Intrusion Behavior Analysis Method and Device Based on Intelligent Vehicle Sensors
By classifying and extracting smart car sensor signals, using time series and discrete event signal abnormal model combined with fuzzy expert system, the problem of intrusion behavior detection in automotive electronic and electrical networks is solved, and efficient intrusion behavior analysis is achieved.
Patent Information
- Application Number
- CN202211237965.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-08
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-10-08
AI Technical Summary
The prior art is difficult to effectively detect intrusion behavior in automotive electronic and electrical networks, especially due to the heterogeneity of vehicle ECUs and differences in network protocols, traditional computer network intrusion detection methods cannot be directly applied, and sensor signals are difficult to effectively collect and analyze.
By obtaining intelligent car sensor signals, classifying and inputting them into the time series conversion module and the discrete event signal conversion module, the time series signal abnormal model and the discrete event signal abnormal model are used for training, and the decision-making and reasoning and judgment are combined with the automobile safety fuzzy expert system to identify intrusion behavior.
It realizes effective analysis of smart car sensor signals, can quickly discover potential attack behaviors, and improves the accuracy and efficiency of intrusion detection.
Smart Images

Figure CN115496109B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing, and in particular, to a method and device for analyzing intrusion behavior based on intelligent vehicle sensors. Background Art
[0002] Currently, for computer networks, intrusion behavior analysis is to establish an abstract model for the computer network itself, including host configuration, network connection, trust relationship between hosts, etc.
[0003] The general process of intrusion behavior analysis is to decompose the target entity, determine the threats to assets from perspectives such as systems, application software, service ports, or application program interface (API) calls, then perform threat analysis based on the network connection data stream between assets, and finally give the analysis method and mitigation measures on the attack path.
[0004] In the automotive electronic and electrical network, different from the computer network environment, a vehicle is composed of many electronic control units (ECUs) and in-vehicle protocols. Due to limited resources and network protocols, the above-mentioned intrusion detection methods and programs for computer networks cannot be directly applied to vehicle intrusion analysis. In addition, the attacker will inevitably leave clues during the process of intruding into the vehicle, and these clues are difficult to directly collect and capture in the ECUs with limited resources, which also brings difficulties to intrusion analysis.
[0005] Vehicle sensors are input devices of the automotive ECU system. They convert various operating conditions of the vehicle during operation, such as vehicle speed, temperature of various media, engine operating conditions, etc., into electrical signals and transmit them to the ECU so that the engine can be in the best working state. The sensors sense the surrounding environment and make corresponding judgments according to the set correct program. If one of the sensors fails or shows an abnormal state, the corresponding device will not work properly.
[0006] In the prior art, the current analysis techniques for intrusion behavior mainly include host intrusion detection analysis and traffic intrusion detection analysis.
[0007] Host intrusion detection analysis mainly installs probes (agents) in the protected system. It requires to be tightly bundled with the operating system kernel and services, and monitors various system events, such as central processing unit (CPU) usage, calls to the kernel or API, calls to specific system files and executable files, etc., to realize the modeling of host behavior.
[0008] Traffic intrusion detection and analysis mainly collect traffic data through physical concatenation, logical concatenation, bypass mirroring, etc., and comprehensively monitor different statistical feature quantities in network traffic, including traffic bandwidth, Internet Protocol (IP) addresses, etc. to achieve network anomaly detection.
[0009] The disadvantages of the prior art are as follows:
[0010] Host-based intrusion detection needs to deploy probes into various ECUs of the vehicle to complete. For some ECUs without an operating system, it is difficult to directly apply.
[0011] The network protocols in automotive electronics and electrical appliances are different from traditional computer network protocols. Due to the millisecond-level communication requirements between ECUs, it becomes unrealistic to deploy technologies such as physical concatenation and logical concatenation.
[0012] In the traffic of in-vehicle networks, many are Controller Area Network (CAN) network protocols. The existing intrusion detection and analysis technologies based on Transmission Control Protocol (TCP) / IP traffic are not applicable, and a new analysis method is needed. Summary of the Invention
[0013] The purpose of the embodiments of the present invention is to provide an intrusion behavior analysis method and device based on intelligent vehicle sensors to solve the disadvantages in the prior art.
[0014] In a first aspect, the present invention provides an intrusion behavior analysis method based on intelligent vehicle sensors, and the method includes:
[0015] Obtain sensor signals of the intelligent vehicle;
[0016] According to different attack surfaces, classify the sensor signals according to the attack path to obtain combined signals;
[0017] Input the combined signals into a time series conversion module and a discrete event signal conversion module respectively to obtain first feature data;
[0018] Input the first feature data into a time series signal anomaly model to be trained and a discrete event signal anomaly model to be trained, train the time series signal anomaly model to be trained to establish a time series signal anomaly model, and train the discrete event signal anomaly model to be trained to establish a discrete event signal anomaly model;
[0019] Input second feature data into the time series signal anomaly model and the discrete event signal anomaly model to obtain whether the intelligent vehicle is abnormal and output the specific anomaly;
[0020] Feed the specific abnormal input into a preset automotive safety fuzzy expert system for decision-making, reasoning, and judgment to output the attack type of intrusion detection.
[0021] In a possible implementation, the obtaining of the sensor signals of the intelligent vehicle specifically includes:
[0022] Obtain multiple sensor signals of a single vehicle; or,
[0023] Obtain a single sensor signal of multiple vehicles; the single sensor signal is the signal of a specific sensor.
[0024] In a possible implementation, the attack surface includes the cloud side, the communication pipeline side, and the vehicle side. The classifying of the sensor signals according to the attack path for different attack surfaces to obtain combined signals specifically includes:
[0025] According to the attack path, combine the sensor signals of the cloud side, the communication pipeline side, the vehicle side, and the user equipment side to obtain combined signals.
[0026] In a possible implementation, the feeding of the combined signals into the time series conversion module and the discrete event signal conversion module respectively to obtain first feature data specifically includes:
[0027] After performing data preprocessing on the combined signals, obtain the preprocessed combined signals;
[0028] Feed the preprocessed combined signals into the time series conversion module to convert the preprocessed combined signals from the observation sequence to the time series by using time series functions and extract first feature data;
[0029] Feed the preprocessed combined signals into the discrete event signal conversion module to encode the preprocessed combined signals from the observed discrete variables into encoded data and extract first feature data from the encoded data.
[0030] In a possible implementation, before feeding the second feature data into the time series signal anomaly model and the discrete event signal anomaly model, the method further includes:
[0031] Obtain the current sensor signals of the intelligent vehicle;
[0032] According to different attack surfaces, classify the current sensor signals according to the attack path to obtain the current combined signals;
[0033] Feed the current combined signals into the time series conversion module and the discrete event signal conversion module respectively to obtain second feature data.
[0034] In a possible implementation manner, the input of the feature data into the fuzzy expert system for decision-making, reasoning and judgment to output the attack type of intrusion detection specifically includes:
[0035] Matching the feature data with the preset knowledge rules of the automotive attack field in the fuzzy expert system; the knowledge rules of the automotive attack field have attack types;
[0036] Determine the attack type matched by the feature data as the target attack type.
[0037] In a second aspect, the present invention provides an intrusion behavior analysis device based on an intelligent vehicle sensor, and the device includes:
[0038] A signal acquisition module, which is used to acquire the sensor signals of the intelligent vehicle;
[0039] A combined signal generation module, which is used to classify the sensor signals according to the attack path according to different attack surfaces to obtain combined signals;
[0040] A feature data generation module, which is used to input the combined signals into a time series conversion module and a discrete event signal conversion module respectively to obtain first feature data;
[0041] A model establishment module, which is used to input the first feature data into a time series signal anomaly model to be trained and a discrete event signal anomaly model to be trained, train the time series signal anomaly model to be trained to establish a time series signal anomaly model, and train the discrete event signal anomaly model to be trained to establish a discrete event signal anomaly model;
[0042] An anomaly output module, which is used to input second feature data into the time series signal anomaly model and the discrete event signal anomaly model to obtain whether the intelligent vehicle is abnormal and output specific anomalies;
[0043] An attack type output module, which is used to input the specific anomaly into a preset automotive safety fuzzy expert system for decision-making, reasoning and judgment to output the attack type of intrusion detection.
[0044] In a third aspect, the present invention provides a computer server, including: a memory, a processor and a transceiver;
[0045] The processor is used to be coupled with the memory, read and execute the instructions in the memory to implement the intrusion behavior analysis method based on the intelligent vehicle sensor described in the first aspect;
[0046] The transceiver is coupled to the processor, and the processor controls the transceiver to send and receive messages.
[0047] In a fourth aspect, the present invention provides a chip system, including a processor, the processor is coupled to a memory, and the memory stores program instructions. When the program instructions stored in the memory are executed by the processor, the intrusion behavior analysis method based on intelligent vehicle sensors according to any one of the first aspects is implemented.
[0048] In a fifth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and the computer program is executed by a processor to perform the intrusion behavior analysis method based on intelligent vehicle sensors according to any one of the first aspects.
[0049] By applying the intrusion behavior analysis method based on intelligent vehicle sensors provided by the present invention, sensor signals are combined to obtain combined signals, and the combined signals are input into a time series conversion module and a discrete event signal conversion module to obtain feature data. The feature data is used to train a time series signal anomaly model and a discrete event signal anomaly model, and the current feature data is input into the trained time series signal anomaly model and discrete event signal anomaly model to obtain specific anomalies. The specific anomalies are subjected to decision-making reasoning through an automotive safety fuzzy expert system to determine the attack type, so that possible attack behaviors can be quickly discovered. Description of the Drawings
[0050] Figure 1 It is one of the schematic flowcharts of the intrusion behavior analysis method based on intelligent vehicle sensors provided in Embodiment 1 of the present invention;
[0051] Figure 2 It is a schematic diagram of a sensor signal and a signal connector provided in Embodiment 1 of the present invention;
[0052] Figure 3 It is a schematic diagram of signal classification provided in Embodiment 1 of the present invention;
[0053] Figure 4 It is a schematic diagram of signal combination provided in Embodiment 1 of the present invention;
[0054] Figure 5 It is a schematic diagram of a time series signal anomaly model provided in Embodiment 1 of the present invention;
[0055] Figure 6 It is a schematic diagram of a discrete event signal anomaly model provided in Embodiment 1 of the present invention;
[0056] Figure 7Schematic diagram II of the intrusion behavior analysis method based on intelligent vehicle sensors provided in Embodiment 1 of the present invention;
[0057] Figure 8 Schematic diagram of the structure of the intrusion behavior analysis device based on intelligent vehicle sensors provided in Embodiment 2 of the present invention;
[0058] Figure 9 Schematic diagram of the structure of the computer server provided in Embodiment 3 of the present invention;
[0059] Figure 10 Schematic diagram of the structure of the chip system provided in Embodiment 4 of the present invention;
[0060] Figure 11 Schematic diagram of the structure of the computer-readable storage medium provided in Embodiment 5 of the present invention. Detailed implementation manners
[0061] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention, rather than limiting the invention. Additionally, it should be noted that for ease of description, only parts related to the relevant invention are shown in the drawings.
[0062] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.
[0063] Embodiment 1
[0064] Embodiment 1 of the present invention provides an intrusion behavior analysis method based on intelligent vehicle sensors. This method is applied to scenarios for abnormal analysis of sensor signals, such as Figure 1 As shown, the present application includes the following steps:
[0065] Step 110, obtain the sensor signals of the intelligent vehicle;
[0066] Specifically, a large number of sensor signals are generated during the stationary or driving process of a vehicle, including physical sensors, such as physical sensor signals generated by environmental sensors, audio sensors, optical sensors, and imaging sensors, and ECU actuators, intelligent functional devices, such as middleware software sensor signals generated by Over-the-Air Technology (OTA), digital keys, and services. Physical sensor signals include, but are not limited to, temperature signals, tire pressure signals, speed signals, mileage signals, Global Positioning System (GPS) signals, voltage signals, current signals, charging gun signals. Middleware software sensor signals include, but are not limited to, OTA periodic request signals, traffic signals for external vehicle communication, traffic signals for in-vehicle communication, and user click screen signals.
[0067] Since the above-mentioned sensor signals are distributed among various services in the intelligent vehicle cloud and have different heterogeneous data formats, various sensor signal connectors are required when obtaining multiple sensor signals. See Figure 2 , for example, message middleware connectors such as kafka, Pulsar, Internet of Things protocols such as Message Queuing Telemetry Transport (MQTT), The Constrained Application Protocol (CoAP), and Robot Operating System (ROS) messages for autonomous driving systems can be used for connection.
[0068] Step 120, classify the sensor signals according to the attack path based on different attack surfaces to obtain combined signals;
[0069] Specifically, after obtaining the physical sensor signals and middleware software sensor signals from the sensor connector, it is necessary to classify these signals from the perspective of information security. This application classifies according to the attacker's attack surface and attack path for the vehicle. It is decomposed according to the vehicle networking architecture of the cloud, communication pipeline end, and vehicle end side on the attack surface. The cloud mainly includes signals of services such as OTA, digital key services, and remote control. The communication pipeline end mainly includes communication signals of these services. The vehicle end side includes user operation instruction sensing signals of the mobile device end of the mobile phone, vehicle condition sensing signals, and ECU controller execution operation instructions, as Figure 3 shown.
[0070] Subsequently, the sensor signals generated by these attack surfaces will form new combined signals according to the attack path, as Figure 4As shown, for example, the above vehicle condition sensing signals and the controller execution operation instructions are combined into associated signals, including the accelerator pedal and speed, and the OTA and digital key service signals are combined into a key sharing signal, including sharing actions and key distribution. Among them, the attack path refers to the node path for cracking and analyzing the target system. For example, for the steering wheel control target of a vehicle, the following node paths may exist. First, invade the vehicle management platform from the cloud, then invade a certain vehicle through this platform, then use the vulnerability to obtain the high-level permission of the in-vehicle controller, and finally use this permission to send CAN instructions for controlling the steering wheel. In this process, each node can be simply regarded as a path point of the entire attack.
[0071] Step 130: Input the combined signals into the time series conversion module and the discrete event signal conversion module respectively to obtain first feature data.
[0072] Among them, step 130 includes:
[0073] After preprocessing the combined signals, obtain the preprocessed combined signals; input the preprocessed combined signals into the time series conversion module to convert the preprocessed combined signals from the observation sequence to the time series using the time series function and extract the first feature data; input the preprocessed combined signals into the discrete event signal conversion module to encode the preprocessed combined signals from the observed discrete variables into encoded data and extract the first feature data from the encoded data.
[0074] Specifically, a large number of time series sensor signals are generated in the vehicle, such as the current and voltage signals in the T-BOX. As the vehicle turns off, starts, and accelerates, the current and voltage values will show certain characteristics over time. Therefore, when the vehicle is attacked in the off state or when a Trojan program has been implanted and is active, the time-frequency characteristics of the current can reflect this attack action, and the resulting combined signals can also reflect this attack action.
[0075] See Figure 5 , after preprocessing the combined signals, input them into the time series conversion module for time series conversion, then perform feature selection, and perform anomaly classification through the anomaly signal detection model. Here, the anomaly signal detection model can be regarded as a time series signal anomaly model.
[0076] Among them, data preprocessing can be screening valid signals, eliminating dirty data, and converting data types. Time series conversion can be converting the combined signal from the observation sequence to the time series using time series functions, including establishing a new period, regular measurement, etc. Specifically, the combined signal constitutes the observation sequence. In the observation sequence, the observation time is not necessarily fixed. For example, an observation data is obtained every 2 minutes, while the time series requires one data per minute. Then, interpolation processing is performed on the observation sequence to convert the observation sequence into a time series. The first feature data is extracted from the time series, which can be feature selection, including selecting aggregated features, historical features, trend features, window features, autocorrelation features, etc., so as to obtain the first feature data.
[0077] See Figure 6 , after preprocessing the combined signal, input it into the discrete event signal conversion module, and the discrete event signal conversion module performs feature selection to obtain the first feature data.
[0078] Among them, data preprocessing can be screening valid signals, eliminating dirty data, and converting data types from the combined signal to obtain the preprocessed combined signal. The discrete signal conversion module encodes the preprocessed combined signal. The preprocessed combined signal includes discrete variables, and numerical encoding is performed on the discrete variables, such as ordinal encoding (OrdinalEncoder), one-hot encoding (One Hot Encoder), and hashing encoding (Hashing Encoder), etc. After encoding, feature selection can be performed. Here, feature selection can be performed using mutual information, maximum information coefficient, feature crossing, etc., so as to obtain the first feature data.
[0079] Step 140, input the first feature data into the time series signal anomaly model and the discrete event signal anomaly model to be trained, train the time series signal anomaly model to be trained to establish a time series signal anomaly model, and train the discrete event signal anomaly model to be trained to establish a discrete event signal anomaly model.
[0080] Specifically, in this application, the time series signals generated in the vehicle form a combined signal. After passing through step 130, the combined signal obtains the first feature data. This application uses, including but not limited to, any one of the autoregressive moving average model (ARMA), the trend and seasonal model (TBATS), the autoregressive integrated moving average model (ARIMA), the artificial neural network (ANN) model, and the long short-term memory (LSTM) model based on vehicle historical data and external human manipulation variables as the time series signal anomaly model to be trained, and trains these time series signal anomaly models to obtain the trained time series signal anomaly model. Subsequently, the trained time series signal anomaly model is used to detect anomalies in the vehicle when it is under attack.
[0081] Among the sensor signals of intelligent vehicles, discrete events are included. Discrete events can be internal message events or external operation events. External operation events refer to events transmitted between the system and its participants. For example, the pressing of a button on a mobile device and an interruption from stepping on the accelerator pedal sensor are both external events. Internal events are events transmitted between internal objects of the system. For example, the signal authentication failure of secure onboard communication (secoc) between ECU controllers is an internal event.
[0082] When a button is pressed on a mobile device, a click sequence is generated. For the mobile click sequence, these click sequences are composed of multiple symbols. A symbol can be regarded as an instruction. The "symbols" in these click sequences correspond to actions such as unlocking the vehicle, locking the vehicle, or turning on the air conditioner. Thus, these actions form a combined signal. After processing these combined signals through step 130, the first feature data is obtained. The first feature data is used to train the discrete event signal anomaly model to detect anomalies in these click sequences through the trained discrete event signal anomaly model, and to detect corresponding irregular or unauthorized user behaviors. Among them, the hidden Markov model (HMM) can be used as the discrete event signal anomaly model, and then the combined signal is input into this model to detect anomalies.
[0083] Step 150: Input the second feature data into the time series signal anomaly model and the discrete event signal anomaly model to obtain whether the intelligent vehicle is abnormal, and output the specific anomaly.
[0084] Specifically, the second feature data needs to be obtained before step 150. The difference between the second feature data and the first feature data is that the first feature data is for model training to obtain the two models in step 140, while the second feature data can be regarded as the current feature data and can be directly input into the trained models to determine whether there is an anomaly. The following describes how to obtain the second feature data before step 150:
[0085] Obtain the current sensor signals of the intelligent vehicle; classify the current sensor signals according to the attack path for different attack surfaces to obtain the current combined signals; input the current combined signals into the time series conversion module and the discrete event signal conversion module respectively to obtain the second feature data.
[0086] Among them, the specific process of obtaining the second feature data here is the same as the specific process of obtaining the first feature data, which will not be elaborated here.
[0087] Among them, the specific anomaly here can be, for example, reporting that a certain controller network connection of the intelligent vehicle is abnormal. Subsequently, through step 160, this kind of anomaly will be specifically determined to determine the attack type.
[0088] Step 160: Input the specific anomaly into a preset automotive security fuzzy expert system for decision-making, reasoning, and judgment to output the attack type of intrusion detection.
[0089] Among them, the automotive security fuzzy expert system includes an automotive attack knowledge base.
[0090] Specifically, the attack type mapping of the classified anomaly is carried out in the way of vehicle attack threat surface and attack path. This application classifies the attack types of the target intelligent vehicle or controller detected by the automotive security fuzzy expert system into 10 types, namely zombie vehicle, botnet vehicle, zombie controller, botnet controller, Trojan vehicle, Trojan controller, zombie vehicle network, in-vehicle malicious device, or ECU, in-vehicle malicious AP, and in-vehicle malicious application. After passing the specific anomaly through this automotive security fuzzy expert system, the result classification will be given. For example, when it is found through a certain model that a vehicle has been in the ignition state for a long time but its position remains unchanged, this abnormal vehicle can be found through the model, and thus this anomaly is attributed to the zombie vehicle, that is, the attack type is zombie vehicle. When a certain controller network connection of the intelligent vehicle is abnormal, the attack type can be determined as zombie vehicle network through detection.
[0091] See Figure 7, in this application, the second feature data extracted from the combined signals in the intelligent vehicle is input into the time series signal anomaly model and the discrete event signal anomaly model to determine specific anomalies, and then the specific anomalies are input into the fuzzy expert system for decision-level judgment; when the expert system reasons, it retrieves automotive attack domain knowledge rules and parameters from the knowledge base and the database, such as ATT&CK, Kill chain, etc., and matches them with the specific anomalies; when a specific anomaly here matches a certain attack type in the automotive attack domain knowledge base, the matched one is determined as the target attack type. Finally, the decision analysis system outputs the attack type classification of intrusion detection.
[0092] Furthermore, the sensor signals in this application can be multi-dimensional signals of a single vehicle and single signals of multiple vehicles, and longitudinal and transverse modeling can be performed based on this to improve the accuracy and generalization ability of the model. Among them, longitudinal refers to the longitudinal dependence of the signal context in the combined signal. For example, the output of one signal is the input of another signal. Transverse refers to the correlation relationship between signals in the combined signal. For example, the occurrence of one signal will cause a change in another signal. Therefore, the combined signal in this application takes into account the horizontal and vertical relationships between signals. Inputting this combined signal into the time series signal anomaly model or the discrete event signal anomaly model can greatly improve the generalization ability of the model.
[0093] Multi-sensor Fusion (MSF) is an information processing process that uses computer technology to automatically analyze and synthesize information and data from multiple sensors or multiple sources according to certain criteria to complete the required decision-making and estimation.
[0094] For example, the process of this application can be considered as multi-domain fusion signal classification based on the DS evidence theory, which is divided into three steps:
[0095] First, it is the target synthesis of automotive sensor signals, that is, signal combination, whose function is to synthesize the anomaly analysis results from a single vehicle sensor into a total combined signal;
[0096] Second, it is the intrusion inference of automotive anomaly results, whose function is to obtain the anomaly results of the sensor and make inferences, and expand the anomaly results of the sensor signal into target inferences;
[0097] Third, it is the update of automotive sensor signal values. Generally, there are random errors or errors caused by reporting in each physical or software sensing signal. Therefore, a set of continuous signals or statistical signals of multiple vehicles are fully considered in terms of time, which is more reliable than any single analysis.
[0098] By applying the intrusion behavior analysis method based on intelligent vehicle sensors provided by the present invention, the sensor signals will be combined to obtain combined signals, and the combined signals will be input into the time series conversion module and the discrete event signal conversion module to obtain feature data. Then, the feature data will be used to train the time series signal anomaly model and the discrete event signal anomaly model, and the current feature data will be input into the trained time series signal anomaly model and the discrete event signal anomaly model to obtain specific anomalies. Finally, the specific anomalies will be used for decision-making and reasoning by the vehicle safety fuzzy expert system to determine the attack type, so that possible attack behaviors can be quickly discovered.
[0099] Embodiment 2
[0100] Embodiment 2 of the present invention provides an intrusion behavior analysis device based on intelligent vehicle sensors, as Figure 7 shown. The device includes a signal acquisition module 810, a combined signal generation module 820, a feature data generation module 830, a model establishment module 840, an anomaly output module 850, and an attack type output module 860.
[0101] The signal acquisition module 810 is used to acquire the sensor signals of the intelligent vehicle;
[0102] The combined signal generation module 820 is used to classify the sensor signals according to different attack surfaces along the attack paths to obtain combined signals;
[0103] The feature data generation module 830 is used to input the combined signals into the time series conversion module and the discrete event signal conversion module respectively to obtain first feature data;
[0104] The model establishment module 840 is used to input the first feature data into the time series signal anomaly model to be trained and the discrete event signal anomaly model to be trained, train the time series signal anomaly model to be trained to establish a time series signal anomaly model, and train the discrete event signal anomaly model to be trained to establish a discrete event signal anomaly model;
[0105] The anomaly output module 850 is used to input the second feature data into the time series signal anomaly model and the discrete event signal anomaly model to obtain whether the intelligent vehicle is abnormal and output specific anomalies;
[0106] The attack type output module 860 is used to input the specific anomalies into a preset vehicle safety fuzzy expert system for decision-making, reasoning, and judgment to output the attack type of intrusion detection.
[0107] Further, the signal acquisition module 810 acquiring sensor signals specifically includes: acquiring multiple sensor signals of a single vehicle; or, acquiring a single sensor signal of multiple vehicles; the single sensor signal is the signal of a specific sensor.
[0108] Further, the attack surface includes the cloud side, the communication pipeline side, and the vehicle side. The combined signal generation module 820 classifies the sensor signals according to the attack path for different attack surfaces to obtain combined signals, specifically including: combining the sensor signals of the cloud side, the pipeline side, and the side of the vehicle according to the attack path.
[0109] Further, the feature data generation module 830 inputs the combined signals into the time series conversion module and the discrete event signal conversion module respectively to obtain first feature data, specifically including: performing data preprocessing on the combined signals to obtain the preprocessed combined signals; inputting the preprocessed combined signals into the time series conversion module to convert the preprocessed combined signals from the observation sequence to the time series by using the time series function and extracting the first feature data; inputting the preprocessed combined signals into the discrete event signal conversion module to encode the preprocessed combined signals from the observed discrete variables into encoded data and extracting the first feature data from the encoded data.
[0110] Further, before the anomaly output module inputs the second feature data into the time series signal anomaly model and the discrete event signal anomaly model, the signal acquisition module 810 is further configured to acquire the current sensor signals of the intelligent vehicle;
[0111] The combined signal generation module 820 is further configured to classify the current sensor signals according to the attack path for different attack surfaces to obtain the current combined signals;
[0112] The feature data generation module 830 is further configured to input the current combined signals into the time series conversion module and the discrete event signal conversion module respectively to obtain second feature data.
[0113] Further, the attack type output module 860 inputs the feature data into the fuzzy expert system for decision-making, reasoning, and judgment to output the attack type of intrusion detection, specifically including: matching the feature data with the preset automotive attack domain knowledge rules in the fuzzy expert system; the automotive attack domain knowledge rules have attack types; determining the attack type matched by the feature data as the target attack type.
[0114] The device provided in the second embodiment of the present invention can execute the method steps in the first method embodiment above, and its implementation principle and technical effects are similar, which will not be elaborated here.
[0115] It should be noted that it should be understood that the division of each module of the above device is only a division of logical functions. In actual implementation, it can be fully or partially integrated into a physical entity, or physically separated. And these modules can all be implemented in the form of software called by processing elements; they can also all be implemented in the form of hardware; or some modules can be implemented in the form of software called by processing elements, and some modules can be implemented in the form of hardware. For example, the determination module can be a separately established processing element, or can be integrated in a certain chip of the above device. In addition, it can also be stored in the memory of the above device in the form of program code, and the function of the above determination module can be called and executed by a certain processing element of the above device. The implementation of other modules is similar. In addition, all or part of these modules can be integrated together or can be independently implemented. The processing element described here can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above modules can be completed by the integrated logic circuit in the processor element or the instruction in the form of software.
[0116] For example, the above modules can be one or more integrated circuits configured to implement the above method, such as: one or more application specific integrated circuits (ASICs), or, one or more digital signal processors (DSPs), or, one or more field programmable gate arrays (FPGAs), etc. Again, when a certain module above is implemented in the form of a processing element scheduling program code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processors that can call program code. Again, these modules can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0117] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The above computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The above computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the above computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wirelessly (such as infrared, wireless, Bluetooth, microwave, etc.). The above computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The above available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.
[0118] Embodiment III
[0119] Embodiment III of the present invention provides a computer server, as Figure 9 shown, including: a memory, a processor, and a transceiver;
[0120] The processor is used to be coupled with the memory, read and execute the instructions in the memory, so as to implement any one of the intrusion behavior analysis methods based on intelligent vehicle sensors provided in the above Embodiment I;
[0121] The transceiver is coupled with the processor, and the processor controls the transceiver to perform message sending and receiving.
[0122] Embodiment IV
[0123] Embodiment IV of the present invention provides a chip system, as Figure 10 shown, including a processor, the processor is coupled with a memory, and the memory stores program instructions. When the program instructions stored in the memory are executed by the processor, any one of the intrusion behavior analysis methods based on intelligent vehicle sensors provided in Embodiment I is implemented.
[0124] Embodiment V
[0125] Embodiment V of the present invention provides a computer-readable storage medium, as Figure 11As shown, it includes programs or instructions that, when run on a computer, implement any one of the intrusion behavior analysis methods based on intelligent vehicle sensors provided in the first embodiment.
[0126] Those skilled in the art should also be able to further realize that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0127] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.
[0128] The above specific implementation manners have further detailed the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above are only the specific implementation manners of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. An intrusion behavior analysis method based on intelligent vehicle sensors, characterized in that , The method includes: Obtaining sensor signals of an intelligent vehicle; Classifying the sensor signals according to attack paths based on different attack surfaces to obtain combined signals; Inputting the combined signals into a time series conversion module and a discrete event signal conversion module respectively to obtain first feature data; Inputting the first feature data into a time series signal anomaly model to be trained and a discrete event signal anomaly model to be trained, training the time series signal anomaly model to be trained to establish a time series signal anomaly model, and training the discrete event signal anomaly model to be trained to establish a discrete event signal anomaly model; Inputting second feature data into the time series signal anomaly model and the discrete event signal anomaly model to obtain whether the intelligent vehicle is abnormal and output specific anomalies; Inputting the specific anomalies into a preset automotive safety fuzzy expert system for decision-making, reasoning, and judgment to output the attack types of intrusion detection; Wherein, before inputting the second feature data into the time series signal anomaly model and the discrete event signal anomaly model, the method further includes: Obtaining the current sensor signals of the intelligent vehicle; Classifying the current sensor signals according to attack paths based on different attack surfaces to obtain current combined signals; Inputting the current combined signals into the time series conversion module and the discrete event signal conversion module respectively to obtain second feature data.
2. The method according to claim 1, wherein The obtaining of the sensor signals of the intelligent vehicle specifically includes: Obtaining multiple sensor signals of a single vehicle; or, Obtaining a single sensor signal of multiple vehicles; the single sensor signal is the signal of a specific sensor.
3. The method according to claim 1, characterized in that, The attack surfaces include the cloud, the communication pipeline end, and the vehicle end side. The classifying of the sensor signals according to attack paths based on different attack surfaces to obtain combined signals specifically includes: Combining the sensor signals of the cloud, the communication pipeline end, the vehicle end side, and the user equipment side according to the attack path to obtain combined signals.
4. The method according to claim 1, wherein The inputting of the combined signals into the time series conversion module and the discrete event signal conversion module respectively to obtain first feature data specifically includes: Performing data preprocessing on the combined signals to obtain preprocessed combined signals; Inputting the preprocessed combined signals into the time series conversion module to convert the preprocessed combined signals from an observation sequence to a time series by using a time series function and extracting first feature data; Inputting the preprocessed combined signals into the discrete event signal conversion module to encode the preprocessed combined signals from observed discrete variables into encoded data and extracting first feature data from the encoded data.
5. The method according to claim 1, wherein The inputting of the feature data into the fuzzy expert system for decision-making, reasoning, and judgment to output the attack types of intrusion detection specifically includes: Matching the feature data with the preset automotive attack domain knowledge rules in the fuzzy expert system; the automotive attack domain knowledge rules have attack types; Determining the attack type matched by the feature data as the target attack type.
6. An intrusion behavior analysis device based on intelligent vehicle sensors, characterized in that , The device includes: A signal acquisition module, which is used to acquire sensor signals of an intelligent vehicle; A combined signal generation module, which is used to classify the sensor signals according to the attack path according to different attack surfaces to obtain combined signals; A feature data generation module, which is used to input the combined signals into a time series conversion module and a discrete event signal conversion module respectively to obtain first feature data; A model establishment module, which is used to input the first feature data into a time series signal anomaly model and a discrete event signal anomaly model to be trained, train the time series signal anomaly model to be trained to establish a time series signal anomaly model, and train the discrete event signal anomaly model to be trained to establish a discrete event signal anomaly model; An anomaly output module, which is used to input second feature data into the time series signal anomaly model and the discrete event signal anomaly model to obtain whether the intelligent vehicle is abnormal and output specific anomalies; An attack type output module, which is used to input the specific anomalies into a preset automotive safety fuzzy expert system for decision-making, reasoning and judgment to output the attack type of intrusion detection; Before the anomaly output module inputs the second feature data into the time series signal anomaly model and the discrete event signal anomaly model, the signal acquisition module is also used to acquire the current sensor signals of the intelligent vehicle; The combined signal generation module is also used to classify the current sensor signals according to the attack path according to different attack surfaces to obtain current combined signals; The feature data generation module is also used to input the current combined signals into the time series conversion module and the discrete event signal conversion module respectively to obtain second feature data.
7. A computer server, characterized in that, Comprising: A memory, a processor and a transceiver; The processor is used to be coupled with the memory, read and execute instructions in the memory to implement the intrusion behavior analysis method based on intelligent vehicle sensors according to any one of claims 1-5; The transceiver is coupled with the processor, and the processor controls the transceiver to perform message sending and receiving.
8. A chip system, characterized in that Comprising a processor, the coupling of the processor with a memory, the memory stores program instructions, and when the program instructions stored in the memory are executed by the processor, the intrusion behavior analysis method based on intelligent vehicle sensors according to any one of claims 1-5 is implemented.
9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and the computer program is executed by the processor to implement the intrusion behavior analysis method based on intelligent vehicle sensors according to any one of claims 1-5.
Citation Information
Patent Citations
Dual-mode intrusion detection device based on integrated machine learning algorithm
CN110213287A
Multidirectional security intrusion detection method and system based on FCNN
CN112491854A