IP Library Granted Patent US 11,880,471
Granted Patent B2
US 11,880,471 · App. 18/012,927 · Granted Jan 23, 2024

Password hardcoding checking method and apparatus based on PCA, and medium

Inventor: Lihua Yan (Jiangsu, CN)
Assignee: INSPUR SUZHOU INTELLIGENT TECHNOLOGY CO., LTD.
G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,880,471
App. No.
18/012,927
Granted
Jan 23, 2024
Kind
B2
Abstract

A password hardcoding checking method and apparatus based on PCA, and a medium. the checking method includes: step one, data collection, involving: collecting function code blocks in which data of password hardcoding that is subject to a false alarm is located; step two, extracting feature values in the function code blocks collected in step one, so as to obtain a feature set; step three, using the function code blocks collected in step one to serve as samples to construct a PCA model; and step four, on the basis of the PCA model constructed in step three and the feature set obtained in step two, detecting whether there is a false alarm in password hardcoding. by means of the method, the false alarm rate of hardcoding checking in code scanning is reduced, and the working efficiency of a developer and a code auditor is improved.

Claims (182)

1. A PCA-based password hard-coding detection method, comprising:

Step 1, performing data collection by collecting a function code block where password hard-coding false alarm data is located;

Step 2, extracting feature values in the function code blocks collected in Step 1 to obtain a feature set;

Step 3, constructing a PCA model by utilizing the function code blocks collected in Step 1 as samples; and

Step 4, detecting whether a false alarm for password hard-coding exists based on the PCA model constructed in Step 3 and the feature set obtained in Step 2;

wherein Step 3 comprises:

Step 3.1, under a condition that the function code blocks collected in Step 1 are samples, a quantity of which is n, and n is an integer greater than 0; and each sample comprises m types of attributes, and m is an integer greater than 0, extracting a group of feature sets F from each sample to obtain F=(F 1 , F 2 . . . F m ), wherein F m represents an m th attribute of the sample;

Step 3.2, calculating a covariance matrix C;

Step 3.3. acquiring feature values of the covariance matrix C and corresponding feature vectors by adopting singular value decomposition; and

Step 3.4, arranging the feature vectors into a matrix U from top to bottom according to a size of the corresponding feature values by rows.

2. The PCA-based password hard-coding detection method according to claim 1 , wherein in Step 1, according to an actual project code of code scanning of fortify, the password hard-coding false alarm data is detected; the function code blocks, in which the password hard-coding false alarm data is located, are collected; and the function code blocks are initial sample data.

3. The PCA-based password hard-coding detection method according to claim 1 , wherein in Step 2, the extracted feature values in the function code blocks comprise a code length, a type of a function return value, a type of a return value for calling a key, a quantity of times of calling the key in abnormal codes, a quantity of keywords comprised in the code blocks, and a quantity of keywords comprised in notes.

4. The PCA-based password hard-coding detection method according to claim 3 , wherein the key is a variable assigned as a specific character string in a function.

5. The PCA-based password hard-coding detection method according to claim 3 , wherein the keywords comprised in the code blocks comprise but not limited to: ‘key’, ‘password’, ‘pwd’, ‘passwd’, ‘encryption’, ‘decrypt’, ‘generate’, ‘Secure Hash Algorithm 256 SHA256’ and ‘Advanced Encryption Standard AES’ or ‘Data Encryption Standard DES’.

6. The PCA-based password hard-coding detection method according to claim 3 , wherein the type of the return value for calling the key comprises at least one of a character string, a Boolean and an object.

7. The PCA-based password hard-coding detection method according to claim 1 , wherein Step 3.2 comprises:

φ

i

=

F

i

-

1

n

j

=

1

n

F

j

,

wherein φ i is a φ value of an i th feature, a value range of i is [1, m], and Fj is a j th attribute of the sample, a value range of j is [1, n]; and

C

=

1

m

X

X

T

,

X

=

(

φ

11

φ

1

m

φ

n

1

φ

nm

)

,

wherein φ nm is a φ value of an m th feature of an n th sample.

8. The PCA-based password hard-coding detection method according to claim 1 , wherein Step 4 comprises:

Step 4.1, extracting feature values for a code segment to-be-detected by utilizing a method in Step 2 to obtain a feature set;

Step 4.2, calculating a distance d from the feature set obtained in Step 4.1 to the matrix U; and

Step 4.3, setting a threshold σ, wherein on a condition that the distance calculated in Step 4.2 is within the threshold range belongs to a false alarm.

9. The PCA-based password hard-coding detection method according to claim 8 , wherein the feature set obtained in Step 4.1 is a 1*m matrix F=(F 1 , F 2 . . . F m ), the matrix U is a m*m matrix, and the distance d obtained by calculation is:

d

=

i

=

1

m

1

=

1

m

(

F

j

-

U

j

i

)

2

,

wherein Fj is a value of a j th column in the matrix F, and U ji is a value of a j th row and an i th column in the matrix U.

10. The PCA-based password hard-coding detection method according to claim 1 , wherein φ is a common variable and represents a value after a feature value is standardized.

11. A Principal Component Analysis (PCA)-based password hard-coding detection device, comprising:

a processor; and a memory, storing a computer program that is executed by a processor, and upon execution by the processor, is configured to cause the processor to:

collect the data and collecting the function code blocks, in which the password hard-coding false alarm data is located;

extract the feature values of the function code blocks to obtain the feature set;

construct the PCA model; and

detect whether the false alarm for password hard-coding exists;

wherein Step 3 comprises:

Step 3.1. under a condition that the function code blocks collected in Step 1 are samples, a quantity of which is n, and n is an integer greater than 0; and each sample comprises m types of attributes, and m is an integer greater than 0, extracting a group of feature sets F from each sample to obtain F=(F 1 , F 2 . . . F m ), wherein F m represents an m th attribute of the sample.

Step 3.2, calculating a covariance matrix C;

Step 3.3, acquiring feature values of the covariance matrix C and corresponding feature vectors by adopting singular value decomposition; and

Step 3.4, arranging the feature vectors into a matrix U from top to bottom according to a size of the corresponding feature values by rows.

12. The PCA-based password hard-coding detection device according to claim 11 , wherein in Step 1, according to an actual project code of code scanning of fortify, the password hard-coding false alarm data is detected; the function code blocks, in which the password hard-coding false alarm data is located, are collected; and the function code blocks are initial sample data.

13. The PCA-based password hard-coding detection device according to claim 11 , wherein in Step 2, the extracted feature values in the function code blocks comprise a code length, a type of a function return value, a type of a return value for calling a key, a quantity of times of calling the key in abnormal codes, a quantity of keywords comprised in the code blocks, and a quantity of keywords comprised in notes.

14. The PCA-based password hard-coding detection device according to claim 13 , wherein the key is a variable assigned as a specific character string in a function.

15. The PCA-based password hard-coding detection device according to claim 13 , wherein the keywords comprised in the code blocks comprise but not limited to: ‘key’, ‘password’, ‘pwd’, ‘passwd’, ‘encryption’, ‘decrypt’, ‘generate’, ‘Secure Hash Algorithm 256 SHA256’ and ‘Advanced Encryption Standard AES’ or ‘Data Encryption Standard DES’.

16. The PCA-based password hard-coding detection device according to claim 11 , wherein Step 3.2 comprises:

φ

i

=

F

i

-

1

n

j

=

1

n

F

j

,

wherein φ i is a φ value of an i th feature, a value range of i is [1, m], and Fj is a j th attribute of the sample, a value range of j is [1, n]; and

C

=

1

m

X

X

T

,

X

=

(

φ

11

φ

1

m

φ

n

1

φ

nm

)

,

wherein φ nm is a φ value of an m th feature of an n th sample.

17. The PCA-based password hard-coding detection device according to claim 11 , wherein Step 4 comprises:

Step 4.1, extracting feature values for a code segment to-be-detected by utilizing a method in Step 2 to obtain a feature set;

Step 4.2, calculating a distance d from the feature set obtained in Step 4.1 to the matrix U; and

Step 4.3, setting a threshold σ, wherein on a condition that the distance calculated in Step 4.2 is within the threshold range belongs to a false alarm.

18. A non-transitory computer-readable storage medium, storing a computer program that is executed by a processor, and upon execution by the processor, is configured to cause the processor to implement operations comprising:

Step 1, collecting data and collecting function code blocks in which password hard-coding false alarm data is located;

Step 2, extracting feature values in the function code blocks collected in Step 1 to obtain a feature set;

Step 3, constructing a Principal Component Analysis (PCA) model by utilizing the function code blocks collected in Step 1 as samples; and

Step 4, detecting whether a false alarm for password hard-coding exists based on the PCA model constructed in Step 3 and the feature set obtained in Step 2;

wherein Step 3 comprises:

Step 3.1. under a condition that the function code blocks collected in Step 1 are samples, a quantity of which is n, and n is an integer greater than 0; and each sample comprises m types of attributes, and m is an integer greater than 0, extracting a group of feature sets F from each sample to obtain F=(F 1 , F 2 . . . F m ), wherein F m represents an m th attribute of the sample;

Step 3.2, calculating a covariance matrix C;

Step 3.3, acquiring feature values of the covariance matrix C and corresponding feature vectors by adopting singular value decomposition; and

Step 3.4. arranging the feature vectors into a matrix U from top to bottom according to a size of the corresponding feature values by rows.

Assignments (2)
LICENSE Recorded Jun 30, 2026
From: IEIT SYSTEMS CO., LTD
To: AIVRES SYSTEMS INC.
Reel/Frame 075857/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 25, 2022
From: YAN, LIHUA
To: INSPUR SUZHOU INTELLIGENT TECHNOLOGY CO., LTD.
Reel/Frame 062199/0707 →
Priority Claims (1)
CN 202010917043.1 · Sep 3, 2020 · national
Continuity (1)
Related Publication 20230195903A1 · Jun 22, 2023