Database vulnerability detection method and system based on large language model, computer equipment and storage medium

By generating and comparing SQL query statements with a large language model, the problem of missed database vulnerability detection in complex scenarios is solved, and higher detection accuracy and coverage are achieved, especially in complex scenarios such as multi-table joins and aggregate functions.

CN120671141APending Publication Date: 2025-09-19JIANGSU DAMENG DATABASE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510761846.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-09
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing database vulnerability detection methods have insufficient detection capabilities in complex query scenarios and are prone to omissions, especially in complex scenarios such as multi-table joins, nested queries, and aggregate functions.

Method used

It uses a large language model (LLM) to generate executable SQL query statements, infer theoretical query results, and compare them with actual query results to automatically detect potential database vulnerabilities. This includes generating basic and complex SQL query statements, covering operations such as multi-table joins, subqueries, and aggregate functions.

Benefits of technology

It significantly improves the accuracy and coverage of database detection, and can cover complex query scenarios, including multi-table joins, subsystem generation and complex SQL query statements, including multi-table joins, subsystem generation, and improves the database vulnerability detection capabilities, especially in solving methods that traditional PQ methods cannot effectively handle, the coverage and accuracy of detection results, especially when dealing with complex query scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671141A_ABST
    Figure CN120671141A_ABST
Patent Text Reader

Abstract

The invention discloses a database vulnerability detection method and system based on a large language model, computer equipment and a storage medium, and the method comprises the steps: generating an executable SQL query statement by using a large language model technology according to a database to be subjected to vulnerability detection; reasoning a theoretical query result corresponding to each executable SQL query statement by utilizing a large language model technology according to data in a database to be subjected to vulnerability detection; querying a database to be subjected to vulnerability detection by utilizing the generated executable SQL query statement to obtain an actual query result; and comparing the theoretical query result with the actual query result, if the theoretical query result is consistent with the actual query result, indicating that the query has no vulnerability, and if the theoretical query result is inconsistent with the actual query result, indicating that the query has vulnerability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of database vulnerability detection, and in particular relates to a database vulnerability detection method, system, computer equipment and storage medium based on a large language model. Background Art

[0002] Database security has always been a key concern in the information technology field. With the advancement of informatization and the continuous expansion of database sizes, complex database systems have become increasingly potential targets for attackers. Database vulnerabilities, especially logical vulnerabilities, can lead to serious security risks such as data leaks, system crashes, and data consistency issues.

[0003] Existing database vulnerability detection methods mostly rely on static analysis, pattern matching, or techniques based on predefined query templates. Traditional Pivot Query Synthesis (PQS) methods detect potential vulnerabilities by generating a series of database queries, but their effectiveness is poor when dealing with complex queries. This is particularly true in complex scenarios such as multi-table joins, nested queries, and aggregate functions, where traditional methods are unable to effectively handle them and are prone to missing results. Summary of the Invention

[0004] Purpose of the invention: To address the problem that existing database vulnerability detection methods are prone to missed detections in complex scenarios, the present invention proposes a database vulnerability detection method, system, computer device and storage medium based on a large language model. By leveraging the powerful natural language understanding and generation capabilities of the large language model, potential database vulnerabilities can be automatically detected. The present invention can greatly improve the accuracy, coverage and detection capabilities of database vulnerability detection, especially when processing complex query scenarios.

[0005] Technical solution: A database vulnerability detection method based on a large language model, including the following steps:

[0006] Step 1: Generate executable SQL query statements based on the database to be tested for vulnerabilities using large language model technology;

[0007] Step 2: Using large language model technology, infer the theoretical query results corresponding to each executable SQL query statement based on the data in the database to be tested for vulnerabilities;

[0008] Step 3: Use the executable SQL query statement generated in step 1 to query the database to be tested for vulnerabilities and obtain the actual query results;

[0009] Step 4: Compare the theoretical query results with the actual query results. If they are consistent, it means that there is no loophole in this query. If they are inconsistent, it means that there is a loophole in this query.

[0010] Furthermore, the aforementioned method of generating an executable SQL query statement based on the database to be detected for vulnerability by using the large language model technology includes the following specific operations:

[0011] Based on the data in the database to be tested for vulnerabilities, the large language model technology is used to generate executable basic SQL query statements;

[0012] Based on the executable basic SQL query statements and the table structure in the database to be tested for vulnerabilities, complex SQL query statements are generated using large language model technology.

[0013] Furthermore, the basic SQL query statement is a SELECT statement.

[0014] Furthermore, the complex SQL query statements include: multi-table join statements, subquery statements, aggregate function statements, GROUP BY statements, and ORDER BY statements.

[0015] The present invention proposes a database vulnerability detection system based on a large language model, comprising:

[0016] The query generation module is used to generate executable SQL query statements based on the database to be tested for vulnerabilities using large language model technology;

[0017] Theoretical truth value generation module is used to use large language model technology to infer the theoretical query results corresponding to each executable SQL query statement based on the data in the database to be tested for vulnerabilities;

[0018] Submit query execution module, which is used to query the database to be tested for vulnerability using the generated executable SQL query statement to obtain the actual query result;

[0019] The truth value comparison module is used to compare the theoretical query results with the actual query results. If they are consistent, it means that there is no vulnerability in this query. If they are inconsistent, it means that there is a vulnerability in this query.

[0020] Furthermore, the query generation module includes the following submodules:

[0021] The basic query generation submodule is used to generate executable basic SQL query statements based on the data in the database to be tested for vulnerabilities using large language model technology;

[0022] The complex query submodule is used to generate complex SQL query statements based on executable basic SQL query statements and the table structure in the database to be detected for vulnerabilities, using large language model technology.

[0023] Furthermore, the basic SQL query statement is a SELECT statement.

[0024] Furthermore, the complex SQL query statements include: multi-table join statements, subquery statements, aggregate function statements, GROUP BY statements, and ORDER BY statements.

[0025] The present invention proposes a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the processor implements the steps of a database vulnerability detection method based on a large language model.

[0026] The present invention proposes a storage medium storing a database vulnerability detection program. When the database vulnerability detection program is executed by at least one processor, the program implements the steps of a database vulnerability detection method based on a large language model.

[0027] Beneficial effects: Compared with the prior art, the present invention has the following advantages:

[0028] (1) The method of the present invention effectively detects potential vulnerabilities in the database by generating complex SQL query statements using a large language model and deriving theoretical truth values ​​for comparison with actual results. The method of the present invention can cover a wider range of query scenarios, including complex operations such as multi-table joins and aggregate queries, significantly improving the accuracy and coverage of vulnerability detection and the ability to handle complex database operations.

[0029] (2) The method of the present invention realizes theoretical true value generation and comparison through LLM, further reducing the need for manual verification and improving the intelligence and automation level of the overall detection process;

[0030] (3) The query generation step in the method of the present invention, in which the query generated by LLM can automatically process complex SQL query operations, including multi-table joins, aggregate functions, subqueries, etc., significantly improving the coverage of queries and making up for the defect that traditional methods cannot handle complex scenarios;

[0031] (4) The step of automatically generating initial database data in the method of the present invention can automatically generate initial data for database detection using LLM, ensuring the diversity and complexity of data, simulating real database scenarios, and improving the reliability of vulnerability detection;

[0032] (5) The theoretical truth value generation step in the method of the present invention uses a large model to automatically generate the theoretical truth value of complex queries based on the database structure and data content, and compare it with the actual execution results, thereby enhancing the accuracy and coverage of vulnerability detection, especially in complex query operations and data processing processes;

[0033] (6) The enhanced query coverage step in the method of the present invention. Since the large model can generate more diverse and complex queries, the method of the present invention can more comprehensively cover the vulnerabilities of the database, especially in multi-table join and complex aggregation scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 This is a flowchart of a database vulnerability detection method based on a large language model proposed by the present invention;

[0035] Figure 2 This is a structural diagram of a database vulnerability detection system based on a large language model proposed by the present invention. DETAILED DESCRIPTION

[0036] The technical solution of the present invention will now be further described with reference to the accompanying drawings and embodiments.

[0037] Example 1:

[0038] In recent years, with the rapid development of large language models (LLMs), particularly breakthroughs in natural language processing and automatic code generation, LLMs have begun to be applied in the database field as auxiliary tools for generating and optimizing SQL queries. LLMs can understand and generate complex language structures and possess strong reasoning and learning capabilities. Therefore, applying LLMs to database vulnerability detection can overcome the shortcomings of traditional methods and improve the efficiency and accuracy of database vulnerability detection.

[0039] like Figure 1 As shown, this embodiment proposes a database vulnerability detection method based on a large language model to solve the problem of insufficient detection capabilities of traditional methods in complex query scenarios and improve the accuracy and coverage of vulnerability detection. The method mainly includes the following steps:

[0040] Step 1: Database initialization: Generate executable statements based on set rules or through random generation technology using a large language model. Create a database environment with multiple table structures and various types of data content. Ensure that the generated data is sufficiently diverse, complex, and representative to simulate real-world database usage scenarios.

[0041] Step 2: Complex query generation: Using the large language model, we generate basic and complex SQL queries. These queries include not only standard SELECT statements but also complex operations such as multi-table joins (JOINs), subqueries, aggregate functions (such as COUNT and SUM), GROUP BY, and ORDER BY. During query generation, both query correctness and efficiency must be considered to ensure that the generated queries effectively cover diverse database operation scenarios.

[0042] Step 3: Generate theoretical truth value. The large language model combines the table structure and data content created in step 1 to automatically derive the theoretical truth value of each SQL query statement. The theoretical truth value refers to the correct result that the database should return when executing the query under ideal circumstances.

[0043] Step 4: Execute the query, submit the generated SQL query statement to the database for actual execution, and obtain the query execution result.

[0044] Step 5: Compare the query results with the theoretical truth value to detect logical vulnerabilities in the database. If the query results do not match the theoretical truth value, the query may contain a vulnerability. Otherwise, the query does not contain a vulnerability.

[0045] Example 2:

[0046] like Figure 2 As shown, this embodiment proposes a database vulnerability detection system based on a large language model, which includes multiple modules, each of which works together to achieve automated vulnerability detection, specifically including:

[0047] The database initialization module is used to create various types of database tables and data based on set rules or through random generation techniques. This ensures that the test environment's data is complex and diverse, effectively simulating a real database environment.

[0048] The query generation module, combined with LLM technology, generates both basic and complex executable SQL queries. These queries include not only standard SELECT statements but also complex operations such as multi-table joins (JOIN), subqueries, aggregate functions (such as COUNT and SUM), GROUP BY, and ORDER BY. The generated queries offer a wide range of coverage, fully detecting potential database vulnerabilities. During query generation, both correctness and efficiency are considered to ensure they effectively cover diverse database operation scenarios.

[0049] The theoretical truth generation module is used to automatically derive the expected results for each query using LLM, combining the database structure and data content. This module is responsible for generating an expected query result for each query, namely the theoretical truth value, which serves as a benchmark for subsequent comparisons.

[0050] The query execution submission module is used to submit the generated SQL query to the database for execution and obtain the query execution result.

[0051] The truth value comparison module leverages the reasoning capabilities of the LLM to compare query execution results with theoretical truth values ​​to detect logical vulnerabilities in the database. If the query execution result does not match the theoretical truth value, the query may contain a vulnerability. Otherwise, the query does not contain a vulnerability.

[0052] Specifically, in this embodiment, the query generation module includes the following submodules:

[0053] The basic query generation submodule generates basic SQL query statements based on the initial data and table structure using a large language model;

[0054] The complex query submodule generates complex SQL query statements based on basic SQL query statements and table structures using a large language model;

[0055] The query syntax optimization submodule uses a large language model to optimize query syntax based on query results and table structure. For example, when an initial query is submitted to the database for execution, the query results and table structure are retrieved. The large language model then uses these results as input and outputs a syntactically optimized query statement (syntactic optimization includes adding indexes and filtering conditions), resulting in a more efficient query statement.

[0056] Example 3:

[0057] Taking a database containing sensor data as an example, we demonstrate how to generate queries and data using a large language model, use the large language model to generate queries, and finally compare them with the theoretical truth to verify the correctness of the query results. The specific implementation steps are as follows:

[0058] Step 1: Database Initialization: LLM technology is used to automatically generate a database environment containing multiple table structures and data content. Based on the pre-defined database schema, LLM generates the table structure and populates it with random or specified data. For example, the generated database includes a sensor table (`sensors`) and a temperature data table (`temperature_data`), populated with random data rows.

[0059] CREATE TABLE sensors(sensor_id INT,sensor_name TEXT);

[0060] CREATE TABLE temperature_data(sensor_id INT,temperature FLOAT,timestamp TIMESTAMP);

[0061] --Insert random data

[0062] INSERT INTO sensors(sensor_id,sensor_name)VALUES

[0063] (1,'Sensor A'),

[0064] (2,'Sensor B'),

[0065] (3, 'Sensor C');

[0066] INSERT INTO temperature_data(sensor_id,temperature,timestamp)VALUES

[0067] (1,22.6,'2023-10-01 12:00:00'),

[0068] (2,25.4,'2023-10-01 12:00:00'),

[0069] (1,23.0,'2023-10-01 13:00:00'),

[0070] (2,26.0,'2023-10-01 13:00:00');

[0071] Step 2: Generate Basic Query: Based on the database structure, LLM automatically generates basic query statements, typically common query types such as SELECT and GROUP BY. This query is a simple aggregation query, intended to provide a data foundation for subsequent complex queries. Suppose the basic query aims to calculate the average temperature for each sensor.

[0072] SELECT sensor_id,AVG(temperature)AS avg_temp

[0073] FROM temperature_data

[0074] GROUP BY sensor_id;

[0075] Step 3: Generate complex queries: After obtaining the table structure, data, and basic query results, LLM further generates complex queries involving more table joins, filter conditions, or other more complex data processing. For example, LLM generated a query to display sensor names and temperatures, and only filter data with temperatures above a certain threshold.

[0076] SELECT s.sensor_name,t.temperature,t.timestamp

[0077] FROM sensors s

[0078] JOIN temperature_data t ON s.sensor_id=t.sensor_id

[0079] WHERE t.temperature>22;

[0080] Step 4: Generate the expected truth: For each query, generate the expected truth. That is, LLM will infer the expected query result based on the database data and query statement to verify the accuracy of subsequent queries.

[0081] Theoretical truth value of complex query:

[0082]

[0083] Step 5: Submit the query to the database: Submit the SQL query statement generated by LLM to the database, and actually execute the complex query result:

[0084]

[0085] Step 6: Verify Error Detection by Comparing the True Values: LLM compares the actual query results with the theoretical true values. Any discrepancies are flagged as potential logic errors. For example, if the average temperature of Sensor A in an aggregation query is 23.0, while the theoretical true value is 22.8, LLM will flag the query as vulnerable. For join queries, LLM will also detect and report errors if an expected record is missing or present.

[0086] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).

[0087] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0088] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.

Claims

1. A database vulnerability detection method based on a large language model, characterized by: The following steps are involved: Step 1: Generate executable SQL query statements based on the database to be tested for vulnerabilities using large language model technology; Step 2: Using large language model technology, infer the theoretical query results corresponding to each executable SQL query statement based on the data in the database to be tested for vulnerabilities; Step 3: Use the executable SQL query statement generated in step 1 to query the database to be tested for vulnerabilities and obtain the actual query results; Step 4: Compare the theoretical query results with the actual query results. If they are consistent, it means that there is no loophole in this query. If they are inconsistent, it means that there is a loophole in this query.

2. The database vulnerability detection method based on a large language model according to claim 1, characterized in that: The aforementioned method of generating executable SQL query statements based on the database to be detected for vulnerabilities by using large language model technology includes the following specific operations: Based on the data in the database to be tested for vulnerabilities, the large language model technology is used to generate executable basic SQL query statements; Based on the executable basic SQL query statements and the table structure in the database to be tested for vulnerabilities, complex SQL query statements are generated using large language model technology.

3. The database vulnerability detection method based on a large language model according to claim 2, characterized in that: The basic SQL query statement is a SELECT statement.

4. The database vulnerability detection method based on a large language model according to claim 2, characterized in that: The complex SQL query statements include: multi-table join statements, sub-query statements, aggregate function statements, GROUP BY statements, and ORDER BY statements.

5. The database vulnerability detection system based on a large language model according to claim 1, characterized in that: include: The query generation module is used to generate executable SQL query statements based on the database to be tested for vulnerabilities using large language model technology; Theoretical truth value generation module is used to use large language model technology to infer the theoretical query results corresponding to each executable SQL query statement based on the data in the database to be tested for vulnerabilities; Submit query execution module, which is used to query the database to be tested for vulnerability using the generated executable SQL query statement to obtain the actual query result; The truth value comparison module is used to compare the theoretical query results with the actual query results. If they are consistent, it means that there is no vulnerability in this query. If they are inconsistent, it means that there is a vulnerability in this query.

6. The database vulnerability detection system based on a large language model according to claim 5, characterized in that: The query generation module includes the following submodules: The basic query generation submodule is used to generate executable basic SQL query statements based on the data in the database to be tested for vulnerabilities using large language model technology; The complex query submodule is used to generate complex SQL query statements based on executable basic SQL query statements and the table structure in the database to be detected for vulnerabilities, using large language model technology.

7. The database vulnerability detection system based on a large language model according to claim 6, characterized in that: The basic SQL query statement is a SELECT statement.

8. The database vulnerability detection system based on a large language model according to claim 6, characterized in that: The complex SQL query statements include: multi-table join statements, sub-query statements, aggregate function statements, GROUP BY statements, and ORDER BY statements.

9. A computer device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the method for detecting a database vulnerability based on a large language model according to any one of claims 1 to 4 are implemented.

10. A storage medium, characterized in that: The storage medium stores a database vulnerability detection program, which, when executed by at least one processor, implements the steps of a database vulnerability detection method based on a large language model as described in any one of claims 1 to 4.