Software supply chain detection system based on large language model
Through the software supply chain detection system based on language big models, the problem of insufficient generalization capabilities of existing tools in unknown threats and hidden attacks is solved, efficient, accurate and real-time risk identification of the software supply chain is achieved, false alarm rate is reduced, and intelligent security protection is provided.
Patent Information
- Application Number
- CN202510470348.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-07-18
AI Technical Summary
Existing software supply chain detection tools have problems such as insufficient generalization capabilities, high false positive rates, and real-time bottlenecks when dealing with unknown threats and semantic hidden attacks, making it difficult to effectively prevent potential security risks in complex software development environments.
The software supply chain detection system based on language big models is adopted, including project management, third-party component extraction, Deep_Seek big model analysis, AI interactive question-and-answer and report generation modules, combined with dynamic SBOM generation and asynchronous detection framework, and through multi-dimensional data fusion and self-learning mechanisms, a comprehensive detection model is built to achieve in-depth analysis of software components, dependencies and code characteristics.
It improves the accuracy and response speed of software supply chain detection, identify potential risks in real time, reduces false alarm rates, and provides intelligent security protection solutions.
Smart Images

Figure CN120337231A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of information security and artificial intelligence, and specifically to a software supply chain detection system based on a large language model. Background Art
[0002] With the wide application of open-source software and third-party components, the efficiency of modern software development has been significantly improved, but at the same time, unprecedented supply chain security risks have been introduced; cyber attackers frequently penetrate and damage the software supply chain by means such as malicious code injection, tampering with build tools, or hijacking dependency libraries, posing a serious threat to system security; how to effectively prevent potential risks while ensuring efficient development has become an important problem that needs to be solved urgently; the modern software supply chain has gradually developed into a highly complex system composed of multiple components, developers, third-party suppliers, automation tools, and organizational collaborations; this complex system supports the high efficiency and rapid iteration of software development, enabling organizations to design, develop, test, and deliver software within a short period of time; however, this complexity and collaboration also bring significant security challenges, making the software supply chain an easily attacked surface; in this context, all links of the supply chain, from the developer's environment and the source of components, to dependency libraries and automated processes, and then to delivery channels, may become targets of attacks, and attackers can use any weak link in the system to achieve their goals.
[0003] Currently, most supply chain security detection tools mainly rely on static rule libraries and signature matching technologies. Such methods have significant effects on detecting known vulnerabilities, but have obvious shortcomings in dealing with unknown threats and covert attacks at the semantic level (such as complex dependency relationships and dynamically evolving attack patterns), and generally face core challenges such as insufficient generalization ability (such as poor cross-domain adaptability), high false positive rates (misjudgment of complex code logic), and real-time bottlenecks (large model inference latency); in view of this situation, the present invention analyzes software's calls to third-party components, SBOM lists, backdoor files, etc. based on an AI large model to determine whether there are vulnerabilities in the system and reduce the risk of supply chain attacks. Summary of the Invention
[0004] Aiming at the deficiencies of the prior art, the present invention provides a software supply chain detection system based on a large language model, which solves the problems raised in the above background art.
[0005] To achieve the above objectives, the present invention is realized through the following technical solutions: A software supply chain detection system based on a large language model, including a project management module, a third-party component extraction module, a Deep_Seek large model analysis module, an AI interactive Q&A module, a report generation module, and a user and permission management module;
[0006] Among them,
[0007] The project management module is used to create, manage, and delete detection projects;
[0008] The third-party component extraction module scans and extracts third-party components in the project to generate an SBOM list;
[0009] The DeepSeek large model analysis module uses the DeepSeek large model to deeply analyze the SBOM and third-party components;
[0010] The interactive Q&A module is responsible for interacting with users, and artificial intelligence answers users' questions about component risks, repair suggestions, etc.;
[0011] The report generation module realizes the export of risk descriptions and SBOM lists;
[0012] In the user and permission management module, the system divides users into ordinary users and administrator users according to permissions; administrator users have user management functions and can modify the passwords and permissions of all users.
[0013] Optionally, the project management module also includes a user registration and login module.
[0014] Optionally, the user registration and login module is as follows:
[0015] When the user enters the login username and password on the registration interface, the system encrypts them using the hash with salt encryption algorithm and stores the encrypted algorithm in the database. When the user attempts to log in, the system encrypts the user's input again using the hash with salt encryption algorithm and compares it with the encrypted password stored in the database; if the encrypted user input password matches the stored encrypted password, the system will allow the user to log in.
[0016] Optionally, the third-party component extraction module is as follows:
[0017] After the user logs in and enters the page, they can enter the project name and description to create a new project. By uploading the project source code, the system automatically extracts the third-party components and dependencies therein, generates an SBOM list containing component information, and generates a report.
[0018] Optionally, the user can use an AI large model trained based on DeepSeek to deeply analyze the dependencies and semantic information of these components, identify potential risks and abnormal behaviors, and generate analysis results. At the same time, the system provides an interactive Q&A function to support users in asking questions about the detection results and obtaining instant answers, so as to better understand the sources of risks and solutions.
[0019] Optionally, the Deep_Seek large model analysis module includes a Model, a View, and a Controller;
[0020] Adopt the MVC architecture of Python + Flask, thereby realizing the separation of the system user interface and business logic, enhancing the scalability, reusability, maintainability, and flexibility of the code; embed the large language model into the detection framework to build a new software supply chain security detection model based on LLM.
[0021] Optionally, in the MVC architecture of Python + Flask, the detection function is defined as:
[0022] D(S) = LLM(SBOM(S), Code(S), Context(S))
[0023] where
[0024] S represents the target software project; SBOM(S) represents the generated bill of materials, which details each component and its dependencies in the project; Code(S) represents the semantic features extracted from the source code, such as function calls, data flows, and comments, etc.; Context(S) includes context information such as the build configuration, historical records, and running environment of the software project; through the fusion of these three types of modal data, the large model can perform in-depth analysis in a unified semantic space, capturing abnormal patterns and potential risks that are difficult to identify by traditional static detection methods;
[0025] (2) Embed the pre-trained large language model into the detection process, and build a comprehensive detection model by mining multi-dimensional information such as software components, dependencies, third-party library vulnerabilities, and code features.
[0026] Optionally, the detection model adopts dynamic SBOM (Software Bill of Materials) generation technology and combines an online fine-tuning mechanism to implement an end-to-end joint training strategy; this strategy enables the detection model to gradually optimize parameters during the process of continuously receiving false positive and false negative feedback, thereby improving the overall detection accuracy and response speed.
[0027] Optionally, the report generation module is as follows:
[0028] Report template customization, allowing users to select corresponding information modules according to detection requirements and standards, including detection information, detection standards, and detection results, supporting diverse report layouts and contents;
[0029] Data collection and processing, sorting, analyzing, and interpreting the real-time obtained detection data to provide support for report generation;
[0030] The report is automatically generated. Based on the preset template and the processed data, it automatically fills in and generates a preliminary inspection report, converting the data into charts or graphs;
[0031] Report review and approval. The generated report needs to be reviewed to ensure that the data is accurate, compliant, and meets industry standards. After passing the review, it will be approved.
[0032] The present invention provides a software supply chain detection system based on a large language model, which has the following beneficial effects:
[0033] This software supply chain detection system based on a large language model embeds a pre-trained large language model into the detection process, and combines the dynamically generated SBOM, code semantic parsing, and project context information. The system realizes real-time and accurate identification and assessment of potential risks in the software supply chain; by using the large model to deeply analyze the code and dependencies, it breaks through the limitations of traditional static analysis methods in detecting unknown vulnerabilities and hidden attacks, effectively improving the accuracy and response speed of risk detection, and providing an intelligent and automated technical solution for supply chain security protection in complex software development environments. Brief Description of the Drawings
[0034] Figure 1 It is a schematic diagram of the functional modules of the invention;
[0035] Figure 2 It is a schematic diagram of the process of the invention;
[0036] Figure 3 It is a schematic diagram of the architecture of the invention;
[0037] Figure 4 It is a schematic diagram of the user registration page in the second embodiment of the invention;
[0038] Figure 5 It is a schematic diagram of the project management page in the second embodiment of the invention;
[0039] Figure 6 It is a schematic diagram of the page for extracting third-party components in the second embodiment of the invention;
[0040] Figure 7 It is a schematic diagram of the report generation page in the second embodiment of the invention;
[0041] Figure 8 It is a schematic diagram of the AI analysis page in the second embodiment of the invention;
[0042] Figure 9 It is a schematic diagram of the user management page in the second embodiment of the invention. Detailed Embodiments
[0043] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.
[0044] In the description of the present invention, unless otherwise specified, the meaning of "a plurality" is two or more; the orientation or positional relationships indicated by the terms "upper", "lower", "left", "right", "inner", "outer", "front end", "rear end", "head", "tail", etc. are based on the orientation or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be construed as a limitation of the present invention. In addition, the terms "first", "second", "third", etc. are only used for descriptive purposes, and cannot be construed as indicating or implying relative importance.
[0045] In the description of the present invention, it should be noted that unless otherwise clearly specified and defined, the terms "connected" and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected, or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0046] Please refer to Figures 1 to 3 , a software supply chain detection system based on a large language model, including a project management module, a third-party component extraction module, a Deep_Seek large model analysis module, an AI interactive Q&A module, a report generation module, and a user and permission management module;
[0047] Among them,
[0048] The project management module is used to create, manage, and delete detection projects. The project management module also includes a user registration and login module, specifically as follows:
[0049] The user enters the login username and password on the registration interface. The system encrypts it using the hash with salt encryption algorithm and stores the encrypted algorithm in the database. When the user attempts to log in, the system encrypts the user's input again using the hash with salt encryption algorithm and compares it with the encrypted password stored in the database; if the encrypted user input password matches the stored encrypted password, the system will allow the user to log in;
[0050] The third-party component extraction module scans and extracts third-party components in the project to generate an SBOM list. The third-party component extraction module is specifically as follows:
[0051] After the user logs in and enters the page, they can input the project name and description to add a project. By uploading the project source code, the system automatically extracts the third-party components and dependency relationships therein, generates an SBOM list containing component information, and generates a report.
[0052] The DeepSeek large model analysis module uses the DeepSeek large model to deeply analyze the SBOM and third-party components, and uses the AI large model trained based on DeepSeek to deeply analyze the dependency relationships and semantic information of these components, identify potential risks and abnormal behaviors, and generate analysis results. At the same time, the system provides an interactive Q&A function, supporting users to ask questions about the detection results and obtain instant answers to better understand the risk sources and solutions.
[0053] The Deep_Seek large model analysis module includes a Model, a View, and a Controller.
[0054] Adopt the MVC architecture of Python + Flask, thereby separating the system user interface from the business logic, enhancing the scalability, reusability, maintainability, and flexibility of the code; embed the large language model into the detection framework to build a new software supply chain security detection model based on the LLM.
[0055] In the MVC architecture of Python + Flask, the detection function is defined as:
[0056] D(S) = LLM(SBOM(S), Code(S), Context(S))
[0057] Among them,
[0058] S represents the target software project; SBOM(S) represents the generated bill of materials, which details the components and their dependency relationships in the project; Code(S) represents the semantic features extracted from the source code, such as function calls, data flows, and comments; Context(S) includes context information such as the build configuration, historical records, and running environment of the software project. Through the fusion of these three types of modal data, the large model can perform in-depth parsing in a unified semantic space, capturing abnormal patterns and potential risks that are difficult to identify by traditional static detection methods.
[0059] (2) Embed the pre-trained large language model into the detection process, and build a comprehensive detection model by mining multi-dimensional information such as software components, dependency relationships, third-party library vulnerabilities, and code features.
[0060] The detection model adopts dynamic SBOM (Software Bill of Materials) generation technology and combines an online fine-tuning mechanism to implement an end-to-end joint training strategy. This strategy enables the detection model to gradually optimize parameters while continuously receiving false positive and false negative feedback, thereby improving the overall detection accuracy and response speed.
[0061] The interactive Q&A module is responsible for interacting with users, and artificial intelligence answers users' questions about component risks, repair suggestions, etc.
[0062] The report generation module realizes the export of risk descriptions and SBOM lists, as follows:
[0063] Report template customization allows users to select corresponding information modules according to detection requirements and standards, including detection information, detection standards, and detection results, supporting diverse report layouts and contents.
[0064] Data collection and processing sorts, analyzes, and interprets the real-time detected data to support report generation.
[0065] Automatic report generation automatically fills and generates a preliminary detection report based on a preset template and processed data, converting the data into charts or graphs.
[0066] Report review and approval: The generated SBOM list report needs to be reviewed to ensure the data is accurate, compliant, and meets industry standards. After the review is error-free, it is approved.
[0067] In the user and permission management module, the system divides user permissions into ordinary users and administrator users. Administrator users have user management functions and can modify the passwords and permissions of all users.
[0068] Embodiment 2: As Figures 4 to 9 shown, the software supply chain detection system based on a large language model has the following specific steps:
[0069] Step 1: User registration and login. As Figure 4 shown, the user enters the login username and password on the registration interface. The system encrypts them using the hash with salt encryption algorithm and stores the encrypted algorithm in the database. When the user attempts to log in, the system encrypts the user input again using the hash with salt encryption algorithm and compares it with the encrypted password stored in the database. If the encrypted user input password matches the stored encrypted password, the system will allow the user to log in. As Figure 4 shown;
[0070] Step 2: Extract the functions of third-party components. As Figure 5 、 Figure 6 and Figure 7As shown, after the user logs in to the page, they can enter the project name and description to add a project. By uploading the project source code, the system automatically extracts the third-party components and dependencies therein, generates an SBOM list containing component information, and generates a report; project management Figure 5 is shown; extracting third-party components such as Figure 6 is shown; report generation is shown as Figure 7 shown;
[0071] Step 3: AI analysis module, as Figure 8 shown, the user can use the AI large model trained based on Deep_Seek to deeply analyze the dependency relationships and semantic information of these components, identify potential risks and abnormal behaviors, and generate analysis results; at the same time, the system provides an interactive Q&A function to support users in asking questions about the detection results and obtaining instant answers, so as to better understand the source of risks and solutions; the AI analysis module is as Figure 8 shown;
[0072] Step 4: User management module, as Figure 9 shown, the system divides users into ordinary users and administrator users; administrator users have user management functions and have functions such as modifying the passwords and permissions of all users; the user management model is as Figure 9 shown.
[0073] The above is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.
Claims
1. A software supply chain detection system based on a large language model, characterized in that, It includes a project management module, a third-party component extraction module, a Deep_Seek large model analysis module, an AI interactive Q&A module, a report generation module, and a user and permission management module; Among them, The project management module is used to create, manage, and delete detection projects; The third-party component extraction module scans and extracts third-party components in the project to generate an SBOM list; The DeepSeek large model analysis module uses the DeepSeek large model to deeply analyze the SBOM and third-party components; The interactive Q&A module is responsible for interacting with users, and the artificial intelligence answers users' questions about component risks and repair suggestions; The report generation module realizes the export of risk descriptions and SBOM lists; In the user and permission management module, the system divides users' permissions into ordinary users and administrator users; administrator users have user management functions and have the functions of modifying the passwords and permissions of all users.
2. The software supply chain detection system based on a large language model according to claim 1, wherein: The project management module also includes a user registration and login module.
3. The software supply chain detection system based on a large language model according to claim 2, characterized in that: The user registration and login module is as follows: Users enter the login username and password on the registration interface. The system encrypts them using the hash with salt encryption algorithm and stores the encrypted algorithm in the database; when users try to log in, the system encrypts the users' input again using the hash with salt encryption algorithm and compares it with the encrypted password stored in the database; if the encrypted user input password matches the stored encrypted password, the system will allow the users to log in.
4. The software supply chain detection system based on a large language model according to claim 1, characterized in that: The third-party component extraction module is as follows: After users log in to the page, they enter the project name and description to create a new project. By uploading the project source code, the system extracts the third-party components and dependency relationships in it, generates an SBOM list containing component information, and generates a report.
5. The software supply chain detection system based on a large language model according to claim 1, wherein: The AI large model trained by DeepSeek deeply analyzes the dependency relationships and semantic information of these components, identifies potential risks and abnormal behaviors, and generates analysis results; at the same time, the system provides an interactive Q&A function to support users in asking questions about the detection results and obtaining instant answers.
6. The software supply chain detection system based on a large language model according to claim 1, wherein: The Deep_Seek large model analysis module includes a model, a view, and a controller; Adopting the MVC architecture of Python+Flask, the separation of the system user interface and business logic is realized, enhancing the scalability, reusability, maintainability, and flexibility of the code; embedding the large language model into the detection framework to build a new software supply chain security detection model based on LLM.
7. The software supply chain detection system based on a large language model according to claim 6, characterized in that: The detection function defined in the MVC architecture of Python+Flask is: D(S) = LLM(SBOM(S), Code(S), Context(S)) Among them, Let \(S\) denote the target software project; \(SBOM(S)\) represents the generated bill of materials, which details each component in the project and its dependencies; \(Code(S)\) represents the semantic features extracted from the source code, including function calls, data flows, and comments; \(Context(S)\) includes context information such as the build configuration, history, and runtime environment of the software project. Through the fusion of these three types of modal data, the large model conducts in-depth analysis within a unified semantic space to capture abnormal patterns and potential risks that are difficult to identify by traditional static detection methods. (2) Embed the pre-trained large language model into the detection process, and construct a comprehensive detection model by mining multi-dimensional information such as software components, dependencies, third-party library vulnerabilities, and code features.
8. The software supply chain detection system based on a large language model according to claim 7, wherein: The detection model adopts dynamic SBOM generation technology and combines an online fine-tuning mechanism to implement an end-to-end joint training strategy. This strategy enables the detection model to gradually optimize its parameters during the process of continuously receiving false positive and false negative feedback, thereby improving the overall detection accuracy and response speed.
9. The software supply chain detection system based on a large language model according to claim 1, wherein: The report generation module is as follows: Report template customization allows users to select corresponding information modules according to detection requirements and standards, including detection information, detection standards, and detection results, and supports diverse report layouts and contents. Data collection and processing organize, analyze, and interpret the real-time acquired detection data to support report generation. Automatic report generation automatically fills in and generates a preliminary detection report based on the preset template and the processed data, and converts the data into charts or graphs. Report review and approval: The generated report needs to be reviewed to ensure that the data is accurate, compliant, and meets industry standards. After passing the review, it will be approved.
Citation Information
Cited By
Security vulnerability detection method and device, computer program product and storage medium
CN120805148A