Information security testing method, device and storage medium for vehicle-mounted system

By installing a test monitoring module on the on-board system, using virtualization technology to run information security test cases and generate status data, the problem of difficulty in accurately locate security vulnerabilities in the existing technology is solved, and all-round information security testing and vulnerability positioning is achieved.

CN115391782BActive Publication Date: 2025-05-23ZHEJIANG ZEEKR INTELLIGENT TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210864888.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-21
Publication Date
2025-05-23
Estimated Expiration
2042-07-21

AI Technical Summary

Technical Problem

The prior art is difficult to accurately determine the location of security vulnerabilities in on-board systems, and it is impossible to conduct comprehensive information security testing.

Method used

Virtualization technology is used to install a test monitoring module on the vehicle's on-board system. By receiving test cases sent by the information security test device, it runs and generates status data, determines whether there are security vulnerabilities in the code, and feedbacks the results to continue testing.

Benefits of technology

Accurate vulnerability positioning and comprehensive information security testing of the on-board system are realized, ensuring that the test cases effectively reach the test target and obtain status data, thereby accurately locateing the location of the security vulnerability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115391782B_ABST
    Figure CN115391782B_ABST
Patent Text Reader

Abstract

The present invention discloses an information security testing method, device and storage medium for an on-board system, which relates to the field of vehicle safety technology and can accurately determine the location of security vulnerabilities in the on-board system. The method comprises: receiving a first test case sent by an information security testing device for testing whether a first part of the code of a target module has a security vulnerability. Running the first test case, and generating first status data of the target module according to the running process. Determining whether a security vulnerability exists in the first part of the code according to the first status data. If it is determined that there is no security vulnerability in the first part of the code, sending the first status data to the information security testing device, receiving a second test case sent by the information security testing device, generating second status data, and sending feedback information to the information security testing device when it is determined that a security vulnerability exists in the second part of the code according to the second status data, and the feedback information is used to indicate that a security vulnerability exists in the target module.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of vehicle safety technology, and in particular to an information security testing method, device and storage medium for a vehicle-mounted system. Background Art

[0002] As the degree of automobile intelligence, networking and electrification continues to increase, the information security issues of intelligent and connected vehicles are becoming increasingly serious. The most common and dangerous automobile information security vulnerabilities include insecure cloud interfaces, unauthorized access, system backdoors, and insecure vehicle communications. Once attackers exploit security vulnerabilities, they can achieve illegal access, steal sensitive data, and remote control, which seriously affects the driving safety of passengers in the car, and even the safety of life and property. For this reason, major automobile manufacturers have conducted information security tests on the vehicle's onboard systems.

[0003] In the prior art, information security testing devices can perform access tests on various external interfaces of a vehicle's onboard system to determine whether the onboard system has security vulnerabilities. However, simply performing access tests on interfaces cannot accurately determine the location of security vulnerabilities in the onboard system, and cannot perform comprehensive information security tests on the onboard system. Summary of the invention

[0004] The present invention provides an information security testing method for an on-vehicle system, a vehicle and a storage medium, which can accurately determine the location of a security vulnerability in the on-vehicle system.

[0005] In order to achieve the above object, the present invention adopts the following technical scheme:

[0006] In a first aspect, the present invention provides an information security testing method for an in-vehicle system, the method comprising:

[0007] Receiving a first test case corresponding to a target module sent by an information security testing device, the first test case being used to test whether a first part of code of the target module has a security vulnerability, the target module being any module among a plurality of functional modules in an onboard system installed in a vehicle;

[0008] Running a first test case, and generating first state data of a target module according to the running process;

[0009] Determining whether the first part of the code has a security vulnerability according to the first state data;

[0010] If it is determined that the first part of the code has a security vulnerability, feedback information is sent to the information security testing device, and the feedback information is used to indicate that the target module has a security vulnerability;

[0011] If it is determined that the first part of the code does not have a security vulnerability, first state data is sent to the information security testing device, the first state data is used by the information security testing device to generate a second test case, the second test case is used to test whether the second part of the code of the target module has a security vulnerability, and the first part of the code is not completely the same as the second part of the code;

[0012] Receive a second test case sent by the information security testing device, generate second status data, and when it is determined according to the second status data that a security vulnerability exists in the second part of the code, send feedback information to the information security testing device, wherein the feedback information is used to indicate that a security vulnerability exists in the target module.

[0013] The information security testing method of the vehicle-mounted system provided by the present invention uses virtualization technology to install a test monitoring module on the vehicle-mounted system of the vehicle. When the target module of the vehicle receives the first test case corresponding to the target module of the vehicle-mounted system sent by the information security testing device, the vehicle runs the first test case. In the process of the vehicle running the first test case, the test monitoring module will generate the first state data of the target module according to the running process, and determine whether the first part of the code of the target module has a security vulnerability according to the first state data. If it is determined that the first part of the code does not have a security vulnerability, the first state data will be sent to the information security testing device, and the second test case generated by the information security testing device according to the first state data and the first test case will be received, and the second test case will continue to run until it is determined that the target module has a security vulnerability, and feedback information is sent to the information security testing device. In the above process, since the test monitoring module is always monitoring the operation of each test case, it can be ensured that the test case effectively reaches the test target (i.e., the code corresponding to the target module), and the corresponding state data after each test case is run is obtained. From the state data, it can be determined whether the corresponding code has a security vulnerability, so that the position of the code with a security vulnerability can be accurately located. Moreover, during the testing process, each test case is different, so that every line of code in the target module can be tested, ensuring the comprehensiveness of the test path.

[0014] In a possible implementation, the information security testing method further includes:

[0015] If it is determined that the first part of the code has a security hole, feedback information is sent to the information security testing device.

[0016] In a possible implementation, if it is determined that the first part of the code has a security vulnerability, the above information security testing method further includes:

[0017] storing first state data and a first test case;

[0018] In response to a user's query operation on a target module, first state data and a first test case are sent to an information security testing device.

[0019] In a possible implementation, the first state data includes a first running path and state information, the first running path is used to indicate the location of the first portion of code, and the state information is used to indicate information of registers and memory corresponding to the target module.

[0020] In a possible implementation, the multiple functional modules in the above-mentioned vehicle-mounted system include: an Ethernet module, a bus module, a Bluetooth module or a wireless communication module.

[0021] In a second aspect, the present invention provides an information security testing method for an in-vehicle system, the method comprising:

[0022] Sending a first test case corresponding to a target module to the vehicle-mounted system, the first test case being used to test whether a first part of code of the target module has a security vulnerability, the target module being any module among a plurality of functional modules in the vehicle-mounted system installed in the vehicle;

[0023] receiving first status data sent by the vehicle-mounted system, where the first status data is sent when it is determined that the target module does not have a security vulnerability;

[0024] Generate a second test case according to the first state data and the first test case, the second test case is used to test whether there is a security vulnerability in the second part of the code of the target module, and the first part of the code is not completely the same as the second part of the code;

[0025] The second test case is sent to the vehicle system.

[0026] In a third aspect, the present invention provides an information security testing device for an in-vehicle system, the information security testing device for the in-vehicle system comprising:

[0027] A receiving unit, configured to receive a first test case corresponding to a target module sent by an information security testing device, wherein the first test case is used to test whether a first part of code of the target module has a security vulnerability, and the target module is any one of a plurality of functional modules in the vehicle-mounted system installed in the vehicle;

[0028] A processing unit, configured to run the first test case and generate first state data of the target module according to the running process;

[0029] a determination unit, configured to determine whether the first part of the code has a security vulnerability according to the first state data; if it is determined that the first part of the code does not have a security vulnerability, the first state data is sent to the information security testing device, the first state data is used by the information security testing device to generate a second test case, the second test case is used to test whether the second part of the code of the target module has a security vulnerability, and the first part of the code is not completely the same as the second part of the code;

[0030] The receiving unit is also used to receive a second test case sent by the information security testing device, generate second status data, and when it is determined based on the second status data that a security vulnerability exists in the second part of the code, feedback information is provided to the information security testing device, and the feedback information is used to indicate that a security vulnerability exists in the target module.

[0031] In a possible implementation, the determination unit is further configured to send feedback information to the information security testing device if it is determined that the first portion of code has a security vulnerability.

[0032] In a possible implementation, the above-mentioned information security testing device for the vehicle-mounted system further includes: a storage unit and a sending unit;

[0033] A storage unit, configured to store the first state data and the first test case if it is determined that the first portion of code has a security vulnerability;

[0034] A sending unit is used to send the first state data and the first test case to the information security testing device in response to a user's query operation on the target module.

[0035] In a possible implementation, the first state data includes a first running path and state information, the first running path is used to indicate the location of the first portion of code, and the state information is used to indicate information of registers and memory corresponding to the target module.

[0036] In a fourth aspect, the present invention provides an information security testing device for an in-vehicle system, the information security testing device for an in-vehicle system comprising: a processor and a memory. The memory is used to store computer program code, and the computer program code comprises computer instructions. When the processor executes the computer instructions, the information security testing device for the in-vehicle system executes the information security testing method for the in-vehicle system of the first aspect and any possible implementation thereof, or executes the information security testing method for the in-vehicle system of the second aspect.

[0037] In a fifth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon. When the computer instructions are executed on an information security testing device of a vehicle-mounted system, the information security testing device of the vehicle-mounted system executes an information security testing method for a vehicle-mounted system as described in the first aspect or any one of the possible implementations of the first aspect, or executes the information security testing method for a vehicle-mounted system as described in the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 A schematic diagram of the structure of an information security testing system for an in-vehicle system provided by an embodiment of the present invention;

[0039] Figure 2 A schematic diagram of the structure of an information security testing device for an on-vehicle system provided by an embodiment of the present invention;

[0040] Figure 3 A schematic diagram of a flow chart of an information security testing method for an in-vehicle system provided by an embodiment of the present invention;

[0041] Figure 4 One of the structural schematic diagrams of a vehicle provided by an embodiment of the present invention;

[0042] Figure 5 The second structural schematic diagram of the vehicle provided in the embodiment of the present invention. DETAILED DESCRIPTION

[0043] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0044] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of the present disclosure, unless otherwise specified, "multiple" means two or more. In addition, the use of "based on" or "according to" means openness and inclusiveness, because the process, steps, calculations or other actions "based on" or "according to" one or more of the conditions or values ​​may be based on additional conditions or values ​​beyond the described values ​​in practice.

[0045] In order to accurately determine the location of the security vulnerability of the vehicle-mounted system, an embodiment of the present invention provides an information security testing method, device and storage medium for the vehicle-mounted system. The embodiment of the present invention uses virtualization technology to install a test monitoring module on the vehicle-mounted system of the vehicle. When the target module of the vehicle receives the first test case corresponding to the target module of the vehicle-mounted system sent by the information security testing device, the vehicle runs the first test case. In the process of the vehicle running the first test case, the test monitoring module generates the first state data of the target module according to the running process, and the abnormal monitoring module determines whether the first part of the code of the target module has a security vulnerability according to the first state data. If it is determined that the first part of the code has a security vulnerability, the test monitoring module sends feedback information to the information security testing device, and the feedback information is used to indicate that the target module has a security vulnerability. After receiving the feedback information, the information security testing device can stop sending test cases to the vehicle. If it is determined that the first part of the code does not have a security vulnerability, the first state data will be sent to the information security testing device, and the second test case generated by the information security testing device according to the first state data and the first test case will be received, and the second test case will continue to run until it is determined that the target module has a security vulnerability, and feedback information is sent to the information security testing device. In the above process, since the test monitoring module is always monitoring the running of each test case, it can ensure that the test case reaches the test target (i.e., the code corresponding to the target module) effectively, and obtains the corresponding status data after each test case is run. From the status data, it can be determined whether the corresponding code has a security vulnerability, so that the location of the code with the security vulnerability can be accurately located. Moreover, during the test process, each test case is different, so that every line of code in the target module can be tested, ensuring the comprehensiveness of the test path.

[0046] The information security testing method for the vehicle-mounted system provided by the embodiment of the present invention can be applicable to the information security testing system for the vehicle-mounted system. Figure 1 FIG. 1 shows a structural diagram of the information security test system of the vehicle-mounted system. Figure 1 As shown, the information security test system of the vehicle-mounted system may include: a vehicle 11 and an information security test device 12. The vehicle 11 and the information security test device 12 may be connected by wireless communication.

[0047] The vehicle 11 is equipped with an onboard system, an onboard hardware device and a virtual machine monitor, and the onboard system and the onboard hardware device are in communication connection. The onboard hardware device includes an electronic control unit (ECU) on the vehicle. The virtual machine monitor is installed on the onboard system and is used to build a virtualization layer using hardware virtualization technology and monitor the operation process of the onboard system on the virtualization layer.

[0048] The information security testing device 12 is used to send corresponding test cases to the target module in the vehicle-mounted system installed in the vehicle, and receive feedback information sent by the vehicle. The feedback information is sent by the vehicle to the information security testing device when the vehicle determines that the target module has a security vulnerability. It is also used to stop sending test cases to the vehicle based on the feedback information. Or receive the status data sent by the vehicle, and obtain the corresponding test case based on the status data to continue to perform information security testing on the target module until it is determined that the target module has a security vulnerability.

[0049] Figure 2 The schematic diagram of the structure of the information security test device of the vehicle system is as follows: Figure 2 As shown, the information security testing device of the vehicle-mounted system may include: a processor 21, a memory 22, a communication interface 23 and a bus 24. The processor 21, the memory 22 and the communication interface 23 may be connected via a communication bus 24.

[0050] The processor 21 is the control center of the information security test device of the vehicle system, which can be a processor 21 or a general term for multiple processing elements. For example, the processor 21 can be a general-purpose central processing unit (CPU) or other general-purpose processors 21. Among them, the general-purpose processor 21 can be a microprocessor 21 or any conventional processor 21.

[0051] As an embodiment, the processor 21 may include one or more CPUs, for example, Figure 2 CPU0 and CPU1 are shown.

[0052] The memory 22 may be a read-only memory 22 (ROM) or other types of static storage devices that can store static information and instructions, a random access memory 22 (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory 22 (EEPROM), a disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0053] In a possible implementation, the memory 22 may exist independently of the processor 21, and the memory 22 may be connected to the processor 21 via a bus 24 to store instructions or program codes. When the processor 21 calls and executes the instructions or program codes stored in the memory 22, the information security testing method of the vehicle-mounted system provided in the following embodiment of the present invention can be implemented.

[0054] In another possible implementation, the memory 22 may also be integrated with the processor 21 .

[0055] The communication interface 23 is used for connecting the information security test device of the vehicle-mounted system with other devices through a communication network, and the communication network may be Ethernet, a radio access network (RAN), a wireless local area network (WLAN), etc. The communication interface 23 may include a receiving unit for receiving data and a sending unit for sending data.

[0056] The bus 24 may be an Industry Standard Architecture (ISA) bus 24, a Peripheral Component Interconnect (PCI) bus 24, or an Extended Industry Standard Architecture (EISA) bus 24. The bus 24 may be divided into an address bus 24, a data bus 24, a control bus 24, etc. For ease of representation, Figure 2 Although only one thick line is used in the figure, it does not mean that there is only one bus 24 or only one type of bus 24.

[0057] Optionally, the information security testing device for the vehicle-mounted system provided by the embodiment of the present invention may also include: a vehicle-mounted system attack surface analysis module, a vehicle-mounted system privilege escalation testing module, a sample mutation module, a vulnerability reporting module and testing modules for functional modules of multiple vehicle-mounted systems.

[0058] Exemplarily, the above-mentioned multiple test modules may include: Ethernet test module, vehicle system CAN test module, vehicle system Bluetooth test module, vehicle system Wifi test module, vehicle system Flexray test module, and vehicle system Lin test module, but are not limited to these.

[0059] Among them, the vehicle system attack surface analysis module is used to scan the network ports of the vehicle system and determine the network ports of multiple functional modules of the vehicle system. The sample mutation module is used to perform targeted mutations on test cases based on the operating status of the target module monitored by the vehicle's test monitoring module. Compared with traditional random mutations, it will have higher sample validity. The vulnerability reporting module is used to determine the location and test cases of security vulnerabilities in the vehicle based on the vehicle's abnormal monitoring module, which facilitates engineers to reproduce vulnerabilities and locate and repair vulnerabilities in the vehicle system.

[0060] It should be pointed out that Figure 2 The structure shown in the figure does not constitute a limitation on the information security test device of the vehicle-mounted system. Figure 2 In addition to the components shown, the information security testing device for the vehicle-mounted system may include more or fewer components than those shown in the figure, or combine certain components, or arrange the components differently.

[0061] The execution subject of the information security testing method for the vehicle-mounted system provided in the embodiment of the present invention is the information security testing device for the vehicle-mounted system. The information security testing device for the vehicle-mounted system can be the above-mentioned vehicle and information security testing device, or it can be the CPU in the above-mentioned vehicle and information security testing device, or it can be the control module in the above-mentioned vehicle and information security testing device for testing whether there are security vulnerabilities in the vehicle-mounted system. The embodiment of the present invention takes the vehicle executing the information security testing method for the vehicle-mounted system as an example to illustrate the information security testing method for the vehicle-mounted system provided by the present invention.

[0062] The following describes a method for testing whether a vehicle-mounted system has a security vulnerability provided by an embodiment of the present invention in conjunction with the accompanying drawings.

[0063] like Figure 3 As shown, the information security testing method of the vehicle-mounted system provided by the embodiment of the present invention includes the following steps 301 to 309.

[0064] 301. The information security testing device sends a first test case corresponding to a target module to the vehicle-mounted system.

[0065] The first test case is used to test whether there is a security vulnerability in the first part of the code of the target module. The target module is any module among multiple functional modules in the vehicle-mounted system installed in the vehicle.

[0066] Optionally, the multiple functional modules in the vehicle-mounted system installed in the vehicle may include: an Ethernet module, a bus module, a Bluetooth module and a wireless communication module. Among them, the bus module may be a CAN bus module of the vehicle-mounted system, a Flexray bus module of the vehicle-mounted system and a Lin bus module of the vehicle-mounted system, but is not limited thereto.

[0067] Exemplarily, when the target module is an Ethernet module, the vehicle can receive the first test case corresponding to the Ethernet module sent by the information security testing device through the Ethernet interface. When the target module is the CAN bus module of the vehicle-mounted system, the vehicle can receive the first test case corresponding to the CAN bus module sent by the information security testing device through the CAN bus interface. When the target module is the Lin bus module of the vehicle-mounted system, the vehicle can receive the first test case corresponding to the Lin bus module sent by the information security testing device through the Lin bus interface. When the target module is the Flexray bus module of the vehicle-mounted system, the vehicle can receive the first test case corresponding to the Flexray bus module sent by the information security testing device through the Flexray bus interface. When the target module is a Bluetooth module, the vehicle can receive the first test case corresponding to the Bluetooth module sent by the information security testing device through the Bluetooth wireless channel. When the target module is a wireless communication module, the vehicle can receive the first test case corresponding to the wireless communication module sent by the information security testing device through the wireless communication channel.

[0068] Optionally, the vehicle-mounted system installed in the vehicle may further include a privilege escalation module of the vehicle-mounted system. The information security testing device may call the kernel system of the vehicle-mounted system through the privilege escalation module to perform security testing on the kernel system of the vehicle-mounted system.

[0069] In actual application, a virtual machine monitor (VMM) can be installed in the vehicle system. It is software, firmware or hardware used to establish and execute virtual machines. The computer used by the virtual machine monitor to execute one or more virtual machines is called the host machine, and the virtual machine is called the guest machine. The virtual machine monitor can provide a virtual operating platform to execute the guest operating system and is responsible for managing the execution phase of other guest operating systems. Guest operating systems can share virtualized hardware resources together. Therefore, after installing the virtual machine monitor on the vehicle system, the vehicle system can run on the virtual machine monitor, and the virtual machine monitor can monitor any behavior of the vehicle system.

[0070] Before the vehicle's on-board system is safety tested, the on-board system must be started first. Specifically, starting the on-board system may include: starting the virtualization layer, using hardware virtualization technology to build a virtualization layer, and initializing the virtualized hardware devices. At the same time, the test monitoring modules are loaded in sequence in the virtualization layer. Among them, loading the test monitoring module includes parsing the test target configuration, parsing the monitoring point configuration, and initializing the detection status. Loading the exception monitoring module includes registering interrupt callbacks, registering memory access exception callbacks, etc. After the test monitoring module and the exception monitoring module are loaded, the on-board system also needs to be loaded. The on-board system pulls up the virtualization layer and runs. It should be noted that the on-board system runs on the virtualization layer, which is consistent with the process of not running on the virtualization layer.

[0071] When the vehicle-mounted system is started, the vehicle-mounted system can be subjected to information security testing by the information security testing device.

[0072] In actual application, when it is necessary to use an information security testing device to perform security testing on a vehicle's onboard system, first, the onboard system attack surface analysis module of the information security testing device is connected to the vehicle's onboard system for communication, and is used to perform a network port scan on the onboard system to determine the network ports of multiple functional modules of the onboard system. After the information security testing device determines the network ports of the functional modules included in the vehicle's onboard system, the information security testing device is connected to the functional modules corresponding to the vehicle's onboard system to send a first test case to the corresponding functional module through the corresponding network port.

[0073] 302. The vehicle receives a first test case corresponding to a target module sent by an information security testing device.

[0074] 303. The vehicle runs a first test case and generates first state data of a target module according to the running process.

[0075] When the vehicle runs the first test case, the test monitoring module on the virtualization layer can monitor the running process and generate the first status data of the target module according to the running process.

[0076] Exemplarily, the first state data may include: a first running path of the first test case on the target module, and state information, wherein the first running path is used to indicate the location of the first part of the code, and the state information is used to indicate information of registers and memory corresponding to the target module.

[0077] 304. The vehicle determines whether the first part of the code has a security vulnerability based on the first status data.

[0078] The test monitoring module is also used to determine whether the target module has a security vulnerability based on the first status data.

[0079] 305. If the vehicle determines that there is no security vulnerability in the first part of the code, it sends the first status data to the information security testing device.

[0080] The first state data is used by the information security testing device to generate a second test case, and the second test case is used to test whether the second part of the code of the target module has a security vulnerability. It should be noted that the first part of the code is not completely the same as the second part of the code.

[0081] Optionally, if the vehicle determines that the first part of the code has a security vulnerability, it sends feedback information to the information security testing device. The feedback information is used to indicate that the target module has a security vulnerability. Specifically, the feedback information can be used to indicate that the first part of the code of the target module has a security vulnerability.

[0082] After receiving the feedback information, the information security testing device may stop sending the test case to the vehicle. However, at this time, the information security testing device may continue to send new test cases to the vehicle in response to the user's test operation.

[0083] Optionally, if the vehicle determines that there is a security vulnerability in the first part of the code, it stores the first state data and the first test case, and sends the first state data and the first test case to the information security testing device in response to the user's query operation on the target module.

[0084] In actual application, if the test monitoring module determines that the first part of the target module has a security vulnerability, the abnormal monitoring module will store the first state data and the first test case for generating the first state data. The embodiment of the present invention is only illustrated by the first test case. That is to say, for any test case, as long as the corresponding code has a security vulnerability, the abnormal monitoring module in the vehicle system will capture the state data corresponding to the test case, and store the test case and the corresponding state data.

[0085] When the engineer needs to obtain the result of this information security test, that is, the vulnerability report, the information security test device can be connected to the vehicle's onboard system through a data cable. The vehicle can send a vulnerability report including first state data and a first test case to the information security test device in response to the user's query operation on the target module. The vulnerability report module in the information security test device is used to receive a vulnerability report including first state data and a first test case sent by the vehicle. The engineer can view the vulnerability report on the information security test device, and can reproduce the vulnerability, accurately locate the vulnerability, and repair the vulnerability based on the vulnerability report.

[0086] 306. The information security testing device generates a second test case according to the first state data and the first test case.

[0087] When the information security testing device receives the first state data sent by the vehicle, the information security testing device can determine that there is no security vulnerability in the current target module. In order to conduct a comprehensive test on the target module, after receiving the first state data, the sample mutation module can perform a directed mutation on the first test case according to the first state data to obtain a second test case, so as to perform an information security test on the second part of the code of the target module. Compared with the traditional random mutation, the directed mutation here will improve the sample validity of the second test case.

[0088] Exemplarily, performing directed mutation on the first test case may include: flipping a specific field bit in the first test case, enumerating a specific field, etc., so that other mutated test cases can discover more path possibilities.

[0089] 307. The information security testing device sends a second test case to the vehicle-mounted system.

[0090] 308. The vehicle receives a second test case sent by the information security testing device, generates second status data, and generates feedback information when it is determined that a security vulnerability exists in the second part of the code according to the second status data.

[0091] The feedback information is used to indicate that a security vulnerability exists in the target module.

[0092] It should be noted that the feedback information at this time is generated and sent after the second test case is run, and the second test case is used to test the second part of the code of the target module. Then, the feedback information indicating that the target module has a security vulnerability is that the feedback information indicates that the second part of the code of the target module has a security vulnerability.

[0093] 309. The vehicle sends feedback information to the information security testing device.

[0094] It should be noted that the test process described in the above steps 301 to 309 is only an example of a test case being mutated only once (from a first test case to a second test case). In actual application, the test case can be mutated multiple times, and each mutation process is the same as the above, which will not be repeated here.

[0095] The information security testing method of the vehicle system provided by the embodiment of the present invention uses virtualization technology to install a test monitoring module and an abnormal monitoring module on the vehicle system of the vehicle. When the target module of the vehicle receives the first test case corresponding to the target module of the vehicle system sent by the information security testing device, the vehicle runs the first test case. In the process of the vehicle running the first test case, the test monitoring module generates the first state data of the target module according to the running process, and determines whether the first part of the code of the target module has a security vulnerability according to the first state data. If it is determined that there is no security vulnerability in the first part of the code, the first state data will be sent to the information security testing device, and the second test case generated by the information security testing device according to the first state data and the first test case will be received, and the second test case will continue to run until it is determined that the target module has a security vulnerability, and feedback information is sent to the information security testing device. In the above process, since the test monitoring module is always monitoring the operation of each test case, it can be ensured that the test case effectively reaches the test target (i.e., the code corresponding to the target module), and the corresponding state data after each test case is run is obtained, and the corresponding code can be determined from the state data Whether there is a security vulnerability, the position of the code with a security vulnerability can be accurately located. Moreover, during the testing process, each test case is different, so that every line of code in the target module can be tested, ensuring the comprehensiveness of the test path.

[0096] Optionally, the information security testing device may further include a vulnerability reporting module. The vulnerability reporting module is used to receive a vulnerability report including the first state data and the first test case sent by the vehicle. Engineers can view the vulnerability report on the information security testing device, and can reproduce the vulnerability, accurately locate the vulnerability, and repair the vulnerability based on the vulnerability report.

[0097] The above mainly introduces the solution provided by the embodiment of the present invention from the perspective of the device. It is understandable that in order to realize the above functions, the device includes a hardware structure and / or software module corresponding to each function. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiment disclosed in this article, the present invention can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0098] Figure 4 A possible schematic diagram of the composition of the information security testing device 400 of the vehicle-mounted system involved in the above embodiment is shown. Figure 4As shown, the information security testing device 400 of the vehicle-mounted system may include: a receiving unit 401 , a processing unit 402 and a determining unit 403 .

[0099] Among them, the receiving unit 401 is used to receive the first test case corresponding to the target module sent by the information security testing device, and the first test case is used to test whether the first part of the code of the target module has a security vulnerability. The target module is any module among multiple functional modules in the vehicle-mounted system installed in the vehicle. The processing unit 402 is used to run the first test case and generate the first state data of the target module according to the running process. The determination unit 403 is used to determine whether the first part of the code has a security vulnerability based on the first state data; if it is determined that the first part of the code has a security vulnerability, feedback information is sent to the information security testing device, and the feedback information is used to indicate that the target module has a security vulnerability.

[0100] Optionally, the above-mentioned determination unit 403 is also used to send first status data to the information security testing device if it is determined that there is no security vulnerability in the first part of the code, and the first status data is used by the information security testing device to generate a second test case, and the second test case is used to test whether there is a security vulnerability in the second part of the code of the target module, and the first part of the code is not exactly the same as the second part of the code.

[0101] Optionally, the receiving unit 401 is further configured to receive a second test case sent by the information security testing device, and continue to run the second test case until it is determined that a security vulnerability exists in the target module, and send feedback information to the information security testing device.

[0102] Figure 5 Another possible schematic diagram of the composition of the information security testing device for the vehicle-mounted system involved in the above embodiment is shown. Figure 5 As shown, the information security testing device 400 of the vehicle-mounted system may further include: a storage unit 501 and a sending unit 502 .

[0103] The storage unit 501 is used to store the first state data and the first test case. The sending unit 502 is used to send the first state data and the first test case to the information security testing device in response to a user's query operation on the target module.

[0104] Of course, the information security testing device for the vehicle-mounted system provided by the embodiment of the present invention includes but is not limited to the above modules.

[0105] In actual implementation, the receiving unit 401, the processing unit 402, the determining unit 403, the storage unit 501 and the sending unit 502 may be composed of Figure 2 The processor 21 shown calls the program code in the memory 22 to implement. The specific execution process can be referred to Figure 3The description of the information security testing method of the vehicle system shown will not be repeated here.

[0106] Another embodiment of the present invention also provides a computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on an information security testing device of a vehicle-mounted system, the information security testing device of the vehicle-mounted system executes each step executed by the information security testing device of the vehicle-mounted system in the method flow shown in the above method embodiment.

[0107] Another embodiment of the present invention further provides a chip system, which is applied to an information security test device for an in-vehicle system. The chip system includes one or more interface circuits and one or more processors 21. The interface circuit and the processor 21 are interconnected by a line. The interface circuit is used to receive a signal from a memory 22 of the information security test device for the in-vehicle system and send the signal to the processor 21, wherein the signal includes a computer instruction stored in the memory 22. When the processor 21 executes the computer instruction, the information security test device for the in-vehicle system executes each step performed by the information security test device for the in-vehicle system in the method flow shown in the above method embodiment.

[0108] In another embodiment of the present invention, a computer program product is also provided. The computer program product includes instructions. When the instructions are executed on an information security testing device of a vehicle-mounted system, the information security testing device of the vehicle-mounted system executes each step executed by the information security testing device of the vehicle-mounted system in the method flow shown in the above method embodiment.

[0109] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer execution instruction is loaded and executed on the computer, the process or function according to the embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (digital subscriber line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that contains one or more servers that can be integrated with the medium. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (eg, a solid state disk (SSD)).

[0110] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions within the technical scope disclosed by the present invention should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.

Claims

1. A method for testing information security of an in-vehicle system. It is characterized in that include: Receiving a first test case corresponding to a target module sent by an information security testing device, wherein the first test case is used to test whether a first part of code of the target module has a security vulnerability, and the target module is any module among a plurality of functional modules in the vehicle-mounted system installed in the vehicle; Running the first test case, and generating first state data of the target module according to the running process; Determining whether the first part of code has a security vulnerability according to the first state data; If it is determined that the first part of the code does not have a security vulnerability, sending the first state data to the information security testing device, the first state data is used by the information security testing device to generate a second test case, the second test case is used to test whether the second part of the code of the target module has a security vulnerability, and the first part of the code is not completely the same as the second part of the code; Receive the second test case sent by the information security testing device, generate second status data, and when it is determined according to the second status data that the second part of the code has a security vulnerability, send feedback information to the information security testing device, wherein the feedback information is used to indicate that the target module has a security vulnerability.

2. The information security testing method of the vehicle-mounted system according to claim 1, It is characterized in that The information security testing method further includes: If it is determined that the first part of code has a security vulnerability, the feedback information is sent to the information security testing device.

3. The information security testing method of the vehicle-mounted system according to claim 1 or 2, It is characterized in that If it is determined that the first part of the code has a security vulnerability, the information security testing method further includes: storing the first state data and the first test case; In response to a user's query operation on the target module, the first state data and the first test case are sent to the information security testing device.

4. The information security testing method of the vehicle-mounted system according to claim 1 or 2, It is characterized in that The first state data includes a first running path and state information. The first running path is used to indicate the location of the first part of the code, and the state information is used to indicate information of registers and memory corresponding to the target module.

5. A method for testing information security of an in-vehicle system. It is characterized in that include: Sending a first test case corresponding to a target module to the vehicle-mounted system, wherein the first test case is used to test whether a first part of code of the target module has a security vulnerability, and the target module is any module among multiple functional modules in the vehicle-mounted system installed in the vehicle; receiving first status data sent by the vehicle-mounted system, wherein the first status data is sent when it is determined that the target module does not have a security vulnerability; Generate a second test case according to the first state data and the first test case, wherein the second test case is used to test whether a second portion of code of the target module has a security vulnerability, and the first portion of code is not completely the same as the second portion of code; The second test case is sent to the in-vehicle system.

6. An information security testing device for an in-vehicle system, It is characterized in that include: A receiving unit, configured to receive a first test case corresponding to a target module sent by an information security testing device, wherein the first test case is used to test whether a first part of code of the target module has a security vulnerability, and the target module is any one of a plurality of functional modules in the vehicle-mounted system installed in the vehicle; A processing unit, configured to run the first test case and generate first state data of the target module according to the running process; a determining unit, configured to determine whether the first portion of code has a security vulnerability according to the first state data; If it is determined that the first part of the code does not have a security vulnerability, sending the first state data to the information security testing device, the first state data is used by the information security testing device to generate a second test case, the second test case is used to test whether the second part of the code of the target module has a security vulnerability, and the first part of the code is not completely the same as the second part of the code; The receiving unit is also used to receive the second test case sent by the information security testing device, generate second status data, and when it is determined that the second part of the code has a security vulnerability based on the second status data, send feedback information to the information security testing device, and the feedback information is used to indicate that the target module has a security vulnerability.

7. The information security testing device for the vehicle-mounted system according to claim 6, It is characterized in that The determining unit is further configured to send the feedback information to the information security testing device if it is determined that the first portion of code has a security vulnerability.

8. The information security testing device for the vehicle-mounted system according to claim 6 or 7, It is characterized in that The information security testing device of the vehicle-mounted system further includes: a storage unit and a sending unit; The storage unit is configured to store the first state data and the first test case if it is determined that the first portion of code has a security vulnerability; The sending unit is used to send the first state data and the first test case to the information security testing device in response to a user's query operation on the target module.

9. An information security testing device for an in-vehicle system, It is characterized in that The information security testing device of the vehicle-mounted system includes: a processor and a memory; the memory is used to store computer program code, and the computer program code includes computer instructions; when the processor executes the computer instructions, the information security testing device of the vehicle-mounted system executes the information security testing method of the vehicle-mounted system as described in any one of claims 1 to 4, or executes the information security testing method of the vehicle-mounted system as described in claim 5.

10. A computer-readable storage medium, It is characterized in that It includes computer instructions. When the computer instructions are run on an information security testing device of a vehicle-mounted system, the information security testing device of the vehicle-mounted system executes the information security testing method of the vehicle-mounted system described in any one of claims 1 to 4, or executes the information security testing method of the vehicle-mounted system described in claim 5.

Citation Information

Patent Citations

  • Optimized test vector generation method based on genetic algorithm and variation analysis

    CN107590313A

  • Vulnerability detection method and system based on path tracing

    CN109063483A