Vehicle cyber intrusion response method, device, and computer-readable storage medium
By analyzing vehicle networks in real time and applying a threat intelligence database, the threat level of network intrusion behavior is determined and corresponding strategies are implemented. This solves the problems of slow response, low automation, and poor linkage in existing automotive security systems, and achieves rapid and accurate network intrusion response and comprehensive protection.
Patent Information
- Application Number
- CN202411822084.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-11
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-12-11
AI Technical Summary
Existing automotive safety systems cannot respond to cyberattacks in real time, have low levels of automation, complex and inflexible security policy configurations, lack effective linkage, and are unable to cope with complex cyber intrusion behaviors.
By analyzing security incident data in vehicle networks in real time, alarm information is generated. Threat intelligence database is used to determine whether the alarm information is a real threat. Based on the threat level, corresponding intrusion response strategies are executed, including multi-layered defense measures and automated emergency handling processes, and support the linkage of multiple security devices.
It enables rapid response and accurate handling of network intrusion attempts, improves the security and reliability of vehicle networks, reduces false alarms and missed alarms, and forms a comprehensive security protection system.
Smart Images

Figure CN119728197B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of automotive network security technology, and in particular to a vehicle network intrusion response method, device and computer-readable storage medium. Background Technology
[0002] With the development of intelligent and connected vehicles, automotive cybersecurity issues are becoming increasingly prominent. Hackers can use various methods to intrude into vehicle systems, illegally control vehicles, and seriously threaten the lives of drivers and passengers. However, current automotive security systems mostly focus on physical protection and simple software security strategies, lacking effective response and emergency handling mechanisms for complex cyberattacks and intrusions.
[0003] Currently, some automotive security solutions on the market can improve the security of automotive networks to a certain extent, such as firewalls and intrusion detection systems (IDS). However, traditional security systems often rely on manual intervention or periodic scanning, and cannot respond to network attacks in real time. Furthermore, they suffer from complex and inflexible security policy configurations, making them difficult to adapt to ever-changing network attack methods.
[0004] Therefore, improving the defense capabilities of automotive networks is an urgent problem to be solved. Summary of the Invention
[0005] To overcome the problems existing in related technologies, this specification provides a method, device and computer-readable storage medium for responding to vehicle network intrusions.
[0006] According to a first aspect of the embodiments of this specification, a vehicle network intrusion response method is provided, the method comprising:
[0007] Analyze security event data in the vehicle network and generate alarm information based on the security event data that identifies network intrusion behavior;
[0008] Determine whether the alarm information is a real threat;
[0009] Based on whether the alarm information is a real threat, the threat level of the network intrusion behavior is determined;
[0010] Execute the defensive measures in the intrusion response strategy corresponding to the threat level to address the threat of the network intrusion.
[0011] According to a vehicle network intrusion response method provided in this application, determining whether the alarm information is a real threat includes:
[0012] Acquire a threat intelligence database, which includes at least one known threat related to vehicle network security; the threat intelligence database includes any of the following collected from the vehicle network: search behavior records, hacker activity characteristics, and resource information provided by white hat hackers.
[0013] Determine whether the alarm information matches known threat information in the threat intelligence database, and determine whether the alarm information is a real threat.
[0014] According to the vehicle network intrusion response method provided in this application, the alarm information includes multi-dimensional alarm attributes;
[0015] Determining whether the alarm information matches known threat information in the threat intelligence database, and determining whether the alarm information is a real threat, includes:
[0016] Based on the filtering conditions associated with alarm filtering attributes related to the vehicle network, and based on the multi-dimensional alarm attributes of the alarm information, the alarm information is filtered.
[0017] Determine whether the filtered alert information matches known threat information in the threat intelligence database, and determine whether the alert information is a real threat.
[0018] According to the vehicle network intrusion response method provided in this application, the alarm information includes alarm content;
[0019] Determining whether the alarm information matches known threat information in the threat intelligence database, and determining whether the alarm information is a real threat, includes:
[0020] Based on the unique source of the data and / or data integrity, select the content from the alarm content for analysis;
[0021] The selected content is matched with the corresponding content in the known threat information to determine whether the alarm information is a real threat.
[0022] According to the vehicle network intrusion response method provided in this application, the alarm information also includes multi-dimensional alarm attributes;
[0023] The step of matching the selected content with the corresponding content in the known threat information to determine whether the alarm information is a real threat includes:
[0024] The selected content is matched with the corresponding content in the known threat information to determine the alarm information that matches successfully;
[0025] Based on the filtering conditions associated with alarm filtering attributes related to the vehicle network, and based on the multi-dimensional alarm attributes of the alarm information, the matched alarm information is filtered.
[0026] Determine whether the filtered alarm messages represent a real threat.
[0027] According to a vehicle network intrusion response method provided in this application, the method for determining the threat level of the network intrusion behavior in response to whether the alarm information is a real threat includes:
[0028] In response to the alarm information being a real threat, a first threat level of the network intrusion behavior is determined. The first threat level is determined based on the threat level of known threat information in the threat intelligence database that matches the alarm information. The threat intelligence database includes at least one known threat information related to vehicle network security. The threat intelligence database includes any of the following: retrieval behavior records, hacker activity characteristics, and resource information provided by white hat hackers collected from the vehicle network.
[0029] According to a vehicle network intrusion response method provided in this application, the method for determining the threat level of the network intrusion behavior in response to whether the alarm information is a real threat includes:
[0030] When the alarm message is not a real threat, a second threat level of the network intrusion behavior is determined, and the second threat level is determined based on the threat level of the alarm message.
[0031] According to a vehicle network intrusion response method provided in this application, when the alarm information is not a real threat, determining a second threat level of the network intrusion behavior includes:
[0032] When the alarm information is not a real threat, a second threat level of the network intrusion behavior is determined. The second threat level is determined by comprehensive analysis of the alarm information and the current status information of the vehicle's intrusion prevention system.
[0033] According to the vehicle network intrusion response method provided in this application, the step of analyzing security event data in the vehicle network and generating alarm information based on the security event data identifying network intrusion behavior includes:
[0034] By using a pre-set intrusion detection model, security event data in the vehicle network is analyzed, and alarm information is generated based on the security event data that identifies network intrusion behavior.
[0035] The intrusion detection model is trained using historical security event data and historical analysis results.
[0036] According to a vehicle network intrusion response method provided in this application, the defensive measures in the intrusion response strategy have information on defense levels;
[0037] The execution of defensive measures in the intrusion response strategy corresponding to the threat level, used to address the threat of the network intrusion behavior, includes:
[0038] Based on the alarm information, the attack chain of the network intrusion behavior is analyzed to identify at least one attack process;
[0039] Match corresponding defense measures to the defense level based on the attack process described;
[0040] Based on the attack process, the defensive measures in the intrusion response strategy corresponding to the threat level are executed sequentially to address the threat of the network intrusion.
[0041] According to the vehicle network intrusion response method provided in this application, after executing the defensive measures in the intrusion response strategy corresponding to the threat level to deal with the threat of the network intrusion behavior, the method further includes:
[0042] Obtain the defense result data after the defense measures are implemented;
[0043] The defense result data is evaluated according to preset evaluation indicators, a feedback report including the evaluation results is generated, and the feedback report is output.
[0044] This application also provides a vehicle network intrusion response device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement any of the vehicle network intrusion response methods described above.
[0045] This application also provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the vehicle network intrusion response method as described above.
[0046] The vehicle network intrusion response method, device, and computer-readable storage medium described in this specification, compared to the current inadequacies of vehicle network defense capabilities, perform real-time analysis of security event data in the vehicle network to promptly identify potential security risks and provide a foundation for subsequent processing. Alarm information is generated by analyzing security event data to enable timely response when network intrusion occurs, improving response speed. Subsequently, in-depth analysis of the alarm information determines whether it is a real threat, avoiding unnecessary resource waste caused by false alarms and ensuring accurate response to genuine threats. Next, the threat level of the network intrusion is determined based on the result of whether the alarm information is a real threat, making the assessment of security events more accurate and enabling appropriate measures to be taken according to different threat levels. Executing the defensive measures in the intrusion response strategy corresponding to the threat level can effectively address the threat of network intrusion, minimizing the damage to the vehicle network and the impact on vehicle and passenger safety. This improves the overall security and reliability of the vehicle network, providing strong protection for the safe operation of intelligent connected vehicles.
[0047] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this specification. Attached Figure Description
[0048] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this specification and, together with the description, serve to explain the principles of this specification.
[0049] Figure 1 This is a flowchart illustrating a vehicle network intrusion response method according to an exemplary embodiment of this specification;
[0050] Figure 2 This specification is a schematic diagram of the architecture of an automotive intrusion response and emergency handling system according to an exemplary embodiment.
[0051] Figure 3 This specification is a schematic diagram illustrating a vehicle network intrusion response device according to an exemplary embodiment.
[0052] Figure 4 This is a schematic block diagram of a vehicle network intrusion response device illustrated in this specification according to an exemplary embodiment. Detailed Implementation
[0053] The technical solutions in the embodiments (or "implementations") of this application will be clearly and completely described herein with reference to the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements.
[0054] If the embodiments of this application contain terms relating to directional indications or positional relationships (such as up, down, left, right, front, back, inside, outside, top, bottom, center, vertical, horizontal, longitudinal, transverse, length, width, counterclockwise, clockwise, axial, radial, circumferential, etc.), such terms are only used to explain the relative positional relationships and movement of the components in a specific posture (as shown in the attached figures); if the specific posture changes, the directional indications or positional relationships will also change accordingly. Furthermore, the terms "first" and "second" used in the embodiments of this application are only for descriptive convenience and should not be construed as indicating or implying relative importance.
[0055] This application provides a method, apparatus, and computer-readable storage medium for responding to intrusions into a vehicle network. The application will now be described in detail with reference to the accompanying drawings. Unless otherwise specified, the following embodiments and features can be combined with each other.
[0056] With the development of intelligent and connected vehicles, automotive cybersecurity issues are becoming increasingly prominent. Hackers can use various methods to intrude into vehicle systems, illegally control vehicles, and seriously threaten the lives of drivers and passengers. Existing automotive security systems mostly focus on physical protection and simple software security strategies, lacking effective response and emergency handling mechanisms for complex cyberattacks and intrusions.
[0057] Currently, there are some automotive security solutions on the market, such as firewalls and intrusion detection systems (IDS). While these can improve the security of automotive networks to some extent, they generally suffer from the following problems:
[0058] Slow response time: Traditional security systems often rely on manual intervention or periodic scanning, and cannot respond to cyberattacks in real time.
[0059] Low level of automation: It lacks an efficient automated response mechanism, making it impossible to quickly block attacks and restore normal system operation.
[0060] Limited strategy: Security policies are complex to configure and lack flexibility, making it difficult to adapt to ever-changing network attack methods.
[0061] Poor coordination: There is a lack of effective coordination between security devices, making it impossible to form a unified defense system.
[0062] To address the aforementioned technical problems, this specification provides a method for responding to vehicle network intrusions.
[0063] Figure 1 This is a flowchart illustrating a vehicle network intrusion response method provided in an embodiment of this specification, including the following steps:
[0064] Step 110: Analyze the security event data in the vehicle network, and generate an alarm message based on the security event data that identifies network intrusion behavior;
[0065] Step 120: Determine whether the alarm message is a real threat;
[0066] Step 130: Responding to the result of whether the alarm message is a real threat, determine the threat level of the network intrusion behavior;
[0067] Step 140: Execute the defense measures in the intrusion response strategy corresponding to the threat level to deal with the threat of the network intrusion behavior.
[0068] Through the above intrusion response and emergency handling process for the vehicle network, this embodiment aims to monitor network intrusion behavior in real time and automatically trigger a preset emergency response mechanism. During emergency response, multiple configurations of intrusion response strategies are set, and different intrusion response strategies are used according to different threat levels to improve the flexibility of defense, quickly block attacks and restore the normal operation of the vehicle network system. At the same time, it supports the linkage of multiple security devices to form an all-round security protection system.
[0069] Through the above method, this embodiment solves the problems existing in the existing automotive security solutions, thereby achieving more efficient and accurate automotive network security protection.
[0070] As an example, the vehicle network intrusion response method can be applied to an automotive intrusion response and emergency handling system (hereinafter referred to as the system). As Figure 2 shown, the system is based on a modular design and includes at least one of an event monitoring module, an alarm investigation module, a scenario management module, a linkage processing module, and a notification management module. Each module communicates with each other through standard interfaces to jointly form a complete intrusion response and emergency handling process.
[0071] The event monitoring module is responsible for real-time collection of security event data in the vehicle network, including but not limited to alarms of vehicle intrusion monitoring systems, firewall logs, abnormal behaviors of vehicle control units (ECUs), etc. An efficient intrusion detection engine is integrated in the event monitoring module, which can analyze network traffic in real time and accurately identify network intrusion behavior.
[0072] In some embodiments, the event monitoring module executes the method of Step 110, adopts data processing technology to ensure rapid and accurate screening and preliminary analysis of a large amount of security events. And it can detect network intrusion behavior in real time and automatically trigger an emergency response mechanism. Specific embodiments of this process will be described in detail in the subsequent chapters.
[0073] Upon receiving alarm information from the event monitoring module, the alarm investigation module automatically initiates the corresponding investigation process. This module utilizes a built-in threat intelligence database to perform in-depth analysis of the alarm information, determining whether it represents a genuine security threat and identifying key information such as the threat type, source, and target.
[0074] In some embodiments, the alarm investigation module performs steps 120 to 130 to improve alarm quality and reduce false alarms and missed alarms. Specific embodiments of this process will be described in detail in subsequent chapters.
[0075] The script management module supports user-defined contingency plans and multiple triggering mechanisms to meet security needs in different scenarios. Specifically, the script management module is responsible for the creation, editing, storage, and retrieval of scripts. Users can flexibly configure scripts according to actual needs to achieve personalized intrusion response strategies. Scripts define a series of automated response processes for specific types of security threats. Scripts are key to achieving automated response, meaning they play a central role in the entire system. Through scripts, the system can automatically handle various security events according to predetermined processes, supporting automated response and contingency plan arrangement without manual intervention, greatly improving response speed and efficiency.
[0076] In some embodiments, users can create and edit scripts through a script management module using a graphical user interface (GUI). The GUI allows users to create and edit scripts more intuitively and conveniently, reducing operational difficulty and improving user experience. As an example, the system can adopt a SOAR (Security Orchestration, Automation and Response) architecture to streamline and automate the monitoring, investigation, analysis, and handling of security incidents.
[0077] Specifically, each script consists of a series of components that represent specific processing steps or decision points in the process flow. These components are interconnected through logical relationships (such as sequential execution, conditional branching, etc.) to form a complete process flow, ensuring that the system can respond to various security situations in an orderly manner.
[0078] The script management module supports various types of components, including but not limited to logical branching components, IP blocking components, and access control components.
[0079] Logical branching component: Used to select branches in the processing flow based on different conditions. For example, when different types of threats are detected, different processing paths can be selected based on the severity of the threat. Users can set branching conditions, such as specific alarm information characteristics or threat levels, and branching events, i.e., the specific actions to be performed when the conditions are met.
[0080] IP blocking component: Used to block specific IP addresses, preventing malicious attacks originating from those addresses. Users need to specify parameters such as the IP address to be blocked, the port, and the validity period. The validity period can be set according to actual needs so that the blocking is automatically lifted after a certain time.
[0081] Access control component: Used to control access permissions to system resources. It allows setting access permissions for different users or roles to restrict unauthorized access. Parameter settings may include user groups, resource types, permission levels, etc.
[0082] In other examples, where the alarm investigation module is integrated into the script management module as a threat intelligence analysis component, or where the alarm investigation module is not present in the system, the script management module also includes a threat intelligence analysis component. This component is responsible for analyzing and processing threat intelligence. It compares received alarm information with data in the threat intelligence database to determine the type and severity of the threat. The component's parameter settings may include selecting the content to analyze (such as IP addresses, domain names, etc.) and setting filtering conditions.
[0083] Within the script management module, each of the above components has specific functions and parameter setting options to meet the processing needs of different scenarios. When creating or editing a script, users need to set parameters for each component. Parameter setting is a crucial step in creating and editing scripts, as these parameters define the specific behavior and triggering conditions of each component.
[0084] As an example, in the logical branching component, users need to set branch conditions and branch events. Understandably, the branch conditions need to be set based on actual conditions to ensure accurate branch selection according to different situations. Branch events need to specify concrete processing operations to ensure correct execution when the conditions are met. In the IP blocking component, users need to specify the blocked IP addresses, ports, and validity periods. Understandably, the blocked IP addresses and ports need to be accurately specified to effectively prevent malicious attacks. The validity period setting should consider the duration and impact of the attack, avoiding excessively long or short blocking times that could cause unnecessary system disruption. In the access control component, the settings for user groups, resource types, and permission levels need to be reasonably allocated based on the system's security requirements and user roles to ensure system security and availability.
[0085] In the script management module, users design script processing flows on the GUI by dragging and dropping components. This method is intuitive and convenient, allowing users to easily build complex processing flows. The intuitive connectors and conditional statements provided by the system help users clearly express the logical relationships between components, making the processing flows easier to understand and maintain. After completing the design, users can save the script and perform tests to verify its correctness and effectiveness. Testing can simulate various security incidents to check whether the script can process according to the expected flow, allowing for the timely identification and repair of potential problems.
[0086] It should be noted that there is a correlation between the intrusion response strategy set in the script and the intrusion response defense measures. When a network intrusion occurs, the defense measures of the intrusion response strategy are executed to counter the threat of the network intrusion. This part will be explained in detail later.
[0087] In this embodiment, the system's script design fully considers flexibility and scalability. Users can customize script content according to actual needs, including adding or deleting components, adjusting component parameters, and setting trigger conditions. Furthermore, the system supports various types of script templates, such as emergency response scripts for specific threats and daily inspection scripts, which users can select or modify based on their specific circumstances. The intrusion response strategy of the emergency response script for specific threats has a higher defense level than that of the intrusion response strategy of the daily inspection script. By using different defense measures corresponding to different defense levels, different scenarios of network intrusion behaviors are handled, effectively avoiding the impact of network intrusion threats and defensive actions on business operations. For example, the intrusion response strategy of the daily inspection script could be to record the network intrusion behavior without affecting vehicle operation, and then improve the vehicle network security level during subsequent system upgrades. The emergency response script for specific threats, on the other hand, could disable the vehicle's network functions and temporarily shut down all network ports to address the threat if the attack severely affects vehicle operation. It is understood that the intrusion response strategies of these two scripts are different, and the choice should be made based on actual needs.
[0088] Furthermore, as cyber threats continue to evolve and technologies advance, the system also supports continuous updates and optimizations to the scripts. Users can adjust and improve the scripts based on the latest threat intelligence and best practices to ensure that the system's protection and emergency response capabilities remain at a high level.
[0089] The coordinated response module plays a crucial role in the entire security protection system. It is triggered when an alarm message is confirmed as a genuine threat after analysis. The module automatically executes corresponding response measures based on predefined intrusion response strategies in the script. These strategies detail the specific actions to be taken in different situations. This design ensures that the system can respond quickly and automatically to cybersecurity threats, greatly improving the efficiency and accuracy of threat response. Furthermore, it supports integration with security devices to form a multi-layered defense system, enhancing the system's synergy.
[0090] In some embodiments, these measures include, but are not limited to, blocking the source of the attack, isolating infected devices, and logging detailed information for subsequent analysis. The aim is to quickly block the source of the attack, isolate infected systems or devices, and initiate incident response procedures, thereby minimizing the impact of the threat on business operations.
[0091] In other embodiments, the coordinated response module achieves efficient network security protection through tight integration with devices such as the vehicle's ECU, firewall, and the vehicle's current IDS (Intrusion Detection System). This integration enables the coordinated response module to respond quickly and effectively to various network security threats.
[0092] Notification Management Module: Throughout the intrusion response and emergency handling process, the notification management module is responsible for notifying relevant personnel of critical information via various means, including email, SMS, and WeChat group messages, ensuring that they are promptly informed of the occurrence and progress of security incidents. In the face of cybersecurity threats, rapid notifications enable relevant personnel to take swift decisions and actions, thereby effectively reducing the impact of security incidents on systems and business operations.
[0093] These notifications include, but are not limited to, alarm notifications, handling result notifications, and system status change notifications.
[0094] The vehicle intrusion response and emergency handling system provided in this application may include the following beneficial effects:
[0095] Firstly, by integrating an advanced intrusion detection engine into the event monitoring module, the system analyzes network traffic in real time to accurately identify intrusion behaviors. Once an intrusion is detected, it automatically triggers emergency response plans, including blocking the attack source, isolating infected devices, and initiating security audits, quickly blocking attacks and minimizing losses. This solves the problem of existing automotive security systems' untimely intrusion response and inability to handle intrusions automatically, thus improving the system's security and reliability.
[0096] Secondly, the script management module supports user-defined contingency plans, allowing users to arrange plan processes according to actual needs. A visual arrangement interface reduces operational difficulty. It also supports multiple triggering mechanisms to ensure accurate and timely response to intrusion attempts. This invention enables the system to adapt to different security scenarios and user needs, improving its flexibility and scalability.
[0097] Thirdly, the system supports integration with various security devices through a linkage processing module, enabling centralized management and unified execution of security policies. Upon detecting intrusion, it automatically sends instructions to relevant security devices to implement control or blocking operations, forming a multi-layered defense system. It also supports reversal operations to address false alarms or misoperations. This invention enhances the system's defense capabilities and improves the effectiveness of security protection.
[0098] Fourthly, the alarm investigation module uses technical means to filter, merge, and analyze alarm information, removing erroneous and duplicate alarms to improve alarm quality. It supports a human-machine collaborative approach to alarm information investigation, allowing users to supplement investigation information and transform low-quality alarms into high-quality, valuable ones. It also provides alarm overview, tracing, and statistical functions. This invention helps users better understand the alarm situation, reduce false alarms and missed alarms, and improve system security and manageability.
[0099] like Figure 1 As shown, based on the aforementioned vehicle intrusion response and emergency handling system, the specific steps of the vehicle network intrusion response method are described below:
[0100] In step 110, security event data in the vehicle network is analyzed, and alarm information is generated based on the security event data that identifies network intrusion behavior.
[0101] The security incident data described in this article refers to various information or records obtained through daily monitoring of the vehicle network environment, including but not limited to alarm data from intrusion detection systems, firewall logs, and abnormal behavior of vehicle control units (ECUs). This data reflects potential anomalies in the vehicle network, but does not necessarily imply that these anomalies constitute a security threat.
[0102] For example, an intrusion detection system might issue an alert due to network fluctuations or normal network activity, but this doesn't necessarily mean an actual attack has occurred. Similarly, some abnormal behaviors of an ECU might be caused by temporary system malfunctions or environmental factors, not necessarily by a security attack. Therefore, security incident data analysis is necessary to determine whether these events are threatening; this process includes analyzing security incident data to identify network intrusion behaviors.
[0103] A vehicle network (V2N) is a network connecting various electronic control units, sensors, actuators, and in-vehicle infotainment systems within the vehicle via wired and wireless communication. It also interacts with external devices and networks through technologies such as Bluetooth, Wi-Fi, and mobile networks. It is responsible not only for ensuring efficient data transmission and collaborative operation between various systems within the vehicle to guarantee normal driving and stable functioning, but also for protecting against various attack threats from external hackers.
[0104] The intrusion detection engine comprehensively analyzes and processes security event data using algorithms to detect potential network intrusion behaviors and generate corresponding alerts. The algorithm used can be any deep learning algorithm, trained through the computation and processing of large volumes of data acquired from historical network usage scenarios. This allows it to identify network intrusion behaviors in different scenarios, thereby improving the accuracy of data identification and resolving the false alarm problem that may arise from current identification methods based on preset rules.
[0105] In some embodiments, step 110 may specifically include: in step 111, analyzing security event data in the vehicle network using a preset intrusion detection model, and generating alarm information based on the security event data that identifies network intrusion behavior; wherein, the intrusion detection model is trained from historical security event data and historical analysis results.
[0106] The intrusion detection engine uses deep learning algorithms to analyze the input security event data and output values related to security levels. These values are then compared with set alarm thresholds. Security event data exceeding the alarm thresholds generate alarm information for subsequent intrusion responses.
[0107] In step 120, it is determined whether the alarm information is a real threat.
[0108] False alarms are quite common in automotive network security monitoring. These false alarms can be caused by factors such as excessively high sensitivity settings on security devices, network complexity, or system malfunctions. For example, an intrusion detection system might misinterpret normal network traffic as an attack, thus issuing an alert. Firewalls may also log unnecessary information due to temporary network configuration changes.
[0109] To improve the efficiency and accuracy of security incident handling, further analysis and investigation of alarm information are needed to determine whether these incidents pose a real threat, improve the accuracy of alarm information, reduce false alarms and missed alarms, and enable security personnel or systems to quickly and accurately identify and handle important security incidents.
[0110] In some embodiments, the above process can be implemented through an alarm investigation module in the system. When an alarm is generated, the alarm investigation module is activated, and its threat intelligence collision analysis begins to function. This process aims to determine whether the alarm represents a real security threat.
[0111] As an example, step 120 may specifically include: in step 121, obtaining a threat intelligence database, which includes at least one known threat information related to vehicle network security; in step 122, determining whether the alarm information matches the known threat information in the threat intelligence database, and determining whether the alarm information is a real threat.
[0112] The system incorporates a threat intelligence database, a collection of static data related to network security. It encompasses one or more of the following: retrieval activity logs, hacker activity characteristics, and resource information provided by white-hat hackers, collected from vehicle networks, forming a large amount of known threat information. Known threat information can include, but is not limited to, malicious IP addresses, domain names, and virus samples.
[0113] Regarding data sources, for web search data, specific search keywords and source IP addresses are recorded to form a queryable search behavior profile. For hacker resource data, including known hacker attack tool characteristics, descriptions of common attack patterns, and malware sample characteristics, this data is stored in the database in the form of detailed documents and signatures. For white-hat hacker resource data, such as security vulnerability discovery reports and defense strategy recommendations, it is also saved in a standardized format to generate a threat intelligence database.
[0114] Specifically, the collision analysis process involves comparing alert messages with data in a built-in threat intelligence database one by one to determine whether the alert message matches any known threat information in the database. Based on the comparison results, it is determined whether the alert is a real threat. The comparison results may include, but are not limited to, the alert message being completely identical to a known threat, or the alert message having a high degree of similarity or matching with data in the threat intelligence database.
[0115] Understandably, if an alert matches a record in the threat intelligence database or a known threat, then the alert is considered a real threat. In other examples, after determining that an alert is a real threat, collision analysis can also provide crucial information about the threat's type, source, and target. For instance, if an alert matches a malicious IP address in the threat intelligence database, then the source of the threat can be determined to be that IP address, and the type of threat, such as malware attack or network scan, can be determined based on the information in the threat intelligence database.
[0116] In other words, if the alert message does not match a record in the threat intelligence database or a known threat, or there is no obvious match, then the alert message is determined to be a non-real threat.
[0117] It's important to note that because the threat information in the threat intelligence database represents actual events, it is closer to reality and more accurate and comprehensive. Therefore, the threat intelligence database can be used to further verify alerts and determine whether the network intrusion behavior corresponding to the alert is a real threat. Furthermore, it can determine the threat level of the network intrusion behavior so that targeted intrusion response strategies can be implemented. It can be understood that both real threats and non-real threats indicate that the network intrusion behavior corresponding to the alert is threatening. Real threats refer to threats that are highly similar to those in the threat intelligence database, conform to network attack trends, and may have a significant impact on vehicle security. Non-real threats are threats that do not exist in the threat intelligence database.
[0118] In some embodiments, the analysis results are displayed in the response record based on the comparison results, informing the user whether the alarm information matches the threat intelligence database and the specific threat information or a non-match message.
[0119] When analyzing alarm information, to improve the efficiency and accuracy of security incident handling, it is necessary to filter the collected security incident data, eliminating false alarms or inaccurate information. This avoids unnecessary waste of resources and misoperation, while also reducing interference with users. Filtering methods can include, but are not limited to, filtering alarm information based on user-defined analysis content and filtering conditions to determine which alarms require further comparison or are ultimately identified as genuine threats.
[0120] As an example, the alarm information includes multi-dimensional alarm attributes; step 122 may specifically include: in step a1, filtering the alarm information based on the multi-dimensional alarm attributes of the alarm information according to the filtering conditions associated with the alarm filtering attributes related to the vehicle network; in step a2, determining whether the filtered alarm information matches the known threat information in the threat intelligence database, and determining whether the alarm information is a real threat.
[0121] Alarm information includes multi-dimensional alarm attributes, which can include, but are not limited to, time range, threat level, source region, and other dimensions.
[0122] Filtering conditions include those associated with at least one of the alarm attributes, which filter alarm information. These include at least one of the following: filtering alarm information based on a set time range. This means that users set specific time ranges, such as focusing only on threat intelligence within the past week. This reduces unnecessary analysis and improves efficiency. If the alarm occurred outside the set time range, the system will not identify it as a real threat for further analysis. In other words, filtering by time range excludes interference from other time periods.
[0123] The system filters alerts based on a defined range of threat levels. Users can set these filtering criteria according to their needs, such as focusing only on high-threat alerts. If an alert's threat level is lower than the set level, the system will not classify it as a real threat. It should be noted that the threat levels corresponding to alerts will be explained in detail in later chapters.
[0124] By setting filtering conditions for the source region, alert information can be filtered. This allows for a focus on threats originating from a specific region. For example, if cyberattack activity is known to be frequent in a particular region, the source region can be set to that region for more rigorous analysis of alerts originating from that area.
[0125] Finally, the alarm messages that meet the criteria are compared one by one with the data in the built-in threat intelligence database to determine whether the alarm message is a real threat.
[0126] In this embodiment, in order to improve the accuracy and efficiency of the analysis, the user can set filtering conditions associated with alarm filtering attributes related to the vehicle network. Only when the alarm information meets all the set filtering conditions will it be identified as a real threat.
[0127] In another example, the alarm information includes alarm content; step 122 may specifically include: in step b1, selecting content from the alarm content for analysis based on the unique source of the data and / or data integrity; in step b2, matching the selected content with the corresponding content in the known threat information to determine whether the alarm information is a real threat.
[0128] Alarm information includes alarm content, which may include, but is not limited to, the IP address, domain name, file hash value, etc. of the event.
[0129] Users can select the content to be analyzed as needed, and can choose the content for collision analysis based on, but not limited to, the unique source of the data (such as IP address, domain name, etc.) and / or data integrity (such as file hash value, etc.). The system will compare the selected content one by one to determine whether it exists in the threat intelligence database.
[0130] Understandably, regarding IP address content, if the system selects to analyze the IP addresses in the alert information, it will compare the source and destination IP addresses in the alert information with malicious IP addresses in the threat intelligence database. For example, if the alert information shows abnormal network connections from a specific IP, and this IP is marked as a malicious IP in the threat intelligence database, then there may be a security threat. Therefore, IP address analysis is used to determine whether any known malicious IPs are attacking the vehicle network. Regarding domain name content, the system checks whether the domain name portion of the alert information matches malicious domain names in the threat intelligence database. For example, if a communication in the vehicle network involves a suspicious domain name, and this domain name is listed in the threat intelligence database as being associated with malicious activity, then further investigation is needed. Therefore, domain name analysis helps identify whether attacks are being carried out through malicious domain names. Regarding file hash value content, when file-related alert information is involved, the security of the file can be determined by analyzing the file hash value. The system compares the file hash value in the alert information with known malicious file hash values in the threat intelligence database. If a match is found, it indicates that the file may be malware or a tampered file, posing a security threat to the vehicle's system.
[0131] In this embodiment, determining which specific elements to extract from the alarm information for comparison is a technical way to identify the object of collision analysis and determine whether the alarm information is a real threat.
[0132] It is worth noting that the above-mentioned filtering methods for alarm information, which analyze content and filter conditions, can be used individually or in combination. When used in combination, the order of the two filtering methods can be adjusted according to actual needs. The following example illustrates the filtering method based on content analysis; other embodiments are basically the same and will not be repeated here.
[0133] In other examples, the alarm information also includes multi-dimensional alarm attributes; step b2 may specifically include: in step b21, matching the selected content with the corresponding content in the known threat information to determine the alarm information that passes the match; in step b22, filtering the alarm information that passes the match based on the multi-dimensional alarm attributes of the alarm information according to the filtering conditions associated with the alarm filtering attributes related to the vehicle network; in step b23, determining whether the filtered alarm information is a real threat.
[0134] In this embodiment, after selecting the content for analysis from the alarm content based on the unique source of the data and / or data integrity, the selected content is matched with the corresponding content in the threat information to determine the alarm information that passes the match. Subsequently, the alarm information that passes the content analysis is filtered to select alarm information that meets the filtering conditions. Only when the alarm information meets all the set filtering conditions is it identified as a real threat.
[0135] After the system completes the collision analysis of alert information based on the threat intelligence database, it will display the analysis results in the response log, informing the user whether the alert information matches the threat intelligence database and providing specific threat information or a "no match" message. If the alert information matches a record in the threat intelligence database, detailed threat information (such as threat level, reputation value, etc.) will be displayed; otherwise, a "no match" message will be displayed.
[0136] In step 130, the threat level of the network intrusion behavior is determined in response to whether the alarm information is a real threat.
[0137] In responding to network intrusions, applying the same measures to all intrusion attempts may waste resources or prevent timely and effective action when facing serious threats. Therefore, it is necessary to determine the threat level of network intrusions and to implement different levels of response and defense measures accordingly. This ensures more precise threat response and avoids overreaction or underreaction.
[0138] In some embodiments, step 130 may specifically include: in step 131, in response to the alarm information being a real threat, determining a first threat level of the network intrusion behavior, wherein the first threat level is determined based on the threat levels of known threat information matching the alarm information in a threat intelligence database.
[0139] The threat intelligence database includes at least one known threat related to vehicle network security. The threat intelligence database includes any of the following collected from vehicle networks: search behavior records, hacker activity characteristics, and resource information provided by white hat hackers.
[0140] Because the known threat information in the threat intelligence database consists of information that has already occurred, it can accurately reflect the degree of threat posed by network intrusion to the vehicle network. Furthermore, since alert information is generated from security event data, incomplete or inaccurate security event data may lead to inaccurate threat level determination based on alert information. Therefore, when matching alert information with known threat information, the threat level corresponding to the known threat information is used as the threat level of the network intrusion corresponding to the current alert information.
[0141] In some other embodiments, step 130 may further include: in step 132, in response to the alarm information being a non-real threat, determining a second threat level of the network intrusion behavior, wherein the second threat level is determined based on the threat level of the alarm information.
[0142] When generating alerts based on security incident data, the system performs a preliminary threat level assessment based on some initial characteristics of the alert information. For example, if the alert information indicates that it comes from an unknown IP address and the behavior pattern of that IP address is suspicious (such as frequently attempting to connect to multiple ports), the system can initially classify it as a low threat level, pending further analysis.
[0143] If the collision analysis determines that the alarm message is a real threat, then the threat level of the alarm message is determined based on the threat level of known threat information that matches the alarm message. If the collision analysis determines that the alarm message is not a real threat, meaning there is no known threat level to refer to, then its threat level is determined based on the content of the alarm message.
[0144] In other examples, step 130 may further include: in step 133, in response to the alarm information being a non-real threat, determining a second threat level of the network intrusion behavior, wherein the second threat level is determined based on a comprehensive analysis of the alarm information and the current status information of the vehicle's intrusion prevention system.
[0145] If collision analysis determines that the alarm message is not a real threat, in order to improve the accuracy of the threat level assessment, the threat level of the alarm message is comprehensively determined based on the current status information of the vehicle's intrusion prevention system. This status information may include, but is not limited to, operational status and update status.
[0146] For example, if an intrusion prevention system is functioning normally and can effectively detect and block potential threats, then even if an alarm message indicates a non-real threat, its secondary threat level may be relatively low. However, if the system has vulnerabilities, performance degradation, or partial functional failure, then even alarm messages that appear to be non-real threats may carry a higher potential risk, thus increasing the secondary threat level.
[0147] For example, consider the interaction status between the intrusion prevention system and other vehicle systems. If the communication between the intrusion prevention system and other critical systems is abnormal, or if changes in the status of other systems may affect the performance of the intrusion prevention system, then the potential risks of alarms for non-real threats need to be reassessed, and the second threat level adjusted accordingly.
[0148] In other embodiments, the threat level of a network intrusion can be determined by combining other factors. These other factors may include, but are not limited to, alarm frequency, system response status, and correlation with other security devices. For example, a scenario where the threat level is determined by alarm frequency. If the same or similar alarm messages appear multiple times within a short period of time, it indicates a possible persistent attack, and the threat level may be high. If multiple attack alarms are received consecutively from the same IP address, then the threat represented by that IP address may be quite serious. In this case, it is necessary to increase the threat level determined solely by alarm messages.
[0149] For example, if other security devices (such as firewalls, intrusion detection systems, etc.) also detect anomalies related to the alert, the severity of the threat can be further determined. For instance, if a firewall detects a large number of connection requests from a specific IP address, and the intrusion detection system also issues an alert for that IP address, then the threat represented by that IP address may be quite serious. The specific implementation methods for determining the threat level by combining other factors are basically the same and will not be elaborated here.
[0150] By accurately identifying the threat level and implementing corresponding response strategies and defensive measures through the above methods, the safety threat posed by network intrusion to vehicles and passengers can be minimized. Timely and effective response measures can prevent further development of attacks, protect critical vehicle systems and functions, and ensure safe vehicle operation and passenger safety.
[0151] To improve alarm quality, this embodiment employs alarm aggregation and alarm analysis techniques to filter, merge, and analyze alarm information, removing erroneous and duplicate alarms and thus enhancing alarm quality. Simultaneously, the system supports human-computer interaction for alarm information investigation, allowing users to supplement investigation information as needed, transforming low-quality alarms into high-quality, valuable ones. Furthermore, the system provides alarm overview (offering a comprehensive view of alarms, allowing users to quickly understand the current alarm situation in the system. The overview interface displays information such as the number, type, and severity of alarms, as well as alarm distribution categorized by time, region, and device), alarm tracing (allowing users to trace specific alarms, viewing their historical process and related event chains. Through alarm tracing, users can understand the origin, development process, and correlation with other alarms), and alarm statistics (statistical analysis of alarm information, generating various reports and charts. The statistical function provides information on alarm distribution, trends, and handling status, helping users understand the system's security status and changing trends). These functions help users comprehensively understand the alarm situation.
[0152] In step 140, defensive measures in the intrusion response strategy corresponding to the threat level are executed to address the threat of the network intrusion behavior.
[0153] After confirming that the alarm information is a real threat, the coordinated response module will automatically execute corresponding response measures according to the intrusion response strategy defined in the script, depending on the different threats.
[0154] It's understandable that in a connected vehicle environment, different response strategies will be adopted for cyberattacks based on their threat level. If the cyberattack is deemed low-threat—meaning it hasn't caused any actual impact or disrupted the vehicle's normal functions—although it's clear the danger is attacking the vehicle, it can be ignored initially as the situation isn't urgent and existing protection technologies remain unaffected. If, later, it's discovered that the attack impacts existing protection technologies, a relatively slow process of upgrading and modifying the entire system will be implemented, followed by a comprehensive update. In the event of a severe attack, the automated process will use emergency measures to first repair the current vehicle's vulnerability and resolve the issue, before performing mass repairs on other vehicles affected by the same attack. Users can create and edit intrusion response strategies in the script management module according to their actual needs.
[0155] In summary, when the system responds to network intrusions, different intrusion response strategies are implemented based on the threat level. For lower threat levels, a more conservative approach is adopted to avoid overreacting and wasting resources; while for higher threat levels, rapid and robust emergency measures are taken to ensure vehicle safety and normal operation. This correlation between response strategy and threat level helps to efficiently utilize resources, accurately respond to various network attacks, and minimize the impact of network attacks on the vehicle-to-everything (V2X) system.
[0156] In some embodiments, the linkage between the system or the linkage handling module in the system and security devices (such as vehicle ECU, firewall, intrusion detection system, endpoint security management system, etc.) enables centralized management and unified execution of security policies, which can quickly and effectively respond to various network security threats and achieve efficient network security protection.
[0157] As an example, when a serious cyberattack is detected that may affect vehicle driving safety, the linkage response module can take measures such as limiting vehicle speed and initiating emergency braking through integration with the ECU to ensure the safe operation of the vehicle.
[0158] As an example, it works in conjunction with firewalls to achieve fine-grained control over network traffic. For instance, the coordinated response module can enhance the monitoring and blocking of specific types of network traffic based on the type and severity of threats, through firewall filtering.
[0159] As an example, the coordinated response module can also feed back the response results to the intrusion detection system so that it can continuously optimize the detection algorithm and improve detection accuracy.
[0160] In other embodiments, the defensive measures in the intrusion response strategy have information on defense levels; step 140 may specifically include: in step 141, analyzing the attack chain of the network intrusion behavior based on the alarm information to determine at least one attack process; in step 142, matching defensive measures corresponding to the defense level according to the attack process; in step 143, sequentially executing the defensive measures in the intrusion response strategy corresponding to the threat level according to the attack process to deal with the threat of the network intrusion behavior.
[0161] Because network intrusion attacks are often not single acts but complex chains of multiple steps, analyzing the components of an attack allows for more precise development of defense strategies. Setting specific protective measures for each step of the attack enables interception and blocking at different levels.
[0162] Specifically, after identifying network intrusion behavior, the entire process of the attack is reflected through security incident data, and the components of the behavior are analyzed. For example, if the attack has 1, 2, and 3 steps, there are three different protective measures (different defensive measures differ in level). Each step of the attack behavior in the attack components is defended one by one, thus forming a multi-layered defense system.
[0163] As an example, defensive measures include both management and technical measures. Regarding technical measures, firewalls, for instance, can issue rules through a platform, which vehicles can then update in a timely manner to achieve immediate protection and rapidly respond to constantly changing attack scenarios. Furthermore, the adjustability of these technical measures allows for flexible optimization and improvement in the face of attacks of different types and intensities, ensuring the security and stability of the vehicle-to-everything (V2X) system. In terms of management measures, V2X security management is standardized through systems and processes.
[0164] In other embodiments, the system also supports rollback operations to ensure that the system can be quickly restored to normal operation in the event of false alarms or erroneous operations.
[0165] After step 140, the vehicle network intrusion response method further includes: in step 150, acquiring defense result data after implementing the defense measures; in step 160, evaluating the defense result data according to preset evaluation indicators, generating a feedback report including the evaluation results, and outputting the feedback report.
[0166] Conducting effectiveness evaluations after the implementation of remedial measures is a crucial step in ensuring the continued effective operation of a cybersecurity protection system. After the remedial measures are completed, the system can assess their effectiveness to understand whether the measures achieved their intended objectives, promptly identify potential problems and shortcomings, and provide strong evidence for future improvements. Simultaneously, feedback reports are provided to relevant personnel. These reports not only include the implementation status of the remedial measures but also a comparison of the security status before and after the remediation, potential risks, and recommended follow-up measures.
[0167] Regarding effectiveness evaluation: The system will assess the defense data or effectiveness after implementing defensive measures based on preset evaluation metrics. Evaluation metrics may include, but are not limited to, blocking success rate (measuring the effectiveness of the measures in blocking the attack source), response time (reflecting the system's response speed to security incidents), and resource consumption (assessing the system resource usage of the measures). These metrics will help users understand the actual effectiveness of the measures and provide a reference for subsequent improvements.
[0168] Regarding feedback reports: After the assessment is completed, the system will automatically generate a feedback report and send it to relevant personnel through various notification methods, which can ensure that relevant personnel receive information on the effectiveness of the measures in a timely manner so that they can take further action promptly.
[0169] As an example, users can choose a suitable notification method according to their needs to improve the efficiency of information acquisition. The notification method may include, but is not limited to, email, WeChat, or DingTalk.
[0170] As an example, these reports detail the implementation process of defensive measures (including but not limited to specific steps taken, systems and devices involved), assessment results, and follow-up recommendations, providing users with comprehensive emergency response information. Based on the assessment results and analysis of potential risks, targeted follow-up recommendations are proposed. These recommendations may include measures to further strengthen security protection, methods to optimize response processes, and suggestions for improving system configurations, providing users with directions for continuously improving their cybersecurity protection systems.
[0171] The embodiments of the vehicle network intrusion response method provided above aim to achieve rapid identification, analysis, and emergency response to automotive network security threats through highly automated processes and intelligent components working together. By streamlining and automating the monitoring, investigation, analysis, and handling of security incidents, the efficiency and accuracy of automotive network security protection are significantly improved.
[0172] This application provides a vehicle network intrusion response method, device, and computer-readable storage medium, which addresses the shortcomings of current vehicle network defense capabilities. It performs real-time analysis of security event data within the vehicle network to promptly identify potential security risks, providing a foundation for subsequent processing. By analyzing security event data, it generates alarm information for timely response to network intrusions, improving response speed. Subsequently, it conducts in-depth analysis of the alarm information to determine whether it represents a real threat, avoiding unnecessary resource waste caused by false alarms and ensuring accurate responses to genuine threats. Next, based on the alarm information's determination of whether it represents a real threat, it determines the threat level of the network intrusion, making security event assessment more accurate and enabling appropriate measures to be taken based on different threat levels. Executing the defensive measures in the intrusion response strategy corresponding to the threat level effectively addresses the threat of network intrusions, minimizing the damage to the vehicle network and the impact on vehicle and passenger safety. This improves the overall security and reliability of the vehicle network, providing strong protection for the safe operation of intelligent connected vehicles.
[0173] Based on the first embodiment described above, a second embodiment of the vehicle network intrusion response method is proposed. The second embodiment is used to illustrate the calibration method when both the target sensor and the sensor to be calibrated are lidar.
[0174] Based on the same concept as the methods described above, this application also proposes a vehicle network intrusion response device, such as... Figure 3 As shown.
[0175] The device includes:
[0176] The alarm generation module 402 is used to analyze security event data in the vehicle network and generate alarm information based on the security event data that identifies network intrusion behavior.
[0177] Alarm analysis module 404 is used to determine whether the alarm information is a real threat;
[0178] Threat determination module 406 is used to determine the threat level of the network intrusion behavior in response to whether the alarm information is a real threat;
[0179] The security defense module 408 is used to execute the defense measures in the intrusion response strategy corresponding to the threat level, in order to deal with the threat of the network intrusion behavior.
[0180] The specific implementation process of the functions and roles of each module / submodule / unit in the above device can be found in the implementation process of the corresponding steps in the above method, which can achieve the same technical effect, and will not be repeated here.
[0181] Figure 4An example is a schematic diagram of the physical structure of a vehicle network intrusion response device, such as... Figure 4 As shown, the vehicle network intrusion response device may include: a processor 810, a communications interface 820, a memory 830, and a communication bus 840. The processor 810, communications interface 820, and memory 830 communicate with each other via the communication bus 840. The processor 810 can call logical instructions stored in the memory 830 to execute vehicle network intrusion response methods.
[0182] Furthermore, the logical instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0183] On the other hand, this application also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer is able to execute the vehicle network intrusion response methods provided by the above methods.
[0184] In another aspect, this application also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the vehicle network intrusion response methods provided by the above methods.
[0185] It should be noted that the technical solutions or features described in the above embodiments can be combined or supplemented with each other without conflict. The scope of protection of this application is not limited to the precise structures described in the above embodiments and shown in the accompanying drawings; all modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A method for responding to intrusions into a vehicle network, characterized in that, The method includes: Analyze security event data in the vehicle network and generate alarm information based on the security event data that identifies network intrusion behavior; Determining whether the alarm information is a real threat; the determination of whether the alarm information is a real threat includes: obtaining a threat intelligence database; determining whether the alarm information matches known threat information in the threat intelligence database, and determining whether the alarm information is a real threat; Based on whether the alarm information is a real threat, the threat level of the network intrusion behavior is determined; The process involves executing defensive measures within the intrusion response strategy corresponding to the threat level to address the network intrusion threat. The defensive measures within the intrusion response strategy contain information about defense levels. This execution includes: analyzing the attack chain of the network intrusion based on the alarm information to identify at least one attack process; matching defensive measures corresponding to the defense level according to the attack process; and sequentially executing the defensive measures within the intrusion response strategy corresponding to the threat level to address the network intrusion threat based on the attack process.
2. The vehicle network intrusion response method as described in claim 1, characterized in that, The threat intelligence database includes at least one known threat related to vehicle network security; the threat intelligence database includes any of the following collected from vehicle networks: search behavior records, hacker activity characteristics, and resource information provided by white hat hackers.
3. The vehicle network intrusion response method as described in claim 2, characterized in that, The alarm information includes multi-dimensional alarm attributes; Determining whether the alarm information matches known threat information in the threat intelligence database, and determining whether the alarm information is a real threat, includes: Based on the filtering conditions associated with alarm filtering attributes related to the vehicle network, and based on the multi-dimensional alarm attributes of the alarm information, the alarm information is filtered. Determine whether the filtered alert information matches known threat information in the threat intelligence database, and determine whether the alert information is a real threat.
4. The vehicle network intrusion response method as described in claim 2, characterized in that, The alarm information includes the alarm content; Determining whether the alarm information matches known threat information in the threat intelligence database, and determining whether the alarm information is a real threat, includes: Based on the unique source of the data and / or data integrity, select the content from the alarm content for analysis; The selected content is matched with the corresponding content in the known threat information to determine whether the alarm information is a real threat.
5. The vehicle network intrusion response method as described in claim 4, characterized in that, The alarm information also includes multi-dimensional alarm attributes; The step of matching the selected content with the corresponding content in the known threat information to determine whether the alarm information is a real threat includes: The selected content is matched with the corresponding content in the known threat information to determine the alarm information that matches successfully; Based on the filtering conditions associated with alarm filtering attributes related to the vehicle network, and based on the multi-dimensional alarm attributes of the alarm information, the matched alarm information is filtered. Determine whether the filtered alarm messages represent a real threat.
6. The vehicle network intrusion response method as described in claim 1, characterized in that, The determination of the threat level of the network intrusion behavior in response to whether the alarm information is a real threat includes: In response to the alarm information being a real threat, a first threat level of the network intrusion behavior is determined. The first threat level is determined based on the threat level of known threat information in the threat intelligence database that matches the alarm information. The threat intelligence database includes at least one known threat information related to vehicle network security. The threat intelligence database includes any of the following collected from the vehicle network: search behavior records, hacker activity characteristics, and resource information provided by white hat hackers.
7. The vehicle network intrusion response method as described in claim 1, characterized in that, The determination of the threat level of the network intrusion behavior in response to whether the alarm information is a real threat includes: When the alarm message is not a real threat, a second threat level of the network intrusion behavior is determined, and the second threat level is determined based on the threat level of the alarm message.
8. The vehicle network intrusion response method as described in claim 7, characterized in that, When the alarm information is not a real threat, determining the second threat level of the network intrusion behavior includes: When the alarm information is not a real threat, a second threat level of the network intrusion behavior is determined. The second threat level is determined by comprehensive analysis of the alarm information and the current status information of the vehicle's intrusion prevention system.
9. The vehicle network intrusion response method as described in claim 1, characterized in that, The analysis of security event data in the vehicle network, and the generation of alarm information based on the identified network intrusion behavior security event data, includes: By using a pre-set intrusion detection model, security event data in the vehicle network is analyzed, and alarm information is generated based on the security event data that identifies network intrusion behavior. The intrusion detection model is trained using historical security event data and historical analysis results.
10. The vehicle network intrusion response method as described in claim 1, characterized in that, After implementing the defensive measures in the intrusion response strategy corresponding to the threat level to address the threat of the network intrusion, the method further includes: Obtain the defense result data after the defense measures are implemented; The defense result data is evaluated according to preset evaluation indicators, a feedback report including the evaluation results is generated, and the feedback report is output.
11. A vehicle network intrusion response device, characterized in that, The system includes a memory, a processor, and a vehicle network intrusion response program stored in the memory and executable on the processor. When the processor executes the vehicle network intrusion response program, it implements the steps of the vehicle network intrusion response method as described in any one of claims 1-10.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a vehicle network intrusion response program, which, when executed, implements the steps of the vehicle network intrusion response method as described in any one of claims 1-10.
Citation Information
Patent Citations
Tracing analysis method for network attacks
CN111490970A
Automobile network security test method and device, medium and equipment
CN117692905A