Automobile part information safety evaluation system based on multi-dimensional penetration test

The automotive parts information security assessment system, which uses multi-dimensional penetration testing, collects and dynamically adjusts security parameters in real time, solving the problems of insufficient accuracy and timeliness of assessment results in traditional assessment methods. It achieves personalized security assessment and rapid response for automotive parts, and improves the system's adaptability and intelligence.

CN120611385AInactive Publication Date: 2025-09-09NAT IND INFORMATION SECURITY DEV RES CENT
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202511103344.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2025-09-09
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional information security assessment methods for automotive components are based on single-dimensional testing and fixed parameters, and are unable to adapt to the complex and changing network security environment. This results in insufficient accuracy and timeliness of assessment results, and makes it impossible to accurately assess the personalized security needs of components. Furthermore, there is a lack of multi-dimensional penetration testing and dynamic parameter adjustment strategies.

Method used

An automotive parts information security assessment system based on multi-dimensional penetration testing is adopted, including a penetration test data acquisition module, a vulnerability analysis module, a security event monitoring module, a parameter matching module and a response execution module. Through real-time data collection, dynamic adjustment of security parameters and self-learning optimization, personalized security assessment and rapid response of automotive parts are achieved.

Benefits of technology

The real-time, accuracy and intelligence level of the assessment system have been improved, and it can accurately assess the personalized safety needs of different components, quickly respond to security incidents, form a virtuous cycle of "assessment-adjustment-learning-optimization", and enhance the system's adaptability and protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120611385A_ABST
    Figure CN120611385A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of automobile part information security evaluation, and discloses an automobile part information security evaluation system based on a multi-dimensional penetration test, and the system comprises a data collection module, a vulnerability analysis module, an event monitoring module, a parameter matching module, a response execution module and a self-learning module. The data acquisition module acquires test data in real time, and generates a dynamic adjustment set of vulnerability severity feature values and security parameters; the vulnerability analysis module generates a personalized security parameter and a dynamic penetration control strategy based on the feature value; the event monitoring module screens abnormal event data; the parameter matching module determines a target adjustment parameter through multi-dimensional matching; the response execution module drives the safety equipment to correct parameters; and the self-learning module updates the security parameters by using the feedback data. The system realizes dynamic evaluation and self-adaptive protection of automobile part information safety, improves the safety protection level, and is suitable for the technical field of automobile part information safety evaluation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of automobile component information security assessment, and in particular to an automobile component information security assessment system based on multi-dimensional penetration testing. Background Art

[0002] With the rapid development of intelligent and connected vehicles, the information security of automotive components is becoming increasingly prominent. Traditional automotive component information security assessment methods, mostly based on single-dimensional testing and fixed-parameter security strategies, are unable to adapt to the complex and ever-changing cybersecurity environment and diverse component security requirements.

[0003] From a technological perspective, early assessment systems primarily relied on static vulnerability scanning and simple rule matching, failing to perceive dynamic risk changes in components during penetration testing. For example, traditional systems lacked effective initial parameter calibration mechanisms for newly connected automotive components, making it difficult to accurately establish their security signature models. For previously connected devices, they also failed to fully leverage historical security data to dynamically adjust assessment parameters, resulting in inaccurate and ineffective assessment results.

[0004] In practice, automotive components operate in complex and diverse environments, and components from different batches and models may face different security threats. Traditional assessment systems, lacking multi-dimensional penetration testing and dynamic parameter adjustment strategies, are unable to accurately assess the individual security needs of components. For example, during vulnerability analysis, traditional methods are unable to dynamically generate adaptive penetration control strategies based on vulnerability severity characteristics, resulting in delayed responses to high-risk vulnerabilities and inaccurate handling.

[0005] Furthermore, traditional systems also suffer from significant shortcomings in security event monitoring and parameter matching. Real-time security event data collected by multi-source sensors cannot be effectively and multi-dimensionally matched with security parameters, making it difficult to quickly and accurately identify abnormal events and determine appropriate adjustment parameters. Furthermore, the lack of an effective parameter self-learning mechanism prevents optimization and updating of security parameters based on historical adjustment data, resulting in low levels of system adaptability and intelligence.

[0006] As automotive cybersecurity standards continue to improve, higher requirements are being placed on the real-time, accurate, intelligent, and personalized security assessment systems for automotive components. Traditional single-dimensional, static assessment methods are no longer able to meet current technical requirements. A new assessment system based on multi-dimensional penetration testing, capable of dynamic adjustment of security parameters and self-learning, is urgently needed to improve the security protection level of automotive components and ensure the healthy development of intelligent and connected vehicles. Summary of the Invention

[0007] The purpose of the present invention is to provide an automobile parts information security assessment system based on multi-dimensional penetration testing to solve the problems raised in the above background technology.

[0008] To achieve the above objectives, the present invention provides the following technical solution: an automobile parts information security assessment system based on multi-dimensional penetration testing, the system comprising: A penetration test data acquisition module is used to collect penetration test data and vulnerability status data of automotive parts in real time through security test terminal equipment, analyze and process them to generate vulnerability severity characteristic values ​​and risk dynamic parameter characteristic values, and generate a dynamic adjustment set of security parameters based on the initial security parameter set stored in the security database; The vulnerability analysis module processes the personalized security parameters of the current batch of automotive parts based on the vulnerability severity characteristic values ​​and generates a dynamic penetration control strategy; The security event monitoring module is used to obtain real-time security event data during the penetration test of automotive parts through multi-source sensors, filter out abnormal event data that meets the dynamic adjustment range, and send it to the parameter matching module; The parameter matching module is used to perform multi-dimensional matching between abnormal event data and each parameter item in the dynamic adjustment set of security parameters, generate the matching degree between real-time data and each security parameter item, and select the security parameter corresponding to the highest matching degree as the target adjustment parameter; The response execution module is used to receive the target adjustment parameters and call the response adjustment protocol preset in the security database to drive the security device to execute the parameter correction operation.

[0009] Preferably, the real-time collection of penetration test data of automobile parts by the security test terminal device is carried out as follows: Identify the unique identification code of the automotive parts. If it is a newly connected device, collect basic security parameters including initial vulnerability scanning intensity, penetration test frequency baseline value and permission control range, establish security feature nodes based on the initial data, perform parameter calibration, and generate vulnerability severity feature values; If it is a historical access device, the historical security data set and vulnerability change curve of the device are extracted. The historical security data set includes scan fluctuation extremes, frequency deviation records and permission control delay duration, and is marked as the initial parameter set for the current security analysis.

[0010] Preferably, generating a dynamic adjustment set of security parameters based on an initial security parameter set stored in a security database specifically includes: Extracting an initial standard set and a dynamic correction coefficient set of each security parameter from a security database, wherein the initial standard set includes: a vulnerability scanning intensity safety range, a frequency fluctuation tolerance interval, and an authority adjustment reference value; The dynamic correction coefficient set includes a scanning intensity compensation coefficient, a frequency gradient adjustment coefficient and an authority response weight parameter; Based on the real-time risk dynamic parameter characteristic value, the initial standard set of each security parameter is dynamically adjusted, and the adjusted parameter set is recorded as the security parameter dynamic adjustment set; The security parameter dynamic adjustment set includes a scanning dynamic range, a frequency adaptability threshold, and an authority optimization control value of each parameter item.

[0011] Preferably, the processing based on the vulnerability severity characteristic value to obtain personalized security parameters of the current batch of automotive parts and generate a dynamic penetration control strategy specifically includes: Based on the vulnerability severity characteristic value, pattern matching is performed with the preset penetration test feature library to determine the priority list for security parameter adjustment; An adaptive control strategy including parameter triggering conditions, adjustment step rules and fault handling mechanism is generated based on the adjustment priority list.

[0012] Preferably, the method of acquiring real-time security event data during the penetration test of automobile parts through multi-source sensors specifically includes: Monitor the real-time event data stream of the security vulnerability formation process, including the change value of the number of vulnerabilities, event uniformity index and risk fluctuation value; When the real-time event data stream exceeds the preset qualified safety range, the abnormal mark is activated and the event data of the abnormal period is extracted as effective monitoring data.

[0013] Preferably, the matching degree between the generated real-time data and each security parameter item specifically includes: Analyze the quantity deviation, uniformity change gradient, and risk fluctuation amplitude in abnormal event data, and perform differential calculations with the scanning dynamic range, frequency adaptability threshold, and authority optimization control value of each security parameter; Based on the difference calculation results, a matching index between real-time data and each security parameter item is generated.

[0014] Preferably, the step of selecting the security parameter corresponding to the highest matching degree as the target adjustment parameter specifically includes: Create a matching ranking list of each security parameter item and select the parameter item with the highest matching degree in the list; If the first matching degree is lower than the preset adjustment trigger threshold, the backup parameter set is called and the matching degree is recalculated.

[0015] Preferably, the matching index between the real-time data and each security parameter item is generated based on the difference calculation result, and the specific processing process is as follows: A multi-dimensional matching algorithm is used to standardize the scan difference, frequency gradient and authority deviation to generate a safety parameter matching value ranging from 0 to 100. The matching value is used to indicate the adaptability of real-time data to security parameters.

[0016] Preferably, the system further includes a parameter self-learning module, specifically including: Record security vulnerability feedback data after each parameter adjustment, including actual vulnerability uniformity, incident control effects, and risk suppression changes; The feedback data is reversely verified with the dynamic adjustment set of security parameters to generate parameter correction factors and update the dynamic correction coefficient set in the security database.

[0017] Preferably, the system generates a parameter correction factor, specifically comprising: Calculate the scan compensation factor, frequency adjustment factor, and authority optimization weight based on the deviation between the feedback data and the expected security target; The exponentially weighted average algorithm is used to dynamically smooth the historical correction factors to generate a new set of dynamic correction coefficients.

[0018] Compared with the prior art, the present invention has the following beneficial effects: In terms of data collection and parameter calibration, the system can identify unique identification codes for newly accessed devices, collect basic security parameters and establish security feature nodes, generate vulnerability severity characteristic values ​​through the first data calibration, and ensure the accuracy of the initial assessment parameters; for historical access devices, it extracts historical security data sets and vulnerability change curves as the initial parameter set, making full use of historical data to achieve continuity and dynamism in the assessment, avoiding the drawbacks of the traditional method of "one size fits all" assessment strategy for new and old equipment.

[0019] The vulnerability analysis and dynamic policy generation module determines a priority list for security parameter adjustments based on pattern matching between vulnerability severity signatures and a penetration testing signature library. This prioritizes trigger conditions, adjustment steps, and troubleshooting mechanisms. This mechanism enables differentiated handling based on vulnerability severity, prioritizing high-risk vulnerabilities. This improves the targeted and efficient nature of vulnerability handling and avoids the delayed response to complex vulnerability scenarios often associated with traditional fixed policies.

[0020] The security event monitoring and parameter matching function uses multi-source sensors to collect real-time data streams such as vulnerability quantity changes and event uniformity indicators. When a situation exceeds a safe range, it activates anomaly flags and extracts valid monitoring data. By analyzing indicators such as quantity deviation and uniformity gradient in anomaly data, and performing multi-dimensional difference calculations and matching analysis with the dynamically adjusted set of security parameters, it can quickly locate the security parameters that best match the real-time anomaly. This creates a rapid response closed loop from event monitoring to parameter adjustment, shortening the time interval for anomaly processing and improving the real-time performance and effectiveness of the system.

[0021] The response execution module invokes the preset response adjustment protocol based on the parameter matching results, driving the security device to execute parameter correction operations. This seamlessly integrates the assessment results with security protection measures, ensuring the effective implementation of the adjustment strategy. The parameter self-learning module records vulnerability feedback data after parameter adjustment, performs reverse verification, and generates parameter correction factors. It uses an exponentially weighted average algorithm to dynamically update the dynamic correction coefficient set, enabling the system to continuously optimize assessment parameters based on historical experience, forming a virtuous cycle of "assessment-adjustment-learning-optimization." This continuously improves the system's adaptability and intelligence, resolving the problem of traditional systems with fixed parameters and an inability to self-evolve. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 This is an overall flow chart of the automobile parts information security assessment system based on multi-dimensional penetration testing according to the present invention; Figure 2 A flowchart of the penetration testing data collection process; Figure 3 A flowchart for real-time security event data monitoring; Figure 4 Flowchart for target adjustment parameter selection; Figure 5 Flowchart generated for parameter correction factors; Figure 6 This is a historical trend chart of the number of device vulnerabilities; Figure 7 A histogram showing the delay duration of permission control. DETAILED DESCRIPTION

[0023] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0024] See also Figure 1-Figure 7The present invention relates to an automotive parts information security assessment system based on multi-dimensional penetration testing. The system includes a penetration test data acquisition module, a vulnerability analysis module, a security event monitoring module, a parameter matching module, and a response execution module. Specifically, the system includes the following steps: A penetration test data acquisition module is used to collect penetration test data and vulnerability status data of automotive parts in real time through security test terminal equipment, analyze and process them to generate vulnerability severity characteristic values ​​and risk dynamic parameter characteristic values, and generate a dynamic adjustment set of security parameters based on the initial security parameter set stored in the security database; The vulnerability analysis module processes the personalized security parameters of the current batch of automotive parts based on the vulnerability severity characteristic values ​​and generates a dynamic penetration control strategy; The security event monitoring module is used to obtain real-time security event data during the penetration test of automotive parts through multi-source sensors, filter out abnormal event data that meets the dynamic adjustment range, and send it to the parameter matching module; The parameter matching module is used to perform multi-dimensional matching between abnormal event data and each parameter item in the dynamic adjustment set of security parameters, generate the matching degree between real-time data and each security parameter item, and select the security parameter corresponding to the highest matching degree as the target adjustment parameter; The response execution module is used to receive the target adjustment parameters and call the response adjustment protocol preset in the security database to drive the security device to execute the parameter correction operation.

[0025] The present invention will be further described below in conjunction with Examples 1 to 5: Example 1: When the penetration test data acquisition module in the system collects penetration test data of automobile parts in real time through security test terminal equipment, its specific implementation method involves the identification and processing of the unique identification code of automobile parts, as well as different data collection strategies and parameter generation logic for new access devices and historical access devices.

[0026] The core operation of this module begins with the recognition of the unique identification code of an automotive part. This unique identification code serves as the identifier of the automotive part within the system. It is unique and uses specific encoding rules to ensure that the system accurately distinguishes between different parts and devices. In practice, the security test terminal device uses a built-in identification module, such as a barcode scanner or RFID reader, to read the identification code on the automotive part. This reading process can be contactless or contactless, depending on the type of identification code and the device design.

[0027] After identifying the unique identification code of an automotive part, the system proceeds to determine whether the device is newly connected or has been previously connected. This determination is typically based on whether the identification code exists in the security database. If the security database does not contain relevant information for the identification code, the device is considered newly connected. At this point, the module initiates the basic security parameter collection process for the new device.

[0028] Specifically, the basic security parameters collected include the initial vulnerability scanning intensity, the penetration test frequency baseline value, and the permission control range. The initial vulnerability scanning intensity refers to the initial scanning strength used when performing a vulnerability scan on a new device. It determines the comprehensiveness and depth of the scan. For example, it can be set to different levels such as lightweight scanning, medium intensity scanning, or full deep scanning. The penetration test frequency baseline value stipulates the basic time interval for penetration testing of the new device, such as once a day, twice a week, etc. This baseline value provides an initial basis for subsequent test frequency adjustments. The permission control range clarifies the range of resources that the new device can access and operate in the system, including read and write permissions for different data files, and permissions to use system functions.

[0029] After completing the collection of basic security parameters, the module will establish a security feature node based on the data collected for the first time. The security feature node is an abstract representation of the security attributes of the new device. It integrates and structures the collected parameters to form a node model that can reflect the initial security status of the device. After the security feature node is established, the system will perform parameter calibration. Parameter calibration is to compare the collected initial parameters with the standard parameter range preset by the system, and adjust the parameters that exceed the reasonable range to ensure that they meet the basic security requirements of the system. For example, if the initial vulnerability scan intensity is set too high, it may affect the normal operation of the device. In this case, the system will adjust it to the appropriate intensity level based on the preset standard range. Through parameter calibration, it is ensured that the generated vulnerability severity characteristic value can accurately reflect the initial security vulnerability severity of the new device.

[0030] However, when a historical access device is identified, meaning that a historical record of this identification code exists in the security database, the module will take a different approach. At this point, the module will extract the device's historical security dataset and vulnerability change curve from the security database. The historical security dataset contains multiple key data items, including the scan fluctuation extremes, which record the maximum and minimum scan intensity of the device during previous penetration tests, reflecting the range of variation in scan intensity. The frequency deviation record stores the deviation between the actual penetration test frequency and the preset frequency baseline value, which is used to analyze the stability of the test frequency. The permission control delay duration records the delay time when performing permission control operations on the device, reflecting the efficiency of permission management.

[0031] The vulnerability change curve is generated based on historical security data. It uses time as the horizontal axis and indicators such as vulnerability number and severity as the vertical axis to visually display the evolution of a device's vulnerabilities over a historical period. By analyzing the vulnerability change curve, you can understand how the device's security status changes over time, such as whether there has been a sudden increase in the number of vulnerabilities or an upward trend in vulnerability severity.

[0032] After extracting historical security data sets and vulnerability change curves, the module marks these data as the initial parameter set for the current security analysis. This historical data provides an important reference for the current security analysis, allowing the system to conduct more targeted security assessments and parameter adjustments based on the device's historical performance, rather than relying solely on a unified initial standard.

[0033] Throughout the data collection and processing process, the module ensures real-time and accuracy. Real-time collection means that as vehicle components operate and penetration testing proceeds, the module continuously acquires the latest test data and vulnerability status information, promptly updating security feature nodes and related parameters. Accuracy is ensured through various methods, including calibration of collection equipment, verification during data transmission, and filtering and correction of abnormal data.

[0034] Furthermore, the module features real-time interaction with a secure database. As new data is collected, the processed results are promptly stored in the secure database for easy access and reference by other modules. Required historical data and preset parameters are also retrieved from the secure database, ensuring the consistency and reliability of the entire data collection and processing process.

[0035] The penetration test data acquisition module can accurately and in real time collect and process penetration test data for different types of automotive parts and equipment, providing reliable data support for subsequent vulnerability analysis, security incident monitoring and other modules, thereby achieving comprehensive assessment and effective management of automotive parts information security.

[0036] like Figure 6, showing the changing trend of the number of vulnerabilities in historical devices over a 30-day testing cycle, is the system's core monitoring indicator for the evolution of the security status of historical devices. As can be observed from the figure, the number of vulnerabilities showed an upward trend in the early stages of the test, reaching a peak on the 8th day, indicating that the device had many security risks in the initial stage. Subsequently, the system activated the security protection mechanism, and the number of vulnerabilities began to fluctuate and decline, reaching its lowest point on the 22nd day. This changing trend intuitively reflects the effectiveness of the implementation of security measures. The two key points marked in the figure (peak and valley) are important security event nodes identified by the system. The peak usually indicates the time when a new attack or vulnerability is discovered, while the valley reflects the optimal state of security protection. By analyzing this changing curve, the system can predict future security risk trends and take protective measures in advance.

[0037] like Figure 7 , which records the historical device permission control delay over a 30-day period and is a key indicator for evaluating system response efficiency. The data shows that the average permission control delay is 0.268 seconds, meeting the real-time requirements of automotive electronic systems (typically <0.5 seconds). However, the chart also shows significant fluctuations, with a particularly unusual peak (0.47 seconds) on day 22, attributed to excessive system load or network latency. Permission control delay directly impacts system security; excessive latency can allow attackers to exploit time differences to perform unauthorized operations. By continuously monitoring this metric, the system can promptly identify performance bottlenecks and optimize permission management mechanisms. The red dashed line in the figure represents the historical average latency level, providing a visual reference benchmark for security operations personnel.

[0038] Example 2: The penetration test data acquisition module generates a dynamically adjusted set of security parameters based on the initial set of security parameters stored in the security database. This involves extracting basic parameters from the database, adjusting the parameters using dynamic correction coefficients, and finally forming a complete logical chain of dynamic parameter sets. This process relies on the security database's storage structure and real-time data interaction mechanism to ensure the scientific and adaptable nature of parameter adjustments.

[0039] The module needs to extract two types of core data sets from the security database, namely the initial standard set of each security parameter and the dynamic correction coefficient set. The initial standard set is the basic parameter framework preset by the system, which includes the vulnerability scanning intensity safety range, the frequency fluctuation tolerance interval and the authority adjustment reference value. Among them, the vulnerability scanning intensity safety range defines the upper and lower limits of the scanning intensity allowed for different types of automotive parts under normal conditions. For example, different intensity ranges may be set for the engine control unit and the in-vehicle entertainment system to avoid affecting the operation of key components due to excessive scanning intensity; the frequency fluctuation tolerance interval stipulates the reasonable range of the penetration test frequency deviation from the baseline value. For example, when the baseline frequency is once a day, a fluctuation range of ±1 time / week is allowed to adapt to the needs of different test scenarios; the authority adjustment reference value clarifies the authority allocation standards for various types of equipment in the initial state, such as the default range division of manufacturer management authority and maintenance personnel operation authority.

[0040] The dynamic correction coefficient set is the key parameter used to adjust the initial standard set, including the scan intensity compensation coefficient, the frequency gradient adjustment coefficient, and the permission response weight parameter. The scan intensity compensation coefficient is used to dynamically compensate the scan intensity according to the real-time risk situation. For example, when a new vulnerability is detected, this coefficient can trigger an increase in scan intensity; the frequency gradient adjustment coefficient controls the adjustment gradient of the test frequency as the risk changes, ensuring the refinement of the frequency adjustment; the permission response weight parameter is used to measure the priority of different permission control operations and determine the order of permission adjustment when multiple events are concurrent. These correction coefficients are not fixed values, but dynamic parameters that are updated in real time based on historical test data, industry security standards, and system operating status. They are stored in a dedicated table structure in the security database to facilitate quick module retrieval.

[0041] After extracting the two sets mentioned above, the module dynamically adjusts the initial standard set based on the real-time risk dynamic parameter eigenvalues. These eigenvalues ​​are generated in real time by the penetration test data acquisition module and reflect the current security risk landscape facing automotive components. These eigenvalues ​​include multi-dimensional metrics such as vulnerability growth rate, frequency of risk events, and difficulty of exploitation. For example, if a component develops multiple high-risk vulnerabilities within a short period of time, the vulnerability growth rate indicator within the risk dynamic parameter eigenvalues ​​will significantly increase. At this point, the module activates a dynamic correction mechanism based on this eigenvalue.

[0042] During the specific adjustment process, the module will process each parameter in the initial standard set separately. For the vulnerability scanning intensity safety range, the module will calculate the current required intensity adjustment range based on the correlation between the scanning intensity compensation coefficient and the risk dynamic parameter characteristic value. For example, if the compensation coefficient is 0.8, and the vulnerability severity index in the risk characteristic value exceeds the baseline value by 20%, the upper limit of the scanning intensity safety range will be increased by 16% (0.8×20%) to enhance the scanning depth; for the frequency fluctuation tolerance range, the module will expand or shrink the original tolerance range through the frequency gradient adjustment coefficient. When the risk characteristic value shows that the system stability has decreased, the tolerance range will be narrowed to improve the monitoring accuracy of the test frequency; for the permission adjustment baseline value, the module will reallocate the priority of each permission item based on the permission response weight parameter. For example, when it is detected that the remote control permission has been abnormally called, the permission response weight parameter will increase the control weight of the permission, thereby narrowing its operational range within the baseline value.

[0043] The adjusted parameter set is the dynamic security parameter adjustment set, which includes the scanning dynamic range, frequency adaptability threshold, and permission optimization control value for each parameter item. The scanning dynamic range is the real-time effective range adjusted based on the initial security range and the risk characteristic value. For example, the original range of [20, 80] may be adjusted to [30, 90]. The frequency adaptability threshold is the critical test frequency value determined based on the current risk situation. When the actual frequency exceeds this threshold, an early warning mechanism is triggered. The permission optimization control value is the result of dynamically optimizing the permission adjustment baseline value. For example, the read permission of a certain type of sensitive data can be reduced from "all maintenance personnel" to "senior maintenance engineers."

[0044] Throughout the parameter adjustment process, the module must ensure the real-time and accurate data exchange. On the one hand, the module continuously retrieves the latest set of initial standards and dynamic correction coefficients from the security database to prevent parameter adjustment delays due to untimely database updates. On the other hand, the adjusted dynamic adjustment set of security parameters is transmitted back to the security database in real time for use by other system components such as the vulnerability analysis module and the parameter matching module. To ensure the reliability of data transmission, the system utilizes an encrypted transmission protocol and verification mechanism to prevent parameter tampering or loss during the interaction process.

[0045] Furthermore, this implementation is both adaptable and scalable. Adaptability is reflected in the automatic optimization of dynamic correction coefficients based on historical adjustment results. For example, if a scan intensity adjustment based on a compensation coefficient effectively reduces the vulnerability miss rate, the system will appropriately increase the weight of that coefficient. Scalability is also reflected in the structural design of the initial standard set and the dynamic correction coefficient set. When new automotive component types are added or new security threats emerge, new parameter items and correction coefficients can be added by expanding the database table structure without requiring large-scale modifications to the core module logic.

[0046] The penetration test data acquisition module dynamically generates an adaptive set of security parameters based on real-time risk conditions, ensuring that the system's penetration testing strategy consistently matches the actual security requirements of automotive components. This process not only considers the baseline role of initial security standards but also enables real-time parameter optimization through a dynamic correction mechanism, thereby enhancing the information security assessment system's adaptability to complex security environments and providing precise parameter support for subsequent vulnerability analysis and security incident response.

[0047] Example 3: The vulnerability analysis module obtains personalized security parameters for the current batch of automotive parts based on vulnerability severity characteristic values ​​and generates a dynamic penetration control strategy. It is closely related to the process of the security event monitoring module obtaining real-time security event data through multi-source sensors. The two form a complete link from vulnerability feature analysis to event data collection in the system.

[0048] The vulnerability analysis module begins processing by receiving a vulnerability severity signature value, generated by the penetration test data acquisition module. This value reflects the vulnerability's impact on the information security of automotive components. The module first performs a pattern match between the vulnerability severity signature value and a pre-set penetration test signature library. The penetration test signature library stores characteristic patterns for different types of vulnerabilities, such as buffer overflow vulnerabilities and authentication vulnerabilities, each with its own corresponding feature vector. The matching process is achieved by calculating the similarity between the vulnerability severity signature value and each pattern in the signature library. The similarity calculation formula is: , in, Represents the similarity value, is the number of feature dimensions, For the The weight of the feature, The severity characteristic value of the vulnerability The actual value of the feature, is the standard value of the corresponding feature in the penetration test feature library, and are the standard maximum and minimum values ​​of the feature respectively. The weight is set based on the impact of the feature on the severity of the vulnerability. For example, the weight corresponding to the difficulty of exploiting the vulnerability will be higher than the weight corresponding to the time of vulnerability discovery.

[0049] Through pattern matching, the module determines a priority list for security parameter adjustments. Priorities are determined based on a comprehensive assessment of similarity and vulnerability impact. For example, a high-risk vulnerability with high similarity receives a higher priority than a medium-risk vulnerability with low similarity. This priority list clarifies the order in which security parameter adjustments should be made, providing a basis for the subsequent generation of dynamic penetration control strategies.

[0050] Based on the adjustment priority list, the module generates an adaptive control strategy consisting of parameter trigger conditions, adjustment step rules, and a fault handling mechanism. The parameter trigger conditions define the thresholds for initiating security parameter adjustments. For example, when the similarity of a certain vulnerability exceeds 80%, the corresponding parameter adjustment is triggered. The adjustment step rules specify the specific process for parameter adjustment, including the adjustment range and interval. For example, increasing the scan intensity to the target value in three steps, with each increase lasting 10 minutes. The fault handling mechanism specifies the response measures for abnormal situations during the adjustment process. If the adjustment timeout occurs, the parameter state is rolled back to the last valid state.

[0051] The security event monitoring module obtains real-time security event data during the penetration test of automotive parts through multi-source sensors. Multi-source sensors include vulnerability monitoring sensors, network traffic sensors, and log recording sensors deployed inside automotive parts, which are used to collect different types of security event data.

[0052] The module monitors the real-time event data stream of the security vulnerability formation process, where the vulnerability number change value is the number of new vulnerabilities per unit time, such as the number of new vulnerabilities per hour; the event uniformity index is used to measure the balance of event occurrence, which is obtained by calculating the ratio of the standard deviation of the number of events per unit time to the mean; the risk fluctuation value reflects the change in the risk level and is calculated based on the real-time monitoring data of the risk indicators.

[0053] When the real-time event data stream exceeds the preset qualified safety range, the module activates the anomaly flag and extracts the event data during the abnormal period as valid monitoring data. The qualified safety range is determined by the relevant parameters in the dynamic adjustment set of security parameters. For example, the qualified range of vulnerability change value is [0, 5] per hour. If the value reaches 7 per hour within a certain period, it is considered out of range. The anomaly flag contains information such as the timestamp of the anomaly, the anomaly type, and the severity of the anomaly, which facilitates subsequent tracing.

[0054] During data collection, multi-source sensors continuously collect data at a preset sampling frequency. This frequency is determined by the safety level and criticality of vehicle components; for example, the engine control unit has a higher sampling frequency than the onboard audio system. The collected data is initially filtered locally to remove obvious errors or duplications before being transmitted to the safety event monitoring module for further processing.

[0055] The module analyzes the collected real-time event data stream in real time, segmenting the data using sliding window technology. The length of each window is set based on monitoring requirements, for example, 5 minutes. Within each window, the real-time value of each indicator is calculated and compared against a qualified safety range. If an out-of-range condition is detected, an anomaly flagging mechanism is triggered immediately.

[0056] The extracted event data for the abnormal period includes the complete data sequence from the period before the abnormality to the period after the abnormality, ensuring data integrity and analyzability. For example, if the abnormality occurred between 10:00 and 10:10, all event data from 9:50 to 10:20 would be extracted. This valid monitoring data is encapsulated into a specific data structure containing fields such as timestamp, sensor type, event type, and event parameters, and then sent to the parameter matching module for subsequent processing.

[0057] The vulnerability analysis module and the security event monitoring module interact via a standardized data interface. The dynamic penetration control strategy generated by the vulnerability analysis module is transmitted to the security event monitoring module in real time, serving as one of the criteria for determining abnormal events. For example, the scanning frequency adjustment range set in the control strategy can affect the qualified safety range of the event uniformity indicator.

[0058] Throughout the implementation process, the module ensures real-time and accurate data collection, enhancing data collection reliability through redundant sensors and data verification mechanisms. If a sensor fails, the system automatically switches to a backup sensor to continue collecting data and logs the failure information for easy repair. Furthermore, the module regularly calibrates sensors to ensure the accuracy of collected data.

[0059] Example 4: When the parameter matching module generates the matching degree between real-time data and various security parameter items, it is necessary to first perform a multi-dimensional analysis of the abnormal event data and calculate the difference with the parameter items in the dynamic adjustment set of security parameters to form a matching index; when selecting the target adjustment parameters, it is necessary to ensure the accuracy and reliability of the parameter adjustment by establishing a sorting list and a backup parameter calling mechanism.

[0060] Taking the penetration test of an in-vehicle communication module as an example, if the security event monitoring module detects five new high-risk vulnerabilities within 30 minutes, and the change in the number of vulnerabilities exceeds a preset range, it transmits abnormal event data, including the number deviation, uniformity gradient, and risk fluctuation range, to the parameter matching module. The module first analyzes the abnormal event data: the number deviation is the difference between the actual number of new vulnerabilities and the standard value. Assuming the standard value is 2 / 30 minutes, the deviation is +3. The uniformity gradient is calculated by calculating the fluctuation range of the event frequency per unit time. For example, if the module originally generated 0.5 vulnerabilities every 10 minutes, but now generates 2 vulnerabilities in 10 minutes, the gradient change is (2-0.5) / 0.5=3. The risk fluctuation range is calculated based on the change in the vulnerability severity characteristic value. For example, if the proportion of high-risk vulnerabilities increases from 10% to 40%, the fluctuation range is 30%.

[0061] Next, the module calculates the difference between this parsed data and the parameters in the security parameter dynamic adjustment set. The scanning dynamic range, frequency adaptability threshold, and permission optimization control value in the security parameter dynamic adjustment set are adjusted based on the real-time risk dynamic parameter characteristic values. Assume that the current scanning dynamic range is [30, 90] (representing the percentage of scanning intensity), the frequency adaptability threshold allows fluctuations of ±1 vulnerability every 30 minutes, and the permission optimization control value limits the frequency of remote control permission operations to no more than 5 times per minute.

[0062] For a quantity deviation of +3, the difference from the frequency adaptability threshold of ±1 is +2; the difference between the uniformity gradient of 3 and the baseline value for the scanning dynamic range adjustment gradient (for example, a baseline gradient of 1.5) is 1.5; and the difference between the risk fluctuation range of 30% and the risk response coefficient in the authority optimization control value (for example, a preset coefficient of 20%) is 10%. These difference calculations reflect the degree of deviation between real-time data and security parameters. The smaller the difference, the higher the degree of match.

[0063] Based on the difference calculation results, the module generates a match index between real-time data and each security parameter. This match index is generated using a multi-dimensional weighting mechanism, where differences in different dimensions are weighted according to their impact on the security assessment. For example, the weight of quantity deviation is 40%, the weight of uniformity gradient is 35%, and the weight of risk fluctuation is 25%. Assuming the match index for quantity deviation is 70 points (the difference + 2 corresponds to a certain scoring rule), the uniformity gradient is 80 points, and the risk fluctuation is 75 points, the overall match index is 70 × 40% + 80 × 35% + 75 × 25% = 74.75 points. During this process, the match index for each parameter is derived through a similar weighting calculation to form the match index for each security parameter.

[0064] When selecting the security parameter with the highest match as the target adjustment parameter, the module creates a ranked list of security parameters based on their matching scores. Assuming the current security parameters include the scan intensity adjustment parameter, the test frequency adjustment parameter, and the access control adjustment parameter, with matching scores of 74.75, 68, and 72, respectively, the scan intensity adjustment parameter is ranked first in the ranked list, and the module selects it as the target adjustment parameter.

[0065] If the first match score is lower than the preset adjustment trigger threshold (such as 70 points), the module calls the backup parameter set and recalculates the match score. For example, if the first match score is 65 points, the module calls the backup parameter set from the security database. This set contains parameters preset based on historical security data and similar vulnerability scenarios, such as backup scan intensity adjustment parameters and frequency compensation parameters. The module then recalculates the difference between the abnormal event data and the backup parameter items and re-evaluates the match score until a parameter item with a match score above the threshold is found.

[0066] In practical applications, the parameter matching module's processing flow must work in conjunction with the real-time update mechanism of the dynamically adjusted security parameter set. This set is updated as penetration test data changes. For example, if the number of vulnerabilities in the vehicle communication module continues to increase, the scanning dynamic range may be adjusted to [40,100], and the frequency adaptability threshold may be reduced to ±0.5 vulnerabilities / 30 minutes. In this case, the module must retrieve the latest parameter set in real time when performing difference calculations to ensure the accuracy of the matching degree calculation.

[0067] As another example, during a penetration test of an automotive electronic control unit, an abnormal permission call event occurred. The risk fluctuation in the abnormal event data was 25%, the uniformity gradient was 2, and the quantity deviation was +1. The permission optimization control value in the security parameter dynamic adjustment set limits the call frequency of sensitive operation permissions to 3 times per minute, with a scanning dynamic range of [25, 85] and a frequency adaptability threshold of ±1.5 vulnerabilities / 30 minutes. After difference calculation, the difference in the permission optimization control value was 25% - 20% (preset risk response factor) = 5%, the difference between the uniformity gradient and the scanning dynamic range baseline gradient of 1.8 was 0.2, and the difference between the quantity deviation and the frequency adaptability threshold was 0. After weighted calculation, the matching degree of the permission optimization control parameter was 85 points, the scanning intensity adjustment parameter was 78 points, and the test frequency adjustment parameter was 70 points. The module selected the permission optimization control parameter as the target adjustment parameter, triggering the adjustment of the permission control policy.

[0068] The parameter matching module also needs to have data caching and historical matching record query capabilities. The caching mechanism temporarily stores recent abnormal event data and matching results, allowing for recovery in the event of a brief system failure. Historical matching records provide a basis for optimizing parameter adjustment strategies. For example, by analyzing the adjustment effects of highly matched parameters in historical records, the weight distribution of each dimension can be optimized.

[0069] Throughout the implementation process, the module's data parsing, calculation, and matching are based on standardized data formats and processing procedures, ensuring unified processing of abnormal event data for different types of automotive parts. Furthermore, data exchange between the module and the secure database is conducted through an encrypted channel, ensuring the security of parameter information and matching results, preventing malicious tampering or theft.

[0070] Example 5: The parameter self-learning module in the system records the security vulnerability feedback data after parameter adjustment, and reversely verifies it with the dynamic adjustment set of security parameters to generate parameter correction factors and update them to the security database to achieve self-optimization of system parameters.

[0071] Taking a penetration test of an in-vehicle entertainment system as an example, when the response execution module increases the scanning intensity based on the target adjustment parameters, the parameter self-learning module initiates the feedback data recording process. Assuming that before the adjustment, the system detected 8 vulnerabilities within 30 minutes, and after the adjustment, the scanning intensity was increased from 60% to 75%, the module would record the security vulnerability feedback data after the adjustment, including actual vulnerability uniformity, event control effectiveness, and risk suppression changes. Actual vulnerability uniformity is reflected in the time interval of vulnerability distribution within 30 minutes after the adjustment. For example, originally, 5 vulnerabilities appeared in 10-20 minutes, but after the adjustment, they were evenly distributed throughout the entire 30 minutes, with 2-3 vulnerabilities appearing every 10 minutes. The event control effectiveness is reflected in the change in the frequency of abnormal events. For example, before the adjustment, 3 permission abnormal events were triggered per hour, but after the adjustment, it dropped to 1. The risk suppression change is reflected in the change in the proportion of high-risk vulnerabilities, for example, from 30% before the adjustment to 15%.

[0072] Feedback data records must follow a standardized data structure, including fields such as the adjustment timestamp, adjustment parameter type, parameter value before adjustment, parameter value after adjustment, and feedback data collection time interval. For example, in the feedback record for the scan intensity adjustment, the timestamp is 14:30 on June 10, 2025, the parameter type is scan intensity, the value before adjustment is 60%, the value after adjustment is 75%, the collection time interval is 14:30-15:00, and the actual vulnerability uniformity is recorded as 2, 3, and 2 vulnerabilities per 10 minutes. The event control effect is 1 permission abnormality event, and the risk suppression change is that the proportion of high-risk vulnerabilities is 15%.

[0073] After recording the feedback data, the module reverse-verifies it against the security parameter dynamic adjustment set. The security parameter dynamic adjustment set stores parameters such as the adjusted scanning dynamic range and frequency adaptability threshold. For example, if the adjusted scanning dynamic range is [50,80], the module needs to verify whether the actual vulnerability uniformity and event control effect are within the expected effect of this dynamic range. The reverse verification process includes data comparison and effect evaluation: data comparison is to compare the number and distribution of vulnerabilities in the feedback data with the preset expected values ​​in the dynamic adjustment set. For example, the number of vulnerabilities should be reduced to 5-7 within 30 minutes after the preset adjustment, but the actual number is 7, which is in line with expectations; the effect evaluation uses expert rules or historical data models to determine whether the adjustment has achieved the purpose of suppressing risks. For example, a 15% decrease in the proportion of high-risk vulnerabilities is judged to be effective suppression.

[0074] Based on the reverse verification results, the module generates a parameter correction factor. During the generation process, the scan compensation factor, frequency adjustment factor, and permission optimization weight are first calculated based on the degree of deviation between the feedback data and the expected security goal. Assuming that the expected security goal is to reduce the proportion of high-risk vulnerabilities to 10% after adjustment, and it actually drops to 15%, with a deviation of 5%, the scan compensation factor needs to be adjusted according to the degree of deviation. For example, if a deviation of 1% corresponds to an increase of 0.1 in the compensation factor, the compensation factor here is increased by 0.5. The calculation of the frequency adjustment factor and the permission optimization weight is similar. If the test frequency does not achieve the expected stability after adjustment, the frequency adjustment factor will be adjusted accordingly; if the permission control effect does not meet expectations, the permission optimization weight will be redistributed.

[0075] After generating the parameter correction factors, the module dynamically smooths the historical correction factors using an exponentially weighted average algorithm to generate a new set of dynamic correction coefficients. For example, if the historical scan compensation factor is 0.8, the current calculated compensation factor is 1.3, and the smoothing coefficient is set to 0.7, the new scan compensation factor is 0.7 × 0.8 + (1 - 0.7) × 1.3 = 0.95. This algorithm assigns higher weight to recent correction factors, allowing the dynamic correction coefficient set to respond more quickly to the latest feedback data while retaining the influence of historical experience and avoiding drastic fluctuations in the correction factors.

[0076] Once a new set of dynamic correction coefficients is generated, it is updated to the security database's dynamic correction coefficient set for use by the penetration test data collection module, parameter matching module, and other modules. For example, if the updated scan intensity compensation coefficient changes from 0.8 to 0.95, when a similar vulnerability occurs again, the penetration test data collection module will generate a dynamic security parameter adjustment set based on the new compensation coefficient, ensuring that the scan intensity adjustment range is more aligned with actual needs.

[0077] Taking the example of adjusting the access control of a certain automobile engine control unit, the response execution module reduced the remote control access frequency limit from 8 to 5 per minute based on target adjustment parameters. The parameter self-learning module then recorded the feedback data after the adjustment: the actual number of access exceptions dropped from 4 to 2 within an hour, but one high-risk operation remained unblocked. Comparing this feedback data with the access optimization control value (expected to reduce the number of exceptions to less than 1) in the dynamic security parameter adjustment set revealed a discrepancy. When calculating the access optimization weight, the module factored in the failure to intercept high-risk operations and increased the weight coefficient of the interception rule. For example, the original weight was adjusted from 0.6 to 0.75. Using an exponentially weighted average algorithm and combining the historical weight of 0.65, a new access response weight parameter of 0.72 was generated. After updating this weight to the security database, the next access control adjustment prioritized the interception rule for high-risk operations.

[0078] The implementation of the parameter self-learning module requires an efficient data storage and retrieval mechanism. A dedicated feedback data table within the security database stores historical adjustment records and feedback data. The table structure includes index fields to speed up queries. The module regularly organizes and analyzes feedback data, deleting outdated data and retaining historical records of reference value to avoid database redundancy that could impact performance.

[0079] The module also features abnormal feedback data filtering. When it detects feedback data abnormalities due to sensor failure or transmission errors, it automatically flags and skips that data, preventing it from influencing the generation of parameter correction factors. For example, if a piece of feedback contains a negative number of vulnerabilities, the module will identify this as abnormal data based on data validation rules and exclude it from the reverse verification process.

[0080] The parameter self-learning module leverages actual feedback data to continuously optimize system parameters, allowing the dynamic adjustment set of security parameters and the dynamic correction coefficient set to gradually adapt to the security characteristics of different automotive components and the changing threat environment. This process forms a closed-loop mechanism of "parameter adjustment - feedback recording - correction and optimization," enhancing the system's adaptability and long-term operational reliability. This allows the information security assessment system to continuously improve its ability to identify and prevent information security risks to automotive components through ongoing penetration testing and parameter optimization.

[0081] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.

[0082] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. The automobile parts information security assessment system based on multi-dimensional penetration testing is characterized by: include: A penetration test data acquisition module is used to collect penetration test data and vulnerability status data of automotive parts in real time through security test terminal equipment, analyze and process them to generate vulnerability severity characteristic values ​​and risk dynamic parameter characteristic values, and generate a dynamic adjustment set of security parameters based on the initial security parameter set stored in the security database; The vulnerability analysis module processes the personalized security parameters of the current batch of automotive parts based on the vulnerability severity characteristic values ​​and generates a dynamic penetration control strategy; The security event monitoring module is used to obtain real-time security event data during the penetration test of automotive parts through multi-source sensors, filter out abnormal event data that meets the dynamic adjustment range, and send it to the parameter matching module; The parameter matching module is used to perform multi-dimensional matching between abnormal event data and each parameter item in the dynamic adjustment set of security parameters, generate the matching degree between real-time data and each security parameter item, and select the security parameter corresponding to the highest matching degree as the target adjustment parameter; The response execution module is used to receive the target adjustment parameters and call the response adjustment protocol preset in the security database to drive the security device to execute the parameter correction operation.

2. The automotive parts information security assessment system based on multi-dimensional penetration testing according to claim 1 is characterized by: The specific process of collecting penetration test data of automobile parts in real time through security test terminal equipment is as follows: Identify the unique identification code of the automotive parts. If it is a newly connected device, collect basic security parameters including initial vulnerability scanning intensity, penetration test frequency baseline value and permission control range, establish security feature nodes based on the initial data, perform parameter calibration, and generate vulnerability severity feature values; If it is a historical access device, the historical security data set and vulnerability change curve of the device are extracted. The historical security data set includes scan fluctuation extremes, frequency deviation records and permission control delay duration, and is marked as the initial parameter set for the current security analysis.

3. The automotive parts information security assessment system based on multi-dimensional penetration testing according to claim 1 is characterized by: Generating a dynamic adjustment set of security parameters based on an initial security parameter set stored in a security database specifically includes: Extracting an initial standard set and a dynamic correction coefficient set of each security parameter from a security database, wherein the initial standard set includes: a vulnerability scanning intensity safety range, a frequency fluctuation tolerance interval, and an authority adjustment reference value; The dynamic correction coefficient set includes a scanning intensity compensation coefficient, a frequency gradient adjustment coefficient and an authority response weight parameter; Based on the real-time risk dynamic parameter characteristic value, the initial standard set of each security parameter is dynamically adjusted, and the adjusted parameter set is recorded as the security parameter dynamic adjustment set; The security parameter dynamic adjustment set includes a scanning dynamic range, a frequency adaptability threshold, and an authority optimization control value of each parameter item.

4. The automotive parts information security assessment system based on multi-dimensional penetration testing according to claim 3 is characterized by: The method of processing the vulnerability severity characteristic values ​​to obtain personalized security parameters of the current batch of automotive parts and generating a dynamic penetration control strategy specifically includes: Based on the vulnerability severity characteristic value, pattern matching is performed with the preset penetration test feature library to determine the priority list for security parameter adjustment; An adaptive control strategy including parameter triggering conditions, adjustment step rules and fault handling mechanism is generated based on the adjustment priority list.

5. The automotive parts information security assessment system based on multi-dimensional penetration testing according to claim 4 is characterized by: The acquisition of real-time security event data during the penetration test of automotive parts through multi-source sensors specifically includes: Monitor the real-time event data stream of the security vulnerability formation process, including the change value of the number of vulnerabilities, event uniformity index and risk fluctuation value; When the real-time event data stream exceeds the preset qualified safety range, the abnormal mark is activated and the event data of the abnormal period is extracted as effective monitoring data.

6. The automotive parts information security assessment system based on multi-dimensional penetration testing according to claim 4 is characterized by: The matching degree between the generated real-time data and each security parameter item specifically includes: Analyze the quantity deviation, uniformity change gradient, and risk fluctuation amplitude in abnormal event data, and perform differential calculations with the scanning dynamic range, frequency adaptability threshold, and authority optimization control value of each security parameter; Based on the difference calculation results, a matching index between real-time data and each security parameter item is generated.

7. The automotive parts information security assessment system based on multi-dimensional penetration testing according to claim 3 is characterized by: The step of selecting the security parameter corresponding to the highest matching degree as the target adjustment parameter specifically includes: Create a matching ranking list of each security parameter item and select the parameter item with the highest matching degree in the list; If the first matching degree is lower than the preset adjustment trigger threshold, the backup parameter set is called and the matching degree is recalculated.

8. The automotive parts information security assessment system based on multi-dimensional penetration testing according to claim 6 is characterized by: The matching index between the real-time data and each security parameter item is generated based on the difference calculation result. The specific processing process is as follows: A multi-dimensional matching algorithm is used to standardize the scan difference, frequency gradient and authority deviation to generate a safety parameter matching value ranging from 0 to 100. The matching value is used to indicate the adaptability of real-time data to security parameters.

9. The automotive parts information security assessment system based on multi-dimensional penetration testing according to claim 1 is characterized by: It also includes parameter self-learning modules, including: Record security vulnerability feedback data after each parameter adjustment, including actual vulnerability uniformity, incident control effects, and risk suppression changes; The feedback data is reversely verified with the dynamic adjustment set of security parameters to generate parameter correction factors and update the dynamic correction coefficient set in the security database.

10. The automobile parts information security assessment system based on multi-dimensional penetration testing according to claim 9 is characterized in that: The generation parameter correction factor specifically includes: Based on the degree of deviation between the feedback data and the expected security target, the scanning compensation factor, frequency adjustment factor and authority optimization weight are calculated; The exponentially weighted average algorithm is used to dynamically smooth the historical correction factors to generate a new set of dynamic correction coefficients.

Citation Information

Cited By

  • Information asset management system and protection intensity evaluation method thereof

    CN121146917A

  • Self-mixing small material feeding intelligent mistake-proofing system

    CN121232613A