The invention discloses an
open source environment
software hidden
vulnerability patch identification method, which is based on a multi-stage architecture and collaborative relationship modeling, and provides a new patch group
identification scheme: firstly, obtaining candidate code submission from an
open source warehouse, extracting correlation characteristics of vulnerabilities and candidate code submission, including rule-based characteristics and semantic characteristics, calculating a correlation
score and screening high-correlation submission; pairwise
pairing the high-correlation submissions, and fusing multi-dimensional features to predict a cooperative relationship between the submissions; and finally, constructing an
undirected graph based on the correlation
score, dividing a maximum connected sub-graph, fusing the features in the group through maximum
pooling, calculating the correlation with the
vulnerability, and outputting an optimal patch group. Meanwhile, an existing patch
identification technology based on sorting learning is combined, an enhancement method based on a submission cooperative relation is provided,
ranking logic submitted by candidate codes is updated through internal association between code submission and by means of correlation between group vectors and vulnerabilities, and the identification precision in a multi-patch scene is improved.