Method and device for determining security level of controller in vehicle, and vehicle
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA FAW CO LTD
- Filing Date
- 2023-08-23
- Publication Date
- 2026-08-07
AI Technical Summary
[0005]本发明实施例提供了一种车辆中控制器的安全等级的确定方法、装置和车辆,以至少解决对控制器的安全等级进行确定的准确性低的技术问题
[0016]In this embodiment of the invention, a vehicle simulation model is run, wherein the simulation model is used to simulate the network environment of the vehicle, and the simulation model includes a controller in the vehicle. During the operation of the simulation model, vulnerability monitoring results obtained by performing vulnerability monitoring on the simulation model, and attack results obtained by attacking the simulation model, wherein the attack results are used to characterize the security performance of the simulation model; a monitoring level corresponding to the vulnerability monitoring results, and an attack level corresponding to the attack results are determined; based on the monitoring level and the attack level, the security level of the controller is determined. In other words, this invention simulates a vehicle to obtain a corresponding vehicle simulation model, determines the vulnerability monitoring results in the simulation model, and obtains the attack results (which can be defense results) obtained by attacking the controller. Based on the monitoring level corresponding to the vulnerability monitoring results and the attack level corresponding to the attack results, the security level of the controller is determined, thereby achieving the technical effect of improving the accuracy of determining the security level of the controller and solving the technical problem of low accuracy in determining the security level of the controller.
Smart Images

Figure CN116866081B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicles, and more specifically, to a method, apparatus, and vehicle for determining the safety level of a controller in a vehicle. Background Technology
[0002] Currently, with the development of intelligent connected vehicle technology, the vehicle network environment in which vehicles operate is becoming increasingly complex, involving more and more threat points, and vehicle security issues are becoming increasingly prominent. Therefore, risk identification and risk assessment of controllers are the foundation for the planning and development of vehicle information security functions.
[0003] In related technologies, the information security of vehicle controllers is usually assessed based on evaluation experience. However, relying solely on evaluation experience can easily lead to misjudgments, resulting in technical problems such as low accuracy in determining the security level of the controller.
[0004] There is currently no effective solution to the problem of low accuracy in determining the safety level of controllers in the existing technologies mentioned above. Summary of the Invention
[0005] This invention provides a method, apparatus, and vehicle for determining the safety level of a controller in a vehicle, to at least solve the technical problem of low accuracy in determining the safety level of the controller.
[0006] According to one aspect of the present invention, a method for determining the security level of a controller in a vehicle is provided. The method may include: running a simulation model of the vehicle, wherein the simulation model is used to simulate the network environment of the vehicle, and the simulation model includes a controller in the vehicle; during the operation of the simulation model, acquiring vulnerability monitoring results obtained by performing vulnerability monitoring on the simulation model, and acquiring attack results obtained by attacking the simulation model, wherein the attack results are used to characterize the security performance of the simulation model; determining a monitoring level corresponding to the vulnerability monitoring results, and determining an attack level corresponding to the attack results; and determining the security level of the controller based on the monitoring level and the attack level.
[0007] Optionally, the vulnerability monitoring results obtained from vulnerability monitoring of the simulation model include: obtaining vulnerability information obtained from vulnerability monitoring of the controller in the simulation model; and determining the correspondence between the vulnerability information and vehicle assets as the vulnerability monitoring results.
[0008] Optionally, determining the monitoring level corresponding to the vulnerability monitoring results includes: determining the impact level of the vulnerability in the vulnerability monitoring results, wherein the impact level is used to represent the degree of impact of the vulnerability on the driving safety performance of the vehicle; and determining the impact level as the monitoring result.
[0009] Optionally, the attack results obtained from attacking the simulation model include: determining the time and extent of the attack on the controller in the simulation model based on historical attack information, wherein the historical attack information is used to determine the attack type; and determining the attack results based on the historical attack information, the time of attack, and the extent of attack, wherein the attack results are used to determine the controller's defense capability against the attack.
[0010] Optionally, the attack result is determined based on historical attack information, the time of breach, and the degree of attack, including: determining the breach time threshold and the degree of attack threshold corresponding to the historical attack information; and determining the attack result based on the matching relationship between the breach time threshold and the breach time, and the matching relationship between the degree of attack threshold and the degree of attack.
[0011] Optionally, the security level of the controller can be determined based on the monitoring level and the attack level, including: looking up the security level in the database based on the monitoring level and the attack level.
[0012] Optionally, before running the vehicle simulation model, the method further includes: constructing a vehicle network test range for the vehicle; connecting the controller to the vehicle network test range to obtain the simulation model.
[0013] According to another aspect of the present invention, a device for determining the security level of a controller in a vehicle is also provided. The device may include: a running unit for running a simulation model of the vehicle, wherein the simulation model simulates the network environment of the vehicle and includes a controller in the vehicle; an acquisition unit for acquiring vulnerability monitoring results obtained by performing vulnerability monitoring on the simulation model and acquiring attack results obtained by attacking the simulation model during the operation of the simulation model, wherein the attack results are used to characterize the security performance of the simulation model; a first determining unit for determining a monitoring level corresponding to the vulnerability monitoring results and an attack level corresponding to the attack results; and a second determining unit for determining the security level of the controller based on the monitoring level and the attack level.
[0014] According to another aspect of the present invention, a computer-readable storage medium is also provided. The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to perform the method for determining the security level of a controller in a vehicle according to the embodiments of the present invention.
[0015] According to another aspect of the present invention, a processor is also provided. The processor is used to run a program, wherein the program, when running, executes the method for determining the safety level of a controller in a vehicle according to the embodiments of the present invention.
[0016] In this embodiment of the invention, a vehicle simulation model is run, wherein the simulation model is used to simulate the network environment of the vehicle, and the simulation model includes a controller in the vehicle. During the operation of the simulation model, vulnerability monitoring results obtained by performing vulnerability monitoring on the simulation model, and attack results obtained by attacking the simulation model, wherein the attack results are used to characterize the security performance of the simulation model; a monitoring level corresponding to the vulnerability monitoring results, and an attack level corresponding to the attack results are determined; based on the monitoring level and the attack level, the security level of the controller is determined. In other words, this invention simulates a vehicle to obtain a corresponding vehicle simulation model, determines the vulnerability monitoring results in the simulation model, and obtains the attack results (which can be defense results) obtained by attacking the controller. Based on the monitoring level corresponding to the vulnerability monitoring results and the attack level corresponding to the attack results, the security level of the controller is determined, thereby achieving the technical effect of improving the accuracy of determining the security level of the controller and solving the technical problem of low accuracy in determining the security level of the controller. Attached Figure Description
[0017] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this invention, illustrate exemplary embodiments of the invention and are used to explain the invention, but do not constitute an undue limitation of the invention. In the drawings:
[0018] Figure 1 This is a flowchart of a method for determining the safety level of a controller in a vehicle according to an embodiment of the present invention;
[0019] Figure 2 This is a schematic diagram of a vehicle-mounted controller safety risk assessment system based on machine learning algorithms according to an embodiment of the present invention;
[0020] Figure 3 This is a flowchart of a method for assessing the safety risks of an in-vehicle controller based on a machine learning algorithm, according to an embodiment of the present invention.
[0021] Figure 4 This is a schematic diagram of a device for determining the safety level of a controller in a vehicle according to an embodiment of the present invention. Detailed Implementation
[0022] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0023] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0024] Example 1
[0025] According to an embodiment of the present invention, an embodiment of a method for determining the safety level of a controller in a vehicle is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0026] Figure 1 This is a flowchart of a method for determining the safety level of a controller in a vehicle according to an embodiment of the present invention, such as... Figure 1 The flowchart shown illustrates a method for determining the safety level of a controller in a vehicle. This method includes the following steps:
[0027] Step S102: Run the vehicle simulation model, wherein the simulation model is used to simulate the vehicle's network environment and includes the vehicle's controller.
[0028] In the technical solution provided in step S102 of the present invention, a vehicle simulation model can be constructed and run. The simulation model can be used to simulate the vehicle's network environment and may include controllers within the vehicle. The network environment refers to the network connection and communication environment between the vehicle's interior and exterior, and may include information about the vehicle's internal network, external network, onboard equipment, sensors, and controllers. The controller, also known as an Electronic Control Unit (ECU), may include a Telematics (TBOX) terminal for vehicle networking devices, an Over-The-Air (OTA) controller, a gateway, a body domain controller, a chassis domain controller, a powertrain domain controller, etc. The vehicle, also known as a vehicle entity, can be an intelligent vehicle, a hybrid vehicle, etc. It should be noted that this is merely an example and does not impose specific limitations on the types of vehicles or controllers.
[0029] Optionally, this embodiment can connect the vehicle entity and controller to the automotive network test range as the controller under test or target to obtain a simulation model containing the controller, and then run the simulation model.
[0030] Step S104: During the simulation model's operation, obtain vulnerability monitoring results obtained from vulnerability monitoring of the simulation model, and obtain attack results obtained from attacking the simulation model, wherein the attack results are used to characterize the security performance of the simulation model.
[0031] In the technical solution provided in step S104 of the present invention, during the operation of the simulation model, vulnerability monitoring results obtained by performing vulnerability monitoring on the simulation model, and attack results obtained by attacking the simulation model, can be acquired. The vulnerability monitoring results can be used to determine the detected vulnerabilities in the controller. The attack results can be used to determine the controller's ability to defend against attacks in the simulation model. Attacks on the simulation model can be scanning and probing attacks, breaching attacks, remote control attacks, and exploitation attacks, etc., and are only examples here; no specific limitations are imposed on the types of attacks.
[0032] Optionally, this embodiment can perform vulnerability monitoring on the simulation model to obtain vulnerability monitoring results. For example, the simulation model can be monitored for vulnerabilities through a security testing unit to obtain vulnerability monitoring results, and the detected vulnerability monitoring results can be submitted to the knowledge acquisition module for analysis.
[0033] Optionally, this embodiment can attack the simulation model to obtain attack results. For example, the controller in the simulation model can be attacked through the vehicle safety drill unit to obtain attack results.
[0034] Step S106: Determine the monitoring level corresponding to the vulnerability monitoring results, and determine the attack level corresponding to the attack results.
[0035] In the technical solution of step S106 of the present invention, the monitoring level corresponding to the vulnerability monitoring result and the attack level corresponding to the attack result can be determined. The monitoring level can be used to characterize the vulnerability situation in the controller; for example, the higher the monitoring level, the more vulnerabilities the controller has. The attack level, also known as the attack feasibility level or threat level, can be used to characterize the controller's ability to resist attacks; for example, the higher the attack level, the higher the controller's ability to resist attacks. It should be noted that this is only an illustrative example and does not impose specific limitations on the content of the monitoring level and attack level.
[0036] Optionally, this embodiment can pre-set vulnerability monitoring results and corresponding monitoring levels, and store them in a database. After obtaining the vulnerability monitoring results from the simulation model, the monitoring level corresponding to the vulnerability monitoring results can be determined from the database.
[0037] Optionally, this embodiment can pre-set the attack level corresponding to the attack result and store it in a database. When the attack result obtained from attacking the simulation model is acquired, the attack level corresponding to the attack result can be determined from the database.
[0038] It should be noted that the above methods for determining monitoring and attack levels are merely illustrative examples. The methods for determining monitoring levels based on vulnerability monitoring results and the corresponding attack levels based on attack results should be within the scope of protection of this application.
[0039] Step S108: Determine the security level of the controller based on the monitoring level and the attack level.
[0040] In the technical solution of step S108 of the present invention, the security level can be derived based on the impact level and the threat level. The security level can be used to determine the security degree of the controller; for example, it can be level one, level two, level three, etc. This is merely an example and does not impose specific limitations on the form in which the security level is expressed.
[0041] For example, the security level can be obtained by weighted summation of the impact level and the threat level. It should be noted that this is merely an example and does not impose specific limitations on the calculation method of the security level.
[0042] In steps S102 to S108 of the present invention, the vehicle is simulated to obtain a simulation model corresponding to the vehicle. The vulnerability monitoring results in the simulation model and the attack results (which can be defense results) obtained by attacking the controller are determined. Based on the monitoring level corresponding to the vulnerability monitoring results and the attack level corresponding to the attack results, the security level corresponding to the controller is determined. This achieves the technical effect of improving the accuracy of determining the security level of the controller and solves the technical problem of low accuracy in determining the security level of the controller.
[0043] The method described in this embodiment will be further described below.
[0044] As an optional implementation, step S104 involves obtaining vulnerability monitoring results from vulnerability monitoring of the simulation model, including: obtaining vulnerability information from vulnerability monitoring of the controller in the simulation model; and determining the correspondence between the vulnerability information and vehicle assets as the vulnerability monitoring results.
[0045] In this embodiment, vulnerability monitoring can be performed on the controller in the simulation model to obtain vulnerability information, and the correspondence between the vulnerability information and vehicle assets can be determined. This correspondence can be defined as the vulnerability monitoring result. Vehicle assets, also known as asset knowledge or vehicle asset knowledge, can include information such as the hardware platform, operating system kernel version, firmware version, middleware version, and application version of vehicle components. It should be noted that this is only an example and does not impose specific limitations on the content of vehicle assets. Vulnerability information can be used to characterize the type and impact of vulnerabilities in the controller; this is also only an example and does not impose specific limitations on the content of the vulnerability information.
[0046] Optionally, this embodiment can extract the relationship between vehicle vulnerabilities and vehicle assets from the knowledge acquisition module through the impact scenario identification module, so as to identify the impact scenarios of different assets and obtain vulnerability monitoring results.
[0047] For example, the vehicle safety testing module can perform vulnerability monitoring on the simulation model, determine the vulnerability information of the controller in the simulation model, and submit the vulnerability information to the knowledge acquisition module. The knowledge acquisition module determines the correspondence between the vulnerability information and vehicle assets, obtains the impact scenarios of different assets, and information such as the location of vulnerabilities in the assets, thereby obtaining the vulnerability monitoring results.
[0048] As an optional implementation method, determining the monitoring level corresponding to the vulnerability monitoring results includes: determining the impact level of the vulnerability in the vulnerability monitoring results, wherein the impact level is used to represent the degree of impact of the vulnerability on the driving safety performance of the vehicle; and determining the impact level as the monitoring result.
[0049] In this embodiment, the impact level of a vulnerability in the vulnerability monitoring results is determined, and the impact level can be used as the monitoring result. The impact level can be used to represent the degree to which a vulnerability affects the driving safety performance of a vehicle. Driving safety can include personal safety, property damage, vehicle operational safety, privacy security, and regulatory security, etc., but this is only an example and does not impose specific limitations on the types of driving safety.
[0050] Optionally, this embodiment can perform impact level analysis on different asset impact scenarios of each controller based on four factors: personal safety, property loss, vehicle operation, privacy, and regulations, in order to determine the impact level of the vulnerability.
[0051] For example, the correspondence between vulnerability information and vehicle assets is determined to obtain vulnerability monitoring results. Based on the four elements of personal safety, property loss, vehicle operation, privacy security, and regulatory security, and based on the vulnerability monitoring results, the impact level analysis is performed on the impact scenarios of vulnerabilities corresponding to different assets of each controller in the simulation model to obtain the impact level corresponding to different vulnerabilities.
[0052] As an optional implementation, step S104, obtaining the attack result obtained by attacking the simulation model, includes: determining the time and extent of the attack on the controller in the simulation model based on historical attack information, wherein the historical attack information is used to determine the attack type; determining the attack result based on the historical attack information, the time and extent of the attack, wherein the attack result is used to determine the controller's defense capability against the attack.
[0053] In this embodiment, acquiring historical attack information allows for attacks on the simulation model to be launched based on this information, thereby determining the time and extent of the attack on the controller within the simulation model. The attack result can be determined based on the historical attack information, the time of attack, and the extent of the attack. The historical attack information can be used to determine the attack type and other information related to the attack on the controller in the simulation model. This historical attack information may include attack name, skill requirements, resource requirements, prerequisites, execution flow, execution consequences, related vulnerabilities, and attack classification. Attack classification may include scanning and probing attacks, breach attacks, remote control attacks, and exploitation attacks. The time of attack can be the time it takes for the controller to be completely compromised.
[0054] Optionally, this embodiment can pre-store historical attack information from historical attack scenarios. When it is desired to analyze the security level of the controller, historical attack information can be retrieved from the pre-stored information. Based on the historical attack information, an attack is launched on the controller in the simulation model to determine the time and extent of the attack. The attack result can be determined based on the historical attack information, the attack time, and the extent of the attack.
[0055] For example, historical attack information from past attack scenarios can be submitted to the knowledge acquisition module. When analyzing the security level of a controller, historical attack information can be obtained from the knowledge acquisition module. Attacks can then be launched against the controller (also known as a target) in the simulation model using the automotive safety drill unit to obtain the attack results.
[0056] Optionally, this embodiment can extract the relationship between different attacks and vehicle assets, as well as the attack paths of different attacks, from the knowledge acquisition module to obtain historical attack information.
[0057] As an optional implementation, the attack result is determined based on historical attack information, the time of breach, and the degree of attack, including: determining the breach time threshold and the degree of attack threshold corresponding to the historical attack information; and determining the attack result based on the matching relationship between the breach time threshold and the breach time, and the matching relationship between the degree of attack threshold and the degree of attack.
[0058] In this embodiment, different historical attack information corresponding to attack time thresholds and attack severity thresholds can be predetermined or set in advance. The relationship between the attack time threshold and the attack time, as well as the relationship between the attack severity threshold and the attack severity, can be determined to determine the attack result. The attack result can be used to characterize the attack feasibility level.
[0059] Optionally, this embodiment can extract attack paths of different attacks from the knowledge acquisition module to obtain historical attack messages, as well as compromise time thresholds and attack severity thresholds matching the historical attack messages. Based on information such as attack name, skill requirements, resource requirements, and prerequisites from the historical attack information, the professional knowledge of the current attack path, the level of understanding of the target, the compromise time, the equipment required for the attack, and the opportunity window are automatically scored to determine the attack feasibility level.
[0060] For example, an automotive cyber range can submit acquired historical vulnerability and attack information to a knowledge acquisition module. This module can then supplement the database with this information to establish a correspondence between historical attack messages and attack time and severity thresholds. When the attack time and severity are obtained, the module can compare these values to determine the attack outcome. For instance, if the attack time exceeds the threshold, it indicates poor controller resilience, resulting in a high attack feasibility level in the attack outcome.
[0061] As an optional implementation, step S106, determining the security level of the controller based on the monitoring level and the attack level, includes: searching for the security level in the database based on the monitoring level and the attack level.
[0062] In this embodiment, security levels corresponding to different monitoring and attack levels can be pre-built in the database based on historical data. Once the monitoring and attack levels are obtained, the corresponding security level can be determined by searching based on the monitoring and attack levels.
[0063] Alternatively, the data in the database can be pre-built based on historical data.
[0064] For example, the automotive cyber range can submit historical vulnerability and attack information to the knowledge acquisition module. The knowledge acquisition module can automatically extract knowledge elements from large-scale, multi-source information that supports standard specification templates, and can extract the correspondence between vehicle asset knowledge and vehicle controllers to determine the security level corresponding to different monitoring levels and attack levels.
[0065] As an optional implementation, before running the vehicle simulation model, the method may further include: constructing a vehicle network range for the vehicle; connecting the controller to the vehicle network range to obtain the simulation model.
[0066] In this embodiment, a vehicle network test range can be constructed. The controller can be connected to the vehicle network test range to obtain a simulation model.
[0067] Optionally, a network range is a simulation platform based on hardware resources that constructs target networks through network simulation. An automotive network range can simulate typical automotive application scenarios, including models for attack and defense drills for intelligent vehicles, security crowdsourcing, verification of new cybersecurity technologies, vulnerability management, and incident response. Vehicle entities and controllers can be connected to the automotive network range to serve as controllers under test and targets.
[0068] This embodiment simulates a vehicle to obtain a corresponding simulation model. It determines the vulnerability monitoring results in the simulation model and the attack results (which can be defense results) obtained by attacking the controller. Based on the monitoring level corresponding to the vulnerability monitoring results and the attack level corresponding to the attack results, it determines the security level of the controller. This achieves the technical effect of improving the accuracy of determining the security level of the controller and solves the technical problem of low accuracy in determining the security level of the controller.
[0069] Example 2
[0070] The technical solutions of the embodiments of the present invention will be illustrated below with reference to preferred embodiments.
[0071] Currently, with the development of intelligent connected vehicle technology, the vehicle network environment in which the vehicle operates is becoming increasingly complex, involving more and more threats. The security issues of automotive electronics are becoming increasingly prominent; therefore, risk identification and risk assessment of electronic control units are the foundation for the planning and development of vehicle information security functions.
[0072] In related technologies, threat severity classification models are typically established based on relevant standards such as ISO / IEC 15408 and ISO / DIS26262, or information security threat analysis and risk assessment methods for vehicle electronic and electrical systems (such as HEAVENS) are used to assess the risks of electronic control units. However, the above risk assessment methods are mainly based on assessment experience, which is prone to misjudgment, resulting in low accuracy in determining the security level of the controller.
[0073] In another alternative embodiment, a vehicle controller safety risk assessment system based on machine learning algorithms is proposed. This method uses artificial neural networks to assess the safety risks of vehicle controllers. However, this method still has the problem of not being able to accurately determine the performance of functional components.
[0074] To address the aforementioned issues, this invention proposes an automated vehicle safety level analysis system and method based on an automotive network range. This system fully utilizes automotive network range resources to analyze vehicle safety levels, resulting in more comprehensive and objective safety level analysis results, thereby improving the accuracy of determining the safety level of the controller.
[0075] Optionally, a network range is a simulation platform that constructs target networks based on hardware resources and network simulation. The automotive network range can simulate typical application scenarios of automobiles. The network range can simulate models of scenarios such as attack and defense exercises for intelligent vehicles, security crowdsourcing, verification of new network security technologies, vulnerability management and emergency response.
[0076] The embodiments of the present invention will be further described below.
[0077] Figure 2 This is a schematic diagram of a vehicle-mounted controller safety risk assessment system based on machine learning algorithms according to an embodiment of the present invention, as shown below. Figure 2 As shown, the system may include: an automotive network range 201, a knowledge acquisition module 202, and an analysis module 203. The automotive network range 201 includes an automotive safety training unit 2011 and an automotive safety testing unit 2012.
[0078] Figure 3 This is a flowchart of a method for assessing the safety risks of an in-vehicle controller based on a machine learning algorithm, according to an embodiment of the present invention. Figure 3 As shown, the method may include the following steps.
[0079] In step S301, the automotive network range submits historical vulnerability and attack information to the knowledge acquisition module.
[0080] In this embodiment, the automotive network range 201 can submit the acquired historical vulnerability and historical attack information to the knowledge acquisition module 202, which can supplement the historical vulnerability and historical attack information in the database.
[0081] In step S302, the knowledge acquisition module automatically extracts knowledge elements from large-scale, multi-source information.
[0082] In this embodiment, the knowledge acquisition module 202 can be used to automatically extract knowledge elements from large-scale, multi-source information supporting standard specification templates, and can extract the correspondence between vehicle asset knowledge and vehicle controllers. The knowledge elements can include vehicle vulnerability knowledge, asset knowledge, attack knowledge, etc. Asset knowledge can include hardware platform information of components, operating system kernel version information, firmware version, middleware version, application version, etc.
[0083] Optionally, the knowledge acquisition module 202 supports automatic acquisition, extraction, and updating of automotive knowledge when connected to the network.
[0084] Step S303: Obtain vulnerability monitoring results and attack results.
[0085] In this embodiment, the vehicle entity and controller can be connected to the automotive network test range 201 to serve as the controller under test or target, thereby obtaining a simulation model containing the controller.
[0086] Optionally, in this embodiment, the security testing unit 2012 can perform vulnerability monitoring on the simulation model to obtain vulnerability monitoring results. The detected vulnerability monitoring results can be submitted to the knowledge acquisition module 202 for analysis.
[0087] Optionally, this embodiment can submit historical attack information from historical attack scenarios to the knowledge acquisition module 202. The historical attack information is then obtained from the knowledge acquisition module 202. Based on this historical attack information, the controller (also known as the target) in the simulation model can be attacked through the vehicle safety training unit 2011 to obtain the attack results. The historical attack information may include the attack name, skill requirements, resource requirements, prerequisites, execution process, consequences, related vulnerabilities, and attack classification. Attack classifications may include scanning and detection, attack breakthrough, remote control, and theft / exploitation.
[0088] Optionally, the targets to be attacked may include OTA targets, TBOX targets, gateway targets, body domain controller targets, chassis domain controller targets, powertrain domain controller targets, etc.
[0089] Step S304: Identify the affected scenarios and attack paths.
[0090] In this embodiment, vulnerability monitoring results and attack results can be transmitted to the knowledge acquisition module 202. The relationship between automotive vulnerabilities and automotive assets can be extracted from the knowledge acquisition module by the impact scenario identification module to identify the impact scenarios of different assets.
[0091] Optionally, this embodiment can perform impact level analysis on different asset impact scenarios of each controller based on four factors: personal safety, property loss, vehicle operation, privacy, and regulations, in order to determine the impact level of the vulnerability.
[0092] In this embodiment, the relationships between different attacks and vehicle assets, as well as the attack paths of different attacks, can be extracted from the knowledge acquisition module. Based on information such as attack name, skill requirements, resource requirements, and prerequisites from historical attack information, the attack path of the current attack is automatically scored for its professional knowledge, understanding of the target, attack time, required equipment, and opportunity window, thereby determining the attack feasibility level.
[0093] Step S305: Determine the safety level of the controller.
[0094] In this embodiment, the security level can be determined based on the impact level and the threat level.
[0095] For example, the security level can be obtained by weighted summation of the impact level and the threat level. It should be noted that this is merely an example and does not impose specific limitations on the calculation method of the security level.
[0096] In this embodiment of the invention, a vehicle is simulated to obtain a simulation model corresponding to the vehicle. The vulnerability monitoring results in the simulation model and the attack results (which can be defense results) obtained by attacking the controller are determined. Based on the monitoring level corresponding to the vulnerability monitoring results and the attack level corresponding to the attack results, the security level corresponding to the controller is determined, thereby achieving the technical effect of improving the accuracy of determining the security level of the controller and solving the technical problem of low accuracy in determining the security level of the controller.
[0097] It should be noted that the above-described embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit it. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the scope of the technology disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
[0098] Example 3
[0099] According to an embodiment of the present invention, a device for determining the safety level of a controller in a vehicle is also provided. It should be noted that this device for determining the safety level of a controller in a vehicle can be used to execute the method for determining the safety level of a controller in a vehicle as described in Embodiment 1.
[0100] Figure 4 This is a schematic diagram of a device for determining the safety level of a controller in a vehicle according to an embodiment of the present invention. Figure 4 As shown, the device 400 for determining the safety level of the controller in the vehicle may include: an operating unit 402, an acquisition unit 404, a first determining unit 406, and a second determining unit 408.
[0101] The running unit 402 is used to run a simulation model of the vehicle, wherein the simulation model is used to simulate the network environment of the vehicle and includes the controller in the vehicle.
[0102] The acquisition unit 404 is used to acquire vulnerability monitoring results obtained by performing vulnerability monitoring on the simulation model during the simulation model's operation, as well as attack results obtained by attacking the simulation model. The attack results are used to characterize the security performance of the simulation model.
[0103] The first determining unit 406 is used to determine the monitoring level corresponding to the vulnerability monitoring result and the attack level corresponding to the attack result.
[0104] The second determining unit 408 is used to determine the security level of the controller based on the monitoring level and the attack level.
[0105] Optionally, the acquisition unit 404 further includes: a first processing module, used to acquire vulnerability information obtained by vulnerability monitoring of the controller in the simulation model; and to determine the correspondence between the vulnerability information and the vehicle assets as the vulnerability monitoring result.
[0106] Optionally, the first processing module further includes: a first determining subunit, used to determine the impact level of a vulnerability in the vulnerability monitoring results, wherein the impact level is used to represent the degree of impact of the vulnerability on the driving safety performance of the vehicle; and to determine the impact level as the monitoring result.
[0107] Optionally, the acquisition unit 404 further includes: a second processing module, used to determine the time and extent of the attack on the controller in the simulation model based on historical attack information, wherein the historical attack information is used to determine the attack type; and to determine the attack result based on the historical attack information, the time and extent of the attack, wherein the attack result is used to determine the controller's defense capability against the attack.
[0108] Optionally, the first processing module further includes: a second determining subunit, used to determine the attack time threshold and attack severity threshold corresponding to the historical attack information; and to determine the attack result based on the matching relationship between the attack time threshold and the attack time, and the matching relationship between the attack severity threshold and the attack severity.
[0109] Optionally, the second determining unit further includes a lookup unit for determining the security level of the controller based on the monitoring level and the attack level, including: looking up the security level in the database based on the monitoring level and the attack level.
[0110] Optionally, the device further includes: a construction unit for constructing a vehicle network range for the vehicle; and connecting the controller to the vehicle network range to obtain a simulation model.
[0111] In this embodiment of the invention, a simulation model of a vehicle is run by a running unit. The simulation model is used to simulate the network environment of the vehicle and includes a controller in the vehicle. During the operation of the simulation model, a vulnerability monitoring result obtained by performing vulnerability monitoring on the simulation model and an attack result obtained by attacking the simulation model are acquired by an acquisition unit. The attack result is used to characterize the security performance of the simulation model. A first determining unit determines the monitoring level corresponding to the vulnerability monitoring result and the attack level corresponding to the attack result. A second determining unit determines the security level of the controller based on the monitoring level and the attack level. This achieves the technical effect of improving the accuracy of determining the security level of the controller and solves the technical problem of low accuracy in determining the security level of the controller.
[0112] Example 4
[0113] According to an embodiment of the present invention, a computer-readable storage medium is also provided, the storage medium including a stored program, wherein the program executes the method for determining the safety level of the controller in the vehicle as described in Embodiment 1.
[0114] Example 5
[0115] According to an embodiment of the present invention, a processor is also provided for running a program, wherein the program executes the method for determining the safety level of the controller in the vehicle as described in Embodiment 1.
[0116] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0117] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0118] In the several embodiments provided by this invention, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection can be through some interfaces; the indirect coupling or communication connection of units or modules can be electrical or other forms.
[0119] The units defined as separate components may or may not be physically separate. Similarly, the components displayed as units may or may not be physical units; they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.
[0120] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0121] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0122] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for determining the safety level of a controller in a vehicle, characterized in that, include: A vehicle network range is constructed for the vehicle, wherein the vehicle network range submits the acquired historical vulnerabilities and historical attack information to the knowledge acquisition module, and the knowledge acquisition module supplements the historical vulnerabilities and historical attack information in the database to construct the correspondence between historical attack information and the compromise time threshold and attack intensity threshold. The controller is connected to the vehicle network test range to obtain a simulation model of the vehicle; Run the simulation model, wherein the simulation model is used to simulate the network environment of the vehicle, and the simulation model includes the controller in the vehicle; During the operation of the simulation model, vulnerability monitoring results obtained by performing vulnerability monitoring on the simulation model and attack results obtained by attacking the simulation model are acquired, wherein the attack results are used to characterize the security performance of the simulation model. Determine the monitoring level corresponding to the vulnerability monitoring results, and determine the attack level corresponding to the attack results; The security level of the controller is determined based on the monitoring level and the attack level. Obtaining the attack result obtained from attacking the simulation model includes: determining the breach time and attack severity of the attack on the controller in the simulation model based on the historical attack information, wherein the historical attack information is used to determine the attack type of the attack, and the historical attack information is obtained by extracting the relationship between different attacks and vehicle assets and the attack paths of different attacks from the knowledge acquisition module, the historical attack information includes attack name, attack skill requirements, resource requirements, prerequisites, execution process, execution consequences, related vulnerabilities, and attack classification, the attack classification includes scanning and detection type, attack breakthrough type, remote control type, and theft and exploitation type; determining the breach time threshold and attack severity threshold corresponding to the historical attack information; and determining the attack result based on the matching relationship between the breach time threshold and the breach time, and the matching relationship between the attack severity threshold and the attack severity, wherein the attack result is used to determine the defense capability of the controller against the attack.
2. The method according to claim 1, characterized in that, Obtaining the vulnerability monitoring results from vulnerability monitoring of the simulation model includes: Obtain vulnerability information obtained by performing vulnerability monitoring on the controller in the simulation model; The correspondence between the vulnerability information and vehicle assets is determined as the vulnerability monitoring result.
3. The method according to claim 2, characterized in that, Determining the monitoring level corresponding to the vulnerability monitoring results includes: Determine the impact level of the vulnerability in the vulnerability monitoring results, wherein the impact level is used to represent the degree of impact of the vulnerability on the driving safety performance of the vehicle; The level of impact is determined as the monitoring result.
4. The method according to claim 1, characterized in that, Determining the security level of the controller based on the monitoring level and the attack level includes: The security level is searched in the database based on the monitoring level and the attack level.
5. A device for determining the safety level of a controller in a vehicle, characterized in that, include: The device is also used to construct a vehicle network range for the vehicle, wherein the vehicle network range submits the acquired historical vulnerabilities and historical attack information to a knowledge acquisition module, and the knowledge acquisition module supplements the historical vulnerabilities and historical attack information in the database to construct a correspondence between historical attack information and attack time thresholds and attack severity thresholds. The controller is connected to the vehicle network test range to obtain a simulation model of the vehicle; A running unit is used to run the simulation model, wherein the simulation model is used to simulate the network environment of the vehicle, and the simulation model includes a controller in the vehicle; The acquisition unit is used to acquire vulnerability monitoring results obtained by performing vulnerability monitoring on the simulation model during the operation of the simulation model, and to acquire attack results obtained by attacking the simulation model, wherein the attack results are used to characterize the security performance of the simulation model. The first determining unit is used to determine the monitoring level corresponding to the vulnerability monitoring result and to determine the attack level corresponding to the attack result; The second determining unit is used to determine the security level of the controller based on the monitoring level and the attack level; The acquisition unit is further configured to determine, based on the historical attack information, the breach time and attack severity of the attack on the controller in the simulation model. The historical attack information is used to determine the attack type, obtained by extracting the relationship between different attacks and vehicle assets, as well as the attack paths of different attacks, from the knowledge acquisition module. The historical attack information includes attack name, skill requirements, resource requirements, prerequisites, execution process, execution consequences, related vulnerabilities, and attack classification. The attack classification includes scanning and detection, attack breakthrough, remote control, and theft / exploitation. The unit also determines the breach time threshold and attack severity threshold corresponding to the historical attack information. Based on the matching relationship between the breach time threshold and the breach time, and the matching relationship between the attack severity threshold and the attack severity, the unit determines the attack result. The attack result is used to determine the controller's defense capability against the attack.
6. A vehicle, characterized in that, Used to perform the method according to any one of claims 1 to 4.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device on which the computer-readable storage medium is located to perform the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Automobile network security risk assessment method and device, storage medium and electronic equipment
CN113472800A
Display method based on intelligent network connection automobile attack matrix
CN115310079A