Method and device for establishing automobile information security attack tree model based on artificial intelligence

Through the automotive information security attack tree model based on artificial intelligence, the limitations of traditional attack trees in dealing with new attack methods are solved, and the effective identification and response of security threats in complex automotive information systems is realized, and the targetedness of security protection measures and the overall security of automotive information systems are improved.

CN120050120AInactive Publication Date: 2025-05-27CHINA AUTOMOTIVE TECH & RES CENT CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510519688.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-05-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The traditional automotive information security attack tree reveals its limitations when dealing with new attack methods, making it difficult to effectively identify and deal with complex automotive information system security threats.

Method used

The automotive information security attack tree model based on artificial intelligence is adopted. By acquiring the automobile source data, extracting and constructing feature data, covariance matrix and low-dimensional matrix are built, and historical attack data is used for training, model parameters are optimized, and model nodes and relationships are updated in real time.

Benefits of technology

It can identify which attack paths are more easily exploited by attackers, thereby strengthening targeted security protection measures, providing a basis for risk assessment and security policy formulation, and improving the security of automotive information systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050120A_ABST
    Figure CN120050120A_ABST
Patent Text Reader

Abstract

The invention provides an artificial intelligence-based automobile information security attack tree model establishment method, which comprises the following steps that: at least one item of source data of an automobile is obtained, and the at least one item of source data comprises an electronic control unit log, a vehicle-mounted network data packet, and a communication record or sensor data of the automobile and an external server; extracting and constructing feature data for the automobile information security attack tree model based on the at least one item of source data; constructing the automobile information security attack tree model, and training by using historical attack data to optimize model parameters; and identifying an attack means or an attack form by using the automobile information security attack tree model, and updating nodes of the model or modifying a relationship between the nodes. The invention further discloses an artificial intelligence-based automobile information security attack tree model establishment device and electronic equipment applying the method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to a method, device and computer-readable storage medium for an automotive information security attack tree model based on artificial intelligence. Background Art

[0002] With the continuous improvement of the intelligence and networking level of automobiles, automotive information systems are facing increasingly complex and diverse security threats. Traditional automotive information security attack trees are gradually showing limitations in dealing with new attack means, and the integration of artificial intelligence technology provides an opportunity to build a more accurate and dynamic attack tree model.

[0003] An automotive information security attack tree model is a graphical and structured model used to describe possible attacks on an automotive information system. As a technology to support security countermeasures, an attack tree automatic generation tool has been proposed. This tool takes the structure information of the system to be analyzed as input and analyzes the script (attack script) until a cyber attack occurs. For example, the structure information of the system is information such as devices, communication channels, applications, and security countermeasures. It shows in a tree structure various attack paths and steps that an attacker may take from the initial state to the final attack target. Such a model helps to systematically analyze automotive information security risks and provides a basis for the formulation of security policies and the design of security mechanisms. In the attack tree, attack information such as the attacked device, the attacked application, and the attack method is recorded. Therefore, by referring to the attack tree, system developers can discuss security countermeasures. Summary of the Invention

[0004] The present invention provides a method, device and computer-readable storage medium for establishing an automotive information security attack tree model based on artificial intelligence. The method for establishing an automotive information security attack tree model based on artificial intelligence can identify which attack paths are more likely to be exploited by attackers, so as to strengthen security protection measures in a targeted manner.

[0005] In a first aspect, a method for establishing an automotive information security attack tree model based on artificial intelligence is provided, including: obtaining at least one piece of source data of the vehicle, where the at least one piece of source data includes: electronic control unit logs, in-vehicle network data packets, communication records between the vehicle and an external server, or sensor data; based on the at least one piece of source data, extracting and constructing feature data for the automotive information security attack tree model, including: constructing a covariance matrix of the at least one piece of source data to describe the correlation between different features; solving the covariance matrix to obtain corresponding eigenvalues and eigenvectors, using the eigenvalues to represent the variance magnitude of the data in the direction of the corresponding eigenvectors, sorting the eigenvectors in descending order according to the eigenvalues, and selecting the first several eigenvectors, where, ≤ n, where n represents the dimension, and the first several feature vectors form a low-dimensional matrix; multiply the covariance matrix by the low-dimensional matrix; construct the automotive information security attack tree model, and use historical attack data for training to optimize the model parameters; use the automotive information security attack tree model to identify attack means or attack forms, update the nodes of the model or modify the relationships between the nodes.

[0006] In some embodiments, obtaining at least one source data of the vehicle includes: performing a preprocessing operation on the at least one source data to correct errors, incomplete, non-standard format, and duplicate data in the dataset; performing a standardization process on the data that has completed the preprocessing operation so that different formats of data become standardized data that meets a predetermined format.

[0007] In some embodiments, constructing the automotive information security attack tree model includes: using the ultimate goal of the attack as the root node of the automotive information security attack tree model, where the ultimate goal includes controlling the steering system of the vehicle or obtaining user data of the vehicle; using the sub-goals or intermediate steps required to achieve the ultimate goal as intermediate nodes, and using the most basic attack actions or conditions as leaf nodes. If there are unsolvable intermediate nodes or leaf nodes, deletion operations are performed.

[0008] In some embodiments, using historical attack data for training to optimize the model parameters includes: dividing the preprocessed data into a training set and a test set, and using the training set data to train a support vector machine model; finding the optimal hyperplane parameters through the sequential minimal optimization algorithm so that the classification error of the model on the training set is minimized and meets the condition of a predetermined maximum margin, thereby determining each branch node.

[0009] In some embodiments, it further includes: adjusting the model parameters or optimizing the data collection strategy by means of metric evaluation.

[0010] In some embodiments, the metrics include accuracy, recall rate, and F1 value.

[0011] Second aspect, an apparatus for an artificial intelligence-based automotive information security attack tree model, comprising: a data acquisition module, configured to acquire at least one source data of the vehicle, wherein the at least one source data includes: electronic control unit logs, in-vehicle network data packets, communication records between the vehicle and an external server, or sensor data; a preprocessing module, configured to extract and construct feature data for the automotive information security attack tree model based on the at least one source data, including: constructing a covariance matrix of the at least one source data to describe the correlation between different features; solving the covariance matrix to obtain corresponding eigenvalues and eigenvectors, using the eigenvalues to represent the variance magnitude of the data in the direction of the corresponding eigenvectors, sorting the eigenvectors in descending order according to the eigenvalues, and selecting the first n eigenvectors, where ≤n, n represents the dimension, and forming a low-dimensional matrix with the first n eigenvectors; multiplying the covariance matrix by the low-dimensional matrix; an intelligent processing module, configured to construct the automotive information security attack tree model and train it using historical attack data to optimize the model parameters; a model update module, configured to identify attack means or attack forms using the automotive information security attack tree model, and update the nodes of the model or modify the relationships between the nodes.

[0012] Third aspect, the present invention provides an electronic device, the electronic device comprising: a processor; a memory, on which computer-readable instructions are stored, and when the computer-readable instructions are executed by the processor, the method for establishing an artificial intelligence-based automotive information security attack tree model as described above is implemented.

[0013] Fourth aspect, the present invention further provides a computer-readable storage medium, characterized in that program code is stored in the computer-readable storage medium, and the program code can be called by a processor to execute the method for establishing an artificial intelligence-based automotive information security attack tree model as described above.

[0014] Compared with the prior art, the present invention can at least achieve one of the following beneficial effects: First, it provides a reference for risk assessment, helping automotive manufacturers and security researchers comprehensively understand the security risks that the automotive information system may face. By analyzing the attack tree, it can be identified which attack paths are more likely to be exploited by attackers, so as to strengthen security protection measures targeted.

[0015] Second, it provides a basis for formulating security policies. According to the attack means in the attack tree, it is possible to determine the system components, network interfaces, and data types that need to be protected with emphasis. For example, in the case of a high risk of software vulnerability exploitation, automotive manufacturers can strengthen the security testing link in the software development process.

[0016] The Summary of the Invention section is provided to introduce, in a simplified form, a selection of concepts that will be further described in the Detailed Description below. The Summary of the Invention section is not intended to identify key features or essential features of the present disclosure, nor is it intended to limit the scope of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The above and other objects, features, and advantages of the present disclosure will become more apparent from the following more detailed description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, in which like reference numerals generally represent like components in the exemplary embodiments of the present disclosure.

[0018] Figure 1 FIG. shows a schematic diagram of a method for establishing an artificial intelligence-based automotive information security attack tree model provided by an embodiment of the present application; Figure 2 FIG. shows a structural block diagram of an apparatus for an artificial intelligence-based automotive information security attack tree model provided by an embodiment of the present application; Figure 3 FIG. shows a schematic diagram of an electronic device for a method for establishing an artificial intelligence-based automotive information security attack tree model provided by an embodiment of the present application. DETAILED DESCRIPTION

[0019] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited by the embodiments set forth herein. Instead, these embodiments are provided so that the present disclosure will be thorough and complete, and will fully convey the scope of the present disclosure to those skilled in the art.

[0020] As used herein, the term "comprising" and variations thereof mean open-ended inclusion, i.e., "including but not limited to". Unless otherwise specified, the term "or" means "and / or". The term "based on" means "at least partially based on". The terms "an exemplary embodiment" and "an embodiment" mean "at least one exemplary embodiment". The term "another embodiment" means "at least one additional embodiment". The terms "first", "second", etc. may refer to different or the same objects. There may be other explicit and implicit definitions hereinafter.

[0021] The present application provides a method for establishing an artificial intelligence-based automotive information security attack tree model. Please refer to Figure 1 , which is a schematic diagram of the first embodiment of the present application. The following will be described in detail with reference to Figure 1 a method 100 for establishing an artificial intelligence-based automotive information security attack tree model provided by the first embodiment of the present application.

[0022] Step S102: Obtain at least one piece of source data of the vehicle, that is, obtain at least one piece of source data of the vehicle, where the at least one piece of source data includes: electronic control unit logs, in-vehicle network data packets, communication records between the vehicle and an external server, or sensor data. For example, collect information from multiple sources such as the electronic control unit (ECU) logs of the vehicle, in-vehicle network data packets, communication records between the vehicle and an external server, and sensor data. For example, the ECU logs record the operating status and error information of each control unit, and the in-vehicle network data packets reflect the communication situation between different components inside the vehicle. These data are crucial for discovering potential attack signs.

[0023] In some embodiments, obtaining at least one piece of source data of the vehicle includes: performing a preprocessing operation on the at least one piece of source data to correct errors, incompleteness, non-standard formats, and duplicate data in the data set; performing a normalization process on the data that has completed the preprocessing operation to make different formats of data become standardized data that meets a predetermined format. In this embodiment, data cleaning and normalization can be achieved. For example, data cleaning refers to the process of discovering and correcting errors, incompleteness, non-standard formats, duplicates, or other non-conforming data in a data set to improve data quality. In the field of artificial intelligence, high-quality data is the basis for training accurate and efficient models. Remove invalid and duplicate data, and perform a normalization process on different formats of data so that it can be effectively utilized by subsequent artificial intelligence algorithms. For example, unify the timestamp format, map the value ranges of different sensors to the same interval, and ensure data quality and consistency.

[0024] Step S104: Extract and construct feature data, that is, based on the at least one piece of source data, extract and construct feature data for the vehicle information security attack tree model.

[0025] In some embodiments, extracting and constructing feature data for the vehicle information security attack tree model includes: constructing a covariance matrix of the at least one piece of source data to describe the correlation between different features; solving the covariance matrix to obtain the corresponding eigenvalues and eigenvectors, where the eigenvalues represent the variance magnitude of the data in the direction of the corresponding eigenvectors, sort the eigenvectors in descending order according to the eigenvalues, and select the first n eigenvectors, where ≤n, n represents the dimension, and form a low-dimensional matrix with the first n eigenvectors; multiply the covariance matrix by the low-dimensional matrix.

[0026] Specifically, feature engineering refers to the process of extracting and constructing features valuable to the model from the original data. These features can better represent the internal structure and patterns of the data, thus helping the model learn more efficiently and make accurate predictions. Appropriate features can reduce the complexity of the model. Through feature engineering, some irrelevant or redundant features can be removed, making the model training process more efficient. Select key features that can characterize the information security state of the vehicle, such as the source address, destination address, port number, data length of network data packets, and parameters such as the load rate and temperature of the ECU. These features will be used as the input of the machine learning model to distinguish normal behavior from attack behavior. For example, through the Principal Component Analysis (PCA) feature analysis technique, new variables can be obtained by linearly combining the processed data and arranging them in descending order of variance. First step, calculate the covariance matrix of the original data. The covariance matrix describes the correlation between different features. For a data set with n features , the covariance matrix 's element represents the covariance between the th feature and the th feature. If , it means that the th feature and the th feature are not correlated. Second step, solve the eigenvalues and eigenvectors of the covariance matrix. The eigenvalue represents the variance size of the data in the direction of the corresponding eigenvector. Sort the eigenvectors in descending order of eigenvalues, and select the first eigenvectors ( is less than the original feature dimension ), and these eigenvectors form a new matrix, which is used to project the original data into a low-dimensional space. Finally, multiply the original data matrix by the selected eigenvector matrix to obtain the data representation in the low-dimensional space. Specifically, assume that the matrix composed of the selected eigenvectors is , then the low-dimensional data . After dimensionality reduction by PCA, it is easier to discover the patterns and rules in the data. Therefore, the PCA technique is used to construct the root node of the attack tree model.

[0027] Step S106: Construct and optimize the model, that is, construct the vehicle information security attack tree model, and use historical attack data for training to optimize the model parameters.

[0028] In some embodiments, constructing the automotive information security attack tree model includes: using the ultimate goal of the attack as the root node of the automotive information security attack tree model, where the ultimate goal includes controlling the steering system of the vehicle or obtaining user data of the vehicle; using the sub-goals or intermediate steps required to achieve the ultimate goal as intermediate nodes, and using the most basic attack actions or conditions as leaf nodes. If there are unsolvable intermediate nodes or leaf nodes, deletion operations are performed.

[0029] In other embodiments, training using historical attack data to optimize model parameters may include: dividing the preprocessed data into a training set and a test set, and training a support vector machine model using the training set data; finding the optimal hyperplane parameters (weight vector and bias term) through the sequential minimal optimization algorithm, such that the classification error of the model on the training set is minimized and meets the condition of a predetermined maximum margin, thereby determining each branch node.

[0030] For example, in combination with actual requirements, multiple artificial intelligence algorithms can work together. First, the decision tree algorithm is used for preliminary classification. It divides the data set into different subsets by performing a series of tests on the features of the data set, quickly screening out samples suspected of being attacks. Then these samples are input into a support vector machine (SVM) for further accurate identification and attack pattern learning. By continuously adjusting the algorithm parameters and training using historical attack data, the model is enabled to have the ability to accurately identify attacks.

[0031] The preprocessed data is divided into a training set and a test set. The support vector machine model is trained using the training set data. The optimal hyperplane parameters (weight vector and bias term) are found through algorithms such as the sequential minimal optimization algorithm, such that the classification error of the model on the training set is minimized and meets the condition of the maximum margin, thereby determining each branch node. Techniques such as cross-validation can be used to train the model and evaluate the performance under different parameter combinations, and the optimal parameter settings are selected to improve the generalization ability and performance of the model.

[0032] Step S108: Model update, that is, using the automotive information security attack tree model to identify attack means or attack forms, updating the nodes of the model or modifying the relationships between the nodes. For example, based on the common attack patterns identified by the trained model and in combination with the architecture of the automotive information system, an initial attack tree can be constructed. The root node is still an ultimate goal such as "illegally obtaining control of the vehicle", and the first-level sub-nodes can be classified according to the main attack routes, such as "exploitation of software vulnerabilities based on artificial intelligence", "intelligent hardware attack", "AI-assisted network attack", etc.

[0033] In some embodiments, it may further include: adjusting model parameters or optimizing data collection strategies by means of metric evaluation. For example, as new data continuously flows in, the model discovers new attack methods or mutated attack forms, and timely adds new nodes to the attack tree or modifies the relationships between existing nodes. For example, when detecting a new attack method that uses artificial intelligence image recognition vulnerabilities to interfere with the vision sensors of autonomous driving, a new sub-node is added under the corresponding "intelligent hardware attack" branch to describe the attack means and prevention key points in detail. The neural network based on deep learning can predict the future possible attack trends of the vehicle information system. By analyzing historical attack data and the current configuration information of the system, it is possible to predict which system components or functions are most likely to be attacked in the future period, helping the security team to deploy preventive measures in advance. For example, based on multiple past attack events caused by in-vehicle entertainment system vulnerabilities and combining with the technical architecture characteristics of the entertainment system of the current new vehicle model, predict the high-risk period of the system in the initial stage of the new vehicle launch, providing a basis for targeted protection.

[0034] In other embodiments, the metrics include accuracy, recall rate, and F1 value. Specifically, metrics such as accuracy, recall rate, and F1 value are used to measure the performance of the model. Accuracy reflects the proportion of correctly identified attacks by the model, the recall rate represents the proportion of actual attacks that the model can detect, and the F1 value comprehensively considers the balance between the two. Regularly evaluate the model, adjust the model parameters or optimize the data collection strategy according to the metric changes to ensure that the model always maintains high performance. Through simulated attack experiments, in a controlled vehicle test environment, according to the attack paths covered by the attack tree model, simulate various known and potential attack scenarios, and observe whether the model can accurately give early warnings, identify, and block attacks. By comparing with the traditional attack tree model, evaluate the advantages of the new model in terms of detection accuracy, response speed, etc.

[0035] The present application provides an apparatus 200 for an automotive information security attack tree model based on artificial intelligence. The processing flow of the apparatus 200 may include the following modules: a data acquisition module 202, a preprocessing module 204, an intelligent processing module 206, and a model update module 208. Specifically, The data acquisition module 202 is used to acquire at least one source data of the vehicle, where the at least one source data includes: electronic control unit logs, in-vehicle network data packets, communication records between the vehicle and an external server, or sensor data; The preprocessing module 204 is used to extract and construct feature data for the automotive information security attack tree model based on the at least one source data; The intelligent processing module 206 is used to construct the automotive information security attack tree model and train it using historical attack data to optimize the model parameters; A model update module 208, configured to use the automotive information security attack tree model to identify attack means or attack forms, update the nodes of the model, or modify the relationships between the nodes.

[0036] As Figure 3 shown, an electronic device provided in an embodiment of the present invention may include a processor 320 and a memory 310. Optionally, the electronic device may further include a transceiver. Among them, the processor is connected to the memory and the transceiver, such as through a communication bus. Computer-readable instructions are stored on the memory, and when the computer-readable instructions are executed by the processor, the steps of the method for establishing an automotive information security attack tree model based on artificial intelligence as described above are implemented.

[0037] In a specific implementation, as an embodiment, the processor 320 may include one or more CPUs.

[0038] Optionally, in a specific implementation, if the memory 310, the processor 320, and the communication interface 330 are integrated on a single chip, the memory 310, the processor 320, and the communication interface 330 may communicate with each other through an internal interface.

[0039] In a specific implementation, as an embodiment, the electronic device may also include multiple processors. For example, each of the processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0040] Among them, the memory is used to store the software program for executing the solution of the present invention and is controlled by the processor for execution. The specific implementation manner may refer to the above method embodiment and will not be elaborated here.

[0041] The transceiver is configured to communicate with a network device or with a terminal device.

[0042] Optionally, the transceiver may include a receiver and a transmitter. Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the sending function.

[0043] Optionally, the transceiver may be integrated with the processor or may exist independently and be coupled to the processor through the interface circuit of the electronic device. The embodiment of the present invention does not make a specific limitation on this.

[0044] It should be noted that the structure of the above electronic device does not constitute a limitation on the electronic device. The actual electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements. In addition, the technical effects of the electronic device may refer to the technical effects of the above method embodiment and will not be elaborated here.

[0045] In an exemplary embodiment, the present invention further provides a computer-readable storage medium, in which at least one instruction is stored, and the at least one instruction is loaded and executed by a processor to implement the steps of the above-mentioned method for establishing an automotive information security attack tree model based on artificial intelligence. For example, the computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0046] An embodiment of the present invention further provides an electronic device, which includes: a processor; a memory, on which computer-readable instructions are stored, and when the computer-readable instructions are executed by the processor, the above-mentioned method for establishing an automotive information security attack tree model based on artificial intelligence is implemented.

[0047] An embodiment of the present invention provides a computer-readable storage medium, characterized in that program code is stored in the computer-readable storage medium, and the program code can be called by a processor to execute the above-mentioned method for establishing an automotive information security attack tree model based on artificial intelligence.

[0048] It should also be understood that the memory in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).

[0049] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Additionally, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship. The specific meaning can be understood by referring to the context before and after.

[0050] It should be understood that in various embodiments of the present invention, the magnitudes of the serial numbers of the above processes do not imply the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0051] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this document can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.

[0052] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the devices, apparatuses, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0053] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other form.

[0054] The embodiments of the present disclosure have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The choice of terms used herein is intended to best explain the principles of the embodiments, practical applications, or technical improvements to the technology in the market, or to enable other ordinary skill in the art to understand the embodiments disclosed herein.

Claims

1. A method for establishing an attack tree model for automobile information security based on artificial intelligence, characterized in that: include: Acquire at least one source data of the automobile, wherein the at least one source data includes: an electronic control unit log, an in-vehicle network data packet, a communication record between the vehicle and an external server, or sensor data; Based on the at least one source data, feature data for the automobile information security attack tree model is extracted and constructed, including: constructing a covariance matrix of the at least one source data to describe the correlation between different features; solving the covariance matrix to obtain corresponding eigenvalues ​​and eigenvectors, using the eigenvalues ​​to represent the variance of the data in the direction of the corresponding eigenvector, sorting the eigenvectors from large to small according to the eigenvalues, and selecting the top feature vectors, where ≤n, n represents the dimension, the previous The eigenvectors form a low-dimensional matrix; multiplying the covariance matrix with the low-dimensional matrix; Constructing the automobile information security attack tree model, and using historical attack data for training to optimize model parameters; The automobile information security attack tree model is used to identify attack means or attack forms, update the nodes of the model or modify the relationship between the nodes.

2. The method for establishing an automobile information security attack tree model based on artificial intelligence according to claim 1 is characterized in that: Acquiring at least one source data of the vehicle, including: Performing preprocessing operations on the at least one source data to correct erroneous, incomplete, irregularly formatted, and duplicated data in the data set; The data that has completed the preprocessing operation is standardized so that the data in different formats becomes standardized data that meets the predetermined format.

3. The method for establishing an automobile information security attack tree model based on artificial intelligence according to claim 1 is characterized in that: Constructing the automobile information security attack tree model includes: The ultimate target of the attack is used as the root node of the automobile information security attack tree model, wherein the ultimate target includes controlling the steering system of the automobile or obtaining the user data of the vehicle; The sub-goals or intermediate steps that need to be completed to achieve the final goal are taken as intermediate nodes, and the most basic attack actions or conditions are taken as leaf nodes. If there are intermediate nodes or leaf nodes with no solution, they will be deleted.

4. The method for establishing an automobile information security attack tree model based on artificial intelligence according to claim 2 is characterized in that: Use historical attack data for training to optimize model parameters, including: The preprocessed data is divided into a training set and a test set, and the support vector machine model is trained using the training set data; The optimal hyperplane parameters are found through the sequential minimum optimization algorithm to minimize the classification error of the model on the training set and meet the predetermined maximum interval conditions, thereby determining each branch node.

5. The method for establishing an automobile information security attack tree model based on artificial intelligence according to any one of claims 1 to 4, characterized in that: Also includes: Use indicator evaluation to adjust model parameters or optimize data collection strategies.

6. The method for establishing an automobile information security attack tree model based on artificial intelligence according to claim 5 is characterized in that: The metrics include precision, recall, and F1 value.

7. A device for an automobile information security attack tree model based on artificial intelligence, characterized in that: include: A data acquisition module, used to acquire at least one source data of the automobile, wherein the at least one source data includes: an electronic control unit log, an in-vehicle network data packet, a communication record between the vehicle and an external server, or sensor data; A preprocessing module is used to extract and construct feature data for the automobile information security attack tree model based on the at least one source data, including: constructing a covariance matrix of the at least one source data to describe the correlation between different features; solving the covariance matrix to obtain corresponding eigenvalues ​​and eigenvectors, using the eigenvalues ​​to represent the variance of the data in the direction of the corresponding eigenvector, sorting the eigenvectors from large to small according to the eigenvalues, and selecting the first feature vectors, where ≤n, n represents the dimension, the previous The eigenvectors form a low-dimensional matrix; multiplying the covariance matrix with the low-dimensional matrix; An intelligent processing module, used to construct the automobile information security attack tree model, and to train with historical attack data to optimize model parameters; The model updating module is used to use the automobile information security attack tree model to identify attack means or attack forms, update the nodes of the model or modify the relationship between the nodes.

8. An electronic device, characterized in that: The electronic device comprises: processor; A memory having computer-readable instructions stored thereon, wherein when the computer-readable instructions are executed by the processor, the method for establishing an automobile information security attack tree model based on artificial intelligence as described in any one of claims 1 to 4 is implemented.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program code, and the program code can be called by a processor to execute the method for establishing an automobile information security attack tree model based on artificial intelligence as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Software security demand recommendation method based on data driving

    CN110750712A

  • Method and system for establishing automobile information security attack tree model

    CN113810365A

  • Attack tree honeypot deployment defense method and device based on deep reinforcement learning

    CN115580430A

  • Information security protection device

    CN118695258A

  • Data asset security monitoring method

    CN118890213A