Auxiliary protection system for computer software development

By designing a computer software development auxiliary protection system that works in collaboration with multiple protection modules, using technical means such as static syntax tree analysis, dynamic sandbox simulation, multi-factor authentication, elliptic curve encryption and machine learning, the problem of lack of comprehensive, automated and real-time protection solutions in the existing technology is solved, and all-round security protection for the software development process is achieved.

CN120217385APending Publication Date: 2025-06-27山东电子职业技术学院
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510305598.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing computer software development protection measures are mostly single means, lacking comprehensive, automated and real-time protection solutions, and cannot effectively deal with various security threats.

Method used

Design a computer software development auxiliary protection system to detect and protect various potential security issues in the development process in real time through the collaborative work of multiple protection modules. The system includes a code security protection module, a multi-factor authentication module, a data flow encryption unit, a behavioral audit engine and an automated compliance detection module, and uses technical means such as static syntax tree analysis, dynamic sandbox simulation, multi-factor authentication, elliptic curve encryption and machine learning.

Benefits of technology

Through the system's multiple protection mechanisms, we will fully guarantee the code security, developer permission management and compliance requirements during the development process, detect and protect various security threats in real time, help the development team to timely discover and repair potential problems, and improve the security and reliability of software development.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217385A_ABST
    Figure CN120217385A_ABST
Patent Text Reader

Abstract

The invention discloses a computer software development auxiliary protection system which detects and protects various potential safety problems in the development process in real time through cooperative work of multiple protection modules. The system comprehensively guarantees code security, developer authority management and compliance requirements in the development process through means of code security protection, multi-factor authentication, data stream encryption, behavior audit, compliance detection and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer software security, and particularly to an auxiliary protection system for the computer software development process. Through multiple protection measures, this system ensures code security, developer access control, data encryption, and behavior auditing during the development process, thereby effectively preventing malicious attacks, logic vulnerabilities, data leakage, and compliance issues, and enhancing the security and reliability of software development. Background Art

[0002] With the rapid development of information technology, the security of software systems has increasingly become the focus of attention of enterprises and organizations. During the software development process, there are many potential security threats, such as malicious code injection, logic vulnerabilities, data leakage, etc. At the same time, issues related to developer authentication and permission management also directly affect the security of the development environment. In addition, with the gradual increase in compliance requirements, security compliance checks during the development process have also become a necessary link.

[0003] Existing computer software development protection measures are mostly single means, lacking comprehensive, automated, and real-time protection solutions, and unable to effectively cope with various security threats. Therefore, it is particularly urgent to develop a comprehensive computer software development auxiliary protection system with multiple protection mechanisms. Summary of the Invention

[0004] The purpose of the present invention is to provide an auxiliary protection system for computer software development, which can detect and protect various potential security problems during the development process in real time through the collaborative work of multiple protection modules. The system comprehensively ensures code security, developer permission management, and compliance requirements during the development process through means such as code security protection, multi-factor authentication, data stream encryption, behavior auditing, and compliance detection.

[0005] The technical solution of the present invention includes the following content:

[0006] Code security protection module: This module adopts a dual detection mechanism of static syntax tree analysis and dynamic sandbox simulation, and can identify logic vulnerabilities and malicious injection behaviors in the code. It specifically includes a static analysis unit and a dynamic sandbox unit. The static analysis unit parses the abstract syntax tree (AST) to detect code structure defects and generates a risk rating in conjunction with the CWE vulnerability database; the dynamic sandbox unit simulates the operation of the code in an isolated environment to capture runtime risks such as memory leaks and out-of-bounds access.

[0007] Multi-factor authentication module: This module integrates multiple authentication methods such as dynamic password verification, developer IP address binding and biometric identification to control the access rights of the development environment. Specifically, it includes a dynamic token generation submodule and an IP whitelist submodule. The dynamic token generation submodule generates a one-time verification code based on the developer's identity and timestamp to enhance the security of identity authentication; the IP whitelist submodule restricts access to sensitive development resources to authorized IP segments only, preventing unauthorized access from the source.

[0008] Data stream encryption unit: This unit uses a hybrid encryption protocol based on elliptic curve cryptography (ECC) and the national SM4 algorithm to segment and encrypt source code, compiled products, and communication data during the development process. By using a high-strength encryption algorithm, it ensures the security of data transmission and storage during the development process and prevents sensitive data leakage.

[0009] Behavior audit engine: This engine analyzes operation logs through machine learning models (such as LSTM neural network models), generates repair suggestions in real time by associating with vulnerability databases, and triggers abnormal operation rollback mechanisms. Specifically, the behavior audit engine is trained to identify abnormal behavior patterns based on historical operation data, and automatically generates a recommendation report for repairing code snippets, helping developers to discover and fix potential problems in a timely manner.

[0010] Automated compliance detection module: During the code submission phase, this module will compare industry security standards, generate compliance assessment reports, and automatically correct patches to ensure that the code complies with industry security specifications and automatically correct non-compliant code.

[0011] Additional functional modules: Static analysis unit: It performs structural analysis on the source code based on the abstract syntax tree (AST), automatically detects potential defects in the code, and generates risk ratings in conjunction with the CWE vulnerability database to help developers evaluate the security of the code.

[0012] Dynamic sandbox unit: simulates running source code in an isolated environment to capture runtime security issues such as memory leaks and out-of-bounds access to detect potential risks that may be caused by the code during execution.

[0013] Beneficial Effects

[0014] The various modules of the system work together to provide full lifecycle protection from code writing, development process to post-release. The code security protection module strengthens code quality and vulnerability repair, the multi-factor authentication module ensures access security to the development environment, the data stream encryption unit ensures encryption protection of sensitive data, the behavior audit engine detects anomalies in real time through machine learning and provides repair suggestions, and the automated compliance detection module ensures code compliance. All these functions combined provide all-round security protection for software development. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 This is the system schematic diagram of the computer software development auxiliary protection system of the present invention. Detailed implementation manners

[0016] The present invention will be described in detail below in conjunction with the accompanying drawings and specific embodiments:

[0017] Implementation of the code security protection module

[0018] The code security protection module includes a static analysis unit and a dynamic sandbox unit. The static analysis unit parses the source code through an Abstract Syntax Tree (AST), detects potential logical vulnerabilities and syntax errors, and links with the CWE vulnerability database to generate a vulnerability risk rating. The dynamic sandbox unit will simulate the operation of the code in an isolated environment to capture potential runtime risks such as memory leaks and out-of-bounds access. The two complement each other and can cover various security issues that may occur during the software development process.

[0019] Implementation of the multi-factor authentication module

[0020] This module provides strict access control for the development environment through a dynamic token generation sub-module, an IP whitelist sub-module, and a biometric recognition function. The dynamic token generation sub-module generates a one-time verification code based on the developer's identity and timestamp to ensure the uniqueness and timeliness of each login verification. The IP whitelist sub-module restricts access by setting an authorized IP segment, allowing only developers from the specified IP segment to access sensitive resources. Biometric recognition further enhances the security of developer identity verification and prevents malicious attackers from impersonating others.

[0021] Implementation of the data stream encryption unit

[0022] The data stream encryption unit adopts a hybrid encryption protocol, including a combination of Elliptic Curve Cryptography (ECC) and the national cipher SM4 algorithm. The ECC algorithm is used for the encryption of source code and compilation products, while the SM4 algorithm is mainly applied to the encryption of communication data. Through segmented encryption, it ensures that data transmission and storage during the development process are fully protected.

[0023] Implementation of the behavior audit engine

[0024] The behavior audit engine analyzes the operation logs during the development process in real time through a machine learning model to identify and correlate abnormal behaviors. This engine is based on the LSTM neural network model and identifies potential abnormal operation patterns by training historical operation data. When an abnormal behavior is detected, the system will generate a suggestion report containing repair code snippets and trigger an abnormal operation rollback mechanism according to the rules to ensure the stability and security of the system.

[0025] Implementation of the Automated Compliance Detection Module

[0026] During the code submission phase, the automated compliance detection module compares the developed code with industry security standards. By automatically generating a compliance assessment report, developers can clearly understand whether the code meets the security requirements. If any non-compliant parts are found, the system will automatically generate a correction patch to ensure that the code always complies with industry security specifications.

[0027] Through the integration of various technical means, the present invention realizes comprehensive protection during the computer software development process, ensuring code security, developer privilege management, data encryption, and compliance review during the development process. This system can not only detect and protect against various security threats in real time, but also help the development team discover and fix potential security problems through behavior auditing and automated compliance detection.

[0028] In the description of this specification, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of this application, "a plurality" means at least two, such as two, three, etc., unless otherwise specifically and clearly defined.

[0029] In the description of this specification, the description referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0030] Although the embodiments of this application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting this application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.

Claims

1. A computer software development auxiliary protection system, characterized in that: include: Code security protection module, which is used to identify logical vulnerabilities and malicious injection behaviors in the code through a dual detection mechanism of static syntax tree analysis and dynamic sandbox simulation; Multi-factor authentication module, integrating dynamic password verification, developer IP address binding and biometric identification to control access rights to the development environment; The data stream encryption unit uses a hybrid encryption protocol based on elliptic curve cryptography (ECC) and the national secret SM4 algorithm to segmentally encrypt source code, compiled products, and communication data during the development process; The behavior audit engine analyzes operation logs through machine learning models, associates them with the vulnerability database in real time to generate repair suggestions, and triggers an abnormal operation rollback mechanism.

2. A computer software development auxiliary protection system according to claim 1, characterized in that: The code security protection module includes: Static analysis unit, which detects code structure defects based on abstract syntax tree (AST) parsing and generates risk ratings in conjunction with the CWE vulnerability database; Dynamic sandbox unit simulates running code in an isolated environment to capture risks such as memory leaks and out-of-bounds access to runtime.

3. A computer software development auxiliary protection system according to claim 1, characterized in that: The multi-factor authentication module further comprises: Dynamic token generation submodule, which generates a one-time verification code based on the developer's identity and timestamp; The IP whitelist submodule restricts access to sensitive development resources to authorized IP segments only.

4. A computer software development auxiliary protection system according to claim 1, characterized in that: The behavior audit engine has a built-in LSTM neural network model, which is trained through historical operation data to identify abnormal behavior patterns and automatically generates a report containing suggestions for repairing code snippets.

5. A computer software development auxiliary protection system according to claim 1, characterized in that: It also includes an automated compliance detection module that compares industry security standards during the code submission phase, generates compliance assessment reports, and automatically corrects patches.