A knowledge graph-based threat analysis method and system for the Internet of Vehicles and a medium
By generating a knowledge graph of vehicle-to-everything (V2X) threats using an algorithm based on expected cross-entropy and Spearman's rank correlation coefficient, and constructing a threat assessment model, the problem of multi-dimensional coverage and complexity in V2X threat analysis is solved, enabling a comprehensive display and flexible analysis of V2X threats.
Patent Information
- Application Number
- CN202411888194.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2044-12-20
AI Technical Summary
Existing vehicle-to-everything (V2X) threat analysis technologies are insufficient to comprehensively cover all dimensions of V2X threats and to capture their multifaceted and complex nature. As a result, the analysis results are limited to the hardware and software systems of V2X, while ignoring the interconnected communication dimensions between people, vehicles, roads, and the cloud.
A hierarchical clustering algorithm based on expected cross-entropy is used to extract feature information of vehicle-to-everything (V2X) threat intelligence. A cross-validation algorithm based on Spearman rank correlation coefficient is combined to characterize the correlation between entity objects and threat intelligence, generate a V2X threat knowledge graph, and construct a threat assessment model for analysis.
It achieves comprehensive coverage and multi-angle display of vehicle-to-everything (V2X) threats, enabling flexible analysis of V2X security posture. It overcomes the limitations of existing technologies in V2X threat analysis, and can intuitively display V2X threat intelligence, facilitating analysis by security analysts.
Smart Images

Figure CN119835026B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle network threat analysis technology, and in particular to a knowledge graph-based vehicle network threat analysis method, system, and medium. Background Technology
[0002] With the rapid development of electrification, intelligence, connectivity, and sharing in the automotive industry, automotive safety is facing unprecedented and complex challenges. While these "new four modernizations" bring about rapid development in the automotive industry, they also bring numerous challenges to automotive safety—the attack surface faced by automobiles is also increasing, including automotive hardware, hardware interfaces, software, wireless communications (Bluetooth, WiFi, radio frequency, cellular network communication), Ethernet communication, and so on.
[0003] From a cybersecurity perspective, modern cars exist within a complex network comprised of "people, vehicles, roads, and the cloud." Every point and every exposed surface generates a vast amount of data that could potentially become a vulnerability or attack point. For example, the standard OBD interface provides direct access to the car's internal network. Interfaces between the multimedia system and the car's controller network, as well as Bluetooth, WiFi, and cellular networks (GPRS, 3G, 4G, 5G), all offer potential entry points into the car's internal network. From an attack perspective, connected cars are not significantly different from PCs and mobile phones in the traditional internet environment, and will face various attacks from the internet world.
[0004] Modern vehicle-to-everything (V2X) networks, through next-generation information and communication technologies, achieve comprehensive network connectivity between vehicles and cloud platforms, vehicles and other vehicles, vehicles and roads, vehicles and people, and within the vehicle itself. This primarily achieves "triple play," integrating in-vehicle networks, inter-vehicle networks, and in-vehicle mobile internet. Therefore, the application environment is relatively unique, the network architecture is more complex, management is more difficult, and security threats are more severe. Threats include remote vehicle attacks, malicious control, and the leakage of personal information. The impact ranges from in-vehicle entertainment system playback to malicious vehicle manipulation causing major traffic accidents, and even to the leakage of travel information, road information, and map information, threatening national security.
[0005] Existing threat analysis technologies for connected vehicles typically focus on specific vulnerabilities and attack methods within the connected vehicle ecosystem. They generally begin by mitigating vulnerabilities and detecting particular attack methods. These threat analysis methods are relatively simplistic and fail to capture the multifaceted and complex nature of connected vehicle threats. Summary of the Invention
[0006] In view of the above problems, the present invention provides a knowledge graph-based method, system and medium for vehicle network threat analysis. It can not only solve the problem of not being able to fully cover the identification of threats in all dimensions of vehicle network, but also intuitively display vehicle network threat intelligence from various angles by analyzing the vehicle network threat knowledge graph, which makes it easier for automotive security analysts to flexibly analyze the vehicle network security situation.
[0007] To achieve the above and other related objectives, the present invention provides the following technical solution:
[0008] A knowledge graph-based method for analyzing threats in the Internet of Vehicles (IoV), the method comprising:
[0009] U1. Collects data information on connected vehicle entities and data information on connected vehicle threat intelligence;
[0010] U2. Based on the data information of the vehicle network threat intelligence, the feature information of the vehicle network threat intelligence is extracted by using a hierarchical clustering algorithm based on expected cross-entropy, and the feature matrix data information of the vehicle network threat intelligence is obtained.
[0011] U3. Based on the data information of the feature matrix of the vehicle network threat intelligence and the data information of the vehicle network entity objects, the cross-validation algorithm based on Spearman rank correlation coefficient is used to characterize the correlation between the entity objects and the feature matrix of the vehicle network threat intelligence, so as to obtain the data information of the correlation between the vehicle network entity objects and the threat intelligence.
[0012] U4. Based on the data information on the correlation between the vehicle network entities and threat intelligence, generate a vehicle network threat knowledge graph, construct a vehicle network threat assessment model, analyze vehicle network threats, and obtain data information on vehicle network threat analysis.
[0013] Furthermore, in step U2, the extraction of feature information from vehicle network threat intelligence using a hierarchical clustering algorithm based on expected cross-entropy includes:
[0014] U21. Based on the data information of the aforementioned vehicle-to-everything (V2X) threat intelligence, establish the expected cross-entropy function F of the V2X threat intelligence.
[0015]
[0016] Where x represents the data information of vehicle-to-everything (V2X) threat intelligence, and α1, α2, and α3 represent the cross-entropy factors of V2X threat intelligence. The cross-entropy information value of V2X threat intelligence is calculated to obtain the data information of the cross-entropy value of V2X threat intelligence.
[0017] U22. Based on the cross-information entropy values of the aforementioned vehicle-to-everything (V2X) threat intelligence, a hierarchical clustering function Q for V2X threat intelligence is established.
[0018]
[0019] Where y represents the cross-information entropy value of the vehicle-to-everything (V2X) threat intelligence, and β1, β2, and β3 are the hierarchical clustering dynamic factors of the V2X threat intelligence.
[0020] U23. Based on the hierarchical clustering function Q of the vehicle network threat intelligence, the feature information of the vehicle network threat intelligence is extracted to obtain the feature matrix data information of the vehicle network threat intelligence.
[0021] Furthermore, the hierarchical clustering dynamic factors β1, β2, and β3 of the vehicle network threat intelligence are,
[0022]
[0023] Where y represents the cross-entropy value of the vehicle-to-everything (V2X) threat intelligence.
[0024] Furthermore, the cross-entropy factors α1, α2, and α3 of the vehicle network threat intelligence are,
[0025] Where x represents data information related to vehicle-to-everything (V2X) threat intelligence.
[0026] Furthermore, in step U3, the characterization of the correlation between the entity object and the feature matrix of the vehicle network threat intelligence using a cross-validation algorithm based on Spearman's rank correlation coefficient includes:
[0027] U31. Based on the data information of the feature matrix of the vehicle network threat intelligence and the data information of the vehicle network entity objects, construct the Spearman rank correlation function W of the vehicle network.
[0028]
[0029] Where z1 is the data information of the feature matrix of vehicle network threat intelligence, z2 is the data information of vehicle network entity objects, δ1, δ2 and δ3 are the relationship factors between vehicle network threat intelligence and entity objects, and the Spearman correlation coefficient between vehicle network threat intelligence and entity objects is characterized to obtain the data information of the Spearman correlation coefficient between vehicle network threat intelligence and entity objects.
[0030] U32. Based on the data information of the Spearman correlation coefficient between the vehicle network threat intelligence and the entity objects, construct the cross-validation optimization function R for the vehicle network.
[0031]
[0032] Where r is the Spearman correlation coefficient data between vehicle network threat intelligence and entity objects, and γ1, γ2 and γ3 are cross-validation optimization parameters for vehicle network. The Spearman correlation coefficient between vehicle network threat intelligence and entity objects is optimized to obtain the optimized Spearman correlation coefficient data of vehicle network threat intelligence and entity objects.
[0033] U33. Based on the optimized Spearman correlation coefficient data between the vehicle network threat intelligence and the entity objects, establish a correlation function S between the entity objects of the vehicle network and the feature matrix of the vehicle network threat intelligence.
[0034]
[0035] Where h represents the Spearman correlation coefficient between the optimized vehicle-to-everything (V2X) threat intelligence and the entity object, and η1, η2, and η3 are weight coefficients that characterize the correlation between the entity object and the feature matrix of the V2X threat intelligence, thus obtaining the correlation data between the V2X entity object and the threat intelligence.
[0036] Furthermore, the constraints on the weighting coefficients η1, η2, and η3 are as follows:
[0037]
[0038] Furthermore, the constraint function g for the cross-validation optimization parameters γ1, γ2, and γ3 of the vehicle-to-everything (V2X) network is,
[0039]
[0040] The constraint function g takes values in the range of (0,1).
[0041] Furthermore, in step U4, the construction of the vehicle-to-everything (V2X) threat assessment model and the analysis of V2X threats include:
[0042] U41. Based on the aforementioned Internet of Vehicles (IoV) threat knowledge graph, construct an IoV threat knowledge graph set;
[0043] U42. Input the aforementioned vehicle-to-everything (V2X) threat knowledge graph into the V2X threat assessment model for training and learning, and determine the V2X threat assessment function G.
[0044]
[0045] Where q is the knowledge graph set of vehicle-to-everything (V2X) threats, and λ1, λ2 and λ3 are V2X threat assessment factors, thus obtaining the trained V2X threat assessment model;
[0046] U43. Based on the trained vehicle-to-everything (V2X) threat assessment model, input the V2X threat knowledge graph to analyze the threats to the V2X and obtain data information on the threat analysis of the V2X.
[0047] To achieve the above and other related objectives, the present invention also provides a knowledge graph-based vehicle network threat analysis system, including a computer device programmed or configured to perform the steps of any of the knowledge graph-based vehicle network threat analysis methods described above.
[0048] To achieve the above and other related objectives, the present invention also provides a computer-readable storage medium storing a computer program programmed or configured to perform any of the knowledge graph-based vehicle network threat analysis methods described in the present invention.
[0049] The present invention has the following positive effects:
[0050] 1. This invention extracts feature information of vehicle network threat intelligence by employing a hierarchical clustering algorithm based on expected cross-entropy, and combines it with a cross-validation algorithm based on Spearman's rank correlation coefficient to characterize the correlation between entity objects and the feature matrix of vehicle network threat intelligence. This not only solves the problem of not being able to fully cover the identification of threats in all dimensions of vehicle networks, but also provides a comprehensive view of the vehicle network threat knowledge graph from various angles, which can intuitively display vehicle network threat intelligence and facilitate automotive security analysts to flexibly analyze the vehicle network security situation.
[0051] 2. This invention analyzes the threats to the Internet of Vehicles (IoV) by constructing an IoV threat assessment model. It can not only flexibly divide the IoV threat knowledge graph into various threat subgraphs to freely and flexibly display the IoV threat situation, but also solve the problem that the final IoV threat analysis can only focus on the hardware and software system threats of the IoV, while ignoring the communication dimension that truly leads to the complexity of IoV threats, which involves the connection between people, vehicles, roads, and the cloud. Attached Figure Description
[0052] Figure 1 This is a schematic diagram of the method flow of the present invention;
[0053] Figure 2 This is a flowchart illustrating the hierarchical clustering algorithm based on expected cross-entropy of the present invention.
[0054] Figure 3 This is a flowchart illustrating the cross-validation algorithm based on Spearman's rank correlation coefficient of the present invention.
[0055] Figure 4 This is a schematic diagram illustrating the process of constructing a vehicle-to-everything (V2X) threat assessment model according to the present invention.
[0056] Figure 5 This is a schematic diagram of the system architecture of the present invention. Detailed Implementation
[0057] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0058] Example 1: As Figure 1 As shown, a knowledge graph-based method for analyzing threats in the Internet of Vehicles (IoV) includes:
[0059] U1. Collects data information on connected vehicle entities and data information on connected vehicle threat intelligence;
[0060] U2. Based on the data information of the vehicle network threat intelligence, the feature information of the vehicle network threat intelligence is extracted by using a hierarchical clustering algorithm based on expected cross-entropy, and the feature matrix data information of the vehicle network threat intelligence is obtained.
[0061] U3. Based on the data information of the feature matrix of the vehicle network threat intelligence and the data information of the vehicle network entity objects, the cross-validation algorithm based on Spearman rank correlation coefficient is used to characterize the correlation between the entity objects and the feature matrix of the vehicle network threat intelligence, so as to obtain the data information of the correlation between the vehicle network entity objects and the threat intelligence.
[0062] U4. Based on the data information on the correlation between the vehicle network entities and threat intelligence, generate a vehicle network threat knowledge graph, construct a vehicle network threat assessment model, analyze vehicle network threats, and obtain data information on vehicle network threat analysis.
[0063] In this embodiment, as Figure 2 As shown, in step U2, the extraction of feature information of vehicle network threat intelligence using a hierarchical clustering algorithm based on expected cross-entropy includes:
[0064] U21. Based on the data information of the aforementioned vehicle-to-everything (V2X) threat intelligence, establish the expected cross-entropy function F of the V2X threat intelligence.
[0065]
[0066] Where x represents the data information of vehicle-to-everything (V2X) threat intelligence, and α1, α2, and α3 represent the cross-entropy factors of V2X threat intelligence. The cross-entropy information value of V2X threat intelligence is calculated to obtain the data information of the cross-entropy value of V2X threat intelligence.
[0067] U22. Based on the cross-information entropy values of the aforementioned vehicle-to-everything (V2X) threat intelligence, a hierarchical clustering function Q for V2X threat intelligence is established.
[0068]
[0069] Where y represents the cross-information entropy value of the vehicle-to-everything (V2X) threat intelligence, and β1, β2, and β3 are the hierarchical clustering dynamic factors of the V2X threat intelligence.
[0070] U23. Based on the hierarchical clustering function Q of the vehicle network threat intelligence, the feature information of the vehicle network threat intelligence is extracted to obtain the feature matrix data information of the vehicle network threat intelligence.
[0071] In this embodiment, the hierarchical clustering dynamic factors β1, β2, and β3 of the vehicle network threat intelligence are,
[0072]
[0073] Where y represents the cross-entropy value of the vehicle-to-everything (V2X) threat intelligence.
[0074] In this embodiment, the cross-entropy factors α1, α2, and α3 of the vehicle network threat intelligence are,
[0075]
[0076] Where x represents data information related to vehicle-to-everything (V2X) threat intelligence.
[0077] In this embodiment, as Figure 5 As shown, in step U3, the characterization of the correlation between the entity object and the feature matrix of the vehicle network threat intelligence using a cross-validation algorithm based on Spearman's rank correlation coefficient includes:
[0078] U31. Based on the data information of the feature matrix of the vehicle network threat intelligence and the data information of the vehicle network entity objects, construct the Spearman rank correlation function W of the vehicle network.
[0079]
[0080] Where z1 is the data information of the feature matrix of vehicle network threat intelligence, z2 is the data information of vehicle network entity objects, δ1, δ2 and δ3 are the relationship factors between vehicle network threat intelligence and entity objects, and the Spearman correlation coefficient between vehicle network threat intelligence and entity objects is characterized to obtain the data information of the Spearman correlation coefficient between vehicle network threat intelligence and entity objects.
[0081] U32. Based on the data information of the Spearman correlation coefficient between the vehicle network threat intelligence and the entity objects, construct the cross-validation optimization function R for the vehicle network.
[0082]
[0083] Where r is the Spearman correlation coefficient data between vehicle network threat intelligence and entity objects, and γ1, γ2 and γ3 are cross-validation optimization parameters for vehicle network. The Spearman correlation coefficient between vehicle network threat intelligence and entity objects is optimized to obtain the optimized Spearman correlation coefficient data of vehicle network threat intelligence and entity objects.
[0084] U33. Based on the optimized Spearman correlation coefficient data between the vehicle network threat intelligence and the entity objects, establish a correlation function S between the entity objects of the vehicle network and the feature matrix of the vehicle network threat intelligence.
[0085]
[0086] Where h represents the Spearman correlation coefficient between the optimized vehicle-to-everything (V2X) threat intelligence and the entity object, and η1, η2, and η3 are weight coefficients that characterize the correlation between the entity object and the feature matrix of the V2X threat intelligence, thus obtaining the correlation data between the V2X entity object and the threat intelligence.
[0087] In this embodiment, the constraints on the weighting coefficients η1, η2, and η3 are as follows:
[0088]
[0089] In this embodiment, the constraint function g for the cross-validation optimization parameters γ1, γ2, and γ3 of the vehicle network is,
[0090]
[0091] The constraint function g takes values in the range of (0,1).
[0092] Example 2: Based on the knowledge graph-based vehicle network threat analysis method in Example 1, the present invention will be further explained and described below.
[0093] like Figure 1 As shown, a knowledge graph-based method for analyzing threats in the Internet of Vehicles (IoV) includes:
[0094] U1. Collects data information on connected vehicle entities and data information on connected vehicle threat intelligence;
[0095] U2. Based on the data information of the vehicle network threat intelligence, the feature information of the vehicle network threat intelligence is extracted by using a hierarchical clustering algorithm based on expected cross-entropy, and the feature matrix data information of the vehicle network threat intelligence is obtained.
[0096] U3. Based on the data information of the feature matrix of the vehicle network threat intelligence and the data information of the vehicle network entity objects, the cross-validation algorithm based on Spearman rank correlation coefficient is used to characterize the correlation between the entity objects and the feature matrix of the vehicle network threat intelligence, so as to obtain the data information of the correlation between the vehicle network entity objects and the threat intelligence.
[0097] U4. Based on the data information on the correlation between the vehicle network entities and threat intelligence, generate a vehicle network threat knowledge graph, construct a vehicle network threat assessment model, analyze vehicle network threats, and obtain data information on vehicle network threat analysis.
[0098] In this embodiment, as Figure 4 As shown, in step U4, the construction of the vehicle-to-everything (V2X) threat assessment model and the analysis of V2X threats include:
[0099] U41. Based on the aforementioned Internet of Vehicles (IoV) threat knowledge graph, construct an IoV threat knowledge graph set;
[0100] U42. Input the aforementioned vehicle-to-everything (V2X) threat knowledge graph into the V2X threat assessment model for training and learning, and determine the V2X threat assessment function G.
[0101]
[0102] Where q is the knowledge graph set of vehicle-to-everything (V2X) threats, and λ1, λ2 and λ3 are V2X threat assessment factors, thus obtaining the trained V2X threat assessment model;
[0103] U43. Based on the trained vehicle-to-everything (V2X) threat assessment model, input the V2X threat knowledge graph to analyze the threats to the V2X and obtain data information on the threat analysis of the V2X.
[0104] In this embodiment, the present invention provides a knowledge graph-based vehicle network threat analysis system, including a computer device that is programmed or configured to perform the steps of any of the knowledge graph-based vehicle network threat analysis methods described above.
[0105] like Figure 5As shown, from the perspective of vehicle network security threats, the vehicle network architecture is divided into the external network communication layer, the in-vehicle platform network layer, and the in-vehicle component layer. The main attack surfaces of the external network communication layer include: Bluetooth car keys, OBD ports, WiFi, TSP, mobile applications (Apps), the vehicle network cloud (including potential VSOC cloud and PKI cloud), and the communication channels between them. The attack surface of the in-vehicle platform network layer is mainly concentrated on the CAN bus. Threats to the in-vehicle component layer mainly come from security vulnerabilities in ECUs (including sensors, IDPS vehicle-side components, and PKI vehicle-side SDKs). ECU security vulnerabilities include both software and firmware vulnerabilities.
[0106] This application consists of four main modules: asset identification module, threat association module, threat analysis module, and threat display module.
[0107] The asset identification module is designed to identify entity elements in the Internet of Vehicles (IoV) and abstract these entity elements into asset node objects in the IoV knowledge graph.
[0108] The threat association module consists of two sub-functions: first, abstracting threat intelligence nodes from information in threat intelligence; and second, creating connections between threat intelligence nodes and connected vehicle asset nodes. This module associates connected vehicle assets with connected vehicle threat knowledge, thereby generating a connected vehicle threat knowledge graph.
[0109] The threat analysis module classifies or calculates threat levels for the knowledge graph asset nodes of the Internet of Vehicles based on threat intelligence.
[0110] The threat visualization module presents a knowledge graph of vehicle-to-everything (V2X) threats in a visual manner, thereby enabling the analysis of V2X threats.
[0111] Asset identification module
[0112] The asset identification module identifies the elements of vehicle-to-everything (V2X) physical assets contained in the three main parts of the V2X network: the external network communication layer, the in-vehicle platform network layer, and the in-vehicle component layer. Asset types include hardware systems (including ECUs, sensors, and other automotive electronic and electrical components, servers, etc.), hardware subsystems, software systems (including basic automotive software systems, cloud platform software systems, etc.), interfaces (including OBD, USB, etc.), communication protocols, bus protocols, etc.
[0113] First, to implement the functionality of this module, it is necessary to collect data on connected vehicle entities. A feasible approach is to collect threat intelligence and extract relevant information about entity assets from the threat intelligence data.
[0114] After obtaining the physical asset objects, these connected vehicle asset elements are abstracted into asset node objects in a knowledge graph. Specifically, partial information from each type of asset node is extracted as the node identifier for that type of asset entity. The extraction method can be summarized as follows: select information that can identify the physical asset object from the information describing the entity object as the asset node identifier, and use the remaining information as the asset object's attribute information.
[0115] For hardware systems, the manufacturer and version information (as detailed as possible) of the hardware system asset object are concatenated to form the asset node's identifier. Other information about the hardware system is used as the attribute information of the hardware system asset node. Similarly, for hardware subsystems, software systems, and software subsystems, the same method is used to identify asset nodes, with other information serving as the asset node's attribute information.
[0116] For interface asset objects, USB interfaces are identified by the protocol used by the interface and the specific version number of the protocol, while other information serves as the attribute information of this type of asset node; OBD interfaces are identified by the vehicle model of the car manufacturer to which the interface is located, while other information serves as the attribute information of this type of node.
[0117] For communication protocols, including those common in automotive network environments such as TCP, UDP, HTTP, SOME / IP, TLS, UDS, and MQTT, the specific version of the protocol is used as the identification information for the protocol asset node, while other information is used as the attribute information of the protocol asset node.
[0118] Using the above extraction method, asset entities in the vehicle network are extracted as asset nodes in the vehicle network knowledge graph.
[0119] In this embodiment, the present invention provides a computer-readable storage medium storing a computer program programmed or configured to perform any of the knowledge graph-based vehicle network threat analysis methods described above.
[0120] Any references to memory, storage, database, or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.
[0121] In summary, this invention not only solves the problem of not being able to comprehensively cover the identification of threats in all dimensions of the Internet of Vehicles (IoV), but also provides an intuitive display of IoV threat intelligence from various angles through the IoV threat knowledge graph, making it easier for automotive security analysts to flexibly analyze the IoV security situation.
[0122] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A knowledge graph-based method for analyzing threats in the Internet of Vehicles (IoV), characterized in that, The method includes: U1. Collects data information on connected vehicle entities and data information on connected vehicle threat intelligence; U2. Based on the data information of the vehicle network threat intelligence, the feature information of the vehicle network threat intelligence is extracted by using a hierarchical clustering algorithm based on expected cross-entropy, and the feature matrix data information of the vehicle network threat intelligence is obtained. U3. Based on the data information of the feature matrix of the vehicle network threat intelligence and the data information of the vehicle network entity objects, the cross-validation algorithm based on Spearman rank correlation coefficient is used to characterize the correlation between the entity objects and the feature matrix of the vehicle network threat intelligence, so as to obtain the data information of the correlation between the vehicle network entity objects and the threat intelligence. U4. Based on the data information on the correlation between the vehicle network entities and threat intelligence, generate a vehicle network threat knowledge graph, construct a vehicle network threat assessment model, analyze vehicle network threats, and obtain data information on vehicle network threat analysis.
2. The knowledge graph-based vehicle network threat analysis method according to claim 1, characterized in that, In step U2, the extraction of feature information from vehicle-to-everything (V2X) threat intelligence using a hierarchical clustering algorithm based on expected cross-entropy includes: U21. Based on the data information of the aforementioned vehicle-to-everything (V2X) threat intelligence, establish the expected cross-entropy function F of the V2X threat intelligence. Where x represents the data information of vehicle-to-everything (V2X) threat intelligence, and α1, α2, and α3 represent the cross-entropy factors of V2X threat intelligence. The cross-entropy information value of V2X threat intelligence is calculated to obtain the data information of the cross-entropy value of V2X threat intelligence. U22. Based on the cross-information entropy values of the aforementioned vehicle-to-everything (V2X) threat intelligence, a hierarchical clustering function Q for V2X threat intelligence is established. Where y represents the cross-information entropy value of the vehicle-to-everything (V2X) threat intelligence, and β1, β2, and β3 are the hierarchical clustering dynamic factors of the V2X threat intelligence. U23. Based on the hierarchical clustering function Q of the vehicle network threat intelligence, the feature information of the vehicle network threat intelligence is extracted to obtain the feature matrix data information of the vehicle network threat intelligence.
3. The knowledge graph-based vehicle network threat analysis method according to claim 2, characterized in that: The hierarchical clustering dynamic factors β1, β2, and β3 of the vehicle network threat intelligence are: Where y represents the cross-entropy value of the vehicle-to-everything (V2X) threat intelligence.
4. The knowledge graph-based vehicle network threat analysis method according to claim 2, characterized in that: The cross-entropy factors α1, α2, and α3 of the aforementioned vehicle-to-everything (V2X) threat intelligence are: Where x represents data information related to vehicle-to-everything (V2X) threat intelligence.
5. The knowledge graph-based vehicle network threat analysis method according to claim 1, characterized in that, In step U3, the characterization of the correlation between the entity object and the feature matrix of the vehicle network threat intelligence using a cross-validation algorithm based on Spearman's rank correlation coefficient includes: U31. Based on the data information of the feature matrix of the vehicle network threat intelligence and the data information of the vehicle network entity objects, construct the Spearman rank correlation function W of the vehicle network. Where z1 is the data information of the feature matrix of vehicle network threat intelligence, z2 is the data information of vehicle network entity objects, δ1, δ2 and δ3 are the relationship factors between vehicle network threat intelligence and entity objects, and the Spearman correlation coefficient between vehicle network threat intelligence and entity objects is characterized to obtain the data information of the Spearman correlation coefficient between vehicle network threat intelligence and entity objects. U32. Based on the data information of the Spearman correlation coefficient between the vehicle network threat intelligence and the entity objects, construct the cross-validation optimization function R for the vehicle network. Where r is the Spearman correlation coefficient data between vehicle network threat intelligence and entity objects, and γ1, γ2 and γ3 are cross-validation optimization parameters for vehicle network. The Spearman correlation coefficient between vehicle network threat intelligence and entity objects is optimized to obtain the optimized Spearman correlation coefficient data of vehicle network threat intelligence and entity objects. U33. Based on the optimized Spearman correlation coefficient data between the vehicle network threat intelligence and the entity objects, establish a correlation function S between the entity objects of the vehicle network and the feature matrix of the vehicle network threat intelligence. Where h represents the Spearman correlation coefficient between the optimized vehicle-to-everything (V2X) threat intelligence and the entity object, and η1, η2, and η3 are weight coefficients that characterize the correlation between the entity object and the feature matrix of the V2X threat intelligence, thus obtaining the correlation data between the V2X entity object and the threat intelligence.
6. The knowledge graph-based vehicle network threat analysis method according to claim 5, characterized in that: The constraints on the weighting coefficients η1, η2, and η3 are as follows:
7. The knowledge graph-based vehicle network threat analysis method according to claim 5, characterized in that: The constraint function g for the cross-validation optimization parameters γ1, γ2, and γ3 of the vehicle network is: The constraint function g takes values in the range of (0,1).
8. The knowledge graph-based vehicle network threat analysis method according to claim 1, characterized in that, In step U4, the construction of the vehicle-to-everything (V2X) threat assessment model and the analysis of V2X threats include: U41. Based on the aforementioned Internet of Vehicles (IoV) threat knowledge graph, construct an IoV threat knowledge graph set; U42. Input the aforementioned vehicle-to-everything (V2X) threat knowledge graph into the V2X threat assessment model for training and learning, and determine the V2X threat assessment function G. Where q is the knowledge graph set of vehicle-to-everything (V2X) threats, and λ1, λ2 and λ3 are V2X threat assessment factors, thus obtaining the trained V2X threat assessment model; U43. Based on the trained vehicle-to-everything (V2X) threat assessment model, input the V2X threat knowledge graph to analyze the threats to the V2X and obtain data information on the threat analysis of the V2X.
9. A knowledge graph-based vehicle network threat analysis system, comprising computer equipment, characterized in that, The computer device is programmed or configured to perform the steps of the knowledge graph-based vehicle network threat analysis method according to any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that is programmed or configured to perform the knowledge graph-based vehicle network threat analysis method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Network security threat management system and method based on knowledge graph
CN117118857A
Method and device for determining security threat intelligence based on user entity behavior analysis
CN117319051A