Automobile distributed intrusion detection and defense system and working method thereof

By using distributed detection nodes and central control units in the automotive distributed intrusion detection and defense system, intrusion detection and defense rules are dynamically generated and issued, and the problems of slow response speed and insufficient detection capabilities caused by the existing system's dependence on a static rule library are solved, and efficient and real-time security protection is achieved.

CN120074960AInactive Publication Date: 2025-05-30AUTOMOTIVE DATA OF CHINA (TIANJIN) CO LTD +1

Patent Information

Application Number
CN202510542640.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-05-30
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing intrusion detection and defense systems rely on static rule bases, resulting in slow response speed, easy omissions or errors, and difficult to adapt to rapidly changing network security attack methods, resulting in insufficient detection capabilities and poses major security risks.

Method used

Design a distributed intrusion detection and defense system for automobiles. Through multiple distributed detection nodes and a central control unit, the vehicle network security related data is monitored and collected in real time. The central control unit receives and analyzes these data to determine whether the car is subject to network security attacks, and dynamically generates and issues new intrusion detection and defense rules based on the attack type.

Benefits of technology

It realizes that each distributed detection node can obtain and execute the latest intrusion detection and defense rules in a timely and accurate manner, solves the shortcomings of the static rule base, meets the needs of efficient and real-time security protection, and improves the detection capabilities of new network security attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074960A_ABST
    Figure CN120074960A_ABST
Patent Text Reader

Abstract

The invention discloses an automobile distributed intrusion detection and defense system and a working method thereof, and relates to the technical field of data security, the system comprises a plurality of distributed detection nodes and a central control unit, the distributed detection nodes are used for monitoring and collecting vehicle network security related data in real time, and the central control unit is used for sending the vehicle network security related data to the distributed detection nodes; the central control unit is used for receiving and analyzing the vehicle network security related data collected by each distributed detection node to judge whether the vehicle is subjected to a network security attack, and determining a new intrusion detection and defense rule based on the type of the network security attack when the vehicle is subjected to the network security attack; and issuing the new intrusion detection and defense rule to each distributed detection node. According to the method and the device, each distributed detection node can timely and accurately obtain and execute the latest intrusion detection and defense rule, dynamic updating of the rule is realized, the problem of static rule inventory is solved, and efficient and real-time security protection requirements can be met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, and particularly to an automotive distributed intrusion detection and prevention system and its working method. Background Art

[0002] In the field of intelligent connected vehicle information security, the Intrusion Detection and Prevention System (IDPS) plays a crucial role. With the continuous development of intelligent connected vehicle technology, network security attack means have become increasingly complex and diverse, posing higher challenges to automotive network security. As the core component of automotive network security, the main function of IDPS is to detect and defend potential security threats in the in-vehicle network to ensure the security and stability of vehicle network communication.

[0003] Currently, most existing intrusion detection and prevention systems use static rule libraries for security protection. The static rule library usually contains rule information such as known malicious IP (Internet Protocol) addresses, virus signatures, attack patterns, etc., which are used to match and identify potential network security attacks. However, the distribution of rules often relies on manual intervention or regular updates, which not only results in a slow response speed of the intrusion detection and prevention system but also easily leads to omissions or errors during the rule update process. In addition, in the face of rapidly evolving network security attack means, the static rule library is often difficult to adapt, resulting in insufficient detection capabilities of the intrusion detection and prevention system for new network security attacks and posing significant security risks. Obviously, traditional static rule library detection has difficulty meeting the requirements of efficient and real-time security protection. Especially in a large-scale network environment, how to ensure that each detection node can obtain and execute the latest rules in a timely and accurate manner has become a technical problem to be solved urgently. Summary of the Invention

[0004] The purpose of this application is to provide an automotive distributed intrusion detection and prevention system and its working method, which can meet the requirements of efficient and real-time security protection.

[0005] To achieve the above object, the following solutions are provided in this application.

[0006] In a first aspect, this application provides an automotive distributed intrusion detection and prevention system, where the automotive distributed intrusion detection and prevention system includes: a plurality of distributed detection nodes and a central control unit, and the monitoring scopes of the plurality of distributed detection nodes are different; The distributed detection nodes are used to monitor and collect vehicle network security-related data in real time; The central control unit is communicatively connected to each of the distributed detection nodes respectively; the central control unit is configured to receive and analyze the vehicle network security-related data collected by each of the distributed detection nodes, to determine whether the vehicle is under a network security attack, and when the vehicle is under a network security attack, to determine new intrusion detection and defense rules based on the type of the network security attack, and send the new intrusion detection and defense rules to each of the distributed detection nodes.

[0007] Optionally, the number of the distributed detection nodes is the same as the number of the key controllers in the vehicle, one of the distributed detection nodes corresponds to one of the key controllers, and the distributed detection node is the key controller corresponding to the distributed detection node; the key controller is a controller in the vehicle that has the ability to communicate externally, undertakes the data transmission function, and undertakes the security-related function; The central control unit is the vehicle security operation center in the cloud.

[0008] Optionally, the distributed detection node is configured to monitor the external vehicle interfaces, the in-vehicle network, and the controller system in real time, and collect the vehicle network security-related data; the vehicle network security-related data includes the system operation state, the process state, and the communication state, the system operation state includes the CPU occupancy rate, the system access, and the file read and write, and the communication state includes the source IP, the destination IP, the source port, the destination port, the traffic size, the protocol type, and the protocol state.

[0009] Optionally, the distributed detection node is configured to perform data preprocessing on the vehicle network security-related data to obtain the preprocessed vehicle network security-related data, and transmit the preprocessed vehicle network security-related data to the central control unit; the data preprocessing includes data cleaning and format conversion.

[0010] Optionally, the central control unit includes an analysis module and an automatic rule distribution module; The analysis module is communicatively connected to each of the distributed detection nodes respectively; the analysis module is configured to receive the vehicle network security-related data collected by each of the distributed detection nodes, and use the trained recognition model to determine whether the vehicle is under a network security attack and determine the type of the network security attack when the vehicle is under a network security attack, taking the vehicle network security-related data collected by each of the distributed detection nodes as inputs, so as to analyze the vehicle network security-related data collected by each of the distributed detection nodes; The automated rule distribution module is communicatively connected to the analysis module and each of the distributed detection nodes respectively; the automated rule distribution module is configured to, when the vehicle is under a cybersecurity attack, determine new intrusion detection and prevention rules based on the type of the cybersecurity attack, and distribute the new intrusion detection and prevention rules to each of the distributed detection nodes.

[0011] Optionally, the trained recognition model adopts a machine learning model, and the types of the cybersecurity attacks include DOS attacks, port scans, illegal access, and brute-force password cracking.

[0012] Optionally, the automated rule distribution module stores intrusion detection and prevention rules corresponding to each type of cybersecurity attack among various types of cybersecurity attacks, and the intrusion detection and prevention rules stored in the automated rule distribution module are updated regularly, and the regular update is completed based on the cybersecurity attack situation of the vehicle from the last update to the current update.

[0013] Optionally, a rule library is stored in the distributed detection node, and the rule library stores a number of intrusion detection and prevention rules; the distributed detection node is configured to identify the vehicle network security-related data based on the rule library, determine whether the vehicle is under a cybersecurity attack, and send an alarm message to the analysis module when the vehicle is under a cybersecurity attack; the alarm message includes the vehicle network security-related data and the type of the cybersecurity attack; The analysis module is configured to use the trained recognition model to determine whether the vehicle is under a cybersecurity attack and determine the type of the cybersecurity attack when the vehicle is under a cybersecurity attack, taking the vehicle network security-related data in the alarm message as an input. If it is determined that the vehicle is not under a cybersecurity attack or the determined type of the cybersecurity attack is different from the type of the cybersecurity attack in the alarm message, it is determined that the alarm message is incorrect; The automated rule distribution module is configured to, when the alarm message is incorrect, optimize and update the intrusion detection and prevention rules corresponding to the type of the cybersecurity attack in the alarm message, and distribute the updated intrusion detection and prevention rules to each of the distributed detection nodes to update the rule library of the distributed detection nodes.

[0014] Optionally, the automated rule distribution module is configured to distribute the new intrusion detection and prevention rules or the updated intrusion detection and prevention rules to each of the distributed detection nodes through a secure channel.

[0015] Second aspect, the present application provides a working method for an automotive distributed intrusion detection and prevention system, which is applied to the above-mentioned automotive distributed intrusion detection and prevention system. The working method of the automotive distributed intrusion detection and prevention system includes: The distributed detection nodes monitor and collect vehicle network security-related data in real time; The central control unit receives and analyzes the vehicle network security-related data collected by each distributed detection node to determine whether the vehicle is under a network security attack. When the vehicle is under a network security attack, new intrusion detection and prevention rules are determined based on the type of the network security attack, and the new intrusion detection and prevention rules are sent to each distributed detection node.

[0016] According to the specific embodiments provided by the present application, the present application has the following technical effects: The present application provides an automotive distributed intrusion detection and prevention system and its working method, which sets multiple distributed detection nodes and a central control unit. The distributed detection nodes are used to monitor and collect vehicle network security-related data in real time, and the central control unit is used to receive and analyze the vehicle network security-related data collected by each distributed detection node to determine whether the vehicle is under a network security attack. When the vehicle is under a network security attack, new intrusion detection and prevention rules are determined based on the type of the network security attack, and the new intrusion detection and prevention rules are sent to each distributed detection node. The present application can determine whether the vehicle is under a network security attack based on the vehicle network security-related data collected by the distributed detection nodes, further determine new intrusion detection and prevention rules based on the type of the network security attack, and send the new intrusion detection and prevention rules to each distributed detection node, so as to ensure that each distributed detection node can obtain and execute the latest intrusion detection and prevention rules in a timely and accurate manner, realize the dynamic update of the rules, solve the problems existing in the static rule library, and meet the requirements of efficient and real-time security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0018] Figure 1 FIG. 1 is a schematic structural diagram of an automotive distributed intrusion detection and prevention system provided in Embodiment 1 of the present application.

[0019] Figure 2 FIG. 2 is a schematic flow chart of a working method for an automotive distributed intrusion detection and prevention system provided in Embodiment 2 of the present application.

[0020] Figure 3 This is a schematic structural diagram of a computer device provided in Embodiment 3 of the present application. Specific implementation manners

[0021] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0022] Embodiment 1.

[0023] This embodiment provides an automotive distributed intrusion detection and prevention system, as Figure 1 shown. The automotive distributed intrusion detection and prevention system includes: a plurality of distributed detection nodes and a central control unit, and the monitoring ranges of the plurality of distributed detection nodes are different.

[0024] The distributed detection nodes are used to monitor and collect vehicle network security-related data in real time.

[0025] The central control unit is respectively communicatively connected to each of the distributed detection nodes. The central control unit is used to receive and analyze the vehicle network security-related data collected by each of the distributed detection nodes to determine whether the vehicle is under a network security attack, and when the vehicle is under a network security attack, determine new intrusion detection and prevention rules based on the type of the network security attack, and send the new intrusion detection and prevention rules to each of the distributed detection nodes.

[0026] For the automotive distributed intrusion detection and prevention system, in this embodiment, a plurality of distributed detection nodes and a central control unit are first divided. In the architecture of the intelligent connected vehicle, each key controller in the vehicle is respectively set as a distributed detection node, and a cloud vehicle security operation center is established as the central control unit.

[0027] In this embodiment, the following three conditions are used to determine whether a controller is a critical controller: (1) Whether it has the ability to communicate externally (i.e., conduct information interaction), including interface communication, wireless network communication, etc. Generally, controllers with the ability to communicate externally have a greater risk; (2) Whether it undertakes important data transmission functions in the vehicle. For example, controllers such as the central gateway of the whole vehicle and the domain controllers of each domain undertake significant tasks, and these controllers are considered to undertake important data transmission functions in the vehicle; (3) Whether it undertakes important functions related to safety, such as controllers responsible for anti-theft functions, intelligent driving functions, and remote control functions. The harm after these controllers are attacked by network security is greater. Based on the above three conditions, this embodiment can regard controllers such as in-vehicle infotainment systems, TBOX (Telematics BOX), central gateways, and domain controllers as critical controllers.

[0028] Each critical controller is used as a distributed detection node to monitor some key indicators, obtain vehicle network security-related data, and determine whether the vehicle has been attacked by network security through the vehicle network security-related data.

[0029] At this time, in this embodiment, the number of distributed detection nodes is the same as the number of critical controllers in the vehicle. One distributed detection node corresponds to one critical controller. The distributed detection node is the critical controller corresponding to this distributed detection node, and the critical controller is a controller in the vehicle that has the ability to communicate externally, undertakes data transmission functions, and undertakes functions related to safety. The central control unit is the vehicle security operation center in the cloud.

[0030] Next, the distributed detection nodes and the central control unit of this embodiment will be introduced in detail.

[0031] (1) Distributed detection nodes.

[0032] The distributed detection node is used to monitor and collect vehicle network security-related data in real time.

[0033] The distributed detection node in this embodiment is used to monitor the external vehicle interface, in-vehicle network, and controller system in real time, and collect vehicle network security-related data. Specifically, it collects information such as the system operation status, process status, and communication status related to vehicle network security in real time to obtain vehicle network security-related data. The vehicle network security-related data includes the system operation status, process status, and communication status. The system operation status includes the CPU (Central Processing Unit) occupancy rate, system access, and file read / write. The file read / write can be the read / write of important files, and whether a file is important is determined by the user according to requirements. The process status can be the critical process status, and whether a process is critical is determined by the user according to requirements. The communication status includes the source IP, destination IP, source port, destination port, traffic volume, protocol type, and protocol status. Of course, other types of data can also be collected as vehicle network security-related data according to user requirements, and this embodiment does not impose any restrictions on this.

[0034] The distributed detection node in this embodiment can also perform preliminary data preprocessing on the vehicle network security-related data, including data cleaning and format conversion, to ensure the accuracy and consistency of the data, and send the preprocessed vehicle network security-related data to the central control unit. Subsequently, the central control unit receives and analyzes the preprocessed vehicle network security-related data.

[0035] At this time, in this embodiment, the distributed detection node is used to perform data preprocessing on the vehicle network security-related data to obtain the preprocessed vehicle network security-related data, and transmit the preprocessed vehicle network security-related data to the central control unit, where the data preprocessing includes data cleaning and format conversion.

[0036] (2) Central control unit.

[0037] The central control unit is used to collect and analyze the detection data of each distributed detection node. That is, the central control unit is communicatively connected to each distributed detection node respectively. The central control unit is used to receive and analyze the vehicle network security-related data collected by each distributed detection node to determine whether the vehicle is under a network security attack, and when the vehicle is under a network security attack, determine new intrusion detection and defense rules based on the type of the network security attack, so as to automatically generate new intrusion detection and defense rules based on the analysis results, and send the new intrusion detection and defense rules to each distributed detection node.

[0038] The central control unit of this embodiment includes an analysis module and an automated rule distribution module. The analysis module uses a pre-trained machine learning model to deeply analyze the pre-processed vehicle network security-related data received, identify potential abnormal behaviors, that is, identify the attack patterns of potential network security attacks, and based on the identification results, analyze and determine whether a real network security attack has occurred, that is, use a pre-trained machine learning model to determine whether the vehicle has been subjected to a network security attack, and when it is determined that the vehicle has been subjected to a network security attack, determine the type of the network security attack. If it is determined that the vehicle has been subjected to a network security attack, the automated rule distribution module intelligently generates new intrusion detection and prevention rules according to the network security attack situation (that is, the type of the network security attack).

[0039] Among them, the machine learning model can adopt a deep learning model, such as a convolutional neural network, GPT (Generative Pre-trained Transformer), etc., or other models other than the deep learning model, such as SVM (Support Vector Machine), etc. The input of the machine learning model is the vehicle network security-related data collected by the distributed detection nodes or the pre-processed vehicle network security-related data obtained after the distributed detection nodes collect and perform data pre-processing. The output is the type of abnormal behavior. The type of abnormal behavior includes no network security attack and the types of network security attacks. If the output is no network security attack, it can be determined that the vehicle has not been subjected to a network security attack. If the output is the type of network security attack, it can be determined that the vehicle has been subjected to a network security attack, and the type of network security attack to which the vehicle is subjected at this time can be determined. The types of network security attacks can include DOS (Denial of Service) attacks, port scans, illegal access, brute force password cracking, etc.

[0040] Among them, the new intrusion detection and prevention rules are determined according to the types of network security attacks found, and the corresponding new intrusion detection and prevention rules are further distributed. For example, a DOS attack is caused by a certain IP continuously accessing a large amount. Then, if a DOS attack is found, it means that there is no intrusion detection and prevention rule corresponding to this DOS attack in the distributed detection nodes on the current vehicle. The intrusion detection and prevention rule corresponding to the DOS attack can be distributed through the automated rule distribution module. By this remote upgrade method, the rules in the distributed detection nodes on the vehicle are updated, and it is set to monitor the amount of data input by each IP within a short period of time. After exceeding a certain size and a certain time, firewall interception can be performed. Thus, through the automated rule distribution module, the new intrusion detection and prevention rules are immediately distributed to each distributed detection node to achieve efficient and intelligent update of the rules.

[0041] Intrusion detection and prevention rules essentially design a protection rule for each type of network security attack to prevent the vehicle from being attacked by the corresponding type of network security attack. Among them, intrusion detection and prevention rules can be divided into warning types and defense types. Warning types only give prompts without taking actions, such as large traffic within a short period, read and write records of important files, etc. Defense types not only give prompts but also take corresponding response actions, such as killing and restarting when a certain process has too high CPU usage, intercepting the IP when the system is under a DOS attack, etc.

[0042] At this time, in this embodiment, the central control unit includes an analysis module and an automatic rule distribution module.

[0043] The analysis module is respectively communicatively connected to each distributed detection node. The analysis module is used to receive the vehicle network security-related data collected by each distributed detection node, and respectively use the vehicle network security-related data collected by each distributed detection node as input, and use the trained recognition model to determine whether the vehicle is under a network security attack and determine the type of network security attack when the vehicle is under a network security attack, so as to analyze the vehicle network security-related data collected by each distributed detection node.

[0044] The automatic rule distribution module is respectively communicatively connected to the analysis module and each distributed detection node. The automatic rule distribution module is used to, when the vehicle is under a network security attack, determine a new intrusion detection and prevention rule based on the type of network security attack, and distribute the new intrusion detection and prevention rule to each distributed detection node.

[0045] Among them, the trained recognition model adopts a machine learning model, and the types of network security attacks include DOS attacks, port scans, illegal access, and brute-force password cracking.

[0046] Among them, the automatic rule distribution module stores the intrusion detection and prevention rules corresponding to each type of network security attack among various types of network security attacks. Thus, based on the correspondence between the type of network security attack and the intrusion detection and prevention rule, a new intrusion detection and prevention rule can be determined based on the type of network security attack.

[0047] In this embodiment, the intrusion detection and prevention rules stored in the automatic rule distribution module are updated regularly. The regular update is completed based on the cyber security attacks suffered by the vehicle between the last update and the current update. Specifically, corresponding intrusion detection and prevention rules can be customized according to the types of cyber security attacks identified between the last update and the current update, and stored in the automatic rule distribution module to update the intrusion detection and prevention rules stored in the automatic rule distribution module. The implementation method of customizing the corresponding intrusion detection and prevention rules can be that cyber security operation personnel design new intrusion detection and prevention rules according to the cyber security attack situation during the period from the last update to the current update. It is necessary to continuously supplement new intrusion detection and prevention rules on the platform side of the central control unit. The automatic rule distribution module automatically distributes new intrusion detection and prevention rules that exist on the platform side but not on the distributed detection nodes of the vehicle to the distributed detection nodes.

[0048] This embodiment discloses a vehicle distributed intrusion detection and prevention system, and designs the automatic rule distribution process of the vehicle distributed intrusion detection and prevention system. For the vehicle distributed intrusion detection and prevention system, multiple distributed detection nodes and a central control unit are divided. The distributed detection nodes are responsible for real-time monitoring and collecting vehicle cyber security related data, and the central control unit is responsible for receiving and analyzing vehicle cyber security related data, and automatically generating new intrusion detection and prevention rules based on the analysis results. The new intrusion detection and prevention rules are immediately distributed to each distributed detection node through the automatic rule distribution module to achieve efficient and intelligent update of the rules.

[0049] The central control unit of this embodiment can also continuously collect the false alarm information reported by each distributed detection node, use a machine learning model to learn the false alarm information, intelligently generate updated intrusion detection and prevention rules, and distribute them to each distributed detection node to reduce subsequent false alarm situations. False alarm information means that some distributed detection nodes send an alarm message to the central control unit according to the intrusion detection and prevention rules, but after being judged by the trained recognition model, it is found that this alarm message is not a real cyber security attack, indicating that there are unreasonable parts in the design of the intrusion detection and prevention rules when this alarm message is sent. At this time, these false alarm information can be marked and then re-input into the trained recognition model for continuous learning to help the trained recognition model better understand the behavior of real cyber security attacks. At the same time, the original less reasonable intrusion detection and prevention rules can also be adjusted. For example, after counting the same type of cyber security attacks, a more accurate threshold can be found through an algorithm to adjust the intrusion detection and prevention rules corresponding to this type of cyber security attack.

[0050] At this time, in this embodiment, a rule library is stored in the distributed detection node, and several intrusion detection and prevention rules are stored in the rule library. The distributed detection node is used to identify vehicle network security-related data based on the rule library, identify potential abnormal behaviors, determine whether the vehicle is under a network security attack, and send an alarm message to the analysis module when the vehicle is under a network security attack. The alarm message includes the vehicle network security-related data at this time and the type of network security attack determined based on the rule library.

[0051] The analysis module is used to use the vehicle network security-related data in the alarm message as input, and use the trained recognition model to determine whether the vehicle is under a network security attack and determine the type of network security attack when the vehicle is under a network security attack. If it is determined by the trained recognition model that the vehicle is not under a network security attack or the determined type of network security attack is different from the type of network security attack in the alarm message, it is determined that the alarm message is incorrect, which is equivalent to the alarm message being a false alarm message at this time.

[0052] The automated rule distribution module is used to optimize and update the intrusion detection and prevention rules corresponding to the type of network security attack in the alarm message when the alarm message is incorrect. Specifically, it can be completed manually, and the updated intrusion detection and prevention rules are distributed to each distributed detection node, replacing the intrusion detection and prevention rules corresponding to the type of network security attack in the original alarm message of each distributed detection node to update the rule library of the distributed detection node.

[0053] In this embodiment, the automated rule distribution module is used to distribute the new intrusion detection and prevention rules or the updated intrusion detection and prevention rules to each distributed detection node through a secure channel. The secure channel can be an encrypted data transmission channel, etc. The new intrusion detection and prevention rules or the updated intrusion detection and prevention rules are quickly distributed through the secure channel. After each distributed detection node receives the new rules, it immediately updates its internal rule library and starts to execute the new intrusion detection and prevention rules. This process realizes the intelligent automated rule distribution function, ensuring that the entire network security protection system can respond to new threats in real time and accurately.

[0054] In this embodiment, each distributed detection node is also used to timely feedback the problems and abnormal situations encountered in its actual operation to the central control unit. The problems and abnormal situations encountered are the alarm messages detected according to the rule base. Except for some false alarm messages among all the alarm messages, the others represent network security attacks. After receiving the feedback, the central control unit immediately conducts analysis and processing, and triggers the emergency update and distribution process of the rules when necessary. Whether it is necessary can be judged according to the level of the alarm, the triggering frequency, the number of vehicles with the same type of alarm, etc. The emergency update and distribution process is to update the intrusion detection and prevention rules in the automatic rule distribution module, which can be specifically completed manually and distributed to each distributed detection node through the automatic rule distribution module to ensure the continuous stability and protection ability of the system.

[0055] In this embodiment, by dividing into multiple distributed detection nodes and a central control unit, the comprehensive monitoring of the network security of intelligent connected vehicles is realized. The distributed detection nodes can monitor and collect the vehicle network security related data in real time, and analyze the vehicle network security related data based on the rule base, so as to ensure the timely discovery and response to potential threats. The central control unit is responsible for receiving and analyzing these vehicle network security related data, and automatically generating new intrusion detection and prevention rules. This process does not require manual intervention, greatly improving the timeliness and accuracy of rule updates. This embodiment introduces advanced machine learning models and automatic rule distribution modules, which can automatically identify and respond to new network security attacks. By continuously collecting and analyzing network threat data, the system can continuously optimize its rule generation and distribution capabilities, so as to achieve rapid response and effective defense against network threats. This feature significantly enhances the adaptive ability and security protection level of the system. This embodiment also has efficient rule caching and synchronization technologies and a perfect feedback processing mechanism. The distributed rule cache can reduce the distribution delay and improve the efficiency of rule distribution. The regular rule verification and synchronization mechanism ensures the consistency of the rules of each distributed detection node. The feedback processing mechanism allows each distributed detection node to timely feedback the problems encountered in its actual operation to the central control unit, thus realizing the continuous optimization and improvement of the system performance.

[0056] Embodiment 2.

[0057] This embodiment provides a working method of an automotive distributed intrusion detection and prevention system, which is applied to the automotive distributed intrusion detection and prevention system described in Embodiment 1, as Figure 2 shown. The working method of the automotive distributed intrusion detection and prevention system includes the following steps.

[0058] S1: The distributed detection nodes monitor and collect the vehicle network security related data in real time.

[0059] S2: The central control unit receives and analyzes the vehicle network security-related data collected by each distributed detection node to determine whether the vehicle is under a cyber security attack. When the vehicle is under a cyber security attack, new intrusion detection and prevention rules are determined based on the type of the cyber security attack, and the new intrusion detection and prevention rules are sent to each distributed detection node.

[0060] Embodiment 3.

[0061] In an exemplary embodiment, a computer device is provided. The computer device can be a server or a terminal, and its internal structure diagram can be as shown in Figure 3 the figure. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a working method of an automotive distributed intrusion detection and prevention system, specifically completing the steps of receiving and analyzing the vehicle network security-related data collected by each distributed detection node to determine whether the vehicle is under a cyber security attack, and when the vehicle is under a cyber security attack, determining new intrusion detection and prevention rules based on the type of the cyber security attack, and sending the new intrusion detection and prevention rules to each distributed detection node.

[0062] Those skilled in the art can understand that Figure 3 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0063] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0064] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0065] In this article, specific examples are used to elaborate on the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation on the present application.

Claims

1. A distributed intrusion detection and defense system for automobiles, characterized in that: The automobile distributed intrusion detection and defense system comprises: a plurality of distributed detection nodes and a central control unit, wherein the monitoring ranges of the plurality of distributed detection nodes are different; The distributed detection nodes are used to monitor and collect vehicle network security related data in real time; The central control unit is respectively communicated with each of the distributed detection nodes; the central control unit is used to receive and analyze the vehicle network security related data collected by each of the distributed detection nodes to determine whether the car is subject to a network security attack, and when the car is subject to a network security attack, determine new intrusion detection and defense rules based on the type of network security attack, and send the new intrusion detection and defense rules to each of the distributed detection nodes.

2. The automobile distributed intrusion detection and defense system according to claim 1, characterized in that: The number of the distributed detection nodes is the same as the number of key controllers in the car, one distributed detection node corresponds to one key controller, and the distributed detection node is the key controller corresponding to the distributed detection node; the key controller is a controller in the car that has external communication capabilities, undertakes data transmission functions and undertakes safety-related functions; The central control unit is a vehicle safety operation center in the cloud.

3. The automobile distributed intrusion detection and defense system according to claim 2, characterized in that: The distributed detection nodes are used to monitor the external vehicle interface, the internal vehicle network and the controller system in real time, and collect vehicle network security related data; The vehicle network security related data includes system operation status, process status and communication status. The system operation status includes CPU occupancy, system access and file reading and writing. The communication status includes source IP, destination IP, source port, destination port, traffic size, protocol type and protocol status.

4. The automobile distributed intrusion detection and defense system according to claim 3, characterized in that: The distributed detection node is used to perform data preprocessing on the vehicle network security related data to obtain the preprocessed vehicle network security related data, and transmit the preprocessed vehicle network security related data to the central control unit; the data preprocessing includes data cleaning and format conversion.

5. The automobile distributed intrusion detection and defense system according to claim 1, characterized in that: The central control unit includes an analysis module and an automation rule issuing module; The analysis module is respectively connected to each of the distributed detection nodes in communication; the analysis module is used to receive the vehicle network security related data collected by each of the distributed detection nodes, and respectively use the vehicle network security related data collected by each of the distributed detection nodes as input, and use the trained recognition model to determine whether the car is subject to a network security attack and determine the type of network security attack when the car is subject to a network security attack, so as to analyze the vehicle network security related data collected by each of the distributed detection nodes; The automated rule delivery module is respectively in communication with the analysis module and each of the distributed detection nodes; The automatic rule sending module is used to determine new intrusion detection and defense rules based on the type of network security attack when the car is attacked by network security, and send the new intrusion detection and defense rules to each of the distributed detection nodes.

6. The automobile distributed intrusion detection and defense system according to claim 5, characterized in that: The trained recognition model adopts a machine learning model, and the types of network security attacks include DOS attacks, port scanning, illegal access and brute force password cracking.

7. The automobile distributed intrusion detection and defense system according to claim 5, characterized in that: The automated rule delivery module stores intrusion detection and defense rules corresponding to each type of network security attack among multiple types of network security attacks, and the intrusion detection and defense rules stored in the automated rule delivery module are updated regularly, and the regular updates are completed based on the network security attacks suffered by the vehicle between the last update and the current update.

8. The automobile distributed intrusion detection and defense system according to claim 5, characterized in that: The distributed detection node stores a rule base, which stores a number of intrusion detection and defense rules; the distributed detection node is used to identify the vehicle network security related data based on the rule base, determine whether the vehicle is subject to a network security attack, and send warning information to the analysis module when the vehicle is subject to a network security attack; the warning information includes the vehicle network security related data and the type of network security attack; The analysis module is used to use the vehicle network security related data in the warning information as input, use the trained recognition model to determine whether the vehicle is subjected to a network security attack and determine the type of network security attack when the vehicle is subjected to a network security attack, and if it is determined that the vehicle is not subjected to a network security attack or the determined type of network security attack is different from the type of network security attack in the warning information, then determine that the warning information is incorrect; The automated rule delivery module is used to optimize and update the intrusion detection and defense rules corresponding to the type of network security attack in the alarm information when the alarm information is incorrect, and deliver the updated intrusion detection and defense rules to each of the distributed detection nodes to update the rule base of the distributed detection nodes.

9. The automobile distributed intrusion detection and defense system according to claim 8, characterized in that: The automated rule delivery module is used to deliver new intrusion detection and defense rules or updated intrusion detection and defense rules to each of the distributed detection nodes through a secure channel.

10. A working method of a vehicle distributed intrusion detection and defense system, applied to the vehicle distributed intrusion detection and defense system according to any one of claims 1 to 9, characterized in that: The working method of the automobile distributed intrusion detection and defense system includes: Distributed detection nodes monitor and collect vehicle network security related data in real time; The central control unit receives and analyzes the vehicle network security related data collected by each distributed detection node to determine whether the car is under network security attack. When the car is under network security attack, it determines new intrusion detection and defense rules based on the type of network security attack and sends the new intrusion detection and defense rules to each distributed detection node.

Citation Information

Patent Citations

  • Vehicle intrusion detection method and defense system

    CN112822684A

  • Cooperative defense method and system for processor network protection

    CN117614745A

  • Vehicle intrusion detection method and device, storage medium and vehicle

    CN117938900A

  • Tracking and management method for responding to a cyber-attack

    US20230072068A1

Cited By

  • Automobile network attack defense method and system based on greedy algorithm under multivariate constraints

    CN122137622A