Vehicle intrusion detection method based on multi-source data, electronic equipment and program product

By collaboratively analyzing the communication data and log data of the vehicle, the problem that a single data source analysis in the prior art is difficult to capture complex intrusion events, improving the coverage and accuracy of vehicle intrusion detection, and achieving multi-dimensional intrusion detection effect.

CN119995940APending Publication Date: 2025-05-13HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411998660.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing vehicle intrusion detection system only supports the analysis of a single data source, making it difficult to fully capture the characteristics of complex intrusion events, resulting in low coverage and accuracy of vehicle intrusion detection.

Method used

By obtaining the communication data and log data of the vehicle for collaborative analysis, the intrusion analysis of communication data can be used to discover potential threats at the network level, and the intrusion analysis of log data can be used to discover abnormal behaviors at the system level, thereby better capturing the characteristics of complex intrusion events and achieving multi-dimensional intrusion detection effect.

Benefits of technology

It improves the coverage and accuracy of vehicle intrusion detection, can capture the characteristics of complex intrusion events more comprehensively, and achieve multi-dimensional intrusion detection effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995940A_ABST
    Figure CN119995940A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent network connection vehicles, and provides a vehicle intrusion detection method based on multi-source data, electronic equipment and a computer program product. The method comprises the following steps: acquiring communication data and log data of a vehicle; performing intrusion analysis processing on the communication data to obtain a first intrusion detection result; performing intrusion analysis processing on the log data to obtain a second intrusion detection result; and determining a composite intrusion detection result of the vehicle according to the first intrusion detection result and the second intrusion detection result. According to the method, potential threats of a network level can be found by utilizing intrusion analysis of communication data, and abnormal behaviors of a system level can be found by utilizing intrusion analysis of log data, so that characteristics of complex intrusion events can be better captured, a multi-dimensional intrusion detection effect is realized, and the coverage rate and accuracy of vehicle intrusion detection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of intelligent connected vehicles, and in particular to a vehicle intrusion detection method, electronic equipment and computer program product based on multi-source data. Background Art

[0002] With the rapid development of artificial intelligence, the Internet of Things, and autonomous driving technologies, the market size of intelligent connected vehicles continues to expand, and the interaction between vehicle systems and external networks has become more frequent, making vehicle systems more vulnerable to external intrusions (such as various network attacks) and posing a greater security risk. To address this problem, vehicles can be equipped with intrusion detection systems, which can monitor intrusion events in a timely manner and formulate corresponding countermeasures to ensure the safety of vehicle systems. However, existing intrusion detection systems usually only support the analysis of a single data source, making it difficult to fully capture the characteristics of complex intrusion events, resulting in low coverage and accuracy of vehicle intrusion detection. Summary of the invention

[0003] In view of this, the embodiments of the present application provide a vehicle intrusion detection method, electronic device and computer program product based on multi-source data, which can improve the coverage and accuracy of vehicle intrusion detection.

[0004] A first aspect of an embodiment of the present application provides a vehicle intrusion detection method based on multi-source data, comprising:

[0005] Obtain vehicle communication data and log data;

[0006] Performing intrusion analysis processing on the communication data to obtain a first intrusion detection result;

[0007] Performing intrusion analysis processing on the log data to obtain a second intrusion detection result;

[0008] A composite intrusion detection result of the vehicle is determined based on the first intrusion detection result and the second intrusion detection result.

[0009] The technical solution of the embodiment of the present application obtains the communication data and log data of the vehicle for collaborative analysis, wherein the communication data is subjected to intrusion analysis processing to obtain a first intrusion detection result, the log data is subjected to intrusion analysis processing to obtain a second intrusion detection result, and finally the two intrusion detection results are fused to obtain a composite intrusion detection result of the vehicle. The above process obtains communication data and log data as multiple data sources, and the intrusion analysis of communication data can discover potential threats at the network level, and the intrusion analysis of log data can discover abnormal behaviors at the system level, thereby better capturing the characteristics of complex intrusion events and achieving multi-dimensional intrusion detection effects, which can improve the coverage and accuracy of vehicle intrusion detection.

[0010] In one implementation of the embodiment of the present application, determining a composite intrusion detection result of the vehicle according to the first intrusion detection result and the second intrusion detection result includes:

[0011] Determining a first anomaly score according to the first intrusion detection result;

[0012] determining a second anomaly score according to the second intrusion detection result;

[0013] Performing a weighted summation process on the first anomaly score and the second anomaly score to obtain a composite anomaly score;

[0014] According to the composite anomaly score, a composite intrusion detection result is determined.

[0015] In one implementation of the embodiment of the present application, the intrusion analysis and processing of the communication data is implemented by a network intrusion detection module, and the intrusion analysis and processing of the log data is implemented by a host intrusion detection module; a weighted summation process is performed on the first anomaly score and the second anomaly score to obtain a composite anomaly score, including:

[0016] Determine a first weight corresponding to the network intrusion detection module and a second weight corresponding to the host intrusion detection module;

[0017] Calculating a first product of the first anomaly score and the first weight, and calculating a second product of the second anomaly score and the second weight;

[0018] The sum of the first product and the second product is calculated to obtain the composite anomaly score.

[0019] In an implementation of the embodiment of the present application, determining a first weight corresponding to the network intrusion detection module and a second weight corresponding to the host intrusion detection module includes:

[0020] Obtaining a first historical detection result of a network intrusion detection module, and obtaining a second historical detection result of a host intrusion detection module;

[0021] Determining a first F1 score of the network intrusion detection module according to the first historical detection result;

[0022] Determining a second F1 score of the host intrusion detection module according to the second historical detection result;

[0023] A first weight and a second weight are determined according to the first F1 score and the second F1 score.

[0024] In another implementation of the embodiment of the present application, determining a first weight corresponding to the network intrusion detection module and a second weight corresponding to the host intrusion detection module includes:

[0025] Obtaining vehicle operating environment information;

[0026] A first weight and a second weight are determined according to the operating environment information.

[0027] In one implementation of the embodiment of the present application, the operating environment information includes vehicle speed, working mode, network communication flow, and road condition environment; determining the first weight and the second weight according to the operating environment information includes:

[0028] If the vehicle speed is greater than the first threshold, the first weight is set to be lower than the second weight; if the vehicle speed is less than or equal to the first threshold, the first weight is set to be higher than the second weight;

[0029] If the working mode is the automatic driving mode, the first weight is set to be higher than the second weight; if the working mode is the manual driving mode, the first weight is set to be lower than the second weight;

[0030] If the network communication flow is greater than the second threshold, the first weight is set higher than the second weight; if the network communication flow is less than or equal to the second threshold, the first weight is set lower than the second weight;

[0031] If the road condition environment is a highway, the first weight is set to be lower than the second weight; if the road condition environment is a city road, the first weight is set to be equal to the second weight.

[0032] In one implementation of the embodiment of the present application, performing intrusion analysis processing on communication data to obtain a first intrusion detection result includes:

[0033] Preprocessing communication data;

[0034] extracting data features of the preprocessed communication data;

[0035] Convert data features into feature vectors, input them into the trained encoder-decoder network for processing, compress the feature vectors into a low-dimensional space through the encoder-decoder network, and reconstruct the feature vectors from the low-dimensional space;

[0036] A first intrusion detection result is determined according to a reconstruction error of the feature vector.

[0037] In one implementation of the embodiment of the present application, performing intrusion analysis processing on log data to obtain a second intrusion detection result includes:

[0038] Preprocess log data;

[0039] The preprocessed log data is converted into a word vector sequence, which is divided into a front-end sequence and an actual back-end sequence;

[0040] The previous sequence is input into the trained text semantic analysis network for processing, and the text semantic analysis network generates a predicted subsequent sequence based on the previous sequence;

[0041] The second intrusion detection result is determined according to the semantic similarity between the predicted latter segment sequence and the actual latter segment sequence.

[0042] A second aspect of an embodiment of the present application provides a vehicle intrusion detection device based on multi-source data, comprising:

[0043] A data acquisition module, used to acquire the communication data and log data of the vehicle;

[0044] A communication data analysis module, used to perform intrusion analysis processing on the communication data to obtain a first intrusion detection result;

[0045] The log data analysis module is used to perform intrusion analysis processing on the log data to obtain a second intrusion detection result;

[0046] The detection result determination module is used to determine the composite intrusion detection result of the vehicle according to the first intrusion detection result and the second intrusion detection result.

[0047] A third aspect of an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the vehicle intrusion detection method based on multi-source data as provided in the first aspect of the embodiment of the present application is implemented.

[0048] A fourth aspect of an embodiment of the present application provides a computer program product. When the computer program product is run on an electronic device, the electronic device executes the vehicle intrusion detection method based on multi-source data provided in the first aspect of the embodiment of the present application.

[0049] The fifth aspect of an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the vehicle intrusion detection method based on multi-source data as provided in the first aspect of an embodiment of the present application.

[0050] It can be understood that the beneficial effects of the second to fifth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 is a flow chart of a vehicle intrusion detection method based on multi-source data provided by an embodiment of the present application;

[0052] Figure 2 This is a schematic diagram of a detection principle of a network intrusion detection module provided in an embodiment of the present application;

[0053] Figure 3This is a schematic diagram of a detection principle of a host intrusion detection module provided in an embodiment of the present application;

[0054] Figure 4 It is a schematic diagram of an operation principle of obtaining a composite intrusion detection result by using a network intrusion detection module and a host intrusion detection module provided in an embodiment of the present application;

[0055] Figure 5 It is a structural schematic diagram of a vehicle intrusion detection device based on multi-source data provided in an embodiment of the present application;

[0056] Figure 6 It is a schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0057] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system structures, technologies, etc. are proposed, so as to thoroughly understand the embodiments of the present application. However, it should be clear to those skilled in the art that the present application can also be implemented in other embodiments without these specific details. In other cases, the detailed description of well-known systems, devices, circuits and methods is omitted to prevent unnecessary details from hindering the description of the present application. In addition, in the description of the present application specification and the attached claims, the terms "first", "second", "third" etc. are only used to distinguish the description, and cannot be interpreted as indicating or suggesting relative importance.

[0058] Intelligent connected vehicles are an organic combination of vehicle networking and intelligent vehicles. They are equipped with advanced on-board sensors, controllers, actuators and other devices, and integrate modern communication and network technologies. They have the advantages of comfort, energy saving and high efficiency. As the market size of intelligent connected vehicles continues to expand, the interaction between vehicle systems and external networks is becoming more frequent, making vehicle systems more vulnerable to external intrusion threats and posing greater security risks. At present, vehicles can monitor intrusion incidents to a certain extent using intrusion detection systems, and can improve the security of vehicle systems by formulating corresponding countermeasures. However, existing intrusion detection systems usually only support the analysis of a single data source such as network traffic data, making it difficult to fully capture the characteristics of complex intrusion events, resulting in low coverage and accuracy of vehicle intrusion detection.

[0059] In view of the above problems existing in the existing intrusion detection system, the embodiments of the present application propose a vehicle intrusion detection method, electronic device and computer program product based on multi-source data, which can improve the coverage and accuracy of vehicle intrusion detection by collaboratively analyzing multiple data sources of the vehicle. For more specific technical implementation details of the embodiments of the present application, please refer to the various method embodiments described below.

[0060] It should be understood that the execution subjects of the various method embodiments proposed in the present application may be various types of electronic devices, such as mobile phones, tablet computers, wearable devices, vehicle gateways, vehicle terminals, augmented reality (AR) / virtual reality (VR) devices, laptop computers, ultra-mobile personal computers (UMPC), netbooks, personal digital assistants (PDA), large-screen TVs, etc. The embodiments of the present application do not impose any restrictions on the specific types of the electronic devices.

[0061] See also Figure 1 , showing a vehicle intrusion detection method based on multi-source data provided by an embodiment of the present application, comprising:

[0062] 101. Obtaining the vehicle's communication data and log data;

[0063] First, obtain the communication data and log data of the vehicle, which can be any type or model of smart vehicle. Among them, the communication data may include in-vehicle wired communication data (such as CAN bus traffic data, etc.) and out-vehicle wireless communication data (such as V2X and other network communication data), which are mainly used to analyze network attack events such as remote hijacking, data leakage and functional interference suffered by the vehicle; log data may include the vehicle's operating system log, application event log and error information log and other data, which are mainly used to analyze abnormal behavior and potential threats within the vehicle system. The embodiment of the present application does not limit the quantity and type of communication data and log data obtained.

[0064] 102. Perform intrusion analysis processing on the communication data to obtain a first intrusion detection result;

[0065] After acquiring the vehicle's communication data, intrusion analysis and processing are performed on the communication data to discover the characteristics of intrusion events that may exist in the communication data, and an intrusion detection result based on the communication data is obtained, which is recorded as the first intrusion detection result. The specific method of performing intrusion analysis and processing on the communication data is described below.

[0066] In one implementation of the embodiment of the present application, performing intrusion analysis processing on communication data to obtain a first intrusion detection result includes:

[0067] (1) Preprocessing the communication data;

[0068] (2) extracting data features of the preprocessed communication data;

[0069] (3) Converting data features into feature vectors, inputting them into the trained codec network for processing, compressing the feature vectors into a low-dimensional space through the codec network, and reconstructing the feature vectors from the low-dimensional space;

[0070] (4) Determine a first intrusion detection result based on a reconstruction error of the feature vector.

[0071] After acquiring the communication data of the vehicle, considering that the original communication data may have redundant fields or data loss, which will affect the accuracy of intrusion detection, the communication data is first preprocessed accordingly, such as removing redundant information and processing missing values, so that the quality of the input data can be improved, thereby improving the effect of subsequent data analysis. Then, the data features of the preprocessed communication data are extracted. For different types of communication data (such as CAN bus data or wireless communication data), different key data features can be extracted according to their respective characteristics. Specifically, the communication data can be input into a trained feature extraction network based on deep learning for processing to extract the corresponding data features. Then, the extracted data features are converted into a vector form to obtain a feature vector so that it can be input into a subsequent codec network for processing. The embodiment of the present application pre-trains a codec network based on deep learning, which can be a deep learning network of various types such as LSTM, CNN, RNN, GRU or Transformer. The codec network has an encoder and a decoder. After the initial feature vector is input into the codec network, the encoder can be used to compress the input feature vector encoding to a potential low-dimensional space, and the decoder can be used to reconstruct the feature vector from the low-dimensional space. Finally, the reconstruction error of the feature vector is calculated, that is, the error between the reconstructed feature vector and the initial feature vector, and the first intrusion detection result is determined based on the reconstruction error. Specifically, if the reconstruction error is small, it means that the input communication data can be successfully reconstructed by the codec network. At this time, the input communication data can be considered normal data and there is no intrusion event; on the contrary, if the reconstruction error is large, it means that the input communication data cannot be successfully reconstructed by the codec network. At this time, the input communication data can be considered abnormal data and there is an intrusion event. In actual operation, a software function module for performing intrusion analysis and processing on communication data can be set based on the above principle, which is recorded as a network intrusion detection module, which can be abbreviated as a NIDS module. The communication data of the vehicle is input into the NIDS module for processing, and the first intrusion detection result can be obtained as an output.

[0072] As an example, Figure 2 It is a schematic diagram of the detection principle of the network intrusion detection module provided in an embodiment of the present application. Figure 2The LSTM network is selected as the encoding and decoding network. The LSTM network is a deep learning network that can capture the time dependency in the data sequence. It is particularly suitable for processing time series data such as CAN bus data or network traffic data. The LSTM network can compress the input communication data into a low-dimensional space by learning the characteristic distribution of normal communication data, and then try to reconstruct the original communication data from the low-dimensional space. Figure 2 In, Z={z0,z1,z2,…,z t} represents the initial feature vector of the communication data input to the LSTM network, which is essentially a time series that is gradually input to the encoder of the LSTM network; the LSTM unit in the encoder calculates the hidden state h for each time step respectively t , the last hidden state h of the encoder T Represents the low-dimensional representation of the time series, which contains the context information of the entire time series; the input of the decoder of the LSTM network is the hidden state h T and the output of the decoder at the previous time step The decoder gradually generates outputs for each time step, and finally outputs the reconstructed time series: Finally, the reconstruction error E is calculated, which is the error between the input time series and the reconstructed time series output by the decoder. It is used to measure the network's learning ability for the input data. The training goal of the network is to minimize the reconstruction error.

[0073] For example, suppose the input time series After encoding by the LSTM network, the encoder generates a hidden state h at each time step t , and finally compress the time series into the final hidden state h T , as the latent code representation of the time series, in this example The decoder uses the final hidden state h T As the initial hidden state, gradually generate the reconstructed time series Then calculate and The difference between them can be used to obtain the reconstruction error E.

[0074] The principle of using the reconstruction error E to determine whether the communication data is abnormal is that the codec network mainly learns how to extract features from normal communication data and reconstruct normal communication data during the training process; due to the low frequency of abnormal communication data, the codec network cannot learn the features of abnormal communication data well during training, and abnormal communication data usually has patterns or features that are significantly different from normal communication data and cannot be effectively compressed and reconstructed by the trained codec network. Therefore, the reconstruction error of abnormal communication data will be significantly higher than the reconstruction error of normal communication data.

[0075] The embodiment of the present application is based on the above-mentioned NIDS module, which can effectively identify abnormal features in vehicle communication data, such as forged information of the CAN bus or abnormal traffic of wireless communication, so as to discover potential threats at the network level and improve the network security of the vehicle.

[0076] 103. Perform intrusion analysis processing on the log data to obtain a second intrusion detection result;

[0077] Similar to the processing process of communication data, after obtaining the vehicle's log data, intrusion analysis and processing are performed on the log data to discover the characteristics of intrusion events that may exist in the log data, and obtain intrusion detection results based on the log data, which are recorded as the second intrusion detection results. The following describes the specific method of performing intrusion analysis and processing on the log data.

[0078] In one implementation of the embodiment of the present application, performing intrusion analysis processing on log data to obtain a second intrusion detection result includes:

[0079] (1) Preprocess log data;

[0080] (2) The preprocessed log data is converted into a word vector sequence, and the word vector sequence is divided into a front segment sequence and an actual back segment sequence;

[0081] (3) Inputting the previous sequence into the trained text semantic analysis network for processing, and generating a predicted subsequent sequence based on the previous sequence through the text semantic analysis network;

[0082] (4) Determine the second intrusion detection result according to the semantic similarity between the predicted back-end sequence and the actual back-end sequence.

[0083] After obtaining the log data of the vehicle, the log data is also preprocessed accordingly, including removing words that are not related to semantic analysis (such as stop words), performing stem extraction and word form restoration, etc., so that the log data can be streamlined and the data dimension can be reduced, thereby improving the training speed and reasoning efficiency of the subsequent text semantic analysis network. Then, the preprocessed log data is subjected to text vectorization, that is, the log data is converted into the form of word vectors to obtain a word vector sequence. Here, the GLoVe (Global Vectors for Word Representation) model can be used to convert the log data into the form of word vectors. The GLoVe model can capture the semantic relationship between words and convert the text data into a high-quality vector representation. In addition, the word vector sequence can be divided into two halves, front and back, respectively recorded as the front segment sequence and the actual back segment sequence. The embodiment of the present application pre-trains a text semantic analysis network based on deep learning, and the front segment sequence is input into the text semantic analysis network for processing. The network can analyze the contextual semantic relationship between each word vector based on the front segment sequence to generate a predicted back segment sequence. Finally, the actual back-end sequence is compared with the predicted back-end sequence. Here, the semantic similarity of the two sequences can be determined by calculating the cosine similarity between the two sequences, and the second intrusion detection result can be determined based on the semantic similarity. Specifically, if the semantic similarity is large, it means that the input log data can be successfully predicted by the text semantic analysis network. At this time, the input log data can be considered normal data and there is no intrusion event; conversely, if the semantic similarity is small, it means that the input log data cannot be successfully predicted by the text semantic analysis network. At this time, the input log data can be considered abnormal data and there is an intrusion event. In actual operation, a software function module for performing intrusion analysis processing on log data can be set based on the above principle, recorded as a host intrusion detection module, which can be abbreviated as a HIDS module. The vehicle log data is input into the HIDS module for processing to obtain the output second intrusion detection result.

[0084] As an example, Figure 3 It is a detection principle schematic diagram of the host intrusion detection module provided in an embodiment of the present application. Figure 3 The bidirectional long short-term memory Bi-LSTM network is selected as the text semantic analysis network. The Bi-LSTM network can simultaneously capture the forward and backward semantic information in the text sequence, model complex contextual relationships, and thus predict more accurate subsequent text sequences. Figure 3 In the above example, each word in the log data is converted into a corresponding word vector V, thus obtaining a word vector sequence [V1, V2, …, V T , V T+1 , V T+2 , …, V T+n], where [V1, V2, …, V T ] is the previous sequence as input, [V T+1 , V T+2 , …, V T+n ] is the actual latter sequence for comparison. T ] is input to the Bi-LSTM network for processing. The hidden neuron layer of the Bi-LSTM network is divided into forward and backward layers, which can capture the semantic features of the previous sequence in two directions. The hidden state vector of time step t in the forward pass and the hidden state vector at time step t in the backward pass Will be combined into the total hidden state vector To capture information in two directions, the time step t represents the position of the input logarithmic sequence. The Bi-LSTM network uses the fully connected layer to collect the hidden state vectors of all time steps, and the result is still a word vector sequence, which is the predicted posterior sequence output by the Bi-LSTM network. After that, calculate the predicted sequence Compared with the actual subsequent sequence [V T+1 , V T+2 , …, V T+n ], which is between [-1, 1], and can represent the semantic similarity of the two sequences. Finally, according to the calculated semantic similarity, it can be determined whether the input log data is abnormal, thereby obtaining the second intrusion detection result.

[0085] The principle of using semantic similarity to determine whether log data is abnormal is that during the training process, the text semantic analysis network will learn the semantic relationships and time series patterns of vehicle system logs (such as the sequence of events, context dependencies, etc.) through a large amount of normal log data. The essence of this learning is to establish the statistical distribution or time pattern of normal log behavior. Therefore, the text semantic analysis network can accurately predict the subsequent sequence of normal log data, and the semantic similarity obtained at this time is very high; as for abnormal log data, its log behavior and time series patterns are usually significantly different from normal log data, such as abnormal order, frequency or content of the log, abnormal vocabulary contained in the log, events that do not conform to the context relationship appear in the log, etc., which will cause the text semantic analysis network to be unable to accurately predict the subsequent sequence of abnormal log data, that is, the semantic similarity finally obtained is significantly reduced.

[0086] The embodiment of the present application is based on the above-mentioned HIDS module, which can effectively identify abnormal phenomena hidden in vehicle log data, such as unknown command execution, abnormal user behavior or system errors, thereby discovering abnormal behavior at the system level and improving the internal safety of the vehicle.

[0087] 104. Determine a composite intrusion detection result of the vehicle based on the first intrusion detection result and the second intrusion detection result.

[0088] After obtaining the first intrusion detection result and the second intrusion detection result in the above manner, the first intrusion detection result and the second intrusion detection result are fused to finally obtain a composite intrusion detection result of the vehicle. Specifically, the above NIDS module focuses on the monitoring of communication data and can timely detect intrusion events at the network level, and the above HIDS module focuses on the monitoring of log data and can timely detect intrusion events at the system level. By fusing the detection results of the two modules for collaborative analysis, the composite intrusion detection result of the vehicle can be determined, providing multi-dimensional intrusion detection capabilities and making up for the limitations of a single detection method. The specific detection result fusion method is described below.

[0089] In one implementation of the embodiment of the present application, determining a composite intrusion detection result of the vehicle according to the first intrusion detection result and the second intrusion detection result includes:

[0090] (1) determining a first anomaly score according to the first intrusion detection result;

[0091] (2) determining a second anomaly score according to the second intrusion detection result;

[0092] (3) performing a weighted summation process on the first anomaly score and the second anomaly score to obtain a composite anomaly score;

[0093] (4) Determine the composite intrusion detection result based on the composite anomaly score.

[0094] According to the first intrusion detection result, a first anomaly score is calculated, and the first anomaly score can be used to indicate the abnormality of the vehicle communication data; according to the second intrusion detection result, a second anomaly score is calculated, and the second anomaly score can be used to indicate the abnormality of the vehicle log data; in order to effectively fuse the two parts of the detection results, a dynamic weighted fusion mechanism can be introduced, and the first anomaly score and the second anomaly score are combined for weighted summation calculation to obtain a composite anomaly score, which can be used to indicate the abnormality of the vehicle's multi-source data (including communication data and log data), thereby inferring the composite intrusion detection result of the vehicle. For example, if the composite anomaly score exceeds the set threshold, it can be considered that the vehicle has been attacked by an intrusion, and if the compliance anomaly score does not exceed the set threshold, it can be considered that the vehicle is in a safe state. In addition, according to the change of the composite anomaly score, different levels of protection response measures can be dynamically triggered. For example, when the composite anomaly score is low, there is no need to start the protection response measures; when the composite anomaly score increases slightly, a log can be recorded or an alarm can be sent to the vehicle system administrator; when the composite anomaly score increases moderately, real-time protection measures can be triggered, such as isolating the network or limiting key functions of the vehicle; when the composite anomaly score increases seriously, the vehicle system can be immediately deactivated or restarted to prevent the security threat from further expanding.

[0095] As an example, the corresponding reconstruction error can be determined based on the first intrusion detection result output by the above-mentioned NIDS module. If the reconstruction error is large, it means that the abnormality of the vehicle communication data is more serious, so a higher first anomaly score is generated, otherwise a lower first anomaly score is generated; the corresponding semantic similarity can be determined based on the second intrusion detection result output by the above-mentioned HIDS module. If the semantic similarity is low, it means that the abnormality of the vehicle log data is more serious, so a higher second anomaly score is generated, otherwise a lower second anomaly score is generated.

[0096] In one implementation of the embodiment of the present application, the intrusion analysis and processing of the communication data is implemented by a network intrusion detection module, and the intrusion analysis and processing of the log data is implemented by a host intrusion detection module; a weighted summation process is performed on the first anomaly score and the second anomaly score to obtain a composite anomaly score, including:

[0097] (1) determining a first weight corresponding to the network intrusion detection module and a second weight corresponding to the host intrusion detection module;

[0098] (2) calculating a first product of the first anomaly score and the first weight, and calculating a second product of the second anomaly score and the second weight;

[0099] (3) Calculate the sum of the first product and the second product to obtain a composite anomaly score.

[0100] Assuming that the intrusion analysis and processing of communication data is implemented through the above-mentioned NIDS module, and the intrusion analysis and processing of log data is implemented through the above-mentioned HIDS module, the core of the dynamic weighted fusion mechanism is to dynamically adjust the fusion weights of the NIDS module and the HIDS module in the comprehensive detection results according to different scenarios, characteristics of data sources and real-time confidence, so as to achieve flexible and efficient vehicle intrusion detection. Specifically, the first weight corresponding to the NIDS module and the second weight corresponding to the HIDS module can be determined, and then the first product of the first anomaly score and the first weight is calculated, and the second product of the second anomaly score and the second weight is calculated, and finally the sum of the first product and the second product is calculated to obtain the composite anomaly score. The dynamic weighted fusion formula can be expressed as: composite anomaly score = w_N(t) × first anomaly score + w_H(t) × second anomaly score, where w_N(t) represents the first weight corresponding to the NIDS module, and w_H(t) represents the second weight corresponding to the HIDS module. w_N(t)+w_H(t)=1 can be set to ensure the balance of the detection results. t represents time. Both the first weight and the second weight are related to time t, indicating that the weight can be dynamically adjusted with time t.

[0101] The dynamic weighted fusion mechanism can dynamically adjust the weights of the NIDS module and the HIDS module according to the historical performance indicators of the NIDS module and the HIDS module, or factors such as the vehicle's operating environment. The specific weight setting method is described below.

[0102] In an implementation of the embodiment of the present application, determining a first weight corresponding to the network intrusion detection module and a second weight corresponding to the host intrusion detection module includes:

[0103] (1) obtaining a first historical detection result of a network intrusion detection module and obtaining a second historical detection result of a host intrusion detection module;

[0104] (2) determining a first F1 score of the network intrusion detection module according to the first historical detection result;

[0105] (3) determining a second F1 score of the host intrusion detection module according to the second historical detection result;

[0106] (4) Determine a first weight and a second weight according to the first F1 score and the second F1 score.

[0107] First, the specific method of dynamically adjusting the module weights according to the historical performance indicators of the NIDS module and the HIDS module is explained. Commonly used module performance indicators include accuracy, recall rate, and F1 score, among which the F1 score is a weighted indicator that comprehensively considers accuracy and recall rate. In actual operation, any performance indicator can be selected for comparison, and a module with better performance indicators is set with a higher weight. For example, if the accuracy of the NIDS module is higher than that of the HIDS module, the first weight w_N can be set higher than the second weight w_H, and so on. However, in order to balance the detection accuracy and detection coverage of the module, the embodiment of the present application can select the F1 score as the performance indicator for comparison. Specifically, first collect the first historical detection result of the NIDS module and the second historical detection result of the HIDS module. Here, the historical detection result closest to the current time is obtained first, which can more accurately reflect the latest performance of the two modules. According to the first historical detection result, various performance indicators of the NIDS module, including accuracy and recall, etc., can be calculated, thereby calculating the first F1 score F1_N of the NIDS module; similarly, according to the second historical detection result, various performance indicators of the HIDS module can be calculated, thereby calculating the second F1 score F1_H of the HIDS module; then, according to the first F1 score F1_N and the second F1 score F1_H, the first weight w_N and the second weight w_H can be calculated, and the specific calculation formulas can be: w_N = F1_N / (F1_H+F1_N) and w_H = F1_H / (F1_H+F1_N). It can be seen that the higher the F1 score of the module, the higher the weight. It can be foreseen that with the development of time, the performance indicators of the two modules will change, so the weights of the two modules will also change dynamically.

[0108] The following describes a specific method for dynamically adjusting the module weights according to the vehicle's operating environment information. The core idea of ​​this method is that the emphasis of threat sources in different environments is different, and data sources that are more relevant to the current environment should be given priority. In another implementation of the embodiment of the present application, determining a first weight corresponding to the network intrusion detection module and a second weight corresponding to the host intrusion detection module includes:

[0109] (1) Obtaining vehicle operating environment information;

[0110] (2) Determine the first weight and the second weight according to the operating environment information.

[0111] The operating environment information of the vehicle is obtained, and the operating environment information may include but is not limited to: vehicle speed, working mode, network communication flow and road environment, etc. This information can be obtained through the vehicle speed sensor, working mode switching signal and communication module flow monitoring, etc. Based on this operating environment information, it can be evaluated which module's detection result has a higher priority under the current vehicle environment conditions, so as to set a higher weight for the module, and finally determine the first weight w_N and the second weight w_H, so that the detection resources can be allocated more reasonably and the comprehensive detection effect can be improved.

[0112] In one implementation of the embodiment of the present application, the operating environment information includes vehicle speed, working mode, network communication flow, and road condition environment; determining the first weight and the second weight according to the operating environment information includes:

[0113] (1) If the vehicle speed is greater than the first threshold, the first weight is set to be lower than the second weight; if the vehicle speed is less than or equal to the first threshold, the first weight is set to be higher than the second weight;

[0114] (2) If the working mode is the automatic driving mode, the first weight is set to be higher than the second weight; if the working mode is the manual driving mode, the first weight is set to be lower than the second weight;

[0115] (3) if the network communication flow is greater than the second threshold, the first weight is set higher than the second weight; if the network communication flow is less than or equal to the second threshold, the first weight is set lower than the second weight;

[0116] (4) If the road condition is a highway, the first weight is set to be lower than the second weight; if the road condition is a city road, the first weight is set to be equal to the second weight.

[0117] During the driving process of the vehicle, its operating environment information has a significant impact on the demand and direction of intrusion detection. For vehicle speed, since many network attacks are launched by attackers when the vehicle is slow or parked, such as GPS spoofing attacks or Wifi man-in-the-middle attacks, the security of external communication data is more critical when the vehicle is slow (e.g. ≤60km / h) or parked, which means that the detection results of the NIDS module need to be given priority, so the first weight w_N is set higher than the second weight w_H; conversely, when the vehicle speed is high (e.g. >60km / h), the log analysis of the vehicle's internal system is more important, which means that the detection results of the HIDS module need to be given priority, so the first weight w_N is set lower than the second weight w_H.

[0118] The working mode of the vehicle generally includes an automatic driving mode and a manual driving mode. If the vehicle is in automatic driving mode, since it needs to receive navigation data through the network, the security of external communication data is more critical, that is, it is necessary to give priority to the detection results of the NIDS module, so the first weight w_N is set higher than the second weight w_H; if the vehicle is in manual driving mode, the monitoring of the system log is more critical, that is, it is necessary to give priority to the detection results of the HIDS module, so the first weight w_N is set lower than the second weight w_H.

[0119] For the vehicle's network communication traffic, if the network communication traffic is large, it means that the vehicle is in a high communication load state. At this time, a lot of communication data is received, so the security of external communication data is more critical, that is, it is necessary to give priority to the detection results of the NIDS module, so the first weight w_N is set higher than the second weight w_H; conversely, if the network communication traffic is small, it means that the vehicle is in a low communication load state. At this time, less communication data is received, and the importance of the NIDS module is reduced, so the first weight w_N can be set lower than the second weight w_H.

[0120] For the road environment, if the vehicle is in a simple road condition such as a highway, since the vehicle needs to travel at high speed on the highway, the weights of the two modules can be set based on the vehicle speed, that is, the first weight w_N is set lower than the second weight w_H. If the vehicle is in a complex road condition such as a city highway or intersection, it is necessary to balance the security of external communication and internal systems. At this time, the detection results of the two modules can be balanced, that is, the first weight w_N is set equal to the second weight w_H.

[0121] It can be foreseen that as time changes, the vehicle's operating environment information will change, so the weights of the two modules will also change dynamically.

[0122] As an example, Figure 4 It is a schematic diagram of an operation principle of obtaining a composite intrusion detection result by using a network intrusion detection module and a host intrusion detection module provided in an embodiment of the present application. Figure 4The intrusion detection system shown includes a NIDS module and a HIDS module. After obtaining the communication data and log data of the vehicle, the communication data is input into the NIDS module for processing. The NIDS module performs preprocessing, feature extraction, encoding and decoding network processing and other operations on the communication data, and finally outputs the first intrusion detection result; the log data is input into the HIDS module for processing. The HIDS module performs preprocessing, log vectorization, text semantic analysis network processing and other operations on the log data, and finally outputs the second intrusion detection result; finally, the weights of the two modules are set according to the historical performance indicators of the two modules and the operating environment information of the vehicle, and the composite intrusion detection result of the vehicle is obtained by weighted fusion. Through such a setting, the characteristics of the in-vehicle system log and the out-of-vehicle communication traffic can be taken into account, and complex joint attack events, such as the linkage of communication forgery and system intrusion, can be detected, thereby realizing real-time evaluation and dynamic protection of the global security situation of the vehicle.

[0123] The technical solution of the embodiment of the present application obtains the communication data and log data of the vehicle for collaborative analysis, wherein the communication data is subjected to intrusion analysis processing to obtain a first intrusion detection result, the log data is subjected to intrusion analysis processing to obtain a second intrusion detection result, and finally the two intrusion detection results are fused to obtain a composite intrusion detection result of the vehicle. The above process obtains communication data and log data as multiple data sources, and the intrusion analysis of communication data can discover potential threats at the network level, and the intrusion analysis of log data can discover abnormal behaviors at the system level, thereby better capturing the characteristics of complex intrusion events and achieving multi-dimensional intrusion detection effects, which can improve the coverage and accuracy of vehicle intrusion detection.

[0124] In summary, the embodiment of the present application proposes a multi-level collaborative intrusion detection solution based on multi-source data. By collaboratively analyzing the detection results of the NIDS module and the HIDS module, it is more suitable for the operating environment of intelligent networked vehicles and can obtain more comprehensive and accurate vehicle intrusion detection results. Moreover, the embodiment of the present application also proposes a dynamic weighted fusion method, which can dynamically adjust the fusion weight of the detection results of each module according to the historical performance indicators of each module and the operating environment of the vehicle, so as to achieve flexible and efficient comprehensive analysis.

[0125] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0126] A vehicle intrusion detection method based on multi-source data is mainly described above. A vehicle intrusion detection device based on multi-source data will be described below.

[0127] See also Figure 5, shows a vehicle intrusion detection device based on multi-source data provided by an embodiment of the present application, comprising:

[0128] The data acquisition module 501 is used to acquire the communication data and log data of the vehicle;

[0129] The communication data analysis module 502 is used to perform intrusion analysis processing on the communication data to obtain a first intrusion detection result;

[0130] The log data analysis module 503 is used to perform intrusion analysis processing on the log data to obtain a second intrusion detection result;

[0131] The detection result determination module 504 is used to determine a composite intrusion detection result of the vehicle according to the first intrusion detection result and the second intrusion detection result.

[0132] In one implementation of the embodiment of the present application, the detection result determination module includes:

[0133] A first anomaly score determining unit, configured to determine a first anomaly score according to the first intrusion detection result;

[0134] A second anomaly score determining unit, configured to determine a second anomaly score according to the second intrusion detection result;

[0135] a composite anomaly score calculation unit, configured to perform a weighted summation process on the first anomaly score and the second anomaly score to obtain a composite anomaly score;

[0136] The detection result determination unit is used to determine the composite intrusion detection result according to the composite anomaly score.

[0137] In one implementation of the embodiment of the present application, the intrusion analysis and processing of the communication data is implemented by a network intrusion detection module, and the intrusion analysis and processing of the log data is implemented by a host intrusion detection module; the composite anomaly score calculation unit includes:

[0138] A weight determination subunit, used to determine a first weight corresponding to the network intrusion detection module and a second weight corresponding to the host intrusion detection module;

[0139] a product calculation subunit, configured to calculate a first product of a first anomaly score and a first weight, and to calculate a second product of a second anomaly score and a second weight;

[0140] The composite anomaly score calculation subunit is used to calculate the sum of the first product and the second product to obtain a composite anomaly score.

[0141] In one implementation of the embodiment of the present application, the weight determination subunit includes:

[0142] A historical detection result acquisition subunit, used to acquire a first historical detection result of a network intrusion detection module and to acquire a second historical detection result of a host intrusion detection module;

[0143] A first F1 score calculation subunit, configured to determine a first F1 score of the network intrusion detection module according to the first historical detection result;

[0144] A second F1 score calculation subunit, used to determine a second F1 score of the host intrusion detection module according to the second historical detection result;

[0145] The weight calculation subunit is used to determine the first weight and the second weight according to the first F1 score and the second F1 score.

[0146] In another implementation of the embodiment of the present application, the weight determination subunit includes:

[0147] An environmental information acquisition subunit, used to acquire the vehicle's operating environment information;

[0148] The weight acquisition subunit is used to determine the first weight and the second weight according to the operating environment information.

[0149] In one implementation of the embodiment of the present application, the operating environment information includes vehicle speed, working mode, network communication flow and road condition environment; the weight acquisition subunit includes:

[0150] A first weight setting subunit, configured to set the first weight lower than the second weight if the vehicle speed is greater than a first threshold; and to set the first weight higher than the second weight if the vehicle speed is less than or equal to the first threshold;

[0151] a second weight setting subunit, configured to set the first weight to be higher than the second weight if the working mode is the automatic driving mode; and to set the first weight to be lower than the second weight if the working mode is the manual driving mode;

[0152] A third weight setting subunit, configured to set the first weight higher than the second weight if the network communication flow is greater than the second threshold; and to set the first weight lower than the second weight if the network communication flow is less than or equal to the second threshold;

[0153] The fourth weight setting subunit is used to set the first weight to be lower than the second weight if the road condition environment is a highway; and to set the first weight to be equal to the second weight if the road condition environment is a city highway.

[0154] In one implementation of the embodiment of the present application, the communication data analysis module includes:

[0155] A first preprocessing unit, used for preprocessing communication data;

[0156] A feature extraction unit, used to extract data features of the preprocessed communication data;

[0157] A vector reconstruction unit is used to convert data features into feature vectors, input them into the trained codec network for processing, compress the feature vectors into a low-dimensional space through the codec network, and reconstruct the feature vectors from the low-dimensional space;

[0158] The first result determination unit is used to determine a first intrusion detection result according to a reconstruction error of the feature vector.

[0159] In one implementation of the embodiment of the present application, the log data analysis module includes:

[0160] A second preprocessing unit, used for preprocessing the log data;

[0161] The vector conversion unit is used to convert the preprocessed log data into a word vector sequence. The word vector sequence is divided into a front segment sequence and an actual back segment sequence.

[0162] A semantic analysis unit, used for inputting the preceding sequence into a trained text semantic analysis network for processing, and generating a predicted subsequent sequence based on the preceding sequence through the text semantic analysis network;

[0163] The second result determination unit is used to determine the second intrusion detection result according to the semantic similarity between the predicted latter segment sequence and the actual latter segment sequence.

[0164] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the vehicle intrusion detection method based on multi-source data described in any of the above embodiments is implemented.

[0165] An embodiment of the present application also provides a computer program product. When the computer program product is run on an electronic device, the electronic device executes the vehicle intrusion detection method based on multi-source data as described in any of the above embodiments.

[0166] Figure 6 is a schematic diagram of an electronic device provided by an embodiment of the present application. Figure 6 As shown, the electronic device 6 of this embodiment includes: a processor 60, a memory 61, and a computer program 62 stored in the memory 61 and executable on the processor 60. When the processor 60 executes the computer program 62, the steps in the above-mentioned embodiments of the vehicle intrusion detection method based on multi-source data are implemented, for example Figure 1 Alternatively, when the processor 60 executes the computer program 62, the functions of each module / unit in the above-mentioned device embodiments are realized, for example, Figure 5Functions of modules 501 - 504 of the illustrated apparatus.

[0167] The computer program 62 may be divided into one or more modules / units, which are stored in the memory 61 and executed by the processor 60 to complete the present application. The one or more modules / units may be a series of computer program instruction segments capable of completing specific functions, which are used to describe the execution process of the computer program 62 in the electronic device 6.

[0168] The processor 60 may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.

[0169] The memory 61 may be an internal storage unit of the electronic device 6, such as a hard disk or memory of the electronic device 6. The memory 61 may also be an external storage device of the electronic device 6, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device 6. Further, the memory 61 may also include both an internal storage unit and an external storage device of the electronic device 6. The memory 61 is used to store the computer program and other programs and data required by the electronic device. The memory 61 may also be used to temporarily store data that has been output or is to be output.

[0170] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.

[0171] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0172] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0173] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0174] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the system embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0175] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the embodiments of the present application.

[0176] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0177] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.

[0178] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A vehicle intrusion detection method based on multi-source data, characterized in that: include: Obtain vehicle communication data and log data; Performing intrusion analysis processing on the communication data to obtain a first intrusion detection result; Performing intrusion analysis processing on the log data to obtain a second intrusion detection result; A composite intrusion detection result of the vehicle is determined based on the first intrusion detection result and the second intrusion detection result.

2. The method according to claim 1, characterized in that The determining, according to the first intrusion detection result and the second intrusion detection result, a composite intrusion detection result of the vehicle includes: Determining a first anomaly score according to the first intrusion detection result; determining a second anomaly score according to the second intrusion detection result; Performing a weighted summation process on the first anomaly score and the second anomaly score to obtain a composite anomaly score; The composite intrusion detection result is determined according to the composite anomaly score.

3. The method according to claim 2, characterized in that The intrusion analysis and processing of the communication data is implemented by a network intrusion detection module, and the intrusion analysis and processing of the log data is implemented by a host intrusion detection module; performing weighted sum processing on the first anomaly score and the second anomaly score to obtain a composite anomaly score includes: Determine a first weight corresponding to the network intrusion detection module and a second weight corresponding to the host intrusion detection module; Calculating a first product of the first anomaly score and the first weight, and calculating a second product of the second anomaly score and the second weight; The sum of the first product and the second product is calculated to obtain the composite anomaly score.

4. The method according to claim 3, characterized in that The determining of the first weight corresponding to the network intrusion detection module and the second weight corresponding to the host intrusion detection module includes: Acquire a first historical detection result of the network intrusion detection module, and acquire a second historical detection result of the host intrusion detection module; Determining a first F1 score of the network intrusion detection module according to the first historical detection result; Determining a second F1 score of the host intrusion detection module according to the second historical detection result; The first weight and the second weight are determined according to the first F1 score and the second F1 score.

5. The method according to claim 3, characterized in that The determining of the first weight corresponding to the network intrusion detection module and the second weight corresponding to the host intrusion detection module includes: Acquiring operating environment information of the vehicle; The first weight and the second weight are determined according to the operating environment information.

6. The method according to claim 5, characterized in that The operating environment information includes vehicle speed, working mode, network communication flow and road condition environment; and determining the first weight and the second weight according to the operating environment information includes: If the vehicle speed is greater than a first threshold, the first weight is set to be lower than the second weight; if the vehicle speed is less than or equal to the first threshold, the first weight is set to be higher than the second weight; If the working mode is the automatic driving mode, the first weight is set to be higher than the second weight; if the working mode is the manual driving mode, the first weight is set to be lower than the second weight; If the network communication flow is greater than a second threshold, the first weight is set higher than the second weight; if the network communication flow is less than or equal to the second threshold, the first weight is set lower than the second weight; If the road condition environment is a highway, the first weight is set to be lower than the second weight; if the road condition environment is a city highway, the first weight is set to be equal to the second weight.

7. The method according to any one of claims 1 to 6, characterized in that: The performing intrusion analysis processing on the communication data to obtain a first intrusion detection result includes: Preprocessing the communication data; Extracting data features of the preprocessed communication data; Convert the data features into feature vectors, input them into a trained codec network for processing, compress the feature vectors into a low-dimensional space through the codec network, and reconstruct the feature vectors from the low-dimensional space; The first intrusion detection result is determined according to a reconstruction error of the feature vector.

8. The method according to any one of claims 1 to 6, characterized in that The performing intrusion analysis processing on the log data to obtain a second intrusion detection result includes: Preprocessing the log data; Convert the preprocessed log data into a word vector sequence, where the word vector sequence is divided into a front segment sequence and an actual back segment sequence; Inputting the preceding sequence into a trained text semantic analysis network for processing, and generating a predicted subsequent sequence based on the preceding sequence through the text semantic analysis network; The second intrusion detection result is determined according to the semantic similarity between the predicted latter-segment sequence and the actual latter-segment sequence.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the vehicle intrusion detection method based on multi-source data as described in any one of claims 1 to 8 is implemented.

10. A computer program product, characterized in that When the computer program product runs on an electronic device, the electronic device executes the vehicle intrusion detection method based on multi-source data as described in any one of claims 1 to 8.