Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

517 results about "Bytecode" patented technology

Bytecode, also termed portable code or p-code, is a form of instruction set designed for efficient execution by a software interpreter. Unlike human-readable source code, bytecodes are compact numeric codes, constants, and references (normally numeric addresses) that encode the result of compiler parsing and performing semantic analysis of things like type, scope, and nesting depths of program objects.

Cross-chain smart contract vulnerability detection method and system based on multi-feature fusion learning

The invention discloses a cross-chain smart contract vulnerability detection method and system based on multi-feature fusion learning. The method comprises the following steps: collecting a cross-chain smart contract vulnerability data set for cleaning and labeling; feature extraction is carried out from the source code and the byte code, an abstract syntax tree (AST) is extracted from the cleaned source code, a basic control flow graph (CFG) is extracted from the byte code, and a cross-chain control flow graph (xCFG) is constructed; carrying out feature representation on AST and xCFG, generating a graph vector through a graph neural network (GNN), generating a semantic vector through CodeBert, and fusing the semantic vector into a feature fusion vector; performing model training and detection, taking the generated vectors as training data and test data, obtaining a cross-chain smart contract vulnerability detection model by adopting Transform-FC model training data, and finally evaluating model performance through accuracy, recall rate, precision rate and F1 value. According to the method, the structural features and semantic features of the codes can be effectively fused, potential vulnerability information in the codes can be fully mined, the recognition capability of the model for cross-chain vulnerabilities can be enhanced, and the accuracy and reliability of the cross-chain vulnerability detection model can be improved, so that the security of a block chain system can be more efficiently guaranteed.
Owner:HOHAI UNIV

Intrusion prevention method, management unit, system and storage medium

PendingCN120238322ASecuring communicationLinux Security ModulesManagement unit
The invention provides an intrusion prevention method, a management unit, a system and a storage medium, and relates to the field of network security, and the method comprises the steps: collecting context operation data corresponding to a to-be-tracked asset object in a kernel, and carrying out the security management of the context operation data, and obtaining a first target security control strategy corresponding to the to-be-tracked asset object; and mounting a first target BPF byte code corresponding to the first target security control strategy in a Linux security module so as to monitor and defend the target asset object through the Linux security module. Or in response to the security policy configuration request, extracting a second target security control policy from the security policy configuration request; and when the second target security control strategy is activated, mounting a second target BPF byte code corresponding to the second target security control strategy in the Linux security module. Therefore, through the above intrusion prevention method, the embodiment of the invention can immediately block attacks and improve the convenience of maintenance and deployment.
Owner:ZTE CORP

Adaptive dependency replay system for ad serving backends

An adaptive dependency replay control system for use in a latency-sensitive ad serving backend, comprising: a microcontroller-based replay control engine configured to receive ad serving requests and interface with a variety of downstream microservices; a latency monitoring unit operatively coupled to the microcontroller, the latency monitoring unit continuously sampling and maintaining real-time latency histograms for each downstream microservice over sliding time windows; a health status aggregator communicatively coupled to the retry control engine, the aggregator configured to receive service-level health indicators, including, but not limited to, HTTP status codes, circuit breaker states, request timeout counters, and error rate thresholds; a retry decision processing unit stored in a memory accessible to the microcontroller, wherein the matrix can generate a retry action vector based on one or more of the following factors: dependency health, request priority, estimated ad impression value, and system resource metrics; a policy execution engine configured to evaluate retry policies expressed in a domain-specific retry policy language, wherein the execution engine resolves the policies into bytecode rules that are executed by the retry control engine in real time on a per-request basis; and at least one fallback path generator capable of returning an approximate or synthetic response instead of retrying a degraded dependency, where the fallback path is selected based on runtime evaluation of the policy conditions and a calculated retry confidence value.
Owner:BOJANAPALLI RAGHU RAM CUMMING +2

Visual track tracing method and system for risk checking task

The invention relates to the field of risk data visual tracing, and provides a visual track tracing method and system for a risk checking task, and the method comprises the steps: analyzing a heterogeneous data stream, separating a source metadata set, calculating an original structure entropy fingerprint, intercepting an end feature, embedding a global tracking identifier, and generating a packaging data package; generating transformed service data by using dynamic byte code instrumentation, constructing a runtime execution context and a differential snapshot, and transmitting an instantiated track node object according to a shunt delivery strategy; mapping and instantiating the logical topology execution graph based on the Hash fragments, and marking a pollution state and generating a total element execution link graph when the logic topology execution graph is abnormal; the method comprises the steps of generating a topology summary data packet, rendering a real-time state view, responding to physical interaction operation to construct a retrieval request data packet, reconstructing a full-amount service load through topology backtracking and reverse data evolution, and generating an attribution view in combination with static codes and rule description. According to the method, a dynamic trajectory tracing and full-link risk visualization mechanism of massive heterogeneous data is constructed.
Owner:NANJING XUANCE INTELLIGENT TECH CO LTD +1

Cross-language application program vulnerability mining method based on static analysis

The invention discloses a cross-language application program vulnerability mining method based on static analysis, which adopts a nested cross-programming language pointer analysis method and a micro-service cross-programming language taint tracking method to effectively solve the limitation of processing nested cross-language control flow and micro-service cross-language data flow. A nested language semantic boundary is accurately positioned by constructing a nested byte code, and a data stream is completely tracked by utilizing an interface relay technology, so that the detection precision is improved. According to the method, part of multi-end data streams and complex control streams of cross-programming language applications can be uniformly processed, and the analysis process in a cross-programming language environment is simplified; by nesting cross-programming language control flow diagram construction and double-end / multi-end data flow diagram construction, a unified analysis framework is constructed, seamless cooperation of static analysis among different languages is achieved, the analysis cost is reduced, the analysis efficiency is improved, efficient and accurate vulnerability mining is achieved in a complex cross-programming language application program, and the method is suitable for application and popularization. And the reliability of cross-language vulnerability detection is improved.
Owner:XIDIAN UNIV

Server-free dynamic management and control method based on extended Berkley packet filter

The invention provides a server-free dynamic management and control method based on an extended Burkley packet filter, and the method comprises the steps: mounting an eBPF program to a kernel cgroup subsystem, monitoring a function instance creation / destruction event in real time, extracting metadata, dynamically generating a fine-grained network strategy, compiling the fine-grained network strategy into an eBPF byte code, and injecting the eBPF byte code into a Map format strategy table, realizing data packet level allowing / discarding control by using a flow control hook; and when the instance is destroyed, the strategy table rule is automatically cleared through a cgroprease event. Through kernel-level dynamic management and control, precise security protection, zero-trust micro-isolation and kernel layer malicious behavior interception of the function instance in the full life cycle are realized, and the security efficiency and the resource utilization rate of the cloud native environment are remarkably improved.
Owner:BEIJING PACTERA JINXIN TECH LTD

Intelligent contract vulnerability detection method based on multi-mode selection state space fusion

The invention relates to the technical field of electrical digital data processing, in particular to an intelligent contract vulnerability detection method based on multi-modal selection state space fusion, and aims to solve the technical problem of low vulnerability detection accuracy in the prior art. The method comprises the following steps: firstly, fusing global and local features of a contract graph to obtain graph modal embedding features; performing feature alignment on the text context information of the intermediate representation text and the byte code text to obtain text modal embedding features; extracting spatial layout features from the color image and the grayscale image, and splicing the spatial layout features to obtain visual modal embedding features; thirdly, performing multiple rounds of feature cross processing on the graph modal embedding features, the text modal embedding features and the visual modal embedding features based on a selection state space to realize intra-modal and inter-modal information interaction, and then performing fusion to obtain multi-modal fusion features; and finally, performing feature normalization and regularization processing on the multi-modal fusion features, and performing classification processing to obtain a vulnerability detection result.
Owner:YANTAI UNIV

Data operation method of model and related device

The invention relates to a data operation method of a model, which is applied to the operation of an artificial intelligence (AI) model. In the method, based on an input tensor of an operation in an AI model during actual operation, a calculation graph corresponding to the operation in the AI model is compiled into a byte code instruction, and then the byte code instruction is interpreted and operated through a virtual machine which is pre-configured with a corresponding processing function, so that the operation in the AI model is executed. The execution of a traditional tedious compiling process is effectively avoided, and the running time of the AI model is shortened.
Owner:HUAWEI TECH CO LTD

AOP-based user behavior data acquisition method

The invention relates to the technical field of data acquisition, in particular to an AOP-based user behavior data acquisition method. The method comprises the following steps: firstly, identifying user behavior related code features by statically analyzing Java source codes of an application program, and constructing a feature template library; during a compiling period, according to a template library identification target method, embedding a point burying instruction by utilizing a byte code enhancement technology, and constructing a monitoring section framework; and during running, dynamically adjusting an execution strategy according to the running state of the application program by virtue of a dynamic rule engine. Meanwhile, an annular buffer area is adopted to asynchronously process user behavior data streams, cache data are managed in a sub-generation mode, and asynchronous processing is triggered when a threshold value is exceeded. The method also constructs an adaptive thread pool model based on a hierarchical thread pool architecture, distributes tasks according to data value weights, monitors the task backlog rate of a high-priority sub-pool, adjusts the sampling frequency or acquisition dimension when the task backlog rate exceeds a threshold value, forms adaptive closed-loop control, and effectively acquires and processes user behavior data.
Owner:STATE GRID FUJIAN ELECTRIC POWER CO LTD

Heterogeneous network services using platform-agnostic extensions

ActiveUS20250317350A1TransmissionData packPathPing
Disclosed are systems, apparatuses, methods, and computer-readable media for heterogenous network services using platform agnostic extensions. A method includes: instantiating a first service having a first data plane control point; instantiating a second service configured to access the first control point in a data plane; receiving a first packet at the first service in a network path; providing at least one of the first packet and first metadata associated with the first packet to the second service to analyze or process the first packet and the first metadata in conjunction with the first service; processing at least one of the first packet or the first metadata in the second service based on external bytecode and generating at least second metadata based on the processing; receiving second metadata to the first service; and processing the first packet or a second packet.
Owner:CISCO TECHNOLOGY INC

Mock platform construction method for travel saas platform

The invention provides a mock platform construction method oriented to a travel saas platform. The mock platform construction method comprises the following steps: demand analysis: determining a target and a demand of a Mock platform; environment preparation: ensuring that the Java environment of the target SaaS platform meets the operation of the java byte code instrumentation technology; integration of a java byte code instrumentation technology: the java byte code instrumentation technology is integrated into an SaaS platform; according to the invention, a Java byte code instrumentation technology is utilized to construct a software as a service (SaaS) platform interface Mock platform which is powerful in function, flexible and easy to use, and the Mock platform can dynamically perform Mock on the interface of the SaaS platform without restarting an application, so that the development and test efficiency is greatly improved, and the development cost is reduced. And the Mock platform also has the characteristics of non-invasiveness, dynamic plugging, class isolation, flexible AOP support, self-definition, real-time monitoring and fault simulation, easiness in integration and use, safety, fault positioning and performance optimization.
Owner:BEIJING BAIJU YIXING TECH CO LTD

Intelligent processing method for single insurance policy based on neural network and machine learning

The invention provides an intelligent solitary policy processing method based on a neural network and machine learning, and relates to the field of data processing. According to the method, strategy byte codes and execution contexts are generated by extracting business rules, supervision calibers and field dependency relationships of the single insurance policy, discovery, repair and arbitration of field abnormity are achieved in combination with a dynamic data governance model, an account-falling confirmation receipt is output through a voting game and a compensation transaction, and a replayable trace and a rare mode index are generated. And a high-confidence label and an error correction prior increment are obtained in combination with triggering verification, and finally, full-link evidence is solidified through continuous distillation, chain type evidence storage and an auditable snapshot library, so that a traceable record of the single insurance policy is formed. By implementing the technical scheme provided by the invention, full-link data processing can be conveniently carried out on the single insurance policy, so that the processing efficiency is effectively improved.
Owner:CHINA LIFE INSURANCE CO LTD HUBEI BRANCH

Software monitoring method, system and equipment based on byte code replacement and risk perception and medium

The invention provides a software monitoring method, system and device based on byte code replacement and risk awareness and a medium, and belongs to the technical field of software security. The method comprises the steps that a special annotation mark in a source code is scanned, a test code entry point is recognized, and metadata information is extracted; performing encryption processing on the metadata and generating a registry file with a digital signature; environment safety data are collected through four monitoring dimensions, and a comprehensive risk score is calculated; generating a grading fusing instruction according to the score; and finally executing the fusing operation of byte code replacement or thread sandbox isolation. According to the invention, accurate identification and real-time protection of the leakage risk of the test code are realized; through a multi-dimensional monitoring and hierarchical fusing mechanism, the system security is ensured, and the influence on the service performance is minimized; and byte code replacement and thread isolation technologies are adopted, so that security protection can be realized without restarting the application, and the availability and the operation and maintenance efficiency of the system are improved.
Owner:SHANDONG ARTAPLAY INTELLIGENT TECH CO LTD

Link tracking monitoring method, system and device and computer readable storage medium

The invention discloses a link tracking monitoring method, system and device and a computer readable storage medium, and relates to the technical field of communication, the method tracks a link needing to be tracked through a preset link tracking model, unnecessary byte code injection, interception and excessive tracking data are prevented from being generated, and the link tracking monitoring efficiency is improved. The influence on a network, a CPU (Central Processing Unit), a memory and the like caused by transmission, analysis and storage of the tracking data is avoided, the relation among the invasion degree of the existing code, the link tracking granularity and the performance overhead is balanced, and the influence on the existing service performance and the concurrent processing capability is avoided; a byte code enhancement technology is adopted to enhance original service processing logic, enforcement coding and decoding byte codes are injected, execution calling information of a specified link (function / method) is intercepted, enhanced, recorded and sent, zero invasion and zero development are carried out on existing service codes, and tracking of the full-link calling process of an application layer data protocol HTTP / RPC and a transmission layer protocol UDP is achieved.
Owner:CHENGDU CORESAT TECH CO LTD

Real-time anti-fraud transaction intelligent analysis system and method based on multi-chain cooperation

The invention discloses a real-time anti-fraud transaction intelligent analysis system and method based on multi-chain collaboration, and the system comprises a dynamic federated learning module which is used for dynamically loading and updating a global model during the operation of a JVM (Java Virtual Machine) by adopting a Java Agent bytecode enhancement technology; the multi-chain collaborative verification engine comprises an alliance chain and a private chain, the alliance chain is formed by taking a plurality of banks as organization nodes and is used for distributed evidence storage of transaction characteristics among financial institutions, and the private chain is maintained by a supervision mechanism and is used for auditing and compliance verification; and the real-time stream processing pipeline processes the transaction request in a stream processing mode to obtain feature data, and makes a decision based on the feature data and the global model output by the dynamic federation learning module. The intelligent risk control system which supports cross-mechanism collaboration, privacy protection, high throughput and low delay is constructed, and the problems that in the prior art, model updating is lagged, a verification mechanism is not transparent, and processing delay is high are solved.
Owner:WUHAN ZBANK CO LTD

Incremental code coverage rate acquisition device based on Java bytecode dynamic instrumentation technology

PendingCN120407398AError detection/correctionJava syntaxData acquisition
The invention discloses an incremental code coverage rate acquisition device based on a Java bytecode dynamic instrumentation technology, and relates to the technical field of software testing and quality control. Comprising a code difference analysis module, a byte code instrumentation module, a coverage rate data acquisition module, a coverage rate data integration module, a coverage rate report generation module and a test trigger and threshold control module, and a syntax tree structure of incremental codes is generated based on a Java syntax analysis tool, so that line level analysis of code differences is realized. According to the method, incremental codes are accurately analyzed through Git and JavaParser, coverage rate data are collected through dynamic instrumentation, a unified report is generated in combination with path analysis, missing scenes are marked in a highlighted mode, and the test efficiency and the code quality control capacity are improved.
Owner:BEIJING BAIJU YIXING TECH CO LTD

Multi-channel APP automatic packaging system

The invention relates to the technical field of mobile application continuous integration automation, and discloses a multi-channel APP automatic packaging system which comprises the steps that byte code files in a released mobile terminal APP installation package are acquired, and an occupied symbol space set is generated; generating an available confusion namespace by using set complementary operation; extracting method-level code change by using an abstract syntax tree difference algorithm, and generating a change method set; generating a patch special confusion rule for the change method set by using a namespace allocation algorithm; compiling and obfuscating the change method set by applying a patch special obfuscating rule to generate a safe obfuscating patch byte code; performing packaging and signature operation on the safe obfuscation patch byte code, and outputting a minimized obfuscation safe hot repair patch pack; according to the method, the technical problems that class definition conflicts or method calling errors occur after the hot repair patch is loaded, and the downloading success rate of a user is affected due to the overlarge size of the hot repair patch are solved.
Owner:ANHUI DUOXIAO INFORMATION TECH CO LTD

Software supply chain risk component calling identification method

The invention provides a software supply chain risk component calling identification method, and belongs to the technical field of basic safety. The method comprises the following steps: loading components in a Java Web application, and dynamically capturing a loaded component list; storing the component list locally and sending the component list to an external intelligence system, acquiring risk component information, and generating a risk calling interface signature according to the risk component information; a preset instrumentation rule file is loaded based on the risk calling interface signature, and accurate monitoring of the risk interface is realized through dynamic method matching and byte code enhancement; screening risk interfaces triggered during operation according to cross comparison of static data and dynamic calling data, and marking high-risk components which must be repaired and risk components which can be postponed to be repaired; the risk report generation module generates repair suggestions and priority reports. According to the method, the accuracy of risk assessment is fundamentally improved, meanwhile, the unnecessary repair cost is remarkably reduced, and an efficient and innovative technical solution is provided for supply chain risk management.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Flash animation media playing system and method based on WASM

The invention discloses a Flash animation media playing system and method based on WASM, belongs to the technical field of webpage playing, and aims to solve the technical problem of how to realize compatible playing of an original Flash file on the premise of not modifying the original Flash file so as to guarantee sustainable use of original educational resources. The analyzer module is used for analyzing the format content of the Flash file and sending the analyzed data to the ActionScript virtual machine and the rendering engine module; the ActionScript virtual machine is used for explaining and executing the ActionScript byte codes, interacting with the JavaScript environment of the browser through the API bridging module, and sending a rendering command to the rendering engine module; and the rendering engine module is used for interacting with a Javascript execution environment to complete display of a rendering result.
Owner:浪潮智能终端有限公司

Strengthening method and device for gap application

The invention belongs to the technical field of information security, and particularly relates to a reinforcing method and device for a swan application. The method comprises the steps of obtaining a to-be-reinforced swan gap application, wherein the swan gap application comprises at least one first byte code file; decompiling the first byte code file into an editable first file, and modifying and reinforcing the first file to generate a second file; and compiling the second file into a second byte code file, and generating the reinforced swan application based on the second byte code file. The invention provides an application reinforcement scheme which is available for a swan-gap system and has better performance.
Owner:BEIJING ZHI YOU WANG AN TECH CO LTD

Intelligent contract vulnerability detection method and system based on multi-modal large language model

The invention relates to the technical field of block chains, in particular to a smart contract vulnerability detection method and system based on a multi-modal large language model.The detection method comprises the steps that S1, the system receives source code input of a smart contract; s2, executing semantic branches and graph structure branches in parallel; executing semantic branch processing, calling an annotation agent, and generating an annotation from the source code of the smart contract; calling a vectorization agent, coding the annotation and the source code, and converting the annotation and the source code into a high-dimensional vector; executing graph structure branch processing, compiling a source code into a byte code by the system, and generating a control flow graph; the vectorization agent generates high-dimensional embedded representation of the nodes based on the control flow graph; and S3, integrating features extracted from the semantic branches and the graph structure branches through a multi-modal feature fusion strategy, and inputting the integrated features into a classifier to detect vulnerabilities. The method is based on a multi-modal large language model agent, and potential vulnerabilities in the smart contract are comprehensively analyzed by integrating high-level semantic information and low-level structured data.
Owner:BEIHANG UNIV

Intelligent contract vulnerability detection method based on multi-level data dependence heterogeneous graph

The invention discloses an intelligent contract vulnerability detection method based on a multi-level data dependence heterogeneous graph, and belongs to the technical field of intelligent contract security. Intelligent contract byte codes are used as input, contract byte codes are converted into operation codes, and a control-data heterogeneous graph with basic blocks as nodes is constructed; designing an in-block data dependency sub-graph, and forming multi-level data dependency with the inter-block data stream; based on the generated control-data heterogeneous graph, a feature weighted relation graph convolutional network is provided, and control flow and data flow feature weights are dynamically adjusted and optimized by using node static attributes such as dominating tree depth and the like, so that multi-modal semantic efficient aggregation is realized. According to the method, for the contract without a public source code on the block chain, vulnerability detection only for the bytecode of the intelligent contract is realized, and high detection efficiency can be achieved under the condition that the detection accuracy is guaranteed.
Owner:TAIYUAN UNIVERSITY OF SCIENCE AND TECHNOLOGY

Non-intrusive thread pool dynamic management method and system

The invention relates to the technical field of data management, and provides a non-intrusive thread pool dynamic management method and system.The method comprises the steps that S1, in the application program loading stage of a virtual machine, a loading request of a thread pool class is intercepted through a Java Agent; s2, performing byte code enhancement processing on the thread pool class; s3, dynamic management during operation: S31, when the configuration monitoring service monitors configuration change, initiating adjustment of related thread pool parameters, and S32, when a monitoring reporting period is reached, reporting the collected indexes; and S33, a blocking queue type set in the thread pool parameters is a bounded queue, and corresponding capacity expansion and capacity reduction operations are performed according to a self-adaptive queue capacity adjustment algorithm in combination with the acquired monitoring indexes. The method has the core advantages of zero transformation cost, fast dynamic response and strong framework compatibility, and provides a thread pool optimization capability which is ready to use when the box is opened for a high-concurrency system.
Owner:SSE INFORMATION NETWORK LTD

Method and device for compiling program code

Embodiments of the present application provide a method and device for compiling program code. The method for compiling program code may include: obtaining source code; and performing a compilation operation to obtain a first compilation result of the source code, where a first code segment in the source code is compiled into machine code in the first compilation result, a second code segment in the source code is compiled into bytecode in the first compilation result, and the first compilation result is configured to be deployed to a target environment. The proposed technical solutions may be conducive to ensuring performance at low storage resource utilization.
Owner:HUAWEI TECH CO LTD +1

Service-level link tracking method and system based on airport service

The invention belongs to the technical field of airport business and link tracking, and discloses a business-level link tracking method and system based on airport business. According to the method, a service-level multi-language adaptive probe based on a dynamic bytecode enhancement technology is utilized, semantic analysis is carried out on collected data through a multi-dimensional label identification engine, flight numbers and event coding service labels are extracted, association mapping of the service labels and technology calling links is established, a service link monitoring system is constructed in an airport multi-manufacturer environment, and the service link monitoring system is used for monitoring the airport multi-manufacturer environment. Service-level fault positioning is realized; performing cross-system link integration based on the service label association information, and constructing a service-driven full-link tracking view; and intelligent positioning and visual display of service faults are realized through multi-dimensional service topology analysis and a dynamic early warning mechanism. According to the invention, sampling can be carried out on demand, only key requests and long-time-consuming interfaces are recorded, and the system can be integrated with other monitoring systems so as to quickly respond and solve problems.
Owner:QINGDAO CIVIL AVIATION KAIYA SYST INTEGRATION CO LTD

Byte code function retrieval method and device of Ethereum virtual machine and computer equipment

The invention relates to a byte code function retrieval method and device of an Ethereum virtual machine and computer equipment, and the method comprises the following steps: processing all byte codes in a byte code library of the Ethereum virtual machine to obtain all byte code functions; calculating a first similarity between the to-be-retrieved natural language query content and all byte code functions based on a pre-trained byte code retriever; inputting the natural language query content into a preset large model to generate a code language function corresponding to the intelligent contract function; calculating a second similarity between the code language function and all byte code functions based on a pre-trained specific retriever; and retrieving a target byte code function corresponding to the natural language query content according to the first similarity and the second similarity. Through the method and the device, the problem of low retrieval accuracy in related technologies is solved, the accurate target byte code function is retrieved on the basis of the first similarity and the second similarity, and then the retrieval recall rate and the retrieval accuracy are enhanced.
Owner:HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY

Contract vulnerability detection method and system based on cross-granularity feature fusion and meta-learning

The invention discloses a contract vulnerability detection method and system based on cross-granularity feature fusion and meta-learning, and relates to the technical field of block chain security, the method comprises the following steps: obtaining a source code and a compiled byte code of a contract to be detected; source code semantic features are extracted from the source code, operation code execution features are extracted from the byte code, and graph structure features are extracted after a program dependency graph is constructed from the source code; performing cross-granularity attention interaction to generate cross-granularity fusion features; performing type-aware feature modulation on the cross-granularity fusion feature and a vulnerability type identifier of the current detection task, training a classifier by adopting a meta-learning strategy, and outputting a vulnerability detection result; and in response to the vulnerability detection result that the vulnerability exists, positioning the vulnerability code position based on the graph-source code attention weight matrix generated in the cross-granularity attention interaction process, thereby solving the problem of poor generalization ability in a rare vulnerability scene with scarce samples.
Owner:CHENGDU UNIV OF INFORMATION TECH

Malware family classification method

The invention provides a malicious software family classification method. The method comprises the following steps: respectively obtaining RGB images based on a byte code file and a configuration file; performing feature extraction on the RGB image based on a designed encoder to obtain a discriminative feature vector; performing data enhancement on each RGB image to generate a sample pair, and optimizing an embedding space by using a supervised contrast learning method to enable feature vectors of samples of the same type to be close to each other and feature vectors of samples of different types to be far away from each other so as to perform learning training on the encoder; an encoder obtained through supervised comparative learning training is used for extracting feature vectors of various types of samples, the feature vectors of the same kind are divided into a plurality of sub-clusters based on hierarchical clustering and contour coefficients, weighted fusion is carried out to generate category prototypes, and malicious software family classification is completed according to the distance between a query sample and each category prototype. The aim of remarkably improving generalization and accuracy of malicious software family classification in a small sample scene is achieved.
Owner:WUXI UNIV

AI service intelligent fault tolerance and degradation method and device based on Java bytecode enhancement technology, equipment, medium and product

The invention discloses an AI service intelligent fault tolerance and degradation method, device and equipment based on a Java bytecode enhancement technology, a medium and a product, and relates to the technical field of AI service integration. According to the method, in a class loading period of Java application starting, a loaded class is scanned to identify target methods marked with declarative fault-tolerant annotations, a bytecode operation framework is utilized to enhance the target methods so as to implant a unified fault-tolerant logic interception entry, and then in a running period, when the target methods are called, the target methods are subjected to fault-tolerant annotation processing. And triggering a fault-tolerant interceptor through the interception entrance to analyze the annotation to obtain a fault-tolerant strategy, allocating an independent fault-tolerant component instance to the fault-tolerant interceptor based on the unique identifier of the method, constructing and executing an enhanced call chain containing a fusing check and retry mechanism, and finally, if the execution of the call chain fails, executing the fault-tolerant interceptor. And if yes, a preset degradation method in the fault-tolerant strategy is automatically executed, so that complete non-intrusive decoupling of AI service fault-tolerant management and service logic can be realized, and the reliability of the system is remarkably improved.
Owner:BEIJING INSIGHT NETWORK CO LTD

Software architecture reconstruction methods for microservice systems

Methods and systems for analyzing architectures of microservice systems are described. An example method includes generating, based on an analysis of a bytecode of a microservice system, a graph-based intermediate representation that models control-flow and data-flow dependencies between a plurality of microservices of the microservice system. The method then includes parsing the graph-based intermediate representation to extract one or more components of the microservice system, and generating, based on the one or more components and a list of attributes for each of the plurality of microservices, a service dependency graph that represents a service view of the microservice system and a context map that represents a domain view of the microservice system. The method additionally includes visualizing, based on the service view and the domain view, an architecture of the microservice system. An example system includes one or more processors that are configured to implement the above-described method.
Owner:BAYLOR UNIVERSITY +1