Vulnerability Data Retrieval Method for Vehicle Operating System and Related Devices
By dividing the vulnerability data of the automotive operating system into multiple data segments, calculating and retrieving it using feature values, the problem of low vulnerability retrieval efficiency in the existing technology is solved, and more efficient and accurate vulnerability detection is achieved.
Patent Information
- Application Number
- CN202210673362.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-14
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-06-14
AI Technical Summary
The existing vulnerability retrieval technology for automotive operating systems is inefficient and requires comparison of each character one by one, resulting in a long search time.
By dividing the vulnerability data into N data segments according to the preset address bus width, calculating the characteristic values of each data segment, and retrieving the corresponding data in the target file based on these characteristic values, the process of comparing characters one by one is avoided.
It improves the efficiency of vulnerable data retrieval, reduces the search time, and ensures the accuracy of the search results.
Smart Images

Figure CN114896473B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent connected vehicles, and more particularly, to a method for retrieving vulnerability data of a vehicle operating system and related devices. Background Art
[0002] An intelligent connected vehicle is an organic combination of an intelligent vehicle and a vehicle network, that is, it is equipped with advanced on-vehicle sensors, controllers, actuators and other devices, and integrates modern communication and network technologies to achieve intelligent information exchange and sharing among people, vehicles, roads, and the background, realize safe, comfortable, energy-saving and efficient driving, and ultimately can replace humans to operate a new generation of vehicles.
[0003] The vehicle operating system of an intelligent connected vehicle is a set of programs running on the intelligent connected vehicle, which manages hardware resources, provides a software platform and interface, and provides basic services for upper-layer applications. From the perspective of whether it is related to the normal operation of the vehicle, the vehicle operating system is divided into a vehicle control operating system and an in-vehicle operating system.
[0004] Currently, open-source manufacturers of operating systems regularly announce the detailed information of patch codes for fixing vulnerabilities on their official websites. Other manufacturers develop vulnerability scanners based on the detailed information of the patch codes to scan whether there are discovered vulnerabilities on the vehicle operating system. Usually, the vulnerability scanner needs to retrieve the patch codes in the binary code file of the vehicle operating system to locate the position of the vulnerability patch codes. When the existing retrieval technology traverses the binary code file, it needs to compare each character in the patch codes one by one, so the retrieval efficiency is extremely low. Summary of the Invention
[0005] The purpose of the present invention is to provide a method for retrieving vulnerability data of a vehicle operating system and related devices, which can improve the efficiency of data retrieval.
[0006] To achieve the above purpose, the technical solutions adopted in the embodiments of the present invention are as follows:
[0007] In a first aspect, an embodiment of the present invention provides a method for retrieving vulnerability data of a vehicle operating system, the method including: obtaining vulnerability data of the vehicle operating system; dividing the vulnerability data into N data segments according to a preset address bus width to obtain the position sequence numbers of the N data segments corresponding to the vulnerability data, where N is a positive integer not less than 1; calculating a feature value of the vulnerability data according to the values of the N data segments and the position sequence number of each data segment; retrieving target data corresponding to the feature value from a target file according to the feature value of the vulnerability data, where the target file is a system file of the vehicle operating system with the vulnerability to be processed.
[0008] Further, the step of calculating the eigenvalue of the vulnerability data according to the values of the N data segments and the position sequence number of each data segment includes:
[0009] Sum the values of all the data segments to obtain a first result;
[0010] Determine the processing coefficient of each data segment according to the N and the position sequence number of each data segment, and the processing coefficient is used to characterize the position relationship between each data segment and the N;
[0011] Process the value of each data segment according to the processing coefficient of each data segment to obtain the processing result of the value of each data segment;
[0012] Sum the processing results of the values of all data segments to obtain a second result;
[0013] Combine the first result and the second result to obtain the eigenvalue of the vulnerability data.
[0014] Further, the formula used for combining the first result and the second result to obtain the eigenvalue of the vulnerability data is:
[0015] R = (low_32_bit(R 1 ) << 32) || (low_32_bit(R 2 ))), where R is the eigenvalue, low_32_bit is a function to take the lower 32 bits, << is the left shift operator, and || is the OR operator; R 1 is the first result, i is the position sequence number of the data segment, and Seg i is the value of the i-th data segment; R 2 is the second result, N is the total number of data segments.
[0016] Further, the step of combining the first result and the second result to obtain the eigenvalue of the vulnerability data further includes:
[0017] Calculate the MD5 value of the first result;
[0018] Calculate the MD5 value of the second result;
[0019] Merge the MD5 value of the first result and the MD5 value of the second result to obtain the eigenvalue of the vulnerability data.
[0020] Further, there is one eigenvalue of the vulnerability data, and the step of retrieving the target data corresponding to the eigenvalue from the target file includes:
[0021] Read first data to be compared with the same data length as the vulnerability data from the target file in sequence;
[0022] Calculate the eigenvalue of the first data to be compared;
[0023] If the eigenvalue of the first data to be compared is the same as the eigenvalue of the vulnerability data, it is determined that there is target data in the target file, where the target data is the first data to be compared.
[0024] Further, the vulnerability data includes first sample data and second sample data, and the eigenvalue of the vulnerability data includes the first eigenvalue of the first sample data and the second eigenvalue of the second sample data. The step of retrieving target data corresponding to the eigenvalue from the target file further includes:
[0025] Read first data to be compared with the same data length as the first sample data from the target file in sequence;
[0026] Calculate the eigenvalue of the first data to be compared;
[0027] If the eigenvalue of the first data to be compared is the same as the first eigenvalue, read second data to be compared with the same data length as the second sample data at a preset offset position from the first data to be compared;
[0028] Calculate the eigenvalue of the second data to be compared;
[0029] If the eigenvalue of the second data to be compared is the same as the second eigenvalue, use the first data to be compared as the target data.
[0030] Further, the method is applied to an intelligent connected vehicle, and the intelligent connected vehicle is communicatively connected to a server. The method further includes:
[0031] If the target data is retrieved from the target file, obtain the version number of the vehicle operating system of the vulnerability to be processed;
[0032] Send the vulnerability data, the target file, and the version number to the server to prompt that there is a vulnerability in the vehicle operating system of the intelligent connected vehicle.
[0033] Second aspect, an embodiment of the present invention provides a vulnerability data retrieval device for a vehicle operating system. The device includes: an acquisition module, configured to acquire vulnerability data of the vehicle operating system; a division module, configured to divide the vulnerability data into N data segments according to a preset address bus width, and obtain position sequence numbers of the N data segments corresponding to the vulnerability data, where N is a positive integer not less than 1; a calculation module, configured to calculate a feature value of the vulnerability data according to values of the N data segments and the position sequence number of each data segment; and a retrieval module, configured to retrieve target data corresponding to the feature value from a target file according to the feature value of the vulnerability data, where the target file is a system file of the vehicle operating system to be processed for vulnerabilities.
[0034] Third aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the vulnerability data retrieval method for a vehicle operating system as described in the first aspect above.
[0035] Fourth aspect, an embodiment of the present invention further provides a vulnerability data retrieval system for a vehicle operating system. The vulnerability data retrieval system for the vehicle operating system includes a server and an intelligent connected vehicle communicatively connected to the server. The intelligent connected vehicle is configured to obtain the vulnerability data of the vehicle operating system from the server and execute the vulnerability data retrieval method for the vehicle operating system as described in the first aspect above.
[0036] Compared with the prior art, a vulnerability data retrieval method and related device provided by an embodiment of the present invention, when it is necessary to perform vulnerability retrieval on a system file of a vehicle operating system to be processed for vulnerabilities, the obtained vulnerability data of the vehicle operating system is segmented to obtain position sequence numbers of N data segments corresponding to the vulnerability data. According to each of the N data segments and the position sequence number of each data segment, a feature value of the vulnerability data is calculated. According to the feature value, target data corresponding to the feature value is retrieved from the target file. In the embodiment of the present invention, the feature value of the vulnerability data is calculated according to the value of the data segment and the position sequence number of the data segment in the vulnerability data, and then data retrieval is performed according to the calculated feature value, avoiding pairwise comparison of each character during data retrieval, thereby improving the retrieval efficiency. Description of the Drawings
[0037] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0038] Figure 1Shows an example diagram of a vulnerability data retrieval system for a vehicle operating system provided by an embodiment of the present invention.
[0039] Figure 2 Shows a block schematic diagram of an intelligent connected vehicle provided by an embodiment of the present invention.
[0040] Figure 3 Shows a flowchart example of a method for retrieving vulnerability data of a vehicle operating system provided by an embodiment of the present invention Figure 1 。
[0041] Figure 4 Shows a flowchart example of a method for retrieving vulnerability data of a vehicle operating system provided by an embodiment of the present invention Figure 2 。
[0042] Figure 5 Shows an example diagram of a processing coefficient calculation provided by an embodiment of the present invention.
[0043] Figure 6 Shows another example diagram of a processing coefficient calculation provided by an embodiment of the present invention.
[0044] Figure 7 Shows a flowchart example of a method for retrieving vulnerability data of a vehicle operating system provided by an embodiment of the present invention Figure 3 。
[0045] Figure 8 Shows an example diagram of reading the first data to be compared provided by an embodiment of the present invention.
[0046] Figure 9 Shows a flowchart example of a method for retrieving vulnerability data of a vehicle operating system provided by an embodiment of the present invention Figure 4 。
[0047] Figure 10 Shows an example diagram of the offset between the second data to be compared and the first data to be compared provided by an embodiment of the present invention.
[0048] Figure 11 Shows a flowchart example diagram for retrieving all target data in a target file provided by an embodiment of the present invention.
[0049] Figure 12 Shows a flowchart example of a method for retrieving vulnerability data of a vehicle operating system provided by an embodiment of the present invention Figure 5 。
[0050] Figure 13 Shows a block schematic diagram of a vulnerability data retrieval device 100 for a vehicle operating system provided by an embodiment of the present invention.
[0051] Icons: 10 - Intelligent connected vehicle; 11 - Processor; 12 - Memory; 13 - Bus; 20 - Server; 100 - Vulnerability data retrieval device for vehicle operating system; 110 - Acquisition module; 120 - Division module; 130 - Calculation module; 140 - Retrieval module. Detailed implementation manners
[0052] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. Components of the embodiments of the present invention usually described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.
[0053] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0054] It should be noted that like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0055] In the description of the present invention, it should be noted that if terms such as "upper", "lower", "inner", "outer", etc. are used to indicate the orientation or positional relationship, it is based on the orientation or positional relationship shown in the accompanying drawings or the orientation or positional relationship when the product of the present invention is normally placed. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention.
[0056] In addition, if terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0057] It should be noted that the features in the embodiments of the present invention can be combined with each other without conflict.
[0058] Please refer to Figure 1 , Figure 1 which shows an example diagram of a vulnerability data retrieval system for a vehicle operating system provided by an embodiment of the present invention. Figure 1Among them, the intelligent connected vehicle 10 and the server 20 are communicatively connected. The system files of the vehicle operating system that is running are stored on the intelligent connected vehicle 10. The developers of the vehicle operating system will regularly announce the vulnerability data of newly discovered vulnerabilities. Some vulnerability detection tools for the vehicle operating system will also update the vulnerability detection tools according to the announced vulnerability data. By running the vulnerability detection tool, it is possible to detect whether the vehicle operating system running on the intelligent connected vehicle 10 has the newly discovered vulnerabilities. For a specific vulnerability, the detection method is as follows: obtain the vulnerability data of the specific vulnerability, divide the vulnerability data into N data segments according to the preset address bus width, calculate the eigenvalue of the vulnerability data according to the values of the N data segments and the position serial numbers of each data segment, and retrieve the target data corresponding to the eigenvalue from the target file in the system file of the vehicle operating system according to the eigenvalue of the specific vulnerability data. If the target data is retrieved, it is determined that the vehicle operating system has the specific vulnerability; otherwise, it is determined that the vehicle operating system does not have the specific vulnerability.
[0059] When it is determined that the vehicle operating system has the specific vulnerability, in order to notify the provider of the vehicle operating system in time for vulnerability repair, the intelligent connected vehicle 10 can send the vulnerability data, the system file, and the version number of the corresponding vehicle operating system to the server 20 pre-specified by the provider of the vehicle operating system, so that the provider of the vehicle operating system can timely repair the vulnerability for this vulnerability.
[0060] The intelligent connected vehicle 10 refers to the organic combination of the vehicle network and the intelligent vehicle. It is equipped with advanced on-vehicle sensors, controllers, actuators and other devices, and integrates modern communication and network technologies to realize intelligent information exchange and sharing among vehicles, people, roads, and the background, realize safe, comfortable, energy-saving, and efficient driving, and ultimately can replace humans to operate a new generation of vehicles.
[0061] It should be noted that the intelligent connected vehicle 10 can also be replaced by an in-vehicle terminal on the vehicle. The in-vehicle terminal is the front-end device of the vehicle monitoring and management system, also called the vehicle dispatching and monitoring TCU terminal (Transmission Control Unit, TCU). The in-vehicle terminal integrates multiple functions such as positioning, communication, and vehicle driving recorder, has a powerful business dispatching function and data processing ability, supports phone book calls, text message voice broadcasts, and has security alarm, wire cutting alarm, and remote safety fuel cut-off and power-off safety protection functions.
[0062] The server 20 is a physical computer device, can also be a virtual machine that realizes the same functions as the physical computer device, or can also be a cloud server.
[0063] On Figure 1 this basis, the embodiment of the present invention further provides Figure 1For a block diagram of the intelligent connected vehicle 10, please refer to Figure 2 , Figure 2 which shows a block diagram of the intelligent connected vehicle 10 provided by an embodiment of the present application. The intelligent connected vehicle 10 includes a processor 11, a memory 12, and a bus 13. The processor 11 is connected to the memory 12 through the bus 13.
[0064] The memory 12 is used to store programs, such as the vulnerability data retrieval device 100 of the vehicle operating system in the embodiments of the present invention. The vulnerability data retrieval device 100 of the vehicle operating system includes at least one software function module that can be stored in the memory 12 in the form of software or firmware. After receiving the execution instruction, the processor 11 executes the program to implement the vulnerability data retrieval method of the vehicle operating system disclosed in the embodiments of the present invention.
[0065] The memory 12 may include a high-speed random access memory (Random Access Memory, RAM), and may also include a non-volatile memory (non-volatile memory, NVM). The preset address bus width in the above embodiments is the maximum bit width that the memory 12 can transfer data at one time.
[0066] The processor 11 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor 11 or the instructions in the form of software. The above processor 11 may be a general-purpose processor, including a central processing unit (Central Processing Unit, CPU), a microcontroller unit (Microcontroller Unit, MCU), a complex programmable logic device (Complex Programmable Logic Device, CPLD), a field programmable gate array (Field Programmable Gate Array, FPGA), an embedded ARM, and other chips.
[0067] Based on Figure 1 and Figure 2 , this embodiment also provides a method for retrieving vulnerability data of a vehicle operating system. This method can be applied to the intelligent connected vehicle 10 in Figure 1 and Figure 2 . For a flowchart example of a method for retrieving vulnerability data of a vehicle operating system provided by an embodiment of the present invention, please refer to Figure 3 , Figure 3 which shows a flowchart example of a method for retrieving vulnerability data of a vehicle operating system provided by an embodiment of the present invention. Figure 1 This method includes the following steps:
[0068] Step S100, obtain vulnerability data of the vehicle operating system.
[0069] In this embodiment, there may be multiple vulnerabilities in the vehicle operating system, and the vulnerability data of different vulnerabilities is different. The vulnerability data of multiple vulnerabilities may be stored in the same system file or different system files. The vulnerability data in this step may be the vulnerability data of any vulnerability in the vehicle operating system. The system file in the vehicle operating system of the vulnerability to be processed that has the same name as the system file where the vulnerability data is located is the target file. For example, if the vulnerability data a is stored in the system file 123.txt, then the system file named 123.txt in the vehicle operating system of the vulnerability to be processed is the target file.
[0070] In this embodiment, the vulnerability data may be a piece of text, a piece of source code, or a piece of executable code. When the vulnerability data is text or source code, the sequence is a character data sequence composed of multiple characters. When the vulnerability data is executable code, the sequence is a binary data sequence composed of 0s and 1s.
[0071] In this embodiment, the vulnerability data includes one or more sequences. When there are multiple sequences, as a specific implementation, one of the multiple sequences is the main sequence, and the remaining sequences are subordinate sequences. The distance between each subordinate sequence and the main sequence is different. For example, the main sequence is the function name of a preset function, and the subordinate sequences are the parameters of the preset function and / or the code located at the preset code line in the preset function.
[0072] Step S101: Divide the vulnerability data into N data segments according to the preset address bus width, and obtain the position serial numbers of the N data segments corresponding to the vulnerability data, where N is a positive integer not less than 1.
[0073] In this embodiment, the preset address bus width can be set according to the actual hardware environment. When performing retrieval, the hardware performance of the intelligent connected vehicle can be fully utilized to read the data to be compared with the preset address bus width from the target file at one time, improving the reading efficiency of the data to be compared. For example, the width of the address bus is 32, that is, the intelligent connected vehicle 10 can read a maximum of 32 bits at a time. The preset address bus width can be set to 32 bits. When the preset address bus width is set according to the width of the hardware address bus, the reading performance of the hardware of the intelligent connected vehicle can be fully utilized to improve the speed of data reading during retrieval, thereby further accelerating the retrieval speed. Of course, the preset address bus width can also be set to a preset multiple of the width of the address bus, or the preset address bus width can be set to other values according to one's own needs.
[0074] In this embodiment, the position sequence numbers of each data segment corresponding to the vulnerability data can be numbered from small to large or from large to small, and this embodiment does not limit this. For example, if the vulnerability data is divided into 4 segments and numbered from small to large starting from 0, the numbers are 0, 1, 2, 3. Of course, it can also be numbered starting from 1.
[0075] Step S102: Calculate the characteristic value of the vulnerability data according to the values of the N data segments and the position sequence number of each data segment.
[0076] In this embodiment, the characteristic value of the vulnerability data is used to uniquely represent the vulnerability data. Different vulnerability data must have different characteristic values. The characteristic value can be, but is not limited to, a hash value, an MD5 value, etc. When calculating the characteristic value in this embodiment, not only the value of each data segment is utilized, but also the position sequence number of each data segment is used. Thus, the one-to-one correspondence between the vulnerability data and its characteristic value is ensured, thereby guaranteeing the accuracy of the retrieval result.
[0077] Step S103: Retrieve the target data corresponding to the characteristic value from the target file, where the target file is the system file of the vehicle operating system with the vulnerability to be processed.
[0078] In this embodiment, the target file can be a text file or a binary file. A binary file generally refers to a file containing data or program instructions (Program instructions) written in ASCII and extended ASCII characters. For example, an Executable and Linkable Format (ELF) file.
[0079] In this embodiment, the target file can include one target data, that is, the target data appears once in the target file, or can include multiple target data, that is, the target data appears multiple times in the target file. The user can determine the maximum number of target data to be retrieved according to the need.
[0080] In this embodiment, when retrieving the target data identical to the vulnerability data, as a specific implementation manner, the length of the data segment can be used as the step size, and each time a comparison data with the same length as the vulnerability data is read from the target file to determine whether the comparison data is the same as the vulnerability data until the entire target file is retrieved. Eventually, all the target data in the target file can be found.
[0081] The above method provided by this embodiment segments the vulnerability data, calculates the eigenvalue of the vulnerability data according to the position serial number corresponding to the data segment in the vulnerability data, and then performs data retrieval according to the eigenvalue of the vulnerability data, avoiding comparing each character one by one during data retrieval, thereby improving the retrieval efficiency. At the same time, since the eigenvalue of the vulnerability data is calculated by considering both the value of each data segment and the position of each data segment in the vulnerability data, the one-to-one correspondence between the vulnerability data and its eigenvalue is ensured, and finally the retrieval result is more accurate.
[0082] Based on this, Figure 3 this embodiment also provides a specific implementation manner for calculating the eigenvalue of the vulnerability data. Please refer to Figure 4 , Figure 4 which shows a flow example of a method for retrieving vulnerability data of a vehicle operating system provided by an embodiment of the present invention. Figure 2 Step S102 includes the following sub-steps:
[0083] Sub-step S1021: Sum the values of all data segments to obtain a first result.
[0084] In this embodiment, since the number of bits of all data segments is the same and is the preset address bus width, therefore, summing the values of all data segments is to add the corresponding bit positions of all data segments. There may be a carry or no carry during the addition. When there is no carry, the sum obtained by the addition is the first result. When there is a carry, in order to facilitate subsequent comparison according to the eigenvalue, the low preset address bus width bit positions obtained by the summation calculation are taken as the first result.
[0085] Sub-step S1022: Determine the processing coefficient of each data segment according to N and the position serial number of each data segment. The processing coefficient is used to represent the position relationship between each data segment and N.
[0086] In this embodiment, the processing coefficient can be obtained by addition, subtraction, weighted addition or weighted subtraction according to the position relationship between each data segment and N. For example, the processing coefficient of each data segment = N - the position serial number of each data segment. Please refer to Figure 5 , Figure 5 which shows an example diagram for calculating a processing coefficient provided by an embodiment of the present invention. Figure 5 In Figure 5 the vulnerability data is divided into 8 data segments, each data segment is 32 bits, and the position serial numbers of segment 1 to segment 8 are 0 to 7 ( Figure 5 only the numbers of segment 1 and segment 8 are marked in
[0087] It should be noted that, as another specific implementation, the position serial number of each data segment can also be used as the processing coefficient of each data segment, or the position serial number of each data segment is multiplied by a preset weight to obtain the processing coefficient of each data segment. Please refer to Figure 6 , Figure 6 FIG. Figure 6 shows an example diagram of another calculation of the processing coefficient provided by an embodiment of the present invention. Figure 6 In Figure 6 , the vulnerability data is segmented into 8 data segments, each data segment is 32 bits, and the numbers of segments 1 to 8 are 1 to 8 respectively ( Figure 5 only the numbers of segments 1 and 8 are marked in Figure 5 , and the numbers of the remaining segments are omitted), then the processing coefficients of segments 1 to 8 are: 1 to 8.
[0088] In this embodiment, since the position serial number of each data segment is unique, the processing coefficient of each data segment is associated with the position serial number of each data segment. Even if an error occurs in the data of any data segment, it is very difficult for the characteristic value of the vulnerability data calculated using the incorrect data segment to be the same as the characteristic value of the vulnerability data calculated using the correct data segment. Thus, the reliability of the calculation result of the characteristic value of the vulnerability data is ensured.
[0089] Sub-step S1023: Process the value of each data segment according to the processing coefficient of each data segment to obtain the processing result of the value of each data segment.
[0090] In this embodiment, the method of processing the value of each data segment according to the processing coefficient of each data segment can be to perform operations such as multiplication, division, addition, or subtraction on the processing coefficient of each data segment and the value of each data segment to obtain the processing result of the value of each data segment.
[0091] Sub-step S1024: Sum up the processing results of the values of all data segments to obtain a second result.
[0092] In this embodiment, similar to the first result, after summing up the processing results of all data segments, the lower 32 bits of the sum can be taken as the second result.
[0093] Sub-step S1025: Combine the first result and the second result to obtain the characteristic value of the vulnerability data.
[0094] In this embodiment, the combination method of the first result and the second result can be to splice the two together to obtain the characteristic value. For example, the first result is used as the upper 32 bits of the characteristic value, and the second result is used as the lower 32 bits of the characteristic value to obtain the characteristic value. As a specific implementation, the formula for combining the first result and the second result to obtain the characteristic value of the vulnerability data is:
[0095] R = (low_32_bit(R 1 ) << 32) || (low_32_bit(R 2 )),where R is the eigenvalue, low_32_bit is the function to extract the lower 32 bits, << is the left shift operator, and || is the OR operator; R 1 is the first result, i is the position sequence number of the data segment, and Seg i is the value of the i-th data segment; R 2 is the second result, and N is the total number of data segments.
[0096] It should be noted that the combination method can also be to perform hash processing on the first result and the second result respectively using a hash function, and then merge the lower 32 bits of the respective obtained hash results to obtain the eigenvalue. For example, the lower 32 bits of the hash result of the first result are used as the higher 32 bits of the eigenvalue, and the lower 32 bits of the hash result of the second result are used as the lower 32 bits of the eigenvalue. In this case, the eigenvalue is also called the hash value.
[0097] It should be noted that the combination method can also be to perform MD5 processing on the first result and the second result respectively, and then merge the lower 32 bits of the respective obtained MD5 results to obtain the eigenvalue. In this case, the eigenvalue is also called the MD5 value. The specific implementation steps are as follows:
[0098] First, calculate the MD5 value of the first result.
[0099] Second, calculate the MD5 value of the second result.
[0100] Third, merge the MD5 value of the first result and the MD5 value of the second result to obtain the eigenvalue of the vulnerability data.
[0101] The above method provided in this embodiment can ensure the accuracy of the eigenvalue of the vulnerability data by determining the first result and the second result, and can also calculate the first result and the second result in parallel, ensuring the calculation efficiency of the eigenvalue of the vulnerability data.
[0102] Based on this, this embodiment also provides a specific implementation method for retrieving target data identical to the vulnerability data in the target file. Please refer to Figure 3 , Figure 7 , Figure 7 which shows a flow example of a method for retrieving vulnerability data of a vehicle operating system provided by an embodiment of the present invention Figure 3 , and step S103 includes the following sub-steps:
[0103] Sub-step S103-10: Sequentially read the first data to be compared with the same data length as the vulnerability data from the target file.
[0104] In this embodiment, when reading the first data to be compared, the preset address bus width is moved each time. Please refer to Figure 8 , Figure 8 FIG. shows an example diagram of reading the first data to be compared provided by an embodiment of the present invention. Figure 8 In, the first data to be compared read for the first time starts from the position of the head of the target file and reads data with the same data length as the vulnerability data. The first data to be compared read for the second time starts from a position offset by the preset address bus width from the position of the head of the target file and reads data with the same data length as the vulnerability data. The first data to be compared read for the third time starts from a position offset by the preset address bus width from the starting position of the first data to be compared read for the second time. Each subsequent read of the first data to be compared is similar, and will not be elaborated here.
[0105] Sub-step S103-11: Calculate the eigenvalue of the first data to be compared.
[0106] In this embodiment, the calculation method of the eigenvalue of the first data to be compared is the same as that of the vulnerability data, and can be implemented through the above steps S101 and S102 or the sub-steps of S102.
[0107] Sub-step S103-12: If the eigenvalue of the first data to be compared is the same as the eigenvalue of the vulnerability data, it is determined that the target data exists in the target file, where the target data is the first data to be compared.
[0108] In this embodiment, each time a data block length of the first data to be compared is read from the target file, the eigenvalue of the first data to be compared is calculated according to the calculation method of the eigenvalue of the vulnerability data disclosed in this embodiment, and the two eigenvalues are compared. If they are consistent, the first data to be compared is the target data, that is, the target data exists in the target file. Otherwise, continue the subsequent retrieval until the target file is traversed once.
[0109] It should be noted that there may be multiple target data in the target file. After finding the first target data, subsequent retrieval can also be continued until all target data in the target file is retrieved, or until a preset number of target data is retrieved.
[0110] In this embodiment, there may be multiple vulnerability data, and each vulnerability data has a corresponding eigenvalue. When all the eigenvalues of the vulnerability data exist in the target file, in order to determine whether the target data exists in the target file, the embodiment of the present invention also provides a specific implementation method when there are multiple vulnerability data on the basis of Figure 3 , please refer to Figure 9 , Figure 9The figure shows a process example of a vulnerability data retrieval method for a vehicle operating system provided by an embodiment of the present invention Figure 4 Step S103 further includes the following sub-steps:
[0111] Sub-step S103-20: Sequentially read first data to be compared with the same data length as the first sample data from the target file.
[0112] In this embodiment, the vulnerability data can be determined by two parts of data. For example, one part of the data represents the name of the function corresponding to the vulnerability data, and the other part of the data represents the implementation code of the function corresponding to the vulnerability data. The offset position between these two parts of data will not change. The first sample data and the second sample data are used to represent these two parts of data respectively, and the first eigenvalue of the first sample data and the second eigenvalue of the second sample data are calculated respectively according to the above method of calculating the eigenvalue.
[0113] Sub-step S103-21: Calculate the eigenvalue of the first data to be compared.
[0114] Sub-step S103-22: If the eigenvalue of the first data to be compared is the same as the first eigenvalue, then read second data to be compared with the same data length as the second sample data at a preset offset position from the first data to be compared.
[0115] Sub-step S103-23: Calculate the eigenvalue of the second data to be compared.
[0116] Sub-step S103-24: If the eigenvalue of the second data to be compared is the same as the second eigenvalue, then use the first data to be compared as the target data.
[0117] In this embodiment, first read the first data to be compared from the target file, calculate the eigenvalue of the first data to be compared, compare the eigenvalue of the first data to be compared with the first eigenvalue. If they are consistent, then read the second data to be compared at a preset offset position from the first data to be compared in the target file, calculate the eigenvalue of the second data to be compared, and compare the eigenvalue of the second data to be compared with the second eigenvalue. If they are consistent, then determine that the first data to be compared is the target data. Otherwise, continue to read the next first data to be compared in the manner of sub-step S103-10, and repeat the above comparison process until the target file is traversed.
[0118] It should be noted that similar to the case where there is one vulnerability data, when there are multiple vulnerability data, there can also be multiple target data in the target file. After finding the first target data, the subsequent retrieval can also be continued according to sub-steps S103-20 to S103-24 until all target data in the target file are retrieved, or until a preset number of target data are retrieved.
[0119] In this embodiment, the second data to be compared can be one or multiple. Please refer to Figure 10 , Figure 10 FIG. shows an example diagram of the offset between the second data to be compared and the first data to be compared provided by an embodiment of the present invention. Figure 10 In [reference], when the second data to be compared is one, the preset offset position is the position of the second data to be compared relative to the first data to be compared, which is also the position of the second sample data relative to the first sample data. When the second data to be compared is two, the second sample data is also two: the second sample data 1 and the second sample data 2, corresponding to the second data to be compared 1 and the second data to be compared 2 respectively. The preset offset position includes the position of the second data to be compared 1 relative to the first data to be compared and the position of the second data to be compared 2 relative to the first data to be compared.
[0120] In this embodiment, when there are multiple second sample data, when the eigenvalue of each second sample data is consistent with the eigenvalue of its corresponding second data to be compared, the first data to be compared is used as the target data. If the eigenvalue of any second sample data is inconsistent with the eigenvalue of its corresponding second data to be compared, the first data to be compared cannot be used as the target data.
[0121] In this embodiment, as a specific implementation method for retrieving all target data in the target file, taking the target file as a binary file, the vulnerability data as two: the first sample data and the second sample data, both being 32 bytes, and the width of the hardware address bus being 32 bits as an example for illustration, the processing process is as follows:
[0122] (1) Read the target file into memory.
[0123] (2) Read 32 bytes of data (i.e., the first data to be compared) from the head of the target file in memory.
[0124] (3) Divide the first data to be compared into 8 data segments, each data segment being 32 bits. Calculate the sum of the 8 data segments, take the lower 32 bits of the sum, and then convert it to hexadecimal as the first 4 bytes of the eigenvalue of the first data to be compared (i.e., the first result).
[0125] (4) Subtract the segment number from the number of each data segment in the first data to be compared to obtain the processing coefficient of each data segment. Then process each data segment according to the corresponding processing coefficient, calculate the sum of the processing results of the 8 data segments, take the lower 32 bits of the sum, and then convert it to hexadecimal as the last 4 bytes of the eigenvalue of the first data to be compared (i.e., the second result).
[0126] (5) Obtain the eigenvalue of the first data to be compared according to the first result and the second result.
[0127] (6) Determine whether the eigenvalue of the first data to be compared is consistent with the eigenvalue of the first sample data. If they are consistent, read the second data to be compared at the position offset by 0x50 from the first data to be compared. If they are inconsistent, read the next first data to be compared in 4-byte steps (delete the first 4 bytes of the first data to be compared, start reading 32 bytes of data from the last 4 bytes of the first data to be compared, and use the read 32-byte data as the new first data to be compared), and go back to (3) to continue execution until the end of the target file is reached.
[0128] (7) Calculate the eigenvalue of the second data to be compared.
[0129] (8) Determine whether the eigenvalue of the second data to be compared is consistent with the eigenvalue of the second sample data. If they are consistent, record the address of the first data to be compared at this time (find a target data, and the first data to be compared at this time is the target data). If they are inconsistent, read the next first data to be compared in 4-byte steps (delete the first 4 bytes of the first data to be compared, start reading 32 bytes of data from the last 4 bytes of the first data to be compared, and use the read 32-byte data as the new first data to be compared), and go back to (3) to continue execution until the end of the target file is reached.
[0130] (9) The addresses of all the recorded first data to be compared are the addresses of all the target data.
[0131] To more clearly describe the above processing procedure, the embodiment of the present invention also provides a flow example diagram of the above processing procedure. Please refer to Figure 11 , Figure 11 which shows a flow example diagram of retrieving all target data in a target file provided by an embodiment of the present invention. It should be noted that the first eigenvalue of the first sample data and the eigenvalue of the second sample data can be pre-calculated or calculated when in use. The embodiment of the present invention does not limit this.
[0132] In this embodiment, when a target data is detected, it means that there is a vulnerability corresponding to the vulnerability data in the vehicle operating system to be processed. To notify the provider of the vehicle operating system in a timely manner, the embodiment of the present invention also provides a specific implementation manner for prompting that there is a vulnerability in the vehicle operating system. Please refer to Figure 12 , Figure 12 which shows a flow example of a method for retrieving vulnerability data of a vehicle operating system provided by an embodiment of the present invention Figure 5 and this method includes the following steps:
[0133] Step S104, if target data is retrieved from the target file, obtain the version number of the vehicle operating system with the vulnerability to be processed.
[0134] In this embodiment, the version number can be obtained through the interface function provided by the vehicle operating system with the vulnerability to be processed. The vehicle operating system with the vulnerability to be processed is the vehicle operating system of the currently detected intelligent connected vehicle 10.
[0135] Step S105: Send the vulnerability data, target file, and version number to the server to prompt that there is a vulnerability in the vehicle operating system of the intelligent connected vehicle.
[0136] In this embodiment, the server can be the server designated by the provider of the vehicle operating system of the intelligent connected vehicle 10. This server can analyze and process the vulnerability data, target files, and version numbers fed back by different intelligent connected vehicles 10, so as to promptly give a relatively comprehensive patch package to repair all newly discovered vulnerabilities.
[0137] To execute the corresponding steps of the vulnerability data retrieval method for the vehicle operating system in the above embodiment and each possible implementation manner, the following gives an implementation manner of a vulnerability data retrieval device 100 for the vehicle operating system. Please refer to Figure 13 , Figure 13 FIG. shows a block diagram of a vulnerability data retrieval device 100 for a vehicle operating system provided by an embodiment of the present invention. It should be noted that the basic principle and the technical effects generated by the vulnerability data retrieval device 100 for the vehicle operating system provided in this embodiment are the same as those in the above embodiment. For the sake of brief description, parts not mentioned in this embodiment are not pointed out.
[0138] The vulnerability data retrieval device 100 for the vehicle operating system includes an acquisition module 110, a division module 120, a calculation module 130, and a retrieval module 140.
[0139] The acquisition module 110 is used to acquire the vulnerability data of the vehicle operating system.
[0140] The division module 120 is used to divide the vulnerability data into N data segments according to a preset address bus width, and obtain the position sequence numbers of the N data segments corresponding to the vulnerability data, where N is a positive integer not less than 1.
[0141] The calculation module 130 is used to calculate the characteristic value of the vulnerability data according to the values of the N data segments and the position sequence number of each data segment.
[0142] Specifically, the calculation module 130 is specifically configured to: sum the values of all data segments to obtain a first result; determine the processing coefficient of each data segment according to N and the position serial number of each data segment, where the processing coefficient is used to characterize the positional relationship between each data segment and N; process the value of each data segment according to the processing coefficient of each data segment to obtain the processing result of the value of each data segment; sum the processing results of the values of all data segments to obtain a second result; combine the first result and the second result to obtain the eigenvalue of the vulnerability data.
[0143] Specifically, when the calculation module 130 is used to combine the first result and the second result to obtain the eigenvalue of the vulnerability data, the formula adopted is:
[0144] R = (low_32_bit(R 1 ) << 32) || (low_32_bit(R 2 ))), where R is the eigenvalue, low_32_bit is a function to take the lower 32 bits, << is the left shift operator, and || is the or operator; R 1 is the first result, i is the position serial number of the data segment, Seg i is the value of the i-th data segment; R 2 is the second result, N is the total number of data segments.
[0145] Specifically, when the calculation module 130 is used to combine the first result and the second result to obtain the eigenvalue of the vulnerability data, it is specifically further configured to: calculate the MD5 value of the first result; calculate the MD5 value of the second result; combine the MD5 value of the first result and the MD5 value of the second result to obtain the eigenvalue of the vulnerability data.
[0146] The retrieval module 140 is configured to retrieve target data corresponding to the eigenvalue from the target file according to the eigenvalue of the vulnerability data, where the target file is the system file of the vehicle operating system to be processed for vulnerabilities.
[0147] Specifically, there is one eigenvalue of the vulnerability data, and the retrieval module 140 is specifically configured to: sequentially read first data to be compared with the same length as the data length of the vulnerability data from the target file; calculate the eigenvalue of the first data to be compared; if the eigenvalue of the first data to be compared is the same as the eigenvalue of the vulnerability data, it is determined that there is target data in the target file, where the target data is the first data to be compared.
[0148] Specifically, the vulnerability data includes first sample data and second sample data. The eigenvalue of the vulnerability data includes the first eigenvalue of the first sample data and the second eigenvalue of the second sample data. When the retrieval module 140 is used to retrieve target data corresponding to the eigenvalue from the target file, it is specifically further used to: sequentially read first data to be compared with the same data length as the first sample data from the target file; calculate the eigenvalue of the first data to be compared; if the eigenvalue of the first data to be compared is the same as the first eigenvalue, then read second data to be compared with the same data length as the second sample data at a preset offset position from the first data to be compared; calculate the eigenvalue of the second data to be compared; if the eigenvalue of the second data to be compared is the same as the second eigenvalue, then use the first data to be compared as the target data.
[0149] Specifically, the vulnerability data retrieval device for the vehicle operating system is further applied to the intelligent connected vehicle 10. The intelligent connected vehicle 10 is communicatively connected to the server. The retrieval module 140 is further used to: if target data is retrieved from the target file, obtain the version number of the vehicle operating system of the vulnerability to be processed; send the vulnerability data, the target file, and the version number to the server to prompt that there is a vulnerability in the vehicle operating system of the intelligent connected vehicle 10.
[0150] The embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the processor 11, it implements the vulnerability data retrieval method for the vehicle operating system disclosed in the above embodiment.
[0151] In summary, the embodiment of the present invention provides a vulnerability data retrieval method and related device for a vehicle operating system. The method includes: obtaining vulnerability data of the vehicle operating system; dividing the vulnerability data into N data segments according to a preset address bus width to obtain the position serial numbers of the N data segments corresponding to the vulnerability data, where N is a positive integer not less than 1; calculating the eigenvalue of the vulnerability data according to the values of the N data segments and the position serial number of each data segment; retrieving target data corresponding to the eigenvalue from the target file according to the eigenvalue of the vulnerability data, where the target file is the system file of the vehicle operating system of the vulnerability to be processed. Compared with the prior art, in the embodiment of the present invention, the eigenvalue of the vulnerability data is calculated according to the value of the data segment and the position serial number of the data segment in the vulnerability data, and then data retrieval is performed according to the calculated eigenvalue, avoiding comparing each character one by one during data retrieval, thereby improving the retrieval efficiency.
[0152] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A method for retrieving vulnerability data of a vehicle operating system, characterized in that, the method includes: Obtaining vulnerability data of a vehicle operating system; Dividing the vulnerability data into N data segments according to a preset address bus width, and obtaining the position sequence numbers of the N data segments corresponding to the vulnerability data, where N is a positive integer not less than 1; Calculating the characteristic value of the vulnerability data according to the values of the N data segments and the position sequence number of each data segment; Retrieving target data corresponding to the characteristic value from a target file according to the characteristic value of the vulnerability data, where the target file is the system file of the vehicle operating system to be processed for vulnerabilities; The step of calculating the characteristic value of the vulnerability data according to the values of the N data segments and the position sequence number of each data segment includes: Summing the values of all the data segments to obtain a first result; Determining the processing coefficient of each data segment according to N and the position sequence number of each data segment, where the processing coefficient is used to characterize the position relationship between each data segment and N; Processing the processing coefficient of each data segment and the value of each data segment to obtain the processing result of the value of each data segment; Summing the processing results of the values of all data segments to obtain a second result; Combining the first result and the second result to obtain the characteristic value of the vulnerability data; The formula used for combining the first result and the second result to obtain the characteristic value of the vulnerability data is: , is the eigenvalue, is the function to take the lower 32 bits, is the left shift operator, is the OR operator; is the first result, , where i is the position serial number of the data segment, is the value of the i-th data segment; is the second result, , where N is the total number of data segments.
2. The method according to claim 1, characterized in that, The step of combining the first result and the second result to obtain the characteristic value of the vulnerability data further includes: Calculating the MD5 value of the first result; Calculating the MD5 value of the second result; Combining the MD5 value of the first result and the MD5 value of the second result to obtain the characteristic value of the vulnerability data.
3. The method according to claim 1, characterized in that, There is one characteristic value of the vulnerability data, and the step of retrieving target data corresponding to the characteristic value from the target file includes: Sequentially reading first data to be compared with the same data length as the vulnerability data from the target file; Calculating the characteristic value of the first data to be compared; If the characteristic value of the first data to be compared is the same as the characteristic value of the vulnerability data, it is determined that there is target data in the target file, where the target data is the first data to be compared.
4. The method according to claim 1, characterized in that, The vulnerability data includes first sample data and second sample data, and the characteristic value of the vulnerability data includes a first characteristic value of the first sample data and a second characteristic value of the second sample data. The step of retrieving target data corresponding to the characteristic value from the target file further includes: Sequentially reading first data to be compared with the same data length as the first sample data from the target file; Calculating the characteristic value of the first data to be compared; If the eigenvalue of the first data to be compared is the same as the first eigenvalue, then read second data to be compared with the same data length as the second sample data at a preset offset position from the first data to be compared; Calculate the eigenvalue of the second data to be compared; If the eigenvalue of the second data to be compared is the same as the second eigenvalue, then use the first data to be compared as the target data.
5. The method according to claim 1, wherein, the method is applied to an intelligent connected vehicle, the intelligent connected vehicle is communicatively connected to a server, and the method further includes: If the target data is retrieved from the target file, then obtain the version number of the vehicle operating system of the vulnerability to be processed; Send the vulnerability data, the target file and the version number to the server to indicate that there is a vulnerability in the vehicle operating system of the intelligent connected vehicle.
6. A device for retrieving vulnerability data of a vehicle operating system, wherein, the device includes: an acquisition module, configured to acquire vulnerability data of a vehicle operating system; a division module, configured to divide the vulnerability data into N data segments according to a preset address bus width, and obtain the position sequence numbers of the N data segments corresponding to the vulnerability data, where N is a positive integer not less than 1; a calculation module, configured to calculate the eigenvalue of the vulnerability data according to the values of the N data segments and the position sequence number of each data segment; a retrieval module, configured to retrieve target data corresponding to the eigenvalue from a target file according to the eigenvalue of the vulnerability data, where the target file is a system file of the vehicle operating system of the vulnerability to be processed; The calculation module is specifically configured to: sum the values of all the data segments to obtain a first result; Determine the processing coefficient of each data segment according to N and the position sequence number of each data segment, where the processing coefficient is used to represent the position relationship between each data segment and N; process the processing coefficient of each data segment and the value of each data segment to obtain the processing result of the value of each data segment; sum the processing results of the values of all data segments to obtain a second result; combine the first result and the second result to obtain the eigenvalue of the vulnerability data; The formula for combining the first result and the second result to obtain the eigenvalue of the vulnerability data is: , is the eigenvalue, is the function to take the lower 32 bits, is the left shift operator, is the OR operator; is the first result, , where i is the position serial number of the data segment, is the value of the i-th data segment; is the second result, , and N is the total number of data segments.
7. A computer-readable storage medium, on which a computer program is stored, wherein, when the computer program is executed by a processor, it implements the method for retrieving vulnerability data of a vehicle operating system according to any one of claims 1-5.
8. A system for retrieving vulnerability data of a vehicle operating system, wherein, the system for retrieving vulnerability data of the vehicle operating system includes a server and an intelligent connected vehicle communicatively connected to the server, and the intelligent connected vehicle is configured to obtain the vulnerability data of the vehicle operating system from the server and execute the method for retrieving vulnerability data of the vehicle operating system according to any one of claims 1-5.
Citation Information
Patent Citations
Firmware vulnerability detection method and system in cross-platform scene
CN111310178A
Vulnerability identifier generation method and device, electronic equipment and storage medium
CN114297667A