Coal industry internet platform adaptation method, device, equipment and medium

Through the steps of uploading software packages, such as vulnerability detection, component library analysis and function matching, adaptation instructions are generated, which solves the accuracy of the adaptation judgment of software products and coal industrial Internet platforms, and ensures the implementation of platform adaptation requirements.

CN120336155APending Publication Date: 2025-07-18SHANXI JINYUN INTERNET TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510507518.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

How to accurately and conveniently determine whether the software products meet the adaptation requirements of the coal industrial Internet platform, considering that there are differences between the products developed by various empowered enterprises and the differences in platform standards.

Method used

By obtaining the software packages and technical documents to be uploaded, vulnerability detection, parse component libraries and development languages, judge the consistency of the technical architecture, openness of the data interface, and function matching, and generate adaptation instructions.

Benefits of technology

A comprehensive assessment of the security, advancedness, standardness, openness and functionality of software products is achieved, ensuring their adaptation requirements with the platform and generating accurate adaptation instructions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120336155A_ABST
    Figure CN120336155A_ABST
Patent Text Reader

Abstract

The invention relates to a coal industry internet platform adaptation method and device, equipment and a medium, and the method comprises the steps: obtaining a to-be-uploaded software package and a technical document, carrying out the vulnerability detection of the to-be-uploaded software package, judging whether the to-be-uploaded software package reaches preset safety or not, judging whether a component library and a development language of the to-be-uploaded software package reach preset advancement or not, and uploading the to-be-uploaded software package to the technical document. Judging whether the technical architecture of the to-be-uploaded software package is consistent with a preset architecture so as to judge whether a preset standard is reached or not, judging whether a data interface and a data set of the to-be-uploaded software package are allowed to be called or not so as to judge whether a preset openness is reached or not, analyzing a technical document to obtain functions of the to-be-uploaded software package, and uploading the to-be-uploaded software package to the to-be-uploaded software package. And judging whether the function meets a preset function list or not so as to judge whether a preset function is achieved or not, and if the preset safety, the preset advancement, the preset standard, the preset openness and the preset function are achieved, generating an adaptation instruction and outputting the adaptation instruction. According to the method, whether the software product meets the adaptation requirement of the platform or not can be judged more accurately and conveniently.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular, to a method, device, equipment and medium for adapting a coal industrial Internet platform. Background Art

[0002] With the popularization and application of the new generation of information technology in various industrial fields, especially in the coal industry, it plays a positive role in promoting the intelligent construction of coal mines and realizing the transformation of coal production methods. In order to empower each coal enterprise, by building an Internet platform, a connection and communication channel between the coal enterprise and the empowering enterprise is established. The empowering enterprise uploads software products, system products, etc. developed by itself that are helpful for the intelligent development of the coal enterprise to the platform. The coal enterprise can select the required products according to its own needs on the platform. However, due to the differences between the products developed by each empowering enterprise and the relevant standards of the platform, it is necessary to judge whether the product is adapted to the platform from multiple aspects. Therefore, how to accurately and conveniently judge whether a software product meets the adaptation requirements of the platform has become a problem. Summary of the Invention

[0003] In order to accurately and conveniently judge whether a software product meets the adaptation requirements of the platform, the present application provides a method, device, equipment and medium for adapting a coal industrial Internet platform.

[0004] In a first aspect, the present application provides a method for adapting a coal industrial Internet platform, adopting the following technical solution: A method for adapting a coal industrial Internet platform includes: Obtain the software package to be uploaded and the corresponding technical document, and perform vulnerability detection on the software package to be uploaded to judge whether the software package to be uploaded meets the preset security; Analyze the component library and development language of the software package to be uploaded, and judge whether the component library and development language meet the preset advancement; Judge whether the technical architecture of the software package to be uploaded is consistent with the preset architecture to judge whether it meets the preset standardization; Analyze the data interface and data set of the software package to be uploaded, and judge whether the data interface and data set are allowed to be called to judge whether it meets the preset openness; Analyze the technical document to obtain the functions of the software package to be uploaded, and judge whether the functions meet the preset function list to judge whether it meets the preset functionality; If it meets the preset security, preset advancement, preset standardization, preset openness and preset functionality, generate an adaptation description of the software package to be uploaded and output the adaptation description.

[0005] By adopting the above technical solutions, the software package to be uploaded and the corresponding technical documents are obtained, and the software package to be uploaded is detected for vulnerabilities to judge the security of the software package to be uploaded. The component library and development language of the software package to be uploaded are parsed to judge whether the component library and development language meet the preset advancement. According to whether the technical architecture of the software package to be uploaded is consistent with the preset architecture required by the platform, it is judged whether the preset standard is met. The data interface and data set of the software package to be uploaded are parsed, and it is judged whether the preset openness is achieved according to the callable situation of the data interface and data set. The functions of the software package to be uploaded are parsed from the technical documents, and it is judged whether the functions meet the preset function list, so as to judge whether the software package to be uploaded meets the preset functionality. If all of the preset security, preset advancement, preset standard, preset openness, and preset functionality are achieved, it means that the software package to be uploaded meets the adaptation requirements of the platform, and an adaptation description about the software package to be uploaded is generated and the adaptation description is output, so that relevant personnel can know the adaptation situation of the software package to be uploaded. The adaptation situation of the software product is judged from five aspects including security and advancement, so as to accurately and conveniently judge whether the software product meets the adaptation requirements of the platform.

[0006] In another possible implementation manner, the detecting the software package to be uploaded for vulnerabilities to judge whether the software package to be uploaded meets the preset security includes: Scanning the software package to be uploaded through a third-party binary SCA tool to obtain the vulnerabilities of the software package to be uploaded; If the number of the vulnerabilities is less than the first preset number, it is determined that the software package to be uploaded meets the preset security.

[0007] In another possible implementation manner, the judging whether the component library and development language meet the preset advancement includes: Parsing all components in the component library and judging whether all the components hit the preset component library; Judging whether the development language hits the preset development language; If the number of the preset components in the preset component library hit by all the components reaches the second preset number and the development language hits the preset development language, it is determined that the component library and development language meet the preset advancement.

[0008] In another possible implementation manner, the method further includes: Simulating and installing the software package to be uploaded on a virtual machine to obtain the installed software; Running the installed software and performing vulnerability detection, data interface detection, and data set detection in the installed software; Update the number of vulnerabilities in the software package to be uploaded according to the vulnerability detection results, and determine whether the preset security level is reached based on the updated number of vulnerabilities; Judge whether the newly detected data interfaces and data sets are allowed to be called according to the data interface detection results and data set detection results, so as to judge whether the preset openness is reached.

[0009] In another possible implementation manner, the method further includes: Perform vulnerability detection on the software package to be uploaded to obtain the vulnerability types of the software package to be uploaded and the number of vulnerabilities of each vulnerability type; Extract text from the technical document to obtain the text information in the technical document, and perform word segmentation on the text information to obtain a plurality of words; Parse the software package to obtain the component library of the software package, and the component library includes at least one component; Based on the words and the component library, search for a target software package in the preset software library whose similarity to the software package to be uploaded reaches a preset similarity threshold; Obtain the vulnerability repair logs of each target software package, and repair the software package to be uploaded based on the vulnerability repair logs to obtain the repaired software package to be uploaded; Upload the repaired software package to be uploaded to the platform.

[0010] In another possible implementation manner, each software package in the preset software library corresponds to at least one word. The step of searching for a target software package in the preset software library whose similarity to the software package to be uploaded reaches a preset similarity threshold based on the words and the component library includes: Filter out the stop words in the words based on the preset blacklist library to obtain a plurality of candidate words except the stop words, and the stop words are the words that hit the preset blacklist library; Determine the target candidate words whose occurrence times reach a preset number threshold from the plurality of candidate words; Determine the number of words in the preset software library of each software package that the target candidate words of the software package to be uploaded hit; Determine the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library; Determine the score representing the similarity based on the matching degree, the number, and their respective corresponding coefficients.

[0011] In another possible implementation manner, the step of determining the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library includes: Determine the first component quantity of all components in the component library of the software package to be uploaded, and the second component quantity of all components in the component library of each software package in the preset software library; Calculate the first ratio of the first component quantity to each second component quantity; Compare the component library of the software package to be uploaded with the component libraries of each software package in the preset software library, and determine the number of consistent components that are the same between the software package to be uploaded and the component libraries of each software package in the preset software library; Determine the matching degree between the component library of the software package to be uploaded and the component libraries of each software package in the preset software library based on the number of consistent components and the first ratio.

[0012] In another possible implementation manner, each vulnerability type corresponds to a preset score, and the method further includes: Determine the number of vulnerabilities corresponding to each vulnerability type, and determine the abnormal score of the software package to be uploaded based on the preset score and the corresponding number of vulnerabilities of each vulnerability type; Determine the target preset score interval where the abnormal score is located from multiple preset score intervals, and each preset score interval corresponds to a preset period; Determine the preset period of the target preset score interval as the scanning period of the software package to be uploaded.

[0013] In a second aspect, the present application provides a coal industrial Internet platform adaptation device, adopting the following technical solution: A coal industrial Internet platform adaptation device includes: A security detection module, configured to obtain the software package to be uploaded and the corresponding technical document, and perform vulnerability detection on the software package to be uploaded to determine whether the software package to be uploaded meets the preset security; An advancement detection module, configured to analyze the component library and development language of the software package to be uploaded, and determine whether the component library and development language meet the preset advancement; A standardization detection module, configured to determine whether the technical architecture of the software package to be uploaded is consistent with the preset architecture, so as to determine whether it meets the preset standardization; An openness detection module, configured to analyze the data interface and data set of the software package to be uploaded, and determine whether the data interface and data set are allowed to be called, so as to determine whether it meets the preset openness; A functionality detection module, configured to analyze the technical document to obtain the functions of the software package to be uploaded, and determine whether the functions meet the preset function list, so as to determine whether it meets the preset functionality; An adaptation description generation module, configured to generate an adaptation description for the software package to be uploaded and output the adaptation description when the preset security, preset advancement, preset standardization, preset openness, and preset functionality are met.

[0014] By adopting the above technical solution, the security detection module obtains the software package to be uploaded and the corresponding technical document, and performs vulnerability detection on the software package to be uploaded to determine the security of the software package to be uploaded. The advancement detection module analyzes the component library and development language of the software package to be uploaded to determine whether the component library and development language meet the preset advancement. The standardization detection module determines whether the technical architecture of the software package to be uploaded is consistent with the preset architecture required by the platform, so as to determine whether the preset standardization is met. The openness detection module analyzes the data interface and data set of the software package to be uploaded, and determines whether the preset openness is met according to the callable situation of the data interface and data set. The functionality detection module analyzes the functions of the software package to be uploaded according to the technical document, and determines whether the functions meet the preset function list, so as to determine whether the software package to be uploaded meets the preset functionality. When the preset security, preset advancement, preset standardization, preset openness, and preset functionality are all met, it indicates that the software package to be uploaded meets the adaptation requirements of the platform. The adaptation description generation module generates an adaptation description for the software package to be uploaded and outputs the adaptation description, so that relevant personnel can know the adaptation situation of the software package to be uploaded. By evaluating the adaptation situation of the software product from five aspects including security and advancement, it is possible to accurately and conveniently determine whether the software product meets the adaptation requirements of the platform.

[0015] In another possible implementation manner, when the security detection module performs vulnerability detection on the software package to be uploaded to determine whether the software package to be uploaded meets the preset security, it is specifically configured to: Scan the software package to be uploaded through a third-party binary SCA tool to obtain the vulnerabilities of the software package to be uploaded; If the number of the vulnerabilities is less than the first preset number, it is determined that the software package to be uploaded meets the preset security.

[0016] In another possible implementation manner, when the advancement detection module determines whether the component library and development language meet the preset advancement, it is specifically configured to: Analyze all components in the component library and determine whether all the components hit the preset component library; Determine whether the development language hits the preset development language; If the number of the preset components in the preset component library hit by all the components reaches the second preset number, and the development language hits the preset development language, it is determined that the component library and development language meet the preset advancement.

[0017] In another possible implementation, the coal industry Internet platform adaptation device further includes: A simulation installation module for performing simulation installation of the software package to be uploaded on a virtual machine to obtain the installed software; A software running detection module for running the installed software and performing vulnerability detection, data interface detection, and data set detection in the installed software; An update module for updating the number of vulnerabilities of the software package to be uploaded according to the vulnerability detection result, and determining whether the preset security level is reached according to the updated number of vulnerabilities; A call detection module for determining whether the newly detected data interfaces and data sets are allowed to be called according to the data interface detection result and the data set detection result, so as to determine whether the preset openness is reached.

[0018] In another possible implementation, the coal industry Internet platform adaptation device further includes: A vulnerability detection module for performing vulnerability detection on the software package to be uploaded to obtain the vulnerability types of the software package to be uploaded and the number of vulnerabilities of each vulnerability type; A word segmentation processing module for extracting text from the technical document to obtain the text information in the technical document, and performing word segmentation processing on the text information to obtain a plurality of words; An analysis module for analyzing the software package to obtain a component library of the software package, where the component library includes at least one component; A search module for searching, based on the words and the component library, a target software package in a preset software library that has a similarity to the software package to be uploaded reaching a preset similarity threshold; A repair module for obtaining the vulnerability repair logs of each target software package, and repairing the software package to be uploaded based on the vulnerability repair logs to obtain a repaired software package to be uploaded; An upload module for uploading the repaired software package to be uploaded to the platform.

[0019] In another possible implementation, each software package in the preset software library corresponds to at least one word. When the search module searches, based on the words and the component library, a target software package in the preset software library that has a similarity to the software package to be uploaded reaching a preset similarity threshold, it specifically is used for: Filtering out the stop words in the words based on a preset blacklist library to obtain a plurality of candidate words other than the stop words, where the stop words are the words that hit the preset blacklist library; Determining target candidate words from the plurality of candidate words whose occurrence times reach a preset occurrence threshold; Determine the number of words in the target candidate words of the software package to be uploaded that match the words of each software package in the preset software library; Determine the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library; Based on the matching degree, the number, and their respective corresponding coefficients, determine the score representing the similarity.

[0020] In another possible implementation manner, when the searching module determines the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library, it specifically is used for: Determine the first component quantity of all components in the component library of the software package to be uploaded, and the second component quantity of all components in the component library of each software package in the preset software library; Calculate the first ratio of the first component quantity to each second component quantity; Compare the component library of the software package to be uploaded with the component library of each software package in the preset software library, and determine the number of consistent components where the software package to be uploaded is consistent with the components of each software package in the preset software library; Based on the number of consistent components and the first ratio, determine the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library.

[0021] In another possible implementation manner, each vulnerability type corresponds to a preset score, and the coal industry Internet of Things platform adaptation device further includes: The first score determination module is used to determine the number of vulnerabilities corresponding to each vulnerability type, and based on the preset score and the corresponding number of vulnerabilities of each vulnerability type, determine the abnormal score of the software package to be uploaded; The interval determination module is used to determine the target preset score interval where the abnormal score is located from multiple preset score intervals, and each preset score interval corresponds to a preset period; The period determination module is used to determine the preset period of the target preset score interval as the scanning period of the software package to be uploaded.

[0022] In a third aspect, the present application provides an electronic device, adopting the following technical solution: An electronic device, the electronic device includes: At least one processor; A memory; At least one application program, where at least one application program is stored in the memory and is configured to be executed by at least one processor, and at least one configuration is used for: executing a coal industry Internet of Things platform adaptation method according to any possible implementation manner of the first aspect.

[0023] Fourth aspect, the present application provides a computer-readable storage medium, adopting the following technical solution: A computer-readable storage medium, when the computer program is executed on a computer, causes the computer to execute the method for adapting a coal industrial Internet platform according to any one of the first aspect.

[0024] In summary, the present application includes at least one of the following beneficial technical effects: Obtain the software package to be uploaded and the corresponding technical documents, perform vulnerability detection on the software package to be uploaded to judge the security of the software package to be uploaded, analyze the component library and development language of the software package to be uploaded to judge whether the component library and development language meet the preset advancement, and judge whether it meets the preset standard according to whether the technical architecture of the software package to be uploaded is consistent with the preset architecture required by the platform, analyze the data interface and data set of the software package to be uploaded, and judge whether it meets the preset openness according to the callable situation of the data interface and data set, analyze the functions of the software package to be uploaded according to the technical documents, and judge whether the functions meet the preset function list, so as to judge whether the software package to be uploaded meets the preset functionality. If all of the preset security, preset advancement, preset standard, preset openness, and preset functionality are met, it means that the software package to be uploaded meets the adaptation requirements of the platform, generate an adaptation description about the software package to be uploaded and output the adaptation description, so that relevant personnel can know the adaptation situation of the software package to be uploaded, and judge the adaptation situation of the software product through five aspects including security and advancement, so as to accurately and conveniently judge whether the software product meets the adaptation requirements of the platform. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 is a schematic flowchart of a method for adapting a coal industrial Internet platform according to an embodiment of the present application.

[0026] Figure 2 is an example diagram of an adaptation description in an embodiment of the present application.

[0027] Figure 3 is a schematic structural diagram of an apparatus for adapting a coal industrial Internet platform according to an embodiment of the present application.

[0028] Figure 4 is a schematic structural diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0029] The following further describes the present application in detail with reference to the accompanying drawings.

[0030] Those skilled in the art can make modifications to this embodiment without creative contributions according to needs after reading this specification, but as long as they are within the scope of the claims of the present application, they are protected by the Patent Law.

[0031] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without making creative efforts fall within the scope of protection of this application.

[0032] In addition, the term "and / or" in this document is merely a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, unless otherwise specified.

[0033] The following will further describe the embodiments of this application in detail with reference to the accompanying drawings of the specification.

[0034] The embodiments of this application provide a method for adapting a coal industry Internet platform, which is executed by an electronic device. The electronic device can be a server or a terminal device. Among them, the server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal device can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc., but is not limited thereto. The terminal device and the server can be directly or indirectly connected through wired or wireless communication methods, and the embodiments of this application do not limit this here. As Figure 1 shown, the method includes step S101, step S102, step S103, step S104, step S105, and step S106, where S101, obtain the software package to be uploaded and the corresponding technical document, and perform vulnerability detection on the software package to be uploaded to determine whether the software package to be uploaded meets the preset security level.

[0035] For the embodiments of this application, after relevant enterprises upload the software package to be uploaded and the technical document, the software package to be uploaded and the technical document are stored in the cloud server. The electronic device is communicatively connected to the cloud server. The electronic device obtains the software package to be uploaded and the corresponding technical document from the cloud server, then performs vulnerability detection using relevant vulnerability detection software, and finally determines whether the software package to be uploaded meets the preset security level according to the vulnerability detection result. The more vulnerabilities, the greater the corresponding security level.

[0036] S102, parse the component library and development language of the software package to be uploaded, and determine whether the component library and development language meet the preset advancement level.

[0037] For the embodiments of the present application, most software packages are compressed files, and the electronic device decompresses the software package to access the content of the software package. For example, an APK file is actually a ZIP file and can be decompressed using standard ZIP tools. After decompression, the components may include code files, resource files, configuration files, etc. The electronic device extracts the component library by using relevant tools and methods to read the configuration file, parse the code structure, or extract specific resource files according to the format of the software package. The richer the components in the component library, the higher the advancement of the software package to be uploaded. The electronic device can determine the development language used by parsing the underlying code of the software package to be uploaded or analyzing the suffix of the project files in the software package to be uploaded. The more novel the development language, the higher the corresponding advancement. Examples of development languages with higher advancement include Java and Python. The electronic device can determine whether the software package to be uploaded meets the preset advancement based on the component library and the development language.

[0038] S103. Determine whether the technical architecture of the software package to be uploaded is consistent with the preset architecture to determine whether it meets the preset standardization.

[0039] For the embodiments of the present application, the technical architecture of the software package to be uploaded needs to be consistent with the technical architecture used or compatible with the platform. The electronic device can parse the source code of the software package to be uploaded, or judge the module division and technology stack of the software package to be uploaded through the code structure such as the directory and file structure, so as to know the technical architecture used by the software package to be uploaded. The preset architecture that the platform can be compatible with is stored in the electronic device. The electronic device compares the technical architecture of the software package to be uploaded with the preset architecture. If they are consistent, it means that the software package to be uploaded meets the compatibility adaptation standard, that is, the preset standardization.

[0040] S104. Parse the data interface and data set of the software package to be uploaded, and determine whether the data interface and data set are allowed to be called to determine whether it meets the preset openness.

[0041] For the embodiments of the present application, the electronic device parses the software package to be uploaded through static parsing, dynamic parsing and other methods to obtain the data interface and data set of the software package to be uploaded. Then the electronic device calls the data interface and data set for a long time to know whether the data interface and data set have the permission to be called. If the data interface and data set can be called, it is determined that the software package to be uploaded meets the preset openness.

[0042] S105. Parse the technical document to obtain the functions of the software package to be uploaded, and determine whether the functions meet the preset function list to determine whether it meets the preset functionality.

[0043] For the embodiments of the present application, the electronic device obtains the functions of the software package to be uploaded by performing semantic recognition on the technical document. A function list required by the platform, i.e., a preset function list, is stored in the electronic device. The electronic device matches the parsed functions with the preset function list. If the parsed functions are in the preset function list, it indicates that the software package to be uploaded meets the preset functionality.

[0044] S106, if the preset security, preset advancement, preset standardization, preset openness, and preset functionality are met, generate an adaptation description for the software package to be uploaded and output the adaptation description.

[0045] For the embodiments of the present application, when the electronic device determines that the software package to be uploaded meets the five aspects of preset security, preset advancement, preset standardization, preset openness, and preset functionality, it indicates that the software package to be uploaded meets the requirements of the platform for adaptation and compatibility in all aspects. The electronic device generates an adaptation description for the software package to be uploaded, that is, retrieves the basic information of the software package to be uploaded, such as software name, product type, company affiliation, etc. Add this basic information to the template of the preset adaptation description to obtain the adaptation description for the software package to be uploaded. Finally, the electronic device outputs the adaptation description in the form of a picture, thereby obtaining a certificate for the software package to be uploaded to adapt to the platform. Refer to Figure 2 , Figure 2 The adaptation description shown is generated based on the relevant basic information of the software package to be uploaded, and is only an example. If at least one of the above five items does not meet the corresponding preset requirements, the adaptation description may not be generated, or an adaptation prompt message may be generated according to the adaptation results that meet the requirements and the adaptation results that do not meet the requirements determined by the electronic device, that is, which ones meet the adaptation requirements and which ones do not.

[0046] A possible implementation manner of the embodiments of the present application. In step S101, for the software package to be uploaded, vulnerability detection is performed to determine whether the software package to be uploaded meets the preset security, specifically including step S1011 (not shown in the figure) and step S1012 (not shown in the figure), where S1011, scan the software package to be uploaded through a third-party binary SCA tool to obtain the vulnerabilities of the software package to be uploaded.

[0047] S1012, if the number of vulnerabilities is less than the first preset number, determine that the software package to be uploaded meets the preset security.

[0048] For the embodiments of the present application, a third-party binary SCA software is installed in the electronic device. The electronic device runs the SCA software to scan the software package to be uploaded, so as to obtain the vulnerabilities of the software package to be uploaded. The first preset quantity serves as the demarcation point for whether there are too many vulnerabilities. The electronic device compares the quantity of the scanned vulnerabilities with the first preset quantity. If the quantity of the vulnerabilities is less than the first preset quantity, it indicates that the quantity of the vulnerabilities is small and meets the requirements of the preset security. Therefore, the electronic device determines that the software package to be uploaded meets the preset security. Further, the electronic device can adopt dynamic debugging logic to scan for in-depth problems and output a detailed SCA report and a detailed inspection result of the Trojan virus vulnerability.

[0049] A possible implementation manner of the embodiments of the present application. In step S102, determining whether the component library and the development language meet the preset advancement specifically includes step S1021 (not shown in the figure), step S1022 (not shown in the figure), and step S1023 (not shown in the figure). Among them, S1021, parsing out all components in the component library and determining whether all components hit the preset component library.

[0050] S1022, determining whether the development language hits the preset development language.

[0051] S1023, if the quantity of the preset components in the preset component library hit by all components reaches the second preset quantity and the development language hits the preset development language, it is determined that the component library and the development language meet the preset advancement.

[0052] For the embodiments of the present application, the electronic device can parse out all components used in the component library by analyzing the source code of the software package to be uploaded. A preset component library that meets the requirements of platform compatibility adaptation and advancement is stored in the electronic device. Then, the electronic device matches all the parsed components with the preset component library to determine whether all components hit the preset component library. Similarly, a preset development language that meets the requirements of platform adaptation compatibility and advancement is stored in the electronic device. The electronic device compares the determined development language of the software package to be uploaded to determine whether the development language of the software package to be uploaded meets the preset development language. The second preset quantity serves as the demarcation point for whether the quantity of the components hitting the preset component library is large. When the electronic device determines that the quantity of the preset components in the preset component library hit by all components reaches the second preset quantity and the development language hits the development language, it indicates that the software package to be uploaded is relatively advanced. Therefore, the electronic device determines that the component library and the development language meet the preset advancement required by the platform.

[0053] A possible implementation manner of the embodiments of the present application. The method further includes step S107 (not shown in the figure), step S108 (not shown in the figure), step S109 (not shown in the figure), and step S110 (not shown in the figure). Among them, S107, perform emulation installation of the software package to be uploaded on a virtual machine to obtain the installed software.

[0054] S108, run the installed software and perform vulnerability detection, data interface detection, and data set detection in the installed software.

[0055] S109, update the number of vulnerabilities of the software package to be uploaded according to the vulnerability detection result, and determine whether the preset security level is reached based on the updated number of vulnerabilities.

[0056] S110, determine whether the newly detected data interfaces and data sets are allowed to be called according to the data interface detection result and the data set detection result, so as to determine whether the preset openness is reached.

[0057] For the embodiments of the present application, virtual machine-related software is installed in the electronic device. The electronic device controls the virtual machine to perform emulation installation on the software package to be uploaded, and then runs the installed software and uses relevant vulnerability detection tools to perform vulnerability detection, data interface detection, and data set detection on the installed software. Since the running software is different from the software package state when not installed, the corresponding number of vulnerabilities, data interfaces, and data sets may also be different. Therefore, the electronic device updates the number of the software package to be uploaded according to the vulnerability detection result after installation. The electronic device compares the updated number of vulnerabilities with the first preset number to determine whether the updated number of vulnerabilities reaches the preset security level. Similarly, the electronic device attempts to call the data interface detection result and the data set detection result to determine whether the newly detected data interfaces and data sets are allowed to be called, so as to determine whether the preset openness is reached.

[0058] A possible implementation manner of the embodiments of the present application, the method further includes steps S111 (not shown in the figure), step S112 (not shown in the figure), step S113 (not shown in the figure), step S114 (not shown in the figure), step S115 (not shown in the figure), and step S116 (not shown in the figure), where S111, perform vulnerability detection on the software package to be uploaded to obtain the vulnerability types of the software package to be uploaded and the number of vulnerabilities of each vulnerability type.

[0059] For the embodiments of the present application, the electronic device can scan the software package to be uploaded through the SCA tool for vulnerability detection, or can perform vulnerability detection through methods such as penetration testing and fuzz testing, so as to obtain the vulnerability types of the software package to be uploaded and the number of vulnerabilities of each vulnerability type. The vulnerability types include cross-site scripting (XSS), SQL injection, command injection, buffer overflow, etc. Various vulnerabilities may occur in the initial stage of software package development. Therefore, it is very necessary to detect the vulnerabilities of the software package before uploading the software package to the platform.

[0060] S112, perform text extraction on the technical document to obtain the text information in the technical document, and perform word segmentation on the text information to obtain multiple words.

[0061] For the embodiments of the present application, the technical document records information about the architecture, design, implementation, testing, and deployment in the process of developing the software package. Therefore, the electronic device can obtain the text information in the technical document by performing text extraction on the technical document. Specifically, the electronic device can use OCR (Optical Character Recognition) technology to perform text extraction on the technical document to obtain the text information. Then the electronic device can perform word segmentation on the text information through relevant word segmentation plug-in software such as jieba to obtain multiple words. The words are extracted from the entire technical document and are used to characterize the relevant attributes and specific situations of the software package.

[0062] S113, parse the software package to obtain the component library of the software package.

[0063] Among them, the component library includes at least one component.

[0064] For the embodiments of the present application, most software packages are compressed files, and the electronic device decompresses the software package to access the content of the software package. For example, an APK file is actually a ZIP file and can be decompressed using a standard ZIP tool. After decompression, the components may include code files, resource files, configuration files, etc. The electronic device uses relevant tools and methods to read the configuration files, parse the code structure, or extract specific resource files according to the format of the software package to extract the component library. Each component corresponds to a function, and it is convenient to know the functions of the software package according to the component library.

[0065] S114, based on the words and the component library, search for the target software package in the preset software library whose similarity to the software package to be uploaded reaches the preset similarity threshold.

[0066] For the embodiments of the present application, in summary, both the word list and the component library reflect the relevant attributes, specific situations, and implemented functions of the software package to be uploaded. The preset software library is a database composed of software that has been uploaded on the platform. Therefore, the electronic device can find a relatively similar target software package from the preset software library according to the words corresponding to the software package to be uploaded and the component library, that is, a target software package whose similarity reaches the preset similarity threshold.

[0067] S115. Obtain the vulnerability repair logs of each target software package, and repair the software package to be uploaded based on the vulnerability repair logs to obtain the repaired software package to be uploaded.

[0068] For the embodiments of the present application, the vulnerability repair logs include the vulnerabilities that have occurred and the patches used to repair each vulnerability. The vulnerability repair logs of each target software package are also stored in the cloud server. Therefore, the electronic device can obtain the vulnerability repair logs of the target software package. Since the target software package is relatively similar to the software package to be uploaded and has similar or the same situations and functions, etc., the same vulnerabilities may occur. The electronic device can repair the software package to be uploaded according to the vulnerability repair logs of these target software packages that are similar to the software package to be uploaded, so that the software package to be uploaded can be more adapted to the platform and more compatible with the platform.

[0069] S116. Upload the repaired software package to be uploaded to the platform.

[0070] For the embodiments of the present application, after the electronic device obtains the repaired software package to be uploaded, it can upload the software package to be uploaded to the platform. Compared with directly uploading to the platform, it reduces the impact of the software package on the platform and enables the software package to be quickly compatible with the platform.

[0071] In a possible implementation manner of the embodiments of the present application, each software package in the preset software library corresponds to at least one word. In step S114, finding a target software package whose similarity to the software package to be uploaded reaches the preset similarity threshold from the preset software library based on the words and the component library specifically includes step S1141 (not shown in the figure), step S1142 (not shown in the figure), step S1143 (not shown in the figure), step S1144 (not shown in the figure), and step S1145 (not shown in the figure), where S1141. Filter out the stop words in the words based on the preset blacklist library to obtain multiple candidate words except the stop words.

[0072] Among them, the stop words are the words that hit the preset blacklist library.

[0073] For the embodiments of this application, the words in the preset blacklist library are formatted words in technical documents, that is, format words that appear in the technical documents of each software package. Therefore, the electronic device screens multiple words of the software package to be uploaded according to the preset blacklist library, filters out useless words, reduces the data volume, and makes the remaining candidate words better represent the attributes and situations of the software package to be uploaded.

[0074] S1142, determine target candidate words whose occurrence times reach a preset occurrence times threshold from multiple candidate words.

[0075] For the embodiments of this application, the electronic device counts the number of occurrences of each candidate word in the technical document to obtain the occurrence times of each candidate word. The more the occurrence times, the better it represents the attributes and situations of the software package to be uploaded. The preset occurrence times threshold is used as the demarcation point for whether the occurrence times are more. For example, the preset occurrence times threshold is 3. The electronic device compares the occurrence times of each candidate word with 3 times to determine the target candidate words that reach 3 times. The target candidate words are the words that can best represent the software package to be uploaded.

[0076] S1143, determine the number of words in the target candidate words of the software package to be uploaded that match the words of each software package in the preset software library.

[0077] For the embodiments of this application, each software package in the preset software library also corresponds to words that represent its own attributes and situations. Therefore, the electronic device matches and compares the target candidate words of the software package to be uploaded with the words of each software package in the preset software library, so as to determine the number of words that match each other in the preset software library. The more the number, the closer the situation attributes of the software package are to the software package to be uploaded.

[0078] S1144, determine the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library.

[0079] For the embodiments of this application, the electronic device compares the component library of the software package to be uploaded with the component library of each software package in the preset software library, so as to determine the matching degree between the component library of each software package in the preset software library and the component library of the software package to be uploaded. The higher the matching degree, the more similar it is to the software package to be uploaded.

[0080] S1145, determine a score representing the similarity based on the matching degree, the number, and their respective corresponding coefficients.

[0081] For the embodiments of the present application, in summary, both the matching degree and the number of identical words are key factors for characterizing whether each software package in the preset software library is similar to and close to the software package to be uploaded. Moreover, the degrees of influence of the matching degree and the number on the similarity are different. Therefore, the staff can set their respective corresponding coefficients for the matching degree and the number. After the electronic device determines the matching degree and the number of each software package in the preset software library, it can call their respective corresponding coefficients for weighted calculation to determine a score representing the similarity. By analyzing the words and the component library to obtain the number of identical words and the matching degree of the component library, and further obtaining the score regarding the similarity, the similarity calculation becomes more accurate and convenient.

[0082] A possible implementation manner of the embodiments of the present application. In step S1144, determining the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library specifically includes step Sa (not shown in the figure), step Sb (not shown in the figure), step Sc (not shown in the figure), and step Sd (not shown in the figure), where Sa, determining the first component quantity of all components in the component library of the software package to be uploaded, and the second component quantity of all components in the component library of each software package in the preset software library.

[0083] For the embodiments of the present application, the electronic device counts the components in the component library of the software package to be uploaded to obtain the first component quantity, and similarly counts the components in the component library of each software package in the preset software library to obtain the second component quantity.

[0084] Sb, calculating the first ratio of the first component quantity to each second component quantity.

[0085] For the embodiments of the present application, the closer the first component quantity and the second component quantity are to a certain extent, the closer the software package to be uploaded is to the software package in the preset software library in terms of the composition of the component library. Therefore, the electronic device divides the first component quantity by the second component quantity to obtain the first ratio. The closer the first ratio is to 1, the closer the first component quantity and the second component quantity are, and the closer the software package to be uploaded is to the software package in the preset software library in terms of the composition of the component library.

[0086] Sc, comparing the component library of the software package to be uploaded with the component library of each software package in the preset software library to determine the number of identical components that are the same between the software package to be uploaded and the component library of each software package in the preset software library.

[0087] For the embodiments of the present application, the electronic device determines the number of components that are the same between the components of each software package in the preset software library and the components of the software package to be uploaded through the comparison between the component libraries. The more the number of identical components of a certain software package is, the more identical functions it has, and thus the closer the software package is to the software package to be uploaded.

[0088] Sd determines the matching degree between the software package to be uploaded and the component library of each software package in the preset software library based on the number of consistent components and the first ratio.

[0089] For the embodiments of the present application, in summary, both the number of consistent components and the first ratio are key factors affecting the matching degree between the software package to be uploaded and each software package in the preset software library. The electronic device can subtract 1 from the first ratio to obtain a difference, and use the absolute value of the difference to represent the first ratio. Then, the electronic device sets respective corresponding coefficients for the difference and the number of consistent components and stores them in the local storage medium of the electronic device. After the electronic device determines the difference and the number of consistent components, it calls the respective corresponding coefficients for weighted calculation to obtain a score representing the matching degree. By comparing and analyzing between component libraries to obtain the first ratio and the number of consistent components and further calculating the score representing the matching degree, the calculation of the matching degree is made more accurate.

[0090] In a possible implementation manner of the embodiments of the present application, each vulnerability type corresponds to a preset score. After step S116, it further includes step one, step two, and step three, where Step one, determine the number of vulnerabilities corresponding to each vulnerability type, and determine the abnormal score of the software package to be uploaded based on the preset score and the corresponding number of vulnerabilities of each vulnerability type.

[0091] For the embodiments of the present application, different types of vulnerabilities have different harm levels and danger levels. Therefore, the staff sets a preset score for different vulnerability types in advance and stores it in the local storage medium of the electronic device. The higher the harm level and danger level of the vulnerability, the higher the corresponding preset score. After the electronic device determines the number of vulnerabilities of each vulnerability type, multiplying the number of vulnerabilities by the preset score can obtain an abnormal score of a vulnerability type. Then, the electronic device performs the same operation to obtain the abnormal score of each vulnerability type. The electronic device sums up the abnormal scores of each vulnerability type to obtain the abnormal score of the software package to be uploaded. The higher the abnormal score, the worse the adaptability and compatibility of the software package to be uploaded with the platform.

[0092] Step two, determine the target preset score interval where the abnormal score is located from multiple preset score intervals.

[0093] Among them, each preset score interval corresponds to a preset period.

[0094] For the embodiments of the present application, the staff can set multiple preset score intervals in advance according to actual situations and requirements. The preset period corresponding to each preset score interval is also set by the staff according to actual situations or calculations. The electronic device compares the abnormal score of the software package to be uploaded with multiple preset score intervals to determine the target preset score interval where the abnormal score is located.

[0095] Step 3: Determine the preset period of the target preset score range as the scanning period of the software package to be uploaded.

[0096] For the embodiments of the present application, after the electronic device determines the target preset score range, it can determine the preset period corresponding to this range as the scanning period of the software to be uploaded. By determining an appropriate vulnerability scanning period according to the vulnerability situation of the software to be uploaded, new vulnerabilities can be discovered more timely after the software to be uploaded is uploaded to the platform.

[0097] A possible implementation manner of the embodiments of the present application includes Step 4, Step 5, Step 6, Step 7, Step 8, and Step 9 after Step S116, where Step 4: Obtain multiple vulnerability scanning results of the software package to be uploaded within a preset time period, and the number of updated repairs between each scanning result and the previous scanning result.

[0098] Among them, the scanning result includes the vulnerability type and the number of vulnerabilities of each vulnerability type.

[0099] For the embodiments of the present application, the preset time period can be the past seven days, the past fifteen days, the past thirty days, etc. After uploading the software package to be uploaded to the platform, the electronic device obtains the vulnerability scanning results within the preset time period. According to the scanning results, the vulnerability generation situation of the software package within the preset time period can be analyzed. Each time the software package uploader updates the software package, the update time is recorded in the cloud server, and the electronic device performs a vulnerability repair each time the software package is scanned for vulnerabilities. Between two vulnerability scans, the software package uploader can also actively repair the vulnerabilities of the software package. Therefore, the electronic device can obtain the number of updated repairs between each scanning result and the previous scanning result from the cloud server according to the preset time period. The number of updated repairs includes the sum of the number of updates and the number of repairs. The more the number of updated repairs, the higher the frequency of the software package uploader's maintenance of the software package, and the higher the compatibility and adaptability of the software package with the platform during repeated maintenance.

[0100] Step 5: Determine the abnormal score of each scanning result.

[0101] For the embodiments of the present application, the electronic device can determine the abnormal score of each scanning result through the content recorded in Step 1, which will not be elaborated here.

[0102] Step 6: Obtain the number of abnormal feedbacks between each scanning result and the previous scanning result, and determine the product of the abnormal score of each scanning result and the corresponding number of abnormal feedbacks.

[0103] For the embodiments of the present application, when a software package is accessed, downloaded, viewed, or otherwise operated on, abnormal situations such as non-responsiveness and crashes may occur. Therefore, the platform can record the number of abnormal feedbacks of the software package. The number of abnormal feedbacks can include the platform's independent feedback and user feedback. The more the number of abnormal feedbacks, the worse the compatibility and adaptability between the software package and the platform. After each vulnerability scan, the vulnerabilities of the software package are repaired. The number of abnormal feedbacks between each scan result and the previous scan result represents the repair effect after the previous scan. Therefore, the electronic device calculates the product of each scan result and the corresponding number of abnormal feedbacks. The larger the product, the worse the repair effect and the compatibility and adaptability between the software package and the platform after the previous scan repair.

[0104] Step seven, calculate the second ratio of the product to the updated repair count.

[0105] Among them, the second ratio represents the adaptation value of the software package to be uploaded after each vulnerability scan.

[0106] For the embodiments of the present application, in order to more accurately determine the compatibility between the software package and the platform after each scan, the electronic device divides the product obtained above by the corresponding updated repair count to obtain the second ratio. The second ratio combines the updated repair count of the software package between two scans, that is, combines the maintenance situation of the software package, making the second ratio more capable of representing the adaptation situation after each scan, and making the adaptation value representing the adaptation situation of the software package after each scan more specific. The larger the adaptation value, the lower the degree of adaptation to the platform.

[0107] Step eight, draw a line chart based on the adaptation value, and determine the change trend, change rate, and average value of the adaptation value from the line chart.

[0108] For the embodiments of the present application, after the electronic device determines multiple adaptation values of the software package, it obtains multiple coordinate points according to the time points corresponding to each adaptation value. The electronic device maps the multiple coordinate points to a preset coordinate system and then connects the coordinate points in sequence to draw a line chart. The horizontal axis of the preset coordinate system is time, and the vertical axis is the adaptation value. Through the line chart, the change situation of the adaptation value can be observed more intuitively. The electronic device inputs the line chart into the origin software plugin for linear fitting to obtain a linear function of the line chart, and then the electronic device calculates the slope of the linear function to determine the change trend and change rate of the adaptation value. When the slope is positive, the change trend is upward; when the slope is negative, the change trend is downward; when the slope is 0, the change trend is unchanged. The magnitude of the slope calculated by the electronic device is the change rate. The electronic device calculates the average value of the ordinates of the points on the line chart to obtain the average adaptation value. It is more accurate to represent the overall adaptation value of the software package within a preset time period through the average adaptation value.

[0109] Step Nine: Adjust the scanning period based on the change trend, change rate, and average value of the adaptation value.

[0110] For the embodiments of the present application, after the electronic device determines the change trend, change rate, and average value of the adaptation value, it can adjust the scanning period, so that the scanning period better conforms to the specific situation of the adaptation degree between the software package and the platform, and then the software package can more quickly improve the adaptation degree and compatibility with the platform under the appropriate scanning period.

[0111] A possible implementation manner of the embodiments of the present application is that in Step Nine, adjusting the scanning period based on the change trend, change rate, and average value of the adaptation value specifically includes Step S1 (not shown in the figure), Step S2 (not shown in the figure), Step S3 (not shown in the figure), and Step S4 (not shown in the figure), where S1: If the change trend of the adaptation value is upward, determine the period correction value based on the change rate and the average value of the adaptation value, and subtract the period correction value from the current scanning period to obtain the adjusted scanning period.

[0112] For the embodiments of the present application, if the change trend of the adaptation value is upward, it indicates that the adaptation value has been increasing and the adaptation degree of the software package is getting worse. Then it is necessary to shorten the scanning period. At this time, the greater the change rate, the faster the adaptation degree deteriorates, and the shorter the scanning period is more needed. The larger the average value of the adaptation value also indicates that the adaptation degree is at a relatively poor level, and the shorter the scanning period is also more needed. Therefore, the staff can set their respective corresponding coefficients for the change rate and the average value of the adaptation value in advance. Then, after the electronic device determines the change rate and the average value of the adaptation value, it calls their respective corresponding coefficients for weighted calculation to obtain the period correction value. Then, the electronic device subtracts the period correction value from the current scanning period to shorten the scanning period to obtain the adjusted scanning period. Scanning the software package according to the adjusted scanning period can more timely detect the vulnerabilities of the software package, and then the software package can more quickly improve the adaptation degree with the platform.

[0113] S2: If the change trend of the adaptation value is downward, determine the period correction value based on the change rate and the average value of the adaptation value, and add the period correction value to the current scanning period to obtain the adjusted scanning period.

[0114] For the embodiments of the present application, if the trend of the adaptation value change is downward, it indicates that the adaptation value has been decreasing, and the adaptation degree of the software package is getting better and better. Then, a shorter scanning period is not required. Therefore, it is necessary to increase the scanning period. At this time, the greater the change rate, the faster the adaptation degree gets better. Just scan according to a longer scanning period, which reduces resource occupancy. The smaller the change rate, the slower the adaptation degree gets better. It is not possible to scan with a greatly increased scanning period. The larger the average value of the adaptation value, it also indicates that the adaptation degree is still at a relatively poor level. It is also not possible to scan with a greatly increased scanning period. The smaller the average value of the adaptation value, it also indicates that the adaptation degree level is relatively high, and it is possible to greatly increase the scanning period for scanning. Therefore, the staff can set their respective corresponding coefficients for the change rate and the average value of the adaptation value in advance. Then, after the electronic device determines the change rate and the average value of the adaptation value, it calls their respective corresponding coefficients to perform weighted calculation to obtain a period correction value. Then, the electronic device adds the period correction value to the current scanning period to shorten the scanning period to obtain an adjusted scanning period. Scanning the software package according to the adjusted scanning period can reduce resource occupancy while ensuring the vulnerability scanning effect and timeliness.

[0115] S3. If the trend of the adaptation value change is unchanged and the average value of the adaptation value is lower than the preset average value threshold, the scanning period is not adjusted.

[0116] For the embodiments of the present application, if the trend of the adaptation value change is unchanged and the average value of the adaptation value is lower than the preset average value threshold, it indicates that the adaptation degree of the software package to the platform has been at a relatively high level, and the current scanning period can be maintained.

[0117] S4. If the trend of the adaptation value change is unchanged and the average value of the adaptation value reaches the preset average value threshold, determine a period correction value based on the average value of the adaptation value, and subtract the period correction value from the current scanning period to obtain an adjusted scanning period.

[0118] For the embodiments of the present application, if the change rate of the adaptation value is unchanged, but the average value of the adaptation value reaches the preset average value threshold, it indicates that the adaptation degree of the software package to the platform has been at a relatively low level, but the adaptation degree still needs to be improved. At this time, the electronic device can multiply the average value of the adaptation value by a preset coefficient to obtain a period correction value. The electronic device subtracts the period correction value from the current scanning period to obtain an adjusted scanning period. Thus, just perform vulnerability scanning according to a shorter scanning period, which can more timely discover the vulnerabilities of the software package, and then enable the software package to more quickly improve the adaptation degree to the platform.

[0119] In a possible implementation manner of the embodiment of the present application, in step S115, the software package to be uploaded is repaired based on the vulnerability repair log to obtain the repaired software package to be uploaded, which specifically includes step S1151 (not shown in the figure), step S1152 (not shown in the figure), step S1153 (not shown in the figure), step S1154 (not shown in the figure), and step S1155 (not shown in the figure). Among them, S1151, determine the target vulnerability repair log from the vulnerability repair logs of all target software packages.

[0120] Among them, the vulnerabilities repaired in the target vulnerability repair log hit the largest number of vulnerabilities of the software package to be uploaded. The vulnerability repair log includes vulnerabilities and corresponding patches.

[0121] For the embodiment of the present application, the vulnerability repair log of each target software package is a set of each repair log. The electronic device compares and matches the vulnerabilities that appear in the vulnerability repair log of each target software package with the vulnerabilities of the software package to be uploaded to determine the target vulnerability repair log. The vulnerabilities in the target vulnerability repair log are the closest to the vulnerabilities of the software package to be uploaded and the largest number of hits. It is more convenient and accurate to further process the target vulnerability repair log to obtain the vulnerability repair solution of the software package to be uploaded.

[0122] S1152, determine the remaining vulnerabilities in the vulnerabilities of the software package to be uploaded that do not hit the target vulnerability repair log.

[0123] For the embodiment of the present application, the electronic device screens the vulnerabilities of the software package to be uploaded through the vulnerabilities in the target vulnerability repair log to obtain the remaining vulnerabilities that do not hit the target vulnerability repair log.

[0124] S1153, determine the patch for each remaining vulnerability from the remaining vulnerability repair logs except the target vulnerability repair log.

[0125] For the embodiment of the present application, after the electronic device determines the remaining vulnerabilities, it can then determine the patch for each remaining vulnerability from the remaining vulnerability repair logs of other target software packages except the target vulnerability repair log. Since the target software packages are all software packages that are relatively similar to the software package to be uploaded, the probability of determining the patch for the remaining vulnerability in the remaining vulnerability repair log is greater.

[0126] S1154, using the target vulnerability repair log as a template, add each remaining vulnerability and the patch for each remaining vulnerability to the template to obtain the vulnerability repair solution of the software package to be uploaded.

[0127] For the embodiments of the present application, since the target vulnerability repair log hits the most vulnerabilities of the software package to be uploaded, the electronic device deletes the vulnerabilities in the target vulnerability repair log that do not belong to the software package to be uploaded, and obtains only the vulnerabilities of the software package to be uploaded and the corresponding patches. Then, the electronic device uses this as a template to add the remaining vulnerabilities and the corresponding patches to the template to obtain the vulnerability repair solution for the software package to be uploaded. By the above method, the efficiency of determining the vulnerability repair solution for the software package to be uploaded is higher and more convenient.

[0128] S1155, repair the software package to be uploaded based on the vulnerability repair solution to obtain the repaired software package to be uploaded.

[0129] For the embodiments of the present application, the patches used after each software package is repaired for vulnerabilities are stored in the cloud server. Therefore, the electronic device calls the required patches from the cloud service according to the determined vulnerability repair solution and repairs the vulnerabilities of the software package to be uploaded, so as to obtain the repaired software package to be uploaded. The vulnerabilities of the software package to be uploaded are repaired before uploading to the platform through the existing repair logs and patches, so that the software package to be uploaded can adapt to the platform faster and be compatible with the platform. Further, if there are remaining vulnerabilities for which corresponding patches are not found, the electronic device repairs the vulnerabilities for which patches have been determined according to the vulnerability repair solution, and then sends a prompt message to the uploader of the software package to be uploaded to remind the uploader to make patches for and process the remaining vulnerabilities.

[0130] The above embodiments introduce a method for adapting a coal industry Internet platform from the perspective of the method flow. The following embodiments introduce a device 20 for adapting a coal industry Internet platform from the perspective of virtual modules or virtual units. For details, see the following embodiments.

[0131] Embodiments of the present application provide a device 20 for adapting a coal industry Internet platform, as Figure 3 shown. A device 20 for adapting a coal industry Internet platform may specifically include: A security detection module, configured to obtain the software package to be uploaded and the corresponding technical documents, and perform vulnerability detection on the software package to be uploaded to determine whether the software package to be uploaded meets the preset security; An advancement detection module, configured to analyze the component library and development language of the software package to be uploaded, and determine whether the component library and development language meet the preset advancement; A standardization detection module, configured to determine whether the technical architecture of the software package to be uploaded is consistent with the preset architecture to determine whether it meets the preset standardization; An openness detection module, configured to analyze the data interface and data set of the software package to be uploaded, and determine whether the data interface and data set are allowed to be called to determine whether it meets the preset openness; A functional detection module, which is used to parse a technical document to obtain the functions of the software package to be uploaded, and determine whether the functions meet a preset function list, so as to determine whether the preset functionality is achieved; An adaptation description generation module, which is used to generate and output an adaptation description of the software package to be uploaded when the preset security, preset advancement, preset standardization, preset openness, and preset functionality are achieved.

[0132] An embodiment of the present application discloses a coal industrial Internet platform adaptation device 20. Among them, a security detection module 201 obtains the software package to be uploaded and the corresponding technical document, and performs vulnerability detection on the software package to be uploaded to determine the security of the software package to be uploaded. An advancement detection module 202 parses the component library and development language of the software package to be uploaded to determine whether the component library and development language meet the preset advancement. A standardization detection module 203 determines whether the technical architecture of the software package to be uploaded is consistent with the preset architecture required by the platform, so as to determine whether the preset standardization is achieved. An openness detection module 204 parses the data interface and data set of the software package to be uploaded, and determines whether the preset openness is achieved according to the callable situation of the data interface and data set. A functional detection module 205 parses the functions of the software package to be uploaded according to the technical document, and determines whether the functions meet the preset function list, so as to determine whether the software package to be uploaded meets the preset functionality. When the preset security, preset advancement, preset standardization, preset openness, and preset functionality are all achieved, it indicates that the software package to be uploaded meets the adaptation requirements of the platform. An adaptation description generation module 206 generates an adaptation description about the software package to be uploaded and outputs the adaptation description, so that relevant personnel can know the adaptation situation of the software package to be uploaded, and judge the adaptation situation of the software product through five aspects including security and advancement, so as to accurately and conveniently determine whether the software product meets the adaptation requirements of the platform.

[0133] In a possible implementation manner of an embodiment of the present application, when the security detection module 201 performs vulnerability detection on the software package to be uploaded to determine whether the software package to be uploaded meets the preset security, it is specifically used for: Scanning the software package to be uploaded through a third-party binary SCA tool to obtain the vulnerabilities of the software package to be uploaded; If the number of vulnerabilities is less than the first preset number, it is determined that the software package to be uploaded meets the preset security.

[0134] In a possible implementation manner of an embodiment of the present application, when the advancement detection module 202 determines whether the component library and development language meet the preset advancement, it is specifically used for: Parsing all components in the component library, and determining whether all components hit the preset component library; Determining whether the development language hits the preset development language; If the number of components in all components that match the preset components in the preset component library reaches the second preset number, and the development language matches the preset development language, it is determined that the component library and the development language reach the preset advancement.

[0135] A possible implementation manner of the embodiment of the present application, a coal industrial Internet platform adaptation device 20 further includes: A simulation installation module, configured to perform simulation installation of the software package to be uploaded on a virtual machine to obtain the installed software; A software operation detection module, configured to run the installed software and perform vulnerability detection, data interface detection, and data set detection in the installed software; An update module, configured to update the number of vulnerabilities of the software package to be uploaded according to the vulnerability detection result, and determine whether the preset security is reached according to the updated number of vulnerabilities; A call detection module, configured to determine whether the newly detected data interface and data set are allowed to be called according to the data interface detection result and the data set detection result, so as to determine whether the preset openness is reached.

[0136] A possible implementation manner of the embodiment of the present application, a coal industrial Internet platform adaptation device 20 further includes: A vulnerability detection module, configured to perform vulnerability detection on the software package to be uploaded to obtain the vulnerability types of the software package to be uploaded and the number of vulnerabilities of each vulnerability type; A word segmentation processing module, configured to perform text extraction on the technical document to obtain the text information in the technical document, and perform word segmentation processing on the text information to obtain a plurality of words; An analysis module, configured to analyze the software package to obtain the component library of the software package, and the component library includes at least one component; A search module, configured to search for a target software package with a similarity to the software package to be uploaded reaching a preset similarity threshold from the preset software library based on the words and the component library; A repair module, configured to obtain the vulnerability repair log of each target software package, and repair the software package to be uploaded based on the vulnerability repair log to obtain the repaired software package to be uploaded; An upload module, configured to upload the repaired software package to be uploaded to the platform.

[0137] A possible implementation manner of the embodiment of the present application, each software package in the preset software library corresponds to at least one word. When the search module searches for a target software package with a similarity to the software package to be uploaded reaching a preset similarity threshold from the preset software library based on the words and the component library, it is specifically configured to: Filter out the stop words in the words based on the preset blacklist library to obtain a plurality of candidate words except the stop words, and the stop words are the words that match the preset blacklist library; Determine a target candidate word whose occurrence count reaches a preset count threshold from multiple candidate words; Determine the number of words in the target candidate word of the software package to be uploaded that match the words in each software package in the preset software library; Determine the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library; Determine a score representing the similarity based on the matching degree, the number, and their respective corresponding coefficients.

[0138] In a possible implementation manner of the embodiment of the present application, when the search module determines the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library, it is specifically used for: Determine the first component quantity of all components in the component library of the software package to be uploaded, and the second component quantity of all components in the component library of each software package in the preset software library; Calculate the first ratio of the first component quantity to each second component quantity; Compare the component library of the software package to be uploaded with the component library of each software package in the preset software library, and determine the number of consistent components where the software package to be uploaded is consistent with the components of each software package in the preset software library; Determine the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library based on the number of consistent components and the first ratio.

[0139] In a possible implementation manner of the embodiment of the present application, each vulnerability type corresponds to a preset score. A coal industry Internet platform adaptation device 20 further includes: A first score determination module, configured to determine the number of vulnerabilities corresponding to each vulnerability type, and determine the abnormal score of the software package to be uploaded based on the preset score and the corresponding number of vulnerabilities of each vulnerability type; An interval determination module, configured to determine the target preset score interval where the abnormal score is located from multiple preset score intervals, and each preset score interval corresponds to a preset period; A period determination module, configured to determine the preset period of the target preset score interval as the scanning period of the software package to be uploaded.

[0140] In a possible implementation manner of the embodiment of the present application, a coal industry Internet platform adaptation device 20 further includes: A data acquisition module, configured to acquire multiple vulnerability scanning results of the software package to be uploaded within a preset time period and the number of updated repairs between each scanning result and the previous scanning result. The scanning result includes the vulnerability type and the number of vulnerabilities of each vulnerability type; A second score determination module, configured to determine the abnormal score of each scanning result; The product determination module is used to obtain the number of abnormal feedbacks between each scan result and the previous scan result, and determine the product of the abnormal score of each scan result and the corresponding number of abnormal feedbacks; The ratio calculation module is used to calculate the second ratio of the product to the number of update and repair times, and the second ratio represents the adaptation value of the software package to be uploaded after each vulnerability scan; The data determination module is used to draw a line chart based on the adaptation value, and determine the change trend, change rate and average value of the adaptation value from the line chart; The adjustment module is used to adjust the scan period based on the change trend, change rate and average value of the adaptation value.

[0141] In a possible implementation manner of the embodiment of the present application, when the adjustment module adjusts the scan period based on the change trend, change rate and average value of the adaptation value, it is specifically used for: If the change trend of the adaptation value is upward, determine the period correction value based on the change rate and the average value of the adaptation value, and subtract the period correction value from the current scan period to obtain the adjusted scan period; If the change trend of the adaptation value is downward, determine the period correction value based on the change rate and the average value of the adaptation value, and add the period correction value to the current scan period to obtain the adjusted scan period; If the change trend of the adaptation value is unchanged and the average value of the adaptation value is lower than the preset average value threshold, do not adjust the scan period; If the change trend of the adaptation value is unchanged and the average value of the adaptation value reaches the preset average value threshold, determine the period correction value based on the average value of the adaptation value, and subtract the period correction value from the current scan period to obtain the adjusted scan period.

[0142] In a possible implementation manner of the embodiment of the present application, when the vulnerability repair module repairs the software package to be uploaded based on the vulnerability repair log to obtain the repaired software package to be uploaded, it is specifically used for: Determine the target vulnerability repair log from the vulnerability repair logs of all target software packages. The number of vulnerabilities repaired in the target vulnerability repair log hits the most vulnerabilities of the software package to be uploaded. The vulnerability repair log includes vulnerabilities and patches corresponding to the vulnerabilities; Determine the remaining vulnerabilities in the vulnerabilities of the software package to be uploaded that do not hit the target vulnerability repair log; Determine the patches for each remaining vulnerability from the remaining vulnerability repair logs except the target vulnerability repair log; Using the target vulnerability repair log as a template, add each remaining vulnerability and the patch for each remaining vulnerability to the template to obtain the vulnerability repair solution for the software package to be uploaded; Repair the software package to be uploaded based on the vulnerability repair solution to obtain the repaired software package to be uploaded.

[0143] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working process of the above-described coal industry Internet platform adaptation device 20 can refer to the corresponding process in the foregoing method embodiment, and will not be elaborated herein.

[0144] An electronic device is provided in an embodiment of the present application, such as Figure 4 shown Figure 4 The electronic device 30 shown includes: a processor 301 and a memory 303. Among them, the processor 301 and the memory 303 are connected, such as connected through a bus 302. Optionally, the electronic device 30 may further include a transceiver 304. It should be noted that in practical applications, the transceiver 304 is not limited to one, and the structure of the electronic device 30 does not constitute a limitation to the embodiment of the present application.

[0145] The processor 301 may be a CPU (Central Processing Unit, central processing unit), a general-purpose processor, a DSP (Digital Signal Processor, data signal processor), an ASIC (Application Specific Integrated Circuit, application-specific integrated circuit), an FPGA (Field Programmable Gate Array, field programmable gate array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in combination with the disclosure of the present application. The processor 301 may also be a combination for implementing computing functions, such as a combination including one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0146] The bus 302 may include a path for transmitting information between the above components. The bus 302 may be a PCI (Peripheral Component Interconnect, peripheral component interconnect standard) bus or an EISA (Extended Industry Standard Architecture, extended industry standard architecture) bus, etc. The bus 302 may be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 4 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.

[0147] The memory 303 can be a ROM (Read Only Memory), or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory), or other types of dynamic storage devices that can store information and instructions. It can also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0148] The memory 303 is used to store the application program code for executing the solution of this application, and is controlled by the processor 301 for execution. The processor 301 is used to execute the application program code stored in the memory 303 to implement the content shown in the foregoing method embodiments.

[0149] Among them, the electronic device includes but is not limited to: mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. It can also be a server, etc. Figure 4 The electronic device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of this application.

[0150] An embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When it runs on a computer, the computer can execute the corresponding content in the foregoing method embodiment. Compared with the related art, in the embodiment of the present application, obtaining the software package to be uploaded and the technical document facilitates subsequent analysis of the software package to be uploaded. Performing a vulnerability scan on the software package to be uploaded to obtain the vulnerability type and the number of vulnerabilities. The technical document records the relevant information of the software package to be uploaded. Therefore, text extraction is performed on the technical document to obtain text information, and then word segmentation processing is performed on the text information to obtain words representing the relevant information and features of the software package to be uploaded. Parsing the software package to be uploaded to obtain a component library that composes the software package to be uploaded. The component library contains components for implementing various functions. According to the words and the component library, a target software package that is relatively similar to the software package to be uploaded can be found from a preset software library. Since the similarity between the target software package and the software package to be uploaded is relatively high, it is convenient to repair the vulnerabilities of the software package to be uploaded according to the vulnerability repair log of the software package to be uploaded, so as to obtain the repaired software package to be uploaded. Finally, the repaired software package to be uploaded can be uploaded to the platform. By performing a vulnerability scan on the software package to be uploaded and then repairing the software package to be uploaded according to the vulnerability repair log of the already uploaded and relatively similar software package, the software package to be uploaded can be made to be more compatible with the platform more quickly, and the compatibility between the software package to be uploaded and the platform is better.

[0151] It should be understood that although the steps in the flowchart of the accompanying drawings are shown in sequence according to the indication of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps is not strictly limited in order, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.

[0152] The above are only some embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and retouches can be made, and these improvements and retouches should also be regarded as the protection scope of the present application.

Claims

1. A method for adapting a coal industrial Internet platform, characterized in that Including: Obtain the software package to be uploaded and the corresponding technical document, and perform vulnerability detection on the software package to be uploaded to determine whether the software package to be uploaded meets the preset security level; Analyze the component library and development language of the software package to be uploaded, and determine whether the component library and development language meet the preset advanced level; Determine whether the technical architecture of the software package to be uploaded is consistent with the preset architecture to determine whether it meets the preset standardization; Analyze the data interface and data set of the software package to be uploaded, and determine whether the data interface and data set are allowed to be called to determine whether it meets the preset openness; Analyze the technical document to obtain the functions of the software package to be uploaded, and determine whether the functions meet the preset function list to determine whether it meets the preset functionality; If it meets the preset security level, preset advanced level, preset standardization, preset openness, and preset functionality, generate an adaptation description for the software package to be uploaded and output the adaptation description.

2. The adaptation method of a coal industry Internet platform according to claim 1, characterized in that The performing vulnerability detection on the software package to be uploaded to determine whether the software package to be uploaded meets the preset security level includes: Scan the software package to be uploaded through a third-party binary SCA tool to obtain the vulnerabilities of the software package to be uploaded; If the number of the vulnerabilities is less than the first preset number, determine that the software package to be uploaded meets the preset security level.

3. The adaptation method of a coal industrial Internet platform according to claim 1, wherein, The determining whether the component library and development language meet the preset advanced level includes: Parse all components in the component library, and determine whether all the components hit the preset component library; Determine whether the development language hits the preset development language; If the number of the preset components in the preset component library hit by all the components reaches the second preset number, and the development language hits the preset development language, determine that the component library and development language meet the preset advanced level.

4. The adaptation method of a coal industrial Internet platform according to claim 1, wherein The method further includes: Perform simulation installation on the software package to be uploaded on a virtual machine to obtain the installed software; Run the installed software and perform vulnerability detection, data interface detection, and data set detection on the installed software; Update the number of the vulnerabilities of the software package to be uploaded according to the vulnerability detection result, and determine whether it meets the preset security level according to the updated number of the vulnerabilities; Determine whether the newly detected data interface and data set are allowed to be called according to the data interface detection result and the data set detection result to determine whether it meets the preset openness.

5. A method for adapting a coal industry Internet platform according to claim 1, characterized in that Characterized in that, The method further includes: Perform vulnerability detection on the software package to be uploaded to obtain the vulnerability types of the software package to be uploaded and the number of vulnerabilities of each vulnerability type; Perform text extraction on the technical document to obtain the text information in the technical document, and perform word segmentation on the text information to obtain multiple words; Analyze the software package to obtain the component library of the software package, and the component library includes at least one component; Based on the words and the component library, search for a target software package in the preset software library whose similarity to the software package to be uploaded reaches the preset similarity threshold; Obtain the vulnerability repair logs of each target software package, and repair the software package to be uploaded based on the vulnerability repair logs to obtain the repaired software package to be uploaded; Upload the repaired software package to be uploaded to the platform.

6. The adaptation method of a coal industry Internet platform according to claim 5, characterized in that Each software package in the preset software library corresponds to at least one word. The method for finding a target software package with a similarity to the software package to be uploaded reaching a preset similarity threshold from the preset software library based on the word and the component library includes: Filter out the stop words in the word based on the preset blacklist library to obtain multiple candidate words other than the stop words, where the stop words are the words that hit the preset blacklist library; Determine the target candidate words whose occurrence times reach the preset occurrence threshold from the multiple candidate words; Determine the number of words in the target candidate words of the software package to be uploaded that hit the words of each software package in the preset software library; Determine the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library; Determine the score representing the similarity based on the matching degree, the number, and their respective corresponding coefficients.

7. A method for adapting a coal industry Internet platform according to claim 6, characterized in that, The determining the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library includes: Determine the first component quantity of all components in the component library of the software package to be uploaded, and the second component quantity of all components in the component library of each software package in the preset software library; Calculate the first ratio of the first component quantity to each second component quantity; Compare the component library of the software package to be uploaded with the component library of each software package in the preset software library, and determine the number of consistent components where the software package to be uploaded is consistent with the components of each software package in the preset software library; Determine the matching degree between the component library of the software package to be uploaded and the component library of each software package in the preset software library based on the number of consistent components and the first ratio.

8. A method for adapting a coal industrial Internet platform according to claim 5, characterized in that, Each vulnerability type corresponds to a preset score. The method further includes: Determine the number of vulnerabilities corresponding to each vulnerability type, and determine the abnormal score of the software package to be uploaded based on the preset score and the corresponding number of vulnerabilities of each vulnerability type; Determine the target preset score interval where the abnormal score is located from multiple preset score intervals, and each preset score interval corresponds to a preset period; Determine the preset period of the target preset score interval as the scanning period of the software package to be uploaded.

9. An adaptation device for a coal industrial Internet platform, characterized in that, Includes: A security detection module, configured to obtain the software package to be uploaded and the corresponding technical documents, and perform vulnerability detection on the software package to be uploaded to determine whether the software package to be uploaded meets the preset security; An advancement detection module, configured to analyze the component library and development language of the software package to be uploaded, and determine whether the component library and development language meet the preset advancement; A standardization detection module, configured to determine whether the technical architecture of the software package to be uploaded is consistent with the preset architecture to determine whether it meets the preset standardization; An openness detection module, configured to analyze the data interface and data set of the software package to be uploaded, and determine whether the data interface and data set are allowed to be called to determine whether it meets the preset openness; A functional detection module, which is used to parse the technical document to obtain the functions of the software package to be uploaded, and determine whether the functions meet a preset function list, so as to determine whether the preset functionality is achieved; An adaptation description generation module, which is used to generate an adaptation description of the software package to be uploaded and output the adaptation description when the preset security, preset advancement, preset standardization, preset openness, and preset functionality are achieved.

10. An electronic device, characterized in that, It includes: At least one processor; A memory; At least one application program, wherein the at least one application program is stored in the memory and is configured to be executed by the at least one processor, and the at least one application program: is used to execute a coal industry Internet platform adaptation method according to any one of claims 1 to 8.