Component-level vulnerability identification method and apparatus, and electronic device

By obtaining the structural view of components, tracking the data flow, and obtaining running data in a simulated environment, the problem of traditional methods not being accurate enough vulnerability identification at the component level is solved, and more efficient and accurate vulnerability identification is achieved.

CN120162789APending Publication Date: 2025-06-17CHINA ACADEMY OF RAILWAY SCI CORP LTD +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510194419.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

Traditional security vulnerability detection methods focus on the system level and are not accurate and efficient enough to identify component-level vulnerabilities.

Method used

By obtaining a structural view of the target component, tracking its data flow, and obtaining operational data in a simulated environment, integrating this information for vulnerability identification.

Benefits of technology

It significantly improves the accuracy and efficiency of identifying internal security vulnerabilities of components, and can comprehensively examine component security from multiple dimensions, thereby more effectively discovering and fixing potential security vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162789A_ABST
    Figure CN120162789A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of vulnerability recognition, and discloses a component-level vulnerability recognition method and device and electronic equipment, and the method comprises the steps: obtaining a structure view of a target component; tracking a data flow direction in the target component; acquiring operation data of the target component in the simulation environment; and performing vulnerability identification on the target component based on the structure view, the data flow direction and the operation data. According to the invention, through multi-dimensional analysis, the accuracy of identifying the internal security vulnerabilities of the component is improved. A structure view of a target component is acquired, and a data flow direction is tracked based on the structure view, so that the structure of the target component and a flow path of internal data are revealed; the actual operation state of the component is simulated by acquiring the operation data of the component in the simulation environment; according to the method, the structure view, the data flow direction and the operation data are integrated to perform vulnerability feature recognition, so that the reliability of a recognition result is improved, the security of the component can be comprehensively checked from different angles, and potential security vulnerabilities can be more effectively found and repaired.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of vulnerability identification, and more particularly, to a method, apparatus, electronic device, and computer-readable storage medium for component-level vulnerability identification. Background Art

[0002] With the rapid development of information technology, software systems have become increasingly complex, and component-based development has become the mainstream trend in software development. Component-based development improves development efficiency and system maintainability by decomposing software systems into reusable independent components. However, this development model also brings new security challenges, especially component-level security vulnerability issues. Component-level vulnerabilities refer to defects existing within a single component or between multiple components, which may be exploited by attackers to undermine the security and stability of the system.

[0003] Traditional security vulnerability detection methods mainly focus on the system level and conduct a comprehensive security assessment of the entire software system. Although these methods can discover most security problems in the system, they are often not precise and efficient enough for component-level vulnerability identification. Summary of the Invention

[0004] To solve one or more defects existing in the prior art, the present invention provides a method, apparatus, electronic device, and computer-readable storage medium for component-level vulnerability identification.

[0005] A method for component-level vulnerability identification includes: Obtaining a structural view of a target component; Tracking the data flow in the target component based on the structural view; Obtaining the running data of the target component in a simulation environment; Identifying vulnerabilities in the target component based on the structural view, the data flow, and the running data to obtain a vulnerability identification result.

[0006] Optionally, the obtaining of the structural view of the target component includes: Obtaining the source code of the target component and analyzing the source code of the target component using a preset code analysis tool set to obtain infrastructure information of the target component; Constructing a structural view of the target component based on the infrastructure information.

[0007] Optionally, after constructing the structural view of the target component based on the infrastructure information, the method further includes: Obtaining a build file of the project where the target component is located; Determining direct dependent components of the target component according to the build file; Determine the indirect dependent components of the target component according to the construction file and the configuration information of the directly dependent components; Determine the dependency relationship of the target component according to the names and version information of the directly dependent components and the indirectly dependent components, and generate a component dependency graph according to the dependency relationship.

[0008] Optionally, the tracing of the data flow in the target component based on the structure view includes: Determine the programming paradigm of the target component based on the structure view; When the programming paradigm of the target component is a functional paradigm, determine the entry point function of the target component based on the structure view; Use a preset traversal algorithm to track each function call starting from the entry point function to obtain the function call chain in the target component.

[0009] Optionally, the method further includes: When the programming paradigm of the target component is an object-oriented programming paradigm, determine all objects in the target component and the association relationship between each object based on the structure view; Use the preset traversal algorithm to track the attribute assignment process of each object during its life cycle and obtain the access data of the object attributes.

[0010] Optionally, the obtaining of the running data of the target component in the simulation environment includes: Obtain system resource parameters, and use a preset simulation tool to build the simulation environment based on the system resource parameters; Start the simulation environment and deploy the target component to the simulation environment; Control the target component to run in the simulation environment and obtain the running data of the target component.

[0011] Optionally, the controlling the target component to run in the simulation environment and obtaining the running data of the target component includes: Obtain at least one simulation script; different simulation scripts simulate different user behaviors; the user behaviors include normal behaviors or attack behaviors; Control the target component to run the simulation script in the simulation environment and obtain the running data of the target component.

[0012] Optionally, the vulnerability identification of the target component based on the structure view, the data flow and the running data to obtain a vulnerability identification result includes: Compare the structural view, the data flow, and the running data with the known vulnerability features in the feature database to obtain a feature similarity. If the feature similarity is greater than a first threshold, determine that the target component has a vulnerability. If the feature similarity is less than a second threshold, determine that the target component does not have a vulnerability.

[0013] Optionally, the method further includes: If the feature similarity is greater than the second threshold and less than the first threshold, detect whether the target component has abnormal behavior based on the running data. If there is, trace the abnormal data flow that causes the abnormal behavior, and determine whether the target component has a vulnerability by analyzing the abnormal data flow.

[0014] A device for component-level vulnerability identification, including: A first acquisition module, configured to acquire a structural view of a target component. A data tracking module, configured to track the data flow in the target component based on the structural view. A second acquisition module, configured to acquire the running data of the target component in a simulation environment. A vulnerability identification module, configured to perform vulnerability identification on the target component based on the structural view, the data flow, and the running data to obtain a vulnerability identification result.

[0015] An electronic device, including: A processor and a memory, where the memory is used to store at least one instruction, and when the instruction is loaded and executed by the processor, it implements the method for component-level vulnerability identification as described in any one of the above.

[0016] A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the method for component-level vulnerability identification as described in any one of the above.

[0017] The method for component-level vulnerability identification provided by the embodiments of the present invention includes obtaining the structural view of a target component; tracking the data flow in the target component based on the structural view; obtaining the running data of the target component in a simulation environment; and identifying vulnerabilities in the target component based on the structural view, data flow, and running data to obtain a vulnerability identification result. Through fine multi-dimensional analysis, the present invention significantly improves the accuracy and efficiency of identifying internal security vulnerabilities in components. First, by obtaining the structural view of the target component and tracking the data flow based on the structural view, the structure of the target component and the flow path of internal data are revealed; then, by obtaining the running data of the component in a simulation environment, the actual running state of the component is simulated; finally, by comprehensively considering the structural view, data flow, and running data, vulnerability feature identification is performed, which not only improves the reliability of the identification result, but also enables a comprehensive review of the security of the component from different perspectives, thereby more effectively discovering and fixing potential security vulnerabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the accompanying drawings required for the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0019] Figure 1 It is a flowchart of a method for component-level vulnerability identification provided by an embodiment of the present invention; Figure 2 For Figure 1 It is a flowchart of an actual manifestation of S01 in a method for component-level vulnerability identification provided; Figure 3 For Figure 1 It is a flowchart of an actual manifestation of S02 in a method for component-level vulnerability identification provided; Figure 4 For Figure 1 It is a flowchart of an actual manifestation of S03 in a method for component-level vulnerability identification provided; Figure 5 For Figure 1 It is a flowchart of an actual manifestation of S04 in a method for component-level vulnerability identification provided; Figure 6 It is a schematic structural diagram of a component-level vulnerability identification device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] To better understand the technical solutions of the present invention, the following describes the embodiments of the present invention in detail with reference to the accompanying drawings.

[0021] It should be clear that the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0022] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "the" and "said" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0023] It should be understood that the term " / and" used herein is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A / and B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " herein generally represents an "or" relationship between the front and rear associated objects.

[0024] With the rapid development of information technology, software systems have become increasingly complex, and component-based development has become the mainstream trend in software development. Component-based development improves development efficiency and system maintainability by decomposing software systems into reusable independent components. However, this development model also brings new security challenges, especially component-level security vulnerability issues. Component-level vulnerabilities refer to defects existing within a single component or between multiple components, which may be exploited by attackers to undermine the security and stability of the system.

[0025] Traditional security vulnerability detection methods mainly focus on the system level and conduct a comprehensive security assessment of the entire software system. Although these methods can discover most security problems in the system, they are often not precise and efficient enough for component-level vulnerability identification. Therefore, the present invention provides a method for component-level vulnerability identification to solve the above problems.

[0026] Please refer to Figure 1 , which is a flowchart of a method for component-level vulnerability identification provided by an embodiment of the present invention, including the following steps: Step S01, obtain the structural view of the target component.

[0027] In this embodiment, obtaining the structural view of the target component means a detailed analysis and representation of the internal structure of the target component and its various components, so as to determine the design logic and working principle of the target component, and provide necessary basic information for subsequent vulnerability identification and security analysis.

[0028] Please refer to Figure 2 , for Figure 1Flowchart of an actual manifestation of S01 in a method for component-level vulnerability identification. In some embodiments, as mentioned in step S01, to obtain the structural view of the target component, the following steps may be specifically included: Step S11: Obtain the source code of the target component, and use a preset code analysis tool set to analyze the source code of the target component to obtain the infrastructure information of the target component.

[0029] In this embodiment, by using a static code analysis tool set to deeply analyze the source code of the target component, the infrastructure information of the component can be identified in detail. It can not only accurately identify basic code elements within the component, such as functions, classes, variables, etc., but also perform refined analysis according to the characteristics of different programming languages, thereby discovering more potential vulnerability-related clues hidden deep in the code.

[0030] For example, for a target component with the programming language Python, tools such as Pylint and Flake8 can be selected to deeply analyze the usage details of variables; for a target component with the programming language C++, the association between header files and source files and the usage of templates can be carefully grasped; for a target Java component, tools such as Checkstyle and FindBugs can be selected.

[0031] Through this ability of in-depth mining and refined analysis, the static code analysis tool set can provide a more comprehensive and accurate code structure view for subsequent vulnerability identification and security analysis, thereby improving the accuracy and efficiency of vulnerability detection.

[0032] Step S12: Construct the structural view of the target component based on the infrastructure information.

[0033] In this embodiment, the structural view can intuitively display each component part in the target component and the relationships between them. Furthermore, the system can compare the structural view of the target component with known vulnerability characteristics to effectively identify whether there are vulnerabilities in the target component. Thereby improving the efficiency and accuracy of vulnerability identification.

[0034] In some embodiments, the structural view of the target component can also be output so that the user system can understand the working mechanism of the target component, including how data is transmitted and processed between different functions and classes. Furthermore, it enables the user to more accurately evaluate the security of the component and identify vulnerabilities that may be exploited by attackers, such as insecure API calls, sensitive information leakage, or inappropriate permission control, etc.

[0035] Furthermore, the structural view can also provide a basis for formulating defense strategies. After understanding the internal structure and data flow of the target component, users can design and implement security measures, such as input validation, encrypted communication, access control, etc., more specifically to prevent potential security threats.

[0036] In the prior art, in complex enterprise-level application systems, there are often multi-level component dependency relationships. Traditional detection means usually only focus on the main component itself and it is difficult to comprehensively consider the vulnerability situations of the dependencies between components. Therefore, based on the above embodiments, in some embodiments, after performing step S12, the problem can also be solved by performing steps S13 to S16: Step S13, obtain the build file of the project where the target component is located.

[0037] In this embodiment, the purpose of this step is to identify and parse the dependency relationships between the target component and other components. The build file contains a detailed list of all external dependencies required by the project, and this information is crucial for understanding the complete dependency graph of the components. By analyzing the build file, the direct dependent components of the target component can be determined, and further, the configuration information of the direct dependent components can be traced to identify the indirect dependent components. This process helps to construct a comprehensive component dependency graph, thereby providing the necessary basic data for subsequent vulnerability identification and risk assessment.

[0038] In some embodiments, the build file that defines the project build configuration and dependencies can be found and extracted in the directory of the software project, such as pom.xml for Maven projects or package.json for Node.js projects.

[0039] Step S14, determine the direct dependent components of the target component according to the build file.

[0040] In this embodiment, by analyzing the dependencies declared in the project build file, other components directly referenced or required by the target component are identified. The purpose of this step is to clarify the direct dependency relationships between the components, so as to be able to trace and manage the security risks that may be introduced by these direct dependent components. The build file contains all external resources required for the component to run or compile. Determining the direct dependent components helps users or security systems understand the functional implementation of the target component and the potential sources of security vulnerabilities, providing key information for subsequent vulnerability detection and security reinforcement.

[0041] In some embodiments, since there may be functional differences or known vulnerabilities in components of different versions, accurately recording version information is crucial for subsequent vulnerability analysis. When sorting out dependency relationships, attention should be paid to version compatibility issues. Therefore, in this embodiment, when determining the direct dependent components of the target component, the names and version information of the direct dependent components can also be recorded.

[0042] Step S15: Determine the indirect dependent components of the target component according to the build file and the configuration information of the direct dependent components.

[0043] In this embodiment, after the direct dependent components of the target component have been identified, the configuration information of these direct dependent components is further analyzed to identify other components indirectly dependent on the target component. Indirect dependent components may not be directly declared in the build file but can be introduced through the dependency relationships of the direct dependencies. These indirect dependent components may also contain security vulnerabilities. Therefore, identifying indirect dependent components is necessary for comprehensive security analysis and risk assessment. In this way, it can be ensured that no dependencies that may affect the security of the components are missed during vulnerability identification, thereby improving the security and stability of the software system.

[0044] In some embodiments, when determining the indirect dependent components of the target component, the names and version information of the indirect dependent components can also be recorded.

[0045] Step S16: Determine the dependency relationship of the target component according to the names and version information of the direct dependent components and the indirect dependent components, and generate a component dependency graph according to the dependency relationship.

[0046] In this embodiment, a complete dependency network is constructed by using the direct dependent component information extracted from the build file and the indirect dependent component information discovered by recursively analyzing the configuration information of the direct dependent components. This network maps the connections between the target component and all direct and indirect dependent components and clarifies the version information of the dependent components. Furthermore, the system can compare the dependency graph of the target component with the known vulnerability features to effectively identify whether there are vulnerabilities in the target component. Thereby, the efficiency and accuracy of vulnerability identification are improved.

[0047] In some embodiments, the obtained dependency graph can also be output so that users can quickly identify potential security risks, such as the impact that a known vulnerability in a certain dependent component may have on the target component. Users can more intuitively understand the mutual influence between components. When a vulnerability occurs in a certain component, they can quickly check the risks of associated components along the relationship graph, greatly improving the efficiency and comprehensiveness of vulnerability troubleshooting.

[0048] Based on the above technical solution, in this embodiment, through source code analysis, the infrastructure information of components is accurately extracted, providing a detailed structural view for vulnerability identification. By analyzing the build files, all direct and indirect dependencies of the components are identified and mapped, ensuring the comprehensiveness of vulnerability analysis. The generated dependency graph provides developers with an intuitive tool for quickly identifying and evaluating security risks between components, thereby improving the efficiency and accuracy of vulnerability detection.

[0049] Step S02: Trace the data flow in the target component based on the structural view.

[0050] In this embodiment, this step is to identify the way data flows in the component, so as to discover potential security vulnerabilities, such as data leakage or insecure data processing operations. By tracing the data flow, potential security risk points in the component can be more accurately identified, providing important information for subsequent vulnerability identification and repair. This embodiment can intuitively display the data flow in the component, helping to improve the accuracy and efficiency of vulnerability detection.

[0051] Please refer to Figure 3 , for Figure 1 a flowchart showing an actual implementation manner of S02 in a method for component-level vulnerability identification provided. In some embodiments, for step S02 mentioned, obtaining the structural view of the target component may specifically include the following steps: Step S21: Determine the programming paradigm of the target component based on the structural view.

[0052] In this embodiment, by analyzing the structural view of the target component to identify its programming paradigm, such as functional or object-oriented programming paradigm. Different programming paradigms have different data management and processing methods, which directly affect the data flow tracing method. For example, functional programming focuses on function calls and return values, while object-oriented programming focuses on object states and behaviors. By determining the programming paradigm, appropriate analysis and tracing techniques can be selected to more accurately trace the data flow in the component, identify potential security vulnerabilities and logical errors, and improve software quality and security.

[0053] In some embodiments, it can be achieved by checking key features in the structural view of the target component, which includes identifying elements such as function definitions, class and object usage, inheritance, and polymorphism in the code. For functional programming, the analysis will focus on function declarations, calls, and data passing between them; while for object-oriented programming, it will focus on class definitions, object creation, and method calls. Through these features, the main programming paradigm adopted by the target component can be determined.

[0054] Step S22: When the programming paradigm of the target component is a functional paradigm, determine the entry point function of the target component based on the structural view.

[0055] In this embodiment, in functional programming, the execution of the target component starts from a clear entry point, and this entry point function is where the target component begins to execute. For example, in the C language, this entry point is usually the main function, which is called by the operating system when the target component starts. Determining the entry point function is crucial for data flow tracing because it is the starting point for tracing the function call chain. Starting from the entry point function, a preset traversal algorithm, such as depth - first search, can be used to track each function call and construct the function call chain in the target component. This helps analyze the transfer and processing of data between functions, thereby identifying potential security vulnerabilities or logical errors.

[0056] Step S23: Use a preset traversal algorithm to start tracking each function call from the entry point function to obtain the function call chain in the target component.

[0057] In this embodiment, by using a preset traversal algorithm, such as depth - first search or breadth - first search, starting from the entry point function of the target component, the systematically tracks and records the call relationships between functions, and details the name of each called function, the specific content and transfer method of the parameters, as well as the processing mechanism of the return value, to construct a complete function call chain. The function call chain details the flow path of data during program execution. In this way, the execution process and data transfer mechanism of the target component can be deeply understood, which is crucial for identifying potential security vulnerabilities, logical errors, or performance bottlenecks in the target component.

[0058] Traditional techniques focus more on the simple observation of parameter passing at the function call level when tracing data flow. Compared with traditional techniques, this embodiment not only focuses on the function call itself but also pays more meticulous attention to every step of data conversion during parameter passing and the processing of return values. This meticulous tracking and recording enable this embodiment to more accurately capture potential vulnerability risks such as tampering and leakage when data flows between functions. By constructing a detailed function call chain, this embodiment provides a more in - depth basis for vulnerability analysis, thus achieving a significant improvement compared with the prior art in terms of vulnerability identification and risk assessment. This method helps discover and fix security vulnerabilities that may be overlooked by traditional techniques, thereby improving the overall security of the software.

[0059] In some embodiments, when tracking the function call chain, it is necessary to pay attention to the recursive call situation of the function. An appropriate recursive depth limit can be set or other strategies to avoid recursive infinite loops can be adopted to avoid getting stuck in an infinite loop during tracking.

[0060] Based on traditional technologies, there is insufficient analysis of the object attribute level and more complex data processing processes when tracking data flow. Therefore, on the basis of the above embodiments, in some embodiments, after performing step S21, the problem can also be solved by performing steps S24 and S25: Step S24, when the programming paradigm of the target component is an object-oriented programming paradigm, determine all objects in the target component and the association relationships between each object based on the structural view.

[0061] When the target component adopts an object-oriented programming paradigm, in this embodiment, the structural view is used to identify the creation of all objects within the component and their association relationships, including reviewing the source code to identify all object creation statements and recording the type of the object and the initialization parameters used in the constructor.

[0062] In addition, this embodiment deeply analyzes the interactions between objects, evaluates how a change in an object's attribute affects other related objects, and determines whether these changes may be the source of security vulnerabilities. This analysis is particularly important for object-oriented systems because the encapsulation, inheritance, and polymorphism of objects may hide data flow and potential security risks. Through this detailed analysis, the behavior of the component can be understood more comprehensively, providing a solid foundation for vulnerability identification and security assessment.

[0063] Step S25, use a preset traversal algorithm to track the attribute assignment process of each object during its life cycle and obtain the access data of the object attributes.

[0064] In this embodiment, a preset traversal algorithm is used to monitor and record how the attributes of an object are assigned and accessed throughout its life cycle from creation to destruction. This includes identifying the source of attribute assignment, such as through a constructor, method call, or other means, and recording the specific circumstances of attribute access, such as in which functions the access occurs, the purpose of the access (reading or modifying), and whether there are improper access behaviors, such as unauthorized or unauthorised access. In addition, the polymorphism of the object is also considered to comprehensively and accurately understand the processing of attributes. This detailed tracking and analysis helps to discover security vulnerabilities that may lead to data leakage or unauthorized access and is crucial for security in object-oriented programming.

[0065] At the object attribute level, this embodiment deeply analyzes the creation, attribute assignment, and access processes of objects in object-oriented components. Through this meticulous analysis, security vulnerabilities caused by improper handling of object attributes can be accurately discovered, such as SQL injection vulnerabilities caused by attribute setting or access problems, making up for the shortcoming of insufficient analysis at the object attribute level in the prior art.

[0066] Based on the above technical solution, through a refined data flow tracing mechanism, this embodiment can achieve a clear and accurate insight into the flow and processing of data within the target component. By closely tracking the function call chain and deeply analyzing the data flow at the object attribute level, various vulnerabilities that may be caused by factors such as improper data transmission, conversion, and access can be accurately captured. For example, data is tampered with during function calls, or unauthorized access occurs when accessing object attributes, thereby further improving the accuracy of vulnerability detection.

[0067] Step S03: Obtain the running data of the target component in the simulation environment.

[0068] This embodiment collects various data generated during the execution of the target component in a simulated test environment, including performance metrics, error logs, resource usage, etc. This step is to observe and analyze the behavior of the component in a controlled environment, so as to identify potential problems and vulnerabilities. By running the component in a simulated environment, the performance and stability of the component can be safely tested and evaluated without affecting the real system. In addition, the collected running data can also be used for subsequent analysis to identify potential performance bottlenecks, security vulnerabilities, or functional defects, so as to optimize and repair them before the product is released.

[0069] Please refer to Figure 4 , for Figure 1 a flowchart showing an actual implementation manner of S03 in a method for component-level vulnerability identification provided by Step S31: Obtain system resource parameters and build a simulation environment based on the system resource parameters using a preset simulation tool.

[0070] In this embodiment, system resource information required for the operation of the target component is collected, such as parameters of CPU, memory, disk, and network configuration, etc., and a specific simulation tool is used to create a test environment similar to the actual operating environment according to these parameters. The purpose of this step is for vulnerability identification, to run and test the target component under conditions similar to but isolated from the production environment, so as to safely evaluate its behavior and performance under various system resource limitations. In this way, potential security vulnerabilities can be discovered and repaired without affecting the actual system, improving the stability and security of the software.

[0071] In some embodiments, when simulating the execution environment of components based on the prior art, often only simple and limited types of environment settings can be made, which cannot truly reflect the performance of components in actual complex and diverse operating scenarios. In view of this, this embodiment has made significant improvements: First, according to the actual operating environment of the target component, this embodiment determines the system resource parameters to be simulated, such as the number of CPU cores, frequency, memory size, disk I / O performance, etc.

[0072] Secondly, in this embodiment, a dedicated system resource simulation tool is used (for example, Docker containers can simulate different system resource environments by setting relevant parameters) or corresponding simulation logic is written in the code (for example, in Java, different memory environments can be simulated by adjusting virtual machine parameters) to implement the simulation of system resources.

[0073] Finally, based on the obtained system resource parameters, this embodiment can accurately simulate system resource conditions in multiple aspects, including CPU processing power, memory size and allocation, disk I / O performance, etc., and can set rich and diverse network environment parameters such as different network bandwidths, latencies, packet loss rates, etc. Through this highly simulated environment simulation, it is possible to more realistically observe the running state of the component under various resource - constrained or network - unstable situations that may actually be encountered.

[0074] For example, for real - time communication components with high requirements for network bandwidth, by simulating parameters such as different network bandwidths, latencies, and packet loss rates, it is possible to accurately observe whether the component will have problems such as data transmission errors and communication interruptions when the network is unstable, and then precisely discover potential vulnerabilities that may be caused thereby. This ability to highly simulate actual application scenarios effectively avoids blind spots in vulnerability detection caused by large differences between the simulation environment and the actual application scenario, ensuring the comprehensiveness and accuracy of vulnerability detection.

[0075] Step S32: Start the simulation environment and deploy the target component into the simulation environment.

[0076] In this embodiment, in order to reproduce various situations that the target component may encounter in actual use in the simulation environment, including normal operation processes and potential attack scenarios, by deploying the target component in the simulation environment, the behavior of the target component can be observed and recorded, and its responses to different inputs and operations can be analyzed, so as to effectively identify and evaluate potential security vulnerabilities without worrying about damaging the real system. This method helps to discover and fix vulnerabilities in advance, enhancing the security and reliability of the software.

[0077] Step S33: Control the target component to run in the simulation environment and obtain the running data of the target component.

[0078] In the already set up and launched simulation environment, by executing preset test cases or simulation scripts, drive the target component to perform specific operations, and monitor its runtime behavior and output, so as to observe the actual performance of the target component in a controlled environment, including the way it processes data, its behavior in response to user input, and its stability under specific conditions. By collecting this runtime data, it is possible to analyze whether the target component has security vulnerabilities, such as unauthorized access, data leakage, buffer overflow, etc. In addition, the runtime data can also be used for performance analysis and optimization to ensure that the component can operate stably under various conditions.

[0079] Based on the above embodiments, in some embodiments, for what is mentioned in step S33, controlling the target component to run in the simulation environment and obtaining the runtime data of the target component can specifically include the following steps: Step S41, obtain at least one simulation script.

[0080] In this embodiment, these simulation scripts are designed to simulate different user behaviors, including normal user operations and potential attack behaviors. The purpose of doing this is to comprehensively test the response of the target component under various usage scenarios, so as to more accurately identify possible security vulnerabilities. Normal behaviors may include standard user interactions, such as logging in, data input, and querying, etc., while attack behaviors may include attempts to inject malicious code, perform unauthorized operations, or trigger abnormal processes, etc. In this way, various situations that may be encountered in the real world can be reproduced in the simulation environment, providing rich data and scenarios for vulnerability identification.

[0081] In some embodiments, the process of obtaining at least one simulation script may include: According to the business process and user operation mode of the target component in the actual usage scenario, use professional script writing tools or simulation frameworks to accurately simulate various typical user behavior patterns, and obtain the corresponding simulation scripts. Among them, the user behavior patterns can cover user operations at different privilege levels, such as the regular browsing and querying operations of ordinary users, and the system configuration and privilege management operations of administrator users, etc.

[0082] Through this comprehensive and practical user behavior simulation method, it is more accurate when analyzing the component's handling of different types of data, and more vulnerabilities caused by user behavior can be discovered. Compared with the relatively single and simple user behavior simulation in the prior art, it can provide a more comprehensive perspective for vulnerability detection.

[0083] Step S42, control the target component to run the simulation script in the simulation environment and obtain the runtime data of the target component.

[0084] In a simulated test environment, an automated tool or script is used to drive the target software component to execute a series of predefined operations, which include normal user interactions or malicious attack behaviors. During the execution of the script, the system monitors and records the running status, performance metrics, error logs, and other relevant data of the component. This high-fidelity simulation of the actual application scenario further enhances the environmental authenticity, effectively avoiding the vulnerability detection blind spots caused by a single simulation scenario and ensuring the comprehensiveness and accuracy of vulnerability detection.

[0085] In some embodiments, during the process of simulating the operation of the target component, various predefined types of possible user data can also be input into the target component, including legitimate data that conforms to the business logic and potentially aggressive data, such as SQL injection statements, cross-site scripting attack codes, etc., so as to comprehensively observe the processing capabilities and response mechanisms of the component to different types of data in the simulated environment, thereby accurately evaluating its security in the actual application scenario.

[0086] Based on the above technical solutions, in this embodiment, by simulating different operating scenarios and deploying the target component into the simulated environment to control its operation, the functions and performance of the component can be tested in a secure environment without endangering the actual production environment. At the same time, by running different simulation scripts, including simulating normal user behaviors and potential attack behaviors, the running data of the target component in various situations can be collected, which helps to discover problems that the component may encounter in actual use. In addition, by simulating attack behaviors, the security of the component can be evaluated, and possible vulnerabilities and weaknesses can be identified. By conducting extensive tests in the simulated environment, potential problems can be discovered and fixed before the product is released, thereby reducing the risks and maintenance costs after the product is released.

[0087] Step S04, based on the structural view, data flow, and running data, identify vulnerabilities in the target component to obtain a vulnerability identification result.

[0088] In this embodiment, by leveraging the structural view of the target component, data flow analysis, and running data collected in the simulated environment, various security analysis techniques and algorithms are comprehensively applied to identify potential security vulnerabilities. This process involves cross-comparing the static code structure of the component, the dynamic data flow situation, and the behavior performance during actual operation to discover weaknesses that may be exploited by attackers or code segments that do not conform to security best practices. The purpose of this method is to improve the accuracy and efficiency of vulnerability identification through multi-dimensional analysis, thereby discovering and fixing security issues in the early stage of the software development life cycle and reducing the security risks and potential economic losses after the software is released.

[0089] In some embodiments, vulnerability identification of a target component can be achieved through an Integrated Development Environment (IDE). This approach allows developers to conduct security tests immediately during the coding process. For example: Security tool plugins can be embedded in the IDE. For example, on Eclipse, by installing plugins (such as FindBugs, Find-sec-bugs, CheckStyle, and SonarLint, etc.), the function of security auditing can be embedded into the IDE. These plugins can not only detect potential errors and security vulnerabilities in the code, but also check the code style to ensure that the code complies with specific coding standards, thereby enabling security tests immediately during the coding process. In this way, developers can discover and solve potential security problems in a timely manner during the development stage, thus protecting the application from attacks. In addition, these plugins support real-time code analysis to help identify potential security problems and improve the overall security of the software.

[0090] Based on the above technical solution, the method for component-level vulnerability identification provided by the embodiments of the present invention includes: obtaining the structural view of the target component; tracking the data flow in the target component based on the structural view; obtaining the running data of the target component in a simulation environment; and performing vulnerability identification on the target component based on the structural view, data flow, and running data to obtain a vulnerability identification result. Through fine multi-dimensional analysis, the present invention significantly improves the accuracy and efficiency of identifying internal security vulnerabilities of components. First, by obtaining the structural view of the target component and tracking the data flow based on the structural view, the structure of the target component and the flow path of internal data are revealed; then, by obtaining the running data of the component in a simulation environment, the actual running state of the component is simulated; finally, by comprehensively considering the structural view, data flow, and running data for vulnerability feature identification, not only the reliability of the identification result is improved, but also the security of the component can be comprehensively examined from different perspectives, thus more effectively discovering and fixing potential security vulnerabilities.

[0091] Please refer to Figure 5 , for Figure 1 a flowchart showing an actual implementation manner of S04 in a method for component-level vulnerability identification provided. In some embodiments, for step S04, performing vulnerability identification on the target component based on the structural view, data flow, and running data to obtain a vulnerability identification result may specifically include the following steps: Step S51: Compare the structural view, data flow, and running data with the known vulnerability features in the feature database to obtain a feature similarity.

[0092] When identifying vulnerability features based on existing technologies, most of them simply compare with known vulnerability patterns and lack in-depth analysis of the underlying causes behind abnormal behaviors. To solve this problem, in this embodiment, by comparing the structure view, data flow, and running data with the known vulnerability features in the feature database, the feature similarity is calculated. If the feature similarity exceeds the set first threshold, the system will enter step S52 and determine that the target component has a vulnerability, which indicates that the behavior or structure of the component highly matches the known vulnerability features, so there may be security risks. On the contrary, if the feature similarity is lower than the second threshold, the system will execute step S53 and determine that the target component does not have a vulnerability, which means that the behavior or structure of the target component has a low match with the known vulnerability features and the security risk is small. The purpose of this process is to quickly and accurately identify potential security problems during the software development and testing phases, so as to take timely measures for repair, thereby improving the security and reliability of the software. By setting thresholds, false positives and false negatives can be reduced to ensure the accuracy of vulnerability identification.

[0093] In some embodiments, the feature database can be constructed by the system based on the vulnerability feature information of known components. The special database can include various common component vulnerability types, such as SQL injection vulnerabilities, cross-site scripting vulnerabilities, buffer overflow vulnerabilities, etc., and provide detailed feature descriptions for each vulnerability type, including detailed information on vulnerability trigger conditions, data flow characteristics, abnormal behavior manifestations, etc.

[0094] Step S52, if the feature similarity is greater than the first threshold, it is determined that the target component has a vulnerability.

[0095] Step S53, if the feature similarity is less than the second threshold, it is determined that the target component does not have a vulnerability.

[0096] Step S54, if the feature similarity is greater than the second threshold and less than the first threshold, it is detected whether the target component has abnormal behavior according to the running data.

[0097] If so, execute step S55.

[0098] In this embodiment, when it is found that the comparison result is close to the known vulnerability features, that is, when the above feature similarity is greater than the second threshold and less than the first threshold, the system can timely adjust the analysis strategy and deeply explore the cause of the vulnerability, that is, detect whether the target component has abnormal behavior according to the running data. If there is, execute step S55, trace the abnormal data flow that causes the abnormal behavior, and determine whether the target component has a vulnerability by analyzing the abnormal data flow to further improve the accuracy of vulnerability identification.

[0099] In some embodiments, if no abnormal behavior is detected, it can be determined that the target component has no vulnerability, thus ending the current vulnerability identification process. This hierarchical analysis method not only improves the accuracy of vulnerability identification, but also helps to reduce false positives and false negatives, ensuring that only real security issues will be further investigated and fixed.

[0100] Step S55: Trace the abnormal data flow that leads to the abnormal behavior, and determine whether the target component has a vulnerability by analyzing the abnormal data flow.

[0101] In this embodiment, the system will trace the data flow behind the abnormal behavior, analyze how the data is transmitted and processed within the component, and whether these operations have caused the abnormality. Through this tracing and analysis, it can be more accurately determined whether the abnormal behavior is caused by a security vulnerability, as well as the nature and possible impact of the vulnerability.

[0102] Based on the above technical solution, in this embodiment, when the above feature similarity is greater than the second threshold and less than the first threshold, abnormal behavior analysis is performed in combination with the running data, such as program crashes, abnormal memory occupancy, etc., and the possible vulnerability causes hidden behind are deeply analyzed. By tracing factors such as function calls and data flows that lead to abnormal behavior, it can accurately find out whether there is a security vulnerability and its specific causes, making up for the deficiency of the prior art in only looking at the surface and not delving into the root cause when analyzing abnormal behavior.

[0103] On the basis of the above embodiment, in some embodiments, after performing step S55 to trace the abnormal data flow that leads to the abnormal behavior and determine whether the target component has a vulnerability by analyzing the abnormal data flow, it is also possible to predict in advance the possible types and locations of vulnerabilities based on the analysis results, provide valuable warning information for users, so that users can take corresponding defensive measures before the vulnerabilities are actually exploited, thereby effectively enhancing the proactive defense ability at the component level.

[0104] In some embodiments, when controlling the target component to run in a simulation environment, it is also possible to evaluate the effectiveness of the defense mechanism in the simulation environment, discover the weak links in the defense system, and thus prompt the user to optimize the defense strategy and adjust the parameters and settings of the defense mechanism to achieve defense optimization.

[0105] In some embodiments, it is also possible to flexibly adjust the analysis strategy and simulation parameters according to different situations to ensure that vulnerabilities in the component can be accurately discovered and the effectiveness of the defense mechanism can be evaluated in various complex application scenarios and changing network security environments.

[0106] Please refer to Figure 6 , which is a schematic structural diagram of a component-level vulnerability identification device provided by an embodiment of the present invention. The component-level vulnerability identification device may include: The first acquisition module 100 is configured to acquire the structural view of the target component; The data tracking module 200 is configured to track the data flow in the target component based on the structural view; The second acquisition module 300 is configured to acquire the operation data of the target component in the simulation environment; The vulnerability identification module 400 is configured to identify vulnerabilities in the target component based on the structural view, data flow, and operation data to obtain a vulnerability identification result.

[0107] Based on the above embodiments, in a specific embodiment, the first acquisition module 100 may specifically be configured to: Acquire the source code of the target component, and analyze the source code of the target component by using a preset code analysis tool set to obtain the infrastructure information of the target component; Construct the structural view of the target component based on the infrastructure information.

[0108] Based on the above embodiments, in a specific embodiment, the first acquisition module 100 may also be configured to: Acquire the build file of the project where the target component is located; Determine the direct dependent components of the target component according to the build file; Determine the indirect dependent components of the target component according to the build file and the configuration information of the direct dependent components; Determine the dependency relationship of the target component according to the names and version information of the direct dependent components and the indirect dependent components, and generate a component dependency relationship diagram according to the dependency relationship.

[0109] Based on the above embodiments, in a specific embodiment, the data tracking module 200 may specifically be configured to: Determine the programming paradigm of the target component based on the structural view; When the programming paradigm of the target component is a functional paradigm, determine the entry point function of the target component based on the structural view; Use a preset traversal algorithm to track each function call starting from the entry point function to obtain the function call chain in the target component.

[0110] Based on the above embodiments, in a specific embodiment, the data tracking module 200 may also be configured to: When the programming paradigm of the target component is an object-oriented programming paradigm, determine all objects in the target component and the association relationship between each object based on the structural view; Use a preset traversal algorithm to track the attribute assignment process of each object during its life cycle and obtain the access data of the object attributes.

[0111] Based on the above embodiments, in a specific embodiment, the second acquisition module 300 may specifically be configured to: Obtain system resource parameters, and build a simulation environment based on the system resource parameters by using a preset simulation tool; Start the simulation environment, and deploy the target component into the simulation environment; Control the target component to run in the simulation environment, and obtain the running data of the target component.

[0112] Based on the above embodiments, in a specific embodiment, the second acquisition module 300 may specifically be configured to: Obtain at least one simulation script; different simulation scripts simulate different user behaviors; user behaviors include normal behaviors or attack behaviors; Control the target component to run the simulation script in the simulation environment, and obtain the running data of the target component.

[0113] Based on the above embodiments, in a specific embodiment, the vulnerability identification module 400 may specifically be configured to: Compare the structure view, data flow, and running data with the known vulnerability features in the feature database to obtain a feature similarity; If the feature similarity is greater than the first threshold, it is determined that the target component has a vulnerability; If the feature similarity is less than the second threshold, it is determined that the target component does not have a vulnerability.

[0114] Based on the above embodiments, in a specific embodiment, the vulnerability identification module 400 may specifically be configured to: If the feature similarity is greater than the second threshold and less than the first threshold, detect whether the target component has abnormal behaviors according to the running data; If there are any, trace the abnormal data flow that causes the abnormal behaviors, and determine whether the target component has a vulnerability by analyzing the abnormal data flow.

[0115] This embodiment provides an electronic device, including a processor and a memory. The memory is used to store at least one instruction. When the instruction is loaded and executed by the processor, it implements the above method for component-level vulnerability identification. Its execution manner and beneficial effects are similar and will not be elaborated here.

[0116] This embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the above method for component-level vulnerability identification. Its execution manner and beneficial effects are similar and will not be elaborated here.

[0117] It should be noted that although the above steps are described in a specific order, it does not mean that the steps must be executed in the above specific order. In fact, some of these steps can be executed concurrently or even in a different order, as long as the required functions can be achieved.

[0118] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.

Claims

1. A method for component-level vulnerability identification, characterized in that: include: Get the structure view of the target component; Tracking the data flow in the target component based on the structural view; Acquiring operation data of the target component in a simulation environment; Based on the structural view, the data flow and the operating data, vulnerabilities of the target component are identified to obtain vulnerability identification results.

2. The method according to claim 1, characterized in that The step of obtaining the structural view of the target component includes: Obtaining the source code of the target component, and analyzing the source code of the target component using a preset code analysis tool set to obtain infrastructure information of the target component; A structural view of the target component is constructed based on the infrastructure information.

3. The method according to claim 2, characterized in that After constructing the structural view of the target component based on the infrastructure information, the method further includes: Obtain the build file of the project where the target component is located; Determine the direct dependent components of the target component according to the build file; Determine the indirect dependent components of the target component according to the build file and the configuration information of the directly dependent components; The dependency relationship of the target component is determined according to the name and version information of the directly dependent component and the indirectly dependent component, and a component dependency graph is generated according to the dependency relationship.

4. The method according to claim 1, characterized in that: The tracking of the data flow in the target component based on the structural view includes: Determining a programming paradigm of the target component based on the structural view; When the programming paradigm of the target component is a functional paradigm, determining an entry point function of the target component based on the structural view; Each function call is tracked starting from the entry point function using a preset traversal algorithm to obtain a function call chain in the target component.

5. The method according to claim 4, characterized in that The method further comprises: When the programming paradigm of the target component is an object-oriented programming paradigm, determining all objects in the target component and the association relationship between each of the objects based on the structural view; The preset traversal algorithm is used to track the attribute assignment process of each object during its life cycle, and access data of the object attributes is obtained.

6. The method according to claim 1, characterized in that The obtaining the operation data of the target component in the simulation environment includes: Acquire system resource parameters, and use a preset simulation tool to build the simulation environment based on the system resource parameters; Starting the simulation environment and deploying the target component into the simulation environment; The target component is controlled to run in the simulation environment, and the running data of the target component is obtained.

7. The method according to claim 6, characterized in that The controlling the target component to run in the simulation environment and obtaining the running data of the target component includes: Obtain at least one simulation script; different simulation scripts simulate different user behaviors; the user behaviors include normal behaviors or attack behaviors; The target component is controlled to run the simulation script in the simulation environment, and the operation data of the target component is obtained.

8. The method according to claim 1, characterized in that: The performing vulnerability identification on the target component based on the structural view, the data flow and the operation data to obtain a vulnerability identification result includes: Comparing the structural view, the data flow and the operation data with known vulnerability features in a feature database to obtain feature similarity; If the feature similarity is greater than a first threshold, it is determined that the target component has a vulnerability; If the feature similarity is less than a second threshold, it is determined that the target component does not have a vulnerability.

9. The method according to claim 8, characterized in that The method further comprises: If the feature similarity is greater than the second threshold and less than the first threshold, detecting whether the target component has abnormal behavior according to the operation data; If so, the abnormal data flow that causes the abnormal behavior is traced back, and whether the target component has a vulnerability is determined by analyzing the abnormal data flow.

10. A device for component-level vulnerability identification, characterized in that: include: A first acquisition module is used to acquire a structural view of a target component; A data tracking module, used for tracking the data flow in the target component based on the structural view; A second acquisition module, used to acquire the operation data of the target component in the simulation environment; The vulnerability identification module is used to identify vulnerabilities of the target component based on the structural view, the data flow and the operation data to obtain a vulnerability identification result.

11. An electronic device, characterized in that: include: A processor and a memory, wherein the memory is used to store at least one instruction, and when the instruction is loaded and executed by the processor, the method for component-level vulnerability identification as described in any one of claims 1-9 is implemented.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for component-level vulnerability identification as described in any one of claims 1 to 9 is implemented.