Vehicle network security risk analysis processing method and device, medium and program product
By obtaining dynamic parameters and attack maps, generating network security risk scenarios, and building a simulation environment, it solves the problem that traditional analysis methods are difficult to deal with dynamic network security threats, and realizes the identification and response of dynamic network security risks of intelligent connected vehicles, improving the safety of vehicles.
Patent Information
- Application Number
- CN202510236740.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-27
AI Technical Summary
Traditional network security risk analysis methods are difficult to deal with dynamic network security threats in complex network environments of intelligent connected vehicles. They can only identify potential risks but cannot effectively deal with dynamically changing attack environments.
By obtaining the dynamic parameters and attack diagram of the target vehicle, a network security risk scenario is generated, and a network security risk simulation environment is built to mine network security risk in the simulated environment to obtain new network security risk information.
It realizes the identification and response to network security risks in vehicle systems in dynamic scenarios, provides a basis for optimizing vehicle network security strategies, and improves vehicle safety.
Smart Images

Figure CN120050106A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of vehicle networking, and in particular, to a method, device, medium, and program product for analyzing and processing vehicle network security risks. Background Art
[0002] With the rapid development of intelligent connected vehicles, in-vehicle networks are becoming more complex, and the application of vehicle networking technology has also introduced more network security threats. Traditional network security risk analysis methods are mostly static analysis. In the face of the complex network environment of intelligent connected vehicles, only identifying potential risks in the vehicle system is not sufficient to cope with dynamic network security threats.
[0003] Therefore, there is an urgent need to provide a vehicle network security analysis solution that can cope with dynamic network security threats. Summary of the Invention
[0004] Embodiments of the present application provide a method, device, medium, and program product for analyzing and processing vehicle network security risks, so as to achieve the effect of identifying potential network security risks in the vehicle system in a dynamic scenario.
[0005] In a first aspect, embodiments of the present application provide a method for analyzing and processing vehicle network security risks, including:
[0006] Obtain dynamic parameters corresponding to a target vehicle, where the dynamic parameters represent the variable states of the target vehicle and the variable factors in the attack environment;
[0007] Generate a network security risk scenario corresponding to the target vehicle according to the attack graph and dynamic parameters corresponding to the target vehicle, where the attack graph shows the possible attack paths and attack effects that an attacker may take;
[0008] Build a network security risk simulation environment for the target vehicle according to the electronic and electrical architecture information of the target vehicle and the recognizable network security risks;
[0009] Based on the network security risk simulation environment, perform network security risk mining in the network security risk scenario to obtain new network security risk information for the target vehicle.
[0010] In a possible implementation manner, building a network security risk simulation environment for the target vehicle according to the electronic and electrical architecture information of the target vehicle and the recognizable network security risks includes:
[0011] Obtain network traffic, where the network traffic includes real vehicle data or simulation-generated data;
[0012] Build a network environment for the target vehicle according to the network traffic and the electronic and electrical architecture information to reproduce the communication topology, protocol stack, and network traffic of the electronic and electrical architecture of the target vehicle;
[0013] Integrate trigger events corresponding to dynamic parameters in a network environment to form a dynamic trigger mechanism, and integrate security configurations corresponding to identifiable network security risks according to the identifiable network security risks to form a network security risk simulation environment for the target vehicle. The dynamic trigger mechanism is used to evaluate the impact of dynamic parameters on the network security risks of the target vehicle.
[0014] In one possible implementation, based on the network security risk simulation environment, conduct network security risk mining in a network security risk scenario to obtain new network security risk information for the target vehicle, including:
[0015] Set the dynamic trigger mechanism of the security risk simulation environment based on the target dynamic parameters corresponding to the network security risk scenario. The dynamic trigger mechanism corresponds to the target dynamic parameters, where the dynamic parameters corresponding to different network security risk scenarios are different;
[0016] In the security risk simulation environment, launch an attack on the target vehicle according to the target attack path indicated by the attack graph;
[0017] If the attack is successful, take the target dynamic parameters and the target attack path as new network security risk information for the target vehicle.
[0018] In one possible implementation, generate a network security risk scenario corresponding to the target vehicle according to the attack graph and dynamic parameters corresponding to the target vehicle, including:
[0019] Arrange and combine the attack paths and dynamic parameters shown in the attack graph corresponding to the target vehicle to generate a network security risk scenario corresponding to the target vehicle, where different arrangements and combinations generate different network security risk scenarios.
[0020] In one possible implementation, it further includes:
[0021] Optimize the threat analysis and risk assessment model based on the new network security risk information, and re-identify the network security risks of the vehicle;
[0022] And / or, optimize the security policy of the vehicle network of the target vehicle based on the new network security risk information.
[0023] In one possible implementation, it further includes:
[0024] Dynamically adjust the security policy in the network security risk simulation environment to verify the inhibitory effect of the security policy on attack behaviors under the corresponding network security risk scenario.
[0025] In one possible implementation, the attack graph is obtained through the following method:
[0026] Input the electronic and electrical architecture information into the Threat Analysis and Risk Assessment (TARA) model for threat analysis and risk assessment to obtain the critical assets, potential attack paths, and the priority risk scores of the potential attack paths of the target vehicle.
[0027] Construct an attack graph based on the critical assets, potential attack paths, and the priority risk scores of the potential attack paths.
[0028] In a second aspect, an embodiment of the present application provides a vehicle network security risk analysis and processing device, including:
[0029] An acquisition module, configured to acquire the dynamic parameters corresponding to the target vehicle, where the dynamic parameters represent the variable states of the target vehicle and the variable factors in the attack environment.
[0030] A generation module, configured to generate a network security risk scenario corresponding to the target vehicle according to the attack graph and the dynamic parameters corresponding to the target vehicle, where the attack graph shows the possible attack paths and attack effects that the attacker may take.
[0031] An environment construction module, configured to construct a network security risk simulation environment for the target vehicle according to the electronic and electrical architecture information of the target vehicle and the recognizable network security risks.
[0032] A risk mining module, configured to perform network security risk mining in the network security risk scenario based on the network security risk simulation environment to obtain new network security risk information for the target vehicle.
[0033] In a third aspect, an embodiment of the present application provides a vehicle network security risk analysis and processing device, including: a memory, a processor;
[0034] The memory stores computer execution instructions;
[0035] The processor executes the computer execution instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementation manners of the first aspect.
[0036] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer execution instructions are stored, and when the computer execution instructions are executed by a processor, they are used to implement the above first aspect and / or various possible implementation manners of the first aspect.
[0037] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the above first aspect and / or various possible implementation manners of the first aspect.
[0038] The vehicle network security risk analysis and processing method, device, medium and program product provided by the embodiments of the present application generate dynamic network security risk scenarios by using the variable states of the vehicle and the variable factors in the attack environment as dynamic parameters and combining the dynamic parameters with the attack graph. A network security risk simulation environment for the target vehicle is built according to the electronic and electrical architecture of the vehicle and the recognizable network security risks. The network security risk scenarios are simulated in the network security simulation environment to explore the potential network security risks of the vehicle in the dynamic scenario, and new network security risk information of the vehicle is obtained, providing a basis for optimizing the vehicle network security strategy and improving the vehicle safety. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with the present application and, together with the specification, are used to explain the principles of the present application.
[0040] Figure 1 Schematic flowchart of the vehicle network security risk analysis and processing method provided by the present application Figure 1 ;
[0041] Figure 2 Schematic flowchart of the vehicle network security risk analysis and processing method provided by the present application Figure 2 ;
[0042] Figure 3 Schematic flowchart of the vehicle network security risk analysis and processing method provided by the present application Figure 3 ;
[0043] Figure 4 Schematic flowchart of the vehicle network security risk analysis and processing method provided by the present application Figure 4 ;
[0044] Figure 5 Schematic structural diagram of the vehicle network security risk analysis and processing device provided by the present application;
[0045] Figure 6 Schematic structural diagram of the vehicle network security risk analysis and processing equipment provided by the present application.
[0046] Through the above-mentioned accompanying drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and text descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0048] With the development of vehicle networking technology, vehicles are interconnected internally or both internally and externally through a network, enabling rapid information interaction, and allowing occupants to greatly enjoy the convenience brought by the network during the driving process. However, at the same time, the data assets and personal privacy information carried on vehicles are increasing day by day, the in-vehicle network is becoming increasingly complex, and attackers continuously launch cyberattacks on vehicles through new attack paths, stealing people's data assets and personal privacy information, and even interfering with the vehicle's control signals, disrupting the normal operation of the vehicle, thereby causing losses. Therefore, vehicle network security issues have received extensive attention.
[0049] In the related art, the TARA method is used to identify the data assets in the vehicle and the threat scenarios faced according to the vehicle's electronic and electrical architecture through methods such as brainstorming, historical data analysis, and industry reports, and obtain network security risk information such as the possible attack paths that attackers may take to attack the vehicle and the feasibility ratings of the attack paths. In the above method, the analysis of the vehicle's network security risks is based on static data, and some fixed vehicle parameter data or historical data are used for analysis, without considering dynamic scenarios such as the vehicle's operation process or changes in the attack environment. Therefore, the potential network security risks in the vehicle under dynamic scenarios cannot be identified.
[0050] In response to this, the vehicle network security risk analysis and processing method provided in the embodiments of the present application takes the variable states of the vehicle and the variable factors in the attack environment as dynamic parameters, combines the dynamic parameters with the attack graph to generate the network security risk scenarios corresponding to the target vehicle; builds a network security risk simulation environment that conforms to the vehicle state according to the vehicle's electronic and electrical architecture and the recognizable network risks, and mines the network security risk information under the network security risk scenarios in the network security risk simulation environment, realizes the mining of dynamic network security threats, identifies the potential security risks in the vehicle under dynamic scenarios, obtains new network security risk information of the vehicle, and provides a basis for optimizing the vehicle network security strategy and improving vehicle safety.
[0051] The following uses specific embodiments to elaborate in detail on the technical solution of this application and how the technical solution of this application solves the above technical problems. The following several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below in conjunction with the accompanying drawings.
[0052] Figure 1 Flow schematic of the vehicle network security risk analysis and processing method provided by this application Figure 1 , such as Figure 1 shown, this method includes:
[0053] S101. Obtain the dynamic parameters corresponding to the target vehicle, where the dynamic parameters represent the variable states of the target vehicle and the variable factors in the attack environment.
[0054] Among them, the variable state of the target vehicle refers to the state that changes dynamically during the operation of the target vehicle, such as the real-time network communication state and the vehicle driving state, etc.
[0055] Exemplarily, the real-time network communication state can be represented by the following parameters: network bandwidth, throughput, latency, latency jitter, packet loss rate, round-trip time of data packets, connection success rate, connection interruption rate, session duration, number of reconnections, usage rate of the network device processor, usage rate of the network device memory, link occupancy rate, buffer occupancy rate, protocol state, number of connected users, traffic distribution, and network signal strength, etc. These parameters are quantifiable and adjustable parameters. By using at least one of the above parameters and dynamically adjusting their values, the network communication state in a dynamic scenario can be simulated. The dynamic parameters can represent the process of the above parameters changing dynamically. For example, the dynamic parameters can represent the process of the vehicle network bandwidth changing from 10 Mbps to 1000 Mbps.
[0056] In another example, in addition to the real-time network communication state, the variable state of the target vehicle can also include the driving state of the vehicle, such as the acceleration signal, brake signal, voltage signal of the battery, current signal of the battery, in-vehicle temperature signal, airbag state signal, seat belt state signal, and signals related to the autonomous driving function, etc. The dynamic parameters can represent the process of the above signals changing. For example, the dynamic parameters can represent the process of the vehicle driving speed changing from 30 km / h to 100 km / h.
[0057] In addition, the variable factors in the attack environment refer to network security factors other than the vehicle state, such as the attacker's ability level, the region where the attacker is located, and the tools used by the attacker. The dynamic parameters can represent the process of the attack environment changing.
[0058] S102. Generate a cybersecurity risk scenario for the target vehicle based on the attack graph and dynamic parameters corresponding to the target vehicle. The attack graph shows the possible attack paths and attack effects that an attacker may take.
[0059] There are usually certain security vulnerabilities in the vehicle network environment, and there may be certain correlation relationships between these vulnerabilities. That is, when one vulnerability is successfully exploited, it may create favorable conditions for the exploitation of another vulnerability. Although it is unrealistic to eliminate all vulnerabilities, ignoring the remaining vulnerabilities in the network environment may cause significant harm to critical resources. In order to thoroughly identify all correlation relationships, by simulating the network attack process of an attacker on a network with security vulnerabilities, all attack paths that can reach the target are found, and these paths are represented in the form of a graph. This graph is the attack graph.
[0060] In some embodiments, the TARA method can be used to analyze the security vulnerabilities in the vehicle network environment, and an attack graph can be generated based on the results of the TARA analysis.
[0061] The attack graph contains multiple possible attack paths that an attacker may take. The cybersecurity risk scenario refers to adding dynamic parameters on the basis of the attack paths indicated by the attack graph, which can simulate the situation of vehicle state changes or attack environment changes, and use the attack paths indicated by the attack graph to launch a network attack on the vehicle. Exemplarily, an attack path indicated by the attack graph is to attack the body control system through the second-generation on-board diagnostics standard port (On-Board Diagnostics II, OBD-II), and the attack target is to make the vehicle functions ineffective. By setting dynamic parameters, a cybersecurity risk scenario can be simulated. For example, attacking the body control system through the OBD-II port when the vehicle is accelerating. Further, it can be verified whether the attack can succeed in this cybersecurity risk scenario, so as to obtain the cybersecurity risk information of the target vehicle.
[0062] S103. Build a cybersecurity risk simulation environment for the target vehicle according to the electronic and electrical architecture information of the target vehicle and the recognizable cybersecurity risks.
[0063] Among them, the electronic and electrical architecture information of the vehicle may include in-vehicle controller architecture information, communication protocol information, and external interface information.
[0064] An identifiable network security risk refers to a publicly disclosed network risk vulnerability. Using the electronic and electrical architecture information of a vehicle and modeling the security configurations corresponding to the identifiable network security risks, a network security risk simulation environment that conforms to the actual state of the vehicle is generated. Since the security configurations corresponding to the identifiable network security risk vulnerabilities are integrated, the generated network security simulation environment is immune to the publicly disclosed identifiable network security risk vulnerabilities, which is conducive to further exploring unknown network security risk vulnerabilities.
[0065] In addition, the network security risk simulation environment also integrates trigger events corresponding to dynamic parameters, such as events like vehicle acceleration, changes in the vehicle's network communication environment, and changes in the attacker's location. Through the trigger events, the changes in the network security state of the vehicle in dynamic scenarios can be simulated.
[0066] S104. Based on the network security risk simulation environment, conduct network security risk mining in the network security risk scenario to obtain new network security risk information for the target vehicle.
[0067] Set the trigger event of the network security risk simulation scenario according to the dynamic parameters indicated by the network security risk scenario, and launch an attack on the network security risk simulation environment according to the attack path indicated by the network security risk scenario. Observe the attack result. If the attack is successful, the dynamic parameters and the attack path indicated by the network security risk scenario are the new network security risk information for the target vehicle. Further, the vehicle network security responsible person can design corresponding security configuration plans based on the new network security risk information to make up for the network security risk vulnerabilities.
[0068] The vehicle network security risk analysis and processing method provided by the embodiments of this application fully considers the vehicle network security risk scenarios in dynamic scenarios, introduces dynamic parameters to represent the variable states of the vehicle and the variable factors in the attack environment, and combines the dynamic parameters with the attack graph to form a dynamic network security risk scenario, which represents the scenario where the target vehicle is attacked according to the attack path in the attack graph in a dynamic context. In addition, according to the electronic and electrical architecture information of the target vehicle and the identifiable network security risks, a network security risk simulation environment that conforms to the network security state of the target vehicle is built, and the network security risk scenario is simulated in the network security simulation environment, and the situation where the target vehicle is successfully attacked is observed, so as to explore unknown network security risk information and obtain new network security risk information of the vehicle, providing a basis for optimizing the vehicle network security strategy and improving the vehicle safety.
[0069] Figure 2 Schematic diagram of the vehicle network security risk analysis and processing method provided by the embodiments of the application Figure 2 . Such as Figure 2As shown, in a possible implementation, a network security risk simulation environment for the target vehicle is built according to the electronic and electrical architecture information of the target vehicle and the recognizable network security risks, including:
[0070] S201. Obtain network traffic, where the network traffic includes real vehicle data or simulation-generated data.
[0071] In some implementations, a network protocol interaction tool can be used to simulate and generate network traffic data.
[0072] S202. Build the network environment of the target vehicle according to the network traffic and the electronic and electrical architecture information to reproduce the communication topology, protocol stack, and network traffic of the electronic and electrical architecture of the target vehicle.
[0073] Among them, the electronic and electrical architecture information of the vehicle includes in-vehicle controller architecture information, communication protocol information, and external interface information. Exemplarily, the electronic and electrical architecture information includes Electronic Control Unit (ECU) information, Telematics Control Unit (TCU) information, Controller Area Network (CAN) protocol information, Local Interconnect Network (LIN) protocol information, Ethernet protocol information, OBD-II interface information, vehicle wireless communication interface information, etc. Using the above information, the actual network environment of the target vehicle is fully simulated to verify the risk of network security risk scenarios in the environment later.
[0074] S203. Integrate trigger events corresponding to dynamic parameters in the network environment to form a dynamic trigger mechanism, and integrate security configurations corresponding to the recognizable network security risks according to the recognizable network security risks to form a network security risk simulation environment for the target vehicle. The dynamic trigger mechanism is used to evaluate the impact of dynamic parameters on the network security risks of the target vehicle.
[0075] Among them, on the basis of fully simulating the actual network environment of the target vehicle, a trigger mechanism corresponding to dynamic parameters is added to form a network environment that can change dynamically, and corresponding security configurations are integrated according to the recognizable network security risks. This is to fully avoid known security risks in order to discover unknown network security risks on this basis later.
[0076] The vehicle network security risk analysis and processing method provided by the embodiments of the present application constructs a network security risk simulation environment that conforms to the actual network environment of the target vehicle, and adds a dynamic trigger mechanism corresponding to dynamic parameters to the network security risk simulation environment, so that the network security risk simulation environment can simulate dynamic network security risk scenarios. Security configurations corresponding to identifiable network security risks are integrated into the network security risk simulation environment, fully considering the publicly disclosed network security risks, and providing a basis for exploring unknown network security risks.
[0077] Figure 3 Schematic flow of the vehicle network security risk analysis and processing method provided by the embodiments of the application Figure 3 As Figure 3 shown, in a possible implementation manner, based on the network security risk simulation environment, network security risk mining is performed in the network security risk scenario to obtain new network security risk information for the target vehicle, including:
[0078] S301. Based on the target dynamic parameters corresponding to the network security risk scenario, set the dynamic trigger mechanism of the security risk simulation environment. The dynamic trigger mechanism corresponds to the target dynamic parameters, where the dynamic parameters corresponding to different network security risk scenarios are different.
[0079] The network security risk scenario includes dynamic parameters and an attack graph. In order to simulate the network security risk scenario in the network security risk simulation environment, a dynamic trigger mechanism corresponding to the dynamic parameters is set in the network security risk simulation environment. The dynamic trigger mechanism includes setting dynamic events in the network security risk simulation environment, such as events like vehicle acceleration, vehicle braking, and changes in the vehicle network communication environment. The dynamic parameters corresponding to different network security risk scenarios are different, and different network security risk scenarios are simulated by adjusting the dynamic trigger mechanism.
[0080] S302. In the security risk simulation environment, initiate an attack on the target vehicle according to the target attack path indicated by the attack graph.
[0081] After the trigger event is started, simulate that the attacker initiates an attack on the target vehicle according to the attack path indicated by the network security risk scenario to check whether there are network security vulnerabilities in the vehicle under the dynamic network security risk scenario. If the attack is successful, it means that there are vulnerabilities in the current vehicle's electronic and electrical architecture or network security configuration. The conditions for a successful attack, including the dynamic event and the attack path, are used as new network security risk information.
[0082] S303. If the attack is successful, take the target dynamic parameters and the target attack path as new network security risk information for the target vehicle.
[0083] The vehicle network security risk analysis and processing method provided by the embodiments of this application simulates network security risk scenarios in a network security risk simulation environment to verify whether there is a risk of successful attack in the network security risk scenarios under the current vehicle configuration. In the network security risk simulation environment, a dynamic trigger mechanism corresponding to the dynamic parameters in the network security risk scenario is set to simulate the occurrence of dynamic events. When a dynamic event is triggered, it is simulated that an attacker launches an attack on the vehicle according to the attack path indicated by the attack graph in the network security risk scenario, thereby mining the network security risk vulnerabilities of the vehicle. Based on the results of static network security analysis, this method fully simulates the situation of the vehicle being attacked under dynamic events and realizes the mining of network security risk information in dynamic scenarios.
[0084] In a possible implementation manner, according to the attack graph and dynamic parameters corresponding to the target vehicle, a network security risk scenario corresponding to the target vehicle is generated, including:
[0085] Arrange and combine the attack paths and dynamic parameters shown in the attack graph corresponding to the target vehicle to generate a network security risk scenario corresponding to the target vehicle, where different arrangements and combinations generate different network security risk scenarios.
[0086] In an example, the dynamic parameters include three variable states of the vehicle: reduced network bandwidth, vehicle acceleration, and the activation of the autonomous driving function. The attack graph path indicates two attack paths: attacking the power system through the entertainment system and remotely attacking the vehicle through the vehicle networking system. Then, six network security risk scenarios can be combined according to the above dynamic parameters and attack paths, including: attacking the power system through the entertainment system when the network bandwidth is reduced; remotely attacking the vehicle through the vehicle networking system when the network bandwidth is reduced; attacking the power system through the entertainment system when the vehicle is accelerating; remotely attacking the vehicle through the vehicle networking system when the vehicle is accelerating; attacking the power system through the entertainment system when the autonomous driving function is activated; remotely attacking the vehicle through the vehicle networking system when the autonomous driving function is activated. Further, the above network security risk scenarios can be simulated in the network security risk simulation environment to verify whether there are network security vulnerabilities under the current electronic and electrical architecture and security configuration of the vehicle.
[0087] In another example, the dynamic parameters include variable factors in two attack environments, including: changes in the attack tools used by the attacker and changes in the region where the attacker is located. The attack graph paths indicate that the two attack paths include: attacking the power system through the entertainment system and remotely attacking the vehicle through the vehicle networking system. Then, based on the above dynamic parameters and attack paths, four network security risk scenarios can be obtained, including: attacking the power system through the entertainment system when the attack tools used by the attacker change; remotely attacking the vehicle through the vehicle networking system when the attack tools used by the attacker change; attacking the power system through the entertainment system when the region where the attacker is located changes; and remotely attacking the vehicle through the vehicle networking system when the region where the attacker is located changes. Further, the above network security risk scenarios can be simulated in a network security risk simulation environment to verify whether there are network security vulnerabilities under the current vehicle's electronic and electrical architecture and security configuration.
[0088] The vehicle network security risk analysis and processing method provided by the embodiments of the present application combines the attack paths indicated by the attack graph obtained by the static analysis method with dynamic parameters to form dynamic network security risk scenarios, fully considering the vehicle's security during the dynamic changes of the vehicle state and the changes in the attack environment, and realizing the excavation of vehicle network security risk vulnerabilities in dynamic scenarios.
[0089] In a possible implementation manner, the vehicle network security risk analysis and processing method further includes:
[0090] Optimizing the threat analysis and risk assessment model based on the new network security risk information and re-identifying the vehicle's network security risks; and / or optimizing the security policy of the vehicle network of the target vehicle based on the new network security risk information.
[0091] Exemplarily, through the threat analysis and risk assessment model, a static network security risk analysis of the vehicle is performed to obtain the attack graph of the vehicle. After obtaining the new network security risk information, the new network security risk information is used as intelligence to feedback and optimize the threat analysis and risk assessment model, and a new attack graph is obtained through iterative update. Further, after obtaining the new attack graph, the attack paths indicated by the new attack graph can be combined with the dynamic parameters to form new vehicle network security risk scenarios, and the network security risk scenarios can be simulated in a network security risk simulation environment to further excavate unknown network security risk information.
[0092] In addition, after obtaining the vehicle's network security risk information, the security policy of the vehicle network can be optimized according to the network security risk information, such as enhancing communication encryption, improving firewall rules, or adjusting access control policies, to enhance the vehicle's security.
[0093] The vehicle network security risk analysis and processing method provided by the embodiments of the present application, after obtaining network security risk information, sets up a feedback mechanism, uses the network security risk information to update the threat analysis and risk assessment model, so as to obtain a new attack graph, and mines the unknown network security risk information in the vehicle based on the new attack graph, and continuously iterates to increase the depth of network security risk information mining. After obtaining the network security risk information, vehicle network security personnel can adopt technical means to formulate security policies corresponding to the network security risk information according to the network security risk information to make up for the existing network security vulnerabilities on the vehicle and improve the security of the vehicle.
[0094] In a possible implementation manner, the vehicle network security risk analysis and processing method further includes: dynamically adjusting the security policy in the network security risk simulation environment to verify the inhibitory effect of the security policy on the attack behavior in the corresponding network security risk scenario.
[0095] It can be understood that the network security risk simulation environment fully simulates the electronic and electrical architecture of the target vehicle. Deploying or adjusting the security policy in the network security risk simulation environment, such as adjusting the communication encryption rule or adjusting the Intrusion Detection and Prevention Systems (IDPS) rule, and simulating an attacker to launch an attack on the target vehicle and observing the possibility of successful attack, can verify the inhibitory effect of the security policy on the attack behavior in the corresponding network security risk scenario.
[0096] The vehicle network security risk analysis and processing method provided by the embodiments of the present application builds a network security risk simulation environment and verifies the security policy in the environment, thereby continuously optimizing and improving the security policy of the vehicle and improving the security of the vehicle.
[0097] In a possible implementation manner, the attack graph is obtained through the following method:
[0098] Input the electronic and electrical architecture information into the Threat Analysis and Risk Assessment (TARA) model for threat analysis and risk assessment to obtain the key assets, potential attack paths, and priority risk scores of the potential attack paths of the target vehicle; construct an attack graph according to the key assets, potential attack paths, and priority risk scores of the potential attack paths.
[0099] The TARA model is a systematic threat analysis and risk assessment method that helps reduce the security risks of a system by identifying threats, analyzing risks, and formulating mitigation measures. The threat analysis and risk assessment of the TARA model generally include the following steps: Asset identification, based on the electronic and electrical architecture information of the vehicle, identify the assets with cybersecurity characteristics and their possible damage scenarios; Threat scenario identification, list the potential damage scenarios and analyze their corresponding threat scenarios; Impact rating, evaluate the impact level of each damage scenario; Attack path analysis, determine the possible attack paths to achieve the threat scenario; Attack feasibility rating, evaluate the feasibility of the attack paths; Risk value determination, determine the risk handling decision based on the impact level, attack path, and risk value; Risk handling decision, select appropriate risk handling measures, such as eliminating, mitigating, transferring, or accepting risks.
[0100] In one implementation, after obtaining the critical assets, potential attack paths, and the priority risk scores of the potential attack paths of the target vehicle through the TARA model, the attack graph is constructed based on the critical assets, potential attack paths, and the priority risk scores of the potential attack paths, including the following steps:
[0101] Select a tool, use an attack graph construction tool, such as Graphviz, Cytoscape, or a custom script.
[0102] Define nodes, each node represents a component in the system, such as an asset, a vulnerability, or an attack step, and create nodes for each step in the critical assets and attack paths.
[0103] Define edges, each edge represents a possible path for the attacker to move from one node to another, and use arrows to indicate the attack direction.
[0104] Annotate risks, annotate risk scores such as high, medium, or low on the nodes or edges. Exemplarily, different risk levels can be distinguished using colors or shapes.
[0105] Optimize the layout, adjust the layout of the nodes and edges to make the attack graph easy to understand.
[0106] The vehicle cybersecurity risk analysis and processing method provided by the embodiments of the present application uses the TARA model to perform static cybersecurity risk analysis on the target vehicle, obtains the critical assets, potential attack paths, and the priority risk scores of the potential attack paths, and further generates an attack graph based on the critical assets, potential attack paths, and the priority risk scores of the potential attack paths, providing a basis for constructing dynamic cybersecurity risk scenarios based on the attack graph and mining vehicle cybersecurity risk information.
[0107] Figure 4 Schematic diagram of the vehicle cybersecurity risk analysis and processing method provided by the embodiments of the application Figure 4. As Figure 4 shown, in one embodiment, the vehicle network security analysis and processing method flow includes the following steps:
[0108] S401. Obtain the electronic and electrical architecture information of the vehicle, and use the TARA model to analyze to obtain the critical assets, potential attack paths, and priority risk scores of the potential paths of the vehicle.
[0109] S402. Construct an attack graph based on the critical assets, potential attack paths, and priority risk scores of the potential paths of the vehicle.
[0110] S403. Construct a network security risk scenario based on the attack graph and dynamic parameters.
[0111] S404. Build a network security risk simulation environment.
[0112] Specifically, use the electronic and electrical architecture information of the vehicle and the recognizable network security risks to build a network security risk simulation environment for the target vehicle.
[0113] S405. Mine the potential network security risk information in the network security risk scenario in the network security risk simulation environment, and verify the security policy.
[0114] S406. Optimize the security policy, improve the vehicle network access rules, and update the TARA model.
[0115] After completing the update of the TARA model, step S401 can be re-executed to achieve iterative update of the entire process.
[0116] The vehicle network security risk analysis and processing method provided by this application, on the basis of analyzing network security risks by the static TARA method, introduces dynamic parameters, constructs a dynamic network security risk scenario, builds a network security risk simulation environment, simulates the network security risk scenario in the network security simulation risk environment, mines the potential network security risk information in the network security risk scenario, and finally iteratively updates the vehicle's security policy, network access rules, and TARA model according to the mined network security risk information to improve the vehicle's security.
[0117] Figure 5 is a schematic structural diagram of the vehicle network security risk analysis and processing device provided by this application. As Figure 5 shown, the vehicle network security risk analysis and processing device 50 provided in this embodiment includes:
[0118] An acquisition module 501, configured to acquire dynamic parameters corresponding to the target vehicle, where the dynamic parameters represent the variable states of the target vehicle and the variable factors in the attack environment;
[0119] A generation module 502, configured to generate a network security risk scenario corresponding to the target vehicle according to the attack graph and dynamic parameters corresponding to the target vehicle, where the attack graph shows the attack paths and attack effects that an attacker may take;
[0120] An environment building module 505, configured to build a network security risk simulation environment for the target vehicle according to the electronic and electrical architecture information of the target vehicle and the recognizable network security risks;
[0121] A risk mining module 504, configured to perform network security risk mining in the network security risk scenario based on the network security risk simulation environment to obtain new network security risk information for the target vehicle.
[0122] In a possible implementation manner, the environment building module 505 is specifically configured to:
[0123] Obtain network traffic, where the network traffic includes real vehicle data or simulation-generated data;
[0124] Build a network environment for the target vehicle according to the network traffic and the electronic and electrical architecture information to reproduce the communication topology, protocol stack, and network traffic of the electronic and electrical architecture of the target vehicle;
[0125] Integrate a trigger event corresponding to the dynamic parameter in the network environment to form a dynamic trigger mechanism, and integrate a security configuration corresponding to the recognizable network security risk according to the recognizable network security risk to form a network security risk simulation environment for the target vehicle. The dynamic trigger mechanism is used to evaluate the impact of the network security risk on the target vehicle.
[0126] In a possible implementation manner, the risk mining module 504 is specifically configured to:
[0127] Set the dynamic trigger mechanism of the security risk simulation environment based on the target dynamic parameter corresponding to the network security risk scenario. The dynamic trigger mechanism corresponds to the target dynamic parameter, where the dynamic parameters corresponding to different network security risk scenarios are different;
[0128] In the security risk simulation environment, launch an attack on the target vehicle according to the target attack path indicated by the attack graph;
[0129] If the attack is successful, use the target dynamic parameter and the target attack path as new network security risk information for the target vehicle.
[0130] In a possible implementation manner, the generation module 502 is specifically configured to:
[0131] Perform permutation and combination on the attack paths and dynamic parameters shown in the attack graph corresponding to the target vehicle to generate a network security risk scenario corresponding to the target vehicle, where different permutation and combination generate different network security risk scenarios.
[0132] In a possible implementation, the vehicle network security risk analysis and processing device 50 further includes an optimization module 505 for:
[0133] Based on the new network security risk information, optimize the threat analysis and risk assessment model, and re-identify the network security risks of the vehicle;
[0134] And / or, based on the new network security risk information, optimize the security policy of the vehicle network of the target vehicle.
[0135] In a possible implementation, the vehicle network security risk analysis and processing device 50 further includes a verification module 506 for:
[0136] Dynamically adjust the security policy in the network security risk simulation environment to verify the inhibitory effect of the security policy on attack behaviors under the corresponding network security risk scenarios.
[0137] The vehicle network security risk analysis and processing device provided in this embodiment can execute the method provided in the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.
[0138] Figure 6 This is a schematic structural diagram of the vehicle network security risk analysis and processing device provided in this application. As Figure 6 shown, the electronic device 60 provided in this embodiment includes: at least one processor 601 and a memory 602. Optionally, the device 60 further includes a communication component 603. Among them, the processor 601, the memory 602, and the communication component 603 are connected through a bus 606.
[0139] In the specific implementation process, at least one processor 601 executes the computer execution instructions stored in the memory 602, so that at least one processor 601 executes the above method.
[0140] The specific implementation process of the processor 601 can refer to the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.
[0141] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the invention may be directly embodied as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor.
[0142] The memory may include a random access memory (RAM), and may also include non-volatile memory (NVM), such as at least one disk memory.
[0143] The bus may be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the buses in the drawings of this application are not limited to only one bus or one type of bus.
[0144] This application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0145] This application also provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the processor executes the computer-executable instructions, the above method is implemented.
[0146] The above-readable storage medium may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk or an optical disc. The readable storage medium may be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0147] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be part of the processor. The processor and the readable storage medium can be located in an Application Specific Integrated Circuits (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in a device.
[0148] The division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Additionally, the couplings or direct couplings or communication connections shown or discussed between each other can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0149] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0150] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0151] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, Read-Only Memory (ROM), Random Access Memory (RAM), magnetic disks or optical discs and other various media that can store program codes.
[0152] Those of ordinary skill in the art will understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments; and the foregoing storage medium includes: various media such as ROM, RAM, magnetic disk, or optical disk that can store program codes.
[0153] Finally, it should be noted that: After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily think of other embodiments of the present invention. The present invention is intended to cover any variations, uses, or adaptations of the present invention, which follow the general principles of the present invention and include known common knowledge or conventional technical means in the technical field not disclosed by the present invention. It is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. A vehicle network security risk analysis and processing method, characterized in that: include: Acquire dynamic parameters corresponding to the target vehicle, wherein the dynamic parameters represent variable states of the target vehicle and variable factors in the attack environment; Generate a network security risk scenario corresponding to the target vehicle according to the attack graph corresponding to the target vehicle and the dynamic parameters, wherein the attack graph shows the attack paths and attack effects that the attacker may take; Building a cybersecurity risk simulation environment for the target vehicle based on the electronic and electrical architecture information of the target vehicle and the identifiable cybersecurity risks; Based on the network security risk simulation environment, network security risk mining is performed in the network security risk scenario to obtain new network security risk information for the target vehicle.
2. The method according to claim 1, characterized in that The step of building a cybersecurity risk simulation environment for the target vehicle based on the electronic and electrical architecture information of the target vehicle and the identifiable cybersecurity risks includes: Acquiring network traffic, wherein the network traffic includes real vehicle data or simulation-generated data; According to the network traffic and the electronic and electrical architecture information, a network environment of the target vehicle is constructed to reproduce the communication topology, protocol stack and network traffic of the electronic and electrical architecture of the target vehicle; In the network environment, trigger events corresponding to the dynamic parameters are integrated to form a dynamic trigger mechanism, and based on the identifiable network security risks, security configurations corresponding to the identifiable network security risks are integrated to form a network security risk simulation environment for the target vehicle. The dynamic trigger mechanism is used to evaluate the impact of dynamic parameters on the network security risks of the target vehicle.
3. The method according to claim 1 or 2, characterized in that: The network security risk simulation environment is based on which network security risk mining is performed in the network security risk scenario to obtain new network security risk information for the target vehicle, including: Based on the target dynamic parameters corresponding to the network security risk scenario, a dynamic trigger mechanism of the security risk simulation environment is set, wherein the dynamic trigger mechanism corresponds to the target dynamic parameters, wherein different network security risk scenarios correspond to different dynamic parameters; In the security risk simulation environment, launching an attack on the target vehicle according to the target attack path indicated by the attack graph; If the attack is successful, the target dynamic parameters and the target attack path are used as new network security risk information for the target vehicle.
4. The method according to claim 1 or 2, characterized in that: The generating, according to the attack graph corresponding to the target vehicle and the dynamic parameter, a network security risk scenario corresponding to the target vehicle comprises: The attack path displayed in the attack graph corresponding to the target vehicle and the dynamic parameters are arranged and combined to generate a network security risk scenario corresponding to the target vehicle, wherein different network security risk scenarios are generated by different arrangements and combinations.
5. The method according to claim 1 or 2, characterized in that: Also includes: Based on the new cybersecurity risk information, optimizing threat analysis and risk assessment models, and re-identifying the cybersecurity risk of the vehicle; And / or, based on the new network security risk information, optimizing the security policy of the vehicle network of the target vehicle.
6. The method according to claim 1 or 2, characterized in that: Also includes: Dynamically adjust the security policy in the network security risk simulation environment to verify the inhibitory effect of the security policy on attack behavior in the corresponding network security risk scenario.
7. The method according to claim 1 or 2, characterized in that: The attack graph is obtained by: Inputting the electronic and electrical architecture information into the threat analysis and risk assessment TARA model for threat analysis and risk assessment to obtain the key assets of the target vehicle, potential attack paths, and priority risk scores of the potential attack paths; The attack graph is constructed based on the key assets, the potential attack paths, and the priority risk scores of the potential attack paths.
8. A vehicle network security risk analysis and processing device, characterized in that: include: An acquisition module, used to acquire dynamic parameters corresponding to the target vehicle, wherein the dynamic parameters represent the variable state of the target vehicle and the variable factors in the attack environment; A generation module, used to generate a network security risk scenario corresponding to the target vehicle according to the attack graph corresponding to the target vehicle and the dynamic parameters, wherein the attack graph shows the attack paths and attack effects that the attacker may take; An environment building module, used to build a cybersecurity risk simulation environment for the target vehicle based on the electronic and electrical architecture information of the target vehicle and the identifiable cybersecurity risks; The risk mining module is used to perform network security risk mining in the network security risk scenario based on the network security risk simulation environment to obtain new network security risk information for the target vehicle.
9. A vehicle network security risk analysis and processing device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.