Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8 results about "Software Security Vulnerability" patented technology

A vulnerability is a security weakness in a software program that puts the program or computer at risk of malicious programs and users.

Code generation method and device based on large model, equipment, medium and product

The invention discloses a code generation method and device based on a large model, equipment, a medium and a product, and the method comprises the steps: carrying out the code generation through a first code large model according to target code demand data, and obtaining an initial code; according to the first code snippet, generating a test code through a second code large model to obtain a unit test code; according to the unit test code and the initial code, code repair based on editing distance regularization is conducted through a third code large model, and a to-be-analyzed code is obtained; performing iterative optimization on the to-be-analyzed code and the unit test code to obtain a target code corresponding to the target code demand data; according to the method, code generation, unit test generation and code repair are carried out in a multi-model cooperation mode, the reliability and accuracy of code generation can be effectively improved, software security vulnerabilities are reduced, and therefore the stability and security of a software system are improved.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Software security vulnerability early warning method based on deep learning

The invention relates to the field of security vulnerability early warning, and particularly discloses a software security vulnerability early warning method based on deep learning, which comprises the following steps: starting from a predefined sensitive sink, screening out a code path set directly related to a potential risk by constructing a global function call graph and carrying out call chain reverse tracing; and the analysis redundancy is reduced from the source. Furthermore, according to the scheme, simple sequence modeling is not carried out on the call chain, function nodes in the call chain are converted into deep semantic vectors, and the semantic influence of key nodes is amplified and the interference of irrelevant information is inhibited by dynamically evaluating the time sequence importance of each function node in the call chain and through adaptive weighting. And finally, deep learning is carried out on the key path subjected to information discrimination, and vulnerability classification prediction is carried out, so that the problem of information overload in a long call chain is effectively overcome, and the accuracy of vulnerability early warning and the capture capability of complex semantic association are improved.
Owner:GUANGZHOU YUNXI TECH CO LTD

A Generative AI-Based Method for Intelligent Discovery and Risk Assessment of Software Security Vulnerabilities

This invention relates to the fields of software security and artificial intelligence, specifically a generative AI-based intelligent vulnerability discovery and risk assessment method for software security. The method includes: generating abnormal behavior patterns by collecting multi-source data from the target software, inputting this data into a pre-trained generative AI model for multi-level correlation reasoning, and automatically outputting a set of vulnerability descriptions containing location, path, and impact. Historical verification of the vulnerability descriptions enhances their accuracy, and a risk posture assessment is performed. The attack entry point exposure, exploitation path feasibility, and system impact scope of each vulnerability are quantitatively calculated to form a structured risk quantification matrix. Based on this matrix, risk level mapping is completed, and remediation suggestions and priority sequences are automatically generated. Finally, a risk assessment report is integrated and output. This method automates and intelligently discovers vulnerabilities and significantly improves the accuracy and operability of risk analysis through multi-dimensional quantitative assessment.
Owner:BEIJING HUAXIN MEASUREMENT & CONTROL TECH CO LTD

Software security vulnerability detection method and device, equipment and storage medium

The invention provides a software security vulnerability detection method, device and equipment and a storage medium, and relates to the technical field of software development security, the detection method comprises the following steps: when security check is automatically triggered based on a preset condition, obtaining a dependency declaration file of a to-be-detected software project, and analyzing the dependency declaration file to obtain a dependency declaration file of the to-be-detected software project; obtaining a to-be-checked dependency item list; obtaining structured security knowledge fragments related to the to-be-checked dependency list according to a preset dynamic security knowledge base; and based on a preset large language model, obtaining a risk detection evaluation report according to the structured security knowledge fragment, the to-be-detected dependency list and the scene data of the to-be-detected software project. According to the method, scenarized and precise analysis of the risk can be realized, the false alarm rate is effectively reduced, the pertinence and practicability of the report are improved, and finally the automation, precision and intelligent level of software project dependence on safety management and control is comprehensively enhanced.
Owner:SUPCON TECH CO LTD

A software security vulnerability intelligent scanning method based on static analysis

PendingCN122331950AProgram graphVulnerability
This invention discloses an intelligent scanning method for software security vulnerabilities based on static analysis, specifically relating to the field of software security testing technology. The method acquires a snapshot of the baseline version source code and a snapshot of the modified version source code corresponding to the software project under test, establishes alignment relationships between program elements of the previous and current versions, and forms a set of modified elements. Combining the baseline version program graph cache, function summary cache, and historical hazard index, a comprehensive quantity of the impact of changes is formed, and a subgraph of the impact of changes is constructed. Static incremental vulnerability analysis is performed on the subgraph of the impact of changes to identify newly added risk paths and activated historical hazard paths, and a trusted comprehensive quantity of risk activation is formed. Based on the trusted comprehensive quantity of risk activation, confirmation screening and baseline updates are performed, and valid incremental alerts or paths awaiting review are output. This invention can narrow the analysis scope, reduce the resource consumption of full scans, and improve the ability to identify incremental vulnerabilities and the activation of historical hazard paths.
Owner:SHANGHAI XUYIN TECHNOLOGY CO LTD

A computer software security vulnerability fixing system and method

The application discloses a computer software security vulnerability repair system and method, relates to the technical field of computer software security, and can comprehensively consider factors such as the number of affected software Asc, the vulnerability level Vc and the vulnerability incubation time Vnt through mutual cooperation of three groups of algorithm units, calculate the effective value Rs of different repair strategies of different vulnerabilities, judge the risk of different vulnerabilities and the effective degree of the repair strategies based on the specific repair strategy effective value Rs obtained through calculation, and preferentially repair vulnerabilities with high repair strategy effective value Rs, so that repair resources and time can be more scientifically and effectively allocated under limited repair resources, the repair efficiency of computer software vulnerabilities is improved, the change trend of the Re value in the database can be obtained, the repair strategy can be adjusted and optimized, and the repair effect of the computer software security vulnerability repair system and the utilization efficiency of repair resources are further improved.
Owner:SHANGHAI SIJIE TECHNOLOGY CO LTD

A software security vulnerability detection method based on text features and function dependency features

The application discloses a software security vulnerability detection method based on text features and function dependency features, and the method comprises the following steps: pre-processing the code in a project, extracting all function information in the project and saving, extracting and merging function text features and function dependency relationship features of the function information, using an Autoencoder to reduce dimensions and remove noise of the merged feature vectors, and finally using a local outlier factor detection method (LOF) to perform anomaly detection to obtain functions containing security vulnerabilities. The application performs software security vulnerability detection based on unsupervised learning, does not need to provide labels of whether samples contain security vulnerabilities, simultaneously considers text features of software and dependency relationship features between functions in the software, and improves the correctness of software security vulnerability detection.
Owner:徐文琳

Security vulnerability detection method, system and device based on artificial intelligence and medium

The invention relates to the technical field of software security detection, in particular to a security vulnerability detection method, system and device based on artificial intelligence and a medium. The method comprises the following steps: firstly, acquiring and preprocessing multi-source software security vulnerabilities to obtain a software security vulnerability data set; secondly, according to a software security vulnerability data set and a model pre-trained on a large-scale universal code data set, calling a neural network to construct an artificial intelligence vulnerability detection model; and finally, according to the vulnerability detection result and the set risk level, the corresponding prevention operation is executed, so that the software security vulnerability detection efficiency and accuracy are greatly improved, and the security risk is reduced.
Owner:SICHUAN PUBLIC SUPERVISION CONSULTING CO LTD