Internet of vehicles threat situation assessment method and device, electronic equipment and storage medium
By subnetting and analyzing the data of the Internet of Vehicles (IoV), and using a graph neural network model to calculate the threat situation assessment value of the IoV, the problem of low accuracy in existing technologies is solved, and more accurate network attack risk assessment and real-time risk trend display are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING TOPSEC NETWORK SECURITY TECH
- Filing Date
- 2022-11-24
- Publication Date
- 2026-04-17
AI Technical Summary
Existing methods for assessing the threat landscape of connected vehicles are inaccurate and difficult to effectively assess the cyberattack risks of connected vehicles.
The vehicle network is divided into several subnets based on the communication relationship between the road test unit and the vehicle unit. Attack threat data, vehicle data and topology information of vehicle nodes in each subnet are obtained. The threat situation assessment value of each subnet is calculated using a graph neural network model, and the overall threat situation assessment value of the vehicle network is calculated based on the weight of the subnet.
It improves the accuracy of threat assessment for connected vehicles, more accurately reflects the overall network attack risk of connected vehicles, and provides real-time threat trend curves, making it easier for users to intuitively understand risk changes.
Smart Images

Figure CN115766262B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computers, and more specifically, to a method, apparatus, electronic device, and storage medium for assessing the threat situation of connected vehicles. Background Technology
[0002] With the implementation of new-generation information and communication technologies in the transportation sector, especially the accelerated application of vehicle-to-everything (V2X) technology, the degree of digital connection between vehicles, roads, people, and networks will become increasingly higher. Consequently, the security risks will also increase. Therefore, it is necessary to assess the threat landscape of V2X.
[0003] However, technicians have found that existing methods for assessing the threat situation in connected vehicles suffer from low accuracy. Summary of the Invention
[0004] The purpose of this application is to provide a method, apparatus, electronic device, and storage medium for assessing the threat situation of vehicle-to-everything (V2X) networks, so as to improve the accuracy of the threat situation assessment of V2X networks facing network attacks.
[0005] In a first aspect, the present invention provides a method for assessing the threat situation of the Internet of Vehicles (IoV), the method comprising:
[0006] Based on the communication relationship between the road test unit and the vehicle unit, the vehicle network is divided into several subnets, each of which includes several vehicle nodes.
[0007] Acquire attack threat data for each vehicle node within each subnet, vehicle data for each vehicle node, and topology information of the subnet;
[0008] Based on the attack threat data of each vehicle node and the vehicle data of each vehicle node, the threat situation assessment value of each subnet within the time window is calculated using the subnet topology information.
[0009] The threat situation assessment value of the vehicle network within the time window is calculated based on the threat situation assessment value of each subnet within the time window.
[0010] In the first aspect of this application, the vehicle network is divided into several subnets based on the communication relationship between the road test unit and the vehicle-mounted unit. Each subnet includes several vehicle nodes. By acquiring attack threat data, vehicle data, and subnet topology information for each vehicle node within each subnet, a threat situation assessment value for each subnet within a time window can be calculated. Finally, based on the threat situation assessment values of each subnet within the time window, the overall threat situation assessment value of the vehicle network within that time window can be calculated. Compared to existing technologies, since this application calculates the threat situation assessment value of the vehicle network using the threat situation assessment values of multiple subnets, it can obtain a more accurate threat situation assessment value for the vehicle network based on the specific threat situation assessment value of each subnet.
[0011] In an optional implementation, after calculating the threat situation assessment value of the vehicle network within the time window based on the threat situation assessment value of each subnet within the time window, the method further includes:
[0012] Based on the threat situation assessment values of the vehicle network within two or more time windows, a threat situation trend change curve is generated and displayed.
[0013] In the above optional implementation, based on the threat situation assessment values of the vehicle network within two or more time windows, a threat situation trend change curve can be generated. At the same time, by displaying the threat situation trend change curve, users can intuitively understand the changing trend of the threat situation.
[0014] In an optional implementation, the calculation of the threat situation assessment value of each subnet within a time window based on the attack threat data of each vehicle node, the vehicle data of each vehicle node, and the subnet topology information includes:
[0015] Based on the attack threat data of each vehicle node, determine the alarm event type of each vehicle node and the number of each alarm event type;
[0016] The number of each of the aforementioned alarm event types is normalized to obtain a normalized value;
[0017] Based on the normalized values and the preset threat level score, the threat situation assessment value for each vehicle node is calculated.
[0018] The importance score of each vehicle node is calculated based on the vehicle data of each vehicle node and the topology information of the subnet.
[0019] Based on the importance score of each vehicle node and the threat situation assessment value of each vehicle node, the threat situation assessment value of the subnet within the time window is calculated.
[0020] In the above optional implementation, based on the attack threat data of each vehicle node, the alarm event type and the quantity of each alarm event type of each vehicle node can be determined. Then, by normalizing the quantity of each alarm event type, a normalized value can be obtained. Based on the normalized value and a preset threat level score, the threat situation assessment value of each vehicle node can be calculated. Furthermore, based on the vehicle data of each vehicle node and the subnet topology information, the importance score of each vehicle node can be calculated. Finally, based on the importance score of each vehicle node and the threat situation assessment value of each vehicle node, the threat situation assessment value of the subnet within a time window can be calculated. Compared with the prior art, this optional implementation, when calculating the threat situation assessment value of the subnet, can determine the importance score of each vehicle node based on the subnet topology information and the vehicle data of each vehicle node. The importance score reflects the degree of influence of vehicle nodes on the subnet, and ultimately, based on the differences in the degree of influence of different vehicle nodes on the subnet, the accuracy of the subnet's threat situation assessment value is higher.
[0021] In an optional implementation, the calculation of the importance score for each vehicle node based on the vehicle data of each vehicle node and the topology information of the subnet includes:
[0022] Based on the vehicle data of each vehicle node, a node attribute embedding vector is generated for each vehicle node;
[0023] The node attribute embedding vector of each vehicle node and the topology information of the subnet are input into the graph neural network model so that the graph neural network model outputs the importance score of each vehicle node.
[0024] In the above optional implementation, based on the vehicle data of each vehicle node, a node attribute embedding vector of each vehicle node can be generated. Then, by inputting the node attribute embedding vector of each vehicle node and the topology information of the subnet into the graph neural network model, the graph neural network model can output the importance score of each vehicle node.
[0025] In an optional implementation, calculating the threat situation assessment value of the vehicle network within the time window based on the threat situation assessment value of each subnet within the time window includes:
[0026] Determine the weight of each of the subnets;
[0027] Based on the threat situation assessment value of each subnet within the time window and the weight of each subnet, the threat situation assessment value of the vehicle network within the time window is calculated.
[0028] In the above optional implementation, by determining the weight of each subnet, the threat situation assessment value of the vehicle network within the time window can be calculated based on the threat situation assessment value of each subnet within the time window and the weight of each subnet. This allows for a more accurate calculation of the threat situation assessment value of the vehicle network within the time window based on the importance of each subnet to the vehicle network.
[0029] In an optional implementation, the formula for calculating the threat situation assessment value of the vehicle network within the time window based on the threat situation assessment value of each subnet within the time window and the weight of each subnet is as follows:
[0030]
[0031] Among them, T 总 T represents the threat situation assessment value of the vehicle-to-everything (V2X) network within the time window. i This represents the threat situation assessment value of the subnet within the time window, where i represents the index of the subnet, and w... i This indicates the weight of the subnet.
[0032] In the above optional implementation, the threat situation assessment value of the Internet of Vehicles within the time window can be calculated using the above calculation formula.
[0033] In an optional implementation, the vehicle data of the vehicle node includes: vehicle model, configuration information, and driver information.
[0034] In the above optional implementation, since the vehicle data includes vehicle model, configuration information and driver information, the differences in vehicle model, configuration information and driver information of different vehicle nodes can be taken into account when calculating the importance score of vehicle nodes.
[0035] Secondly, the present invention provides a vehicle-to-everything (V2X) threat situation assessment device, the device comprising:
[0036] The grid partitioning module is used to partition the vehicle network based on the communication relationship between the roadside unit and the vehicle unit, resulting in several subnets, wherein each subnet includes several vehicle nodes;
[0037] The acquisition module is used to acquire attack threat data of each vehicle node in each subnet, vehicle data of each vehicle node, and topology information of the subnet;
[0038] The first calculation module is used to calculate the threat situation assessment value of each subnet within a time window based on the attack threat data of each vehicle node, the vehicle data of each vehicle node, and the topology information of the subnet.
[0039] The second calculation module is used to calculate the threat situation assessment value of the vehicle network within the time window based on the threat situation assessment value of each subnet within the time window.
[0040] The apparatus of the second aspect of this application, by executing a vehicle-to-everything (V2X) threat situation assessment method, can divide the V2X into several subnets based on the communication relationship between the road test unit and the vehicle unit. Each subnet includes several vehicle nodes. Furthermore, by acquiring attack threat data, vehicle data, and subnet topology information for each vehicle node within each subnet, the apparatus can calculate the threat situation assessment value of each subnet within a time window based on these data. Finally, based on the threat situation assessment values of each subnet within the time window, the apparatus can calculate the overall threat situation assessment value of the V2X within that time window. Compared to existing technologies, since this application calculates the V2X threat situation assessment value based on the threat situation assessment values of multiple subnets, it can obtain a more accurate V2X threat situation assessment value based on the specific threat situation assessment value of each subnet.
[0041] Thirdly, the present invention provides an electronic device, comprising:
[0042] Processor; and
[0043] The memory is configured to store machine-readable instructions that, when executed by the processor, perform the vehicle-to-everything (V2X) threat situation assessment method as described in any of the foregoing embodiments.
[0044] The electronic device of the third aspect of this application, by executing a vehicle-to-everything (V2X) threat situation assessment method, can divide the V2X into several subnets based on the communication relationship between the road test unit and the vehicle unit. Each subnet includes several vehicle nodes. Furthermore, by acquiring attack threat data, vehicle data, and subnet topology information for each vehicle node within each subnet, the electronic device can calculate the threat situation assessment value of each subnet within a time window based on these factors. Finally, based on the threat situation assessment values of each subnet within the time window, the overall threat situation assessment value of the V2X within the time window can be calculated. Compared to existing technologies, since this application calculates the V2X threat situation assessment value based on the threat situation assessment values of multiple subnets, it can obtain a more accurate V2X threat situation assessment value based on the specific threat situation assessment value of each subnet.
[0045] Fourthly, the present invention provides a storage medium storing a computer program, the computer program being executed by a processor as described in any of the foregoing embodiments of the vehicle network threat situation assessment method.
[0046] The storage medium of the fourth aspect of this application, by executing a vehicle-to-everything (V2X) threat situation assessment method, can divide the V2X into several subnets based on the communication relationship between the road test unit and the vehicle unit. Each subnet includes several vehicle nodes. Furthermore, by acquiring attack threat data, vehicle data, and subnet topology information for each vehicle node within each subnet, the application can calculate the threat situation assessment value of each subnet within a time window based on these data. Finally, based on the threat situation assessment value of each subnet within the time window, the overall threat situation assessment value of the V2X within the time window can be calculated. Compared to existing technologies, since this application calculates the V2X threat situation assessment value based on the threat situation assessment values of multiple subnets, it can obtain a more accurate V2X threat situation assessment value based on the specific threat situation assessment value of each subnet. Attached Figure Description
[0047] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0048] Figure 1 This is a flowchart illustrating a method for assessing the threat situation of the Internet of Vehicles disclosed in an embodiment of this application;
[0049] Figure 2 This is a schematic diagram of a vehicle network topology disclosed in an embodiment of this application;
[0050] Figure 3 This is a schematic diagram of the structure of a vehicle-to-everything (V2X) threat situation assessment device disclosed in an embodiment of this application;
[0051] Figure 4 This is a schematic diagram of the structure of an electronic device disclosed in an embodiment of this application. Detailed Implementation
[0052] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0053] Example 1
[0054] Please see Figure 1 , Figure 1 This is a flowchart illustrating a method for assessing the threat situation in the Internet of Vehicles (IoV) disclosed in an embodiment of this application. Figure 1 As shown, the method in this application embodiment includes the following steps:
[0055] 101. Based on the communication relationship between the road test unit and the vehicle unit, the vehicle network is divided into several subnets, each of which includes several vehicle nodes.
[0056] 102. Obtain attack threat data for each vehicle node within each subnet, vehicle data for each vehicle node, and subnet topology information;
[0057] 103. Based on the attack threat data of each vehicle node, the vehicle data of each vehicle node, and the subnet topology information, calculate the threat situation assessment value of each subnet within the time window.
[0058] 104. Based on the threat situation assessment value of each subnet within the time window, the threat situation assessment value of the vehicle network within the time window is calculated.
[0059] In this embodiment, the vehicle network is divided into several subnets based on the communication relationship between the road test unit and the vehicle-mounted unit. Each subnet includes several vehicle nodes. By acquiring the attack threat data, vehicle data, and subnet topology information of each vehicle node within each subnet, the threat situation assessment value of each subnet within a time window can be calculated. Finally, based on the threat situation assessment values of each subnet within the time window, the overall threat situation assessment value of the vehicle network within the time window can be calculated. Compared with existing technologies, since this application calculates the threat situation assessment value of the vehicle network through the threat situation assessment values of multiple subnets, it can obtain a more accurate threat situation assessment value of the vehicle network based on the specific threat situation assessment value of each subnet.
[0060] In this embodiment, for vehicle 101, communication between the vehicle and neighboring vehicles is achieved through a VANET (Vehicle Ad-hoc Network). This network structure has certain topological properties: the vehicle and its neighbors form a series of connections, and through connections with roadside unit nodes, they form a series of subnets. An attack threat within a subnet has lateral propagation; an attack will first spread within that subnet. Therefore, it is necessary to consider the threat situation information of each subnet by dividing it into subnets. Further, please refer to... Figure 2 , Figure 2 This is a schematic diagram of a vehicle network topology disclosed in an embodiment of this application. For example... Figure 2 As shown, the vehicle network can be divided into 3 subnets. Each subnet corresponds to a Road Side Unit (RSU). Multiple Onboard Units (OBUs) associated with a Road Side Unit constitute a subnet, and the vehicle where the OBU is located is a vehicle node in the subnet.
[0061] It should be noted that the vehicle network in this application refers to a network structure composed of multiple vehicle nodes.
[0062] In this embodiment of the application, for step 101, exemplarily, by dividing the vehicle network, several subnets can be obtained, wherein the set of several subnets can be represented as {g1, g2, g3, ..., g m} represents the network, and each subnet can include n vehicle nodes.
[0063] In this embodiment of the application, for step 102, the attack threat data of the vehicle node can be captured by the vehicle. For example, when the vehicle is under attack threat, it generates attack threat data and sends it to the server in the form of a log.
[0064] In this embodiment of the application, for step 102, the vehicle data of the vehicle node can be uploaded by the vehicle itself. Further, the vehicle data of the vehicle node includes: vehicle model, configuration information, and driver information. Since the vehicle data includes vehicle model, configuration information, and driver information, the differences in vehicle model, configuration information, and driver information among different vehicle nodes can be considered when calculating the importance score of the vehicle node.
[0065] It should be noted that vehicle data, in addition to vehicle model, configuration information, and driver information, may also include vehicle attributes such as the vehicle's age.
[0066] In this embodiment, the configuration information may further include information such as the vehicle's braking system. On the other hand, the driver information may include information such as the driver's years of driving experience.
[0067] In this embodiment, for step 102, the subnet's topology information is represented by a topology graph, where the communication relationships between vehicles are described by edges. For details on how the network structure is represented by a topology graph, please refer to existing technologies.
[0068] In an optional implementation, after calculating the threat situation assessment value of the vehicle network within the time window based on the threat situation assessment value of each subnet within the time window, the method of this application embodiment further includes the following steps:
[0069] Based on the threat situation assessment values of the Internet of Vehicles within two or more time windows, a threat situation trend change curve is generated and displayed.
[0070] In the above optional implementation, based on the threat situation assessment values of the Internet of Vehicles within two or more time windows, a threat situation trend change curve can be generated. At the same time, by displaying the threat situation trend change curve, users can intuitively understand the changing trend of the threat situation.
[0071] In the above optional implementation, since the vehicles are moving in real time, the threat situation assessment value of the vehicle nodes also changes in real time, and consequently the threat situation assessment value of the Internet of Vehicles also changes in real time. Therefore, it is necessary to reflect the real-time changes in the threat situation assessment value of the Internet of Vehicles through a threat situation trend change curve.
[0072] In an optional implementation, the step of calculating the threat situation assessment value of each subnet within a time window based on the attack threat data of each vehicle node, the vehicle data of each vehicle node, and the subnet topology information includes the following sub-steps:
[0073] Based on the attack threat data for each vehicle node, determine the alarm event type for each vehicle node and the number of each alarm event type;
[0074] The number of each alarm event type is normalized to obtain a normalized value;
[0075] Based on normalized values and preset threat level scores, the threat situation assessment value for each vehicle node is calculated.
[0076] The importance score of each vehicle node is calculated based on the vehicle data and subnet topology information of each vehicle node.
[0077] Based on the importance score and threat situation assessment value of each vehicle node, the threat situation assessment value of the subnet within the time window is calculated.
[0078] In the above optional implementation, based on the attack threat data of each vehicle node, the alarm event type and the quantity of each alarm event type for each vehicle node can be determined. Then, by normalizing the quantity of each alarm event type, a normalized value can be obtained. Based on the normalized value and a preset threat level score, the threat situation assessment value of each vehicle node can be calculated. Furthermore, based on the vehicle data and subnet topology information of each vehicle node, the importance score of each vehicle node can be calculated. Finally, based on the importance score and the threat situation assessment value of each vehicle node, the threat situation assessment value of the subnet within the time window can be calculated. Compared with the prior art, this optional implementation, when calculating the threat situation assessment value of the subnet, can determine the importance score of each vehicle node based on the subnet topology information and the vehicle data of each vehicle node. The importance score reflects the degree of influence of each vehicle node on the subnet, and ultimately, based on the differences in the degree of influence of different vehicle nodes on the subnet, the accuracy of the subnet threat situation assessment value is higher.
[0079] In the above optional implementation, specifically, based on the importance score of each vehicle node and the threat situation assessment value of each vehicle node, the calculation formula corresponding to the threat situation assessment value of the subnet within the time window is as follows:
[0080]
[0081] Among them, T g s represents a subnet i t represents the importance score of the vehicle node. i This represents the threat situation assessment value of the vehicle node.
[0082] In an optional implementation, the importance score of each vehicle node is calculated based on the vehicle data and subnet topology information of each vehicle node, including:
[0083] Based on the vehicle data of each vehicle node, generate the node attribute embedding vector for each vehicle node;
[0084] The node attribute embedding vector of each vehicle node and the subnet topology information are input into the graph neural network model so that the graph neural network model outputs the importance score of each vehicle node.
[0085] In the above optional implementation, based on the vehicle data of each vehicle node, a node attribute embedding vector for each vehicle node can be generated. Then, by inputting the node attribute embedding vector of each vehicle node and the subnet topology information into the graph neural network model, the graph neural network model can output the importance score of each vehicle node.
[0086] In an optional implementation, the step of calculating the threat situation assessment value of the vehicle network within the time window based on the threat situation assessment value of each subnet within the time window includes the following sub-steps:
[0087] Determine the weight of each subnet;
[0088] Based on the threat situation assessment value of each subnet within the time window and the weight of each subnet, the threat situation assessment value of the vehicle-to-everything (V2X) network within the time window is calculated.
[0089] In the above optional implementation, by determining the weight of each subnet, the threat situation assessment value of the vehicle network within the time window can be calculated based on the threat situation assessment value of each subnet within the time window and the weight of each subnet. This allows for a more accurate calculation of the threat situation assessment value of the vehicle network within the time window based on the importance of each subnet to the vehicle network.
[0090] In an optional implementation, based on the threat situation assessment value of each subnet within the time window and the weight of each subnet, the calculation formula corresponding to the threat situation assessment value of the vehicle network within the time window is as follows:
[0091]
[0092] Among them, T 总 T represents the threat situation assessment value of the Internet of Vehicles within a time window. i This represents the threat situation assessment value of a subnet within a time window, where i represents the subnet's index, and w... i This indicates the weight of the subnet.
[0093] In the above optional implementation, the threat situation assessment value of the Internet of Vehicles within the time window can be calculated using the above calculation formula.
[0094] Example 2
[0095] Please see Figure 3 , Figure 3 This is a schematic diagram of the structure of a vehicle-to-everything (V2X) threat situation assessment device disclosed in an embodiment of this application, as shown below. Figure 3 As shown, the apparatus in this embodiment includes the following functional modules:
[0096] The mesh partitioning module 201 is used to partition the vehicle network based on the communication relationship between the roadside unit and the vehicle unit, resulting in several subnets, each subnet including several vehicle nodes.
[0097] The acquisition module 202 is used to acquire attack threat data for each vehicle node in each subnet, vehicle data for each vehicle node, and subnet topology information.
[0098] The first calculation module 203 is used to calculate the threat situation assessment value of each subnet within the time window based on the attack threat data of each vehicle node, the vehicle data of each vehicle node, and the subnet topology information.
[0099] The second calculation module 204 is used to calculate the threat situation assessment value of the vehicle network within the time window based on the threat situation assessment value of each subnet within the time window.
[0100] The apparatus in this embodiment executes a vehicle-to-everything (V2X) threat situation assessment method, thereby dividing the V2X into several subnets based on the communication relationship between the road test unit and the vehicle unit. Each subnet includes several vehicle nodes. Furthermore, by acquiring attack threat data for each vehicle node within each subnet, vehicle data for each vehicle node, and the subnet's topology information, the apparatus calculates the threat situation assessment value for each subnet within a time window based on these data. Finally, based on the threat situation assessment values of each subnet within the time window, the overall threat situation assessment value of the V2X within the time window is calculated. Compared to existing technologies, since this application calculates the V2X threat situation assessment value using the threat situation assessment values of multiple subnets, it can obtain a more accurate V2X threat situation assessment value based on the specific threat situation assessment value of each subnet.
[0101] It should be noted that for other detailed descriptions of the apparatus in the embodiments of this application, please refer to the relevant description in Embodiment 1 of this application, which will not be repeated in the embodiments of this application.
[0102] Example 3
[0103] Please see Figure 4 , Figure 4 This is a schematic diagram of the structure of an electronic device disclosed in an embodiment of this application, such as... Figure 4 As shown, the electronic device in this application embodiment includes:
[0104] Processor 301; and
[0105] The memory 302 is configured to store machine-readable instructions, which, when executed by the processor 301, perform a vehicle-to-everything (V2X) threat situation assessment method as described in any of the foregoing embodiments.
[0106] The electronic device in this application embodiment executes a vehicle-to-everything (V2X) threat situation assessment method, thereby dividing the V2X into several subnets based on the communication relationship between the road test unit and the vehicle unit. Each subnet includes several vehicle nodes. Furthermore, by acquiring attack threat data for each vehicle node within each subnet, vehicle data for each vehicle node, and the subnet's topology information, the device can calculate the threat situation assessment value for each subnet within a time window based on the attack threat data, vehicle data, and subnet topology information. Finally, based on the threat situation assessment values of each subnet within the time window, the overall threat situation assessment value of the V2X within the time window can be calculated. Compared to existing technologies, since this application calculates the V2X threat situation assessment value using the threat situation assessment values of multiple subnets, it can obtain a more accurate V2X threat situation assessment value based on the specific threat situation assessment value of each subnet.
[0107] Example 4
[0108] This application provides a storage medium storing a computer program, which is executed by a processor as a vehicle network threat situation assessment method according to any of the foregoing embodiments.
[0109] The storage medium in this embodiment executes a vehicle-to-everything (V2X) threat situation assessment method, thereby dividing the V2X into several subnets based on the communication relationship between the road test unit and the vehicle unit. Each subnet includes several vehicle nodes. Furthermore, by acquiring attack threat data for each vehicle node within each subnet, vehicle data for each vehicle node, and the subnet's topology information, the threat situation assessment value for each subnet within a time window can be calculated based on these data. Finally, based on the threat situation assessment values of each subnet within the time window, the overall threat situation assessment value of the V2X within the time window can be calculated. Compared to existing technologies, since this application calculates the V2X threat situation assessment value using the threat situation assessment values of multiple subnets, it can obtain a more accurate V2X threat situation assessment value based on the specific threat situation assessment value of each subnet.
[0110] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and there may be other division methods in actual implementation. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the coupling or direct coupling or communication connection shown or discussed may be through some communication interface; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0111] Furthermore, the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0112] Furthermore, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0113] It should be noted that if a function is implemented as a software module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0114] In this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, without necessarily requiring or implying any such actual relationship or order between these entities or operations.
[0115] The above are merely embodiments of this application and are not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A method for assessing the threat situation of the Internet of Vehicles (IoV), characterized in that, The method includes: Based on the communication relationship between the road test unit and the vehicle unit, the vehicle network is divided into several subnets. Each subnet includes several vehicle nodes. Each subnet corresponds to one road test unit. Multiple vehicle units associated with a road test unit constitute a subnet, and the vehicle where the vehicle unit is located is a vehicle node in the subnet. Acquire attack threat data for each vehicle node within each subnet, vehicle data for each vehicle node, and topology information of the subnet; Based on the attack threat data of each vehicle node, the alarm event type and the number of each alarm event type of each vehicle node are determined, and the number of each alarm event type is normalized to obtain a normalized value. Based on the normalized values and the preset threat level score, the threat situation assessment value of each vehicle node is calculated, and based on the vehicle data of each vehicle node, the node attribute embedding vector of each vehicle node is generated. The node attribute embedding vector of each vehicle node and the topology information of the subnet are input into the graph neural network model so that the graph neural network model outputs the importance score of each vehicle node; Based on the importance score of each vehicle node and the threat situation assessment value of each vehicle node, the threat situation assessment value of the subnet within the time window is calculated. The threat situation assessment value of the vehicle network within the time window is calculated based on the threat situation assessment value of each subnet within the time window.
2. The method of claim 1, wherein, After calculating the threat situation assessment value of the vehicle network within the time window based on the threat situation assessment value of each subnet within the time window, the method further includes: Based on the threat situation assessment values of the vehicle network within two or more time windows, a threat situation trend change curve is generated and displayed.
3. The method of claim 1, wherein, The calculation of the threat situation assessment value of the vehicle network within the time window based on the threat situation assessment value of each subnet within the time window includes: Determine the weight of each of the subnets; Based on the threat situation assessment value of each subnet within the time window and the weight of each subnet, the threat situation assessment value of the vehicle network within the time window is calculated.
4. The method of claim 3, wherein, The formula for calculating the threat situation assessment value of the vehicle network within the time window, based on the threat situation assessment value of each subnet within the time window and the weight of each subnet, is as follows: wherein, represents a threat posture evaluation value of the vehicle network in the time window, represents a threat posture evaluation value of the subnet in the time window, represents a subscript of the subnet, represents a weight of the subnet.
5. The method as described in claim 1, characterized in that, The vehicle data of the vehicle node includes: vehicle model, configuration information, and driver information.
6. A vehicle-to-everything (V2X) threat situation assessment device, characterized in that, The device includes: The grid partitioning module is used to partition the vehicle network based on the communication relationship between the road test unit and the vehicle unit, resulting in several subnets. Each subnet includes several vehicle nodes. Each subnet corresponds to one road test unit, and multiple vehicle units associated with one road test unit constitute a subnet. The vehicle in which the vehicle unit is located is a vehicle node in the subnet. The acquisition module is used to acquire attack threat data of each vehicle node in each subnet, vehicle data of each vehicle node, and topology information of the subnet; The first calculation module is used to determine the alarm event type and the number of each alarm event type for each vehicle node based on the attack threat data of each vehicle node; normalize the number of each alarm event type to obtain a normalized value; calculate the threat situation assessment value of each vehicle node based on the normalized value and a preset threat level score; generate a node attribute embedding vector for each vehicle node based on the vehicle data of each vehicle node; input the node attribute embedding vector of each vehicle node and the topology information of the subnet into a graph neural network model so that the graph neural network model outputs the importance score of each vehicle node; and calculate the threat situation assessment value of the subnet within a time window based on the importance score of each vehicle node and the threat situation assessment value of each vehicle node. The second calculation module is used to calculate the threat situation assessment value of the vehicle network within the time window based on the threat situation assessment value of each subnet within the time window.
7. An electronic device, characterized in that, include: processor; as well as The memory is configured to store machine-readable instructions that, when executed by the processor, perform the vehicle-to-everything (V2X) threat situation assessment method as described in any one of claims 1-5.
8. A storage medium, characterized in that, The storage medium stores a computer program, which is executed by a processor using the vehicle network threat situation assessment method as described in any one of claims 1-5.
Citation Information
Patent Citations
Internet of Vehicles data situation awareness method based on network security
CN110324336A