Network security monitoring method and device for automobile, vehicle and storage medium

By evaluating the impact of network security damage and the feasibility of attacks, determining whether a network security incident is triggered, and diagnosing and monitoring are carried out based on the log content, the hacker attack and malware intrusion problems faced by the vehicle network system is solved, and effective monitoring and protection of vehicle network security is achieved.

CN120074909APending Publication Date: 2025-05-30CHERY AUTOMOBILE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510211955.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Vehicle network systems are facing threats such as hacker attacks and malware intrusions, resulting in the vehicle control system being tampered with and user data being leaked, endangering driving safety and affecting the normal operation of the vehicle.

Method used

Provides a method for network security monitoring of automobiles. By evaluating the impact of network security damage and the feasibility of attacks, generate threat and risk analysis results, determine the scope and format of network security log development, determine whether network security incidents are triggered, and diagnose and monitor based on the log content to generate network security monitoring results.

Benefits of technology

Effectively identify and respond to potential network security threats, prevent vehicle control system tampering and user data leakage, ensure driving safety and ensure normal operation of the vehicle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074909A_ABST
    Figure CN120074909A_ABST
Patent Text Reader

Abstract

The invention relates to a network security monitoring method and device for an automobile, a vehicle and a storage medium, and the method comprises the steps: generating a threat and risk analysis result of the automobile based on the network security damage impact evaluation data and attack feasibility evaluation data of the automobile; determining a network security log development range and network security log format content of the automobile, and judging whether the automobile triggers a network security event meeting a preset condition or not according to the network security log development range and the network security log format content; and diagnosing the network security log of the automobile according to the log development content of the automobile, and monitoring the network security log according to the network security diagnosis data. According to the embodiment of the invention, the existing diagnosis path is utilized, the existing diagnosis cloud and the V-SOC cloud interface are connected, and continuous network security detection and monitoring are realized. Therefore, the problems of recording, collecting and analyzing the network security events of the non-networked vehicle type and the problem of meeting the sea of the non-networked vehicle type are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of intelligent connected vehicles, and particularly relates to a method, device, vehicle and storage medium for network security monitoring of an automobile. Background Art

[0002] With the rapid development of technology and the times, automobiles have far exceeded the definition of traditional transportation tools. Modern automobiles are not only transportation tools, but complex systems integrating various advanced technologies and components, evolving into a mobile terminal with rich functions. The increase in networking functions and the complexity of in-vehicle networks have continuously increased the information security risks of modern automobiles.

[0003] In related technologies, there are already various automobile network security protection measures, such as firewalls, intrusion detection systems (IDS), and data encryption technologies. These measures have improved the security of vehicle network systems to a certain extent. In addition, standards for automotive functional safety, such as ISO 26262, have also been widely applied in the automotive industry to reduce risks caused by failures of electrical and electronic systems.

[0004] However, in related technologies, vehicle network systems face various threats such as hacker attacks and malware intrusions, resulting in serious consequences such as the tampering of vehicle control systems and the leakage of user data, endangering driving safety, causing the in-vehicle network to be overloaded, and then affecting the normal operation of the vehicle, which urgently needs to be improved. Summary of the Invention

[0005] The present application provides a method, device, vehicle and storage medium for network security monitoring of an automobile to solve the problems in related technologies that vehicle network systems face various threats such as hacker attacks and malware intrusions, resulting in serious consequences such as the tampering of vehicle control systems and the leakage of user data, endangering driving safety, causing the in-vehicle network to be overloaded, and then affecting the normal operation of the vehicle.

[0006] The first aspect embodiment of the present application provides a method for network security monitoring of an automobile, including the following steps: generating a threat and risk analysis result of the automobile based on network security damage impact assessment data and attack feasibility assessment data of the automobile; determining a network security log development scope and network security log format content of the automobile based on the threat and risk analysis result of the automobile, and determining whether the automobile triggers a network security event that meets a preset condition according to the network security log development scope and the network security log format content; if the automobile triggers the network security event that meets the preset condition, diagnosing the network security log of the automobile according to the log development content of the automobile to generate network security diagnosis data of the automobile, and monitoring the network security log according to the network security diagnosis data to generate a network security monitoring result of the automobile.

[0007] Optionally, in an embodiment of the present application, after generating the network security monitoring result of the vehicle, it further includes: detecting the network security log of the vehicle according to the network security monitoring result to generate the monitoring detection data of the vehicle; generating at least one acoustic alarm action and / or at least one optical alarm action of the vehicle according to the monitoring detection data, and executing the at least one acoustic alarm action and / or the at least one optical alarm action to prompt the driver of the network security status of the vehicle.

[0008] Optionally, in an embodiment of the present application, diagnosing the network security log of the vehicle according to the log development content of the vehicle to generate the network security diagnosis data of the vehicle includes: extracting the timestamp information in the network security log based on the log development content of the vehicle, and determining the time information of the network security log according to the timestamp information; identifying the event type of the network security log, and checking the actual operation result recorded in the network security log; generating the network security diagnosis data of the vehicle according to the time information, the event type and the actual operation result of the network security log.

[0009] Optionally, in an embodiment of the present application, monitoring the network security log to generate the network security monitoring result of the vehicle includes: reading the network security log stored in the vehicle terminal to generate the network security reading data of the vehicle; uploading the network security reading data to generate an upload result, and monitoring the network security risk of the vehicle according to the upload result to generate risk warning information corresponding to the network security risk; adjusting the risk assessment level of the vehicle according to the risk warning information to generate the network security monitoring result of the vehicle according to the risk assessment level.

[0010] Optionally, in an embodiment of the present application, after determining whether the vehicle triggers a network security event that meets a preset condition according to the network security log development scope and the network security log format content, it further includes: if the vehicle triggers at least one of a high-risk abnormal external connection record and monitoring data, controller resource usage, and suspected security event information, it is determined that the vehicle triggers the network security event that meets the preset condition.

[0011] The second aspect of the present application provides a network security monitoring device for a vehicle, including: a generation module, configured to generate a threat and risk analysis result of the vehicle based on network security damage impact assessment data and attack feasibility assessment data of the vehicle; a judgment module, configured to determine a network security log development scope and network security log format content of the vehicle based on the threat and risk analysis result of the vehicle, and determine whether the vehicle triggers a network security event that meets a preset condition according to the network security log development scope and the network security log format content; a monitoring module, configured to diagnose the network security log of the vehicle according to the log development content of the vehicle when the vehicle triggers the network security event that meets the preset condition, generate network security diagnosis data of the vehicle, and monitor the network security log according to the network security diagnosis data to generate a network security monitoring result of the vehicle.

[0012] Optionally, in an embodiment of the present application, it further includes: a detection module, configured to detect the network security log of the vehicle according to the network security monitoring result after generating the network security monitoring result of the vehicle, to generate monitoring detection data of the vehicle; a prompt module, configured to generate at least one acoustic alarm action and / or at least one optical alarm action of the vehicle according to the monitoring detection data, and execute the at least one acoustic alarm action and / or the at least one optical alarm action to prompt the driver of the network security state of the vehicle.

[0013] Optionally, in an embodiment of the present application, the monitoring module includes: an extraction unit, configured to extract timestamp information in the network security log based on the log development content of the vehicle, and determine the time information of the network security log according to the timestamp information; an inspection unit, configured to identify the event type of the network security log and inspect the actual operation result recorded in the network security log; a generation unit, configured to generate network security diagnosis data of the vehicle according to the time information, the event type and the actual operation result of the network security log.

[0014] Optionally, in an embodiment of the present application, the monitoring module includes: a reading unit, configured to read the network security log stored in the vehicle terminal of the vehicle to generate network security reading data of the vehicle; an uploading unit, configured to upload the network security reading data to generate an upload result, and monitor the network security risk of the vehicle according to the upload result to generate risk warning information corresponding to the network security risk; a monitoring unit, configured to adjust the risk assessment level of the vehicle according to the risk warning information, and generate a network security monitoring result of the vehicle according to the risk assessment level.

[0015] Optionally, in one embodiment of the present application, it also includes: a determination module, which is used to determine whether the car triggers a network security event that meets the preset conditions after determining whether the car triggers a network security event that meets the preset conditions based on the network security log development scope and the network security log format content, and when the car triggers at least one of the high-risk abnormal external connection records and monitoring data, controller resource usage and suspected security event information.

[0016] A third aspect of the present application provides a vehicle, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the network security monitoring method for the automobile as described in the above embodiment.

[0017] A fourth aspect of the present application provides a computer-readable storage medium, which stores a computer program that, when executed by a processor, implements the above-mentioned network security monitoring method for a vehicle.

[0018] The embodiment of the present application can record, collect and analyze vehicle-side security events for non-networked vehicles, avoiding network security risks from vehicles. The non-networked continuous monitoring solution combined with the IDPS solution can include all OEM vehicles in the continuous monitoring range, and use the existing diagnostic path to open up the existing diagnostic cloud and V-SOC cloud interface to achieve continuous network security detection and monitoring. This solves the problem in related technologies that the vehicle network system faces multiple threats from hacker attacks, malware intrusions, etc., resulting in serious consequences such as tampering with the vehicle control system and leakage of user data, endangering driving safety, causing vehicle network overload, and thus affecting the normal operation of the vehicle.

[0019] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0021] Figure 1 A flowchart of a network security monitoring method for an automobile provided according to an embodiment of the present application;

[0022] Figure 2 is a flow chart of a method for network security monitoring of a vehicle according to an embodiment of the present application;

[0023] Figure 3 A schematic diagram of the structure of a network security monitoring device for an automobile provided according to an embodiment of the present application;

[0024] Figure 4 It is a schematic diagram of the structure of a vehicle provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0025] Embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.

[0026] The following describes the network security monitoring method, device, vehicle and storage medium of the automobile of the embodiment of the present application with reference to the accompanying drawings. In view of the related technologies mentioned in the above background technology, the vehicle network system faces multiple threats from hacker attacks, malware intrusions, etc., resulting in serious consequences such as tampering of the vehicle control system and leakage of user data, endangering driving safety, causing the vehicle network to be overloaded, and thus affecting the normal operation of the vehicle. The present application provides a network security monitoring method for an automobile, in which the vehicle-side security events of non-networked vehicles can be recorded, collected and analyzed to avoid the network security risks from the vehicle. The non-networked continuous monitoring solution is combined with the IDPS solution to include all OEM vehicles in the continuous monitoring range, and the existing diagnostic path is used to open the existing diagnostic cloud and V-SOC cloud interface to achieve continuous network security detection and monitoring. Thus, the problem that the vehicle network system faces multiple threats from hacker attacks, malware intrusions, etc. in the related technology, resulting in serious consequences such as tampering of the vehicle control system and leakage of user data, endangering driving safety, causing the vehicle network to be overloaded, and thus affecting the normal operation of the vehicle is solved.

[0027] Specifically, Figure 1 A schematic flow chart of a method for network security monitoring of an automobile provided in an embodiment of the present application.

[0028] like Figure 1 As shown, the network security monitoring method of the automobile includes the following steps:

[0029] In step S101, based on the network security damage impact assessment data and attack feasibility assessment data of the automobile, a threat and risk analysis result of the automobile is generated.

[0030] It can be understood that the car in the embodiment of the present application can be a non-networked car; the damage impact assessment in the embodiment of the present application can be to determine the negative impact that may be caused once a security incident occurs, and the attack feasibility assessment can be the actual possibility of an attacker exploiting a specific vulnerability to attack.

[0031] In the actual implementation process,Figure 2 As shown, embodiments of the present application can identify high-risk points of vehicle network security and key controllers based on automotive network security damage impact assessment data and attack feasibility assessment data, and generate threat and risk analysis results for the vehicle, thereby effectively identifying and mitigating potential threats and risks in the field of automotive network security.

[0032] Among them, Figure 2 The key controllers for vehicle network security are generally important controllers inside the vehicle, such as: DMC (Digital Media Controller, information entertainment controller), CGW (Central Gateway), and autonomous driving controller (ADCC). The key controllers for vehicle network security are usually high-risk components obtained through in-vehicle network security analysis. When in-vehicle components are suspected of being cyber-attacked, a network security event is triggered and recorded and stored in the controller in the form of a diagnostic DID (Data Identifier). The monitoring scope of the high-risk cyber components is selected as follows:

[0033] Central Gateway (CGW): It is a core component of the vehicle network, responsible for the connection and management of the vehicle's internal network, and is one of the most vulnerable targets in the vehicle network. Therefore, continuous monitoring is required.

[0034] Audio host (DMC): It is the control center of the vehicle information entertainment system. The audio host is usually connected to external networks such as wifi, Bluetooth, USB, etc. Therefore, continuous monitoring is also required.

[0035] Autonomous driving controller (ADCC): It is a component closely related to safe driving, and it is necessary to continuously ensure its normal operation and the authenticity and integrity of data. Therefore, continuous monitoring is also required.

[0036] Diagnostic instrument: It is a portable intelligent vehicle self-checking instrument used to detect vehicle logs and faults. It can quickly read the network security logs in the vehicle's electronic control system and display the log information through a liquid crystal display screen. The security logs can be clicked through the screen buttons and uploaded to the CDMS platform. Embodiments of the present application can insert the diagnostic instrument into the vehicle-mounted OBD port, enter the network security log function interface, start reading the magnet, and at the same time, the diagnostic instrument adds the vehicle VIN number and log upload time to the log information for assisting subsequent analysis and disposal.

[0037] CDMS platform: A diagnostic back-end service system. After the network security logs read by the diagnostic instrument are uploaded to the CDMS platform, the network security logs can be transparently transmitted to the VSOC platform through the CDMS.

[0038] V-SOC: Responsible for accessing and analyzing vehicle network security log data uploaded by the vehicle-side controller, identifying possible security risks, and providing visual data display.

[0039] In step S102, based on the threat and risk analysis results of the automobile, the network security log development scope and network security log format content of the automobile are determined, and according to the network security log development scope and network security log format content, it is determined whether the automobile triggers a network security event that meets preset conditions.

[0040] It can be understood that the network security log format content in the embodiment of the present application includes but is not limited to the time of event occurrence, event type, cause of event occurrence and other related information; a network security event that meets the preset conditions can be an abnormal event that triggers network security.

[0041] Among them, the embodiments of the present application can define the scope of network security log development and clarify the format and content of the network security log based on the threat and risk analysis results of the automobile, according to the key network security controllers and their network security risk exposure areas, and determine whether the automobile triggers a network security event that meets certain conditions based on the scope of network security log development and the format and content of the network security log.

[0042] The embodiments of the present application can implement a response mechanism in a targeted manner according to the judgment results, effectively monitor and identify network security events in the car, and ensure vehicle network security.

[0043] It should be noted that the preset conditions can be set by those skilled in the art according to actual conditions and are not specifically limited here.

[0044] Optionally, in one embodiment of the present application, after determining whether a car triggers a network security event that meets preset conditions based on the network security log development scope and the network security log format content, it also includes: if the car triggers at least one of high-risk abnormal external connection records and monitoring data, controller resource usage, and suspected security event information, it is determined that the car triggers a network security event that meets preset conditions.

[0045] It can be understood that the high-risk abnormal external connection records and monitoring data in the embodiments of the present application generally involve unauthorized or abnormal external network connections and network security monitoring data; controller resource usage is an important indicator for evaluating system performance and stability; suspected security incident information generally involves behaviors or events that may threaten network security but have not yet been confirmed as real security incidents.

[0046] Among them, in the embodiments of the present application, when the vehicle triggers high-risk abnormal external connection records and monitoring data (such as data of wifi, Bluetooth, USB connection, etc.), controller resource usage (such as CPU usage rate, memory usage rate, and application processes), and suspected security event information (such as abnormal processes, configuration tampering, and firewalls, etc.) and other network security events, it is determined that the vehicle triggers network security events that meet certain conditions.

[0047] By collecting and analyzing high-risk abnormal external connection records and monitoring data, controller resource usage, and suspected security event information, the embodiments of the present application not only help to detect and respond to potential security threats in a timely manner, but also provide strong guarantee for the long-term stable operation of the system.

[0048] It should be noted that the preset conditions can be set by those skilled in the art according to the actual situation, and no specific limitation is made here.

[0049] In step S103, if the vehicle triggers a network security event that meets the preset conditions, the network security log of the vehicle is diagnosed according to the log development content of the vehicle, network security diagnosis data of the vehicle is generated, and the network security log is monitored according to the network security diagnosis data to generate a network security monitoring result of the vehicle.

[0050] It can be understood that the network security log in the embodiments of the present application can be diagnosed by using the vehicle terminal developed by the core controller and read and uploaded to the diagnostic cloud platform through a diagnostic instrument.

[0051] In the actual execution process, in the embodiments of the present application, when the vehicle triggers a network security event that meets certain conditions, the network security log of the vehicle can be triggered and recorded according to the log development content of the vehicle, diagnosis data is generated, and after the log is generated, a diagnostic instrument can be used to read the network security log from the vehicle terminal through the vehicle OBD port and upload it to the CDMS platform, and the network security log is monitored to generate a network security monitoring result of the vehicle.

[0052] Among them, in the embodiments of the present application, when a suspected network security event or a high-risk external connection occurs, the vehicle terminal network security key controller records and stores it in the controller in the form of a diagnostic DID, and designs secure access control for the log storage. The network security log DID includes the event type, the cause of the event, the time of the event, etc., which can assist in the subsequent analysis of network security events. When a network security event occurs, the network security log stored in the vehicle terminal can be read through the vehicle OBD port by a diagnostic instrument. After the reading is successful, clicking the log upload button on the diagnostic instrument screen can upload the vehicle terminal network security log to the CDMS platform; the CDMS platform transparently transmits the received network security log to the V-SOC.

[0053] The embodiments of the present application can utilize the existing diagnostic path, connect the existing diagnostic cloud and V-SOC cloud interface, and realize continuous network security detection and monitoring, thereby solving the problems of recording, collecting, and analyzing network security incidents of non-networked vehicles and the compliance issues of non-networked vehicles going overseas.

[0054] Optionally, in one embodiment of the present application, after generating the network security monitoring results of the car, it also includes: detecting the network security log of the car according to the network security monitoring results to generate monitoring detection data of the car; generating at least one acoustic alarm action and / or at least one optical alarm action of the car according to the monitoring detection data, and executing at least one acoustic alarm action and / or at least one optical alarm action to prompt the driver of the network security status of the car.

[0055] It can be understood that in the embodiment of the present application, at least one acoustic alarm action can be a sound alarm issued by the vehicle horn, and at least one optical alarm action can be a light flashing alarm on the vehicle display screen.

[0056] In the actual implementation process, after the CDMS platform receives the log information from the diagnostic instrument, the embodiment of the present application can directly transmit it to the V-SOC. The V-SOC platform develops a parsing dictionary based on the diagnostic DID content. When a network security log is received, the received network security log can be parsed and an alarm can be issued according to the defined parsing dictionary. The embodiment of the present application detects the network security log of the car based on the network security monitoring results to generate monitoring detection data of the car, and performs at least one acoustic alarm action and / or at least one optical alarm action based on the monitoring detection data to prompt the driver of the network security status of the car.

[0057] The embodiment of the present application can utilize the V-SOC platform to receive network security logs from the vehicle side through the CDMS platform, wherein the security analysis engine of the V-SOC platform can implement security detection and analysis of the received log data, and issue an alarm based on the operational configuration when an abnormality is found, thereby solving the problems of recording, collecting, and analyzing network security incidents of non-networked vehicles and the overseas compliance issues of non-networked vehicles.

[0058] Optionally, in one embodiment of the present application, the network security log of the automobile is diagnosed according to the log development content of the automobile to generate diagnostic data of the automobile, including: extracting timestamp information in the network security log based on the log development content of the automobile, and determining the time information of the network security log according to the timestamp information; identifying the event type of the network security log, and checking the actual operation results recorded in the network security log; generating the network security diagnostic data of the automobile according to the time information, event type and actual operation results of the network security log.

[0059] It can be understood that the timestamp in the embodiments of the present application is an important identifier for recording the occurrence time of an event, which helps to determine the specific occurrence time; the embodiments of the present application can use a diagnostic instrument to diagnose network security.

[0060] In the actual execution process, the embodiments of the present application can extract the timestamp information in the network security log based on the log development content of the vehicle, and determine the time information of the network security log according to the timestamp information. The embodiments of the present application can identify the event type of the network security log. Clarifying the event type helps to quickly locate possible security threats or vulnerabilities, and check the actual operation results recorded in the network security log to verify the results of each network security event, such as whether an unauthorized access attempt has been successfully blocked, or whether there has been any data leakage. The embodiments of the present application can generate the network security diagnosis data of the vehicle according to the time information, event type and actual operation results of the network security log, and can effectively monitor and manage the network security status of non-networked vehicle models to ensure that even in the absence of a network connection, potential security threats can be detected and responded to in a timely manner.

[0061] The embodiments of the present application can not only effectively improve the network security protection ability of the vehicle, but also ensure the stability and reliability of the system, providing a safer and more reliable driving experience for users.

[0062] Optionally, in an embodiment of the present application, monitoring the network security log to generate the network security monitoring result of the vehicle includes: reading the network security log stored in the vehicle terminal to generate the network security reading data of the vehicle; uploading the network security reading data to generate an upload result, and monitoring the network security risk of the vehicle according to the upload result to generate risk warning information corresponding to the network security risk; adjusting the risk assessment level of the vehicle according to the risk warning information to generate the network security monitoring result of the vehicle according to the risk assessment level.

[0063] It can be understood that the embodiments of the present application can read the network security log stored in the vehicle terminal through the OBD port of the vehicle, and the generated network security reading data can be uploaded to the diagnostic cloud platform (CDMS).

[0064] In the actual implementation process, the embodiment of the present application can read the network security log stored in the vehicle to generate the network security reading data of the vehicle. When uploading the network security reading data, the security and integrity of the data can be ensured to prevent the data from being tampered with or leaked. By analyzing the uploaded network security reading data, the potential network security risks of the vehicle can be identified, such as unauthorized access, data leakage, malware infection, etc. The embodiment of the present application can monitor network security risks to generate risk warning information corresponding to network security risks, and adjust the risk assessment level of the vehicle according to the risk warning information to ensure timely discovery and warning of potential network security risks, so as to generate the network security monitoring results of the vehicle, and record the network security status of the vehicle, the identified risks and their treatment measures in detail according to the monitoring results.

[0065] According to the automobile network security monitoring method proposed in the embodiment of the present application, the vehicle-side security events of non-networked vehicles can be recorded, collected and analyzed to avoid network security risks from vehicles. The non-networked continuous monitoring solution combined with the IDPS solution can include all OEM vehicles in the continuous monitoring range, and use the existing diagnostic path to open up the existing diagnostic cloud and V-SOC cloud interface to achieve continuous network security detection and monitoring. In this way, the problem in the related technology that the vehicle network system faces multiple threats from hacker attacks, malware intrusions, etc., resulting in serious consequences such as tampering with the vehicle control system and leakage of user data, endangering driving safety, causing overload of the vehicle network, and thus affecting the normal operation of the vehicle is solved.

[0066] Next, the network security monitoring device for a car proposed in accordance with an embodiment of the present application will be described with reference to the accompanying drawings.

[0067] Figure 3 It is a structural schematic diagram of a network security monitoring device for a car in an embodiment of the present application.

[0068] like Figure 3 As shown, the network security monitoring device 10 of the automobile includes: a generating module 100 , a judging module 200 and a monitoring module 300 .

[0069] Specifically, the generation module 100 is used to generate a threat and risk analysis result of the automobile based on the network security damage impact assessment data and attack feasibility assessment data of the automobile.

[0070] The judgment module 200 is used to determine the network security log development scope and network security log format content of the vehicle based on the threat and risk analysis results of the vehicle, and to judge whether the vehicle triggers a network security event that meets preset conditions based on the network security log development scope and network security log format content.

[0071] The monitoring module 300 is used to diagnose the cybersecurity log of the vehicle based on the log development content of the vehicle, generate the cybersecurity diagnostic data of the vehicle, and monitor the cybersecurity log according to the cybersecurity diagnostic data to generate the cybersecurity monitoring result of the vehicle when the vehicle triggers a cybersecurity event that meets the preset conditions.

[0072] Optionally, in an embodiment of the present application, the cybersecurity monitoring device 10 of the vehicle further includes: a detection module and a prompt module.

[0073] Wherein, the detection module is used to detect the cybersecurity log of the vehicle according to the cybersecurity monitoring result after generating the cybersecurity monitoring result of the vehicle, so as to generate the monitoring detection data of the vehicle.

[0074] The prompt module is used to generate at least one acoustic alarm action and / or at least one optical alarm action of the vehicle according to the monitoring detection data, and execute at least one acoustic alarm action and / or at least one optical alarm action to prompt the driver of the cybersecurity status of the vehicle.

[0075] Optionally, in an embodiment of the present application, the monitoring module 300 includes: an extraction unit, an inspection unit, and a generation unit.

[0076] Wherein, the extraction unit is used to extract the timestamp information in the cybersecurity log based on the log development content of the vehicle, and determine the time information of the cybersecurity log according to the timestamp information.

[0077] The inspection unit is used to identify the event type of the cybersecurity log and check the actual operation result recorded in the cybersecurity log.

[0078] The generation unit is used to generate the cybersecurity diagnostic data of the vehicle according to the time information, event type, and actual operation result of the cybersecurity log.

[0079] Optionally, in an embodiment of the present application, the monitoring module 300 includes: a reading unit, an uploading unit, and a monitoring unit.

[0080] Wherein, the reading unit is used to read the cybersecurity log stored at the vehicle end of the vehicle to generate the cybersecurity reading data of the vehicle.

[0081] The uploading unit is used to upload the cybersecurity reading data to generate an upload result, and monitor the cybersecurity risk of the vehicle according to the upload result to generate risk warning information corresponding to the cybersecurity risk.

[0082] The monitoring unit is used to adjust the risk assessment level of the vehicle according to the risk warning information, so as to generate the cybersecurity monitoring result of the vehicle according to the risk assessment level.

[0083] Optionally, in one embodiment of the present application, the automobile network security monitoring device 10 further includes: a determination module.

[0084] Among them, the judgment module is used to judge whether the car triggers a network security event that meets the preset conditions after judging whether the car triggers a network security event that meets the preset conditions according to the network security log development scope and the network security log format content, and when the car triggers at least one of the high-risk abnormal external connection records and monitoring data, controller resource usage and suspected security event information.

[0085] It should be noted that the above explanation of the embodiment of the network security monitoring method for a car is also applicable to the network security monitoring device for a car of this embodiment, and will not be repeated here.

[0086] According to the network security monitoring device for automobiles proposed in the embodiment of the present application, it is possible to record, collect and analyze vehicle-side security events for non-networked vehicles, and avoid network security risks from vehicles. The non-networked continuous monitoring solution combined with the IDPS solution can include all OEM vehicles in the continuous monitoring range, and use the existing diagnostic path to open up the existing diagnostic cloud and V-SOC cloud interface to achieve continuous network security detection and monitoring. This solves the problem in related technologies that the vehicle network system faces multiple threats from hacker attacks, malware intrusions, etc., resulting in serious consequences such as tampering with the vehicle control system and leakage of user data, endangering driving safety, causing overload of the vehicle network, and thus affecting the normal operation of the vehicle.

[0087] Figure 4 A schematic diagram of the structure of a vehicle provided in an embodiment of the present application. The vehicle may include:

[0088] Memory 401 , processor 402 , and a computer program stored in the memory 401 and executable on the processor 402 .

[0089] When the processor 402 executes the program, the network security monitoring method for the automobile provided in the above embodiment is implemented.

[0090] Furthermore, the vehicle also includes:

[0091] The communication interface 403 is used for communication between the memory 401 and the processor 402 .

[0092] The memory 401 is used to store computer programs that can be executed on the processor 402 .

[0093] The memory 401 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.

[0094] If the memory 401, the processor 402, and the communication interface 403 are implemented independently, the communication interface 403, the memory 401, and the processor 402 can be interconnected via a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 it is represented by only one thick line in Figure 4 , but this does not mean that there is only one bus or one type of bus.

[0095] Optionally, in a specific implementation, if the memory 401, the processor 402, and the communication interface 403 are integrated on a single chip, the memory 401, the processor 402, and the communication interface 403 can communicate with each other via an internal interface.

[0096] The processor 402 may be a Central Processing Unit (CPU), or an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.

[0097] This embodiment also provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the above-mentioned network security monitoring method for an automobile is implemented.

[0098] In the description of this specification, the descriptions with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or N embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0099] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the technical features indicated. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In the description of this application, the meaning of "N" is at least two, such as two, three, etc., unless otherwise specifically defined.

[0100] Any process or method description represented in a flowchart or described otherwise herein can be understood to represent a module, segment, or portion of code including one or N executable instructions for implementing a customized logical function or process. The scope of the preferred embodiments of this application includes additional implementations, where functions may be executed in a substantially simultaneous manner or in a reverse order according to the functions involved, rather than in the order shown or discussed, which should be understood by those skilled in the technical field to which the embodiments of this application pertain.

[0101] The logic and / or steps represented in a flowchart or described otherwise herein, for example, can be considered as a sequenced list of executable instructions for implementing a logical function, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in conjunction with such instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection portion with one or N wirings (electronic device), a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable media on which the program can be printed, as the program can be obtained electronically by optically scanning the paper or other media, followed by editing, interpretation, or otherwise processing as appropriate, and then stored in a computer memory.

[0102] It should be understood that each part of the present application can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, the N steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one of the following techniques known in the art or a combination thereof can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0103] Those of ordinary skill in the art can understand that all or part of the steps carried by the method of the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.

[0104] In addition, in each embodiment of the present application, each functional unit can be integrated in a processing module, or each unit can exist physically alone, or two or more units can be integrated in a module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. When the above integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0105] The above-mentioned storage medium can be a read-only memory, a magnetic disk, an optical disc, etc. Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.

Claims

1. A method for monitoring network security of an automobile, characterized in that: The following steps are involved: Generating threat and risk analysis results of the vehicle based on the cybersecurity damage impact assessment data and attack feasibility assessment data of the vehicle; Based on the threat and risk analysis results of the automobile, determine the network security log development scope and network security log format content of the automobile, and determine whether the automobile triggers a network security event that meets preset conditions according to the network security log development scope and the network security log format content; If the car triggers the network security event that meets the preset conditions, the network security log of the car is diagnosed according to the log development content of the car to generate network security diagnostic data of the car, and the network security log is monitored according to the network security diagnostic data to generate the network security monitoring result of the car.

2. The method according to claim 1, characterized in that After generating the network security monitoring result of the automobile, the method further includes: Detecting the network security log of the vehicle according to the network security monitoring result to generate monitoring detection data of the vehicle; At least one acoustic alarm action and / or at least one optical alarm action of the car is generated according to the monitoring detection data, and the at least one acoustic alarm action and / or the at least one optical alarm action is executed to prompt the driver of the network security status of the car.

3. The method according to claim 1, characterized in that The step of diagnosing the network security log of the vehicle according to the log development content of the vehicle to generate network security diagnostic data of the vehicle includes: Extracting timestamp information from the network security log based on the log development content of the automobile, and determining time information of the network security log according to the timestamp information; Identify the event type of the network security log, and check the actual operation results recorded in the network security log; The network security diagnostic data of the vehicle is generated according to the time information of the network security log, the event type and the actual operation result.

4. The method according to claim 1, characterized in that: The monitoring of the network security log to generate the network security monitoring result of the automobile includes: Reading the network security log stored in the vehicle end of the vehicle to generate network security reading data of the vehicle; Uploading the network security reading data to generate an upload result, and monitoring the network security risk of the automobile according to the upload result to generate risk warning information corresponding to the network security risk; The risk assessment level of the automobile is adjusted according to the risk warning information to generate a network security monitoring result of the automobile according to the risk assessment level.

5. The method according to claim 1, characterized in that After determining whether the automobile triggers a network security event that meets preset conditions according to the network security log development scope and the network security log format content, the method further includes: If the car triggers at least one of the high-risk abnormal external connection records and monitoring data, controller resource usage and suspected security event information, it is determined that the car triggers the network security event that meets the preset conditions.

6. A network security monitoring device for a car, characterized in that: include: A generation module, for generating a threat and risk analysis result of the vehicle based on the network security damage impact assessment data and the attack feasibility assessment data of the vehicle; A judgment module, used to determine the network security log development scope and network security log format content of the vehicle based on the threat and risk analysis results of the vehicle, and judge whether the vehicle triggers a network security event that meets preset conditions according to the network security log development scope and the network security log format content; A monitoring module is used to diagnose the network security log of the vehicle according to the log development content of the vehicle, generate network security diagnostic data of the vehicle, and monitor the network security log according to the network security diagnostic data to generate network security monitoring results of the vehicle when the vehicle triggers the network security event that meets the preset conditions.

7. The device according to claim 6, characterized in that Also includes: A detection module, configured to detect the network security log of the vehicle according to the network security monitoring result after generating the network security monitoring result of the vehicle, so as to generate monitoring detection data of the vehicle; A prompt module is used to generate at least one acoustic alarm action and / or at least one optical alarm action of the automobile according to the monitoring detection data, and execute the at least one acoustic alarm action and / or the at least one optical alarm action to prompt the driver of the network security status of the automobile.

8. The device according to claim 6, characterized in that The monitoring module comprises: an extraction unit, configured to extract timestamp information in the network security log based on the log development content of the automobile, and determine time information of the network security log according to the timestamp information; A checking unit, used to identify the event type of the network security log and check the actual operation results recorded in the network security log; A generating unit is used to generate network security diagnostic data of the vehicle according to the time information of the network security log, the event type and the actual operation result.

9. A vehicle, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the network security monitoring method for a vehicle as described in any one of claims 1 to 5.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: The program is executed by a processor to implement the network security monitoring method for a vehicle as described in any one of claims 1 to 5.

Citation Information

Cited By

  • Network security detection method and apparatus for vehicle, vehicle, and storage medium

    WO2026179432A1