A cloud-cooperative network intrusion feature capture method based on bus domain controller

Through the cloud-collaborative network intrusion feature capture method based on the bus domain controller, the problem of scheduling out of control of the bus system under network attacks was solved, rapid response and effective defense against DDoS attacks were achieved, and the security and operational efficiency of the system were improved.

CN116827667BActive Publication Date: 2025-09-23XIAMEN KING LONG UNITED AUTOMOTIVE IND CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310952454.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-31
Publication Date
2025-09-23
Estimated Expiration
2043-07-31

AI Technical Summary

Technical Problem

Existing technologies are unable to effectively deal with cyber attacks on public transportation systems, especially under closed management, which makes it impossible to capture network intrusion characteristics, resulting in an inability to quickly respond and alleviate scheduling out-of-control problems.

Method used

A cloud-collaborative network intrusion feature capture method based on the bus domain controller is adopted. By collecting characteristic information of vehicles and intersection facilities, machine learning is used to set floating thresholds, and radial basis functions are combined to simulate attack targets in real time. The defense strategy is adjusted and defense measures are deployed synchronously at the V2X service base station and the vehicle domain controller.

Benefits of technology

It achieves real-time network intrusion feature capture and defense for the public transportation system, improves the ability to identify and mitigate DDoS attacks, and reduces network resource consumption and operational efficiency loss.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116827667B_ABST
    Figure CN116827667B_ABST
Patent Text Reader

Abstract

A cloud-coordinated network intrusion feature capture method based on a public transportation domain controller includes: 1. Collecting feature information based on the spatiotemporal flow of the vehicle network; 2. Extracting useful information from multiple dimensions and setting a floating threshold based on machine learning for abnormal information to adaptively form machine-discriminative features suitable for the current attack type; 3. Using radial basis functions to simulate the attacker's attack target in real time, synchronously adjusting the defense strategy and implementing it simultaneously on the V2X service base station and the vehicle's domain controller. Based on the operational characteristics of public transportation systems, this method designs probe parameters centered around maximizing the interests of the suspected attacker. Using radial basis functions, it simulates the threat level (Threat_degree) of the attacker's attack target to the entire public transportation system in real time, thereby enabling adjustments to the defense response based on the evolving offensive and defensive situation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of vehicle networking security technology, and more specifically to a cloud-coordinated network intrusion capture method based on a public transportation domain controller. Background Art

[0002] Existing research applies artificial intelligence and algorithms based on eigenvalue distribution to conduct in-depth analysis of this dataset and identify normal and attack clusters. A common approach to countering traditional network attacks begins by obtaining the intrusion detection algorithm's judgment of suspicious traffic. If suspicious traffic is identified as attack traffic, the attack type is analyzed. Next, mitigation strategies are developed based on the attack type, such as traffic scrubbing and service redirection. Finally, the planned attack mitigation strategies are distributed to switches, which then execute the strategies to mitigate the attack. This consumes considerable network resources.

[0003] However, due to the closed management nature of public transportation information systems, it is impossible to sample information about all cyberattacks, resulting in a lack of information dimensions. Artificial intelligence is not very practical in capturing the characteristics of network intrusion data. Furthermore, even if a bus operation command system, which relies on V2X service base stations for information and positioning services, confirms a cyberattack, it lacks appropriate emergency response measures to mitigate or resolve the resulting out-of-control scheduling issues. This requires deploying a method and mechanism for rapidly capturing the causes of network intrusions and analyzing their purpose, based on the resource characteristics and management needs of the bus intelligent command network, in addition to traditional systems, along with a coordinated domain controller device, to effectively defend against cyberattacks on intelligent bus systems. To this end, we provide a cloud-based collaborative network intrusion feature capture method based on a bus domain controller. Summary of the Invention

[0004] The present invention provides a cloud-coordinated network intrusion capture method based on a public transportation domain controller, aiming to solve the problem that the existing artificial intelligence for capturing network intrusions cannot be used for public transportation systems to deal with network attacks.

[0005] The present invention adopts the following technical solutions:

[0006] A cloud-coordinated network intrusion feature capture method based on a public transportation domain controller includes the following steps:

[0007] Step 1: Collect feature information based on the spatiotemporal flow of the vehicle network;

[0008] Step 2: Extract useful information from multiple dimensions and set a floating threshold based on machine learning for abnormal information, adaptively forming machine-recognized features suitable for the current attack type. This includes: 2.1. Setting parameters for hypothetical attack traffic flow and hypothetical attack loss of public transportation operating efficiency; 2.2. Designing probe parameters to maximize the interests of the suspected attacker.

[0009] Step 3: Execution of attack and defense strategies;

[0010] Step 4: Use radial basis functions to simulate the attacker's attack target in real time, adjust the defense strategy synchronously, and deploy and execute it simultaneously on the V2X service base station and the vehicle's domain controller;

[0011] Step 5: Verify the DDoS defense performance of the selected method.

[0012] The above-mentioned step 1 specifically includes: 1.1. Collecting information on public buses, including summarizing bus models equipped with V2X interaction equipment; 1.2. Collecting information on V2X facilities at intersections related to bus operation and scheduling. The V2X facilities include 5Gv2x service base stations that provide bus positioning and information services, intersection monitoring sensors, edge computing equipment, and smart bus stations; 1.3. Identifying the V2X service base stations around the bus routes selected in step 1.2 and collecting information security information.

[0013] The hypothetical attack traffic parameters in step 2.1 above include: a. The time t1 from the initiation of the attack to the recognition of the attack; b. The time t2 from the recognition of the attack to the deployment of mitigation measures; c. The time t3 for the mitigation measures to take effect; d. The time t4 from the cessation of the attack to the removal of the mitigation measures; e. The channel capacity lost before the attack is launched, Lost_f1ow1, before the mitigation measures are taken, calculated as a percentage; f. The sum of the network traffic capacity lost due to the mitigation measures taken by the feint attack plus the remaining attack effects, Lost_flow2, calculated as a percentage; g. The channel capacity actually lost between the cessation of the attack and the removal of the mitigation measures, Lost_flow3; h. The current traffic domain value k1 that triggers the judgment that the attack is under attack.

[0014] The hypothetical attack bus operation efficiency loss parameters in step 2.1 above include: ① bus line load parameter line_load: Among them: line station id∈n, idn is the number of passengers boarding at each station; ② The relevant data of the attacker can use the crowd density formula to calculate the expected value of line_load line_load_p: line_load_p = the crowd density value 500 meters around the station in the public information * crowd density ratio; ③ The bus line vehicle SOC (vehicle remaining power status) line_SOC; ④ The bus line operation efficiency loss effic_lost: effic_lost = line_load-line_load_p; ⑤ The overall traffic efficiency is reduced due to the bus breaking down due to the network attack, disrupting the normal traffic flow: effic_lost_k = e^(-((line_load-line_load_p) / line_load_p)^2*0.5 / (1+line_SOC)^2).

[0015] The probe parameters in step 2.2 above include: the ID of the attacked line (att_line_id), the start time of the attack on the specific line (att_line_id_time_sta), the estimated end time of the attack on the specific line (att_line_id_time_end_p), the V2X serving base station ID of the attacked line (att_line_id_serve_id), the ID of the vehicle affected by the attack (att_line_id_veh_id), and the vehicle parameter deviation (att_line_id_serve_id_dev).

[0016] The focusing process of the probe parameters in the above step 2.2 is as follows: (1) By calculating the traffic anomaly characteristics, the attacked bus line att_line_id and the v2x service base station att_line_id_serve_id of the attacked line can be finally determined; (2) After determining the bus line, the start and expected end time of the attack are calculated: att_line_id_time_end_p = att_line_id_time_sta + t5; (3) Through the attacked base station and the vehicle connected to it, the vehicle affected by the attack, att_line_id_veh_id, can be determined; (4) By determining the attacked vehicle, the affected vehicle parameters are determined: att_line_id_serve_id_dev = the bus state parameters of this vehicle - the big data expected state parameters.

[0017] Furthermore, from step 2.1, we can see that the characterization factor (line_load - line_load_p) / line_load_p, which maximizes the change in the number of passengers on a bus route, and the characterization factor 1+line_SOC of the bus's own battery SOC are the two core indicators that drive the maximization of attack benefits. Our actual loss channel capacity per unit time, Lost_flow5, is the main indicator for evaluating the effectiveness of the attacker's means. Combined with the affected vehicle parameters determined by the attacked vehicle in step 2.2, the calculation formula for the characterization factor of the bus's own battery SOC is set to: 1+line_SOC / att_line_id_serve_id_dev. When the vehicle network attack defense system is compromised to the extent that it can affect bus messages and even chassis control information, the vehicle is broken down, which is equivalent to an SOC of 0, and the att_line_id_serve_id_dev value is extremely large, and line_SOC / att_line_id_serve_id_dev is 0.

[0018] The formula of the radial basis function in the above step 4 is: Threat_degree=e^(-((line_load-line_load_p) / line_load_p)^2*0.5 / (1+line_SOC / att_line_id_serve_id_dev)^2).

[0019] The specific process of adjusting the defense strategy in step 4 above and deploying it at the v2x service base station is as follows: 4.2.1. Investigate suspicious attack ports on the base station; 4.2.2. Invoke the intersection epidemic prevention system for artificial intelligence identification and monitoring; 4.2.3. Use the artificial intelligence vehicle and pedestrian dynamic capture technology at the intersection to identify the dynamic parameters of human targets and determine whether they are the perpetrators of information attacks.

[0020] The specific steps for adjusting the defense strategy in step 4 above and synchronously deploying and executing it on the vehicle's domain controller are as follows: Through the parameter analysis in step 4.2.3, if the vehicle control system and message system of the bus have not been compromised and the conditions for implementing defense deployment on its domain controller are met, the domain controller security defense instructions will be issued through the preliminary security channel, the defense strategy driver in the domain controller will be activated, and the regular message ports will begin to be closed, and the bus will enter the emergency operation state.

[0021] It can be seen from the above description of the present invention that, compared with the prior art, the present invention has the following advantages:

[0022] Based on the characteristics of public transportation system operation, the present invention designs probe parameters around maximizing the interests of the suspected attacker and uses radial basis functions to simulate the threat degree (Threat_degree) of the attacker's attack target to the entire public transportation system in real time, so that the defense response can be adjusted according to the changing attack and defense situation. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 This is a structural block diagram of the public transportation vehicle communication system of the present invention.

[0024] Figure 2 This is a schematic diagram of the public transportation characteristic information collected by the public transportation system of the present invention.

[0025] Figure 3 This is a schematic diagram of the identification of the V2X service base stations around the bus routes selected by the present invention.

[0026] Figure 4 This is a coordinate diagram of the number of Packet-In messages and time in the present invention.

[0027] Figure 5 This is a schematic diagram of characteristic information of threats to the public transportation system of the present invention.

[0028] Figure 6 This is a three-dimensional map of the intersection where the threatened public transport vehicle is located, identified by the artificial intelligence of the present invention.

[0029] Figure 7 This is a schematic diagram of the artificial intelligence of the present invention identifying and monitoring a human-shaped target at an intersection. DETAILED DESCRIPTION

[0030] The following describes specific embodiments of the present invention with reference to the accompanying drawings. Numerous details are provided below to provide a comprehensive understanding of the present invention, but those skilled in the art will appreciate that the present invention can be practiced without these details. Well-known components, methods, and processes are not described in detail below.

[0031] The present invention provides a cloud-based collaborative network intrusion feature capture method based on a public transportation domain controller. Figure 1 Buses are equipped with a domain controller integration system, a vehicle-mounted system, and a TBOX. These buses utilize three primary communication channels: 1. Wireless (Wi-Fi or 4G / 5G) between the TBOX and the vehicle-mounted system; 2. Onboard Ethernet communication between the CGW and each domain controller; and 3. CAN bus network. Network intrusions into these three communication channels primarily utilize contact attacks, near-field attacks, and remote attacks.

[0032] The cloud-coordinated network intrusion feature capture method based on the bus domain controller specifically includes the following steps:

[0033] Step 1: Collect feature information based on the spatiotemporal flow of the Internet of Vehicles.

[0034] The above step 1 specifically includes:

[0035] 1.1. Collect information about public buses. For example, collect information about buses equipped with V2X interactive devices. Figure 1 The information polling window below the present invention provides real-time feedback as follows (the license plate number is a randomly generated pseudo code):

[0036] ID1 | Min D21476C | Latitude and longitude: 118.204675, 24.633898 | Can vehicle speed: 24.8 | Battery voltage: 608.1 | Remaining power: 16% | Battery current: -195.7 | Vehicle type: XMQ6601AGBEVL1

[0037] ID2 | Min D74191J | Latitude and longitude: 118.207132, 24.633915 | Vehicle speed: 6.2 | Battery voltage: 608.4 | Remaining power: 41% | Battery current: -209.64 | Vehicle model: XMQ6850BGBEVM1

[0038]

[0039] ID36 | Min D53824F | Latitude and longitude: 118.023382, 24.483688 | Can vehicle speed: 49.6 | Battery voltage: 608.3 | Remaining power: 34% | Battery current: -192.71 | Vehicle model: XMQ6106AGBEVM1

[0040] The above information represents a certain dimension (under the premise of effective operation of the v2x function) to query the vehicle's operating information and prepare data for subsequent comprehensive analysis. Figure 2 The box in the map interface reflects the location of the selected vehicle model on the map. At the same time, when the system determines that the signal traffic is unstable or there are other abnormalities, the color of the box will gradually change from cold tones to warm tones based on the severity of the abnormality determined by the system.

[0041] 1.2. Collect information on V2X facilities at intersections related to bus operation and dispatch (5Gv2x service base stations that provide bus vehicle positioning and information services, intersection monitoring sensors, edge computing devices, smart bus stations, etc.), see Figure 2 Left information bar.

[0042] The selected (or polled) bus route is highlighted, and the number of passengers at each stop at the current polling beat is displayed on the right side of the interface:

[0043] First Wharf (BRT): 20 people, Kaihe Road Intersection (BRT): 10 people, Sibei (BRT): 4 people, Douxi Road (BRT): 25 people, Ershi (BRT): 2 people, Wenzao (BRT): 8 people, Jinbang Park (BRT): 20 people, Railway Station (BRT): 11 people, Lianban (BRT): 5 people, Longshan Bridge (BRT): 0 people, Wolong Xiaocheng (BRT): 20 people, Dongfang Villa (BRT): 0 people, Caitang (BRT): 0 people, Jinshan (BRT): 13 people, Municipal Administrative Service Center (BRT): 9 people, Shuangshi Middle School (BRT): 7 people, Xianhou (BRT): 18 people, Gaoqi Airport (BRT): 1 Airport (BRT): 6 people, T4 Terminal (BRT): 19 people, Fenglin (BRT): 2 people, Dong'an (BRT): 2 people, Houtian (BRT): 8 people, Dongting (BRT): 8 people, Meifeng (BRT): 19 people, Caidian (BRT): 23 people, Panti (BRT): 21 people, Binhai New City (Xi Ke) Hub Station (BRT): 17 people, Guanxun (BRT): 24 people, Light Industry and Food Park (BRT): 2 people, Sikouzhen (BRT): 18 people, Industrial Concentration Zone (BRT): 24 people, Third Hospital (BRT): 25 people, Chengnan (BRT): 2 people, Tong'an Hub Station (BRT): 1 person.

[0044] Collect the operation information of the v2x service base station equipment selected or polled according to specific dimensions. By storing the Packet-In information and flow table feature information, it can better predict and detect attacks.

[0045] Figure 3 The v2x service base stations around the bus routes selected in step 1.2 are identified and their information security status is collected. Figure 3 The network traffic in the image is marked with A (the greater the traffic load, the redder the color). The data structure of the Packet-In message is as follows:

[0046]

[0047]

[0048] Table 1. V2X service base station traffic situation table

[0049] Regarding "flow table characteristic information" and "attacker characteristic information", since the information used by network operators for network attack mitigation and positioning has a low relevance to bus operation safety in the present invention, the present invention only performs probabilistic characteristic statistics on "Packet-In message frequency statistics".

[0050] In traditional network attack and defense scenarios, when attackers launch attacks at low rates, early warning and monitoring mechanisms based on packet-in rates are not responsive enough, allowing attack traffic to successfully attack servers and disrupt normal operations. Therefore, it's necessary to combine the packet-in message frequency with other system information to effectively defend against and mitigate the impact of attacks on bus operation and dispatch systems. Figure 4 It can be seen that there is a significant jump in information load during the period from 780s to 840s.

[0051] The following example imports a real map from OpenStreetMap and selects a test area. In this area, a virtual v2x service base station is selected and used Figure 2 The signal tower symbol "A" indicates that Figure 3 In the figure, the circle surrounding the v2x service base station represents the communication coverage of the v2x service base station. The latitude and longitude of these v2x service base stations and their communication coverage are shown in Table 2. After determining the latitude and longitude and communication coverage of the v2x service base station, the distance between all vehicles and the v2x service base station is calculated every second based on the trajectory dataset of the monitored buses in the system. In this way, the behavior information (such as speed, time, location, vehicle ID, and vehicle type) of all vehicles within the communication range of the v2x service base station is obtained. In this case, the traffic flow observed by each v2x service base station is obtained.

[0052] Use open source tools to simulate DDoS attacks in the Internet of Vehicles and obtain data sets for each time period.

[0053] v2x service base station ID latitude longitude Communication coverage 4a14c6b99cf7cc6a1c1d112c0 24.546552 118.154111 500(m) 4a14c6b99cf7cc6a1c1d112c1 24.535102 118.148108 500(m) 4a14c6b99cf7cc6a1c1d112c2 24.494329 118.146947 500(m) 4al4c6b99cf7cc6a1c1d112c3 24.482768 118.146554 500(m) 4a14c6b99cf7cc6a1c1d112c4 24.489899 118.146202 500(m) 4a14c6b99cf7cc6a1c1d112c5 24.475386 118.093712 500(m) 4a14c6b99cf7cc6a1c1d112c6 24.466847 118.100225 500(m) 4a14c6b99cf7cc6a1c1d112c7 24.463053 118.080003 500(m) 4a14c6b99cf7cc6a1c1d112c8 24.479557 118.131015 500(m) 4a14c6b99cf7cc6a1c1d112c9 24.722238 118.14053 500(m) 4a14c6b99cf7cc6a1c1d112c10 24.604354 118.119837 500(m) 4a14c6b99cf7cc6a1c1d112c11 24.687668 118.129724 500(m) 4a14c6b99cf7cc6a1cld112c12 24.677358 118.1368 500(m)

[0054] Table 2. Latitude and longitude of v2x service base stations and their communication coverage (experimental data)

[0055] Step 2: Given that the cybersecurity industry often uses four metrics—adjusted Rand coefficient, adjusted mutual information, F1-measure, and accuracy—to evaluate an algorithm's ability to distinguish between normal and abnormal connections, when new DDoS attack types emerge, trained classifier models often fail to effectively distinguish between normal and abnormal data flows. This step extracts useful information from multiple dimensions and sets a variable threshold for abnormal information based on machine learning. This adaptively generates machine-recognized features tailored to the current attack type, thereby improving the performance of DDoS attack identification and targeted mitigation measures.

[0056] 2.1、Setting up hypothetical attack parameters.

[0057] 2.1.1 Attack traffic parameter settings:

[0058] In this case, the attacker will first conduct a exploratory attack on several points (base stations). Similarly, machine intelligence will identify several key parameters that we use to identify the attack and take measures:

[0059] a. The time t1 from the time the attack is launched to the time we recognize we are being attacked;

[0060] b. The time t2 from when we identify the attack to when we deploy mitigation measures;

[0061] c. The effective time of the mitigation measures, t3;

[0062] d. The time t4 from the cessation of the attack to the lifting of mitigation measures;

[0063] e. Lost_flow1: The channel capacity lost before we take action when the attack is launched, expressed as a percentage:

[0064] For example, if the attack traffic is 7 times the normal traffic, Lost_flow1 = (100 / (7+1)*7) / 100 = 87.5%;

[0065] f. The sum of the network flow capacity lost by launching a feint attack due to mitigation measures and the remaining attack effect is Lost_flow2, calculated as a percentage:

[0066] For example, if the attack traffic is 7 times the normal traffic, blocking the suspected attack address can reduce the attack traffic by 89.1%, but this will result in 20% of the channel resources being blocked. In this case, the actual channel capacity loss is: Lost_flow2 = ((100 / (7+1)*7)*(1-89.1%)+100*20%) / 100 = 29.53%;

[0067] It can be seen that even if the attack is quickly contained, nearly one-third of the traffic capacity is still suppressed during the period from the start of the attack to the end of the attack, and from the adoption of mitigation measures to the lifting of the measures.

[0068] g. Lost_flow3, the actual channel capacity loss between the cessation of the attack and the lifting of mitigation measures: 20% in this example;

[0069] h. The traffic threshold value k1 that currently triggers our judgment of being attacked;

[0070] Based on the above parameters, the attacker can determine the attack duration t5 and calculate the actual loss of channel capacity per unit time (Lost_flow5) during the complete attack period (t5 + t4):

[0071] Lost_flow5=(t1+t2+t3)*Lost_flow1+(t5-(t1+t2+t3))*Lost_flow2+t4*Lost_flow3 / (t5+t4)

[0072] The attack effect indicator of the attacker in terms of traffic is based on the maximization of Lost_flow5.

[0073] 2.1.2. Parameter settings for hypothetical attack on bus operation efficiency loss:

[0074] ①Bus line load parameter line_load: Where: line station id∈n, idn is the number of passengers boarding at each station;

[0075] ② The attacker's relevant data can be used to calculate the expected line_load value line_load_p using the crowd density formula: line_load_p = the crowd density value 500 meters around the site in public information * crowd density ratio;

[0076] For example: line_load_p = 1000 people / square kilometer * 0.0023 (Note: This population density->passenger boarding mapping ratio is 0.0023, which is a big data statistical constant). The expected value of line_load in the current time period is 2.3 people.

[0077] ③Bus line vehicle SOC (vehicle remaining power) line_SOC;

[0078] ④Bus line operation efficiency loss effic_lost:

[0079] effic_lost=line_load-line_load_p;

[0080] ⑤ The effic_lost_k caused by the bus breakdown due to the cyber attack, disrupting the normal traffic flow and resulting in a decrease in overall traffic efficiency:

[0081] effic_lost_k = e^(-((line_load-line_load_p) / line_load_p)^2*0.5 / (1+line_SOC)^2) (Note: Considering the extreme case, when line_SOC is close to 0 and the entire bus line is paralyzed and the number of passengers is 0, the traffic efficiency drops the most, and effic_lost_k drops to the minimum);

[0082] effic_lost_k is called key loss because it can cause the observed system to lose extension;

[0083] 2.2. The defender's focus on setting probe parameters for the "Denial of Service attack (Denial of Service attack method that makes the attacked system unable to provide normal services) defense system".

[0084] The present invention does not involve a method of combining unknown device types and traffic to monitor and identify attack device IPs, but instead designs probe parameters around maximizing the interests of suspected attackers.

[0085] 2.2.1. Target parameters captured by the defender's information feature detection;

[0086] Compared with the mainstream information security probe solutions in the industry (full traffic processing, asset and service discovery, traffic and access relationship discovery, and fine-grained traffic auditing), this embodiment is different in that it does not perform fine-grained audits on all traffic, but instead focuses on detecting the attack point and attack duration t5 of the attacker.

[0087] The main task of this invention is to capture the attack characteristics that cause the greatest interference to the daily operation of public transportation, and then screen out the attacker's key attack routes and times, as well as the duration of possible attacks, and then make defensive emergency plan action deployments in a short time. The main parameters are:

[0088] Attacked line ID: att_line_id;

[0089] The time when a specific line is attacked: att_line_id_time_sta;

[0090] Estimated end time of attack on a specific line: att_line_id_time_end_p;

[0091] The v2x serving base station ID of the attacked line: att_line_id_serve_id;

[0092] The id of the vehicle affected by the attack: att_line_id_veh_id;

[0093] Vehicle parameter deviation: att_line_id_serve_id_dev.

[0094] The system focusing process is as follows:

[0095] (1) By calculating the traffic anomaly characteristics, we can finally determine: the attacked bus line att_line_id and the attacked base station att_line_id_serve_id;

[0096] (2) After determining the bus line, start calculating the start and expected end time of the attack: att_line_id_time_end_p = att_line_id_time_sta + t5;

[0097] (3) The attacked base station and its linked vehicle can be used to determine: the attacked vehicle att_line_id_veh_id;

[0098] (4) Determine the affected vehicle parameters by identifying the attacked vehicle: att_line_id_serve_id_dev = bus state parameters of this vehicle - big data expected state parameters.

[0099] Step 3: Execution of attack and defense strategies.

[0100] From step 2.1.2 above, we can see that the factor representing the maximum change in the number of passengers on a bus route, (line_load - line_load_p) / line_load_p, and the factor representing the battery SOC of the bus itself, 1 + line_SOC (where +1 represents regularization), are the two core indicators that drive the maximization of attack benefits. The actual channel loss capacity per unit time, Lost_flow5, is the main indicator for evaluating the effectiveness of the attacker's means.

[0101] Combined with the affected vehicle parameters determined in step 2.2.1, the formula for calculating the bus's battery SOC characteristic factor is set to: 1 + line_SOC / att_line_id_serve_id_dev. When the vehicle's cyberattack defense system is compromised to the point where it can affect bus messages and even chassis control information, the vehicle is disabled, equivalent to an SOC of 0 and a maximum att_line_id_serve_id_dev value, with line_SOC / att_line_id_serve_id_dev being 0.

[0102] Step 4: Assume that the attacker is blindly trying various actions through the intelligent agent, and then conduct a comparative analysis based on the impact of the actions on the indicators. Finally, an attack strategy is formulated to maximize the effect of the attacker's target. During the execution process, relevant parameters are continuously adjusted to lock in the goal of maximizing the attack effect on a certain target area.

[0103] The present invention simulates the attacker's attack target in real time through radial basis functions, adjusts the defense strategy synchronously, and deploys and executes it synchronously in the V2X service base station and the vehicle's domain controller.

[0104] 4.1. Use radial basis functions to simulate the threat degree (Threat_degree) of the attacker’s attack target to the entire public transportation system in real time, so that the defense response can be adjusted according to the changing attack and defense situation.

[0105] The radial basis function formula for representing the degree of attack threat is: Threat_degree = e^(-((line_ioad-line_load_p) / line_load_p)^2*0.5 / (1+line_SOC / att_line_id_serve_id_dev)^2).

[0106] The above function expressions are shown in Figure 5 . Figure 5 The upper left corner is the result of evaluating the above formula, where:

[0107] line_load = 173.278828;

[0108] line_load_p=6.617264;

[0109] line_soc=0.022647;

[0110] att_line_id_serve_id_dev=0.593027.

[0111] Further query of the parameter table shows that the attacker has the following strategy: Figure 5 As shown:

[0112] The bus route code is: f5b531573370194b9ce32134;

[0113] The names of the attacking bus routes are: Route 938 (Shangtouting-Shuangqiao Mingzhu);

[0114] The attack base station is: f5b531573370194b9ce321340.

[0115] Infer through parameters:

[0116] A. The number of people on the line has increased from 6.6 in normal times to 173, so there must be an emergency or an event taking place nearby.

[0117] B. The battery condition of the vehicle on this route, line_SOC = 0.022647, has dropped to 2%, indicating a severe battery shortage. This may be caused by an attack on the management and dispatching system or the vehicle bus.

[0118] C. att_line_id_serve_id_dev=0.593027 shows that the vehicle bus abnormality is not serious.

[0119] It can be preliminarily determined that the bus dispatching system was effectively attacked, causing the vehicles to lose power, which in turn caused the buses to consume all the power of their power batteries and paralyze the line.

[0120] 4.2. Adjust the defense strategy and deploy it on the v2x service base station:

[0121] 4.2.1. Deploy the base station numbered f5b531573370194b9ce321340 to conduct a check on suspicious attack ports.

[0122] 4.2.2. Call the intersection defense system for artificial intelligence recognition and monitoring, see Figure 5 Lower left corner, Figure 6 、 Figure 7 lower left corner;

[0123] pass Figure 6 The artificial intelligence vehicle model recognized that a military emergency convoy was passing through the attacked intersection and preliminarily determined that the anomaly at 4.1 was an emergency.

[0124] 4.2.3. Dynamic capture technology of artificial intelligence vehicles and pedestrians at intersections to identify Figure 7 The dynamic parameter of the humanoid target on the left is 0.110628. The smaller the parameter, the smaller the person's movements. If this person remains motionless at the intersection for a long time, he or she may be a person carrying out an information attack (further investigation is needed to determine whether he or she is carrying an information attack device).

[0125] 4.3. Adjust the defense strategy and deploy and execute it synchronously on the vehicle's domain controller;

[0126] Through the above parameter analysis, the vehicle control system and message system of the bus have not been breached, and the conditions for implementing defense deployment on its domain controller are met. Therefore, the domain controller security defense instruction is issued through the preliminary security channel, and the defense policy driver in the domain controller is activated, and the regular message port begins to be closed, and the bus enters the emergency operation state.

[0127] Step 5: Verify the DDoS defense performance of the selected method.

[0128] The above is only a specific implementation of the present invention, but the design concept of the present invention is not limited to this. Any non-substantial changes to the present invention using this concept shall be deemed as an infringement of the protection scope of the present invention.

Claims

1. A cloud-coordinated network intrusion feature capture method based on a public transportation domain controller, characterized in that: The following steps are involved: Step 1: Collect feature information based on the spatiotemporal flow of the vehicle network; Step 2: Extract useful information from multiple dimensions and set a floating threshold based on machine learning for abnormal information, adaptively forming machine identification features suitable for the current attack type; specifically, 2.

1. Set hypothetical attack traffic parameters and hypothetical attack bus operation efficiency loss parameters. The hypothetical attack bus operation efficiency loss parameters include: ① Bus ​​line load parameter line_load: line_load= , where: line station id n, idn is the number of passengers boarding at each stop; ② The attacker's relevant data uses the crowd density formula to calculate the expected line_load value line_load_p: line_load_p = the crowd density value 500 meters around the stop in public information * the crowd density ratio; ③ The remaining battery capacity of the vehicle line_SOC; ④ The loss of bus line operating efficiency effic_lost: effic_lost = line_load - line_load_p; ⑤ The overall traffic efficiency loss caused by the bus breakdown caused by the cyber attack, which disrupts normal traffic flow, effic_lost_k: effic_lost_k = e^(-((line_load - line_load_p) / line_load_p)^2*0.5 / (1+line_SOC)^2); 2.

2. The probe parameters are designed to maximize the interests of the suspected attacker; Step 3: Execution of attack and defense strategies; Step 4: Use radial basis functions to simulate the attacker's attack target in real time, adjust the defense strategy synchronously, and deploy and execute it simultaneously on the V2X service base station and the vehicle's domain controller; Step 5: Verify the DDoS defense performance of the selected method.

2. A cloud-coordinated network intrusion feature capture method based on a public transportation domain controller according to claim 1, characterized in that: The first step specifically includes: 1.

1. Collecting information on public buses, including summarizing bus models equipped with v2x interactive devices; 1.

2. Collecting information on v2x facilities at intersections related to bus operation and scheduling, including 5Gv2x service base stations that provide bus positioning and information services, intersection monitoring sensors, edge computing devices, and smart bus stations; 1.

3. Identifying the v2x service base stations around the bus routes selected in step 1.2 and collecting information security information.

3. The cloud-coordinated network intrusion feature capture method based on a public transportation domain controller according to claim 1 is characterized in that: The hypothetical attack traffic parameters of step 2.1 include: a. the length of time t1 from the launch of the attack to the time we recognize that we are under attack; b. the length of time t2 from the time we recognize that we are under attack to the time we deploy mitigation measures; c. the length of time t3 for the mitigation measures to take effect; d. the length of time t4 from the time the attack stops to the time the mitigation measures are lifted; e. the channel capacity Lost_flow1 lost before we take measures when the attack is launched, counted as a percentage; f. the sum of the network traffic capacity lost by taking mitigation measures due to launching a feint attack plus the remaining partial attack effects Lost_flow2, counted as a percentage; g. the channel capacity Lost_flow3 actually lost during the period from the cessation of the attack to the lifting of the mitigation measures; h. the traffic domain value k1 that currently triggers us to determine that we are under attack.

4. A cloud-coordinated network intrusion feature capture method based on a public transportation domain controller as claimed in claim 3, characterized in that: The probe parameters in step 2.2 include: the attacked line att_line_id, the start time of the attack on the specific line att_line_id_time_sta, the estimated end time of the attack on the specific line att_line_id_time_end_p, the v2x serving base station att_line_id_serve_id of the attacked line, the vehicle affected by the attack att_line_id_veh_id, and the vehicle parameter deviation att_line_id_serv_id_dev.

5. A cloud-coordinated network intrusion feature capture method based on a public transportation domain controller as claimed in claim 4, characterized in that: The focusing process of the probe parameters in step 2.2 is as follows: (1) By calculating the traffic anomaly characteristics, the attacked line att_line_id and the v2x service base station att_line_id_serve_id of the attacked line are finally determined; (2) After determining the bus line, the start and expected end time of the attack are calculated: att_line_id_time_end_p=att_line_id_time_sta+t5, t5 is the length of the attack duration; (3) Through the attacked base station and its linked vehicles, the vehicle affected by the attack att_line_id_veh_id is determined; (4) By determining the attacked vehicle, the affected vehicle parameters are determined: att_line_id_serve_id_dev=the bus state parameters of this vehicle-the expected state parameters of the big data.

6. The method for capturing cloud-based network intrusion signatures based on a public transportation domain controller according to claim 5, characterized in that: As shown in step 2.1, the factor representing the maximum change in the number of passengers on a bus route (line_load - line_load_p) / line_load_p and the factor representing the bus's battery SOC (1 + line_SOC) are the two core indicators that maximize the attack's benefits. Lost_flow5, the actual channel capacity lost per unit time, is the primary indicator for evaluating the attacker's effectiveness. Combined with the affected vehicle parameters determined by the attacked vehicle in step 2.2, the formula for calculating the factor representing the bus's battery SOC is set to: 1 + line_SOC / att_line_id_serve_id_dev. When the vehicle's network attack defense system is compromised to the point of affecting bus messages and even chassis control information, the vehicle's breakdown is equivalent to an SOC of 0, and the att_line_id_serve_id_dev value is extremely high, resulting in line_SOC / att_line_id_serve_id_dev being 0.

7. A method for capturing cloud-based network intrusion features based on a public transportation domain controller according to claim 6, characterized in that: The formula of the radial basis function in step 4 is: Threat_degree=e^(-((line_load-line_load_p) / line_load_p)^2*0.5 / (1+line_SOC / att_line_id_serve_id_dev)^2).

8. The cloud-coordinated network intrusion feature capture method based on a public transportation domain controller according to claim 1 is characterized in that: The specific process of adjusting the defense strategy in step 4 and deploying it at the v2x service base station is as follows: 4.2.

1. Checking the base station for suspicious attack ports; 4.2.

2. Calling the intersection epidemic prevention system for artificial intelligence identification and monitoring; 4.2.

3. Using the artificial intelligence vehicle and pedestrian dynamic capture technology at the intersection, identifying the dynamic parameters of the humanoid target, and determining whether it is the person carrying out the information attack.

9. A cloud-coordinated network intrusion feature capture method based on a public transportation domain controller as claimed in claim 8, characterized in that: The specific method of adjusting the defense strategy in step 4 and synchronously deploying and executing it on the vehicle's domain controller is as follows: through the parameter analysis in step 4.2.3, if the vehicle control system and message system of the public bus have not been compromised, the conditions for implementing defense deployment on its domain controller are met, and the domain controller security defense instruction is issued through the preliminary security channel. The defense strategy driver in the domain controller is activated, and the regular message port begins to be closed, and the public bus enters the emergency operation state.

Citation Information

Patent Citations

  • IOV intrusion attack detection method and system based on artificial intelligence behaviour analysis

    CN107948172A

  • An anomaly intrusion detection method for vehicle networking based on traffic flow density difference

    CN109005173A