Internet of vehicles network security protection method and device, vehicle and cloud platform
By deploying probe packets on the vehicle end, monitoring and uploading network security incidents in real time to the cloud platform, forming a closed-loop management system, solving the problem that protective measures in the existing technology focus on one aspect, and achieving effective response to multi-dimensional security threats for vehicles.
Patent Information
- Application Number
- CN202510241231.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-06-03
AI Technical Summary
In the prior art, vehicle safety protection measures focus on one aspect and cannot effectively deal with multi-dimensional security threats.
Deploy probe packets on the vehicle end, monitor network activities and host systems in real time, detect network security events and upload them to the vehicle management node, report the vehicle management node to the cloud platform, and the cloud platform analyzes and issues target operations to the vehicle end to execute, forming a closed-loop management system.
Real-time security monitoring of vehicle network activities and host systems is realized, timely and effectively handles security incidents, provides multi-level and comprehensive security protection, and effectively resists complex attack methods.
Smart Images

Figure CN120090840A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of vehicles, and particularly to an Internet of Vehicles (IoV) network security protection method, device, vehicle, and cloud platform. Background Art
[0002] With the rapid development of information technology, ICC (Intelligent and Connected Cars) has become an important part of modern transportation. Through the integration of advanced sensors, communication technologies, and computing capabilities, the interconnection and interoperability between vehicle-to-vehicle, vehicle-to-infrastructure, and vehicle-to-Internet have been realized. In related technologies, most of the protection measures for ensuring vehicle safety focus on the security protection of a certain aspect (such as only focusing on in-vehicle entertainment systems or the defense against specific types of cyberattacks), and cannot effectively cope with multi-dimensional security threats. Summary of the Invention
[0003] This application provides an IoV network security protection method, device, vehicle, and cloud platform to solve the problems that most of the protection measures in related technologies focus on the security protection of a certain aspect and cannot effectively cope with multi-dimensional security threats.
[0004] In a first aspect of an embodiment of this application, an IoV network security protection method is provided, including the following steps: Deploying probe packets in the vehicle terminal; Detecting network security events in the vehicle terminal based on the probe packets, and uploading the network security events to the vehicle's vehicle management node, where the vehicle management node reports the network security events to the cloud platform, and the cloud platform determines a target operation according to the network security events and issues the target operation to the vehicle terminal to achieve closed-loop management.
[0005] Optionally, the probe packet includes: the first to fourth components. Detecting network security events in the vehicle terminal based on the probe packet and uploading the network security events to the vehicle's vehicle management node includes: Detecting network security events in the vehicle terminal based on the second and third components, where the network security events are stored in the fourth component and uploaded to the first component; The first component reports the network security events to the vehicle management node.
[0006] Optionally, detecting network security events in the vehicle terminal based on the second and third components includes: Receiving the monitoring application rules configured by the cloud platform, where the second component detects the network dimension of the vehicle terminal based on the monitoring application rules, and the third component detects the host dimension of the vehicle terminal based on the monitoring application rules; Determining the network security events of the vehicle terminal according to the detection results.
[0007] Optionally, the vehicle management node is deployed in the in-vehicle terminal device, the first component and the fourth component are deployed in each controller, the second component is deployed in the in-vehicle entertainment system and the in-vehicle terminal device, and the third component is deployed in the in-vehicle entertainment system.
[0008] In the second aspect of the embodiments of the present application, a vehicle networking network security protection method is provided. This method is applied to a cloud platform and includes the following steps: receiving a network security event reported by a vehicle management node at the vehicle end; determining a target operation based on the network security event, and sending the target operation to the vehicle end to achieve closed-loop management.
[0009] Optionally, before receiving the network security event reported by the vehicle end, it further includes: receiving a rule request sent by the vehicle management node; configuring monitoring application rules according to the rule request, where the monitoring application rules include one or more of firewall rules, intrusion detection rules, and event type configuration rules; sending the configured monitoring application rules to the vehicle management node, where the vehicle management node receives and stores the configured monitoring application rules, and sends the configured monitoring application rules to the first components on each controller node.
[0010] In the third aspect of the embodiments of the present application, a vehicle networking network security protection device is provided. This device is applied to a vehicle and includes: a deployment module for deploying a probe packet at the vehicle end; a protection module for detecting a network security event at the vehicle end based on the probe packet and uploading the network security event to the vehicle management node at the vehicle end, where the vehicle management node reports the network security event to the cloud platform, and the cloud platform determines a target operation based on the network security event and sends the target operation to the vehicle end to achieve closed-loop management.
[0011] In the fourth aspect of the embodiments of the present application, a vehicle networking network security protection device is provided. This device is applied to a cloud platform and includes: a receiving module for receiving a network security event reported by the vehicle management node at the vehicle end; a management module for determining a target operation based on the network security event and sending the target operation to the vehicle end to achieve closed-loop management.
[0012] In the fifth aspect of the embodiments of the present application, a vehicle is provided, including: a memory, a processor, and a computer program stored on the memory and executable on the processor. The processor executes the program to implement the vehicle networking network security protection method as described in the above embodiments.
[0013] In the sixth aspect of the embodiments of the present application, a cloud platform is provided, including: a memory, a processor, and a computer program stored on the memory and executable on the processor. The processor executes the program to implement the vehicle networking network security protection method as described in the above embodiments.
[0014] Therefore, the present application has at least the following beneficial effects:
[0015] In the embodiments of the present application, real-time security monitoring of the vehicle internal network activities and the host system is achieved by deploying probe packets at the vehicle end. When a network security event is detected, it is first uploaded to the vehicle management node, and then reported by the vehicle management node to the cloud platform. The cloud platform determines the target operations based on event analysis and sends these operation instructions back to the vehicle end for execution, forming a complete closed-loop management system, ensuring that all security events can be processed in a timely and effective manner. At the same time, it also provides multi-level and all-round security protection to effectively resist complex attack means. Thus, the problem that most of the protection measures in the related art focus on security protection in a certain aspect and cannot effectively cope with multi-dimensional security threats is solved.
[0016] Additional aspects and advantages of the present application will be given in part in the following description, will become apparent in part from the following description, or will be understood through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The above and / or additional aspects and advantages of the present application will become apparent and easy to understand from the following description of the embodiments in conjunction with the drawings, in which:
[0018] Figure 1 is a flowchart of a vehicle networking network security protection method according to an embodiment of the present application;
[0019] Figure 2 is a flowchart of the vehicle end reporting a network security event to the cloud platform according to an embodiment of the present application;
[0020] Figure 3 is a flowchart of a vehicle networking network security protection method according to another embodiment of the present application;
[0021] Figure 4 is a schematic flowchart of the cloud platform configuring rules for the probe packets at the vehicle end according to an embodiment of the present application;
[0022] Figure 5 is a block diagram of a vehicle networking network security protection device according to an embodiment of the present application;
[0023] Figure 6 is a block diagram of a vehicle networking network security protection device according to another embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] Embodiments of the present application will be described in detail below. Examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the drawings are exemplary and are intended to explain the present application and should not be construed as limiting the present application.
[0025] The method, device, vehicle, and cloud platform for vehicle networking network security protection according to the embodiments of the present application will be described below with reference to the accompanying drawings. In view of the problems mentioned in the above background art, the present application provides a method for vehicle networking network security protection. In this method, real-time security monitoring of the internal network activities and host systems of the vehicle is achieved by deploying probe packets at the vehicle end. When a network security event is detected, it is first uploaded to the vehicle management node, and then reported by the vehicle management node to the cloud platform. The cloud platform determines the target operations based on event analysis and sends these operation instructions back to the vehicle end for execution, forming a complete closed-loop management system, ensuring that all security events can be processed in a timely and effective manner, and at the same time providing multi-level and all-round security protection to effectively resist complex attack means. Thus, the problems in the related art that most of the protection measures focus on a certain aspect of security protection and cannot effectively cope with multi-dimensional security threats are solved.
[0026] Specifically, Figure 1 is a schematic flowchart of a method for vehicle networking network security protection provided by an embodiment of the present application.
[0027] As Figure 1 shown, this vehicle networking network security protection method is applied to a vehicle and includes the following steps:
[0028] In step S101, probe packets are deployed at the vehicle end.
[0029] Among them, the probe packet includes: the first to fourth components. The first component and the fourth component are deployed in each controller, the second component is deployed in the in-vehicle entertainment system and in-vehicle terminal devices, and the third component is deployed in the in-vehicle entertainment system.
[0030] Specifically, the first component Node Manager in the embodiment of the present application can be a management node within the controller, deployed in each component, and both ICC and TBOX will be deployed. It is responsible for managing the intrusion detection and prevention components at the vehicle end, interacting with the vehicle management node, obtaining the rules configured by VSOC, and reporting information such as security events, logs, and traffic; the second component NIDPS can be a network dimension intrusion detection and prevention component, deployed in ICC and TBOX to implement functions such as firewall configuration, network intrusion detection, deep packet detection, traffic detection, and Bluetooth detection; the third component HIDS can be a host system dimension intrusion detection, deployed in ICC to implement functions such as log monitoring, interface status monitoring, system environment monitoring, integrity detection, and rootkit detection, and the fourth component SELOG can be a security log collection and storage component, deployed in each component to implement the function of collecting and storing the vehicle's security logs.
[0031] It should be noted that the ICC in the embodiments of the present application has two operating systems. QNX is the main system, and the Android system is a virtual machine. The embodiments of the present application can be processed separately according to the actual situation. For the QNX system of the ICC, three components, namely NodeManager, NIDPS, and SELOG, are deployed, which are responsible for the node management function in the QNX system of the ICC device, intrusion detection and prevention in the network dimension, and event log aggregation function within the QNX system respectively. For the Android system of the ICC, four components, namely NodeManager, HIDS, NIDPS, and SELOG, are deployed, which are responsible for the node management function in the Android system of the ICC device, intrusion detection and monitoring in the system dimension, intrusion detection and prevention in the network dimension, and event log aggregation function within the Android system respectively.
[0032] In step S102, network security events at the vehicle end are detected based on probe packets, and the network security events are uploaded to the vehicle management node at the vehicle end. Among them, the vehicle management node reports the network security events to the cloud platform, and the cloud platform determines the target operation according to the network security events and sends the target operation to the vehicle end to achieve closed-loop management.
[0033] It can be understood that the embodiments of the present application can use the above-deployed probe packets to monitor the network security status at the vehicle end in real time and take corresponding actions according to the detected security events. Finally, by executing the target operation sent from the cloud platform, a complete security event response cycle is completed, realizing closed-loop management from event detection to disposal and then to feedback, effectively improving the overall network security level of intelligent connected vehicles.
[0034] In an embodiment of the present application, detecting network security events at the vehicle end based on probe packets and uploading the network security events to the vehicle management node at the vehicle end includes: detecting network security events at the vehicle end based on the second component and the third component, where the network security events are stored in the fourth component and the network security events are uploaded to the first component; the first component reports the network security events to the vehicle management node.
[0035] Further, detecting network security events at the vehicle end based on the second component and the third component includes: receiving the monitoring application rules configured by the cloud platform, where the second component detects the network dimension at the vehicle end based on the monitoring application rules, and the third component detects the host dimension at the vehicle end based on the monitoring application rules; determining the network security events at the vehicle end according to the detection results.
[0036] Specifically, the embodiments of the present application can configure the rules of the monitoring application, send the rules to the vehicle management node Vehicle Manager, and the Vehicle Manager forwards the rules to the controller node Node Manager. The HIDS loads and uses the rules. Periodically query the Android system application list to analyze the installation and uninstallation logs to monitor the illegal installation and uninstallation of applications. When an installation or uninstallation operation is monitored, a network security event is generated. Monitor the proc file system to query the programs running on the system and compare them with the rules for monitoring applications to monitor the illegal startup of applications, and generate an event network security event when monitored. In the actual execution process, the HIDS uses SELOG to report the event to the Node Manager for event aggregation within the controller; then the Node Manager reports the event to the Vehicle Manager for vehicle-wide event aggregation and unified upload; finally, the Vehicle Manager reports the event to the VSOC for monitoring network security time, such as Figure 2 shown.
[0037] In some embodiments, in order to improve the response speed and reduce the dependence on the external network, the vehicle management node can be deployed in the in-vehicle terminal device, which can accelerate the processing speed of security events and, to a certain extent, ensure that the vehicle can still perform basic security event management and preliminary processing when the network connection is unstable or interrupted.
[0038] According to the vehicle networking network security protection method proposed by the embodiments of the present application, real-time security monitoring of the vehicle internal network activities and host systems is achieved by deploying probe packets at the vehicle end. When a network security event is detected, it is first uploaded to the vehicle management node, and then reported by the vehicle management node to the cloud platform. The cloud platform determines the target operations based on event analysis and sends these operation instructions back to the vehicle end for execution, forming a complete closed-loop management system, ensuring that all security events can be processed in a timely and effective manner, and at the same time providing multi-level and all-round security protection to effectively resist complex attack means.
[0039] Secondly, another embodiment of the present application also provides a vehicle networking network security protection method, which is applied to the cloud platform, as Figure 3 shown, and includes the following steps:
[0040] In step S201, receive the network security events reported by the vehicle management node at the vehicle end.
[0041] In step S202, determine the target operations according to the network security events and send the target operations to the vehicle end to achieve closed-loop management.
[0042] It can be understood that the probe packets deployed at the vehicle end in the embodiments of the present application are responsible for real-time monitoring of the internal network activities of the vehicle and the security status of the host system. Once any abnormal behavior or potential threat is detected, it is marked as a network security event. The detected network security events are first uploaded to the Vehicle Manager at the vehicle end. The Vehicle Manager acts as an intermediary. It is not only responsible for collecting security events from various components, but also further reports these events to the cloud platform. After receiving the network security events reported from the vehicle end, the cloud platform formulates corresponding target operations and sends them back to the vehicle end through the same communication link. After receiving the instructions from the cloud, the Vehicle Manager distributes them to the corresponding components for execution. For example, if the target operation is to update the firewall rules, it is the NIDPS component that is responsible for execution; if it is to check the system integrity or uninstall illegal applications, the HIDS component completes the corresponding tasks.
[0043] In an embodiment of the present application, before receiving the network security events reported from the vehicle end, it further includes: receiving a rule request sent by the Vehicle Manager; configuring monitoring application rules according to the rule request, where the monitoring application rules include one or more of firewall rules, intrusion detection rules, and event type configuration rules; sending the configured monitoring application rules to the Vehicle Manager, where the Vehicle Manager receives and stores the configured monitoring application rules, and sends the configured monitoring application rules to the first components on each controller node.
[0044] It can be understood that, in order to further enhance the flexibility and response ability of the vehicle networking network security protection system, before receiving the network security events reported from the vehicle end, it further includes a series of steps for pre-configuring monitoring application rules. These steps ensure that the system can dynamically adjust its protection strategy according to the latest security threats and effectively apply them to each controller node.
[0045] Specifically, as Figure 4 shown, the Vehicle Manager will regularly or based on specific conditions initiate a rule request to the cloud platform. This request contains the security status information of the current vehicle and the types of rules that need to be updated. After receiving the rule request, the cloud platform will configure the corresponding monitoring application rules according to the latest security intelligence, regulatory requirements, and the specific needs of the vehicle. These rules can include but are not limited to:
[0046] 1) Firewall rules: Define which network traffic should be allowed or blocked;
[0047] 2) Intrusion detection rules: Specify how to identify potential attack behaviors;
[0048] 3) Event type configuration rules: Determine which types of events should be regarded as security events and trigger alarms or other response measures;
[0049] After the configuration is completed, the cloud platform will send the new monitoring application rules to the vehicle management node. These rules are transmitted through a secure communication link to ensure the integrity and confidentiality of the data. After receiving the new rules, the vehicle management node will first verify these rules to ensure their correctness, and then store them in the local database for subsequent use.
[0050] Furthermore, the vehicle management node will distribute these configured monitoring application rules to the Node Manager (the first component) on each controller node. The Node Manager performs the rule distribution operation, gives the rules to each detection engine, and notifies the engine to perform rule reloading, ensuring that all relevant security components can obtain the latest protection rules in a timely manner, thereby effectively improving security.
[0051] It should be noted that in the embodiments of the present application, each modification of the rules will generate a new rule version, and the version number is pushed to the vehicle side together with the rules. The embodiments of the present application adopt a rule management based on the version method, which can more efficiently distribute and deploy the rules.
[0052] In addition, referring to the accompanying drawings, a vehicle networking network security protection device according to an embodiment of the present application is described. This method is applied to a vehicle. As Figure 5 shown, the vehicle networking network security protection device 10 includes: a deployment module 100 and a protection module 200.
[0053] Among them, the deployment module 100 is used to deploy probe packets in the vehicle side; the protection module 200 is used to detect network security events in the vehicle side based on the probe packets, and upload the network security events to the vehicle management node in the vehicle side. Among them, the vehicle management node reports the network security events to the cloud platform, and the cloud platform determines the target operation according to the network security events, and sends the target operation to the vehicle side to achieve closed-loop management.
[0054] In an embodiment of the present application, the probe packet includes: the first to fourth components. The protection module is further used to: detect network security events in the vehicle side based on the second component and the third component, where the network security events are stored in the fourth component, and upload the network security events to the first component; the first component reports the network security events to the vehicle management node.
[0055] In one embodiment of the present application, the protection module is further configured to: receive the monitoring application rules configured by the cloud platform, wherein the second component detects the network dimension of the vehicle end based on the monitoring application rules, and the third component detects the host dimension of the vehicle end based on the monitoring application rules; determine the network security events of the vehicle end according to the detection results.
[0056] In one embodiment of the present application, the vehicle management node is deployed in the in-vehicle terminal device, the first component and the fourth component are deployed in each controller, the second component is deployed in the in-vehicle entertainment system and the in-vehicle terminal device, and the third component is deployed in the in-vehicle entertainment system.
[0057] As Figure 6 shown, another vehicle networking network security protection device 20 is provided in an embodiment of the present application. The device is applied to the cloud platform and includes: a receiving module 300 configured to receive the network security events reported by the vehicle management node of the vehicle end; a management module 400 configured to determine a target operation according to the network security events and send the target operation to the vehicle end to implement closed-loop management.
[0058] In one embodiment of the present application, the vehicle networking network security protection device 20 further includes: a configuration module configured to, before receiving the network security events reported by the vehicle end, receive a rule request sent by the vehicle management node; configure the monitoring application rules according to the rule request, where the monitoring application rules include one or more of firewall rules, intrusion detection rules, and event type configuration rules; send the configured monitoring application rules to the vehicle management node, where the vehicle management node receives and stores the configured monitoring application rules, and sends the configured monitoring application rules to the first component on each controller node.
[0059] It should be noted that the foregoing explanation of the embodiments of the vehicle networking network security protection method also applies to the vehicle networking network security protection device of this embodiment, and will not be elaborated here.
[0060] According to the vehicle networking network security protection device proposed in the embodiment of the present application, real-time security monitoring of the internal network activities and host systems of the vehicle is achieved by deploying probe packets at the vehicle end. When a network security event is detected, it is first uploaded to the vehicle management node, and then reported by the vehicle management node to the cloud platform. The cloud platform determines the target operations based on event analysis and sends these operation instructions back to the vehicle end for execution, forming a complete closed-loop management system, ensuring that all security events can be processed in a timely and effective manner, and at the same time providing multi-level and all-round security protection to effectively resist complex attack means.
[0061] An embodiment of the present application further provides a vehicle, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the processor executes the program to implement the vehicle networking network security protection method applied to the vehicle as described in the above embodiment.
[0062] An embodiment of the present application further provides a cloud platform, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the processor executes the program to implement the vehicle networking network security protection method applied to the cloud platform as described in the above embodiment.
[0063] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms are not necessarily directed to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or N embodiments or examples in a suitable manner. In addition, without conflict, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0064] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of the features. In the description of the present application, the meaning of "N" is at least two, such as two, three, etc., unless otherwise specifically defined.
[0065] Any process or method description in the flowchart or described in other ways herein can be understood to represent a module, segment, or part of code including one or more executable instructions for implementing a customized logic function or process, and the scope of the preferred embodiments of the present application includes additional implementations, where the functions can be executed in a substantially simultaneous manner or in a reverse order according to the involved functions, rather than in the order shown or discussed, which should be understood by those skilled in the art of the embodiments of the present application.
[0066] It should be understood that each part of the present application can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, the N steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays, field programmable gate arrays, and the like.
[0067] Those of ordinary skill in the art can understand that all or part of the steps carried by the method of the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.
[0068] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.
Claims
1. A method for protecting the network security of an Internet of Vehicles, characterized in that: The method is applied to a vehicle and comprises the following steps: Deploy the probe package in the vehicle end; The network security event on the vehicle side is detected based on the probe package, and the network security event is uploaded to the vehicle management node on the vehicle side, wherein the vehicle management node reports the network security event to the cloud platform, and the cloud platform determines the target operation according to the network security event, and sends the target operation to the vehicle side to realize closed-loop management.
2. The vehicle network security protection method according to claim 1 is characterized in that: The probe package includes: first to fourth components, and the detection of the network security event of the vehicle side based on the probe package and uploading the network security event to the vehicle management node of the vehicle side includes: Detecting a network security event on the vehicle side based on the second component and the third component, wherein the network security event is stored in the fourth component, and uploading the network security event to the first component; The first component reports the network security incident to the vehicle management node.
3. The vehicle network security protection method according to claim 2 is characterized in that: Detecting vehicle-side network security events based on the second and third components includes: Receiving monitoring application rules configured by the cloud platform, wherein the second component detects the network dimension of the vehicle end based on the monitoring application rules, and the third component detects the host dimension of the vehicle end based on the monitoring application rules; The network security event of the vehicle is determined according to the detection result.
4. The vehicle network security protection method according to claim 2 or 3, characterized in that: The vehicle management node is deployed in the vehicle terminal device, the first component and the fourth component are deployed in respective controllers, the second component is deployed in the vehicle entertainment system and the vehicle terminal device, and the third component is deployed in the vehicle entertainment system.
5. A method for protecting the network security of an Internet of Vehicles, characterized in that: The method is applied to a cloud platform and comprises the following steps: Receive network security events reported by the vehicle management node on the vehicle side; A target operation is determined based on the network security event, and the target operation is sent to the vehicle end to implement closed-loop management.
6. The vehicle network security protection method according to claim 5 is characterized in that: Before receiving the cybersecurity incident reported by the vehicle, it also includes: Receiving a rule request sent by the vehicle management node; Configure monitoring application rules according to the rule request, wherein the monitoring application rules include one or more of firewall rules, intrusion detection rules, and event type configuration rules; The configured monitoring application rules are sent to the vehicle management node, wherein the vehicle management node receives and stores the configured monitoring application rules, and sends the configured monitoring application rules to the first component on each controller node.
7. A vehicle network security protection device, characterized in that: The device is applied to a vehicle and comprises: A deployment module is used to deploy the probe package in the vehicle; A protection module is used to detect network security events on the vehicle side based on the probe package, and upload the network security events to the vehicle side's vehicle management node, wherein the vehicle management node reports the network security events to the cloud platform, and the cloud platform determines the target operation according to the network security event, and sends the target operation to the vehicle side to realize closed-loop management.
8. A vehicle network security protection device, characterized in that: The device is applied to a cloud platform and includes: A receiving module is used to receive network security events reported by the vehicle management node on the vehicle side; A management module is used to determine a target operation based on the network security event and send the target operation to the vehicle end to realize closed-loop management.
9. A vehicle, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the vehicle network security protection method as described in any one of claims 1 to 4.
10. A cloud platform, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the vehicle network security protection method as described in claim 5 or 6.