Intelligent terminal security protection method and system based on RASP
By loading RASP probes in V2G smart terminals and sending custom security protection rules, monitoring and responding to abnormal behaviors in real time, the problem of insufficient security protection capabilities of smart terminals in the interactive scenarios of the car network is solved, and more powerful deep security defense and bypass attack detection are achieved.
Patent Information
- Application Number
- CN202411856152.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-05-06
AI Technical Summary
In the current interactive scenario of car network, the security protection capabilities of smart terminals are relatively limited, and they cannot effectively detect mutated attack behaviors at the traffic level, and cannot locate vulnerability attack details. Moreover, security protection devices at the network level are easily bypassed.
Load RASP probes in V2G smart terminals, send custom security protection rules through V2GSMS system, RASP probes monitor network requests and application behavior in real time, identify abnormal traffic patterns and code execution or data access, take response measures and push alert notifications.
It improves the deep security defense capabilities of smart terminals, enhances the detection and defense capabilities of bypassing attacks at the network level, and improves the flexibility, accuracy and management efficiency when protecting vulnerable attacks.
Smart Images

Figure CN119946639A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a smart terminal security protection method and system based on RASP. Background Art
[0002] Currently, RASP-RuntimeApplication Self-Protection-Runtime Application Self-Protection is a new type of application security protection technology that directly embeds the protection engine into the application, can perceive the application context, monitor and block attacks in real time, and enable the program itself to have the ability to protect itself.
[0003] At present, the high interconnectivity and complexity of the Internet of Vehicles make the data exchange between vehicles and infrastructure very frequent, which hides many security risks. At present, the security protection of smart terminals in the vehicle-network interaction scenario basically adopts traditional security protection products, such as WAF application firewall, network traffic abnormal behavior threat perception, HIPS (Host Intrusion Prevent System, i.e. host intrusion prevention system) unified security management system, NIPS (Network Intrusion Prevent System, i.e. network intrusion prevention system), etc., without understanding the working principle of the application inside the smart terminal, and making assumptions about how the request affects the operation and security of the application through feature rules, and relying heavily on attack features to identify and block malicious behavior. However, in actual attack activities, network-level security protection devices are usually bypassed at the traffic level, such as adding additional coding to the request to bypass WAF protection so that its WAF configuration rules cannot be matched normally, thereby executing the payload in the smart terminal, causing security threats. Therefore, given the limited security protection capabilities of smart terminals in current vehicle-grid interaction scenarios, the inability to effectively detect variant attack behaviors at the traffic level and the inability to locate vulnerability attack details, how to provide a comprehensive and effective technical solution for smart terminal security protection methods in vehicle-grid interaction scenarios has become a technical problem that needs to be solved urgently. Summary of the invention
[0004] In view of the problems existing in the existing RASP-based intelligent terminal security protection method and system, the present invention is proposed.
[0005] Therefore, in order to solve the problem that the security protection capabilities of smart terminals in current vehicle-grid interaction scenarios are relatively limited, the present invention adopts a smart terminal security protection method based on RASP to solve it.
[0006] In order to solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, an embodiment of the present invention provides a smart terminal security protection method based on RASP, which includes loading a RASP probe in a V2G smart terminal, where the V2G smart terminal is a smart fusion terminal composed of a V2G charging pile, a new energy vehicle and a smart grid in a vehicle-grid interaction scenario, and the RASP probe is a security detection module of a real-time application self-protection technology in the V2G smart terminal; sending the configured custom security protection rules to the RASP probe in the V2G smart terminal through the V2GSMS system, wherein the V2GSMS is a vehicle-grid interaction security management system, a system for configuring and managing custom security protection rules; monitoring the network requests and application behaviors of the V2G smart terminal in real time through the RASP probe, using network request monitoring to detect abnormal network requests and traffic patterns of the smart terminal, identifying abnormal code execution or data access, and performing security protection on the smart terminal.
[0008] As a preferred solution of the RASP-based smart terminal security protection method of the present invention, wherein: the loading of the RASP probe in the V2G smart terminal includes detecting abnormal behavior through the RASP probe in the V2G smart terminal;
[0009] When the RASP probe in the V2G intelligent terminal detects abnormal behavior, the security protection module takes response measures, which include the following:
[0010] Through the RASP probe, when abnormal network traffic is detected in the V2G smart terminal, the abnormal network traffic is blocked and the abnormal process is terminated;
[0011] Through the RASP probe, the detected abnormal behavior and response measures are pushed to the V2GSMS system in real time, and an alarm notification is generated;
[0012] Through the security big model technology, known vulnerabilities in V2G smart terminals can be automatically repaired or tampered data can be restored.
[0013] As a preferred solution of the RASP-based intelligent terminal security protection method of the present invention, the security detection module includes summarizing the abnormal behavior information monitored by the RASP probe, generating a security log, and pushing it to the V2GSMS system. The specific steps are as follows:
[0014] Monitor V2G smart terminals through RASP probes and collect all detected abnormal behavior information in real time, including network traffic anomalies, abnormal application behavior, and unauthorized access attempts;
[0015] Through the RASP probe, the collected abnormal behavior information is classified by type and a description of each abnormal behavior event is generated, including the specific behavior detected, the triggered security rules and response measures;
[0016] Through the RASP probe, the security logs generated are stored locally in the V2G smart terminal, and the security logs are pushed to the V2GSMS system in batches using two modes: scheduled push and event-driven push.
[0017] As a preferred solution of the RASP-based smart terminal security protection method described in the present invention, wherein: the sending of the configured custom security protection rules to the RASP probe in the V2G smart terminal through the V2GSMS system includes compiling and generating a rule version supporting feedback mutation based on the existing security protection rules, recording the rule coverage through the plugging technology, adding the abnormal behavior information collected by the RASP probe as the initial seed to the input queue, mutating the seed information in the input queue according to the strategy, and generating the mutated security protection rules;
[0018] Apply the mutated rules to run in a controlled environment and monitor their status. Combine the security large model detection engine and the deep traffic learning algorithm to monitor the running effect of the mutated rules in real time, record the coverage of the rules and the abnormal behavior detection effect;
[0019] When the mutated security rules update the coverage or detect new abnormal behavior patterns, the mutated rules are retained and added to the input queue, and the security protection rules are continuously mutated and optimized. Through the RASP probe, the mutated security protection rules are automatically updated and applied, the effectiveness of rule mutation and iteration is evaluated, and the security protection strategy is further optimized.
[0020] As a preferred solution of the RASP-based smart terminal security protection method of the present invention, wherein: the real-time monitoring of network requests and application behaviors of V2G smart terminals by RASP probes includes identifying abnormal traffic patterns according to security protection rules issued by the V2GSMS system, using the RASP probes to match the monitored behaviors with pre-configured security rules, and detecting code injection, data tampering and unauthorized access of abnormal behaviors;
[0021] When the RASP probe in the V2G smart terminal detects abnormal behavior, the security protection module immediately takes response measures, which also include blocking suspicious behavior, alarm notification and automatic repair;
[0022] When the RASP probe detects abnormal network traffic or suspicious behavior in the V2G smart terminal, it immediately blocks the abnormal network traffic and terminates the abnormal process to prevent the spread of malicious behavior;
[0023] When the RASP probe pushes the detected abnormal behavior and response measures to the V2GSMS system in real time and generates an alarm notification, the administrator can promptly understand the security status of the smart terminal through the V2GSMS system.
[0024] As a preferred solution of the RASP-based smart terminal security protection method described in the present invention, the identification of abnormal code execution or data access includes identifying abnormal traffic patterns according to the security protection rules issued by the V2GSMS system, and intelligently selecting the most appropriate recovery point and recovery strategy for tampered data or damaged applications with the help of a large security model. The RASP probe restores the system to a normal state through a backup recovery mechanism to ensure business continuity.
[0025] As a preferred solution of the RASP-based smart terminal security protection method described in the present invention, the security protection of the smart terminal includes using the abnormal behavior information pushed by the RASP probe as a seed, mutating the original security protection rules, and iterating the security protection rules.
[0026] In the second aspect, an embodiment of the present invention provides a smart terminal security protection system based on RASP, which includes: a detection module, which loads a RASP probe in a V2G smart terminal, and the V2G smart terminal is an intelligent fusion terminal composed of a V2G charging pile, a new energy vehicle and a smart grid in a vehicle-grid interaction scenario, and the RASP probe is a security detection module of real-time application self-protection technology in the V2G smart terminal; a custom module, which sends the configured custom security protection rules to the RASP probe in the V2G smart terminal through the V2GSMS system, wherein the V2GSMS is a vehicle-grid interaction security management system, a system for configuring and managing custom security protection rules; a protection module, which monitors the network requests and application behaviors of the V2G smart terminal in real time through the RASP probe, uses network request monitoring to detect abnormal network requests and traffic patterns of the smart terminal, identifies abnormal code execution or data access, and performs security protection on the smart terminal.
[0027] In a third aspect, an embodiment of the present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, wherein: when the processor executes the computer program, any step of the above-mentioned RASP-based smart terminal security protection method is implemented.
[0028] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, any step of the above-mentioned RASP-based smart terminal security protection method is implemented.
[0029] The beneficial effects of the present invention are as follows: the present invention loads a RASP probe in a V2G smart terminal, and after the RASP probe is activated, the configured custom security protection rules are sent to the RASP probe in the V2G smart terminal through the V2GSMS system; the network requests and application behaviors of the V2G smart terminal are monitored in real time through the RASP probe; the above method solves the problems of poor deep-level security defense capabilities of smart terminals in vehicle-network interaction scenarios and bypassing of security protection devices at the network level at the traffic level by introducing RASP probes and variant security rule algorithms, and compared with the prior art, the flexible change capability, accuracy and management efficiency when protecting against vulnerability attacks are improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. Among them:
[0031] Figure 1 A specific flow chart of a smart terminal security protection method and system based on RASP provided for one embodiment of the present invention.
[0032] Figure 2 A schematic diagram of a protection method for a smart terminal security protection method and system based on RASP is provided for one embodiment of the present invention. DETAILED DESCRIPTION
[0033] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.
[0034] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0035] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.
[0036] The present invention is described in detail with reference to schematic diagrams. When describing the embodiments of the present invention, for the sake of convenience, the cross-sectional diagrams showing the device structure will not be partially enlarged according to the general scale, and the schematic diagrams are only examples, which should not limit the scope of protection of the present invention. In addition, in actual production, the three-dimensional dimensions of length, width and depth should be included.
[0037] At the same time, in the description of the present invention, it should be noted that the directions or positional relationships indicated by the terms "upper, lower, inner and outer" are based on the directions or positional relationships shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific direction, be constructed and operated in a specific direction, and therefore cannot be understood as limiting the present invention. In addition, the terms "first, second or third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0038] In the present invention, unless otherwise clearly specified and limited, the terms "install, connect, connect" should be understood in a broad sense, for example: it can be a fixed connection, a detachable connection or an integral connection; it can also be a mechanical connection, an electrical connection or a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0039] Example 1
[0040] Reference Figure 1 and Figure 2 , which is the first embodiment of the present invention, and provides a smart terminal security protection method based on RASP, including:
[0041] S1: Load the RASP probe in the V2G smart terminal. The V2G smart terminal is an intelligent fusion terminal composed of V2G charging piles, new energy vehicles and smart grids in the vehicle-grid interaction scenario. The RASP probe is a safety detection module for the real-time application self-protection technology in the V2G smart terminal.
[0042] Wherein, loading the RASP probe in the V2G smart terminal includes detecting abnormal behavior through the RASP probe in the V2G smart terminal;
[0043] When the RASP probe in the V2G smart terminal detects abnormal behavior, the security protection module takes response measures, which include the following:
[0044] Through the RASP probe, when abnormal network traffic is detected in the V2G smart terminal, the abnormal network traffic is blocked and the abnormal process is terminated;
[0045] Through the RASP probe, the detected abnormal behavior and response measures are pushed to the V2GSMS system in real time, and an alarm notification is generated;
[0046] Through the security big model technology, known vulnerabilities in V2G smart terminals can be automatically repaired or tampered data can be restored.
[0047] S1.1: The security detection module includes summarizing the abnormal behavior information detected by the RASP probe, generating a security log, and pushing it to the V2GSMS system. The specific steps are as follows:
[0048] Monitor V2G smart terminals through RASP probes and collect all detected abnormal behavior information in real time, including network traffic anomalies, abnormal application behavior, and unauthorized access attempts;
[0049] Through the RASP probe, the collected abnormal behavior information is classified by type and a description of each abnormal behavior event is generated, including the specific behavior detected, the triggered security rules and response measures;
[0050] Through the RASP probe, the security logs generated are stored locally in the V2G smart terminal, and the security logs are pushed to the V2GSMS system in batches using two modes: scheduled push and event-driven push.
[0051] S2: The configured custom safety protection rules are sent to the RASP probe in the V2G smart terminal through the V2GSMS system. V2GSMS is a vehicle-grid interactive safety management system used to configure and manage custom safety protection rules.
[0052] Among them, sending the configured custom security protection rules to the RASP probe in the V2G smart terminal through the V2GSMS system includes compiling and generating a rule version that supports feedback mutation based on the existing security protection rules, recording the rule coverage through the plugging technology, and adding the abnormal behavior information collected by the RASP probe as the initial seed to the input queue, mutating the seed information in the input queue according to the strategy, and generating the mutated security protection rules;
[0053] Apply the mutated rules to run in a controlled environment and monitor their status. Combine the security large model detection engine and the deep traffic learning algorithm to monitor the running effect of the mutated rules in real time, record the coverage of the rules and the abnormal behavior detection effect;
[0054] When the mutated security rules update the coverage or detect new abnormal behavior patterns, the mutated rules are retained and added to the input queue, and the security protection rules are continuously mutated and optimized. Through the RASP probe, the mutated security protection rules are automatically updated and applied, the effectiveness of rule mutation and iteration is evaluated, and the security protection strategy is further optimized.
[0055] S3: Use RASP probes to monitor the network requests and application behaviors of V2G smart terminals in real time, use network request monitoring to detect abnormal network requests and traffic patterns of smart terminals, identify abnormal code execution or data access, and provide security protection for smart terminals.
[0056] Among them, real-time monitoring of network requests and application behaviors of V2G smart terminals through RASP probes includes identifying abnormal traffic patterns according to the security protection rules issued by the V2GSMS system, matching the monitored behaviors with pre-configured security rules using RASP probes, and detecting code injection, data tampering and unauthorized access of abnormal behaviors;
[0057] When the RASP probe in the V2G smart terminal detects abnormal behavior, the security protection module immediately takes response measures, which also include blocking suspicious behavior, alarm notification and automatic repair;
[0058] When the RASP probe detects abnormal network traffic or suspicious behavior in the V2G smart terminal, it immediately blocks the abnormal network traffic and terminates the abnormal process to prevent the spread of malicious behavior;
[0059] When the RASP probe pushes the detected abnormal behavior and response measures to the V2GSMS system in real time and generates an alarm notification, the administrator can promptly understand the security status of the smart terminal through the V2GSMS system.
[0060] Furthermore, identifying abnormal code execution or data access includes identifying abnormal traffic patterns based on the security protection rules issued by the V2GSMS system. For tampered data or damaged applications, the RASP probe intelligently selects the most appropriate recovery point and recovery strategy with the help of the security big model. The RASP probe restores the system to normal through the backup and recovery mechanism to ensure business continuity.
[0061] Furthermore, security protection for smart terminals includes using the abnormal behavior information pushed by the RASP probe as a seed, mutating the original security protection rules, and iterating the security protection rules.
[0062] In a preferred embodiment, a RASP-based smart terminal security protection system includes a detection module, which loads a RASP probe in a V2G smart terminal, where the V2G smart terminal is a smart fusion terminal composed of a V2G charging pile, a new energy vehicle and a smart grid in a vehicle-grid interaction scenario, and the RASP probe is a security detection module for real-time application self-protection technology in the V2G smart terminal; a custom module, which sends the configured custom security protection rules to the RASP probe in the V2G smart terminal through a V2GSMS system, wherein V2GSMS is a vehicle-grid interaction security management system, a system for configuring and managing custom security protection rules; a protection module, which monitors the network requests and application behaviors of the V2G smart terminal in real time through the RASP probe, uses network request monitoring to detect abnormal network requests and traffic patterns of the smart terminal, identifies abnormal code execution or data access, and performs security protection on the smart terminal.
[0063] The above-mentioned unit modules may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to the above-mentioned modules.
[0064] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covering the display screen, or a key, trackball or touchpad provided on the housing of the computer device, or an external keyboard, touchpad or mouse, etc.
[0065] In summary, the present invention loads a RASP probe in a V2G smart terminal, and after the RASP probe is activated, sends the configured custom security protection rules to the RASP probe in the V2G smart terminal through the V2GSMS system; the network requests and application behaviors of the V2G smart terminal are monitored in real time through the RASP probe; the above method solves the problems of poor deep-level security defense capabilities of smart terminals in vehicle-network interaction scenarios and bypassing of security protection devices at the network level at the traffic level by introducing RASP probes and variant security rule algorithms. Compared with the prior art, the flexible change capability, accuracy and management efficiency when protecting against vulnerability attacks are improved.
[0066] Example 2
[0067] Reference Figure 1 and Figure 2 , which is the second embodiment of the present invention, and this embodiment provides a smart terminal security protection method based on RASP. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through simulation experiments.
[0068] In the experimental process of the intelligent terminal security protection method and system based on RASP, the RASP probe was first loaded in the V2G intelligent terminal (including the intelligent fusion terminal composed of V2G charging piles, new energy vehicles and smart grids) to ensure that it can monitor the terminal's network requests and application behaviors in real time. Experimental data show that after loading the RASP probe, the CPU usage of the V2G charging pile increased from 10% to 15%, the memory usage increased from 30% to 35%, and the network traffic remained at around 5Mbps, indicating that the loading of the RASP probe has little impact on system resources. The experimental data of the present invention is shown in Table 1 below:
[0069] Table 1 Experimental data table of the present invention
[0070]
[0071] Table 1 shows the key performance indicators and effects of the RASP-based smart terminal security protection method and system during the experiment, highlighting the significant advantages of this technical solution in improving the security protection capabilities of smart terminals. The comparison between the present invention and the prior art is shown in Table 2 below:
[0072] Table 2 Comparison between the present invention and the prior art
[0073]
[0074] Table 2 shows the significant advantages of the present invention in improving the security protection effect and system stability of smart terminals, especially in dealing with new threats, automated management, resource occupation and business continuity, etc., providing more comprehensive and effective security protection for V2G smart terminals in vehicle-network interaction scenarios.
[0075] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A smart terminal security protection method based on RASP, characterized in that: include, Loading a RASP probe in a V2G smart terminal, which is a smart fusion terminal consisting of a V2G charging pile, a new energy vehicle, and a smart grid in a vehicle-grid interaction scenario, and the RASP probe is a safety detection module for real-time application self-protection technology in the V2G smart terminal; The configured custom safety protection rules are sent to the RASP probe in the V2G smart terminal through the V2GSMS system, where V2GSMS is a vehicle-grid interactive safety management system used to configure and manage custom safety protection rules; The RASP probe is used to monitor the network requests and application behaviors of V2G smart terminals in real time. Network request monitoring is used to detect abnormal network requests and traffic patterns of smart terminals, identify abnormal code execution or data access, and provide security protection for smart terminals.
2. The RASP-based intelligent terminal security protection method according to claim 1, characterized in that: The loading of the RASP probe in the V2G smart terminal includes detecting abnormal behavior through the RASP probe in the V2G smart terminal; When the RASP probe in the V2G intelligent terminal detects abnormal behavior, the security protection module takes response measures, which include the following: Through the RASP probe, when abnormal network traffic is detected in the V2G smart terminal, the abnormal network traffic is blocked and the abnormal process is terminated; Through the RASP probe, the detected abnormal behavior and response measures are pushed to the V2GSMS system in real time, and an alarm notification is generated; Through the security big model technology, known vulnerabilities in V2G smart terminals can be automatically repaired or tampered data can be restored.
3. The RASP-based intelligent terminal security protection method according to claim 2, characterized in that: The security detection module includes summarizing the abnormal behavior information monitored by the RASP probe, generating a security log, and pushing it to the V2GSMS system. The specific steps are as follows: Monitor V2G smart terminals through RASP probes and collect all detected abnormal behavior information in real time, including network traffic anomalies, abnormal application behavior, and unauthorized access attempts; Through the RASP probe, the collected abnormal behavior information is classified by type and a description of each abnormal behavior event is generated, including the specific behavior detected, the triggered security rules and response measures; Through the RASP probe, the security logs generated are stored locally in the V2G smart terminal, and the security logs are pushed to the V2GSMS system in batches using two modes: scheduled push and event-driven push.
4. The RASP-based intelligent terminal security protection method according to claim 3, characterized in that: The sending of the configured custom security protection rules to the RASP probe in the V2G smart terminal through the V2GSMS system includes compiling and generating a rule version supporting feedback mutation based on the existing security protection rules, recording the rule coverage through the plugging technology, adding the abnormal behavior information collected by the RASP probe as the initial seed to the input queue, mutating the seed information in the input queue according to the strategy, and generating the mutated security protection rules; Apply the mutated rules to run in a controlled environment and monitor their status. Combine the security large model detection engine and the deep traffic learning algorithm to monitor the running effect of the mutated rules in real time, record the coverage of the rules and the abnormal behavior detection effect; When the mutated security rules update the coverage or detect new abnormal behavior patterns, the mutated rules are retained and added to the input queue, and the security protection rules are continuously mutated and optimized. Through the RASP probe, the mutated security protection rules are automatically updated and applied, the effectiveness of rule mutation and iteration is evaluated, and the security protection strategy is further optimized.
5. The RASP-based intelligent terminal security protection method according to claim 4, characterized in that: The real-time monitoring of network requests and application behaviors of V2G smart terminals by RASP probes includes identifying abnormal traffic patterns according to security protection rules issued by the V2GSMS system, matching the monitored behaviors with pre-configured security rules using the RASP probes, and detecting code injection, data tampering, and unauthorized access of abnormal behaviors; When the RASP probe in the V2G smart terminal detects abnormal behavior, the security protection module immediately takes response measures, which also include blocking suspicious behavior, alarm notification and automatic repair; When the RASP probe detects abnormal network traffic or suspicious behavior in the V2G smart terminal, it immediately blocks the abnormal network traffic and terminates the abnormal process to prevent the spread of malicious behavior; When the RASP probe pushes the detected abnormal behavior and response measures to the V2GSMS system in real time and generates an alarm notification, the administrator can promptly understand the security status of the smart terminal through the V2GSMS system.
6. The RASP-based intelligent terminal security protection method according to claim 5, characterized in that: The identification of abnormal code execution or data access includes the RASP probe identifying abnormal traffic patterns according to the security protection rules issued by the V2GSMS system. For tampered data or damaged applications, the most appropriate recovery point and recovery strategy are intelligently selected with the help of the security big model. The RASP probe restores the system to a normal state through the backup recovery mechanism to ensure business continuity.
7. The RASP-based intelligent terminal security protection method according to claim 6, characterized in that: The security protection of the smart terminal includes using the abnormal behavior information pushed by the RASP probe as a seed, mutating the original security protection rules, and iterating the security protection rules.
8. A smart terminal security protection system based on RASP, based on the smart terminal security protection method based on RASP according to any one of claims 1 to 7, characterized in that: include, A detection module, which loads a RASP probe in a V2G smart terminal, which is an intelligent fusion terminal composed of a V2G charging pile, a new energy vehicle, and a smart grid in a vehicle-grid interaction scenario. The RASP probe is a safety detection module for real-time application self-protection technology in the V2G smart terminal; A custom module, which sends the configured custom safety protection rules to the RASP probe in the V2G smart terminal through the V2GSMS system, wherein the V2GSMS is a vehicle-grid interactive safety management system for configuring and managing custom safety protection rules; The protection module monitors the network requests and application behaviors of V2G smart terminals in real time through RASP probes, uses network request monitoring to detect abnormal network requests and traffic patterns of smart terminals, identifies abnormal code execution or data access, and provides security protection for smart terminals.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the RASP-based smart terminal security protection method described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the RASP-based intelligent terminal security protection method described in any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Multi-security protection method and system for electric power application shopping mall
CN121530728A