Software model selection method and device, equipment, medium and product

By obtaining and evaluating the files and basic information of third-party open source software, determining vulnerability information and scoring it, the problem of insufficient manual evaluation in existing technologies is solved, and more efficient and accurate software selection is achieved.

CN120705879APending Publication Date: 2025-09-26INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510823105.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

In the existing technology, the selection of third-party open source software relies on manual evaluation, which leads to insufficient rationality, comprehensiveness and accuracy of the evaluation, affecting the efficiency of software use.

Method used

By obtaining the software files and basic information of the software to be evaluated, the target vulnerability information is determined, and the evaluation is performed based on the software basic information and vulnerability information to obtain the target score, and the selection is made based on the score.

Benefits of technology

It improves the efficiency, comprehensiveness and accuracy of software selection, replaces manual selection, and provides a more reliable evaluation basis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705879A_ABST
    Figure CN120705879A_ABST
Patent Text Reader

Abstract

The invention discloses a software type selection method and device, equipment, a medium and a product, and relates to the technical field of data processing. The method comprises the steps of obtaining a software file of to-be-evaluated software and at least one piece of software basic information, and determining target vulnerability information existing in the to-be-evaluated software; evaluating the to-be-evaluated software according to the basic information and the target vulnerability information of each piece of software to obtain a target score of the to-be-evaluated software; and performing model selection on the to-be-evaluated software according to the target score. According to the technical scheme provided by the embodiment of the invention, whether the open source software can be adopted and used or not is evaluated from a multi-dimensional angle, so that manual selection processing can be replaced, the selection evaluation efficiency is improved, the comprehensiveness and rationality of evaluation can be further improved, and the selection evaluation accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to a software selection method, apparatus, device, medium and product. Background Art

[0002] With the development of internet and computer technologies, the demand for a stable and secure supply chain for third-party open source software is growing. Enterprises and manufacturers have certain requirements for the stable operation of the third-party open source software they import. Therefore, how to accurately and efficiently select third-party open source software has become a key research focus for technicians in related fields.

[0003] Currently, in most cases, industry workers use security assessments to select third-party open source software. However, this security assessment process still relies heavily on manual evaluation and screening, which cannot guarantee the rationality, comprehensiveness, and accuracy of the software evaluation, nor can it improve the efficiency of software selection, which can easily affect enterprises' use of open source software. Summary of the Invention

[0004] This application provides a software selection method, device, equipment, medium and product to improve the rationality and accuracy of software selection and enhance the selection efficiency.

[0005] According to one aspect of the present application, a software selection method is provided, comprising:

[0006] Obtaining software files and at least one type of basic software information of the software to be evaluated, and determining target vulnerability information present in the software to be evaluated;

[0007] Evaluate the software to be evaluated based on the basic information and target vulnerability information of each software to obtain the target score of the software to be evaluated;

[0008] Based on the target score, select the software to be evaluated.

[0009] According to another aspect of the present application, a software selection device is provided, comprising:

[0010] An information acquisition module is used to obtain software files and at least one type of basic software information of the software to be evaluated, and to determine target vulnerability information existing in the software to be evaluated;

[0011] The software scoring module is used to evaluate the software to be evaluated based on the basic information and target vulnerability information of each software to obtain the target score of the software to be evaluated;

[0012] The evaluation and selection module is used to select the software to be evaluated based on the target score.

[0013] According to another aspect of the present application, an electronic device is provided, comprising:

[0014] at least one processor; and

[0015] a memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the software selection method described in any embodiment of the present application.

[0017] According to another aspect of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the software selection method described in any embodiment of the present application when executed.

[0018] According to another aspect of the present application, a computer program product is provided, which includes a computer program. When the computer program is executed by a processor, it implements the software selection method according to any embodiment of the present application.

[0019] In the technical solution of the embodiment of the present application, the software files and at least one software basic information of the software to be evaluated are obtained, and the target vulnerability information existing in the software to be evaluated is determined. The software basic information and target vulnerability information of the software to be evaluated are obtained, which can provide an accurate basis for the subsequent scoring of the software to be evaluated from different aspects; according to each piece of software basic information and target vulnerability information, the software to be evaluated is evaluated to obtain the target score of the software to be evaluated, and the software to be evaluated is evaluated from multiple aspects such as the software basic information and the target vulnerability information. Whether the open source software can be adopted and used is evaluated from a multi-dimensional perspective, which can not only replace manual selection processing and improve the efficiency of evaluation and selection, but also further improve the comprehensiveness and rationality of the evaluation, and improve the accuracy of evaluation and selection.

[0020] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0022] Figure 1 This is a flowchart of a software selection method provided according to the first embodiment of the present application;

[0023] Figure 2 This is a schematic diagram of selecting and storing open source software applicable to Example 2 of the present application;

[0024] Figure 3 This is a structural diagram of a software selection device provided according to the third embodiment of the present application;

[0025] Figure 4 It is a structural diagram of an electronic device that implements the software selection method of an embodiment of the present application. DETAILED DESCRIPTION

[0026] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0028] Example 1

[0029] Figure 1 A flowchart of a software selection method is provided for the first embodiment of the present application. This embodiment is applicable to the case of selecting and storing open source software. The method can be executed by a software selection device. The software selection device can be implemented in the form of hardware and / or software. The software selection device can be configured in an electronic device. Figure 1 As shown, the method includes:

[0030] S110: Obtain software files and at least one type of software basic information of the software to be evaluated, and determine target vulnerability information existing in the software to be evaluated.

[0031] Among them, the software to be evaluated can be any open source software that needs to be evaluated and selected, and the embodiment of this application does not limit the type and function of the open source software. The basic software information can be basic information about the properties, sources and application of the software to be evaluated. The software file can be a data entity of the software to be evaluated, for example, existing as a jar package. The embodiment of this application does not limit the form of the software file of the software to be evaluated. The basic software information can include but is not limited to the open source community information, maintenance record information, user usage information, software compatibility information and metadata information of the open source software. Among them, the metadata information can be the underlying information of the open source software, for example, it can include but is not limited to the development information and version information of the open source software.

[0032] The target vulnerability information can be all vulnerability information present in the software to be evaluated. It should be noted that the development of any open source software is not absolutely rigorous. The software version will be iteratively upgraded. During the use of open source software, many usage problems will be exposed, collectively referred to as vulnerability information. This vulnerability information can be obtained by performing vulnerability scanning on the software to be evaluated, or through records in the open source software community and public vulnerability databases. The embodiments of this application do not limit the method for obtaining target vulnerability information. Of course, the vulnerability scanning of the software files of the software to be evaluated can use any scanning tool in the relevant technology.

[0033] S120 : Evaluate the software to be evaluated based on the basic information and target vulnerability information of each software to obtain a target score for the software to be evaluated.

[0034] The target score of the software to be evaluated can be used to characterize the software quality of the software to be evaluated and to determine whether the software to be evaluated can be adopted as open source software that the enterprise or manufacturer itself allows internal personnel to use.

[0035] It is understandable that the basic software information contains information of different dimensions, which can characterize the performance advantages of the software to be evaluated from different dimensions, while the target vulnerability information can characterize the defects and disadvantages of the software to be evaluated. Scoring from both the advantages and disadvantages can comprehensively evaluate the performance of the software to be evaluated, so that the obtained target score can more completely reflect the selectability of the software to be evaluated and provide an accurate basis for the selection of the software to be evaluated.

[0036] Exemplarily, the software basic information and the target vulnerability information can be scored separately. The scoring standard can be set in advance for the information in the software basic information that can reflect the advantages of the software. The greater the advantage, the higher the score. The software basic information that meets the corresponding scoring standard can be assigned a corresponding score. Similarly, the scoring standard can be set in advance for the information in the vulnerability information that reflects the disadvantages of the software. The more vulnerabilities or the greater the disadvantages, the lower the score. The target vulnerability information that meets the corresponding scoring standard can be assigned a corresponding score. The two scores are directly added or weighted summed to obtain the target score. Of course, the weights of the two scores can be pre-set by technicians in the relevant fields according to actual conditions, and the embodiments of the present application do not limit this.

[0037] S130. Select the software to be evaluated based on the target score.

[0038] Based on the target score obtained in the previous steps, determine whether the software to be evaluated can be adopted for use. For example, a selection score threshold can be pre-set. If the target score reaches the selection score threshold, the software can be adopted for use. If the target score does not reach the selection score threshold, the software will not be adopted for use.

[0039] In the technical solution of the embodiment of the present application, the software files and at least one software basic information of the software to be evaluated are obtained, and the target vulnerability information existing in the software to be evaluated is determined. The software basic information and target vulnerability information of the software to be evaluated are obtained, which can provide an accurate basis for the subsequent scoring of the software to be evaluated from different aspects; according to each piece of software basic information and target vulnerability information, the software to be evaluated is evaluated to obtain the target score of the software to be evaluated, and the software to be evaluated is evaluated from multiple aspects such as the software basic information and the target vulnerability information. Whether the open source software can be adopted and used is evaluated from a multi-dimensional perspective, which can not only replace manual selection processing and improve the efficiency of evaluation and selection, but also further improve the comprehensiveness and rationality of the evaluation, and improve the accuracy of evaluation and selection.

[0040] In an optional embodiment, the software technical information includes open source community information, maintenance record information, user usage information and software compatibility information of the software to be evaluated;

[0041] S120 evaluates the software to be evaluated based on the basic information of each software and the target vulnerability information to obtain a target score for the software to be evaluated, which may include:

[0042] S121. Determine an evaluation score for at least one dimension of the software to be evaluated based on at least one of target vulnerability information, open source community information, maintenance record information, user usage information, and software compatibility information.

[0043] Among them, open source community information can be community feedback in the Internet community where the open source software is released. It should be noted that open source software is generally released by developers in the Internet community. Adhering to the original intention of open source sharing on the Internet, the open source software is maintained and updated for users. Therefore, for Internet communities that widely release open source software, there are a lot of users who participate in downloading, using and providing feedback on the use of open source software. Therefore, open source community information can include the feedback of these Internet communities on the open source software. Exemplarily, open source community confidence can include but is not limited to community activity information, problem response speed information, and user feedback information.

[0044] Maintenance records can include information about the operation and maintenance of the software under evaluation by the open source software developer or operations personnel. It's understandable that after the developer releases the software to the internet community, they naturally need to operate and maintain it to ensure that it can properly provide the corresponding functions and benefits to users. Therefore, information about the maintenance performed on the software under evaluation is recorded and retained within the internet community. For example, maintenance records may include, but are not limited to, information about the version submission frequency, release cycle, and long-standing unresolved issues of the software under evaluation.

[0045] User usage information can be information about how users (individuals, units, organizations, etc.) use the open source software to be evaluated. For example, user usage information can include, but is not limited to, user usage frequency information, user preference information, and historical problem record information.

[0046] Software compatibility information can be used to characterize the compatibility and stability of the software to be evaluated during operation. Software compatibility information may include, but is not limited to, software compatibility information and historical stability information.

[0047] On the other hand, dimensional assessment scores can be derived from the aforementioned information across different dimensions. Each of these dimensional information (target vulnerability information, open source community information, maintenance records, user usage information, and software compatibility information) describes the software being evaluated from different perspectives. This information can be pre-assigned to different scoring rules, converting the software's performance and strengths and weaknesses expressed in this information into specific scores.

[0048] S122. According to the preset dimension weights, the evaluation scores of each dimension are weighted and calculated to obtain the target score.

[0049] The dimension weights can be the weights corresponding to the dimension evaluation scores, that is, the proportion of the evaluation scores corresponding to the software information in different dimensions in the final target score. The weighted sum of the evaluation scores of each dimension is calculated to obtain the final target score.

[0050] In the above implementation, by scoring the software information of different dimensions in the software to be evaluated, the evaluation situation of different dimensions is obtained, and the evaluation scores of each dimension are weighted and calculated. The obtained target score performs a more fair and specific evaluation of the software to be evaluated, ensuring the comprehensiveness and fairness of the evaluation of open source software. The obtained target score has high accuracy, which provides a reliable basis for the subsequent software selection.

[0051] In a further optional embodiment, determining the evaluation score of at least one dimension of the software to be evaluated based on at least one of target vulnerability information, open source community information, maintenance record information, user usage information, and software compatibility information may include:

[0052] The vulnerability score corresponding to the target vulnerability information is determined based on the vulnerability severity information, impact scope information, and remediation difficulty information in the target vulnerability information. The vulnerability severity information can be information that characterizes the severity of the vulnerability to be assessed. For example, it can be determined based on the amount of target vulnerability data; the more vulnerabilities there are, the higher the severity. For example, a score corresponding to the number of vulnerabilities can be pre-set: the more vulnerabilities there are, the higher the risk, and the lower the score; conversely, the fewer vulnerabilities there are, the lower the risk, and the higher the score. The impact scope information can be used to characterize the scope of impact caused by the target vulnerability information when a fault occurs. For example, the impact scope can be based on the number of code lines affected by a fault caused by a particular vulnerability information. The more code lines affected, the greater the impact scope. Similarly, a score corresponding to the number of affected code lines can be pre-set: the more affected code lines, the lower the score; conversely, the fewer affected code lines, the higher the score. The remediation difficulty information can be the vulnerability remediation difficulty information retrieved from a common vulnerability scoring system based on the vulnerability information. The score corresponding to the remediation difficulty information can be retrieved from the common vulnerability scoring system: for example, high-risk vulnerabilities are assigned lower scores, while low-risk vulnerabilities are assigned higher scores. The general vulnerability scoring system can be directly obtained through the Internet, and the embodiments of the present application are not described in detail here. The scores corresponding to the above three different information are accumulated or weighted summed to obtain the vulnerability score.

[0053] The community score corresponding to the open source community information is determined based on community activity information, question response speed information, and user feedback information within the open source community. Community activity information can be used to indicate the level of discussion of the software being evaluated within the open source community. Open source communities allow users to review or star-rate software released by developers. The more discussions there are, the higher the level of discussion, and the more active the software is in the community. Scoring rules corresponding to community activity can be pre-defined. For example, a certain number of comments can be assigned a certain number of points, with more comments giving a higher score, while fewer comments give a lower score. Question response speed can be measured by the time between the publisher's posting of a question and the response. Similarly, scoring rules can be pre-defined for this time difference, with shorter time differences giving higher scores, and longer time differences giving lower scores. User feedback information can include both positive and negative feedback from users who have used the open source software. This can include both positive and negative feedback, i.e., favorable and unfavorable reviews. Scoring rules can be pre-set based on the proportion of positive and negative reviews in the overall ratings. The more positive reviews and fewer negative reviews, the higher the score. Conversely, the fewer positive reviews and more negative reviews, the lower the score. The scores corresponding to the three different types of information are accumulated or weighted to obtain the community score.

[0054] The maintenance score corresponding to the maintenance record information is determined based on the version submission frequency information, release cycle information, and long-standing unresolved issues information in the maintenance record information. The version submission frequency information may refer to the frequency of software version updates. Constant issue fixes often result in minor software version updates, such as from version 1.0.1 to 1.0.2. The release cycle information may refer to the time interval between major software releases, such as the time between updates from version 1.0 to 1.1. Scoring rules corresponding to frequency and time interval can be pre-set. For example, higher version submission frequency or shorter time intervals correspond to higher scores. It is understood that a higher frequency of version updates indicates more diligent maintenance by developers, making it easier to obtain better-performing open source software. Furthermore, long-standing unresolved issues information may refer to issues in the open source software that have not been addressed or fixed in the community for a long time. The number of these issues determines the developer's willingness to upgrade the software. Similarly, a scoring rule corresponding to the number of long-standing unresolved issues can be pre-set. A higher number of issues corresponds to a lower score, while a lower number of issues corresponds to a higher score. The scores corresponding to the above three different types of information are cumulatively added or weighted together to obtain the maintenance score.

[0055] The user rating corresponding to the user usage information is determined based on the user usage frequency information, user preference information, and historical problem record information in the user usage information. Among them, the user usage frequency information can be the download frequency of the software by users in the Internet community. The user preference information can be the star rating of the software by users in the Internet community. The scoring rules corresponding to the download frequency and star rating can be pre-set. For example, the higher the download frequency or the more stars in the rating, the higher the score. A high download frequency indicates a high growth in the number of users using the software, and a high star rating indicates high user satisfaction and recognition. The historical problem record information can be the number of low-star ratings fed back by users. Similarly, the scoring rules corresponding to the number of low-star ratings can be pre-set. For example, the higher the number of low-star ratings, the lower the score. The scores corresponding to the above three different information are accumulated or weighted summed to obtain the user rating.

[0056] According to the software compatibility information and historical stability information in the software compatibility information, the compatibility score corresponding to the software compatibility information is determined. Among them, the software compatibility information is used to characterize the adaptability and compatibility of the software to be evaluated for various application environments, and can be measured by the number of compatibility error data. For example, the higher the number of compatibility error reports, the worse the compatibility. The historical stability information can be the stability information fed back by users who have used the software in the past, which is used to characterize the stability of the software to be evaluated under long-term use. It can be measured by the number of stability error reports. For example, the higher the number of stability error reports, the worse the stability. Then, the scoring rules corresponding to the number of compatibility error reports and the number of stability error reports can be pre-set. For example, the more compatibility error reports or the more stability error reports, the lower the score. The scores corresponding to the above two different information are accumulated or weighted summed to obtain the compatibility score.

[0057] The sum of the dimension weights corresponding to the vulnerability score, community score, maintenance score, user score, and compatibility score is 1. For example, the weight of the vulnerability score can be 0.4; the weight of the community score can be 0.2; the weight of the maintenance score can be 0.2; the weight of the user score can be 0.1; and the weight of the compatibility score can be 0.1. Of course, the weight values ​​corresponding to each score can be set by technicians in related fields based on a large number of experiments or actual situations. The embodiments of this application are only examples.

[0058] In the above implementation, information of different dimensions is analyzed, and scores are calculated from the subordinate data of each dimension of information, which can evaluate an open source software from multiple aspects to the greatest extent, ensure the comprehensiveness of the evaluation basis and the rationality of the evaluation process, and make the final evaluation results highly referenceable.

[0059] In an optional embodiment, selecting the software to be evaluated based on the target score as described in S130 may include: in response to the target score being greater than or equal to a preset score threshold, determining that the software to be evaluated meets the selection conditions; storing the software files of the software to be evaluated in a preset software warehouse, and storing the basic software information in a preset software product management platform.

[0060] The score threshold can be a basis for determining whether the target score is qualified as a selection condition. For example, if the score threshold is 80 points, when the target score is greater than or equal to 80 points, the software to be evaluated is determined to meet the selection requirements and can be selected as the software to be evaluated; on the contrary, when the target score is less than 80 points, it is determined that the evaluation software does not meet the selection requirements and does not meet the usage requirements. Therefore, the software to be evaluated is discarded and not selected for the bid. Of course, the score threshold can be set by technicians in the relevant field based on a large number of experiments or manual experience, and the embodiments of the present application do not limit this.

[0061] The main operations for evaluating software selection include storing the software files of the selected software in a software repository and storing the basic software information in a software product management platform. This software repository can be pre-built to store the data entities of the selected software. Users can directly select and download the required open source software from the software repository. The software product management platform is also pre-built and primarily stores the basic software information of the selected open source software. This basic information is placed on the software product management platform for users to query and identify. The software product management platform is connected to the software repository and manages the various open source software stored in the software repository through the software product management platform. It is conceivable that users can use the software product management platform to view information about the various selected open source software, such as the functions they can perform, the software developer and version information, the software maintenance information, and the software manual, etc., to provide a reference for their selection. Users select and access a specific open source software through the software product management platform, and the software product management platform helps users download the software files from the software repository for installation and use.

[0062] Of course, the construction method of the software warehouse and the software product management platform can adopt any construction method in the relevant field, and the embodiments of the present application are not limited to this.

[0063] In the above implementation, a preset score threshold is used to determine whether the target score can represent the performance of the software to be evaluated and whether it can be selected and adopted, which provides a practical method for the selection of open source software, can improve the efficiency of software selection, and make use of the pre-built software product management platform and software warehouse. The software warehouse is used to store the software files that have been selected, and the software product management platform is used to manage the software files in the warehouse to assist users in downloading, installing and using them. Users do not need to search in different Internet communities and consider whether they can download a certain open source software for use. Instead, they can directly make decisions on the selected software through the internal platform of the enterprise, which can further improve the convenience of users in using open source software.

[0064] In an optional implementation, the method may further include: displaying software basic information and recommended version information corresponding to the software stored in the software product management platform.

[0065] Among them, the recommended version information can be the version of the open source software that has been selected and successfully bid, which is recommended for users to download and use in the software product management platform. It is understandable that the same open source software will continuously fix problems and update new versions of the software during the release and iteration process, but at the same time, the new version of the software may also have other problems. The stability and compatibility of different versions of the same open source software are different. Therefore, in general, the software version with the best stability and compatibility is recommended to users, which is reflected in the corresponding recommended version information in the software product management platform. Users can check the basic software information in the software product management platform to determine whether the functions of a certain open source software meet their needs, and download the corresponding version of the software file from the software management platform according to the recommended version information for use.

[0066] In the above implementation, the basic software information and recommended version information corresponding to the software stored in the software product management platform are displayed, providing an intuitive reference for users to select software and download recommended versions, which helps to improve the user's convenience in using open source software.

[0067] In another optional implementation, the step of obtaining the software file of the software to be evaluated and determining target vulnerability information in the software to be evaluated in S110 may include:

[0068] S111. Obtain the software files of the software to be evaluated, as well as supplementary vulnerability information of the software to be evaluated on the open source platform.

[0069] The open source platform may be a platform that records vulnerability information for open source software, including, but not limited to, internet communities and public vulnerability information databases. Supplemental vulnerability information may be vulnerability information of the software to be assessed that is stored and recorded on the open source platform. This supplemental vulnerability information can be used to supplement other vulnerabilities not discovered in the software files after scanning.

[0070] It is understandable that the supplementary vulnerability information on the open source platform can be directly obtained through query, for example, by querying the public vulnerability information database according to the name of the software to be evaluated, and determining the vulnerability information that has been registered as the supplementary vulnerability information.

[0071] S112: Perform vulnerability scanning on the software file to obtain scanning vulnerability information of the software to be evaluated.

[0072] Among them, the vulnerability information scanned can be vulnerability information obtained by scanning software files through a vulnerability scanning operation. Of course, the vulnerability scanning method can adopt any vulnerability scanning method in the relevant technology, and the embodiments of the present application are not limited to this. Exemplarily, a general vulnerability scanning tool is used, which includes a vulnerability database, a vulnerability scanning function and an open interface. The vulnerability scanning function is called through the interface to scan the software medium (i.e., software file) of the software to be evaluated. For the vulnerability information in the vulnerability database, it is determined which vulnerability information the software meets, as the result of the scan, that is, the scan vulnerability information.

[0073] S113: Add the supplementary vulnerability information to the scanned vulnerability information to obtain target vulnerability information.

[0074] As you can understand, supplementary vulnerability information is used to supplement vulnerabilities that were not detected during the scan. Therefore, the supplementary vulnerability information obtained from the open source platform is integrated with the scan vulnerability information to obtain the final target vulnerability information. As you can understand, the target vulnerability information more comprehensively reflects the vulnerability status of the software to be evaluated.

[0075] In the above implementation, supplementary vulnerability information obtained from the open source platform is used to supplement the scanned vulnerability information. This allows the target vulnerability information to encompass a wider range of vulnerabilities in the software being evaluated, more comprehensively reflecting the various vulnerabilities of the software being evaluated. This provides a more accurate and comprehensive basis for subsequent target scoring based on the target vulnerability information. This helps improve the accuracy of scoring, and thus further enhances the accuracy of software selection.

[0076] Example 2

[0077] Figure 2This is a schematic diagram of the selection and warehousing of open source software provided in Example 2 of the present application. This example is a specific example provided on the basis of the aforementioned embodiments and implementation methods. This example is mainly used in banking scenarios. When bank back-end developers need to use third-party open source software, the open source software is automatically selected and stored in the warehouse to provide back-end developers with a better quality software warehouse.

[0078] like Figure 2 As shown, the systems for software selection and storage include vulnerability scanning tools, data collection tools, industry-specific open source software databases, open source software security assessment and analysis tools, software product management systems, and software warehouses.

[0079] Vulnerability scanning tool: An industry-wide vulnerability scanning tool used to scan software products for vulnerability information. This scanning tool includes a vulnerability information library, vulnerability scanning functionality, and an externally accessible data interface. The vulnerability scanning functionality scans the software's media (software files), compares the vulnerability information in the vulnerability library, and generates vulnerability scan results for the relevant software products.

[0080] Data collection tools: By collecting third-party open source software information from open source software communities, open source platforms, and public vulnerability databases, we supplement the missing vulnerability information in the vulnerability scanning tool information library, as well as the metadata information required by the industry's open source software security management requirements. At the same time, we collect data such as open source software community activity, historical vulnerability repair records, open source software evaluations, etc. required by open source software analysis tools, and store these data in the industry's unique open source software database.

[0081] Our proprietary open source software database: This database maintains a database of third-party open source software, including vulnerability information from vulnerability scanning tools and open source software metadata collected by data collection tools. It also includes open source software analysis and assessment data generated by open source software security assessment and analysis tools.

[0082] Open Source Software Security Assessment and Analysis Tool: This tool designs an open source software scoring algorithm based on industry open source software management requirements. It uses a customized set of refined scoring criteria to evaluate the usability and recommendation of open source software, and stores the relevant results in an industry-specific open source software database. The open source software scoring criteria are not unique and may change with industry open source software management requirements, and the relevant data is continuously updated. The evaluation method is as follows:

[0083] Vulnerability Data Scoring (40% weighting): This takes into account the severity of the vulnerability (high, medium, or low), the scope of impact, and the difficulty of remediation. High-risk vulnerabilities are assigned low scores, low-risk vulnerabilities are assigned high scores, and so on.

[0084] Community feedback score (weight 20%): includes community activity (number of community stars, etc.), problem response speed, and the ratio of positive to negative feedback.

[0085] Maintenance frequency score (weight 20%): The open source software community is scored based on its recent submission frequency, release cycle, and the number and proportion of long-term unresolved issues.

[0086] User behavior score (weight 10%): Score the open source software based on the frequency of use, user preference information, and historical problem records within the industry and on the Internet.

[0087] Compatibility and stability score (weight 10%): Evaluate the compatibility and historical stability of the open source software with other commonly used components and assign a score.

[0088] Software Product Management System: This industry-wide open source software information management system is used to import and register open source software for use in application projects. This system automatically completes the open source software import process by importing open source software data from the industry's unique open source software database, eliminating the need for developers to manually input and analyze information. All imported and registered open source software can display metadata, analysis reports, and recommended versions on the platform.

[0089] Software Repository: Built and deployed based on an open source repository manager, it is used to store, organize, and distribute software artifacts, primarily third-party open source software, in-house developed software, and purchased software. Software resources are pulled and uploaded through the software repository during application project construction. By connecting to an in-house open source software database, the platform can display metadata and open source software evaluation reports on the open source software details page. Furthermore, the platform can be linked to software product management systems to control open source software access.

[0090] This invention uses customized data collection tools and open source software security assessment methods to build an industry-specific open source software database. It automatically analyzes open source software for introduction and provides recommended open source software versions for application, completing open source software selection and version standardization. This significantly reduces the workload for developers to introduce and evaluate third-party open source software, improves open source software management efficiency, and ensures the security of open source software use.

[0091] Example 3

[0092] Figure 3 This is a schematic diagram of the structure of a software selection device provided in Example 3 of this application. Figure 3 As shown, the device 300 includes:

[0093] The information acquisition module 310 is used to obtain the software files and at least one kind of basic software information of the software to be evaluated, and determine the target vulnerability information existing in the software to be evaluated;

[0094] The software scoring module 320 is used to evaluate the software to be evaluated based on the basic information and target vulnerability information of each software to obtain a target score for the software to be evaluated;

[0095] The evaluation and selection module 330 is used to select the software to be evaluated based on the target score.

[0096] In the technical solution of the embodiment of the present application, the software files and at least one software basic information of the software to be evaluated are obtained, and the target vulnerability information existing in the software to be evaluated is determined. The software basic information and target vulnerability information of the software to be evaluated are obtained, which can provide an accurate basis for the subsequent scoring of the software to be evaluated from different aspects; according to each piece of software basic information and target vulnerability information, the software to be evaluated is evaluated to obtain the target score of the software to be evaluated, and the software to be evaluated is evaluated from multiple aspects such as the software basic information and the target vulnerability information. Whether the open source software can be adopted and used is evaluated from a multi-dimensional perspective, which can not only replace manual selection processing and improve the efficiency of evaluation and selection, but also further improve the comprehensiveness and rationality of the evaluation, and improve the accuracy of evaluation and selection.

[0097] In an optional embodiment, the software technical information includes open source community information, maintenance record information, user usage information and software compatibility information of the software to be evaluated;

[0098] The software scoring module 320 may include:

[0099] A dimension evaluation unit, configured to determine at least one dimension evaluation score of the software to be evaluated based on at least one of target vulnerability information, open source community information, maintenance record information, user usage information, and software compatibility information;

[0100] The scoring weighting unit is used to calculate the weighted sum of the evaluation scores of each dimension according to the preset dimension weights to obtain the target score.

[0101] In an optional implementation, the dimension evaluation unit may include:

[0102] A vulnerability scoring subunit is used to determine the vulnerability score corresponding to the target vulnerability information based on the vulnerability severity information, impact scope information, and repair difficulty information in the target vulnerability information;

[0103] A community scoring subunit is used to determine the community score corresponding to the open source community information based on the community activity information, question response speed information and user feedback information in the open source community information;

[0104] A maintenance scoring unit is used to determine a maintenance score corresponding to the maintenance record information based on the version submission frequency information, release cycle information, and long-term unresolved problem information in the maintenance record information;

[0105] A user rating unit is used to determine a user rating corresponding to the user usage information based on the user usage frequency information, user preference information and historical question record information in the user usage information;

[0106] a compatibility scoring unit, configured to determine a compatibility score corresponding to the software compatibility information based on the software compatibility information and the historical stability information in the software compatibility information;

[0107] Among them, the sum of the dimension weights corresponding to the vulnerability score, community score, maintenance score, user score, and compatibility score is 1.

[0108] In an optional implementation, the evaluation and selection module 330 may include:

[0109] A selection judgment unit, configured to determine that the software to be evaluated meets the selection conditions in response to the target score being greater than or equal to a preset score threshold;

[0110] The storage management unit is used to store the software files of the software to be evaluated in a pre-set software warehouse and store the basic software information in a preset software product management platform.

[0111] In an optional implementation, the apparatus 300 may include:

[0112] The software display module is used to display the basic software information and recommended version information corresponding to the software stored in the software product management platform.

[0113] In an optional implementation, the information acquisition module 310 may include:

[0114] A vulnerability supplementation unit is used to obtain the software files of the software to be evaluated and the supplementary vulnerability information of the software to be evaluated on the open source platform;

[0115] A vulnerability scanning unit is used to perform vulnerability scanning operations on software files to obtain scanning vulnerability information of the software to be evaluated;

[0116] The vulnerability determination unit is used to add the supplementary vulnerability information to the scanned vulnerability information to obtain the target vulnerability information.

[0117] The software selection device provided in the embodiments of the present application can execute the software selection method provided in any embodiment of the present application, and has the corresponding functional modules and beneficial effects for executing each software selection method.

[0118] Example 4

[0119] Figure 4 A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present application is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or required herein.

[0120] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0121] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0122] The processor 11 may be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the software selection method.

[0123] In some embodiments, the software selection method may be implemented as a computer program that is tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the software selection method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the software selection method in any other appropriate manner (e.g., by means of firmware).

[0124] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0125] Computer programs for implementing the methods of the present application may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0126] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. A computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0127] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0128] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0129] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.

[0130] The present application also discloses a computer program product, comprising a computer program that, when executed by a processor, implements the software selection method provided in any of the embodiments of the present application. This program product and the software selection method disclosed in each embodiment of the present application share the same inventive concept and are therefore not described in detail here.

[0131] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this application can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of this application can be achieved. This is not limited herein.

[0132] The above specific embodiments do not constitute a limitation on the scope of protection of this application. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application shall be included within the scope of protection of this application.

Claims

1. A software selection method, characterized in that: include: Obtaining software files and at least one piece of software basic information of the software to be evaluated, and determining target vulnerability information present in the software to be evaluated; Evaluate the software to be evaluated based on the basic information of each software and the target vulnerability information to obtain a target score for the software to be evaluated; The software to be evaluated is selected according to the target score.

2. The method according to claim 1, characterized in that The software technical information includes the open source community information, maintenance record information, user usage information and software compatibility information of the software to be evaluated; The step of evaluating the software to be evaluated based on the basic information of each software and the target vulnerability information to obtain a target score for the software to be evaluated includes: Determining at least one dimension evaluation score of the software to be evaluated based on at least one of the target vulnerability information, the open source community information, the maintenance record information, the user usage information, and the software compatibility information; According to the preset dimension weights, the weighted sum of the dimension evaluation scores is calculated to obtain the target score.

3. The method according to claim 2, characterized in that The determining, based on at least one of the target vulnerability information, the open source community information, the maintenance record information, the user usage information, and the software compatibility information, of at least one dimension evaluation score of the software to be evaluated comprises: Determine a vulnerability score corresponding to the target vulnerability information based on vulnerability severity information, impact scope information, and repair difficulty information in the target vulnerability information; Determining a community score corresponding to the open source community information based on community activity information, question response speed information, and user feedback information in the open source community information; Determine a maintenance score corresponding to the maintenance record information based on the version submission frequency information, release cycle information, and long-term unresolved issue information in the maintenance record information; Determining a user score corresponding to the user usage information based on user usage frequency information, user preference information, and historical question record information in the user usage information; determining a compatibility score corresponding to the software compatibility information based on the software compatibility information and the historical stability information in the software compatibility information; The sum of the dimension weights corresponding to the vulnerability score, the community score, the maintenance score, the user score, and the compatibility score is 1.

4. The method according to claim 1, wherein The selecting the software to be evaluated according to the target score includes: In response to the target score being greater than or equal to a preset score threshold, determining that the software to be evaluated meets the selection conditions; The software files of the software to be evaluated are stored in a pre-set software warehouse, and the basic software information is stored in a preset software product management platform.

5. The method according to claim 4, characterized in that The method comprises: The software basic information and recommended version information corresponding to the software stored in the software product management platform are displayed.

6. The method according to claim 1, characterized in that The obtaining of software files of the software to be evaluated and determining target vulnerability information present in the software to be evaluated includes: Obtaining software files of the software to be evaluated, as well as supplementary vulnerability information of the software to be evaluated on the open source platform; Performing a vulnerability scanning operation on the software file to obtain scanning vulnerability information of the software to be evaluated; The supplementary vulnerability information is added to the scanned vulnerability information to obtain the target vulnerability information.

7. A software selection device, characterized in that: include: An information acquisition module, configured to acquire software files and at least one type of basic software information of the software to be evaluated, and determine target vulnerability information present in the software to be evaluated; A software scoring module is used to evaluate the software to be evaluated based on the basic information of each software and the target vulnerability information to obtain a target score for the software to be evaluated; An evaluation and selection module is used to select the software to be evaluated according to the target score.

8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor. The computer program is executed by the at least one processor so that the at least one processor can execute the software selection method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the software selection method according to any one of claims 1 to 6 when executed.

10. A computer program product, characterized in that The computer program product comprises a computer program, which, when executed by a processor, implements the software selection method according to any one of claims 1 to 6.