Dynamic and static combination-based SCA component intelligent analysis method and system
By adopting a combination of dynamic and static SCA component intelligent analysis method in software component analysis, combined with static and dynamic analysis technology, the problems of identifying dynamic load dependencies and testing coverage limitations in the existing technology are solved, and more accurate component risk identification and software security improvement are achieved.
Patent Information
- Application Number
- CN202510601260.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-05-12
AI Technical Summary
The prior art has problems in software component analysis that static analysis is difficult to identify dynamic loading dependencies and dynamic analysis is subject to test coverage limitations, resulting in software security and maintainability challenges.
The intelligent analysis method of SCA component based on the combination of dynamic and static is adopted. By collecting static and dynamic data of the target application, the data is standardized, and the probability score of component components is calculated in combination with static and dynamic analysis technology, and the final weighted calculation is used to obtain the target component components and analyze their vulnerabilities.
Through the intelligent analysis method combining dynamic and static, software components and their associated risks can be more accurately identified, real-time alarms can be made, and software security can be effectively improved.
Smart Images

Figure CN120124074A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of software security, and particularly relates to an intelligent analysis method and system for SCA components based on the combination of static and dynamic analysis. Background Art
[0002] In the modern software development process, Software Composition Analysis (SCA) has become an important means to ensure the security of the software supply chain. With the widespread use of open source software in various applications, enterprises often integrate a large number of open source components, third-party libraries and frameworks during the development process. However, these external dependencies may have known vulnerabilities, license compliance risks or code quality problems, posing challenges to software security and maintainability. However, relying solely on static analysis or dynamic analysis has certain limitations. For example, static analysis may be difficult to accurately identify some dynamically loaded dependencies, while dynamic analysis is limited by test coverage and may not fully expose all components and their associated risks. Summary of the Invention
[0003] Based on the above deficiencies in the prior art, the present invention provides an intelligent analysis method and system for SCA components based on the combination of static and dynamic analysis.
[0004] To achieve the above invention objective, the present invention adopts the following technical solutions: An intelligent analysis method for SCA components based on the combination of static and dynamic analysis includes the following steps: S1. Collect the underlying data of the target application; wherein, the underlying data includes static data and dynamic data; S2. Respectively perform data standardization processing on the collected static data and dynamic data to obtain standardized static data and standardized dynamic data; S3. Perform static analysis on the standardized static data to obtain the first probability score of the component components related to the target application; Perform dynamic analysis on the standardized dynamic data to obtain the second probability score of the component components related to the target application; S4. Perform weighted calculation on the first probability score and the second probability score of the component components related to the target application to obtain the target component components corresponding to the target application; S5. Report the target component components and analyze the corresponding vulnerabilities.
[0005] As a preferred solution, in the step S1, the collection of static data includes the following process: Search for the target application and find the target application path; Analyze all dynamic link libraries linked to the target application using the ldd command to obtain the paths, library names, and version information of all dynamic link libraries; Use the readelf command to extract the file headers, program header tables, section header tables, string tables, symbol tables, relocation tables, and debugging information from the application file and library files of the target application; among them, the file header includes the file type, machine code, and program entry point.
[0006] As a preferred solution, in step S1, the acquisition of dynamic data includes the following process: Read the configuration file of the SCA component, identify the language type of the target application, and use eBPF technology to instrument and monitor system functions and functions of user-mode processes: If the language type is JAVA, monitor the file name, package name, class name, function name, and function byte hash value opened / called; If the language type is C / C++ / GO, monitor the function name, function instruction set, static area variables, and system IO operations; If the voice type is Python, monitor the mounted module name, function call name, and function byte hash value; When the function of the monitored user-mode process or system function is called, read the kernel structure information of the called function and capture the input and output information of the called function.
[0007] As a preferred solution, in step S2, the data normalization process includes unifying the timestamp, unit conversion, and feature construction.
[0008] As a preferred solution, the process of static analysis in step S3 includes: Construct a heterogeneous graph containing tables, files, columns, and entities based on the standardized static data, use multi-relational graph convolutional layers to capture cross-modal associations, introduce an abnormal attention gating mechanism, fuse local features through a third-order decay aggregation strategy, and input them into a graph neural network based on an abnormal propagation algorithm to output an abnormal feature matrix; Perform multi-dimensional abnormal scoring based on the abnormal feature matrix to obtain the first probability score of the components related to the target application.
[0009] As a preferred solution, the first probability score is: ; Among them, , , are weight coefficients respectively, , , are the mode deviation degree, content correlation degree, and correlation abnormality degree respectively; ; where max is the maximum similarity between the abnormal feature matrix and the normal sequence; ; where is the reconstruction error between the abnormal feature matrix and the normal sequence, is the distance between the abnormal feature matrix and the normal sequence; ; where is the number of nodes directly connected to node i, is the set of positive integers for j, is the cross score between node i and node j calculated by the inner product of vectors, where i and j are the rows and columns of the abnormal feature matrix.
[0010] As a preferred solution, the process of dynamic analysis in step S3 includes: Using the standardized dynamic data obtained by processing multi-modal dynamic data with a streaming processing engine, combining heterogeneous data with an attention mechanism; then using a sliding window to monitor data distribution drift, triggering fine-tuning of an online learning model of a long short-term memory neural network (LSTM) based on the attention mechanism, and synchronously applying a time decay strategy to dynamically adjust the anomaly threshold, which is the second probability score of the component components related to the target application.
[0011] As a preferred solution, in step S4, the first probability score and the second probability score are weighted at a ratio of 1:1, and according to the comprehensive score after weighted calculation, the component components corresponding to the comprehensive score exceeding the target threshold are used as the target component components.
[0012] As a preferred solution, step S5 further includes: determining whether the vulnerability is a newly discovered vulnerability; if so, issuing an alarm.
[0013] The present invention also provides an SCA component intelligent analysis system based on the combination of static and dynamic analysis, applying the SCA component intelligent analysis method described in any one of the above, and the SCA component intelligent analysis system includes: An acquisition module for acquiring the underlying data of the target application; A standardization module for respectively performing data standardization processing on the acquired static data and dynamic data to obtain standardized static data and standardized dynamic data; A static and dynamic combined analysis module for respectively performing static analysis and dynamic analysis on the standardized static data and standardized dynamic data to obtain the first probability score and the second probability score of the component components related to the target application; A component component determination module for performing weighted calculation on the first probability score and the second probability score of the component components related to the target application to obtain the target component components corresponding to the target application; A reporting and analysis module for reporting the target component components and analyzing the corresponding vulnerabilities.
[0014] Compared with the prior art, the beneficial effects of the present invention are as follows: Based on the intelligent judgment of dynamic and static dual dimensions, the present invention analyzes the component composition and vulnerability information applied by the target software through the combination of dynamic and static intelligent analysis, gives real-time warnings, and effectively improves software security. Description of the Drawings
[0015] Figure 1 It is a hierarchical flowchart of the SCA component intelligent analysis method based on the combination of dynamic and static for Embodiment 1 of the present invention; Figure 2 It is a flowchart of the SCA component intelligent analysis method based on the combination of dynamic and static for Embodiment 1 of the present invention; Figure 3 It is a flowchart of data collection for Embodiment 1 of the present invention; Figure 4 It is a flowchart of static analysis for Embodiment 1 of the present invention; Figure 5 It is a flowchart of dynamic analysis for Embodiment 1 of the present invention; Figure 6 It is a module architecture diagram of the SCA component intelligent analysis system based on the combination of dynamic and static for Embodiment 1 of the present invention. Detailed Embodiments
[0016] To more clearly illustrate the embodiments of the present invention, the specific embodiments of the present invention will be described below with reference to the accompanying drawings. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings, and other embodiments can be obtained.
[0017] The SCA component intelligent analysis method and system based on the combination of dynamic and static of the present invention capture information of the running state of the application program through eBPF technology to collect probes, combine the extraction of static information of binary files, implement an intelligent analysis algorithm combining dynamic and static, match the analyzed components with vulnerabilities, conduct real-time dynamic risk assessment, timely discover the components used by it and their vulnerabilities, and give corresponding notifications and warnings.
[0018] Embodiment 1: As Figure 1 shown, the SCA component intelligent analysis method based on the combination of dynamic and static of this embodiment includes three levels: a data collection layer, an intelligent analysis layer, and an alarm handling layer. The data collection layer realizes the acquisition and preprocessing of dynamic and static binary analysis data; the intelligent analysis layer is based on the AI intelligent judgment of dynamic and static dual dimensions to analyze the component composition and vulnerability information of the target software; the alarm handling layer realizes the reporting of component composition and the warning of newly added vulnerabilities.
[0019] As Figure 2 shown, the intelligent analysis method of SCA components based on the combination of static and dynamic states in this embodiment includes the following steps: (1) Data collection, collecting the underlying data of the target application; among them, the underlying data includes static data and dynamic data; The data collection in this embodiment specifically includes two major categories: the collection of static data of binary files and the collection of dynamic data generated by Hook during the operation of binary programs; retrieving the target application and collecting static data; when the target application program is running, using eBPF collection probes for Hook to dynamically collect information such as the file names opened during program operation, function names used, and system files called.
[0020] Specifically, the above-mentioned static data includes file headers (file type, machine code, program entry point), program header tables, section header tables, string tables, symbol tables, relocation tables, debug information, etc.
[0021] The dynamic data in this embodiment collects different major indicators according to the different language types of the target application, specifically including: If the language type is JAVA, then monitor the file names opened / called, package names, class names, function names, function byte hash values, etc.; If the language type is C / C++ / GO, then monitor function names, function instruction sets, static area variables, system IO operations, etc.; If the language type is Python, then monitor the mounted module names, function call names, function byte hash values, etc.
[0022] Specifically, as Figure 3 shown, the collection of the above-mentioned static data includes the following process: Initialization, search for the target application and find the target application path; Use the ldd command to analyze all dynamic link libraries linked to the target application, and obtain the basic information of all dynamic link libraries, including paths, library names, and version information; Use the readelf command to extract the basic information of the application file and library file of the target application, including file headers, program header tables, section header tables, string tables, symbol tables, relocation tables, debug information; among them, the file header includes file type, machine code, and program entry point.
[0023] As Figure 3 shown, the collection of the above-mentioned dynamic data includes the following process: eBPF initialization, read the configuration file of the SCA component, identify the target application language type, and use eBPF technology to instrument and monitor system functions and functions of user-mode processes: If the language type is JAVA, monitor the file name, package name, class name, function name, and function byte hash value when opening / calling. If the language type is C / C++ / GO, monitor the function name, function instruction set, static area variables, and system IO operations. If the language type is Python, monitor the mounted module name, function call name, and function byte hash value. When a function of the monitored user-mode process or a system function is called, read the kernel structure information of the called function and capture the call information of the called function, including input and output information.
[0024] (2) Data standardization processing; Perform standardization processing on the above-mentioned underlying data collected, including unifying timestamps, unit conversion, feature construction, etc. Among them, for unit conversion, such as converting both minutes and seconds to seconds; feature construction mainly performs aggregated features, such as features reflecting discrete states, etc.; after the above-mentioned standardization processing of the underlying data, standardized static data and standardized dynamic data are obtained respectively.
[0025] (3) Perform static analysis on the standardized static data to obtain the first probability score of the components related to the target application; Specifically, construct a knowledge graph of application files and library file information, and use a batch scheduling method to perform static analysis based on the anomaly propagation algorithm of graph neural networks and multi-dimensional anomaly scoring. As Figure 4 shown, the specific process of static analysis includes: First, construct a heterogeneous graph containing tables, files, columns, and entities based on the standardized static data, that is, heterogeneous node feature extraction; then, use a multi-relational graph convolutional layer to capture cross-modal associations, and introduce an anomaly attention gating mechanism, fuse local features through a third-order decay aggregation strategy, input it into the graph neural network based on the anomaly propagation algorithm for cross-modal propagation, and output an anomaly feature matrix; among them, the third-order decay aggregation strategy is a method for adjusting the learning rate, regularization, or other forms of optimization control using third-order information; finally, perform multi-dimensional anomaly scoring based on the anomaly feature matrix, and perform anomaly score aggregation to obtain the first probability score of the components related to the target application; The above first probability score Score 1 is: ; Among them, 、 、 are weight coefficients respectively, 、 、 are the mode deviation degree, content correlation degree, and association anomaly degree respectively; ; where max is the maximum similarity between the abnormal feature matrix and the normal sequence; ; where is the reconstruction error between the abnormal feature matrix and the normal sequence, is the distance between the abnormal feature matrix and the normal sequence; ; where is the number of nodes directly connected to node i, is the set of positive integers for j, is the cross score between node i and node j calculated by vector inner product, where i and j are the rows and columns of the abnormal feature matrix.
[0026] (4) Perform dynamic analysis on the standardized dynamic data to obtain the second probability score of the components related to the target application; As Figure 5 shown, in this embodiment, the standardized dynamic data obtained by processing multi-modal dynamic data using a streaming processing engine is combined with heterogeneous data through an attention mechanism; then, a sliding window is used to monitor data distribution drift, triggering fine-tuning of an online learning model of a long short-term memory neural network LSTM based on the attention mechanism, and at the same time, a time decay strategy is used to dynamically adjust the anomaly threshold, which is the second probability score Score of the components related to the target application 2 ; in addition, through a closed-loop feedback mechanism, the manual verification results are converted into incremental training data to drive the self-optimization of the above online learning model.
[0027] Among them, the above online learning model uses a long short-term memory neural network LSTM based on the attention mechanism, which integrates multi-scale time perception networks, captures both second-level mutations and minute-level trend changes at the same time, avoids the limitations of a single time window, and combines the attention mechanism to strictly ensure that the prediction at time T only depends on the data at time T and before in a real-time scenario. For details, reference can be made to the existing technology and will not be elaborated here.
[0028] (5) Perform weighted calculation on the first probability score and the second probability score of the components related to the target application to obtain the target component corresponding to the target application; This embodiment adopts a disposal strategy combining static and dynamic methods, assigns weights to the first probability scores and the second probability scores of the above static analysis and dynamic analysis in a ratio of 1:1, and calculates the comprehensive score Score = Score 1 + Score 2 , and takes the component corresponding to the comprehensive score exceeding the target threshold as the target component.
[0029] (6) Report the target component and analyze the corresponding vulnerabilities; Specifically, corresponding reports are made for the analyzed target component components, and corresponding vulnerabilities are analyzed; among them, the components and the corresponding vulnerabilities are known. After the target component components are analyzed, the corresponding vulnerabilities can be known; further, it is determined whether the vulnerability is a newly discovered vulnerability; if so, an alarm is issued. Specifically, the initial static analysis alarm is the first component version information speculation and its corresponding vulnerability information generated after the component component analysis of the static part; the real-time dynamic and static combined analysis alarm will continuously analyze according to the captured information reported dynamically, improve the speculation accuracy rate of the component and its version information, and once it is higher than 80%, the component information is newly reported, and the corresponding vulnerability information is alarmed.
[0030] Based on the above SCA component intelligent analysis method combining dynamic and static analysis, as Figure 6 shown, the SCA component intelligent analysis system combining dynamic and static analysis in this embodiment includes the following functional modules: a collection module, a standardization module, a dynamic and static combined analysis module, a component component determination module, a reporting and analysis module, and an alarm module; The collection module of this embodiment is used to collect the underlying data of the target application; The standardization module of this embodiment is used to perform data standardization processing on the collected static data and dynamic data respectively to obtain standardized static data and standardized dynamic data; The dynamic and static combined analysis module of this embodiment is used to perform static analysis and dynamic analysis on the standardized static data and standardized dynamic data respectively to obtain the first probability score and the second probability score of the component components related to the target application; The component component determination module of this embodiment is used to perform weighted calculation on the first probability score and the second probability score of the component components related to the target application to obtain the target component components corresponding to the target application; The reporting and analysis module of this embodiment is used to report the target component components and analyze their corresponding vulnerabilities; The alarm module of this embodiment issues an alarm when it determines that the vulnerability is a newly discovered vulnerability.
[0031] The detailed processing process of the above functional modules can refer to the detailed description of the above SCA component intelligent analysis method, which will not be elaborated here.
[0032] The above is only a detailed description of the preferred embodiments and principles of the present invention. For those of ordinary skill in the art, according to the idea provided by the present invention, there will be changes in the specific implementation manners, and these changes should also be regarded as the protection scope of the present invention.
Claims
1. The SCA component intelligent analysis method based on the combination of dynamic and static is characterized by: The following steps are involved: S1. Collect the underlying data of the target application; wherein the underlying data includes static data and dynamic data; S2, respectively performing data standardization processing on the collected static data and dynamic data to obtain standardized static data and standardized dynamic data; S3, performing static analysis on the standardized static data to obtain a first probability score of the component components related to the target application; Dynamically analyzing the standardized dynamic data to obtain a second probability score of the component components related to the target application; S4, performing weighted calculation on the first probability score and the second probability score of the component components related to the target application to obtain the target component components corresponding to the target application; S5. Report the target component components and analyze their corresponding vulnerabilities.
2. The SCA component intelligent analysis method according to claim 1 is characterized in that: In step S1, the collection of static data includes the following process: Search for the target application and find the target application path; Use the ldd command to analyze all dynamic link libraries linked to the target application and obtain all dynamic link library paths, library names, and version information; Use the readelf command to extract the file header, program header table, section header table, string table, symbol table, relocation table, and debugging information from the application file and library file of the target application; the file header includes the file type, machine code, and program entry point.
3. The SCA component intelligent analysis method according to claim 2 is characterized in that: In step S1, the collection of dynamic data includes the following process: Read the configuration file of the SCA component, identify the target application language type, and use eBPF technology to instrument and monitor system functions and user-mode process functions: If the language type is JAVA, the file name, package name, class name, function name, and function byte hash value of the opened / called file are monitored; If the language type is C / C++ / GO, the function name, function instruction set, static area variables, and system IO operations are monitored; If the voice type is Python, monitor the mounted module name, function call name, and function byte hash value; When the function of the monitored user-mode process or system function is called, the kernel structure information of the called function is read to capture the input and output information of the called function.
4. The SCA component intelligent analysis method according to claim 3 is characterized in that: In step S2, data standardization processing includes unified timestamp, unit conversion and feature construction.
5. The SCA component intelligent analysis method according to claim 1, characterized in that: The static analysis process in step S3 includes: Based on standardized static data, a heterogeneous graph containing tables, files, columns, and entities is constructed. A multi-relation graph convolution layer is used to capture cross-modal associations, and an abnormal attention gating mechanism is introduced. Local features are fused through a third-order attenuation aggregation strategy and input into a graph neural network based on anomaly propagation algorithm to output an abnormal feature matrix. Multi-dimensional anomaly scoring is performed based on the anomaly feature matrix to obtain the first probability scores of the target application-related component components.
6. The SCA component intelligent analysis method according to claim 5, characterized in that: The first probability score is: ; in, , , are weight coefficients, , , They are pattern deviation, content relevance, and relevance anomaly; ; Where max is the maximum similarity between the abnormal feature matrix and the normal sequence; ;in, is the reconstruction error between the abnormal feature matrix and the normal sequence, is the distance between the abnormal feature matrix and the normal sequence; ;in, is the number of nodes directly connected to node i, is a set where j is a positive integer, is the cross score between node i and node j calculated by vector inner product, i and j are the rows and columns of the abnormal feature matrix.
7. The SCA component intelligent analysis method according to claim 6 is characterized in that: The process of dynamic analysis in step S3 includes: The standardized dynamic data obtained by processing multimodal dynamic data with a streaming processing engine is then fused with heterogeneous data in combination with the attention mechanism. Then, a sliding window is used to monitor the data distribution drift, triggering fine-tuning of the long short-term memory neural network LSTM online learning model based on the attention mechanism, and simultaneously using the time decay strategy to dynamically adjust the anomaly threshold, which is the second probability score of the component components related to the target application.
8. The SCA component intelligent analysis method according to claim 7, characterized in that: In step S4, the first probability score and the second probability score are weighted at 1:1, and based on the comprehensive score after weighted calculation, the component component corresponding to the comprehensive score exceeding the target threshold is used as the target component component.
9. The SCA component intelligent analysis method according to any one of claims 1 to 8, characterized in that: The step S5 also includes: determining whether the vulnerability is a newly discovered vulnerability; if so, issuing an alarm.
10. An SCA component intelligent analysis system based on the combination of dynamic and static, applying the SCA component intelligent analysis method according to any one of claims 1 to 9, characterized in that: The SCA component intelligent analysis system includes: The acquisition module is used to collect the underlying data of the target application; A standardization module is used to perform data standardization processing on the collected static data and dynamic data respectively to obtain standardized static data and standardized dynamic data; A static-dynamic combined analysis module is used to perform static analysis and dynamic analysis on the standardized static data and the standardized dynamic data respectively, and obtain a first probability score and a second probability score of the target application related component components; A component composition determination module, used for performing weighted calculation on the first probability score and the second probability score of the component composition related to the target application to obtain the target component composition corresponding to the target application; The reporting and analysis module is used to report the components of the target component and analyze its corresponding vulnerabilities.
Citation Information
Patent Citations
Software vulnerability detection method based on static analysis and dynamic analysis
CN116049831A
Abnormal state detection method and system for automobile chassis
CN117150388A
Bill of material SBOM + analysis method and device for open source software supply chain
CN117195233A
Software supply chain auditing method and system and computer readable storage medium
CN117807603A
Open source component security vulnerability processing method and system
CN119167370A