Data packet filtering method and device for vehicle-mounted host firewall
By registering hook functions and preset analytical functions in the kernel state of the on-board host, filtering the protocol data of each layer in the on-board host firewall is solved, and the problem of being unable to filter the application layer and other three-layer protocols simultaneously in the prior art is solved, and the security of vehicle network communication is improved.
Patent Information
- Application Number
- CN202510343469.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-05-13
AI Technical Summary
The existing on-board host firewall cannot filter the application layer and other three-layer protocols at the same time, and cannot effectively avoid risks and threats in on-board communications.
By registering hook functions and preset analysis functions in the kernel state of the on-board host, receiving filtering rules issued by the user state, intercepting and parsing the protocol data of each layer in the network traffic data packet to be transmitted, and filtering and packet transmission are performed according to the filtering rules.
It realizes comprehensive filtering of link layer, network layer, transmission layer and application layer data in vehicle host firewall, improving the security and reliability of vehicle network traffic data packet transmission.
Smart Images

Figure CN119996059A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicle-mounted host firewall applications, and in particular to a method and device for filtering data packets of a vehicle-mounted host firewall. Background Art
[0002] Firewall is a commonly used intrusion prevention technology. When it comes to firewalls, conventional firewalls are separate devices that separate two networks and filter traffic specified by rules. In the vehicle network, a single ECU is also at risk of being attacked. It is necessary to deploy a firewall on an ECU to filter the network traffic entering the ECU. This firewall is called a vehicle host firewall.
[0003] At present, the vehicle host firewall is limited to filtering data packets at the link layer, network layer and transport layer; the inventor has found that in actual applications, if you want to filter vehicle network application layer protocols such as SOME / IP, DDS, DoIP, etc., you need to develop them separately or superimpose other products; there is currently no suitable product in the field of vehicle host firewalls that can put the application layer protocol together with the other three-layer protocols, and provide efficient firewall functions in the form of a single product to avoid the risks and threats in vehicle communications. Summary of the invention
[0004] In view of this, the purpose of the present invention is to provide a data packet filtering method and device for a vehicle-mounted host firewall to alleviate the technical problem in the prior art that the vehicle-mounted host firewall cannot simultaneously filter the application layer and the remaining three layers of protocols.
[0005] In a first aspect, the present invention provides a method for filtering data packets of a vehicle-mounted host firewall, the method comprising:
[0006] Receiving filtering rules for network traffic data packets to be transmitted, which are sent from the user state of the vehicle-mounted host to the network firewall in the kernel state of the vehicle-mounted host;
[0007] Based on the hook function in the kernel state and the filtering rules, the network traffic data packet to be transmitted is intercepted, and the first protocol layer data in the network traffic data packet is parsed and filtered; wherein the first protocol layer data is link layer data, network layer data and transport layer data;
[0008] Parsing and filtering the second protocol layer data based on the filtering rule and a preset parsing function corresponding to the protocol type of the second protocol layer data in the network traffic data packet; the second protocol layer data is application layer data;
[0009] The parsed and filtered first protocol layer data and second protocol layer data are packaged and transmitted.
[0010] In an optional implementation, the step of receiving a filtering rule for a network traffic data packet to be transmitted, which is sent from the user state of the vehicle-mounted host to the network firewall in the kernel state of the vehicle-mounted host, includes:
[0011] Using the kernel state of the vehicle host in advance, register a callback function for receiving the filtering rules sent by the user state of the vehicle host;
[0012] Based on the callback function, filtering rules for each protocol layer data in the network traffic data packet to be transmitted are received.
[0013] In an optional implementation, based on the hook function in the kernel state and the filtering rule, intercepting the network traffic data packet to be transmitted, and parsing and filtering the first protocol layer data in the network traffic data packet include:
[0014] Pre-registering a hook function according to the network firewall in the kernel state;
[0015] Based on the hook function, intercepting the network traffic data packet to be transmitted;
[0016] According to the filtering rules of the first protocol layer data in the network traffic data packet, the link layer data, the network layer data and the transport layer data in the network traffic data packet are parsed and filtered respectively.
[0017] In an optional implementation, the step of parsing and filtering the second protocol layer data based on the filtering rule and a preset parsing function corresponding to the protocol type of the second protocol layer data in the network traffic data packet includes:
[0018] Determine, based on the transport layer data and the application layer data in the network traffic data packet to be transmitted, the protocol type corresponding to the application layer data in the network traffic data packet;
[0019] According to the filtering rules of the application layer data in the network traffic data packet and the preset parsing function corresponding to the protocol type, the application layer data in the network traffic data packet is parsed and filtered.
[0020] In an optional implementation, based on the transport layer data and the application layer data in the network traffic data packet to be transmitted, the step of determining the protocol type corresponding to the application layer data in the network traffic data packet includes:
[0021] Determine the first protocol type of the application layer data in the network traffic data packet based on the comparison consistency between the port number of the transport layer data in the network traffic data packet to be transmitted and the preset port number; wherein the first protocol type includes the DOIP protocol type;
[0022] Based on the comparison consistency between the target byte content and the preset byte content of the application layer data in the network traffic data packet to be transmitted, the second protocol type of the application layer data in the network traffic data packet is determined; wherein the target byte content includes data length, protocol version and protocol interface version; the second protocol type includes DDS protocol type and SOME / IP protocol type.
[0023] In an optional implementation, the step of packaging and transmitting the parsed and filtered first protocol layer data and second protocol layer data includes:
[0024] The parsed and filtered link layer data, network layer data, transport layer data and application layer data are packaged in turn to obtain the target network traffic data packet filtered by the vehicle host firewall, and then the target network traffic data packet is transmitted to the corresponding ECU module.
[0025] In an optional implementation manner, before the step of receiving the filtering rules for the network traffic data packets to be transmitted sent from the user state to the network firewall in the kernel state, the method further includes:
[0026] Establish a network connection between the user state of the vehicle host and the kernel state of the vehicle host.
[0027] In a second aspect, the present invention provides a data packet filtering device for a vehicle-mounted host firewall, the device comprising:
[0028] A receiving module receives filtering rules for network traffic data packets to be transmitted, which are sent from the user state of the vehicle-mounted host to the network firewall in the kernel state of the vehicle-mounted host;
[0029] A first filtering module, based on the hook function in the kernel state and the filtering rule, intercepts the network traffic data packet to be transmitted, and parses and filters the first protocol layer data in the network traffic data packet; wherein the first protocol layer data is link layer data, network layer data and transport layer data;
[0030] A second filtering module, based on the filtering rule and a preset parsing function corresponding to the protocol type of the second protocol layer data in the network traffic data packet, parses and filters the second protocol layer data; the second protocol layer data is application layer data;
[0031] The packet assembly module assembles and transmits the parsed and filtered first protocol layer data and second protocol layer data.
[0032] In a third aspect, the present invention provides an electronic device, comprising a memory and a processor, wherein the memory stores a computer program executable on the processor, and when the processor executes the computer program, the steps of the method described in any one of the aforementioned implementation modes are implemented.
[0033] In a fourth aspect, the present invention provides a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions. When the machine-executable instructions are called and executed by a processor, the machine-executable instructions prompt the processor to implement the steps of the method described in any one of the aforementioned implementations.
[0034] The embodiment of the present invention provides a data packet filtering method and device for a vehicle-mounted host firewall. The method and device receive filtering rules for network traffic data packets to be transmitted to an ECU module from the user state to the network firewall in the kernel state through the network connection between the user state and the kernel state of the vehicle-mounted host; parse and filter the link layer data, network layer data and transport layer data in the network traffic data packets to be transmitted through the filtering rules and the hook function in the kernel state; then search for the corresponding parsing function according to the protocol type of the application layer data in the network traffic packet to be transmitted to implement parsing, and filter based on the filtering rules; finally, the data of each protocol layer after the parsing and filtering operations are packaged and then transmitted to the ECU module.
[0035] Other features and advantages of the present disclosure will be set forth in the following description, or some features and advantages may be inferred or unambiguously determined from the description, or may be learned by implementing the above-mentioned technology of the present disclosure.
[0036] In order to make the above-mentioned objectives, features and advantages of the present disclosure more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0038] Figure 1 A schematic diagram of the protocol layer structure of a network traffic data packet provided by an embodiment of the present invention;
[0039] Figure 2 A flow chart of a method for filtering data packets of a vehicle-mounted host firewall provided by an embodiment of the present invention;
[0040] Figure 3A schematic diagram of an application scenario of a data packet filtering method of a vehicle-mounted host firewall provided by an embodiment of the present invention;
[0041] Figure 4 A functional module diagram of a data packet filtering device of a vehicle-mounted host firewall provided by an embodiment of the present invention;
[0042] Figure 5 A schematic diagram of the hardware architecture of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0043] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0044] The protocol layer structure of the current network traffic data packet is as follows Figure 1 As shown, it includes a link layer responsible for device-to-device transmission, a network layer responsible for host-to-host communication, a transport layer responsible for process-to-process communication, and an application layer that represents the corresponding services of the application program. The inventors have found that the vehicle-mounted host firewall can only parse and filter the data of the remaining three layers except the application layer. If it is desired to parse and filter the application layer data, additional corresponding products need to be designed, which is not conducive to the security of network traffic data packet transmission between vehicle ECUs.
[0045] Based on this, an embodiment of the present invention provides a data packet filtering method and device for a vehicle-mounted host firewall, which enables the vehicle-mounted host firewall to filter the data of each protocol layer of the network traffic data packets transmitted between ECU modules without introducing additional components while ensuring the security and reliability of vehicle data packet communications.
[0046] To facilitate understanding of this embodiment, a data packet filtering method of a vehicle-mounted host firewall disclosed in an embodiment of the present invention is first introduced in detail. This method is mainly used in vehicle-mounted hosts, vehicle control devices, such as vehicle-mounted host firewalls in kernel-mode operating systems.
[0047] Figure 2 A flow chart of a method for filtering data packets of a vehicle-mounted host firewall provided in an embodiment of the present invention.
[0048] like Figure 2 As shown, the method comprises the following steps:
[0049] Step S102, receiving filtering rules for network traffic data packets to be transmitted, which are sent from the user state of the vehicle-mounted host to the network firewall in the kernel state of the vehicle-mounted host.
[0050] Among them, the network traffic data packets to be transmitted can be understood as data to be input into the vehicle ECU module, or to be output from the vehicle ECU module to enter another vehicle ECU module; the user state of the vehicle host involves the corresponding application APP used to issue filtering rules; the kernel state of the vehicle host can be understood as the structure of operating systems such as QNX, Linux, etc. in the user state, which includes the vehicle host firewall.
[0051] Step S104, based on the hook function and filtering rules in the kernel state, intercept the network traffic data packet to be transmitted, and parse and filter the first protocol layer data in the network traffic data packet.
[0052] Among them, the kernel state structure includes a hook function, which can parse and filter the first protocol layer data in the network traffic data packet under the action of the hook function and the filtering rules obtained in the aforementioned embodiment; the first protocol layer data is link layer data, network layer data and transport layer data.
[0053] Step S106, parsing and filtering the second protocol layer data based on the filtering rule and the preset parsing function corresponding to the protocol type of the second protocol layer data in the network traffic data packet.
[0054] Here, the corresponding parsing functions of various application layer protocol types are set in advance, and the current kernel state structure can select the corresponding preset parsing function based on the parsing type corresponding to the application layer data of the network traffic data packet, and then match the filtering rules determined in the steps of the aforementioned embodiment to implement the parsing and filtering of the second protocol layer data, i.e., the application layer data;
[0055] It is understandable that the current kernel state structure can obtain the corresponding protocol type according to the presentation state of the application layer data (currently unparsed).
[0056] Step S108: Packaging and transmitting the parsed and filtered first protocol layer data and second protocol layer data.
[0057] For example, the assembly is performed in sequence according to the distribution order of each protocol layer, and the assembled data packets are filtered to more reliably ensure the security of data transmission between ECU modules.
[0058] In a preferred embodiment of actual application, through the network connection between the user state and the kernel state of the vehicle-mounted host, the filtering rules for the network traffic data packets to be transmitted to the ECU module are received from the user state to the network firewall in the kernel state; the link layer data, network layer data and transport layer data in the network traffic data packets to be transmitted are parsed and filtered through the filtering rules and the hook function in the kernel state; then the corresponding parsing function is searched for the protocol type of the application layer data in the network traffic packet to be transmitted to implement the parsing, and filtering is performed based on the filtering rules; finally, the data of each protocol layer after the parsing and filtering operations are packaged and transmitted to the ECU module.
[0059] In some embodiments, before step S102, it is determined whether the user state and kernel state of the vehicle-mounted host are connected. If they are connected, step S102 is executed; if not, step 1.1) is executed; step 1.1) establishes a network connection between the user state of the vehicle-mounted host and the kernel state of the vehicle-mounted host.
[0060] The vehicle host firewall netfilter creates a network connection between the kernel state and the user state. This network connection is used to receive the filtering rules for each protocol layer data in the network traffic data packet sent by the user state application to the kernel state vehicle host firewall;
[0061] Specifically, the netlink_kernel_create method can be used to build a network connection, as shown in the following code:
[0062] gnlsk_=netlink_kernel_create(&init_net,NETLINK_USER,&cfg);
[0063] In practical applications, it is only necessary to pre-execute step S102 once to obtain filtering rules for each protocol layer data in the network traffic data packet, that is, step S102 is no longer involved in the subsequent ECU data packet filtering process; exemplary step S102 includes:
[0064] Step 2.1), using the kernel state of the vehicle-mounted host in advance, register a callback function for receiving the filtering rules sent by the user state of the vehicle-mounted host.
[0065] Specifically, use the structnetlink_kernel_cfg kernel state structure to register a callback function to receive the firewall rule content sent by the user state application; the registered callback function is netlinkProcessMessage, which is used to receive the firewall filtering rules sent by the user state program to the kernel state firewall. The registration of the callback function can be implemented through the following code:
[0066] struct netlink_kernel_cfgcfg={
[0067] .input=netlinkProcessMessage,
[0068] };
[0069] Step 2.2), based on the callback function, receiving the filtering rules of each protocol layer data in the network traffic data packet to be transmitted.
[0070] Under the action of the callback function and the network connection, the filtering rules for each protocol layer data in the network traffic data packet to be transmitted can be obtained; here, as an optional embodiment, it is possible to determine in real time or at a preset period whether the filtering rules in the kernel state are the current latest filtering rules; if so, execute step S104; if not, execute step 2.2).
[0071] Based on the above-mentioned embodiment, step S104 can parse and filter the first protocol layer data in the network traffic data packet to be transmitted through the kernel state structure, which specifically includes:
[0072] Step 3.1), pre-register the hook function according to the network firewall in the kernel state.
[0073] Using the struct nf_hook_ops structure of the vehicle host firewall netfilter in the kernel state, register the hook function in the structure. The function of the hook function is to guide the data flow in the kernel for subsequent parsing and filtering. The following code can be used to implement the hook function registration:
[0074] nf_blockicmppkt_ops=(struct nf_hook_ops*)kcalloc(1,sizeof(struct nf_hook_ops),GFP_KERNEL);
[0075] nf_blockicmppkt_ops->hook=(nf_hookfn*)validatePacket;
[0076] The validatePacket function registered above is a hook function. After registration, under the action of the hook function, the kernel will intercept and introduce network traffic data packets.
[0077] Step 3.2), based on the hook function, intercept the network traffic data packets to be transmitted.
[0078] After registering the hook function, the network data packets will be directed to the hook function for the execution of subsequent steps.
[0079] Step 3.3), according to the filtering rules of the first protocol layer data in the network traffic data packet, the link layer data, the network layer data and the transport layer data in the network traffic data packet are parsed and filtered respectively.
[0080] Specifically, the hook function uses the struct ethhdr defined in the system to parse the link layer data (the content of the link layer protocol header) in the network traffic data packet, uses the struct iphdr to parse the network layer data (the content of the network layer protocol header) in the network traffic data packet, and uses the struct tcphdr and struct udphdr to parse the transport layer data (the content of the transport layer protocol header) in the network traffic data packet.
[0081] Based on the above embodiment, step S106 may parse and filter the second protocol layer data in the network traffic data packet to be transmitted, including:
[0082] Step 4.1), based on the transport layer data and application layer data in the network traffic data packet to be transmitted, determine the protocol type corresponding to the application layer data in the network traffic data packet.
[0083] Exemplarily, the following steps can be used to determine the application layer parsing type based on the data state when the application layer data is not parsed, and then select the corresponding parsing function to achieve the subsequent parsing and filtering purpose, specifically including:
[0084] Step 4.1.1), based on the comparison consistency between the port number of the transport layer data in the network traffic data packet to be transmitted and the preset port number, determine the first protocol type of the application layer data in the network traffic data packet; wherein the first protocol type includes the DOIP protocol type;
[0085] For example, the preset port number 13400 corresponding to the DOIP protocol is pre-set, and the port number of the transport layer data can be obtained after parsing the transport layer data based on the aforementioned step S104; the port number is compared with the preset port number; if the two are consistent, the application protocol of the application layer data of the current network quantity data packet is the DOIP protocol type, and at this time, the application layer data can be diverted to the parsing function corresponding to the DOIP protocol type for parsing, and there is no need to execute step 4.1.2); if the two are inconsistent, execute step 4.1.2).
[0086] Step 4.1.2), based on the comparison consistency between the target byte content and the preset byte content of the application layer data in the network traffic data packet to be transmitted, determine the second protocol type of the application layer data in the network traffic data packet.
[0087] It is understandable that the application layer data in an unparsed state is generally 50 / 100 bytes of binary or hexadecimal data, and its target byte content can be preliminarily seen, and the target byte content includes data length, protocol version and protocol interface version.
[0088] In actual applications, the target byte content corresponding to the application layer data of the second protocol type can be preset, that is, the preset byte content; the second protocol type includes the DDS protocol type and the SOME / IP protocol type. For example, starting from the fourth byte of the application layer data corresponding to the SOME / IP protocol, four bytes are counted to extract the content representing the data length, the thirteenth byte is the protocol version of SOME / IP, the protocol version of the SOME / IP protocol is 0x01, and the fourteenth byte is the protocol interface version of SOME / IP 0x01; for another example, the first four bytes of the application layer data corresponding to the DDS protocol represent the bytes 'R', 'T', 'P', 'S', and two bytes are taken from the eleventh byte to represent the data length.
[0089] According to the matching of the target byte content of the actual application layer data and the preset byte content, the application layer protocol type corresponding to the current network traffic data packet is determined.
[0090] Step 4.2), according to the filtering rules of the application layer data in the network traffic data packet and the preset parsing function corresponding to the protocol type, the application layer data in the network traffic data packet is parsed and filtered.
[0091] Based on the application layer protocol type determined in the above embodiment, the corresponding parsing function is selected to parse the application layer data, and the application layer data in the network traffic data packet is filtered through the filtering rules of the application layer data. At this point, the vehicle host firewall implements parsing and filtering of all protocol layer data of the network traffic data packet to be transmitted. For example, the validateDoIPPacket function is a parsing function of DoIP. Inside the validateDoIPPacket function, the application layer data of the DoIP application layer protocol is parsed and threat discovery operations are performed.
[0092] In some embodiments, Figure 3 As shown, the network traffic data packet is directed to the kernel-state hook function, and is parsed layer by layer according to the link layer, network layer, and transport layer protocol formats defined by the system; when it comes to application layer data, the protocol type identification method is used to pass the corresponding type of application layer data into the corresponding parsing function, and the parsing function parses the corresponding application layer content and performs threat discovery operations based on the filtering rules corresponding to the application layer data.
[0093] After the data of each protocol layer of the network traffic data packet is parsed and filtered, it is necessary to perform packet assembly and retransmission according to step S108 to ensure transmission reliability, including:
[0094] Step 5.1), the parsed and filtered link layer data, network layer data, transport layer data and application layer data are packaged in turn to obtain the target network traffic data packet filtered by the vehicle host firewall, and then the target network traffic data packet is transmitted to the corresponding ECU module.
[0095] The embodiment of the present invention uses the vehicle-mounted host firewall netfilter technology, uses the internal structure of the firewall to preset rules to filter the link layer, network layer and transport layer data, and uses the hook technology to hook the sub-function in the network, that is, the callback function performs protocol type analysis on the application layer data, and sends it to the corresponding protocol analysis and detection function for protocol analysis and detection according to the identified protocol type. In this way, the host firewall technology and the application layer protocol analysis are combined in one program, realizing fast network data packet filtering and protocol analysis; the whole process is carried out in the kernel, and there is no need to copy the network traffic data packet from the kernel state to the user state, which improves the analysis efficiency of the network traffic data packet.
[0096] In some embodiments, Figure 4 As shown, the embodiment of the present invention also provides a data packet filtering device 200 of a vehicle-mounted host firewall, the device comprising:
[0097] The receiving module 201 receives filtering rules for network traffic data packets to be transmitted, which are sent from the user state of the vehicle-mounted host to the network firewall in the kernel state of the vehicle-mounted host;
[0098] The first filtering module 202 intercepts the network traffic data packet to be transmitted based on the hook function in the kernel state and the filtering rule, and parses and filters the first protocol layer data in the network traffic data packet; wherein the first protocol layer data is link layer data, network layer data and transport layer data;
[0099] The second filtering module 203 parses and filters the second protocol layer data based on the filtering rule and a preset parsing function corresponding to the protocol type of the second protocol layer data in the network traffic data packet; the second protocol layer data is application layer data;
[0100] The packetizing module 204 packets the parsed and filtered first protocol layer data and second protocol layer data and transmits them.
[0101] On the one hand, the embodiments of the present invention are that the programs are all running in the kernel state, and there is no need to copy the network data packets from the kernel state to the user state for application layer protocol analysis, which improves the program efficiency. On the other hand, the functions of the traditional firewall are expanded, so that the program has the firewall's filtering capabilities for the link layer, network layer, and transport layer, and also has the ability to parse and filter the vehicle-mounted application layer protocol.
[0102] Furthermore, the receiving module 201 is specifically used to pre-register a callback function for receiving filtering rules issued by the user state of the vehicle-mounted host using the kernel state of the vehicle-mounted host; based on the callback function, receive filtering rules for each protocol layer data in the network traffic data packet to be transmitted.
[0103] Furthermore, the first filtering module 202 is specifically used to pre-register a hook function according to the network firewall in the kernel state; based on the hook function, intercept the network traffic data packet to be transmitted; and according to the filtering rules of the first protocol layer data in the network traffic data packet, parse and filter the link layer data, network layer data and transport layer data in the network traffic data packet respectively.
[0104] Furthermore, the second filtering module 203 is specifically used to determine the protocol type corresponding to the application layer data in the network traffic data packet based on the transport layer data and application layer data in the network traffic data packet to be transmitted; and to parse and filter the application layer data in the network traffic data packet according to the filtering rules of the application layer data in the network traffic data packet and the preset parsing function corresponding to the protocol type.
[0105] Furthermore, the second filtering module 203 is specifically used to determine the first protocol type of the application layer data in the network traffic data packet to be transmitted based on the comparison consistency between the port number of the transport layer data in the network traffic data packet to be transmitted and the preset port number; wherein the first protocol type includes the DOIP protocol type; based on the comparison consistency between the target byte content of the application layer data in the network traffic data packet to be transmitted and the preset byte content, determine the second protocol type of the application layer data in the network traffic data packet; wherein the target byte content includes data length, protocol version and protocol interface version; the second protocol type includes the DDS protocol type and the SOME / IP protocol type.
[0106] Furthermore, the packet assembly module 204 is specifically used to sequentially assemble the parsed and filtered link layer data, network layer data, transport layer data and application layer data to obtain the target network traffic data packet filtered by the vehicle-mounted host firewall, and then transmit the target network traffic data packet to the corresponding ECU module.
[0107] Furthermore, before the step of receiving the filtering rules for the network traffic data packets to be transmitted sent from the user state to the network firewall in the kernel state, the device is also used to establish a network connection between the user state of the vehicle-mounted host and the kernel state of the vehicle-mounted host.
[0108] Figure 5 Schematic diagram of the hardware architecture of the electronic device 300 provided in an embodiment of the present invention. Figure 5 As shown, the electronic device 300 includes: a machine-readable storage medium 301 and a processor 302, and may also include a non-volatile storage medium 303, a communication interface 304 and a bus 305; wherein the machine-readable storage medium 301, the processor 302, the non-volatile storage medium 303 and the communication interface 304 complete mutual communication through the bus 305. The processor 302 can execute the method for filtering data packets of the vehicle-mounted host firewall described in the above embodiment by reading and executing the machine-executable instructions for filtering data packets of the vehicle-mounted host firewall in the machine-readable storage medium 301.
[0109] The machine-readable storage medium mentioned in this article can be any electronic, magnetic, optical or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium can be: RAM (Radom Access Memory), volatile memory, non-volatile memory, flash memory, storage drive (such as hard disk drive), any type of storage disk (such as CD, DVD, etc.), or similar storage medium, or a combination thereof.
[0110] The non-volatile medium may be a non-volatile memory, a flash memory, a storage drive (such as a hard drive), any type of storage disk (such as a CD, DVD, etc.), or a similar non-volatile storage medium, or a combination thereof.
[0111] It can be understood that the specific operation methods of each functional module in this embodiment can refer to the detailed description of the corresponding steps in the above method embodiment, and will not be repeated here.
[0112] The computer-readable storage medium provided in the embodiment of the present invention stores a computer program. When the computer program code is executed, the data packet filtering method of the vehicle-mounted host firewall described in any of the above embodiments can be implemented. The specific implementation can be found in the method embodiment, which will not be repeated here.
[0113] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system and device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0114] In addition, in the description of the embodiments of the present invention, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0115] In the description of the present invention, it should be noted that the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc., indicating the orientation or positional relationship, are based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as limiting the present invention. In addition, the terms "first", "second", and "third" are used for descriptive purposes only, and cannot be understood as indicating or implying relative importance.
[0116] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present invention, which are used to illustrate the technical solutions of the present invention rather than to limit them. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the aforementioned embodiments, those of ordinary skill in the art should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the aforementioned embodiments within the technical scope disclosed by the present invention, or can easily conceive of changes, or make equivalent replacements for some of the technical features therein. Such modifications, changes or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the protection scope of the present invention.
Claims
1. A data packet filtering method for a vehicle-mounted host firewall, characterized in that: The method comprises: Receiving filtering rules for network traffic data packets to be transmitted, which are sent from the user state of the vehicle-mounted host to the network firewall in the kernel state of the vehicle-mounted host; Based on the hook function in the kernel state and the filtering rules, the network traffic data packet to be transmitted is intercepted, and the first protocol layer data in the network traffic data packet is parsed and filtered; wherein the first protocol layer data is link layer data, network layer data and transport layer data; Parsing and filtering the second protocol layer data based on the filtering rule and a preset parsing function corresponding to the protocol type of the second protocol layer data in the network traffic data packet; the second protocol layer data is application layer data; The parsed and filtered first protocol layer data and second protocol layer data are packaged and transmitted.
2. The method according to claim 1, characterized in that The step of receiving the filtering rules for the network traffic data packets to be transmitted sent by the network firewall in the user state of the vehicle-mounted host to the kernel state of the vehicle-mounted host, comprises: Using the kernel state of the vehicle host in advance, register a callback function for receiving the filtering rules sent by the user state of the vehicle host; Based on the callback function, filtering rules for each protocol layer data in the network traffic data packet to be transmitted are received.
3. The method according to claim 1, characterized in that Based on the hook function in the kernel state and the filtering rule, the steps of intercepting the network traffic data packet to be transmitted and parsing and filtering the first protocol layer data in the network traffic data packet include: Pre-registering a hook function according to the network firewall in the kernel state; Based on the hook function, intercepting the network traffic data packet to be transmitted; According to the filtering rules of the first protocol layer data in the network traffic data packet, the link layer data, the network layer data and the transport layer data in the network traffic data packet are parsed and filtered respectively.
4. The method according to claim 1, characterized in that The step of parsing and filtering the second protocol layer data based on the filtering rule and a preset parsing function corresponding to the protocol type of the second protocol layer data in the network traffic data packet comprises: Determine, based on the transport layer data and the application layer data in the network traffic data packet to be transmitted, the protocol type corresponding to the application layer data in the network traffic data packet; According to the filtering rules of the application layer data in the network traffic data packet and the preset parsing function corresponding to the protocol type, the application layer data in the network traffic data packet is parsed and filtered.
5. The method according to claim 4, characterized in that The step of determining the protocol type corresponding to the application layer data in the network traffic data packet based on the transport layer data and the application layer data in the network traffic data packet to be transmitted comprises: Determine the first protocol type of the application layer data in the network traffic data packet based on the comparison consistency between the port number of the transport layer data in the network traffic data packet to be transmitted and the preset port number; wherein the first protocol type includes the DOIP protocol type; Based on the comparison consistency between the target byte content and the preset byte content of the application layer data in the network traffic data packet to be transmitted, the second protocol type of the application layer data in the network traffic data packet is determined; wherein the target byte content includes data length, protocol version and protocol interface version; the second protocol type includes DDS protocol type and SOME / IP protocol type.
6. The method according to claim 1, characterized in that The step of packaging and transmitting the parsed and filtered first protocol layer data and second protocol layer data comprises: The parsed and filtered link layer data, network layer data, transport layer data and application layer data are packaged in turn to obtain the target network traffic data packet filtered by the vehicle host firewall, and then the target network traffic data packet is transmitted to the corresponding ECU module.
7. The method according to claim 1, characterized in that Before the step of receiving the filtering rules for the network traffic data packets to be transmitted sent from the user state to the network firewall in the kernel state, the method further includes: Establish a network connection between the user state of the vehicle host and the kernel state of the vehicle host.
8. A data packet filtering device for a vehicle-mounted host firewall, characterized in that: The device comprises: A receiving module receives filtering rules for network traffic data packets to be transmitted, which are sent from the user state of the vehicle-mounted host to the network firewall in the kernel state of the vehicle-mounted host; A first filtering module, based on the hook function in the kernel state and the filtering rule, intercepts the network traffic data packet to be transmitted, and parses and filters the first protocol layer data in the network traffic data packet; wherein the first protocol layer data is link layer data, network layer data and transport layer data; A second filtering module, based on the filtering rule and a preset parsing function corresponding to the protocol type of the second protocol layer data in the network traffic data packet, parses and filters the second protocol layer data; the second protocol layer data is application layer data; The packet assembly module assembles and transmits the parsed and filtered first protocol layer data and second protocol layer data.
9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program that can be run on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A machine-readable storage medium, characterized in that: The machine-readable storage medium stores machine-executable instructions. When the machine-executable instructions are called and executed by a processor, the machine-executable instructions prompt the processor to implement the steps of the method described in any one of claims 1 to 7.