A vehicle network attack group warning and protection method based on end-cloud collaboration

Through end-cloud collaboration, the intrusion warning information and operation data of the first vehicle are used to conduct risk analysis, generate and send solutions, solve the real-time protection problem of cross-vehicle network threats, and improve the response capability of vehicle information security.

CN119696865BActive Publication Date: 2025-09-12BEIHANG UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411812177.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-10
Publication Date
2025-09-12
Estimated Expiration
2044-12-10

AI Technical Summary

Technical Problem

Existing technologies lack an effective coordination mechanism to respond to cross-vehicle network threats in real time, resulting in the inability to respond to vehicle information security incidents in a timely manner. Attacks may spread to other vehicles, and traditional information security responses are delayed and unable to effectively prevent the spread of attacks.

Method used

Through end-cloud collaboration, the first vehicle that detects an intrusion incident receives intrusion warning information and operating data, conducts risk analysis, determines the risk prediction results of the second vehicle that may be affected, and generates a solution, which is sent to the second vehicle for protection.

Benefits of technology

It enables real-time response to cross-vehicle network threats, improves the information security protection capabilities of all vehicles in a certain area, and provides timely warnings and protection through cloud-based supervision, reducing the risk of attack spread.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119696865B_ABST
    Figure CN119696865B_ABST
Patent Text Reader

Abstract

This invention provides a method for early warning and protection against group cyberattacks on vehicles based on end-to-end collaboration, relating to the field of automotive information security technology. The method comprises: when a first vehicle detects an intrusion event, receiving an intrusion warning message and first operating data of the first vehicle; performing a risk analysis on the intrusion warning message and the first operating data to determine a risk prediction result for a second vehicle other than the first vehicle being attacked; generating a solution to the intrusion event and, based on the risk prediction result, sending the solution to the second vehicle. This solution enhances the information security protection capabilities of all vehicles within a certain area.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of automobile information security technology, and in particular to a method for early warning and protection against automobile network attack groups based on end-cloud collaboration. Background Art

[0002] As vehicles become increasingly intelligent and connected, the development of vehicle-to-everything (V2X) technology enables vehicles to communicate with cloud platforms, the surrounding environment, other vehicles, and infrastructure. However, this high degree of network connectivity also exposes vehicles to more attack surfaces, making them more vulnerable to cyberattacks. Consequently, relevant regulations and standards require vehicle manufacturers and relevant departments to establish comprehensive vehicle information security management systems and implement emergency response measures for information security incidents, thereby mitigating automotive safety risks.

[0003] On the one hand, current vehicle information security measures mostly focus on the defense of the vehicle itself, lacking an effective coordination mechanism to respond to cross-vehicle cyber threats in real time. On the other hand, leveraging other vehicles' experience in responding to information security threats to improve their own capabilities is often achieved through periodic remote over-the-air (OTA) upgrades, which often occur several months apart. In a connected vehicle environment, once a vehicle is attacked, other vehicles may be at similar risk due to lack of timely alerts and using similar information security configurations, and may also be vulnerable to the same attack method. In addition, traditional information security responses often lag behind the attack, resulting in an inability to effectively prevent the spread of the attack. Therefore, a method for early warning and protection against group automotive cyber attacks based on end-cloud collaboration is needed. Summary of the Invention

[0004] The present invention provides a method for early warning and protection against group automobile network attacks based on end-cloud collaboration. By analyzing the invaded vehicle, the network security attack warning against the vehicle is spread to all vehicles within the possible impact range, thereby improving the information security early warning and protection capabilities of all vehicles in the area.

[0005] In a first aspect, the present invention provides a method for early warning and protection against group attacks on automobile networks based on end-cloud collaboration, comprising:

[0006] When a first vehicle detects an intrusion event, receiving intrusion warning information and first operating data of the first vehicle;

[0007] performing a risk analysis on the intrusion warning information and the first operating data to determine a risk prediction result of a second vehicle other than the first vehicle being attacked;

[0008] A solution for the intrusion event is generated, and the solution is sent to the second vehicle based on the risk prediction result.

[0009] Optionally, the intrusion warning information includes the geographical location of the first vehicle when the intrusion event is detected, the target controller and target network attacked by the intrusion event, and the repair status of the first vehicle when the intrusion warning information is issued;

[0010] The first operating data includes an operating trajectory of the first vehicle, in-vehicle communication data, and vehicle-to-vehicle communication data between the first vehicle and the second vehicle.

[0011] Optionally, before performing risk analysis on the intrusion alarm information and the first operating data, the method further includes:

[0012] Determining a communication influence range centered on the first vehicle based on the communicable range of the first vehicle; wherein the communication influence range changes in real time as the first vehicle moves;

[0013] Determining the running trajectory of the first vehicle as a path influence range;

[0014] Determining whether the intrusion event is a spreadable virus according to the intrusion alarm information;

[0015] If the judgment result is yes, then determining the virus infection wave;

[0016] The total impact range of the intrusion event is determined according to the communication impact range, the path impact range and the virus infection wave; wherein the second vehicle is located within the total impact range.

[0017] Optionally, performing risk analysis on the intrusion warning information and the first operating data to determine a risk prediction result of a second vehicle other than the first vehicle being attacked includes:

[0018] Performing attack path analysis based on the intrusion alarm information and the first operating data to determine the location of the vulnerability;

[0019] Performing a risk analysis on the second vehicle based on the vulnerability location, the target controller, the target network, and the geographic location to determine a probability that the second vehicle will be attacked by the intrusion event;

[0020] When the repair status is unrepaired, the risk behavior caused by the first vehicle to the second vehicle is predicted based on the first operating data and the second operating data of the second vehicle; wherein the risk prediction result includes the probability of being attacked by the intrusion event and the risk behavior.

[0021] Optionally, generating a solution for the intrusion event includes:

[0022] adding a contamination mark to the inter-vehicle communication data; wherein the contamination mark is used to indicate that the inter-vehicle communication data received by the second vehicle is at risk;

[0023] When the repair status is repaired, determining a temporary solution adopted by the first vehicle from the first operating data, and using the temporary solution as a short-term solution for emergency recovery;

[0024] When the repair status is unrepaired, analyzing the intrusion event to generate a short-term plan for emergency recovery;

[0025] The intrusion event and the first operating data are analyzed to determine a long-term solution for repair.

[0026] Optionally, sending the solution to the second vehicle according to the risk prediction result includes:

[0027] determining a second vehicle that presents a risk based on the risk prediction result;

[0028] When the repair status is repaired, sending the short-term solution to the second vehicle at risk;

[0029] When the repair status is unrepaired, sending the short-term solution to the first vehicle for verification to obtain a verification result;

[0030] When receiving the verification result as valid, sending the short-term plan to the second vehicle at risk;

[0031] The long-term plan is sent to the second vehicle.

[0032] Optionally, it also includes:

[0033] When the repair status is unrepaired, the communication connection between the first vehicle and the second vehicle is disconnected, and when the repair status is repaired, the communication connection between the first vehicle and the second vehicle is restored.

[0034] In a second aspect, the present invention provides a vehicle network attack group warning and protection device based on end-cloud collaboration, comprising:

[0035] a response module, configured to receive intrusion warning information and first operating data of the first vehicle when the first vehicle detects an intrusion event;

[0036] an analysis module, configured to perform a risk analysis on the intrusion warning information and the first operating data, and determine a risk prediction result of a second vehicle other than the first vehicle being attacked;

[0037] A protection module is used to generate a solution for the intrusion event and send the solution to the second vehicle based on the risk prediction result.

[0038] In a third aspect, an embodiment of the present invention further provides a computing device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the method described in any first aspect of this specification is implemented.

[0039] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to execute the method described in any one of the first aspects of this specification.

[0040] In a fifth aspect, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the steps of the method described in any first aspect of this specification.

[0041] An embodiment of the present invention provides a method for early warning and protection against group attacks on automobile networks based on end-cloud collaboration. It is applied in the cloud. When a first vehicle detects an intrusion event, it receives intrusion warning information and the operating data of the first vehicle. Then, it performs risk analysis based on the intrusion warning information and the operating data to determine the risk prediction results of attacks on other vehicles (i.e., the second vehicle) in a certain area other than the first vehicle, and generates a solution for the intrusion event so that the solution can be sent to the second vehicle for protection based on the risk prediction results. In this way, the present invention obtains data on vehicles that have been invaded through the cloud so as to determine the risk prediction results of attacks on other vehicles caused by the vehicle through analysis, and completes risk warnings for other vehicles; at the same time, protection for other vehicles is achieved by sending the solution to other vehicles. The present invention gives full play to the supervisory role of the cloud and improves the information security protection capabilities of all vehicles in a certain area. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0043] Figure 1 This is a flow chart of a method for early warning and protection against group attacks on automobile networks based on end-cloud collaboration, provided by one embodiment of the present invention;

[0044] Figure 2 This is a hardware architecture diagram of a computing device provided by one embodiment of the present invention;

[0045] Figure 3 This is a structural diagram of a vehicle network attack group warning and protection device based on end-cloud collaboration provided by one embodiment of the present invention. DETAILED DESCRIPTION

[0046] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0047] The specific implementation of the concept of this application is described below.

[0048] Please refer to Figure 1 The embodiment of the present invention provides a method for early warning and protection against group attacks on automobile networks based on end-cloud collaboration, which is applied in the cloud. The method includes:

[0049] Step 100 , when a first vehicle detects an intrusion event, receiving intrusion warning information and first operating data of the first vehicle;

[0050] Step 102: Perform risk analysis on the intrusion warning information and the first operating data to determine a risk prediction result of a second vehicle other than the first vehicle being attacked;

[0051] Step 104 : Generate a solution to the intrusion event and send the solution to the second vehicle based on the risk prediction result.

[0052] In an embodiment of the present invention, when a first vehicle detects an intrusion event, it receives intrusion alarm information and the operating data of the first vehicle, and then performs risk analysis based on the intrusion alarm information and the operating data to determine the risk prediction results of attacks on other vehicles (i.e., the second vehicle) within a certain area other than the first vehicle, and generates a solution for the intrusion event so that the solution can be sent to the second vehicle for protection based on the risk prediction results. In this way, the present invention obtains data on vehicles that have been invaded through the cloud, so as to determine the risk prediction results of attacks on other vehicles caused by the vehicle through analysis, and complete risk warnings for other vehicles; at the same time, protection of other vehicles is achieved by sending the solution to other vehicles. The present invention gives full play to the supervisory role of the cloud, realizes real-time response to cross-vehicle network threats, and improves the information security protection capabilities of all vehicles in a certain area.

[0053] It should be noted that in the present invention, both the first vehicle and the second vehicle can be connected to the cloud, and the vehicles and the cloud can communicate with each other; the present invention does not make specific restrictions on the transmission method and communication protocol used, but only restricts the content of the transmitted data.

[0054] Described below Figure 1 How to perform the steps shown.

[0055] First, in step 100, the intrusion warning information includes the geographical location of the first vehicle when the intrusion event is detected, the target controller and target network attacked by the intrusion event, and the repair status of the first vehicle when the intrusion warning information is issued;

[0056] The first operating data includes an operating trajectory of the first vehicle, in-vehicle communication data, and vehicle-to-vehicle communication data between the first vehicle and the second vehicle.

[0057] It should be noted that the model and brand of the first vehicle and the second vehicle may be the same or different. At the same time, in order to implement the method of the present invention, both the first vehicle and the second vehicle can process the solution normally to achieve protection; and the first vehicle is equipped with an information security intrusion monitoring system (IDS) or an intrusion detection and prevention system (IDPS). Among them, the operating data in the present invention are all desensitized vehicle network data streams and expected driving paths, and the expected driving path is a planned route planned by on-board navigation. The operating trajectory is used to represent the vehicle's actual historical driving path and the expected driving path at a future moment.

[0058] After step 100 and before step 102, the method further includes:

[0059] Determining a communication influence range centered on the first vehicle based on the communicable range of the first vehicle; wherein the communication influence range changes in real time as the first vehicle moves;

[0060] Determining the running trajectory of the first vehicle as the path influence range;

[0061] Determine whether the intrusion event is a spreadable virus based on the intrusion alarm information;

[0062] If the judgment result is yes, the virus transmission wave is determined;

[0063] The total impact range of the intrusion event is determined based on the communication impact range, the path impact range, and the virus transmission wave; wherein the second vehicle is located within the total impact range.

[0064] It should be noted that communication methods between different vehicles mainly include vehicle ad hoc networking technology, cellular communication, multi-hop communication, and vehicle communication technology based on communication base stations. The communication range is affected by the communication distance of the communication technology. For example, if the communication range of Wi-Fi is 50 meters, the communication range is the area with a radius of 50 meters centered on the geographic location of the first vehicle at time t. This range also changes as the vehicle moves.

[0065] In the present invention, the communication range moves as a whole along with the path influence range. At the same time, the viruses that cause the intrusion event are divided into transmissible viruses and non-transmissible viruses. If it is a transmissible virus, the propagation range of the virus needs to be considered. Finally, by performing a union operation on the communication influence range, the path influence range and the virus transmission wave, the time domain and spatial domain range affected by the intrusion event are determined, so as to provide early warning and protection for the second vehicle affected by the intrusion event in the specific area, thereby improving the information protection capability of other vehicles.

[0066] With respect to step 102, a risk analysis is performed on the intrusion warning information and the first operating data to determine a risk prediction result of a second vehicle other than the first vehicle being attacked, including:

[0067] Perform attack path analysis based on the intrusion alarm information and the first operation data to determine the location of the vulnerability;

[0068] Performing a risk analysis on the second vehicle based on the vulnerability location, target controller, target network, and geographic location to determine the probability of the second vehicle being attacked by the intrusion event;

[0069] When the repair status is unrepaired, risk behavior caused by the first vehicle to the second vehicle is predicted based on the first operating data and the second operating data of the second vehicle; wherein the risk prediction result includes the probability of being attacked by the intrusion event and the risk behavior.

[0070] In the present invention, for the second vehicle, the probability of being attacked in the same way at the location of the vulnerability, the target controller, the target network, and the same geographical location is greater, so it is necessary to focus on analyzing these factors to determine the probability of the second vehicle being attacked in the same way by the intrusion event. At the same time, when the first vehicle is not repaired, since the first vehicle still carries the intrusion virus, there is not only a risk of transmission during continued driving, but also uncontrollable risk behavior. The risk behavior is the risk caused by the first vehicle to the second vehicle (chain event attack caused by the intrusion event), including physical field risks, such as collisions caused by the loss of control of the first vehicle; cyber domain risks, such as using the vehicle to attack other surrounding vehicles. In this way, the risk prediction results including the probability of being attacked by the intrusion event and the risk behavior are obtained through prediction, and an early warning is provided to the second vehicle in a timely manner.

[0071] In a preferred embodiment, the method further includes: sending the risk prediction result to the corresponding second vehicle, so as to issue an early warning when the second vehicle receives the risk prediction result.

[0072] In step 104, a solution to the intrusion event is generated, including:

[0073] Adding a contamination mark to the inter-vehicle communication data; wherein the contamination mark is used to indicate that the inter-vehicle communication data received by the second vehicle is at risk;

[0074] When the repair status is repaired, determining a temporary solution adopted by the first vehicle from the first operating data, and using the temporary solution as a short-term solution for emergency recovery;

[0075] When the repair status is unrepaired, analyze the intrusion event and generate a short-term plan for emergency recovery;

[0076] Analyze the intrusion incident and first run data to determine a long-term plan for remediation.

[0077] It should be noted that short-term solutions can include forcing nearby vehicles to switch key seeds, updating certificates, re-establishing a network with nearby devices and vehicles, re-verifying, or using a hotfix to fix the vulnerability. Long-term solutions can include using an OTA fix, locating the attacker, or reporting to relevant departments or alerting the police.

[0078] In the present invention, since there is inter-vehicle communication data between the first vehicle and the second vehicle, in order to further prevent the second vehicle from being attacked by risks in the inter-vehicle communication data, the data can be intercepted or prompted to the second vehicle by adding a pollution mark, thereby further improving the risk warning for other vehicles. At the same time, for the short-term emergency recovery plan, it is first determined whether the first vehicle has been repaired. If it has been repaired, the temporary solution adopted by the first vehicle is directly used as the short-term plan; if it has not been repaired, the intrusion event is analyzed to generate a short-term plan. Finally, after determining the short-term plan, in order to further improve the vehicle's protection against the intrusion event, the intrusion event and the first operating data are further comprehensively analyzed to further determine the optimal long-term plan for repair, so as to try to avoid the vehicle from being attacked in the future.

[0079] In the present invention, after emergency treatment is carried out through a short-term solution, the current intrusion incident is resolved, and the first vehicle is repaired, a long-term solution is further used to comprehensively protect the first vehicle, thereby improving the vehicle's safety protection capability.

[0080] In step 104, a solution is sent to the second vehicle based on the risk prediction result, including:

[0081] Determine a second vehicle that presents a risk based on the risk prediction result;

[0082] When the repair status is repaired, a short-term solution is sent to the second vehicle at risk;

[0083] When the repair status is unrepaired, the short-term solution is sent to the first vehicle for verification to obtain a verification result;

[0084] Upon receiving a validation result that is valid, sending the short-term plan to the second vehicle at risk;

[0085] The long-term plan is sent to the second vehicle.

[0086] In the present invention, the risk prediction result indicating that the probability of being attacked by an intrusion event is greater than a preset threshold, and the second vehicle corresponding to the risk prediction result indicating the presence of risky behavior, are determined as the second vehicle at risk, so that a short-term solution is immediately sent to the second vehicle at risk for early warning and protection; at the same time, a long-term solution is sent to the second vehicle to enhance its security protection capabilities. Specifically, for the short-term solution, if the repair status of the first vehicle is repaired, the short-term solution is directly sent to the second vehicle at risk; however, if the repair status of the first vehicle is unrepaired, the short-term solution generated in the cloud needs to be further verified on the first vehicle, and the verification result is fed back to the cloud. If the verification result is valid, the short-term solution is sent from the cloud to the second vehicle at risk.

[0087] In a preferred embodiment, it also includes:

[0088] When the repair status is unrepaired, the communication connection between the first vehicle and the second vehicle is disconnected, and when the repair status is repaired, the communication connection between the first vehicle and the second vehicle is restored.

[0089] In the present invention, since the first vehicle and the second vehicle can communicate, in order to further reduce the risk of the second vehicle being attacked, the communication connection between the first vehicle and the second vehicle can be disconnected when the first vehicle is not repaired, and the communication connection can be restored when it is monitored that the first vehicle has been repaired.

[0090] In a preferred embodiment, it also includes:

[0091] Determine a risk avoidance path for the second vehicle based on the risk prediction result, the running trajectory of the first vehicle, and the running trajectory of the second vehicle.

[0092] In the present invention, by analyzing the risk prediction results and the expected operation trajectory of the vehicle, a vehicle-side information security response plan is formulated for the second vehicle, or the affected area is avoided.

[0093] In this invention, the above-mentioned method, based on end-to-end cloud collaboration, enables real-time data processing and decision-making in vehicles. It also uploads intrusion warning information and first operational data to the cloud for deeper analysis and learning, resulting in more optimal solutions and improving the safety and protection capabilities of existing vehicles. Furthermore, by distributing some computing tasks to the terminal, bandwidth resources are conserved, fully leveraging the respective advantages of cloud computing and terminal devices to achieve efficient resource utilization.

[0094] like Figure 2 、 Figure 3 As shown, the embodiment of the present invention provides a vehicle network attack group warning and protection device based on end-cloud collaboration. The device embodiment can be implemented through software, hardware, or a combination of software and hardware. From the hardware level, such as Figure 2 The figure shows a hardware architecture diagram of a computing device where a vehicle network attack group warning and protection device based on end-cloud collaboration is located, in addition to Figure 2 In addition to the processor, memory, network interface, and non-volatile memory shown, the computing device in the embodiment may also include other hardware, such as a forwarding chip responsible for processing messages, etc. Taking software implementation as an example, Figure 3 As shown, as a logical device, the CPU of the computing device in which it is located reads the corresponding computer program in the non-volatile memory into the internal memory and runs it. This embodiment provides a vehicle network attack group warning and protection device based on end-cloud collaboration, which includes:

[0095] A response module 300 is configured to receive intrusion warning information and first operating data of the first vehicle when an intrusion event is detected by the first vehicle;

[0096] An analysis module 302 is configured to perform a risk analysis on the intrusion warning information and the first operating data to determine a risk prediction result of a second vehicle other than the first vehicle being attacked;

[0097] The protection module 304 is configured to generate a solution for the intrusion event and send the solution to the second vehicle based on the risk prediction result.

[0098] In some specific implementations, the response module 300 may be used to perform the above step 100 , the analysis module 302 may be used to perform the above step 102 , and the protection module 304 may be used to perform the above step 104 .

[0099] In one embodiment of the present invention, the intrusion warning information includes the geographic location of the first vehicle when the intrusion event is detected, the target controller and target network attacked by the intrusion event, and the repair status of the first vehicle when the intrusion warning information is issued;

[0100] The first operating data includes an operating trajectory of the first vehicle, in-vehicle communication data, and vehicle-to-vehicle communication data between the first vehicle and the second vehicle.

[0101] In one embodiment of the present invention, the analysis module 302 is further configured to perform the following operations:

[0102] Determining a communication influence range centered on the first vehicle based on the communicable range of the first vehicle; wherein the communication influence range changes in real time as the first vehicle moves;

[0103] Determining the running trajectory of the first vehicle as the path influence range;

[0104] Determine whether the intrusion event is a spreadable virus based on the intrusion alarm information;

[0105] If the judgment result is yes, the virus transmission wave is determined;

[0106] The total impact range of the intrusion event is determined based on the communication impact range, the path impact range, and the virus transmission wave; wherein the second vehicle is located within the total impact range.

[0107] In one embodiment of the present invention, the analysis module 302 is further configured to perform the following operations:

[0108] Perform attack path analysis based on the intrusion alarm information and the first operation data to determine the location of the vulnerability;

[0109] Performing a risk analysis on the second vehicle based on the vulnerability location, target controller, target network, and geographic location to determine the probability of the second vehicle being attacked by the intrusion event;

[0110] When the repair state is unrepaired, predicting a risk behavior of the first vehicle on the second vehicle based on the first operating data and the second operating data of the second vehicle; wherein the risk prediction result includes the probability of being attacked by the intrusion event and the risk behavior;

[0111] The risk prediction result is sent to the corresponding second vehicle.

[0112] In one embodiment of the present invention, the protection module 304 is further configured to perform the following operations:

[0113] Adding a contamination mark to the inter-vehicle communication data; wherein the contamination mark is used to indicate that the inter-vehicle communication data received by the second vehicle is at risk;

[0114] When the repair status is repaired, determining a temporary solution adopted by the first vehicle from the first operating data, and using the temporary solution as a short-term solution for emergency recovery;

[0115] When the repair status is unrepaired, analyze the intrusion event and generate a short-term plan for emergency recovery;

[0116] Analyze the intrusion incident and first run data to determine a long-term plan for remediation;

[0117] Determine a second vehicle that presents a risk based on the risk prediction result;

[0118] When the repair status is repaired, a short-term solution is sent to the second vehicle at risk;

[0119] When the repair status is unrepaired, the short-term solution is sent to the first vehicle for verification to obtain a verification result;

[0120] Upon receiving a validation result that is valid, sending the short-term plan to the second vehicle at risk;

[0121] The long-term plan is sent to the second vehicle.

[0122] In one embodiment of the present invention, the protection module 304 is further configured to perform the following operations:

[0123] When the repair status is unrepaired, the communication connection between the first vehicle and the second vehicle is disconnected, and when the repair status is repaired, the communication connection between the first vehicle and the second vehicle is restored.

[0124] It should be understood that the illustrated structure of the embodiments of the present invention does not constitute a specific limitation on a device-cloud collaborative automotive network attack swarm warning and protection device. In other embodiments of the present invention, a device-cloud collaborative automotive network attack swarm warning and protection device may include more or fewer components than illustrated, or may combine or separate certain components, or employ different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of both.

[0125] The information interaction, execution process, etc. between the modules in the above-mentioned device are based on the same concept as the embodiment of the method of the present invention. For specific contents, please refer to the description in the embodiment of the method of the present invention and will not be repeated here.

[0126] An embodiment of the present invention also provides a computing device including a memory and a processor, wherein the memory stores a computer program. When the processor executes the computer program, it implements a method for early warning and protection against group automobile network attacks based on end-cloud collaboration in any embodiment of the present invention.

[0127] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the processor executes a method for early warning and protection against group automobile network attacks based on end-cloud collaboration in any embodiment of the present invention.

[0128] An embodiment of the present application also provides a computer program product, which includes a computer program. The processor of a computer device reads the computer program from a computer-readable storage medium, and the processor executes the computer program, so that the computer device executes any of the above-mentioned embodiments. A method for early warning and protection against group automobile network attacks based on end-cloud collaboration.

[0129] Specifically, a system or device equipped with a storage medium can be provided, on which software program codes that implement the functions of any of the above-mentioned embodiments are stored, and a computer (or CPU or MPU) of the system or device can be enabled to read and execute the program codes stored in the storage medium.

[0130] In this case, the program code itself read from the storage medium can realize the function of any one of the above-mentioned embodiments, and thus the program code and the storage medium storing the program code constitute part of the present invention.

[0131] Examples of storage media for providing program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Alternatively, the program code can be downloaded from a server computer via a communication network.

[0132] In addition, it should be clear that the functions of any of the above embodiments can be achieved not only by executing the program code read by the computer, but also by enabling the operating system on the computer to complete part or all of the actual operations based on instructions of the program code.

[0133] In addition, it can be understood that the program code read from the storage medium is written into a memory provided in an expansion board inserted into the computer or into a memory provided in an expansion module connected to the computer, and then based on the instructions of the program code, a CPU installed on the expansion board or expansion module is enabled to perform part or all of the actual operations, thereby realizing the functions of any of the above embodiments.

[0134] It should be noted that, in this article, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises", "comprising" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprising a ..." do not exclude the presence of other identical factors in the process, method, article or device comprising the elements.

[0135] Those skilled in the art will understand that all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: ROM, RAM, disk or optical disk, etc. Various media that can store program codes.

[0136] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A vehicle network attack group warning and protection method based on end-cloud collaboration, characterized by: include: When a first vehicle detects an intrusion event, receiving intrusion warning information and first operating data of the first vehicle; The intrusion warning information includes the geographical location of the first vehicle when the intrusion event is detected, the target controller and target network attacked by the intrusion event, and the repair status of the first vehicle when the intrusion warning information is issued; Determining a communication influence range centered on the first vehicle based on the communicable range of the first vehicle; wherein the communication influence range changes in real time as the first vehicle moves; Determining the running trajectory of the first vehicle as a path influence range; Determining whether the intrusion event is a spreadable virus according to the intrusion alarm information; If the judgment result is yes, then determining the virus infection wave; determining a total impact range of the intrusion event based on the communication impact range, the path impact range, and the virus infection wave; wherein the second vehicle is located within the total impact range; Performing attack path analysis based on the intrusion alarm information and the first operating data to determine the location of the vulnerability; Performing a risk analysis on the second vehicle based on the vulnerability location, the target controller, the target network, and the geographic location to determine a probability that the second vehicle will be attacked by the intrusion event; When the repair state is unrepaired, predicting a risk behavior of the first vehicle on the second vehicle based on the first operating data and the second operating data of the second vehicle; wherein the risk prediction result includes a probability of being attacked by the intrusion event and the risk behavior; A solution for the intrusion event is generated, and the solution is sent to the second vehicle based on the risk prediction result.

2. The method according to claim 1, characterized in that The first operating data includes an operating trajectory of the first vehicle, in-vehicle communication data, and vehicle-to-vehicle communication data between the first vehicle and the second vehicle.

3. The method according to claim 2, characterized in that Generating a solution to the intrusion event includes: adding a contamination mark to the inter-vehicle communication data; wherein the contamination mark is used to indicate that the inter-vehicle communication data received by the second vehicle is at risk; When the repair status is repaired, determining a temporary solution adopted by the first vehicle from the first operating data, and using the temporary solution as a short-term solution for emergency recovery; When the repair status is unrepaired, analyzing the intrusion event to generate a short-term plan for emergency recovery; The intrusion event and the first operating data are analyzed to determine a long-term solution for repair.

4. The method according to claim 3, characterized in that The step of sending the solution to the second vehicle according to the risk prediction result includes: determining a second vehicle that presents a risk based on the risk prediction result; When the repair status is repaired, sending the short-term solution to the second vehicle at risk; When the repair status is unrepaired, sending the short-term solution to the first vehicle for verification to obtain a verification result; When receiving the verification result as valid, sending the short-term plan to the second vehicle at risk; The long-term plan is sent to the second vehicle.

5. The method according to claim 2, characterized in that Also includes: When the repair status is unrepaired, the communication connection between the first vehicle and the second vehicle is disconnected, and when the repair status is repaired, the communication connection between the first vehicle and the second vehicle is restored.

6. A vehicle network attack group warning and protection device based on end-cloud collaboration, characterized in that: Used to implement the method according to any one of claims 1 to 5, comprising: a response module, configured to receive intrusion warning information and first operating data of the first vehicle when the first vehicle detects an intrusion event; an analysis module, configured to perform a risk analysis on the intrusion warning information and the first operating data, and determine a risk prediction result of a second vehicle other than the first vehicle being attacked; A protection module is used to generate a solution for the intrusion event and send the solution to the second vehicle based on the risk prediction result.

7. A computing device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the method according to any one of claims 1 to 5 is implemented.

8. A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to execute the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Industrial control network security defense method and device, electronic equipment and storage medium

    CN116319022A