Software data security detection method and system based on artificial intelligence

Through artificial intelligence-based methods, the detection results of multiple static scanning tools are comprehensively analyzed, the credibility ratio of each tool is calculated and the vulnerability risk estimate is performed, which solves the problem of inaccurate detection results of static scanning tools in the existing technology, and achieves more accurate software source code security detection.

CN120145401AInactive Publication Date: 2025-06-13JIMIAO CLOUD (WUHAN) DIGITAL TECHNOLOGY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510608470.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-06-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing static scanning tools have high missed and false alarm rates in software source code vulnerability detection, resulting in inaccurate vulnerability detection results.

Method used

Using an artificial intelligence-based approach, by obtaining the vulnerability detection results of multiple static scanning tools and their correctness and error reporting rates, the credibility ratio of each tool is calculated, and the overall risk estimate score of the vulnerability is calculated based on these values, and finally security detection is carried out.

Benefits of technology

By comprehensively analyzing the detection results of multiple static scanning tools, the missed and false alarm rates are reduced, and the accuracy of software source code security detection is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145401A_ABST
    Figure CN120145401A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to a software data security detection method and system based on artificial intelligence, and the method comprises the steps: weighting a vulnerability average estimation value of each function in a software source code to be detected according to the vulnerability missing report rate and the vulnerability false report rate of each static scanning tool, obtaining a credibility proportion value of each static scanning tool; based on the credibility ratio values of different static scanning tools, obtaining an overall risk estimation value of each vulnerability in the software source code to be detected; and performing security detection on the to-be-detected software source code based on the overall risk estimation value. The accuracy of the security detection result of the software source code to be detected is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and particularly to a software data security detection method and system based on artificial intelligence. Background Art

[0002] With the continuous innovation and development of the Internet applied to the computer software industry, network security issues have increasingly attracted people's attention. Generally speaking, the biggest threat to network security is the vulnerability in the software program; the commonly used detection method for program vulnerabilities is the static analysis method; the static analysis method mainly uses static detection tools to scan and analyze the program source code to identify its security vulnerabilities; security vulnerabilities refer to inappropriate operations, viruses, non-strong passwords and other things, which will damage the security of the software program system; using a single static detection tool to scan and analyze the program source code will have a high false negative rate and false positive rate; when using multiple static scanning tools for vulnerability detection, due to each static scanning tool having its own unique advantages and disadvantages, the vulnerability detection result of the software source code will still have an excessively high false negative rate and false positive rate. Summary of the Invention

[0003] The present invention provides a software data security detection method and system based on artificial intelligence to solve the existing problem that when using multiple static scanning tools for vulnerability detection, due to each static scanning tool having its own unique advantages and disadvantages, the vulnerability detection result of the software source code will still have an excessively high false negative rate and false positive rate.

[0004] A software data security detection method and system based on artificial intelligence of the present invention adopts the following technical solutions: The present invention proposes a software data security detection method based on artificial intelligence, and the method includes the following steps: Obtain the vulnerability detection results of several static scanning tools, as well as the correct reporting rate and error reporting rate of each static scanning tool; the vulnerability detection result of each static scanning tool is: under each static scanning tool, the risk level score of each vulnerability corresponding to each function in the software source code to be detected; By analyzing the estimated risk scores of each vulnerability corresponding to each function in the software source code to be detected under the detection of each static scanning tool, the average estimated vulnerability score of each function in the software source code to be detected is obtained under the detection of each static scanning tool; according to the correct reporting rate and false reporting rate of each static scanning tool, the false positive rate of vulnerabilities of each static scanning tool is obtained; according to the correct reporting rate of each static scanning tool and the total number of all vulnerabilities corresponding to all functions in the software source code to be detected, the missed reporting rate of vulnerabilities of each static scanning tool is obtained; according to the missed reporting rate and false positive rate of vulnerabilities of each static scanning tool, the average estimated vulnerability score of each function in the software source code to be detected is weighted to obtain the credibility ratio value of each static scanning tool; based on the credibility ratio values of different static scanning tools, the overall estimated risk score of each vulnerability in the software source code to be detected is obtained. Perform security detection on the software source code to be detected based on the overall estimated risk score.

[0005] Preferably, the specific method for obtaining the average estimated vulnerability score of each function in the software source code to be detected under the detection of each static scanning tool by analyzing the estimated risk scores of each vulnerability corresponding to each function in the software source code to be detected under the detection of each static scanning tool is as follows: By analyzing the estimated risk scores of each vulnerability corresponding to each function in the software source code to be detected under the detection of each static scanning tool, obtain the estimation score factor of the th vulnerability corresponding to the th function; Take the mean of the estimation score factors of all vulnerabilities corresponding to the th function in the software source code to be detected as the average estimated vulnerability score of the

[0006] th function in the software source code to be detected. Preferably, the specific method for obtaining the estimation score factor of the th vulnerability corresponding to the th function is as follows: Multiply the estimated risk score of the th vulnerability corresponding to the th function in the software source code to be detected under the detection of the th static scanning tool by the number of times the th vulnerability is detected by the th static scanning tool as the estimation score factor of the

[0007] Preferably, the specific method for obtaining the false positive rate of vulnerabilities for each static scanning tool according to the correct reporting rate and false reporting rate of each static scanning tool is as follows: Take the sum of the correct reporting rate of the th static scanning tool and the false reporting rate of the th static scanning tool as the first sum value; take the ratio of the correct reporting rate of the th static scanning tool to the first sum value as the false positive rate of vulnerabilities for the th static scanning tool.

[0008] Preferably, the specific method for obtaining the false negative rate of vulnerabilities for each static scanning tool according to the correct reporting rate of each static scanning tool and the total number of all vulnerabilities corresponding to all functions in the software source code to be detected is as follows: Take the inverse normalization value of the ratio between the correct reporting rate of the th static scanning tool and the total number of all vulnerabilities corresponding to all functions in the software source code to be detected under the detection of the th static scanning tool as the false negative rate of vulnerabilities for the th static scanning tool.

[0009] Preferably, the specific method for weighting the average estimated vulnerability value of each function in the software source code to be detected according to the false negative rate and false positive rate of each static scanning tool to obtain the credibility ratio value of each static scanning tool is as follows: Take the sum of the reciprocal of the false positive rate of the th static scanning tool and the reciprocal of the false negative rate of the th static scanning tool as the weighting factor of the th static scanning tool; take the normalized value of the product of the weighting factor of the th static scanning tool and the sum of the average estimated vulnerability values of all functions in the software source code to be detected under the detection of the th static scanning tool as the credibility ratio value of each th static scanning tool.

[0010] Preferably, the specific method for obtaining the overall risk assessment value of each vulnerability in the software source code to be detected based on the credibility ratio values of different static scanning tools is as follows: For any vulnerability corresponding to the th function in the software source code to be detected, obtain the risk assessment factor of the any vulnerability under the detection of the th static scanning tool; Take the The product of the risk assessment factor for any one of the following vulnerabilities detected by a static scanning tool and the credibility ratio value of the th static scanning tool is denoted as the risk assessment value of any one of the following vulnerabilities detected by the th static scanning tool; the sum of the risk assessment values of any one of the following vulnerabilities detected by all static scanning tools is used as the overall risk assessment value of any one of the following vulnerabilities. The product of the risk assessment factor for any one of the following vulnerabilities detected by a static scanning tool and the credibility ratio value of the th static scanning tool is denoted as the risk assessment value of any one of the following vulnerabilities detected by the th static scanning tool; the sum of the risk assessment values of any one of the following vulnerabilities detected by all static scanning tools is used as the overall risk assessment value of any one of the following vulnerabilities. The product of the risk assessment factor for any one of the following vulnerabilities detected by a static scanning tool and the credibility ratio value of the th static scanning tool is denoted as the risk assessment value of any one of the following vulnerabilities detected by the th static scanning tool; the sum of the risk assessment values of any one of the following vulnerabilities detected by all static scanning tools is used as the overall risk assessment value of any one of the following vulnerabilities.

[0011] Preferably, the specific method for obtaining the risk assessment factor for any one of the following vulnerabilities detected by the th static scanning tool is as follows: Preferably, the specific method for obtaining the risk assessment factor for any one of the following vulnerabilities detected by the th static scanning tool is as follows: Preset a score parameter ; when detected by the th static scanning tool, if any one of the following vulnerabilities is detected by the th static scanning tool, the risk assessment value of any one of the following vulnerabilities corresponding to the th function in the software source code to be detected when detected by the th static scanning tool is denoted as the risk assessment factor for any one of the following vulnerabilities detected by the th static scanning tool; if any one of the following vulnerabilities is not detected by the th static scanning tool, the score parameter ; when detected by the th static scanning tool, if any one of the following vulnerabilities is detected by the th static scanning tool, the risk assessment value of any one of the following vulnerabilities corresponding to the th function in the software source code to be detected when detected by the th static scanning tool is denoted as the risk assessment factor for any one of the following vulnerabilities detected by the th static scanning tool; if any one of the following vulnerabilities is not detected by the th static scanning tool, the score parameter ; when detected by the th static scanning tool, if any one of the following vulnerabilities is detected by the th static scanning tool, the risk assessment value of any one of the following vulnerabilities corresponding to the th function in the software source code to be detected when detected by the th static scanning tool is denoted as the risk assessment factor for any one of the following vulnerabilities detected by the th static scanning tool; if any one of the following vulnerabilities is not detected by the th static scanning tool, the score parameter ; when detected by the th static scanning tool, if any one of the following vulnerabilities is detected by the th static scanning tool, the risk assessment value of any one of the following vulnerabilities corresponding to the th function in the software source code to be detected when detected by the th static scanning tool is denoted as the risk assessment factor for any one of the following vulnerabilities detected by the th static scanning tool; if any one of the following vulnerabilities is not detected by the th static scanning tool, the score parameter ; when detected by the th static scanning tool, if any one of the following vulnerabilities is detected by the th static scanning tool, the risk assessment value of any one of the following vulnerabilities corresponding to the th function in the software source code to be detected when detected by the th static scanning tool is denoted as the risk assessment factor for any one of the following vulnerabilities detected by the th static scanning tool; if any one of the following vulnerabilities is not detected by the th static scanning tool, the score parameter ; when detected by the th static scanning tool, if any one of the following vulnerabilities is detected by the th static scanning tool, the risk assessment value of any one of the following vulnerabilities corresponding to the th function in the software source code to be detected when detected by the th static scanning tool is denoted as the risk assessment factor for any one of the following vulnerabilities detected by the th static scanning tool; if any one of the following vulnerabilities is not detected by the th static scanning tool, the score parameter ; when detected by the th static scanning tool, if any one of the following vulnerabilities is detected by the th static scanning tool, the risk assessment value of any one of the following vulnerabilities corresponding to the th function in the software source code to be detected when detected by the th static scanning tool is denoted as the risk assessment factor for any one of the following vulnerabilities detected by the th static scanning tool; if any one of the following vulnerabilities is not detected by the th static scanning tool, the score parameter is denoted as the risk assessment factor for any one of the following vulnerabilities detected by the th static scanning tool. is denoted as the risk assessment factor for any one of the following vulnerabilities detected by the th static scanning tool.

[0012] Preferably, the specific method for performing security detection on the software source code to be detected based on the overall risk assessment value is as follows: Preset a threshold parameter ; for any one of the following vulnerabilities corresponding to any one of the functions in the software source code to be detected, if the overall risk assessment value of any one of the following vulnerabilities corresponding to any one of the functions is greater than or equal to the threshold parameter , any one of the following vulnerabilities corresponding to any one of the functions is denoted as a vulnerability that accurately exists in the software source code to be detected; if the overall risk assessment value of any one of the following vulnerabilities corresponding to any one of the functions is less than the threshold parameter , any one of the following vulnerabilities corresponding to any one of the functions is denoted as a misjudged vulnerability in the software source code to be detected.

[0013] The present invention also proposes a software data security detection system based on artificial intelligence, including a memory and a processor, and the processor executes the computer program stored in the memory to implement the steps of the above-mentioned software data security detection method based on artificial intelligence.

[0014] The beneficial effects of the technical solution of the present invention are as follows: According to the false negative rate and false positive rate of vulnerabilities of each static scanning tool, the average estimated vulnerability value of each function in the software source code to be detected is weighted to obtain the credibility ratio value of each static scanning tool; based on the credibility ratio values of different static scanning tools, the overall risk estimated value of each vulnerability in the software source code to be detected is obtained; based on the overall risk estimated value, the software source code to be detected is subjected to security detection; thus, through comprehensive analysis of the vulnerability detection results of each static scanning tool, the vulnerability detection results are mutually verified and complemented; furthermore, the false negative rate of the vulnerability detection results of a single static scanning tool can be reduced, and as many vulnerabilities as possible existing in the software source code to be detected can be discovered; making the security detection results of the software source code to be detected more accurate. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0016] Figure 1 It is a flowchart of the steps of a software data security detection method based on artificial intelligence according to the present invention; Figure 2 It is a flowchart of the characteristic relationship of a software data security detection method based on artificial intelligence according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] In order to further elaborate on the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following will, in conjunction with the accompanying drawings and preferred embodiments, describe in detail the specific implementation manners, structures, characteristics, and effects of a software data security detection method and system based on artificial intelligence according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.

[0018] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field of the present invention.

[0019] The following will specifically describe the specific solutions of a software data security detection method and system based on artificial intelligence provided by the present invention in conjunction with the accompanying drawings.

[0020] Please refer to Figure 1, which shows the step flowchart of a software data security detection method based on artificial intelligence provided by an embodiment of the present invention. The method includes the following steps: Step S001: Obtain the vulnerability detection results of several static scanning tools, as well as the correct reporting rate and false reporting rate of each static scanning tool; the vulnerability detection result of each static scanning tool is: under each static scanning tool, the risk level assessment of each vulnerability corresponding to each function in the software source code to be detected.

[0021] It should be noted that in view of the large number of false positives and false negatives in existing source code static scanning tools, these tools can be integrated to perform static scanning on the software source program, and then data analysis can be performed on these scanning detection results to reduce the false positive rate and false negative rate of software security vulnerabilities and obtain accurate software security vulnerabilities.

[0022] In a specific implementation manner of the embodiment of the present invention, several static scanning tools are used to perform vulnerability detection on each function in the software source code to be detected, and the vulnerability detection results of several static scanning tools are obtained; Among them, the vulnerability detection result of each static scanning tool is: under each static scanning tool, the risk level assessment of each vulnerability corresponding to each function in the software source code; and through the parameter information of each static scanning tool, the correct reporting rate and false reporting rate of each static scanning tool are obtained; among them, the static scanning tools selected in this embodiment are: Its4, Rats, Flawfinder.

[0023] So far, the vulnerability detection results of several static scanning tools, as well as the correct reporting rate and false reporting rate of each static scanning tool, are obtained through the above method.

[0024] Step S002: By analyzing the risk level assessment values of each vulnerability corresponding to each function in the software source code to be detected under each static scanning tool, obtain the average vulnerability assessment value of each function in the software source code to be detected under each static scanning tool; according to the correct reporting rate and false reporting rate of each static scanning tool, obtain the false positive rate of each static scanning tool; according to the correct reporting rate of each static scanning tool and the total number of all vulnerabilities corresponding to all functions in the software source code to be detected, obtain the false negative rate of each static scanning tool; according to the false negative rate and false positive rate of each static scanning tool, weight the average vulnerability assessment value of each function in the software source code to be detected to obtain the credibility ratio value of each static scanning tool; based on the credibility ratio values of different static scanning tools, obtain the overall risk assessment value of each vulnerability in the software source code to be detected.

[0025] It should be noted that different static scanning tools are used to scan the software source code to be detected. From the vulnerability detection results of several static scanning tools, it can be found that each static scanning tool has its own unique advantages and disadvantages. If the vulnerability detection results of each static scanning tool are comprehensively analyzed after appropriate formatting, the vulnerability detection results can be mutually verified and complementary to each other. On the one hand, the false negative rate of the vulnerability detection results of a single static scanning tool can be reduced, and as many vulnerabilities as possible existing in the software source code to be detected can be discovered. On the other hand, if a reasonable level assessment is carried out on the comprehensive detection results, the false positive rate of vulnerabilities will also be reduced. Therefore, by adjusting the credibility ratio values of each static scanning tool, the overall score of each vulnerability can be obtained, and then the vulnerabilities accurately existing in the software source code to be detected can be obtained.

[0026] Preferably, in some implementation manners of the embodiments of the present invention, the specific method for obtaining the average vulnerability score value of each function in the software source code to be detected under the detection of each static scanning tool by analyzing the risk level score value of each vulnerability corresponding to each function in the software source code to be detected under the detection of each static scanning tool is as follows: Multiply the risk level score value of the th vulnerability corresponding to the th function in the software source code to be detected under the detection of the th static scanning tool by the number of times the th vulnerability is detected by the th static scanning tool, and use the product as the score value factor of the th vulnerability corresponding to the th function; take the average value of the score value factors of all vulnerabilities corresponding to the th function in the software source code to be detected as the average vulnerability score value of the th function in the software source code to be detected; The specific formula is: In the formula, represents the average vulnerability score value of the th function in the software source code to be detected under the detection of the th static scanning tool; represents the total number of times all vulnerabilities corresponding to the th function in the software source code to be detected are detected by the th static scanning tool; represents the risk level score value of the th vulnerability corresponding to the th function in the software source code to be detected under the detection of the The risk level evaluation score of a vulnerability; Indicates the th vulnerability corresponding to the th function in the software source code to be detected, and the number of times the

[0027] Preferably, in some implementation manners of the embodiments of the present invention, according to the correct reporting rate and the false reporting rate of each static scanning tool, the specific method for obtaining the false positive rate of a vulnerability for each static scanning tool is as follows: Denote the sum of the correct reporting rate of the th static scanning tool and the false reporting rate of the th static scanning tool as the first sum value; take the ratio of the correct reporting rate of the th static scanning tool to the first sum value as the false positive rate of the th static scanning tool.

[0028] Preferably, in some implementation manners of the embodiments of the present invention, according to the correct reporting rate of each static scanning tool and the total number of all vulnerabilities corresponding to all functions in the software source code to be detected, the specific method for obtaining the false negative rate of a vulnerability for each static scanning tool is as follows: Take the inverse normalization value of the ratio between the correct reporting rate of the th static scanning tool and the total number of all vulnerabilities corresponding to all functions in the software source code to be detected under the detection of the th static scanning tool as the false negative rate of the th static scanning tool.

[0029] Preferably, in some implementation manners of the embodiments of the present invention, according to the false negative rate and the false positive rate of each static scanning tool, weight the average evaluation score of a vulnerability for each function in the software source code to be detected, and the specific method for obtaining the credibility ratio value of each static scanning tool is as follows: Denote the sum of the reciprocal of the false positive rate of the th static scanning tool and the reciprocal of the false negative rate of the th static scanning tool as the weighting factor of the th static scanning tool; take the normalization value of the product of the weighting factor of the th static scanning tool and the sum of the average evaluation scores of vulnerabilities of all functions in the software source code to be detected under the detection of the th static scanning tool as the credibility ratio value of each th static scanning tool; The specific formula is: In the formula, represents the credibility ratio value of the th static scanning tool; represents the false positive rate of vulnerabilities of the th static scanning tool; represents the false negative rate of vulnerabilities of the th static scanning tool; represents the number of all functions in the software source code to be detected; represents the average estimated value of vulnerabilities of the th function in the software source code to be detected under the detection of the th static scanning tool; represents a linear normalization function.

[0030] It should be noted that if the false negative rate and false positive rate of vulnerabilities of the th static scanning tool are lower, the detection effect of the th static scanning tool on the software source code to be detected for vulnerabilities is better. Therefore, the credibility ratio value of the th static scanning tool should be assigned a higher value; the larger the average estimated value of vulnerabilities of the th function in the software source code to be detected under the th static scanning tool, it indicates that the th static scanning tool has a higher credibility of vulnerabilities for the th function. Therefore, the sum of the average estimated values of vulnerabilities of all functions in the software source code to be detected, the larger the value, it indicates that the th static scanning tool has a better detection effect on the software source code to be detected for vulnerabilities.

[0031] Preferably, in some implementation manners of the embodiments of the present invention, the specific method for obtaining the overall risk estimated value of each vulnerability in the software source code to be detected based on the credibility ratio values of different static scanning tools is as follows: Preset a score parameter , where in this embodiment, is taken as an example for description, and this embodiment does not make specific limitations, where is determined according to specific implementation situations; For any vulnerability corresponding to the th function in the software source code to be detected, under the detection of the th static scanning tool, if the any vulnerability is detected by the th static scanning tool, under the detection of the th static scanning tool, the The risk level assessment score of any one of the vulnerabilities corresponding to a function is denoted as the risk assessment factor of any one of the vulnerabilities under the detection of the th static scanning tool; if any one of the vulnerabilities is not detected by the th static scanning tool, the score parameter is denoted as the risk assessment factor of any one of the vulnerabilities under the detection of the th static scanning tool; Multiply the risk assessment factor of any one of the vulnerabilities under the detection of the th static scanning tool by the credibility ratio value of the th static scanning tool, and denote it as the risk assessment score of any one of the vulnerabilities under the detection of the th static scanning tool; The sum of the risk assessment scores of any one of the vulnerabilities under the detection of all static scanning tools is used as the overall risk assessment score of any one of the vulnerabilities.

[0032] So far, the overall risk assessment scores of each vulnerability in the software source code to be detected are obtained through the above method.

[0033] Step S003: Perform security detection on the software source code to be detected based on the overall risk assessment score.

[0034] Preferably, in some implementation manners of the embodiments of the present invention, all the vulnerabilities in the software source code to be detected are screened based on the overall risk assessment score of each vulnerability, and all the accurately existing vulnerabilities in the software source code to be detected are obtained.

[0035] Preset a threshold parameter , where this embodiment is described by taking as an example, and this embodiment is not specifically limited, where is determined according to the specific implementation situation; For any one of the vulnerabilities corresponding to any one of the functions in the software source code to be detected, if the overall risk assessment score of any one of the vulnerabilities corresponding to any one of the functions is greater than or equal to the threshold parameter , record any one of the vulnerabilities corresponding to any one of the functions as an accurately existing vulnerability in the software source code to be detected; If the overall risk assessment score of any one of the vulnerabilities corresponding to any one of the functions is less than the threshold parameter , record any one of the vulnerabilities corresponding to any one of the functions as a misjudged vulnerability in the software source code to be detected.

[0036] So far, all the accurately existing vulnerabilities in the software source code to be detected are obtained through the above method.

[0037] Please refer toFigure 2 , which shows a characteristic relationship flowchart of a software data security detection method based on artificial intelligence.

[0038] Through the above steps, a software data security detection method based on artificial intelligence is completed.

[0039] Another embodiment of the present invention provides a software data security detection system based on artificial intelligence. The system includes a memory and a processor. When the processor executes the computer program stored in the memory, it executes the above method steps S001 to step S003.

[0040] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. A software data security detection method based on artificial intelligence, characterized in that: The method comprises the following steps: Obtain vulnerability detection results of several static scanning tools, as well as the correct reporting rate and the error reporting rate of each static scanning tool; the vulnerability detection result of each static scanning tool is: the risk level estimation score of each vulnerability corresponding to each function in the source code of the software to be detected under each static scanning tool; By analyzing the estimated risk level of each vulnerability corresponding to each function in the software source code to be detected under the detection of each static scanning tool, the average estimated vulnerability score of each function in the software source code to be detected under the detection of each static scanning tool is obtained; the false alarm rate of vulnerabilities of each static scanning tool is obtained according to the correct reporting rate and the error reporting rate of each static scanning tool; the missed vulnerability rate of each static scanning tool is obtained according to the correct reporting rate of each static scanning tool and the total number of all vulnerabilities corresponding to all functions in the software source code to be detected; the average estimated vulnerability score of each function in the software source code to be detected is weighted according to the missed vulnerability rate and the false alarm rate of each static scanning tool to obtain the credibility ratio value of each static scanning tool; based on the credibility ratio values ​​of different static scanning tools, the overall risk estimated score of each vulnerability in the software source code to be detected is obtained; Perform security checks on the source code of the software to be tested based on the overall risk assessment score.

2. According to the artificial intelligence-based software data security detection method of claim 1, it is characterized in that: The specific method of obtaining the average estimated score of the vulnerability of each function in the software source code to be detected under each static scanning tool by analyzing the estimated score of the danger level of each vulnerability corresponding to each function in the software source code to be detected under each static scanning tool is as follows: By analyzing the estimated risk level of each vulnerability corresponding to each function in the source code of the software to be detected under each static scanning tool, the first The function corresponding to The scoring factor for each vulnerability; The source code of the software to be tested The average of the estimated score factors of all vulnerabilities corresponding to the function is used as the first The average estimated vulnerability score of the function.

3. According to the artificial intelligence-based software data security detection method of claim 2, it is characterized in that: The acquisition The function corresponding to The specific method for estimating the scoring factor of a vulnerability is: The first The static scanning tool is used to detect the source code of the software to be detected. The function corresponding to The risk level of the vulnerability is estimated by the The vulnerability was The product of the number of times detected by the static scanning tools is taken as the The function corresponding to The scoring factor for each vulnerability.

4. According to the artificial intelligence-based software data security detection method of claim 1, it is characterized in that: The specific method for obtaining the vulnerability false alarm rate of each static scanning tool according to the correct reporting rate and the error reporting rate of each static scanning tool is: The first The correct reporting rate of the static scanning tool is comparable to that of the The sum of the error reporting rates of the static scanning tools is recorded as the first sum value; The ratio of the correct reporting rate of the static scanning tool to the first sum is taken as the The false positive rate of vulnerabilities in static scanning tools.

5. According to the artificial intelligence-based software data security detection method of claim 1, it is characterized in that: The specific method for obtaining the vulnerability missed reporting rate of each static scanning tool according to the correct reporting rate of each static scanning tool and the total number of all vulnerabilities corresponding to all functions in the software source code to be detected is: The first The correct reporting rate of the static scanning tool is comparable to that of the The inverse normalized value of the ratio between the total number of vulnerabilities corresponding to all functions in the source code of the software to be detected under the detection of the static scanning tool is used as the first The vulnerability false positive rate of static scanning tools.

6. According to the artificial intelligence-based software data security detection method of claim 1, it is characterized in that: The specific method of weighting the average estimated vulnerability score of each function in the source code of the software to be detected according to the vulnerability missed alarm rate and the vulnerability false alarm rate of each static scanning tool to obtain the credibility ratio value of each static scanning tool is as follows: The first The inverse of the false positive rate of the vulnerability of the static scanning tool is The sum of the reciprocals of the vulnerability missed reporting rates of the static scanning tools is recorded as The weighting factor of the static scanning tool; The weighting factor of the static scanning tool is the same as that of the The normalized value of the product of the cumulative sum of the average estimated scores of the vulnerabilities of all functions in the source code of the software to be detected under the detection of the static scanning tool is used as the The confidence ratio value of a static scanning tool.

7. According to the artificial intelligence-based software data security detection method of claim 1, it is characterized in that: The specific method for obtaining the overall risk estimation value of each vulnerability in the software source code to be detected based on the credibility ratio values ​​of different static scanning tools is: For the first Any vulnerability corresponding to a function is obtained in A static scanning tool is used to detect the risk assessment factor of any of the vulnerabilities described below; Will be in The risk assessment factor of any vulnerability detected by a static scanning tool is the same as the risk assessment factor of the first The product of the confidence ratio values ​​of the static scanning tools is recorded as The risk estimation score of any one of the vulnerabilities detected by a static scanning tool is used; and the cumulative sum of the risk estimation scores of any one of the vulnerabilities detected by all the static scanning tools is used as the overall risk estimation score of the any one of the vulnerabilities.

8. According to the artificial intelligence-based software data security detection method of claim 7, it is characterized in that: The acquisition is in The specific method of using a static scanning tool to detect the risk assessment factor of any of the above vulnerabilities is: Preset a score parameter , in If any of the above vulnerabilities are detected by the first static scanning tool, The static scanning tool detects it and will The static scanning tool is used to detect the source code of the software to be detected. The estimated risk level of any vulnerability corresponding to the function is recorded as A static scanning tool is used to detect the risk assessment factor of any of the vulnerabilities described below; if any of the vulnerabilities is not detected by the first Static scanning tools detect it and set the score parameter , recorded as A static scanning tool is used to detect the risk assessment factor of any of the vulnerabilities mentioned below.

9. The software data security detection method based on artificial intelligence according to claim 1 is characterized in that: The specific method of performing security detection on the software source code to be detected based on the overall risk estimation score is: Preset a threshold parameter For any vulnerability corresponding to any function in the source code of the software to be detected, if the overall risk assessment value of any vulnerability corresponding to any function is greater than or equal to the threshold parameter , any vulnerability corresponding to any one of the functions is recorded as a vulnerability that accurately exists in the source code of the software to be detected; if the overall risk estimation value of any vulnerability corresponding to any one of the functions is less than the threshold parameter , any vulnerability corresponding to any of the functions is recorded as a false positive vulnerability in the software source code to be detected.

10. A software data security detection system based on artificial intelligence, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the computer program is executed by the processor, the steps of the software data security detection method based on artificial intelligence as described in any one of claims 1 to 9 are implemented.

Citation Information

Patent Citations

  • Vulnerability scanning method and device, computer equipment and storage medium

    CN117034290A

  • Security test method and device based on deep learning intelligent system code vulnerability

    CN118094564A

  • Vulnerability analysis for computer drivers

    CN118215917A

  • Vulnerability detection tool evaluation method, system, device and medium

    CN119883919A