open-source component vulnerabilities can be defined as . Among them, represents the entity set, including the component name, component version in the basic information of the collected open-source components, and the basic information of the vulnerabilities of the open-source components: vulnerability name, vulnerability type, vulnerability description, and other information. represents the relationship set, which is used to describe the relationships between open-source component entities, the relationships between open-source component entities and vulnerability entities, and the relationships between vulnerability entities and vulnerability information. These relationships can include direct dependency, indirect dependency, influence, and inclusion, etc. represents the triple set, which constructs reference triples for the relationships among open-source components, vulnerabilities, and vulnerability information , where represents the head entity, represents the tail entity, represents the head entity and the relationship between the tail entity . For the triples to be detected, they can also be constructed in the same way.
[0021] Exemplarily, for the composition example of triples, it can be as shown in Table 1 below: Table 1: Composition Example of Triples It can be understood that for the open-source component dependency configuration file and the open-source component vulnerability detection file to be detected, they can be parsed to obtain each triple to be detected according to the structural requirements similar to those in Table 1 above, and based on the entity relationships provided by each triple to be detected, at least one relationship subgraph can be constructed for each triple. Among them, at least one relationship subgraph is one relationship subgraph or two relationship subgraphs, such as a relationship subgraph centered on the open-source component and a relationship subgraph centered on the vulnerability.
[0022] For example, if the entities in a triple include open-source component A and open-source component B, the relational subgraph of the triple includes the relational subgraph centered on open-source component A and the relational subgraph centered on open-source component B. Another example is that if the entities in a triple include open-source component A and vulnerability C, the relational subgraph of the triple includes the relational subgraph centered on open-source component A and the relational subgraph centered on vulnerability C. Still another example is that if the entities in a triple include vulnerability C and vulnerability information, the relational subgraph of the triple only includes the relational subgraph centered on vulnerability C.
[0023] Exemplarily, for the relational subgraph of a certain central node, multiple entities having an entity relationship with the central node can be first determined, and an adjacency subgraph can be constructed by using the entity relationships between the central node and each entity, and attention aggregation is performed on the adjacency subgraph to obtain the relational subgraph of the central node. Among them, the central node can be the above-mentioned open-source component or vulnerability, and the entity can be an open-source component or a vulnerability.
[0024] It can be understood that if two relational subgraphs are constructed for a triple, the embedding representations of these two relational subgraphs are fused to obtain the embedding representation of the fused relational subgraph of the triple. If there is only one relational subgraph for a triple, the embedding representation of this relational subgraph is used as the embedding representation of the fused relational subgraph of the triple.
[0025] Exemplarily, the open-source component vulnerability knowledge graph includes multiple reference triples, whose structures are the same as the triples in this example, and each reference triple has a fused relational subgraph. When constructing the fused relational subgraph of the reference triple, the embedding representation of the fused relational subgraph of the reference triple can be stored in the open-source component vulnerability relational subgraph feature library for subsequent matching of the relational subgraph of the triple to be detected to determine whether the triple to be detected is included in the open-source component vulnerability knowledge graph.
[0026] Exemplarily, the embedding representation of the fused relational subgraph of the triple to be detected is matched with the embedding representations of the fused relational subgraphs of each reference triple in the open-source component vulnerability knowledge graph. For example, calculating the Euclidean distance or cosine similarity between them can obtain their similarity. If the similarity is greater than the preset similarity threshold, it is determined that the triple is included in the open-source component vulnerability knowledge graph, and the graph can be used to analyze the dependency chain of the open-source component and the influence range of the vulnerability for the triple. If the similarity is less than the preset threshold, it is determined that the triple is not included in the open-source component vulnerability knowledge graph, and the triple can be considered as invalid information and cannot be used to analyze the dependency chain of the open-source component and the influence range of the vulnerability for the triple.
[0027] Exemplarily, if each triple corresponding to the open-source component dependency configuration file and the open-source component vulnerability detection file to be detected is not included in the open-source component vulnerability knowledge graph, it indicates that the open-source component dependency configuration file and the open-source component vulnerability detection file are invalid files.
[0028] Exemplarily, when it is identified that the triple to be detected is included in the open-source component vulnerability knowledge graph if the entities in the triple include an open-source component, node analysis is performed on the knowledge graph to obtain the dependency chain of the open-source component; if the entities in the triple include a vulnerability, node analysis is performed on the knowledge graph to calculate the impact scope of the vulnerability.
[0029] According to the above implementation method, the open-source component dependency configuration file and the open-source component vulnerability detection file to be detected are parsed to obtain multiple triples to be detected. Among them, a triple includes a head entity, a tail entity, and the entity relationship between the head entity and the tail entity. The head entity includes an open-source component or a vulnerability, and the tail entity includes an open-source component, a vulnerability, or vulnerability information. Based on the entity relationships provided by the above multiple triples, at least one relationship subgraph centered on an open-source component and / or at least one relationship subgraph centered on a vulnerability is constructed for each triple, and then subgraph fusion is performed on at least one relationship subgraph corresponding to each triple to obtain the fused relationship subgraph of each triple. In this way, a relationship subgraph describing the relationship between the open-source component and the vulnerability in the open-source component dependency configuration file and the open-source component vulnerability detection file can be accurately obtained. In this way, using the fused relationship subgraph of the triple to be detected, it can be accurately determined whether the triple to be detected is included in the open-source component vulnerability knowledge graph. If so, the open-source component vulnerability knowledge graph can be used to find the dependency chain of the open-source component and / or the impact scope of the vulnerability in the triple, so as to realize the analysis of the dependency chain of the open-source component and / or the impact scope of the vulnerability.
[0030] In one implementation manner, based on the entity relationships provided by multiple triples, constructing at least one relationship subgraph for each triple includes: when the head entity with the entity type of vulnerability or open-source component and the tail entity with the entity type of vulnerability or open-source component are included in the triple, based on the entity relationships provided by multiple triples, a relationship subgraph centered on the head entity and a relationship subgraph centered on the tail entity are constructed for the triple; when the head entity with the entity type of vulnerability and the tail entity with the entity type of vulnerability information are included in the triple, based on the entity relationships provided by multiple triples, only a relationship subgraph centered on the head entity is constructed for the triple.
[0031] Exemplarily, if both the head entity and the tail entity of the triple are open-source components, relationship subgraphs are constructed with these two open-source components as one central node respectively, and this triple has two relationship subgraphs centered on open-source components.
[0032] Exemplarily, if the head entity of a triple is an open-source component and the tail entity is a vulnerability, then this triple has a relationship subgraph centered on the open-source component and a relationship subgraph centered on the vulnerability. Or, if the head entity of a triple is a vulnerability and the tail entity is an open-source component, then this triple has a relationship subgraph centered on the open-source component and a relationship subgraph centered on the vulnerability.
[0033] Exemplarily, if the head entity of a triple is a vulnerability and the tail entity is vulnerability information, then this triple has only one relationship subgraph centered on the open-source component.
[0034] Exemplarily, when constructing the relationship subgraph of a certain central node, based on the entity relationships provided by multiple tuples to be detected, among the entities involved in multiple triples, the neighbor nodes of the central node can be determined, and based on the entity relationships between the central node and these neighbor nodes, the relationship subgraph of the central node can be constructed.
[0035] According to the above embodiments, for a triple, according to the entity types of the head entity and the tail entity of the triple, that is, whether they are open-source components or vulnerabilities, it is determined whether to construct a relationship subgraph centered on the head entity and a relationship subgraph centered on the tail entity. In this way, each triple can obtain at least one relationship subgraph centered on an open-source component or a relationship subgraph centered on a vulnerability.
[0036] In one embodiment, constructing the relationship subgraph centered on the head entity includes: based on the entity relationships provided by multiple triples, among all the entities involved in each triple, determining multiple one-hop neighbors that have an entity relationship with the head entity; based on the entity relationship types between the head entity and each one-hop neighbor of the head entity, constructing an adjacency subgraph centered on the head entity under each entity relationship type; using a graph attention network to perform attention aggregation on the adjacency subgraphs centered on the head entity under each entity relationship type to obtain the relationship subgraph centered on the head entity.
[0037] In one embodiment, constructing the relationship subgraph centered on the tail entity includes: based on the entity relationships provided by multiple triples, among all the entities involved in each triple, determining multiple one-hop neighbors that have an entity relationship with the tail entity; based on the entity relationship types between the tail entity and each one-hop neighbor of the tail entity, constructing an adjacency subgraph centered on the tail entity under each entity relationship type; using a graph attention network to perform attention aggregation on the adjacency subgraphs centered on the tail entity under each entity relationship type to obtain the relationship subgraph centered on the tail entity.
[0038] Exemplarily, using a graph attention network, attention aggregation is performed on the adjacency subgraphs under each entity relationship type to obtain the relationship subgraph of the central node, which may specifically include: for the adjacency subgraphs under each entity relationship type, based on the concatenation result between the central node and each adjacent node in the adjacency subgraph under this entity relationship type, the relevant weight coefficients between the central node and each adjacent node are determined, and using the relevant weight coefficients between the central node and each adjacent node, each adjacent node is aggregated to obtain the aggregation information of the adjacency subgraph under this entity relationship type. The multi-head attention mechanism is used to perform attention calculation on the aggregation information of the adjacency subgraph under this entity relationship type to obtain the attention score of the adjacency subgraph under this entity relationship type, and based on the attention scores of the adjacency subgraphs under each entity relationship type, the adjacency subgraphs under each entity relationship type are aggregated to obtain the relationship subgraph of the central node. Among them, the central node may be the above-mentioned head entity or tail entity.
[0039] Exemplarily, since the head entity can include two entity types, namely open-source components and vulnerabilities, the relationship subgraph centered on the head entity may include the relationship subgraph centered on open-source components and the relationship subgraph centered on vulnerabilities.
[0040] Exemplarily, since the tail entity can include two entity types, namely open-source components and vulnerabilities, the relationship subgraph centered on the tail entity may include the relationship subgraph centered on open-source components and the relationship subgraph centered on vulnerabilities.
[0041] Specifically, the calculation process of the embedding representation of the relationship subgraph centered on open-source components and the relationship subgraph centered on vulnerabilities will be introduced below: Exemplarily, given an embedding representation of a triple the initial embeddings of the entities and relationships of the triple can be obtained through TransE, is the initial embedding of the head entity ; is the initial embedding of the relationship ; is the initial embedding of the tail entity . Among them, is the function of the embedding representation. Then, the initial embeddings of the entities and relationships are projected into the same feature space to obtain the vector representations of the entities and relationships respectively, which are: ; ; .
[0042] Among them, represents the vector representation of the head entity, Vector representation of entity relationship Vector representation of the tail entity Entity transformation matrix Entity relationship transformation matrix
[0043] Exemplarily, the above entity transformation matrix and entity relationship transformation matrix can be obtained by learning the embedded representation of triples in the knowledge graph using a neural network.
[0044] Exemplarily, if the entity type of the central node is an open-source component, the entity relationship type is , where represents the relationship type where the entity relationship between open-source components is indirect dependence represents the relationship type where the entity relationship between open-source components is indirect dependence represents the relationship type where the entity relationship between an open-source component and a vulnerability is inclusion. Divide all one-hop neighbors of the central node into subgraphs, and assign the one-hop neighbors to the adjacent subgraphs under the corresponding entity relationship type according to the entity relationship type between the one-hop neighbors and the open-source component central node. Thus, adjacent subgraphs centered on the open-source component under each entity relationship type are generated.
[0045] Exemplarily, if the entity type of the central node is a vulnerability, the entity relationship type is , where represents another vulnerability included in the vulnerability central node, as well as the vulnerability name, vulnerability type, vulnerability description, vulnerability level, vulnerability hazard level, and vulnerability exploitation method, etc., of the vulnerability central node represents the open-source components affected by the vulnerability central node. Divide all one-hop neighbors of the central node into subgraphs, and assign the one-hop neighbors to the adjacent subgraphs under the corresponding entity relationship type according to the entity relationship type between the one-hop neighbors and the vulnerability central node. Thus, adjacent subgraphs centered on the vulnerability under each entity relationship type are generated.
[0046] Exemplarily, taking the node as the central node, determine the neighbor node of the central node in the adjacent subgraph under the entity relationship type , and splice the vector representation connecting the central node with the vector representation of its neighbor node to obtain the splicing result, specifically as follows: ; where is the vector representation of the central node and its neighbor node The concatenation result of the vector representation, is the linear transformation matrix, is the concatenation function, represents the neighbor node of the vector representation, represents the open-source component as the central node of the vector representation.
[0047] Exemplarily, based on the vector representation of the central node and the concatenation result of the vector representations of each neighbor node, calculate the central node in the adjacency subgraph under the entity relationship type The correlation weight coefficient between and the neighbor node is: ; Among them, is the central node in the adjacency subgraph under the entity relationship type The correlation weight coefficient between and the neighbor node is, is the exponential function, is the activation function, is the central node and the neighbor node The linear transformation matrix in the adjacency subgraph, is to connect the central node The set of all neighbor nodes of, is the central node And the The linear transformation matrix of the th neighbor node in the adjacency subgraph.
[0048] After obtaining the correlation weight coefficients between the central node and each neighbor node in the adjacency subgraph under each entity relationship type, based on the graph attention network, aggregate the information of the adjacency subgraph under each entity relationship type, and calculate the attention of the aggregated information of the adjacency subgraph under each entity relationship type. Using the attention result, further aggregate the aggregated information of the adjacency subgraph under each entity relationship type, and the relationship subgraph of the central node can be obtained.
[0049] Exemplarily, set the central node of the adjacency subgraph under the entity relationship type to be , connect the central node The set of all neighbor nodes of is .
[0050] Adopt the multi-head attention mechanism for the adjacency subgraph under the entity relationship type The one associated with the central node in Aggregate the information of all neighboring nodes connected, and the embedded representation of the aggregation result is: ; Among them, is the aggregation information of all neighboring nodes connected to the central node in the adjacent subgraph with the entity relationship type of , and can also be called the embedded representation of the adjacent subgraph with the entity relationship type of centered on the node . is the aggregation operation of multi-head attention, is the number of multi-head attention, is the activation function under the multi-head attention mechanism.
[0051] Since there are three entity relationship types centered on the open-source component, namely . Similarly, by combining the above formula as an example, the aggregation information of all neighboring nodes connected to the central node in the adjacent subgraph under the other two relationship types can be obtained. Thus, the embedded representations of the three adjacent subgraphs centered on the node under the above three entity relationship types can be: .
[0052] Calculate the attention score for the embedded representation of the adjacent subgraph, and the attention score of the embedded representation of this adjacent subgraph relative to the central node can be obtained as: .
[0053] Among them, is the attention score of the adjacent subgraph under the entity relationship type , is the embedded representation of the central node in the adjacent subgraph, is the diagonal matrix corresponding to the adjacent subgraph under the entity relationship type , is the transformation function, is the embedded representation of the adjacent subgraph with the entity relationship type of centered on the node .
[0054] In some examples, perform a normalization operation on the attention score to obtain the normalized attention score of each adjacent subgraph of the entity relationship type relative to the central node, specifically as follows: ; Among them, is the entity relationship type The adjacency subgraph with respect to the central node The normalized attention score of
[0055] After obtaining the normalized attention scores of the adjacency subgraphs of each entity relationship type with respect to the central node, a multi-head attention mechanism is adopted to calculate the embedding representation of the relationship subgraph with the open-source component entity node as the central node, which is specifically as follows: .
[0056] Among them, represents the relationship subgraph with node as the central node, where node is an open-source component.
[0057] Exemplarily, the calculation process of the embedding representation of the relationship subgraph with a vulnerability as the central node can be similar to the calculation process of the embedding representation of the relationship subgraph with an open-source component as the central node, except that the entity relationship types related to the vulnerability central node are .
[0058] Therefore, a multi-head attention mechanism is adopted to calculate the embedding representation of the relationship subgraph with a vulnerability as the central node , which is specifically as follows: ; Among them, is the number of multi-head attentions, 2 is the number of entity relationship types, is the transformation function, is the vector representation with a vulnerability as the central node , is the embedding representation of the adjacency subgraph under the entity relationship type with a vulnerability as the central node .
[0059] According to the above embodiments, for each central node, the attention aggregation of the adjacency subgraphs under each entity relationship type of the central node is respectively performed through the attention mechanism, and the relationship subgraph with the open-source component as the central node and the relationship subgraph with the vulnerability as the central node can be obtained.
[0060] In one implementation, subgraph fusion is performed on at least one relationship subgraph corresponding to each triple to obtain a fused relationship subgraph for each triple, including: when a relationship subgraph centered on the head entity and a relationship subgraph centered on the tail entity are constructed for a triple, vector concatenation is performed on the relationship subgraph centered on the head entity and the relationship subgraph centered on the tail entity of the triple to obtain a fused relationship subgraph for the triple; when only a relationship subgraph centered on the head entity is constructed for a triple, based on the relationship subgraph centered on the head entity of the triple, the fused relationship subgraph for the triple is determined.
[0061] It can be understood that for any triple, the fused relationship subgraph thereof can be calculated in the above manner.
[0062] Exemplarily, if the head entity of a triple is an open-source component and the tail entity is a vulnerability, or if the head entity is a vulnerability and the tail entity is an open-source component, then the relationship subgraph of the triple includes a relationship subgraph centered on the open-source component and a relationship subgraph centered on the vulnerability. By fusing these two subgraphs, the relationship subgraph of the triple can be obtained.
[0063] For example, by fusing the embedding representation of the relationship subgraph centered on the open-source component and the embedding representation of the relationship subgraph centered on the vulnerability, the embedding representation of the fused relationship subgraph of the triple can be obtained. , calculated as: ; where is the embedding representation of the relationship subgraph centered on the open-source component, is the embedding representation of the relationship subgraph centered on the vulnerability, represents the symbol for concatenation.
[0064] Exemplarily, if the head entities of a triple are all open-source components, then the relationship subgraph of the triple includes two relationship subgraphs centered on the open-source components. These two relationship subgraphs are also fused to obtain the fused relationship subgraph of the triple. If the head entities of a triple are all vulnerabilities, then the relationship subgraph of the triple includes two relationship subgraphs centered on the vulnerabilities. These two relationship subgraphs are also fused to obtain the fused relationship subgraph of the triple.
[0065] It can be understood that for the knowledge graph of open-source component vulnerabilities The fusion relationship sub-graph of the reference triples in [the above] can also be calculated in a similar process as described above. Then, the calculated fusion relationship sub-graph of the reference triples is stored in the open-source component vulnerability relationship sub-graph feature library. Thus, in the process of analyzing each triple to be detected for open-source components and their vulnerabilities, based on the fusion relationship sub-graph of the triple to be detected, a target fusion relationship sub-graph with a similarity meeting the requirements can be searched for in the open-source component vulnerability relationship sub-graph feature library. If found, it indicates that the triple to be detected is included in the open-source component vulnerability knowledge graph. Furthermore, the dependency chain of the open-source component in the triple and / or the scope of influence of the vulnerability can be searched for in the graph.
[0066] According to the above-described embodiment, the fusion relationship sub-graphs of each triple to be detected can be calculated to facilitate subsequent searching in the open-source component vulnerability knowledge graph for reference triples whose fusion relationship sub-graphs match the fusion relationship sub-graph of the triple to be detected.
[0067] In one embodiment, in the open-source component vulnerability knowledge graph, searching for the dependency chain of the open-source component in the first triple and / or the scope of influence of the vulnerability includes: when the first triple includes a first open-source component, using the first open-source component as the initial central node, performing the following searching operation until the found open-source component neighbor nodes no longer meet the preset requirements, then stopping the searching operation and connecting the found central nodes in sequence to obtain the dependency chain of the first open-source component in the first triple; when the first triple includes a first vulnerability, using the first vulnerability as the initial central node, performing the searching operation until the found open-source component neighbor nodes no longer meet the preset requirements, then stopping the searching operation and connecting the found central nodes in sequence to obtain the scope of influence of the first vulnerability in the first triple; where the searching operation includes: in the open-source component vulnerability knowledge graph, searching for open-source component neighbor nodes that have an entity relationship with the central node and meet the preset requirements, and based on the relevance degree between the central node and each open-source component neighbor node, determining the central node for the next searching operation among each open-source component neighbor node.
[0068] In one embodiment, the searching operation further includes: determining the first similarity between the central node and the open-source component neighbor node based on the number of neighbor nodes of each node in the intersection between the neighbor node set of the central node and the neighbor node set of the open-source component neighbor node; determining the second similarity between the central node and the open-source component neighbor node based on the ratio between the number of nodes in the intersection between the neighbor node set of the central node and the neighbor node set of the open-source component neighbor node, and the number of nodes in the union between the neighbor node set of the central node and the neighbor node set of the open-source component neighbor node; and determining the relevance degree between the central node and the open-source component neighbor node based on the first similarity and the second similarity.
[0069] Exemplarily, in the open-source component vulnerability knowledge graph select nodes that are similarity-matched with the first open-source component or the first vulnerability in the triple to be detected as the central node for the next execution of the above-mentioned search operation. The node is the open-source component neighbor node of the node , where is the total number of all open-source component neighbor nodes of the central node
[0070] Exemplarily, determine the intersection between the neighbor node set of the central node and the neighbor node set of the open-source component neighbor node, and use the sum of the reciprocals of the logarithms of the total number of neighbor nodes of each node in this intersection as the first similarity between the central node and the open-source component neighbor node
[0071] Exemplarily, adopt the Adamic Adar algorithm to calculate and The correlation between them, and the calculation formula is: ; where is the similarity degree between the node and the node , is the neighbor node set of the central node , is the neighbor node set of the node , belongs to and The node in the intersection node set of the neighbor node sets is the node The number of neighbor nodes
[0072] Exemplarily, use the ratio between the number of nodes in the intersection of the neighbor node set of the central node and the neighbor node set of the open-source component neighbor node and the number of nodes in the union of the neighbor node set of the central node and the neighbor node set of the open-source component neighbor node as the second similarity between the central node and the open-source component neighbor node
[0073] Exemplarily, adopt the Jaccard similarity to calculate and The trend factor between them, and the calculation formula is: ; where is the neighbor node set of the central node , is the node The set of neighbor nodes of The symbol representing the intersection of sets, The symbol representing the union of sets, The value of is between and node The closer it is to 1, the more similar the nodes
[0074] Exemplarily, by taking the average of the reciprocal of the first similarity and the second similarity, the correlation degree between the central node and the neighbor nodes of the open-source component can be obtained.
[0075] Exemplarily, calculate the central node and the neighbor nodes of the open-source component The correlation degree is: ; where The value of is between For example If then discard the corresponding neighbor node.
[0076] It can be understood that by calculating the correlation degree between the central node and all its neighbor nodes, arranging them in descending order of the correlation degree values, and selecting the node with the highest correlation degree value as the central node for the next search operation, and repeating the above search operation in turn until all nodes in the entire knowledge graph are executed or until the correlation degree between the central node and all its neighbor nodes is lower than the preset threshold, then stop executing the above search operation.
[0077] Exemplarily, starting from the initial central node, connecting the found central nodes in the order of the search of the central node, the dependency chain of the open-source component and the influence range of the vulnerability can be obtained.
[0078] It can be understood that through the above method, the unique meta-path of the dependency chain of the open-source component and the influence range of the vulnerability can be determined. If it is set that there is a finite path between the central node and the final neighbor node then it is represented as the meta-path where is the number of relationships in the meta-path. If the node to be detected is an open-source component, then determine that the open-source component has layers of dependency relationships. If the node to be detected is a vulnerability, then determine that the vulnerability affects the open-source component and has layers of vulnerability propagation.
[0079] According to the above embodiments, the unique meta - path for determining the dependency chain of open - source components and the scope of influence of vulnerabilities can be determined.
[0080] Figure 2 It is a structural block diagram of an open - source component vulnerability detection device according to an embodiment of the present invention.
[0081] As Figure 2 shown, the open - source component vulnerability detection device includes: A configuration file parsing module 210, configured to parse the open - source component dependency configuration file and the open - source component vulnerability detection file to be detected, and obtain a corresponding plurality of triples. Among them, the triple includes a head entity, a tail entity, and the entity relationship between the head entity and the tail entity. The head entity includes an open - source component or a vulnerability, and the tail entity includes an open - source component, a vulnerability, or vulnerability information; A relationship sub - graph construction module 220, configured to construct at least one relationship sub - graph for each of the triples based on the entity relationships provided by the plurality of triples. Among them, the at least one relationship sub - graph includes a relationship sub - graph centered on an open - source component and / or a relationship sub - graph centered on a vulnerability; A sub - graph fusion module 230, configured to perform sub - graph fusion on the at least one relationship sub - graph corresponding to each of the triples to obtain a fused relationship sub - graph for each of the triples; An inclusion relationship judgment module 240, configured to determine whether each of the triples is included in the open - source component vulnerability knowledge graph based on the similarity between the fused relationship sub - graph of each of the triples and the fused relationship sub - graph of each reference triple in the open - source component vulnerability knowledge graph; A graph search module 250, configured to, when it is determined that a first triple among the plurality of triples is included in the open - source component vulnerability knowledge graph, search for the dependency chain of the open - source component and / or the scope of influence of the vulnerability in the first triple in the open - source component vulnerability knowledge graph.
[0082] In one embodiment, the relationship sub - graph construction module 220 includes: A first sub - graph construction unit, configured to, when the head entity with an entity type of a vulnerability or an open - source component and the tail entity with an entity type of a vulnerability or an open - source component are included in the triple, construct a relationship sub - graph centered on the head entity and a relationship sub - graph centered on the tail entity for the triple based on the entity relationships provided by the plurality of triples; A second sub - graph construction unit, configured to, when the head entity with an entity type of a vulnerability and the tail entity with an entity type of vulnerability information are included in the triple, construct only a relationship sub - graph centered on the head entity for the triple based on the entity relationships provided by the plurality of triples.
[0083] In one implementation, constructing a relational subgraph with the head entity as the central node includes: Based on the entity relationships provided by the multiple triples, among all the entities involved in each triple, determine multiple one-hop neighbors that have an entity relationship with the head entity; Based on the entity relationship types between the head entity and each of its one-hop neighbors, construct an adjacency subgraph with the head entity as the central node under each entity relationship type; Use a graph attention network to perform attention aggregation on the adjacency subgraphs with the head entity as the central node under each entity relationship type to obtain a relational subgraph with the head entity as the central node.
[0084] In one implementation, constructing a relational subgraph with the tail entity as the central node includes: Based on the entity relationships provided by the multiple triples, among all the entities involved in each triple, determine multiple one-hop neighbors that have an entity relationship with the tail entity; Based on the entity relationship types between the tail entity and each of its one-hop neighbors, construct an adjacency subgraph with the tail entity as the central node under each entity relationship type; Use a graph attention network to perform attention aggregation on the adjacency subgraphs with the tail entity as the central node under each entity relationship type to obtain a relational subgraph with the tail entity as the central node.
[0085] In one implementation, the subgraph fusion module 230 includes: A first fusion unit, configured to concatenate the vectors of the relational subgraph with the head entity as the central node and the relational subgraph with the tail entity as the central node of the triple to obtain a fused relational subgraph of the triple when the relational subgraphs with the head entity as the central node and the tail entity as the central node are constructed for the triple; A second fusion unit, configured to determine the fused relational subgraph of the triple based on the relational subgraph with the head entity as the central node of the triple when only the relational subgraph with the head entity as the central node is constructed for the triple.
[0086] In one implementation, the graph lookup module 250 includes: A dependency chain determination unit, which is used to, when the first open-source component is included in the first triple, use the first open-source component as an initial central node to perform the following search operation until the found open-source component neighbor nodes no longer meet the preset requirements, stop performing the search operation, and sequentially connect the found central nodes to obtain the dependency chain of the first open-source component in the first triple; An influence scope determination unit, which is used to, when the first vulnerability is included in the first triple, use the first vulnerability as an initial central node to perform the search operation until the found open-source component neighbor nodes no longer meet the preset requirements, stop performing the search operation, and sequentially connect the found central nodes to obtain the influence scope of the first vulnerability in the first triple; Wherein, the search operation includes: in the open-source component vulnerability knowledge graph, searching for open-source component neighbor nodes that have an entity relationship with the central node and meet the preset requirements, and based on the relevance degree between the central node and each open-source component neighbor node, determining the central node for the next execution of the search operation among each open-source component neighbor node.
[0087] In one implementation manner, the search operation further includes: Based on the number of neighbor nodes of each node in the intersection between the neighbor node set of the central node and the neighbor node set of the open-source component neighbor node, determining the first similarity between the central node and the open-source component neighbor node; Based on the ratio between the number of nodes in the intersection between the neighbor node set of the central node and the neighbor node set of the open-source component neighbor node, and the number of nodes in the union between the neighbor node set of the central node and the neighbor node set of the open-source component neighbor node, determining the second similarity between the central node and the open-source component neighbor node; Based on the first similarity and the second similarity, determining the relevance degree between the central node and the open-source component neighbor node.
[0088] For the specific functions and examples of each module and sub-module of the system in the embodiments of the present invention, reference can be made to the relevant descriptions of the corresponding steps in the above method embodiments, which will not be elaborated here.
[0089] In the technical solution of the present invention, the acquisition, storage, and application of the user's personal information involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0090] According to the embodiments of the present invention, the present invention also provides a system and a readable storage medium.
[0091] Figure 3FIG. shows a schematic block diagram of an exemplary electronic device 800 that can be used to implement embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely exemplary and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0092] As Figure 3 shown, the electronic device 800 includes a computing unit 801 that can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0093] A plurality of components in the electronic device 800 are connected to the I / O interface 805, including: an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a magnetic disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the electronic device 800 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0094] The computing unit 801 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 executes the various methods and processes described above, such as the power system production simulation method considering the peak shaving characteristics of coal-fired units. For example, in some embodiments, the power system production simulation method considering the peak shaving characteristics of coal-fired units can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as the storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the computing unit 801, one or more steps of the power system production simulation method considering the peak shaving characteristics of coal-fired units described above can be executed. Alternatively, in other embodiments, the computing unit 801 can be configured to execute the power system production simulation method considering the peak shaving characteristics of coal-fired units in any other suitable manner (e.g., by means of firmware).
[0095] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special or general programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0096] The program code for implementing the method of the present invention can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.
[0097] In the context of the present invention, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0098] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0099] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.
[0100] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, a server of a distributed system, or a server incorporating a blockchain.
[0101] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in the present invention can be achieved, and no limitations are imposed herein.
[0102] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for detecting open source component vulnerabilities, characterized in that: include: Parsing the open source component dependency configuration file and the open source component vulnerability detection file to be detected to obtain a corresponding plurality of triples, wherein the triples include a head entity, a tail entity, and an entity relationship between the head entity and the tail entity, the head entity includes an open source component or a vulnerability, and the tail entity includes an open source component, a vulnerability, or vulnerability information; Based on the entity relationships provided by the multiple triples, construct at least one relationship subgraph for each of the triples, wherein the at least one relationship subgraph includes a relationship subgraph with an open source component as a central node and / or a relationship subgraph with a vulnerability as a central node; Performing subgraph fusion on at least one relationship subgraph corresponding to each of the triples to obtain a fused relationship subgraph of each of the triples; Based on the similarity between the fusion relationship subgraph of each triple and the fusion relationship subgraph of each reference triple in the open source component vulnerability knowledge graph, determining whether each triple is included in the open source component vulnerability knowledge graph; When it is determined that a first triple of the multiple triples is included in the open source component vulnerability knowledge graph, the dependency chain of the open source component and / or the impact scope of the vulnerability in the first triple is searched in the open source component vulnerability knowledge graph.
2. The method according to claim 1, characterized in that: The step of constructing at least one relationship subgraph for each triple based on the entity relationships provided by the multiple triples comprises: In a case where the triple includes a head entity whose entity type is vulnerability or open source component and a tail entity whose entity type is vulnerability or open source component, based on the entity relationships provided by the multiple triples, constructing a relationship subgraph with the head entity as a central node and a relationship subgraph with the tail entity as a central node for the triple; In the case where the triple includes a head entity whose entity type is vulnerability and a tail entity whose entity type is vulnerability information, based on the entity relationships provided by the multiple triples, only a relationship subgraph with the head entity as the central node is constructed for the triple.
3. The method according to claim 2, characterized in that The constructing of a relationship subgraph with the head entity as a central node includes: Based on the entity relationships provided by the multiple triples, determining multiple one-hop neighbors having entity relationships with the head entity among all entities involved in each of the triples; Based on the entity relationship types between the head entity and each one-hop neighbor of the head entity, construct an adjacency subgraph with the head entity as a central node under each entity relationship type; A graph attention network is used to perform attention aggregation on adjacent subgraphs with the head entity as the central node under each entity relationship type, so as to obtain a relationship subgraph with the head entity as the central node.
4. The method according to claim 2, characterized in that: The constructing of a relationship subgraph with the tail entity as a central node includes: Based on the entity relationships provided by the multiple triples, determining, among all entities involved in each of the triples, multiple one-hop neighbors having an entity relationship with the tail entity; Based on the entity relationship types between the tail entity and each one-hop neighbor of the tail entity, construct an adjacency subgraph with the tail entity as a central node under each entity relationship type; A graph attention network is used to perform attention aggregation on adjacent subgraphs with the tail entity as the central node under each entity relationship type, so as to obtain a relationship subgraph with the tail entity as the central node.
5. The method according to claim 1, characterized in that The step of performing subgraph fusion on at least one relationship subgraph corresponding to each of the triples to obtain a fused relationship subgraph of each of the triples includes: In the case where the triple is constructed with a relationship subgraph with the head entity as a central node and a relationship subgraph with the tail entity as a central node, vector concatenation is performed on the relationship subgraph with the head entity as a central node and the relationship subgraph with the tail entity as a central node of the triple to obtain a fused relationship subgraph of the triple; In the case that the triple only constructs a relation subgraph with the head entity as a central node, a fused relation subgraph of the triple is determined based on the relation subgraph of the triple with the head entity as a central node.
6. The method according to claim 1, characterized in that The step of searching, in the open source component vulnerability knowledge graph, the dependency chain of the open source component in the first triple and / or the impact scope of the vulnerability includes: In the case where the first triplet includes a first open source component, taking the first open source component as the initial central node, performing the following search operation until all the neighbor nodes of the open source component found do not meet the preset requirements, stopping the search operation, and connecting the found central nodes in sequence to obtain a dependency chain of the first open source component in the first triplet; In the case where the first triplet includes a first vulnerability, when the first vulnerability is an initial central node, the search operation is performed until none of the found open source component neighbor nodes meets the preset requirement, the search operation is stopped, and the found central nodes are connected in sequence to obtain the impact scope of the first vulnerability in the first triplet; Among them, the search operation includes: in the open source component vulnerability knowledge graph, searching for open source component neighbor nodes that have an entity relationship with the central node and meet the preset requirements, and based on the degree of correlation between the central node and each of the open source component neighbor nodes, determining the central node for performing the search operation next time among each of the open source component neighbor nodes.
7. The method according to claim 6, characterized in that The search operation also includes: Determine a first similarity between the central node and the open source component neighbor node based on the number of neighbor nodes of each node in the intersection between the neighbor node set of the central node and the neighbor node set of the open source component neighbor node; Determine a second similarity between the central node and the open source component neighbor node based on the ratio between the number of nodes in the intersection between the neighbor node set of the central node and the neighbor node set of the open source component neighbor node, and the number of nodes in the union between the neighbor node set of the central node and the neighbor node set of the open source component neighbor node; Based on the first similarity and the second similarity, a correlation degree between the central node and the open source component neighbor node is determined.
8. An open source component vulnerability detection device, characterized in that: include: A configuration file parsing module, used to parse the open source component dependency configuration file and the open source component vulnerability detection file to be detected, and obtain a corresponding plurality of triples, wherein the triples include a head entity, a tail entity, and an entity relationship between the head entity and the tail entity, the head entity includes an open source component or a vulnerability, and the tail entity includes an open source component, a vulnerability, or vulnerability information; A relationship subgraph construction module, configured to construct at least one relationship subgraph for each of the triples based on the entity relationships provided by the multiple triples, wherein the at least one relationship subgraph includes a relationship subgraph with an open source component as a central node and / or a relationship subgraph with a vulnerability as a central node; A subgraph fusion module, used for performing subgraph fusion on at least one relationship subgraph corresponding to each of the triples to obtain a fused relationship subgraph of each of the triples; An inclusion relationship judgment module is used to determine whether each of the triples is included in the open source component vulnerability knowledge graph based on the similarity between the fusion relationship subgraph of each of the triples and the fusion relationship subgraph of each reference triple in the open source component vulnerability knowledge graph; A graph search module is used to search the dependency chain and / or impact scope of the vulnerability of the open source component in the first triplet in the open source component vulnerability knowledge graph when it is determined that the first triplet among the multiple triples is included in the open source component vulnerability knowledge graph.
9. An electronic device, characterized in that: include: at least one processor, and a memory communicatively coupled to the at least one processor; The memory stores instructions executable by the processor, and the processor is used to obtain the instructions from the memory and execute the instructions, so that the processor can execute the open source component vulnerability detection method described in any one of claims 1-7.
10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to be provided to a computer to instruct the computer to execute the open source component vulnerability detection method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Machine reading understanding method, system and device based on external knowledge enhancement
CN111078836A
Software component supply chain security detection method and device based on knowledge graph
CN115033894A
Intelligent search method and device suitable for open source software supply chain
CN115658846A
Knowledge graph confidence evaluation method and device, electronic equipment and medium
CN115757837A
Open source component risk detection method and device, electronic equipment and storage medium
CN116167056A
Cited By
Real-time financial supervision data processing method and system
CN120912330A