Attack type detection method, system and device for automobile communication network and medium
By constructing an undirected weighted graph and using graph neural network model, feature extraction and prediction of attack types in automotive communication networks is solved, and the problem of difficulty in accurately distinguishing attack types in the prior art is solved, and high-accurate attack type detection is achieved.
Patent Information
- Application Number
- CN202510494479.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-05-23
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The prior art is difficult to accurately distinguish different types of attacks in automotive communication networks, and traditional methods can only detect abnormal behaviors and are difficult to classify.
Undirected weighted graph is constructed by building arbitration fields of data frames in the network traffic sequence of the automotive communication network, and a feature extraction and attack type prediction are used for graphs (such as the neural network model) to perform feature extraction and attack type prediction on the graphs, and then abnormal alarms are made.
It realizes accurate detection and classification of different types of attacks in automotive CAN networks, improves the accuracy and efficiency of detection, and overcomes the technical difficulties in building an undirected weighted graph.
Smart Images

Figure CN120034397A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of automobile technology, and in particular to a method, system, device and medium for detecting attack types in an automobile communication network. Background Art
[0002] With the rapid development of the automotive field, vehicle control systems are increasingly dependent on complex network architectures, including multiple control units interconnected through bus technologies such as controller communication networks. These systems implement control from engine management to autonomous driving assistance functions. As the networking and intelligence levels of automotive systems have significantly improved, the risk of automotive systems being subjected to various network attacks (such as spoofing attacks, replay attacks, and denial of service attacks) has also increased. These attacks may have a serious impact on the safety and reliability of vehicles. Therefore, an effective attack detection system is crucial to ensure the safety of automotive systems, while traditional rule-based or statistical methods (such as threshold monitoring and message frequency analysis) can usually only detect abnormal behaviors (such as a surge in CAN bus load and the appearance of illegal IDs), but it is difficult to accurately distinguish the type of attack. Summary of the invention
[0003] In view of this, the present application provides a method, system, device and medium for detecting attack types of automobile communication networks, aiming to classify and warn of attacks on automobile communication networks.
[0004] In a first aspect, the present application provides a method for detecting attack types in an automobile communication network, the method comprising: Determining a corresponding undirected weighted graph according to an arbitration field of a data frame in a network traffic sequence input into the automobile communication network, wherein a graph data node in the undirected weighted graph is composed of the arbitration field; Extracting features from the undirected weighted graph using an attack type prediction model, and predicting attack types based on the extracted features to obtain corresponding prediction results; According to the prediction result, a corresponding abnormal alarm is issued.
[0005] Optionally, determining a corresponding undirected weighted graph according to an arbitration field of a data frame in a network traffic sequence input into the automobile communication network includes: Extracting arbitration fields from each data frame of a network traffic sequence input into the automotive communication network; Create corresponding graph data nodes based on the extracted arbitration fields; Converting the extracted arbitration field into a feature vector, and using the feature vector as a vector representation of a graph data node corresponding to the arbitration field; According to the adjacency relationship between arbitration fields, undirected edges are established for graph data nodes corresponding to arbitration fields having adjacency relationships, so as to construct an undirected graph, wherein the adjacency relationship is the temporal adjacency of arbitration fields of data frames in a network traffic sequence; Determining the weight of each undirected edge in the undirected graph according to the repeated adjacency relationship between the arbitration fields; Based on the undirected graph and the weights of each undirected edge, a corresponding undirected weighted graph is constructed.
[0006] Optionally, create a corresponding graph data node based on the extracted arbitration field, including: Determine whether the extracted arbitration field exists in an arbitration field data set, where the arbitration field data set is used to record a data set of arbitration fields corresponding to the created graph data node; If not present, create a graph data node corresponding to the extracted arbitration field.
[0007] Optionally, converting the extracted arbitration field into a feature vector, and using the feature vector as a vector representation of a graph data node corresponding to the arbitration field, includes: Filtering the extracted first bit data of the arbitration field, and performing base conversion on each bit data of the filtered arbitration field to obtain target base data corresponding to each bit data in the target base; Convert the target base data into floating point data of a floating point type in a set interval through a preset algorithm; splicing each floating-point data of the arbitration field to obtain a feature vector corresponding to the arbitration field; The feature vector is used as a vector representation of the graph data node corresponding to the arbitration field.
[0008] Optionally, according to the prediction result, a corresponding abnormal alarm is performed, including: According to the prediction results, determining the number of attacks of various attack types within a preset time period; Compare the number of attacks of various attack types with the corresponding set thresholds to obtain comparison results; According to the comparison result, it is determined whether to issue an abnormality alarm corresponding to various attack types.
[0009] Optionally, construct an attack network traffic sequence for training an attack type prediction model, including: Determine the second data frame number of the single sub-network traffic sequence group according to the data frame number of the attack network traffic sequence to be generated and the first data frame number of the attack data frame to be inserted; Sequentially dividing the collected normal network traffic sequence into a plurality of sub-network traffic sequence groups of a second number of data frames; The attack data frames of the first data frame number under the target attack type are randomly inserted into the sub-network traffic sequence group to obtain the corresponding attack network traffic sequence.
[0010] Optionally, determining the second number of data frames of a single sub-network traffic sequence group according to the number of data frames of the attack network traffic sequence to be generated and the first number of data frames of the attack data frames to be inserted includes: According to the number of data frames of the attack network traffic sequence to be generated and the first number of data frames of the attack data frames to be inserted under the target attack type, the second number of data frames of the single sub-network traffic sequence group under the target attack type is determined.
[0011] Optionally, before determining the corresponding undirected weighted graph according to the arbitration field of the data frame in the network traffic sequence input into the automobile communication network, the method further includes: determining a number of data frames of a sequence of network traffic input into a vehicle communication network; The step of determining a corresponding undirected weighted graph according to an arbitration field of a data frame in a network traffic sequence input into the automobile communication network comprises: When the number of data frames reaches a set value, a corresponding undirected weighted graph is determined according to arbitration fields of data frames in a network traffic sequence input into the automobile communication network.
[0012] Optionally, when the attack type prediction model is a graph neural network model, extracting features from the undirected weighted graph using the attack type prediction model, and predicting the attack type on the extracted features to obtain corresponding prediction results includes: Performing physical sign extraction on the undirected weighted graph through a graph convolutional layer of a graph neural network model; The extracted features are compressed into a low-dimensional vector space through the node aggregation layer of the graph neural network model to obtain the first feature; The attack type is predicted for the first feature through the graph neural network model to obtain the corresponding prediction result.
[0013] A second aspect of the present application provides an attack type detection system for an automobile communication network, the system comprising: A data preprocessing module, used for determining a corresponding undirected weighted graph according to an arbitration field of a data frame in a network traffic sequence input into the automobile communication network, wherein a graph data node in the undirected weighted graph is composed of the arbitration field; An attack detection module, used to extract features from the undirected weighted graph through an attack type prediction model, and predict attack types based on the extracted features to obtain corresponding prediction results; The abnormality alarm module is used to make corresponding abnormality alarms according to the prediction results.
[0014] The third aspect of the present application provides an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and running on the processor, wherein when the computer program is executed by the processor, the steps in the method for detecting attack types in an automobile communication network as described in the first aspect of the present application are implemented.
[0015] The fourth aspect of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the method for detecting attack types in an automobile communication network as described in the first aspect of the present application are implemented.
[0016] The present application provides a method for detecting attack types in a vehicle communication network, which has the following advantages: The embodiment of the present application provides a method for detecting attack types of automobile communication networks. First, according to the arbitration field of the data frame in the network traffic sequence of the input automobile communication network, the corresponding undirected weighted graph is determined, and the graph data node in the undirected weighted graph is composed of the arbitration field; the undirected weighted graph is subjected to feature extraction through the attack type prediction model, and the extracted features are subjected to attack type prediction to obtain the corresponding prediction results; and the corresponding abnormal alarm is performed according to the prediction results. Therefore, in the field of CAN network attack detection, the present application introduces an attack type prediction model (preferably a graph neural network model) and an undirected weighted graph to classify attacks on the CAN network, and establishes a graph representation of the automobile CAN network traffic, using nodes to represent the arbitration field in the data frame, and edges to represent the front-end relationship between the data frames. Through this method, the deep features in the graph structure can be used to detect and distinguish different types of attacks on the automobile CAN network. This method overcomes the technical difficulties of introducing graph neural network models and undirected weighted graphs into the field of CAN network attack detection (i.e., in order to achieve the purpose of attack classification of attacks on the automotive CAN network, the nodes and weights that need to be paid attention to are determined in the process of constructing an undirected weighted graph). It can detect the attack type of attacks on the automotive CAN network. At the same time, the detection of attack types based on graph structure through deep learning models can improve the accuracy and efficiency of detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the description of the embodiments of the present application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative labor.
[0018] Figure 1A flowchart of a method for detecting attack types in an automobile communication network is shown as an embodiment of the present application; Figure 2 A schematic diagram of a network traffic sequence in a method for detecting attack types in an automobile communication network according to an embodiment of the present application; Figure 3 A flowchart of generating an attack network traffic sequence in a method for detecting attack types in an automobile communication network according to an embodiment of the present application; Figure 4 A schematic diagram of an attack type detection system for an automobile communication network is shown as an embodiment of the present application; Figure 5 An attack detection flow chart of an attack type detection system for an automobile communication network is shown as an embodiment of the present application. DETAILED DESCRIPTION
[0019] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0020] refer to Figure 1 , Figure 1 The following is a flow chart of a method for detecting attack types in a vehicle communication network according to an embodiment of the present application. Figure 1 As shown, the method includes: Step S1: determining a corresponding undirected weighted graph according to an arbitration field of a data frame in a network traffic sequence input into an automobile communication network, wherein graph data nodes in the undirected weighted graph are constituted by arbitration fields.
[0021] In this embodiment, the network traffic input into the automobile communication network (i.e., the automobile CAN network) is obtained in real time. After obtaining a certain amount of network traffic and arranging the network traffic sequence in chronological order, the arbitration field of each data frame in the network traffic sequence is extracted. A corresponding undirected weighted graph is created by extracting all the arbitration fields in the network traffic sequence, and the graph data nodes in the undirected weighted graph are composed of the extracted arbitration fields. Among them, the arbitration field of a single data frame in the network traffic sequence is a string of numbers consisting of a CAN ID and an RTR bit (Remote Transmission Request).
[0022] Step S2: extracting features from the undirected weighted graph through an attack type prediction model, and predicting attack types based on the extracted features to obtain corresponding prediction results.
[0023] In this embodiment, after obtaining the undirected weighted graph corresponding to the network traffic sequence through step S1, the undirected weighted graph is feature extracted through a pre-trained attack type prediction model, and the attack type prediction is performed on the extracted features through the attack type prediction model to obtain the corresponding prediction result, which includes the attacks on the automobile CAN network at each time determined based on the undirected weighted graph and the attack types of these attacks. Among them, the attack type prediction model is preferably a graph neural network model (GNN Graph Neural Network). It should be understood that this is only a preferred implementation of the attack type prediction model. The attack type prediction model can also be other neural network models. For other neural network models, it is necessary to adapt to the graph structure, such as the convolutional neural network model (CNN Convolutional Neural Network) is mainly used to process image data, and the graph data is nodes and lines, unlike the image data belonging to the square pixel grid, so the graph data can be converted into image data and then processed by the convolutional neural network model. Among them, the attack types include but are not limited to DoS attacks (Denial of Service Attack), replay attacks, message tampering attacks, and physical access attacks.
[0024] Step S3: According to the prediction result, a corresponding abnormal alarm is issued.
[0025] In this embodiment, by analyzing the prediction results obtained in step S2, it is determined whether the current vehicle CAN network is under attack, and the attack type and attack intensity of the attack are determined. Based on the determined attack type and attack intensity of the current vehicle CAN network, an alarm is given to the user. The alarm can be in the form of displaying the attack type and attack intensity to the user through a visual interface, and corresponding warning lights of different colors are set for different attack intensities, and the corresponding color warning lights are lit based on the attack intensity.
[0026] In this embodiment, the attack intensity may be determined based on the number of attack types currently received and / or the number of attacks received. The greater the number of attack types currently received, the higher the corresponding attack intensity; the greater the number of attacks currently received, the higher the corresponding attack intensity.
[0027] The embodiment of the present application provides a method for detecting attack types of automobile communication networks. First, according to the arbitration field of the data frame in the network traffic sequence of the input automobile communication network, the corresponding undirected weighted graph is determined, and the graph data node in the undirected weighted graph is composed of the arbitration field; the undirected weighted graph is subjected to feature extraction through the attack type prediction model, and the extracted features are subjected to attack type prediction to obtain the corresponding prediction results; and the corresponding abnormal alarm is performed according to the prediction results. Therefore, in the field of CAN network attack detection, the present application introduces an attack type prediction model (preferably a graph neural network model) and an undirected weighted graph to classify attacks on the CAN network, and establishes a graph representation of the automobile CAN network traffic, using nodes to represent the arbitration field in the data frame, and edges to represent the front-end relationship between the data frames. Through this method, the deep features in the graph structure can be used to detect and distinguish different types of attacks on the automobile CAN network. This method overcomes the technical difficulties of introducing graph neural network models and undirected weighted graphs into the field of CAN network attack detection (i.e., in order to achieve the purpose of attack classification of attacks on the automobile CAN network, the nodes that need to be paid attention to and the weights of the edges need to be determined in the process of constructing an undirected weighted graph). It can detect the attack types of attacks on the automobile CAN network. At the same time, the detection of attack types based on graph structure through deep learning models can improve the accuracy and efficiency of detection.
[0028] In combination with the above embodiments, in one implementation, the embodiment of the present application further provides a method for detecting attack types in a vehicle communication network. In the method for detecting attack types in a vehicle communication network, step S1 may include steps S11 to S16: Step S11: extracting arbitration fields from each data frame of a network traffic sequence input into the automobile communication network.
[0029] Step S12: Create corresponding graph data nodes according to the extracted arbitration fields.
[0030] Step S13: converting the extracted arbitration field into a feature vector, and using the feature vector as a vector representation of a graph data node corresponding to the arbitration field.
[0031] Step S14: according to the adjacency relationship between arbitration fields, undirected edges are established for graph data nodes corresponding to arbitration fields having adjacency relationships to construct an undirected graph, wherein the adjacency relationship is the temporal adjacency of arbitration fields of data frames in a network traffic sequence.
[0032] Step S15: Determine the weight of each undirected edge in the undirected graph according to the repeated adjacency relationship between arbitration fields.
[0033] Step S16: constructing a corresponding undirected weighted graph based on the undirected graph and the weights of each undirected edge.
[0034] In this embodiment, the network traffic input into the automobile communication network (i.e., the automobile CAN network) is obtained in real time. After obtaining a certain amount of network traffic and arranging the network traffic sequence in chronological order, the arbitration field of each data frame in the network traffic sequence is extracted. Since the arbitration field is a string of numbers corresponding to the priority and data type of the message, there may be multiple arbitration fields with the same numbers among all arbitration fields extracted from the network traffic sequence. When the present application creates a graph data node based on all arbitration fields extracted from the network traffic sequence, only one graph data node is created for multiple arbitration fields with the same extracted numbers, that is, among all arbitration fields extracted, only one graph data node is created regardless of the number of arbitration fields of one number. Then, the arbitration field corresponding to the graph data node is converted into a feature vector, and the obtained feature vector is used as a vector representation of the graph data node corresponding to the arbitration field. For example, there are 5 arbitration fields with the number 0350 among all arbitration fields extracted from the network traffic sequence, and only one graph data node is created for the arbitration field with the number 0350.
[0035] In this embodiment, the undirected edges between the constructed graph data nodes are established in the same manner, which is described by an example: based on the extracted arbitration field, it is determined whether the data frames corresponding to the arbitration field are temporally adjacent to each other. When the data frames corresponding to the arbitration field are temporally adjacent to the data frames corresponding to the arbitration field, an undirected edge is established between the two graph data nodes corresponding to the two arbitration fields. After the undirected edges are established between the graph data nodes that meet the conditions through the same implementation method, an undirected graph corresponding to the network traffic sequence is obtained. For example, Figure 2 As shown, the data frame corresponding to the arbitration field with the number 0350 (a number expressed in hexadecimal) in the first row of data and the data frame corresponding to the arbitration field with the number 02c0 (a number expressed in hexadecimal) in the second row of data are adjacent in time, so an undirected edge is established between the graph data node created based on the arbitration field with the number 0350 and the graph data node created based on the arbitration field with the number 02c0.
[0036] In this embodiment, when the extracted arbitration field and the other arbitration field are temporally adjacent to each other for multiple times in the network traffic sequence, it is determined that the two arbitration fields have a repeated adjacency relationship with each other, and the weights of the undirected edges corresponding to the two arbitration fields in the undirected graph are determined based on the repeated adjacency relationship between the arbitration fields. The more repeated adjacencies there are between arbitration fields, the higher the weights of the undirected edges corresponding to the two arbitration fields in the undirected graph. Among them, an optional implementation method for determining the weights of the undirected edges corresponding to the two arbitration fields in the undirected graph based on the repeated adjacency relationship between arbitration fields is: pre-establishing a mapping table between the weight values of the undirected edges and the number of repeated adjacencies, and after determining the number of repeated adjacencies of the two arbitration fields in the network traffic sequence, determining the weight values of the undirected edges corresponding to the two arbitration fields in the undirected graph by querying the mapping table. An undirected weighted graph corresponding to the network traffic sequence of the input automobile CAN network is constructed based on the constructed undirected graph and the weight values of each undirected edge in the undirected graph.
[0037] For example, Figure 2 As shown, Figure 2 The arbitration fields of the first and second rows of data are 0350 and 02c0 respectively. Figure 2 The arbitration fields in the third-to-last row and the fourth-to-last row are 0350 and 02c0 respectively. Therefore, there are two repeated adjacencies between the arbitration field 0350 and the arbitration field 02c0. Accordingly, the corresponding weight value is determined based on the number of repeated adjacencies 2 between the two, and the weight value is used as the weight of the undirected edge between the graph data node corresponding to the arbitration field 0350 and the graph data node corresponding to the arbitration field 02c0.
[0038] In combination with the above embodiments, in one implementation, the embodiment of the present application further provides a method for detecting attack types in a vehicle communication network. In the method for detecting attack types in a vehicle communication network, step S12 may include steps S121 to S122: Step S121: determining whether the extracted arbitration field exists in an arbitration field data set, where the arbitration field data set is used to record a data set of arbitration fields corresponding to the created graph data nodes.
[0039] Step S122: if the extracted arbitration field does not exist, create a graph data node corresponding to the extracted arbitration field.
[0040] In this embodiment, the present application pre-creates a corresponding arbitration field data set for a single network traffic sequence, and the arbitration field data set is used to record the arbitration field corresponding to the graph data node created based on the network traffic sequence. In the case where the corresponding graph data node has not been created based on the arbitration field extracted from the network traffic sequence, the arbitration field data set is correspondingly empty. Take out the arbitration field extracted from the data frame of the network traffic sequence, and determine whether the extracted arbitration field exists in the arbitration field data set. If it does not exist, it indicates that the corresponding graph data node has not been created for the extracted arbitration field. At this time, the corresponding graph data node is created based on the extracted arbitration field, and then the extracted arbitration field is recorded in the arbitration field data set. In the case of existence, it indicates that the corresponding graph data node has been created for the extracted arbitration field. At this time, the corresponding graph data node will no longer be created based on the extracted arbitration field, and it continues to determine whether the newly extracted arbitration field exists in the arbitration field data set to determine whether it is necessary to create a corresponding graph data node based on the newly extracted arbitration field.
[0041] For example, Figure 2 As shown, Figure 2 A network traffic sequence is shown in FIG. The four digits after the ID in the figure are the arbitration fields of the network traffic sequence. When creating a graph data node corresponding to the arbitration field, an arbitration field data set corresponding to the network traffic sequence is created in advance, and the arbitration field of each data frame in the network traffic sequence is extracted. Then, the extracted arbitration field (such as Figure 2 0350 in the first row of data in the arbitration field dataset. If not, create the arbitration field (i.e. Figure 2 0350) in the first row of data) corresponds to a graph data node, and then the extracted arbitration field (i.e. Figure 2 0350 of the first row of data in the arbitration field data set. Then continue to determine the extracted new arbitration field (such as Figure 2 Whether the third row of data from the end of the list (0350) exists in the arbitration field data set, due to the above Figure 2 The first row of data 0350 has been stored in the arbitration field data set. At this time, the new arbitration field (i.e. Figure 2 0350) already exists in the arbitration field dataset, so the new arbitration field (i.e. Figure 2 The corresponding graph data node has been created for the third row of data from the last row. At this time, based on the extracted new arbitration field (i.e. Figure 20350) of the third to last row of data in the data set will no longer create a corresponding graph data node, but continue to determine whether the newly extracted arbitration field exists in the arbitration field data set to determine whether it is necessary to create a corresponding graph data node based on the newly extracted arbitration field.
[0042] In combination with the above embodiments, in one implementation, the embodiment of the present application further provides a method for detecting attack types in a vehicle communication network. In the method for detecting attack types in a vehicle communication network, step S13 may include steps S131 to S134: Step S131: filtering the extracted first bit data of the arbitration field, and performing base conversion on each bit data of the filtered arbitration field to obtain target base data corresponding to each bit data in the target base.
[0043] Step S132: converting the target base data into floating point data of a floating point type within a set interval using a preset algorithm.
[0044] Step S133: concatenate the floating-point data of the arbitration field to obtain a feature vector corresponding to the arbitration field.
[0045] Step S134: using the feature vector as a vector representation of a graph data node corresponding to the arbitration field.
[0046] In this embodiment, an optional implementation of step S13 is: Figure 2 As shown, the arbitration field of the data frame in the network traffic sequence is represented as 4-bit hexadecimal data. Since the first RTR bit is used to distinguish between standard data frames and remote data frames, the network traffic sequence is basically a standard data frame. Therefore, in order to improve processing efficiency, the present application first filters the first data (i.e., the RTR bit) of the arbitration field extracted from the network traffic sequence. At this time, the extracted arbitration field will become a 3-bit hexadecimal. Then, each bit of the 3-bit hexadecimal data of the filtered arbitration field extracted from the network traffic sequence is converted from hexadecimal to target data of the target system, wherein the target system is preferably decimal. In order to adapt to the differences in CAN IDs of different vehicle models, the present application converts each target data of the target system into each floating-point data of the floating-point type in a set interval through a preset algorithm for the target data corresponding to each bit of data, wherein the expression of the preset algorithm is: , setting the interval to be -1.000 to 1.000. Finally, concatenate the floating point data corresponding to each bit of data to obtain the feature vector corresponding to the arbitration field, and then determine the feature vector as the vector representation of the graph data node corresponding to the arbitration field.
[0047] In this embodiment, when an optional implementation of step S12 is steps S121 to S122, another optional implementation of step S13 is: Figure 2 As shown, the arbitration field of the data frame in the network traffic sequence is represented as 4-bit hexadecimal data. The present application first filters the first bit data (i.e., RTR bit) of the arbitration field in the arbitration field data set. Then, each bit of the 3-bit hexadecimal data of the arbitration field after filtering in the arbitration field data set is converted from hexadecimal to target data of the target system, wherein the target system is preferably decimal. In order to adapt to the differences in CAN IDs of different vehicle models, the present application converts each target data of the target system to each floating-point data of the floating-point type in a set interval through a preset algorithm for each bit of data, wherein the expression of the preset algorithm is: , set the interval to be -1.000 to 1.000. Finally, concatenate the floating point data corresponding to each bit of data to obtain the feature vector corresponding to the arbitration field, and then determine the feature vector as the vector representation of the graph data node corresponding to the arbitration field. Since the arbitration field of the corresponding graph data node is directly recorded and created in the arbitration field data set, the corresponding feature vector is directly created based on the arbitration field recorded in the arbitration field data set as the vector representation of the corresponding graph data node, which can effectively improve the efficiency of determining the vector representation of the graph data node.
[0048] In combination with the above embodiments, in one implementation, the embodiment of the present application further provides a method for detecting attack types in a vehicle communication network. In the method for detecting attack types in a vehicle communication network, step S3 may include steps S31 to S33: Step S31: According to the prediction result, the number of attacks of various attack types occurring within a preset time period is determined.
[0049] In this embodiment, the prediction result obtained by step S2 records the attacks suffered by the vehicle CAN network at various times and the attack types of these attacks. After obtaining the prediction result, the number of attacks of each type of attack occurring within a preset time is determined. The preset time can be set according to the actual application scenario and is not specifically limited here, such as 100ms, 500ms, 1s, etc.
[0050] Step S32: Compare the number of times each attack type occurs with the corresponding set threshold to obtain a comparison result.
[0051] In this embodiment, since the types of attacks that the automobile CAN network may be subjected to are various, and the attack frequencies of different attack types in a short period of time are different, the present application pre-sets a set threshold value corresponding to each attack type for better attack detection. After obtaining the number of attacks of each attack type within the preset time length through step S31, the number of attacks of each attack type within the preset time length is compared with the corresponding set threshold value to obtain the corresponding comparison result.
[0052] Step S33: Determine whether to issue an abnormality alarm corresponding to each attack type according to the comparison result.
[0053] In this embodiment, after the corresponding comparison result is obtained through step S32, when the number of attacks of a certain attack type occurring within a preset time period is greater than or equal to the set threshold corresponding to the attack type, an abnormal alarm is given to the user that the vehicle CAN network is attacked by the network of the attack type, and the corresponding attack intensity is determined based on the degree to which the number of attacks of the attack type occurring within the preset time period is greater than the set threshold corresponding to the attack type, and the attack intensity is prompted when the abnormal alarm of the vehicle CAN network being attacked by the network of the attack type is given to the user, so that the user can respond in time. At the same time, according to the comparison result, it is determined how many types of attacks have occurred, and when the number of attack types is greater than or equal to the preset threshold, an abnormal alarm is given to the user that the vehicle CAN network is attacked by multiple types of joint network attacks, and the corresponding attack intensity is determined based on the degree to which the number of attack types is greater than the preset threshold, and the attack intensity is prompted when the abnormal alarm of the vehicle CAN network being attacked by multiple types of joint network attacks is given to the user, so that the user can respond in time.
[0054] In combination with the above embodiments, in one implementation, the embodiment of the present application also provides an attack type detection method for an automobile communication network. In the attack type detection method for an automobile communication network, an attack network traffic sequence for training an attack type prediction model is constructed, including: determining the second data frame number of a single sub-network traffic sequence group according to the number of data frames of the attack network traffic sequence to be generated and the first data frame number of the attack data frame to be inserted; dividing the collected normal network traffic sequence into multiple sub-network traffic sequence groups of the second data frame number in turn; and randomly inserting the attack data frames of the first data frame number under the target attack type into the sub-network traffic sequence group to obtain the corresponding attack network traffic sequence.
[0055] In this embodiment, before obtaining a qualified attack type prediction model that can be used to predict the attack type of the network traffic sequence of the automobile CAN network, it is necessary to perform model training on the established initial model, and it is difficult to obtain the attack traffic sequence containing the attack data frame for model training. Therefore, the present application provides an implementation method for automatically constructing an attack network traffic sequence to reduce the time and economic cost of manually collecting the attack traffic sequence.
[0056] In this embodiment, the proposed implementation process of the automatic construction of the attack network traffic sequence is as follows: This application finds that the automobile CAN network will be subject to various types of attacks, such as DoS attacks, Fuzzing attacks, Replay attacks, Spoofing / Masquerade attacks, etc. DoS attacks may manifest as abnormally frequent frames of certain high-priority CAN IDs, occupying bus bandwidth; Fuzzing attacks may involve a large number of random or invalid CAN IDs, trying to crash the receiver; Replay attacks may show repeated CAN ID sequences, indicating that the attacker replays previously captured frames; Spoofing / Masquerade attacks may show uncommon CAN ID combinations, indicating that the attacker is disguised as a legitimate ECU. Normal automobile CAN network communications usually show obvious periodicity. Therefore, in order to efficiently and quickly generate an attack network traffic sequence with the characteristics contained in the attack type, this application obtains the attack network traffic sequence of the corresponding attack type by randomly inserting the attack data frame of the corresponding attack type into the normal network traffic sequence. This construction method not only destroys the periodicity of normal automobile CAN network communication, so that the normal network traffic sequence becomes an attack network traffic sequence after the attack data frame is inserted, but also the generated attack network traffic sequence retains the characteristics of the corresponding attack type. For example, when constructing an attack network traffic sequence of a DoS attack type, a large number of data frames of a high-priority CAN ID are randomly inserted into a normal network traffic sequence to construct an attack network traffic sequence of a DoS attack type; when constructing an attack network traffic sequence of a Fuzzing attack type, a large number of data frames of a random or invalid CAN ID are randomly inserted into a normal network traffic sequence to construct an attack network traffic sequence of a Fuzzing attack type; when constructing an attack network traffic sequence of a Replay attack type, a data frame sequence of multiple repeated CANID sequences is randomly inserted into a normal network traffic sequence to construct an attack network traffic sequence of a Replay attack type. For the attack network traffic sequence of the Replay attack type, when inserting, a data frame sequence of a single repeated CAN ID sequence needs to be randomly inserted into the normal network traffic sequence as a single attack data frame to avoid destroying the repetitive characteristics of the data frame sequence; when constructing an attack network traffic sequence of a Spoofing / Masquerade attack type, a data frame sequence of multiple uncommon CAN ID sequences is randomly inserted into the normal network traffic sequence to construct an attack network traffic sequence of a Spoofing / Masquerade attack type. When inserting, a single uncommon CAN The data frame sequence of the ID sequence is randomly inserted into the normal network traffic sequence as a single attack data frame to avoid destroying the characteristic that the data frame sequence belongs to an uncommon sequence.
[0057] In this embodiment, the implementation method of automatically constructing the attack network traffic sequence is as follows: Figure 3 As shown, the number of data frames of the attack network traffic sequence to be generated is determined in advance based on the total length of the data frames in a single network traffic sequence that will be input into the trained attack type prediction model later, such as Figure 3 p in . At the same time, the number of data frames of the attack data frame to be inserted into the normal network traffic sequence to construct the attack traffic sequence is preset, and the number of data frames is the first number of data frames of the attack data frame to be inserted, such as Figure 3 q in . The number of data frames of the attack network traffic sequence to be generated is pre-determined and the first number of data frames of the attack data frame to be inserted into the normal network traffic sequence to construct the attack traffic sequence is subtracted to obtain the number of data frames of a single sub-network traffic sequence group. This number of data frames is the second number of data frames of a single sub-network traffic sequence group, i.e., pq. In the actual construction process, the normal network traffic sequence actually collected during the normal driving of the vehicle (e.g., Figure 3 As shown, the total number of data frames of the normal network traffic sequence is set to N) and is sequentially divided into a plurality of sub-network traffic sequence groups whose number of data frames is the second number of data frames, such as Figure 3N / (pq) in the equation. Finally, the attack data frames of the first data frame number under the target attack type are randomly inserted into the same sub-network traffic sequence group, and an attack network traffic sequence corresponding to the same sub-network traffic sequence group can be obtained, wherein the target attack type can be any attack type in this embodiment. For example, based on the total length of the data frames in the single network traffic sequence that will be input into the trained attack type prediction model later being 200, the number of data frames of the attack network traffic sequence to be generated is determined to be 200, and the first number of data frames of the attack data frames to be inserted into the normal network traffic sequence is pre-set to 40. The number of data frames of the determined attack network traffic sequence to be generated, 200, is subtracted from the first number of data frames of the attack data frames to be inserted into the normal network traffic sequence, 40, to obtain the number of data frames of the single sub-network traffic sequence group, 160, which is the second number of data frames of the single sub-network traffic sequence group. Then, the normal network traffic sequence (assuming the length is 16000) collected during normal driving of the vehicle is divided into multiple (i.e., 100) sub-network traffic sequence groups with the number of data frames being the second number of data frames being 160. Finally, the attack data frames with the first number of data frames being 40 under the target attack type are randomly inserted into the same sub-network traffic sequence group, and a corresponding attack network traffic sequence can be obtained. The obtained attack network traffic sequence is an attack network traffic sequence containing 40 attack data frames under the target attack type. The number of data frames in the attack network traffic sequence is the same as the total length of the data frames in the single network traffic sequence that will be subsequently input into the trained attack type prediction model, which is 200. Each sub-network traffic sequence group divided by the same implementation method can construct a corresponding attack network traffic sequence.
[0058] In this embodiment, a certain number of attack network traffic sequences are created for each attack type through the same implementation method, and each attack traffic sequence is labeled with the attack type according to the attack type to which each attack traffic sequence belongs. A large number of network traffic sequences of multiple attack types labeled with the attack type are composed into an attack network traffic sequence data set, and the composed attack network traffic sequence data set and the normal network traffic data set together constitute a total training data set for training the constructed initial model to obtain a qualified attack type prediction model. Among them, the normal network traffic data set records a large number of normal network traffic sequences, and the data frame length of each normal network traffic sequence in these normal network traffic sequences is the same as the total length of the data frames in a single network traffic sequence that will be input into the trained attack type prediction model later.
[0059] In combination with the above embodiments, in one implementation, the embodiment of the present application further provides an attack type detection method for an automobile communication network. In the attack type detection method for an automobile communication network, the second data frame number of a single sub-network traffic sequence group is determined according to the number of data frames of the attack network traffic sequence to be generated and the first data frame number of the attack data frame to be inserted, including: determining the second data frame number of a single sub-network traffic sequence group under the target attack type according to the number of data frames of the attack network traffic sequence to be generated and the first data frame number of the attack data frame to be inserted under the target attack type.
[0060] In this embodiment, since the types of attacks that the automobile CAN network may be subjected to are various, and the attack frequencies of different attack types in a short period of time are different, this application is to construct an attack network traffic sequence that is more in line with the actual attack scenario. When constructing the attack network traffic sequence of different attack types, this application determines the attack frequencies of various attack types in the set time under the actual attack scenario in advance through statistical analysis for different attack types. Based on the determined attack frequencies corresponding to each of the various attack types, the number of data frames of the attack data frames to be inserted corresponding to each of the different attack types is pre-set.
[0061] Specifically: the number of data frames of the attack network traffic sequence to be generated is determined in advance based on the total length of the data frames in a single network traffic sequence that will be input into the trained attack type prediction model later. At the same time, the number of data frames of the attack data frames to be inserted into the normal network traffic sequence under the target attack type is pre-set, and the number of data frames is the first number of data frames of the attack data frames to be inserted under the target attack type, wherein the target attack type can be any attack type, and different attack types have their own corresponding first data frame number values. The number of data frames of the attack network traffic sequence to be generated is pre-subtracted from the first number of data frames of the attack data frames to be inserted into the normal network traffic sequence under the target type, and the number of data frames of a single sub-network traffic sequence group under the target attack type is determined, and the number of data frames is the second number of data frames of a single sub-network traffic sequence group under the target attack type. In the actual construction process, the normal network traffic sequence actually collected during normal driving of the vehicle is divided into multiple sub-network traffic sequence groups with the number of data frames being the second number of data frames under the target attack type. Finally, the attack data frames of the first data frame number under the target attack type are randomly inserted into the same sub-network traffic sequence group under the target attack type, and an attack network traffic sequence under a target attack type corresponding to the same sub-network traffic sequence group can be obtained.
[0062] For example, based on the total length of the data frames in a single network traffic sequence to be input into the trained attack type prediction model later being 200, the number of data frames of the attack network traffic sequence to be generated is determined to be 200, the first number of data frames of the attack data frames to be inserted into the normal network traffic sequence under attack type A is preset to be 40, and the first number of data frames of the attack data frames to be inserted into the normal network traffic sequence under attack type B is preset to be 50. Subtract the determined number of data frames of the attack network traffic sequence to be generated, 200, from the first number of data frames of the attack data frames to be inserted into the normal network traffic sequence under attack type A, 40, to obtain the number of data frames of the single sub-network traffic sequence group under attack type A, 160, which is the second number of data frames of the single sub-network traffic sequence group under attack type A. Subtract the number of data frames 200 of the attack network traffic sequence to be generated from the first number of data frames 50 of the attack data frames to be inserted into the normal network traffic sequence under attack type B, and obtain the number of data frames 150 of the single sub-network traffic sequence group under attack type B, which is the second number of data frames of the single sub-network traffic sequence group under attack type B. Then, the normal network traffic sequence (assuming the length is 16000) actually collected during normal driving of the vehicle is divided into multiple (i.e., 100) sub-network traffic sequence groups whose number of data frames is 160, the second number of data frames under attack type A. Then, the normal network traffic sequence (assuming the length is 16000) actually collected during normal driving of the vehicle is divided into multiple (i.e., 106) sub-network traffic sequence groups whose number of data frames is 150, the second number of data frames under attack type B, and the remaining 100 data frames cannot form a sub-network traffic sequence of the second number of data frames under attack type B. Finally, the attack data frames with the first data frame quantity of 40 under attack type A are randomly inserted into the same sub-network traffic sequence group under attack type A, and an attack network traffic sequence corresponding to attack type A can be obtained. The obtained attack network traffic sequence is an attack network traffic sequence containing 40 attack data frames under attack type A. The number of data frames in the attack network traffic sequence is the same as the total length of data frames in a single network traffic sequence that will be subsequently input into the trained attack type prediction model, both of which are 200. Finally, the attack data frames with the first data frame quantity of 50 under attack type B are randomly inserted into the same sub-network traffic sequence group under attack type B, and an attack network traffic sequence corresponding to attack type B can be obtained. The obtained attack network traffic sequence is an attack network traffic sequence containing 50 attack data frames under attack type B. The number of data frames in the attack network traffic sequence is the same as the total length of data frames in a single network traffic sequence that will be subsequently input into the trained attack type prediction model, both of which are 200.
[0063] In combination with the above embodiments, in one implementation, the embodiment of the present application further provides a method for detecting attack types in an automobile communication network. In the method for detecting attack types in an automobile communication network, before step S1, the method further includes step S01: determining the number of data frames of a network traffic sequence input into the automobile communication network.
[0064] In this embodiment, in order to ensure the real-time detection of attacks on the automobile CAN network, the present application performs attack type detection on attack network traffic sequences with multiple different numbers of data frames in advance, and determines the time difference between the time when the attack behavior actually occurs and the time difference between the type of attack determined to occur by the detection, and determines the best time difference from all the time differences. The best time difference can ensure the real-time detection of the attack while avoiding the problem of too high detection frequency caused by taking a smaller number of data frames for attack detection each time. This is because taking a smaller number of data frames for attack detection each time can improve the real-time detection of the attack, but the detection frequency is too high, which will occupy computing resources for a long time. Therefore, the present application determines the number of data frames corresponding to the best time difference as the length of a network traffic sequence for each attack detection, and the number of data frames corresponding to the best time difference is the setting value for whether to perform attack detection confirmation. Specifically, first determine the number of data frames of the network traffic sequence currently input to the automobile CAN network that has not yet been subjected to attack detection.
[0065] In the present application, when the method further includes step S01 before step S1, step S1 may include: when the number of data frames reaches a set value, determining a corresponding undirected weighted graph according to the arbitration field of the data frame in the network traffic sequence input into the automobile communication network.
[0066] In this embodiment, when it is determined that the number of data frames of the network traffic sequence currently input into the automobile CAN network that has not yet been attacked has reached a set value, the arbitration field of the data frame in the network traffic sequence of the current set value is determined, and a corresponding undirected weighted graph is established based on the determined arbitration field to predict the attack type.
[0067] In combination with the above embodiments, in one implementation, the embodiment of the present application also provides an attack type detection method for an automobile communication network. In the attack type detection method for an automobile communication network, when the attack type prediction model is a graph neural network model, the attack type prediction model is used to extract features from the undirected weighted graph, and the extracted features are predicted to perform attack types to obtain corresponding prediction results, including: performing physical sign extraction on the undirected weighted graph through the graph convolution layer of the graph neural network model; compressing the extracted features into a low-dimensional vector space through the node aggregation layer of the graph neural network model to obtain a first feature; and predicting the attack type of the first feature through the graph neural network model to obtain a corresponding prediction result.
[0068] In this embodiment, when the attack type prediction model in this application is a graph neural network model, one implementation of step S2 is: extracting features of an undirected weighted graph determined based on the arbitration field of a data frame in a network traffic sequence of an input automobile CAN network through the graph convolution layer of the graph neural network model, and then compressing the extracted features to a low-dimensional vector space through the node aggregation layer of the graph neural network model to obtain the corresponding first feature, and finally predicting the attack type through the first feature obtained after space compression through the graph neural network model to obtain a prediction result corresponding to the network traffic sequence of the input automobile CAN network. Among them, the qualified trained graph neural network model also includes a Dropout layer, which is used to randomly shut down some neurons during the training process of the graph neural network model, so as to force the model not to rely on a single feature, thereby achieving the purpose of preventing the model from overfitting. Among them, The first graph convolutional layer in the The layer contains a nonlinear activation function Relu, which is used to add nonlinear features so that the model can capture complex graph structures.
[0069] Based on the same inventive concept, an embodiment of the present application provides an attack type detection system for an automobile communication network, such as Figure 4 As shown, the system 400 includes: The data preprocessing module 401 is used to determine a corresponding undirected weighted graph according to the arbitration field of the data frame in the network traffic sequence input into the automobile communication network, wherein the graph data nodes in the undirected weighted graph are composed of the arbitration field; An attack detection module 402 is used to extract features from the undirected weighted graph through an attack type prediction model, and predict attack types based on the extracted features to obtain corresponding prediction results; The abnormality alarm module 403 is used to make corresponding abnormality alarms according to the prediction results.
[0070] Optionally, the data preprocessing module 401 includes: An arbitration field extraction module, used for extracting arbitration fields from each data frame of a network traffic sequence input into the automobile communication network; A graph data node creation module, used to create corresponding graph data nodes according to the extracted arbitration fields; A vector representation determination module, used for converting the extracted arbitration field into a feature vector, and using the feature vector as a vector representation of a graph data node corresponding to the arbitration field; An undirected graph construction module, used to establish undirected edges for graph data nodes corresponding to arbitration fields having an adjacency relationship according to the adjacency relationship between arbitration fields, so as to construct an undirected graph, wherein the adjacency relationship is the temporal adjacency of arbitration fields of data frames in a network traffic sequence; A weight determination module, used to determine the weight of each undirected edge in the undirected graph according to the repeated adjacency relationship between arbitration fields; The data preprocessing submodule is used to construct a corresponding undirected weighted graph based on the undirected graph and the weights of each undirected edge.
[0071] Optional, graph data node creation module, including: A first creation module, used to determine whether the extracted arbitration field exists in an arbitration field data set, where the arbitration field data set is used to record a data set of arbitration fields corresponding to the created graph data nodes; The second creation module is used to create a graph data node corresponding to the extracted arbitration field if it does not exist.
[0072] Optionally, a vector representation determination module includes: A first conversion module is used to filter the first bit data of the arbitration field extracted, and perform base conversion on each bit data of the arbitration field after filtering to obtain target base data corresponding to each bit data in the target base; A second conversion module, used for converting the target base data into floating point data of a floating point type in a set interval by using a preset algorithm; A splicing module, used for splicing each floating point data of the arbitration field to obtain a feature vector corresponding to the arbitration field; The vector representation determination submodule is used to use the feature vector as the vector representation of the graph data node corresponding to the arbitration field.
[0073] Optionally, the abnormality alarm module 403 includes: An attack quantity determination module, used to determine the number of attacks of various attack types within a preset time period according to the prediction result; A comparison result determination module is used to compare the number of attacks of various attack types with the corresponding set thresholds to obtain a comparison result; The abnormality alarm submodule is used to determine whether to perform abnormality alarms corresponding to various attack types according to the comparison results.
[0074] Optionally, the system 400 further includes an attack network traffic sequence generation module, which is used to construct an attack network traffic sequence for training an attack type prediction model; the attack network traffic sequence generation module includes: A second data frame quantity determination module, used to determine the second data frame quantity of a single sub-network traffic sequence group according to the data frame quantity of the attack network traffic sequence to be generated and the first data frame quantity of the attack data frame to be inserted; A network traffic sequence group division module, used for sequentially dividing the collected normal network traffic sequence into a plurality of sub-network traffic sequence groups of a second number of data frames; The attack data frame insertion module is used to randomly insert the attack data frames of the first data frame quantity under the target attack type into the sub-network traffic sequence group to obtain the corresponding attack network traffic sequence.
[0075] Optionally, a second data frame quantity determination module is used to determine the second data frame quantity of a single sub-network traffic sequence group under the target attack type based on the data frame quantity of the attack network traffic sequence to be generated and the first data frame quantity of the attack data frames to be inserted under the target attack type.
[0076] Optionally, the system 400 further includes: a data frame quantity determination module, used to determine the number of data frames of a network traffic sequence input into the automobile communication network; The data preprocessing module 401 is used to determine the corresponding undirected weighted graph according to the arbitration field of the data frame in the network traffic sequence input into the automobile communication network when the number of data frames reaches a set value.
[0077] Optionally, when the attack type prediction model in the attack detection module 402 is a graph neural network model, the attack detection module 402 is used to extract physical signs of the undirected weighted graph through the graph convolution layer of the graph neural network model; and to compress the extracted features into a low-dimensional vector space through the node aggregation layer of the graph neural network model to obtain a first feature; and to predict the attack type of the first feature through the graph neural network model to obtain a corresponding prediction result.
[0078] In this embodiment, if Figure 5As shown, the attack type detection system for an automobile communication network provided by the present application mainly includes a data preprocessing module, an attack detection module, an attack network traffic sequence generation module and an abnormal alarm module. Before deployment, it is necessary to train the graph neural network model configured in the attack detection module to obtain a qualified graph neural network model that can be used to predict the attack type of the automobile CAN network. Before training, in order to efficiently obtain a large number of attack network traffic sequence data of different attack types for model training, the present application will generate a large number of attack network traffic sequence data of different attack types through the attack network traffic sequence generation module based on the long sequence of normal network traffic sequences generated during the normal driving of the vehicle. The specific generation process is similar to the generation process of the attack network traffic sequence in the attack type detection method for an automobile communication network provided by the present application, and will not be repeated here. Based on the generated large number of attack network traffic sequence data of different attack types and a large number of normal network traffic sequence data, each network traffic sequence data is processed by the data preprocessing module to obtain an undirected weighted graph corresponding to each network traffic sequence, and all the obtained undirected weighted graphs constitute a graph data set to train the graph neural network model to obtain a qualified graph neural network model that can be used to predict the attack type of the automobile CAN network. Among them, the data frame lengths of the attack network traffic sequence data and the normal network traffic sequence data in the graph data set are the same, and are both pre-set data frame lengths of set values. After training to obtain a qualified graph neural network model that can be used to predict the type of attacks on the automotive CAN network, the graph neural network model is deployed in the attack detection module, and the corresponding parameter t and the threshold value corresponding to the attack type are set in the attack detection module. The parameter t indicates the network attack on the automotive CAN network determined within time t, and the parameter threshold indicates the number of attacks on the corresponding attack type within time t. After the deployment is completed, the network traffic sequence of the automobile CAN network is collected in real time, and it is determined whether the number of data frames of the collected network traffic sequence reaches the set value. After reaching the set value, the network traffic sequence with the current number of data frames being the set value is input into the data preprocessing module for processing to obtain an undirected weighted graph corresponding to the network traffic sequence, and then the undirected weighted graph is input into the attack detection module to predict the attack type and obtain the corresponding prediction result, which is sent to the abnormal alarm module for analysis to determine the attack type and attack intensity that require abnormal alarm, and the analyzed attack type and attack intensity are visualized and alarmed to the user through the automobile threat perception platform.
[0079] Based on the same inventive concept, an embodiment of the present application provides an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and running on the processor. When the computer program is executed by the processor, it implements the steps in the attack type detection method for an automobile communication network as described in the first aspect of the present application.
[0080] Based on the same inventive concept, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the method for detecting attack types in an automobile communication network as described in the first aspect of the present application are implemented.
[0081] As for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0082] It should be noted that, for the method embodiments, for the sake of simplicity, they are all described as a series of action combinations, but those skilled in the art should be aware that the embodiments of the present application are not limited by the described order of actions, because according to the embodiments of the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present application.
[0083] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0084] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the embodiments of the present application may adopt the form of complete hardware embodiments, complete software embodiments, or embodiments in combination with software and hardware. Moreover, the embodiments of the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0085] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0086] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0087] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0088] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present application.
[0089] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or terminal device including the elements.
[0090] The above is a detailed introduction to the attack type detection method, system, device and medium for an automobile communication network provided by the present application. This article uses specific examples to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for general technical personnel in this field, according to the idea of the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A method for detecting attack types in a vehicle communication network, characterized in that: The method comprises: Determining a corresponding undirected weighted graph according to an arbitration field of a data frame in a network traffic sequence input into the automobile communication network, wherein a graph data node in the undirected weighted graph is composed of the arbitration field; Extracting features from the undirected weighted graph using an attack type prediction model, and predicting attack types based on the extracted features to obtain corresponding prediction results; According to the prediction results, a corresponding abnormal alarm is issued.
2. The method for detecting attack types of an automobile communication network according to claim 1, characterized in that: According to the arbitration field of the data frame in the network traffic sequence input into the automobile communication network, the corresponding undirected weighted graph is determined, including: Extracting arbitration fields from each data frame of a network traffic sequence input into the automotive communication network; Create corresponding graph data nodes based on the extracted arbitration fields; Converting the extracted arbitration field into a feature vector, and using the feature vector as a vector representation of a graph data node corresponding to the arbitration field; According to the adjacency relationship between arbitration fields, undirected edges are established for graph data nodes corresponding to arbitration fields having adjacency relationships, so as to construct an undirected graph, wherein the adjacency relationship is the temporal adjacency of arbitration fields of data frames in a network traffic sequence; Determining the weight of each undirected edge in the undirected graph according to the repeated adjacency relationship between the arbitration fields; Based on the undirected graph and the weights of each undirected edge, a corresponding undirected weighted graph is constructed.
3. The method for detecting attack types of an automobile communication network according to claim 2, characterized in that: According to the extracted arbitration field, create the corresponding graph data node, including: Determine whether the extracted arbitration field exists in an arbitration field data set, where the arbitration field data set is used to record a data set of arbitration fields corresponding to the created graph data node; If not present, create a graph data node corresponding to the extracted arbitration field.
4. The method for detecting attack types of an automobile communication network according to claim 2, characterized in that: Converting the extracted arbitration field into a feature vector, and using the feature vector as a vector representation of a graph data node corresponding to the arbitration field, includes: Filtering the extracted first bit data of the arbitration field, and performing base conversion on each bit data of the filtered arbitration field to obtain target base data corresponding to each bit data in the target base; Convert the target base data into floating point data of a floating point type in a set interval through a preset algorithm; splicing each floating-point data of the arbitration field to obtain a feature vector corresponding to the arbitration field; The feature vector is used as a vector representation of the graph data node corresponding to the arbitration field.
5. The method for detecting attack types of an automobile communication network according to claim 1, characterized in that: According to the prediction results, corresponding abnormal alarms are issued, including: According to the prediction results, determining the number of attacks of various attack types within a preset time period; Compare the number of attacks of various attack types with the corresponding set thresholds to obtain comparison results; According to the comparison result, it is determined whether to issue an abnormality alarm corresponding to various attack types.
6. The method for detecting attack types of an automobile communication network according to claim 1, characterized in that: Construct attack network traffic sequences for training attack type prediction models, including: Determine the second data frame number of the single sub-network traffic sequence group according to the data frame number of the attack network traffic sequence to be generated and the first data frame number of the attack data frame to be inserted; Sequentially dividing the collected normal network traffic sequence into a plurality of sub-network traffic sequence groups of a second number of data frames; The attack data frames of the first data frame quantity under the target attack type are randomly inserted into the sub-network traffic sequence group to obtain the corresponding attack network traffic sequence, and the target attack type is any attack type.
7. The method for detecting attack types of an automobile communication network according to claim 1, characterized in that: Determining the second data frame number of a single sub-network traffic sequence group according to the data frame number of the attack network traffic sequence to be generated and the first data frame number of the attack data frame to be inserted includes: According to the number of data frames of the attack network traffic sequence to be generated and the first number of data frames of the attack data frames to be inserted under the target attack type, the second number of data frames of the single sub-network traffic sequence group under the target attack type is determined.
8. The method for detecting attack types of an automobile communication network according to claim 1, characterized in that: Before determining the corresponding undirected weighted graph according to the arbitration field of the data frame in the network traffic sequence input into the automobile communication network, the method further includes: determining a number of data frames of a sequence of network traffic input into a vehicle communication network; The step of determining a corresponding undirected weighted graph according to an arbitration field of a data frame in a network traffic sequence input into the automobile communication network comprises: When the number of data frames reaches a set value, a corresponding undirected weighted graph is determined according to arbitration fields of data frames in a network traffic sequence input into the automobile communication network.
9. The method for detecting attack types of an automobile communication network according to claim 1, characterized in that: In the case where the attack type prediction model is a graph neural network model, extracting features from the undirected weighted graph using the attack type prediction model, and predicting the attack type of the extracted features to obtain corresponding prediction results include: Performing physical sign extraction on the undirected weighted graph through a graph convolutional layer of a graph neural network model; The extracted features are compressed into a low-dimensional vector space through the node aggregation layer of the graph neural network model to obtain the first feature; The attack type is predicted for the first feature through the graph neural network model to obtain the corresponding prediction result.
10. A vehicle communication network attack type detection system, characterized in that: The system comprises: A data preprocessing module, used for determining a corresponding undirected weighted graph according to an arbitration field of a data frame in a network traffic sequence input into the automobile communication network, wherein a graph data node in the undirected weighted graph is composed of the arbitration field; An attack detection module, used to extract features from the undirected weighted graph through an attack type prediction model, and predict attack types based on the extracted features to obtain corresponding prediction results; The abnormality alarm module is used to make corresponding abnormality alarms according to the prediction results.
11. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and running on the processor, wherein when the computer program is executed by the processor, the steps in the method for detecting attack types in an automobile communication network as described in any one of claims 1 to 9 are implemented.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the method for detecting attack types in an automobile communication network as described in any one of claims 1 to 9 are implemented.
Citation Information
Patent Citations
Low-delay and safe vehicle-mounted intrusion detection method based on deep learning
CN113162902A
Network security early warning method, device and equipment and readable storage medium
CN114205212A
Vehicle-mounted CAN bus abnormal flow detection traceability method and system
CN116827641A