The invention discloses a
risk identification method based on an environment
open source component, and relates to the technical field of
network security, and the method comprises the steps: collecting heterogeneous data of the
open source component in a development, deployment and operation environment, carrying out the
semantic alignment of the heterogeneous data, and generating a
semantic vector set with a unified dimension; inputting the
semantic vector set into a multi-environment
risk identification model, focusing on risk
semantics of development, deployment and operation environment generality, and generating a risk tag; based on a cross-
modal self-attention mechanism, performing dynamic weighting on the development, deployment and operation environment features to generate context feature vectors; constructing an environment component association
graph based on the context
feature vector, and modeling a risk propagation path by using a graph
attention network; and based on the risk propagation weight matrix, the risk tag and the environment component association graph, calculating a dynamic risk
score, and generating a multi-environment fusion risk
score list. According to the method, through a multi-environment
risk identification model, codes and dependency features are extracted, general risk
semantics are focused, and accurate risk tags are generated.