Security Assessment Method and Device for Internet of Vehicles

By labeling multiple evaluation objects of the Internet of Vehicles and assigning risk weights, and using the evaluation model for evaluation, the problem of inaccurate security evaluation of Internet of Vehicles in the existing technology is solved, and more accurate and comprehensive consistent evaluation results are achieved.

CN115038087BActive Publication Date: 2025-06-24BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210657101.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-10
Publication Date
2025-06-24
Estimated Expiration
2042-06-10

AI Technical Summary

Technical Problem

The existing safety assessment methods for Internet of Vehicles mainly conduct risk assessment from a single perspective, resulting in inaccurate assessment results and the inability to fully understand the security situation of Internet of Vehicles.

Method used

By labeling multiple evaluation objects in the Internet of Vehicles and determining the risk weight of the evaluation objects based on multiple risk models, the evaluation model is used to evaluate the evaluation objects to generate more accurate and comprehensive consistent evaluation results.

Benefits of technology

It has achieved a multi-faceted overall assessment of the Internet of Vehicles, improved the accuracy and comprehensiveness of the security assessment, and can dynamically monitor security threats and provide reliable security situation assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115038087B_ABST
    Figure CN115038087B_ABST
Patent Text Reader

Abstract

The present application discloses a security assessment method and device for an Internet of Vehicles. The method includes: performing tagging processing on multiple groups of assessment objects of the Internet of Vehicles to classify and label multiple assessment objects in the assessment object groups, where the assessment object groups are sets of objects for respectively assessing multiple different aspects of the Internet of Vehicles; determining assessment indicators corresponding to the assessment objects that have been classified and labeled, where the assessment indicators are indications for assessing the assessment objects from multiple aspects; determining the risk weights of the assessment objects based on multiple risk models for characterizing different types of risks of the Internet of Vehicles; and in the case of receiving an assessment instruction for assessing the Internet of Vehicles, using at least one assessment model retrieved from an assessment model repository to assess the assessment objects based on at least the risk weights and / or assessment indicators of the assessment objects, and generating corresponding assessment results. This method can comprehensively assess the Internet of Vehicles and effectively improve the accuracy of security assessment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle networking security situation, and particularly relates to a security assessment method and device for vehicle networking. Background Art

[0002] Vehicle networking refers to the effective utilization of all vehicle dynamic information in an information network platform by in-vehicle devices on vehicles through wireless communication technology to provide different functional services during vehicle operation. The security assessment of vehicle networking is particularly important. Currently, for the security assessment of vehicle networking, the risk assessment is usually carried out from the perspective of assets, and the source of original evaluation data is relatively single, which will lead to inaccurate results of security assessment. For example, the overall assessment is not carried out from each evaluation object involved in the vehicle, resulting in single evaluation data and inaccurate results of vehicle networking security assessment, thus posing a potential safety hazard to the vehicle. Summary of the Invention

[0003] The purpose of the embodiments of this application is to provide a security assessment method for vehicle networking, which can comprehensively evaluate vehicle networking based on overall assessment data from multiple aspects of vehicle networking as the assessment basis, and effectively improve the accuracy of the security assessment of vehicle networking.

[0004] To achieve the above purpose, the embodiments of this application provide a security assessment method for vehicle networking, including:

[0005] Perform tagging processing on multiple evaluation object groups of vehicle networking to classify and label multiple evaluation objects in the evaluation object group, where the evaluation object group is a set of objects for separately evaluating multiple different aspects of the vehicle networking;

[0006] Determine the evaluation indicators corresponding to the evaluation objects that have been classified and labeled, where the evaluation indicators are instructions for evaluating the evaluation objects from multiple different aspects;

[0007] Based on multiple risk models for characterizing different types of risks of the vehicle networking, determine the risk weights of the evaluation objects;

[0008] When receiving an evaluation instruction for evaluating the vehicle networking, use at least one evaluation model retrieved from an evaluation model warehouse to evaluate the evaluation objects at least based on the risk weights and / or the evaluation indicators of the evaluation objects, and generate corresponding evaluation results.

[0009] Optionally, the evaluation object group includes at least one of the following: in-vehicle device data object, vehicle control application program data object, vehicle networking platform data object, communication data object, vehicle networking vulnerability object, and vehicle networking asset object;

[0010] Correspondingly, the process of tagging multiple evaluation objects in the vehicle networking includes:

[0011] Tagging the in-vehicle device data object, the vehicle control application program data object, the vehicle networking platform data object, the communication data object, the vehicle networking vulnerability object, and / or the vehicle networking asset object respectively.

[0012] Optionally, determining the evaluation indicators corresponding to the evaluation objects with classification labels includes:

[0013] Based on a preset construction model, constructing a multi-layer evaluation hierarchy corresponding to the evaluation object, where each layer of the evaluation hierarchy has the evaluation content indicated by the evaluation indicator.

[0014] Optionally, the evaluation object includes a vehicle networking vulnerability object, and the risk model includes: a vehicle networking vulnerability model; determining the risk weight of the evaluation object based on multiple risk models for characterizing different types of risks in the vehicle networking includes:

[0015] Using the vehicle networking vulnerability model to classify the vehicle networking vulnerability object;

[0016] Based on the risk level of the vehicle networking vulnerability object, assigning a risk weight to the classified vehicle networking vulnerability object.

[0017] Optionally, the evaluation object includes a vehicle networking security event object, and the risk model includes: a security event frequency weight model; determining the risk weight of the evaluation object based on multiple risk models for characterizing different types of risks in the vehicle networking includes:

[0018] Using the security event frequency weight model to assign a risk weight to the vehicle networking security event object, where the vehicle networking security event object includes at least one of the following: the frequency of occurrence of the security event, the importance level of the associated asset, and the vulnerability level of the asset association.

[0019] Optionally, the risk model includes: an external risk report model; determining the risk weight of the evaluation object based on multiple risk models for characterizing different types of risks in the vehicle networking includes:

[0020] Using the external risk report model to assign risk weights to the vehicle networking asset object, the vehicle networking vulnerability object, and the vehicle networking security event object associated with the received external risk report.

[0021] Optionally, using at least one evaluation model retrieved from an evaluation model repository, evaluating the evaluation object based on at least the risk weight of the evaluation object and / or the evaluation indicators of the evaluation object, and generating a corresponding evaluation result, including:

[0022] Retrieving the corresponding evaluation model from the evaluation model repository based on the evaluation object and the evaluation rules selected from the evaluation rule repository accordingly;

[0023] Performing standardization processing on the sample data of the evaluation object through the evaluation model, where the sample data includes the risk weight and evaluation indicators of the evaluation object;

[0024] Performing evaluation deduction on the sample data through the evaluation model to generate the evaluation result.

[0025] Optionally, using at least one evaluation model retrieved from an evaluation model repository, evaluating the evaluation object based on at least the risk weight of the evaluation object and / or the evaluation indicators of the evaluation object, and generating a corresponding evaluation result, including:

[0026] Based on the evaluation instruction, determining whether there is a corresponding evaluation model for the evaluation object in the evaluation model repository;

[0027] If not, querying whether there is an evaluation rule corresponding to the evaluation object in the evaluation rule repository;

[0028] If not, generating a corresponding evaluation rule based on the evaluation object and storing the evaluation rule in the evaluation rule repository.

[0029] Optionally, the method further includes:

[0030] Visualizing and outputting the evaluation result;

[0031] Disposing of the threats to the vehicle networking included in the evaluation result.

[0032] An embodiment of the present application further provides a security evaluation device for a vehicle networking, including:

[0033] A label module configured to perform labeling processing on multiple evaluation object groups of the vehicle networking to classify and label multiple evaluation objects in the evaluation object group, where the evaluation object group is a set of objects for respectively evaluating multiple different aspects of the vehicle networking;

[0034] A determination module configured to determine the evaluation indicators corresponding to the evaluation object that has been classified and labeled, where the evaluation indicator is an indication for evaluating the evaluation object from multiple different aspects;

[0035] A risk weight module configured to determine the risk weight of the evaluation object based on multiple risk models for characterizing different types of risks of the vehicle networking.

[0036] A processing module configured to, when receiving an evaluation instruction for evaluating the vehicle networking, use at least one evaluation model retrieved from an evaluation model repository to evaluate the evaluation object based on at least the risk weight and / or evaluation indicators of the evaluation object, and generate a corresponding evaluation result.

[0037] The security evaluation method of the present application has a comprehensive dimension of security situation evaluation indicators for vehicle networking, a wide coverage range, can comprehensively support multi-dimensional analysis of the security situation of vehicle networking, and has a high reliability of evaluation results. In addition, the risk weight of the evaluation object is considered and dynamically combined with the evaluation indicators to achieve dynamic monitoring of security threat evaluation. By using an automated evaluation model, the accuracy and comprehensiveness of the security situation evaluation of vehicle networking are greatly improved. Description of the Drawings

[0038] Figure 1 It is a flowchart of the security evaluation method for vehicle networking according to an embodiment of the present application;

[0039] Figure 2 According to an embodiment of the present application Figure 1 It is a flowchart of an embodiment of step S300;

[0040] Figure 3 According to an embodiment of the present application Figure 1 It is a flowchart of an embodiment of step S400;

[0041] Figure 4 According to an embodiment of the present application Figure 1 It is a flowchart of a specific embodiment of step S400;

[0042] Figure 5 It is a structural block diagram of the security evaluation device for vehicle networking according to an embodiment of the present application. Detailed Embodiments

[0043] Various solutions and features of the present application are described herein with reference to the drawings.

[0044] It should be understood that various modifications can be made to the embodiments applied herein. Therefore, the above description should not be regarded as a limitation, but only as an example of the embodiments. Those skilled in the art will think of other modifications within the scope and spirit of the present application.

[0045] The accompanying drawings, which are included in and form a part of this specification, illustrate embodiments of the present application and, together with the general description of the present application given above and the detailed description of the embodiments given below, serve to explain the principles of the present application.

[0046] These and other features of the present application will become apparent from the following description of the preferred forms of the embodiments, given by way of non-limiting example, with reference to the accompanying drawings.

[0047] It should also be understood that although the present application has been described with reference to some specific examples, those skilled in the art can surely implement many other equivalent forms of the present application.

[0048] The above and other aspects, features and advantages of the present application will become more apparent in view of the following detailed description when taken in conjunction with the accompanying drawings.

[0049] Specific embodiments of the present application will be described hereinafter with reference to the accompanying drawings; however, it should be understood that the embodiments claimed are merely examples of the present application and can be implemented in various ways. Well-known and / or repetitive functions and structures are not described in detail to avoid obscuring the present application with unnecessary or redundant details. Therefore, the specific structural and functional details claimed herein are not intended to be limiting, but rather are merely a basis and representative basis for the claims to teach those skilled in the art to use the present application in substantially any suitable detailed structure in a variety of ways.

[0050] This specification may use the phrases "in one embodiment", "in another embodiment", "in yet another embodiment" or "in other embodiments", each of which may refer to one or more of the same or different embodiments according to the present application.

[0051] A security assessment method for an Internet of Vehicles in an embodiment of the present application. This method can use vehicle-side data, platform-side data, vehicle control application program data, pipeline-side, vulnerability and other data as multi-faceted basic data sources, so as to conduct security assessments from multiple different aspects of the Internet of Vehicles. During the assessment process, corresponding weights are added to the assessment objects, and an assessment model corresponding to the assessment objects is used for assessment, so as to obtain a more accurate assessment result.

[0052] The following will describe this method in detail with reference to the accompanying drawings. Figure 1 is a flowchart of the security assessment method for the Internet of Vehicles in an embodiment of the present application, as Figure 1 shown, this method includes the following steps:

[0053] S100, perform tagging processing on multiple assessment object groups of the Internet of Vehicles to classify and label the multiple assessment objects in the assessment object groups, where the assessment object groups are object sets for respectively assessing multiple different aspects of the Internet of Vehicles.

[0054] Exemplarily, the vehicle networking has multiple different groups of evaluation objects for evaluation, and different groups of evaluation objects focus on different evaluation directions. And each group of evaluation objects includes at least one evaluation object, thereby further refining the data sources for evaluation.

[0055] For example, the group of evaluation objects includes at least one of the following: in-vehicle device data object, vehicle control application (APP) data object, vehicle networking platform data object, communication data object, vehicle networking vulnerability object, and vehicle networking asset object. Each of the above groups of evaluation objects includes at least one evaluation object. For example, the vehicle control APP data object includes application program data objects such as the vehicle networking T-BOX, OBD, and IVI.

[0056] In this embodiment, multiple groups of evaluation objects of the vehicle networking are subjected to tagging processing, and the evaluation objects in each group of evaluation objects are classified and labeled, so that it is convenient to operate and process them when calling the evaluation objects. For example, each evaluation object in the group of evaluation objects is named and numbered in a standardized manner.

[0057] Continuing with the above embodiment as an example, when the in-vehicle device data object is subjected to tagging processing, data such as corresponding security logs, security events, vulnerabilities, and alarms for access control, authorization, authentication, permission access, networking, and self-detection on the in-vehicle device side can be classified and labeled.

[0058] When the vehicle control application (APP) data object is subjected to tagging processing, data such as vehicle networking platform server security, network security, storage security, data security, identity authentication and authorization can be classified and labeled.

[0059] When the vehicle networking platform data object is subjected to tagging processing, data such as terminal location, user authentication, and communication logs can be classified and labeled.

[0060] When the vehicle networking vulnerability object is subjected to tagging processing, it can include classifying and labeling data such as vulnerability level tags, vulnerability type tags, and vulnerability-affected entities.

[0061] When the vehicle networking asset object is subjected to tagging processing, an asset database can be formed.

[0062] The tagged groups of evaluation objects enable the details of the above-mentioned various evaluation objects to be concerned, and then facilitate subsequent processing of them, such as retrieving each evaluation object by the labeled name.

[0063] S200, determining the evaluation indicators corresponding to the evaluation objects that have been classified and labeled, where the evaluation indicators are indications for evaluating the evaluation objects from multiple different aspects.

[0064] Exemplarily, each evaluation object can be evaluated from multiple evaluation metrics. The setting of the evaluation metrics corresponding to the evaluation object can be determined according to the type, function, specific content included, and / or importance of the evaluation object. The evaluation metrics can be divided into multiple levels, such as large levels, middle levels, and small levels, so as to conduct a rich and hierarchical evaluation of the evaluation object based on the evaluation metrics.

[0065] For example, for the APP security in the vehicle control application program data object, it includes basic security metrics, storage security metrics, and running security metrics. Among them, the basic security metrics include lower-level APP reinforcement metrics, security authentication metrics, minimum privilege metrics, and APP anti-tampering metrics, etc.; the storage security metrics include lower-level data encryption metrics, log encryption metrics, and certificate encryption metrics; the running security metrics include lower-level environment detection metrics and information input detection metrics. The above evaluation metrics are indicators for evaluating the APP security in the vehicle control application program data object from multiple different aspects. Thus, the APP security can be evaluated from the above evaluation metrics to obtain a complete and accurate evaluation result. Of course, the corresponding evaluation metrics can also be determined for other evaluation objects in the vehicle networking.

[0066] S300. Based on multiple risk models for characterizing different types of risks in the vehicle networking, determine the risk weight of the evaluation object.

[0067] Exemplarily, the preset multiple different risk models have different focuses. The risk models can assign risk weights to the corresponding evaluation objects. For example, the risk models include the vehicle networking vulnerability model, the security event frequency weight model, and the external risk report model. Among them, the vehicle networking vulnerability model is preset for the risks related to security vulnerabilities in the evaluation objects of the vehicle networking and can assign risk weights to the vulnerabilities. The security event frequency weight model is preset for the relevant information about the occurrence of security events in the evaluation objects of the vehicle networking; the external risk report model is preset for the risk content involved in the external risk reports of the vehicle networking.

[0068] The risk models assign risk weights to the evaluation objects according to the risk types they target, so that when conducting risk assessment on the evaluation objects, accurate calculations can be performed on the evaluation objects based on the risk weights, thereby obtaining accurate evaluation results.

[0069] S400. When receiving an evaluation instruction for evaluating the vehicle networking, use at least one evaluation model retrieved from the evaluation model repository to evaluate the evaluation object based on at least the risk weight of the evaluation object and / or the evaluation metrics of the evaluation object, and generate a corresponding evaluation result.

[0070] Exemplarily, the evaluation instruction may be an instruction to initiate a security evaluation of the vehicle networking. The evaluation instruction corresponds to an evaluation task. For example, the evaluation task may be a task to initiate a security evaluation of the vehicle networking at a predetermined time, which specifically includes retrieving an evaluation model from an evaluation model repository and using the evaluation model.

[0071] The evaluation model repository stores at least one evaluation model. Each evaluation model has a different focus direction for evaluation. Using multiple evaluation models can evaluate the evaluation object from multiple dimensions.

[0072] For example, the evaluation model repository stores an overall situation analysis model, a built-in evaluation model, a custom evaluation model, a special topic situation analysis model, a threat portrait analysis model, and an abnormal behavior analysis model. The above-mentioned evaluation models have their respective focus evaluation directions. One or more evaluation models can be used to evaluate the evaluation object, so as to obtain a multi-dimensional evaluation result, and the evaluation result is comprehensive and accurate.

[0073] For example, by combining the built-in evaluation model and the custom evaluation model, evaluation indicators, learning time, and evaluation dimensions can be customized. The threat portrait analysis model can perform portrait analysis on attack behaviors that threaten the security of the vehicle networking, including threat sources, IPs, ports, associated modules, associated vulnerabilities, and levels, to form a threat portrait analysis situation. The abnormal behavior analysis model can analyze behaviors that endanger the security of the vehicle networking, including asset and user behavior dimensions, changes, tampering, and security events of abnormal assets, as well as monitoring of user behaviors, including monitoring of behaviors such as permission settings and operation settings.

[0074] In this embodiment, when using an evaluation model to evaluate an evaluation object, the evaluation of the evaluation object is at least based on the risk weight of the evaluation object and / or the evaluation indicators of the evaluation object. Different evaluation objects have corresponding risk weights and evaluation indicators. This will enable the evaluation model to comprehensively evaluate all the given evaluation indicators during evaluation, and can also focus on evaluation objects with larger risk weights, making the generated evaluation results more accurate and comprehensive.

[0075] The security evaluation method of this application has a comprehensive dimension of security situation evaluation indicators related to the vehicle networking, a wide coverage range, can comprehensively support multi-dimensional analysis of the vehicle networking security situation, and the evaluation result has high reliability. In addition, the risk weight of the evaluation object is considered and dynamically combined with the evaluation indicators to achieve dynamic monitoring of security threat evaluation. By using an automated evaluation model, the accuracy and comprehensiveness of the vehicle networking security situation evaluation are greatly improved.

[0076] In one embodiment of the present application, the evaluation object group includes at least one of the following: in-vehicle computer data object, vehicle control application program data object, vehicle networking platform data object, communication data object, vehicle networking vulnerability object, and vehicle networking asset object;

[0077] Correspondingly, the process of tagging multiple evaluation object groups of the vehicle networking includes:

[0078] Respectively perform tagging on the in-vehicle computer data object, the vehicle control application program data object, the vehicle networking platform data object, the communication data object, the vehicle networking vulnerability object, and / or the vehicle networking asset object.

[0079] Exemplarily, the in-vehicle computer is an in-vehicle information platform installed in a vehicle, and the in-vehicle computer data object is an evaluation object related to the in-vehicle computer side. Tagging the in-vehicle computer data object is to classify and label the corresponding security logs, security events, vulnerabilities, alarms, etc. data of access control, authorization, authentication, privilege access, networking, self-detection, etc. on the in-vehicle computer side.

[0080] The vehicle control application program data object is an evaluation object of the relevant program for controlling the vehicle. Such as security logs, security events, vulnerabilities, alarms, etc. data. Performing tagging on it can be to classify and label the corresponding security logs, security events, vulnerabilities, alarms, etc. data of access control, authorization, authentication, privilege access, networking, self-detection, etc. on the in-vehicle computer side.

[0081] The vehicle networking platform data object is an evaluation object related to the platform side of the vehicle networking, such as a vehicle networking platform server. Tagging the vehicle networking platform data object can be to classify and label the data of vehicle networking platform server security, network security, storage security, data security, identity authentication and authorization, etc.

[0082] The communication data object is an object for internal and external communication of the vehicle, such as data of terminal location, user authentication, communication logs, etc. Tagging the communication data object can be to classify and label the data of terminal location, user authentication, communication logs, etc.

[0083] The vehicle networking vulnerability object may include a vulnerability level label, a vulnerability type label, and a vulnerability-affected entity. Tagging the vehicle networking vulnerability object includes classifying and labeling the data such as the vulnerability level label, the vulnerability type label, and the vulnerability-affected entity.

[0084] Tagging the vehicle networking asset object can form an asset database.

[0085] In one embodiment of the present application, the steps for determining the evaluation indicators corresponding to the evaluated objects that have been classified and labeled include the following:

[0086] Based on a preset construction model, construct a multi-level evaluation hierarchy corresponding to the evaluation object, where each level of the evaluation hierarchy has the evaluation content indicated by the evaluation index.

[0087] Exemplarily, there is an association relationship between the multi-level evaluation hierarchies of the constructed evaluation object (or evaluation object group), such as a large level, a middle level, and a small level, or a large category level, a middle category level, and a small category level. Among them, the middle category level enriches and refines the content of the large category level, and the small category further enriches and refines the content of the middle category. As shown in Table 1 below:

[0088]

[0089]

[0090]

[0091]

[0092]

[0093] Each level of the evaluation hierarchy in this embodiment has the evaluation content indicated by the evaluation index. For example, in the large category level: terminal security, TSP, APP security, CAN bus, communication security, personnel, and security mechanism are the evaluation content evaluated by the evaluation index. Similarly, the middle category level and the small category level can also be the evaluation content evaluated by the gradually refined evaluation index.

[0094] In an embodiment of the present application, as Figure 2 shown, the evaluation object includes a vehicle networking vulnerability object, and the risk model includes: a vehicle networking vulnerability model; determining the risk weight of the evaluation object based on multiple risk models for characterizing different types of risks of the vehicle networking includes:

[0095] S310, classify the vehicle networking vulnerability object by using the vehicle networking vulnerability model;

[0096] S320, assign a risk weight to the classified vehicle networking vulnerability object based on the risk degree of the vehicle networking vulnerability object.

[0097] Exemplarily, the evaluation object includes a vehicle networking vulnerability object, and the vehicle networking vulnerability object has different types. The importance levels of different types of vehicle networking vulnerability objects may also be different. For example, the vulnerability of the in-vehicle unit data object is usually more important, while the vulnerability in the vehicle control application program data object is relatively less important.

[0098] In this embodiment, in order to assign a relatively accurate risk weight to the vehicle networking vulnerability object, the vehicle networking vulnerability object can be classified first, and the risk weights of the vehicle networking vulnerability objects in the same category are the same or similar. Thus, the accurate assignment of the vulnerability risk weight is realized. For example, the parameters of the vehicle networking vulnerability model are set to classify the vehicle networking vulnerability objects modularly, including in-vehicle unit vulnerabilities, APP vulnerabilities, platform vulnerabilities, etc. The set of the vehicle networking vulnerability model in two dimensions is carried out for the classified vulnerabilities, including the level of the vulnerability itself and the degree of harm to the vehicle networking. The degree of harm is divided into the highest for in-vehicle unit vulnerabilities, the second for platform vulnerabilities, and the third for vehicle control APP vulnerabilities.

[0099] In another embodiment of the present application, the evaluation object includes a vehicle networking security event object, and the risk model includes: a security event frequency weight model; determining the risk weight of the evaluation object based on a plurality of risk models for characterizing different types of risks of the vehicle networking includes:

[0100] Using the security event frequency weight model, a risk weight is assigned to the vehicle networking security event object, where the vehicle networking security event object includes at least one of the following: the frequency of occurrence of the security event, the importance level of the associated asset, and the vulnerability level of the asset association.

[0101] Exemplarily, the evaluation object includes a vehicle networking security event object, and the security event frequency weight model is pre-constructed for the vehicle networking security event object. It can assign corresponding risk weights based on the specific content of the vehicle networking security event object. Among them, the vehicle networking security event object includes at least one of the following: the frequency of occurrence of the security event, the importance level of the associated asset, and the vulnerability level of the asset association. For example, the security event frequency weight model can assign the risk weight of the frequency of occurrence of the security event to the first risk weight, assign the risk weight of the importance level of the associated asset to the second risk weight, assign the risk weight of the vulnerability level of the asset association to the third risk weight, etc.

[0102] In yet another embodiment of the present application, the risk model includes: an external risk report model; determining the risk weight of the evaluation object based on a plurality of risk models for characterizing different types of risks of the vehicle networking includes:

[0103] Using the external risk report model, a risk weight is assigned to the vehicle networking asset object, the vehicle networking vulnerability object, and the vehicle networking security event object associated with the received external risk report.

[0104] Exemplarily, the external risk report can be a report independent of the vehicle itself, which can be sent to the vehicle networking to provide a basis for the security assessment of the vehicle networking. The specific content in the external risk report may not be limited, so that the external risk report can point out any security issues in the vehicle networking. Among them, the external risk report can point out the relevant content of the evaluation object, including pointing out the relevant content of the vehicle networking asset object, the vehicle networking vulnerability object, and the vehicle networking security event object.

[0105] The external risk report model in this embodiment can be pre-constructed for the external risk report, so that the external risk report can be analyzed, and risk weights can be assigned to the vehicle networking asset object, the vehicle networking vulnerability object, and the vehicle networking security event object associated with the external risk report.

[0106] In an embodiment of the present application, as Figure 3 shown and in combination with Figure 4 , using at least one evaluation model retrieved from the evaluation model repository, at least based on the risk weight of the evaluation object and / or the evaluation index of the evaluation object, evaluating the evaluation object to generate a corresponding evaluation result, including:

[0107] S410, based on the evaluation object and the corresponding evaluation rule selected from the evaluation rule repository, retrieving the corresponding evaluation model from the evaluation model repository.

[0108] Exemplarily, the evaluation model repository is associated with the evaluation rule repository. A plurality of evaluation models are stored in the evaluation model repository, and a plurality of evaluation rules are stored in the evaluation rule repository. In the case of receiving an evaluation instruction for evaluating the vehicle networking, a corresponding evaluation scheduling task is generated according to the evaluation instruction. According to the evaluation scheduling task, the corresponding evaluation rule can be selected from the evaluation rule repository, and the corresponding evaluation model can be retrieved from the evaluation model repository, and the generated evaluation scheduling task is processed according to the determined evaluation rule.

[0109] S420, performing standardization processing on the sample data of the evaluation object through the evaluation model, where the sample data includes the risk weight and evaluation index of the evaluation object.

[0110] Exemplarily, the sample data of the evaluation object can be the content details included in the evaluation object, including the risk weight and evaluation index of the evaluation object, and can also include other relevant information of the evaluation object, such as the evaluation time, evaluation progress, etc.

[0111] The sample data can be analyzed as a sample of the evaluation model, and the sample data can be determined based on the sample resource pool. The algorithm analysis unit determined from the standard library of the algorithm analysis unit is used to perform standardization processing on the sample data to facilitate the use of the sample data.

[0112] S430, perform an evaluation and deduction on the sample data through the evaluation model to generate the evaluation result.

[0113] Exemplarily, in the process of performing an evaluation and deduction on sample data through an evaluation model, one or more evaluation models can be used to complete the evaluation and deduction, so as to more accurately perform an evaluation and deduction on the sample data of each evaluation object in a targeted manner and generate accurate evaluation results.

[0114] In an embodiment of the present application, continue to combine Figure 4 , use at least one evaluation model retrieved from the evaluation model repository to evaluate the evaluation object at least based on the risk weight of the evaluation object and / or the evaluation index of the evaluation object, and generate a corresponding evaluation result, including:

[0115] Based on the evaluation instruction, determine whether there is an evaluation model corresponding to the evaluation object in the evaluation model repository;

[0116] If not, query whether there is an evaluation rule corresponding to the evaluation object in the evaluation rule repository;

[0117] If not, generate a corresponding evaluation rule based on the evaluation object and store the evaluation rule in the evaluation rule repository.

[0118] Exemplarily, combine Figure 4 , establish an evaluation object, and determine whether there is a corresponding evaluation scheduling task; if so, set the parameters of the evaluation model according to the current evaluation scheduling task and export the evaluation model to evaluate the evaluation object; otherwise, newly add an evaluation scheduling task corresponding to the evaluation object; query whether there is a corresponding evaluation model in the current evaluation model repository; if so, set the parameters of the evaluation model according to the current evaluation scheduling task and export the evaluation model to evaluate the evaluation object, otherwise, query the evaluation rule repository to determine whether there is an evaluation rule required to create an evaluation model; if so, create a template based on the evaluation rule and store it in the evaluation module repository, otherwise, create a new evaluation rule and store it in the evaluation rule repository, and then create an evaluation model based on the evaluation rule and store it in the evaluation model repository; then the parameters of the evaluation model can be set according to the current evaluation scheduling task and the evaluation model can be exported; the automated evaluation and deduction device calls the evaluation model, and the evaluation model automatically collects and obtains standardized sample data from the data collection device for algorithmic automated evaluation and deduction. An algorithm evaluation device can output the evaluation result in a graphic and text manner, including the evaluation object, threat index, and evaluation security suggestions.

[0119] Optionally, the method further includes the following steps: visually outputting the evaluation result; and disposing of the threats to the vehicle networking included in the evaluation result.

[0120] Exemplarily, visually outputting the evaluation result enables the user to be clearer about the evaluation result, so that corresponding processing can be performed on the vehicle networking according to the evaluation result, thereby increasing the security of the vehicle networking. In addition, the threats to the vehicle networking included in the evaluation result can also be disposed of, thereby making up for loopholes and eliminating threats.

[0121] According to the same inventive concept, an embodiment of the present application further provides a security evaluation device for a vehicle networking, as Figure 5 shown, including:

[0122] A label module configured to perform labeling processing on multiple evaluation object groups of the vehicle networking to classify and label multiple evaluation objects in the evaluation object group, where the evaluation object group is a set of objects for respectively evaluating multiple different aspects of the vehicle networking.

[0123] Exemplarily, the vehicle networking has multiple different evaluation object groups for evaluation, and different evaluation object groups focus on different evaluation directions. And each evaluation object group includes at least one evaluation object, thereby further refining the data sources for evaluation.

[0124] For example, the evaluation object group includes at least one of the following: in-vehicle device end data objects, vehicle control application (APP) data objects, vehicle networking platform data objects, communication data objects, vehicle networking vulnerability objects, and vehicle networking asset objects. Each of the above evaluation object groups includes at least one evaluation object. For example, the vehicle control APP data object includes application program data objects such as the vehicle networking's T-BOX, OBD, and IVI.

[0125] In this embodiment, the label module performs labeling processing on multiple evaluation object groups of the vehicle networking and classifies and labels the evaluation objects in each evaluation object group, so as to facilitate the operation and processing of the evaluation objects when they are called. For example, standard naming and digital labeling are performed on each evaluation object in the evaluation object group.

[0126] Continuing with the above embodiment for illustration, the label module performs labeling processing on the in-vehicle device end data objects, and can classify and label data such as corresponding security logs, security events, vulnerabilities, and alarms for access control, authorization, authentication, permission access, networking, and self-detection on the in-vehicle device side.

[0127] The labeling module performs labeling on the data objects of the vehicle control application (APP), and can classify and label data such as vehicle networking platform server security, network security, storage security, data security, identity authentication and authorization, etc.

[0128] The labeling module performs labeling on the data objects of the vehicle networking platform, and can classify and label data such as terminal location, user authentication, communication logs, etc.

[0129] The labeling module performs labeling on the vehicle networking vulnerability objects, which can include classifying and labeling data such as vulnerability level labels, vulnerability type labels, and vulnerable impact subjects.

[0130] The labeling module performs labeling on the vehicle networking asset objects, and can form an asset database.

[0131] The labeled evaluation object group enables the details of each of the above-mentioned evaluation objects to be concerned, and then facilitates subsequent processing thereof, such as retrieving each evaluation object by the labeled name.

[0132] A determination module, configured to determine evaluation indicators corresponding to the evaluation objects that have been classified and labeled, wherein the evaluation indicators are indications for evaluating the evaluation objects from multiple different aspects.

[0133] Exemplarily, each evaluation object can be evaluated from multiple evaluation indicators. The setting of the evaluation indicators corresponding to the evaluation objects can be performed according to the type, function, specific content included, and / or importance of the evaluation objects. The evaluation indicators can be divided into multiple levels, such as large levels, middle levels, and small levels, so as to enable rich and hierarchical evaluation of the evaluation objects according to the evaluation indicators.

[0134] For example, for the APP security in the data objects of the vehicle control application, it includes basic security indicators, storage security indicators, and operation security indicators. Among them, the basic security indicators include the next-level APP reinforcement indicators, security authentication indicators, minimum privilege indicators, and APP anti-tampering indicators, etc.; the storage security indicators include the next-level data encryption indicators, log encryption indicators, and certificate encryption indicators; the operation security indicators include the next-level environment detection indicators and information input detection indicators. The above-mentioned evaluation indicators are indications for evaluating the APP security in the data objects of the vehicle control application from multiple different aspects. Thus, the APP security can be evaluated from the above-mentioned evaluation indicators to obtain a complete and accurate evaluation result. Of course, the determination module can also respectively determine the corresponding evaluation indicators for other evaluation objects of the vehicle networking.

[0135] A risk weight module, configured to determine the risk weight of the evaluation object based on multiple risk models for characterizing different types of risks of the vehicle networking.

[0136] Exemplarily, the preset multiple different risk models have different focus directions, and the risk models can assign risk weights to the corresponding evaluation objects. For example, the risk models include a vehicle network vulnerability model, a security event frequency weight model, and an external risk report model. Among them, the vehicle network vulnerability model is preset for the risks related to security vulnerabilities in the evaluation objects of the vehicle network and can assign risk weights to the vulnerabilities. The security event frequency weight model is preset for the relevant information related to the occurrence of security events in the evaluation objects of the vehicle network; the external risk report model is preset for the risk content involved in the external risk report of the vehicle network.

[0137] The risk weight module assigns risk weights to the evaluation objects through the risk models, so that when performing risk assessment on the evaluation objects, accurate calculations can be performed on the evaluation objects based on the risk weights, thereby obtaining accurate evaluation results.

[0138] A processing module, configured to, when receiving an evaluation instruction for evaluating the vehicle network, use at least one evaluation model retrieved from an evaluation model repository to evaluate the evaluation object based at least on the risk weight of the evaluation object and / or the evaluation index of the evaluation object, and generate a corresponding evaluation result.

[0139] Exemplarily, the evaluation instruction may be an instruction to start a security evaluation of the vehicle network, and the evaluation instruction corresponds to an evaluation task. For example, the evaluation task may be a task to start a security evaluation of the vehicle network at a predetermined time, specifically including retrieving an evaluation model from the evaluation model repository and using the evaluation model.

[0140] The evaluation model repository stores at least one evaluation model, and each evaluation model has a different focus direction for evaluation. The processing module can use multiple evaluation models to evaluate the evaluation object from multiple dimensions.

[0141] For example, the evaluation model repository stores an overall situation analysis model, a built-in evaluation model, a custom evaluation model, a special topic situation analysis model, a threat portrait analysis model, and an abnormal behavior analysis model. The above evaluation models have their respective focus evaluation directions. The processing module can use one or more evaluation models to evaluate the evaluation object, thereby obtaining multi-dimensional evaluation results, and the evaluation results are comprehensive and accurate.

[0142] For example, the combination of the built-in evaluation model and the custom evaluation model can customize evaluation metrics, learning time, and evaluation dimensions. The threat portrait analysis model can perform portrait analysis on attack behaviors that threaten the security of the vehicle network, including threat sources, IPs, ports, associated modules, associated vulnerabilities, and levels, to form a threat portrait analysis situation. The abnormal behavior analysis model can analyze behaviors that endanger the security of the vehicle network, including asset and user behavior dimensions, changes, tampering, and security events of abnormal assets, as well as the monitoring of user behaviors, including the monitoring of behaviors such as permission settings and operation settings.

[0143] In this embodiment, when the processing module uses the evaluation model to evaluate the evaluation object, it evaluates the evaluation object based at least on the risk weight of the evaluation object and / or the evaluation metrics of the evaluation object. Different evaluation objects have corresponding risk weights and evaluation metrics. This will enable the evaluation model to comprehensively evaluate all the given evaluation metrics during evaluation, and can also focus on evaluation objects with larger risk weights, making the generated evaluation results more accurate and comprehensive.

[0144] In an embodiment of the present application, the evaluation object group includes at least one of the following: in-vehicle device end data object, vehicle control application program data object, vehicle network platform data object, communication data object, vehicle network vulnerability object, and vehicle network asset object;

[0145] Correspondingly, the tagging module is further configured to:

[0146] Perform tagging on the in-vehicle device end data object, the vehicle control application program data object, the vehicle network platform data object, the communication data object, the vehicle network vulnerability object, and / or the vehicle network asset object, respectively.

[0147] In an embodiment of the present application, the determination module is further configured to:

[0148] Based on a preset construction model, construct a multi-layer evaluation hierarchy corresponding to the evaluation object, where each layer of the evaluation hierarchy has the evaluation content indicated by the evaluation metrics.

[0149] In an embodiment of the present application, the evaluation object includes a vehicle network vulnerability object, and the risk model includes: a vehicle network vulnerability model; the risk weight module is further configured to:

[0150] Use the vehicle network vulnerability model to classify the vehicle network vulnerability object;

[0151] Based on the risk level of the vehicle network vulnerability object, assign a risk weight to the classified vehicle network vulnerability object.

[0152] In an embodiment of the present application, the evaluation object includes a vehicle networking security event object, and the risk model includes: a security event frequency weight model; the risk weight module is further configured to:

[0153] Use the security event frequency weight model to assign risk weights to the vehicle networking security event objects, where the vehicle networking security event objects include at least one of the following: the frequency of occurrence of security events, the importance level of associated assets, and the vulnerability level of asset association.

[0154] In an embodiment of the present application, the risk model includes: an external risk report model; the risk weight module is further configured to:

[0155] Use the external risk report model to assign risk weights to the vehicle networking asset objects, vehicle networking vulnerability objects, and vehicle networking security event objects associated with the received external risk reports.

[0156] In an embodiment of the present application, the processing module is further configured to:

[0157] Based on the evaluation object and the evaluation rules selected from the evaluation rule repository accordingly, retrieve the corresponding evaluation model from the evaluation model repository;

[0158] Perform standardization processing on the sample data of the evaluation object through the evaluation model, where the sample data includes the risk weights and evaluation indicators of the evaluation object;

[0159] Perform evaluation and deduction on the sample data through the evaluation model to generate the evaluation result.

[0160] In an embodiment of the present application, the processing module is further configured to:

[0161] Based on the evaluation instruction, determine whether there is a corresponding evaluation model in the evaluation model repository for the evaluation object;

[0162] If not, query whether there are evaluation rules corresponding to the evaluation object in the evaluation rule repository;

[0163] If not, generate corresponding evaluation rules based on the evaluation object and store the evaluation rules in the evaluation rule repository.

[0164] An embodiment of the present application further provides an electronic device, including a memory and a processor. An executable program is stored in the memory, and the processor executes the executable program to implement the following steps:

[0165] Label multiple evaluation object groups of the vehicle networking to classify and label multiple evaluation objects in the evaluation object groups, where the evaluation object groups are sets of objects for respectively evaluating multiple different aspects of the vehicle networking;

[0166] Determine the evaluation indicators corresponding to the evaluation objects that have been classified and labeled, where the evaluation indicators are indications for evaluating the evaluation objects from multiple different aspects;

[0167] Based on multiple risk models for characterizing different types of risks of the vehicle networking, determine the risk weights of the evaluation objects;

[0168] When receiving an evaluation instruction for evaluating the vehicle networking, use at least one evaluation model retrieved from an evaluation model repository to evaluate the evaluation objects based at least on the risk weights and / or the evaluation indicators of the evaluation objects, and generate corresponding evaluation results.

[0169] An embodiment of the present application further provides a storage medium, which carries one or more computer programs, and when the one or more computer programs are executed by a processor, the steps of the method in any embodiment are implemented.

[0170] The storage medium in this embodiment can be included in an electronic device / system; or it can exist alone without being assembled into the electronic device / system. The above storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiment of the present application is implemented.

[0171] According to an embodiment of the present application, the computer-readable storage medium can be a non-volatile computer-readable storage medium, for example, it can include but is not limited to: portable computer disks, hard disks, random access memories (RAMs), read-only memories (ROMs), erasable programmable read-only memories (EPROMs or flash memories), portable compact disk read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, device, or device.

[0172] The above embodiments are only exemplary embodiments of the present application and are not used to limit the present application. The protection scope of the present application is defined by the claims. Those skilled in the art can make various modifications or equivalent replacements within the essence and protection scope of the present application, and such modifications or equivalent replacements should also be regarded as falling within the protection scope of the present application.

Claims

1. A security assessment method for an Internet of Vehicles, characterized in that Including: Performing tagging processing on multiple evaluation object groups of the vehicle networking to classify and label multiple evaluation objects in the evaluation object groups, where the evaluation object groups are sets of objects for respectively evaluating multiple different aspects of the vehicle networking; Determining evaluation indicators corresponding to the evaluation objects that have been classified and labeled, where the evaluation indicators are indications for evaluating the evaluation objects from multiple different aspects; Based on multiple risk models for characterizing different types of risks of the vehicle networking, determining the risk weights of the evaluation objects; When receiving an evaluation instruction for evaluating the vehicle networking, using at least one evaluation model retrieved from an evaluation model repository, and evaluating the evaluation objects at least based on the risk weights and / or the evaluation indicators of the evaluation objects to generate corresponding evaluation results; where The using at least one evaluation model retrieved from an evaluation model repository and evaluating the evaluation objects at least based on the risk weights and / or the evaluation indicators of the evaluation objects to generate corresponding evaluation results includes: Based on the evaluation objects and corresponding evaluation rules selected from an evaluation rule repository, retrieving the corresponding evaluation model from the evaluation model repository; Performing standardization processing on the sample data of the evaluation objects through the evaluation model, where the sample data includes the risk weights and evaluation indicators of the evaluation objects; Performing evaluation deduction on the sample data through the evaluation model to generate the evaluation results.

2. The method according to claim 1, wherein The evaluation object groups include at least one of the following: in-vehicle terminal data objects, vehicle control application program data objects, vehicle networking platform data objects, communication data objects, vehicle networking vulnerability objects, and vehicle networking asset objects; Correspondingly, the performing tagging processing on multiple evaluation object groups of the vehicle networking includes: Performing tagging on the in-vehicle terminal data objects, the vehicle control application program data objects, the vehicle networking platform data objects, the communication data objects, the vehicle networking vulnerability objects, and / or the vehicle networking asset objects respectively.

3. The method according to claim 1, characterized in that, The determining evaluation indicators corresponding to the evaluation objects that have been classified and labeled includes: Based on a preset construction model, constructing a multi-layer evaluation hierarchy corresponding to the evaluation objects, where each layer of the evaluation hierarchy has the evaluation content indicated by the evaluation indicators.

4. The method according to claim 1, characterized in that The evaluation objects include vehicle networking vulnerability objects, and the risk models include: vehicle networking vulnerability models; the based on multiple risk models for characterizing different types of risks of the vehicle networking and determining the risk weights of the evaluation objects includes: Using the vehicle networking vulnerability models to classify the vehicle networking vulnerability objects; Based on the risk levels of the vehicle networking vulnerability objects, assigning risk weights to the classified vehicle networking vulnerability objects.

5. The method according to claim 1, wherein The evaluation objects include vehicle networking security event objects, and the risk models include: security event frequency weight models; the based on multiple risk models for characterizing different types of risks of the vehicle networking and determining the risk weights of the evaluation objects includes: Using the security incident frequency weight model, risk weights are assigned to the vehicle networking security incident objects, where the vehicle networking security incident objects include at least one of the following: the frequency of occurrence of security incidents, the importance level of associated assets, and the vulnerability level of asset associations.

6. The method according to claim 1, characterized in that The risk model includes: an external risk report model; determining the risk weight of the evaluation object based on multiple risk models for characterizing different types of risks of the vehicle networking, including: Using the external risk report model, risk weights are assigned to the vehicle networking asset objects, vehicle networking vulnerability objects, and vehicle networking security incident objects associated with the received external risk reports.

7. The method according to claim 1, wherein Using at least one evaluation model retrieved from the evaluation model repository, evaluating the evaluation object based on at least the risk weight of the evaluation object and / or the evaluation indicators of the evaluation object to generate corresponding evaluation results, including: Based on the evaluation instruction, determining whether there is an evaluation model corresponding to the evaluation object in the evaluation model repository; If not, querying whether there is an evaluation rule corresponding to the evaluation object in the evaluation rule repository; If not, generating a corresponding evaluation rule based on the evaluation object and storing the evaluation rule in the evaluation rule repository.

8. The method according to claim 7, wherein The method further includes: Visualizing and outputting the evaluation results; Disposing of the threats to the vehicle networking included in the evaluation results.

9. A security assessment device for an Internet of Vehicles, characterized in that, Including: A labeling module configured to label multiple evaluation object groups of the vehicle networking to classify and label multiple evaluation objects in the evaluation object group, where the evaluation object group is a set of objects obtained by separately evaluating multiple different aspects of the vehicle networking; A determination module configured to determine the evaluation indicators corresponding to the evaluation objects that have been classified and labeled, where the evaluation indicators are instructions for evaluating the evaluation objects from multiple different aspects; A risk weight module configured to determine the risk weights of the evaluation objects based on multiple risk models for characterizing different types of risks of the vehicle networking; A processing module configured to, when receiving an evaluation instruction for evaluating the vehicle networking, use at least one evaluation model retrieved from the evaluation model repository to evaluate the evaluation object based on at least the risk weight of the evaluation object and / or the evaluation indicators of the evaluation object to generate corresponding evaluation results; where The processing module is further configured to: Based on the evaluation object and the corresponding evaluation rules selected from the evaluation rule repository, retrieve the corresponding evaluation model from the evaluation model repository; Standardize the sample data of the evaluation object through the evaluation model, where the sample data includes the risk weight and evaluation indicators of the evaluation object; Evaluate and deduce the sample data through the evaluation model to generate the evaluation results.

Citation Information

Patent Citations

  • Method and system for evaluating data quality of Internet of Vehicles

    CN113806343A