Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

559 results about "Static analysis" patented technology

Static analysis, static projection, or static scoring is a simplified analysis wherein the effect of an immediate change to a system is calculated without regard to the longer-term response of the system to that change. If the short-term effect is then extrapolated to the long term, such extrapolation is inappropriate.

Computing power analysis method, matching method and computer device used in cloud computing environment

PendingCN121326563AResource allocationError detection/correctionPower analysisPower mapping
The invention discloses a computing power analysis method used in a cloud computing environment, a matching method and a computer device. The computing power analysis method used in the cloud computing environment comprises the steps that historical task operation data of different types of computing power nodes in a cloud computing platform are acquired, associated computing power portraits corresponding to the computing power nodes are generated through preprocessing, and then a target model is trained in combination with the historical task operation data to obtain a task-computing power mapping model; performing multi-dimensional dynamic and static analysis on a to-be-executed user calculation task to obtain task feature information; and analyzing the task feature information based on the task-computing power mapping model to obtain analysis information of each type of computing power nodes. According to the method, the required computing power resources and the analysis information of each type of computing power nodes can be accurately predicted according to the dynamic and static analysis feature information of the task before the task is executed, so that accurate computing power identification and intelligent matching are realized, the reasonability and efficiency of task allocation are improved, the resource waste rate is effectively reduced, and the adaptation accuracy in a multi-tenant environment is improved.
Owner:BEIJING ELECTRONIC DIGITAL INTELLIGENCE TECHNOLOGY CO LTD

Vulnerability hidden danger intelligent detection method based on large model

The invention discloses a vulnerability hidden danger intelligent detection method based on a large model, and the method comprises the steps: firstly carrying out the global static analysis of a source code set, constructing a complete call graph and a complete data flow graph of a program, and forming a structured code knowledge graph; and then, aiming at the identified candidate vulnerability slices, based on the maps, carrying out accurate context retrieval and enhancement, converting key information such as a call chain and a data traceability path which are strongly related to the vulnerability slices into natural language description which can be understood by a large language model, and injecting the natural language description into cue words, so that missing global context information is provided for the model. And the defect of complex code analysis capability is overcome. In this way, the problem that an attention mechanism loses efficacy in remote code association is solved, and the accuracy and reliability of vulnerability detection are remarkably improved.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +1

High-precision static aeroelastic model optimization design method based on model correction technology

The invention discloses a high-precision static aeroelastic model optimization design method based on a model correction technology, and relates to the technical field of aircraft design, and the method comprises the following steps: S1, firstly constructing an initial model, and carrying out statics pre-analysis to verify integrity; s2, executing SOL 101 statics analysis based on the initial model and outputting a physical field result; s3, carrying out consistency analysis in combination with test data and generating a correction decision; s4, screening high-priority correction parameters through local or global sensitivity analysis; s5, correcting model parameters by adopting a mixed algorithm of a gradient method and an agent model, and verifying precision and generalization ability; s6, the corrected model is output as a Nastran file and a reduced-order model in a standardized mode, and a parameter change log is recorded; s7, executing static aeroelastic coupling and flutter analysis, and feeding back a result to drive optimization iteration; s8, constructing a multidisciplinary coupling optimization model in combination with aeroelastic and flutter results to realize collaborative optimization; and S9, finally performing engineering standardization packaging on the optimization model and outputting a verification report.
Owner:BEIJING ZHUOSHI TECHNOLOGY CO LTD

Neural network large model efficient reasoning method based on multiple GPGPUs

The invention belongs to the technical field of artificial intelligence and high-performance computing, and particularly relates to a neural network large model efficient reasoning method based on multiple GPGPUs. The method aims to solve the problems of high communication overhead, non-uniform load, low resource utilization rate, high data transmission delay and the like among multiple processors. Dividing a calculation task into a plurality of sub-graphs through static analysis and mixed granularity partitioning of a model calculation graph; distributing the sub-graphs to the optimal GPGPU based on a weighted cost function in combination with heterogeneous resource perception and a dynamic mapping strategy; a global pipeline scheduling plan is constructed by using communication topology perception, and calculation and communication overlap are maximized; data are loaded in advance through a host side hierarchical caching and asynchronous prefetching mechanism, and transmission delay is hidden; multi-stream concurrent execution and event-based lightweight synchronization are adopted on each GPGPU, so that waiting overhead is reduced. According to the method, the reasoning delay can be remarkably reduced, the throughput and the hardware utilization rate are improved, and the method has good adaptivity and expandability.
Owner:BEIJING TOPMOO TECH

Code generation and repair method and device based on multi-round feedback of large language model

The invention discloses a code generation and restoration method and device based on multi-round feedback of a large language model, and the method comprises the following steps: 1, converting problem description into a structured tetrad (target, input, output and constraint) through a two-stage task demand deconstruction mechanism, and generating a pseudo-code frame according to the structured tetrad; 2, generating a plurality of candidate code schemes in parallel based on different implementation strategies; 3, selecting an optimal code implementation scheme through multi-dimensional evaluation; 4, generating an extended test case through boundary condition analysis and public test reasoning, and expanding a verification range; 5, classifying error types in combination with static analysis and dynamic execution information, and applying a special repair strategy; 6, providing detailed repair reasons and ideas by an interpretable repair mechanism; and 7, establishing a multi-round feedback repair verification iteration mechanism composed of testing, analysis, repair and verification. According to the method, the performance of an existing large language model in processing a complex programming task is effectively improved.
Owner:WUHAN UNIV +1

Intelligent generation and closed-loop optimization method for aviation airborne software test case

The invention discloses an aviation airborne software test case intelligent generation and closed-loop optimization method, which comprises the following steps of: knowledge graph construction: analyzing a DO-178C standard document and a related field document, extracting entities and relationships defined in the DO-178C standard document and the related field document, and constructing a field knowledge graph fused with DO-178C standard knowledge; initial test case generation: based on the domain knowledge graph, combining a static analysis result of the source code of the tested airborne software, and utilizing a large language model to drive and generate an initial test case set; and closed-loop iterative optimization: executing the test case, evaluating whether the structural coverage rate reaches the standard or not, automatically identifying uncovered codes when the structural coverage rate does not reach the standard, generating a supplementary test case for iterative optimization, and outputting a final test case set until a coverage rate target corresponding to the software security level is met. According to the method, the test quality and efficiency of the aviation airborne software can be improved.
Owner:YANGZHOU UNIV

Source code vulnerability detection method and system based on semantic comparative learning

The invention belongs to the technical field of vulnerability detection, and particularly relates to a source code vulnerability detection method and system based on semantic comparative learning. Comprising the steps of obtaining source codes, preprocessing the source codes, and generating positive and negative samples paired with the source codes; improving the CodeBERT model to obtain an encoder, and building a momentum contrast learning model comprising a vulnerability classification branch, a representation consistency branch and a contrast learning branch based on the obtained encoder; training the momentum contrast learning model comprising the three branches by adopting a contrast learning method; and based on the trained momentum contrast learning model, performing vulnerability detection on a to-be-analyzed code. According to the method, a semantic contrast learning-driven source code vulnerability detection framework is designed and realized, and the problems of limitation of traditional static analysis and insufficient generalization ability of an existing deep learning model are solved by learning representation which is robust to code semantic changes and sensitive to vulnerability modes.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN +2

Open source component multi-mode dependence risk tracing method and device

The invention relates to an open source component multi-modal dependency risk tracing method and device, and the method comprises the steps: employing a mode of combining static analysis and dynamic analysis to analyze a component dependency relationship of software, and combining AST analysis and construction script analysis; function-level features are extracted, a binary fingerprint database is constructed, the similarity between different versions is analyzed through LSH, behavior patterns in binary codes are analyzed, and hidden dependencies or malicious code injection is detected; the version updating history of the dependent component is analyzed and monitored by using a time sequence, and the vulnerability security of the component is evaluated in combination with attack graph analysis; high-risk components on the path are calculated, potential supply chain attack points are identified, and risk points are subjected to cross validation; a time sequence diagram database is used for recording the component dependency relationship, and time backtracking query is supported. According to the method, a multi-mode dependency analysis method is adopted, potential dependency risks are rapidly identified, and potential supply chain attack risks are timely warned.
Owner:FUJIAN YIRONG INFORMATION TECH +1

System and method for deterministically generating reproducible evaluative scores for a subject of analysis

The present invention relates to a system and method for deterministically generating reproducible evaluative scores for a subject of analysis (e.g., a security). The system comprises a processor and memory storing instructions to: receive verified data describing the subject; store this data in a fixed and version-controlled corpus to define a static analytical context; execute a large-language model (LLM) under a structured prompt framework that directs a controlled scratch-pad reasoning process for preliminary interpretations and evidence extraction; perform a multi-pass deterministic analysis of the fixed corpus to produce structured, synthesized statements as reproducible evidentiary outputs; and finally, apply a rubric-based scoring engine that converts these statements into calibrated alignment scores and aggregates them to generate a composite deterministic score. This architecture ensures reproducibility, transparency, and auditability by anchoring the flexible analysis of the LLM and the final scoring logic to a known, unchanging evidence corpus.
Owner:VIALAB

Knowledge extraction and envelope coverage-oriented software vulnerability test method and related equipment

The invention discloses a knowledge extraction and envelope coverage-oriented software vulnerability test method and related equipment, and the method comprises the steps: obtaining vulnerability key information of target software, and obtaining sensitive function features through defect dependence analysis and construction based on the vulnerability key information; performing semantic analysis on the analysis report and the code abstract associated with the sensitive function characteristics, screening to obtain a target sensitive function, performing path envelope reverse tracking on the target sensitive function, and constructing to obtain a target path envelope; and obtaining coverage information enveloped by the target path, and carrying out fuzzy testing on the basis of the coverage information in combination with the iteratively optimized variation sample. According to the method, through intelligent closed loop of analysis-positioning-testing-feedback-optimization, static analysis provides accurate guidance for dynamic testing, and the static analysis strategy is inversely optimized by the result of the dynamic testing, so that the maximum improvement of the testing efficiency and the vulnerability discovery accuracy is realized in limited testing resources, and the testing efficiency and the vulnerability discovery accuracy are improved. The method can be widely applied to the technical field of software security.
Owner:GUANGZHOU UNIVERSITY

Automatic compiling method and device of test case, electronic equipment and storage medium

The invention discloses an automatic compiling method and device for a test case, electronic equipment and a storage medium, and relates to the technical field of computers, and the method comprises the steps: carrying out the structural analysis of a demand document for creative and creative transformation, and extracting the demand information of the demand document; the code warehouse is connected to obtain the source code and performs static analysis to generate code logic; establishing a semantic association mapping table of the demand information and the code logic, generating a test scene library according to the semantic association mapping table, and automatically generating a test case according to the parameter type and the constraint rule; and performing multi-dimensional verification on the generated test case to generate a verification result, and adjusting the priority of the test case according to the verification result. The method has the technical effects of improving marginal scene coverage depth and breadth, improving test case writing efficiency and accuracy, reducing manual dependence, and optimizing test case quality and execution pertinence.
Owner:CHINA CONSTRUCTION BANK

Software variation test system and method based on structure-semantic fusion

The invention discloses a software variation testing system and method based on structure-semantic fusion, and the system comprises a document analysis module, a structure diagram construction module, an agent module, a defect injection module and an influence domain verification module.The method comprises the steps that a function document or natural language description serves as an entry, and after a code structure diagram (such as a function call diagram) is constructed through static analysis, the influence domain is verified; an agent autonomously explores semantic information of a code under the guidance of a structure diagram, precise positioning from function description to a target code position is completed, and defect injection and influence domain verification are carried out.
Owner:SHANGHAI JIAOTONG UNIV +1

Cross-architecture code automatic migration method, system and equipment based on large language model agent and medium

The invention relates to a cross-architecture code automatic migration method, system and device based on a large language model agent and a medium. The method comprises the following steps: acquiring a source code, a construction script and an architecture related header file of a target project; based on a pre-constructed transplantation target system architecture knowledge base, analyzing system architecture differences in combination with construction scripts and positioning architecture related positions needing to be modified in source codes to obtain a preliminary modification scheme; constructing scripts through static analysis and carrying out abstract syntax tree analysis on source codes to obtain a global dependency directed graph; based on a transplantation target system architecture knowledge base, performing migration code semantic matching on the source code according to the preliminary modification scheme and the global dependency directed graph, and generating a semantic equivalent replacement code to obtain a patch list; and sequentially executing incremental compiling, function consistency testing and performance regression verification on the migration project copy after the patch list is applied to generate verification information and a verification result. By adopting the method, cross-architecture code automatic migration can be realized.
Owner:陈华芳

Code change influence identification and automatic test execution method and system

PendingCN121880205AError detection/correctionAlgorithmEntry point
The invention relates to the technical field of software development, in particular to a code change influence recognition and automatic test execution method and system.The method comprises the steps that multiple types of nodes are extracted from code data, relation edges among the nodes are constructed according to code dependency relations, weights are set, and a semantic map is obtained; when the code is changed, analyzing by using a static analysis strategy, a dynamic analysis strategy and a semantic understanding strategy to obtain a change entry node; calculating the affected probability of each node according to each entry node, the semantic map and a preset propagation threshold; and obtaining and executing a test case related to each influenced node to obtain a test result. It can be understood that according to the technical scheme, three analysis strategies are combined, the direct influence and indirect influence of code change are comprehensively captured, then the test cases can completely cover the influence nodes, and the test efficiency is high.
Owner:武汉易久数科智能机器人有限公司

Time domain and frequency domain combined impact resistance analysis method and device for ship stern tube

The invention provides a time domain and frequency domain combined impact resistance analysis method and device for a ship stern tube, and the method comprises the steps: building geometric models of all parts in the stern tube through three-dimensional modeling software according to an actual engineering drawing of the stern tube, carrying out virtual assembly on the geometric model of each component according to the actual assembly relation of each component to obtain a geometric model of the tail shaft tube; importing the geometric model of the tail shaft tube into finite element software, endowing each component with material attributes, and carrying out grid division on the geometric model by adopting an overall network size control method; and performing static analysis on the geometric model after grid division to obtain static working stress, performing dynamic analysis on the geometric model after grid division to obtain dynamic impact stress, and synthesizing the static working stress and the dynamic impact stress into total stress. According to the method, time domain and frequency domain combined shock resistance response calculation is carried out for the tail shaft tube as a core component of the ship propulsion system, and the accuracy of shock resistance response calculation is improved.
Owner:SANYA SCI & EDUCATION INNOVATION PARK WUHAN UNIV OF TECH

Bridge anti-fatigue performance analysis and optimization method and system based on finite element analysis

The invention discloses a bridge anti-fatigue performance analysis and optimization method and system based on finite element analysis. The method comprises the following steps: constructing a bridge finite element basic model and a random fleet time-varying load spectrum, and executing damage-rigidity dynamic coupling iterative calculation; a fatigue sensitive area is automatically identified through the strain energy density gradient, a high-precision sub-model is generated, a basic model stiffness matrix is updated in real time through a sub-model calculation result, and a fatigue evolution cloud picture containing a stiffness degradation track is generated; and finally, identifying a damage hotspot based on the cloud picture, and generating an optimization strategy containing a traffic current limiting threshold and a structure reinforcement opportunity by using a genetic algorithm. According to the method, the problem of prediction deviation of traditional static analysis is solved by simulating the reverse influence of damage on rigidity and internal force redistribution, and accurate evaluation and scientific decision-making of the whole life cycle of the bridge are achieved.
Owner:JINING JIZOU EXPRESSWAY CO LTD +1

Program defect detection method for heterogeneous fusion of symbolic execution tree and LLM vector space

The invention provides a symbolic execution tree and LLM vector space heterogeneous fusion program defect detection method, relates to the technical field of program static analysis, and solves the problems of path explosion and overhigh constraint solution complexity in C / C + + program defect detection of traditional symbolic execution. The method comprises the steps that firstly, a symbolic execution tree of a target program to be detected is constructed, key feature information is extracted from the symbolic execution tree and converted into multi-dimensional feature representation, and corresponding symbolic execution feature vectors are formed; then constructing a mapping model, realizing a mapping process from the symbolic execution feature vector to an LLM vector space, and obtaining an LLM mapping result; symbolic execution analysis is achieved based on the symbolic execution tree, LLM analysis is achieved based on the LLM mapping result, and finally two kinds of analysis results are fused to obtain a program defect detection result. For optimization training of the mapping model, a comparative learning strategy is also adopted. According to the invention, accurate detection of complex program defects can be effectively realized, and the detection efficiency is improved.
Owner:10TH RES INST OF CETC

Detecting impact of API usage in microservices

A computer hardware system includes a static analyzer, a load estimator, and a hardware processor configured to perform the following executable operations. Using the static analyzer and for each egress API call site respectively associated with an ingress API handler of a microservice, a weight is generated and is included within a static analysis of the microservice also generated by the static analyzer. Using the load estimator and for each of the egress API call sites, a load is determined based upon the weight for the egress API call site, a number of times, over a predetermined period of time, a particular ingress API handler associated with the egress API call site is called, and a cost of a call to the egress API call site. Based upon the load, the microservice is modified.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

MCM-GPU-oriented resource storage optimization method, device and equipment

The invention provides an MCM-GPU-oriented resource storage optimization method, device and equipment, and the method comprises the steps: carrying out the static analysis of an operator-level data flow diagram of a calculation task in a compiling stage, and extracting the data dependence relation and life cycle characteristics of each operator; generating a storage optimization scheme based on the data dependency relationship and life cycle characteristics of each operator; in the operation stage, task and data collaborative allocation is carried out according to a data prefetching strategy and a data replacement strategy, task and data collaborative allocation and the calculation task are executed in parallel, and a data flow diagram and an operator dependency relationship of the task are analyzed by utilizing a compiling period; in combination with the data locality characteristics of the MCM-GPU multi-level storage architecture and the concurrency requirements of different modules for data access, an appropriate GPU module is selected to carry out data optimization management, so that frequent data exchange between a GPU and a CPU is reduced, and the performance potential of the MCM-GPU architecture in a super-large-scale task is brought into full play.
Owner:NAT INNOVATION INST OF DEFENSE TECH PLA ACAD OF MILITARY SCI

Code sample optimization method and device based on language large model

The invention relates to the technical field of computers, in particular to a code sample optimization method and system based on a language large model, and the method comprises the steps: firstly, obtaining a source code sample, determining a code sample boundary, and generating a mark sequence; then, based on a compiling result, a static analysis result and a unit test result, a quality label is generated, and a training sample set is formed; then, taking a Transform neural network model of bidirectional context coding as an encoder, and carrying out training under the supervision of quality annotation to obtain a quality evaluation model; and finally, screening according to a preset quality score threshold to obtain a high-quality code sample set. According to the technical scheme, by combining the deep grammar analysis and context understanding of the code samples, the accuracy and efficiency of automatic screening are improved, manual intervention is reduced, and the method can adapt to automatic evaluation of a large-scale code library.
Owner:CHONGQING ZHONGKE YUNCONG TECH CO LTD +1

Power communication network fault intelligent diagnosis method based on dynamic topology simulation

PendingCN121396740ATransmissionPhysical layerThree dimensional matrix
The invention relates to the technical field of power communication network fault diagnosis, in particular to a power communication network fault intelligent diagnosis method based on dynamic topology simulation. The electric power communication network fault intelligent diagnosis scheme is implemented by six steps: firstly, collecting physical layer, protocol layer and topological data, and constructing an equipment-time-performance index three-dimensional matrix; decomposing the matrix to calculate a stability index, and primarily judging an abnormal time period and an abnormal area; mapping a physical topology, and accurately positioning a fault area by using a dynamic convex hull and a ray algorithm; extracting historical data to generate a characteristic curve, and matching a sample library to identify a fault type; the theoretical and actual parameters are iteratively compared to verify the reliability; and finally generating a report and matching a repair strategy. Rapid positioning, accurate identification and reliable diagnosis of faults are achieved, the defects of static analysis, data splitting and verification deficiency in the prior art are overcome, and the operation and maintenance efficiency and the safety level of an electric power communication network are improved.
Owner:INFORMATION & COMM COMPANY OF QINGHAI ELECTRIC POWER

EBPF-based adaptive probe deployment and distributed context tracking method, system and device, and storage medium

PendingCN121277785AHardware monitoringShardProbe type
The invention relates to the technical field of cloud native monitoring, in particular to an eBPF-based adaptive probe deployment and distributed context tracking method, system and device and a storage medium. Performing static analysis and dynamic monitoring on a target application through an adaptive probe scheduler, constructing a function criticality scoring model, intelligently selecting a probe type and deploying the probe type to a key function; the method comprises the following steps: capturing a distributed tracking identifier by applying a semantic probe, analyzing application layer data, performing desensitization processing, and injecting an anchor point context into kernel mode storage; establishing a context transfer mechanism based on the process group identifier, monitoring cross-service calling through a network connection hook probe, and realizing deterministic association transfer by using a socket identifier; and performing multi-level context fusion through a network behavior probe, and associating the network behavior with the application context in real time to generate complete call chain information. According to the method, the problems of static fragility and context fragmentation of probe deployment in a cloud native environment are solved, and self-adaptive end-to-end full link tracking is realized.
Owner:GUANGDONG POWER GRID CO LTD INFORMATION CENT

LLM-powered threat modeling

Techniques for implementing an AI threat modeling tool are disclosed. A static analysis tool is used to extract a candidate code snippet from a code repository. The candidate code snippet is identified as potentially being a security relevant code element. The static analysis tool generates additional context associated with the candidate code snippet. An LLM prompt is generated. This prompt is structured to include the candidate code snippet, the context, and a directive to assign a classification to the candidate code snippet. The classification includes a source classification, a sink classification, a sanitizer classification, or a flow step classification. The LLM operates on the prompt to generate output comprising a specific classification for the candidate code snippet. The output is formatted into a data extension file that is consumable by the static analysis tool.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Cross-file semantic association analysis system based on hierarchical rule engine

The invention provides a cross-file semantic association analysis system based on a hierarchical rule engine. The cross-file semantic association analysis system comprises a plurality of modules, wherein a code compilation analysis module is used for converting an input code file into an AST object and executing cross-file dependency and reference analysis; the semantic fact construction module generates an initial fact set according to the data output by the code compiling and analyzing module; the rule interpreter receives the rule set of the hierarchical rule base and constructs a corresponding hierarchical rule network; the rule matcher injects the initial fact set into the hierarchical rule network in a streaming mode to execute rule matching; the condition verification module verifies a rule matching condition according to the input fact data and returns a result; when rule matching succeeds, the rule executor executes corresponding processing logic and updates the fact base; and the result analyzing and processing module analyzes and integrates the final reasoning fact data and writes a result into a conclusion library. The method can be used for constructing a universal cross-file code context analysis system, and the code static analysis performance is improved.
Owner:SOUTH CHINA UNIV OF TECH

Smart city information management method and system based on GIS and AI fusion

The invention relates to the technical field of smart city information management, in particular to a smart city information management method and system based on GIS and AI fusion, and the method comprises the steps: carrying out the data mining and statistical analysis of the basic information of each economic entity in a city, and achieving the overview of economic development situations; collecting geographic position data of an economic body and matching coordinates, and constructing a three-dimensional digital city model associated with a GIS system; a hierarchical comprehensive evaluation algorithm is adopted to calculate the economic innovation value, the contribution degree of the economic innovation value is analyzed, and a long-short memory network is utilized to carry out space-time dynamic evolution analysis and trend prediction; and intelligent semantic understanding and personalized question and answer feedback are realized by analyzing a multi-modal query request of a user. The problems that an existing system is difficult in data fusion, static state analysis lags behind, and decision support is insufficient are solved, unified perception, intelligent analysis and scientific decision support of the urban operation state are achieved, and the urban fine management and service level is remarkably improved.
Owner:GUIZHOU MERCHANTS EASY TECH SERVICE CO LTD

Explanatable vulnerability detection method and system based on large model enhanced graph learning

The invention discloses an interpretable vulnerability detection method based on large model enhanced graph learning, which comprises the following steps of: 1) performing sample denoising on training data, constructing a code attribute graph, and learning and training a vulnerability detection model based on a causal graph; 2) performing static analysis and feature extraction on a to-be-detected sample, and inputting the to-be-detected sample into the trained model for vulnerability detection; 3) performing context enhancement on the detected vulnerability sample to generate explanatory description information; according to the method, a real vulnerability mode is learned from a vulnerability sample with noise through sample denoising and a causal graph attention network model, meanwhile, a context-enhanced interpretation generation technology is put forward, high-quality vulnerability description is generated under the guidance of a retrieved similar sample to serve as interpretive information, and the vulnerability can be accurately identified. And the accuracy and interpretability of vulnerability detection are improved. The invention also provides an interpretable software vulnerability detection system based on large model enhanced causal graph learning.
Owner:NANJING UNIV OF POSTS & TELECOMM

Techniques for code intent discovery

A system and method for detecting code intent of code objects in a computing environment for assessing cybersecurity risk is presented. The method includes detecting a plurality of code objects in a computing environment; statically analyzing each code object of the plurality of code objects to determine a plurality of potential intents, each potential intent corresponding to an action; generating a cybersecurity signal in the computing environment based on a plurality of event records; detecting in the cybersecurity signal a first event corresponding to a potential intent; determining that the potential intent is a code intent based on the detection; detecting in the cybersecurity signal a second event which does not correspond to any potential intent; and initiating a remediation action in the computing environment based on the detected second event.
Owner:WIZ INC

Data blood relationship management system supporting multi-source heterogeneous data dependency analysis

The invention provides a data consanguinity management system supporting multi-source heterogeneous data dependency analysis. The system comprises an automatic data analysis module, a consanguinity collecting and updating module, a fine-grained dependency analysis module and an interactive consanguinity analysis module. Wherein the automatic data analysis module is used for acquiring multi-source heterogeneous data and automatically analyzing the multi-source heterogeneous data to generate target standardized metadata; the blood relationship acquisition and updating module generates blood relationship data through static analysis, dynamic analysis and message queue acquisition; the fine-grained dependency analysis module performs dependency analysis from the table level and the field level to generate fine-grained dependency analysis data; and the interactive blood relationship analysis module performs interactive tracing based on the data and constructs a visual interface. Through cooperation of the four modules, automatic processing, fine-grained dependency analysis and real-time dynamic updating of multi-source heterogeneous data are achieved, and the accuracy and efficiency of data management are improved.
Owner:DIGITAL HAINAN CO LTD

Self-adaptive scheduling compensation system and method for GPU (Graphics Processing Unit) architecture

The invention discloses a GPU (Graphics Processing Unit) architecture-oriented adaptive scheduling compensation system and method, and relates to the technical field of crossing of computer hardware and artificial intelligence. Comprising a GPU-operator dynamic matching module, a reinforcement learning scheduling center, a prediction-feedback compensation module and an adaptive optimization knowledge base, and a'perception-decision-execution-feedback-optimization 'closed-loop collaborative mechanism is formed through real-time data interaction; according to the method, features are extracted through static analysis and dynamic tracking fusion, a dynamic matching matrix is constructed through weighted cosine similarity, and deep adaptation of operators and GPU hardware is achieved; a deviation and differentiation compensation rule is predicted through an LSTM model, the performance loss is reduced, and the precision is guaranteed; through transfer learning and classification index multiplexing historical optimization experience, the cross-architecture adaptation period is shortened, the problems of low adaptation accuracy, scheduling staticization, compensation lag and low cross-architecture adaptation efficiency in the heterogeneous GPU environment are effectively solved, and the method is suitable for efficient and stable deployment of the AI model on the multi-architecture GPU.
Owner:CHINA SOUTHERN POWER GRID ARTIFICIAL INTELLIGENCE TECHNOLOGY CO LTD

Object-level authorization vulnerability automatic detection method and system based on large language model

The invention provides an automatic object-level authorization vulnerability detection method based on a large language model, which comprises the following steps of: firstly, identifying a sensitive resource table through SQL (Structured Query Language) grammar analysis, and analyzing an operation path from a tracking request parameter to the sensitive resource table by utilizing a forward data stream; then, performing context sensing analysis on the database operation by adopting LLM to infer object-level sensitive operation; thirdly, recognizing program logic and a conditional protection mechanism in database query through static analysis, and recognizing custom verification logic such as method-level annotation and administrator permission in combination with an LLM and character string matching method; and finally, judging whether the sensitive operation lacks user-defined verification, ownership SQL constraint and access control conditions at the same time or not by integrating the mechanism, and generating a vulnerability report according to the judgment result. The invention further provides an automatic object-level authorization vulnerability detection system based on the large language model. Therefore, the detection precision can be effectively improved, and false alarm and missing alarm are remarkably reduced.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI