Intelligent vehicle information security vulnerability assessment method and system

By reading data streams from intelligent vehicle ECUs, generating vulnerability assessment information and issuing warnings, the problem of insufficient security in intelligent vehicle ECUs is solved, and efficient and widespread vulnerability assessment and remediation are achieved.

CN114491564BActive Publication Date: 2026-02-03PATEO CONNECT (WUHAN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210136762.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-15
Publication Date
2026-02-03
Estimated Expiration
2042-02-15

AI Technical Summary

Technical Problem

There is insufficient attention paid to the security of existing intelligent vehicle ECUs, and the CAN bus lacks effective security protection, making the ECUs vulnerable to attacks. There is also a lack of mature security standards and evaluation methods.

Method used

Data streams are read from the vehicle ECU via the CAN bus to generate vulnerability assessment information. The vulnerability level is determined based on the mutation success rate, and corresponding warning information is issued to achieve the assessment and remediation of ECU security vulnerabilities.

Benefits of technology

It provides comprehensive testing, efficiently assesses ECU security vulnerabilities, promptly identifies vulnerability levels, reduces manual remediation workload, and improves security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114491564B_ABST
    Figure CN114491564B_ABST
Patent Text Reader

Abstract

The application discloses a kind of intelligent vehicle information security vulnerability evaluation method and system, non-transitory machine-readable medium, data processing system and car machine system, to analyze the security vulnerability possibly existing in vehicle ECU, so that evaluation personnel can master whether there is a vulnerability and the level of vulnerability in time.The intelligent vehicle information security evaluation method comprises: reading data stream from the electronic control unit of the vehicle through the CAN bus;Based on the data stream obtained, generate vulnerability assessment information for assessing the level of vulnerability;And according to the level of vulnerability of vulnerability assessment information, issue early warning information corresponding to vulnerability assessment information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intelligent vehicle information security, and more specifically, to a method and system for assessing information security vulnerabilities in a CAN (Controller Area Network) bus connected to an intelligent ECU (Electronic Control Unit). Background Technology

[0002] Intelligent vehicles are comprehensive systems integrating environmental perception, planning and decision-making, and multi-level assisted driving functions. They utilize technologies such as computers, modern sensors, information fusion, communication, artificial intelligence, and automatic control, making them typical high-tech complexes. With the rapid development of vehicle manufacturing and network communication technologies, vehicles are becoming increasingly intelligent, with more and more connected functions and a greater diversity of components. Currently, most manufacturers focus only on the performance testing of intelligent vehicle ECUs, paying less attention to their security features, and there are no mature international or domestic ECU security standards. Furthermore, the CAN bus connected to most vehicle ECUs lacks any security protection. This allows many ECUs to be accessed by attackers. While a few manufacturers have protective measures, these are only at a rudimentary stage, such as gateway packet filtering, and their reliability is low. Summary of the Invention

[0003] The purpose of this application is to provide a method and system for assessing information security vulnerabilities in intelligent vehicles, a non-transitory machine-readable medium, a data processing system, and an in-vehicle system. Its advantage is that it can issue different warning messages according to the vulnerability level, so that assessors can intuitively understand the vulnerability situation.

[0004] The purpose of this application is to provide a method system for assessing information security vulnerabilities in intelligent vehicles, a non-transitory machine-readable medium, a data processing system, and an in-vehicle system. Its advantages are that it can analyze potential security vulnerabilities in ECUs, has a wide testing coverage, and high execution efficiency.

[0005] The purpose of this application is to provide a method and system for assessing information security vulnerabilities in intelligent vehicles, a non-transitory machine-readable medium, a data processing system, and an in-vehicle system. Its advantage lies in its ability to initiate corresponding assessment level responses based on vulnerability levels, enabling assessors to promptly grasp whether vulnerabilities have occurred and their vulnerability levels.

[0006] To achieve the above objectives, this application provides a method for assessing the information security of intelligent vehicles, comprising: reading data streams from the vehicle's electronic control unit via a CAN bus; generating vulnerability assessment information based on the acquired data streams to evaluate vulnerability levels; and issuing early warning information corresponding to the vulnerability assessment information based on the vulnerability level of the vulnerability assessment information. This method can be performed when a vulnerability appears in the intelligent vehicle, or it can be used to perform attack simulation detection before a vulnerability appears. Furthermore, this method can also be applied to fields requiring the detection of information security vulnerabilities.

[0007] In one embodiment, generating vulnerability assessment information for evaluating vulnerability levels based on the acquired data stream may include: generating a first number of single-frame messages from the acquired data stream, and extracting a second number of single-frame messages with the same message ID from the first number of generated single-frame messages, wherein each single-frame message corresponds to a field; for each field in the second number of fields corresponding to the second number of single-frame messages, mutating the field to generate multiple CAN data frame test cases, determining the mutation success rate of the field based on a first ratio of the number of CAN data frame test cases in which the field successfully mutates to the total number of CAN data frame test cases in the field; determining a second ratio of the mutation success rate of each field in the second number of fields to the sum of the mutation success rates of all fields in the second number of fields, and generating vulnerability assessment information for evaluating vulnerability levels based on the magnitude of the second ratio.

[0008] In one embodiment, generating vulnerability assessment information for evaluating vulnerability levels based on the magnitude of the second ratio may include: generating vulnerability assessment information for evaluating vulnerability levels based on a comparison result of the second ratio with at least one predetermined threshold. The at least one threshold includes a first threshold and a second threshold, and wherein generating vulnerability assessment information for evaluating vulnerability levels based on the comparison result of the second ratio with at least one predetermined threshold includes at least one of the following: generating vulnerability assessment information corresponding to low-risk vulnerabilities in response to the second ratio being less than the first threshold; generating vulnerability assessment information corresponding to medium-risk vulnerabilities in response to the second ratio being greater than or equal to the first threshold and less than the second threshold; and generating vulnerability assessment information corresponding to high-risk vulnerabilities in response to the second ratio being greater than or equal to the second threshold.

[0009] In one embodiment, issuing warning information corresponding to vulnerability assessment information based on vulnerability level may include issuing different warning information based on different vulnerability levels of the received vulnerability assessment information.

[0010] To achieve the above objectives, this application provides an intelligent vehicle information security vulnerability assessment system, comprising: a data acquisition unit configured to read data streams from a vehicle ECU via a CAN bus; a data assessment unit configured to generate vulnerability assessment information based on the data streams from the data acquisition unit to assess vulnerability levels; and an assessment response unit configured to issue warning information corresponding to the vulnerability assessment information based on the vulnerability level of the vulnerability assessment information after receiving the vulnerability assessment information.

[0011] To achieve the above objectives, this application also provides a non-transitory machine-readable medium storing instructions that, when executed by a processor, instruct the processor to perform the aforementioned intelligent vehicle information security assessment method.

[0012] To achieve the above objectives, this application also provides a data processing system, including: a processor; and a memory connected to the processor to store instructions, which, when executed by the processor, cause the processor to perform the above-described intelligent vehicle information security assessment method.

[0013] To achieve the above objectives, this application also provides a vehicle infotainment system, including the aforementioned data processing system.

[0014] Compared with existing technologies, this application offers broader testing coverage and higher execution efficiency. Because it can classify vulnerability levels, assessors can intuitively view vulnerability information and implement remediation. Furthermore, the ability to issue corresponding early warning responses based on vulnerability levels allows assessors to promptly ascertain the existence and severity of vulnerabilities. Attached Figure Description

[0015] Figure 1 This is a schematic diagram of an intelligent vehicle information security vulnerability assessment system according to an embodiment of this application.

[0016] Figure 2 This is a schematic diagram of the data evaluation unit of the intelligent vehicle information security vulnerability assessment system according to an embodiment of this application.

[0017] Figure 3 This is a schematic diagram of the assessment response unit of the intelligent vehicle information security vulnerability assessment system according to an embodiment of this application.

[0018] Figure 4 This is a flowchart illustrating a method for assessing information security vulnerabilities in intelligent vehicles according to an embodiment of this application.

[0019] Figure 5 This is a flowchart illustrating a specific process for generating vulnerability assessment information for evaluating vulnerability levels based on the acquired data stream, according to an embodiment of this application.

[0020] Figure 6This is a schematic block diagram illustrating a data processing system according to an embodiment of this application. Detailed Implementation

[0021] Various embodiments and aspects of this application will be described with reference to the details discussed below, and the accompanying drawings will illustrate these various embodiments. The following description and drawings are illustrative of this application and should not be construed as limiting it. Many specific details are described to provide a comprehensive understanding of the various embodiments of this application. However, in some cases, well-known or conventional details have not been described to provide a concise discussion of the embodiments of this application.

[0022] It should also be understood that, unless explicitly stated otherwise or contradicted by the context, the specific steps included in the methods described in this application are not necessarily limited to the order in which they are described. For example, a particular process sequence may be performed differently from the order in which they are described. For instance, two consecutively described processes may be performed substantially simultaneously, or in the reverse order of their description.

[0023] The present application will now be described in detail with reference to the accompanying drawings and embodiments.

[0024] Figure 1 This is a schematic diagram of an intelligent vehicle information security vulnerability assessment system according to an embodiment of this application.

[0025] like Figure 1 As shown, according to an embodiment of this application, the intelligent vehicle information security vulnerability assessment system 10 may include a data acquisition unit 100, a data assessment unit 200, and an assessment response unit 300. The output terminal of the data acquisition unit 100 is electrically connected to the input terminal of the data assessment unit 200, and the output terminal of the data assessment unit 200 is electrically connected to the input terminal of the assessment response unit 300. According to an embodiment of this application, the intelligent vehicle information security vulnerability assessment system 10 may further include a data storage unit 400, which is electrically connected to another output terminal of the data assessment unit 200.

[0026] In the vehicle control network, vehicle ECUs cooperate with each other via CAN bus data. Under normal operation, the vehicle ECU can periodically send CAN data frames describing its own status to the vehicle control network, and can also receive data frames with the same ID that change the ECU's functional status. Each ECU obtains the message information it needs by recognizing the CAN data frame ID, so system 10 can communicate with the ECUs via the CAN bus.

[0027] According to an embodiment of this application, the data acquisition unit 100 can be configured to acquire data frames from the vehicle ECU via the CAN bus (i.e., read data streams from the vehicle ECU) and transmit the acquired data streams to the data evaluation unit 200.

[0028] The data evaluation unit 200 can be configured to preprocess the acquired data stream. Specifically, the data evaluation unit 200 can be configured to generate vulnerability assessment information based on the data stream from the data acquisition unit 100, which assesses the vulnerability level. The vulnerability level may include, for example, low-risk, medium-risk, and high-risk levels. However, it should be understood that the vulnerability level is not limited to this, and fewer or more levels can be set as needed.

[0029] The assessment response unit 300 can be configured to issue a warning message corresponding to the vulnerability assessment information based on the vulnerability level of the vulnerability assessment information after receiving the vulnerability assessment information. The warning message may include, for example, voice messages, indicator light messages, etc. However, it should be understood that the warning message is not limited to these; the warning message can be any type of information, as long as it can facilitate the assessment personnel to notice the vulnerability.

[0030] The data storage unit 400 can store the simulation results of the data evaluation unit 200. For example, the data storage unit 400 can store the simulation results in the form of a log. It should be understood that the storage format and the stored data are not limited thereto. According to embodiments of this application, the data storage unit 400 can also store at least one predetermined threshold for evaluating vulnerability levels, which will be described in detail below.

[0031] Figure 2 This is a schematic diagram of the data evaluation unit of the intelligent vehicle information security vulnerability assessment system according to an embodiment of this application.

[0032] like Figure 2 As shown, according to an embodiment of this application, the data evaluation unit 200 may include a data processing module 210, a data simulation module 220, a vulnerability detection module 230, and a classification module 240. The input terminal of the data simulation module 220 may be electrically connected to the output terminal of the data processing module 210, the output terminal of the data simulation module 220 may be electrically connected to the input terminal of the vulnerability detection module 230, and the output terminal of the vulnerability detection module 230 may be electrically connected to the input terminal of the classification module 240. The data evaluation unit 200 may also include an early warning control module 250, and the output terminal of the classification module 240 may be electrically connected to the input terminal of the early warning control module 250.

[0033] The data processing module 210 can be configured to generate a first number of single-frame messages from the acquired data stream, and extract a second number of single-frame messages with the same message ID from the generated first number of single-frame messages, wherein each single-frame message corresponds to a field. In embodiments of this application, when the first number of single-frame messages includes multiple IDs, the first number may be greater than the second number, while when the first number of single-frame messages includes only one ID, the first number may be equal to the second number.

[0034] In one example of this application, the data processing module 210 can parse the data stream read from the ECU into multiple single-frame messages, extract the ID and data from each frame message, record the timestamp, compare the IDs between two adjacent frames, and if the message IDs are the same, send the messages with the same ID to the data simulation module 220. It should be understood that if there are message data with multiple IDs in the message data stream, each ID category of message data is processed in the same way before being sent to the data simulation module 220.

[0035] The data simulation module 220 can be configured to mutate each of a second number of fields corresponding to a second number of single-frame messages with the same ID to generate multiple CAN data frame test samples. According to an embodiment of this application, mutating fields to generate multiple CAN data frame test samples may include: for fields having a non-periodic incrementing attribute and valid bytes, mutating by valid bytes to generate multiple CAN data frame test samples.

[0036] In one example of this application, the data simulation module 220 may also receive data features describing the incremental attributes of a field from the data processing module 210. Typically, when the data stream of the message corresponding to a field is not under attack, the field includes periodically increasing bytes, i.e., the field has a periodically increasing attribute; while when the data stream of the message corresponding to a field is under attack, the field includes non-periodic increasing bytes, i.e., the field has a non-periodic increasing attribute. The data simulation module 220 can generate the field format of a test sample based on the received message ID and data features (i.e., the incremental attribute of the field), and based on the field type and field format in the message, mutate the acquired message data according to the field format of the test sample. Typically, mutation methods may include, for example, deleting bytes, adding bytes, or changing bytes. In an embodiment of this application, preferably, the mutation method can employ incremental mutation of a single byte to generate multiple CAN data frame test samples. If there are multiple valid bytes in the CAN message, each valid byte is mutated separately to generate a corresponding CAN data frame test sample. The mutation method used in this application has the advantages of wide coverage of generated test cases and high execution efficiency. Furthermore, since the incremental attribute of a field can be used to determine whether the data stream of the corresponding message has been attacked, this application can also directly repair existing vulnerabilities according to existing vulnerability handling solutions, reducing the workload of manual repair.

[0037] The vulnerability detection module 230 can be configured to: for each field in a second number of fields corresponding to a second number of single-frame messages, determine the mutation success rate of the field based on a first ratio of the number of successfully mutated CAN data frame test samples of the field to the total number of CAN data frame test samples of the field; and determine a second ratio of the mutation success rate of each field in the second number of fields to the sum of the mutation success rates of all fields in the second number of fields. According to an embodiment of this application, determining the mutation success rate of a field based on the first ratio of the number of successfully mutated CAN data frame test samples of the field to the total number of CAN data frame test samples of the field may include: detecting whether a CAN data frame test sample has been successfully mutated based on whether there is an abnormal response in the CAN signal corresponding to a CAN data frame test sample mutated by a single byte (e.g., a single valid byte); and determining the mutation success rate of the field based on the first ratio of the number of successfully mutated CAN data frame test samples of the field to the total number of CAN data frame test samples of the field.

[0038] In one example of this application, assuming the total number of all test samples for field i is S, and the number of test samples with abnormal responses (i.e., test samples with abnormal responses in the corresponding CAN signal) when all test samples for this field are tested is M, then the mutation success rate P of this field is... i It can be expressed by the following formula (1):

[0039]

[0040] That is, the mutation success rate P of field i i The first ratio of the number M of test cases with abnormal responses to the total number S of test cases for this field.

[0041] The vulnerability detection module 230 can calculate the success mutation rate P of each field using the following formula (2). i The second ratio W is relative to the sum of the successful mutation rates of all fields in the second quantity.

[0042]

[0043] Where 0≤i≤n, and n is the number of bytes included in the field (e.g., the number of valid bytes).

[0044] The vulnerability classification module 240 can be configured to generate vulnerability assessment information for evaluating vulnerability levels based on the magnitude of a second ratio. According to an embodiment of this application, the vulnerability classification module 240 can be configured to generate vulnerability assessment information for evaluating vulnerability levels based on a comparison result between the second ratio and at least one predetermined threshold. As described above, the predetermined at least one threshold can be stored in the data storage unit 400. According to an embodiment of this application, the at least one threshold may include a first threshold and a second threshold, but this application is not limited thereto; the number of thresholds can vary depending on the number of vulnerability levels set as needed.

[0045] When at least one threshold includes a first threshold and a second threshold, the level classification module 240 generates vulnerability assessment information for assessing vulnerability levels based on a comparison result of a second ratio with at least one predetermined threshold, which may include at least one of the following: generating vulnerability assessment information corresponding to low-risk vulnerabilities in response to a second ratio being less than a first threshold; generating vulnerability assessment information corresponding to medium-risk vulnerabilities in response to a second ratio being greater than or equal to a first threshold and less than a second threshold; and generating vulnerability assessment information corresponding to high-risk vulnerabilities in response to a second ratio being greater than or equal to a second threshold.

[0046] In one example of this application, the vulnerability classification module 240 can compare the aforementioned second ratio W with a first threshold K1 and a second threshold K2 in a set of vulnerability level thresholds {K1, K2}. If the second ratio W is less than the first threshold K1, the vulnerability classification module 240 can generate vulnerability assessment information corresponding to low-risk vulnerabilities. If the second ratio W is greater than or equal to the first threshold K1 and less than the second threshold K2, the vulnerability classification module 240 can generate vulnerability assessment information corresponding to medium-risk vulnerabilities. If the second ratio W is greater than or equal to the second threshold K2, the vulnerability classification module 240 can generate vulnerability assessment information corresponding to high-risk vulnerabilities.

[0047] The early warning control module 250 can be configured to send the vulnerability assessment information generated by the level classification module 240 to the assessment response unit 300.

[0048] Figure 3 This is a schematic diagram of the assessment response unit of the intelligent vehicle information security vulnerability assessment system according to an embodiment of this application.

[0049] like Figure 3As shown, the assessment response unit 300 may include an assessment output module 310 and an assessment warning module 320. In embodiments of this application, the input terminals of the assessment output module 310 and the assessment warning module 320 are electrically connected to the output terminal of the warning control module 250. After receiving vulnerability assessment information from the warning control module 250, the assessment output module 310 can output an assessment report. The assessment warning module 320 can issue different warning messages according to the received vulnerability level. For example, the assessment warning module 320 can display different colored warning lights or emit different warning sounds according to different warning messages (but this application is not limited to this), so that assessors can intuitively understand the vulnerability situation.

[0050] As described above, in the intelligent vehicle information security vulnerability assessment system 10 according to this application, the data acquisition unit 100 reads the data stream from the ECU of the intelligent vehicle and transmits the acquired data stream to the data assessment unit 200. The data processing module 210 preprocesses the acquired data stream, parses the data stream read from the ECU into single-frame messages, and extracts the ID and data from each frame message, while recording the timestamp. The IDs of two adjacent frames are compared. If the message IDs are the same, the message ID is sent to the data simulation module 220. At the same time, the data with the same message ID is also compared. If there is a periodically increasing byte, the increasing attribute is also sent to the data simulation module 220. If there are message data with multiple IDs in the message data stream, they are processed separately. The same method is used to process the messages of each ID category, and the obtained data information is sent to the data simulation module 220. The data simulation module 220 generates CAN data frame test samples. The vulnerability detection module 230 calculates the ratio of the successful mutation rate of each field to the sum of the successful mutation rates of all fields. The level classification module 240 compares the obtained vulnerability information with the level classification threshold obtained from the data storage unit 400 to determine the level of the vulnerability. The leveled vulnerability information is then transmitted to the early warning control module 250, and then transmitted by the early warning control module 250 to the evaluation response unit 300. The evaluation output module 310 can output an evaluation report. The evaluation early warning module 320 can issue different early warning information according to the vulnerability level so that the evaluators can intuitively understand the vulnerability situation.

[0051] As described above, in the intelligent vehicle information security vulnerability assessment system 10 according to this application, data streams are read from the ECU of the intelligent vehicle, and the acquired message data is mutated according to the field format of the test sample. The CAN data frame test sample is used for simulation detection to obtain the mutation success rate of each field. By calculating the ratio of the success mutation rate of each field to the sum of the success mutation rates of all fields, the potential security vulnerabilities in the ECU can be analyzed. This makes the test coverage of this application broad and the execution efficiency high.

[0052] In the intelligent vehicle information security vulnerability assessment system 10 according to this application, during the vulnerability assessment process, the ratio is compared with a set minimum threshold to classify and store the vulnerability, so that the assessed vulnerability report can be easily viewed by the assessor and the vulnerability can be repaired.

[0053] In the intelligent vehicle information security vulnerability assessment system 10 according to this application, when assessing vulnerabilities, it can initiate a corresponding assessment level response based on the vulnerability level, so that assessors can promptly grasp whether a vulnerability has occurred and the vulnerability level.

[0054] Figure 4 This is a flowchart illustrating a method for assessing information security vulnerabilities in intelligent vehicles according to an embodiment of this application. Figure 5 This is a flowchart illustrating a specific process for generating vulnerability assessment information for evaluating vulnerability levels based on the acquired data stream, according to an embodiment of this application.

[0055] like Figure 4 As shown, according to the embodiments of this application, the intelligent vehicle information security vulnerability assessment method 400 may include: step S410, reading a data stream from the vehicle's electronic control unit via a CAN bus; step S420, generating vulnerability assessment information for assessing vulnerability levels based on the acquired data stream; and step S430, issuing warning information corresponding to the vulnerability assessment information based on the vulnerability level of the vulnerability assessment information.

[0056] In embodiments of this application, vulnerability levels may include, for example, low-risk, medium-risk, and high-risk levels. However, it should be understood that vulnerability levels are not limited to these, and fewer or more levels may be set as needed.

[0057] In the embodiments of this application, the warning information may include, for example, voice information, indicator light information, etc. However, it should be understood that the warning information is not limited to these; the warning information can be any type of information, as long as it can facilitate the assessment personnel to notice the vulnerability.

[0058] like Figure 5As shown, according to the embodiment of this application, step S420 may include: step S422, generating a first number of single-frame messages from the acquired data stream, and extracting a second number of single-frame messages with the same message ID from the first number of generated single-frame messages, wherein each single-frame message corresponds to a field; step S424, for each field in the second number of fields corresponding to the second number of single-frame messages, mutating the field to generate multiple CAN data frame test samples, and determining the mutation success rate of the field based on a first ratio of the number of CAN data frame test samples with successful mutation to the total number of CAN data frame test samples of the field; step S426, determining a second ratio of the mutation success rate of each field in the second number of fields to the sum of the mutation success rates of all fields in the second number of fields; step S428, generating vulnerability assessment information to assess the vulnerability level based on the magnitude of the second ratio.

[0059] In embodiments of this application, when the first number of single-frame messages includes multiple IDs, the first number may be greater than the second number, while when the first number of single-frame messages includes only one ID, the first number may be equal to the second number.

[0060] In one example of this application, step S422 may be implemented, for example, as parsing the data stream read from the ECU into multiple single-frame messages, extracting the ID and data from each frame message, recording a timestamp, and comparing the IDs between two adjacent frames to extract single-frame messages with the same message ID. It should be understood that if there are message data with multiple IDs in the message data stream, the same method is used to process the data for each ID category of the message.

[0061] According to the embodiments of this application, the step S424 of mutating the field to generate multiple CAN data frame test samples may include: for fields with non-periodic increasing attributes and valid bytes, mutating by valid bytes to generate multiple CAN data frame test samples.

[0062] In one example of this application, data features describing the incremental attributes of a field can also be obtained. Typically, when the data stream of the message corresponding to a field is not attacked, the field includes periodically increasing bytes, i.e., the field has a periodically increasing attribute; while when the data stream of the message corresponding to a field is attacked, the field includes non-periodic increasing bytes, i.e., the field has a non-periodic increasing attribute. Based on the message ID and data features (i.e., the incremental attribute of the field), and according to the type and format of the field in the message, the field format of the test sample can be generated, and the obtained message data can be mutated according to the field format of the test sample. Typically, the mutation method can include, for example, deleting bytes, adding bytes, or changing bytes. In an embodiment of this application, preferably, the mutation method can use incremental mutation of a single byte to generate multiple CAN data frame test samples. If there are multiple valid bytes in the CAN message, each valid byte is mutated separately to generate the corresponding CAN data frame test sample. The mutation method used in this application has the advantages of wide coverage of generated test samples and high execution efficiency. Furthermore, since the data stream of the message corresponding to a field can be determined by the incrementing attribute of the field, this application can also directly repair the existing vulnerability based on the identified vulnerability and the existing vulnerability handling scheme, thereby reducing the workload of manual repair.

[0063] According to an embodiment of this application, determining the field mutation success rate in step S424 based on a first ratio of the number of CAN data frame test samples with successful field mutation to the total number of CAN data frame test samples for the field may include: detecting whether a CAN data frame test sample has been successfully mutated based on whether there is an abnormal response in the CAN signal corresponding to a CAN data frame test sample with a single byte (e.g., a single valid byte) mutated; and determining the field mutation success rate based on a first ratio of the number of CAN data frame test samples with successful field mutation to the total number of CAN data frame test samples for the field.

[0064] In one example of this application, assuming the total number of all test samples for field i is S, and the number of test samples with abnormal responses (i.e., test samples with abnormal responses in the corresponding CAN signal) when all test samples for this field are tested is M, then the mutation success rate P of this field is... i This is expressed by the following formula (3):

[0065]

[0066] That is, the mutation success rate P of field i i The first ratio of the number M of test cases with abnormal responses to the total number S of test cases for this field.

[0067] The success rate of mutation P for each field can be calculated using the following formula (4). i The second ratio W is relative to the sum of the successful mutation rates of all fields in the second quantity.

[0068]

[0069] Where 0≤i≤n, and n is the number of bytes included in the field (e.g., the number of valid bytes).

[0070] According to the embodiments of this application, the vulnerability assessment information for assessing the vulnerability level in step S428 may include: generating vulnerability assessment information for assessing the vulnerability level based on the comparison result of the second ratio with at least one predetermined threshold.

[0071] According to embodiments of this application, at least one threshold may include a first threshold and a second threshold, but this application is not limited thereto, and the number of thresholds may vary depending on the number of vulnerability levels set in actual needs. When at least one threshold includes a first threshold and a second threshold, generating vulnerability assessment information for evaluating vulnerability levels based on a comparison result of a second ratio with at least one predetermined threshold may include at least one of the following: generating vulnerability assessment information corresponding to low-risk vulnerabilities in response to a second ratio being less than a first threshold; generating vulnerability assessment information corresponding to medium-risk vulnerabilities in response to a second ratio being greater than or equal to a first threshold and less than a second threshold; and generating vulnerability assessment information corresponding to high-risk vulnerabilities in response to a second ratio being greater than or equal to a second threshold.

[0072] According to the embodiments of this application, issuing warning information corresponding to vulnerability assessment information based on vulnerability level may include: issuing different warning information based on different vulnerability levels of the received vulnerability assessment information.

[0073] In the intelligent vehicle information security vulnerability assessment method according to this application, different warning messages can be issued according to the vulnerability level, which enables assessors to intuitively understand the vulnerability situation.

[0074] In the intelligent vehicle information security vulnerability assessment method according to this application, data streams are read from the ECU of the intelligent vehicle, and the acquired message data is mutated according to the field format of the test sample. The CAN data frame test sample is used for simulation detection to obtain the mutation success rate of each field. By calculating the ratio of the success mutation rate of each field to the sum of the success mutation rates of all fields, the potential security vulnerabilities in the ECU can be analyzed. This makes the test coverage of this application broad and the execution efficiency high.

[0075] In the intelligent vehicle information security vulnerability assessment method according to this application, during the vulnerability assessment process, the ratio is compared with a set minimum threshold to classify and store the vulnerability level, so that the assessed vulnerability report can be easily viewed by the assessor and the vulnerability can be repaired.

[0076] In the intelligent vehicle information security vulnerability assessment method according to this application, when assessing vulnerabilities, a corresponding assessment level response can be initiated based on the vulnerability level, enabling assessors to promptly grasp whether a vulnerability has occurred and the vulnerability level.

[0077] Figure 6 A block diagram of a data processing system 500 according to an embodiment of this application is shown. For example, system 500 may represent any data processing system performing any of the above-described processes or methods, such as the aforementioned client device or server. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or claimed herein.

[0078] System 500 may include many different components. These components may be implemented as integrated circuits (ICs), portions of integrated circuits, discrete electronic devices, or other modules suitable for circuit boards (such as motherboards or expansion cards of a computer system), or implemented as components otherwise incorporated into the rack of a computer system.

[0079] It should also be noted that System 500 is intended to show a high-level view of the many components of a computer system. However, it should be understood that additional components may be present in some implementations, and that arrangements of components different from those shown may appear in other implementations. System 500 may represent a desktop computer, laptop computer, tablet computer, server, mobile phone, media player, personal digital assistant (PDA), smartwatch, personal communicator, gaming device, network router or hub, wireless access point (AP) or repeater, set-top box, or a combination thereof. Furthermore, although only a single machine or system is shown, the terms "machine" or "system" should also be understood to include any combination of machines or systems that individually or jointly execute a set (or more) of instructions to perform any one or more methods discussed herein.

[0080] like Figure 6As shown, system 500 includes processor 501, which can perform various appropriate actions and processes according to a computer program stored in read-only memory (ROM) 502 or a computer program loaded from memory 508 into random access memory (RAM) 503. RAM 503 may also store various programs and data required for the operation of system 500. Processor 501, ROM 502, and RAM 503 are interconnected via bus 504. I / O interface (input / output interface) 505 is also connected to bus 504.

[0081] Multiple components in system 500 are connected to I / O interface 505, including: input unit 506, such as keyboard, mouse, etc.; output unit 507, such as various types of monitors, speakers, etc.; memory 508, such as disk, optical disk, etc.; and communication unit 509, such as network card, modem, wireless transceiver, etc. Communication unit 509 allows system 500 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0082] Processor 501 can be a variety of general-purpose and / or special-purpose processing units with processing and computing capabilities. Some examples of processor 501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 501 performs the various methods and processes described above, such as the intelligent vehicle information security assessment method. For example, in some embodiments, the intelligent vehicle information security assessment method can be implemented as a computer software program tangibly contained in a machine-readable storage medium, such as memory 508. In some embodiments, part or all of the computer program can be loaded and / or installed on the data processing system 500 via ROM 502 and / or communication unit 509. When the computer program is loaded into RAM 503 and executed by processor 501, one or more steps of the intelligent vehicle information security assessment method described above can be performed. Alternatively, in other embodiments, processor 501 can be configured to perform the intelligent vehicle information security assessment method by any other suitable means (e.g., by means of firmware).

[0083] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0084] The program code used to implement the methods of this application may be written in any combination of one or more programming languages. The program code may be packaged into a computer program product. This program code or computer program product may be provided to the processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by processor 501, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0085] In the context of this application, a machine-readable storage medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable storage medium can be a machine-readable signal storage medium or a machine-readable storage medium. A machine-readable storage medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0086] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0087] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0088] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service ecosystem, addressing the shortcomings of traditional physical hosts and VPS (Virtual Private Server, or simply "VPS") services, such as high management difficulty and weak business scalability. A server can also be a server in a distributed system or a server incorporating blockchain technology.

[0089] According to an embodiment of this application, a vehicle infotainment system (not shown) is also provided, which includes the data processing system 500 described above.

[0090] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this application can be achieved, and this is not limited herein.

[0091] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for assessing the information security of intelligent vehicles, the method comprising: Data streams are read from the vehicle's electronic control unit via the CAN bus; Vulnerability assessment information is generated based on the acquired data stream to evaluate the vulnerability level. as well as Based on the vulnerability level of the vulnerability assessment information, issue a warning message corresponding to the vulnerability assessment information; Vulnerability assessment information, generated based on the acquired data stream, is used to evaluate the vulnerability level and includes: A first number of single-frame messages are generated from the acquired data stream, and a second number of single-frame messages with the same message ID are extracted from the first number of generated single-frame messages, wherein each single-frame message corresponds to a field; For each of the second number of fields corresponding to the second number of single-frame messages: The fields are mutated to generate multiple CAN data frame test samples; The mutation success rate of the field is determined based on a first ratio of the number of CAN data frame test cases that successfully mutated the field to the total number of CAN data frame test cases for the field; and Determine a second ratio of the mutation success rate of each field in the second number of fields to the sum of the mutation success rates of all fields in the second number of fields, and Based on the magnitude of the second ratio, vulnerability assessment information is generated to evaluate the vulnerability level.

2. The method according to claim 1, wherein, The field is mutated to generate multiple CAN data frame test examples, including: For fields with non-periodic incrementing attributes and valid bytes, mutate according to the valid bytes to generate multiple CAN data frame test samples.

3. The method according to claim 1, wherein, The mutation success rate of the field is determined based on a first ratio of the number of successful CAN data frame test cases for that field to the total number of CAN data frame test cases for that field, including: The success of the CAN data frame test sample mutation is determined by whether there is an abnormal response in the CAN signal corresponding to the CAN data frame test sample with a single byte mutated; and The mutation success rate of the field is determined based on a first ratio of the number of CAN data frame test cases in which the mutation of the field is successful relative to the total number of CAN data frame test cases in the field.

4. The method according to claim 1, wherein, The vulnerability assessment information, which evaluates the vulnerability level based on the magnitude of the second ratio, includes: The vulnerability assessment information for evaluating the vulnerability level is generated based on the comparison result between the second ratio and at least one predetermined threshold.

5. The method according to claim 4, wherein, The at least one threshold includes a first threshold and a second threshold, and wherein generating the vulnerability assessment information for assessing the vulnerability level based on a comparison between the second ratio and the predetermined at least one threshold includes at least one of the following: In response to the second ratio being less than the first threshold, vulnerability assessment information corresponding to the low-risk vulnerability is generated; In response to the second ratio being greater than or equal to the first threshold and less than the second threshold, vulnerability assessment information corresponding to the medium-risk vulnerability is generated; and In response to the second ratio being greater than or equal to the second threshold, vulnerability assessment information corresponding to the high-risk vulnerability is generated.

6. The method according to claim 5, wherein, Based on the vulnerability level, the warning information corresponding to the vulnerability assessment information includes: Different warning messages are issued based on the different vulnerability levels of the received vulnerability assessment information.

7. The method according to claim 2, wherein, Test examples for generating multiple CAN data frames by mutating based on valid bytes include: The multiple CAN data frame test samples are generated by incrementally increasing the number of valid bytes.

8. A non-transitory machine-readable medium storing instructions that, when executed by a processor, cause the processor to perform the method according to any one of claims 1-7.

9. A data processing system, comprising: processor; as well as A memory, coupled to the processor, for storing instructions that, when executed by the processor, cause the processor to perform the method according to any one of claims 1-7.

10. A vehicle infotainment system, comprising the data processing system according to claim 9.

11. A smart vehicle information security vulnerability assessment system, the system comprising: The data acquisition unit is configured to read data streams from the vehicle ECU via the CAN bus; The data evaluation unit is configured to generate vulnerability evaluation information based on the data stream from the data acquisition unit to assess the vulnerability level. as well as The assessment response unit is configured to issue a warning message corresponding to the vulnerability assessment information based on the vulnerability level of the vulnerability assessment information after receiving the vulnerability assessment information. The data evaluation unit generates vulnerability evaluation information for assessing vulnerability levels based on the acquired data stream, including: A first number of single-frame messages are generated from the acquired data stream, and a second number of single-frame messages with the same message ID are extracted from the first number of generated single-frame messages, wherein each single-frame message corresponds to a field; For each of the second number of fields corresponding to the second number of single-frame messages: The fields are mutated to generate multiple CAN data frame test samples; The mutation success rate of the field is determined based on a first ratio of the number of CAN data frame test cases that successfully mutated the field to the total number of CAN data frame test cases for the field; and Determine a second ratio of the mutation success rate of each field in the second number of fields to the sum of the mutation success rates of all fields in the second number of fields, and Based on the magnitude of the second ratio, vulnerability assessment information is generated to evaluate the vulnerability level.

Citation Information

Patent Citations

  • Vehicle CAN bus test method and device, computer equipment and storage medium

    CN110191019A

  • Vehicle information safety monitoring device

    CN111131136A