Software supply chain interruption risk assessment method and device, equipment, medium and program product

By constructing a supply chain entity relationship diagram and collecting current events in real time, the software supply chain disruption risk is dynamically assessed, solving the problem of untimely assessment in existing technologies and achieving accurate quantification and real-time monitoring of risks.

CN120671132APending Publication Date: 2025-09-19INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411945075.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing technologies are unable to reflect dynamic changes in a timely manner when assessing software supply chain disruption risks, resulting in the inability to quickly identify and respond to potential risks, and static monitoring methods are not comprehensive enough.

Method used

By constructing a supply chain entity relationship diagram, current events associated with the target software are collected in real time. By using sentiment classification models and risk propagation paths, supply chain disruption risks are dynamically assessed and risk changes are captured and quantified in real time.

Benefits of technology

It has achieved dynamic and accurate quantitative assessment of software supply chain disruption risks, improved the real-time and accuracy of risk assessment, and enhanced the company's ability to respond to potential risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671132A_ABST
    Figure CN120671132A_ABST
Patent Text Reader

Abstract

The invention provides a software supply chain interruption risk assessment method, and relates to the field of artificial intelligence, the field of information security, the field of financial science and technology or other technical fields. The method comprises the steps that at least one current event associated with entity nodes contained in a supply chain entity relation graph of target software is collected in real time; determining a first score of an associated entity node according to the at least one current event, wherein the first score indicates a risk degree of a supply chain entity mapped by the node; obtaining respective first scores of N end point entity nodes connected with a target software node in the supply chain entity relation graph; a second score of the target software is calculated according to the first scores of the N end point entity nodes, the second score indicates the risk degree of supply chain interruption of the target software, and N is an integer larger than or equal to 1.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the fields of artificial intelligence, information security, financial technology, or other technical fields, and more specifically, to a software supply chain disruption risk assessment method, apparatus, device, medium, and program product. Background Art

[0002] Driven by digitalization, the software supply chain is becoming increasingly complex, diverse, and globalized. Enterprises face numerous challenges in software supply chain management, including complex links, growing processes and supply chain lengths, and a multitude of suppliers. Risks can exist at every stage of the software supply chain, threatening the security of an enterprise's software supply chain.

[0003] In related technologies, risk indicator data corresponding to each risk indicator of each supplier can be determined based on the operational information and product information of multiple suppliers in the supply chain, the operational information of each supplier's products in the supply chain, and multiple preset risk indicators. Based on the preset supplier weights, the comprehensive risk data of each supplier is weighted and calculated to obtain the comprehensive risk data of the supply chain.

[0004] In the process of realizing the inventive concept of the present disclosure, the inventors discovered that the software supply chain is becoming increasingly complex, the processes and chain lengths are increasing, and there are many suppliers. The relevant technologies only conduct risk assessments from the perspective of risk indicators, which is not comprehensive and is a static monitoring with a long cycle. It is difficult to reflect the dynamic changes in the software supply chain environment in a timely manner, resulting in the inability to quickly identify and respond to potential risks. Summary of the Invention

[0005] In view of the above problems, the present disclosure provides a software supply chain disruption risk assessment method, apparatus, device, medium, and program product.

[0006] According to a first aspect of the present disclosure, a software supply chain disruption risk assessment method is provided, comprising: real-time collection of at least one current event associated with an entity node included in a supply chain entity relationship diagram of target software; determining a first score of the associated entity node based on the at least one current event, the first score indicating the risk level of the supply chain entity mapped by the node; obtaining a first score of each of N terminal entity nodes connected to the target software node in the supply chain entity relationship diagram, wherein the first score of at least one of the terminal entity nodes is obtained based on the first score of the connected starting point entity node or the first score of the intermediate entity node; and calculating a second score of the target software based on the first scores of each of the N terminal entity nodes, wherein the second score indicates the risk level of the target software supply chain disruption, where N is an integer greater than or equal to 1.

[0007] According to an embodiment of the present disclosure, determining the first score of the associated entity node based on the at least one current event includes: determining the event risk score of the associated entity node based on the at least one current event; determining the risk propagation scores of the remaining entity nodes connected to each of the associated entity nodes through directed edges; and obtaining the first score of each entity node based on the event risk score and the risk propagation score.

[0008] According to an embodiment of the present disclosure, determining the event risk score of the associated entity node based on the at least one current event includes: obtaining an initial score based on the attributes of the supply chain entity mapped by each of the associated entity nodes; obtaining the risk impact factor of each current event of each of the associated entity nodes, and the sum of all the risk impact factors; and obtaining the event risk score of each entity node based on the sum and the initial score.

[0009] According to an embodiment of the present disclosure, obtaining the risk impact factor of each current event of each associated entity node includes: performing sentiment classification on each current event of each associated entity node according to a sentiment classification model; and determining the risk impact factor according to the sentiment type of each current event.

[0010] According to an embodiment of the present disclosure, the sentiment classification model includes a sentiment vocabulary obtained based on supply chain risk historical data and target software industry data, and sentiment classification of each current event of each associated entity node according to the sentiment classification model includes: matching the event content of each current event with the vocabulary set in the sentiment vocabulary; and sentiment classification of each current event based on at least one matched vocabulary.

[0011] According to an embodiment of the present disclosure, real-time collection of at least one current event associated with an entity node included in a supply chain entity relationship diagram of a target software includes: using S pre-configured collection rules to filter out at least one current event, wherein each collection rule is obtained based on historical supply chain risk data, and S is an integer greater than or equal to 1; using Q pre-configured classification rules to determine the risk type of each current event, wherein each classification rule is obtained based on historical supply chain risk data of a corresponding type, and Q is an integer greater than or equal to 1; and associating the risk type of each current event with the corresponding entity node.

[0012] According to an embodiment of the present disclosure, there is at least one risk propagation path in the supply chain entity relationship graph, which includes a starting point entity node, at least one intermediate entity node and an end point entity node connected in sequence.

[0013] According to an embodiment of the present disclosure, after calculating the second score of the target software based on the first scores of each of the N endpoint entity nodes, the method further includes: executing early warning measures of corresponding levels based on the second score of the target software, wherein different second score ranges correspond to different early warning measures.

[0014] According to an embodiment of the present disclosure, after calculating the second score of the target software based on the first scores of each of the N terminal entity nodes, the method further includes: generating early warning information for the software supply chain interruption risk when the second score of the target software is less than or equal to a first threshold; wherein the early warning information includes visually displaying at least one target risk propagation path in the supply chain entity relationship diagram, and each of the target risk propagation paths is determined based on the path where the entity nodes whose first scores are less than or equal to the second threshold are located.

[0015] Another aspect of an embodiment of the present disclosure provides a software supply chain disruption risk assessment device, comprising: an event collection module for collecting, in real time, at least one current event associated with an entity node included in a supply chain entity relationship diagram of a target software; a node scoring module for determining, based on the at least one current event, a first score for the associated entity node; an endpoint scoring module for obtaining a first score for each of N endpoint entity nodes connected to the target software node in the supply chain entity relationship diagram, wherein the first score of at least one of the endpoint entity nodes is obtained based on the first score of the connected starting entity node or the first score of the intermediate entity node, and the first score indicates the risk level of the supply chain entity mapped by the node; and an disruption assessment module for calculating a second score for the target software based on the first scores of the N endpoint entity nodes, wherein the second score indicates the risk level of the target software supply chain disruption, and N is an integer greater than or equal to 1.

[0016] Another aspect of an embodiment of the present disclosure provides an electronic device, comprising: one or more processors; and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the method described above.

[0017] Another aspect of an embodiment of the present disclosure provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the processor is caused to perform the method described above.

[0018] Another aspect of an embodiment of the present disclosure provides a computer program product, including a computer program, which implements the above method when executed by a processor.

[0019] One or more of the above-mentioned embodiments have the following beneficial effects: Different from the static evaluation method in related technologies, based on constructing the supply chain entity relationship diagram of the target software, at least one current event associated with the entity node contained therein is obtained, and events that may affect the stability of the supply chain are extracted, thereby capturing and evaluating the dynamic changes of the supply chain disruption risk in real time. The supply chain entity relationship diagram can intuitively display the relationship between the various supply chain entities in the software supply chain and the dynamic changes in the attributes of each supply chain entity. The dynamic risk scoring system is used to convert complex risk information into intuitive scoring results, and the accuracy and real-time performance of risk assessment are improved through the idea of ​​dynamic risk propagation, thereby achieving a dynamic and accurate comprehensive quantitative assessment of the supply chain disruption risk of the target software node. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:

[0021] Figure 1 A diagram schematically illustrates an application scenario for implementing software supply chain disruption risk assessment according to an embodiment of the present disclosure;

[0022] Figure 2 Schematically shows a data structure diagram of a supply chain entity relationship diagram according to an embodiment of the present disclosure;

[0023] Figure 3 Schematically shows a supply chain entity relationship diagram according to an embodiment of the present disclosure;

[0024] Figure 4 A flowchart of a software supply chain disruption risk assessment method according to an embodiment of the present disclosure is schematically shown;

[0025] Figure 5 Schematically shows a flow chart of real-time acquisition events according to an embodiment of the present disclosure;

[0026] Figure 6 Schematically shows a flow chart for determining a first score according to an embodiment of the present disclosure;

[0027] Figure 7 Schematically shows a flow chart for obtaining risk impact factors according to an embodiment of the present disclosure;

[0028] Figure 8 The following schematically shows a structural block diagram of a software supply chain disruption risk assessment device according to an embodiment of the present disclosure;

[0029] Figure 9 A block diagram of an electronic device suitable for implementing a software supply chain disruption risk assessment method according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION

[0030] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.

[0031] With the acceleration of globalization and digitalization, software supply chains are becoming increasingly complex, involving numerous suppliers and components with highly intertwined dependencies. This complexity not only increases the risk of supply chain attacks but also makes supply chain disruption risks caused by licensing changes, product delistings, and supplier bankruptcies more difficult to predict and manage. Traditional supply chain risk management methods rely on static monitoring, periodic risk assessments, and manual updates of software information. These methods fail to reflect dynamic changes in the supply chain environment, hindering the rapid identification and response to potential risks. Therefore, a method that can capture, dynamically assess, and issue early warnings for software supply chain disruption risks in real time can enhance enterprises' ability to address potential risks and ensure business continuity and system stability.

[0032] Some embodiments of the present disclosure provide a software supply chain disruption risk assessment method that can be dynamically evaluated. Different from the static assessment method in related technologies, based on constructing a supply chain entity relationship diagram of the target software, at least one current event associated with the entity nodes contained therein is obtained, and events that may affect the stability of the supply chain are extracted, thereby capturing and evaluating the dynamic changes of the supply chain disruption risk in real time. The information contained in each entity node and the node status will continue to change. The supply chain entity relationship diagram can intuitively show the relationship between each supply chain entity in the software supply chain and the dynamic changes in the attributes of each supply chain entity. The complex risk information is converted into intuitive scoring results through a dynamic risk scoring system, and the accuracy and real-time performance of the risk assessment are improved through the idea of ​​dynamic risk propagation, so as to achieve a dynamic and accurate comprehensive quantitative assessment of the supply chain disruption risk of the target software node.

[0033] Figure 1 The following schematically illustrates an application scenario diagram for implementing software supply chain disruption risk assessment according to an embodiment of the present disclosure. Figure 1 What is shown are merely examples to which the embodiments of the present disclosure may be applied, to help those skilled in the art understand the technical content of the present disclosure, but does not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments or scenarios.

[0034] like Figure 1As shown, the application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 is used as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links or optical fiber cables.

[0035] A user may use a first terminal device 101, a second terminal device 102, or a third terminal device 103 to interact with a server 105 via a network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, or the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).

[0036] The first terminal device 101 , the second terminal device 102 , and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.

[0037] Server 105 can be a server that provides various services, such as a backend management server (for example only) that supports websites browsed by users using first terminal device 101, second terminal device 102, and third terminal device 103. The backend management server can analyze and process received user requests and other data, and provide feedback (e.g., web pages, information, or data obtained or generated based on user requests) to the terminal devices. For example, server 105 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud computing, network services, and middleware services.

[0038] For example, the software involved in the present disclosure may include applications such as client applications and web applications (abbreviated as APP in English), wherein the client (i.e., front-end) and the server (i.e., back-end) can communicate data through network messages. For example, in the APP client, the parameters that the server needs to obtain from the client are assembled, and the network request method is called to send them to the server.

[0039] It should be noted that the software supply chain disruption risk assessment method provided in the embodiments of the present disclosure can generally be executed by at least one of a terminal device or a server. Accordingly, the software supply chain disruption risk assessment device provided in the embodiments of the present disclosure can generally be installed in at least one of a terminal device or a server.

[0040] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0041] The following will be based on Figure 1 The scene described by Figures 2 to 7 The software supply chain disruption risk assessment method according to an embodiment of the present disclosure is described in detail.

[0042] Figure 2 A data structure diagram of a supply chain entity relationship diagram according to an embodiment of the present disclosure is schematically shown. Figure 3 The diagram schematically shows a supply chain entity relationship diagram according to an embodiment of the present disclosure.

[0043] For example, data related to software supply chain disruption risks can be collected from data sources such as the enterprise's software management system and software bill of materials, and then analyzed as follows: Figure 2 The data structure shown in the figure processes and stores the data in a unified manner for subsequent use. The following will expand on the data collection and data processing of the supply chain entity relationship diagram.

[0044] During the data collection phase, the following information is obtained from the enterprise's internal software management system and software material list: Figure 2 The data shown includes software product information such as product name, version information, supplier, license information, and hash value. This type of data is usually structured data with a fixed format and is obtained from the data source through a customized data driver.

[0045] During the data processing phase, the collected data in different formats and structures are standardized and converted into a unified format for storage. To facilitate the subsequent construction of entity-relationship diagrams, structures corresponding to the various entity nodes in the entity-relationship diagram are used to store relevant information about the entities. Each structure has multiple fields for storing information related to each entity, such as name, version number, supplier information, etc. The structure also includes data describing the dependencies between entities. This design allows for the subsequent construction of entity-relationship diagrams to directly use this structured information to draw relationships between entities, such as the dependencies between software products and their components, and the connections between components and their suppliers.

[0046] In some embodiments, the supply chain entity relationship diagram includes a target software node, which maps a software product, including key attributes such as product name, version, supplier, licensing information, and maintainer.

[0047] The supply chain entity relationship diagram includes at least one of the following entity nodes:

[0048] Component nodes are used to map the components that the target software depends on. Components include libraries, frameworks, or modules that the software product relies on. Component nodes include attributes such as name, version, vendor, and licensing information. Changes to licensing information or compatibility issues can affect the availability of the software product and cause supply chain disruptions.

[0049] Supplier nodes are used to map the target software or component suppliers. Suppliers are companies or organizations that provide software products and components and have actual control over them. Supplier nodes contain attributes such as supplier name, website (URL), contact information (phone number), and location. This information helps identify supply chain disruption risks caused by supplier factors.

[0050] The License node maps the target software's license document or component's license document. License documents control the use, distribution, and modification of software products and components. Changes to the license may render the software or component unusable. The License node contains attributes such as the license name, version, and issuing authority.

[0051] Maintainer nodes are used to map the maintainers of the target software or components affiliated with the vendor. Maintainers are individuals or organizations responsible for maintaining software products and components. The nodes contain attributes such as name, contact information, company, and location. This information can be used to assess the reliability and reachability of maintainers.

[0052] A geolocation node is used to map the location of any supplier or maintenance personnel. Both suppliers and maintenance personnel have geographic location attributes. Force majeure factors caused by geographic location (such as major natural disasters, import and export restrictions, etc.) may affect the supply of products and maintenance services, disrupt supply relationships, and create supply chain disruption risks.

[0053] Reference Figure 3 ,The dependency relationships between entities reflect the interactions and dependencies between entities such as software products, ,components, suppliers, and maintainers, as follows:

[0054] "hasComponent" relationship: A composition relationship exists between a software product and its components. A software product is usually not a single entity, but a complex system composed of multiple components.

[0055] "hasSupplier" relationship: A supplier relationship exists between a software product or component and its supplier. Software products and components are typically provided by suppliers, and changes or stability of suppliers directly affect the availability of software products and components.

[0056] Obey relationships: Ownership relationships represent the subordination of software products and components to licensing information. This relationship is based on the requirement that the legal use, distribution, and modification of software products and components must comply with licensing regulations. Any changes to licensing information may impact the software supply chain.

[0057] "hasMaintainer" relationship: This relationship describes the connection between software products and components and their maintainers. Software products and components require maintenance by maintainers, and interruptions in maintenance services can impact the stability of the software supply chain.

[0058] "employedBy" relationship: An employment relationship, which indicates the affiliation between a maintainer and a specific vendor. Maintainers are usually employed by a specific vendor.

[0059] "locatedAt" relationships: Location relationships indicate the geographic location of suppliers and maintenance personnel. This relationship indicates that the stability of the software supply chain is also affected by geography. Force majeure factors such as natural disasters or import / export restrictions can cause supply disruptions of software products or maintenance services.

[0060] After data collection and processing, a supply chain entity relationship diagram that can model the software supply chain can be constructed. The construction of the entity relationship diagram can reflect the complex relationships between entities in the software supply chain, provide a basis for subsequent risk assessment, and also facilitate users to intuitively view the structure of the entire software supply chain. Figure 3 The construction process of the supply chain entity relationship diagram shown may include the following steps:

[0061] (1) Entity recognition and extraction: Identify entity information, such as software products, suppliers, components, etc., from the collected and processed data, and extract relevant information from the structure that stores the entity information.

[0062] (2) Entity node creation: Use graph database tools to create a graph node for each entity and map the extracted information to node attributes so that users can view the detailed information of the node from the entity relationship diagram.

[0063] (3) Determination of relationship type: Analyze and determine the types of dependency relationships between entities, such as "dependency", "supply", "maintenance", etc.

[0064] (4) Adding directed edges: Based on the relationship between entities, use graph database tools to add directed edges between corresponding graph nodes. The attributes of the edges reflect the type of relationship.

[0065] (5) Graphical interface display: In order to intuitively display the entity relationship diagram stored in the graph database to users, a graphical user interface is used to visualize the entity relationship diagram.

[0066] Below, as Figure 3 Taking the supply chain entity relationship diagram shown in the figure as an example, the various execution steps of the software supply chain disruption risk assessment method are further explained.

[0067] Figure 4 The flowchart of the software supply chain disruption risk assessment method according to an embodiment of the present disclosure is schematically shown.

[0068] like Figure 4 As shown, this embodiment includes:

[0069] In operation S410 , at least one current event associated with an entity node included in a supply chain entity relationship graph of the target software is collected in real time;

[0070] For example, with authorization, web crawler technology can be used to access and monitor multiple Internet data sources in real time, including product homepages (to obtain the latest announcements, update logs and related information of software products), news media (to monitor reports from mainstream news websites and industry portals), social media platforms (to capture relevant discussions and user feedback on social media platforms), technical forums (to obtain discussion dynamics in the developer community) and supplier announcements (to monitor financial reports and operational dynamics published on the supplier's official website), etc.

[0071] Current events include newly occurring events related to an entity node that may affect the stability of the supply chain. For example, a current event for an entity node may be a supplier declaring bankruptcy or a software library experiencing a security vulnerability.

[0072] It is understood that in operation S410, current events associated with one or more entity nodes may be collected in real time, or current events that may affect supply chain stability may not occur at any entity node. When current events associated with one or more entity nodes are collected, the following operations are performed.

[0073] In operation S420 , a first score of the associated entity node is determined based on the at least one current event, the first score indicating a risk level of the supply chain entity mapped by the node;

[0074] For example, a neural network-based risk assessment model can be pre-trained, which can score the risk of each associated entity node based on event type, impact scope, and historical data, and based on the attributes of the entity node and the current event.

[0075] Alternatively, a pre-built event-based risk assessment model can be used to assess the risk of each entity node based on a predefined set of event rules. These rules can be developed based on expert knowledge and historical data to determine the specific impact of different event types, impact scopes, and historical performance on risk scores.

[0076] In some embodiments, as Figure 3 ,There is at least one risk propagation path in the supply chain entity ,relationship graph, including a starting entity node, at least one intermediate entity node and an ,end entity node that are connected in sequence.

[0077] In operation S430, a first score of each of N terminal entity nodes connected to the target software node in the supply chain entity relationship graph is obtained, wherein the first score of at least one terminal entity node is obtained based on the first score of the starting entity node or the first score of the intermediate entity node connected to it in the risk propagation path;

[0078] For example, the objective correlation between entity nodes can be used to consider the impact of each entity node in the form of risk propagation. In this way, the risk is considered to be transmitted in the form of propagation towards the target software node in each risk propagation path.

[0079] For example, risk assessment of each entity node can be completed before or after constructing the supply chain entity relationship diagram, or simultaneously with the construction of the relationship network diagram. For example, a scoring card algorithm (such as feature weighted fusion, Bayesian information fusion algorithm, etc.) or a machine learning algorithm (such as support vector machine algorithm, logistic regression algorithm, and decision tree algorithm, etc.) can be used to initially score the inherent risk of each entity node.

[0080] In operation S440 , a second score of the target software is calculated based on the first scores of the N endpoint entity nodes, where the second score indicates a risk level of supply chain disruption of the target software, and N is an integer greater than or equal to 1.

[0081] For example, the second score of the target software may be obtained by summing the first scores of the N endpoint entity nodes.

[0082] Alternatively, graph centrality analysis can be used to assess node importance. The number of connections to a node can be used to measure its importance. The more nodes a terminal entity node connects to, the greater its weight is assigned. The first scores of each of the N terminal entity nodes are then weighted to produce a second score for the target software.

[0083] Alternatively, machine learning techniques can be used to train a model to predict the risk of software supply chain disruption. By training on a large amount of historical data (including the first scores and other relevant features of end-point entities), it is possible to learn which types of end-point characteristics are highly correlated with supply chain disruption risk. The trained model is then used to process the end-point features and the first scores to predict the second score of the target software.

[0084] According to the embodiments of the present disclosure, dynamic changes in supply chain disruption risks can be captured and assessed in real time. The information contained in each entity node and the node status are constantly changing. The supply chain entity relationship diagram can intuitively display the relationships between supply chain entities in the software supply chain and the dynamic changes in the attributes of each supply chain entity. A dynamic risk scoring system transforms complex risk information into intuitive scoring results, and the accuracy and real-time nature of risk assessment are improved through the concept of dynamic risk propagation, achieving a dynamic, accurate, and comprehensive quantitative assessment of the supply chain disruption risk of the target software node.

[0085] Figure 5 The flowchart of real-time collection of events according to an embodiment of the present disclosure is schematically shown.

[0086] like Figure 5 As shown, this embodiment is one of the embodiments of operation S210, including:

[0087] In operation S510, at least one current event is screened using S pre-configured collection rules, where each collection rule is obtained based on historical supply chain risk data of a corresponding type, and S is an integer greater than or equal to 1;

[0088] To identify and extract risk events that could impact supply chain stability, a set of collection rules must be established in advance. Keywords and phrases related to supply chain disruption risks can be defined, such as "bankruptcy," "discontinuation of production," "licensing change," "product delisting," "supplier merger and acquisition," and "vulnerability." Then, a set of collection rules containing these keywords can be developed. For example, if (text contains "bankruptcy" OR "discontinuation of production" OR "licensing change" OR "product delisting" OR "supplier merger" OR "acquisition") THEN flag it as a potential risk event.

[0089] Applying the above collection rules, the captured raw data is screened and extracted to determine which text fragments constitute potential risk events. Qualified text fragments are extracted and stored as structured risk event data.

[0090] In operation S520, the risk type of each current event is determined using Q pre-configured classification rules, each classification rule being derived based on historical supply chain risk data of a corresponding type, where Q is an integer greater than or equal to 1;

[0091] After successfully extracting potential risk events, these events are categorized using pre-set classification rules and labeled with their respective risk types. Risk types include supplier risk (involving the supplier's financial status, operational changes, etc.), technical risk (involving technical vulnerabilities in software products, deprecation of dependent components, etc.), and legal risk (involving licensing changes, compliance issues, etc.).

[0092] The event classification process uses a matching mechanism based on classification rules to categorize events into corresponding risk types. For example: if (the event contains "bankruptcy" or "discontinuation of production"), then it is classified as a vendor risk; if (the event contains "vulnerability disclosure" or "dependency deprecation"), then it is classified as a technical risk.

[0093] In operation S530 , the risk type of each current event is associated with a corresponding entity node.

[0094] According to the embodiments of the present disclosure, a rule-based event extraction mechanism can promptly capture risk events that impact supply chain stability. This process not only enhances the efficiency of risk classification, as automated risk classification reduces the workload of manual classification and improves overall efficiency, but also associates risk types with entity nodes, enabling more accurate assessment and management of supply chain disruption risks.

[0095] Figure 6 The flowchart of determining the first score according to an embodiment of the present disclosure is schematically shown.

[0096] like Figure 6 As shown, this embodiment is one of the embodiments of operation S220, including:

[0097] In operation S610, an event risk score of an associated entity node is determined based on at least one current event;

[0098] For example, each event may be scored based on its severity, urgency, and potential impact using a pre-set scoring criteria, which may be derived from expert experience.

[0099] Alternatively, we can first collect historical data on supply chain disruption events, including key information such as event type, impact scope, and duration. Next, we can apply statistical analysis methods, such as regression analysis, to identify key factors influencing event risk scores. We can then build a scoring model that automatically assigns event risk scores to associated entity nodes based on the event characteristics.

[0100] Alternatively, an expert system containing supply chain risk management knowledge can be constructed. This system embeds expert risk assessment logic for different types of events. Key features are extracted from each current event, such as its urgency and the supply chain links it affects. These extracted features are input into the expert system to generate event risk scores for the associated entity nodes.

[0101] Alternatively, in some embodiments, determining an event risk score of an associated entity node based on at least one current event includes:

[0102] First, an initial score is obtained based on the attributes of the supply chain entity mapped by each associated entity node;

[0103] Exemplarily, the initial score includes a score obtained based on attributes (such as financial status, historical performance, etc.) of the supply chain entity mapped by the entity node.

[0104] The premise of quantitative risk scoring is to have metrics that can be used for scoring. To identify disruption risks in the software supply chain, in some embodiments, a measurement model for quantitatively describing software supply chain disruption risks is proposed. The model includes seven specific risks that may cause software supply chain disruptions and corresponding metrics, as shown in Table 1.

[0105] The metrics in the model can be divided into three categories: the first is information that can be directly obtained from the entity-relationship diagram, such as authorization and licensing information; the second is information that needs to be further processed based on the data in the entity-relationship diagram. For example, by traversing all nodes related to software product A in the entity-relationship diagram and obtaining geographical location-related information in the nodes, the geographical distribution of suppliers and maintenance personnel of software product A can be statistically obtained. When the geographical location involved in software product A encounters import and export restrictions, natural disasters, etc., the supply interruption risk of software product A will be reflected in the initial score through metric indicators, and will be reflected in the risk propagation score of subsequent nodes through risk propagation; the third is information that needs to be manually supplemented by the user. For example, the user can measure the substitutability of software product A and score it based on experience and knowledge.

[0106] Table 1: Software supply chain disruption risk measurement model

[0107]

[0108] For example, "License Change" can be used as a metric to evaluate the Authorization and Licensing node, using attributes such as license information and change information to derive an initial score for the Authorization and Licensing node. "Product Delisting" and "Supplier Bankruptcy or Business Restructuring" can each be used as a metric to evaluate the Supplier node, using attributes such as the supplier's credit score and financial reports to derive an initial score for the Supplier node. "Poor Substitutability" and "Product Upgrade and Compatibility" can each be used as a metric to evaluate the Software node, using attributes such as substitutability, version update frequency, and the number of user-reported compatibility issues to derive an initial score for the Software node. "Technical Support and Service Level" can be used as a metric to evaluate the Maintenance Personnel node, using attributes such as user satisfaction surveys and fault response time to derive a score for the Maintenance Personnel node. "Occurrence of Force Majeure Factors Related to Geographic Location" can be used as a metric to evaluate the Geographic Location node, using the geographical distribution of suppliers, the geographical distribution of maintenance personnel (e.g., concentration; the more concentrated, the more dangerous, the lower the score), and the number of Force Majeure events in each location to derive an initial score for the Geographic Location node.

[0109] For example, the initial score range is [0, 10], where a higher score indicates a lower risk. The initial score is then calculated by taking a weighted average of the scores of one or more metrics. The initial score calculation formula is as follows: Formula 1:

[0110] Formula 1

[0111] Among them, S represents the node, represents the initial score; w i is the weight of the ith metric (e.g., supplier bankruptcy risk weight), which can be specified by the user based on experience, or obtained by performing algorithm optimization after mathematical statistics of historical data. The sum of the weights can be 1; M i (S) is the score of the ith metric; n is the total number of metrics.

[0112] Then, the risk impact factor of each current event of each associated entity node and the sum of all risk impact factors are obtained;

[0113] The risk impact factor involved in the present disclosure includes a value that affects the initial score of an entity node. The risk propagation factor includes a weight for risk propagation between two entity nodes.

[0114] For example, the risk impact factor can be automatically given based on the characteristics of the event using the above-mentioned scoring model. Alternatively, the risk impact factor of the event can be given using the above-mentioned expert system. Alternatively, Figure 7 The risk impact factor is obtained in the manner shown.

[0115] Figure 7The flowchart of obtaining the risk impact factor according to an embodiment of the present disclosure is schematically shown.

[0116] like Figure 7 As shown, this embodiment includes:

[0117] In operation S710 , sentiment classification is performed on each current event of each associated entity node according to a sentiment classification model;

[0118] In operation S720 , a risk impact factor is determined according to the emotion type of each current event.

[0119] Sentiment classification models are used to identify and classify emotional tendencies (such as positive, negative, and neutral) in text or speech. They can be obtained based on machine learning algorithms or rules compiled based on expert experience.

[0120] In some embodiments, the sentiment classification model includes a sentiment vocabulary derived from historical supply chain risk data and target software industry data. Sentiment classification of each current event for each associated entity node based on the sentiment classification model includes: matching the event content of each current event with a set of words in the sentiment vocabulary; and classifying each current event into sentiment categories such as positive, negative, and neutral based on at least one matched word.

[0121] For example, to further assess the specific impact of an event on the supply chain, sentiment analysis can be used to determine the emotional tendency of the event text and whether the impact is positive or negative. Sentiment analysis uses a pre-made sentiment word list, and the specific steps include:

[0122] Sentiment word list construction: Based on historical data and industry-specific language, a sentiment word list containing both positive and negative sentiment words is constructed. Positive words include "optimization," "improvement," "expansion," "growth," and "enhancement," while negative words include "decline," "stagnation," "reduction," "bankruptcy," and "discontinuation of production."

[0123] Sentiment Assessment: Scan the event text using a sentiment word list and count the frequency of positive and negative words. If the frequency of negative words exceeds the frequency of positive words, the event impact is considered negative; otherwise, it is considered positive. A sentiment score is calculated for each event, with both positive and negative impact factors set to 1. This is used to update the risk score. If (number of positive words > number of negative words) then the impact factor is 1; else if (number of negative words > number of positive words) then the impact factor is -1; else the impact factor is 0.

[0124] Summation processing: Add up the risk impact factors of all current events to obtain the sum result.

[0125] Then, the event risk score of each entity node is obtained based on the summed result and the initial score. The score result of each entity node after being affected by the event can be updated dynamically in real time.

[0126] Considering that software products and components may be affected by multiple risk events within a certain time window, the score is updated by comprehensively considering the impact of all events within the time window. First, the software supply chain manager determines the basic risk score P for each node based on the information provided by the dependency graph and professional experience knowledge. base (S) as the basic risk score, and then add the sum of the event impact factors to the basic risk score to get the event risk score The dynamic score update formula is as follows:

[0127] Formula 2

[0128] Among them, P base (S) is the basic risk score of node S, that is, the initial score in formula 1 , I positive,i and I negative,j are the i-th positive and j-th negative impact factors, N is the total number of events involved in the calculation, n and m are the number of positive and negative events, respectively, and the indicator function f (N>0) The value is 1 when N > 0 and 0 when N = 0. When no risk event occurs, that is, (N = 0), the indicator function f (N>0) The value of is 0, so P new (S) = P base (S). When one or more risk events occur, that is, (N > 0), the indicator function f (N>0) The value of is 1, the formula becomes:

[0129] Formula 3

[0130] In order to ensure the risk score P new The value of (S) is in the interval [0,10]. After the score update, a regularization step is required to ensure that the score is within 10 points:

[0131] Formula 4

[0132] In operation S620 , risk propagation scores of remaining entity nodes connected to each associated entity node via directed edges are determined;

[0133] In operation S630 , a first score of each entity node is obtained according to the event risk score and the risk propagation score.

[0134] For example, after the risk score of the node directly affected by the incident is updated, it is necessary to further update the risk scores of other software products and component nodes in the supply relationship diagram that may be affected by the node. The specific update method is: starting from the node directly affected by the incident, reversely traverse the entity relationship diagram based on breadth-first, and record all nodes in the path in the traversal order, such as software nodes and component nodes, or other entity nodes. If the reverse traversal path passes through other software products and component nodes, it means that the risk brought by the incident may be transmitted from the directly affected node to other software products and component nodes through the dependency relationship of the software supply chain. For all reachable nodes, the following formula is used to obtain the first score:

[0135] Formula 5

[0136] in, represents the risk propagation score. I represents the affected node in the path; D(I) is the set of all downstream nodes C that node I depends on; P new' (I) is the event risk score of node I based on formula 4; F C,I is the risk propagation factor from node I to downstream node C; P new (C) is the updated event risk score of the downstream node C as in Formula 4. If there is a node in the set D(I) without an updated risk score (i.e., the impact of the event has not been propagated to the node through the dependency graph), the basic risk score P of the node is used. base (C) Replace P in the formula new (C) Participate in the calculation. The updated score still goes through the above regularization step to ensure that the score is within 10 points.

[0137] The calculation method of the risk communication score is not limited to Formula 5. For example, Formula 5 can also be multiplied by 0.5.

[0138] If the impact of risk propagation is large, the absolute value of the risk propagation factor can be large. In the case where a smaller score indicates a greater risk, the risk propagation factor can be negative, resulting in a negative risk propagation score.

[0139] like Figure 3 ,Take the supplier 3 node as an example, the geographical location 3 node and the supplier 3 node are connected ,through directed edges.

[0140] First, determine the first score (i.e., initial score) and risk propagation factor for the node at geographic location 3. The risk propagation factor for the node at geographic location 3 can be dynamically changing. When different risk events occur at geographic location 3, the risk propagation factor will vary based on the event risk score of the risk event. For example, when extreme weather occurs at geographic location 3, the impact of risk propagation is greater, and the absolute value of the risk propagation factor can be larger. In the case where a smaller score indicates a greater risk, the risk propagation factor can be a negative value, so that, as shown in Formula 5, The calculated risk transmission score is negative.

[0141] Then, the first score of the supplier 3 node can be calculated as shown in Formula 5. In the case that the supplier 3 node is also connected to other downstream nodes, the risk propagation scores of the other downstream nodes can be obtained as shown in Formula 5 and added to the risk propagation score of the geographical location 3 node.

[0142] For example, if information about a supplier going bankrupt is extracted, the supplier node in the supply chain diagram is determined based on the supplier's name. The node is then used to locate the software product or component nodes supplied by the supplier, as well as the nodes of the maintenance personnel employed by the supplier. The risk scores of all software product or component nodes potentially affected by the incident are then updated based on the impact factors. For example, when the risk score of a component is updated, the risk scores of other product and component nodes that depend on it also need to be updated.

[0143] According to the embodiments of the present disclosure, a dynamic risk scoring system is used to convert current event information into intuitive scoring results in real time, and the accuracy and real-time performance of risk assessment are improved through the idea of ​​dynamic risk propagation.

[0144] Exemplarily, the risk propagation factor may be determined based on at least one of respective attributes of the two nodes, dependency relationships, directed edge directions, and real-time events collected by multiple data sources.

[0145] For example, centrality analysis methods can be used to determine the importance of each entity node in the supply chain network, such as degree centrality and betweenness centrality. By simulating the risk propagation process in the supply chain network, the risk propagation capacity of each node is analyzed. Based on the node's influence in risk propagation and the characteristics of the network structure, the risk propagation factor of each downstream entity node to the upstream entity node is determined.

[0146] Alternatively, the strength of the dependencies between supplier entities can be assessed, for example, through questionnaires, historical supply chain risk data, or expert assessments to determine the strength of each relationship. Based on the strength of the dependency, a weight is assigned to each directed edge, representing the risk propagation factor from the downstream entity node to the upstream entity node.

[0147] For example, if the downstream node is a licensing node, natural language processing (NLP) can be used to perform semantic analysis on the licensing document to identify restrictive clauses, such as those on scope of use, modification, and distribution. Risk quantification is then performed for each restrictive clause, assessing its potential impact on the software supply chain, such as the legal risks and supply chain disruptions that could result from a violation. Using the licensing node as a starting point, the risk propagation path and impact on upstream nodes (such as software nodes) are analyzed. Based on the risk quantification results for the restrictive clauses, a corresponding risk weighting factor is assigned to the licensing node.

[0148] During the execution of operation S230, Figure 3 The Component 2 node shown is one of the endpoint entity nodes of the Software Product A node. Its connected target entity nodes include the Maintainer 2 node, the Supplier 3 node, and the License node. As shown in Formula 5, the event risk score for Component 2 is obtained. The risk propagation scores for each of the Maintainer 2 node, the Supplier 3 node, and the License node are then calculated, yielding the first score for Component 2.

[0149] During the execution of operation S240, Figure 3 As shown, the terminal entity nodes of software product A node include component 1 node, authorization license node, supplier 1 node and component 2 node. As shown in Formula 5, the event risk score of software product A node can be obtained. Then, the risk propagation score of each of component 1 node, authorization license node, supplier 1 node and component 2 node can be obtained. Then, based on Formula 5, the risk score of software product A node can be obtained. , which is the second score.

[0150] In some embodiments, after calculating the second score of the target software based on the first scores of each of the N endpoint entity nodes, corresponding warning measures are executed based on the second score of the target software, wherein different second score ranges correspond to different warning measures.

[0151] For example, first set two thresholds T, high and low high 、T low The risk level is divided into three levels: low, medium and high. high 、T low The values ​​of are all in the interval [0,10]. The second score value is used to determine the risk level. Since the smaller the risk, the higher the score, so if P new > T high , it means that the node is low risk; if T low < P new ≤ T low , it means that the node is medium risk; if P new≤ T low , it means that the node is high risk.

[0152] The implementation of the early warning mechanism is determined based on the risk level, resulting in different early warning measures. If a node is judged to be low risk, no early warning will be issued. If a node is judged to be medium risk, the user will be reminded through the system's visual interface, displaying the affected nodes and their risk scores, highlighting the affected nodes on the interface, and providing detailed risk information such as node name, risk type, risk score, and description of the impacting event. If a node is judged to be high risk, in addition to reminding the user on the visual interface, the system will also send detailed early warning information to relevant managers via email, text messages, and other means.

[0153] In some embodiments, after calculating the second score of the target software based on the first scores of each of the N terminal entity nodes, warning information for the software supply chain disruption risk is generated when the second score of the target software is less than or equal to the first threshold; wherein the warning information includes visually displaying at least one target risk propagation path in the supply chain entity relationship diagram, and each target risk propagation path is determined based on the path where the entity node whose first score is less than or equal to the second threshold is located.

[0154] Automatically generate warning information based on pre-set warning information templates to ensure the standardization and integrity of warning content. Warning information templates include the following:

[0155] Title: For example, "High Risk Warning: Supplier Y Financial Risk".

[0156] Node Information: Detailed information about the affected node, including name, type, and risk score.

[0157] Event description: A detailed description of the event that caused the risk, including the time of occurrence, event content, and event source.

[0158] Risk propagation path: Displays the path along which risk events propagate to other nodes through the dependency graph.

[0159] Recommended measures: Provide recommended response measures based on the risk type and severity for management's reference.

[0160] In addition, you can also customize the following parameters:

[0161] Risk threshold setting: Users can dynamically adjust the values ​​of Thigh and Tlow based on the company's risk tolerance.

[0162] Warning channel configuration: Users can choose which channels to receive warning information (such as email, SMS, system notification, etc.).

[0163] Customization of warning information content: Users can customize the content and format of warning information templates to ensure that warning information complies with the company's internal processes and standards.

[0164] Notification frequency and strategy: Users can set the frequency of sending warning information (such as real-time sending, batch sending) and sending strategy (such as only sending the first warning, sending every time the score is updated, etc.).

[0165] According to the embodiments of the present disclosure, the multi-level warning mechanism takes differentiated warning measures according to different risk levels, ensuring that high-risk information can be quickly transmitted to relevant management personnel to facilitate timely response measures.

[0166] Based on the above software supply chain interruption risk assessment method, the present disclosure also provides a software supply chain interruption risk assessment device. Figure 8 The device is described in detail.

[0167] Figure 8 The following schematically shows a structural block diagram of a software supply chain disruption risk assessment device according to an embodiment of the present disclosure.

[0168] like Figure 8 As shown, the software supply chain disruption risk assessment device 800 of this embodiment includes an event collection module 810 , a node scoring module 820 , an endpoint scoring module 830 and a disruption assessment module 840 .

[0169] The event collection module 810 may perform operation S210 for collecting, in real time, at least one current event associated with an entity node included in a supply chain entity relationship graph of the target software;

[0170] The node scoring module 820 may perform operation S220 for determining a first score of the associated entity node based on at least one current event;

[0171] The endpoint scoring module 830 may perform operation S230 to obtain a first score for each of N endpoint entity nodes connected to the target software node in the supply chain entity relationship graph, wherein the first score of at least one endpoint entity node is obtained based on the first score of the connected origin entity node or the first score of the intermediate entity node, and the first score indicates the risk level of the supply chain entity mapped by the node;

[0172] The disruption assessment module 840 may perform operation S240 to calculate a second score of the target software based on the first scores of the N endpoint entity nodes, wherein the second score indicates the risk level of disruption of the target software supply chain, and N is an integer greater than or equal to 1.

[0173] In some embodiments, the node scoring module 820 may further perform operations S610 to S630, which will not be described in detail here.

[0174] In some embodiments, the node scoring module 820 is also used to obtain an initial score based on the attributes of the supply chain entity mapped by each associated entity node; obtain the risk impact factor of each current event of each associated entity node, and the sum of all risk impact factors; and obtain the event risk score of each entity node based on the sum result and the initial score.

[0175] In some embodiments, the node scoring module 820 may further perform operations S710 to S720, which will not be described in detail here.

[0176] In some embodiments, the node scoring module 820 is further configured to match the event content of each current event with a vocabulary set in the sentiment vocabulary; and perform sentiment classification on each current event based on at least one matched vocabulary.

[0177] In some embodiments, the event collection module 810 may further perform operations S510 to S530, which will not be described in detail here.

[0178] In some embodiments, the software supply chain disruption risk assessment apparatus 800 may further include an early warning module configured to execute early warning measures of corresponding levels based on the target software's second score, with different second score ranges corresponding to different early warning measures. Alternatively, if the target software's second score is less than or equal to a first threshold, an early warning message regarding the software supply chain disruption risk may be generated.

[0179] For the parts not mentioned in the apparatus part, they can be understood with reference to the various embodiments of the above-mentioned method. That is, the apparatus part includes modules for executing the various steps of any one of the method embodiments described above. In addition, the implementation methods, technical problems solved, functions achieved, and technical effects achieved of each module / unit / subunit, etc. in the apparatus part embodiment are respectively the same or similar to the implementation methods, technical problems solved, functions achieved, and technical effects achieved of each corresponding step in the method part embodiment, and will not be repeated here.

[0180] According to an embodiment of the present disclosure, any multiple modules among the event collection module 810, the node scoring module 820, the endpoint scoring module 830, and the interruption assessment module 840 can be combined into a single module, or any one of these modules can be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules can be combined with at least part of the functionality of other modules and implemented in a single module.

[0181] According to an embodiment of the present disclosure, at least one of the event collection module 810, the node scoring module 820, the endpoint scoring module 830, and the interruption assessment module 840 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented in hardware or firmware by any other reasonable means of circuit integration or packaging, or implemented in any one of the three implementation methods of software, hardware, and firmware, or in any appropriate combination of any of them. Alternatively, at least one of the event collection module 810, the node scoring module 820, the endpoint scoring module 830, and the interruption assessment module 840 may be at least partially implemented as a computer program module, which, when executed, may perform the corresponding function.

[0182] Figure 9 A block diagram of an electronic device suitable for implementing a software supply chain disruption risk assessment method according to an embodiment of the present disclosure is schematically shown.

[0183] like Figure 9 As shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage unit 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiment of the present disclosure.

[0184] Various programs and data required for the operation of the electronic device 900 are stored in the RAM 903. The processor 901, ROM 902, and RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method flow according to the embodiment of the present disclosure by executing the programs in the ROM 902 and / or RAM 903. It should be noted that the programs may also be stored in one or more memories other than the ROM 902 and RAM 903. The processor 901 may also perform various operations of the method flow according to the embodiment of the present disclosure by executing the programs stored in one or more memories.

[0185] According to an embodiment of the present disclosure, electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to bus 904. Electronic device 900 may also include one or more of the following components connected to I / O interface 905: an input section 906 including a keyboard, mouse, etc.; an output section 907 including devices such as a cathode ray tube (CRT), liquid crystal display (LCD), and speakers; a storage section 908 including a hard disk; and a communication section 909 including a network interface card such as a LAN card or modem. Communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to I / O interface 905 as needed. Removable media 911, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed in drive 910 as needed, so that computer programs read from the removable media can be installed into storage section 908 as needed.

[0186] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when executed, implements the method according to the embodiments of the present disclosure.

[0187] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium, and may include, for example, but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include the ROM 902 and / or RAM 903 described above, and / or one or more memories other than ROM 902 and RAM 903.

[0188] The embodiments of the present disclosure also include a computer program product, which includes a computer program containing program code for executing the method shown in the flowchart. When the computer program product is run in a computer system, the program code is used to enable the computer system to implement the method provided by the embodiments of the present disclosure.

[0189] The computer program executes the above functions defined in the system / device of the embodiment of the present disclosure when the processor 901 executes the computer program. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.

[0190] In one embodiment, the computer program may be stored on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal on a network medium, downloaded and installed via the communication portion 909, and / or installed from a removable medium 911. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to wireless, wired, or any suitable combination thereof.

[0191] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from a removable medium 911. When the computer program is executed by the processor 901, the above-described functions defined in the system of the embodiment of the present disclosure are performed. According to the embodiment of the present disclosure, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.

[0192] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).

[0193] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0194] Those skilled in the art will appreciate that the features described in the various embodiments of the present disclosure may be combined and / or coupled in various ways, even if such combinations or couplings are not explicitly described in the present disclosure. In particular, the features described in the various embodiments of the present disclosure may be combined and / or coupled in various ways without departing from the spirit and teachings of the present disclosure. All such combinations and / or couplings fall within the scope of the present disclosure.

[0195] The embodiments of the present disclosure are described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be used in combination to advantage. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present disclosure.

Claims

1. A software supply chain disruption risk assessment method, comprising: collecting in real time at least one current event associated with an entity node included in a supply chain entity relationship graph of the target software; determining a first score of the associated entity node based on the at least one current event, the first score indicating a risk level of the supply chain entity mapped by the node; Obtaining a first score for each of N terminal entity nodes connected to the target software node in the supply chain entity relationship graph, wherein the first score of at least one of the terminal entity nodes is obtained based on the first score of the starting entity node or the first score of the intermediate entity node connected to it in the risk propagation path; A second score of the target software is calculated based on the first scores of each of the N endpoint entity nodes, wherein the second score indicates a risk level of supply chain disruption of the target software, and N is an integer greater than or equal to 1.

2. The method according to claim 1, characterized in that Determining a first score of the associated entity node according to the at least one current event includes: determining an event risk score of an associated entity node based on the at least one current event; Determining risk propagation scores of remaining entity nodes connected to each associated entity node via directed edges; A first score for each entity node is obtained according to the event risk score and the risk propagation score.

3. The method according to claim 2, characterized in that Determining an event risk score of an associated entity node according to the at least one current event includes: Obtaining an initial score according to the attributes of the supply chain entity mapped by each associated entity node; Obtaining the risk impact factor of each current event of each associated entity node and the sum of all the risk impact factors; The event risk score of each entity node is obtained according to the summed result and the initial score.

4. The method according to claim 3, characterized in that Obtaining the risk impact factor of each current event of each associated entity node includes: Performing sentiment classification on each current event of each associated entity node according to a sentiment classification model; A risk impact factor is determined according to the emotion type of each current event.

5. The method according to claim 4, characterized in that The sentiment classification model includes a sentiment word list obtained based on supply chain risk history data and target software industry data. Performing sentiment classification on each current event of each associated entity node according to the sentiment classification model includes: Matching the event content of each current event with the vocabulary set in the sentiment vocabulary; Emotion classification is performed on each current event according to the matched at least one word.

6. The method according to claim 1, characterized in that Real-time collection of at least one current event associated with an entity node included in a supply chain entity relationship diagram of the target software includes: Filter out at least one current event using S pre-configured collection rules, where each collection rule is derived based on historical supply chain risk data, and S is an integer greater than or equal to 1; Determine the risk type of each current event using Q pre-configured classification rules. Each classification rule is derived based on historical supply chain risk data of the corresponding type, where Q is an integer greater than or equal to 1. The risk type of each current event is associated with a corresponding entity node.

7. The method according to claim 1, characterized in that There is at least one risk propagation path in the supply chain entity relationship diagram, which includes a starting entity node, at least one intermediate entity node and an end entity node connected in sequence.

8. The method according to claim 1, characterized in that After calculating the second score of the target software according to the first scores of the N endpoint entity nodes, the method further includes: According to the second score of the target software, early warning measures of corresponding levels are executed, wherein different second score ranges correspond to different early warning measures.

9. The method according to claim 1 or 8, characterized in that After calculating the second score of the target software according to the first scores of the N endpoint entity nodes, the method further includes: generating warning information for software supply chain disruption risk when the second score of the target software is less than or equal to the first threshold; The warning information includes visually displaying at least one target risk propagation path in the supply chain entity relationship diagram, and each target risk propagation path is determined based on the path where the entity node whose first score is less than or equal to the second threshold is located.

10. A software supply chain disruption risk assessment device, comprising: An event collection module, configured to collect in real time at least one current event associated with an entity node included in a supply chain entity relationship graph of the target software; a node scoring module, configured to determine a first score of an associated entity node according to the at least one current event; An endpoint scoring module is configured to obtain a first score for each of N endpoint entity nodes connected to the target software node in the supply chain entity relationship graph, wherein the first score of at least one of the endpoint entity nodes is obtained based on the first score of the starting entity node or the first score of the intermediate entity node connected to it in the risk propagation path, and the first score indicates the risk level of the supply chain entity mapped by the node; The interruption assessment module is configured to calculate a second score of the target software based on the first scores of each of the N endpoint entity nodes, wherein the second score indicates a risk level of interruption in the supply chain of the target software, and N is an integer greater than or equal to 1.

11. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 9.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.

13. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.