The invention relates to an
open source component multi-
modal dependency risk tracing method and device, and the method comprises the steps: employing a mode of combining
static analysis and dynamic analysis to analyze a component dependency relationship of
software, and combining AST analysis and construction
script analysis; function-level features are extracted, a binary
fingerprint database is constructed, the similarity between different versions is analyzed through LSH, behavior patterns in binary codes are analyzed, and hidden dependencies or malicious
code injection is detected; the version updating history of the dependent component is analyzed and monitored by using a
time sequence, and the
vulnerability security of the component is evaluated in combination with
attack graph analysis; high-risk components on the path are calculated, potential supply chain
attack points are identified, and risk points are subjected to
cross validation; a
time sequence diagram
database is used for recording the component dependency relationship, and time
backtracking query is supported. According to the method, a multi-mode dependency
analysis method is adopted, potential dependency risks are rapidly identified, and potential supply chain
attack risks are timely warned.