The invention relates to the technical field of
information processing, in particular to a supply chain cross-packet
vulnerability detection method, device and equipment and a storage medium. A
vulnerability packet name, a sensitive API, a trigger parameter and
vulnerability description are integrated into tetrad information; if so, performing cross-packet call chain analysis on the
source code file by using a cross-packet chain
reachability analysis
algorithm, obtaining a function call sequence of the sensitive API based on a cross-packet call chain analysis result, realizing
vulnerability detection on a cross-packet call chain, generating a vulnerability
verification code based on tetrad information by using a preset large
language model, and performing vulnerability
verification on the vulnerability
verification code. The method comprises the following steps: establishing a function call sequence of a bug verification code, verifying the
accessibility of the bug verification code in the function call sequence, determining the bug confidence according to the
energy consumption condition of a large
language model, and generating bug alarm information when the
accessibility verification result is that the bug is accessible and the bug confidence is high, thereby realizing double judgment of the bug, reducing the
false alarm rate of the bug and improving the
user satisfaction.