Software vulnerability detection method and system based on expert knowledge optimization
By preprocessing the software source code and slice extraction of expert knowledge optimization, and combining with the preset prompt word training model, the problem of low accuracy of existing software vulnerability detection tools is solved, and more efficient vulnerability detection is achieved.
Patent Information
- Application Number
- CN202510565840.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-07-11
AI Technical Summary
The existing software vulnerability detection tools have low detection accuracy and poor detection results, making it difficult to effectively identify and locate vulnerabilities.
By preprocessing the program source code text of the software to be tested, the vulnerability code feature semantic information is obtained by using expert knowledge analysis to obtain the vulnerability code feature semantic information for slice extraction, and the vulnerability detection model is trained in combination with preset prompt words to optimize the code text slicing to improve the accuracy of vulnerability detection.
While ensuring the integrity of vulnerability information, it reduces irrelevant information in slices, improves the accuracy and efficiency of software vulnerability detection, and improves the accuracy and effectiveness of vulnerability detection.
Smart Images

Figure CN120296748A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of application security. More specifically, it relates to a software vulnerability detection method and system optimized based on expert knowledge. Background Art
[0002] Software vulnerabilities have always been the main problem faced by network application security. Although people have taken various measures to fix vulnerabilities, according to the report of the Common Vulnerabilities and Exposures (CVE), there are still a large number of unresolved vulnerabilities. Timely detecting vulnerabilities and patching them is the key means to eliminate vulnerabilities. Ideally, vulnerability detection tools should have high accuracy, low false negative rate, low false positive rate, and be able to accurately locate the positions of vulnerabilities. However, existing vulnerability detection tools cannot achieve satisfactory results.
[0003] For example, for existing deep learning-based static vulnerability detection methods, there are still many problems with the proposed slice-level detection method. The slice-level detection method decomposes the code into independent code slices and uses a deep learning model to learn the features and vulnerability patterns of each slice to achieve the purpose of software vulnerability detection. However, the vulnerability information contained in the extracted slices is often incomplete and contains a lot of vulnerability-irrelevant information, making it difficult for the model to learn accurate vulnerability patterns, resulting in low accuracy and poor detection effect of software vulnerability detection.
[0004] Therefore, how to better achieve software vulnerability detection has become an urgent technical problem in the industry. Summary of the Invention
[0005] Aiming at the defects of the existing technology, the purpose of this application is to better achieve software vulnerability detection, aiming to solve the problems of low accuracy and poor detection effect of software vulnerability detection existing in existing vulnerability detection tools.
[0006] To achieve the above purpose, in the first aspect, this application provides a software vulnerability detection method optimized based on expert knowledge, including: Preprocess the program source code text of the software to be tested, and determine each suspected vulnerability code statement in the program source code text; Extract slices for each suspected vulnerability code statement by using the semantic information of vulnerability code features. The obtained code text slices correspond to each suspected vulnerability code statement; the semantic information of vulnerability code features is analyzed based on expert knowledge; Input each of the sliced code texts and the first preset prompt word into a vulnerability detection model to obtain the vulnerability detection report information of the software to be tested output by the vulnerability detection model; the vulnerability detection model is trained on a code large model according to the first preset prompt word, as well as code text slice samples and their corresponding vulnerability labels and preset vulnerability report texts.
[0007] Optionally, the slicing and extraction of each suspected vulnerability code statement using the semantic information of vulnerability code features to obtain the code text slice corresponding to each suspected vulnerability code statement includes: Based on each suspected vulnerability code statement, determine the corresponding suspected vulnerability node in the program dependence graph corresponding to the program source code text; Slice the program dependence graph with each suspected vulnerability node as the starting node to obtain the sliced subgraph corresponding to each suspected vulnerability code statement; Truncate each sliced subgraph according to the semantic information of vulnerability code features to obtain the optimized sliced subgraph corresponding to each suspected vulnerability code statement; Map each optimized sliced subgraph to the program source code text respectively to obtain the code text slice corresponding to each suspected vulnerability code statement.
[0008] Optionally, the semantic information of vulnerability code features includes semantic information of vulnerability-triggering code features and semantic information of vulnerability root cause code features; the truncating each sliced subgraph according to the semantic information of vulnerability code features to obtain the optimized sliced subgraph corresponding to each suspected vulnerability code statement includes: In the sliced subgraph corresponding to each suspected vulnerability code statement, locate multiple vulnerability-triggering nodes corresponding to the semantic information of vulnerability-triggering code features and multiple vulnerability root cause nodes corresponding to the semantic information of vulnerability root cause code features; In the sliced subgraph corresponding to each suspected vulnerability code statement, truncate from the vulnerability-triggering node farthest from the suspected vulnerability node and truncate from the vulnerability root cause node closest to the suspected vulnerability node to obtain the optimized sliced subgraph corresponding to each suspected vulnerability code statement.
[0009] Optionally, the slicing the program dependence graph with each suspected vulnerability node as the starting node to obtain the sliced subgraph corresponding to each suspected vulnerability code statement includes: Taking each suspected vulnerability node as the starting node, traverse along the data dependence edge direction in the program dependence graph respectively to obtain the forward subgraph starting from each suspected vulnerability node; Taking each of the suspected vulnerability nodes as a starting node, traverse in the reverse direction of the data dependence edges in the program dependence graph to obtain a backward subgraph starting from each of the suspected vulnerability nodes; Merge the forward subgraph and the backward subgraph corresponding to each of the suspected vulnerability nodes to obtain a slice subgraph corresponding to each of the suspected vulnerability code statements.
[0010] Optionally, the preprocessing of the program source code text of the software to be tested to determine each suspected vulnerability code statement in the program source code text includes: Slice the program source code text of the software to be tested at the program function granularity to obtain multiple function code text segments corresponding to the software to be tested; Locate the vulnerability statements based on the multiple function code text segments to determine each suspected vulnerability code statement in the program source code text.
[0011] Optionally, the locating the vulnerability statements based on the multiple function code text segments to determine each suspected vulnerability code statement in the program source code text includes: Input the multiple function code text segments and a second preset prompt word into a preset general large model to obtain each suspected vulnerability code statement in the program source code text output by the preset general large model; The second preset prompt word is designed based on different program vulnerability types.
[0012] Optionally, before inputting each of the code text slices and a first preset prompt word into the vulnerability detection model to obtain the vulnerability detection report information of the software to be tested output by the vulnerability detection model, the method further includes: Obtain a dataset of vulnerability code text samples with patch information; Preprocess each vulnerability code text sample in the dataset of vulnerability code text samples to determine each suspected vulnerability code statement in each vulnerability code text sample; Use the semantic information of the vulnerability code features to extract slices of each suspected vulnerability code statement in each vulnerability code text sample to obtain a dataset of code text slice samples corresponding to each vulnerability code text sample, and label them with the patch information of each vulnerability code text sample to obtain a vulnerability label dataset corresponding to each dataset of code text slice samples; Determine each code text slice sample and its corresponding vulnerability label according to each dataset of code text slice samples and its corresponding vulnerability label dataset, and use the first preset prompt word, as well as each code text slice sample and its corresponding vulnerability label and a preset vulnerability report text as a set of training samples to obtain multiple sets of training samples; Fine-tune and train the code large model using the multiple sets of training samples to obtain a trained vulnerability detection model.
[0013] In a second aspect, the present application provides a software vulnerability detection system optimized based on expert knowledge, including: A preprocessing module for preprocessing the program source code text of the software to be tested and determining each suspected vulnerability code statement in the program source code text; A slicing module for slicing and extracting each of the suspected vulnerability code statements using the semantic information of vulnerability code features to obtain a code text slice corresponding to each of the suspected vulnerability code statements; the semantic information of vulnerability code features is obtained by analyzing expert knowledge; A detection module for inputting each of the code text slices and a first preset prompt word into the vulnerability detection model to obtain the vulnerability detection report information of the software to be tested output by the vulnerability detection model; the vulnerability detection model is trained on the code large model based on the first preset prompt word, as well as the code text slice samples and their corresponding vulnerability labels and preset vulnerability report texts.
[0014] In a third aspect, the present application provides an electronic device, including: at least one memory for storing a program; at least one processor for executing the program stored in the memory, and when the program stored in the memory is executed, the processor is used to execute the method described in the first aspect or any one of the possible implementation manners of the first aspect.
[0015] In a fourth aspect, the present application provides a computer-readable storage medium storing a computer program, and when the computer program runs on a processor, it causes the processor to execute the method described in the first aspect or any one of the possible implementation manners of the first aspect.
[0016] In a fifth aspect, the present application provides a computer program product, and when the computer program product runs on a processor, it causes the processor to execute the method described in the first aspect or any one of the possible implementation manners of the first aspect.
[0017] It can be understood that the beneficial effects of the above second aspect to fifth aspect can refer to the relevant descriptions in the first aspect above, and will not be elaborated here.
[0018] Generally speaking, compared with the prior art through the above technical solutions conceived by the present application, the following beneficial effects are obtained: A software vulnerability detection method and system optimized based on expert knowledge provided by this application, by considering the rich vulnerability-related knowledge of vulnerability experts, using expert knowledge analysis to obtain semantic information of vulnerability code features and integrating it into code text slices, can reduce the information unrelated to vulnerabilities in the slices while ensuring the integrity of vulnerability information in the code text slices; at the same time, by pre-screening each suspected vulnerability code statement in the source code text of the software program to be tested, and then slicing each suspected vulnerability code statement, the number of slices can be further reduced, and a code large model trained with code text slice samples is used to perform inference and prediction on each code text slice, which can improve the efficiency of software vulnerability detection while effectively improving the accuracy and detection effect of software vulnerability detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 is one of the flow schematic diagrams of the software vulnerability detection method optimized based on expert knowledge provided by an embodiment of this application; Figure 2 is the flow schematic diagram of locating suspected vulnerability code statements in the software vulnerability detection method provided by an embodiment of this application; Figure 3 is the flow schematic diagram of program code slicing in the software vulnerability detection method provided by an embodiment of this application; Figure 4 is the second flow schematic diagram of the software vulnerability detection method optimized based on expert knowledge provided by an embodiment of this application; Figure 5 is the structural schematic diagram of the software intelligent vulnerability detection system provided by an embodiment of this application; Figure 6 is the structural schematic diagram of the software vulnerability detection system optimized based on expert knowledge provided by an embodiment of this application; Figure 7 is the structural schematic diagram of the electronic device provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] In order to make the objectives, technical solutions and advantages of this application clearer, the following further describes this application in detail with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.
[0021] The terms "first" and "second" in the description and claims of this application are used to distinguish different objects, rather than to describe a specific order of the objects. For example, the first preset prompt word and the second preset prompt word are used to distinguish different preset prompt words, rather than to describe the specific order of the preset prompt words.
[0022] In the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0023] In the description of the embodiments of the present application, unless otherwise specified, "a plurality of" means two or more. For example, a plurality of vulnerability trigger nodes means two or more vulnerability trigger nodes, etc.
[0024] The embodiments of the present application will be described below with reference to the accompanying drawings in the embodiments of the present application.
[0025] Figure 1 is one of the flow diagrams of the software vulnerability detection method optimized based on expert knowledge provided by the embodiments of the present application. As Figure 1 shown, it includes: Step S1: Preprocess the program source code text of the software to be tested, and determine each suspected vulnerability code statement in the program source code text; Step S2: Use the semantic information of vulnerability code features to slice and extract each suspected vulnerability code statement to obtain a code text slice corresponding to each suspected vulnerability code statement; the semantic information of vulnerability code features is analyzed and obtained based on expert knowledge; Step S3: Input each code text slice and a first preset prompt word into the vulnerability detection model to obtain the vulnerability detection report information of the software to be tested output by the vulnerability detection model; the vulnerability detection model is trained on the code large model according to the first preset prompt word, as well as the code text slice samples and their corresponding vulnerability labels and preset vulnerability report texts.
[0026] Specifically, the suspected vulnerability code statements described in the embodiments of the present application refer to statements or code fragments that may have security vulnerabilities in the program source code of the software to be tested.
[0027] The semantic information of vulnerability code features described in the embodiments of the present application is the code feature semantics closely related to vulnerabilities analyzed and summarized based on expert knowledge. Specifically, it can be the semantic information of the root cause code of vulnerabilities (i.e., the code where vulnerability taint data is generated) and the vulnerability trigger code where taint data causes vulnerability triggers summarized using the taint analysis idea in expert knowledge.
[0028] The first preset prompt word described in the embodiments of the present application refers to a prompt word designed in advance according to the vulnerability principle and vulnerability code characteristics and generated in combination with the corresponding prompt word template, which is used to guide the code large model to perform high-quality vulnerability detection and generate a high-quality vulnerability detection report that meets expectations.
[0029] In the embodiments of the present application, in step S1, prompt engineering can be used to preprocess the program source code text of the software to be tested. By designing natural language prompts, the generative AI model is guided to perform reasoning and analysis on the program source code text, and each suspected vulnerability code statement is located from the program source code text.
[0030] In the embodiments of the present application, in step S2, the semantic information of the vulnerability code characteristics obtained by analyzing with expert knowledge is further used to perform slice extraction and optimization on each suspected vulnerability code statement, and the code text slice corresponding to each suspected vulnerability code statement can be obtained.
[0031] Furthermore, in the embodiments of the present application, in step S3, the code large model can be trained in advance using the designed first preset prompt word, as well as the code text slice samples and their corresponding vulnerability labels and preset vulnerability report texts, to obtain a trained vulnerability detection model. Each code text slice obtained in the foregoing steps and the pre-prepared first preset prompt word are input into the vulnerability detection model. After the reasoning analysis and report generation of the vulnerability detection model, the vulnerability detection report information of the software to be tested is obtained.
[0032] The software vulnerability detection method based on expert knowledge optimization in the embodiments of the present application, by considering the rich vulnerability-related knowledge of vulnerability experts and using the semantic information of the vulnerability code characteristics obtained by analyzing with expert knowledge to be incorporated into the code text slices, can reduce the information unrelated to the vulnerability in the slices while ensuring the integrity of the vulnerability information in the code text slices; at the same time, by pre-screening each suspected vulnerability code statement in the program source code text of the software to be tested and then slicing each suspected vulnerability code statement, the number of slices can be further reduced, and the code large model trained with the code text slice samples is used to perform reasoning and prediction on each code text slice, which can effectively improve the accuracy and detection effect of software vulnerability detection while improving the software vulnerability detection efficiency.
[0033] Based on the content of the above embodiments, as an optional embodiment, preprocessing the program source code text of the software to be tested and determining each suspected vulnerability code statement in the program source code text includes: The program source code text of the software to be tested is segmented according to the program function granularity to obtain multiple function code text segments corresponding to the software to be tested; The vulnerability statements are located based on multiple function code text fragments to determine each suspected vulnerability code statement in the program source code text.
[0034] Specifically, in the embodiment of the present application, the specific implementation method of preprocessing the program source code text of the software to be tested is as follows: First, the program source code text of the software to be tested is segmented according to the program function granularity to obtain multiple function code text fragments corresponding to the software to be tested. Figure 2 As shown, by splitting the function at the function level granularity, the code text fragment corresponding to the interrupt function "i8042_interrupt" is obtained.
[0035] Furthermore, in an embodiment of the present application, a general large model can be used to locate vulnerability statements based on multiple function code text fragments, and identify each suspected vulnerability code statement in the program source code text.
[0036] The method of the embodiment of the present application can improve the accuracy of locating suspected vulnerability code statements by segmenting the program source code text of the software to be tested according to the granularity of program functions, and using prompt engineering to allow the general large model to infer and locate vulnerability statement features for each segmented function code text fragment, thereby providing reliable basic data for subsequent code slicing.
[0037] Based on the content of the above embodiment, as an optional embodiment, vulnerability statements are located according to multiple function code text fragments to determine each suspected vulnerability code statement in the program source code text, including: Inputting multiple function code text fragments and a second preset prompt word into a preset general large model to obtain each suspected vulnerability code statement in the program source code text output by the preset general large model; The second preset prompt word is designed based on different program vulnerability types.
[0038] Specifically, the second preset prompt word described in the embodiment of the present application refers to a prompt word designed in advance according to different program vulnerability types and in combination with expert knowledge.
[0039] It should be noted that there are multiple cases of suspected vulnerability code statements for each vulnerability type. According to the characteristics of the vulnerability type, prompt words are designed based on expert knowledge, such as vulnerability root cause code statements or vulnerability trigger code statements. A small number of samples are provided for each case to assist the general large model in identifying suspected vulnerability code statements.
[0040] Here, the preset prompt words in this embodiment may include three parts: 1) Specify the current role of the big model: vulnerability auditor or vulnerability code analysis expert; 2) Introduce the principle of the type of vulnerability to be checked and the characteristics of the vulnerable code; 3) Give a task instruction, requiring the model to locate the statements with the above types of vulnerabilities in the given function and answer in JSON format.
[0041] As Figure 2 shown, the template adopted by the second preset prompt word can be expressed as: "You are a C / C++ code auditor, I will give you a function code and you should analyze what the function achieves first. Find the presence of null pointer statements and specific null pointer variables in a function by referring to whether the statement satisfies one of the following conditions. Condition 1: the statement performs an assignment operation on a pointer variable and the value assigned is null pointer …… Condition2: …… #function code: …… Please answer in the following json format ……" For general large models, parameters need to be carefully designed to ensure the accuracy of the model's answers. Using the framework of prompt engineering, ensure that the model outputs the function name, the statements with suspected vulnerabilities, and the key variable information that determines the vulnerability in the statements in a specific format. If the model has hallucinations and cannot answer according to the instructions, it needs to be re-questioned until the model outputs an answer in the specified format.
[0042] Among them, the key variable information refers to the information associated with the type of vulnerability, which determines whether the code statement has a vulnerability.
[0043] Further, input multiple function code text fragments and a second preset prompt word into a preset general large model to obtain each suspected vulnerability code statement in the program source code text output by the preset general large model. Specifically, for each processed function code text fragment, a corresponding set of second preset prompt words can be generated according to the vulnerability type in the aforementioned manner. For example, Figure 2 as shown, traverse and select the vulnerability type corresponding to "CWE-476" from the CWE vulnerability type library. According to this vulnerability type, combine the corresponding prompt word template to generate the second preset prompt word. Furthermore, after setting the parameters of the general large model, submit the function code text fragment and the corresponding second preset prompt word, and output the results in JSON format, including function name, vulnerability type, suspected vulnerability code statement, and key variable information related to the vulnerability type in the statement, etc.
[0044] Among them, the CWE type refers to the software weakness type defined in "Common Weakness Enumeration", which provides a standardized way to describe the weaknesses in software, enabling security experts, developers, and users to uniformly refer to and discuss the same weakness.
[0045] The method of the embodiment of the present application can further improve the accuracy and reliability of locating suspected vulnerability code statements by designing prompt words based on the characteristics of the vulnerability type in combination with expert knowledge and using a general large model to locate each suspected vulnerability code statement from the program source code text.
[0046] Based on the content of the above embodiment, as an optional embodiment, slice extraction is performed on each suspected vulnerability code statement according to the semantic information of the vulnerability code characteristics to obtain the code text slice corresponding to each suspected vulnerability code statement, including: Based on each suspected vulnerability code statement, determine the corresponding suspected vulnerability node in the program dependence graph corresponding to the program source code text; Slice the program dependence graph with each suspected vulnerability node as the starting node to obtain the sliced subgraph corresponding to each suspected vulnerability code statement; Perform truncation processing on each sliced subgraph according to the semantic information of the vulnerability code characteristics to obtain the optimized sliced subgraph corresponding to each suspected vulnerability code statement; Map each optimized sliced subgraph to the program source code text respectively to obtain the code text slice corresponding to each suspected vulnerability code statement.
[0047] Specifically, the sliced subgraph described in the embodiment of the present application refers to the graphical representation of the suspected vulnerability code statement mapped to the program dependence graph through intermediate language instructions.
[0048] In the embodiments of the present application, a source code program analysis tool can be used to obtain a function call graph and a program dependency graph based on the program source code text of the software to be tested. Taking the Static Value Flow Graph (SVFG) in the LLVM compiler framework as an example, it is a graphical representation method for static analysis. SVFG is widely used in program analysis, especially in aspects such as software security, performance optimization, and code understanding. SVFG can represent a program as a graph, where nodes represent various elements in the program (such as functions, variables, statements, etc.), and edges represent the relationships between them. SVFG captures the value flow relationships in the code in the form of a graph. SVFG emphasizes the transfer and flow of values in the program, which helps to understand the dependency relationships and data flow between variables, and is also the key to analyzing vulnerabilities in the program, optimizing performance, or understanding the code.
[0049] Specifically, first, compile the software program to be tested to generate an intermediate language file. Through the intermediate language file, map each suspected vulnerability code statement located in the source code text of the software program to be tested to the intermediate language instructions one by one. At the same time, use a program analysis tool to obtain the program dependency graph corresponding to the intermediate language instructions of the software program to be tested at the intermediate language level, and locate the suspected vulnerability code statements on the program dependency graph.
[0050] More specifically, determine the line number in the source code file according to the suspected vulnerability code statement. Then, map the suspected vulnerability code statement on the source code to the intermediate language instructions according to the file name, function name, and line number, and then map the corresponding instruction value to the nodes on the program dependency graph. Thus, the suspected vulnerability nodes corresponding to each suspected vulnerability code statement can be determined in the program dependency graph.
[0051] Furthermore, in the embodiments of the present application, taking each suspected vulnerability node as the starting node, use the control dependency and data dependency in the program dependency graph to perform forward and backward slicing on the program dependency graph, and slice the program dependency graph to obtain the slice subgraph corresponding to each suspected vulnerability code statement.
[0052] Based on the content of the above embodiments, as an optional embodiment, slicing the program dependency graph with each suspected vulnerability node as the starting node to obtain the slice subgraph corresponding to each suspected vulnerability code statement includes: Taking each suspected vulnerability node as the starting node, traverse along the direction of the data dependency edges in the program dependency graph respectively to obtain the forward subgraph starting from each suspected vulnerability node; Taking each suspected vulnerability node as the starting node, traverse along the reverse direction of the data dependency edges in the program dependency graph to obtain the backward subgraph starting from each suspected vulnerability node; Merge the forward subgraph and the backward subgraph corresponding to each suspected vulnerability node to obtain a sliced subgraph corresponding to each suspected vulnerability code statement.
[0053] Specifically, in the embodiment of the present application, for each suspected vulnerability statement, taking the corresponding suspected vulnerability node as the starting node, perform a depth-first traversal along the direction of the data dependence edge in the program dependence graph from the current position of this node, and a forward subgraph starting from the suspected vulnerability node can be obtained.
[0054] Furthermore, in the embodiment of the present application, taking each suspected vulnerability node as the starting node and traversing along the reverse direction of the data dependence edge in the program dependence graph, a backward subgraph starting from each suspected vulnerability node can be obtained.
[0055] Finally, merge the forward subgraph and the backward subgraph corresponding to each suspected vulnerability node, output the complete subgraph, and thus a sliced subgraph corresponding to each suspected vulnerability code statement can be obtained.
[0056] The method of the embodiment of the present application is different from the previous method that only considers forward slicing from the vulnerability source point or backward slicing towards the vulnerability source point. By using both control dependence and data dependence in the program dependence graph for forward and backward slicing simultaneously, it can better ensure the integrity of vulnerability-related information in the slice, which is beneficial to improving the accuracy of subsequent software vulnerability detection.
[0057] Furthermore, in the embodiment of the present application, truncate each sliced subgraph according to the semantic information of the vulnerability code features determined by expert knowledge to obtain an optimized sliced subgraph corresponding to each suspected vulnerability code statement.
[0058] Based on the content of the above embodiment, as an alternative embodiment, the semantic information of the vulnerability code features includes the semantic information of the vulnerability-triggering code features and the semantic information of the vulnerability root cause code features; using the semantic information of the vulnerability code features to truncate the sliced subgraph corresponding to each suspected vulnerability code statement to obtain an optimized sliced subgraph corresponding to each suspected vulnerability code statement includes: In the sliced subgraph corresponding to each suspected vulnerability code statement, locate multiple vulnerability-triggering nodes corresponding to the semantic information of the vulnerability-triggering code features and multiple vulnerability root cause nodes corresponding to the semantic information of the vulnerability root cause code features; In the sliced subgraph corresponding to each suspected vulnerability code statement, truncate from the vulnerability-triggering node farthest from the suspected vulnerability node and truncate from the vulnerability root cause node closest to the suspected vulnerability node to obtain an optimized sliced subgraph corresponding to each suspected vulnerability code statement.
[0059] Specifically, the vulnerability code feature semantic information described in the embodiments of the present application includes vulnerability trigger code feature semantic information and vulnerability root cause code feature semantic information, which can be specifically obtained by summarizing vulnerability trigger code features and vulnerability root cause code features based on the taint analysis idea and combining expert rules.
[0060] Among them, the vulnerability trigger code feature semantic information refers to the text semantic information of the code in the program code that triggers the vulnerability behavior; the vulnerability root cause code feature semantic information refers to the text semantic information of the root cause code in the program code that causes the vulnerability behavior.
[0061] More specifically, using the syntax semantic information of the vulnerability code features to locate and truncate the feature statements in the slice subgraph to complete slice optimization, specifically including the following steps: First, according to the vulnerability trigger code feature semantic information and vulnerability root cause code feature semantic information summarized by expert knowledge, use the code syntax semantic information in the abstract syntax tree to map the vulnerability trigger code features and vulnerability root cause code features to the code statements, and locate the vulnerability trigger code and vulnerability root cause code.
[0062] Second, through the intermediate language instructions, locate multiple vulnerability trigger nodes corresponding to the vulnerability trigger code in the slice subgraph, and multiple vulnerability root cause nodes corresponding to the vulnerability root cause code, that is, obtain multiple vulnerability trigger nodes corresponding to the vulnerability trigger code feature semantic information, and multiple vulnerability root cause nodes corresponding to the vulnerability root cause code feature semantic information.
[0063] Finally, truncate the slice subgraph corresponding to each suspected vulnerability code statement. Specifically, in the slice subgraph corresponding to each suspected vulnerability code statement, since it is in the static analysis scenario, the nearest vulnerability trigger node may not necessarily trigger the vulnerability behavior. Therefore, it is necessary to truncate from the vulnerability trigger node farthest from the suspected vulnerability node.
[0064] At the same time, the vulnerability root cause is the fundamental reason for the vulnerability behavior, which is manifested as different assignments in the program code. In program execution, the assignment of the nearest vulnerability root cause node will overwrite the assignment of the distant vulnerability root cause node. Therefore, it is only necessary to truncate from the vulnerability root cause node closest to the suspected vulnerability node. Finally, through the above front and back truncation operations, an optimized slice subgraph corresponding to each suspected vulnerability code statement can be obtained.
[0065] The method of the embodiments of the present application optimizes the code slice by using expert knowledge, and integrates the vulnerability trigger code features and vulnerability root cause code features summarized by expert knowledge into the slice information corresponding to the suspected vulnerability code statements, which can not only ensure the integrity of the vulnerability information, but also improve the conciseness of the slice subgraph data, and is beneficial to further improving the accuracy and efficiency of subsequent software vulnerability detection.
[0066] Furthermore, in an embodiment of the present application, each optimized slice subgraph is respectively mapped to the program source code text of the software to be tested to obtain a code text slice corresponding to each suspected vulnerability code statement.
[0067] Figure 3 is a flow chart of program code slicing in the software vulnerability detection method provided in the embodiment of the present application, such as Figure 3 As shown, in an embodiment of the present application, the process includes: Step 1) generating a program dependency graph. Here, a program analysis tool can be used to generate a program dependency graph corresponding to the source code text of the software program to be tested at the intermediate language level. Step 2) Locate suspected vulnerability nodes. Here, an intermediate language file can be generated by compiling the software program to be tested. Through the intermediate language file, the suspected vulnerability code statements located in the source code text of the software program to be tested are mapped one by one to the intermediate language instructions, and through instruction value mapping, the suspected vulnerability nodes corresponding to each suspected vulnerability code statement are located on the program dependency graph.
[0068] Step 3) Slice forward to the vulnerability trigger node. Here, each suspected vulnerability node can be sliced forward and backward from the current node in the project to obtain a slice subgraph. Locate the vulnerability trigger node farthest from the suspected vulnerability node in the forward slice, truncate from this position, and delete the subsequent forward slices; Step 4) Slice backward to the vulnerability root cause node. Here, you can further match the vulnerability root node closest to the suspected vulnerability node in the backward slice and truncate from this position; Step 5) Get the intermediate language slice. Here, following step 4), you can finally retain the intermediate language slice between the nearest vulnerability root cause node and the farthest vulnerability trigger node, that is, get the optimized slice subgraph; Step 6) Get the code text slice. Finally, map each optimized slice subgraph to the program source code text of the software to be tested to get the code text slice corresponding to each suspected vulnerability code statement.
[0069] The method of the embodiment of the present application combines expert knowledge in the vulnerability detection field and program static analysis technology to slice and extract each suspected vulnerability code statement, so that the extracted code text slices can contain more complete and accurate vulnerability-related codes as much as possible, which is conducive to improving the effect of vulnerability detection on real software and accurately reporting the vulnerability triggering code lines.
[0070] Based on the content of the above embodiment, as an optional embodiment, before inputting each code text slice and the first preset prompt word into the vulnerability detection model to obtain the vulnerability detection report information of the software to be tested output by the vulnerability detection model, the method further includes: Get a sample dataset of vulnerability code text with patch information; Preprocess each vulnerability code text sample in the vulnerability code text sample dataset to determine each suspected vulnerability code statement in each vulnerability code text sample; Use the semantic information of vulnerability code features to slice and extract each suspected vulnerability code statement in each vulnerability code text sample, obtaining a dataset of code text slice samples corresponding to each vulnerability code text sample, and label it with the patch information of each vulnerability code text sample to obtain a vulnerability label dataset corresponding to each dataset of code text slice samples; Based on each dataset of code text slice samples and its corresponding vulnerability label dataset, determine each code text slice sample and its corresponding vulnerability label, and use the first preset prompt word, each code text slice sample and its corresponding vulnerability label, and the preset vulnerability report text as a set of training samples to obtain multiple sets of training samples; Use multiple sets of training samples to fine-tune and train the code large model to obtain a trained vulnerability detection model.
[0071] Specifically, in the embodiments of the present application, before using the vulnerability detection model to detect software vulnerabilities, it is also necessary to pre-train the vulnerability detection model in advance to obtain a trained vulnerability detection model.
[0072] More specifically, first, a dataset of vulnerability code text samples with patch information can be obtained through public security databases and platforms. For the dataset of vulnerability code text samples, each vulnerability code text sample in the dataset of vulnerability code text samples can be preprocessed by using prompt engineering in the manner of the foregoing embodiments to determine each suspected vulnerability code statement in each vulnerability code text sample.
[0073] Furthermore, in accordance with the foregoing implementation manner of code text slice generation, using the semantic information of vulnerability code features obtained by expert knowledge analysis, for each suspected vulnerability code statement in each vulnerability code text sample, forward slicing and backward slicing are performed in its corresponding program dependence graph, and each sliced subgraph is optimized, and each optimized sliced subgraph is respectively mapped into the vulnerability code text sample to obtain the corresponding code text slice sample, so that a dataset of code text slice samples corresponding to each vulnerability code text sample can be obtained.
[0074] Furthermore, in the embodiments of the present application, each processed code text slice sample is labeled with the patch information of each vulnerability code text sample. Samples containing the code before patch modification are vulnerable, and samples containing the code after patch modification are not vulnerable. The data is structured in a question-and-answer format. The question is whether there is a vulnerability in the following slice, and the corresponding answer is the patch annotation result. Thus, a vulnerability label dataset corresponding to each dataset of code text slice samples can be finally obtained.
[0075] Further, according to each code text slice sample dataset and its corresponding vulnerability label dataset, determine each code text slice sample and its corresponding vulnerability label, and use the first preset prompt word, each code text slice sample and its corresponding vulnerability label, and the preset vulnerability report text as a set of training samples to obtain multiple sets of training samples, thereby obtaining an instruction fine-tuning dataset composed of multiple sets of training samples. Here, the preset vulnerability report text refers to the vulnerability report text written in advance according to the code text slice sample and its corresponding vulnerability label, which is used to guide the code large model to generate a vulnerability detection report text with the expected content and format.
[0076] Finally, the instruction fine-tuning dataset containing multiple sets of training samples can be used to fine-tune the code large model to obtain a trained vulnerability detection model. More specifically, the large model lightweight fine-tuning (LORA) method can be used to fine-tune the code large model, such as the Qwen-2.5-Code series models, in combination with the obtained instruction fine-tuning dataset, so as to obtain the final vulnerability detection model.
[0077] The method of the embodiment of the present application disassembles the sample processing task in an engineering, modular, and process-oriented manner, integrates domain expert knowledge into the deep learning vulnerability detection method, realizes the optimization of the sliced samples, ensures the integrity of the sliced sample data and the accuracy of the vulnerability information, and obtains a vulnerability detection model by fine-tuning the code large model using the obtained sliced training dataset, enabling the model to learn accurate vulnerability patterns and effectively improving the accuracy and effect of the code large model in software vulnerability detection.
[0078] Figure 4 It is the second flowchart of the software vulnerability detection method based on expert knowledge optimization provided by the embodiment of the present application. As Figure 4 shown, this method includes two stages: model training and vulnerability detection.
[0079] The model training stage is used to process the training program project. Input the vulnerability code text sample dataset, that is, the vulnerability dataset. Use prompt engineering to locate the suspected vulnerability statements in the dataset code, extract slices starting from this position, and finally generate code slice samples closely related to the vulnerability. Use the patch information to label the code slices with whether there is a vulnerability, so as to obtain an instruction fine-tuning dataset containing multiple sets of training samples and fine-tune the code large model.
[0080] During the vulnerability detection phase, the program data to be tested, i.e., the source code text of the software to be tested, is preprocessed, and then the same method as described above is used to locate the suspected vulnerable code statements, generate a code program slice closely related to the vulnerability, and then use the trained vulnerability detection model to classify whether there is a vulnerability in the code program slice and determine the location of the vulnerable line. Finally, a vulnerability detection report is output.
[0081] Among them, the model training phase includes: Steps to locate suspected vulnerable code: Extract the vulnerable code text samples in the vulnerable code text sample dataset by function unit to obtain function code text fragments. Design prompt words for each vulnerability type. After deploying the large model, use the prompt words to guide the model to locate the suspected vulnerable code statements in the function code text fragments, and output the results in JSON format, including function name, vulnerability type, suspected vulnerable code statements, and key variables affecting the vulnerability in the statements.
[0082] Steps to generate code slices: Compile the training program to generate an intermediate language file. Map the suspected vulnerable code statements located in the source code to the intermediate language instructions one by one, and use the program analysis tool to obtain the program dependence graph of the code at the intermediate language level and locate the suspected vulnerable code statements on the graph. Starting from the position of the suspected vulnerable node corresponding to the suspected vulnerable code statement on the graph, extract the forward and backward slices to obtain a slice subgraph.
[0083] Steps to optimize slices with expert knowledge: For each suspected vulnerable node, perform a forward slice starting from this node until the corresponding vulnerability trigger node with the farthest distance is reached, to obtain a slice subgraph from the specified suspected vulnerable node to the vulnerability trigger node; then perform a backward slice starting from the suspected vulnerable node until the corresponding vulnerability root cause node closest to it is reached, to obtain a slice subgraph from the specified suspected vulnerable node to the vulnerability root cause node. Finally, map the intermediate language instructions on the slice subgraph to the source code to obtain the code text slice samples.
[0084] Steps for sample annotation: Use the patch information in the dataset to annotate the extracted slice samples to obtain vulnerability labels, and combine the obtained code text slice samples, the first preset prompt words, and the preset vulnerability report text to obtain an instruction fine-tuning dataset.
[0085] Steps to fine-tune the large model with instructions: Use the method of large model lightweight fine-tuning (LORA) to fine-tune the code large model in combination with the obtained instruction fine-tuning dataset to obtain the final vulnerability detection model.
[0086] Among them, the vulnerability detection phase includes: Steps for preprocessing the software code library: Preprocess the program data to be tested, screen out the code files and split them according to the function-level granularity to obtain multiple corresponding function code text fragments.
[0087] Steps to locate suspected vulnerable code: For multiple input function code text fragments, design prompt words for each vulnerability type. After deploying the large model, use the prompt words to guide the model to locate the suspected vulnerable code statements in each function code text fragment, and output the results in JSON format, including the function name, vulnerability type, suspected vulnerable code statement, and key variables affecting the vulnerability in the statement.
[0088] The steps of generating code slices and optimizing slices with expert knowledge are the same as those in the code slice generation step and the expert knowledge optimization slice step in the aforementioned model training phase, and will not be elaborated here.
[0089] Vulnerability detection steps: Use the aforementioned trained vulnerability detection model to detect vulnerabilities in each code text slice output by the expert knowledge optimized slice sub-module, and output a vulnerability detection report.
[0090] Correspondingly, as Figure 5 shown, an embodiment of the present application also provides a software intelligent vulnerability detection system based on the generation of optimized samples with expert knowledge corresponding to the Figure 4 method shown, which specifically includes the following modules: A model training module for processing training program projects. Input the vulnerable code text sample data set, that is, the vulnerability data set. Use prompt engineering to locate the suspected vulnerable statements in the data set code, extract slices starting from this position, and finally generate code slice samples closely related to the vulnerability. Use patch information to label the code slices as whether there are vulnerabilities, obtain the instruction fine-tuning data set, and fine-tune the code large model.
[0091] A vulnerability detection module for preprocessing the program source code text of the software to be tested, using the same method as above to locate the suspected vulnerable code statements, generating code program slices closely related to the vulnerability, then using the trained vulnerability detection model to classify whether there are vulnerabilities in the code program slices and determine the location of the vulnerable lines, and finally outputting a vulnerability detection report.
[0092] Among them, the model training module includes: A sub-module for locating suspected vulnerable code, which is used to execute the steps of locating suspected vulnerable code in the aforementioned model training phase.
[0093] A sub-module for generating code slices, which is used to execute the steps of generating code slices in the aforementioned model training phase.
[0094] A sub-module for optimizing slices with expert knowledge, which is used to execute the steps of optimizing slices with expert knowledge in the aforementioned model training phase.
[0095] A sample annotation sub-module for executing the sample annotation steps in the aforementioned model training phase.
[0096] The instruction fine-tuning large model sub-module is used to execute the instruction fine-tuning large model step in the aforementioned model training stage.
[0097] Among them, the vulnerability detection module includes: The software code library preprocessing sub-module is used to execute the software code library preprocessing step in the aforementioned vulnerability detection stage.
[0098] The suspected vulnerability code location sub-module is used to execute the suspected vulnerability code location step in the aforementioned vulnerability detection stage.
[0099] The code slice generation sub-module is used to execute the code slice generation step in the aforementioned vulnerability detection stage.
[0100] The expert knowledge optimized slice sub-module is used to execute the expert knowledge optimized slice step in the aforementioned vulnerability detection stage.
[0101] The vulnerability detection sub-module is used to execute the vulnerability detection step in the aforementioned vulnerability detection stage.
[0102] The software vulnerability detection system based on expert knowledge optimization provided by the present application will be described below. The software vulnerability detection system based on expert knowledge optimization described below can be correspondingly referred to the software vulnerability detection method based on expert knowledge optimization described above.
[0103] Figure 6 is a schematic structural diagram of the software vulnerability detection system based on expert knowledge optimization provided by the embodiments of the present application. As Figure 6 shown, it includes: The preprocessing module 10 is used to preprocess the program source code text of the software to be tested and determine each suspected vulnerability code statement in the program source code text; The slicing module 20 is used to slice and extract each suspected vulnerability code statement by using the semantic information of vulnerability code features to obtain the code text slice corresponding to each suspected vulnerability code statement; the semantic information of vulnerability code features is obtained by analyzing expert knowledge. The detection module 30 is used to input each code text slice and the first preset prompt word into the vulnerability detection model to obtain the vulnerability detection report information of the software to be tested output by the vulnerability detection model; the vulnerability detection model is trained on the code large model according to the first preset prompt word, the code text slice sample and its corresponding vulnerability label, and the preset vulnerability report text.
[0104] It can be understood that the detailed function implementation of the above-mentioned each unit / module can be referred to the introduction in the foregoing method embodiments, and will not be elaborated here.
[0105] It should be understood that the above device is used to execute the method in the above embodiment. The corresponding program modules in the device have similar implementation principles and technical effects to those described in the above method. The working process of the device can refer to the corresponding process in the above method, which will not be elaborated here.
[0106] The software vulnerability detection system optimized based on expert knowledge in the embodiment of the present application, by considering the rich vulnerability-related knowledge of vulnerability experts and using expert knowledge to analyze and obtain the semantic information of vulnerability code features and integrating it into the code text slices, can reduce the information unrelated to vulnerabilities in the slices while ensuring the integrity of vulnerability information in the code text slices. At the same time, by pre-screening each suspected vulnerability code statement in the source code text of the software program to be tested and then slicing each suspected vulnerability code statement, the number of slices can be further reduced, and the trained code large model of the code text slice samples can be used to perform inference and prediction on each code text slice, which can improve the efficiency of software vulnerability detection while effectively improving the accuracy and detection effect of software vulnerability detection.
[0107] Based on the method in the above embodiment, the embodiment of the present application provides an electronic device, as Figure 7 shown. The electronic device may include: a processor (Processor) 710, a communication interface (Communications Interface) 720, a memory (Memory) 730, and a communication bus 740. Among them, the processor 710, the communication interface 720, and the memory 730 communicate with each other through the communication bus 740. The processor 710 can call the logical instructions in the memory 730 to execute the method in the above embodiment.
[0108] In addition, when the logical instructions in the above memory 730 are implemented in the form of software function units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application.
[0109] Based on the method in the above embodiment, the embodiment of the present application provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program runs on the processor, it causes the processor to execute the method in the above embodiment.
[0110] Based on the method in the above embodiments, an embodiment of the present application provides a computer program product. When the computer program product runs on a processor, it causes the processor to execute the method in the above embodiments.
[0111] It can be understood that the processor in the embodiment of the present application may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0112] The method steps in the embodiment of the present application may be implemented in a hardware manner or by a processor executing software instructions. The software instructions may be composed of corresponding software modules, and the software modules may be stored in a random access memory (RAM), flash memory, read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), registers, hard disks, removable hard disks, CD-ROMs, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may be located in an ASIC.
[0113] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.
[0114] It can be understood that the various numerical numbers involved in the embodiments of the present application are only for the convenience of description and are not used to limit the scope of the embodiments of the present application.
[0115] It should be understood that expressions such as "including" and "may include" that can be used in the present application indicate the existence of the disclosed functions, operations, or constituent elements, and do not limit one or more additional functions, operations, and constituent elements. In the present application, terms such as "including" and / or "having" can be interpreted as indicating a specific characteristic, number, operation, constituent element, component, or a combination thereof, but cannot be interpreted as excluding the existence or possibility of addition of one or more other characteristics, numbers, operations, constituent elements, components, or a combination thereof.
[0116] As described above, the above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A software vulnerability detection method optimized based on expert knowledge, characterized in that, Including: Preprocess the program source code text of the software to be tested to determine each suspected vulnerability code statement in the program source code text; Use the semantic information of vulnerability code features to slice and extract each suspected vulnerability code statement to obtain a code text slice corresponding to each suspected vulnerability code statement; the semantic information of vulnerability code features is obtained by analyzing expert knowledge; Input each code text slice and a first preset prompt word into a vulnerability detection model to obtain the vulnerability detection report information of the software to be tested output by the vulnerability detection model; The vulnerability detection model is trained on a code large model according to the first preset prompt word, as well as the code text slice samples and their corresponding vulnerability labels and preset vulnerability report texts.
2. The software vulnerability detection method according to claim 1, wherein The using the semantic information of vulnerability code features to slice and extract each suspected vulnerability code statement to obtain a code text slice corresponding to each suspected vulnerability code statement includes: Based on each suspected vulnerability code statement, determine the corresponding suspected vulnerability node in the program dependency graph corresponding to the program source code text; Slice the program dependency graph with each suspected vulnerability node as the starting node to obtain a sliced sub-graph corresponding to each suspected vulnerability code statement; Perform truncation processing on each sliced sub-graph according to the semantic information of vulnerability code features to obtain an optimized sliced sub-graph corresponding to each suspected vulnerability code statement; Map each optimized sliced sub-graph to the program source code text respectively to obtain a code text slice corresponding to each suspected vulnerability code statement.
3. The software vulnerability detection method according to claim 2, wherein The semantic information of vulnerability code features includes semantic information of vulnerability trigger code features and semantic information of vulnerability root cause code features; the performing truncation processing on each sliced sub-graph according to the semantic information of vulnerability code features to obtain an optimized sliced sub-graph corresponding to each suspected vulnerability code statement includes: In the sliced sub-graph corresponding to each suspected vulnerability code statement, locate multiple vulnerability trigger nodes corresponding to the semantic information of vulnerability trigger code features and multiple vulnerability root cause nodes corresponding to the semantic information of vulnerability root cause code features; In the sliced sub-graph corresponding to each suspected vulnerability code statement, truncate at the vulnerability trigger node farthest from the suspected vulnerability node and truncate at the vulnerability root cause node closest to the suspected vulnerability node to obtain an optimized sliced sub-graph corresponding to each suspected vulnerability code statement.
4. The software vulnerability detection method according to claim 2, wherein The slicing the program dependency graph with each suspected vulnerability node as the starting node to obtain a sliced sub-graph corresponding to each suspected vulnerability code statement includes: Taking each suspected vulnerability node as the starting node, traverse along the data dependency edge direction in the program dependency graph respectively to obtain a forward sub-graph starting from each suspected vulnerability node; Taking each suspected vulnerability node as the starting node, traverse along the reverse direction of the data dependency edge in the program dependency graph to obtain a backward sub-graph starting from each suspected vulnerability node. Merge the forward subgraph and the backward subgraph corresponding to each of the suspected vulnerability nodes to obtain a sliced subgraph corresponding to each of the suspected vulnerability code statements.
5. The software vulnerability detection method according to any one of claims 1-4, characterized in that, The preprocessing of the program source code text of the software to be tested to determine each suspected vulnerability code statement in the program source code text includes: Slice the program source code text of the software to be tested at the program function granularity to obtain multiple function code text segments corresponding to the software to be tested; Locate the vulnerability statements based on the multiple function code text segments to determine each suspected vulnerability code statement in the program source code text.
6. The software vulnerability detection method according to claim 5, wherein The locating of the vulnerability statements based on the multiple function code text segments to determine each suspected vulnerability code statement in the program source code text includes: Input the multiple function code text segments and a second preset prompt word into a preset general large model to obtain each suspected vulnerability code statement in the program source code text output by the preset general large model; The second preset prompt word is designed based on different program vulnerability types.
7. The software vulnerability detection method according to any one of claims 1-4, characterized in that, Before inputting each of the code text slices and a first preset prompt word into the vulnerability detection model to obtain the vulnerability detection report information of the software to be tested output by the vulnerability detection model, the method further includes: Obtain a dataset of vulnerability code text samples with patch information; Preprocess each vulnerability code text sample in the dataset of vulnerability code text samples to determine each suspected vulnerability code statement in each vulnerability code text sample; Use the semantic information of the vulnerability code features to extract slices of each suspected vulnerability code statement in each vulnerability code text sample to obtain a dataset of code text slice samples corresponding to each vulnerability code text sample, and label them with the patch information of each vulnerability code text sample to obtain a vulnerability label dataset corresponding to each dataset of code text slice samples; Based on each dataset of code text slice samples and its corresponding vulnerability label dataset, determine each code text slice sample and its corresponding vulnerability label, and use the first preset prompt word, as well as each code text slice sample, its corresponding vulnerability label, and a preset vulnerability report text as a set of training samples to obtain multiple sets of training samples; Use the multiple sets of training samples to fine-tune and train a code large model to obtain a trained vulnerability detection model.
8. A software vulnerability detection system optimized based on expert knowledge, characterized in that, It includes: A preprocessing module for preprocessing the program source code text of the software to be tested to determine each suspected vulnerability code statement in the program source code text; A slicing module for using the semantic information of the vulnerability code features to extract slices of each suspected vulnerability code statement to obtain a code text slice corresponding to each suspected vulnerability code statement; the semantic information of the vulnerability code features is obtained by analyzing expert knowledge; A detection module for inputting each of the code text slices and a first preset prompt word into the vulnerability detection model to obtain the vulnerability detection report information of the software to be tested output by the vulnerability detection model; The vulnerability detection model is obtained by training a code large model based on a first preset prompt word, a code text slice sample and its corresponding vulnerability label, and a preset vulnerability report text.
9. An electronic device, characterized in that, It includes: At least one memory for storing computer programs; At least one processor for executing the program stored in the memory. When the program stored in the memory is executed, the processor is used to execute the method according to any one of claims 1-7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program runs on the processor, the processor is caused to execute the method according to any one of claims 1-7.
Citation Information
Cited By
Vulnerability verification method and device based on compilable code extraction, medium and product
CN120724446A