A method, device and equipment for constructing an Internet of Vehicles honeypot and a storage medium

By combining virtual road test units, vehicle-mounted units, and electronic control units, a vehicle-to-everything (V2X) honeypot is generated, solving the problem that V2X systems cannot actively defend against attacks and enabling the recording of attack behaviors and enhanced security.

CN116074045BActive Publication Date: 2025-11-11JIANGSU INTELLIGENT NETWORK AUTOMOBILE INNOVATION CENT CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211596545.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-12
Publication Date
2025-11-11
Estimated Expiration
2042-12-12

AI Technical Summary

Technical Problem

Existing vehicle networking systems can only record attacks after they have been launched, making them unable to truly defend against attackers and lacking proactive defense measures.

Method used

Virtual road test units, virtual vehicle units, and virtual electronic control units are constructed and combined with a cloud service platform to generate vehicle-to-everything (V2X) honeypots. The virtual system is used to induce attacks and record attack behaviors.

Benefits of technology

Vehicle-to-everything (V2X) honeypots can lure attackers into launching attacks, record attack behavior, reduce attack efficiency, increase attack costs, and ensure the security of real-world V2X systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116074045B_ABST
    Figure CN116074045B_ABST
Patent Text Reader

Abstract

This invention discloses a method, apparatus, device, and storage medium for constructing a vehicle-to-everything (V2X) honeypot. It includes: constructing a virtual road test unit and a virtual vehicle-mounted unit, and establishing a communication tunnel between the virtual road test unit and the virtual vehicle-mounted unit; constructing a virtual electronic control unit (ECU); and combining the virtual road test unit, virtual vehicle-mounted unit, communication tunnel, and virtual ECU based on a cloud service platform to generate a V2X honeypot. By virtually constructing the virtual road test unit and virtual vehicle-mounted unit through firmware manipulation, and establishing a communication tunnel between them, and by virtually constructing a virtual ECU through relevant parameters, the virtual V2X system generated by combining the virtual road test unit, virtual vehicle-mounted unit, communication tunnel, and virtual ECU via a cloud service platform serves as the V2X honeypot. The V2X honeypot can lure attackers to launch attacks and record them, thus ensuring the security of the real V2X system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet technology, and in particular to a method, apparatus, device and storage medium for constructing a honeypot for vehicle networking. Background Technology

[0002] As the network environment becomes increasingly complex, network security issues are becoming more and more prominent. In order to protect users' data and information security, a variety of defense tools have been developed. Honeypot systems are one of the more mature decoy defense measures. Honeypot systems can deploy some hosts, network services or information as bait to lure attackers to launch attacks, thereby capturing and analyzing the attack behavior.

[0003] With the development of vehicle networking technology, there are more and more types of connected vehicles, which exposes more and more attack surfaces to attackers. Current vehicle networking systems often only record attacks after they have been attacked, making it impossible to truly defend against attackers. Summary of the Invention

[0004] This invention provides a method, apparatus, device, and storage medium for constructing a vehicle-to-everything (V2X) honeypot, which is used as bait to induce attacks.

[0005] According to one aspect of the present invention, a method for constructing a vehicle-to-everything (V2X) honeypot is provided, the method comprising:

[0006] Construct virtual road test units and virtual vehicle-mounted units, and construct communication tunnels between the virtual road test units and virtual vehicle-mounted units;

[0007] Construct a virtual electronic control unit;

[0008] Based on a cloud service platform, virtual road test units, virtual vehicle units, communication tunnels, and virtual electronic control units are combined to generate vehicle-to-everything (V2X) honeypots.

[0009] Optionally, constructing a virtual road test unit and a virtual vehicle unit includes: acquiring the road test unit firmware and the vehicle unit firmware; simulating the road test unit firmware to generate an initial road test unit, generating a virtual road test unit based on the initial road test unit; and simulating the vehicle unit firmware to generate a virtual vehicle unit.

[0010] Optionally, generating a virtual road test unit based on the initial road test unit includes: obtaining a public IP address and using the public IP address as the lead address for the cloud service platform; mapping the lead address to the initial road test unit to generate the virtual road test unit.

[0011] Optionally, constructing a communication tunnel between the virtual road test unit and the virtual vehicle unit includes: encapsulating a specified protocol using an Ethernet tunneling protocol to generate an encapsulated specified protocol, wherein the specified protocol is the original communication protocol of the road test unit firmware and the vehicle unit firmware; obtaining the transmit and receive addresses, and constructing a communication tunnel based on the transmit and receive addresses and the encapsulated specified protocol.

[0012] Optionally, the virtual electronic control unit includes a virtual gateway control unit, a virtual power control unit, a virtual chassis control unit, and a virtual body control unit. Constructing the virtual electronic control unit includes: encapsulating the in-vehicle bus protocol matrix through an Ethernet tunneling protocol to generate a virtual gateway control unit; acquiring relevant vehicle parameters, and generating the virtual power control unit, virtual chassis control unit, and virtual body control unit based on the relevant parameters.

[0013] Optionally, a virtual power control unit, a virtual chassis control unit, and a virtual body control unit can be generated based on relevant parameters, including: generating a virtual power control unit based on engine dynamics parameters; generating a virtual chassis control unit based on steering wheel parameters, gear parameters, and throttle opening parameters; and generating a virtual body control unit based on door parameters, window parameters, trunk parameters, headlight parameters, and horn parameters.

[0014] Optionally, after combining the virtual road test unit, virtual vehicle unit, communication tunnel and virtual electronic control unit based on the cloud service platform to generate a vehicle-to-everything (V2X) honeypot, the method also includes: configuring an intrusion detection system for the virtual gateway control unit; and detecting attack behavior on the virtual gateway control unit through the intrusion detection system.

[0015] According to another aspect of the present invention, a vehicle-to-everything (V2X) honeypot construction device is provided, the device comprising:

[0016] The virtual road test and vehicle unit construction module is used to construct virtual road test units and virtual vehicle units, and to construct the communication tunnel between the virtual road test units and virtual vehicle units;

[0017] The virtual electronic control unit construction module is used to construct virtual electronic control units;

[0018] The vehicle-to-everything (V2X) honeypot generation module is used to combine virtual road test units, virtual vehicle units, communication tunnels, and virtual electronic control units based on a cloud service platform to generate V2X honeypots.

[0019] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0020] At least one processor; and

[0021] A memory communicatively connected to the at least one processor; wherein,

[0022] The memory stores a computer program that can be executed by the at least one processor, which is then executed by the at least one processor to enable the at least one processor to execute a vehicle-to-everything (V2X) honeypot construction method according to any embodiment of the present invention.

[0023] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions, the computer instructions being configured to cause a processor to execute and implement a vehicle-to-everything (V2X) honeypot construction method according to any embodiment of the present invention.

[0024] The technical solution of this invention virtually constructs a virtual road test unit and a virtual vehicle unit by modifying the firmware, and constructs a communication tunnel between the virtual road test unit and the virtual vehicle unit. It also virtually constructs a virtual electronic control unit by modifying relevant parameters. The virtual vehicle network system generated by combining the virtual road test unit, the virtual vehicle unit, the communication tunnel, and the virtual electronic control unit through a cloud service platform serves as a vehicle network honeypot. The vehicle network honeypot can lure attackers to launch attacks and record them, thus ensuring the security of the real vehicle network system.

[0025] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0026] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0027] Figure 1 This is a flowchart of a method for constructing a vehicle-to-everything (V2X) honeypot according to Embodiment 1 of the present invention;

[0028] Figure 2 This is a flowchart of another method for constructing a vehicle-to-everything (V2X) honeypot according to Embodiment 1 of the present invention;

[0029] Figure 3 This is a schematic diagram of the structure of a vehicle networking honeypot according to Embodiment 1 of the present invention;

[0030] Figure 4 This is a flowchart of another method for constructing a vehicle-to-everything (V2X) honeypot according to Embodiment 2 of the present invention;

[0031] Figure 5This is a schematic diagram of a vehicle-to-everything (V2X) honeypot construction device according to Embodiment 3 of the present invention;

[0032] Figure 6 This is a schematic diagram of the structure of an electronic device that implements a method for constructing a vehicle-to-everything (V2X) honeypot according to an embodiment of the present invention. Detailed Implementation

[0033] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0034] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0035] Example 1

[0036] Figure 1 This is a flowchart illustrating a method for constructing a vehicle-to-everything (V2X) honeypot according to Embodiment 1 of the present invention. This embodiment is applicable to situations where a V2X honeypot is constructed for inducing attacks. This method can be executed by a V2X honeypot construction device, which can be implemented in hardware and / or software and can be configured in a computer. Figure 1 As shown, the method includes:

[0037] S110. Construct virtual road test units and virtual vehicle-mounted units, and construct communication tunnels between the virtual road test units and virtual vehicle-mounted units.

[0038] Among them, a Road Side Unit (RSU) is a device installed on the roadside that communicates bidirectionally with nearby passing vehicles and exchanges data. For example, an RSU can collect traffic light data from nearby traffic lights and send it to passing vehicles to guide their speed, enabling them to pass through intersections without stopping. An On Board Unit (OBU) is a device installed on a vehicle to communicate with the RSU. Through the OBU, vehicle-related information can be automatically identified and tolls deducted, achieving automatic traffic control. Virtualization refers to the process of abstracting and simulating key business flows in the vehicle-to-everything (V2X) network. Virtual Road Side Units and Virtual On Board Units are simulated RSUs and OBUs. Tunneling refers to a communication method that disguises types not allowed by the firewall as types / ports allowed by the firewall to make requests. Communication tunnels are used for communication between virtual Road Side Units and virtual On Board Units. The host machine constructs virtual Road Side Units and virtual On Board Units, and then simulates the communication link to build a communication tunnel between the virtual Road Side Units and virtual On Board Units.

[0039] Optionally, constructing a virtual road test unit and a virtual vehicle unit includes: acquiring the road test unit firmware and the vehicle unit firmware; simulating the road test unit firmware to generate an initial road test unit, generating a virtual road test unit based on the initial road test unit; and simulating the vehicle unit firmware to generate a virtual vehicle unit.

[0040] Specifically, the host machine uses virtualization technology to virtualize the firmware of the road test unit to generate the initial road test unit, and simulates the firmware of the vehicle-mounted unit to generate a virtual vehicle-mounted unit. Firmware refers to the driver programs stored within the road test unit or virtual unit; through the firmware, the road test unit or virtual unit can perform specific operational actions according to standard device drivers. The host machine is the executing entity of this method, i.e., a physical server deployed with a virtualization environment. The host machine is the computing platform that carries the entire vehicle-to-everything (V2X) honeypot terminal portion, and can be a regular PC or server. For example, the host machine can be an Intel x86 architecture running the Ubuntu system. The virtual road test unit and the virtual vehicle-mounted unit run in a virtual environment where the hardware is simulated using the QEMU virtual operating system emulator.

[0041] Optionally, generating a virtual road test unit based on the initial road test unit includes: obtaining a public IP address and using the public IP address as the lead address for the cloud service platform; mapping the lead address to the initial road test unit to generate the virtual road test unit.

[0042] Specifically, the host machine will also configure external network induction attack addresses. During configuration, the host machine will obtain the public Internet Protocol (IP) address, i.e., the public IP address, and use the public IP address as the induction address for the cloud service platform; the induction address will be mapped to the initial drive test unit to generate a virtual drive test unit. At the same time, the host machine will also set up a firewall to prevent internal traffic from launching attacks from the outside, and to prevent the honeypot system from becoming a node in the botnet.

[0043] Optionally, constructing a communication tunnel between the virtual road test unit and the virtual vehicle unit includes: encapsulating a specified protocol using an Ethernet tunneling protocol to generate an encapsulated specified protocol, wherein the specified protocol is the original communication protocol of the road test unit firmware and the vehicle unit firmware; obtaining the transmit and receive addresses, and constructing a communication tunnel based on the transmit and receive addresses and the encapsulated specified protocol.

[0044] In this context, Ethernet tunneling protocol refers to Transmission Control Protocol / Internet Protocol (TCP / IP), a suite of protocols that enables information transmission between multiple different networks. The specified protocol refers to the original communication protocol of the road test unit firmware and the vehicle unit firmware; this specified protocol can be the PC5 protocol. The host machine simulates PC5 communication between the virtual road test unit and the virtual vehicle unit via Ethernet tunneling. This involves encapsulating the PC5 protocol using TCP / IP and obtaining default sender and receiver addresses (the addresses of the data sender and receiver). The data sender encapsulates the packets, and the data receiver decapsulates them, thus forming a communication tunnel and simulating the PC5 network.

[0045] S120, Construct a virtual electronic control unit.

[0046] The Electronic Control Unit (ECU) refers to the vehicle's onboard computer. A vehicle has multiple ECUs, which can acquire data from sensors in different parts of the vehicle as input, depending on their function. This implementation method virtualizes the ECUs related to the core business of the vehicle, using the gateway ECU, body ECU, powertrain ECU, and chassis ECU as core ECUs. The protocols, processing logic, and status monitoring of each core ECU are designed to construct the virtual ECU, which includes a virtual gateway control unit, a virtual powertrain control unit, a virtual chassis control unit, and a virtual body control unit.

[0047] Figure 2This invention provides a flowchart of a method for constructing a vehicle-to-everything (V2X) honeypot according to Embodiment 1. Step S120 mainly includes the following steps S121 to S122:

[0048] S121. The in-vehicle bus protocol matrix is ​​encapsulated using the Ethernet tunneling protocol to generate a virtual gateway control unit.

[0049] Specifically, the gateway ECU can provide secure and seamless communication between the network and other ECUs. Other ECUs communicate through the in-vehicle bus protocol. Therefore, the virtual gateway control unit can be generated by encapsulating the in-vehicle bus protocol matrix through the Ethernet tunnel protocol.

[0050] S122. Obtain relevant vehicle parameters and generate a virtual power control unit, a virtual chassis control unit, and a virtual body control unit based on the relevant parameters.

[0051] Specifically, the host machine can acquire relevant vehicle parameters and generate virtual power control units, virtual chassis control units, and virtual body control units by simulating these parameters. Each virtual ECU unit also runs in a virtual environment where the hardware is simulated using the QEMU virtual operating system simulator.

[0052] S130 combines virtual road test units, virtual vehicle units, communication tunnels, and virtual electronic control units based on a cloud service platform to generate a vehicle-to-everything (V2X) honeypot.

[0053] A honeypot, in the context of the internet, is a technique used to deceive attackers. By deploying decoy hosts, network services, or information, attackers are lured into attacking these decoys. This allows for the capture and analysis of the attack, revealing the tools and methods used, and inferring the attacker's intent and motives. This enables defenders to clearly understand the security threats they face and enhance the security capabilities of their actual systems through technical and management measures. A vehicle-to-everything (V2X) honeypot is a virtual V2X attack-inducing system. It can induce attackers to launch attacks, delaying their chances of attacking the real system.

[0054] Optionally, after combining the virtual road test unit, virtual vehicle unit, communication tunnel and virtual electronic control unit based on the cloud service platform to generate a vehicle-to-everything (V2X) honeypot, the method also includes: configuring an intrusion detection system for the virtual gateway control unit; and detecting attack behavior on the virtual gateway control unit through the intrusion detection system.

[0055] Specifically, the host machine is configured with an intrusion detection system for the virtual mesh control unit. The intrusion detection system can detect abnormal CAN frames of the virtual gateway control unit, and can detect attack behavior in time when the vehicle is running abnormally or the CAN frames are abnormal.

[0056] Furthermore, the host machine, based on a cloud service platform, combines virtual road test units, virtual vehicle units, communication tunnels, and virtual electronic control units, and configures an intrusion detection system for the virtual mesh control unit, thus generating the final vehicle-to-everything (V2X) honeypot. Figure 3 This embodiment provides a schematic diagram of the structure of a vehicle-to-everything (V2X) honeypot. Figure 3 The system includes a virtual road test unit, a virtual vehicle unit, a virtual gateway control unit, a virtual power control unit, a virtual chassis control unit, and a virtual body control unit. A communication tunnel is used for communication between the virtual road test unit and the virtual vehicle unit. The virtual mesh control unit is used for communication between the virtual vehicle unit and the virtual power control unit, virtual chassis control unit, and virtual body control unit, as well as communication between these units. A firewall is installed in the virtual road test unit to prevent internal traffic from launching attacks, thus avoiding the honeypot system becoming a node in a botnet. An intrusion detection system is configured for the virtual mesh control unit. In summary, the vehicle-to-everything (V2X) honeypot of this invention can be deployed in a real network. Because it possesses a complete V2X business process, it can effectively disguise attacks, allowing attackers to conduct attacks within the honeypot. This allows attackers to discover the attack surface exposed by the real V2X system, the vulnerabilities they possess, their weapon arsenal, and their attack logic. This enables the trapping of attacks, reducing the attacker's attack efficiency and increasing their attack costs.

[0057] The technical solution of this invention virtually constructs a virtual road test unit and a virtual vehicle unit by modifying the firmware, and constructs a communication tunnel between the virtual road test unit and the virtual vehicle unit. It also virtually constructs a virtual electronic control unit by modifying relevant parameters. The virtual vehicle network system generated by combining the virtual road test unit, the virtual vehicle unit, the communication tunnel, and the virtual electronic control unit through a cloud service platform serves as a vehicle network honeypot. The vehicle network honeypot can lure attackers to launch attacks and record them, thus ensuring the security of the real vehicle network system.

[0058] Example 2

[0059] Figure 4 This is a flowchart of a method for constructing a vehicle-to-everything (V2X) honeypot according to Embodiment 2 of the present invention. This embodiment adds a process for generating a virtual power control unit, a virtual chassis control unit, and a virtual body control unit based on relevant parameters, based on Embodiment 1. The specific content of steps S210-S220 and S260 is largely the same as steps S110, S121, and S130 in Embodiment 1, and therefore will not be repeated in this embodiment. Figure 4 As shown, the method includes:

[0060] S210. Construct virtual road test units and virtual vehicle-mounted units, and construct communication tunnels between the virtual road test units and virtual vehicle-mounted units.

[0061] Optionally, constructing a virtual road test unit and a virtual vehicle unit includes: acquiring the road test unit firmware and the vehicle unit firmware; simulating the road test unit firmware to generate an initial road test unit, generating a virtual road test unit based on the initial road test unit; and simulating the vehicle unit firmware to generate a virtual vehicle unit.

[0062] Optionally, generating a virtual road test unit based on the initial road test unit includes: obtaining a public IP address and using the public IP address as the lead address for the cloud service platform; mapping the lead address to the initial road test unit to generate the virtual road test unit.

[0063] Optionally, constructing a communication tunnel between the virtual road test unit and the virtual vehicle unit includes: encapsulating a specified protocol using an Ethernet tunneling protocol to generate an encapsulated specified protocol, wherein the specified protocol is the original communication protocol of the road test unit firmware and the vehicle unit firmware; obtaining the transmit and receive addresses, and constructing a communication tunnel based on the transmit and receive addresses and the encapsulated specified protocol.

[0064] S220: The in-vehicle bus protocol matrix is ​​encapsulated using the Ethernet tunneling protocol to generate a virtual gateway control unit.

[0065] S230: Generate a virtual power control unit based on engine dynamics parameters.

[0066] Specifically, engine dynamics parameters refer to indicators of engine power, such as engine output. The power ECU is the engine's electronic control unit, which mainly controls functions such as fuel injection, ignition, and torque distribution. The host machine can virtually generate a virtual power control unit based on the engine dynamics parameters.

[0067] S240 generates a virtual chassis control unit based on steering wheel parameters, gear parameters, and throttle opening parameters.

[0068] Specifically, the chassis ECU is used to adopt different gear strategies according to the vehicle's driving status. The host machine can generate a virtual chassis control unit by simulating steering wheel parameters, gear parameters, and throttle opening parameters.

[0069] S250 generates a virtual body control unit based on door parameters, window parameters, trunk parameters, headlight parameters, and horn parameters.

[0070] Specifically, the vehicle ECU mainly controls the vehicle's electrical systems, such as lights, windshield wipers, door locks, power windows, sunroof, and horn. Therefore, the host computer can generate a virtual vehicle control unit by simulating the parameters of the doors, windows, trunk, lights, and horn.

[0071] S260 combines virtual road test units, virtual vehicle units, communication tunnels, and virtual electronic control units based on a cloud service platform to generate vehicle-to-everything (V2X) honeypots.

[0072] Optionally, after combining the virtual road test unit, virtual vehicle unit, communication tunnel and virtual electronic control unit based on the cloud service platform to generate a vehicle-to-everything (V2X) honeypot, the method also includes: configuring an intrusion detection system for the virtual gateway control unit; and detecting attack behavior on the virtual gateway control unit through the intrusion detection system.

[0073] The technical solution of this invention virtually constructs a virtual road test unit and a virtual vehicle unit by modifying the firmware, and constructs a communication tunnel between the virtual road test unit and the virtual vehicle unit. A virtual electronic control unit is then constructed by modifying relevant parameters. This virtual electronic control unit includes a virtual gateway control unit, a virtual power control unit, a virtual chassis control unit, and a virtual body control unit. A virtual vehicle network system, generated by combining the virtual road test unit, virtual vehicle unit, communication tunnel, and virtual electronic control unit through a cloud service platform, serves as a vehicle network honeypot. This honeypot can lure attackers to launch attacks and record them, thus ensuring the security of the real vehicle network system.

[0074] Example 3

[0075] Figure 5 This is a schematic diagram of a vehicle-to-everything (V2X) honeypot construction device provided in Embodiment 3 of the present invention. Figure 5 As shown, the device includes: a virtual road test and vehicle unit construction module 310, used to construct virtual road test units and virtual vehicle units, and to construct a communication tunnel between the virtual road test units and virtual vehicle units; a virtual electronic control unit construction module 320, used to construct virtual electronic control units; and a vehicle-to-everything (V2X) honeypot generation module 330, used to combine the virtual road test units, virtual vehicle units, communication tunnels and virtual electronic control units based on a cloud service platform to generate a V2X honeypot.

[0076] Optionally, the virtual road test and vehicle unit construction module 310 specifically includes: a firmware acquisition submodule, used to acquire road test unit firmware and vehicle unit firmware; a virtual road test unit generation submodule, used to simulate the road test unit firmware to generate an initial road test unit, and generate a virtual road test unit based on the initial road test unit; and a virtual vehicle unit generation submodule, used to simulate the vehicle unit firmware to generate a virtual vehicle unit.

[0077] Optionally, a virtual road test unit generation submodule is used to obtain a public network address, use the public network address as the induction address of the cloud service platform, and map the induction address to the initial road test unit to generate a virtual road test unit.

[0078] Optionally, the virtual road test and vehicle unit construction module 310 further includes: a communication tunnel construction submodule, used to encapsulate a specified protocol using the Ethernet tunneling protocol to generate an encapsulated specified protocol, wherein the specified protocol is the original communication protocol of the road test unit firmware and the vehicle unit firmware; obtain the transmit and receive addresses, and construct a communication tunnel based on the transmit and receive addresses and the encapsulated specified protocol.

[0079] Optionally, the virtual electronic control unit construction module 320 specifically includes: a virtual gateway control unit generation submodule, used to encapsulate the in-vehicle bus protocol matrix through the Ethernet tunnel protocol to generate a virtual gateway control unit; and a related parameter virtual submodule, used to obtain relevant vehicle parameters and generate a virtual power control unit, a virtual chassis control unit, and a virtual body control unit based on the relevant parameters.

[0080] Optionally, a virtual submodule for related parameters is used to generate a virtual power control unit based on engine dynamics parameters; a virtual chassis control unit based on steering wheel parameters, gear parameters, and throttle opening parameters; and a virtual body control unit based on door parameters, window parameters, trunk parameters, headlight parameters, and horn parameters.

[0081] Optionally, the device also includes: an intrusion detection configuration module, used to configure an intrusion detection system for the virtual gateway control unit after combining the virtual road test unit, virtual vehicle unit, communication tunnel and virtual electronic control unit on the cloud service platform to generate a vehicle-to-everything honeypot; and to detect attack behavior on the virtual gateway control unit through the intrusion detection system.

[0082] The technical solution of this invention virtually constructs a virtual road test unit and a virtual vehicle unit by modifying the firmware, and constructs a communication tunnel between the virtual road test unit and the virtual vehicle unit. It also virtually constructs a virtual electronic control unit by modifying relevant parameters. The virtual vehicle network system generated by combining the virtual road test unit, the virtual vehicle unit, the communication tunnel, and the virtual electronic control unit through a cloud service platform serves as a vehicle network honeypot. The vehicle network honeypot can lure attackers to launch attacks and record them, thus ensuring the security of the real vehicle network system.

[0083] The vehicle-to-everything (V2X) honeypot construction device provided in this embodiment of the invention can execute the V2X honeypot construction method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0084] Example 4

[0085] Figure 6A schematic diagram of an electronic device 10 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0086] like Figure 6 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0087] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0088] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as a method for building a vehicle-to-everything (V2X) honeypot.

[0089] In some embodiments, a method for constructing a vehicle-to-everything (V2X) honeypot can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the V2X honeypot construction method described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to execute a V2X honeypot construction method by any other suitable means (e.g., by means of firmware).

[0090] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0091] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0092] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0093] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0094] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0095] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0096] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0097] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method for constructing a honeypot for vehicle networking, characterized in that, include: Construct virtual road test units and virtual vehicle-mounted units, and construct a communication tunnel between the virtual road test units and the virtual vehicle-mounted units; Construct a virtual electronic control unit; The virtual road test unit, the virtual vehicle unit, the communication tunnel, and the virtual electronic control unit are combined based on a cloud service platform to generate a vehicle-to-everything (V2X) honeypot. The virtual electronic control unit includes a virtual gateway control unit, a virtual power control unit, a virtual chassis control unit, and a virtual body control unit. The construction of the virtual electronic control unit includes: The virtual gateway control unit is generated by encapsulating the in-vehicle bus protocol matrix using the Ethernet tunneling protocol. Acquire relevant vehicle parameters, and generate the virtual power control unit, the virtual chassis control unit, and the virtual body control unit based on the relevant parameters, including: The virtual power control unit is generated based on engine dynamics parameters, wherein the engine dynamics parameters include engine power; The virtual chassis control unit is generated based on steering wheel parameters, gear parameters, and throttle opening parameters. The virtual chassis control unit is used to adopt different gear strategies according to the driving state of the vehicle. The virtual body control unit is generated based on the parameters of the doors, windows, trunk, lights, and horn. The virtual body control unit is used to control the vehicle's electrical systems.

2. The method according to claim 1, characterized in that, The construction of the virtual road test unit and the virtual vehicle unit includes: Obtain the firmware of the road test unit and the vehicle-mounted unit; The firmware of the drive test unit is simulated to generate an initial drive test unit, and the virtual drive test unit is generated based on the initial drive test unit; The vehicle unit firmware is simulated to generate the virtual vehicle unit.

3. The method according to claim 2, characterized in that, The step of generating the virtual road test unit based on the initial road test unit includes: Obtain a public IP address and use that public IP address as the redirection address for the cloud service platform; The induced address is mapped to the initial drive test unit to generate the virtual drive test unit.

4. The method according to claim 2, characterized in that, The construction of the communication tunnel between the virtual road test unit and the virtual vehicle unit includes: The specified protocol is encapsulated using the Ethernet tunneling protocol to generate the encapsulated specified protocol, wherein the specified protocol is the original communication protocol of the road test unit firmware and the vehicle unit firmware; Obtain the send and receive addresses, and construct the communication tunnel based on the send and receive addresses and the encapsulated specified protocol.

5. The method according to claim 1, characterized in that, After combining the virtual road test unit, the virtual vehicle unit, the communication tunnel, and the virtual electronic control unit on the cloud service platform to generate a vehicle-to-everything (V2X) honeypot, the method further includes: Configure an intrusion detection system for the virtual gateway control unit; The intrusion detection system detects attack behavior on the virtual gateway control unit.

6. A device for constructing a honeypot for a vehicle network, characterized in that, include: A virtual road test and vehicle-mounted unit construction module is used to construct virtual road test units and virtual vehicle-mounted units, and to construct the communication tunnel between the virtual road test units and the virtual vehicle-mounted units; The virtual electronic control unit construction module is used to construct virtual electronic control units; The vehicle-to-everything (V2X) honeypot generation module is used to combine the virtual road test unit, the virtual vehicle unit, the communication tunnel, and the virtual electronic control unit based on a cloud service platform to generate a V2X honeypot. The virtual electronic control unit includes a virtual gateway control unit, a virtual power control unit, a virtual chassis control unit, and a virtual body control unit. The virtual electronic control unit construction module specifically includes a virtual gateway control unit generation submodule, which is used to encapsulate the in-vehicle bus protocol matrix through an Ethernet tunneling protocol to generate the virtual gateway control unit. The relevant parameter virtual submodule is used to acquire relevant vehicle parameters and generate the virtual power control unit, the virtual chassis control unit, and the virtual body control unit based on the relevant parameters; The related parameter virtual submodule is used to: generate the virtual power control unit based on engine dynamics parameters, wherein the engine dynamics parameters include engine power; The virtual chassis control unit is generated based on steering wheel parameters, gear parameters, and throttle opening parameters. The virtual chassis control unit is used to adopt different gear strategies according to the driving state of the vehicle. The virtual body control unit is generated based on the parameters of the doors, windows, trunk, lights, and horn. The virtual body control unit is used to control the vehicle's electrical systems.

7. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-5.

8. A computer storage medium, characterized in that, The computer storage medium stores computer instructions that are used to cause a processor to execute the method of any one of claims 1-5.

Citation Information

Patent Citations

  • Attack trapping system based on firmware simulation

    CN112417444A

  • Safe trapping method and device and computer equipment

    CN114584359A