Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1181 results about "Vulnerability detection" patented technology

Unmanned aerial vehicle flight control system vulnerability detection method based on data flow analysis and LLM

The invention discloses an unmanned aerial vehicle flight control system vulnerability detection method based on data flow analysis and LLM, and belongs to the technical field of intelligent software testing. Comprising the following steps: extracting a code function module associated with user operation in an unmanned aerial vehicle flight control system through a data flow analysis method, and establishing an operation-code mapping relation library; generating a structured natural language semantic description for each function module code by adopting a large language model LLM, and forming a multi-dimensional semantic feature vector; based on correlation analysis of multi-module semantic features, a combined test scene is constructed, and a natural language test case is generated; the natural language test case is converted into an executable test code through reverse semantic mapping, and coding reconstruction of test logic is completed; and executing a test code and capturing a runtime log in an unmanned aerial vehicle simulation environment, and performing vulnerability feature extraction and root cause positioning by using a large language model. According to the method, the efficiency is improved, and meanwhile, the deep coverage test of a complex interaction scene is supported.
Owner:HUAZHONG UNIV OF SCI & TECH

Vulnerability description and repair suggestion generation method based on big language model reasoning and retrieval enhancement

The invention discloses a big language model reasoning and retrieval enhancement-based vulnerability description and repair suggestion generation method, which comprises the following steps of: constructing a vulnerability knowledge base by integrating vulnerability databases such as CWE and CVE and an external knowledge source, providing prompt information of professional knowledge for a big language model, preprocessing a to-be-tested code by utilizing a code analysis tool, and generating a big language model reasoning and retrieval enhancement-based vulnerability description and repair suggestion. And extracting vulnerability knowledge most related to a to-be-detected code from the vulnerability knowledge base through semantic matching and code matching, generating detailed vulnerability description and repair suggestions by utilizing a large language model based on the related vulnerability knowledge obtained in the retrieval enhancement stage, and optimizing a generation result through a thinking chain technology. By combining the semantic comprehension ability, the retrieval enhancement technology and the reasoning enhancement technology of the large language model, detailed and targeted vulnerability description and repair suggestions can be quickly generated, the vulnerability repair efficiency is remarkably improved, and the method can be flexibly applied to existing vulnerability detection tools and is suitable for various programming languages and vulnerability types.
Owner:HARBIN INST OF TECH

Artificial intelligence security vulnerability detection platform based on deep learning

The invention discloses a deep learning artificial intelligence security vulnerability detection platform, and relates to the technical field of intelligent detection, and the platform comprises an information processing module which collects heterogeneous data in real time, carries out the labeling, format unification and modal aggregation processing of the data, and generates a sample set; the feature learning module is used for performing feature unwrapping on the sample set by using a variational auto-encoder, extracting modal data features and potential space representation learning, and outputting a potential space vector; the response generation module is used for generating a vulnerability response strategy through a modal consistency verification and response template matching mechanism based on the vulnerability risk level vector in combination with a response generation engine; and the repair feedback module is used for executing automatic vulnerability repair operation in combination with federal reinforcement learning and Bayesian optimization, performing feedback optimization according to an execution result, and outputting the vulnerability repair operation and a feedback result. According to the method, the response strategy is combined with intelligent matching of the real-time risk level, so that the accuracy and adaptability of vulnerability repair are improved.
Owner:HEFEI TANOVO INFORMATION SECURITY TECH CO LTD

Intelligent contract vulnerability detection and repair system based on heterogeneous graph neural network

The invention discloses an intelligent contract vulnerability detection and repair system based on a heterogeneous graph neural network, and belongs to the technical field of block chain security, and the system comprises a contract analysis module, a multilayer graph construction module, a heterogeneous graph neural network module, a vulnerability feature library, a vulnerability recognition engine, an automatic repair module and a visual interface. After the source code of the intelligent contract is input, code analysis and standardization are completed by a contract analysis module; the multi-layer graph construction module constructs a contract internal heterogeneous graph, an inter-contract interaction graph and an ecosystem relation graph based on a graph theory; the heterogeneous graph neural network module learns a vulnerability feature mode; the vulnerability recognition engine combines the vulnerability feature library to realize vulnerability classification and risk assessment; the automatic repairing module generates a repairing scheme; and the visual interface realizes detection progress monitoring, result display and encrypted report export. The intelligent contract vulnerability detection and restoration system based on the heterogeneous graph neural network provided by the invention provides technical support for block chain digital asset security and ecological stability.
Owner:GUANGDONG UNIV OF TECH

PHP taint type vulnerability detection method based on heterogeneous graph neural network

The invention discloses a PHP taint type vulnerability detection method based on a heterogeneous graph neural network, and belongs to the field of software security. The method comprises the following steps: performing annotation removal, variable naming standardization and character string standardization processing on a PHP source code through a code preprocessing module to generate a standardized code; based on a vulnerability sub-attribute graph extraction module, reversely tracking vulnerability sinks to a taint source, extracting a simplified vulnerability sub-attribute graph, and removing redundant nodes and edges; fusing BERT semantic features and node type features through a graph node embedding module to generate an initial embedding vector, and constructing a heterogeneous graph comprising an abstract syntax tree edge, a program flow graph edge and a control dependence graph edge; a heterogeneous graph neural network vulnerability detection module is adopted to perform independent feature aggregation on multiple types of edges, dynamic weighted fusion is performed in combination with an attention mechanism, and key nodes are screened through Top-k graph pooling; and finally, inputting the graph-level features into a classifier to realize vulnerability detection.
Owner:YANSHAN UNIV

Dynamic and static combined detection method for security vulnerabilities of power system software

The invention is applicable to the technical field of vulnerability detection, and provides a power system software security vulnerability dynamic and static combined detection method, which comprises the following steps: acquiring static source code data of power system software and dynamic behavior log data during operation; generating a hierarchical abstract syntax tree and structured time series data; performing multi-dimensional feature extraction on the static source code data and the dynamic behavior log data based on a vulnerability knowledge graph of the power system; generating a domain constraint confrontation sample based on the power protocol features and the abnormal features during operation, and inputting the domain constraint confrontation sample into the constructed hybrid detection model for confrontation training to obtain a trained hybrid detection model; and performing automatic detection on the power system software by utilizing the trained hybrid detection model, and outputting a detection result containing a static code defect position and a dynamic attack path. The full-life-cycle accurate detection of the software vulnerability of the power system is realized, and the network security protection capability of the power system is improved.
Owner:GUANGXI POWER GRID CORP

Active Vulnerability Detection for a Compute Environment

Improved vulnerability detection in a cloud computing environment may be achieved by monitoring, by an agent executing in a compute asset of the cloud computing environment, one or more events associated with code deployed in the cloud computing environment; based at least in part on the one or more events, determining whether the code is active in the cloud computing environment; in response to the code being active, scanning the code to identify one or more vulnerabilities; and performing a notification in response to identifying one or more vulnerabilities.
Owner:FORTINET INC

Internet of vehicles vulnerability management method, system and device based on block chain, and medium

The invention provides an Internet of Vehicles vulnerability management method, system, device and medium based on a block chain, and relates to the technical field of vehicle networks, the method can comprehensively identify potential safety risks of vehicles through a dynamic and static combined vulnerability detection mechanism, and generates a structured vulnerability report; hash abstract chaining evidence storage is performed on key data of reports and subsequent repair links by using a block chain, so that the whole process of vulnerability discovery, analysis and repair is ensured not to be tampered and traceable, and the authenticity and credibility of data are improved; the integrity of the report is verified at the cloud end, and an AI analysis engine is combined to associate a CVE database and threat intelligence, so that intelligent generation and decision support of a repair scheme are realized; the hash abstract on the chain of the OTA patch is verified at the vehicle end, so that the credibility of the patch source and the integrity of the content are guaranteed; and finally, through feedback of an installation result and secondary uplink archiving, complete closed-loop management from vulnerability discovery to repair verification is formed.
Owner:FIFTH ELECTRONICS RSCH INST OF MINISTRY OF IND & INFO TECH

Vulnerability hidden danger intelligent detection method based on large model

The invention discloses a vulnerability hidden danger intelligent detection method based on a large model, and the method comprises the steps: firstly carrying out the global static analysis of a source code set, constructing a complete call graph and a complete data flow graph of a program, and forming a structured code knowledge graph; and then, aiming at the identified candidate vulnerability slices, based on the maps, carrying out accurate context retrieval and enhancement, converting key information such as a call chain and a data traceability path which are strongly related to the vulnerability slices into natural language description which can be understood by a large language model, and injecting the natural language description into cue words, so that missing global context information is provided for the model. And the defect of complex code analysis capability is overcome. In this way, the problem that an attention mechanism loses efficacy in remote code association is solved, and the accuracy and reliability of vulnerability detection are remarkably improved.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +1

Cross-chain smart contract vulnerability detection method and system based on multi-feature fusion learning

The invention discloses a cross-chain smart contract vulnerability detection method and system based on multi-feature fusion learning. The method comprises the following steps: collecting a cross-chain smart contract vulnerability data set for cleaning and labeling; feature extraction is carried out from the source code and the byte code, an abstract syntax tree (AST) is extracted from the cleaned source code, a basic control flow graph (CFG) is extracted from the byte code, and a cross-chain control flow graph (xCFG) is constructed; carrying out feature representation on AST and xCFG, generating a graph vector through a graph neural network (GNN), generating a semantic vector through CodeBert, and fusing the semantic vector into a feature fusion vector; performing model training and detection, taking the generated vectors as training data and test data, obtaining a cross-chain smart contract vulnerability detection model by adopting Transform-FC model training data, and finally evaluating model performance through accuracy, recall rate, precision rate and F1 value. According to the method, the structural features and semantic features of the codes can be effectively fused, potential vulnerability information in the codes can be fully mined, the recognition capability of the model for cross-chain vulnerabilities can be enhanced, and the accuracy and reliability of the cross-chain vulnerability detection model can be improved, so that the security of a block chain system can be more efficiently guaranteed.
Owner:HOHAI UNIV

Intelligent detection method for network security vulnerabilities based on artificial intelligence and big data

The invention relates to a network security vulnerability intelligent detection method based on artificial intelligence and big data, and the method comprises the steps: carrying out the dynamic time synchronization processing of multi-modal network security data, and generating a multi-source data flow with aligned time sequences through cross-modal correlation analysis; extracting cross-modal features from the data stream, and performing semantic fusion on the cross-modal features in combination with a vulnerability knowledge graph to generate a multi-dimensional feature vector; training the multi-dimensional feature vector through a hybrid model to obtain a vulnerability detection model, detecting real-time network behavior data by using the model, and outputting a vulnerability probability and an abnormal risk score; and performing automatic vulnerability verification according to the vulnerability probability and the abnormal risk score to obtain a verification result, and updating the vulnerability detection model according to the result. The system can effectively improve the accuracy, timeliness and stability of network security vulnerability detection and reduce the false report and missing report rate through multi-modal data collaboration, hybrid model dual detection and closed-loop optimization mechanisms.
Owner:YANTAI VOCATIONAL COLLEGE +1

Intelligent contract vulnerability detection method based on heterogeneous graph attention network

The invention discloses an intelligent contract vulnerability detection method based on a heterogeneous graph attention network. According to the method, firstly, the source code of the intelligent contract is preprocessed, the SCIR of the code of the intelligent contract is constructed, the complexity of the code of the contract is reduced, and vulnerability features are enriched; and constructing an intelligent contract code attribute graph SCPG based on SCIR, integrating various code graph structures such as an abstract syntax tree and a control flow graph, and comprehensively describing syntax and semantic features of the contract. And then constructing an intelligent contract code heterogeneous graph SCHG on the basis of the SCPG, optimizing code graph structure representation, and realizing high-quality modeling of node features. And finally, detecting the vulnerability of the smart contract by using a customized multi-layer heterogeneous graph attention network model MHGAN. The intelligent contract vulnerability detection method based on deep learning makes up for the defects of an existing intelligent contract vulnerability detection method based on deep learning, effectively improves the accuracy of intelligent contract vulnerability detection, and is excellent in the interpretability of the detection result.
Owner:HANGZHOU DIANZI UNIV

Code fingerprint-based open source component identification and vulnerability detection method

The invention discloses a code fingerprint-based open source component identification and vulnerability detection method, which comprises the following steps of: receiving a local or remote code, extracting a difference file, generating an AST and constructing a code attribute graph; sHA-256 Hash fingerprints and GNN semantic fingerprints are calculated for the function level sub-graphs to form mixed fingerprints, accurate matching is conducted through a Bloom filter, semantic matching is completed through nearest neighbor, and a component version is determined through a distribution difference algorithm. The method comprises the steps that firstly, a component identifier is mapped into a PURL or an SWID, an OSV / NVD library is inquired to obtain a CVE, comprehensive risks are calculated in combination with CVSS, EPSS and dependency depth, and an SBOM and a vulnerability report conforming to CycloneDX or SPDX are output. The method is high in speed and high in accuracy, and the open source risk can be automatically treated in continuous integration.
Owner:GUANGDONG POWER GRID CO LTD +1

Generative ai ops for cyber security threat detection

ActiveUS20250317464A1Securing communicationIndustrial securityIndustrial safety system
An industrial security system leverages generative artificial intelligence (AI) to automate the process of identifying software or hardware insecurities on industrial assets, generate recommendations for mitigating these vulnerabilities, and, where appropriate, deploy countermeasures to the vulnerable assets. By leveraging automated asset discovery, real-time asset and network monitoring, and generative AI-assisted vulnerability detection and remediation, the system can reduce the amount of time spent by security administrators in identifying and closing security vulnerabilities within their plant environments, and can alert administrators of potential security issues before those issues become critical.
Owner:ROCKWELL AUTOMATION TECH INC

Supply chain cross-packet vulnerability detection method and device, equipment and storage medium

The invention relates to the technical field of information processing, in particular to a supply chain cross-packet vulnerability detection method, device and equipment and a storage medium. A vulnerability packet name, a sensitive API, a trigger parameter and vulnerability description are integrated into tetrad information; if so, performing cross-packet call chain analysis on the source code file by using a cross-packet chain reachability analysis algorithm, obtaining a function call sequence of the sensitive API based on a cross-packet call chain analysis result, realizing vulnerability detection on a cross-packet call chain, generating a vulnerability verification code based on tetrad information by using a preset large language model, and performing vulnerability verification on the vulnerability verification code. The method comprises the following steps: establishing a function call sequence of a bug verification code, verifying the accessibility of the bug verification code in the function call sequence, determining the bug confidence according to the energy consumption condition of a large language model, and generating bug alarm information when the accessibility verification result is that the bug is accessible and the bug confidence is high, thereby realizing double judgment of the bug, reducing the false alarm rate of the bug and improving the user satisfaction.
Owner:JIHUA LAB

Systems and methods for advanced vulnerability detection and remediation within computer networks

A system for dynamic vulnerability detection and remediation is provided. The system includes a memory device and at least one processor coupled to the memory device. The at least one processor is programmed to: (a) store within a database an inventory of computer assets included within a computer ecosystem; (b) retrieve a vulnerability report including vulnerability definitions; (c) analyze the database to identify a potential vulnerability by comparing the computer assets stored within the database to the vulnerability definitions; (d) upon detecting the potential vulnerability, determine a service owner associated with the computer assets identified as being involved in the potential vulnerability; and (e) provide content to a user computing device associated with the service owner causing the user device to display a notification alert advising the service owner of the potential vulnerability and providing a remediation plan to address the potential vulnerability.
Owner:MASTERCARD INT INC

Large model agent configuration leakage vulnerability detection method and device

The invention relates to a large model agent configuration leakage vulnerability detection method and device, and the method comprises the steps: carrying out the tool pre-configuration according to the characteristic information of an online agent store, so as to generate tool pre-configuration information; respectively generating corresponding initial attack seeds for the cue word, the application programming interface and the knowledge base file leakage vulnerability; applying at least one variation strategy to the initial attack seed to bypass external and internal defense strategies of the intelligent agent, and determining a cue word after variation; interacting with the target web page by utilizing a preset automation framework to obtain the output of the intelligent agent; and detecting whether the output of the intelligent agent leaks the corresponding configuration or not by using the preset fine-tuned large model to obtain a detection result of the leakage vulnerability of the intelligent agent configuration of the large model. Therefore, the problems that existing work lacks an automatic detection mechanism for an online agent store, and lacks research and detection on leakage vulnerabilities of cue words, APIs and knowledge base files are solved.
Owner:TSINGHUA UNIVERSITY

Fuzzy test method and device, equipment, storage medium and product

The invention discloses a fuzzy testing method and device, equipment, a storage medium and a product, and the method comprises the steps: obtaining a target code, carrying out the static analysis of the target code, and determining the possible vulnerability information and vulnerability reachable path information of the target code; generating a test seed according to the possible vulnerability information and the vulnerability reachable path information; performing a fuzzy test on the target code through the test seed, determining vulnerabilities existing in the target code, and collecting dynamic feedback information in the fuzzy test process; and optimizing the test seed according to the dynamic feedback information, and returning to execute the step of performing the fuzzy test on the target code through the test seed until a preset test stop condition is met. According to the fuzzy test method disclosed by the invention, the dynamic feedback information is collected in each fuzzy test process, and the test seeds are optimized according to the dynamic feedback information, so that the test efficiency and accuracy can be improved, and finally efficient vulnerability detection and security evaluation are realized.
Owner:INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER +2

Code vulnerability detection method, device and equipment

The invention discloses a code vulnerability detection method, a code vulnerability rule configuration method, a static single assignment SSA code acquisition method, devices corresponding to the methods, and electronic equipment. The code vulnerability detection method comprises the following steps: acquiring a plurality of source code files and code vulnerability rules of an application program; generating an abstract syntax tree of the source code file, and obtaining a function call relationship; and traversing the abstract syntax tree, and obtaining a cross-function risk propagation path according to the function call relationship and the code vulnerability rule. By the adoption of the processing mode, the function calling relation and the abstract syntax tree are fused to conduct cross-function code vulnerability detection, cross-function vulnerability detection of context sensitivity, flow sensitivity and domain sensitivity is achieved, and vulnerability false report and missing report are avoided; therefore, the accuracy and recall rate of vulnerability detection can be effectively improved.
Owner:ALIBABA (CHINA) CO LTD

Automatic code auditing method and device, computer equipment and storage medium

The invention relates to an automatic code auditing method and device, computer equipment and a storage medium. The automatic code auditing method comprises the steps of obtaining a grammar structure, a control flow and a data flow of a to-be-audited code; constructing a context graph of the to-be-audited code according to the grammatical structure, the control flow and the data flow of the to-be-audited code; obtaining a multi-modal collaborative vulnerability detection method, wherein the multi-modal collaborative vulnerability detection method comprises a static analysis method based on rule matching, a symbolic execution method based on a code path, a large model reasoning method based on semantic understanding and weights of the methods; and identifying one or more code vulnerabilities, the vulnerability type of each code vulnerability and the confidence coefficient according to the context graph of the to-be-audited code and the multi-modal collaborative vulnerability detection method. According to the method, the audit codes of various vulnerability types can be processed while the code audit efficiency can be improved.
Owner:SHANGHAI SHUHE INFORMATION TECH CO LTD

Unauthorized vulnerability detection method, device and equipment and readable storage medium

The invention discloses an unauthorized vulnerability detection method, device and equipment and a readable storage medium, and is applied to the field of security detection, and the method comprises the steps: carrying out the semantic recognition of real business flow data through a large language model, and determining a to-be-detected interface; performing semantic analysis on the parameters of the to-be-detected interface by using a large language model to determine target parameters; extracting a parameter value with an unauthorized vulnerability risk in the target parameter from the historical real service flow data; generating a test effective load of the to-be-detected interface based on the target parameter and the parameter value by utilizing a large language model and a preset rule base; and performing unauthorized vulnerability detection on the to-be-detected interface by using the test payload, and determining a detection result. According to the method, the natural language understanding capability of a large language model is utilized, the limitation of traditional regularization preprocessing and effective load generation is broken through, and the method is adaptive to diversified scenes of a complex system.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Smart contract vulnerability detection method and device based on multi-modal features

The invention relates to the technical field of block chains, in particular to a smart contract vulnerability detection method and device based on multi-modal features, and the method mainly comprises the steps: training a meta-learning model in a dynamic adaptation module, and adjusting the global parameters of a modal feature extraction module, a dynamic gating fusion module and a classifier through the meta-learning model, the dynamic adaptation module comprises a meta-learning model constructed based on an MAML framework, and is used for optimizing global parameters of each module according to vulnerability features learned in pre-training; and inputting the multi-modal fusion feature vector into a classifier, and generating and outputting a vulnerability detection result of the smart contract. According to the method, known vulnerabilities can be accurately detected by fusing multi-modal features, and novel vulnerabilities can be rapidly adapted and detected.
Owner:SUN YAT SEN UNIV

Code vulnerability detection method based on multi-dimensional feature fusion and edge semantic enhancement

The invention discloses a code vulnerability detection method based on multi-dimensional feature fusion and edge semantic enhancement, and the method comprises the steps: carrying out AST sub-tree structure compression based on a sub-tree folding rule on the basis of retaining an AST high-level grammar framework, fusing a PDG data flow and control flow dependency relationship, and constructing a lightweight program semantic graph; extracting node multi-dimensional features from the program semantic graph, extracting program-level global features in combination with an edge semantic enhancement mechanism, and performing vectorization representation; and inputting the program semantic graph features into a full connection layer, identifying potential vulnerabilities and outputting a detection result. According to the scheme, a context modeling mechanism based on a scope path is introduced, a semantic subtree, a grammar structure and scope information are combined, multi-dimensional features are extracted, multi-dimensional information fusion is realized through a dynamic attention mechanism, local and global feature splitting is prevented, and the edge semantic enhancement module is constructed to realize multi-dimensional information fusion. And the distinguishing capability and the feature expression capability of the model on heterogeneous edges are improved.
Owner:CHENGDU UNIV OF INFORMATION TECH

Network security vulnerability detection method and system based on artificial intelligence

The invention belongs to the technical field of network security vulnerability detection, and relates to a network security vulnerability detection method and system based on artificial intelligence, and the method comprises the steps: extracting structured and unstructured feature fields of a target protocol data packet from network traffic in real time, and carrying out the syntax tree analysis of the structured feature fields to generate a nested hierarchical feature vector; generating a dominant abnormal confidence coefficient through positive and negative sample comparison of the feature vector, performing time sequence state tracking and dynamic qualification verification on the unstructured feature field, generating a hidden abnormal confidence coefficient, judging the existence of the network security vulnerability by integrating the dominant abnormal confidence coefficient and the hidden abnormal confidence coefficient, if the judgment result is yes, identifying vulnerability attributes, and if the judgment result is no, identifying the network security vulnerability. A blocking strategy corresponding to known vulnerabilities or novel vulnerabilities is triggered, accurate identification and efficient response of a network protocol level to security vulnerability threats are realized, and the threats are effectively intercepted at a network communication bottom layer, so that safe and stable operation of a network is guaranteed.
Owner:JINAN VOCATIONAL COLLEGE +1

Computer code vulnerability detection method and system based on artificial intelligence

The invention relates to a computer code vulnerability detection method and system based on artificial intelligence, and the method comprises the steps: obtaining a detection demand input by a user, analyzing the detection demand based on a natural language processing algorithm, and extracting a target source code set corresponding to the detection demand from a to-be-detected code warehouse; performing standardization processing on the target source code set, and constructing a code feature data set; inputting the code feature data set into the trained vulnerability detection model, identifying to obtain a vulnerability code snippet, and generating a vulnerability score and a vulnerability type; and grading the vulnerability code snippets according to the vulnerability scores, generating repair suggestions in combination with vulnerability types, and outputting a corresponding detection report which comprises risk levels and the repair suggestions. The method has the effect of improving the accuracy of vulnerability detection.
Owner:BEIJING SHENZHOU EVERBRIGHT TECH CO LTD

Chain reasoning hidden backdoor vulnerability detection method for vision-language-action model

The invention relates to the field of personal intelligent security evaluation, and particularly discloses a chain reasoning hidden backdoor vulnerability detection method of a vision-language-action model, which comprises the following steps of: respectively injecting micro pixel disturbance and rare character marks into vision and language input; on the basis of model autoregression prediction characteristics, designing a hybrid reasoning chain fusing normal reasoning steps and abnormal backdoor branches; adopting prefix tuning to take the hybrid reasoning sequence as a pluggable prefix injection model; and generating the vulnerability sensitivity of the abnormal action instruction through the systematic verification process detection model. Compared with an existing method, the method has the advantages that a nondestructive testing mechanism based on prefix adjustment and optimization does not need to modify model parameters or depend on training data, and the safety and reproducibility of detection are guaranteed; a multi-mode triggering mechanism is constructed, and the hidden vulnerability of the model in a complex scene is effectively revealed; the abnormal branches and the normal process are fused in a chain mode, and the defense capability of the model for the concealment logic offset can be systematically evaluated.
Owner:HUNAN UNIV

Source code vulnerability detection method combining static and dynamic analysis

The invention discloses a static and dynamic analysis-combined source code vulnerability detection method, which comprises the following steps of: performing static scanning on an input source code, and preliminarily positioning potential vulnerabilities according to a preset vulnerability rule base; executing program slicing based on the control flow diagram and the data flow diagram, and extracting a precise code subset related to the vulnerability; a large language model based on a Transform structure is utilized, and a dynamic verification attack case is automatically generated according to the vulnerability type and the slice code; executing the test case in a sandbox environment, monitoring program abnormal behaviors in real time, and confirming actual availability of vulnerabilities; and finally, synthesizing static and dynamic results to generate a multi-level vulnerability detection report. According to the method, the accuracy and coverage rate of vulnerability detection can be effectively improved, the false report and missing report rate is reduced, high automation and intelligence of the source code vulnerability detection process are realized, and the method has good applicability and popularization value.
Owner:GUANGDONG POWER GRID CO LTD +1

Notebook software vulnerability scanning method and system based on security policy

The invention relates to a notebook software vulnerability scanning method based on a security policy. According to the method, firstly, a security policy library of a target notebook is obtained, and the security policy library comprises access control rules, data operation limiting conditions and vulnerability detection reference requirements for different software types; collecting software running data of the target notebook computer, wherein the software running data comprises current running process information, file system operation records, network connection states and software configuration parameters; performing matching analysis on the software operation data and the security policy library to generate a preliminary scanning result; evaluating the risk level of the software vulnerability according to the preliminary scanning result; and finally, based on the risk level and the repair guide terms in the security policy library, generating software vulnerability repair guide information. Therefore, notebook software vulnerabilities can be scanned comprehensively and accurately, and effective repair guidance is provided.
Owner:SHENZHEN ZHUO CHUANG INTELLIGENT TECH CO LTD

Vulnerability detection method and system based on semantic sensitive contrast learning and graph representation

The invention discloses a vulnerability detection method and system based on semantic sensitive contrast learning and graph representation, and belongs to the technical field of vulnerability detection.The method comprises the steps that source codes and transformed codes are input into a vulnerability detection model to be processed, and a vulnerability classification result is obtained; the vulnerability detection model comprises a semantic learning module, a graph representation learning module, a feature fusion module and a support vector machine; wherein the construction process of the vulnerability detection model comprises the following steps: taking a source code and a transformed code as a positive sample pair for comparative learning to obtain code semantic feature embedding; the source code is represented as a graph structure, the graph structure is processed, and then code structure feature embedding is obtained; and performing feature fusion on the code semantic feature embedding and the code structure feature embedding to obtain fusion vectors, and classifying the fusion vectors to obtain a vulnerability classification result. The model is guided to learn semantics related to vulnerabilities through comparative learning, and meanwhile, the accuracy of vulnerability detection is improved in combination with grammatical structure features of codes.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1

Cross-language application program vulnerability mining method based on static analysis

The invention discloses a cross-language application program vulnerability mining method based on static analysis, which adopts a nested cross-programming language pointer analysis method and a micro-service cross-programming language taint tracking method to effectively solve the limitation of processing nested cross-language control flow and micro-service cross-language data flow. A nested language semantic boundary is accurately positioned by constructing a nested byte code, and a data stream is completely tracked by utilizing an interface relay technology, so that the detection precision is improved. According to the method, part of multi-end data streams and complex control streams of cross-programming language applications can be uniformly processed, and the analysis process in a cross-programming language environment is simplified; by nesting cross-programming language control flow diagram construction and double-end / multi-end data flow diagram construction, a unified analysis framework is constructed, seamless cooperation of static analysis among different languages is achieved, the analysis cost is reduced, the analysis efficiency is improved, efficient and accurate vulnerability mining is achieved in a complex cross-programming language application program, and the method is suitable for application and popularization. And the reliability of cross-language vulnerability detection is improved.
Owner:XIDIAN UNIV