A network intrusion detection method, device, equipment and storage medium

By acquiring instruction characteristic information and network traffic information from the vehicle control terminal, and utilizing cross-matching and dynamic baseline detection, the problem of insufficient detection of unknown threats in existing technologies is solved, achieving high-precision network intrusion detection and enhancing network security between the vehicle control terminal and the server.

CN116707964BActive Publication Date: 2026-05-12CHINA AUTOMOTIVE INNOVATION CORP
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA AUTOMOTIVE INNOVATION CORP
Filing Date
2023-06-30
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing network intrusion detection methods cannot effectively detect unknown intrusion threats, and existing abnormal behavior detection methods cannot achieve timely, comprehensive, fast, and accurate intrusion detection, making the interaction system between the vehicle control terminal and the server vulnerable to hacker attacks.

Method used

By acquiring the instruction feature information of the target vehicle control command and historical vehicle control network traffic information, a dynamic traffic baseline information is generated using a long short-term memory network model. This baseline information is then combined with the instruction feature information and standard instruction feature information for cross-matching to detect network intrusion.

Benefits of technology

It improves the accuracy of network intrusion detection, enhances the security of network transmission, and can promptly identify and defend against unknown attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116707964B_ABST
    Figure CN116707964B_ABST
Patent Text Reader

Abstract

The application discloses a network intrusion detection method, device and equipment and a storage medium. The method comprises the following steps: obtaining a target vehicle control instruction and instruction feature information corresponding to the target vehicle control instruction, wherein the instruction feature information represents a behavior control sequence corresponding to the target vehicle control instruction, so as to obtain first detection information according to the instruction feature information and standard instruction feature information, wherein the standard instruction feature information represents a standard behavior control sequence corresponding to the target vehicle control instruction, and then obtaining a network intrusion detection result according to the first detection information. The technical scheme provided by the application can improve the accuracy of network intrusion detection, and thus improve the security of network transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle security threat detection and analysis technology, and in particular to a network intrusion detection method, device, equipment and storage medium. Background Technology

[0002] To ensure the security of the interaction system between the vehicle control terminal and the server, it is necessary to perform network intrusion detection on the network of the interaction system between the vehicle control terminal and the server. In order to identify potential threats in the interaction system in a timely manner through network intrusion detection, the system's defense capabilities can be enhanced, thereby preventing malicious attacks from hackers on the interaction between the vehicle control terminal and the server, which could cause serious loss of life and property.

[0003] Currently, network intrusion detection solutions mainly employ two methods: misuse detection and abnormal behavior detection. Misuse detection compares observed attack types with known threat rule types to achieve network intrusion detection, while abnormal behavior detection identifies attacks based on normal system behavior to achieve network intrusion detection. However, misuse detection can only detect known intrusion threats and cannot detect unknown intrusion threats. Although abnormal behavior detection can detect unknown intrusion threats, existing abnormal behavior detection methods cannot achieve timely, comprehensive, fast, and accurate intrusion detection, making the interaction between the vehicle control terminal and the server highly vulnerable to hacker attacks.

[0004] Therefore, an improved network intrusion detection scheme is needed to address the problems existing in the above-mentioned technologies. Summary of the Invention

[0005] To address the problems of the prior art, this application provides a technical solution for a network intrusion detection method, apparatus, device, and storage medium, the technical solution of which is described below:

[0006] On the one hand, a network intrusion detection method is provided, the method comprising:

[0007] Acquire a target vehicle control command and the command feature information corresponding to the target vehicle control command, wherein the command feature information characterizes the behavior control sequence corresponding to the target vehicle control command;

[0008] Based on the instruction feature information and the standard instruction feature information, first detection information is obtained, wherein the standard instruction feature information characterizes the standard behavior control sequence corresponding to the target vehicle control instruction;

[0009] Based on the first detection information, the network intrusion detection result is obtained.

[0010] Further, obtaining the first detection information based on the instruction feature information and the standard instruction feature information includes:

[0011] Based on the instruction feature information, feature sequence information corresponding to the target vehicle control instruction is obtained, wherein the feature sequence information is sorting information that sorts the instruction feature information;

[0012] The first detection information is obtained based on the feature sequence information and the standard feature sequence information corresponding to the standard instruction feature information.

[0013] Further, obtaining the first detection information based on the standard feature sequence information corresponding to the feature sequence information and the standard instruction feature information includes:

[0014] The first detection information is obtained by cross-matching the feature sequence information with the standard feature sequence information.

[0015] Furthermore, before obtaining the network intrusion detection result based on the first detection information, the method further includes:

[0016] Obtain historical vehicle control network traffic information and the actual vehicle control network traffic value corresponding to the target vehicle control command, wherein the historical vehicle control network traffic information is the vehicle control network traffic information within a preset historical time period;

[0017] Based on the historical vehicle control network traffic information, dynamic traffic baseline information is obtained;

[0018] The second detection information is obtained based on the dynamic traffic baseline information and the actual vehicle control network traffic value.

[0019] Further, obtaining the second detection information based on the dynamic traffic baseline information and the actual vehicle control network traffic value includes:

[0020] Based on the dynamic traffic baseline information, the predicted vehicle control network traffic value corresponding to the execution of the target vehicle control command is obtained;

[0021] The second detection information is obtained based on the predicted vehicle control network traffic value and the actual vehicle control network traffic value.

[0022] Further, obtaining the second detection information based on the predicted vehicle control network traffic value and the actual vehicle control network traffic value includes:

[0023] Based on the predicted vehicle control network traffic value and the actual vehicle control network traffic value, a comparison result between the predicted vehicle control network traffic value and the actual vehicle control network traffic value is obtained;

[0024] Based on the comparison results, the second detection information is obtained.

[0025] Furthermore, the method also includes:

[0026] Obtain the instruction feature information and historical vehicle control network traffic information corresponding to the target vehicle control instruction;

[0027] The first detection information is obtained based on the instruction feature information and the standard instruction feature information;

[0028] Based on the historical vehicle control network traffic information, dynamic traffic baseline information is obtained;

[0029] Based on the dynamic traffic baseline information, the second detection information is obtained;

[0030] The network intrusion detection result is obtained based on the first detection information and the second detection information.

[0031] On the other hand, a network intrusion detection device is provided, the device comprising:

[0032] The data acquisition module is used to acquire the target vehicle control command and the command feature information corresponding to the target vehicle control command, wherein the command feature information characterizes the behavior control sequence corresponding to the target vehicle control command;

[0033] The first detection information determination module is used to obtain first detection information based on the instruction feature information and the standard instruction feature information, wherein the standard instruction feature information characterizes the standard behavior control sequence corresponding to the target vehicle control instruction;

[0034] The detection result determination module is used to obtain the network intrusion detection result based on the first detection information.

[0035] On the other hand, a network intrusion detection device is provided, which includes a processor and a memory. The memory stores at least one instruction, at least one program, code set, or instruction set. The at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the network intrusion detection method as described above.

[0036] On the other hand, a computer-readable storage medium is provided, wherein at least one instruction, at least one program, code set, or instruction set is stored therein, wherein the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by a processor to implement the network intrusion detection method described above.

[0037] The network intrusion detection method, apparatus, device, and storage medium provided in this application have the following technical effects:

[0038] This application embodiment obtains a target vehicle control command and corresponding command feature information, wherein the command feature information represents the behavior control sequence corresponding to the target vehicle control command. Based on the command feature information and standard command feature information, first detection information is obtained, wherein the standard command feature information represents the standard behavior control sequence corresponding to the target vehicle control command. Then, based on the first detection information, a network intrusion detection result is obtained. The technical solution provided by this application can improve the accuracy of network intrusion detection, thereby improving the security of network transmission. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 A flowchart illustrating a network intrusion detection method provided in an embodiment of this application;

[0041] Figure 2 A flowchart illustrating the first detection information determination method provided in an embodiment of this application;

[0042] Figure 3 A flowchart illustrating another network intrusion detection method provided in this application embodiment;

[0043] Figure 4 A flowchart illustrating the method for determining network intrusion detection results provided in this application embodiment;

[0044] Figure 5 This is a schematic diagram of the structure of a network intrusion detection device provided in an embodiment of this application;

[0045] Figure 6 This is a schematic diagram of the structure of the first detection information determination module provided in the embodiments of this application;

[0046] Figure 7 This is a schematic diagram of another network intrusion detection device provided in an embodiment of this application;

[0047] Figure 8 This is a schematic diagram of the structure of a server provided in an embodiment of this application. Detailed Implementation

[0048] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0049] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in sequences other than those illustrated or described herein.

[0050] Please see Figure 1 The diagram shown is a flowchart of a network intrusion detection method provided in an embodiment of this application. The following is a summary of the process. Figure 1 The technical solution of this application is described in detail. It should be noted that this specification provides the method operation steps as shown in the embodiments or flowcharts, but based on conventional or non-inventive labor, more or fewer operation steps may be included. The order of steps listed in the embodiments is merely one possible execution order among many steps and does not represent the only execution order. The specific method includes the following steps:

[0051] S101: Obtain the target vehicle control command and the command feature information corresponding to the target vehicle control command. The command feature information represents the behavior control sequence corresponding to the target vehicle control command.

[0052] In this embodiment, the target vehicle control command is the vehicle control command to be detected in the communication data between the vehicle control terminal and the server. The command feature information characterizes the behavior control sequence corresponding to the target vehicle control command. The behavior control sequence of the vehicle control command has uniqueness, that is, different vehicle control commands have different behavior control sequences. This can be understood as different vehicle control commands having different command feature information. Therefore, the security status of the network can be determined by judging whether the command feature information corresponding to the target vehicle control command is in a normal state.

[0053] It should be noted that when subjected to malicious attacks, the hacker's continuous attempts to crack the code will prevent the command feature information corresponding to the target vehicle control command from communicating in its inherent manner. Therefore, by detecting the command feature information corresponding to the target vehicle control command, it is possible to determine whether the network has been subjected to malicious attacks.

[0054] S102: Based on the instruction feature information and the standard instruction feature information, the first detection information is obtained, wherein the standard instruction feature information represents the standard behavior control sequence corresponding to the target vehicle control instruction.

[0055] S103: Based on the first detection information, obtain the network intrusion detection result.

[0056] In this embodiment, first detection information is obtained by comparing instruction feature information and standard instruction feature information. The first detection information includes whether the instruction feature information is the same as the standard instruction feature information or not. If the instruction feature information is the same as the standard instruction feature information, it indicates that there has been no external hacker attack. If the instruction feature information is different from the standard instruction feature information, it indicates that there has been an external hacker attack. This application improves the accuracy of network intrusion detection by detecting the instruction feature information corresponding to the target vehicle control instruction. At the same time, this application identifies attacks based on the behavioral state of the target vehicle control instruction itself, thereby detecting unknown attack behaviors and improving the security of network transmission.

[0057] In one alternative implementation, such as Figure 2 As shown, this is a flowchart illustrating the first detection information determination method provided in an embodiment of this application. Step S102 may include:

[0058] S1021: Based on the instruction feature information, obtain the feature sequence information corresponding to the target vehicle control instruction. The feature sequence information is the sorting information for sorting the instruction feature information.

[0059] S1022: Obtain the first detection information based on the standard feature sequence information corresponding to the feature sequence information and the standard instruction feature information.

[0060] In this embodiment, the feature sequence information corresponding to the vehicle control command is unique, that is, different vehicle control commands have different feature sequence information. Therefore, by determining whether the feature sequence information is the same as the standard feature sequence information, it can be determined whether the network has been maliciously attacked by hackers. It should be noted that by detecting the feature sequence information corresponding to the target vehicle control command, it is possible to detect malicious hacker intrusions into the application with relatively accurate identification, thereby further improving the accuracy of network intrusion detection.

[0061] In an optional implementation, step S1022 may include:

[0062] S10221: Cross-match the feature sequence information with the standard feature sequence information to obtain the first detection information.

[0063] Specifically, cross-matching requires that at least one head sequence and at least one tail sequence of two sequences be compared. That is, at least one head sequence and at least one tail sequence of the feature sequence information and the standard feature sequence information must be compared. This can be understood as comparing the instruction feature information in the feature sequence information with the standard instruction feature information in the corresponding standard feature sequence information to avoid the situation where the feature sequence information is delayed due to network jitter or the influence of a certain network processing module, and is mistakenly identified as a network intrusion.

[0064] In one alternative implementation, such as Figure 3 As shown, this is a flowchart illustrating another network intrusion detection method provided in an embodiment of this application. Before step S103, the method further includes:

[0065] S1031: Obtain historical vehicle control network traffic information and the actual vehicle control network traffic value corresponding to the target vehicle control command. The historical vehicle control network traffic information is the vehicle control network traffic information within a preset historical time period.

[0066] S1032: Obtain dynamic traffic baseline information based on historical vehicle control network traffic information.

[0067] S1033: Based on the dynamic traffic baseline information and the actual vehicle control network traffic value, the second detection information is obtained.

[0068] In this embodiment, the dynamic traffic baseline information is the baseline information determined by the vehicle control network traffic value corresponding to the execution of the vehicle control command. The dynamic traffic baseline information is determined by a long short-term memory network model based on historical vehicle control network traffic information and a preset vehicle control network traffic value corresponding to the target vehicle control command. Specifically, the historical vehicle control network traffic information and the preset vehicle control network traffic value corresponding to the target vehicle control command are input into the long short-term memory network model to obtain the vehicle control network traffic information corresponding to the execution of the target vehicle control command, thereby obtaining the dynamic traffic baseline information.

[0069] In practical applications, second detection information is obtained through dynamic traffic baseline information and actual vehicle control network traffic values, so as to obtain network intrusion detection results based on the second detection information. This application detects the vehicle control network traffic information corresponding to the execution of the target vehicle control command, so as to further improve the accuracy and reliability of network intrusion detection, and at the same time, it can also enhance the detection granularity.

[0070] It should be noted that when subjected to malicious attacks, the vehicle control network traffic information corresponding to the execution of target vehicle control commands will change. The change is generally manifested as a surge in vehicle control network traffic. Therefore, by detecting the vehicle control network traffic information corresponding to the execution of target vehicle control commands, it is possible to determine whether the network has been subjected to malicious attacks.

[0071] In an optional implementation, step S1033 may include:

[0072] S10331: Based on the dynamic traffic baseline information, obtain the predicted vehicle control network traffic value corresponding to the execution of the target vehicle control command.

[0073] S10332: The second detection information is obtained based on the predicted vehicle control network traffic value and the actual vehicle control network traffic value.

[0074] In an optional implementation, step S10332 may include:

[0075] S103321: Based on the predicted vehicle control network traffic value and the actual vehicle control network traffic value, obtain the comparison results between the predicted vehicle control network traffic value and the actual vehicle control network traffic value.

[0076] S103322: Based on the comparison results, the second detection information is obtained.

[0077] In this embodiment, the predicted vehicle control network traffic value is the vehicle control network traffic value corresponding to the execution of the target vehicle control command, determined based on dynamic traffic baseline information. Then, by comparing the predicted vehicle control network traffic value with the actual vehicle control network traffic value corresponding to the execution of the target vehicle control command, second detection information is obtained. Specifically, the second detection information is determined based on the comparison result between the predicted vehicle control network traffic value and the actual vehicle control network traffic value corresponding to the execution of the target vehicle control command. The comparison result can be the difference between the predicted vehicle control network traffic value and the actual vehicle control network traffic value. If the difference is greater than a preset difference threshold, the second detection information indicates that the network has been attacked by a hacker; if the difference is less than or equal to the preset difference threshold, the second detection information indicates that the network has not been attacked by a hacker. Thus, the result of the network intrusion is determined through the second detection information.

[0078] In one alternative implementation, such as Figure 4 As shown, this is a flowchart illustrating a method for determining network intrusion detection results provided in an embodiment of this application. The method may further include:

[0079] S104: Obtain the instruction characteristic information and historical vehicle control network traffic information corresponding to the target vehicle control instruction.

[0080] S105: Obtain the first detection information based on the instruction feature information and the standard instruction feature information.

[0081] S106: Based on historical vehicle control network traffic information, obtain dynamic traffic baseline information.

[0082] S107: Obtain the second detection information based on the dynamic traffic baseline information.

[0083] S108: Based on the first detection information and the second detection information, obtain the network intrusion detection result.

[0084] In this embodiment, while detecting the feature sequence information corresponding to the target vehicle control command, the vehicle control network traffic information corresponding to the execution of the target vehicle control command is also detected, so as to achieve comprehensive, fast and accurate network intrusion detection and improve the security of network transmission.

[0085] It should be noted that by detecting the feature sequence information corresponding to the target vehicle control command, malicious hacker intrusions targeting applications can be detected with relatively high accuracy, thereby further improving the accuracy of network intrusion detection. However, this method cannot detect hacker intrusions other than those targeting applications. On the other hand, detecting the vehicle control network traffic information corresponding to the execution of the target vehicle control command has a wider detection coverage, but this method cannot detect hacker intrusions attacking applications. Therefore, by using the above two detection methods, all hacker intrusion detections can be covered, thus achieving comprehensive, fast, and accurate network intrusion detection.

[0086] As can be seen from the above technical solutions of the embodiments of this application, the following technical effects are achieved:

[0087] This application embodiment obtains a target vehicle control command and corresponding command feature information, wherein the command feature information represents the behavior control sequence corresponding to the target vehicle control command. Based on the command feature information and standard command feature information, first detection information is obtained, wherein the standard command feature information represents the standard behavior control sequence corresponding to the target vehicle control command. Then, based on the first detection information, a network intrusion detection result is obtained. The technical solution provided by this application can improve the accuracy of network intrusion detection, thereby improving the security of network transmission.

[0088] This application also provides a network intrusion detection device, such as... Figure 5 As shown, this is a schematic diagram of the structure of a network intrusion detection device provided in an embodiment of this application. The device specifically includes:

[0089] The data acquisition module 10 is used to acquire the target vehicle control command and the command feature information corresponding to the target vehicle control command. The command feature information represents the behavior control sequence corresponding to the target vehicle control command.

[0090] The first detection information determination module 20 is used to obtain first detection information based on instruction feature information and standard instruction feature information, wherein the standard instruction feature information represents the standard behavior control sequence corresponding to the target vehicle control instruction.

[0091] The detection result determination module 30 is used to obtain the network intrusion detection result based on the first detection information.

[0092] Furthermore, such as Figure 6 As shown, this is a schematic diagram of the structure of the first detection information determination module provided in an embodiment of this application. The first detection information determination module 20 may include:

[0093] The feature sequence information determination submodule 201 is used to obtain the feature sequence information corresponding to the target vehicle control instruction based on the instruction feature information. The feature sequence information is sorting information that sorts the instruction feature information.

[0094] The first detection information determination submodule 202 is used to obtain the first detection information based on the standard feature sequence information corresponding to the feature sequence information and the standard instruction feature information.

[0095] Furthermore, the first detection information determination submodule 202 may include:

[0096] The first detection information determination unit 2021 is used to perform cross-matching of feature sequence information and standard feature sequence information to obtain the first detection information.

[0097] Furthermore, such as Figure 7 As shown, this is a schematic diagram of another network intrusion detection device provided in an embodiment of this application. The network intrusion detection device further includes:

[0098] The traffic data acquisition module 40 is used to acquire historical vehicle control network traffic information and the actual vehicle control network traffic value corresponding to the target vehicle control command. The historical vehicle control network traffic information is the vehicle control network traffic information within a preset historical time period.

[0099] The dynamic traffic baseline information determination module 50 is used to obtain dynamic traffic baseline information based on historical vehicle control network traffic information.

[0100] The second detection information determination module 60 is used to obtain the second detection information based on the dynamic traffic baseline information and the actual vehicle control network traffic value.

[0101] Furthermore, the second detection information determination module 60 may include:

[0102] The vehicle control network traffic value determination submodule 601 is used to obtain the predicted vehicle control network traffic value corresponding to the execution of the target vehicle control command based on the dynamic traffic baseline information.

[0103] The second detection information determination submodule 602 is used to obtain the second detection information based on the predicted vehicle control network traffic value and the actual vehicle control network traffic value.

[0104] Furthermore, the second detection information determination submodule 602 may include:

[0105] The comparison result determination unit 6021 is used to obtain the comparison result between the predicted vehicle control network traffic value and the actual vehicle control network traffic value based on the predicted vehicle control network traffic value and the actual vehicle control network traffic value.

[0106] The second detection information determination unit 6022 is used to obtain the second detection information based on the comparison results.

[0107] Furthermore, the network intrusion detection device may further include:

[0108] The information acquisition module 70 is used to acquire instruction feature information and historical vehicle control network traffic information corresponding to the target vehicle control instruction.

[0109] The first detection information acquisition module 80 is used to obtain the first detection information based on the instruction feature information and the standard instruction feature information.

[0110] The dynamic traffic baseline information acquisition module 90 is used to obtain dynamic traffic baseline information based on historical vehicle control network traffic information.

[0111] The second detection information acquisition module 100 is used to obtain the second detection information based on the dynamic traffic baseline information.

[0112] The network intrusion detection result acquisition module 110 is used to obtain network intrusion detection results based on the first detection information and the second detection information.

[0113] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.

[0114] This application provides a network intrusion detection device, which includes a processor and a memory. The memory stores at least one instruction, at least one program, code set, or instruction set. The at least one instruction, at least one program, code set, or instruction set is loaded and executed by the processor to implement the network intrusion detection method provided in the above method embodiments.

[0115] Memory can be used to store software programs and modules. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory. Memory can primarily include a program storage area and a data storage area. The program storage area can store the operating system, application programs required for the functions, etc.; the data storage area can store data created based on the use of the device, etc. Furthermore, memory can include high-speed random access memory, and can also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, memory can also include a memory controller to provide the processor with access to the memory.

[0116] The network intrusion detection device can be a server. This application embodiment also provides a schematic diagram of a server structure. Please refer to [link / reference]. Figure 8 The server 800 is used to implement the data processing method provided in the above embodiments. The server 800 can vary significantly due to different configurations or performance, and may include one or more processors 810 (e.g., one or more processors) and storage 830, and one or more storage media 820 (e.g., one or more mass storage devices) for storing applications 823 or data 822. The memory 830 and storage media 820 can be temporary or persistent storage. The program stored in the storage media 820 may include one or more modules, each module including a series of instruction operations on the server. Furthermore, the processor 810 may be configured to communicate with the storage media 820 and execute a series of instruction operations in the storage media 820 on the server 800. The server 800 may also include one or more power supplies 860, one or more wired or wireless network interfaces 850, one or more input / output interfaces 840, and / or one or more operating systems 821, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.

[0117] Embodiments of this application also provide a computer-readable storage medium, which can be disposed in a server to store at least one instruction, at least one program, code set, or instruction set related to implementing a data processing method in the method embodiments. The at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the network intrusion detection method provided in the above method embodiments.

[0118] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0119] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system and server embodiments are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0120] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A network intrusion detection method, characterized in that, The method includes: The system acquires a target vehicle control command, the command feature information corresponding to the target vehicle control command, historical vehicle control network traffic information, and the actual vehicle control network traffic value corresponding to the target vehicle control command. The command feature information characterizes the behavior control sequence corresponding to the target vehicle control command. The historical vehicle control network traffic information is the vehicle control network traffic information within a preset historical time period. The target vehicle control command is the vehicle control command to be detected in the communication data between the vehicle control terminal and the server. The behavior control sequence of the vehicle control command has uniqueness. Based on the instruction feature information and the standard instruction feature information, first detection information is obtained, wherein the standard instruction feature information characterizes the standard behavior control sequence corresponding to the target vehicle control instruction; Based on the historical vehicle control network traffic information, dynamic traffic baseline information is obtained; The second detection information is obtained based on the dynamic traffic baseline information and the actual vehicle control network traffic value; Based on the first detection information and the second detection information, the network intrusion detection result is obtained.

2. The method according to claim 1, characterized in that, The step of obtaining the first detection information based on the instruction feature information and the standard instruction feature information includes: Based on the instruction feature information, feature sequence information corresponding to the target vehicle control instruction is obtained, wherein the feature sequence information is sorting information that sorts the instruction feature information; The first detection information is obtained based on the feature sequence information and the standard feature sequence information corresponding to the standard instruction feature information.

3. The method according to claim 2, characterized in that, The step of obtaining the first detection information based on the feature sequence information and the standard feature sequence information corresponding to the standard instruction feature information includes: The first detection information is obtained by cross-matching the feature sequence information with the standard feature sequence information.

4. The method according to claim 1, characterized in that, The step of obtaining the second detection information based on the dynamic traffic baseline information and the actual vehicle control network traffic value includes: Based on the dynamic traffic baseline information, the predicted vehicle control network traffic value corresponding to the execution of the target vehicle control command is obtained; The second detection information is obtained based on the predicted vehicle control network traffic value and the actual vehicle control network traffic value.

5. The method according to claim 4, characterized in that, The step of obtaining the second detection information based on the predicted vehicle control network traffic value and the actual vehicle control network traffic value includes: Based on the predicted vehicle control network traffic value and the actual vehicle control network traffic value, a comparison result between the predicted vehicle control network traffic value and the actual vehicle control network traffic value is obtained; Based on the comparison results, the second detection information is obtained.

6. A network intrusion detection device, characterized in that, The device includes: The data acquisition module is used to acquire the target vehicle control command, the command feature information corresponding to the target vehicle control command, historical vehicle control network traffic information, and the actual vehicle control network traffic value corresponding to the target vehicle control command. The command feature information represents the behavior control sequence corresponding to the target vehicle control command. The historical vehicle control network traffic information is the vehicle control network traffic information within a preset historical time period. The target vehicle control command is the vehicle control command to be detected in the communication data between the vehicle control terminal and the server. The behavior control sequence of the vehicle control command has uniqueness. The first detection information determination module is used to obtain first detection information based on the instruction feature information and the standard instruction feature information, wherein the standard instruction feature information characterizes the standard behavior control sequence corresponding to the target vehicle control instruction; The dynamic traffic baseline information determination module is used to obtain dynamic traffic baseline information based on the historical vehicle control network traffic information. The second detection information determination module is used to obtain second detection information based on the dynamic traffic baseline information and the actual vehicle control network traffic value; The detection result determination module is used to obtain the network intrusion detection result based on the first detection information and the second detection information.

7. A network intrusion detection device, characterized in that, The method includes a processor and a memory, wherein the memory stores at least one instruction, at least one program, a code set, or an instruction set, and the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the network intrusion detection method as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction or at least one program segment, which is loaded and executed by a processor to implement the network intrusion detection method as described in any one of claims 1 to 5.