Method and device for identifying vehicle end remote attack, electronic equipment and storage medium
By collecting and analyzing remote control logs, identifying whether the vehicle is subject to remote attacks and launching alarms, it solves the network security risk problem in vehicle remote control scenarios in Internet of Vehicles technology, and realizes the ability to promptly discover and respond to remote attacks.
Patent Information
- Application Number
- CN202510205233.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-16
AI Technical Summary
The popularization of Internet of Vehicles technology has brought about network security risks. Attackers may illegally obtain car owners or vehicle information through vulnerabilities or malicious means, and even achieve remote control of other vehicles, threatening the safety of car owners' lives and property.
By collecting the remote control logs generated by the control device during remote control of the vehicle, identifying whether there is a remote attack on the vehicle, and launching a remote attack alarm in the presence of a remote attack.
It realizes the timely discovery of the remote attack risks in vehicle remote control scenarios, and provides necessary alarms to avoid losses and improve the network security of the vehicle.
Smart Images

Figure CN120017393A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network information security technology, and in particular to methods, devices, electronic devices and storage media for identifying vehicle-side remote attacks. Background Art
[0002] With the rapid development of automobile intelligence and networking, Internet of Vehicles technology has become an important part of modern automobiles, greatly improving driving convenience and user experience. Among them, the remote control function, as an important application of Internet of Vehicles, allows car owners to remotely operate their vehicles through a dedicated APP on their smartphones. These operations include remotely unlocking doors and windows, turning on the air conditioner in the car, setting remote start, etc., providing car owners with a more flexible and convenient way to manage their vehicles.
[0003] However, as the popularity and complexity of connected vehicle technology increases, cybersecurity risks are gradually emerging. Attackers may illegally obtain information about car owners or vehicles through loopholes or malicious means, or even remotely control other vehicles. These security risks may seriously threaten the safety of life and property of car owners, and further affect the public's trust in smart connected vehicles. Summary of the invention
[0004] To overcome the problems existing in the related art, this specification provides a method, device, electronic device and storage medium for identifying vehicle-side remote attacks.
[0005] According to a first aspect of an embodiment of this specification, a method for identifying a vehicle-side remote attack is provided, the method comprising:
[0006] Collect remote control logs generated by the control device during the process of remotely controlling the vehicle;
[0007] Identify whether there is a remote attack on the vehicle according to the remote control log, and initiate a remote attack alarm for the vehicle if there is a remote attack.
[0008] According to a second aspect of an embodiment of this specification, a device for identifying a vehicle-side remote attack is provided, the device comprising:
[0009] A remote control log collection module is used to collect remote control logs generated by the control device during the process of remotely controlling the vehicle;
[0010] The remote attack identification module is used to identify whether there is a remote attack against the vehicle according to the remote control log, and initiate a remote attack alarm against the vehicle if there is a remote attack.
[0011] According to a third aspect of the embodiments of this specification, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the method described in the first aspect are implemented.
[0012] According to a fourth aspect of the embodiments of this specification, there is provided a computer-readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the steps of the method described in the first aspect.
[0013] The technical solutions provided by the embodiments of this specification may have the following beneficial effects:
[0014] By collecting the remote control logs generated by the control device during the process of remotely controlling the vehicle, and identifying whether there is a remote attack against the vehicle based on the remote control logs, a remote attack alarm against the vehicle is initiated in the event of a remote attack. It can be seen that by implementing this solution, the risk of remote attacks in the vehicle remote control scenario can be discovered in a timely manner and necessary alarms can be issued, so as to promptly prompt relevant personnel to check the vehicle's software and hardware vulnerabilities, etc., to avoid losses.
[0015] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present specification. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the specification and, together with the description, serve to explain the principles of the specification.
[0017] Figure 1 The present specification is a schematic diagram of a scenario in which a control device remotely controls a vehicle according to an exemplary embodiment.
[0018] Figure 2 This is a flow chart of a method for identifying a vehicle-side remote attack according to an exemplary embodiment of the present specification.
[0019] Figure 3 It is a structural schematic diagram of an electronic device according to an exemplary embodiment of the present specification.
[0020] Figure 4 This is a block diagram of a device for identifying a vehicle-side remote attack according to an exemplary embodiment of the present specification. DETAILED DESCRIPTION
[0021] With the rapid development of automobile intelligence and networking, Internet of Vehicles technology has become an important part of modern automobiles, greatly improving driving convenience and user experience. Among them, the remote control function, as an important application of Internet of Vehicles, allows car owners to remotely operate their vehicles through a dedicated APP on their smartphones. These operations include remotely unlocking doors and windows, turning on the air conditioner in the car, setting remote start, etc., providing car owners with a more flexible and convenient way to manage their vehicles.
[0022] like Figure 1 As shown, Figure 1 This is a schematic diagram of a scenario in which a control device remotely controls a vehicle according to an exemplary embodiment of this specification. The control device 12 may be a smart phone, a smart watch, a smart key, a voice assistant device, a computer, an Internet of Things control device, etc. It should be noted that the control device 12 is not limited to a device with a control application provided by a manufacturer installed. For an attacker, the control device 12 may be a device constructed with an attack script or an attack tool, which is used to disguise as a legitimate control device and simulate the user's control request line. It can be seen that the control device 12 may be any device that realizes remote operation of the vehicle. Specifically, a control request (such as remotely unlocking the door) may be initiated to the server 10 through the network. The server 10 may receive the control request and verify the identity of the owner and the legitimacy of the control request. In addition, the server 10 may also record the interaction process between the control device 12 and the server 10 in the remote control log. After verifying that the request is legitimate, the server 10 may send the control request to the vehicle 11. After receiving the control request forwarded by the server 10, the vehicle 11 may perform the corresponding operation and feedback the execution result to the server 10.
[0023] With the increasing popularity and complexity of Internet of Vehicles technology, network security risks are gradually emerging. Attackers may illegally obtain information about the owner or vehicle through loopholes or malicious means, or even remotely control other vehicles. These security risks may seriously threaten the safety of the owner's life and property, and further affect the public's trust in smart connected vehicles. For example, an attacker can crack the owner's remote control account and use the owner's account to send a disguised legal control request to the server 10. The server 10 sends the disguised control request to the vehicle 11, resulting in the illegal control of the vehicle 11.
[0024] However, for some models, the security detection module was not deployed on the vehicle side at the beginning of the design, so it is impossible to identify network security attacks on the vehicle side. Although some models that have deployed security detection modules can identify network security attacks on the vehicle side, in the vehicle remote control scenario, the security detection module is difficult to identify the characteristics of remote attacks. For example, the vehicle cannot determine whether requests sent from different locations at the same time are reasonable (for example, the owner is in place A, and the attacker's forged request is in place B).
[0025] In view of the problem that the above-mentioned local network security detection method on the vehicle side is difficult to cover the vehicle remote control scenario, this solution proposes a method for identifying remote attacks on the vehicle side to make up for the shortcomings of the local network security detection method on the vehicle side.
[0026] Next, the embodiments of this specification are described in detail.
[0027] like Figure 2 As shown, Figure 2 This is a flowchart of a method for identifying a vehicle-side remote attack according to an exemplary embodiment of the present specification. This method can be applied to Figure 1 The server 10 comprises steps 201-202:
[0028] Step 201: Collect the remote control log generated by the control device during the process of remotely controlling the vehicle.
[0029] In one embodiment, the user may initiate a control request for remotely controlling the vehicle to the server through the control device. For example, the user may initiate a control request to the server to unlock the door, start the engine, etc. After receiving the control request sent by the control device, the server may store the remote control log recording the control request to the log service platform, and when the remote control log needs to be collected, the remote control log may be obtained from the log service platform.
[0030] The remote control log can be a record of the entire process of the control request, for example, it can record the entire process of sending, processing and responding to the control request. The remote control log can record the account ID that sent the control request, the content of the control request (such as unlocking, starting the vehicle or turning on the air conditioner, etc.), the time when the request was initiated, the VIN code of the vehicle requested to be controlled, the IP address used by the requester, the network protocol, and other information.
[0031] The log service platform can establish connections with different data sources, which can be data processing records generated by the server processing vehicle remote control requests. When the control device sends a control request to the server, the data source will generate a remote control log for the control request in real time. The log service platform can collect and store the remote control log generated by the control device in the process of remotely controlling the vehicle from the data source. In addition, the log service platform can also monitor the data source, and when the data source generates a new remote control log, the remote control log is collected to the log service platform in a timely manner. The log service platform can be a tool or service for collecting, storing, analyzing and managing log data. In this solution, it is used to collect and process the remote control log generated by the server processing the control request sent by the control device.
[0032] When obtaining the remote control log from the log service platform, the content of the remote control log can be preprocessed after the remote control log is obtained. For example, if the remote control log stored in the log service platform is in an unstructured format, the unstructured remote control log stored in the log service platform can be converted into a structured remote control log, and the structured remote control log can be used to identify whether there is a remote attack against the vehicle. Optionally, the parameters used to analyze the remote attack can be determined, and the corresponding parameters can be parsed from the acquired remote control log, and the parsed parameters can be stored in a structured format, and whether there is a remote attack against the vehicle can be identified based on the parsed parameters. Further, for the case where the parsed parameters have missing values or abnormal values, default values can be used to fill them. In addition, when obtaining the remote control log, new parameters can be generated according to the content in the acquired remote control log, and the newly generated parameters can be combined with the content in the acquired remote control log to identify whether there is a remote attack against the vehicle. For example, if there is no location for sending a control request in the acquired remote control log, but the location information belongs to a relatively important remote attack feature, the location for sending the control request can be calculated according to the IP address in the acquired remote control log, and the location information can be used in the remote attack analysis of the vehicle. When identifying whether there is a remote attack on the vehicle based on the remote control log, combining new parameters can analyze the attack characteristics from more angles, thereby improving the comprehensiveness of detection.
[0033] When the log service platform collects the original remote control log generated by the control request from the data source, it can pre-process the collected original control log. For example, the collected unstructured original remote control log (such as text format) can be structured into a structured remote control log (such as JSON format) and stored. Of course, the data cleaning work of the original control log can also be carried out on the log service platform, so that when the remote control log is obtained from the log service platform, the acquisition efficiency can be improved.
[0034] Step 202: Identify whether there is a remote attack on the vehicle according to the remote control log, and initiate a remote attack alarm on the vehicle if there is a remote attack.
[0035] Remote attacks often have obvious abnormal behavior characteristics, which can be captured in remote control logs. For example, users usually use IP addresses within a fixed range, while attackers may come from different countries or use proxy IP addresses. If the IP addresses displayed in the remote control logs of the same user in different time periods change significantly, it may be identified as the vehicle being remotely attacked. For example, normal users have a limited frequency of operation (such as controlling the vehicle several times a day), while attackers may send a large number of remote control requests to the server in a short period of time through brute force cracking. If the remote control log shows that the account has tried to unlock the vehicle multiple times in a short period of time, it may be identified as the vehicle being remotely attacked. For another example, normal users usually use the vehicle during the day, while attackers may choose to perform illegal operations late at night. The remote control log shows that the operation time is obviously deviated from the user's normal usage behavior, which may be identified as the vehicle being remotely attacked.
[0036] The remote control log can be used to analyze whether there is a remote attack on the vehicle from different dimensions such as account dimension, device dimension and time dimension. This specification does not limit the specific method of using the remote control log to identify remote attack behavior.
[0037] It can be seen that by implementing this solution, the risk of remote attacks in vehicle remote control scenarios can be discovered in a timely manner and necessary warnings can be issued, so that relevant personnel can be promptly prompted to check the vehicle's software and hardware vulnerabilities to avoid losses.
[0038] Next, this specification provides a preferred method of using remote control logs to identify remote attack behaviors, see the following embodiments for details:
[0039] In one embodiment, after obtaining the remote control log, the control parameters can be parsed from the remote control log, and whether there is a remote attack on the vehicle can be identified based on the control parameters. Specifically, it can be determined whether the control parameters meet the preset rules. If the preset rules are not met, it is determined that the vehicle is under remote attack. The control parameters can be the field values of the key fields recorded in the control log. For example, the control parameters can be the requester ID, the requester's IP address, the request time information, the request method, the requester port, and the VIN code of the vehicle. Specifically, it can be combined with a single or multiple control parameters parsed from the same remote control log to identify whether there is a remote attack on the vehicle, and it can also be combined with different control parameters parsed from different remote control logs to identify whether there is a remote attack on the vehicle. For example, if the control parameter parsed from the remote control log is that the requester ID is an illegal requester ID, it can be identified that the vehicle is under remote attack. For example, the control parameters parsed from the remote control log are the requester ID and the VIN code of the vehicle. If the requester ID is not an account bound to the VIN code of the vehicle, it can be identified that the vehicle is under remote attack. For example, multiple remote control logs of the same requester within a period of time can be obtained, and the request frequency of the requester can be analyzed. If the request frequency is greater than a preset threshold, it can be identified that the vehicle is under remote attack. For example, different remote control logs with the same control parameter value can be analyzed. If the same requester ID is recorded in multiple remote control logs, it indicates that these remote control logs record the request behavior of the same requester. Then, it can be identified whether the vehicle is under remote attack based on the IP address and the vehicle's VIN code recorded in these remote control logs.
[0040] In one embodiment, a preferred method for identifying the presence of a remote attack on a vehicle based on control parameters is provided:
[0041] The same requester initiates remote control requests to different vehicles within a first time interval. Exemplarily, the same requester initiates remote control requests to different vehicles using the same or different IP addresses within the first time interval. For example, VIN codes of different vehicles are extracted from multiple remote control logs that record the same requester ID within the first time interval. Under normal circumstances, each requester ID (such as a user account or device identifier) is usually only bound to a specific vehicle, and remote control requests are only initiated for bound vehicles. Even if a user has multiple bound vehicles, requests to operate multiple vehicles usually do not occur intensively within a very short time interval. Therefore, the above behavior indicates that the vehicle is under remote attack, and the requester ID is suspected to be stolen by the attacker and used to initiate control requests to different vehicles.
[0042] The same vehicle is remotely controlled by different requesters within the second time interval. For example, different requester IDs are extracted from multiple remote control logs that record the VIN code of the same vehicle within the second time interval. A vehicle is usually bound to a specific user or device, and the remote control operation should be initiated by the bound requester. In a short period of time, there are usually no multiple different requesters trying to control the same vehicle at the same time. Therefore, the above behavior indicates that the vehicle is under remote attack, and the attacker attempts to control the target vehicle by forging multiple control requests.
[0043] Different requesters use the same IP address to initiate remote control requests to the same vehicle within the third time interval. For example, the same vehicle VIN code and different requester IDs are extracted from multiple remote control logs with the same IP address within the third time interval. Under normal circumstances, different requesters generally use different IP addresses to initiate remote control requests to different vehicles. Therefore, the above behavior indicates that the vehicle is under remote attack, and the attacker attempts to control the same vehicle by forging different requester IDs through a proxy IP address.
[0044] Different requesters use the same IP address to initiate remote control requests to different vehicles during the fourth time interval. For example, different requester IDs and vehicle VIN codes are extracted from multiple remote control logs with the same IP address during the fourth time interval. Under normal circumstances, different requester IDs are independent of each other, and the same IP address is unlikely to initiate control requests to multiple different vehicles. Therefore, the above behavior indicates that the vehicle is under remote attack, and the attacker may attempt to forge different requester IDs through a proxy IP address to control different vehicles.
[0045] In the case where the remote control log contains HTTP requests, the HTTP requests can be extracted from the remote control log, and HTTP parameters can be parsed from the HTTP requests as control parameters. Since the HTTP parameters in the HTTP request (such as request method, URL, request header and request body, etc.) are easily tampered by attackers, the attack intention can be detected by analyzing these HTTP parameters. For example, it can be determined whether the request method complies with the specification of the remote control API. If the request method is an unauthorized request method, it is identified that the vehicle is under remote attack. For example, it can be identified whether the URL points to a legal resource path. If it is detected that an illegal resource path is accessed, it can be identified that the vehicle is under remote attack. Of course, in addition to the above-mentioned requests based on HTTP or HTTPS protocols, requests based on SOAP (Simple Object Access Protocol) protocol, requests based on CoAP (Constrained Application Protocol, Constrained Application Protocol) protocol, etc. can also be included. After extracting requests sent based on different protocols from the remote control log, it can be identified whether the vehicle is under remote attack based on the characteristics of the protocol parameters in different protocols.
[0046] In one embodiment, the remote control log can be input into the abnormal recognition model, and the abnormal recognition model is used to identify whether there is a remote attack against the vehicle. The abnormal recognition model can be a large model, such as a convolutional neural network (CNN), a long short-term memory network (LSTM) or a Transformer model. The abnormal recognition model is trained by using historical remote control logs to enable it to have the ability to identify remote attacks based on remote control logs. Among them, historical remote control logs suspected of remote attacks can be continuously collected in practical applications, and these historical remote attack logs can be used to train the abnormal recognition model. Of course, public data sets can also be used to train the abnormal recognition model, and this specification does not impose any restrictions on this. In order to further improve the effect of the abnormal recognition model, self-supervised learning or reinforcement learning techniques can be introduced so that the abnormal recognition model can autonomously discover unknown safety hazards. The abnormal recognition model can process a large amount of log data and quickly screen out potential abnormal behaviors, which is particularly suitable for real-time processing of large-scale requests in the Internet of Vehicles environment.
[0047] In one embodiment, after a remote attack on a vehicle is identified based on a remote control log, a remote attack alarm for the vehicle may be initiated. Among them, an alarm may be directly initiated to the vehicle that has been remotely attacked. For example, an alarm may be issued to the vehicle that has been remotely attacked, and of course an alarm may also be initiated to the account bound to the vehicle to remind the user of the account security. Alternatively, after determining a remote control log that is suspected of a remote attack, a network security engineer may conduct a secondary analysis to determine whether a remote attack on the vehicle actually exists. If so, the specific vehicle that has been attacked is located and an alarm is initiated to the vehicle. Introducing a secondary review of the identification results by a network security engineer can reduce false disturbances to the car owner.
[0048] In one embodiment, in the event of a remote attack, the remote control request to the vehicle can be rejected, and the user can be reminded to manually control the vehicle during the dangerous period. By directly blocking the attacker's operation, the attacker cannot unlock the target vehicle, start the engine, etc. through a forged remote control request, effectively protecting the safety of the vehicle and the owner. In addition, network security engineers can perform security analysis on the attacked vehicle and release the remote control request sent by the control device to the vehicle after eliminating false alarms or security risks.
[0049] Corresponding to the embodiments of the aforementioned method, this specification also provides embodiments of a device and a terminal to which it is applied.
[0050] like Figure 3 As shown, Figure 3 It is a structural diagram of an electronic device shown in this specification according to an exemplary embodiment. At the hardware level, the electronic device 300 includes a processor 302, an internal bus 304, a network interface 306, a memory 308 and a non-volatile memory 310, and of course may also include hardware required for other services. One or more embodiments of this specification can be implemented based on software, such as the processor 302 reading the corresponding computer program from the non-volatile memory 310 into the memory 308 and then running it. Of course, in addition to the software implementation, one or more embodiments of this specification do not exclude other implementations, such as logic devices or a combination of software and hardware, etc., that is to say, the execution subject of the following processing flow is not limited to each logic module, but can also be hardware or logic devices.
[0051] like Figure 4 As shown, Figure 4 This is a block diagram of a device for identifying a vehicle-side remote attack according to an exemplary embodiment of the present specification. The device can be applied to Figure 3 In the electronic device 300 shown, the technical solution of this specification is implemented. The device includes:
[0052] The remote control log collection module 402 is used to collect the remote control logs generated by the control device during the process of remotely controlling the vehicle;
[0053] The remote attack identification module 404 is used to identify whether there is a remote attack against the vehicle according to the remote control log, and initiate a remote attack alarm against the vehicle if there is a remote attack.
[0054] Optionally, the device further includes a remote control log storage module 406, which is used to receive a control request for remotely controlling a vehicle sent by the control device, and store a remote control log recording the control request to a log service platform. The remote control log collection module 402 is specifically used to obtain the remote control log from the log service platform.
[0055] Optionally, the remote attack identification module 404 is specifically used to parse control parameters from the remote control log, and identify whether there is a remote attack against the vehicle based on the control parameters; or, input the remote control log into an anomaly identification model, and use the anomaly identification model to identify whether there is a remote attack against the vehicle.
[0056] Optionally, the remote control log includes an HTTP request, and the remote attack identification module 404 is specifically configured to extract the HTTP request from the remote control log, and parse HTTP parameters from the HTTP request as the control parameters.
[0057] Optionally, the control parameters include: requester ID, requester IP address, request time information and the VIN code of the vehicle.
[0058] Optionally, the identification of the existence of a remote attack against the vehicle based on the control parameters includes at least one of the following: the same requester initiates remote control requests to different vehicles within a first time interval; the same vehicle is initiated with remote control requests by different requesters within a second time interval; different requesters initiate remote control requests to the same vehicle using the same IP address within three time intervals; different requesters initiate remote control requests to different vehicles using the same IP address within a fourth time interval.
[0059] Optionally, the device further includes a denial of service module 408, which is specifically configured to refuse to send a remote control request to the vehicle in the event of the remote attack.
[0060] The implementation process of the functions and effects of each module in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, which will not be repeated here.
[0061] For the device embodiment, since it basically corresponds to the method embodiment, the relevant parts can refer to the partial description of the method embodiment. The device embodiment described above is only schematic, wherein the modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place, or they may be distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this specification. Ordinary technicians in this field can understand and implement it without paying creative work.
[0062] The present specification also provides a computer-readable storage medium having a computer program stored thereon, and when the program is executed by a processor, the steps of any of the aforementioned methods for identifying vehicle-side remote attacks provided in the present application are implemented.
[0063] Specifically, computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media and memory devices, including, for example, semiconductor memory devices (such as EPROM, EEPROM and flash memory devices), magnetic disks (such as internal hard disks or removable disks), magneto-optical disks, and CD ROM and DVD-ROM disks.
[0064] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0065] Those skilled in the art will readily appreciate other embodiments of the specification after considering the specification and practicing the invention claimed herein. The specification is intended to cover any variations, uses or adaptations of the specification that follow the general principles of the specification and include common knowledge or customary techniques in the art that are not claimed in the specification. The specification and examples are to be considered exemplary only, and the true scope and spirit of the specification are indicated by the following claims.
[0066] It should be understood that the present description is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present description is limited only by the appended claims.
[0067] The above description is only a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this specification should be included in the scope of protection of this specification.
Claims
1. A method for identifying a vehicle-side remote attack, characterized in that: The method comprises: Collect remote control logs generated by the control device during the process of remotely controlling the vehicle; Identify whether there is a remote attack on the vehicle according to the remote control log, and initiate a remote attack alarm for the vehicle if there is a remote attack.
2. The method according to claim 1, characterized in that The method further includes: receiving a control request for remotely controlling a vehicle sent by the control device, and storing a remote control log recording the control request in a log service platform; The collecting of remote control logs generated by the control device during the process of remotely controlling the vehicle includes: acquiring the remote control logs from the log service platform.
3. The method according to claim 1, characterized in that Identifying whether there is a remote attack on the vehicle according to the remote control log includes one of the following: parsing control parameters from the remote control log, and identifying whether there is a remote attack on the vehicle based on the control parameters; or, The remote control log is input into an abnormality recognition model, and the abnormality recognition model is used to identify whether there is a remote attack on the vehicle.
4. The method according to claim 3, characterized in that The remote control log includes an HTTP request, and the parsing of the control parameters from the remote control log includes: The HTTP request is extracted from the remote control log, and HTTP parameters are parsed from the HTTP request as the control parameters.
5. The method according to claim 3, characterized in that: The control parameters include: requester ID, requester IP address, request time information and the VIN code of the vehicle.
6. The method according to claim 5, characterized in that The identifying the existence of a remote attack against the vehicle based on the control parameter comprises at least one of the following: The same requester initiates remote control requests to different vehicles within a first time interval; Remote control requests are initiated by different requesting parties on the same vehicle within a second time interval; Different requesting parties initiate remote control requests to the same vehicle using the same IP address within a third time interval; The same requester initiates remote control requests to different vehicles using the same IP address within a fourth time interval.
7. The method according to claim 1, characterized in that The method further comprises: In the event of the remote attack, the remote control request to the vehicle is rejected.
8. A device for identifying remote attacks on a vehicle, characterized in that: The device comprises: A remote control log collection module is used to collect remote control logs generated by the control device during the process of remotely controlling the vehicle; The remote attack identification module is used to identify whether there is a remote attack against the vehicle according to the remote control log, and initiate a remote attack alarm against the vehicle if there is a remote attack.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.