Intelligent Analysis Method and System for SCA Components Based on the Combination of Static and Dynamic
Through the intelligent analysis method of SCA component combining dynamic and static, graph neural network and long-term memory neural network analysis software components are used to solve the limitations of identifying open source components in the existing technology, and the improvement of software security and maintainability is achieved.
Patent Information
- Application Number
- CN202510601260.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-05-12
AI Technical Summary
In the prior art, relying solely on static analysis or dynamic analysis has limitations, making it difficult to fully identify open source components and their associated risks, resulting in software security and maintainability challenges.
The intelligent analysis method of SCA component based on the combination of dynamic and static data is adopted. After collecting static and dynamic data, the data is standardized, and the graph neural network and long-term memory neural network are used for analysis, combined with weighted calculation, and real-time alarm component components and their vulnerabilities are noted.
A comprehensive analysis of the components of the target software components is achieved, vulnerabilities are discovered in real time, and software security and maintainability are improved.
Smart Images

Figure CN120124074B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of software security, and particularly relates to a method and system for intelligent analysis of SCA components based on the combination of static and dynamic analysis. Background Art
[0002] In the modern software development process, Software Composition Analysis (SCA) has become an important means to ensure the security of the software supply chain. With the widespread use of open source software in various applications, enterprises often integrate a large number of open source components, third-party libraries, and frameworks during the development process. However, these external dependencies may have known vulnerabilities, license compliance risks, or code quality issues, posing challenges to software security and maintainability. However, relying solely on static analysis or dynamic analysis has certain limitations. For example, static analysis may be difficult to accurately identify some dynamically loaded dependencies, while dynamic analysis is limited by test coverage and may not fully expose all components and their associated risks. Summary of the Invention
[0003] Based on the above deficiencies existing in the prior art, the present invention provides a method and system for intelligent analysis of SCA components based on the combination of static and dynamic analysis.
[0004] To achieve the above invention object, the present invention adopts the following technical solutions:
[0005] The method for intelligent analysis of SCA components based on the combination of static and dynamic analysis includes the following steps:
[0006] S1. Collect the underlying data of the target application; wherein, the underlying data includes static data and dynamic data;
[0007] S2. Respectively perform data standardization processing on the collected static data and dynamic data to obtain standardized static data and standardized dynamic data;
[0008] S3. Perform static analysis on the standardized static data to obtain the first probability score of the component components related to the target application;
[0009] Perform dynamic analysis on the standardized dynamic data to obtain the second probability score of the component components related to the target application;
[0010] S4. Perform weighted calculation on the first probability score and the second probability score of the component components related to the target application to obtain the target component components corresponding to the target application;
[0011] S5. Report the target component components and analyze the corresponding vulnerabilities.
[0012] As a preferred solution, in step S1, the acquisition of static data includes the following processes:
[0013] Search for the target application and find the target application path;
[0014] Use the ldd command to analyze all dynamic link libraries linked to the target application, and obtain all dynamic link library paths, library names, and version information;
[0015] Use the readelf command to extract the file headers, program header tables, section header tables, string tables, symbol tables, relocation tables, and debug information from the application files and library files of the target application; among them, the file header includes the file type, machine code, and program entry point.
[0016] As a preferred solution, in step S1, the acquisition of dynamic data includes the following processes:
[0017] Read the configuration file of the SCA component, identify the target application language type, and use the eBPF technology to perform instrumentation monitoring on system functions and functions of user-mode processes:
[0018] If the language type is JAVA, then monitor the file name, package name, class name, function name, and function byte hash value that are opened / called;
[0019] If the language type is C / C++ / GO, then monitor the function name, function instruction set, static area variables, and system IO operations;
[0020] If the voice type is Python, then monitor the mounted module name, function call name, and function byte hash value;
[0021] When the function of the monitored user-mode process or system function is called, read the kernel structure information of the called function and capture the input and output information of the called function.
[0022] As a preferred solution, in step S2, the data standardization process includes unifying timestamps, unit conversion, and feature construction.
[0023] As a preferred solution, the process of static analysis in step S3 includes:
[0024] Based on the standardized static data, construct a heterogeneous graph containing tables, files, columns, and entities, use a multi-relational graph convolutional layer to capture cross-modal associations, introduce an abnormal attention gating mechanism, fuse local features through a third-order decay aggregation strategy, and input it into a graph neural network based on an abnormal propagation algorithm to output an abnormal feature matrix;
[0025] Perform multi-dimensional anomaly scoring based on the abnormal feature matrix to obtain the first probability score of the components related to the target application.
[0026] As a preferred solution, the first probability score is:
[0027] ;
[0028] where , , are weight coefficients respectively, , , are the pattern deviation degree, content relevance degree, and relevance anomaly degree respectively;
[0029] ; where max is the maximum similarity between the abnormal feature matrix and the normal sequence;
[0030] ; where is the reconstruction error between the abnormal feature matrix and the normal sequence, is the distance between the abnormal feature matrix and the normal sequence;
[0031] ; where is the number of nodes directly connected to node i, is the set of positive integers for j, is the cross score between node i and node j calculated by vector inner product, and i, j are the rows and columns of the abnormal feature matrix.
[0032] As a preferred solution, the process of dynamic analysis in step S3 includes:
[0033] Using the standardized dynamic data obtained by processing multi-modal dynamic data with a streaming processing engine, integrating heterogeneous data with an attention mechanism; then using a sliding window to monitor data distribution drift, triggering fine-tuning of the long short-term memory neural network LSTM online learning model based on the attention mechanism, and synchronously applying a time decay strategy to dynamically adjust the anomaly threshold, which is the second probability score of the relevant components of the target application.
[0034] As a preferred solution, in step S4, the first probability score and the second probability score are weighted at a ratio of 1:1, and according to the comprehensive score after weighted calculation, the component components whose comprehensive score exceeds the target threshold are used as the target component components.
[0035] As a preferred solution, step S5 further includes: determining whether the vulnerability is a newly discovered vulnerability; if so, issuing an alarm.
[0036] The present invention also provides an SCA component intelligent analysis system based on the combination of static and dynamic analysis, applying the SCA component intelligent analysis method described in any one of the above, and the SCA component intelligent analysis system includes:
[0037] The acquisition module is used to acquire the underlying data of the target application;
[0038] The normalization module is used to perform data normalization processing on the acquired static data and dynamic data respectively to obtain normalized static data and normalized dynamic data;
[0039] The static-dynamic combined analysis module is used to perform static analysis and dynamic analysis on the normalized static data and normalized dynamic data respectively to obtain the first probability score and the second probability score of the component components related to the target application;
[0040] The component component determination module is used to perform weighted calculation on the first probability score and the second probability score of the component components related to the target application to obtain the target component components corresponding to the target application;
[0041] The reporting and analysis module is used to report the target component components and analyze the corresponding vulnerabilities.
[0042] Compared with the prior art, the beneficial effects of the present invention are:
[0043] Based on the intelligent judgment of the dynamic and static dual dimensions, the present invention analyzes the component components and vulnerability information applied by the target software in a way of combining static and dynamic intelligent analysis, gives real-time warnings, and effectively improves software security. Description of the Drawings
[0044] Figure 1 It is the hierarchical flowchart of the static-dynamic combined SCA component intelligent analysis method according to Embodiment 1 of the present invention;
[0045] Figure 2 It is the flowchart of the static-dynamic combined SCA component intelligent analysis method according to Embodiment 1 of the present invention;
[0046] Figure 3 It is the flowchart of data acquisition according to Embodiment 1 of the present invention;
[0047] Figure 4 It is the flowchart of static analysis according to Embodiment 1 of the present invention;
[0048] Figure 5 It is the flowchart of dynamic analysis according to Embodiment 1 of the present invention;
[0049] Figure 6 It is the module architecture diagram of the static-dynamic combined SCA component intelligent analysis system according to Embodiment 1 of the present invention. Detailed Embodiments
[0050] To more clearly illustrate the embodiments of the present invention, the specific implementation manners of the present invention will be described below with reference to the accompanying drawings. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings, and other implementation manners can also be obtained.
[0051] The present invention is based on an intelligent analysis method and system for SCA components that combines static and dynamic analysis. By using eBPF technology to collect probes for capturing information on the running state of application programs, and combining with the extraction of static information from binary files, an intelligent analysis algorithm that combines static and dynamic analysis is realized. The components analyzed are then subjected to vulnerability matching and real-time dynamic risk assessment to timely discover the components used and their vulnerabilities, and corresponding notifications and alarms are issued.
[0052] Embodiment 1:
[0053] As Figure 1 shown, the intelligent analysis method for SCA components based on the combination of static and dynamic analysis in this embodiment includes three levels: a data collection layer, an intelligent analysis layer, and an alarm handling layer. The data collection layer realizes the acquisition and preprocessing of dynamic and static binary analysis data; the intelligent analysis layer is based on AI intelligent judgment in both dynamic and static dimensions to analyze the component composition and vulnerability information of the target software; the alarm handling layer realizes the reporting of component composition and the alarm of newly added vulnerabilities.
[0054] As Figure 2 shown, the intelligent analysis method for SCA components based on the combination of static and dynamic analysis in this embodiment includes the following steps:
[0055] (1) Data collection, collecting the underlying data of the target application; among them, the underlying data includes static data and dynamic data;
[0056] The data collection in this embodiment specifically includes two major categories: the collection of static data of binary files and the collection of dynamic data generated by Hook during the running of binary programs; static data is collected by retrieving the target application; when the target application program is running, eBPF collection probes are used for Hook to dynamically collect information such as the file names opened during program running, the function names used, and the system files called.
[0057] Specifically, the above-mentioned static data includes file headers (file type, machine code, program entry point), program header tables, section header tables, string tables, symbol tables, relocation tables, debug information, etc.
[0058] The dynamic data in this embodiment collects different major indicators according to the different language types of the target application, specifically including:
[0059] If the language type is JAVA, monitor the file name, package name, class name, function name, function byte hash value, etc. opened / called;
[0060] If the language type is C / C++ / GO, monitor the function name, function instruction set, static area variables, system IO operations, etc.;
[0061] If the voice type is Python, monitor the mounted module name, function call name, function byte hash value, etc.
[0062] Specifically, as Figure 3 shown, the acquisition of the above static data includes the following processes:
[0063] Initialization, search for the target application, and find the target application path;
[0064] Use the ldd command to analyze all dynamic link libraries linked to the target application, and obtain the basic information of all dynamic link libraries, including the path, library name, and version information;
[0065] Use the readelf command to extract the basic information of the application file and library file of the target application, including the file header, program header table, section header table, string table, symbol table, relocation table, and debugging information; among them, the file header includes the file type, machine code, and program entry point.
[0066] As Figure 3 shown, the acquisition of the above dynamic data includes the following processes:
[0067] eBPF initialization, read the configuration file of the SCA component, identify the target application language type, and use eBPF technology to instrument and monitor system functions and functions of user-space processes:
[0068] If the language type is JAVA, monitor the file name, package name, class name, function name, function byte hash value opened / called;
[0069] If the language type is C / C++ / GO, monitor the function name, function instruction set, static area variables, system IO operations;
[0070] If the voice type is Python, monitor the mounted module name, function call name, function byte hash value;
[0071] When the function of the monitored user-space process or system function is called, read the kernel structure information of the called function, and capture the call information of the called function, including input and output information.
[0072] (2)Data standardization processing;
[0073] Standardize the above-mentioned underlying data collected, including unifying timestamps, unit conversion, feature construction, etc. Among them, for unit conversion, units such as minutes and seconds are both converted to seconds; feature construction mainly creates aggregated features, such as features reflecting discrete states, etc.; after the above-mentioned standardization processing of the underlying data, standardized static data and standardized dynamic data are obtained respectively.
[0074] (3)Conduct static analysis on the standardized static data to obtain the first probability score of the components related to the target application;
[0075] Specifically, construct a knowledge graph of application files and library file information, and adopt a batch scheduling method to perform static analysis based on the anomaly propagation algorithm and multi-dimensional anomaly scoring of the graph neural network. As Figure 4 shown, the specific process of static analysis includes: First, construct a heterogeneous graph containing tables, files, columns, and entities based on the standardized static data, that is, extract heterogeneous node features; then, use a multi-relational graph convolutional layer to capture cross-modal associations, and introduce an anomaly attention gating mechanism, fuse local features through a third-order decay aggregation strategy, and input them into the graph neural network based on the anomaly propagation algorithm for cross-modal propagation, and output an anomaly feature matrix; among them, the third-order decay aggregation strategy is a method for adjusting the learning rate, regularization, or other forms of optimization control using third-order information; finally, perform multi-dimensional anomaly scoring based on the anomaly feature matrix, and perform anomaly score aggregation to obtain the first probability score of the components related to the target application;
[0076] The above first probability score Score1 is:
[0077] ;
[0078] Among them, 、 、 are weight coefficients respectively, 、 、 are the pattern deviation degree, content correlation degree, and correlation anomaly degree respectively;
[0079] ; among them, max is the maximum similarity between the anomaly feature matrix and the normal sequence;
[0080] ; among them, is the reconstruction error between the anomaly feature matrix and the normal sequence, is the distance between the anomaly feature matrix and the normal sequence;
[0081] ; among them, is the number of nodes directly connected to node i, is the set of positive integers for j, is the cross score between node i and node j calculated by the vector inner product, where i and j are the rows and columns of the abnormal feature matrix.
[0082] (4) Perform dynamic analysis on the standardized dynamic data to obtain the second probability score of the components related to the target application;
[0083] As Figure 5 shown, in this embodiment, the standardized dynamic data obtained by processing the multi-modal dynamic data using the streaming processing engine is combined with the attention mechanism to fuse heterogeneous data; then a sliding window is used to monitor the data distribution drift, triggering fine-tuning of the online learning model of the long short-term memory neural network LSTM based on the attention mechanism, and at the same time using the time decay strategy to dynamically adjust the anomaly threshold, which is the second probability score Score2 of the components related to the target application; in addition, through a closed-loop feedback mechanism, the manual verification results are converted into incremental training data to drive the self-optimization of the above online learning model.
[0084] Among them, the above online learning model uses a long short-term memory neural network LSTM based on the attention mechanism, which integrates multi-scale time perception networks, captures both second-level mutations and minute-level trend changes at the same time, avoids the limitations of a single time window, and combines the attention mechanism to strictly ensure that the prediction at time T only depends on the data at time T and before in a real-time scenario. For details, reference can be made to the prior art and will not be elaborated here.
[0085] (5) Perform weighted calculation on the first probability score and the second probability score of the components related to the target application to obtain the target component corresponding to the target application;
[0086] In this embodiment, a disposal strategy combining static and dynamic methods is adopted. The first probability scores and the second probability scores of the above static analysis and dynamic analysis are weighted at a ratio of 1:1, and the comprehensive score Score = Score1 + Score2 is calculated based on the weighted probability scores. The component corresponding to the comprehensive score exceeding the target threshold is used as the target component.
[0087] (6) Report the target component and analyze the corresponding vulnerabilities;
[0088] Specifically, corresponding reports are made for the analyzed target component components, and corresponding vulnerabilities are analyzed. Among them, the components and their corresponding vulnerabilities are known. After analyzing the target component components, their corresponding vulnerabilities can be known. Further, it is determined whether the vulnerability is a newly discovered vulnerability. If so, an alarm is issued. Specifically, the initial static analysis alarm is the first speculation of the component version information and its corresponding vulnerability information after the component component analysis of the static part. The real-time dynamic and static combined analysis alarm will continuously analyze according to the captured information reported dynamically, improve the speculation accuracy rate of the component and its version information. Once it is higher than 80%, the component information is newly reported, and the corresponding vulnerability information is alarmed.
[0089] Based on the above SCA component intelligent analysis method combining dynamic and static analysis, as Figure 6 shown, the SCA component intelligent analysis system combining dynamic and static analysis in this embodiment includes the following functional modules: a collection module, a standardization module, a dynamic and static combined analysis module, a component component determination module, a reporting and analysis module, and an alarm module;
[0090] The collection module of this embodiment is used to collect the underlying data of the target application;
[0091] The standardization module of this embodiment is used to perform data standardization processing on the collected static data and dynamic data respectively to obtain standardized static data and standardized dynamic data;
[0092] The dynamic and static combined analysis module of this embodiment is used to perform static analysis and dynamic analysis on the standardized static data and standardized dynamic data respectively to obtain the first probability score and the second probability score of the component components related to the target application;
[0093] The component component determination module of this embodiment is used to perform weighted calculation on the first probability score and the second probability score of the component components related to the target application to obtain the target component components corresponding to the target application;
[0094] The reporting and analysis module of this embodiment is used to report the target component components and analyze their corresponding vulnerabilities;
[0095] The alarm module of this embodiment issues an alarm when it determines that the vulnerability is a newly discovered vulnerability.
[0096] For the detailed processing procedures of the above functional modules, reference can be made to the detailed description of the above SCA component intelligent analysis method, which will not be elaborated here.
[0097] The above is only a detailed description of the preferred embodiments and principles of the present invention. For those of ordinary skill in the art, according to the idea provided by the present invention, there will be changes in the specific implementation manners, and these changes should also be regarded as the protection scope of the present invention.
Claims
1. An intelligent analysis method for SCA components based on the combination of static and dynamic, characterized in that, It includes the following steps: S1. Collect the underlying data of the target application; among them, the underlying data includes static data and dynamic data; S2. Respectively perform data standardization processing on the collected static data and dynamic data to obtain standardized static data and standardized dynamic data; S3. Perform static analysis on the standardized static data to obtain the first probability score of the component components related to the target application; Perform dynamic analysis on the standardized dynamic data to obtain the second probability score of the component components related to the target application; Among them, the process of static analysis in step S3 includes: Construct a heterogeneous graph containing tables, files, columns, and entities based on the standardized static data, use a multi-relational graph convolutional layer to capture cross-modal associations, introduce an abnormal attention gating mechanism, fuse local features through a third-order decay aggregation strategy, input it into a graph neural network based on an abnormal propagation algorithm, and output an abnormal feature matrix; Perform multi-dimensional abnormal scoring based on the abnormal feature matrix to obtain the first probability score of the component components related to the target application; the first probability score is: ; Among them, , , are weight coefficients respectively, , , are the pattern deviation degree, content correlation degree, and correlation anomaly degree respectively; ; where max is the maximum similarity between the abnormal feature matrix and the normal sequence; ; wherein, is the reconstruction error between the abnormal feature matrix and the normal sequence, is the distance between the abnormal feature matrix and the normal sequence; ; where, is the number of nodes directly connected to node i, is a set where j is a positive integer, is the cross score between node i and node j calculated through the inner product of vectors, where i and j are the rows and columns of the abnormal feature matrix; The process of dynamic analysis in step S3 includes: Use the standardized dynamic data obtained by the streaming processing engine to process multi-modal dynamic data, fuse heterogeneous data by combining the attention mechanism; then use a sliding window to monitor data distribution drift, trigger fine-tuning of the long short-term memory neural network LSTM online learning model based on the attention mechanism, and synchronously use a time decay strategy to dynamically adjust the abnormal threshold, and this abnormal threshold is the second probability score of the component components related to the target application; S4. Perform weighted calculation on the first probability score and the second probability score of the component components related to the target application to obtain the target component components corresponding to the target application; S5. Report the target component components and analyze the corresponding vulnerabilities.
2. The intelligent analysis method for SCA components according to claim 1, wherein In step S1, the collection of static data includes the following process: Search for the target application and find the target application path; Use the ldd command to analyze all dynamic link libraries linked to the target application, and obtain all dynamic link library paths, library names, and version information; Use the readelf command to extract the file headers, program header tables, section header tables, string tables, symbol tables, relocation tables, and debug information in the application files and library files of the target application; among them, the file header includes the file type, machine code, and program entry point.
3. The SCA component intelligent analysis method according to claim 2, wherein In step S1, the collection of dynamic data includes the following process: Read the configuration file of the SCA component, identify the language type of the target application, and use eBPF technology to perform instrumentation monitoring on system functions and user-mode process functions: If the language type is JAVA, monitor the file name, package name, class name, function name, and function byte hash value opened / called; If the language type is C / C++ / GO, monitor the function name, function instruction set, static area variables, and system IO operations; If the voice type is Python, monitor the mounted module name, function call name, and function byte hash value; When the function of the monitored user-mode process or the system function is called, read the kernel structure information of the called function and capture the input and output information of the called function.
4. The intelligent analysis method for SCA components according to claim 3, wherein In step S2, the data standardization processing includes unifying timestamps, unit conversion, and feature construction.
5. The intelligent analysis method for SCA components according to claim 1, wherein In the step S4, the first probability score and the second probability score are weighted at a ratio of 1:1, and according to the comprehensive score after weighted calculation, the component composition corresponding to the comprehensive score exceeding the target threshold is used as the target component composition.
6. The intelligent analysis method for the SCA component according to any one of claims 1-5, characterized in that The step S5 further includes: determining whether the vulnerability is a newly discovered vulnerability; if so, an alarm is issued.
7. An intelligent analysis system for SCA components based on the combination of static and dynamic analysis, applying the intelligent analysis method for SCA components according to any one of claims 1-6, characterized in that, The SCA component intelligent analysis system includes: a collection module for collecting the underlying data of the target application; a standardization module for performing data standardization processing on the collected static data and dynamic data respectively to obtain standardized static data and standardized dynamic data; a static-dynamic combined analysis module for performing static analysis and dynamic analysis on the standardized static data and the standardized dynamic data respectively to obtain the first probability score and the second probability score of the component composition related to the target application; a component composition determination module for performing weighted calculation on the first probability score and the second probability score of the component composition related to the target application to obtain the target component composition corresponding to the target application; a reporting and analysis module for reporting the target component composition and analyzing the corresponding vulnerability.
Citation Information
Patent Citations
Abnormal state detection method and system for automobile chassis
CN117150388A
Code review optimization method, system and equipment
CN119167376A
Binary file vulnerability analysis method based on multi-modal features
CN119760716A