Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1094 results about "Abstract syntax tree" patented technology

In computer science, an abstract syntax tree (AST), or just syntax tree, is a tree representation of the abstract syntactic structure of source code written in a programming language. Each node of the tree denotes a construct occurring in the source code.

Large model code security review method based on control flow analysis and retrieval enhancement

The invention relates to the technical field of code security analysis, and discloses a control flow analysis and retrieval enhancement-based large model code security review method, which comprises the following steps of: analyzing an incremental code to generate an abstract syntax tree and data flow analysis information; retrieving local knowledge base association business rules and historical vulnerabilities based on grammatical features, and generating a context enhancement prompt; calling a large language model to jointly analyze codes and contexts, identifying vulnerabilities and outputting a structured report; and combining with a historical false alarm data optimization result and then integrating to a development assembly line. Multi-source information is fused through an RAG technology to enhance semantic understanding, and control flow node tracking and cross-version semantic association are combined, so that the problems of a traditional tool business logic vulnerability detection blind area, incremental code analysis failure and high false alarm rate are solved, synchronous improvement of security examination accuracy and efficiency is realized, and the method is adaptive to an agile development scene.
Owner:HANGZHOU BAIHA YIBAI INFORMATION TECHNOLOGY CO LTD

Method for generating SQL (structured query language) from natural language based on bidirectional mapping and semantic analysis

The invention provides a method for generating an SQL (Structured Query Language) by a natural language based on bidirectional mapping and semantic parsing, which relates to the technical field of database query and comprises the following steps of: extracting natural language query elements and packaging the natural language query elements into structured data, and establishing a mapping relationship from a query field to a service attribute and a physical data table by adopting a bidirectional Hash index technology; and automatically identifying multi-table association keys, performing semantic extension and compliance verification, generating an abstract syntax tree, performing processing according to user permission, and finally converting the abstract syntax tree into an SQL statement conforming to a target database syntax specification. According to the method, the accuracy and the efficiency of converting the natural language into the SQL are improved, and the flexibility and the safety of the system are enhanced.
Owner:北京科杰科技有限公司

Cross-framework code migration method and system, electronic equipment and storage medium

PendingCN120447959AVersion controlProgram code adaptionCode migrationTight frame
The invention provides a cross-frame code migration method and system, electronic equipment and a storage medium, and the code migration method comprises the steps: carrying out the frame-level conversion of a first frame code, and generating a target engineering skeleton adaptive to a second frame protocol; analyzing the construction configuration and the entry file, determining an entry point and a compiling rule of code migration, analyzing the first frame code through an abstract syntax tree, and generating a target code range list needing to be migrated; and according to the target code range list and the dependency item list, applying a preset conversion rule to the first framework code, and generating a second framework code adaptive to a second framework protocol. Through automatic framework-level conversion and dynamic rule adaptation, rapid migration from the first framework code to the second framework code is realized, a multi-terminal code library is unified, the manpower development cost is reduced, synchronous operation of business iteration and migration is supported, and the development efficiency is improved.
Owner:SHANGHAI TRAVEL INFORMATION TECH CO LTD

Intelligent data acquisition and conversion method based on visual rule model

The invention discloses an intelligent data acquisition and conversion method based on a visual rule model, which comprises the following steps: S1, converting a configured rule chain into a data body in a JSON format by a visual rule modeling layer, analyzing the data body into an AST abstract syntax tree, and performing field mapping on the AST abstract syntax tree, the mapping fields are converted into executable codes through an intelligent conversion engine, and an execution plan is generated; s2, the intelligent acquisition layer pulls data from the heterogeneous data source, cleans the data and then allocates the data to an intelligent conversion engine for parallel processing; and S3, the intelligent conversion engine monitors the data consanguinity map and the field-level conversion path in real time, and sends a signal to the visual rule modeling layer or the intelligent acquisition layer according to the abnormal condition type so as to realize rule chain reconfiguration or data reacquisition. The method has the advantages that non-coding docking and real-time supervision of heterogeneous system data are realized, and the problems of dynamic adaptation, semantic understanding and data blood relationship interpretability in financial fund management are solved.
Owner:INST OF SCI & TECHN INFORMATION OF CHINA

Log quality detection method and system, electronic equipment and storage medium

The invention discloses a log quality detection method and system, electronic equipment and a storage medium. The method comprises the following steps: acquiring a multi-modal input source; performing reverse anchoring operation in a dynamic analysis stage of the running log to establish direct mapping between the running log and the source code; compiling the abstract syntax tree based on the source code, establishing a grammar dependence graph according to the abstract syntax tree, and traversing the abstract syntax tree to construct a structured data set; based on the running log, obtaining a quality detection result through structured analysis, and generating a semantic detection result by using a large language model; performing cooperative operation on the structured data set and the grammar dependency graph to generate a code log coverage score, and performing arrangement according to a quality detection result and a semantic detection result to obtain an abnormal mode feature; and performing feedback adjustment based on the code log coverage score and the abnormal mode feature in combination with a preset correction rule. The method can efficiently and accurately realize log quality detection, and can be widely applied to the technical field of data processing.
Owner:SUN YAT SEN UNIV

PHP taint type vulnerability detection method based on heterogeneous graph neural network

The invention discloses a PHP taint type vulnerability detection method based on a heterogeneous graph neural network, and belongs to the field of software security. The method comprises the following steps: performing annotation removal, variable naming standardization and character string standardization processing on a PHP source code through a code preprocessing module to generate a standardized code; based on a vulnerability sub-attribute graph extraction module, reversely tracking vulnerability sinks to a taint source, extracting a simplified vulnerability sub-attribute graph, and removing redundant nodes and edges; fusing BERT semantic features and node type features through a graph node embedding module to generate an initial embedding vector, and constructing a heterogeneous graph comprising an abstract syntax tree edge, a program flow graph edge and a control dependence graph edge; a heterogeneous graph neural network vulnerability detection module is adopted to perform independent feature aggregation on multiple types of edges, dynamic weighted fusion is performed in combination with an attention mechanism, and key nodes are screened through Top-k graph pooling; and finally, inputting the graph-level features into a classifier to realize vulnerability detection.
Owner:YANSHAN UNIV

Distributed storage method based on source code semantic partitioning

The invention provides a distributed storage method based on source code semantic partitioning, and particularly relates to the technical field of cloud data distributed storage. The method comprises the steps of performing semantic partitioning on a source code, and segmenting the source code into a plurality of semantic blocks according to dimensions such as functional semantics, an abstract syntax tree structure, author information and version information; generating metadata containing information such as grammar type tags, file paths, line number ranges, author identifiers, version identifiers and access popularity for each semantic block; constructing a weighted directed acyclic graph (DAG) based on the semantic chunks and the dependency relationship thereof; superposing a metadata layer in the DAG structure, and recording information such as function call dependency, inter-block reference relationship and version evolution chain; blocks with relatively high access frequency and close semantics are aggregated into super blocks, the traversal depth is reduced, and meanwhile, hot data and cold data are differentiated for hierarchical storage by adopting a cold and hot data management strategy; and evaluating a parent block aggregation degree through a BDS algorithm, determining a block sorting priority, and optimizing super block boundary division. Compared with the prior art, the method has the advantages that the semantic retrieval efficiency, the incremental updating capability and the distributed query performance of the source code storage system are improved.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Multi-mode fusion product document and source code association retrieval method based on knowledge graph

The invention discloses a multi-mode fusion product document and source code association retrieval method based on a knowledge graph, and relates to the technical field of software engineering and artificial intelligence. The method comprises the steps that source codes are preprocessed, and code structure information and business semantics are mapped in combination with a predefined business term dictionary; performing controlled induction on a code file and a product document by utilizing a large model, extracting business terms, logic intentions and a subject relationship, fusing with original codes, and establishing a vector retrieval index system; further analyzing a code structure by using an abstract syntax tree, and extracting an entity and a calling relationship; semantic enhancement and relation normalization are performed in combination with the large model, entities and relations are stored in a graph database, and a knowledge graph is formed; and performing parallel processing on user query based on a full-text retrieval index, a vector retrieval index system and a knowledge graph, and finally generating a product concept. According to the method, the retrieval speed, the semantic depth and the logical reasoning ability can be considered at the same time, and the retrieval accuracy is improved.
Owner:MARCO POLO TRAVEL TECH CO LTD

Prompt word compiling and generating method and system for large language model

The invention relates to the technical field of artificial intelligence and natural language processing, in particular to a cue word compiling and generating method and system for a large language model.The method comprises the steps that in response to a compiling calling request, a PDL protocol is received to serve as a compiling input text; performing lexical and grammatical analysis on the compiled input text, and constructing a corresponding abstract syntax tree AST as an intermediate representation according to a context-independent method; semantic verification and structure correction are carried out on the AST, and when semantics are effective, structure optimization is carried out to generate an optimized AST; and traversing the optimized AST, matching a cue word template in a cue word generation rule base, mapping semantic nodes into structured text fragments, splicing the structured text fragments to form a final cue word text, and outputting a compilation result consistent with PDL protocol semantics. By introducing a PDL-oriented compiling mechanism, automatic analysis, structure optimization and high-quality cue word generation of an input protocol are realized before cue words of a large language model are generated, and the development efficiency and the output quality of the cue words are improved.
Owner:BEIJING WENYIN INTERNET TECH CO LTD

Dynamic and static combined detection method for security vulnerabilities of power system software

The invention is applicable to the technical field of vulnerability detection, and provides a power system software security vulnerability dynamic and static combined detection method, which comprises the following steps: acquiring static source code data of power system software and dynamic behavior log data during operation; generating a hierarchical abstract syntax tree and structured time series data; performing multi-dimensional feature extraction on the static source code data and the dynamic behavior log data based on a vulnerability knowledge graph of the power system; generating a domain constraint confrontation sample based on the power protocol features and the abnormal features during operation, and inputting the domain constraint confrontation sample into the constructed hybrid detection model for confrontation training to obtain a trained hybrid detection model; and performing automatic detection on the power system software by utilizing the trained hybrid detection model, and outputting a detection result containing a static code defect position and a dynamic attack path. The full-life-cycle accurate detection of the software vulnerability of the power system is realized, and the network security protection capability of the power system is improved.
Owner:GUANGXI POWER GRID CORP

Semantic-based migration and consistency verification method, system and equipment and medium

The invention provides a semantic-based migration and consistency verification method, system and device and a medium, and relates to the technical field of databases. The method comprises the following steps: performing metadata topology scanning analysis by obtaining metadata, including generating an abstract syntax tree and constructing a semantic graph; according to a metadata topology scanning analysis result, performing data mapping and conversion, including loading a YAML rule and generating corresponding type mapping and constraint conversion; data migration is carried out through primary key fragmentation parallel migration, batch writing optimization and real-time double-writing verification; through structure-data-business three-layer verification, simulation business SQL comparison and automatic difference repair, the integrity of migrated data and business compliance are ensured, the semantic gap problem in heterogeneous database migration is solved, high-precision and high-efficiency database migration is realized, the migration efficiency is improved, and the data migration efficiency is improved. The method is suitable for scenes with strict requirements on data consistency and migration efficiency, such as financial, government affair and enterprise-level data centers.
Owner:CHINA YANGTZE POWER

Method for realizing SQL grammar conversion of different databases based on middleware and middleware

The invention discloses a method for realizing SQL (Structured Query Language) grammar conversion of different databases based on middleware and the middleware, belongs to the technical field of databases, and aims to solve the technical problem of how to realize SQL grammar conversion of different databases through the middleware. The following operations are executed through the middleware to realize the grammar conversion of the SQL between the source database and the target data constructing an abstract syntax tree AST by taking various SQL elements as nodes; operating nodes in the AST on the basis of requirements of a target database; based on the data type in the target database, performing data type mapping by applying a data type conversion rule, and generating an SQL statement adapted to the target database; performing security check on the generated SQL statement; caching the query result and the generated SQL statement based on a caching mechanism; and recording the conversion process and query processing of the SQL statement.
Owner:INSPUR ZHUOSHU BIG DATA IND DEV CO LTD

Security code automatic generation method and system based on full information theory and mechanism ambiguity

The invention provides a security code automatic generation method and system based on a full information theory and mechanism ambiguity, and the method comprises the steps: S1, carrying out the feature extraction of a grammar verification layer of an input demand, extracting the grammar features of a code through the topological features of an abstract syntax tree, and carrying out the formalized rule verification of the extracted grammar features; s2, constructing a semantic association model of a cross-code snippet through a semantic analysis layer, and forming a propagation path for tracking a data flow and a control flow; s3, in the pragmatic optimization layer, combining pragmatic constraints of the business scene, and generating a security policy through a dynamic utility function; and step S4, optimizing parameters and security policies of the dynamic utility function through knowledge federal evolution and a closed-loop feedback mechanism. According to the method, a deep collaboration mechanism of grammar, semantic and pragmatic three-dimensional information and a dynamic strategy generation model are reconstructed, security logic is converted from external attributes to endogenous cognitive competence, and the security, interpretability and adaptability of automatic code generation are improved.
Owner:SHENZHEN CESTBON TECH CO

Systems and methods for iterative feedback-driven code synthesis using syntax trees and large language models

PendingUS20250306882A1Code compilationSource to sourceCode synthesisObject code
A system for translating source code in a first programming language to a target language is provided. The system is configured to receive source code for converting to target code; determine an abstract syntax tree from the source code; determine program specifications from the source code; determine a dependency graph from the source code; determine a plurality of chunks based at least in part on the abstract syntax tree, the program specifications, and the dependency graph; determine a plurality of converted chunks based at least in part on the plurality of chunks and a deep learning model, the deep learning model converting the plurality of chunks from the language of the source code to the language of the target code; post-process the plurality of converted chunks to obtain intermediate code; and provide the intermediate code as the target code.
Owner:UST GLOBAL INC

Cross-chain smart contract vulnerability detection method and system based on multi-feature fusion learning

The invention discloses a cross-chain smart contract vulnerability detection method and system based on multi-feature fusion learning. The method comprises the following steps: collecting a cross-chain smart contract vulnerability data set for cleaning and labeling; feature extraction is carried out from the source code and the byte code, an abstract syntax tree (AST) is extracted from the cleaned source code, a basic control flow graph (CFG) is extracted from the byte code, and a cross-chain control flow graph (xCFG) is constructed; carrying out feature representation on AST and xCFG, generating a graph vector through a graph neural network (GNN), generating a semantic vector through CodeBert, and fusing the semantic vector into a feature fusion vector; performing model training and detection, taking the generated vectors as training data and test data, obtaining a cross-chain smart contract vulnerability detection model by adopting Transform-FC model training data, and finally evaluating model performance through accuracy, recall rate, precision rate and F1 value. According to the method, the structural features and semantic features of the codes can be effectively fused, potential vulnerability information in the codes can be fully mined, the recognition capability of the model for cross-chain vulnerabilities can be enhanced, and the accuracy and reliability of the cross-chain vulnerability detection model can be improved, so that the security of a block chain system can be more efficiently guaranteed.
Owner:HOHAI UNIV

Intelligent contract vulnerability detection method based on heterogeneous graph attention network

The invention discloses an intelligent contract vulnerability detection method based on a heterogeneous graph attention network. According to the method, firstly, the source code of the intelligent contract is preprocessed, the SCIR of the code of the intelligent contract is constructed, the complexity of the code of the contract is reduced, and vulnerability features are enriched; and constructing an intelligent contract code attribute graph SCPG based on SCIR, integrating various code graph structures such as an abstract syntax tree and a control flow graph, and comprehensively describing syntax and semantic features of the contract. And then constructing an intelligent contract code heterogeneous graph SCHG on the basis of the SCPG, optimizing code graph structure representation, and realizing high-quality modeling of node features. And finally, detecting the vulnerability of the smart contract by using a customized multi-layer heterogeneous graph attention network model MHGAN. The intelligent contract vulnerability detection method based on deep learning makes up for the defects of an existing intelligent contract vulnerability detection method based on deep learning, effectively improves the accuracy of intelligent contract vulnerability detection, and is excellent in the interpretability of the detection result.
Owner:HANGZHOU DIANZI UNIV

Code reconstruction method, system and equipment based on function identification and medium

The invention discloses a code reconstruction method, system and device based on function recognition and a medium, and the method specifically comprises the steps: scanning a project file topological structure, and constructing a knowledge graph based on a code import relation and a technology stack feature; performing context enhancement by analyzing the code function description and combining with the knowledge graph to generate a code modification instruction set; based on the code modification instruction set, in combination with data stream sensitivity marking and performance portrait analysis, evaluating the target code to obtain an evaluation result; based on an evaluation result, matching a historical optimal practice mode through a graph neural network, and generating an optimization scheme which retains an original design style; by comparing abstract syntax tree differences between original codes and verified optimization schemes, only functional logic nodes are replaced, and legal code style features are reserved. According to the method, the efficiency and quality of code reconstruction and optimization are improved, and a more convenient, efficient and intelligent code processing tool is provided for software developers.
Owner:广州三七极耀网络科技有限公司

Intelligent Bug management method and platform based on AI large model

The invention discloses an intelligent Bug management method and platform based on an AI large model. The method comprises the steps that structured error codes, unstructured log texts and development communication records are collected; standardized Bug features are obtained after preprocessing; semantic matching is performed based on a CodeBERT large model to generate a historical similar Bug case set, and a problem code segment is analyzed and positioned in combination with an AST abstract syntax tree; according to the project technology stack features, the historical similar Bug case set and the problem code segment, generating a repair scheme including code modification suggestions, automatically generated repair code snippets and implementation risk assessment; constructing and optimizing a triple knowledge graph; and finally, associating the standardized Bug features, the problem code segment, the repair scheme and the knowledge graph to obtain a Bug diagnosis result, and outputting the Bug diagnosis result. According to the method, intelligent positioning and accurate repairing of the Bug are achieved, the average Bug solving time is remarkably shortened, and meanwhile automatic precipitation of development experience is achieved through the continuously optimized knowledge graph.
Owner:FUJIAN HEALTH ROAD HEALTH TECHNOLOGY CO LTD

Method and system for building compilable customized module

Disclosed in the present invention are a method and system for building a compilable customized module. The method comprises: customizing a module on the basis of a process, defining a modeling language syntax, and generating a modeling language file corresponding to the customized module; establishing a text matching rule and a grammar matching rule, using flex to generate a source program file of a lexical analyzer from the text matching rule, and using bison to generate a source program file of a syntax analyzer from the grammar matching rule; performing lexical analysis and generating an abstract syntax tree; traversing the syntax tree, generating a translation C++ file for a modeling language on the basis of a syntax-based translation configuration file, and compiling the translation C++ file; and importing the built customized module and an executable binary file into a simulation platform, and performing flow simulations for different scenarios including process simulation, optimization and parameter tuning. The present invention can realize the rapid commissioning of a process and can seamlessly switch a customized model to various application scenarios.
Owner:SUPCON TECH CO LTD

Private intelligent code collaborative optimization method and system based on graph retrieval

The invention provides a private intelligent code collaborative optimization method and system based on graph retrieval, and relates to the technical field of software engineering intelligent auxiliary tools, and the method comprises the steps: obtaining a source code file and operation log data of a private project; the method comprises the following steps: performing syntax tree analysis on a source code file through a Tree-siter analyzer to generate a corresponding abstract syntax tree; constructing a code knowledge graph by analyzing a function call relationship, an inheritance relationship and a module dependency relationship; monitoring the change of a project file in the code knowledge graph through a code change event processor, and updating the code knowledge graph in real time when the file is changed; establishing an association relationship between the running log data and a corresponding function node in the code knowledge graph; the method comprises the following steps: analyzing a natural language problem of a developer into a Cypher query statement through an intelligent Agent; obtaining a query result from the graph database; and formatting the query result to generate a final result.
Owner:QINGTA TECH

File uploading attack interception method based on semantic entropy enhancement

The invention provides a file uploading attack interception method based on semantic entropy enhancement, and aims at overcoming the defects of an existing file uploading security protection technology in the face of complex attacks. The method specifically comprises the steps that S1, file format analysis and content extraction are conducted, hidden scripts are mined through nested content recognition, and intermediate representation is generated through grammar cleaning and coding specifications; s2, constructing an abstract syntax tree and semantic entropy calculation, tracking a pollution chain, analyzing a high-risk function, identifying a high-entropy character string, modeling and controlling flow complexity, and generating a semantic entropy vector; s3, dynamic scoring and decision making are carried out, and accurate judgment is carried out in combination with white list perception, feature comparison, multi-modal model scoring, adaptive threshold and sandbox observation; and S4, carrying out real-time interception and feature synchronization, blocking malicious file landing, generating an attack log and synchronizing an attack fingerprint. The method takes the semantic entropy vector as a core, breaks through the limitation of static features, remarkably improves the recognition rate of complex attacks, reduces missed judgment, and guarantees the safety of Web applications.
Owner:CHINA LIFE INSURANCE CO LTD

SQL (Structured Query Language) statement optimization suggestion generation method and device, medium and electronic equipment

The invention provides an SQL statement optimization suggestion generation method and device, a medium and electronic equipment, and is applied to the technical field of artificial intelligence. The method comprises the following steps: acquiring SQL log monitoring data, including an execution timestamp and a time consumption value of an SQL statement, dividing the data according to a preset time window, and constructing a to-be-processed data set; a median approximation algorithm is used for calculating the median of SQL execution time consumption, and then abnormal SQL statements in the running log are screened out. And for each abnormal SQL, reconstructing an execution context thereof, obtaining an abstract syntax tree and an execution plan, and substituting the abstract syntax tree and the execution plan into a preset cue word template to generate cue words. And finally, calling a large model to analyze the cue word so as to obtain an optimization suggestion for the abnormal SQL. By collecting and analyzing the SQL logs and combining the median algorithm and the large model technology, efficient SQL statement optimization is achieved.
Owner:CAIXIN SECURITIES CO LTD

Vulnerability repair rule generation method based on AI and related equipment

The invention discloses an AI-based vulnerability repair rule generation method and related equipment, and relates to the field of electric digital data processing. A computer device performs double analysis on a vulnerability code snippet and a vulnerability description text through a large language model, constructs double representation of an abstract syntax tree and a semantic graph, and performs cross-modal alignment on the semantic graph and the abstract syntax tree to obtain a vulnerability context relationship matrix. And the computer device traverses the abstract syntax tree, extracts vulnerability code feature vectors, and determines a plurality of repair modes according to vulnerability type identifiers. And the computer equipment calculates the similarity between the vulnerability code feature vector and a plurality of context constraint conditions, screens a target repair mode, performs feasibility verification on the target repair mode based on the vulnerability context relation matrix, and determines an optimal repair mode, thereby generating a repair rule. The double analysis and cross-modal alignment mode greatly improves the accuracy and reliability of vulnerability repair rule generation.
Owner:HANGZHOU XIAODAO TECH CO LTD

Script preservation method, device, equipment, medium and program product

The invention provides a script preservation method which can be applied to the technical field of artificial intelligence. The script preservation method comprises the following steps: carrying out semantic understanding on demand related files by utilizing a large model, extracting core elements, and generating a structured demand change list; analyzing to obtain an abstract syntax tree of an existing script code, and constructing a mapping relationship between the software automation test element and a script code block; dynamically comparing the structured demand change list with an existing script code structure tree based on a mapping relation between software automation test elements and script code blocks, identifying a script range influenced by demand change, and outputting a change influence matrix; and based on the change influence matrix, generating an automatic script code snippet needing to be updated, and realizing preservation of the automatic script. The invention further provides a script preservation device and equipment, a storage medium and a program product.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Multi-source field-level blood relationship tracking method and system

The invention discloses a multi-source field-level blood relationship tracking method and system. The method comprises the following steps: extracting features from a multi-source heterogeneous system, matching templates, triggering a corresponding acquisition strategy, and outputting an original blood relationship log; reading an original blood relationship log to generate an abstract syntax tree, extracting a source / target field set to output a field-level mapping relation, further writing the field-level mapping relation into a graph database to form a blood relationship edge, writing metadata into a relational database, establishing a two-level index, and outputting a blood relationship graph capable of being quickly positioned; and taking the blood relationship map as input, returning a target path with the maximum sum of confidence coefficients by adopting a weighted shortest path algorithm, outputting a link-level traceability result, and displaying the link-level traceability result. According to the method, complete tracking of the field-level blood relationship is realized, the query response time is shortened to a millisecond level, rapid access to multiple types of data sources is supported, and the problems of insufficient blood relationship analysis precision, low query efficiency and weak multi-source adaptability in the prior art are solved.
Owner:SHANGHAI QUZHI NETWORK TECH CO LTD

Code vulnerability detection method, device and equipment

The invention discloses a code vulnerability detection method, a code vulnerability rule configuration method, a static single assignment SSA code acquisition method, devices corresponding to the methods, and electronic equipment. The code vulnerability detection method comprises the following steps: acquiring a plurality of source code files and code vulnerability rules of an application program; generating an abstract syntax tree of the source code file, and obtaining a function call relationship; and traversing the abstract syntax tree, and obtaining a cross-function risk propagation path according to the function call relationship and the code vulnerability rule. By the adoption of the processing mode, the function calling relation and the abstract syntax tree are fused to conduct cross-function code vulnerability detection, cross-function vulnerability detection of context sensitivity, flow sensitivity and domain sensitivity is achieved, and vulnerability false report and missing report are avoided; therefore, the accuracy and recall rate of vulnerability detection can be effectively improved.
Owner:ALIBABA (CHINA) CO LTD

System for assisting to transplant Android language to ArkTS (Arkaus) language of swan Mongolia

The invention relates to the technical field of computer software engineering and cross-platform development, in particular to a system for assisting in transplanting Android language to ArkTS (ArkTS) of the swan Mongolia, which comprises a code input module for acquiring Java and Kotlin double-language source codes, an analysis module for analyzing codes by using an improved grammar analysis algorithm, and a storage module for storing the codes. The translation module constructs an abstract syntax tree based on an analysis result and generates an attribute description array, and the generation module generates an ArkTS interface code according to the attribute description array; the distributed computing architecture realizes efficient task scheduling and processing, and the post-processing optimization module guarantees the code quality. Through multi-module cooperation, the probability-rule fusion algorithm, the type dynamic mapping and other technologies, code transplantation can be rapidly and accurately completed, the large project transplantation period is shortened from several weeks to several days, the manual correction cost is reduced, the code conversion accuracy and the system stability are improved, and the development of the wide-gap application ecology is powerfully promoted.
Owner:XIAMEN BEST DIGITAL TECH CO LTD

Validating code generated by artificial intelligence using abstract syntax trees

Validating code generated by artificial intelligence using abstract syntax trees includes generating, by an artificial intelligence (AI) language model, output source code based on input source code; determining an equivalency mapping between a first abstract syntax tree (AST) constructed for the input source code and a second AST constructed for the output source code; and indicating, based on the equivalency mapping, a validation result for the output source code.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Fragmented storage and query optimization method and system for high-concurrency database

The invention belongs to the field of query optimization, and particularly relates to a fragmentation storage and query optimization method and system for a high-concurrency database, and the method comprises the steps: analyzing business features through a preset decision tree model, and selecting an optimal fragmentation key, constructing a fragmentation rule engine and initializing a database in combination with hash, range and list fragmentation rules and a fragmentation splitting-merging strategy; generating a query abstract syntax tree by using an ANTLR4 analyzer, and detecting whether a preset Cube is hit or not to directly return a result; if not, dynamically routing to a target fragment list based on a fragment key field, load balancing and a failover strategy, accelerating data retrieval in combination with a high-frequency index, and combining fragment-level results through a T-TopK algorithm; according to the method, the self-adaptive matching of the fragmentation strategy and the service requirement, the calculation push-down of the query process and the result optimization are realized, and the low delay and the high availability in a high-concurrency scene are ensured.
Owner:JIANGSU LINGHAO NETWORK TECH CO LTD

Code quality adaptive evaluation and optimization method, system, equipment and medium

The invention provides a code quality adaptive evaluation and optimization method, system and device and a medium, and belongs to the technical field of computers. The method comprises the following steps: performing redundant information cleaning and standardization processing on an original code; selecting an adaptive parser to convert the processed code into an abstract syntax tree, and optimizing the abstract syntax tree; performing embedding processing on each node of the abstract syntax tree by using a pre-trained deep learning model to generate a node semantic vector, and performing aggregation, feature extraction and vector normalization operation to obtain a semantic vector representing code semantic features; extracting a dependency relationship from the abstract syntax tree to construct a program dependency graph, extracting node features by using a neural network model, and generating a dependency relationship analysis result; based on the semantic vector and the dependency analysis result, identifying a code potential problem by using an optimization algorithm and generating an optimization suggestion; codes are automatically modified according to optimization suggestions, the optimization effect is re-evaluated, and related models and algorithms are iteratively optimized according to feedback information.
Owner:浪潮智慧科技有限公司 +2