A vehicle anomaly monitoring method and device and a storage medium
By deploying anomaly prediction models and strategies on cloud servers and utilizing cloud resources for vehicle anomaly monitoring, the problem of vehicle-side hardware resource limitations is solved, enabling efficient monitoring of complex attack behaviors and ensuring vehicle security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Z-ONE TECH CO LTD
- Filing Date
- 2023-05-25
- Publication Date
- 2026-06-02
AI Technical Summary
Existing vehicle intrusion detection and prevention (IDPS) systems are limited by the vehicle's limited hardware resources, making it difficult to effectively monitor highly complex intrusion behaviors and unable to detect unknown threats, variants of known threats, or attacks involving multiple scenarios.
Deploy anomaly prediction models and/or anomaly data prediction strategies in cloud servers, utilize the abundant hardware resources in the cloud for anomaly monitoring, and construct anomaly prediction models and/or anomaly data prediction strategies by collecting comprehensive information data of vehicles to monitor anomalies of connected vehicles.
It achieves highly reliable and accurate monitoring of unknown threats, known threat variants, and complex attack behaviors, ensuring the safe operation of vehicles.
Smart Images

Figure CN116707875B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of automotive cybersecurity technology, and in particular to a method, device and storage medium for monitoring vehicle anomalies. Background Technology
[0002] The widespread adoption of intelligent vehicles has brought immense convenience to people's lives. However, in recent years, numerous incidents of hacker attacks on various car models have been frequently reported in the media, raising concerns and fears about the security of intelligent vehicles. Therefore, vehicle security remains one of the major challenges facing intelligent vehicles. Currently, many research projects focus on vehicle security, with real-time monitoring and detection of intrusion threats, as the first line of defense, receiving increasing attention. Current vehicle intrusion monitoring and detection primarily relies on deploying IDPS (Intrusion Detection and Prevention Systems) on the vehicle side for threat detection. However, IDPS has many limitations. Constrained by the limited hardware resources on the vehicle side, it struggles to effectively and promptly handle highly complex intrusion behaviors. This limits the effectiveness of IDPS in detecting threat scenarios or intrusion behaviors, making it unable to monitor unknown intrusion threats, variants of known threats, or attacks involving multiple scenarios—all highly complex attacks. Therefore, how to more effectively monitor vehicle attack threats has become a pressing issue for the industry. Summary of the Invention
[0003] In view of this, embodiments of this application provide a vehicle anomaly monitoring method, apparatus, and storage medium to solve the above-mentioned problems at least or in part.
[0004] In a first aspect, embodiments of this application provide a method for monitoring vehicle anomalies, including:
[0005] Collect comprehensive information data about the vehicle;
[0006] Based on the comprehensive information data, determine the anomaly prediction model and / or anomaly data prediction strategy;
[0007] Deploy the anomaly prediction model and / or anomaly data prediction strategy on a cloud server;
[0008] Anomaly monitoring is performed on connected vehicles using the aforementioned anomaly prediction model and / or anomaly data prediction strategy deployed on a cloud server.
[0009] Optionally, in one embodiment of this application, determining anomaly prediction models and / or anomaly data prediction strategies based on the comprehensive information data includes:
[0010] The comprehensive information is preprocessed to obtain preprocessed data;
[0011] Based on the preprocessed data and attack data, determine the anomaly prediction model and / or anomaly data prediction strategy.
[0012] Optionally, in one embodiment of this application, the preprocessing includes:
[0013] The comprehensive information data is then subjected to data normalization processing;
[0014] Data filtering is performed on the data after the normalization process;
[0015] Based on the VIN code and timestamp information associated with the filtered data, the data is merged to obtain a merged data table;
[0016] The merged data table is logically processed to obtain logical data;
[0017] The logical data is filtered using a feature-based filtering method to identify important feature data.
[0018] The important feature data is subjected to dimensionality reduction processing to obtain the preprocessed data.
[0019] Optionally, in one embodiment of this application, determining the anomaly prediction model and / or anomaly data prediction strategy based on the preprocessed data and attack data includes:
[0020] The preprocessed data is divided into training data and test data;
[0021] The classification prediction model is trained using the training and testing data.
[0022] Based on the trained classification prediction model, an anomaly prediction model is constructed.
[0023] And / or,
[0024] The vehicle was attacked using penetration testing to obtain attack data;
[0025] Determine the distinguishing features between the attack data and the normal data in the preprocessed data;
[0026] Based on the distinguishing features, the abnormal data prediction strategy is determined.
[0027] Optionally, in one embodiment of this application, the step of using the anomaly prediction model and / or anomaly data prediction strategy deployed on a cloud server to perform anomaly monitoring of networked vehicles includes:
[0028] The anomaly prediction model and / or anomaly data prediction strategy deployed on the cloud server are executed periodically to monitor vehicles that have established network communication with the cloud server.
[0029] Optionally, in one embodiment of this application, the vehicle anomaly monitoring method further includes:
[0030] Obtain the results of the anomaly monitoring;
[0031] Generate and display alarm results corresponding to the aforementioned abnormal monitoring results.
[0032] Optionally, in one embodiment of this application, the vehicle anomaly monitoring further includes:
[0033] The alarm results were analyzed and verified.
[0034] If the analysis and verification result is a false alarm, the anomaly prediction model and / or anomaly data prediction strategy shall be optimized and adjusted based on the analysis and verification result.
[0035] Optionally, in one embodiment of this application, the alarm result is analyzed and verified, including:
[0036] Obtain vehicle operation log data;
[0037] The alarm results are judged based on the log data or expert input data, so as to analyze and verify the alarm results.
[0038] Secondly, based on the vehicle anomaly monitoring method provided in the first aspect of this application, embodiments of this application also provide a vehicle anomaly monitoring device, including:
[0039] The data acquisition module is used to collect comprehensive information data about the vehicle.
[0040] The module is used to determine the anomaly prediction model and / or anomaly data prediction strategy based on the comprehensive information data.
[0041] The deployment module deploys the anomaly prediction model and / or anomaly data prediction strategy on a cloud server;
[0042] The monitoring module is used to monitor networked vehicles for anomalies using the anomaly prediction model and / or anomaly data prediction strategy deployed on a cloud server.
[0043] Thirdly, embodiments of this application also provide a storage medium storing computer-executable instructions, which, when executed, perform any of the vehicle anomaly monitoring methods described in the first aspect of this application.
[0044] Fourthly, embodiments of this application also provide an electronic device for training a graph neural network. The device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements any of the vehicle anomaly monitoring methods described in the first aspect of this application.
[0045] This application provides a vehicle anomaly monitoring method, device, and related equipment. By collecting comprehensive vehicle information data, an anomaly prediction model and / or anomaly data prediction strategy are determined based on this data. The anomaly prediction model and / or anomaly data prediction strategy are deployed on a cloud server, and the networked vehicles are monitored for anomalies using this deployed model and / or strategy. This method of deploying the anomaly prediction model and / or anomaly data prediction strategy on a cloud server fully and rationally utilizes the cloud server's hardware resources, achieving highly reliable and accurate anomaly monitoring of vehicles. It also enables the detection and prediction of complex attacks, such as unknown intrusion threats, variants of known threats, or attacks involving multiple scenarios, thereby effectively and reliably monitoring various attack threats to vehicles and ensuring vehicle operational safety. Attached Figure Description
[0046] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings.
[0047] Figure 1 A schematic diagram illustrating the workflow of a vehicle anomaly monitoring method provided in this application embodiment;
[0048] Figure 2 This is a schematic diagram of the structure of a vehicle anomaly monitoring device provided in an embodiment of this application. Detailed Implementation
[0049] To enable those skilled in the art to better understand the technical solutions in the embodiments of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art should fall within the protection scope of the embodiments of this application.
[0050] It should be understood that the steps described in the method embodiments of this application may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this application is not limited in this respect.
[0051] Example 1
[0052] This application provides a method for monitoring vehicle anomalies, such as... Figure 1 As shown, Figure 1 A schematic diagram of the workflow of a vehicle anomaly monitoring method provided in this application embodiment includes:
[0053] Step S101: Collect comprehensive vehicle information data. In this embodiment, the comprehensive information data includes all relevant data related to the vehicle's operation and control. Specifically, the comprehensive information data includes, but is not limited to, the following aspects:
[0054] Event data triggered by NIDS (Network Intrusion Detection System) includes information such as event time, event name, and quintuple.
[0055] Flow data of various devices in each vehicle under their operating status;
[0056] HIDS (Host-based Intrusion Detection System) data refers to data from a host-based intrusion detection system. As a monitor and analyzer for a computer system, it does not operate on external interfaces but focuses on the internal workings of the system, monitoring the dynamic behavior of all or part of the system and the overall state of the computer system.
[0057] CAN-IDS data essentially involves matching collected CAN traffic with rules from three aspects: message, scenario, and network, according to a predetermined rule base, to identify relevant data of attack / abnormal messages.
[0058] The data uploaded by the vehicle includes embedded points and dynamic data collection, such as vehicle GPS, vehicle speed, mileage, whether the vehicle is powered on, whether the engine is off, the status of each door, the status of each door handle, the status of the windows, the status of the trunk, the status of the locks, battery voltage, current, and battery level.
[0059] This includes one or more vehicle-related data points such as remote vehicle control data, digital key data, message notification data, vehicle model and brand data, OTA (Over-The-Air) data, and remote vehicle diagnostic data. This allows for subsequent steps to ensure the accuracy and comprehensiveness of the vehicle anomaly prediction model or anomaly data prediction strategy based on this data from multiple dimensions.
[0060] Step S102: Based on the comprehensive information data, determine the anomaly prediction model and / or anomaly data prediction strategy. Specifically, the comprehensive information data can be divided into a training sample set and a test dataset. Classification prediction models such as logistic regression, random forest, and XGBoost can be constructed sequentially and trained using the training sample set for anomaly prediction. The trained classification prediction model can then be optimized using the test dataset to determine the anomaly prediction model. Furthermore, in this embodiment, a penetration test can be used to launch a system attack on a running vehicle to collect data such as remote vehicle control data. This data can then be visualized to obtain the difference between normal and abnormal data. Based on this difference, an anomaly data prediction strategy can be determined, allowing for a simpler way to predict abnormal vehicle data.
[0061] Optionally, in one implementation of this application embodiment, determining anomaly prediction models and / or anomaly data prediction strategies based on comprehensive information data includes: preprocessing the comprehensive information to obtain preprocessed data, and determining anomaly prediction models and / or anomaly data prediction strategies based on the preprocessed data and attack data. The preprocessed data conforms to the input format of classification prediction models such as logistic regression, random forest, and XGBoost, while the attack data is anomaly data obtained through system attack testing. The anomaly data includes event anomalies, timestamp anomalies, or difference anomalies. Event anomalies can be operational control events that should not occur during the current vehicle operation phase. Timestamp anomalies indicate that the difference between the timestamp corresponding to the start or end time of a control command and the timestamp corresponding to the start or end time of the control command execution is greater than a preset threshold. Difference anomalies occur when the actual mileage and the mileage calculated via GPS are greater than or equal to a preset difference mileage. Of course, this embodiment of the application is merely an illustrative description of the anomaly data and does not represent a limitation of the application. This approach simplifies the process of developing anomaly prediction models and / or anomaly data prediction strategies to some extent, while ensuring that the constructed anomaly prediction models and / or anomaly data prediction strategies have good accuracy.
[0062] Optionally, in one implementation of this application embodiment, the preprocessing specifically includes: performing data normalization on the comprehensive information data; filtering the normalized data; merging the data based on the VIN code and timestamp information associated with the filtered data to obtain a merged data table; performing logical processing on the merged data table to obtain logical data; filtering the logical data using feature filtering to identify important feature data; and performing data dimensionality reduction on the important feature data to obtain the preprocessed data. In this application embodiment, since the obtained comprehensive information data comes from different sources, such as some data existing in a MySQL database and some in Hive, it is first normalized. On the other hand, due to the large volume of data and numerous forms, it is necessary to filter and screen the comprehensive information data to remove redundant or duplicate data, select the necessary tables and fields, and further merge the data into corresponding tables according to VIN codes and timestamps. This makes the comprehensive information of different vehicles more orderly. Then, logical processing methods such as data removal, median replacement, and mean replacement are used to handle outliers and default values in the merged data tables. Finally, since the data volume is still large and complex, it is necessary to further filter and reduce the dimensionality of the logically processed data by performing correlation calculations or variance calculations to select more important features. For data that still has many features, principal component analysis is used to reduce the dimensionality of the logically processed data, making the preprocessed data more suitable for model training and optimization. The processing is also relatively simple and improves the efficiency of model training or determining outlier prediction strategies.
[0063] Optionally, in one embodiment of this application, determining the anomaly prediction model and / or anomaly data prediction strategy based on the preprocessed data and attack data includes: dividing the preprocessed data into training data and test data; using the training data and test data to train the classification prediction model; and constructing an anomaly prediction model based on the trained classification prediction model, so as to improve the accuracy and efficiency of constructing the anomaly prediction model.
[0064] And / or; attack the vehicle through penetration testing, obtain attack data, determine the distinguishing features between the attack data and the normal data in the preprocessed data, i.e. the difference between normal data and attack data, and determine an anomaly prediction strategy based on the distinguishing features to further simplify the process of determining the anomaly prediction strategy.
[0065] In this embodiment of the application, the constructed anomaly prediction model can detect and predict vehicle-side anomalies caused by unknown threats, variants of known threats, and attacks involving multiple event phases.
[0066] Specifically, in one implementation of this application, the abnormal data prediction strategy includes, but is not limited to, one or more of the following: mileage tampering, GPS anomalies, remote vehicle control service-related event anomalies, timestamp anomalies, etc.
[0067] Step S103: Deploy the anomaly prediction model and / or anomaly data prediction strategy in a cloud server.
[0068] Step S104: Utilize the anomaly prediction model and / or anomaly data prediction strategy deployed on a cloud server to perform anomaly monitoring on networked vehicles. This allows for parallel monitoring of multiple vehicle models and types on the cloud server. In this embodiment, compared to traditional local anomaly monitoring on the vehicle side, where limited local resources make complex data processing and calculations difficult, cloud servers offer abundant resources. This allows for anomaly monitoring of more complex vehicle anomalies, covering more vehicle threats or anomaly scenarios, further improving the accuracy and comprehensiveness of anomaly monitoring. Furthermore, it enables reasonable mobilization of cloud server data processing resources to uncover unknown threats or anomalies, resulting in better anomaly monitoring efficiency. Additionally, because cloud servers involve fewer stakeholders and have relatively simpler links, iteration on the cloud is simpler, overcoming the difficulty of iteration on the traditional vehicle side. For example, when optimization or new features are needed, rapid iteration or updates of the anomaly prediction model or strategy can be easily implemented on the cloud server.
[0069] Optionally, in one implementation of this application embodiment, anomaly monitoring of networked vehicles is performed using an anomaly prediction model and / or anomaly data prediction strategy deployed on a cloud server. This includes periodically executing the anomaly prediction model and / or anomaly data prediction strategy deployed on the cloud server to perform anomaly monitoring of vehicles that have established network communication with the cloud server, so as to effectively ensure the sustainability and stability of vehicle anomaly monitoring while saving system resources.
[0070] Optionally, in one embodiment of this application, the vehicle anomaly monitoring method further includes: obtaining the result of the anomaly monitoring, generating an alarm result corresponding to the anomaly monitoring result, and displaying it.
[0071] Optionally, in one embodiment of this application, the vehicle anomaly monitoring further includes: analyzing and verifying the alarm results; if the analysis and verification results are false alarms, then optimizing and adjusting the anomaly prediction model and / or anomaly data prediction strategy based on the analysis and verification results, to further ensure the reliability of anomaly monitoring.
[0072] Optionally, in one embodiment of this application, analyzing and verifying the alarm result includes: acquiring vehicle operation log data, and judging the alarm result based on the log data or expert input data, thereby analyzing and verifying the alarm result. This method provides the simplest and most reliable way to analyze and verify the alarm result, reducing the difficulty of analysis and verification and making it easy for ordinary users to implement.
[0073] This application provides a vehicle anomaly monitoring method. By collecting comprehensive vehicle information data, an anomaly prediction model and / or anomaly data prediction strategy are determined based on this data. The anomaly prediction model and / or anomaly data prediction strategy are then deployed on a cloud server. This method, by deploying the anomaly prediction model and / or anomaly data prediction strategy on a cloud server, fully and rationally utilizes the cloud server's hardware resources, achieving highly reliable and accurate anomaly monitoring of vehicles. It also enables the detection and prediction of complex attacks, such as unknown intrusion threats, variants of known threats, or attacks involving multiple scenarios, thereby effectively and reliably monitoring various attack threats to vehicles and ensuring vehicle operational safety.
[0074] Example 2
[0075] Based on the vehicle anomaly monitoring method described in Embodiment 1 of this application, this embodiment also provides a vehicle anomaly monitoring device, such as... Figure 2 As shown, Figure 2 This is a schematic diagram of the structure of a vehicle anomaly monitoring device 20 provided in an embodiment of this application. The vehicle anomaly control device 20 includes:
[0076] The data acquisition module 201 is used to collect comprehensive information data of the vehicle;
[0077] Module 202 is used to determine anomaly prediction models and / or anomaly data prediction strategies based on the comprehensive information data;
[0078] Deployment module 203 deploys the anomaly prediction model and / or anomaly data prediction strategy on a cloud server;
[0079] The monitoring module 204 is used to monitor networked vehicles for anomalies using the anomaly prediction model and / or anomaly data prediction strategy deployed on a cloud server.
[0080] Optionally, in one implementation of this application embodiment, the construction module 202 is further configured to: preprocess the comprehensive information to obtain preprocessed data; and determine an anomaly prediction model and / or anomaly data prediction strategy based on the preprocessed data and attack data.
[0081] Optionally, in one implementation of this application embodiment, the construction module 202 is further configured to: perform data normalization processing on the comprehensive information data; perform data filtering on the data after normalization processing; merge the data according to the VIN code and timestamp information associated with the data after data filtering to obtain a merged data table; perform logical processing on the merged data table to obtain logical data; use feature filtering to filter the logical data to filter out important feature data; and perform data dimensionality reduction processing on the important feature data to obtain the preprocessed data.
[0082] Optionally, in one implementation of this application embodiment, the construction module 202 is further configured to: divide the preprocessed data into training data and test data; train the classification prediction model using the training data and test data; construct an anomaly prediction model based on the trained classification prediction model; and / or, attack the vehicle through penetration testing to obtain attack data; determine the distinguishing features between the attack data and the normal data in the preprocessed data; and determine the anomaly prediction strategy based on the distinguishing features.
[0083] Optionally, in one implementation of this application embodiment, the monitoring module 204 is further configured to: periodically execute the anomaly prediction model and / or anomaly data prediction strategy deployed on the cloud server to perform anomaly monitoring on vehicles that have established network communication with the cloud server.
[0084] Optionally, in one implementation of this application embodiment, the vehicle anomaly monitoring device 20 further includes an early warning module (not shown in the figures), which is used to: obtain the result of the anomaly monitoring; generate an alarm result corresponding to the anomaly monitoring result and display it.
[0085] Optionally, in one implementation of this application embodiment, the vehicle anomaly monitoring device 20 further includes an optimization module (not shown in the figures), which is used to: analyze and verify the alarm result; if the analysis and verification result is a false alarm, optimize and adjust the anomaly prediction model and / or anomaly data prediction strategy according to the analysis and verification result.
[0086] Optionally, in one implementation of this application embodiment, the optimization module is further configured to acquire vehicle operation log data; and to judge the alarm result based on the log data or expert input data, so as to analyze and verify the alarm result.
[0087] This application provides a vehicle anomaly monitoring device. It collects comprehensive vehicle information data through a data acquisition module, constructs a model to determine anomaly prediction and / or anomaly data prediction strategies based on the comprehensive information data, deploys the anomaly prediction model and / or anomaly data prediction strategies on a cloud server, and sets up a monitoring module to monitor networked vehicles using the deployed anomaly prediction model and / or anomaly data prediction strategies on the cloud server. This method of deploying the anomaly prediction model and / or anomaly data prediction strategies on a cloud server fully and rationally utilizes the hardware resources of the cloud server, achieving highly reliable and accurate anomaly monitoring of vehicles. It also enables the detection and prediction of complex attacks, such as unknown intrusion threats, variants of known threats, or attacks involving multiple scenarios, thereby effectively and reliably monitoring various attack threats to vehicles and ensuring vehicle operational safety.
[0088] Example 3
[0089] This application embodiment also provides a storage medium storing a computer program thereon, which, when executed by a processor, implements any of the vehicle anomaly monitoring methods described in Embodiment 1 of this application. The vehicle anomaly monitoring method includes, but is not limited to:
[0090] Collect comprehensive information data about the vehicle;
[0091] Based on the comprehensive information data, determine the anomaly prediction model and / or anomaly data prediction strategy;
[0092] Deploy the anomaly prediction model and / or anomaly data prediction strategy on a cloud server;
[0093] Anomaly monitoring is performed on connected vehicles using the aforementioned anomaly prediction model and / or anomaly data prediction strategy deployed on a cloud server.
[0094] This application has now described specific embodiments of the subject matter. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing can be advantageous.
[0095] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (e.g., a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system layer onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0096] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0097] The system layers, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.
[0098] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.
[0099] Those skilled in the art will understand that embodiments of this application can be provided as methods, system-level, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0100] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0101] This application can be described in the general context of computer-executable instructions that are executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific transactions or implement specific abstract data types. This application can also be practiced in distributed computing environments where transactions are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0102] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system-level embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0103] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method for monitoring vehicle anomalies, characterized in that, include: Collect comprehensive information data about the vehicle; Based on the comprehensive information data, determine the anomaly prediction model and / or anomaly data prediction strategy; Deploy the anomaly prediction model and / or the anomaly data prediction strategy on a cloud server; The cloud server, which is equipped with the aforementioned anomaly prediction model and / or the aforementioned anomaly data prediction strategy, is used to monitor networked vehicles for anomalies. The step of determining the anomaly prediction model and / or anomaly data prediction strategy based on the comprehensive information data includes: The comprehensive information data is preprocessed to obtain preprocessed data; Based on the preprocessed data and attack data, the anomaly prediction model and / or the anomaly data prediction strategy are determined, wherein the vehicle is attacked through penetration testing to obtain attack data; Determine the distinguishing features between the attack data and the normal data in the preprocessed data; Based on the distinguishing features, the abnormal data prediction strategy is determined.
2. The vehicle anomaly monitoring method according to claim 1, characterized in that, The preprocessing includes: The comprehensive information data is then subjected to data normalization processing; Data filtering is performed on the data after the normalization process; Based on the VIN code and timestamp information associated with the filtered data, the data is merged to obtain a merged data table; The merged data table is logically processed to obtain logical data; The logical data is filtered using a feature-based filtering method to identify important feature data. The important feature data is subjected to dimensionality reduction processing to obtain the preprocessed data.
3. The vehicle anomaly monitoring method according to claim 1, characterized in that, The step of determining the anomaly prediction model and / or the anomaly data prediction strategy based on the preprocessed data and attack data further includes: The preprocessed data is divided into training data and test data; The classification prediction model is trained using the training and testing data. The anomaly prediction model is constructed based on the trained classification prediction model.
4. The vehicle anomaly monitoring method according to claim 1, characterized in that, The method of using the cloud server deployed with the anomaly prediction model and / or the anomaly data prediction strategy to perform anomaly monitoring on networked vehicles includes: The anomaly prediction model and / or the anomaly data prediction strategy deployed on the cloud server are executed periodically to monitor vehicles that have established network communication with the cloud server.
5. The vehicle anomaly monitoring method according to claim 1, characterized in that, The method further includes: Obtain the results of the anomaly monitoring; Generate and display alarm results corresponding to the aforementioned abnormal monitoring results.
6. The vehicle anomaly monitoring method according to claim 5, characterized in that, The method further includes: The alarm results were analyzed and verified. If the analysis and verification result is a false alarm, the anomaly prediction model and / or anomaly data prediction strategy shall be optimized and adjusted based on the analysis and verification result.
7. The vehicle anomaly monitoring method according to claim 6, characterized in that, The analysis and verification of the alarm results includes: Obtain vehicle operation log data; The alarm results are judged based on the log data or expert input data, so as to analyze and verify the alarm results.
8. A vehicle anomaly monitoring device, characterized in that, include: The data acquisition module is used to collect comprehensive information data about the vehicle. The module is used to determine the anomaly prediction model and / or anomaly data prediction strategy based on the comprehensive information data. The deployment module deploys the anomaly prediction model and / or the anomaly data prediction strategy on a cloud server; The monitoring module is used to monitor networked vehicles for anomalies using the cloud server on which the anomaly prediction model and / or the anomaly data prediction strategy are deployed. The step of determining the anomaly prediction model and / or anomaly data prediction strategy based on the comprehensive information data includes: The comprehensive information data is preprocessed to obtain preprocessed data; Based on the preprocessed data and attack data, the anomaly prediction model and / or the anomaly data prediction strategy are determined, wherein the vehicle is attacked through penetration testing to obtain attack data; Determine the distinguishing features between the attack data and the normal data in the preprocessed data; Based on the distinguishing features, the abnormal data prediction strategy is determined.
9. A computer storage medium, characterized in that, The computer storage medium stores computer-executable instructions, which, when executed, perform the vehicle anomaly monitoring method as described in any one of claims 1-7.