Code-level security vulnerability intelligent verification method, electronic equipment and storage medium

By parsing the application source code to obtain feature vectors and using AI models to simulate execution, the problem of inefficient code security vulnerability verification in existing technologies is solved, and fast and accurate vulnerability identification is achieved.

CN120671152AActive Publication Date: 2025-09-19QINGDAO WANDAO (BEIJING) INFORMATION TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511180133.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-22
Publication Date
2025-09-19
Estimated Expiration
2045-08-22

AI Technical Summary

Technical Problem

Existing code security vulnerability verification methods rely on dynamic testing and manual analysis, which is inefficient and costly, and cannot effectively identify vulnerabilities without compiling or deploying applications.

Method used

By parsing the application source code to obtain feature vectors, the AI ​​model is used to simulate execution, and vulnerability identification is performed in combination with the test parameter list and operating environment. The prediction score is output to determine the presence or absence of the vulnerability.

Benefits of technology

It enables rapid and accurate identification of security vulnerabilities without compiling or deploying applications, improving vulnerability location efficiency and reducing manpower and time costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671152A_ABST
    Figure CN120671152A_ABST
Patent Text Reader

Abstract

The invention provides a code-level security vulnerability intelligent verification method, electronic equipment and a storage medium, and relates to the technical field of artificial intelligence, and the method comprises the following steps: analyzing an application source code, obtaining a feature vector of a code, obtaining a test parameter list of the application source code for security vulnerability detection, obtaining a plurality of initial test parameter value lists based on the database, obtaining a running environment of the application source code based on the attribute information of the application source code and the attribute information of the initial test parameter values, and inputting a plurality of target test parameter value lists, the feature vectors of the application source code and the running environment of the application source code into a target AI model; and performing simulation execution on the application source code by using the target AI model to perform vulnerability identification, obtaining a prediction score of each preset vulnerability, and if the prediction score of one preset vulnerability is greater than a preset vulnerability threshold, outputting a first verification result, and accurately identifying the security vulnerability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and in particular to a code-level security vulnerability intelligent verification method, electronic equipment, and storage medium. Background Art

[0002] During software development, identifying code security vulnerabilities is a core component of ensuring application security. Current vulnerability verification methods typically require writing and deploying a running system, relying primarily on dynamic testing or manual analysis. Dynamic testing triggers program anomalies by injecting randomized test parameters. While this method can identify some runtime vulnerabilities, dynamic testing is primarily performed blindly, resulting in insufficient coverage and an inability to effectively associate vulnerabilities with code context, leading to inefficient vulnerability location. Manual analysis, on the other hand, is highly inefficient and requires significant labor and time. Therefore, there is an urgent need for a method to verify security vulnerabilities without compiling or deploying running applications. Summary of the Invention

[0003] In view of the above technical problems, the technical solution adopted by the present invention is: According to a first aspect of the present invention, a method for intelligently verifying code-level security vulnerabilities is provided, the method comprising the following steps: S100, parsing the application source code to obtain a feature vector of the application source code, where the features corresponding to the feature vector include at least: a function name; S200, obtaining a list of initial test parameter values ​​for security vulnerability detection in application source code based on a database, the list of initial test parameter values ​​including initial test parameter values ​​corresponding to the plurality of test parameters; S300, based on attribute information of the application source code and attribute information of the initial test parameter value, obtaining an operating environment of the application source code, wherein the attribute information of the application source code includes at least: a code programming language; the attribute information of the initial test parameter value includes at least: a data type and a preset operating environment of the initial test parameter value; S400: Inputting a plurality of target test parameter value lists, a feature vector of the application source code, and an operating environment of the application source code into a target AI model, using the target AI model to simulate execution of the application source code to identify vulnerabilities, and obtaining a prediction score for each preset vulnerability, wherein the target test parameter value list including the plurality of target test parameter values ​​is one of the plurality of initial test parameter value lists; S500: If the predicted score of a preset vulnerability is greater than a preset vulnerability threshold, output a first verification result; otherwise, output a second verification result, wherein the first verification result is different from the second verification result.

[0004] According to a second aspect of the present invention, a non-transitory computer-readable storage medium is provided, in which a computer program is stored. The computer program is loaded and executed by a processor to implement the aforementioned method.

[0005] According to a third aspect of the present invention, an electronic device is provided, comprising: a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor implements the aforementioned method when executing the computer program.

[0006] The present invention has at least the following beneficial effects: parsing the application source code, obtaining the feature vector of the code, obtaining a list of test parameters for security vulnerability detection in the application source code, and obtaining several initial test parameter value lists based on a database, obtaining the operating environment of the application source code based on the attribute information of the application source code and the attribute information of the initial test parameter value, inputting several target test parameter value lists, the feature vector of the application source code and the operating environment of the application source code into the target AI model, using the target AI model to simulate the execution of the application source code for vulnerability identification, obtaining the predicted score of each preset vulnerability, if the predicted score of a preset vulnerability is greater than the preset vulnerability threshold, outputting a first verification result; otherwise, outputting a second verification result. The present invention simulates code running through the AI ​​model to realize security vulnerability verification without compiling or deploying the application source code, quickly simulates the application running results, and thus accurately identifies security vulnerabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0008] Figure 1 A flowchart of a method for intelligent verification of code-level security vulnerabilities provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0009] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of the present invention.

[0010] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar tasks and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or server that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0011] The embodiment of the present invention provides a method for intelligent verification of code-level security vulnerabilities, such as Figure 1 As shown, the method includes the following steps: S100: parse the application source code to obtain a feature vector of the application source code. Features corresponding to the feature vector include at least a function name.

[0012] S200: Obtaining a list of initial test parameter values ​​for security vulnerability detection based on the application source code from a database, wherein the list of initial test parameter values ​​includes initial test parameter values ​​corresponding to a plurality of test parameters. Specifically, the initial test parameter values ​​are parameter values ​​for security vulnerability testing.

[0013] S300, based on the attribute information of the application source code and the attribute information of the initial test parameter value, obtain the operating environment of the application source code, the attribute information of the application source code at least includes: code programming language; the attribute information of the initial test parameter value at least includes: data type, preset operating environment of the initial test parameter value.

[0014] Specifically, different programming languages ​​require different interpreters or compilers; code may rely on third-party libraries with specific version requirements, or some code may only work on specific operating systems. Therefore, the runtime environment for the application source code is determined based on the programming language of the application source code and, further, based on the code's configuration files and other factors.

[0015] Specifically, the attribute information of the initial test parameter value includes data types such as integer, floating point, etc. It is understood that different initial test parameter values ​​may have fixed operating environments. For example, the initial test parameter value of the Windows registry requires the Windows operating environment.

[0016] S400, inputting several target test parameter value lists, feature vectors of application source code and operating environment of application source code into the target AI model, using the target AI model to simulate the execution of application source code to identify vulnerabilities, and obtaining the prediction score of each preset vulnerability, wherein the target test parameter value list including several target test parameter values ​​is one of several initial test parameter value lists.

[0017] Specifically, the test parameters are determined based on the application source code, and initial test parameter values ​​corresponding to the test parameters are randomly selected from the database as the target test parameter value list.

[0018] Specifically, instructions are issued to the target AI model: based on the target test parameter value list, the code's feature vector and the operating environment of the application source code, the code's feature vector is simulated and run. By analyzing the logic of the code's feature vector and the behavior of the target test parameter value list, the probability score of the preset vulnerability in the code output is detected.

[0019] S500: If the predicted score of a preset vulnerability is greater than a preset vulnerability threshold, output a first verification result; otherwise, output a second verification result, wherein the first verification result is different from the second verification result.

[0020] In an exemplary description of the present invention, the first verification result is: the output of the application source code has a preset vulnerability; the second verification result is: the application source code is safe and does not have the preset vulnerability.

[0021] In summary, the application source code is parsed, the feature vector of the code is obtained, the test parameter list for security vulnerability detection of the application source code is obtained, and several initial test parameter value lists are obtained based on the database. Based on the attribute information of the application source code and the attribute information of the initial test parameter value, the operating environment of the application source code is obtained, and several target test parameter value lists, the feature vector of the application source code and the operating environment of the application source code are input into the target AI model. The target AI model is used to simulate the execution of the application source code to identify vulnerabilities, and the predicted score of each preset vulnerability is obtained. If the predicted score of a preset vulnerability is greater than the preset vulnerability threshold, the first verification result is output; otherwise, the second verification result is output. The present invention simulates code running through the AI ​​model to realize security vulnerability verification without compiling or deploying the application source code, and quickly simulates the application running results, thereby accurately identifying security vulnerabilities.

[0022] Specifically, S100 further includes obtaining a feature vector of the application source code through the following steps: S110: Decompose the application source code into grammatical units using a compiler, and construct a tree-structured application source code based on the grammatical units; wherein the grammatical units include at least expressions and function names, and also include statements, etc.

[0023] S120 traverses each node of the tree-structured application source code to obtain code syntax features, including node type and hierarchical relationships. The root node represents the entire program, and child nodes represent code blocks. As can be understood, an AST (Abstract Syntax Tree) is generated and its structural features are extracted.

[0024] S130: Split the application source code into a graph structure. The graph structure includes several linearly connected basic blocks. The edges connecting two basic blocks are control transfer statements. Basic blocks contain a set of statements that are executed sequentially. Specifically, a control flow graph (CFG) is constructed. Control transfer statements include conditional branches, loop jumps, function calls, etc.

[0025] S140 , obtaining graph structure attribute features based on the graph structure application source code, where the graph structure attribute features include: the number of basic blocks and edge types.

[0026] S150 , vectorizing the code syntax features and the graph structure attribute features respectively, and performing vector fusion on the vectorized code syntax features and the vectorized graph structure attribute features to obtain a feature vector of the application source code.

[0027] In one embodiment of the present invention, a graph neural network (GNN) is used to convert graph structure attribute features into vectors. The vectorized code syntax features and the vectorized graph structure attribute features are aggregated into a code feature vector through a pooling operation.

[0028] Specifically, in S400, the target test parameter value list is obtained through the following steps: S410: Obtain a target weight for each attribute information of an initial test parameter value.

[0029] S420 , clustering the initial test parameter vectors converted from the initial test parameter value list based on the attribute information of the initial test parameter value and the target weight of the attribute information to obtain a plurality of clusters.

[0030] Specifically, the test parameters are determined based on the application source code, initial test parameter values ​​corresponding to several test parameters are obtained, and the initial test parameter values ​​corresponding to the test parameters are converted into an initial test parameter vector; and the target weight of each dimension of the initial test parameter vector is determined based on the target weight of the preset attribute information and the attribute information of the initial test parameter value.

[0031] In an exemplary embodiment of the present invention, parameters X1 and X2 are tested, and the initial test parameter value FX1 corresponding to X1 and the initial test parameter value FX2 corresponding to X2 are obtained, thereby determining the initial test parameter vector (FX1, FX2), and determining the target weight of FX1 based on the attribute information of FX1, and determining the target weight of FX2 based on the attribute information of FX2.

[0032] S430 , extracting a fixed number of initial test parameter vectors from each cluster as designated parameter vectors, and using the initial test parameter value list corresponding to the designated parameter vectors as the target test parameter value list.

[0033] In one embodiment of the present invention, the fixed number is 1, and the initial test parameter vector with the smallest distance to the center vector of the cluster is used as the designated parameter vector.

[0034] In summary, the target weight of each preset attribute information is obtained based on the application source code, the initial test parameter vector converted from the initial test parameter value is obtained, and the target weight of each dimension of the initial test parameter vector is obtained based on the target weight of each attribute information. Based on the initial test parameter vector and the target weight of each dimension of the initial test parameter vector, the initial test parameter vector is clustered to obtain several clustering clusters, and a fixed number of initial test parameter vectors are extracted from each clustering cluster as the designated parameter vector. The initial test parameter value list corresponding to the designated parameter vector is used as the target test parameter value list. The present invention clusters the initial test parameter vectors and selects them separately from each cluster to ensure that various types of test parameter data are included, thereby making the target AI model prediction more accurate.

[0035] Furthermore, S410 further includes obtaining the target weight of the attribute information of the initial test parameter value through the following steps: S411: Obtain a list of historical attribute weights for several historical codes and the parameters of each historical code when performing security vulnerability testing. The list of historical attribute weights includes the weights of several historical attributes. It will be appreciated that different attribute information has different impacts on security vulnerability detection for different codes. Therefore, a corresponding attribute weight list is provided for each historical code.

[0036] S412: Obtain a historical feature vector corresponding to the historical code, and then determine the historical feature vector with the smallest distance to the feature vector of the application source code as the designated feature vector. By finding the historical feature vector closest to the feature vector of the code, the weight of the attribute information in the historical feature vector is used as the weight of the same attribute information in the application source code.

[0037] S413: Determine the target weight of the attribute information of the initial test parameter value based on the historical attribute weight list of the historical code corresponding to the specified feature vector. It can be understood that if the attribute information and the historical attribute are the same, the weight of the historical attribute is used as the target weight of the attribute information of the initial test parameter.

[0038] The following steps are used to obtain the historical attribute weight list of the historical code: S001, obtaining a historical attribute list of parameters of historical codes used in security vulnerability testing, wherein the historical attribute list includes a plurality of historical attributes. Specifically, the historical attributes are attributes of parameters of historical codes used in security vulnerability testing.

[0039] S002. Obtain a historical attribute value list corresponding to a historical attribute list, and obtain a test vector converted from the historical attribute value list, wherein the historical attribute value list includes a plurality of first historical attribute values ​​corresponding to first attributes and a plurality of second historical attribute values ​​corresponding to second attributes, the first attribute is a historical attribute randomly selected from the historical attribute list, and the first historical attribute value corresponding to the first attribute is a corresponding preset extreme value, and the second attribute is a historical attribute in the historical attribute list that is different from the first attribute.

[0040] It can be understood that several historical attributes are randomly selected from the historical attribute list as the first attribute, the first historical attribute value corresponding to the first attribute is set to the corresponding preset extreme value, and the historical attributes in the historical attribute list other than the first attribute are used as the second attribute. In one embodiment of the present invention, the second historical attribute value corresponding to the second attribute is the corresponding attribute value selected from the database. In another embodiment of the present invention, the second historical attribute value corresponding to the second attribute is the normal attribute value of the historical code.

[0041] S003: Substitute each test vector into the historical code for execution, obtain the actual vulnerability determination result corresponding to each measurement vector during the execution of the historical code, and use the test vector and the actual vulnerability determination result as a piece of training data. Specifically, the actual vulnerability determination result is: vulnerability exists or does not exist. In one embodiment of the present invention, the existence of a vulnerability is marked as 1, and the non-existence of a vulnerability is marked as 0.

[0042] S004: Based on the training data, a logistic regression model is used to obtain the weight coefficient between each historical attribute and the actual vulnerability judgment result, thereby obtaining a list of historical attribute weights for the historical code. The logistic regression model is used to learn the impact of test parameters on the actual vulnerability judgment results.

[0043] In summary, a historical attribute list of parameters of the historical code when performing security vulnerability testing is obtained, a historical attribute value list corresponding to the historical attribute list is obtained, and a test vector converted from the historical attribute value list is obtained. Each test vector list is substituted into the historical code for execution, and the real vulnerability judgment result corresponding to each measurement vector is obtained. The test vector and the real vulnerability judgment result are used as a piece of training data. Based on several pieces of training data, a logistic regression model is used to obtain the weight coefficient between each historical attribute and the real vulnerability judgment result, thereby obtaining a historical attribute weight list of the historical code. The present invention finds the attribute weight of the application source code through the attribute weight of the historical code, thereby more accurately finding the target test parameters.

[0044] Specifically, obtain the target AI model through the following steps: S401, build an initial AI model.

[0045] S402 : Acquire a first training data set and a second training data set, where the first training data set includes a plurality of first training data lists, each of which includes a preset vulnerability code of a first vulnerability type and actual vulnerability results corresponding to the preset vulnerability code of the first vulnerability type.

[0046] The second training data includes a plurality of second training data lists, each of which includes: preset vulnerability codes of a second vulnerability type and actual vulnerability results corresponding to the preset vulnerability codes of the second vulnerability type; wherein the first vulnerability type is different from the second vulnerability type. Specifically, the preset vulnerability codes of the first vulnerability type are common vulnerability types and safe vulnerability types. The preset vulnerability codes of the second vulnerability type are pre-set vulnerability codes of an adversarial type, such as real vulnerability codes with variable renaming or invalid code insertion, or safe codes that mimic vulnerability patterns.

[0047] S403: Obtain a mixed training sample of the first training data set and the second training data set, and use the mixed training sample to train the initial AI model to obtain a target AI model.

[0048] Specifically, the training results of the initial AI model are obtained by using mixed training samples. If the training results meet the preset training conditions, the trained initial AI model is used as the target AI model.

[0049] In summary, by training the AI ​​model using common types of vulnerabilities and adversarial types of vulnerabilities, the AI ​​model can better identify vulnerabilities.

[0050] Furthermore, after outputting the first verification result, the method further includes: S510 , dividing the application source code into a plurality of statements, and obtaining a statement list, wherein the statement list includes the plurality of statements.

[0051] Specifically, the statement list A={A1, A2, ..., A i ,…,A m}, A i is the i-th statement.

[0052] Specifically, the statements include declaration statements and executable statements.

[0053] In one embodiment of the present invention, N-grams are used to divide the application source code into several statements.

[0054] In another embodiment of the present invention, a single-line statement is treated as one statement.

[0055] S520, obtaining vulnerability prediction scores B for the first i statements of the application source code for the preset vulnerability i , the value of i ranges from 1 to m, where m is the number of statements.

[0056] Specifically, the first i statements are A1 to Ai, and A1 to A i , several target test parameter value lists and the operating environment of the application source code are input into the target AI model to obtain a prediction score B for a preset vulnerability i .

[0057] S530, obtaining a single sentence score C i , marked C i Statements greater than the threshold are considered vulnerable statements, where the score of a single statement is C i Equal to B i Subtract B i-1 The difference, B i-1 C1 is the vulnerability prediction score of the first i-1 statements in the application source code for the preset vulnerability. When i = 1, C1 is equal to B1. Specifically, it can be understood that when i is equal to 1, C1 is the score of the first statement.

[0058] In summary, divide the application source code into several statements, obtain the statement list, and obtain A1 to A i For a given vulnerability, the team obtains the score of each statement, marks statements with scores greater than a threshold as vulnerable, and accurately locates the vulnerability based on these steps. Compared to directly predicting each statement, using multiple statements to collectively predict the score of the given vulnerability is more accurate.

[0059] An embodiment of the present invention also provides a non-transitory computer-readable storage medium, which can be set in an electronic device to store a computer program related to a method in the method embodiment. The computer program is loaded and executed by the processor to implement the method provided in the above embodiment.

[0060] An embodiment of the present invention further provides an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method provided in the above embodiment when executing the computer program.

[0061] An embodiment of the present invention further provides a computer program product comprising program code. When the program product is run on an electronic device, the program code is used to enable the electronic device to execute the steps of the method according to various exemplary embodiments of the present invention described above in this specification.

[0062] Although some specific embodiments of the present invention have been described in detail by way of examples, it should be understood by those skilled in the art that the above examples are for illustration only and are not intended to limit the scope of the present invention. It should also be understood by those skilled in the art that various modifications may be made to the embodiments without departing from the scope and spirit of the present invention.

Claims

1. A code-level security vulnerability intelligent verification method, characterized in that: The method comprises the following steps: S100, parsing the application source code to obtain a feature vector of the application source code, where the features corresponding to the feature vector include at least: a function name; S200, obtaining a list of initial test parameter values ​​for security vulnerability detection in application source code based on a database, the list of initial test parameter values ​​including initial test parameter values ​​corresponding to the plurality of test parameters; S300, based on attribute information of the application source code and attribute information of the initial test parameter value, obtaining an operating environment of the application source code, wherein the attribute information of the application source code includes at least: a code programming language; the attribute information of the initial test parameter value includes at least: a data type and a preset operating environment of the initial test parameter value; S400: Inputting a plurality of target test parameter value lists, a feature vector of the application source code, and an operating environment of the application source code into a target AI model, using the target AI model to simulate execution of the application source code to identify vulnerabilities, and obtaining a prediction score for each preset vulnerability, wherein the target test parameter value list including the plurality of target test parameter values ​​is one of the plurality of initial test parameter value lists; S500: If the predicted score of a preset vulnerability is greater than a preset vulnerability threshold, output a first verification result; otherwise, output a second verification result, wherein the first verification result is different from the second verification result.

2. The code-level security vulnerability intelligent verification method according to claim 1, characterized in that: S100 also includes the following steps to obtain a feature vector of the application source code: S110, using a compiler to decompose the application source code into syntax units, and constructing a tree-structured application source code based on the syntax units; wherein the syntax units include at least expressions and function names; S120, traversing each node of the application source code in the tree structure to obtain code syntax features, wherein the code syntax features include: node type and hierarchical relationship; S130, splitting the application source code into a graph structure, wherein the graph structure includes a plurality of linearly connected basic blocks, where an edge connecting two basic blocks is a control transfer statement, and the basic block includes a set of statements executed sequentially; S140, obtaining graph structure attribute features based on the graph structure application source code, wherein the graph structure attribute features include: the number of basic blocks and edge types; S150 , vectorizing the code syntax features and the graph structure attribute features respectively, and performing vector fusion on the vectorized code syntax features and the vectorized graph structure attribute features to obtain a feature vector of the application source code.

3. The code-level security vulnerability intelligent verification method according to claim 1, characterized in that: In S400, the target test parameter value list is obtained through the following steps: S410, obtaining a target weight for each attribute information of an initial test parameter value; S420, clustering the initial test parameter vectors converted from the initial test parameter value list based on the attribute information of the initial test parameter value and the target weight of the attribute information to obtain a plurality of clusters; S430 , extracting a fixed number of initial test parameter vectors from each cluster as designated parameter vectors, and using the initial test parameter value list corresponding to the designated parameter vectors as the target test parameter value list.

4. The code-level security vulnerability intelligent verification method according to claim 3, characterized in that: S410 also includes obtaining the target weight of each attribute information of the initial test parameter value through the following steps: S411, obtaining a list of historical attribute weights of several historical codes and parameters of each historical code when performing security vulnerability testing, wherein the list of historical attribute weights includes weights of several historical attributes; S412, obtaining a historical feature vector corresponding to the historical code, and obtaining a historical feature vector with the smallest distance to the feature vector of the application source code as a designated feature vector; S413, determining a target weight of the attribute information of the initial test parameter value based on a historical attribute weight list of the historical code corresponding to the designated feature vector; The historical attribute weight list of the historical code is obtained through the following steps: S001, obtaining a historical attribute list of parameters of historical codes used in security vulnerability testing, wherein the historical attribute list includes a plurality of historical attributes; S002: Obtain a historical attribute value list corresponding to the historical attribute list, and obtain a test vector converted from the historical attribute value list, wherein the historical attribute value list includes a plurality of first historical attribute values ​​corresponding to first attributes and a plurality of second historical attribute values ​​corresponding to second attributes, wherein the first attribute is a historical attribute randomly selected from the historical attribute list, and the first historical attribute value corresponding to the first attribute is a corresponding preset extreme value, and the second attribute is a historical attribute in the historical attribute list that is different from the first attribute; S003, substituting each test vector into the historical code for execution, obtaining the actual vulnerability judgment result corresponding to each measurement vector during the execution of the historical code, and using the test vector and the actual vulnerability judgment result as a piece of training data; S004: Based on a number of training data, a logistic regression model is used to obtain a weight coefficient between each historical attribute and the actual vulnerability judgment result, thereby obtaining a historical attribute weight list of the historical code.

5. The code-level security vulnerability intelligent verification method according to claim 3 is characterized in that: The number is fixed to 1, and the initial test parameter vector with the smallest distance to the center vector of the cluster is used as the specified parameter vector.

6. The code-level security vulnerability intelligent verification method according to claim 1, characterized in that: Obtain the target AI model through the following steps: S401, building an initial AI model; S402: Acquire a first training data set and a second training data set, where the first training data set includes a plurality of first training data lists, each of which includes a preset vulnerability code of a first vulnerability type and actual vulnerability results corresponding to the preset vulnerability code of the first vulnerability type; The second training data includes a plurality of second training data lists, the second training data lists including: a preset vulnerability code of a second vulnerability type and actual vulnerability results corresponding to the preset vulnerability code of the second vulnerability type; wherein the first vulnerability type is different from the second vulnerability type; S403: Obtain a mixed training sample of the first training data set and the second training data set, and use the mixed training sample to train the initial AI model to obtain a target AI model.

7. The code-level security vulnerability intelligent verification method according to claim 6, characterized in that: Obtain the training results of the initial AI model using the mixed training samples. If the training results meet the preset training conditions, the trained initial AI model is used as the target AI model.

8. The code-level security vulnerability intelligent verification method according to claim 1, characterized in that: After outputting the first verification result, the method further includes: S510, dividing the application source code into a plurality of statements, obtaining a statement list, wherein the statement list includes the plurality of statements; S520, obtaining vulnerability prediction scores B for the first i statements of the application source code for the preset vulnerability i , the value of i ranges from 1 to m, where m is the number of statements; S530, obtaining a single sentence score C i , marked C i Statements greater than the threshold are considered vulnerable statements, where the score of a single statement is C i Equal to B i Subtract B i-1 The difference, B i-1 C1 is the vulnerability prediction score of the first i-1 statements in the application source code for the preset vulnerability. When i=1, C1 is equal to B1.

9. A non-transitory computer-readable storage medium, characterized in that The storage medium stores a computer program, which is loaded and executed by a processor to implement the code-level security vulnerability intelligent verification method according to any one of claims 1 to 8.

10. An electronic device comprising: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor implements the code-level security vulnerability intelligent verification method as described in any one of claims 1 to 8 when executing the computer program.

Citation Information

Patent Citations

  • Source code vulnerability detection method and device and storage medium

    CN115017511A

  • Software program code testing method and device, electronic equipment and storage medium

    CN116383833A

  • Source code vulnerability detection method and system based on adaptive graph neural network

    CN119272275A

  • Software vulnerability detection method, system and product based on bidirectional gating graph neural network

    CN120030550A

  • Large model enhanced code security detection method

    CN120372627A