Applied Mathematics and Nonlinear Sciences
Journal license

Journal

Applied Mathematics and Nonlinear Sciences


Volume
& Issue

Volume 9, Issue 1


Published
on

January 31, 2024


Pages


DOI

Article

Effective Application of Artificial Intelligence Techniques in Security Risk Assessment and Dependency Analysis of Open Source Components

Check for updates


Authors

Jian Hu Affiliation:
Information Center, China Southern Power Grid Yunnan Power Grid Co., Ltd., Kunming, Yunnan, 650217, China.
, Zhiyu Zhao Affiliation:
Information Center, China Southern Power Grid Yunnan Power Grid Co., Ltd., Kunming, Yunnan, 650217, China.
, Feilu Hang Affiliation:
Information Center, China Southern Power Grid Yunnan Power Grid Co., Ltd., Kunming, Yunnan, 650217, China.
and Jun Yin Affiliation:
Information Center, China Southern Power Grid Yunnan Power Grid Co., Ltd., Kunming, Yunnan, 650217, China.


Abstract

With the wide application of open source software, the security of open source components has become a non-negligible problem in software development. In this paper, based on the research on deep learning algorithms, the deep reinforcement learning algorithm DQN is proposed, and the DQN-LightGBM model is constructed by combining LightGBM classifiers to achieve better mining performance. This model introduces the attention mechanism and BiLSTM network, and the TextACBL vulnerability identification algorithm is proposed. In the end, the performance of the open source component vulnerability mining model is evaluated to investigate its impact on vulnerability identification, risk assessment, and dependency analysis of open source components. The results show that the performance of DQN-LightGBM model is above 0.9 in accuracy, checking accuracy, checking completeness, AUC value, and F1, and the mining completion time is only 54s, which is the best. The accuracy of TextACBL model in identifying the types of vulnerabilities is above 94%, and the vulnerability danger levels on the seven items measured are high, low, high, high, and high risk, respectively, medium risk, high risk, and medium risk. The differences in the global graph features of the identified normal and vulnerability samples are obvious, and there are frequent dependencies in the probability graphs of the opcodes of the vulnerability samples. This study allows for the assessment of security risks of open source components and the comprehensive, accurate, and efficient conduct of dependency analysis.


Keywords

DQN-LightGBM model, TextACBL model, Open source components, Risk assessment, Dependency analysis, 68T01


Citation

Hu, J., Zhao, Z., Hang, F., & Yin, J. (2024). Effective application of artificial intelligence techniques in security risk assessment and dependency analysis of open source components. Applied Mathematics and Nonlinear Sciences, 9(1). https://doi.org/10.2478/amns-2024-0040
1 Total citations
0.61 FWCI
1 Recent citations
(2 years)
24 References
Open Access Yes
View full metrics

Published by: Engineering Journals

Engineering Journals Logo