Safety detection method and system based on vehicle networking

By constructing a timely updated network topology and risk control detection model, generating a proprietary vulnerability database, and conducting risk level and protection level assessments, the problems of low efficiency, poor real-time performance, and low accuracy in vehicle security detection in existing technologies are solved, achieving efficient network security detection.

CN117834180BActive Publication Date: 2025-11-18AI SUPER EYE TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202311563355.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-22
Publication Date
2025-11-18
Estimated Expiration
2043-11-22

AI Technical Summary

Technical Problem

Existing vehicle safety inspection methods are inefficient, lack real-time performance, and have low accuracy, making it difficult to meet the needs of modern vehicle safety inspection.

Method used

By constructing a network topology structure that is updated in a timely manner, generating a proprietary vulnerability database, fitting a risk control detection model, conducting risk level assessment and protection level assessment, generating risk control early warning information, and triggering active and passive defenses.

Benefits of technology

It improves the efficiency, real-time performance, and accuracy of vehicle safety inspection, achieving efficient network security inspection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117834180B_ABST
    Figure CN117834180B_ABST
Patent Text Reader

Abstract

The application discloses a safety detection method and system based on Internet of Vehicles, and relates to the technical field of artificial intelligence, which comprises the following steps: reading the basic data of Internet of Vehicles, and constructing a network topology structure; searching for driving logs in a predetermined time zone, performing risk control analysis to mine risk points, and generating a special vulnerability library; fitting the special vulnerability library and the network topology structure, and supervising and training a risk control detection model; reading a network transmission signal to be detected, transmitting the network transmission signal to the risk control detection model for risk level evaluation, and determining a network security coefficient; determining whether the network security coefficient meets a threshold standard, and generating risk control early warning information based on a risk control source; and transmitting defense efficiency to the risk control detection model for protection level evaluation. The application solves the technical problems of low detection efficiency, poor real-time performance and low precision in the prior art, and achieves the technical effects of improving detection efficiency, real-time performance and high precision through safety detection based on Internet of Vehicles.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of artificial intelligence technology, and specifically to a safety detection method and system based on the Internet of Vehicles. Background Technology

[0002] With the rapid development of vehicle-to-everything (V2X) technology, communication between vehicles has become increasingly common, providing drivers with a more convenient transportation environment. However, with the increase in the number of vehicles and the increasing complexity of road conditions, vehicle safety issues are becoming more prominent, placing higher demands on vehicle safety inspections. Traditional vehicle safety inspection methods often rely on manual inspections and periodic maintenance, which suffer from low inspection efficiency, poor real-time performance, and low accuracy, making it difficult to meet the needs of modern vehicle safety inspections. Summary of the Invention

[0003] This application provides a safety detection method and system based on the Internet of Vehicles, which is used to address the technical problems of low efficiency, poor real-time performance and low accuracy in the prior art.

[0004] In view of the above problems, this application provides a safety detection method and system based on vehicle networking.

[0005] The first aspect of this application provides a security detection method based on vehicle networking, the method comprising:

[0006] The system reads basic data from the vehicle network to construct a network topology, which is updated in a timely manner. It retrieves driving logs within a predetermined time zone, performs risk control analysis to identify risk points, and generates a proprietary vulnerability database. It then fits the proprietary vulnerability database to the network topology and supervises the training of a risk control detection model, which includes parallel risk control prediction and detection branches. The system reads network transmission signals to be detected and transmits them to the risk control detection model for risk level assessment, determining a network security coefficient, which is marked with a risk control source. It then determines whether the network security coefficient meets a threshold standard and generates risk control early warning information based on the risk control source. Finally, it transmits the defense effectiveness to the risk control detection model for protection level assessment.

[0007] A second aspect of this application provides a vehicle-to-everything (V2X) based safety detection system, the system comprising:

[0008] The system comprises the following modules: a network topology construction module, which reads basic data from the vehicle network and constructs a network topology that is updated in a timely manner; a proprietary vulnerability database generation module, which retrieves driving logs within a predetermined time zone, performs risk control analysis to identify risk points, and generates a proprietary vulnerability database; a risk control detection model training module, which fits the proprietary vulnerability database with the network topology and supervises the training of a risk control detection model, which includes parallel risk control prediction and risk control detection branches; a risk level assessment module, which reads the network transmission signal to be detected, transmits it to the risk control detection model for risk level assessment, and determines a network security coefficient, which is marked with a risk control source; a risk control early warning information generation module, which determines whether the network security coefficient meets a threshold standard and generates risk control early warning information based on the risk control source; an active and passive defense module, which triggers the protection system to perform active and passive defense against the risk control source based on the risk control early warning information and provides feedback on the defense effectiveness; and a protection level assessment module, which transmits the defense effectiveness to the risk control detection model for protection level assessment.

[0009] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0010] This application constructs a network topology by reading basic data from the Internet of Vehicles (IoV); retrieves driving logs within a predetermined time zone, performs risk control analysis to identify risk points, and generates a proprietary vulnerability database; fits the proprietary vulnerability database to the network topology and supervises the training of a risk control detection model; reads the network transmission signals to be detected and transmits them to the risk control detection model for risk level assessment to determine the network security coefficient; determines whether the network security coefficient meets the threshold standard and generates risk control early warning information based on the risk control source; and transmits the defense efficiency to the risk control detection model for protection level assessment. This solves the technical problems of low detection efficiency, poor real-time performance, and low accuracy in existing technologies, achieving improved detection efficiency, real-time performance, and high accuracy through IoV-based security detection. Attached Figure Description

[0011] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0012] Figure 1 This is a schematic diagram of the safety detection method based on the Internet of Vehicles provided in the embodiments of this application;

[0013] Figure 2 A schematic diagram illustrating the process of determining the network security coefficient in the vehicle-to-everything (V2X) security detection method provided in this application embodiment;

[0014] Figure 3 This is a schematic diagram of the structure of a vehicle-to-everything (V2X) based safety detection system provided in an embodiment of this application.

[0015] Figure labeling: Network topology construction module 11, proprietary vulnerability database generation module 12, risk control detection model training module 13, risk level assessment module 14, risk control early warning information generation module 15, active and passive defense module 16, protection level assessment module 17. Detailed Implementation

[0016] This application provides a vehicle-to-everything (V2X) based safety detection method to address the problems of low detection efficiency, poor real-time performance, and low accuracy in existing traditional vehicle safety detection methods, thereby improving the efficiency, real-time performance, and accuracy of vehicle safety detection.

[0017] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0018] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or modules not explicitly listed or inherent to such processes, methods, products, or devices.

[0019] Example 1

[0020] like Figure 1 As shown, this application provides a security detection method based on the Internet of Vehicles, the method comprising:

[0021] Step S100: Read the basic data of the vehicle network and construct the network topology, wherein the network topology is updated in a timely manner;

[0022] In this embodiment, various basic vehicle data, including but not limited to vehicle status, location, speed, and acceleration, are acquired through a communication interface with the vehicle. This data can be collected and transmitted using the vehicle's built-in sensors, GPS, and other devices. The read data requires preprocessing and cleaning to ensure its accuracy and integrity.

[0023] When constructing the network topology, a network topology describing the communication relationships between vehicles is built based on the acquired vehicle baseline data. This structure can be represented as a graph or network, where nodes represent vehicles or network devices, and edges represent the connections between them. The network topology needs to be timely updated, meaning it can be updated in real time as vehicles and the network change.

[0024] When a vehicle enters or leaves a certain area, the network topology needs to add or delete nodes accordingly. When two vehicles establish or disconnect a connection, the network topology needs to add or delete edges accordingly. To ensure timely updates, the network topology needs to continuously obtain the latest vehicle status and location information from the vehicle network to update its structure promptly.

[0025] Step S200: Retrieve driving logs within the predetermined time zone, conduct risk control analysis to identify risk points, and generate a proprietary vulnerability database;

[0026] In this embodiment of the application, when retrieving driving logs within a predetermined time zone, the predetermined time zone range to be retrieved is first determined, such as the past hour or the past day. Vehicle driving log data within the predetermined time zone is then obtained from the vehicle network system. The driving logs include various vehicle status and operational information, such as time, location, speed, acceleration, and driver behavior.

[0027] When conducting risk control analysis to identify risk points, the retrieved vehicle log data is cleaned and organized to remove outliers and invalid data. Risk control analysis algorithms are then used to identify risk points within the vehicle log data. These algorithms may include abnormal behavior detection, threat detection, and pattern recognition to identify potentially risky behaviors and operations. For example, frequent changes in driving routes or sudden acceleration and deceleration within a short period might be considered abnormal behavior.

[0028] Finally, the identified risks are categorized and summarized to generate a proprietary vulnerability database. This database includes various potential security vulnerabilities and attack surfaces, such as driver misconduct, malicious vehicle control, and network communication interference. Each vulnerability requires a detailed description, severity assessment, and remediation recommendations.

[0029] Step S300: Fit the proprietary vulnerability database to the network topology, and supervise the training of the risk control detection model, wherein the risk control detection model includes a parallel risk control prediction branch and a risk control detection branch;

[0030] In this embodiment, when fitting the proprietary vulnerability database to the network topology, the vulnerabilities in the proprietary vulnerability database are first associated with the nodes and edges in the network topology. For each vulnerability, the network topology can be used to identify potentially affected vehicles and network devices. This association method allows for a better understanding of the vulnerability's impact and potential risks throughout the network.

[0031] Next, the risk control detection model is trained under supervised supervision using existing security detection data and labels. Training data includes normal network communication data and communication data with security risks. Before training, features related to security risks are extracted from network transmission signals. These features may include network traffic, protocol type, port usage, and abnormal behavior. For each feature, its meaning, value range, and calculation method need to be determined. Security event data are labeled with corresponding categories, such as normal behavior or attack behavior. Existing security event datasets or manually labeled datasets can be used. The prepared dataset is divided into training and test sets. The training set is used to train the model, and the test set is used to evaluate the model's performance. Techniques such as cross-validation are typically used to avoid overfitting and underfitting.

[0032] The model is trained using a logistic regression algorithm and a training dataset. During training, appropriate regularization parameters and optimization algorithms need to be selected to avoid overfitting and underfitting, and to improve the model's generalization ability. For the parallel branches in the risk control detection model, logistic regression can be used for training separately. Network traffic, protocol types, port usage, and abnormal behavior are input into the model, and the output is evaluated against the labels in the test set to adjust and optimize the model. The risk control prediction branch mainly predicts future security risk trends based on current transmission signals, while the risk control detection branch identifies and assesses current security risks based on historical security event data.

[0033] The risk control detection model comprises parallel risk control prediction and risk control detection branches. The risk control prediction branch is responsible for predicting and analyzing network communication data to identify potential risk points. The risk control detection branch is responsible for in-depth analysis and detection of the identified risk points to determine whether any security risks exist. These two branches work together to achieve more efficient and accurate security detection.

[0034] Step S400: Read the network transmission signal to be detected, transmit it to the risk control detection model for risk level assessment, and determine the network security coefficient, wherein the network security coefficient is marked with the risk control source;

[0035] In this embodiment, network transmission signals to be detected are acquired through an interface connection with a vehicle-to-everything (V2X) system. These network transmission signals include communication data between vehicles, between vehicles and data centers, and between vehicles and cloud platforms. Each network transmission signal requires preprocessing and cleaning to ensure data accuracy and integrity.

[0036] The pre-processed and cleaned network transmission signals are then fed into the pre-trained risk control detection model and used for reverse traffic risk level assessment. The risk control prediction branch is responsible for making preliminary risk predictions on the network transmission signals. The risk control detection branch then uses the trained model to further analyze and detect the risk prediction results. By comprehensively analyzing factors such as the characteristics, patterns, and abnormal behaviors of the network transmission signals, the risk control detection model can assess the risk level of each network transmission signal. Based on the risk level assessed by the risk control detection model, the network security coefficient of each network transmission signal can be determined. The network security coefficient is a quantitative indicator representing the degree of security of network communication; a higher value indicates greater network security.

[0037] While determining the network security level, it's necessary to identify the risk control source for each risk signal. Risk control sources can be vehicles, drivers, network devices, applications, etc. Identifying these sources provides a clearer understanding of the origins and distribution of security risks.

[0038] Step S500: Determine whether the network security coefficient meets the threshold standard, and generate risk control early warning information based on the risk control source;

[0039] In this embodiment, a network security coefficient is determined based on a pre-set threshold standard to determine whether the network security coefficient meets the requirements. If the network security coefficient is lower than the threshold, a security risk is considered to exist; otherwise, the network security coefficient is considered to meet the requirements. Based on the determination result, if the network security coefficient does not meet the threshold standard, corresponding risk control early warning information needs to be generated. The risk control early warning information needs to include the risk control source, early warning level, early warning time, and early warning description. The early warning level can be divided into high, medium, and low to better reflect the severity of the security risk. The early warning description needs to explain in detail the reason for the early warning and the possible scope of its impact.

[0040] Step S600: Based on the risk control early warning information, trigger the protection system to perform active and passive defense against the risk control source and provide feedback on the defense efficiency;

[0041] In this embodiment, after risk control warning information is generated, the corresponding protection system needs to be triggered based on this information to perform active and passive defense. The risk control warning information contains information about the risk control source, and the protection system can perform targeted defense based on this information. During active defense, proactive measures are taken, such as sending warning information to the driver, restricting certain vehicle functions, and disconnecting network connections, to prevent or mitigate security risks. During passive defense, various vehicle data and behaviors are monitored and recorded to provide data support for subsequent analysis and evidence collection.

[0042] After implementing active and passive defense measures, feedback on defense efficiency is needed. This feedback includes the success or failure of the defense, the time taken for the defense, and the impact on vehicle performance. This feedback information can be used to evaluate the performance and effectiveness of the protection system, as well as to improve and optimize protection strategies.

[0043] Step S700: Transmit the defense efficiency to the risk control detection model to evaluate the protection level.

[0044] In this embodiment, after a single active or passive defense operation is completed, relevant defense efficiency data is collected and transmitted to the risk control detection model. This data may include the effectiveness of the defense measures, execution time, and impact on vehicle performance. The risk control detection model uses the received defense efficiency data to assess the protection level. The protection level assessment is a comprehensive evaluation based on multiple factors, including defense effectiveness, execution efficiency, and the difference in network security coefficients determined before and after protection. The assessment result can be a classification from low to high, such as low, medium, and high.

[0045] Furthermore, step S100 in the method provided in this application embodiment further includes:

[0046] Based on the basic data of the Internet of Vehicles, a distributed network is built and the connection ports are identified. The connection ports include at least the vehicle terminal, mobile terminal, road network terminal and platform terminal.

[0047] The distributed network is differentiated based on the connection ports to determine the network topology.

[0048] Perform real-time tracking based on the connection port to synchronously update the network topology.

[0049] In this embodiment, the basic data of the vehicle network includes information such as vehicle location, speed, acceleration, and direction, as well as communication data between vehicles and network topology information. Using this basic data, a distributed network is built, comprising multiple nodes, namely vehicles and other connection ports and edges, i.e., communication connections between nodes.

[0050] In a distributed network, it is necessary to identify different connection ports, including at least vehicle-mounted devices, mobile terminals, road network devices, and platform devices. Vehicle-mounted devices refer to equipment inside the vehicle, such as in-vehicle cameras and sensors. Mobile terminals refer to mobile devices that communicate with the vehicle, such as mobile phones and tablets. Road network devices refer to equipment in road infrastructure, such as traffic lights and roadside units. Platform devices refer to equipment in the vehicle-to-everything (V2X) platform or cloud platform, such as servers and data centers.

[0051] For each connection port in the distributed network, a differentiated identifier is created based on its type and characteristics. This identifier can include color coding, shape coding, labels, etc., to distinguish different types of connection ports. Based on the node and edge information in the distributed network, and the differentiated identifiers of the connection ports, the network topology is determined. The network topology can include star, tree, ring, mesh, etc., and a suitable topology is selected based on the actual situation.

[0052] During real-time tracking, for each connection port in the distributed network, dynamic information such as its position, velocity, and acceleration is acquired using real-time monitoring and tracking technologies. Real-time tracking enables status monitoring and anomaly detection of connection ports, allowing for timely identification and handling of security risks. Since nodes and connections in a distributed network are dynamically changing, the network topology needs to be updated periodically or in real-time. Real-time tracking based on connection ports acquires the latest node and connection information, enabling synchronous updates to the network topology. The frequency of these updates can be adjusted based on specific needs to meet varying real-time and accuracy requirements.

[0053] Furthermore, step S200 in the method provided in this application embodiment further includes:

[0054] Identify the driving logs and filter vehicle-to-everything (V2X) risk events related to cybersecurity;

[0055] The risk points of the aforementioned vehicle-to-everything (V2X) risk events are analyzed, and the sources of these risk points are traced to identify multiple risk control sequences. Each risk control sequence is represented as a risk point-risk control source.

[0056] Based on the risk control source, the multiple risk control sequences are clustered to determine multiple groups of risk control sequences;

[0057] Based on the aforementioned multiple risk control sequences, a proprietary vulnerability database is built.

[0058] In this embodiment, when identifying vehicle logs, the collected vehicle network data is analyzed to identify logs related to cybersecurity. Vehicle logs include vehicle communication data, sensor data, control commands, etc., which may contain information related to cybersecurity incidents. From the identified vehicle logs, risk events related to cybersecurity are filtered out. These risk events may include unauthorized access, data breaches, malicious control, etc.

[0059] The selected cybersecurity risk events are analyzed to identify the risk points for each event. Risk points may include system vulnerabilities, fragile network connections, and insecure communication protocols. For each risk point, a source tracing analysis is performed to determine its origin and cause. This may require in-depth investigation of network communication records, system configurations, and software development. Based on the analyzed risk points and the source tracing results, a corresponding risk control sequence is determined for each risk point. The risk control sequence refers to a series of risk control measures used to prevent or mitigate the security threats posed by the risk points.

[0060] For each risk control sequence, its source and execution method are analyzed, and clustering is performed based on similarity. This helps group similar risk control sequences for easier subsequent management and analysis. Based on the clustering results, the risk control sequences are divided into multiple groups, each with similar sources and execution methods. Each group of risk control sequences corresponds to a specific risk control source or multiple related risk control sources.

[0061] For each risk control sequence, analyze its corresponding risk control source and security vulnerability. Store this information in a proprietary vulnerability database for subsequent security audits and risk management. After establishing the proprietary vulnerability database, it is necessary to continuously monitor the operational status of the vehicle network and its network security. Once new security risks or vulnerabilities are discovered, the proprietary vulnerability database needs to be updated promptly to maintain its accuracy and timeliness.

[0062] Furthermore, the method also includes:

[0063] For the multiple risk control sequences, effective points are mined for each set of risk control sequences to determine multiple effective risk control sequences. Among them, effective risk points are risk points that meet the preset frequency.

[0064] The multiple effective risk control sequences are integrated into the proprietary vulnerability database.

[0065] Set a preset update cycle, call the time zone driving log based on periodic nodes, and extract the newly added risk control information;

[0066] Based on the newly added risk control information, incremental learning of the proprietary vulnerability database is performed.

[0067] In this embodiment, for each risk control sequence, its corresponding risk control source and security vulnerability are analyzed to identify effective points. Effective points refer to risk control measures or technologies that can effectively mitigate or prevent security risks. Effective points can be determined based on multiple factors such as the frequency, severity, and scope of impact of the risk points. Then, based on the effective point mining results for each group of risk control sequences, multiple effective risk control sequences are determined. Each effective risk control sequence corresponds to an effective handling method for one or more risk points.

[0068] Multiple effective risk control sequences are integrated to form a dedicated risk control library for vehicle-to-everything (V2X) security, known as a proprietary vulnerability library. This library contains effective risk control measures and corresponding implementation strategies for various cybersecurity risks.

[0069] Based on the actual operation and security requirements of the vehicle-to-everything (V2X) network, a preset update cycle is set. This cycle can be a fixed time interval, such as daily, weekly, or monthly. At the end of each preset update cycle, time zone driving logs based on periodic nodes are retrieved. By analyzing these logs, newly added risk control information is extracted, including new security risks and corresponding risk control measures.

[0070] Finally, for the extracted new risk control information, incremental learning is performed to update the proprietary vulnerability database. Incremental learning refers to training and updating only the newly added or changed data without retraining the entire model. Through incremental learning, the real-time nature and accuracy of the proprietary vulnerability database can be maintained to address constantly evolving cybersecurity threats. After completing incremental learning, the operational status and cybersecurity of the connected vehicle network continue to be monitored. Once new security risks or vulnerabilities are discovered, the proprietary vulnerability database should be updated immediately to ensure it remains up-to-date.

[0071] Furthermore, such as Figure 2 As shown, the method further includes:

[0072] The interaction is based on the network location of the proprietary vulnerability database as a necessary detection point;

[0073] Read the network transmission signal based on the necessary detection points, transmit it to the risk control detection model for risk level assessment, and determine a risk control detection result;

[0074] Random detection points are determined, and based on a predetermined detection cycle, network transmission signals based on the random detection points are read and transmitted to the risk control detection model for risk level assessment, thereby determining two risk control detection results.

[0075] The network security coefficient is determined by combining the results of one risk control test with the results of two risk control tests.

[0076] In this embodiment, by interacting with a proprietary vulnerability database, key location information in the network can be obtained, and these locations can serve as necessary detection points. These key locations may include connection points of network devices, data transmission intersections, etc. For each necessary detection point, its network transmission signals are read. These signals may include data packets, communication protocols, traffic, etc. The read network transmission signals are transmitted to the risk control detection model, and a risk level assessment is performed based on the characteristics and patterns of the signals. Finally, based on the assessment results of the risk control detection model, a risk control detection result is determined, which may be a risk level or a security factor.

[0077] To more comprehensively assess network security, random detection points need to be identified. These detection points may include key locations within the network or random locations. At the end of each predetermined detection period, network transmission signals based on these random detection points are read. This period can be a time interval, such as an hour, a day, or a week. The read network transmission signals are then transmitted to the risk control detection model for risk level assessment. Based on the assessment results, another risk control detection result is determined.

[0078] The results of two risk control tests—one from necessary detection points and one from random detection points—are combined. This provides a more comprehensive reflection of the overall security status of the network. Based on the combined results of the two risk control tests, a network security coefficient can be determined. This coefficient represents the overall security level or risk level of the network.

[0079] After obtaining the network security coefficient, it is necessary to continuously monitor the network's operational status and security condition. Once new security risks or vulnerabilities are discovered, the proprietary vulnerability database needs to be updated immediately, and the above steps should be repeated to determine the new network security coefficient. Through this continuous monitoring and updating, accurate assessments of the network security status and timely responses can be maintained.

[0080] Furthermore, the method also includes:

[0081] Based on the risk control detection branch, a real-time risk level assessment based on the network transmission signal is performed, and the risk control assessment result is output.

[0082] The risk control assessment results are transmitted to the risk control prediction branch, and predictions based on the scope of impact and risk nodes of the network transmission signals are performed to determine the risk control prediction results.

[0083] The network security coefficient is determined based on the risk control assessment results and the risk control prediction results.

[0084] Configure an active defense strategy based on the risk control prediction results.

[0085] In this embodiment, the risk control detection branch is an independent module or subsystem responsible for real-time monitoring of network transmission signals and performing risk level assessments. Based on the characteristics and patterns of network transmission signals, the risk control detection branch can determine the level of security risks present in the network in real time. The result of the risk level assessment will be output as the risk control assessment result.

[0086] The risk control prediction branch is a separate module or subsystem responsible for predictive analysis of network transmission signals. It transmits risk control assessment results, i.e., the network's security risk level, to the risk control prediction branch, providing it with reference data. Based on the received risk control assessment results and other relevant information, the risk control prediction branch predicts the scope of potential security threats and potential risk nodes within the network, helping to identify which areas or devices may be attacked or have security vulnerabilities in the future. Based on the predictive analysis, the risk control prediction branch generates one or more risk control prediction results. These results may include potential risk nodes, the scope of possible security threats, and recommended defensive measures.

[0087] By combining the risk control assessment results and risk control prediction results, a network security coefficient can be determined. This coefficient represents the overall security level or risk level of the current network. Based on the network security coefficient, the appropriate level of defense strategy can be determined. Finally, based on the risk control prediction results and the network security coefficient, corresponding proactive defense strategies are configured. Proactive defense strategies include, but are not limited to, firewall settings, intrusion detection, defense system configuration, data encryption, and access control. By configuring proactive defense strategies, network attacks can be prevented or mitigated in advance, improving network security.

[0088] After configuring a proactive defense strategy, it is necessary to continuously monitor the network's operational status and security condition. Once new security risks or vulnerabilities are discovered, the risk control model and related strategies must be updated immediately to address the new threats. Through this continuous monitoring and updating, accurate assessments and timely responses to network security issues can be maintained.

[0089] Furthermore, the method also includes:

[0090] Based on the risk control assessment results, implement passive defense based on the protection system;

[0091] Based on the risk control prediction results, the protection system performs proactive defense based on an active defense strategy.

[0092] In this embodiment, the risk control assessment result reflects the current security risk level of the network. Based on this result, passive defense based on the protection system can be implemented. The protection system may include firewalls, intrusion detection systems, antivirus software, etc., which can provide basic protection against known attacks and threats. Based on the risk control assessment result, the settings of the protection system can be adjusted, such as stricter firewall rules, more frequent IDS scans, etc., to enhance the defense against known risks.

[0093] Risk control forecasts provide predictions of potential future attacks and threats. Based on these predictions, corresponding proactive defense strategies can be developed and implemented. Proactive defense strategies may include proactively changing firewall rules, updating systems in advance, and deploying honeypots or honeynets to lure and detect new threats or attacks. When implementing proactive defense strategies, it is necessary to consider the capabilities of the protection system. For example, if the IDS detects a new attack pattern, rules targeting this attack pattern can be added to the IDS rules to ensure timely detection and blocking in subsequent attacks.

[0094] After implementing passive defense based on risk control assessment results and active defense based on risk control prediction results, it is necessary to continuously monitor the network's security status. If attacks or threats persist even after implementing new defense strategies, the risk control assessment and prediction results need to be reassessed, and the defense strategies updated accordingly.

[0095] In summary, the embodiments of this application have at least the following technical effects:

[0096] This application constructs a network topology by reading basic data from the Internet of Vehicles (IoV); retrieves driving logs within a predetermined time zone, performs risk control analysis to identify risk points, and generates a proprietary vulnerability database; fits the proprietary vulnerability database to the network topology and supervises the training of a risk control detection model; reads the network transmission signals to be detected and transmits them to the risk control detection model for risk level assessment to determine the network security coefficient; determines whether the network security coefficient meets the threshold standard and generates risk control early warning information based on the risk control source; and transmits the defense efficiency to the risk control detection model for protection level assessment. This solves the technical problems of low detection efficiency, poor real-time performance, and low accuracy in existing technologies, achieving improved detection efficiency, real-time performance, and high accuracy through IoV-based security detection.

[0097] Example 2

[0098] Based on the same inventive concept as the vehicle-to-everything (V2X) based security detection method in the foregoing embodiments, such as Figure 3 As shown, this application provides a vehicle-to-everything (V2X)-based safety detection system. The system and method embodiments in this application are based on the same inventive concept. The system includes:

[0099] A network topology construction module 11 is used to read basic data of the vehicle network and construct a network topology, wherein the network topology has timely update capability.

[0100] The proprietary vulnerability database generation module 12 generates a proprietary vulnerability database by retrieving driving logs within a predetermined time zone, performing risk control analysis to identify risk points, and generating the database.

[0101] The risk control detection model training module 13 trains the risk control detection model by fitting the proprietary vulnerability database and the network topology. The risk control detection model includes a parallel risk control prediction branch and a risk control detection branch.

[0102] Risk level assessment module 14 reads the network transmission signal to be detected and transmits it to the risk control detection model to conduct risk level assessment and determine the network security coefficient. The network security coefficient is marked with the risk control source.

[0103] The risk control early warning information generation module 15 generates risk control early warning information based on the risk control source by determining whether the network security coefficient meets the threshold standard.

[0104] Active and passive defense module 16, which triggers the protection system to perform active and passive defense against the risk control source based on the risk control early warning information, and provides feedback on the defense efficiency;

[0105] The protection level assessment module 17 transmits the defense efficiency to the risk control detection model to perform a protection level assessment.

[0106] Furthermore, the system also includes:

[0107] Based on the basic data of the Internet of Vehicles, a distributed network is built and the connection ports are identified. The connection ports include at least the vehicle terminal, mobile terminal, road network terminal and platform terminal.

[0108] The distributed network is differentiated based on the connection ports to determine the network topology.

[0109] Perform real-time tracking based on the connection port to synchronously update the network topology.

[0110] Furthermore, the system also includes:

[0111] Identify the driving logs and filter vehicle-to-everything (V2X) risk events related to cybersecurity;

[0112] The risk points of the aforementioned vehicle-to-everything (V2X) risk events are analyzed, and the sources of these risk points are traced to identify multiple risk control sequences. Each risk control sequence is represented as a risk point-risk control source.

[0113] Based on the risk control source, the multiple risk control sequences are clustered to determine multiple groups of risk control sequences;

[0114] Based on the aforementioned multiple risk control sequences, a proprietary vulnerability database is built.

[0115] Furthermore, the system also includes:

[0116] For the multiple risk control sequences, effective points are mined for each set of risk control sequences to determine multiple effective risk control sequences. Among them, effective risk points are risk points that meet the preset frequency.

[0117] The multiple effective risk control sequences are integrated into the proprietary vulnerability database.

[0118] Set a preset update cycle, call the time zone driving log based on periodic nodes, and extract the newly added risk control information;

[0119] Based on the newly added risk control information, incremental learning of the proprietary vulnerability database is performed.

[0120] Furthermore, the system also includes:

[0121] The interaction is based on the network location of the proprietary vulnerability database as a necessary detection point;

[0122] Read the network transmission signal based on the necessary detection points, transmit it to the risk control detection model for risk level assessment, and determine a risk control detection result;

[0123] Random detection points are determined, and based on a predetermined detection cycle, network transmission signals based on the random detection points are read and transmitted to the risk control detection model for risk level assessment, thereby determining two risk control detection results.

[0124] The network security coefficient is determined by combining the results of one risk control test with the results of two risk control tests.

[0125] Furthermore, the system also includes:

[0126] Based on the risk control detection branch, a real-time risk level assessment based on the network transmission signal is performed, and the risk control assessment result is output.

[0127] The risk control assessment results are transmitted to the risk control prediction branch, and predictions based on the scope of impact and risk nodes of the network transmission signals are performed to determine the risk control prediction results.

[0128] The network security coefficient is determined based on the risk control assessment results and the risk control prediction results.

[0129] Configure an active defense strategy based on the risk control prediction results.

[0130] Furthermore, the system also includes:

[0131] Based on the risk control assessment results, implement passive defense based on the protection system;

[0132] Based on the risk control prediction results, the protection system performs proactive defense based on an active defense strategy.

[0133] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0134] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

[0135] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and modifications fall within the scope of this application and its equivalents, this application intends to include such modifications and modifications.

Claims

1. A safety detection method based on vehicle-to-everything (V2X) communication, characterized in that, The method includes: Read the basic data of the vehicle network and construct a network topology, wherein the network topology is updated in a timely manner; Retrieve driving logs within the predetermined time zone, conduct risk control analysis to identify risk points, and generate a proprietary vulnerability database; Fit the proprietary vulnerability database to the network topology and supervise the training of the risk control detection model, which includes a parallel risk control prediction branch and a risk control detection branch. The network transmission signal to be detected is read and transmitted to the risk control detection model for risk level assessment to determine the network security coefficient, wherein the network security coefficient is marked with the risk control source; the determination of the network security coefficient includes: The interaction is based on the network location of the proprietary vulnerability database as a necessary detection point; Read the network transmission signal based on the necessary detection points, transmit it to the risk control detection model for risk level assessment, and determine a risk control detection result; Random detection points are determined, and based on a predetermined detection cycle, network transmission signals based on the random detection points are read and transmitted to the risk control detection model for risk level assessment, thereby determining two risk control detection results. By combining the results of one risk control test with the results of two risk control tests, the network security coefficient is determined; Determine whether the network security coefficient meets the threshold standard, and generate risk control early warning information based on the risk control source; Based on the risk control early warning information, the protection system is triggered to perform active and passive defense against the risk control source and to provide feedback on the defense efficiency. The defense efficiency is transmitted to the risk control detection model for protection level assessment.

2. The method as described in claim 1, characterized in that, The method involves reading basic data from the vehicle network and constructing a network topology, including: Based on the basic data of the Internet of Vehicles, a distributed network is built and the connection ports are identified. The connection ports include at least the vehicle terminal, mobile terminal, road network terminal and platform terminal. The distributed network is differentiated based on the connection ports to determine the network topology. Perform real-time tracking based on the connection port to synchronously update the network topology.

3. The method as described in claim 1, characterized in that, The method involves conducting risk control analysis to identify risk points and generating a proprietary vulnerability database. Identify the driving logs and filter vehicle-to-everything (V2X) risk events related to cybersecurity; The risk points of the aforementioned vehicle-to-everything (V2X) risk events are analyzed, and the sources of these risk points are traced to identify multiple risk control sequences. Each risk control sequence is represented as a risk point-risk control source. Based on the risk control source, the multiple risk control sequences are clustered to determine multiple groups of risk control sequences; Based on the aforementioned multiple risk control sequences, a proprietary vulnerability database is built.

4. The method as described in claim 3, characterized in that, Based on the aforementioned multiple risk control sequences, the proprietary vulnerability database is constructed. This method includes: For the multiple risk control sequences, effective points are mined for each set of risk control sequences to determine multiple effective risk control sequences. Among them, effective risk points are risk points that meet the preset frequency. The multiple effective risk control sequences are integrated into the proprietary vulnerability database. Set a preset update cycle, call the time zone driving log based on periodic nodes, and extract the newly added risk control information; Based on the newly added risk control information, incremental learning of the proprietary vulnerability database is performed.

5. The method as described in claim 1, characterized in that, The method involves transmitting the data to the risk control detection model for risk level assessment, and includes: Based on the risk control detection branch, a real-time risk level assessment based on the network transmission signal is performed, and the risk control assessment result is output. The risk control assessment results are transmitted to the risk control prediction branch, and predictions based on the scope of impact and risk nodes of the network transmission signals are performed to determine the risk control prediction results. The network security coefficient is determined based on the risk control assessment results and the risk control prediction results. Configure an active defense strategy based on the risk control prediction results.

6. The method as described in claim 5, characterized in that, The trigger protection system performs active and passive defense against the risk control source, the method including: Based on the risk control assessment results, implement passive defense based on the protection system; Based on the risk control prediction results, the protection system performs proactive defense based on an active defense strategy.

7. A vehicle-to-everything (V2X) based safety detection system, characterized in that: The system includes: A network topology construction module is used to read basic data of the vehicle network and construct a network topology, wherein the network topology is updated in a timely manner. A proprietary vulnerability database generation module, which generates a proprietary vulnerability database by retrieving driving logs within a predetermined time zone, performing risk control analysis to identify risk points; The risk control detection model training module trains the risk control detection model by fitting the proprietary vulnerability database and the network topology. The risk control detection model includes a parallel risk control prediction branch and a risk control detection branch. The risk level assessment module reads the network transmission signal to be detected and transmits it to the risk control detection model for risk level assessment to determine the network security coefficient. The network security coefficient is marked with the risk control source. The module is also used to interact with the network location based on the proprietary vulnerability database as a necessary detection point. Read the network transmission signal based on the necessary detection points, transmit it to the risk control detection model for risk level assessment, and determine a risk control detection result; Random detection points are determined, and based on a predetermined detection cycle, network transmission signals based on the random detection points are read and transmitted to the risk control detection model for risk level assessment, thereby determining two risk control detection results. By combining the results of one risk control test with the results of two risk control tests, the network security coefficient is determined; A risk control early warning information generation module generates risk control early warning information based on risk control sources by determining whether the network security coefficient meets the threshold standard. An active and passive defense module, which triggers the protection system to perform active and passive defense against the risk control source based on the risk control early warning information, and provides feedback on the defense efficiency; The protection level assessment module transmits the defense efficiency to the risk control detection model to perform a protection level assessment.

Citation Information

Patent Citations

  • Vehicle safety operation and maintenance operation system based on central computing platform and vehicle

    CN115296860A

  • Security assessment method and device, equipment and storage medium

    CN116150756A

  • Method about data center network asset topology

    CN116232907A

  • Information system risk assessment method and system

    CN116248489A

  • Vehicle network security early warning method and device, electronic equipment and storage medium

    CN116488911A