Software security testing method and device

Through an improved code risk scoring model, behavioral sequence anomaly detection, and intelligent fuzz testing that maximizes the probability of vulnerability discovery, the low efficiency and insufficient accuracy of existing software security testing methods are solved, and efficient and comprehensive security assessment and vulnerability detection of software are achieved.

CN120671145APending Publication Date: 2025-09-19WUHAN MINGHE YONGAN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510794245.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-13
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing software security testing methods are inefficient and lack accuracy, making it difficult to fully cover complex business logic and abnormal paths, resulting in the omission of critical vulnerabilities.

Method used

Through intelligent static analysis using an improved code risk scoring model, combined with an anomaly detection model for behavioral sequences and an intelligent fuzzy test generation strategy that maximizes the probability of vulnerability discovery, multi-dimensional security assessments are conducted, and a continuous optimization mechanism is established to dynamically adjust parameters.

Benefits of technology

It has improved the accuracy and efficiency of software security testing, effectively identified potential vulnerabilities, reduced false alarm rates, and improved dynamic behavior detection capabilities and fuzz testing coverage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671145A_ABST
    Figure CN120671145A_ABST
Patent Text Reader

Abstract

The invention relates to a software security testing method and device, and relates to the technical field of data test.The method comprises the steps that intelligent static analysis is conducted on target codes through an improved code risk scoring model, and comprehensive risk values of code segments are determined; executing dynamic behavior analysis based on an anomaly detection model of the behavior sequence, and determining an abnormal behavior score; determining the vulnerability discovery probability by adopting an intelligent fuzzy test generation strategy with maximized vulnerability discovery probability; performing multi-dimensional security assessment by integrating the comprehensive risk value of the code segment, the abnormal behavior score and the vulnerability discovery probability, and determining an overall security score of the software security test; and establishing a continuous optimization mechanism to dynamically adjust parameters of each security test link to obtain updated parameter values. According to the invention, the accuracy and efficiency of software security testing can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data testing technology, and in particular to a software security testing method, device, electronic device, and non-transitory computer-readable storage medium. Background Art

[0002] Today, software security testing methods mainly include static code analysis, dynamic runtime testing, fuzzing, penetration testing, etc. These methods are often used in combination to identify potential vulnerabilities at different levels.

[0003] However, existing software security testing methods still suffer from significant issues in practical applications, including low efficiency, insufficient accuracy, and limited coverage. Static analysis tools often generate numerous false positives, increasing the burden of manual screening and failing to effectively detect dynamic behaviors such as runtime privilege escalation. Furthermore, dynamic testing and fuzz testing often rely on manually configured scenarios or input models, making it difficult to fully cover complex business logic and unusual paths, leading to the omission of critical vulnerabilities. Summary of the Invention

[0004] In response to the technical problems existing in the prior art, the present invention provides a software security testing method, device, electronic device and non-transitory computer-readable storage medium that can improve the accuracy and efficiency of software security testing.

[0005] The technical solution of the present invention to solve the above technical problems is as follows:

[0006] The present invention provides a software security testing method, the method comprising:

[0007] Perform intelligent static analysis on target code through an improved code risk scoring model to determine the comprehensive risk value of the code segment;

[0008] The anomaly detection model based on behavior sequence performs dynamic behavior analysis to determine the abnormal behavior score;

[0009] Adopting an intelligent fuzz test generation strategy that maximizes the probability of vulnerability discovery to determine the probability of vulnerability discovery;

[0010] Perform a multi-dimensional security assessment based on the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability to determine the overall security score of the software security test;

[0011] Establish a continuous optimization mechanism to dynamically adjust the parameters of each safety testing link to obtain updated parameter values.

[0012] Optionally, performing intelligent static analysis on the target code using the improved code risk scoring model to determine the comprehensive risk value of the code segment includes:

[0013] Integrate the weight coefficient, vulnerability index and code complexity factor of each vulnerability type to obtain the first risk value;

[0014] The second risk value is obtained by integrating the dangerousness of each code pattern, the code dependency depth and the error propagation coefficient;

[0015] Integrate the maintainability index and interface security index of each code pattern to obtain the third risk value;

[0016] The first risk value, the second risk value and the third risk value are weightedly integrated to obtain a comprehensive risk value of the code segment.

[0017] Optionally, the comprehensive risk value of the code segment is expressed as:

[0018] R=α∑(W i ·V i ·C i )+β∑(P i ·D i ·E i )+γ∑(M i I i );

[0019] Among them, R is the comprehensive risk value of the code segment, W i is the weight coefficient of the i-th type of vulnerability, V i is the vulnerability index of the i-th type vulnerability, C i is the code complexity factor, P i is the danger level of the i-th code pattern, D i is the code dependency depth, E i is the error propagation coefficient, M i is the code maintainability index, I i is the interface security index, α, β, and γ are the first, second, and third adjustment factors, respectively.

[0020] Optionally, the behavior sequence-based anomaly detection model performs dynamic behavior analysis to determine an abnormal behavior score, including:

[0021] Calculate the abnormal behavior intensity based on the abnormality of the behavior sequence weighted by time correlation;

[0022] According to the entropy value of historical abnormal behavior and the impact factor of historical images, the time correction factor is obtained by processing the observation time window of the behavior using the time decay coefficient;

[0023] The abnormal behavior score is obtained according to the abnormal behavior intensity and the time correction factor, combined with the normalization processing result of the behavior deviation degree and frequency.

[0024] Optionally, the abnormal behavior score is expressed as:

[0025]

[0026] Among them, A is the abnormal behavior score, S i is the abnormality of the ith behavior sequence, T i is the time correlation weight, H is the historical abnormal behavior entropy value, D i is the behavioral deviation, F i is the behavior frequency, λ is the historical impact factor, θ is the time decay coefficient, and t is the observation time window.

[0027] Optionally, the method of using an intelligent fuzz test generation strategy that maximizes the probability of vulnerability discovery to determine the probability of vulnerability discovery includes:

[0028] Co-optimize boundary value test coverage with untested path weights and operation sequence complexity;

[0029] Dynamically integrate historical vulnerability similarity with new feature weights;

[0030] Merge the collaborative optimization results with the dynamic fusion results to obtain an enhancement in vulnerability discovery capabilities;

[0031] Based on the convergence control parameters, test case effectiveness indicators and execution path depth, the test saturation and stability control items are obtained;

[0032] The vulnerability discovery probability is determined according to the vulnerability discovery capability enhancement item and the test saturation and stability control item.

[0033] Optionally, the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability are integrated to perform a multi-dimensional security assessment to determine an overall security score of the software security test, including:

[0034] Normalizing the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability to obtain a basic score item;

[0035] A compensation correction mechanism is implemented for the evaluation error rate to obtain an error correction term;

[0036] Perform score enhancement adjustment based on the confidence index to obtain a confidence correction term;

[0037] A weighted fusion calculation is performed on the basic scoring item, the error correction item, and the confidence correction item to obtain the overall safety score.

[0038] Optionally, establishing a continuous optimization mechanism to dynamically adjust parameters of each security test link to obtain updated parameter values ​​includes:

[0039] Obtaining an error term corresponding to the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability;

[0040] Performing weighted summation on the plurality of error terms according to the feedback weight of each error term to obtain an error feedback term;

[0041] Construct noise suppression terms based on noise factors;

[0042] The current parameters of each of the safety test links are processed according to the error feedback item and the noise suppression item to obtain the updated parameter value.

[0043] Optionally, the method further includes:

[0044] Based on the overall security score, a mapping relationship table between the assessment results and actual vulnerabilities is established;

[0045] According to the mapping relationship table, the deviation matrix between the predicted value and the measured value of each model is calculated;

[0046] Constructing an adaptive adjustment algorithm for the error influencing factors of each of the models according to the deviation matrix;

[0047] According to the adaptive adjustment algorithm, the parameters of each model are updated online.

[0048] The present invention also provides a software security testing device, comprising:

[0049] Static analysis module, used to perform intelligent static analysis on target code using an improved code risk scoring model to determine the comprehensive risk value of the code segment;

[0050] A dynamic analysis module is used to perform dynamic behavior analysis based on an anomaly detection model of behavior sequences and determine an abnormal behavior score;

[0051] A vulnerability discovery module is used to determine the probability of vulnerability discovery by adopting an intelligent fuzz test generation strategy that maximizes the probability of vulnerability discovery;

[0052] A security testing module is used to perform a multi-dimensional security assessment based on the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability to determine an overall security score for the software security test;

[0053] The parameter update module is used to establish a continuous optimization mechanism to dynamically adjust the parameters of each security test link to obtain updated parameter values.

[0054] In addition, to achieve the above objectives, the present invention also proposes an electronic device, comprising: a memory for storing computer software programs; a processor for reading and executing the computer software programs, thereby implementing a software security testing method as described above.

[0055] In addition, to achieve the above-mentioned purpose, the present invention also proposes a non-transitory computer-readable storage medium, in which a computer software program is stored. When the computer software program is executed by a processor, a software security testing method as described above is implemented.

[0056] The beneficial effects of the present invention are:

[0057] (1) The present invention uses an improved code risk scoring model (CRSM) to integrate multi-dimensional factors such as code vulnerability weight, fragility, complexity, and interface security to achieve fine-grained modeling and assessment of static code segment risks, effectively avoiding the problems of "many missed reports and high false positives" in traditional static analysis methods.

[0058] (2) The present invention introduces the behavior sequence modeling and anomaly scoring function (BASF), which combines historical behavior entropy, behavior deviation and frequency to achieve dynamic capture and timeliness judgment of runtime anomalies, and effectively identify potential timing attacks, abnormal pattern triggers and behavior drift.

[0059] (3) The present invention uses the vulnerability discovery probability maximization function (VPMF) to automatically generate targeted test paths, covering key areas such as boundary values, complex sequences, historical features, and new features, greatly improving the test depth and trigger probability of fuzz testing, and effectively reducing the blind spots of manual testing.

[0060] In summary, the present invention constructs an intelligent, automated, adjustable and quantifiable software security testing method. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Figure 1 A flowchart of a software security testing method provided by the present invention;

[0062] Figure 2 A schematic structural diagram of a software security testing device provided by the present invention;

[0063] Figure 3 A schematic diagram of the hardware structure of a possible electronic device provided by the present invention;

[0064] Figure 4 A schematic diagram of the hardware structure of a possible computer-readable storage medium provided by the present invention. DETAILED DESCRIPTION

[0065] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of the present invention.

[0066] In the description of the present invention, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include one or more of the specified features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.

[0067] In the description of the present invention, the term "for example" is used to mean "used as an example, illustration or illustration". Any embodiment of the present invention described as "for example" is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is given to enable any person skilled in the art to implement and use the present invention. In the following description, details are listed for the purpose of explanation. It should be understood that a person of ordinary skill in the art can recognize that the present invention can be implemented without using these specific details. In other examples, well-known structures and processes are not elaborated in detail to avoid obscuring the description of the present invention with unnecessary details. Therefore, the present invention is not intended to be limited to the embodiments shown, but is consistent with the widest scope consistent with the principles and features disclosed herein.

[0068] See also Figure 1 , provides a flowchart of a software security testing method of the present invention, comprising the following steps:

[0069] Step 201: Perform intelligent static analysis on the target code using the improved code risk scoring model to determine the comprehensive risk value of the code segment.

[0070] In some embodiments, step 201 may include:

[0071] Integrate the weight coefficient, vulnerability index and code complexity factor of each vulnerability type to obtain the first risk value;

[0072] The second risk value is obtained by integrating the dangerousness of each code pattern, the code dependency depth and the error propagation coefficient;

[0073] Integrate the maintainability index and interface security index of each code pattern to obtain the third risk value;

[0074] The first risk value, the second risk value and the third risk value are weightedly integrated to obtain a comprehensive risk value of the code segment.

[0075] In some embodiments, the comprehensive risk value of a code segment is expressed as:

[0076] R=α∑(W i ·V i ·C i )+β∑(P i ·D i ·E i )+γ∑(M i I i );

[0077] Among them, R is the comprehensive risk value of the code segment, W i is the weight coefficient of the i-th type of vulnerability, V i is the vulnerability index of the i-th type vulnerability, C i is the code complexity factor, P i is the danger level of the i-th code pattern, D i is the code dependency depth, E i is the error propagation coefficient, M i is the code maintainability index, I i is the interface security index, α, β, and γ are the first, second, and third adjustment factors, respectively.

[0078] In practice, this formula aims to quantitatively assess the comprehensive security risk value R of a code segment. It combines the multi-dimensional factors in static analysis and aggregates different types of code risk sources through three parts. The following explains the meaning and function of each part item by item:

[0079] Vulnerability factor aggregation term α∑(W i ·V i ·C i ) reflects the known vulnerability categories and their impacts in the code. If a piece of code has multiple serious vulnerabilities and is located in a highly complex structure, the score for this item is high and the risk is increased. ∑(W i ·V i ·C i ) is the first risk value, W i is the weight coefficient of the i-th type of vulnerability, which indicates the weight of this type of vulnerability. For example, SQL injection may be more dangerous than CSS injection. i Is the vulnerability index of the i-th type of vulnerability, indicating the vulnerability index of this type of vulnerability, which can be based on CVSS or static rule evaluation results. iis the code complexity factor, which indicates the complexity of the code segment where the vulnerability is located (such as cyclomatic complexity and number of nesting levels). The higher the complexity, the harder it is to find and fix the vulnerability. α is the first adjustment factor, controlling its contribution to the overall risk.

[0080] The structural dependence risk term β∑(P i ·D i ·E i ), measures the potential pattern risks and coupling problems in the code structure. Some dangerous coding patterns exist in deep dependency chains and are prone to cause chain reactions of failures, so the risk value of this part increases. ∑(P i ·D i ·E i ) is the second risk value, P i is the danger level of the i-th code pattern, indicating the danger level of the code pattern, such as abuse of reflection, dynamic execution, and exposed API. i It is the code dependency depth, which indicates the dependency depth of the code where the pattern is located. The deeper the module level, the stronger the coupling and the more difficult it is to repair. i is the error propagation coefficient, i.e., the probability that a code error will propagate in the structure if it occurs. β is the second adjustment factor.

[0081] Maintainability and interface security term γ∑(M i I i ) Evaluate the maintainability of the code and the security of the exposed interface. If a code interface is exposed but lacks maintainability, there are long-term security risks, and the value of this item is larger. ∑(M i I i ) is the third risk value, M i It is a code maintainability index, which indicates the maintainability index of this part of the code, such as comment rate, refactoring score, and repeated code rate. i is the interface security index, which indicates the interface security index exposed by the code module, such as whether there are authentication flaws or permission bypass risks. γ is the third adjustment factor, which adjusts the coefficient of this impact.

[0082] In summary, the present invention calculates the comprehensive risk value of a code segment through three aspects: the explicit risk of the vulnerability itself, the implicit risk caused by structural and dependency transmission, and the long-term risk of maintenance difficulty and interface exposure. The advantage of this model is that it realizes modular modeling of quantitative assessment of local code security and supports large-scale static analysis tool integration.

[0083] Step 202: Perform dynamic behavior analysis based on the anomaly detection model of the behavior sequence to determine an abnormal behavior score.

[0084] In some embodiments, step 202 may include:

[0085] Calculate the abnormal behavior intensity based on the abnormality of the behavior sequence weighted by time correlation;

[0086] According to the entropy value of historical abnormal behavior and the impact factor of historical images, the time correction factor is obtained by processing the observation time window of the behavior using the time decay coefficient;

[0087] The abnormal behavior score is obtained according to the abnormal behavior intensity and the time correction factor, combined with the normalization processing result of the behavior deviation degree and frequency.

[0088] In some embodiments, the abnormal behavior score is expressed as:

[0089]

[0090] Among them, A is the abnormal behavior score, S i is the abnormality of the ith behavior sequence, T i is the time correlation weight, H is the historical abnormal behavior entropy value, D i is the behavioral deviation, F i is the behavior frequency, λ is the historical impact factor, θ is the time decay coefficient, and t is the observation time window.

[0091] Specifically, this formula is used for dynamic behavior analysis, which evaluates whether there are abnormal patterns, attack behaviors or potential threats through serialized monitoring and statistical analysis of program running behaviors.

[0092] The numerator includes the abnormal behavior intensity and the time correction factor (∑(S i ·T i ))·(1+λH)·e ―θt , which means that in the current observation window, the more abnormal the behavior, the more concentrated the time, and the more chaotic the history, the higher the score; but the influence of long time will be weakened. i ·T i ) aggregates the abnormality level S of all behavior sequences i , and weighted by its relevance in the time dimension T i Behavioral sequences with high abnormality and large temporal impact will have a more prominent impact on the score.

[0093] In (1+λH), H is the entropy of historical behavior, reflecting the degree of disorder in the distribution of past anomalies in the system. λ is its impact factor, which is used to emphasize the amplifying effect of historical anomalies on the current score. ―θt A time decay coefficient is added. As the time window t increases, the impact of past abnormal behavior will be naturally attenuated. θ controls the decay rate.

[0094] Behavioral fluctuations and frequency normalization If the behavior deviation is high and frequent, the denominator becomes larger and the final score decreases (indicating that the system has suppressed the fluctuation to avoid false positives). i is the deviation of the ith behavior, which measures the degree of difference between the behavior and the "normal mode", such as the deviation from the trajectory of the behavior map. i It is the frequency of the behavior. The more frequently it occurs, the wider its impact. The square of the behavioral deviation multiplied by its frequency emphasizes severe and frequent abnormal behaviors. Finally, the square root is used for normalization to prevent extreme values ​​from causing out-of-control scores.

[0095] A is the abnormal behavior score, the higher the score, the more likely it is to be abnormal. i is the abnormality of the ith behavior sequence, such as that calculated based on Markov chain, HMM, cluster distance, etc. i is the time correlation weight, the closer to the current time, the higher the weight. H is the entropy value of historical abnormal behavior, the more complex and random the abnormal distribution, the higher its value. i is the degree of behavioral deviation, the gap with the baseline behavioral model (which can be measured by distance, probability, etc.). i is the behavior frequency, which is the frequency of occurrence of the i-th behavior. λ is the historical influence factor, which controls the influence of past information on the current score. θ is the time decay coefficient, which controls the decay rate of old behaviors in the current window. t is the observation time window, for example, 10 seconds or 5 minutes.

[0096] Step 203: adopt an intelligent fuzzy test generation strategy that maximizes the vulnerability discovery probability to determine the vulnerability discovery probability.

[0097] In some embodiments, step 203 may include:

[0098] Co-optimize boundary value test coverage with untested path weights and operation sequence complexity;

[0099] Dynamically integrate historical vulnerability similarity with new feature weights;

[0100] Merge the collaborative optimization results with the dynamic fusion results to obtain an enhancement in vulnerability discovery capabilities;

[0101] Based on the convergence control parameters, test case effectiveness indicators and execution path depth, the test saturation and stability control items are obtained;

[0102] The vulnerability discovery probability is determined according to the vulnerability discovery capability enhancement item and the test saturation and stability control item.

[0103] Among them, the vulnerability discovery probability can be expressed as:

[0104]

[0105] Among them, P is the probability of vulnerability discovery, B i is the boundary value test coverage, O i is the operation sequence complexity, U i is the untested path weight, L i is the historical vulnerability similarity, N i is the new feature weight, Z i is the test case effectiveness indicator, Y i is the execution path depth, K is the normalization coefficient, and Q is the convergence control parameter.

[0106] Specifically, this formula aims to calculate the probability P of vulnerability discovery in fuzz testing or intelligent testing, and quantify the "probability of a set of test cases triggering real vulnerabilities" from multiple dimensions.

[0107] Enhanced vulnerability discovery capability∑(B i ·O i ·U i )+∑(L i ·N i ), reflecting the ability to explore new paths + the possibility of potentially triggering deep-seated defects. ∑(B i ·O i ·U i ) Measures the strength of test cases in terms of coverage, complexity, and unexplored paths. i is the boundary value test coverage of item i. The more boundary scenarios are tested, the easier it is to find boundary vulnerabilities. i It is the complexity of the operation sequence, such as API combination calls and user interaction paths; complex paths are more likely to expose hidden problems. i It is the weight of the untested path, which is used to encourage the test to focus on the execution path that has not been explored yet.

[0108] ∑(L i ·N i ) is to combine historical experience and novelty to predict the probability of vulnerability triggering. This item combines vulnerability inducibility (historical drive) and exploration (new features). i is the similarity between the i-th item and the known vulnerability (can be derived from CV library features, semantic embedding, etc.). N i is the weight of new features, which encourages the discovery of new types of defects that have not appeared before.

[0109] Test saturation and stability control term 1+exp(―Q·∑(Z i ·Y i )) to prevent invalid or repeated test cases from causing the probability of vulnerability discovery to be nonlinearly inflated, and to increase evaluation stability. i Y is the effectiveness indicator of the i-th test case, reflecting whether it can be executed to the sensitive points or vulnerability points.i is the execution path depth that this use case can reach. ∑(Z i ·Y i ) is the “penetration capability” of the comprehensive test case. exp(―Q·…) is the convergence and suppression mechanism implemented using a sigmoid-like function.

[0110] K is the normalization coefficient that keeps the results within an interpretable range (e.g., 0 to 1). Q is the convergence control parameter that controls the slope of the sigmoid function, i.e., the speed at which the “test depth” affects the formula.

[0111] In summary, this invention can be applied to fuzz testing frameworks to select and sort test cases; to adaptive vulnerability mining to determine how to adjust testing strategies; and to the training scoring function of vulnerability detection AI models, used to reinforce the reward construction of learning strategies. The overall goal is to improve testing efficiency and quality, prioritizing the execution of test cases most likely to discover vulnerabilities.

[0112] Step 204: Perform a multi-dimensional security assessment based on the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability to determine the overall security score of the software security test.

[0113] In some embodiments, step 204 may include:

[0114] Normalizing the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability to obtain a basic score item;

[0115] A compensation correction mechanism is implemented for the evaluation error rate to obtain an error correction term;

[0116] Perform score enhancement adjustment based on the confidence index to obtain a confidence correction term;

[0117] A weighted fusion calculation is performed on the basic scoring item, the error correction item, and the confidence correction item to obtain the overall safety score.

[0118] Among them, the overall safety score can be expressed as:

[0119]

[0120] Where X is the overall security score, R is the comprehensive risk value of the code segment, A is the abnormal behavior score, P is the probability of vulnerability discovery, ω1, ω2, and ω3 are the first, second, and third weights, respectively, E is the evaluation error rate, C is the confidence index, δ is the error impact factor, and μ is the confidence adjustment parameter.

[0121] Specifically, this formula is the core formula used in the entire solution to comprehensively assess the security of the target system or program. It combines static, dynamic, and fuzz testing results, and incorporates error control and confidence correction mechanisms to produce a quantifiable security score value X.

[0122] Basic scoring items It integrates static, dynamic, and fuzzy methods to create an "initial security score." R represents the risk value derived from static code analysis, A represents the anomaly score from dynamic behavior analysis, and P represents the probability of vulnerability discovery. These three factors are weighted and averaged to represent the contribution of each detection method to the final score. max(R, A, P) is used for normalization to prevent individual anomalies from inflating the overall score, ensuring a consistent score.

[0123] The error correction term (1-δE) addresses model uncertainty. Larger errors indicate lower confidence in the system, leading to a more appropriate discount in the score. A larger δ indicates a greater discount. E is the error rate of the current assessment, which can arise from factors such as model uncertainty and false positives. δ is the error impact factor, controlling the weight of E in the score.

[0124] The confidence modifier (1 + μC) reflects the confidence level of the score. When the confidence level of the detection process is high (for example, due to extensive test coverage), the score should be increased accordingly. C is the confidence level of the score, such as test coverage, data volume, and model confidence output. μ is the confidence adjustment parameter that controls the degree to which confidence is increased in the score.

[0125] X is the overall security score; higher scores indicate greater security. R is the comprehensive risk value of the code segment; higher scores indicate greater risk. A is the abnormal behavior score; higher scores indicate greater abnormality. P is the probability of vulnerability discovery; higher scores indicate greater potential risk. ω1, ω2, and ω3 are the first, second, and third weights, respectively, used for weighted fusion. E is the evaluation error rate, which comes from model uncertainty or differences in manual annotation. C is a confidence index, such as test coverage and model prediction probability. δ is the error impact factor, which indicates the degree of error's impact on the score and is generally set between 0.1 and 0.5. μ is the confidence adjustment parameter, which determines the strength of the confidence gain on the score.

[0126] Assume that a system detects:

[0127] R = 0.6, indicating that the code has a medium risk;

[0128] A = 0.8, severe behavioral abnormality;

[0129] P=0.3, the probability of vulnerability exposure in the test is low;

[0130] The weight settings ω1, ω2, and ω3 are 0.4, 0.4, and 0.2, respectively;

[0131] Error rate E = 0.15, confidence level C = 0.7, let δ = 0.3, μ = 0.5.

[0132]

[0133] (1-δE)=1-0.3·0.15=0.955;

[0134] (1+μC)=1+0.5·0.7=1.35;

[0135] X=0.775·0.955·1.35≈0.999;

[0136] It means that after comprehensive consideration, the system is currently in a "relatively safe" state.

[0137] Step 205: Establish a continuous optimization mechanism to dynamically adjust the parameters of each safety test link to obtain updated parameter values.

[0138] In some embodiments, step 205 may include:

[0139] Obtaining an error term corresponding to the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability;

[0140] Performing weighted summation on the plurality of error terms according to the feedback weight of each error term to obtain an error feedback term;

[0141] Construct noise suppression terms based on noise factors;

[0142] The current parameters of each of the safety test links are processed according to the error feedback item and the noise suppression item to obtain the updated parameter value.

[0143] Among them, the updated parameter value can be expressed as:

[0144]

[0145] Among them, P new is the updated parameter value, P old is the current parameter value, ΔR is the error term of R, ΔA is the error term of A, ΔP is the error term of P, are the first feedback weight, the second feedback weight and the third feedback weight respectively, ε is the noise factor, and η is the learning rate.

[0146] Specifically, this formula is a parameter self-learning formula, similar to a gradient update mechanism, suitable for dynamically adjusting model weights, adjustment factors, or control parameters. It updates the model's internal control parameters by applying weighted feedback to errors in static risk (R), behavioral anomalies (A), and vulnerability probability (P), combined with noise factors and learning rates.

[0147] P new is the updated parameter value (such as adjustment factor, weight coefficient, etc.), P old It is the updated parameter value (such as adjustment factor, weight coefficient, etc.). This part reflects "new value = old value + increment", which is the standard adaptive optimization form.

[0148] Parameter increment (error feedback term) The errors detected by the three modules will in turn adjust the control parameters for the next round of iterative optimization. ΔR is the error in the static analysis risk value (such as the difference between expectation and reality), ΔA is the deviation in the anomaly score (such as a behavior not being accurately identified), and ΔP is the difference between the actual trigger rate and the predicted probability in vulnerability detection. is the weight of each feedback, which is used to control the influence of errors from different sources on parameter update.

[0149] Noise suppression term (regularization) ε is a noise factor representing sample perturbations, test randomness, or model fluctuations. The denominator is similar to L2 regularization, preventing updates from being too large and thus suppressing unstable feedback.

[0150] η controls the overall update amplitude (smaller is more conservative, larger is faster to converge but with higher risk), and is usually set between 0.001 and 0.1, depending on the error stability.

[0151] Suppose we want to dynamically update a certain adjustment factor α in static analysis, and we already have:

[0152] ΔR=-0.12, ΔA=+0.05, ΔP=+0.08, are 0.6, 0.3 and 0.1 respectively, ∑ε 2 =0.02,η=0.05,P old =1.2.

[0153] The calculation process is as follows:

[0154] P new =1.2+0.05·(-0.0486)=1.2-0.00243=1.19757.

[0155] Indicates that due to the high error of static analysis, P new It was slightly adjusted downwards to reduce the risk score weight and achieve convergence.

[0156] In some embodiments, the present invention may further include:

[0157] Based on the overall security score, a mapping relationship table between the assessment results and actual vulnerabilities is established;

[0158] According to the mapping relationship table, the deviation matrix between the predicted value and the measured value of each model is calculated;

[0159] Constructing an adaptive adjustment algorithm for the error influencing factors of each of the models according to the deviation matrix;

[0160] According to the adaptive adjustment algorithm, the parameters of each model are updated online.

[0161] Specifically, after completing the calculation of the overall security score S, the system compares the score with the actual vulnerability data obtained through subsequent real detection or manual confirmation to form an "assessment-evidence" mapping table, which is used to mark: the number of real vulnerabilities corresponding to a certain score range; the deviation of the predicted values ​​of each model (static analysis, behavioral analysis, fuzz testing).

[0162] Based on this mapping table, we can calculate:

[0163] The numerical error between the predicted value (such as R, A, P) given by the model and the actual vulnerability (ground truth); these errors are constructed into a multi-dimensional deviation matrix, that is, the "error distribution map" of each model, reflecting which indicators and within which ranges the prediction is inaccurate. In some embodiments, the system can extract the key variables that affect the error based on the deviation matrix, and dynamically calculate the error impact factor δ corresponding to each model; then combine the learning rate and feedback factor (such as ), build a set of adaptive parameter adjustment algorithms, that is: for indicators with large errors, reduce their weights or adjust their input factors; for models with high accuracy, increase their contribution.

[0164] In some embodiments, based on the adaptive adjustment results, the following may be updated in real time:

[0165] The model's internal weights and adjustment factors in each formula enable online hot updates of the model without offline retraining, enhancing the system's adaptability to new environments and new samples.

[0166] See also Figure 2 , Figure 2 This is a structural diagram of a software security testing device provided by the present invention.

[0167] like Figure 2 As shown, a software security testing device proposed in an embodiment of the present invention includes:

[0168] Static analysis module 301, used to perform intelligent static analysis on target code using an improved code risk scoring model to determine the comprehensive risk value of the code segment;

[0169] A dynamic analysis module 302 is configured to perform dynamic behavior analysis based on an anomaly detection model of a behavior sequence to determine an abnormal behavior score;

[0170] A vulnerability discovery module 303 is configured to determine the vulnerability discovery probability by adopting an intelligent fuzzy test generation strategy that maximizes the vulnerability discovery probability;

[0171] A security testing module 304 is configured to perform a multi-dimensional security assessment based on the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability to determine an overall security score for the software security test;

[0172] The parameter updating module 305 is used to establish a continuous optimization mechanism to dynamically adjust the parameters of each safety test link to obtain updated parameter values.

[0173] It should be noted that the specific embodiments and beneficial effects of the above modules 301 to 305 can be found in the above detailed description of steps 201 to 205, which will not be repeated here.

[0174] See also Figure 3 , Figure 3 Schematic diagram of an embodiment of an electronic device provided by an embodiment of the present invention. Figure 3 As shown, an embodiment of the present invention provides an electronic device 400, including a memory 410, a processor 420, and a computer program 411 stored in the memory 410 and executable on the processor 420. When the processor 420 executes the computer program 411, the following steps are implemented:

[0175] Perform intelligent static analysis on target code through an improved code risk scoring model to determine the comprehensive risk value of the code segment;

[0176] The anomaly detection model based on behavior sequence performs dynamic behavior analysis to determine the abnormal behavior score;

[0177] Adopting an intelligent fuzz test generation strategy that maximizes the probability of vulnerability discovery to determine the probability of vulnerability discovery;

[0178] Perform a multi-dimensional security assessment based on the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability to determine the overall security score of the software security test;

[0179] Establish a continuous optimization mechanism to dynamically adjust the parameters of each safety testing link to obtain updated parameter values.

[0180] See also Figure 4 , Figure 4 Schematic diagram of an embodiment of a computer-readable storage medium provided in an embodiment of the present invention. Figure 4As shown, this embodiment provides a computer-readable storage medium 500 on which a computer program 411 is stored. When the computer program 411 is executed by a processor, the following steps are implemented:

[0181] Perform intelligent static analysis on target code through an improved code risk scoring model to determine the comprehensive risk value of the code segment;

[0182] The anomaly detection model based on behavior sequence performs dynamic behavior analysis to determine the abnormal behavior score;

[0183] Adopting an intelligent fuzz test generation strategy that maximizes the probability of vulnerability discovery to determine the probability of vulnerability discovery;

[0184] Perform a multi-dimensional security assessment based on the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability to determine the overall security score of the software security test;

[0185] Establish a continuous optimization mechanism to dynamically adjust the parameters of each safety testing link to obtain updated parameter values.

[0186] It should be noted that, in the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0187] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatus, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0188] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (apparatus), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as a combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded computer, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0189] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0190] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0191] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0192] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A software security testing method, characterized in that: The method comprises: Perform intelligent static analysis on target code through an improved code risk scoring model to determine the comprehensive risk value of the code segment; The anomaly detection model based on behavior sequence performs dynamic behavior analysis to determine the abnormal behavior score; Adopting an intelligent fuzz test generation strategy that maximizes the probability of vulnerability discovery to determine the probability of vulnerability discovery; Perform a multi-dimensional security assessment based on the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability to determine the overall security score of the software security test; Establish a continuous optimization mechanism to dynamically adjust the parameters of each safety testing link to obtain updated parameter values.

2. The software security testing method according to claim 1, characterized in that: The intelligent static analysis of the target code using the improved code risk scoring model to determine the comprehensive risk value of the code segment includes: Integrate the weight coefficient, vulnerability index and code complexity factor of each vulnerability type to obtain the first risk value; The second risk value is obtained by integrating the dangerousness of each code pattern, the code dependency depth and the error propagation coefficient; Integrate the maintainability index and interface security index of each code pattern to obtain the third risk value; The first risk value, the second risk value and the third risk value are weightedly integrated to obtain a comprehensive risk value of the code segment.

3. The software security testing method according to claim 2, characterized in that: The comprehensive risk value of the code segment is expressed as: R=α∑(W i ·V i ·C i )+β∑(P i ·D i ·E i )+γ∑(M i ·I i ); Among them, R is the comprehensive risk value of the code segment, W i is the weight coefficient of the i-th type of vulnerability, V i is the vulnerability index of the i-th type vulnerability, C i is the code complexity factor, P i is the danger level of the i-th code pattern, D i is the code dependency depth, E i is the error propagation coefficient, M i is the code maintainability index, I i is the interface security index, α, β, and γ are the first, second, and third adjustment factors, respectively.

4. The software security testing method according to claim 3, characterized in that: The behavior sequence-based anomaly detection model performs dynamic behavior analysis to determine an abnormal behavior score, including: Calculate the abnormal behavior intensity based on the abnormality of the behavior sequence weighted by time correlation; According to the entropy value of historical abnormal behavior and the impact factor of historical images, the time correction factor is obtained by processing the observation time window of the behavior using the time decay coefficient; The abnormal behavior score is obtained according to the abnormal behavior intensity and the time correction factor, combined with the normalization processing result of the behavior deviation degree and frequency.

5. The software security testing method according to claim 4, characterized in that: The abnormal behavior score is expressed as: Among them, A is the abnormal behavior score, S i is the abnormality of the ith behavior sequence, T i is the time correlation weight, H is the historical abnormal behavior entropy value, D i is the behavioral deviation, F i is the behavior frequency, λ is the historical impact factor, θ is the time decay coefficient, and t is the observation time window.

6. The software security testing method according to claim 5, characterized in that: The intelligent fuzz test generation strategy for maximizing the vulnerability discovery probability is used to determine the vulnerability discovery probability, including: Co-optimize boundary value test coverage with untested path weights and operation sequence complexity; Dynamically integrate historical vulnerability similarity with new feature weights; Merge the collaborative optimization results with the dynamic fusion results to obtain an enhancement in vulnerability discovery capabilities; Based on the convergence control parameters, test case effectiveness indicators and execution path depth, the test saturation and stability control items are obtained; The vulnerability discovery probability is determined according to the vulnerability discovery capability enhancement item and the test saturation and stability control item.

7. The software security testing method according to claim 6, characterized in that: The comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability are comprehensively evaluated to determine the overall security score of the software security test, including: Normalizing the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability to obtain a basic score item; A compensation correction mechanism is implemented for the evaluation error rate to obtain an error correction term; Perform score enhancement adjustment based on the confidence index to obtain a confidence correction term; A weighted fusion calculation is performed on the basic scoring item, the error correction item, and the confidence correction item to obtain the overall safety score.

8. The software security testing method according to claim 7, characterized in that: The establishment of a continuous optimization mechanism to dynamically adjust the parameters of each security test link to obtain updated parameter values ​​includes: Obtaining an error term corresponding to the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability; Performing weighted summation on the plurality of error terms according to the feedback weight of each error term to obtain an error feedback term; Construct noise suppression terms based on noise factors; The current parameters of each of the safety test links are processed according to the error feedback item and the noise suppression item to obtain the updated parameter value.

9. The software security testing method according to claim 8, characterized in that: The method further comprises: Based on the overall security score, a mapping relationship table between the assessment results and actual vulnerabilities is established; According to the mapping relationship table, the deviation matrix between the predicted value and the measured value of each model is calculated; Constructing an adaptive adjustment algorithm for the error influencing factors of each of the models according to the deviation matrix; According to the adaptive adjustment algorithm, the parameters of each model are updated online.

10. A software security testing device, characterized in that: The device comprises: Static analysis module, used to perform intelligent static analysis on target code using an improved code risk scoring model to determine the comprehensive risk value of the code segment; A dynamic analysis module is used to perform dynamic behavior analysis based on an anomaly detection model of behavior sequences and determine an abnormal behavior score; A vulnerability discovery module is used to determine the probability of vulnerability discovery by adopting an intelligent fuzz test generation strategy that maximizes the probability of vulnerability discovery; A security testing module is used to perform a multi-dimensional security assessment based on the comprehensive risk value of the code segment, the abnormal behavior score, and the vulnerability discovery probability to determine an overall security score for the software security test; The parameter update module is used to establish a continuous optimization mechanism to dynamically adjust the parameters of each security test link to obtain updated parameter values.