Method and device for evaluating influence of network attack on vehicle network layer CAN bus

By building a CAN bus attack impact model, quantifying the impact of network attacks on the CAN bus network layer of vehicle information physical system, solving the problem of network attack evaluation in the existing technology and improving the effectiveness of network attack defense.

CN119996064AActive Publication Date: 2025-05-13CHONGQING UNIV
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510390523.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-05-13
Estimated Expiration
2045-03-31

AI Technical Summary

Technical Problem

The existing in-vehicle network communication protocols, especially the CAN bus protocol, lack privacy and security protection mechanisms, making it difficult to evaluate and prevent the impact of network attacks on the vehicle network layer.

Method used

By acquiring the system communication model of the vehicle information physical system, the real transmission data of the CAN bus in the network attack state is determined, and compared with the reference transmission data in the state without the network attack state, the data is processed based on evaluation rules to quantify the impact of the network attack on the availability and integrity of the CAN bus, and a CAN bus attack impact model is constructed.

Benefits of technology

Effectively evaluate the impact of network attacks on the CAN bus of the network layer of the vehicle information physical system, predict the changing trends of future attack impacts, and thus take targeted preventive measures to improve the defense effect of network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996064A_ABST
    Figure CN119996064A_ABST
Patent Text Reader

Abstract

The invention relates to the field of network security, and relates to a method and equipment for evaluating the influence of network attack on a vehicle network layer CAN bus. The method for evaluating the influence of the network attack on the vehicle network layer CAN bus comprises the following steps: acquiring a system communication model of a vehicle information physical system; determining real transmission data when the vehicle exchanges information through the CAN bus in a network attack state according to the system communication model; acquiring reference transmission data; processing the real transmission data and the reference transmission data based on a first evaluation rule to obtain influence information of the network attack on the availability of the CAN bus; processing the real transmission data based on a second evaluation rule to obtain influence information of the network attack on the integrity of the CAN bus; and determining an attack influence evaluation result of the vehicle information physical system according to the influence information of the network attack on the availability of the CAN bus and the influence information of the network attack on the integrity of the CAN bus. According to the method, the influence of the network attack on the CAN bus of the vehicle information physical system can be effectively and quantitatively evaluated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular to a method and device for evaluating the impact of network attacks on a vehicle network layer CAN bus. Background Art

[0002] The rapid development of radio frequency identification technology (RFID), sensor technology and communication technology in recent years has accelerated the process of intelligentization and informatization of automobiles and transportation, and promoted the development of "intelligent transportation" (i.e., providing diversified services for traffic participants with the collection, processing, release, exchange, analysis and utilization of information as the main line). Modern vehicles are equipped with more automated modules, in which the vehicles are autonomous and less controlled by the driver. Although the safety of the vehicle is critical in all aspects, computer failure may cause vehicle chaos. All submodules of the transmission system, steering system and electrical system are controlled by electronic control units (ECUs). Modern vehicles usually contain hundreds of ECUs, which are connected together and communicate with each other through a common bus called CAN, enabling them to work at high speed to ensure the driving safety and entertainment performance of the car.

[0003] While in-vehicle networks provide benefits by providing connectivity, they also present opportunities for cyberattacks. While the Internet of Vehicles introduces intelligent services such as the Internet and big data analysis into vehicles through external communication interfaces, it also introduces potential risks of network intrusion. The closed nature of traditional in-vehicle networks has resulted in existing in-vehicle network communication protocols, especially the most widely deployed CAN bus protocol, lacking privacy and security protection mechanisms including access control, authentication, and encryption when they are released. Due to the lack of access control mechanisms, attackers can directly invade the in-vehicle network by breaking through external interfaces, causing information leakage, stealing money, and even threatening personal safety. Summary of the invention

[0004] The present application aims to at least solve the technical problems existing in the prior art and provide a method and device for evaluating the impact of network attacks on the CAN bus of the vehicle network layer.

[0005] In a first aspect, the present invention provides a method for evaluating the impact of a network attack on a vehicle network layer CAN bus, comprising:

[0006] Obtaining a system communication model of a vehicle cyber-physical system;

[0007] Determine the real transmission data when vehicles exchange information through the CAN bus under the network attack state based on the system communication model;

[0008] Obtain reference transmission data, where the reference transmission data is used to represent CAN bus message transmission information in a state without network attack;

[0009] Based on the first evaluation rule, the real transmission data and the reference transmission data are processed to obtain information on the impact of the network attack on the availability of the CAN bus, where the availability of the CAN bus represents the transmission ratio of the CAN bus to valid messages, and the valid messages represent messages sent by nodes inside the vehicle;

[0010] Based on the second evaluation rule, the real transmission data is processed to obtain the impact information of the network attack on the integrity of the CAN bus. The integrity of the CAN bus indicates the transmission ratio of the valid messages whose contents have not been modified by the CAN bus.

[0011] According to the impact information of network attacks on the availability of CAN bus and the impact information of network attacks on the integrity of CAN bus, a CAN bus attack impact model is constructed to obtain the attack impact assessment results of the vehicle cyber-physical system.

[0012] In a second aspect, the present invention provides an electronic device, the electronic device comprising:

[0013] at least one processor; and,

[0014] a memory communicatively connected to the at least one processor; wherein,

[0015] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the above-mentioned method for evaluating the impact of the network attack on the vehicle network layer CAN bus.

[0016] In summary, this application includes the following beneficial technical effects:

[0017] This application considers the different impacts of attacks on the CAN bus. Starting from the two dimensions of CAN bus availability and CAN bus integrity, the impact of network attacks on the bus is divided into the impact on bus availability and the impact on bus integrity. The impact of CAN bus availability and the impact on CAN bus integrity are calculated using real transmission data and reference transmission data, and the impact of network attacks on the network layer CAN bus of the vehicle information physical system is effectively quantified and evaluated, solving the problem that the cross-effect of attacks is difficult to quantify.

[0018] According to the CAN bus attack impact model, the changes in attack impacts over a period of time can be obtained, which helps to predict the changing trend of future attack impacts, so as to take targeted preventive measures and improve the effectiveness of network attack defense. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 A flow chart of a method for evaluating the impact of a network attack on a vehicle network layer CAN bus provided by an embodiment of the present invention;

[0020] Figure 2 A system architecture diagram of a vehicle cyber-physical system provided in one embodiment of the present invention;

[0021] Figure 3 A schematic diagram of the structure of an electronic device for implementing a method for evaluating the impact of a network attack on a vehicle network layer CAN bus provided by an embodiment of the present invention.

[0022] Reference numerals: 10, processor; 11, memory; 12, communication bus; 13, communication interface.

[0023] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0024] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and cannot be understood as limiting the present invention.

[0025] In the description of the present invention, it is necessary to understand that the terms "longitudinal", "lateral", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating the orientation or position relationship, are based on the orientation or position relationship shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on the present invention.

[0026] In the description of the present invention, unless otherwise specified and limited, it should be noted that the terms "installed", "connected" and "connected" should be understood in a broad sense. For example, it can be a mechanical connection or an electrical connection, or it can be the internal connection between two components. It can be a direct connection or an indirect connection through an intermediate medium. For ordinary technicians in this field, the specific meanings of the above terms can be understood according to the specific circumstances.

[0027] Reference Figure 1 FIG. 1 is a flow chart of a method for evaluating the impact of a network attack on a vehicle network layer CAN bus provided by an embodiment of the present invention. In this embodiment, the method for evaluating the impact of a network attack on a vehicle network layer CAN bus includes:

[0028] S1. Obtain a system communication model of a vehicle cyber-physical system.

[0029] Reference Figure 2The architecture of the vehicle cyber-physical system includes attackers and several internal nodes of the vehicle, which are connected by CAN bus; the internal nodes of the vehicle include sensors, controllers and actuators, etc. The attackers can be hackers, car theft gangs and / or terrorists' corresponding devices, etc. Different attackers will launch different types of attacks. DoS attacks will destroy availability, and deception attacks / replay attacks will destroy integrity.

[0030] The nodes inside the vehicle communicate with each other through the CAN bus. Specifically, the CAN network adopts an arbitration mechanism for the information sent. The messages sent by the internal nodes of the car with high priority will be sent first, and only one message will be sent at a time. After the current message is sent, the next message to be sent will be selected from the arbitration between the nodes to be sent. The CAN bus sends messages in a broadcast mode, and all the internal nodes of the vehicle can know the sent messages.

[0031] Based on the characteristics of the CAN bus arbitration mechanism, an attacker can create a high-priority fake internal node to send a large number of useless messages (such as DoS attacks, which are short for Denial of Service Attack in English and “denial of service attacks” in Chinese), causing delays in messages sent by internal nodes on the CAN bus. In severe cases, messages cannot even be sent, causing the vehicle’s cyber-physical system to be unable to make decisions in a timely manner, thus destroying the bus availability. Based on the characteristics of the CAN bus broadcast, an attacker can also obtain and modify the value of the transmitted message, which will cause the message sent by the vehicle’s internal node to be modified, causing the vehicle’s cyber-physical system to make wrong decisions and destroying the integrity of the bus.

[0032] According to the communication mechanism of the vehicle cyber-physical system, the system communication model of the vehicle cyber-physical system is built. According to the characteristics of the CAN bus, the relationship between the CAN bus, the internal nodes of the car and the attacker is constructed:

[0033] Specifically, when building the system communication model, the system communication model is constructed based on the number of nodes inside the vehicle, priority, message sending cycle, number and value of messages transmitted inside the CAN bus, attacker attack frequency and attack time, etc. The system communication model is the basis of the method for assessing the impact of attacks on the CAN bus of the network layer of the vehicle's cyber-physical system. The bus availability and integrity are calculated based on the messages transmitted on the bus in the model and the attacker's attack method and time.

[0034] In this embodiment, the system communication model is defined as

[0035] BS={Im,{B1,B2,…,B m ,…,B n}}

[0036] Among them, BS{.} represents the system communication model, Im is the message set of the vehicle internal nodes that have been successfully transmitted by the CAN bus so far, and B m is the message of the internal node of the vehicle sent by the CAN bus, m is the message index of the internal node of the vehicle sent by the CAN bus, n represents the total number of messages of the internal node of the vehicle successfully transmitted by the CAN bus so far, and n is a positive integer greater than or equal to 1;

[0037] B m It can be defined as

[0038] B m = {Ns m ,Vm m}

[0039] Among them, Ns m is the number of the node that sent the message m, Vm m is the size of the value passed in message m.

[0040] S2. Determine the actual transmission data when the vehicle exchanges information through the CAN bus under the network attack state according to the system communication model.

[0041] The actual transmission data includes the messages successfully sent per unit time on the CAN bus in the vehicle's cyber-physical system under a cyber attack state.

[0042] S3. Obtain reference transmission data.

[0043] The reference transmission data is used to represent the CAN bus message transmission information in the state without network attack. The reference transmission data includes the messages successfully sent per unit time of the CAN bus in the vehicle information-physical system in the state without network attack. The reference transmission data can be imported by the staff through an external device or obtained through a cloud system. This application does not restrict the method of obtaining the reference transmission data. Network attacks will cause changes in the system communication model BS. The impact of network attacks on the CAN bus is obtained by calculating the normal values ​​and abnormal values ​​of the system communication model, and an attack impact model is constructed.

[0044] S4. Process the real transmission data and the reference transmission data based on the first evaluation rule to obtain information on the impact of the network attack on the availability of the CAN bus.

[0045] CAN bus availability refers to the transmission ratio of the CAN bus to valid messages, where valid messages refer to messages sent by nodes inside the vehicle.

[0046] Since different attack methods may cause different impacts, and too many indicator calculations will increase the complexity of analysis and affect the accuracy of evaluation, some indicators are selected for evaluation. Most attacks can be divided into interruption attacks that affect availability and target deception attacks that affect integrity, or a mixture of the two attacks. Therefore, the availability and integrity indicators of the CAN bus are selected for evaluation.

[0047] For availability, four indicators are selected for evaluation: the number of internal messages successfully sent per unit time on the CAN bus in the vehicle information-physical system under network attack and non-network attack conditions, and the number of all messages successfully sent per unit time on the CAN bus under network attack and non-network attack conditions.

[0048] Specifically, the real transmission data and the reference transmission data are processed based on the first evaluation rule to obtain the impact information of the network attack on the availability of the CAN bus, including:

[0049] S41. Filter out valid messages successfully sent per unit time by the CAN bus under the network attack state from the real transmission data.

[0050] S42. Determine the actual availability of the CAN bus according to the proportion of valid messages successfully sent per unit time by the CAN bus in the actual transmission data under the network attack state.

[0051] S43. Filter out valid messages successfully sent by the CAN bus within a unit time in a state without network attack from the reference transmission data.

[0052] S44. Determine the expected availability of the CAN bus according to the proportion of valid messages successfully sent per unit time by the CAN bus in the reference transmission data in a state without network attacks.

[0053] S45. Determine information on the impact of the network attack on the availability of the CAN bus according to the actual availability of the CAN bus and the expected availability of the CAN bus.

[0054] The actual availability of the CAN bus is calculated by the ratio of the number of valid messages transmitted per unit time in the vehicle cyber-physical system to the number of all messages transmitted on the bus under attack conditions and the ratio of the number of valid messages transmitted per unit time in the vehicle cyber-physical system to the number of all messages transmitted on the bus under normal conditions. At time t a When , the calculation formula of the actual availability ABA of the CAN bus is:

[0055]

[0056] Among them, lra(t a ) is t in the network attack state a-1Time to t a The ratio of the bus occupied by effective message transmission within a certain time, lra(t a )∈[0,1];

[0057] lre(t a ) is the state without network attack a-1 to a The ratio of the valid messages in the real transmission data occupied by the CAN bus within a certain time, lre(t a )∈[0,1];

[0058] Im(t a ) is the actual situation to t a The total number of vehicle cyber-physical system internal messages successfully transmitted by the bus at this moment. Vehicle cyber-physical system internal messages refer to valid messages sent by internal nodes of the vehicle;

[0059] To t in the case of no network attack a The total number of messages within the vehicle cyber-physical system that have been successfully transmitted by the bus at this moment;

[0060] Im(t a-1 ) is the actual situation to t a-1 The total number of internal messages of the vehicle cyber-physical system that have been successfully transmitted by the bus at this moment;

[0061] To t in the case of no network attack a-1 The total number of messages within the vehicle's cyber-physical system that have been successfully transmitted by the bus at this moment.

[0062] It should be noted that t a It just represents a certain moment; the moment t a-1 At time t a It is a unit time, for example, the unit time is 1 second or 5 seconds. Different time intervals can be divided according to needs to obtain the dynamic impact of network attacks under different time conditions.

[0063] The impact of network attacks on the availability of the CAN bus is represented by the difference between the actual availability of the CAN bus and the expected availability of the CAN bus.

[0064] At time t in the non-attack network state a The expected bus availability EBA is defined as:

[0065]

[0066]

[0067] The impact of network attack on CAN bus availability is denoted as IBA, and at time t a Impact of cyber attacks on CAN bus availability IBA(t a ) is:

[0068]

[0069] The degree of influence of the network attack on the availability of the CAN bus of the automobile information-physical system is determined according to the specific value of the information IBA of the influence of the network attack on the availability of the CAN bus. In this embodiment, the proportion of the effective information in the automobile information-physical system that is blocked can be determined according to the value of IBA. The specific determination method is shown in Table 1.

[0070] Table 1 Impact of cyber attacks on bus availability of automotive cyber-physical systems

[0071]

[0072] The degree of impact of the network attack on the availability of the CAN bus includes multiple levels, and the level of impact of the network attack on the availability of the CAN bus is determined according to the difference IBA between the actual availability of the CAN bus and the expected availability of the CAN bus.

[0073] The level of impact can be set according to the actual judgment progress requirement. In this embodiment, the impact level of CAN bus availability includes 7 levels: no impact, slight impact, mild impact, moderate impact, high impact, severe impact and complete impact. The impact level is determined according to the specific value of IBA. The specific judgment rules can be referred to Table 2:

[0074] Table 2 Impact of network attacks on bus availability

[0075]

[0076] The specific threshold ranges for each level of the CAN bus availability impact degree may be set according to actual needs, and this embodiment does not impose any limitation thereto.

[0077] S5. Process the real transmission data based on the second evaluation rule to obtain information about the impact of the network attack on the integrity of the CAN bus.

[0078] CAN bus integrity refers to the transmission ratio of valid messages whose contents have not been modified on the CAN bus.

[0079] For integrity, the number of valid messages that have not been modified and successfully sent per unit time on the CAN bus in the automotive information-physical system under non-network attack conditions and actual conditions is selected, and evaluated using four indicators: the number of valid messages successfully sent per unit time on the CAN bus under non-network attack conditions and actual conditions.

[0080] Specifically, based on the second evaluation rule, the real transmission data is processed to obtain the impact information of the network attack on the integrity of the CAN bus, including:

[0081] S51. Filter out valid messages whose contents are not modified and are successfully sent per unit time by the CAN bus under the network attack state from the real transmission data.

[0082] S52. Determine the actual integrity of the CAN bus according to the proportion of valid messages whose contents have not been modified and successfully sent per unit time by the CAN bus in the network attack state in the actual transmission data.

[0083] S53. Filter out valid messages whose contents are not modified and are successfully sent per unit time by the CAN bus under the network attack state from the reference transmission data.

[0084] S54. Determine the expected integrity of the CAN bus according to the proportion of valid messages whose contents have not been modified and successfully sent per unit time by the CAN bus in a state without network attacks in the reference transmission data.

[0085] S55. Determine information on the impact of the network attack on the integrity of the CAN bus based on the actual integrity of the CAN bus and the expected integrity of the CAN bus.

[0086] The actual integrity of the CAN bus is recorded as ABI, t a The actual integrity of the CAN bus at the moment ABI (t a ) is calculated as:

[0087]

[0088] Among them, mt s (t a ) represents the CAN bus at t a-1 to a The number of all messages in the vehicle's cyber-physical system that are transmitted at any given moment;

[0089] mt m (t a ) represents the CAN bus at t a-1 to a The number of valid messages transmitted at any time that have not been modified;

[0090] Im s (t a ) until t a The number of valid messages successfully transmitted at any moment;

[0091] Im s (t a-1 ) until ta-1 The number of valid messages successfully transmitted at any moment;

[0092] Rv is the expected value of the message transmitted by the automotive cyber-physical system in the non-attack state;

[0093] Sv is the actual value of the message transmitted by the vehicle's cyber-physical system in actual situations.

[0094] The expected integrity of the CAN bus without network attacks is recorded as EBI, t a Expected CAN bus integrity EBI at time (t a ) is calculated as:

[0095]

[0096] The impact of network attacks on the integrity of the CAN bus is represented by the difference between the actual integrity of the CAN bus and the expected integrity of the CAN bus.

[0097] The impact of network attacks on the integrity of the CAN bus is recorded as IBI, at time t a Impact of network attacks on bus integrity IBI(t a ) is calculated as:

[0098]

[0099] The degree of influence of the network attack on the integrity of the CAN bus of the automobile information-physical system is determined according to the specific value of the information EBI of the influence of the network attack on the integrity of the CAN bus. In this embodiment, the proportion of the modified valid information in the automobile information-physical system can be determined according to the value of EBI. The specific determination method is shown in Table 3.

[0100] Table 3 Impact of cyber attacks on the bus integrity of automotive cyber-physical systems

[0101]

[0102] The impact of a network attack on the integrity of the CAN bus includes multiple levels, and the level of the impact of a network attack on the integrity of the CAN bus is determined by the difference between the actual integrity of the CAN bus and the expected integrity of the CAN bus.

[0103] The level of impact of the CAN bus integrity can be set according to the actual judgment progress requirement. In this embodiment, the impact level of the CAN bus integrity includes 7 levels: no impact, slight impact, mild impact, moderate impact, high impact, severe impact and complete impact. The impact level is determined according to the specific value of IBI. The specific judgment rules can refer to Table 4:

[0104] Table 4 Impact of network attacks on bus integrity

[0105]

[0106]

[0107] The specific threshold ranges for each level of the CAN bus integrity impact degree may be set according to actual needs, and this embodiment does not impose any limitation thereto.

[0108] S6. Construct a CAN bus attack impact model based on the impact information of network attacks on the availability of the CAN bus and the impact information of network attacks on the integrity of the CAN bus to obtain the attack impact assessment results of the vehicle cyber-physical system.

[0109] The CAN bus attack impact model is represented in a matrix form. Specifically, the expression of the CAN bus impact change matrix IAS corresponding to the CAN bus attack impact model is:

[0110]

[0111] IAS is the impact change matrix of cyber attacks on the CAN bus of the automotive cyber-physical system. IAS can represent the change matrix of the impact of cyber attacks on the CAN bus of the automotive cyber-physical system at t0-t n The impact of cyber attacks on the availability of the CAN bus of the automotive cyber-physical system IBA at time t0-t n The impact of the network on the integrity of the CAN bus of the automotive cyber-physical system (IBI) can be observed through the IAS matrix to observe the changes in the impact of the attack over a period of time.

[0112] By analyzing the changes in the impact of different attacks at different times, it will help processing personnel better understand the impact of network attacks on the CAN bus, help formulate targeted optimization protection strategies, and improve the safety of the car.

[0113] This application starts from the two dimensions of CAN bus availability and CAN bus integrity, divides the impact of network attacks on the bus into the impact on bus availability and the impact on bus integrity, and calculates them through evaluation indicators, solving the problem that the cross-impact of attacks is difficult to quantify.

[0114] In addition, the technical solution of the present application can obtain the changes in attack impacts over a period of time based on the impact change matrix of the CAN bus of the automotive cyber-physical system, and construct a CAN bus attack assessment model based on dynamic coupling analysis, which helps to predict the changing trends of future attack impacts, so as to take targeted preventive measures.

[0115] Reference Figure 3 Based on the same inventive concept, the present application also discloses an electronic device, such as Figure 3, which is a schematic diagram of the structure of an electronic device for a method for evaluating the impact of a network attack on a vehicle network layer CAN bus provided by an embodiment of the present invention. The electronic device may include at least one processor 10, a memory 11 connected to the at least one processor for communication, a communication bus 12, and a communication interface 13, and may also include a computer program stored in the memory 11 and executable on the processor 10, such as a program for evaluating the impact of a network attack on a vehicle network layer CAN bus.

[0116] Among them, the processor 10 can be composed of an integrated circuit in some embodiments, for example, it can be composed of a single packaged integrated circuit, or it can be composed of multiple integrated circuits with the same function or different functions, including one or more central processing units (CPU), microprocessors, digital processing chips, graphics processors and various control chips. The processor 10 is the control core (Control Unit) of the electronic device, which uses various interfaces and lines to connect various components of the entire electronic device, and executes or executes programs or modules stored in the memory 11 (for example, executing an evaluation method for the impact of network attacks on the vehicle network layer CAN bus, etc.), and calls data stored in the memory 11 to execute various functions of the electronic device and process data.

[0117] The memory 11 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, mobile hard disk, multimedia card, card-type memory (for example: SD or DX memory, etc.), magnetic memory, disk, optical disk, etc. In some embodiments, the memory 11 can be an internal storage unit of an electronic device, such as a mobile hard disk of the electronic device. In other embodiments, the memory 11 can also be an external storage device of an electronic device, such as a plug-in mobile hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. equipped on the electronic device. Further, the memory 11 can also include both an internal storage unit of the electronic device and an external storage device. The memory 11 can not only be used to store application software and various types of data installed in the electronic device, such as the code of the evaluation method program for the impact of network attacks on the vehicle network layer CAN bus, but can also be used to temporarily store data that has been output or is to be output.

[0118] The communication bus 12 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. The bus is configured to realize connection and communication between the memory 11 and at least one processor 10, etc.

[0119] The communication interface 13 is used for communication between the above-mentioned electronic device and other devices, including a network interface and a user interface. Optionally, the network interface may include a wired interface and / or a wireless interface (such as a WI-FI interface, a Bluetooth interface, etc.), which is generally used to establish a communication connection between the electronic device and other electronic devices. The user interface may be a display (Display), an input unit (such as a keyboard (Keyboard)), and optionally, the user interface may also be a standard wired interface, a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, and an OLED (Organic Light-Emitting Diode, organic light-emitting diode) touch device, etc. Among them, the display may also be appropriately referred to as a display screen or a display unit, which is used to display information processed in the electronic device and to display a visual user interface.

[0120] Figure 3 Only an electronic device with components is shown, and those skilled in the art will understand that Figure 3 The structure shown does not constitute a limitation on the electronic device, and may include fewer or more components than shown, or combine certain components, or arrange the components differently. For example, although not shown, the electronic device may also include a power supply (such as a battery) for supplying power to each component. Preferably, the power supply may be logically connected to at least one processor 10 through a power management device, so that functions such as charging management, discharging management, and power consumption management are implemented through the power management device. The power supply may also include any components such as one or more DC or AC power supplies, recharging devices, power failure detection circuits, power converters or inverters, power status indicators, etc. The electronic device may also include a variety of sensors, Bluetooth modules, Wi-Fi modules, etc., which will not be repeated here.

[0121] It should be understood that the embodiment is for illustration only and the scope of the patent application is not limited by this structure.

[0122] Furthermore, if the module / unit integrated in the electronic device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. The computer-readable storage medium can be volatile or non-volatile.

[0123] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", "an implementation", "a preferred implementation" or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0124] Although the embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.

Claims

1. A method for evaluating the impact of network attacks on the CAN bus of a vehicle network layer, characterized in that: The method comprises: Obtaining a system communication model of a vehicle cyber-physical system; Determine the real transmission data when vehicles exchange information through the CAN bus under the network attack state based on the system communication model; Obtain reference transmission data, where the reference transmission data is used to represent CAN bus message transmission information in a state without network attack; Based on the first evaluation rule, the real transmission data and the reference transmission data are processed to obtain information on the impact of the network attack on the availability of the CAN bus, where the availability of the CAN bus represents the transmission ratio of the CAN bus to valid messages, and the valid messages represent messages sent by nodes inside the vehicle; Based on the second evaluation rule, the real transmission data is processed to obtain the impact information of the network attack on the integrity of the CAN bus. The integrity of the CAN bus indicates the transmission ratio of the valid messages whose contents have not been modified by the CAN bus. According to the impact information of network attacks on the availability of CAN bus and the impact information of network attacks on the integrity of CAN bus, a CAN bus attack impact model is constructed to obtain the attack impact assessment results of the vehicle cyber-physical system.

2. The method for evaluating the impact of a network attack on a vehicle network layer CAN bus as claimed in claim 1, characterized in that: The real transmission data includes the messages successfully sent by the CAN bus within a unit time under the network attack state; the reference transmission data includes the messages successfully sent by the CAN bus within a unit time under the non-network attack state.

3. The method for evaluating the impact of a network attack on a vehicle network layer CAN bus as claimed in claim 2, characterized in that: The processing of the real transmission data and the reference transmission data based on the first evaluation rule to obtain information on the impact of the network attack on the availability of the CAN bus includes: Filter out valid messages successfully sent per unit time on the CAN bus under the network attack state from the real transmission data; The actual availability of the CAN bus is determined based on the proportion of valid messages successfully sent per unit time in the actual transmission data of the CAN bus under the network attack state; Filter out valid messages successfully sent per unit time on the CAN bus in a state without network attacks from the reference transmission data; The expected availability of the CAN bus is determined according to the proportion of valid messages successfully sent per unit time by the CAN bus in the reference transmission data in the absence of network attacks; The impact of network attacks on the availability of the CAN bus is determined based on the actual availability of the CAN bus and the expected availability of the CAN bus.

4. The method for evaluating the impact of a network attack on a vehicle network layer CAN bus as claimed in claim 3 is characterized in that: The impact of network attacks on the availability of the CAN bus is represented by the difference between the actual availability of the CAN bus and the expected availability of the CAN bus.

5. The method for evaluating the impact of a network attack on a vehicle network layer CAN bus as claimed in claim 4, characterized in that: The impact of cyber attacks on CAN bus availability includes multiple levels; The method further includes: determining the level of influence of the network attack on the availability of the CAN bus according to the difference between the actual availability of the CAN bus and the expected availability of the CAN bus.

6. The method for evaluating the impact of a network attack on a vehicle network layer CAN bus as claimed in claim 2, characterized in that: The processing of the real transmission data based on the second evaluation rule to obtain the impact information of the network attack on the integrity of the CAN bus includes: Filter out valid messages whose contents have not been modified and are successfully sent per unit time by the CAN bus under the network attack state from the real transmission data; The actual integrity of the CAN bus is determined based on the proportion of valid messages with unmodified content that are successfully sent per unit time in the CAN bus under network attack conditions in the actual transmission data; Filter out valid messages whose contents are not modified and are successfully sent per unit time on the CAN bus under the network attack state from the reference transmission data; The expected integrity of the CAN bus is determined based on the proportion of valid messages with unmodified content successfully sent per unit time in the reference transmission data under the condition of no network attack; The impact of network attacks on the integrity of the CAN bus is determined based on the actual integrity of the CAN bus and the expected integrity of the CAN bus.

7. The method for evaluating the impact of a network attack on a vehicle network layer CAN bus as claimed in claim 6, characterized in that: The impact of network attacks on the integrity of the CAN bus is represented by the difference between the actual integrity of the CAN bus and the expected integrity of the CAN bus.

8. The method for evaluating the impact of a network attack on a vehicle network layer CAN bus as claimed in claim 7, characterized in that: The impact of cyber attacks on the integrity of the CAN bus includes multiple levels; The method further includes: determining the level of influence of the network attack on the integrity of the CAN bus by the difference between the actual integrity of the CAN bus and the expected integrity of the CAN bus.

9. The method for evaluating the impact of a network attack on a vehicle network layer CAN bus according to any one of claims 1 to 8, characterized in that: The CAN bus attack impact model includes the impact information of network attacks on the CAN bus availability and the impact information of the CAN bus integrity at different times.

10. An electronic device, characterized in that: The electronic device comprises: at least one processor (10); and, a memory (11) communicatively connected to the at least one processor (10); The memory (11) stores a computer program executable by the at least one processor (10), and the computer program is executed by the at least one processor (10) so that the at least one processor (10) can execute the method for evaluating the impact of a network attack on a vehicle network layer CAN bus as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Security risk assessment method for risk cascade of power distribution network under network attack

    CN115361150A

  • Intrusion detection method for vehicle-mounted CAN network

    CN118869263A

  • Online real-time intelligent connected vehicle network attack threat analysis and risk assessment method

    CN118900203A

  • Intrusion response apparatus and method for vehicle network

    US20190332823A1

  • Universally applicable signal-based controller area network (CAN) intrusion detection system

    US20220374515A1