CN113987522B - 一种用于源代码漏洞检测的代码属性图压缩方法及装置 - Google Patents
一种用于源代码漏洞检测的代码属性图压缩方法及装置 Download PDFInfo
- Publication number
- CN113987522B CN113987522B CN202111637333.1A CN202111637333A CN113987522B CN 113987522 B CN113987522 B CN 113987522B CN 202111637333 A CN202111637333 A CN 202111637333A CN 113987522 B CN113987522 B CN 113987522B
- Authority
- CN
- China
- Prior art keywords
- node
- nodes
- graph
- candidate
- code
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 230000006835 compression Effects 0.000 title claims abstract description 47
- 238000007906 compression Methods 0.000 title claims abstract description 47
- 238000000034 method Methods 0.000 title claims abstract description 43
- 238000001514 detection method Methods 0.000 title claims description 24
- 238000010606 normalization Methods 0.000 claims abstract description 15
- 238000012545 processing Methods 0.000 claims abstract description 14
- 238000012217 deletion Methods 0.000 claims abstract description 9
- 230000037430 deletion Effects 0.000 claims abstract description 9
- 239000011159 matrix material Substances 0.000 claims description 24
- 230000007704 transition Effects 0.000 claims description 12
- 238000004364 calculation method Methods 0.000 claims description 7
- 230000002776 aggregation Effects 0.000 claims description 4
- 238000004220 aggregation Methods 0.000 claims description 4
- 230000006870 function Effects 0.000 claims description 4
- 230000001174 ascending effect Effects 0.000 claims description 3
- 238000012549 training Methods 0.000 abstract description 8
- 230000008569 process Effects 0.000 description 7
- 238000010586 diagram Methods 0.000 description 4
- 238000004458 analytical method Methods 0.000 description 3
- 238000005516 engineering process Methods 0.000 description 3
- 238000005259 measurement Methods 0.000 description 3
- 230000009466 transformation Effects 0.000 description 3
- 230000009286 beneficial effect Effects 0.000 description 2
- 230000003068 static effect Effects 0.000 description 2
- 238000006243 chemical reaction Methods 0.000 description 1
- 238000004891 communication Methods 0.000 description 1
- 238000013135 deep learning Methods 0.000 description 1
- 230000007547 defect Effects 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000002349 favourable effect Effects 0.000 description 1
- 238000002513 implantation Methods 0.000 description 1
- 238000010801 machine learning Methods 0.000 description 1
- 238000012216 screening Methods 0.000 description 1
- 238000006467 substitution reaction Methods 0.000 description 1
- 230000001131 transforming effect Effects 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/577—Assessing vulnerabilities and evaluating computer system security
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
- G06F21/563—Static detection by source code analysis
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/03—Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
- G06F2221/033—Test or assess software
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computing Systems (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Compression, Expansion, Code Conversion, And Decoders (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Abstract
Description
Claims (7)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202111637333.1A CN113987522B (zh) | 2021-12-30 | 2021-12-30 | 一种用于源代码漏洞检测的代码属性图压缩方法及装置 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202111637333.1A CN113987522B (zh) | 2021-12-30 | 2021-12-30 | 一种用于源代码漏洞检测的代码属性图压缩方法及装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN113987522A CN113987522A (zh) | 2022-01-28 |
CN113987522B true CN113987522B (zh) | 2022-05-03 |
Family
ID=79734938
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202111637333.1A Active CN113987522B (zh) | 2021-12-30 | 2021-12-30 | 一种用于源代码漏洞检测的代码属性图压缩方法及装置 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN113987522B (zh) |
Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN113822315A (zh) * | 2021-06-17 | 2021-12-21 | 深圳市腾讯计算机系统有限公司 | 属性图的处理方法、装置、电子设备及可读存储介质 |
Family Cites Families (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US10803061B2 (en) * | 2018-07-31 | 2020-10-13 | Veracode, Inc. | Software vulnerability graph database |
US20210279338A1 (en) * | 2020-03-04 | 2021-09-09 | The George Washington University | Graph-based source code vulnerability detection system |
CN111783100B (zh) * | 2020-06-22 | 2022-05-17 | 哈尔滨工业大学 | 基于图卷积网络对代码图表示学习的源代码漏洞检测方法 |
CN112699377B (zh) * | 2020-12-30 | 2023-04-28 | 哈尔滨工业大学 | 基于切片属性图表示学习的函数级代码漏洞检测方法 |
-
2021
- 2021-12-30 CN CN202111637333.1A patent/CN113987522B/zh active Active
Patent Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN113822315A (zh) * | 2021-06-17 | 2021-12-21 | 深圳市腾讯计算机系统有限公司 | 属性图的处理方法、装置、电子设备及可读存储介质 |
Also Published As
Publication number | Publication date |
---|---|
CN113987522A (zh) | 2022-01-28 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
RU2697955C2 (ru) | Система и способ обучения модели обнаружения вредоносных контейнеров | |
RU2654146C1 (ru) | Система и способ обнаружения вредоносных файлов с использованием элементов статического анализа | |
US9983984B2 (en) | Automated modularization of graphical user interface test cases | |
US20130151536A1 (en) | Vertex-Proximity Query Processing | |
CN111552969A (zh) | 基于神经网络的嵌入式终端软件代码漏洞检测方法及装置 | |
CN106682514B (zh) | 基于子图挖掘的系统调用序列特征模式集生成方法 | |
CN111767547B (zh) | 一种基于复杂网络社团的软件漏洞检测方法 | |
CN116579618B (zh) | 基于风险管理的数据处理方法、装置、设备及存储介质 | |
CN116305158A (zh) | 一种基于切片代码依赖图语义学习的漏洞识别方法 | |
JPWO2018092237A1 (ja) | プログラムコード生成装置、プログラムコード生成方法及びプログラムコード生成プログラム | |
CN113228017A (zh) | 攻击树生成装置、攻击树生成方法以及攻击树生成程序 | |
EP4191470A1 (en) | Feature selection method and device, network device and computer-readable storage medium | |
CN113987522B (zh) | 一种用于源代码漏洞检测的代码属性图压缩方法及装置 | |
CN109032946B (zh) | 一种测试方法和装置、计算机可读存储介质 | |
CN116229535A (zh) | 人脸检测模型的训练方法、人脸检测方法及装置 | |
CN112906824B (zh) | 车辆聚类方法、系统、设备及存储介质 | |
CN114281691A (zh) | 测试用例排序方法、装置、计算设备及存储介质 | |
CN113850395A (zh) | 一种数据处理方法及系统 | |
CN112750047A (zh) | 行为关系信息提取方法及装置、存储介质、电子设备 | |
US20230419145A1 (en) | Processor and method for performing tensor network contraction in quantum simulator | |
JP2019160008A (ja) | プログラム分析装置及びプログラム分析方法 | |
US20230325664A1 (en) | Method and apparatus for generating neural network | |
CN113378543B (zh) | 数据分析方法、训练数据分析模型的方法及电子设备 | |
CN117609870B (zh) | 结构识别模型训练、模型结构识别方法、设备及介质 | |
CN117114087B (zh) | 故障预测方法、计算机设备和可读存储介质 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
CB03 | Change of inventor or designer information |
Inventor after: Gao Cuiyun Inventor after: Xu Guoai Inventor after: Chen Yupan Inventor after: Wang Xuan Inventor after: Liu Chuanyi Inventor after: Liao Qing Inventor after: Han Peiyi Inventor after: Chen Yujia Inventor before: Gao Cuiyun Inventor before: Chen Yupan Inventor before: Wang Xuan Inventor before: Liu Chuanyi Inventor before: Liao Qing Inventor before: Han Peiyi Inventor before: Chen Yujia |
|
CB03 | Change of inventor or designer information |