Intrusion detection and defense method, device and equipment based on dynamic honeypot and medium

By deploying dynamic honeypots on vehicle controllers to monitor and analyze attacker behavior, and using hidden Markov models to predict attack phases and dynamically update strategies, the passive and dependent problems of existing vehicle network intrusion detection solutions are solved, achieving proactive defense and self-optimization, and improving vehicle network security.

CN121056207APending Publication Date: 2025-12-02DONGFENG COMML VEHICLE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511228807.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-12-02

AI Technical Summary

Technical Problem

Existing vehicle-to-everything (V2X) intrusion detection solutions rely on known attack characteristics, cannot actively lure attackers, lack in-depth analysis and prediction capabilities of attacker behavior, have insufficient protection capabilities in offline environments, and cannot operate independently or self-optimize on the vehicle side.

Method used

A dynamic honeypot trapping environment is deployed on the vehicle controller. By monitoring attacker behavior logs, a hidden Markov model is used to identify attack phases and predict the next action, and the honeypot configuration strategy is dynamically updated for proactive defense.

Benefits of technology

It enables proactive defense of vehicle network security systems, reduces the probability of successful attacks, promptly detects and responds to new attack methods, provides the latest threat intelligence, and protects the security of vehicle controllers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121056207A_ABST
    Figure CN121056207A_ABST
Patent Text Reader

Abstract

The invention provides an intrusion detection and defense method, device and equipment based on a dynamic honeypot and a medium, and belongs to the technical field of information security, and the method comprises the steps: deploying a honeypot trapping environment on a vehicle controller; monitoring and recording behavior logs of suspected attackers accessing the honeypot trapping environment; based on a hidden Markov model, identifying the current attack stage of the suspected visitor according to the behavior log, and predicting the next attack behavior of the suspected visitor; and generating a new honeypot configuration strategy according to the next attack behavior, and dynamically updating the honeypot trapping environment according to the honeypot configuration strategy. According to the method, the vehicle end honeypot is dynamically deployed, and the vehicle end safety is improved while the intrusion detection efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, specifically to an intrusion detection and defense method, device, equipment, and medium based on dynamic honeypots. Background Technology

[0002] With the rapid development of vehicle-to-everything (V2X) technology, the connection between vehicles and external networks is becoming increasingly close, and the cybersecurity threats they face are becoming increasingly complex and covert. Traditional vehicle security protection methods mostly rely on static rule bases and matching known attack characteristics, which are insufficient to cope with new attacks and the exploitation of unknown vulnerabilities.

[0003] Currently, mainstream vehicle network intrusion detection solutions mainly include the following categories: I. Decision Tree-Based CAN Bus Intrusion Detection Scheme: This scheme collects normal CAN bus communication data, converts the data field bytes into decimal features, and uses the C4.5 decision tree algorithm to construct a classification model to identify abnormal frames. However, this method relies on known attack patterns, cannot effectively detect zero-day attacks, and lacks the ability to proactively induce and analyze attacker behavior.

[0004] II. Intrusion Detection Scheme Based on TCP Protocol Characteristics: This scheme extracts the basic and business characteristics of the TCP protocol and constructs a decision tree model to judge malicious requests. Its limitations lie in its ability to identify only known attack characteristics, its inability to cope with new attack methods at the protocol level, and its lack of self-evolution capability.

[0005] III. Multi-layered Active Defense System for Vehicle Information Security: This system deploys protection functions at multiple levels, including cloud, network endpoints, perimeter, components, and kernel, and combines honeypot and probe technologies to capture attackers and construct threat profiles. While possessing a certain level of active defense capability, it is highly dependent on cloud resources and cannot operate independently when vehicles are offline. Furthermore, the accuracy of attack prediction and honeypot strategy adjustments is limited.

[0006] In summary, existing technologies generally suffer from the following shortcomings: reliance on known attack signature databases, inability to proactively lure attackers, lack of in-depth analysis and prediction capabilities of attacker behavior, insufficient protection in offline environments, and lack of independent deployment and self-optimization capabilities. Therefore, there is an urgent need for an intrusion detection and protection system that can operate independently on the vehicle side and possesses proactive trapping, behavioral analysis, and dynamic defense capabilities. Summary of the Invention

[0007] In view of this, it is necessary to provide an intrusion detection and defense method, device, equipment and medium based on dynamic honeypots to solve the technical problems of passive and lagging intrusion detection in the existing technology, which cannot effectively deal with unknown attacks and APT attacks, as well as the technical problems of active defense relying too much on the cloud and being unable to achieve intelligent dynamic defense independently on the vehicle.

[0008] To address the aforementioned technical problems, in a first aspect, the present invention provides an intrusion detection and defense method based on dynamic honeypots, comprising: Deploy honeypot trapping environments on the vehicle controller; Monitor and record the behavior logs of suspected attackers accessing the honeypot trapping environment; Based on the Hidden Markov Model, the attack stage of the suspected visitor is identified according to the behavior log, and the next attack behavior of the suspected visitor is predicted. A new honeypot configuration strategy is generated based on the next attack behavior, and the honeypot trapping environment is dynamically updated based on the honeypot configuration strategy.

[0009] In one possible implementation, deploying the honeypot trapping environment on the vehicle controller includes: Port emulation is performed on the vehicle controller to generate a fake service port, and the fake service port is configured as an open port with a weak password for access. Vulnerability simulation was performed on the vehicle controller. The vehicle controller performs credential forgery, including forged ordinary user credentials corresponding to the operating system and forged certificates corresponding to vehicle-to-cloud communication; Fake data is generated in the vehicle controller, which includes fake log files and fake configuration files containing fake sensitive information.

[0010] In one possible implementation, the vehicle controller includes a critical controller on which vulnerability simulation is performed, including: An independent, isolated operating environment is constructed on the critical controller using isolation technology; the isolated operating environment is a virtual environment with resource isolation, used to isolate and run one or more software services that have vulnerabilities. Deploy an open-source software vulnerability environment on the isolated operating environment; the open-source software vulnerability environment includes a known vulnerability environment and a fictitious vulnerability environment. Deploy an application-layer software vulnerability environment on the isolated operating environment.

[0011] In one possible implementation, monitoring and recording the behavior logs of suspected attackers accessing the honeypot trapping environment includes: Users who access the honeypot trapping environment are identified as suspected attackers by using a taint-marking method. The behavior log of the suspected attacker is recorded, including operating system layer attack behavior information, cloud access attack behavior information, and network scanning information.

[0012] In one possible implementation, the step of identifying the current attack stage of the suspected visitor based on the behavior log, and predicting the next attack behavior of the suspected visitor, based on the Hidden Markov Model, includes: The Hidden Markov Model is trained based on the training dataset to obtain an attack identification and prediction model; the training dataset includes labeled training data for attack phase types and attack behavior types; the attack phase types include intelligence gathering phase, initial intrusion phase, lateral movement phase, and information gathering and leakage phase. The behavioral characteristics are obtained from the behavioral logs, and the behavioral characteristics are input into the attack identification and prediction model to output the current attack stage and the predicted next attack behavior.

[0013] In one possible implementation, generating a new honeypot configuration strategy based on the next attack behavior includes: When the next attack action is the intelligence gathering phase, the honeypot configuration strategy is determined to be to perform the port emulation. When the next attack action is the initial intrusion phase, the honeypot configuration strategy is determined to perform the vulnerability simulation. When the next attack action is the lateral movement phase, the honeypot configuration policy is determined to perform the credential forgery. When the next attack action is the lateral movement phase, the honeypot configuration strategy is determined to generate the fake data.

[0014] One possible implementation also includes: Obtain basic attack information, reputation database whitelist, attacker's geographical location, and payload characteristics; An attacker profile is constructed based on the reputation database whitelist, the attacker's geographical location, the payload characteristics, the basic attack information, and the behavior logs. The attacker's profile and the behavior logs are uploaded to the cloud server.

[0015] Secondly, the present invention also provides an intelligent vehicle, comprising: Deployment module for deploying honeypot trapping environments on vehicle controllers; The monitoring module is used to monitor and record the behavior logs of suspected attackers accessing the honeypot trapping environment; The identification module is used to identify the current attack stage of the suspected visitor based on the behavior log using a hidden Markov model, and to predict the next attack behavior of the suspected visitor. The configuration module is used to generate a new honeypot configuration strategy based on the next attack behavior, and to dynamically update the honeypot trapping environment based on the honeypot configuration strategy.

[0016] Thirdly, the present invention also provides an electronic device, including a memory and a processor, wherein, The memory is used to store programs; The processor, coupled to the memory, is used to execute the program stored in the memory to implement the steps in the dynamic honeypot-based intrusion detection and defense method described in any of the above implementations.

[0017] Fourthly, the present invention also provides a computer-readable storage medium for storing a computer-readable program or instruction, which, when executed by a processor, can implement the steps of the intrusion detection and defense method based on dynamic honeypots described in any of the above implementations.

[0018] The beneficial effects of this invention are as follows: The intrusion detection and defense method based on dynamic honeypots provided by this invention, after first deploying a honeypot trapping environment on the vehicle controller, can actively attract attackers and guide their attack behavior to the honeypot system, thereby discovering potential attack threats in advance. Moreover, after deploying the honeypot on the vehicle controller, attackers may attack the honeypot first rather than directly attacking the normal functional modules of the vehicle, which provides a buffer time for vehicle network security protection. In addition, by deploying the honeypot trapping environment, attacker behavior information can be collected, which is very valuable for understanding the attacker's intent and attack methods. This can help vehicle manufacturers discover security vulnerabilities in the vehicle controller in a timely manner, thereby enabling them to fix and improve the system. Furthermore, by recording detailed attacker behavior logs, accurate basis can be provided for subsequent attack stage identification and behavior prediction. Furthermore, through the accurate identification of attack stages using Hidden Markov Models, the vehicle network security system can take targeted defensive measures. Based on the prediction of attack behavior, the vehicle network security system can deploy defensive strategies in advance. Moreover, the prediction of the next attack behavior enables the vehicle network security system to shift from passive defense to active defense, effectively reducing the probability of successful attacks. Furthermore, dynamically updating honeypot configuration strategies based on predicted attack behaviors allows honeypots to better adapt to attackers' methods. This dynamic updating also enables timely adjustments to the honeypot's decoy strategy, making it difficult for attackers to verify its authenticity, thus increasing the probability of false positives and improving the decoy effectiveness. Additionally, dynamically updated honeypots can promptly detect new attack methods. By continuously adjusting configurations, the honeypot system can capture new attack methods and tools attempted by attackers, providing the vehicle network security system with the latest threat intelligence to counter new attack threats and effectively protect the vehicle controller's security. Attached Figure Description To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 A schematic flowchart of an embodiment of the intrusion detection and defense method based on dynamic honeypots provided by the present invention; Figure 2 This is a schematic diagram of the automatic optimization process of the Hidden Markov Model of the present invention; Figure 3 This is a schematic diagram illustrating the overall process and deployment location of the present invention, which uses honeypot technology to lure attackers when there is a network connection. Figure 4This is a schematic diagram illustrating the overall process and deployment location of the present invention for inducing attackers using honeypot technology in the absence of network connectivity. Figure 5 A schematic diagram of an embodiment of the electronic device provided by the present invention. Detailed Implementation

[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0021] In the description of the embodiments of the present invention, unless otherwise stated, "multiple" means two or more. "And / or" describes the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0022] The terms "first," "second," etc., used in the embodiments of this invention are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, a technical feature defined with "first" or "second" may explicitly or implicitly include at least one of that feature.

[0023] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0024] Before demonstrating the embodiments, the following terms will be explained.

[0025] A honeypot is a cybersecurity technology that uses one or more fake, seemingly vulnerable systems or network resources to lure attackers. This allows for the monitoring, detection, and collection of attacker information, analysis of attack methods, and the provision of a basis for defense to prevent attacks. A honeypot resembles a real computer system, containing applications and data that cybercriminals use to identify ideal targets. For example, a honeypot can masquerade as a system containing sensitive consumer data to attract attackers. As attackers compromise the honeypot, IT teams can observe the attacker's progress, understand their attack methods, objectives, and sources, and provide a basis for cybersecurity strategies, improving the effectiveness of defensive measures.

[0026] A Hidden Markov Model (HMM) is a statistical model that describes a Markov process with hidden, unknown parameters. A Markov process is a stochastic process characterized by the fact that, given the current state, future states are independent of past states, exhibiting "memorylessness." For example, in a simple weather model, today's weather depends only on yesterday's weather, and not on the weather the day before yesterday or earlier. In this HMM, the states are invisible (implicit), but each state generates a visible output.

[0027] Nmap (Network Mapper) is a very popular network scanning and security auditing tool that helps network security experts, system administrators, and penetration testers understand the devices, services, and potential vulnerabilities in a network. Nmap scan information refers to the results and data obtained after scanning a target network or host using the Nmap tool.

[0028] An APT (Advanced Persistent Threat) attack is a sophisticated, covert, and persistent cyberattack, typically carried out by professional attackers (such as state-sponsored hacking groups) against specific targets (such as government agencies, large enterprises, critical infrastructure, etc.). The purpose of an APT attack is to steal sensitive information, disrupt critical systems, or remain dormant for a long period to gain a strategic advantage.

[0029] Payload is the part of malware or attack tools that actually performs the attack function. Payload typically includes malicious code, instruction sets, and data. In the fields of network security and computer security, payload characteristics refer to the specific attributes or patterns of the payload used to achieve the attack purpose in malware (such as viruses, Trojans, worms, etc.) or attack tools (such as exploits). Payload characteristics can help security systems identify and detect malicious activities.

[0030] This invention provides an intrusion detection and defense method, device, equipment, and medium based on dynamic honeypots, which are described below.

[0031] Figure 1 This is a schematic flowchart of an embodiment of the intrusion detection and defense method based on dynamic honeypots provided by the present invention, as shown below. Figure 1 As shown, the intrusion detection and defense method based on dynamic honeypots includes: S100, Deploy a honeypot trapping environment on the vehicle controller.

[0032] It's important to clarify that vehicle controllers refer to the hardware modules within a vehicle responsible for performing specific functions. Vehicle controllers include T-BOX (Telematics Box), IVI (In-Vehicle Infotainment system), Gateway ECU, Engine Control Unit, ABS (Anti-lock Braking System), BMS (Battery Management System), and other ECUs (Electronic Control Units). A honeypot environment, on the other hand, refers to a fake computer system, network service, or data resource specifically designed to attract, deceive, and trap attackers. It does not carry any real business functions; its sole value lies in being detected, attacked, and intruded upon. The honeypots on the vehicle are not deployed on real critical security controllers (such as brake controllers ECU and engine controllers ECM), but on controllers with strong processing capabilities, running operating systems (such as Linux or QNX), and having communication interfaces with the outside world, such as gateways, smart cockpit domain controllers, and T-Boxes. These controllers are the main springboards for attackers to enter the vehicle network, and therefore are excellent locations for deploying decoy environments.

[0033] Choose a suitable vehicle controller (non-critical security controller) as the hardware foundation for deploying the honeypot system. Vehicle controllers typically have multiple interfaces, such as CAN bus interfaces and LIN bus interfaces. Reserve a dedicated port on the controller for honeypot access. For example, an unused CAN bus port on the controller can be used to connect to the honeypot system via a small CAN bus interface module. This port can be a simple microcontroller responsible for connecting the honeypot to the vehicle controller's internal network and simulating the characteristics of a normal vehicle communication node. Additionally, ensure that the honeypot system's hardware resources (such as storage capacity and processing power) can meet the needs of subsequent behavior logging and attack behavior analysis. Create an independent, controlled, isolated operating environment for the honeypot on the non-critical security controller's operating system. Deploy the honeypot system in this isolated environment, setting its network parameters (such as IP address and port number) to enable normal network operation. Based on the vehicle controller's normal functions and communication protocols, design an attractive trapping service to deploy the honeypot trapping environment.

[0034] S200. Monitor and record the behavior logs of suspected attackers accessing the honeypot trapping environment.

[0035] It's important to note that to monitor honeypot access behavior, multiple monitoring points need to be set up within the honeypot system. These monitoring points can capture all attacker interactions. The network monitoring capabilities of the vehicle controller are used to monitor the honeypot system's network traffic in real time. Monitoring methods based on network protocol analysis can be employed. For example, deploying a network sniffing tool (such as a lightweight version of Wireshark) on the vehicle controller can capture all data packets passing through the honeypot port. Additionally, logging tools, such as using a syslog service, can be set up within the honeypot system to centrally collect various behavioral logs (such as access logs and error logs). The monitored behavioral logs and data are then categorized and stored in a database for easy analysis and retrieval later.

[0036] S300. Based on the Hidden Markov Model, identify the current attack stage of the suspected visitor according to the behavior log, and predict the next attack behavior of the suspected visitor.

[0037] It should be noted that the attack identification and prediction model in the following embodiments is obtained by training a Hidden Markov Model. The state space (i.e., attack stages) of the attack identification and prediction model is defined. Observation sequences are determined based on behavior logs. Based on these observation sequences, the identification and prediction model is used to calculate the probability that a suspected attacker is in each attack stage, thereby identifying the current attack stage of the attacker. Furthermore, the identification and prediction model can predict the next state (i.e., the next attack behavior) that the attacker might enter based on the state transition probabilities.

[0038] S400. Generate a new honeypot configuration strategy based on the next attack behavior, and dynamically update the honeypot trapping environment based on the honeypot configuration strategy.

[0039] It should be noted that: based on the predicted attack behavior, a new honeypot configuration strategy is generated and adjusted. This new strategy is then applied to the honeypot environment using the vehicle controller's software update mechanism to update the honeypot system's trapping service content, thereby updating the honeypot trapping environment. Of course, the updated honeypot trapping environment can also be tested to ensure it functions correctly and effectively traps attackers. If the honeypot trapping environment fails to function correctly or effectively trap attackers, the cause of the honeypot update failure can be investigated (e.g., incorrect network parameter configuration, incorrect port configuration, or a weak connection between the honeypot and the vehicle controller). Based on the cause of the update failure, the honeypot system should be reconfigured or the honeypot configuration strategy should be readjusted.

[0040] In summary, this invention, by deploying a honeypot trapping environment on the vehicle controller, can actively attract attackers and guide their attack behavior into the honeypot system, thereby discovering potential attack threats in advance. Furthermore, after deploying the honeypot on the vehicle controller, attackers may target the honeypot first, rather than directly attacking the vehicle's normal functional modules, providing a buffer time for vehicle network security protection. Additionally, deploying the honeypot trapping environment allows for the collection of attacker behavioral information, which is invaluable for understanding attacker intent and attack methods. This helps vehicle manufacturers promptly discover security vulnerabilities in the vehicle controller, enabling timely remediation and improvement. Moreover, detailed recording of attacker behavior logs provides accurate data for subsequent attack phase identification and behavior prediction. Furthermore, through accurate identification of attack phases using Hidden Markov Models, the vehicle network security system can take targeted defensive measures. Based on the prediction of attack behavior, the vehicle network security system can deploy defensive strategies in advance, and the prediction of subsequent attack behavior allows the vehicle network security system to shift from passive to active defense, effectively reducing the probability of successful attacks. Furthermore, dynamically updating honeypot configuration strategies based on predicted attack behaviors allows honeypots to better adapt to attackers' methods. This dynamic updating also enables timely adjustments to the honeypot's decoy strategy, making it difficult for attackers to verify its authenticity, thus increasing the probability of false positives and improving the decoy effectiveness. Additionally, dynamically updated honeypots can promptly detect new attack methods. By continuously adjusting configurations, the honeypot system can capture new attack methods and tools attempted by attackers, providing the vehicle network security system with the latest threat intelligence to counter new attack threats and effectively protect the vehicle controller's security.

[0041] In some embodiments of the present invention, such as Figure 2 As shown, step S100 includes: S110. Perform port emulation on the vehicle controller to generate a fake service port, and configure the fake service port as an open port with weak password access.

[0042] It's important to note that a port emulator is a software or hardware tool used to simulate the behavior of real hardware ports. It can mimic the functionality of various common network services on real ports (such as HTTP, FTP, SSH, Telnet, SMTP, etc.) to enable communication or debugging with real devices. By selecting a suitable port emulator for the vehicle controller environment, deploying it on the vehicle controller, and generating multiple fake service ports, these fake service ports are configured to be open to attract attackers to scan and attack. Weak passwords can also be configured for these fake service ports to entice attackers to attempt logins. In this way, the fake service ports can simulate the normal network services of the vehicle controller, such as remote diagnostics and software update services. For example, port 21 could be opened for FTP service, port 22 for SSH service, port 5037 for adb service, and port 3306 for MySQL service. These services can be configured with weak passwords to lure attackers into a honeypot. The port emulator can record all attack information targeting these fake service ports.

[0043] S120. Perform vulnerability simulation on the vehicle controller.

[0044] It should be noted that, based on the software and hardware characteristics of the vehicle controller, select certain vulnerabilities, build a vulnerable environment on the vehicle controller, and simulate the behavior of these selected vulnerabilities. Alternatively, exploit tools (such as Metasploit) can be used to test the built vulnerable environment to ensure that the vulnerabilities can be successfully triggered and that the attack behavior can be recorded.

[0045] S130. The vehicle controller performs credential forgery, and the forged credentials include forged ordinary user credentials corresponding to the operating system and forged certificates corresponding to vehicle-cloud communication.

[0046] It's important to note that in Unix-like operating systems (such as Linux), users are divided into root users and non-root users. Non-root users are ordinary users with limited privileges. Their permissions are typically restricted, allowing them only access to and manipulation of their own user directory and execution of basic commands, but not system-level modifications or operations. The attacker generates forged ordinary user credentials in the vehicle controller, including forged usernames and passwords. These forged credentials can mimic the login credentials of legitimate ordinary users on the vehicle controller, enticing attackers to attempt to log in using these forged credentials. Configuring forged ordinary user credentials corresponding to the operating system involves configuring the login user to be a non-root user (low privileges). This way, when an attacker successfully infiltrates the honeypot system through vulnerabilities (such as web vulnerabilities or weak SSH passwords), the system intentionally doesn't grant them root privileges but instead assigns them forged ordinary user credentials. In other words, it deliberately only grants the suspected attacker ordinary user privileges. Because the suspected attacker has a low-privilege account, in order to complete the attack, they must attempt to use the `su` (switch user) or `sudo` (superuser do) commands to interactively escalate privileges, i.e., raise their own privilege level. Thus, when the attacker starts using the `su` or `sudo` commands and interacts, the honeypot system will meticulously record all of the attacker's actions throughout the entire process.

[0047] A vehicle-to-cloud (V2X) communication certificate is a digital certificate used for authentication and encrypted communication between a vehicle and the cloud. A V2X communication address is the network address used by the vehicle to communicate with the cloud. After configuring a forged ordinary user credential, a forged V2X communication certificate is then configured in the vehicle controller. Specifically, in the honeypot system, a very simple and easily guessed or cracked root user (high privileges) forged superuser credential is configured, and the forged V2X communication certificate is deliberately stored in a directory of the honeypot system's file system. The forged certificate includes both the forged V2X communication certificate and the forged V2X communication address, misleading the attacker into believing they have complete control of the vehicle controller. This induces the attacker to use the forged V2X communication certificate and address to establish a connection with the real cloud server. The honeypot system can monitor all outbound connection requests using these forged certificates, thereby discovering the attacker's target server, the tools used, and recording the attacker's cloud attack payload (such as malicious commands).

[0048] S240. Generating false data in the vehicle controller, the false data including a fake log file and a fake configuration file containing false sensitive information.

[0049] It's important to note that forged log files and configuration files containing false sensitive information are generated within the vehicle controller to obtain fake data. The forged log files simulate the normal operation of the vehicle controller, but contain fabricated sensitive information such as fake vehicle location information and fake user driving habits. The forged configuration files simulate the normal configuration files of the vehicle controller, but contain fabricated sensitive information such as fake network configuration information and user settings. These forged log files and configuration files are stored in the vehicle controller's file system, ensuring attackers have access to these files. A honeypot system is configured to record attacker access to these forged sensitive information log files and configuration files, including access time and method. This information is recorded in the honeypot's behavior log for subsequent attack analysis. For example, the forged log files can be stored in the ` / var / log` directory of the vehicle controller, and the forged configuration files can be stored in the ` / etc` directory.

[0050] This embodiment constructs a multi-layered honeypot system by performing port emulation, vulnerability simulation, credential forgery, and fake data generation on the vehicle controller, comprehensively attracting and luring attackers. This multi-layered defense mechanism effectively protects the vehicle controller from attacks while collecting rich attack information, providing valuable threat intelligence for vehicle manufacturers. Furthermore, by recording attacker behavior on fake service ports, simulated vulnerabilities, forged credentials, and fake data, abundant threat intelligence can be collected. This intelligence helps vehicle manufacturers promptly identify new attack methods, tools, and targets, enabling them to take proactive defensive measures and optimize security strategies. Moreover, by constructing a multi-layered honeypot system on the vehicle controller through port emulation, vulnerability simulation, credential forgery, and fake data generation, limited network security resources can be concentrated on addressing the most pressing threats. For example, attracting attackers through port emulation and vulnerability simulation reduces attacks on real services, saving resources for protecting critical functions. Simultaneously, generating fake data and forged credentials induces attackers to engage in more attack behaviors, thereby collecting more attack information and further optimizing security strategies.

[0051] In some embodiments of the present invention, the vehicle controller includes a critical controller, and step S200 includes: S211. An independent isolated operating environment is constructed on the important controller using isolation technology; the isolated operating environment is a virtual environment with resource isolation, used to isolate and run one or more software services with vulnerabilities.

[0052] It should be noted that critical controllers include in-vehicle infotainment systems, T-Boxes, and gateways. Containerization or virtualization technologies can be used to create isolated runtime environments. Based on container engines such as Docker or LXC, independent container images can be created on the critical controller for each vulnerable service to be simulated (such as SSH, FTP, and MySQL services) to establish an isolated runtime environment. Alternatively, lightweight virtual machines can be deployed on the critical controller, running a streamlined copy of the operating system within the virtual machine to establish an isolated runtime environment.

[0053] S212. Deploy an open-source software vulnerability environment on the isolated operating environment; the open-source software vulnerability environment includes a known vulnerability environment and a fictitious vulnerability environment.

[0054] It's important to clarify that an open-source software vulnerability environment refers to a system-level environment where open-source software, libraries, or services with known or intentionally crafted vulnerabilities are deployed to simulate an insecure system. The goal is to trick attackers into exploiting these vulnerabilities to gain initial access or escalate privileges. For example, in a vehicle's critical controllers, a software environment filled with "traps" is deliberately created. These traps include both real-world vulnerabilities (known vulnerabilities) and designed, non-existent vulnerabilities (fictitious vulnerabilities) to attract, deceive, and facilitate in-depth research by attackers.

[0055] You can collect known historical vulnerabilities affecting commonly used open-source components in vehicles (such as BusyBox, CURL, OpenSSL, and databases) from sources like CVE (Common Vulnerability Disclosure) databases, security vendor reports, and open-source project issues. Obtain vulnerable software versions that are widely disclosed in the real world and have publicly available exploit code (EXP). Based on these versions, obtain the corresponding source code, compile and package it into an installer for the known vulnerable software. Install this installer in each container image, run the software within the container, expose the port, and configure a weak password to deploy the vulnerable environment. For example, you can crawl the internet to find known vulnerabilities affecting vehicles and their exploitation methods, and then deploy the exploit environment on critical controllers via virtualization. This could include deploying vulnerable BusyBox, CURL, adb, SSH, FTP, and MySQL modules.

[0056] Alternatively, you can write or configure seemingly vulnerable interfaces, services, or programs and install them in a container image to create a fictitious vulnerability environment. Fictitious vulnerabilities include Web API vulnerabilities, binary program vulnerabilities, and logic vulnerabilities. For example, a Web API vulnerability could be an unauthorized command execution interface deliberately created in a simulated diagnostic or remote control app. A binary program vulnerability could be a program intentionally designed with a simple stack overflow or format string vulnerability and placed in the controller's file system under seemingly important names. A logic vulnerability could be a client program that requires a vehicle cloud certificate, but intentionally flawed in its certificate verification logic (e.g., ignoring certificate expiration), tricking attackers into connecting with an expired certificate. The fictitious vulnerability program or web service can then be deployed in a container or virtual machine prepared for a honeypot to create the fictitious vulnerability environment. In short, to avoid introducing real risks, the deployment of either known or fictitious vulnerability environments should never involve directly installing vulnerable software or programs on the operating system of a real, critical controller; instead, it should be deployed in an isolated runtime environment.

[0057] S213. Deploy an application-layer software vulnerability environment on the isolated operating environment.

[0058] It's important to clarify that an application-layer software vulnerability environment refers to a simulated application built at the business application level, based on a real vehicle function application. This simulated application intentionally contains vulnerabilities or traps as bait to deploy an application-layer software vulnerability environment on critical controllers. The goal is to lure attackers who have already gained initial access to the system into attacking these high-value business applications, thereby exposing their ultimate objective and attack methods. Packet capture analysis can be performed on real diagnostic services or remote services to understand their communication protocols (typically HTTP / HTTPS, MQTT, Some / IP, etc.), API interface formats (such as / v1 / doors / unlock), data formats (such as JSON, XML structures), and authentication methods, and to mimic the user interface (UI) or service responses of the real application. Alternatively, some open-source projects can be used to simulate vehicle services. The simulated application intentionally creates vulnerabilities that should never exist in the real application. This vulnerable simulated application (at least one of known or fabricated vulnerabilities) is installed in an isolated runtime environment, and then run in that environment to complete the deployment of the application-layer software vulnerability environment.

[0059] For example, suppose a vehicle is equipped with a real diagnostic app and a real remote control app. The diagnostic app can read vehicle fault codes, execute diagnostic commands, and even rewrite the ECU. The remote control app can control door locks, air conditioning, windows, start the engine, etc. A diagnostic simulation app, which simulates the real diagnostic app but contains vulnerabilities, can be deployed in an isolated operating environment. This diagnostic simulation app includes a debug interface for command execution, " / v1 / debug?cmd=". A remote control simulation app, which simulates the real remote control app but contains vulnerabilities, can also be deployed in an isolated operating environment. This remote control simulation app can be configured to return a successful command execution result without verifying the authenticity of the cloud platform.

[0060] This embodiment constructs an independent, isolated operating environment, isolating vulnerable software services from other critical functions of the vehicle controller. Even if an attacker successfully exploits a vulnerability in the isolated operating environment, they cannot directly access other parts of the vehicle controller, thus preventing the attack from spreading throughout the entire system. Furthermore, the isolated operating environment restricts the attacker's activities, limiting them to attacks only within the isolated environment. This helps reduce the impact of attacks on the overall security of the vehicle controller and protects the vehicle's critical functions from attack. Moreover, the isolated operating environment is a resource-isolated virtual environment, ensuring that vulnerable software services do not compete for system resources with other critical functions. This helps improve the overall stability of the system and avoids performance degradation or crashes caused by resource contention. When a problem occurs in a software service within the isolated operating environment, the fault can be quickly located and isolated without affecting other parts of the vehicle controller. This helps to quickly restore normal system operation and reduce the impact of the fault on vehicle operation. Furthermore, because the software service in the isolated environment is isolated from other parts of the vehicle controller, specific security policies can be formulated for the isolated environment without considering the impact on the entire system. When a vulnerability is discovered in a software service within the isolated operating environment, it can be repaired and updated independently without affecting other parts of the vehicle controller. This helps to quickly fix vulnerabilities and improve system security. Furthermore, by building independent, isolated operating environments on critical controllers and deploying open-source software vulnerability environments and application-layer software vulnerability environments within these isolated operating environments, a multi-layered honeypot system can be constructed to comprehensively attract and trap attackers.

[0061] In some embodiments of the present invention, step S200 includes: S210. Users who access the honeypot trapping environment are identified as suspected attackers by using a taint marking method.

[0062] It's important to note that taint tagging is a technique used to track data flow. It tracks the source and direction of data by attaching specific tags (taint tags) to it. In cybersecurity, taint tagging is commonly used to track attack behavior and identify potential attackers. When a user accessing a honeypot trapping environment is flagged as a suspected attacker, the subsequent system can identify and monitor these users' behavior, thereby better analyzing and responding to potential attacks. This application assigns a unique taint tag to each user accessing the honeypot system. This taint tag can be a number, string, or hash value, used to uniquely identify the user. Thus, when a user first accesses the honeypot trapping environment, the honeypot system generates a taint tag and associates it with the user's session. This tag can be stored in the user's session information, such as HTTP cookies, TCP connection information, etc. Once a user is flagged as a suspected attacker through the taint tag, the taint tag is propagated in subsequent interactions.

[0063] S220. Record the behavior log of the suspected attacker, the behavior log including operating system layer attack behavior information, cloud access attack behavior information and network scanning information.

[0064] It should be noted that traditional intrusion detection systems operate in a static and passive manner. The honeypot trapping environment established in embodiments S110 to S140 of this application allows the honeypot system to achieve dynamic and proactive attack data capture. The data captured by the honeypot system includes basic attack information, operating system-level attack behavior information, cloud access attack behavior information, and network scanning information. Basic attack information includes the suspected attacker's source address, source port, destination IP, destination port, and protocol. Operating system-level attack behavior information is attacker behavior data recorded after a suspected attacker logs into the operating system, including login time, login method (SSH, RDP, ADB), process name, command-line parameters, and parent process ID. Cloud access attack behavior information is attacker behavior data recorded when a suspected attacker sends malicious commands through the cloud, including request headers and payloads. Network scanning information is obtained through traffic capture using nmap's TCP option information, including nmap option combinations (MSS, Wscale, SACK, Timestamp, NOP) and specific parameters within those combinations.

[0065] This application's embodiments utilize taint tagging to quickly identify users accessing the honeypot as suspected attackers. This tagging mechanism takes effect immediately upon a user's first access to the honeypot, ensuring timely follow-up monitoring and analysis. Furthermore, taint tagging provides each user with a unique identifier, aiding in the accurate differentiation of different attackers in complex network environments. Even when multiple attackers use the same attack methods, taint tagging helps distinguish the behavior of different attackers. Further, by recording attack behaviors at multiple levels, including the operating system layer, cloud access, and network scanning, a comprehensive understanding of attacker methods and targets can be achieved. This helps identify various attack pathways that attackers may utilize, thereby providing more comprehensive defense measures. By analyzing the attack behaviors recorded in behavior logs and taint tagging, security strategies can be optimized based on actual attack behavior data. This helps ensure the effectiveness and relevance of security measures, reduces the waste of security resources, and improves the overall security of the system. Moreover, the attack behaviors recorded in behavior logs and taint tagging serve as an important source of threat intelligence, helping security teams understand the current network threat environment. By analyzing this data, new attack methods, tools, and targets can be discovered, allowing for timely updates to security measures and enhancing the system's resilience.

[0066] In one possible implementation, step S300 includes: S310. Train the Hidden Markov Model based on the training dataset to obtain an attack identification and prediction model; the training dataset includes labeled training data for attack phase types and attack behavior types; the attack phase types include intelligence gathering phase, initial intrusion phase, lateral movement phase, and information gathering and leakage phase. S320. Obtain behavioral features based on the behavioral log, input the behavioral features into the attack identification and prediction model to output the current attack stage, and output the predicted next attack behavior.

[0067] It should be noted that, based on the characteristics of APT attacks, the attack phases are divided into four stages: intelligence gathering, initial intrusion, lateral movement, and information gathering and leakage. The hidden state sequence of the Hidden Markov Model includes these four attack phases: information gathering and leakage, initial intrusion, lateral movement, and information gathering and leakage. The observation sequence is the data sequence corresponding to the attack behavior type. This application constructs a training dataset, which includes a large amount of labeled training data. Each training data point is labeled with the attack phase type and attack behavior type. The training data can be obtained from a large number of behavior logs collected from honeypot systems, or from publicly available attack data with known attack behaviors and attack phase types crawled from the internet. The collected behavior logs or publicly available attack data are labeled to clarify which attack phase type (e.g., intelligence gathering, initial intrusion, lateral movement, information gathering and leakage) and specific attack behavior type (e.g., port scanning, vulnerability exploitation, file access) each behavior log or publicly available attack data belongs to, thus obtaining the training data. Then, invalid or erroneous behavior logs or publicly available attack data are removed to ensure the accuracy and completeness of the data. Furthermore, useful behavioral features, such as the attacker's IP address, attack time, attack method, and attack target, are extracted from behavior logs or publicly available attack data. These features will be used to train the Hidden Markov Model.

[0068] After obtaining the training dataset, the state space of the Hidden Markov Model (HMM) is defined sequentially, the state transition matrix is ​​initialized, the observation space is defined, and the observation probability matrix is ​​initialized. The state space includes the information gathering and leakage phase (S1), the initial intrusion phase (S2), the lateral movement phase (S3), and the information gathering and leakage phase (S4). The state transition matrix represents the transition probabilities between different attack phases; initially, these probabilities can be uniformly distributed or set based on prior knowledge. The observation space includes specific attack behavior types, such as port scanning (O1), vulnerability exploitation (O2), and file access (O3). The observation probability matrix represents the observation probability of different attack behaviors at each attack phase; initially, these probabilities can be uniformly distributed or set based on prior knowledge. The HMM is initialized using the defined state space, state transition matrix, and observation probability matrix. The hidden Markov model (HMM) is iteratively trained using the forward-backward algorithm (Baum-Welch algorithm), with model parameters updated incrementally until the model converges or reaches a predetermined number of iterations. This ensures that the extracted features better reflect the characteristics of the attack behavior. Once the HMM's performance reaches a threshold, it is saved as an attack identification and prediction model for actual attack detection and prediction. Examples of behavioral features corresponding to the four attack stages are shown in Table 1.

[0069] Table 1. Examples of behavioral characteristics corresponding to the four attack phases:

[0070] This application utilizes a trained attack identification and prediction model to accurately identify the attacker's current attack stage, enabling targeted defensive measures. For example, if the model identifies the attacker as being in the information gathering and leakage stage, network traffic monitoring can be strengthened to promptly detect and prevent further actions. The trained attack identification and prediction model effectively predicts attack behavior. Based on these predictions, vehicle network security systems can shift from passive to proactive defense, allowing for advance deployment of defensive strategies and improved defense capabilities and attack analysis efficiency. For instance, if it is predicted that the attacker might next target the vehicle controller's remote control function, the system can proactively strengthen the security of this function, such as updating authentication mechanisms and restricting access permissions.

[0071] In one possible implementation, generating a new honeypot configuration strategy based on the next attack behavior includes: When the next attack action is the intelligence gathering phase, the honeypot configuration strategy is determined to be to perform the port emulation. When the next attack action is the initial intrusion phase, the honeypot configuration strategy is determined to perform the vulnerability simulation. When the next attack action is the lateral movement phase, the honeypot configuration policy is determined to perform the credential forgery. When the next attack action is the lateral movement phase, the honeypot configuration strategy is determined to generate the fake data.

[0072] It should be noted that when the attack identification and prediction model predicts that the next attack behavior is the intelligence gathering stage, port emulation on the vehicle controller can be performed as described in embodiment S110 above. When the attack identification and prediction model predicts that the next attack behavior is the initial intrusion stage, vulnerability simulation on the vehicle controller can be performed as described in embodiment S120 above. When the attack identification and prediction model predicts that the next attack behavior is the lateral movement stage, credential forgery on the vehicle controller can be performed as described in embodiment S130 above. When the attack identification and prediction model predicts that the next attack behavior is the information gathering and leakage stage, fake data can be generated on the vehicle controller as described in embodiment S140 above.

[0073] Through a dynamic prediction mechanism, the most likely transfer path in the current state is calculated, the next attack method is predicted, and the honeypot is dynamically configured. The honeypot configuration strategies generated according to different attack stages are shown in Table 2. After the honeypot configuration strategy is updated, the HMM parameters are updated by capturing further attacker interaction information and fed back to the HMM model for optimization, thus completing the attack step identification and optimization closed loop.

[0074] Table 2. Honeypot configuration strategies for different attack phases:

[0075] This embodiment constructs a multi-layered honeypot system by adopting corresponding honeypot configuration strategies at different attack stages, comprehensively attracting and trapping attackers. This multi-layered defense mechanism effectively protects the vehicle controller from attacks while collecting rich attack information, providing valuable threat intelligence for vehicle manufacturers. Dynamically adjusting the honeypot trapping environment through honeypot configuration strategies can effectively improve the security of the vehicle controller, enhance the monitoring and analysis capabilities of attack behavior, and thus better protect the vehicle system from attacks.

[0076] In one possible implementation, step S400 is followed by: S500: Obtain basic attack information, reputation database whitelist, attacker's geographical location, and payload characteristics; S600. Construct an attacker profile based on the reputation database whitelist, the attacker's geographical location, the payload characteristics, the basic attack information, and the behavior logs. S700. Upload the attacker's profile and the behavior log to the cloud server.

[0077] Specifically, a reputation database whitelist is maintained, recording known secure IP addresses and domains. These whitelisted IP addresses and domains typically belong to trusted users or service providers. When an attack is detected, the attacker's IP address is queried to see if it is on the whitelist. If it is, it may be a false alarm and requires further verification. IP geolocation services (such as MaxMind GeoIP, IPinfo, etc.) are used to query the attacker's IP address's corresponding geographic location information, including country, city, and ISP. This geographic location information is recorded in the attack log for subsequent analysis. Feature extraction tools such as YARA and ClamAV are used to analyze the behavior logs and extract payload features, such as malware signatures and attack tool characteristics. The obtained basic attack information, reputation database whitelist, attacker geographic location, payload features, and behavior logs are cleaned and transformed to obtain formatted log data, ensuring data consistency and integrity. Then, data mining and machine learning techniques are used to integrate the cleaned and formatted log data to generate an attacker profile. For example, clustering algorithms can be used to classify attackers, or decision tree algorithms can be used to predict attacker intent. Attacker profiling includes attacker type (individual, organization, state-sponsored, etc.), attack intent (data theft, sabotage, extortion, etc.), attack capabilities (technical skill level, tools used, etc.), and geographical location. Then, the attacker profiling and structured log data are uploaded to other controllers or information security platforms (e.g., cloud servers) via a specified protocol, so that the generated honeypot configuration can be distributed to the attacked vehicle controller.

[0078] This embodiment, by acquiring basic attack information, a reputation database whitelist, attacker geographic location, and payload characteristics, provides a comprehensive understanding of all aspects of attack behavior, offering rich data support for subsequent analysis and defense. Querying the reputation database whitelist reduces false positives, preventing legitimate users from being mistaken for attackers. Furthermore, obtaining the attacker's geographic location allows analysis of their origin and distribution, enabling targeted defense measures. Based on the attacker's geographic location, regional defense strategies can be optimized, such as restricting access to specific areas. Further, analyzing payload characteristics identifies and extracts malicious code signatures, attacker tools, and methods, facilitating rapid identification and defense against known malware and providing a basis for subsequent defense. Moreover, integrating multiple data sources to construct a comprehensive attacker profile allows for more accurate identification of attacker behavior patterns and intentions. Attackers can be categorized and managed, such as individual attackers, organized attackers, and state-sponsored attackers, allowing for different defense strategies. Furthermore, uploading attacker profiles and behavior logs to cloud servers enables centralized data management and analysis, facilitating unified monitoring and management by the security team. It also allows for data sharing between different systems, improving the efficiency of the security team, effectively enhancing the security of vehicle controllers, and strengthening the monitoring and analysis capabilities against attack behaviors, thereby better protecting vehicle systems from attacks.

[0079] For example, selecting a vehicle with internet connectivity, the Hidden Markov Model (HMM) automatic optimization process is as follows: Figure 2 As shown, the overall process and deployment location of using honeypot technology to lure attackers when there is network access are as follows: Figure 3As shown, a honeypot is deployed in the network controller, including initial honeypot configuration, an active intrusion detection module, and a data interaction module. An intrusion data analysis module and a data interaction module are deployed on the cloud server. When a vehicle is suspected of being under cyberattack, the log information recorded in the active intrusion detection module is transmitted to the intrusion data analysis module for analysis via the data interaction module. This includes NMAP option combinations to obtain the NMAP version, NMAP option combinations, attacker basic information logs, and attacker behavior logs, obtaining the attacker's geographical location, attack time, commonly used attack codes, and attack habits. The IP reputation database whitelist obtained from the threat intelligence platform is matched against the attacker's geographical location and attack time, and the attack team's attack characteristics are matched against the obtained commonly used attack codes and attack habits. If a match is successful, the attack behavior is attributed to an existing attack team; if no match is successful, a new attack characteristic database is created for the next match, ultimately generating an alarm message. The alarm message is sent to the information security platform via the data interaction module. Simultaneously, the IP address of the attack team is sent to the vehicle-side network controller for blacklisting, prohibiting subsequent access from that IP address. Simultaneously, the attacker's behavior logs are analyzed using a Hidden Markov Model (HMM) to determine the stages of the attack. Instructions are generated based on different stages and sent to the vehicle-side network controller via the data interaction module for dynamic deployment. The honeypot configuration strategies generated according to different attack stages are shown in Table 2 of the above embodiment.

[0080] For example, given the characteristics of vehicle operation, there may be areas without cellular networks, or situations where the network is maliciously disconnected by an attacker. In such cases, an attacker can launch an attack by accessing the vehicle. The Hidden Markov Model (HMM) automatic optimization process is as follows: Figure 2 As shown, the overall process and deployment location of using honeypot technology to lure attackers in the absence of network connectivity are as follows: Figure 4As shown, before deployment, commonly used attack codes and attack habits need to be pre-configured in the intrusion data analysis module. Honeypots are deployed in the vehicle gateway, network controller, and other important controllers. Dynamic honeypot configuration, intrusion behavior detection, and data interaction are deployed in the gateway and other important controllers. Dynamic honeypot configuration, intrusion behavior detection, data interaction, and intrusion data analysis are deployed in the network controller. When the vehicle gateway, important controllers, and network controller are suspected of being under network attack, the active intrusion behavior detection module records log information, including the NMAP version obtained from NMAP option combinations, NMAP option combinations, attacker basic information logs, and attacker behavior logs, obtaining the attacker's geographical location, attack time, commonly used attack codes, and attack habits. The vehicle gateway or important controller transmits the log information recorded in the active intrusion behavior detection module to the intrusion data analysis module of the network controller for analysis through the data interaction module. The log information recorded by the network controller is directly transmitted to its own intrusion data analysis module for analysis. The intrusion data analysis module matches attack characteristics with pre-configured commonly used attack codes and attack habits. If a match is successful, the attack is attributed to an existing attack team; if no match is found, a new attack signature database is created for the next match, ultimately generating an alarm message. The alarm message is stored locally and protected until the vehicle network is restored, at which point it is uploaded to the information security platform. Simultaneously, the attacker's behavior logs are analyzed using a Hidden Markov Model (HMM) to determine the stages of the attack. Instructions are generated based on these stages and sent to the attacked controller (including the vehicle gateway, critical controllers, or vehicle-to-everything (V2X) controller) via a data interaction module for dynamic deployment. The deployment strategy is described in Table 1 of the aforementioned embodiment. The attacker's basic information log, attacker behavior log, and alarm message from the attacked vehicle controller can be exported from external devices for analysis.

[0081] This invention uses honeypot technology to lure attackers, consuming their attack costs while simultaneously collecting information for attribution. It also transmits vehicle intrusion detection alerts to an information security platform, enabling more comprehensive and efficient identification of information security attacks against vehicles. This allows for accurate attacker profiling, prediction of future attacks, and the generation of effective protective strategies. Furthermore, it provides effective protection even when a vehicle is attacked and loses network access, monitoring and protecting against network attacks occurring when the vehicle's cellular network fails. Additionally, honeypot configurations are tailored to the network attack risks faced by the vehicle, improving intrusion detection efficiency. Combining APT attack characteristics, a Hidden Markov Model (HMM) is used to identify current attack steps and dynamically deploy vehicle-side honeypots, effectively enhancing the security of the vehicle controller and strengthening the monitoring and analysis capabilities for attack behavior, thereby better protecting the vehicle system from attacks.

[0082] To better implement the intrusion detection and defense method based on dynamic honeypots in this invention, this invention also provides an intelligent vehicle, which includes: Deployment module for deploying honeypot trapping environments on vehicle controllers; The monitoring module is used to monitor and record the behavior logs of suspected attackers accessing the honeypot trapping environment; The identification module is used to identify the current attack stage of the suspected visitor based on the behavior log using a hidden Markov model, and to predict the next attack behavior of the suspected visitor. The configuration module is used to generate a new honeypot configuration strategy based on the next attack behavior, and to dynamically update the honeypot trapping environment based on the honeypot configuration strategy.

[0083] The intelligent vehicle provided in the above embodiments can implement the technical solutions described in the above embodiments of the intrusion detection and defense method based on dynamic honeypots. The specific implementation principles of each module or unit can be found in the corresponding content of the above embodiments of the intrusion detection and defense method based on dynamic honeypots, which will not be repeated here.

[0084] like Figure 5 As shown, the present invention also provides an electronic device 500. The electronic device 500 includes a processor 501, a memory 502, and a display 503. Figure 5 Only some components of the electronic device 500 are shown, but it should be understood that it is not required to implement all the components shown, and more or fewer components may be implemented instead.

[0085] In some embodiments, processor 501 may be a central processing unit (CPU), microprocessor, or other data processing chip, used to run program code stored in memory 502 or process data, such as the intrusion detection and defense method based on dynamic honeypot in this invention.

[0086] In some embodiments, processor 501 may be a single server or a group of servers. The server group may be centralized or distributed. In some embodiments, processor 501 may be local or remote. In some embodiments, processor 501 may be implemented on a cloud platform. In one embodiment, the cloud platform may include a private cloud, public cloud, hybrid cloud, community cloud, distributed cloud, inter-cloud, multi-cloud, or any combination thereof.

[0087] In some embodiments, memory 502 may be an internal storage unit of electronic device 500, such as a hard disk or memory of electronic device 500. In other embodiments, memory 502 may also be an external storage device of electronic device 500, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc. equipped on electronic device 500.

[0088] Furthermore, the memory 502 may include both internal storage units of the electronic device 500 and external storage devices. The memory 502 is used to store application software and various types of data installed on the electronic device 500.

[0089] In some embodiments, display 503 may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, or an OLED (Organic Light-Emitting Diode) touchscreen. Display 503 is used to display information from electronic device 500 and to display a visual user interface. Components 501-503 of electronic device 500 communicate with each other via a system bus.

[0090] In one embodiment, when the processor 501 executes the intrusion detection and defense method program based on dynamic honeypot in the memory 502, the following steps can be implemented: Deploy honeypot trapping environments on the vehicle controller; Monitor and record the behavior logs of suspected attackers accessing the honeypot trapping environment; Based on the Hidden Markov Model, the attack stage of the suspected visitor is identified according to the behavior log, and the next attack behavior of the suspected visitor is predicted. A new honeypot configuration strategy is generated based on the next attack behavior, and the honeypot trapping environment is dynamically updated based on the honeypot configuration strategy.

[0091] It should be understood that when the processor 501 executes the intrusion detection and defense method program based on dynamic honeypot in the memory 502, in addition to the functions mentioned above, it can also implement other functions, as can be found in the description of the corresponding method embodiments above.

[0092] Furthermore, this embodiment of the invention does not specifically limit the type of electronic device 500 mentioned. Electronic device 500 can be a mobile phone, tablet computer, personal digital assistant (PDA), wearable device, laptop computer, or other portable electronic device. Exemplary embodiments of portable electronic devices include, but are not limited to, portable electronic devices running iOS, Android, Microsoft, or other operating systems. The aforementioned portable electronic device can also be other portable electronic devices, such as a laptop computer with a touch-sensitive surface (e.g., a touch panel). It should also be understood that in some other embodiments of the invention, electronic device 500 may not be a portable electronic device, but rather a desktop computer with a touch-sensitive surface (e.g., a touch panel).

[0093] Accordingly, this application also provides a computer-readable storage medium for storing computer-readable programs or instructions. When the programs or instructions are executed by a processor, they can implement the steps or functions of the intrusion detection and defense methods based on dynamic honeypots provided in the above-described method embodiments.

[0094] Those skilled in the art will understand that all or part of the processes of the methods described in the above embodiments can be implemented by a computer program instructing related hardware (such as a processor, controller, etc.), and the computer program can be stored in a computer-readable storage medium. The computer-readable storage medium may be a disk, optical disk, read-only memory, or random access memory, etc.

[0095] The above provides a detailed description of the intrusion detection and defense method, apparatus, equipment, and medium based on dynamic honeypots provided by this invention. Specific examples have been used to illustrate the principles and implementation methods of this invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this invention. At the same time, those skilled in the art will recognize that there will be changes in the specific implementation methods and application scope based on the ideas of this invention. Therefore, the content of this specification should not be construed as a limitation of this invention.

Claims

1. An intrusion detection and defense method based on dynamic honeypots, characterized in that, include: Deploy honeypot trapping environments on the vehicle controller; Monitor and record the behavior logs of suspected attackers accessing the honeypot trapping environment; Based on the Hidden Markov Model, the attack stage of the suspected visitor is identified according to the behavior log, and the next attack behavior of the suspected visitor is predicted. A new honeypot configuration strategy is generated based on the next attack behavior, and the honeypot trapping environment is dynamically updated based on the honeypot configuration strategy.

2. The intrusion detection and defense method based on dynamic honeypots according to claim 1, characterized in that, The deployment of the honeypot trapping environment on the vehicle controller includes: Port emulation is performed on the vehicle controller to generate a fake service port, and the fake service port is configured as an open port with a weak password for access. Vulnerability simulation was performed on the vehicle controller. The vehicle controller performs credential forgery, including forged ordinary user credentials corresponding to the operating system and forged certificates corresponding to vehicle-to-cloud communication; Fake data is generated in the vehicle controller, which includes fake log files and fake configuration files containing fake sensitive information.

3. The intrusion detection and defense method based on dynamic honeypots according to claim 2, characterized in that, The vehicle controller includes critical controllers, and vulnerability simulation is performed on the vehicle controller, including: An independent, isolated operating environment is constructed on the critical controller using isolation technology; the isolated operating environment is a virtual environment with resource isolation, used to isolate and run one or more software services that have vulnerabilities. Deploy an open-source software vulnerability environment on the isolated operating environment; the open-source software vulnerability environment includes a known vulnerability environment and a fictitious vulnerability environment. Deploy an application-layer software vulnerability environment on the isolated operating environment.

4. The intrusion detection and defense method based on dynamic honeypots according to claim 1, characterized in that, The monitoring and recording of behavior logs of suspected attackers accessing the honeypot trapping environment includes: Users who access the honeypot trapping environment are identified as suspected attackers by using a taint-marking method. The behavior log of the suspected attacker is recorded, including operating system layer attack behavior information, cloud access attack behavior information, and network scanning information.

5. The intrusion detection and defense method based on dynamic honeypots according to claim 2, characterized in that, The method based on a Hidden Markov Model (HMM) identifies the current attack stage of the suspected visitor based on the behavior logs and predicts the next attack behavior of the suspected visitor, including: The Hidden Markov Model is trained based on the training dataset to obtain an attack identification and prediction model; the training dataset includes labeled training data for attack phase types and attack behavior types; the attack phase types include intelligence gathering phase, initial intrusion phase, lateral movement phase, and information gathering and leakage phase. The behavioral characteristics are obtained from the behavioral logs, and the behavioral characteristics are input into the attack identification and prediction model to output the current attack stage and the predicted next attack behavior.

6. The intrusion detection and defense method based on dynamic honeypots according to claim 5, characterized in that, The step of generating a new honeypot configuration strategy based on the next attack behavior includes: When the next attack action is the intelligence gathering phase, the honeypot configuration strategy is determined to be to perform the port emulation. When the next attack action is the initial intrusion phase, the honeypot configuration strategy is determined to perform the vulnerability simulation. When the next attack action is the lateral movement phase, the honeypot configuration policy is determined to perform the credential forgery. When the next attack action is the lateral movement phase, the honeypot configuration strategy is determined to generate the fake data.

7. The intrusion detection and defense method based on dynamic honeypots according to any one of claims 1 to 6, characterized in that, Also includes: Obtain basic attack information, reputation database whitelist, attacker's geographical location, and payload characteristics; An attacker profile is constructed based on the reputation database whitelist, the attacker's geographical location, the payload characteristics, the basic attack information, and the behavior logs. The attacker's profile and the behavior logs are uploaded to the cloud server.

8. An intelligent vehicle, characterized in that, include: Deployment module for deploying honeypot trapping environments on vehicle controllers; The monitoring module is used to monitor and record the behavior logs of suspected attackers accessing the honeypot trapping environment; The identification module is used to identify the current attack stage of the suspected visitor based on the behavior log using a hidden Markov model, and to predict the next attack behavior of the suspected visitor. The configuration module is used to generate a new honeypot configuration strategy based on the next attack behavior, and to dynamically update the honeypot trapping environment based on the honeypot configuration strategy.

9. An electronic device, characterized in that, Including memory and processor, among which, The memory is used to store programs; The processor, coupled to the memory, is used to execute the program stored in the memory to implement the steps in the dynamic honeypot-based intrusion detection and defense method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Used to store computer-readable programs or instructions, which, when executed by a processor, can implement the steps in the dynamic honeypot-based intrusion detection and defense method described in any one of claims 1 to 7.

Citation Information

Cited By

  • Attack isolation method and system for multi-level honeynet architecture

    CN121441648A