With the rapid development of information technology,audit objects and audit itself are more and more inseparable from software.As an important means of software security audit,code security audit will become an impor...With the rapid development of information technology,audit objects and audit itself are more and more inseparable from software.As an important means of software security audit,code security audit will become an important aspect of future audit that cannot be ignored.However,the existing code security audit ismainly based on source code,which is difficult to meet the audit needs of more and more programming languages and binary commercial software.Based on the idea of normalized transformation,this paper constructs a cross language code security audit framework(CLCSA).CLCSA first uses compile/decompile technology to convert different highlevel programming languages and binary codes into normalized representation,and then usesmachine learning technology to build a cross language code security audit model based on normalized representation to evaluate code security and find out possible code security vulnerabilities.Finally,for the discovered vulnerabilities,the heuristic search strategy will be used to find the best repair scheme from the existing normalized representation sample library for automatic repair,which can improve the effectiveness of code security audit.CLCSA realizes the normalized code security audit of different types and levels of code,which provides a strong support for improving the breadth and depth of code security audit.展开更多
数字化浪潮下,软件供应链安全成为支撑数字经济安全稳定发展的必要环节.系统综述软件供应链安全检测评估技术体系,从软件成分分析(software component analysis,SCA)、软件物料清单(software bill of material,SBOM)、依赖关系追溯等核...数字化浪潮下,软件供应链安全成为支撑数字经济安全稳定发展的必要环节.系统综述软件供应链安全检测评估技术体系,从软件成分分析(software component analysis,SCA)、软件物料清单(software bill of material,SBOM)、依赖关系追溯等核心技术出发,针对软件检测和评价中关键的技术——组件分析、漏洞扫描、代码审查等,分析当前面临的问题与解决思路,再通过国内外最新的研究成果和应用案例进行对比论述,结合兴业证券SCA治理平台、中国电信SBOM管理平台等典型实践,并就SLSA框架、GitHub依赖图谱等新兴前沿技术发展状况进行分析.在此基础上针对该领域的技术发展现状及产业需要展望技术融合与协同、智能化与自动化、全生命周期覆盖等未来10年发展10大趋势.展开更多
基金This work was supported by the Universities Natural Science Research Project of Jiangsu Province under Grant 20KJB520026the Natural Science Foundation of Jiangsu Province under Grant BK20180821.
摘要With the rapid development of information technology,audit objects and audit itself are more and more inseparable from software.As an important means of software security audit,code security audit will become an important aspect of future audit that cannot be ignored.However,the existing code security audit ismainly based on source code,which is difficult to meet the audit needs of more and more programming languages and binary commercial software.Based on the idea of normalized transformation,this paper constructs a cross language code security audit framework(CLCSA).CLCSA first uses compile/decompile technology to convert different highlevel programming languages and binary codes into normalized representation,and then usesmachine learning technology to build a cross language code security audit model based on normalized representation to evaluate code security and find out possible code security vulnerabilities.Finally,for the discovered vulnerabilities,the heuristic search strategy will be used to find the best repair scheme from the existing normalized representation sample library for automatic repair,which can improve the effectiveness of code security audit.CLCSA realizes the normalized code security audit of different types and levels of code,which provides a strong support for improving the breadth and depth of code security audit.
摘要数字化浪潮下,软件供应链安全成为支撑数字经济安全稳定发展的必要环节.系统综述软件供应链安全检测评估技术体系,从软件成分分析(software component analysis,SCA)、软件物料清单(software bill of material,SBOM)、依赖关系追溯等核心技术出发,针对软件检测和评价中关键的技术——组件分析、漏洞扫描、代码审查等,分析当前面临的问题与解决思路,再通过国内外最新的研究成果和应用案例进行对比论述,结合兴业证券SCA治理平台、中国电信SBOM管理平台等典型实践,并就SLSA框架、GitHub依赖图谱等新兴前沿技术发展状况进行分析.在此基础上针对该领域的技术发展现状及产业需要展望技术融合与协同、智能化与自动化、全生命周期覆盖等未来10年发展10大趋势.