Method, device and equipment for protecting internet of vehicles service platform and storage medium
By dynamically scheduling the security protection levels and multi-level protection strategies of the Internet of Vehicles service platform, the problems of single protection levels and imperfect strategies in existing technologies have been solved, multi-level security protection and timely warnings for the Internet of Vehicles information service platform have been achieved, and network security protection capabilities have been improved.
Patent Information
- Application Number
- CN202510042204.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-01-10
AI Technical Summary
The existing Internet of Vehicles information service platform has a single network security protection level, fixed hierarchical relationships, imperfect security protection strategies, insufficient monitoring and alarm capabilities, and lacks specificity, resulting in poor overall protection effects.
By obtaining the processing results of each security protection layer of the Internet of Vehicles service platform within a preset historical period, calculating risk measurement indicators and determining risk levels, dynamically scheduling the order of security protection levels, and using multi-level dynamic security protection layers to process data traffic, including specific strategies for boundary, network, application, system and data protection layers to detect and intercept abnormal traffic, generate security logs and upload them to the monitoring and alarm platform.
It has achieved multi-level and three-dimensional security protection for the Internet of Vehicles information service platform, improved network security protection capabilities, timely discovered and responded to security incidents, improved monitoring and alarm capabilities, and enhanced the overall protection effect of the platform.
Smart Images

Figure CN119835068B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of Internet of Vehicles, in particular to a protection method and device for an Internet of Vehicles service platform, equipment and a storage medium. BACKGROUND
[0002] With the rapid development of intelligent and connected vehicle (ICV) technology, the Internet of Vehicles information service platform has become an indispensable part of the modern automotive industry. However, with its wide application, the network security threats faced by the Internet of Vehicles information service platform are becoming increasingly serious. In recent years, network security attacks targeting the Internet of Vehicles information service platform have occurred frequently at home and abroad. These attacks not only easily lead to vehicle theft and data leakage, but also cause the vehicle to lose control while driving, seriously threatening road traffic safety and user privacy.
[0003] The existing security protection methods for the Internet of Vehicles have many shortcomings, mainly manifested in single protection level, fixed hierarchical relationship, imperfect security protection strategy, insufficient monitoring and alarm capability, and lack of pertinence. These methods often only focus on protection at one level, with simple strategies and lack of response capability to complex threats, while the monitoring and alarm mechanism is not perfect, making it difficult to discover and respond to security incidents in a timely manner. Moreover, the specific needs and characteristics of the Internet of Vehicles information service platform are not fully considered, resulting in poor overall protection effect. SUMMARY
[0004] Therefore, the embodiments of the present application provide a protection method and device for an Internet of Vehicles service platform, equipment and a storage medium to solve the problems of single protection level, fixed hierarchical relationship, imperfect security protection strategy, insufficient monitoring and alarm capability, and lack of pertinence of the Internet of Vehicles information service platform network security protection in the prior art.
[0005] In a first aspect, the embodiments of the present application provide a protection method for an Internet of Vehicles service platform, applied to the Internet of Vehicles service platform, the method comprising:
[0006] obtaining the processing results output by each security protection layer in the Internet of Vehicles service platform in a preset historical period;
[0007] calculating the risk measurement index corresponding to the processing results according to a preset evaluation standard, and determining the risk level of the security protection layer associated with each processing result based on the risk measurement index;
[0008] scheduling the hierarchical order of the security protection layers in the Internet of Vehicles service platform according to the risk level, to obtain dynamic security protection layers with hierarchical relationship;
[0009] The dynamic security protection layer with the hierarchical relationship is used to perform corresponding protection operations on the vehicle networking service platform.
[0010] Further, the risk degree index corresponding to the processing result is calculated according to a preset evaluation standard, and the risk level of the security protection layer associated with each processing result is determined based on the risk degree index, including:
[0011] The number of events in the processing result in a preset historical period is obtained;
[0012] The risk type of each risk event is identified, and the risk value corresponding to the risk event is determined according to the risk type;
[0013] The risk level of the security protection layer associated with each processing result is calculated based on the number of events in the processing result and the risk value corresponding to each risk event.
[0014] Further, the dynamic security protection layer with the hierarchical relationship is used to perform corresponding protection operations on the vehicle networking service platform, including:
[0015] Receiving first data traffic sent by an external network to a vehicle networking service platform;
[0016] The first data traffic is sequentially input into the dynamic security protection layer with a hierarchical relationship in the vehicle networking service platform, wherein at least one security protection strategy is configured in each dynamic security protection layer;
[0017] The configured security protection strategy is called based on the dynamic security protection layer to process the first data traffic to obtain a processing result;
[0018] A security log is generated according to the processing result, and the security log is uploaded to a monitoring and alarming platform.
[0019] Further, if the dynamic security protection layer is a boundary protection layer, the processing result is obtained by processing the first data traffic based on the configured security protection strategy of the dynamic security protection layer, including:
[0020] Based on the denial of service attack protection strategy configured by the boundary protection layer, it is detected whether there is first abnormal traffic of denial of service attack in the first data traffic;
[0021] If the first abnormal traffic exists, the first abnormal traffic in the first data traffic is intercepted, and the first data traffic is limited to access platform addresses and platform resource libraries through the asset protection strategy configured by the boundary protection layer, to obtain a first processing result.
[0022] Further, if the dynamic security protection layer is a network protection layer, the processing of the first data flow based on the security protection strategy configured by the dynamic security protection layer comprises:
[0023] acquiring second data flow transmitted to the network protection layer, wherein the second data flow is obtained by processing the first data flow by a dynamic security protection layer at a previous level;
[0024] detecting whether a virus feature exists in the second data flow based on a virus protection strategy configured by the network protection layer;
[0025] if the virus feature exists, intercepting second abnormal flow with the virus feature in the second data flow, limiting a communication source of the second abnormal flow based on an access control strategy configured by the network protection layer, and generating a second processing result.
[0026] Further, if the dynamic security protection layer is an application protection layer, the processing of the first data flow based on the security protection strategy configured by the dynamic security protection layer comprises:
[0027] acquiring third data flow transmitted to the application protection layer, wherein the third data flow is obtained by processing the second data flow by a dynamic security protection layer at a previous level;
[0028] detecting whether third abnormal flow of application interface call exists in the third data flow based on an API protection strategy configured by the application protection layer;
[0029] if the third abnormal flow exists, analyzing the third abnormal flow to obtain identity information, performing a verification operation on the identity information based on a website protection strategy configured by the application protection layer, and generating a third processing result.
[0030] Further, if the dynamic security protection layer is a system protection layer, the processing of the first data flow based on the security protection strategy configured by the dynamic security protection layer comprises:
[0031] acquiring fourth data flow transmitted to the system protection layer, wherein the fourth data flow is obtained by processing the third data flow by a dynamic security protection layer at a previous level;
[0032] analyzing the fourth data flow based on an asset management strategy configured by the system protection layer to determine whether an intrusion behavior exists in a service running environment;
[0033] If the intrusion behavior exists, intercept fourth abnormal traffic of the fourth data traffic with the intrusion behavior, and check configuration information of the service running environment and file isolation based on a cooperative protection policy configured by the system protection layer to generate a fourth processing result.
[0034] Further, if the dynamic security protection layer is a data protection layer, the processing result obtained by processing the first data traffic based on the security protection policy configured by the dynamic security protection layer includes:
[0035] Obtain fifth data traffic transmitted to the data protection layer, wherein the fifth data traffic is obtained by processing fourth data traffic by a dynamic security protection layer at a previous level;
[0036] Detect the fifth data traffic flowing into the data protection layer based on a transmission encryption policy configured by the data protection layer;
[0037] Determine whether there is a data transmission requirement according to the fifth data traffic;
[0038] If the data transmission requirement exists, generate a plurality of keys based on a storage encryption policy configured by the data protection layer, and perform an encryption operation on transmission data of a local server and a local database based on the keys and the transmission requirement to generate a fifth processing result.
[0039] Further, the encryption operation on the transmission data of the local server and the local database based on the keys and the transmission requirement includes:
[0040] Obtain a transmission requirement corresponding to the transmission data;
[0041] If the transmission requirement is from a remote terminal to the local server, verify a second key in the transmission data according to a first key stored in the local server, and after verification, encrypt the transmission data using a first encryption policy to obtain first encrypted data;
[0042] If the transmission requirement is from a remote server to the local server, encrypt the transmission data using a second encryption policy to obtain second encrypted data;
[0043] If the transmission requirement is from a remote database to the local database, encrypt the transmission data using a third key stored in the local database to obtain third encrypted data;
[0044] If the transmission requirement is from a data file to a local disk, encrypt the transmission data using a fourth key stored by a key generator to obtain fourth encrypted data.
[0045] In a second aspect, the embodiments of the present application provide a protection method and device of a vehicle Internet service platform, which are applied to the vehicle Internet service platform, and the device comprises:
[0046] a obtaining module, configured to obtain processing results output by each security protection layer in the vehicle Internet service platform in a preset historical period;
[0047] a calculating module, configured to calculate a risk measurement index corresponding to the processing results according to a preset evaluation standard, and determine a risk level of the security protection layer associated with each of the processing results based on the risk measurement index;
[0048] a scheduling module, configured to schedule a hierarchical order of the security protection layers in the vehicle Internet service platform according to the risk level, and obtain dynamic security protection layers having a hierarchical relationship;
[0049] an executing module, configured to execute corresponding protection operations on the vehicle Internet service platform by using the dynamic security protection layers having the hierarchical relationship.
[0050] In a third aspect, the embodiments of the present application provide a computer device, which comprises a memory and a processor, the memory and the processor are communicatively connected with each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the method of the first aspect or any of the corresponding embodiments thereof.
[0051] In a fourth aspect, the embodiments of the present application provide a computer readable storage medium, which stores computer instructions, and the computer instructions are used to make a computer execute the method of the first aspect or any of the corresponding embodiments thereof.
[0052] The method provided by the embodiments of the present application has the following beneficial effects:
[0053] The method provided by the present application can comprehensively understand the working conditions of the vehicle Internet service platform by obtaining the processing results of each security protection layer of the vehicle Internet service platform in a preset historical period, provide accurate data for risk evaluation and protection layer scheduling, and find potential security problem trends to take preventive measures. The risk measurement index of the processing results is calculated, and the risk level of the protection layer is determined, so that the risk degree can be quantified, the security situation can be intuitively understood, the security resources can be allocated accordingly, the protection efficiency can be improved, the high-risk layer can be found in time, and strict measures can be taken to reduce the possibility of accidents. The hierarchical order of the protection layers is scheduled according to the risk level, so that the security protection system can flexibly adapt to different risks, more resources can be put into adjustment of the order, the overall protection effect can be improved, and the resource allocation can be optimized. The protection operation is executed by using the dynamic security protection layer, multi-level and three-dimensional protection is realized, different layers are used for special protection against different security threats, and data flow is processed in sequence to intercept potential threats and reduce the impact.
[0054] The method provided by the embodiment of the present application can traverse the risk event statistical quantity in the historical processing result, explicitly determine the total security risk quantity of the platform in a specific period, provide basic data for risk assessment, and understand the stability of the security condition and the risk trend. Identifying the risk type and determining the risk value can help to classify and assess different security risks, measure the severity thereof, and provide specific risk indicators to facilitate taking corresponding protection measures. The protection layer risk grade is calculated based on the event quantity and the risk value, the risk can be quantified to enable the manager to understand the condition, adjust the protection strategy to improve the effect, and provide a basis for hierarchical scheduling to ensure that the high-risk layer is processed first to reduce the possibility of accidents.
[0055] The method provided by the embodiment of the present application can realize comprehensive and multi-level security protection of the vehicle networking information service platform through the vehicle networking multi-layer network security protection method and the monitoring and alarming architecture, solve the problems of single protection level, fixed protection layer structure, imperfect security protection strategy, insufficient monitoring and alarming capability, and lack of pertinence in the prior art. By sequentially inputting the received external network data flow into the security protection layers with hierarchical relationship and calling the security protection strategies configured in each layer for processing, multi-level and three-dimensional security protection of the vehicle networking information service platform is realized, and the network security protection capability of the platform is effectively improved. By generating a security log and uploading the log to the monitoring and alarming platform, timely discovery and response to network security events are realized, the monitoring and alarming capability of the platform is improved, and it is helpful to take timely countermeasures to reduce losses.
[0056] The method provided by the embodiment of the present application can detect and intercept abnormal flow in time, limit access to platform addresses and resource libraries, and thus effectively resist network threats such as denial of service attacks, by configuring denial of service attack protection strategies and asset protection strategies in the boundary protection layer. In the network protection layer, by configuring virus protection strategies and access control strategies, data flow with virus characteristics can be detected and intercepted, and the communication source thereof is limited, further enhancing the network security protection effect of the platform. In the application protection layer, by configuring API protection strategies and website protection strategies, abnormal flow of application interface calls can be detected and processed, and identity information is verified, ensuring the security and stability of the application layer. In the system protection layer, by configuring asset management strategies and collaborative protection strategies, data flow can be analyzed and it can be determined whether there is intrusion behavior in the service running environment, abnormal flow can be intercepted in time and configuration information and file isolation can be checked, effectively ensuring the security of the system layer. In the data protection layer, by configuring transmission encryption strategies and storage encryption strategies, transmission data can be encrypted, ensuring the confidentiality and integrity of the data, and preventing data leakage and tampering. BRIEF DESCRIPTION OF DRAWINGS
[0057] In order to more clearly illustrate the technical solutions in the specific embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the specific embodiments or prior art description. Obviously, the drawings described below are some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.
[0058] Figure 1 Figure is a flow diagram of a protection method of a vehicle networking service platform according to an embodiment of the present application;
[0059] Figure 2 Figure is a scheduling structure diagram of a security protection layer of a vehicle networking information service platform according to an embodiment of the present application
[0060] Figure 3 Figure is a protection structure diagram of a security protection layer of a vehicle networking information service platform according to an embodiment of the present application;
[0061] Figure 4 Figure is a structure diagram of an internal unit of each protection layer of a vehicle networking information service platform according to an embodiment of the present application;
[0062] Figure 5 Figure is a flow diagram of a key-related operation of a vehicle networking information service platform according to an embodiment of the present application;
[0063] Figure 6 Figure is a structure diagram of a monitoring and alarming architecture of a vehicle networking information service platform according to an embodiment of the present application;
[0064] Figure 7 Figure is a structure block diagram of a protection method device of a vehicle networking service platform according to an embodiment of the present application;
[0065] Figure 8 Figure is a hardware structure diagram of a computer device according to an embodiment of the present application. DETAILED DESCRIPTION
[0066] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the following will combine the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the protection scope of the present application.
[0067] According to an embodiment of the present application, a vehicle networking service platform protection method, device, equipment and storage medium are provided. It should be noted that the steps shown in the flowchart of the drawings can be executed in a computer system such as a group of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from here.
[0068] In the present embodiment, a vehicle networking service platform protection method is provided, which is applied to a vehicle networking service platform, Figure 1 is a flowchart of a vehicle networking service platform protection method according to an embodiment of the present application, as shown in the flowchart, the flow includes the following steps: Figure 1
[0069] Step S11, obtaining the processing result of each security protection layer in the vehicle networking service platform in a preset historical period.
[0070] In the present embodiment, the results of the data processing of each security protection layer of the vehicle networking service platform in the past period are collected. These processing results reflect the processing situation of each security protection layer to the external network data flow in the historical period, including whether abnormal flow is detected, which protection measures are taken and the final processing effect and other information. By obtaining these processing results, data basis can be provided for subsequent evaluation of the risk level of each security protection layer.
[0071] Step S12, calculating the risk measurement index corresponding to the processing result according to the preset evaluation standard, and determining the risk level of the security protection layer associated with each processing result based on the risk measurement index.
[0072] In the present embodiment, step S12 includes the following steps A1-A3:
[0073] Step A1, traversing the risk events in the processing result in the preset historical period to obtain the number of events.
[0074] Specifically, the processing result of each security protection layer obtained is checked in detail to identify the risk events therein. For example, in the processing result of the Internet boundary protection layer, the risk events can include the number of detected denial of service attacks, the number of abnormal IP access times, etc.; in the network protection layer, the risk events can include the number of virus detection, the number of intrusion events, etc. The number of risk events in the processing result of each security protection layer is counted to provide an important parameter for subsequent determination of the risk level.
[0075] Step A2, identifying the risk type of each risk event, and determining the risk value corresponding to the risk event according to the risk type.
[0076] Specifically, different risk events belong to different risk types, for example, a denial of service attack belongs to a high risk type, and some minor abnormal access belongs to a low risk type. According to pre-set rules, different risk types are assigned corresponding risk values. Events of a high risk type are assigned higher risk values, and events of a low risk type are assigned lower risk values.
[0077] Step A3, based on the number of events in the processing result and the risk values corresponding to each risk event, the risk level of the security protection layer associated with each processing result is calculated.
[0078] Specifically, the number of risk events in the processing result and the risk value of each risk event are comprehensively analyzed and processed to calculate the risk level of each security protection layer. For example, the risk level can be determined by weighted summation of the number of risk events and the risk value. The risk level can be divided into multiple levels, such as first level: high risk, second level: medium risk, third level: low risk, etc., to intuitively reflect the security risk degree faced by each security protection layer.
[0079] Step S13, according to the risk level, the hierarchical order of the security protection layer in the Internet of Vehicles service platform is scheduled, and a dynamic security protection layer with hierarchical relationship is obtained.
[0080] In the embodiments of the present application, according to the risk level, the hierarchical order of the security protection layer in the Internet of Vehicles service platform is scheduled, and a dynamic security protection layer with hierarchical relationship is obtained. This step is to adjust the hierarchical order of the security protection layer according to the determined risk level. If the risk level of a certain security protection layer is high, it needs to be adjusted to a more forward level, so as to play a role earlier in processing external network data flow and strengthen the protection of high-risk areas. By dynamically adjusting the hierarchical order, the security protection system of the Internet of Vehicles service platform can more flexibly cope with different security risk situations, optimize the allocation of security protection resources, and improve the overall security protection efficiency.
[0081] It should be noted that, as shown in Figure 2 The scheduling structure of the security protection layer of the Internet of Vehicles information service platform includes a monitoring and alarm platform 6, an intelligent analysis unit 7, and an intelligent scheduling unit 8. The monitoring and alarm platform 6 includes a log collection unit 61 and an alarm unit (14, 24, 33, 49, 53). The intelligent analysis unit 7 stores a risk level table 71, which covers period (which can be selected from min, hour, day, and month), risk type (including DDoS, virus, API, vulnerability, file, etc.), risk measurement index (risk number, period, risk value, and weight), and risk level (divided into four levels: 1, 2, 3, and 4). The intelligent scheduling unit 8 includes a configuration management module 81 and a policy management module 82.
[0082] Step S14, using the dynamic security protection layer with hierarchical relationship to perform corresponding protection operation on the vehicle networking service platform.
[0083] In the embodiment of the present application, the dynamic security protection layer with hierarchical relationship is used to perform corresponding protection operation on the vehicle networking service platform. This step is to apply the adjusted dynamic security protection layer to the actual vehicle networking service platform protection.
[0084] The method provided by the present application can comprehensively understand the working condition of the vehicle networking service platform by obtaining the processing results of each security protection layer in the preset historical period, provide accurate data for risk assessment and protection layer scheduling, and find potential security problem trends to take preventive measures. The risk measurement index of the calculation processing result and the determination of the protection layer risk level can quantify the risk degree, intuitively understand the security situation, allocate security resources accordingly, improve the protection efficiency, and timely find high-risk layers and take strict measures to reduce the possibility of accidents. According to the risk level, the protection layer hierarchical order is scheduled, which can make the security protection system flexibly adapt to different risks, increase the order to input more resources, improve the overall protection effect and optimize the allocation of resources. The dynamic security protection layer is used to perform protection operation, realize multi-level and three-dimensional protection, different layers are used for special protection against different security threats, and the data flow is processed in sequence to intercept potential threats and reduce the impact.
[0085] In the embodiment of the present application, step S14 includes steps S21-S24:
[0086] Step S21, receiving first data flow sent by an external network to the vehicle networking service platform.
[0087] In the embodiment of the present application, the vehicle networking service platform receives the first data flow sent by the external network, wherein the external network can include multiple sources, such as other vehicle networking devices, traffic management systems, various Internet of Things devices, etc. This data flow is the object of subsequent security protection processing. After receiving the data flow, it will enter the subsequent security protection processing flow, that is, it will be input into the dynamic security protection layer with hierarchical relationship in the vehicle networking service platform in sequence for processing.
[0088] Step S22, inputting the first data flow into the dynamic security protection layer with hierarchical relationship in the vehicle networking service platform in sequence, wherein at least one security protection strategy is configured in each dynamic security protection layer.
[0089] As an example, as shown in FIG. 2, the vehicle networking service platform includes three dynamic security protection layers, and each dynamic security protection layer is configured with at least one security protection strategy. Figure 3As shown, the protection structure of the dynamic security shield includes five levels, from high to low, the boundary protection layer 1, the network protection layer 2, the application protection layer 3, the system protection layer 4 and the data protection layer 5. For each dynamic security shield, a corresponding preset security protection strategy is selected, wherein each security protection strategy corresponds to different security defense technologies for implementing network security protection of the vehicle networking information platform. Specifically, the Internet boundary protection layer adopts DDoS protection, bastion host technology; the network protection layer adopts firewall technology; the application protection layer adopts web application firewall, API gateway technology; the system firewall adopts host security, container security technology; and the data protection layer adopts data transmission encryption and data storage encryption technology.
[0090] In step S23, the first data flow is processed based on the security protection strategy configured by the dynamic security shield to obtain a processing result.
[0091] As an example, as shown in the figure, Figure 4 As shown, the boundary protection layer 1 includes a denial-of-service attack protection unit 11, an asset protection unit 12, a permission management unit 13 and a first monitoring alarm unit 14; the network protection layer 2 includes an intrusion protection unit 21, a virus protection unit 22, an access control unit 23 and a second monitoring alarm unit 24; the application protection layer 3 includes a website protection unit 31, an API protection unit 32 and a third monitoring alarm unit 33; the system protection unit 4 includes an asset management unit 41, a container protection unit 42, a vulnerability management unit 43, a baseline check unit 44, an intrusion detection unit 45, a virus protection unit 46, a file protection unit 47, an authentication protection unit 48 and a fourth monitoring alarm unit 49; and the data protection unit 5 includes a transmission encryption unit 51, a storage encryption unit 52 and a fifth monitoring alarm unit 53.
[0092] In the embodiment of the present application, when the first data flow enters each dynamic security shield in turn, each layer processes the data flow according to the pre-configured strategy. For example, in the Internet boundary protection layer 1, the denial-of-service attack protection unit 11 prevents DDoS attacks, the asset protection unit 12 protects the platform IP, the permission management unit 13 manages user permissions, and the first monitoring alarm unit 14 collects and analyzes uploaded security logs, and then the data flow enters the network protection layer 2. In the network protection layer 2, the intrusion protection unit 21 performs intrusion detection protection, the virus protection unit 22 detects and disposes viruses, the access control unit 23 performs access control, and the second monitoring alarm unit 24 collects and analyzes uploaded security logs. The data flow then passes through the application protection layer 3, the system protection layer 4 and the data protection layer 5 in turn, and each layer processes according to the corresponding strategy to finally obtain a processing result. In this way, external network data flow can be comprehensively protected in multiple levels to prevent network attacks and improve the security of the vehicle networking service platform.
[0093] In the embodiments of the present application, if the dynamic security protection layer is a boundary protection layer, step S23 includes the following steps B1-B2:
[0094] Step B1, detecting whether there is first abnormal traffic of denial of service attack in the first data traffic based on the denial of service attack protection policy configured by the boundary protection layer.
[0095] Specifically, first, the denial of service attack protection unit 11 of the boundary protection layer can monitor the first data traffic by using a specific algorithm and mechanism. The algorithm can be based on traffic characteristics such as the distribution of the source IP address of the traffic. In normal circumstances, the traffic source IP of the Internet of Vehicles platform is scattered, and a large number of traffic requests from the same or a small number of IP in a short time is a sign of DDos attack (such as SYNFlood attack, in which the attacker sends a large number of fake TCP connection requests to exhaust server resources). Second, the traffic rate is monitored. The normal network traffic rate fluctuates within a reasonable range. If it suddenly and sharply rises far beyond the normal business demand, there is a risk of denial of service attack, for example, UDPFlood attack, in which the attacker sends a large number of UDP data packets to occupy the network bandwidth, so that the service cannot normally respond to normal requests. In addition, the data packet content is analyzed. The data packets of some denial of service attacks have specific patterns or abnormal structures, such as containing malicious instructions or abnormal protocol headers. The denial of service attack protection unit 11 finds these abnormal content patterns by deeply analyzing the data packets. Finally, the source IP address distribution, traffic rate, data packet content and other factors of the first data traffic are comprehensively judged to determine whether there is abnormal traffic of denial of service attack. If there is, the related protection measures of the boundary protection layer are triggered to protect the safety of the Internet of Vehicles service platform.
[0096] Step B2, if there is first abnormal traffic, the first abnormal traffic in the first data traffic is intercepted, and the platform address and platform resource library are accessed by the asset protection policy configured by the boundary protection layer, and a first processing result is obtained.
[0097] Specifically, first, after the denial of service attack protection unit 11 detects the first abnormal traffic, it is intercepted according to the detection characteristic information. If the abnormal traffic is identified according to the IP address distribution (such as a large amount of traffic from a malicious IP), a rule is set at the network entrance to prevent it from entering the platform; if the abnormal traffic is found by analyzing the data packet content (such as containing malicious instructions or abnormal protocol headers), it is determined and intercepted according to the TCP / IP protocol rules.
[0098] Second, the asset protection unit 12 in the boundary protection layer maintains a list of legal IP addresses. When the first data traffic enters, it checks whether the source IP is in the list. If not, it is refused to visit the platform address, and only the IP of the authorized device can access. In addition, for domain name access, the asset protection unit 12 monitors and restricts the domain name resolution process, only handles legal requests, and prevents tampering with the resolution result to guide the traffic to a malicious place.
[0099] Finally, the permission control unit 13 performs user permission verification on the first data traffic accessing the platform resource library (such as server, storage, database, and other resources), and only the traffic initiated by the user authenticated and authorized by the authentication and authorization mechanism and having the corresponding permission is allowed to access the specific resource, such as the ordinary user can only access part of the public resource information, and the administrator with high-level permission can access and operate more sensitive resources. The asset protection unit 12 can also set access rules according to the resource type and importance, such as the database resource has more stringent restrictions (limiting access frequency, time, etc.), and the traffic that does not meet the rules will be denied access to the platform resource library.
[0100] Through the above interception of the first abnormal traffic and the limitation of the first data traffic accessing the platform address and the platform resource library, a first processing result is obtained, which is used as a part of the processing result of the subsequent other dynamic security protection layer or the whole security protection, thereby guaranteeing the security of the vehicle networking service platform.
[0101] In the embodiment of the application, if the dynamic security protection layer is a network protection layer, step S23 includes the following steps C1-C3:
[0102] Step C1, obtaining the second data traffic transmitted to the network protection layer, wherein the second data traffic is obtained after the first data traffic is processed by the dynamic security protection layer at the upper level.
[0103] Specifically, in the vehicle networking security protection system, when the dynamic security protection layer is a network protection layer, the traffic processed by the upper layer is received. The second data traffic is obtained after the first data traffic (the traffic from the external network to the vehicle networking platform) is processed by the dynamic security protection layer at the first level. The traffic processed by the dynamic security protection layer at the upper level is transmitted to the network protection layer for further detection and protection after being processed by multiple units.
[0104] Step C2, detecting whether there is a virus feature in the second data traffic based on the virus protection strategy configured by the network protection layer.
[0105] Specifically, first, the virus protection unit 22 of the network protection layer detects with the virus feature library containing the known virus feature information such as specific code segment, file structure mode, and data byte sequence. When the second data traffic enters, the unit scans the packet content. For file type data, the virus protection unit 22 checks the header, metadata, and key content part to see if it matches the file virus feature, such as checking whether the specific offset position of the executable file contains the known malicious pattern. For the network stream data part, the network protocol is parsed, and it is checked whether the data payload part contains the network virus related feature, such as checking whether the specific field of the network packet contains malicious content.
[0106] Second, the virus protection unit 22 uses a heuristic detection algorithm based on common virus behavior patterns. For example, when certain viruses infect or spread, they frequently connect to malicious servers or abnormally read and write system files. If the second data flow contains data that matches these malicious behavior patterns, even if it does not completely match the specific features in the virus signature library, it will be considered to contain virus signatures. Virus signatures in the second data flow are detected through virus signature library matching checks and heuristic detection algorithms.
[0107] Step C3: If virus features exist, intercept the second abnormal traffic with virus features in the second data traffic, and limit the communication source of the second abnormal traffic based on the access control policy configured by the network protection layer to generate a second processing result.
[0108] Specifically, first, after detecting the presence of virus signatures in the second data traffic and determining the second abnormal traffic, the virus protection unit 22 marks the data packets with the virus signatures (based on the virus type or a general "danger" flag). Then, the intrusion prevention unit 21 of the network protection layer sets checkpoints at network traffic inlets or key nodes based on the signatures. If a marked data packet is found, it blocks its transmission, thereby intercepting the second abnormal traffic.
[0109] In addition to tagging and interception, when complex or new virus signatures are difficult to accurately identify with simple tags, the Intrusion Prevention Unit 21 performs deep packet inspection to identify suspected secondary abnormal traffic. This unit analyzes the packet content, including its structure, flow direction, and connections with other packets. For example, some viruses distribute malicious code across multiple packets and execute them in unique combinations. The Intrusion Prevention Unit 21 identifies these combined patterns and intercepts the relevant packets, preventing them from spreading across the IoV platform network.
[0110] Next, the access control unit 23 checks the source IP address of the second abnormal traffic within the access control policy. If an IP address is identified as the source and is not in the trusted IP list, further communication requests from that IP address are denied. For example, if a certain IP address (XXXX) is the source of the second abnormal traffic, the firewall rules block all packets from that IP address from entering the IoV platform.
[0111] In addition, the access control unit 23 also checks the network protocol and port number of the second abnormal traffic. If a specific malicious protocol or banned port (such as port 21 used for malicious attacks, i.e., FTP port, which is often used for malicious attacks) is used for communication, the access control rule prohibits communication of the relevant protocol and port, thereby restricting the communication path.
[0112] By intercepting the second abnormal traffic and limiting its communication source, a second processing result is generated. This result will be used for subsequent dynamic security protection layer processing or as part of the overall security protection processing result, thereby ensuring the security of the Internet of Vehicles information service platform.
[0113] In the embodiments of the present application, if the dynamic security protection layer is an application protection layer, step S23 includes the following steps D1-D3.
[0114] Step D1, obtaining third data traffic transmitted to the application protection layer, wherein the third data traffic is obtained after the second data traffic is processed by the dynamic security protection layer at the previous level.
[0115] Specifically, in the vehicle networking security protection system, when the dynamic security protection layer is an application protection layer, the processed traffic at the previous level will be received. The third data traffic is obtained after the second data traffic (processed traffic after the first level protection layer is processed through the second level protection layer) is processed at the previous level. After the second data traffic is processed by various units at the previous level, the processed traffic is transmitted to the application protection layer for further detection and protection.
[0116] Step D2, detecting whether the third abnormal traffic of application interface call exists in the third data traffic based on the API protection strategy configured by the application protection layer.
[0117] Specifically, first, the API protection unit 32 in the application protection layer first establishes a legal API call specification model, which includes API name, parameter type, number, call frequency, sequence, etc. When the third data traffic enters, the API protection unit 32 parses the API call part and checks whether it conforms to the model parameter characteristics. If the API name is not in the legal list, the parameter type does not match or the number is not correct (such as two integer parameters, but actually one string and one integer parameter or only one parameter), it is determined as the third abnormal traffic. Second, the API call frequency is detected. If the API is called at an abnormal frequency in a short time, even if the name and parameters are correct, it is confirmed as malicious attack (such as brute force cracking or abnormal data acquisition), which is determined as the existence of the third abnormal traffic of application interface call. For example, if a normal vehicle location query API is called several times in a few minutes, but is called several tens of times in one second, it is abnormal. Through the comparison and analysis of the name, parameter type, number and call frequency of API call and the legal API call specification model from multiple aspects, whether the third abnormal traffic of application interface call exists in the third data traffic is detected.
[0118] Step D3, if the third abnormal traffic exists, the third abnormal traffic is parsed to obtain identity information, and a verification operation is performed on the identity information based on the website protection strategy configured by the application protection layer to generate a third processing result.
[0119] Specifically, after determining the third abnormal traffic, first, the API protection unit 32 parses the third abnormal traffic according to a protocol (such as HTTP, a custom protocol, etc.). The HTTP protocol parses the request header to find identity information (such as the "Authorization" field), and the custom protocol finds the relevant part according to the format. Then, identity key information (such as the request header identity identifier, the account ID in the request body, the device number, etc.) is extracted from the parsed data, and whether the information format conforms to the platform regulations is analyzed. In addition, related information is mined, including analyzing the correlation between the traffic source IP address and the user / device, considering time and operation sequence related information (such as different IP addresses in a short period of time and identity identifiers that change frequently but similar operations), to obtain more accurate identity information. Through the above protocol parsing, data extraction and analysis, and related information mining operations, more accurate identity information is obtained.
[0120] Secondly, the website protection unit 31 verifies the identity information according to the identity verification rules of the network protection layer website protection strategy. First, it is checked whether it is in the legal identity list (the vehicle network platform has a database of related identifiers), and if not, it is preliminarily not passed; the permission part is matched according to the rules, and the API calling identity performs operations beyond the permission range, and is also not passed. In addition to static verification, there is dynamic verification, including sending a verification code to the related device, and if the correct verification code is not received within a specified time, it fails; when the device behavior is abnormal (such as a suspicious API call during the sleep period), more stringent verification (requiring more proof or inspection) is required. The website protection unit 31 verifies the identity information in association with other security information, associates it with the network protection layer IP access history, and the identity corresponds to the IP for a short period of time. A large number of abnormal accesses are not passed; and is associated with the system protection layer device security state and vulnerability, and the device has a vulnerability that affects the result, and needs to be repaired or measures are taken to allow it to pass.
[0121] Through the above verification operations, the third processing result is generated, which will be used as part of the overall security protection processing result or as subsequent other dynamic security protection layer processing, so as to protect the security of the vehicle network information service platform.
[0122] In the embodiments of the present application, if the dynamic security protection layer is the system protection layer, step S23 includes the following steps E1-E3:
[0123] Step E1, obtaining the fourth data traffic transmitted to the system protection layer, wherein the fourth data traffic is obtained after the third data traffic is processed by the dynamic security protection layer at the previous level.
[0124] Specifically, in the vehicle network security protection system, when the dynamic security protection layer is a system protection layer, it receives the traffic processed by the previous level. The fourth data traffic is obtained after the third data traffic is processed by the previous level (from the first level protection layer, in turn through the second level protection layer, the third level protection layer). After the third data traffic is processed by the multiple units of the previous level, the processed traffic is transmitted to the system protection layer for further detection and protection.
[0125] Step E2: Analyze the fourth data traffic based on the asset management strategy configured by the system protection layer to determine whether there is an intrusion behavior in the service running environment.
[0126] Specifically, the asset management unit 41 organizes the fourth data traffic information and establishes an association mapping with the service running environment assets (servers, containers, etc.) (identifies IP addresses, container identifiers, and corresponds to registered assets). The vulnerability management unit 43 detects the fourth data traffic based on the vulnerability knowledge base, checks whether the application interaction or system call information matches the vulnerability characteristics, and contains application calls with specific version vulnerabilities (such as SQL injection vulnerabilities) that have intrusion risks. The intrusion detection unit 45 monitors the behavior pattern (source, destination, flow frequency, operation type, etc.) of the fourth data traffic. Normally, the data traffic has a regular pattern (stable communication frequency of specific services, predictable operation types such as query and update operations). If there is an abnormal pattern (a large number of suspicious write operations from an unknown source to a critical server), there is an intrusion behavior. The baseline checking unit 44 compares the system configuration information of the fourth data traffic with the security baseline (such as port opening and user permission setting). If it does not match (a port that should not be opened has interaction or a low-privilege user performs a high-privilege operation), it indicates that there is an intrusion behavior.
[0127] Through the above detection and analysis of the asset management unit, the vulnerability management unit, the intrusion detection unit, and the baseline checking unit, it is comprehensively judged whether there is an intrusion behavior in the service running environment.
[0128] Step E3: If there is an intrusion behavior, intercept the fourth abnormal traffic in the fourth data traffic that has an intrusion behavior, and check the configuration information and file isolation of the service running environment based on the cooperative protection strategy configured by the system protection layer, and generate a fourth processing result.
[0129] Specifically, first, after determining that the service running environment has an intrusion behavior, the intrusion detection unit 45 marks the fourth abnormal traffic according to the intrusion type (for example, a malicious software intrusion is marked as "malware related abnormal traffic"). The container protection unit 42 sets checkpoints at the container cluster network traffic entrance and the interaction key node, and the file protection unit 47 sets checkpoints at the server file system key access path, and the two are marked to identify the fourth abnormal traffic. After identifying the fourth abnormal traffic, the container protection unit 42 intercepts illegal traffic in and out of the container cluster (for example, cutting off the transmission channel when the malicious program abnormally transmits data from the intruded container to the outside), and the file protection unit 47 prevents illegal access operations (such as malicious reading, modifying, and deleting requests) of the fourth abnormal traffic to important files (system configuration, user data files, etc.) of the server, and intercepts the fourth abnormal traffic to prevent damage to the files in the service running environment.
[0130] Secondly, the container protection unit 42 checks the file isolation situation in the container. The container is used to isolate applications or services in the Internet of Vehicles environment, and the files in the container should be well isolated to prevent illegal interaction. It checks whether the file sharing settings between containers are in compliance and whether there is an abnormal sharing channel (for example, if two containers that should be isolated have a file access channel, there is a hidden danger). The file protection unit 47 checks the server file isolation situation, especially the files used by different users or services, checks whether the system and user files are correctly isolated to prevent malicious programs from accessing key files through vulnerabilities, and also checks the file access permission settings. If the permission is illegally expanded (for example, a normal user has a system file write permission), it indicates that the file isolation has a problem and there is a security risk.
[0131] Through the above operations of intercepting the fourth abnormal traffic and checking the configuration information and file isolation situation of the service running environment, the fourth processing result is generated. This result will be used as the processing result of the subsequent other dynamic security protection layer or as part of the overall security protection processing result, so as to protect the security of the Internet of Vehicles information service platform.
[0132] In the embodiment of the present application, if the dynamic security protection layer is a data protection layer, step S23 includes F1-F4:
[0133] Step F1, acquire the fifth data traffic transmitted to the data protection layer, wherein the fifth data traffic is obtained by processing the fourth data traffic by the last level dynamic security protection layer.
[0134] Specifically, in the vehicle network security protection system, when the dynamic security protection layer is a data protection layer, the traffic processed by the previous layer will be received. The fifth data traffic is obtained after the fourth data traffic is processed by the previous layer (the traffic processed by the first layer protection layer, in turn, through the second layer protection layer, the third layer protection layer, and the fourth layer protection layer). After the fourth data traffic is processed by the previous layer through multiple units, the processed traffic is transmitted to the data protection layer for further detection and protection.
[0135] Step F2, detecting the fifth data traffic flowing into the data protection layer based on the transmission encryption strategy configured by the data protection layer.
[0136] Specifically, first, the transmission encryption unit 51 checks the source identifier of the fifth data traffic (including the sender address, network area, device type, etc.), and different sources correspond to different security and encryption needs (strict detection for external untrusted devices, relatively loose for internal specific devices). Then, analyze the data format and protocol type (such as JSON, XML format, HTTP, MQTT protocol), different encryption detection methods should be used (HTTP checks specific fields in the request header, JSON checks data structure key information). Next, verify the encryption mark or metadata, check its legality according to the transmission encryption strategy requirements, and missing or incorrect format indicates that the transmission is problematic or risky. In addition, according to the sampling rule, part of the fifth data traffic is sampled and decrypted for detection (in a safe environment), and whether the decrypted data meets the expected format and content requirements (such as whether the vehicle state information has reasonable and complete values) is checked. If abnormal, the entire traffic has security problems that need to be processed or intercepted.
[0137] Through the above detection of the source identifier, data format and protocol type, encryption mark or encryption metadata, and partial data sampling and decryption of the fifth data traffic, the detection of the fifth data traffic flowing into the data protection layer based on the transmission encryption strategy configured by the data protection layer is realized.
[0138] Step F3, determining whether there is a data transmission requirement based on the fifth data traffic.
[0139] Specifically, first, the data protection layer related unit (transmission encryption unit 51 or storage encryption unit 52) parses the fifth data traffic header information, which identifies or instructs the data transmission requirement, such as the data transmission destination (local server storage or forwarding, etc.) indicated by the specific field of the header. If there is an identifier indicating that the data is sent from a remote terminal to a local server for storage, it can be preliminarily determined that there is such a transmission requirement direction.
[0140] Then, the data content characteristics of the fifth data traffic are analyzed. Different data contents are related to specific transmission requirements. For example, if the data is real-time vehicle status information and the format conforms to the local database storage specification, it can be inferred that there is a transmission requirement to the local database; if it contains local server specific service call request information, there is a transmission requirement to the local server.
[0141] Then, the matching of the fifth data traffic with the predefined business logic rules is checked. The Internet of Vehicles platform has business logic rules that specify different data transmission conditions and target locations. For example, vehicle diagnostic data that meets certain conditions (faults or regular maintenance) needs to be transmitted to the local server. If the data in the fifth data traffic meets the requirements, it is determined that there is a transmission requirement to the local server.
[0142] In addition, the source and destination information of the fifth data traffic is considered. If the source is a remote terminal (such as a vehicle terminal) and the destination is a local server or database (identified by IP address, etc.), it is an important basis for determining the transmission requirement; if the source is a remote server and the destination is a local server or database and the data content meets the local receiving and processing requirements, it can also be determined that there is a transmission requirement.
[0143] Through the above analysis of the packet header information, data content characteristics, matching with business logic rules, and source and destination information of the fifth data traffic, it is determined whether there is a data transmission requirement.
[0144] Step F4, if there is a data transmission requirement, a plurality of keys are generated based on the storage encryption policy configured by the data protection layer, and encryption operations are performed on the transmission data of the local server and the local database based on the keys and the transmission requirements, to generate a fifth processing result.
[0145] As an example, as shown in Figure 5 The key generator generates a plurality of keys, such as key-0, key-1, key-2, key-3, and key-n. Then, the keys are transmitted to the key manager. The key manager sends key-0 to the server and key-1 to the remote terminal. When data transmission is performed between the server and the remote terminal, the data is encrypted using the SSH algorithm, and the matching between key-0 and key-1 is used for verification operations. In addition, when data transmission is performed between servers, the AEAD algorithm is used for encryption. In addition, the key manager also sends key-2 to the data encryptor, and when the data encryptor obtains the data file, it uses key-2 to write the data file to storage disk 1, storage disk 2, and storage disk n. The key manager sends key-3 to the database, so that when data encryption transmission is performed between the databases, the AEAD algorithm and key-3 can be used.
[0146] In the embodiments of the present application, the transmission data of the local server and the local database is subjected to an encryption operation based on a key and transmission requirements, including the following steps F41-F45:
[0147] Step F41, obtaining the transmission requirements corresponding to the transmission data.
[0148] Specifically, the related unit of the data protection layer checks the transmission data packet header or specific field identifier (such as the vehicle-to-vehicle state data packet header identifier), analyzes the content structure (vehicle state data organized according to the local database storage structure is stored, data containing local server service call request structure is transmitted to the local server), checks the matching condition with the predefined template (if matched, the transmission requirement is determined, such as the vehicle fault diagnosis data matching the template to determine the transmission direction), considers the source and destination metadata (such as the source being a vehicle sensor and the destination being the local database to infer the storage requirement), and obtains the transmission requirement through multi-aspect analysis.
[0149] Step F42, if the transmission requirement is from the remote terminal to the local server, the second key in the transmission data is verified according to the first key stored in the local server, and after verification, the transmission data is encrypted using the first encryption strategy to obtain the first encrypted data.
[0150] Specifically, the local server stores a pre-configured first key. After receiving the transmission data from the remote terminal, the second key is extracted according to its specific format. The data protection layer encryption verification module compares and verifies the two, which can be compared by hash value (if the hash values are the same, it is preliminarily matched) or public key-private key pair verification mechanism (verified by the private key corresponding to the public key of the local server). After verification, the first encryption strategy (based on symmetric encryption algorithms such as AES algorithm, or asymmetric encryption algorithms such as RSA algorithm, and including encryption modes such as CBC mode, padding mode and other parameters) is used to encrypt the transmission data according to the pre-set first encryption strategy for the transmission scenario.
[0151] The specific encryption process includes: the encryption unit (such as the transmission encryption unit 51 in the data protection layer) performs bit-by-bit or block-by-block encryption operation on the effective data part (excluding the header or marker part that has been used for key verification and the like) in the transmission data according to the first encryption strategy. For example, if the CBC mode of the AES algorithm is used, the transmission data is divided into blocks according to the specified block size, and then each block of data is encrypted according to the initial vector (IV) and the first key, and finally the first encrypted data after encryption is obtained.
[0152] Step F43, if the transmission requirement is from the remote server to the local server, the transmission data is encrypted using the second encryption strategy to obtain the second encrypted data.
[0153] Specifically, the second encryption strategy is customized for the transmission from the remote server to the local server, including a specific algorithm (such as the AES-GCM algorithm) and related parameters (determined by the vehicle networking platform multi-factor). The effective data is obtained according to the transmission data format (the message header, tail, and check part are removed when the specific message packaging format is used). Taking the AES-GCM algorithm as an example, the IV is generated in a predetermined manner (randomly or based on system parameters), and the effective data is encrypted block by block using the pre-stored key and IV (each block is operated with the previous block result and IV) to ensure security and integrity. The encryption result is packaged and labeled as the second encrypted data containing the effective data, algorithm identification, and IV (used for decryption at the receiving end), and subsequent operations are performed according to the platform process.
[0154] Step F44, if the transmission requirement is from the remote database to the local database, the third key stored in the local database is used to encrypt the transmission data to obtain the third encrypted data.
[0155] Specifically, the local database stores the third key in a secure manner (such as encrypted storage or based on HSM). The data main part (excluding the data header and check part) is determined and extracted according to the transmission data format protocol. The main part is encrypted using the third key according to the encryption algorithm suitable for the database (such as AES and related modes, for example, the IV needs to be generated according to the rules in the CBC mode of AES, and each block of data is operated with the previous block result and IV during encryption). The encryption result is recombined or packaged into the third encrypted data containing the main encryption result, algorithm identification, and IV, etc. auxiliary information, so as to perform subsequent operations according to the platform process.
[0156] Step F45, if the transmission requirement is data file to local disk, the fourth key stored in the key generator is used to encrypt the transmission data to obtain the fourth encrypted data.
[0157] Specifically, first, the pre-stored fourth key is obtained from the key generator, wherein the key generator is used to generate multiple keys, and the fourth key has been generated and securely stored. The encryption part is determined according to the format structure of the transmission data (the data file contains the file header, main body, and file tail, and usually the main body part is encrypted). The main body part of the file is encrypted using the fourth key and a symmetric encryption algorithm (taking the AES algorithm as an example): if the AES-CBC mode is used, the initial vector is randomly determined, the main body of the file is divided into blocks of 128 bits, and each block is operated with the previous block result and the initial vector (such as XOR operation). The encrypted main body and the original file header and file tail are recombined or packaged into the fourth encrypted data containing the encrypted main body, the original file header and file tail, the encryption algorithm identification (such as AES-CBC), and the initial vector (for decryption at the receiving end) and other auxiliary information, so as to be transmitted to the local disk or stored in a specific location.
[0158] Step S24, generating a security log according to the processing result, and uploading the security log to the monitoring and alarming platform.
[0159] In the embodiments of the present application, as shown in Figure 6 The monitoring and alarming architecture of the vehicle networking information service platform mainly consists of a monitoring and alarming platform and five monitoring and alarming units, each of which is located in a dynamic security protection layer and connected to the unified monitoring and alarming platform. The first monitoring and alarming unit is located in the boundary protection layer, the second monitoring and alarming unit is located in the network protection layer, the third monitoring and alarming unit is located in the application protection layer, the fourth monitoring and alarming unit is located in the system protection layer, and the fifth monitoring and alarming unit is located in the data protection layer.
[0160] Specifically, in the security protection system of the vehicle networking information service platform, each layer generates corresponding security processing results after performing security operations. For example, the denial of service attack protection unit 11 in the boundary protection layer 1 records the defense situation, attack source and scale of DDos attack; the asset protection unit 12 records the IP threat state and protection effect; and the permission control unit 13 records the user permission operation. These information is summarized into a security log, which details the execution of each protection unit.
[0161] Subsequently, the monitoring and alarming units of each dynamic security protection layer are responsible for uploading these security logs to the monitoring and alarming platform. Specifically, the monitoring and alarming unit 14 of the boundary protection layer 1 collects and uploads the logs of each unit; similarly, the monitoring and alarming unit 24 of the network protection layer 2, the monitoring and alarming unit 33 of the application protection layer 3, the monitoring and alarming unit 49 of the system protection layer 4, and the monitoring and alarming unit 53 of the data protection layer 5 all perform the same operation. In this way, the monitoring and alarming platform can centrally obtain the security logs of each layer, and comprehensively analyze, monitor and alarm the overall security of the vehicle networking information service platform.
[0162] The method provided by the embodiments of the present application realizes comprehensive and multi-level security protection of the vehicle networking information service platform through the multi-layer network security protection method and the monitoring and alarming architecture, solves the problems of single protection level, fixed protection layer structure, imperfect security protection strategy, insufficient monitoring and alarming capability, and lack of pertinence in the prior art. By sequentially inputting the received external network data flow into the security protection layers with hierarchical relationship and calling the security protection strategies configured in each layer for processing, multi-level and three-dimensional security protection of the vehicle networking information service platform is realized, and the network security protection capability of the platform is effectively improved. By generating a security log and uploading the log to the monitoring and alarming platform, timely discovery and response to network security events are realized, the monitoring and alarming capability of the platform is improved, which helps to take timely measures to reduce losses.
[0163] The embodiments further provide a protection method and device of a vehicle networking service platform. The device is used to implement the above-described embodiments and preferred embodiments, and will not be described again. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, implementation in hardware or a combination of software and hardware is also possible and contemplated.
[0164] The embodiments provide a protection method and device of a vehicle networking service platform, which is applied to a vehicle networking service platform, as shown in the following figure, and includes: Figure 7
[0165] The obtaining module 701 is configured to obtain processing results output by each security protection layer in the vehicle networking service platform in a preset historical period.
[0166] The computing module 702 is configured to calculate a risk measurement index corresponding to the processing results according to a preset evaluation standard, and determine a risk level of the security protection layer associated with each processing result based on the risk measurement index.
[0167] The scheduling module 703 is configured to schedule a hierarchical order of the security protection layers in the vehicle networking service platform according to the risk levels, to obtain dynamic security protection layers having a hierarchical relationship.
[0168] The execution module 704 is configured to perform corresponding protection operations on the vehicle networking service platform by using the dynamic security protection layers having the hierarchical relationship.
[0169] In an optional embodiment of the present application, the computing module 702 is configured to traverse risk events in the processing results in the preset historical period to obtain an event quantity, identify risk types of the risk events, and determine risk values corresponding to the risk events according to the risk types; and calculate the risk level of the security protection layer associated with each processing result based on the event quantity in the processing results and the risk values corresponding to the risk events.
[0170] In an optional embodiment of the present application, the execution module 704 includes a receiving submodule, an input submodule, a processing submodule, and a generating submodule, and specifically:
[0171] The receiving submodule is configured to receive first data traffic sent to the vehicle networking service platform by an external network.
[0172] The input submodule is configured to input the first data traffic into the dynamic security protection layers having a hierarchical relationship in the vehicle networking service platform in sequence, wherein at least one security protection strategy is configured in each dynamic security protection layer.
[0173] The processing submodule is configured to process the first data flow based on the security protection strategy configured by the dynamic security protection layer to obtain a processing result.
[0174] The generating submodule is configured to generate a security log according to the processing result and upload the security log to a monitoring and alarming platform.
[0175] In an optional embodiment of the present application, the processing submodule is configured to, if the dynamic security protection layer is a boundary protection layer, detect whether there is first abnormal flow of a denial-of-service attack in the first data flow based on a denial-of-service attack protection strategy configured by the boundary protection layer; if there is the first abnormal flow, intercept the first abnormal flow in the first data flow, and limit access of the first data flow to a platform address and a platform resource library based on an asset protection strategy configured by the boundary protection layer to obtain a first processing result.
[0176] In an optional embodiment of the present application, the processing submodule is configured to, if the dynamic security protection layer is a network protection layer, obtain second data flow transmitted to the network protection layer, wherein the second data flow is obtained by processing the first data flow by a dynamic security protection layer at a previous level; detect whether there is a virus feature in the second data flow based on a virus protection strategy configured by the network protection layer; if there is the virus feature, intercept second abnormal flow with the virus feature in the second data flow, and limit a communication source of the second abnormal flow based on an access control strategy configured by the network protection layer to generate a second processing result.
[0177] In an optional embodiment of the present application, the processing submodule is configured to, if the dynamic security protection layer is an application protection layer, obtain third data flow transmitted to the application protection layer, wherein the third data flow is obtained by processing the second data flow by a dynamic security protection layer at a previous level; detect whether there is third abnormal flow of application interface calling in the third data flow based on an API protection strategy configured by the application protection layer; if there is the third abnormal flow, parse the third abnormal flow to obtain identity information, and perform a verification operation on the identity information based on a website protection strategy configured by the application protection layer to generate a third processing result.
[0178] In an optional embodiment of the present application, the processing submodule is configured to, if the dynamic security protection layer is a system protection layer, obtain fourth data flow transmitted to the system protection layer, wherein the fourth data flow is obtained by processing the third data flow by a dynamic security protection layer at a previous level; analyze the fourth data flow based on an asset management strategy configured by the system protection layer to determine whether there is intrusion behavior in a service running environment; if there is the intrusion behavior, intercept fourth abnormal flow with the intrusion behavior in the fourth data flow, and check configuration information of the service running environment and file isolation based on a cooperative protection strategy configured by the system protection layer to generate a fourth processing result.
[0179] In an optional embodiment of the present application, the processing submodule is configured to acquire fifth data traffic transmitted to the data protection layer, wherein the fifth data traffic is obtained by processing the fourth data traffic by the dynamic security protection layer at the upper level; detect the fifth data traffic flowing into the data protection layer based on the transmission encryption strategy configured by the data protection layer; determine whether there is a data transmission requirement based on the fifth data traffic; and if there is a data transmission requirement, generate a plurality of keys based on the storage encryption strategy configured by the data protection layer, and perform an encryption operation on the transmission data of the local server and the local database based on the keys and the transmission requirement to generate a fifth processing result.
[0180] In an optional embodiment of the present application, the processing submodule is configured to acquire a transmission requirement corresponding to the transmission data; if the transmission requirement is from a remote terminal to a local server, verify a second key in the transmission data based on a first key stored in the local server, and after verification, encrypt the transmission data based on a first encryption strategy to obtain first encrypted data; if the transmission requirement is from a remote server to a local server, encrypt the transmission data based on a second encryption strategy to obtain second encrypted data; if the transmission requirement is from a remote database to a local database, encrypt the transmission data based on a third key stored in the local database to obtain third encrypted data; and if the transmission requirement is from a data file to a local disk, encrypt the transmission data based on a fourth key stored by a key generator to obtain fourth encrypted data.
[0181] Please refer to Figure 8 , Figure 8 is a structural schematic diagram of a computer device provided by an optional embodiment of the present application, as shown in Figure 8 the computer device includes one or more processors 10, a memory 20, and an interface for connecting various components, including a high-speed interface and a low-speed interface. Various components are communicatively connected to each other by using different buses, and can be installed on a common mainboard or in other ways as needed. The processor can process instructions executed in the computer device, including instructions stored in the memory or graphics information of the memory to display a GUI on an external input / output device, such as a display device coupled to the interface. In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple storage devices. Similarly, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system).
[0182] The processor 10 can be a central processing unit, a network processing unit, or a combination thereof. The processor 10 can further include a hardware chip. The hardware chip can be an application specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device can be a complex programmable logic device, a field programmable logic device, a generic array logic, or any combination thereof.
[0183] The memory 20 stores instructions executable by the at least one processor 10 for causing the at least one processor 10 to perform the methods illustrated in the above embodiments.
[0184] The memory 20 can include a program storage area and a data storage area. The program storage area can store an operating system and applications required by at least one function. The data storage area can store data created by the use of the computer device according to the presentation of a small program landing page, and the like. In addition, the memory 20 can include a high-speed random access memory, and can further include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some optional embodiments, the memory 20 can optionally include a memory disposed remotely relative to the processor 10, and these remote memories can be connected to the computer device through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0185] The memory 20 can include a volatile memory, such as a random access memory, and can also include a non-volatile memory, such as a flash memory, a hard disk, or a solid state disk. The memory 20 can further include a combination of the above-mentioned types of memories.
[0186] The computer device further includes a communication interface 30 for communication of the computer device with other devices or communication networks.
[0187] The embodiments of the present application further provide a computer readable storage medium, and the method according to the embodiments of the present application can be implemented in hardware, firmware, or recorded in a storage medium, or be implemented as computer codes stored in a remote storage medium or a non-transitory machine readable storage medium and downloaded through a network and stored in a local storage medium, so that the method described herein can be processed by such software on a storage medium using a general purpose computer, a special purpose processor, or programmable or special hardware. The storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid state disk, etc. Further, the storage medium can also include a combination of the above-mentioned types of memories. It can be understood that the computer, the processor, the microprocessor controller, or the programmable hardware includes a storage component that can store or receive software or computer codes, when the software or computer codes are accessed and executed by the computer, the processor, or the hardware, the method shown in the above embodiments is implemented.
[0188] Although the embodiments of the present application are described in conjunction with the accompanying drawings, various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present application, and such modifications and changes fall within the scope defined by the appended claims.
Claims
1. A protection method for an Internet of Vehicles service platform, applied to an Internet of Vehicles service platform, characterized in that: The method comprises: Obtaining processing results output by each security protection layer in the Internet of Vehicles service platform within a preset historical period; Calculating the risk measurement index corresponding to the processing result according to the preset evaluation standard, and determining the risk level of the security protection layer associated with each processing result based on the risk measurement index; Scheduling the hierarchical order of the security protection layers in the Internet of Vehicles service platform according to the risk level to obtain a dynamic security protection layer with a hierarchical relationship; Utilizing the hierarchical dynamic security protection layer to perform corresponding protection operations on the Internet of Vehicles service platform; The step of calculating the risk measurement index corresponding to the processing result according to a preset evaluation standard and determining the risk level of the security protection layer associated with each processing result based on the risk measurement index includes: traversing the risk events in the processing results within a preset historical period to obtain the number of events; identifying the risk type of each risk event and determining the risk value corresponding to the risk event based on the risk type; and calculating the risk level of the security protection layer associated with each processing result based on the number of events in the processing result and the risk value corresponding to each risk event. Among them, the use of the hierarchical security protection layer to perform corresponding protection operations on the Internet of Vehicles service platform includes: receiving a first data flow sent from an external network to the Internet of Vehicles service platform; inputting the first data flow into the hierarchical dynamic security protection layer in the Internet of Vehicles service platform in sequence, wherein each of the dynamic security protection layers is configured with at least one security protection strategy; processing the first data flow based on the configured security protection strategy called by the dynamic security protection layer to obtain a processing result; generating a security log according to the processing result, and uploading the security log to the monitoring and alarm platform.
2. The method according to claim 1, characterized in that If the dynamic security protection layer is a boundary protection layer, the processing of the first data traffic by calling the configured security protection policy based on the dynamic security protection layer to obtain a processing result includes: Detecting whether there is a first abnormal traffic of a denial of service attack in the first data traffic based on the denial of service attack protection strategy configured by the boundary protection layer; If the first abnormal traffic exists, the first abnormal traffic in the first data traffic is intercepted, and the asset protection policy configured by the boundary protection layer is used to restrict the first data traffic from accessing the platform address and the platform resource library to obtain a first processing result.
3. The method according to claim 1, characterized in that If the dynamic security protection layer is a network protection layer, the processing of the first data traffic by calling the configured security protection policy based on the dynamic security protection layer to obtain a processing result includes: Obtaining second data traffic transmitted to the network protection layer, wherein the second data traffic is obtained after the first data traffic is processed by the upper-level dynamic security protection layer; detecting whether the second data flow contains virus characteristics based on the virus protection strategy configured by the network protection layer; If the virus feature exists, the second abnormal traffic with the virus feature in the second data traffic is intercepted, and the communication source of the second abnormal traffic is restricted based on the access control policy configured by the network protection layer to generate a second processing result.
4. The method according to claim 1, wherein If the dynamic security protection layer is an application protection layer, the processing of the first data traffic by calling the configured security protection policy based on the dynamic security protection layer to obtain a processing result includes: Obtaining third data traffic transmitted to the application protection layer, wherein the third data traffic is obtained after the second data traffic is processed by the upper-level dynamic security protection layer; Detecting whether there is a third abnormal traffic of application interface call in the third data traffic based on the API protection strategy configured by the application protection layer; If the third abnormal traffic exists, the third abnormal traffic is parsed to obtain identity information, and a verification operation is performed on the identity information based on the website protection policy configured by the application protection layer to generate a third processing result.
5. The method according to claim 1, wherein If the dynamic security protection layer is a system protection layer, the processing of the first data traffic to obtain a processing result by calling the configured security protection policy based on the dynamic security protection layer includes: Acquire fourth data traffic transmitted to the system protection layer, wherein the fourth data traffic is obtained after the third data traffic is processed by the upper-level dynamic security protection layer; Analyzing the fourth data flow based on the asset management policy configured by the system protection layer to determine whether there is any intrusion in the service operation environment; If the intrusion behavior exists, the fourth abnormal traffic containing the intrusion behavior in the fourth data traffic is intercepted, and the configuration information of the service operating environment and the file isolation status are checked based on the collaborative protection strategy configured by the system protection layer to generate a fourth processing result.
6. The method according to claim 1, characterized in that If the dynamic security protection layer is a data protection layer, the processing of the first data traffic by calling the configured security protection policy based on the dynamic security protection layer to obtain a processing result includes: Acquire a fifth data flow transmitted to the data protection layer, wherein the fifth data flow is obtained after the fourth data flow is processed by the upper-level dynamic security protection layer; detecting fifth data traffic flowing into the data protection layer based on a transmission encryption policy configured by the data protection layer; determining whether there is a data transmission demand according to the fifth data flow; If the data transmission requirement exists, multiple keys are generated based on the storage encryption strategy configured by the data protection layer, and encryption operations are performed on the transmission data of the local server and the local database based on the keys and the transmission requirement to generate the fifth processing result.
7. The method according to claim 6, characterized in that The performing an encryption operation on the transmission data of the local server and the local database based on the key and the transmission requirement includes: Obtaining a transmission requirement corresponding to the transmission data; If the transmission requirement is from a remote terminal to a local server, verifying the second key in the transmission data according to the first key stored in the local server, and after the verification is passed, encrypting the transmission data using the first encryption strategy to obtain first encrypted data; If the transmission requirement is from a remote server to a local server, encrypting the transmission data using a second encryption strategy to obtain second encrypted data; If the transmission requirement is from a remote database to a local database, encrypting the transmission data using a third key stored in the local database to obtain third encrypted data; If the transmission requirement is to transmit a data file to a local disk, the transmission data is encrypted using the fourth key stored in the key generator to obtain fourth encrypted data.
8. A protective device for a vehicle networking service platform, applied to a vehicle networking service platform, characterized in that: The device comprises: An acquisition module, configured to obtain processing results output by each security protection layer in the Internet of Vehicles service platform within a preset historical period; a calculation module, configured to calculate a risk measurement index corresponding to the processing result according to a preset evaluation standard, and determine a risk level of the security protection layer associated with each processing result based on the risk measurement index; A scheduling module, configured to schedule the hierarchical order of the security protection layers in the Internet of Vehicles service platform according to the risk level, to obtain a dynamic security protection layer with a hierarchical relationship; An execution module, configured to execute corresponding protection operations on the Internet of Vehicles service platform using the hierarchical dynamic security protection layer; The calculation module is configured to traverse the risk events in the processing results within a preset historical period to obtain the number of events; identify the risk type of each risk event and determine the risk value corresponding to the risk event based on the risk type; and calculate the risk level of the security protection layer associated with each processing result based on the number of events in the processing results and the risk value corresponding to each risk event; The execution module includes: a receiving submodule, an input submodule, a processing submodule and a generating submodule. Specifically: The receiving submodule is configured to receive a first data flow sent from an external network to the Internet of Vehicles service platform; The input submodule is configured to sequentially input the first data traffic into the hierarchical dynamic security protection layers in the Internet of Vehicles service platform, wherein each of the dynamic security protection layers is configured with at least one security protection strategy; The processing submodule is configured to process the first data traffic based on the security protection policy configured by the dynamic security protection layer to obtain a processing result; The generating submodule is used to generate a security log according to the processing result and upload the security log to the monitoring alarm platform.
Citation Information
Patent Citations
Safety protection method and device for customer service management system
CN118611899A
Multi-level isolation and dynamic protection combined network protection method and system
CN118984247A