The invention provides a
software supply chain risk component calling identification method, and belongs to the technical field of basic safety. The method comprises the following steps: loading components in a
Java Web application, and dynamically capturing a loaded component
list; storing the component
list locally and sending the component
list to an external
intelligence system, acquiring risk component information, and generating a risk calling interface signature according to the risk component information; a preset
instrumentation rule file is loaded based on the risk calling interface signature, and accurate monitoring of the risk interface is realized through
dynamic method matching and
byte code enhancement; screening risk interfaces triggered during operation according to cross comparison of
static data and dynamic calling data, and marking high-risk components which must be repaired and risk components which can be postponed to be repaired; the risk
report generation module generates repair suggestions and priority reports. According to the method, the accuracy of
risk assessment is fundamentally improved, meanwhile, the unnecessary repair cost is remarkably reduced, and an efficient and innovative technical solution is provided for supply chain risk management.