Method and system for carrying out automobile information safety protection based on artificial intelligence AI
Through artificial intelligence-based methods, real-time collection and analysis of automotive information and generation of dynamic protection strategies, it solves the problem that traditional automotive information security protection technology is difficult to cope with complex attacks and dynamic threats, and achieves efficient and flexible automotive information security protection.
Patent Information
- Application Number
- CN202510140440.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2025-06-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing automotive information security protection technologies are difficult to detect and respond to security threats from complex attack methods and dynamic changes in real time, and traditional protective measures have limitations in protection depth and response speed, and there are protection blind spots.
Using an artificial intelligence-based method, by obtaining automotive information (such as network traffic, ECU status and sensor data), building a risk assessment function, calculating risk scores, generating dynamic protection strategies, executing protection measures, and optimizing the security protection process based on the protection effect.
It realizes multi-dimensional real-time data collection and preprocessing of automotive information systems, quickly detects potential security threats, responds in real time and implements protective measures, improves the security and stability of automotive information systems, and can effectively deal with complex network security threats.
Smart Images

Figure CN120105573A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to but is not limited to the field of data processing technology, and in particular to a method and system for automobile information security protection based on artificial intelligence (AI). Background Art
[0002] With the continuous development of automobile intelligence, automotive electronic systems have gradually become an important part of modern automobiles. These systems include in-vehicle entertainment systems, autonomous driving systems, vehicle-to-everything (V2X) communication systems, etc. They interact with the external environment through the Internet, thereby improving the functionality and user experience of the car. In order to ensure the security of automobile information, existing practices mainly rely on traditional network security protection technologies such as firewalls, encryption technology, intrusion detection systems (IDS), vulnerability scanning, etc. These technologies prevent malicious attacks, data leakage, and information tampering by monitoring and protecting the electronic control unit (ECU), vehicle network, and communication interface of the car.
[0003] However, existing practices are often limited to static rules and pattern recognition, and cannot effectively respond to increasingly complex attack methods and dynamically changing security threats. As attackers' attack methods continue to evolve and automotive information systems become increasingly complex, traditional protection methods are difficult to discover and respond to unknown security vulnerabilities in real time. At the same time, traditional security protection measures are often limited in protection depth and response speed, making it difficult to achieve rapid detection and automated response, which may lead to security risks when attacks occur. In addition, with the high degree of interconnection of automotive systems, existing protection mechanisms often cannot fully cover all interfaces and communication channels, and there are blind spots in protection. Summary of the invention
[0004] In view of this, the embodiment of the present application at least provides a method and system for automobile information security protection based on artificial intelligence AI. The technical solution of the embodiment of the present application is implemented as follows:
[0005] On the one hand, the embodiment of the present application provides a method for automobile information security protection based on artificial intelligence AI, including:
[0006] Acquire vehicle information and construct features of the vehicle information; the vehicle information at least includes network traffic, ECU status, and sensor data;
[0007] Constructing a risk assessment function, and calculating a risk score of the vehicle information according to the risk assessment function;
[0008] generating a dynamic protection strategy for the automobile information according to the risk score of the automobile information;
[0009] Executing protection measures corresponding to the dynamic protection strategy on the automobile information;
[0010] The protective effect of the protective measures is evaluated and feedback is given, and the security protection process for the automobile information is optimized based on the protective effect.
[0011] In some embodiments, constructing a risk assessment function comprises:
[0012] Obtaining a feature weight, a dynamic adjustment coefficient, an attenuation factor, and a historical abnormal record for each of the features;
[0013] Acquire a first balancing parameter for adjusting the overall risk of the feature, and a second balancing parameter for adjusting the historical abnormal record;
[0014] The risk assessment function is constructed according to the number of feature dimensions of the feature, the feature weight, dynamic adjustment coefficient, attenuation factor and historical abnormality record of each feature, as well as the first balance parameter and the second balance parameter.
[0015] In some embodiments, the risk assessment function is expressed as:
[0016]
[0017] Among them, RiskScore is the risk assessment function, ω i is the feature weight of the i-th feature, θ i is the dynamic adjustment coefficient of the i-th feature, λ i is the attenuation factor of the i-th feature, y i is the historical anomaly record of the i-th feature, α is the first balance parameter, β is the second balance parameter, and n is the number of feature dimensions.
[0018] In some embodiments, the method further comprises:
[0019] Constructing a multi-layer neural network for detecting anomalies in the automobile information;
[0020] Performing anomaly detection on the features of the automobile information according to the activation function of the multi-layer neural network to obtain a corresponding anomaly score;
[0021] Abnormal automobile information is determined according to the abnormality score.
[0022] In some embodiments, the activation function of the multi-layer neural network is expressed as:
[0023]
[0024] Among them, ActivFunc(z) is the activation function of the multi-layer neural network, tanh(z) is the hyperbolic tangent function, σ(z) is the sigmoid function, arc tanh(z) is the inverse hyperbolic tangent function, and z is the input value of the neural network.
[0025] In some embodiments, generating a dynamic protection strategy for the vehicle information according to the risk score of the vehicle information includes:
[0026] Determining a strategy factor and a threat level for each of the features based on the risk assessment and anomaly score of each of the features;
[0027] Obtaining a load adjustment parameter for adjusting the relationship between network protection strength and system load;
[0028] The protection response strength to the vehicle information is determined according to the strategy factor and threat level of each feature and the load adjustment parameter to generate the dynamic protection strategy.
[0029] In some embodiments, the evaluating and providing feedback on the protective effect of the protective measures includes:
[0030] Obtaining a time weight, a protection response time, a threat weight, and a threat level for each of the features;
[0031] Obtain the system performance impact factor for adjusting the protection effect;
[0032] According to the time weight, protection response time, threat weight and threat level of each feature, and the system performance influencing factor, the protection effectiveness score of the protection measure is determined, so as to evaluate and provide feedback on the protection effectiveness of the protection measure according to the protection effectiveness score.
[0033] In some embodiments, the protective measures include at least: network traffic control, interface access restriction, system resource isolation and emergency response triggering of the vehicle information.
[0034] In some embodiments, the method for optimizing the security protection process for the automobile information includes at least: adjusting the weight of each of the features, updating the parameters of the risk assessment function, optimizing the parameters of the protection response strength algorithm, and changing the anomaly detection threshold for anomaly detection of the features.
[0035] On the other hand, the present application provides a computer system, including a memory and a processor, wherein the memory stores a computer program executable on the processor, and the processor implements the steps in the above method when executing the program.
[0036] The beneficial effects of this application include at least:
[0037] This application can detect potential security threats at the first time through real-time collection and preprocessing of multi-dimensional data of the automobile system (such as network traffic, ECU status, sensor data, etc.). At the same time, based on the deep learning anomaly detection model, it can quickly discover abnormal behaviors in the system, respond in real time and implement protective measures to ensure that the vehicle system can respond quickly when attacked and avoid the expansion and spread of security incidents. This real-time dynamic protection mechanism can effectively respond to increasingly complex network security threats and ensure the security and stability of automobile information systems.
[0038] This application provides an efficient, flexible and comprehensive automobile information security protection solution by combining artificial intelligence technology with deep learning. Through the application of key technologies such as real-time data collection, intelligent risk assessment, dynamic protection response, and adaptive learning, it can achieve efficient security protection, system optimization and threat detection, and significantly improve the security, response speed and protection capabilities of automobile information systems in the face of various network attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The drawings herein are incorporated into the specification and constitute a part of the specification. These drawings illustrate embodiments consistent with the present application and are used together with the specification to illustrate the technical solution of the present application.
[0040] Figure 1 A schematic diagram of the implementation flow of a method for protecting automobile information security based on artificial intelligence (AI) provided in an embodiment of the present application.
[0041] Figure 2 A hardware entity diagram of a computer system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0042] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application is further elaborated in detail below in conjunction with the accompanying drawings and embodiments. The described embodiments should not be regarded as limiting the present application. All other embodiments obtained by ordinary technicians in this field without making creative work belong to the scope of protection of the present application. In the following description, "some embodiments" are involved, which describe a subset of all possible embodiments, but it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict. The terms "first / second / third" involved are only used to distinguish similar objects and do not represent a specific order for the objects. It can be understood that "first / second / third" can be interchanged with a specific order or sequence where permitted, so that the embodiments of the present application described here can be implemented in an order other than that illustrated or described here.
[0043] The embodiment of the present application provides a method for automobile information security protection based on artificial intelligence (AI), which can be executed by a processor of a computer system. The computer system can refer to a device with data processing capabilities such as a server, a laptop, a tablet computer, and a desktop computer.
[0044] Figure 1 A schematic diagram of the implementation process of a method for protecting automobile information security based on artificial intelligence AI provided in an embodiment of the present application is shown in FIG. Figure 1 As shown, the method includes:
[0045] Step S10: Acquire automobile information and construct features of the automobile information.
[0046] Among them, automobile information includes at least network traffic, ECU status and sensor data.
[0047] Among them, network traffic refers to the communication data traffic between various electronic control units (ECUs) inside the car. For example, various modules in the car (such as engine control, braking system, in-vehicle entertainment system, etc.) will exchange data through the in-vehicle network (such as CAN bus). Network traffic data can provide information about the communication frequency, data transmission rate and communication content between systems, thereby helping to identify potential faults or performance issues.
[0048] Among them, ECU (Electronic Control Unit) is a microprocessor system that controls various functions in modern cars. Obtaining ECU status means collecting the working status information of different ECUs, including whether each ECU is working properly, fault codes, system load, error detection information, etc. ECU status data is crucial for diagnosing the health of the car system.
[0049] Among them, sensor data refers to the large number of sensors that modern cars are equipped with to monitor and collect vehicle status information, such as speed sensors, temperature sensors, pressure sensors, acceleration sensors, oxygen sensors, etc. Sensor data can reflect the vehicle's operating status, environmental conditions, driving behavior, etc. These data are very important for optimizing vehicle performance and ensuring safety.
[0050] In some embodiments, the health status of the network, abnormal behavior of data communication, and other information can be extracted by analyzing the transmission rate, communication frequency, data packet size, and other indicators of network traffic data. For example, if the communication frequency between an ECU and other modules increases abnormally, it may indicate that the ECU is faulty.
[0051] In some embodiments, information such as whether there is a fault, the type of error code, and workload can be extracted from the ECU's status data. These features help evaluate the operating status of various electronic systems in the vehicle and identify potential problems early.
[0052] In some embodiments, sensor data features can perform statistical analysis or time series analysis on sensor data to extract features such as acceleration changes, temperature fluctuation range, oil pressure, vehicle speed, etc. These features help evaluate the dynamic performance of the vehicle, driving behavior, etc. For example, abnormal oil pressure or engine temperature may indicate a problem with the system.
[0053] In summary, this application collects data from different systems and sensors of the car to extract key features that can describe the vehicle status, behavior and performance. These features can be used for subsequent data analysis, fault detection, performance optimization and other applications.
[0054] Step S20: constructing a risk assessment function, and calculating the risk score of the automobile information according to the risk assessment function.
[0055] In some embodiments, step S20 may include:
[0056] Obtaining a feature weight, a dynamic adjustment coefficient, an attenuation factor, and a historical abnormal record for each of the features;
[0057] Acquire a first balancing parameter for adjusting the overall risk of the feature, and a second balancing parameter for adjusting the historical abnormal record;
[0058] The risk assessment function is constructed according to the number of feature dimensions of the feature, the feature weight, dynamic adjustment coefficient, attenuation factor and historical abnormality record of each feature, as well as the first balance parameter and the second balance parameter.
[0059] In some embodiments, the risk assessment function may be expressed as:
[0060]
[0061] Among them, RiskScore is the risk assessment function, ω i is the feature weight of the i-th feature, θ i is the dynamic adjustment coefficient of the i-th feature, λ i is the attenuation factor of the i-th feature, y i is the historical anomaly record of the i-th feature, α is the first balance parameter, β is the second balance parameter, and n is the number of feature dimensions.
[0062] In the specific implementation, RiskScore is a risk assessment function used to solve the overall risk score, which is a quantitative assessment of the current risk status of the system. The score is dynamically adjusted based on the data characteristics and historical behaviors of each feature dimension, reflecting the security status of the vehicle information system when it is potentially threatened.
[0063] ω i is the feature weight of the ith feature, which is usually used to indicate the degree of influence of the feature on the overall risk assessment. The larger the weight value, the greater the contribution of the feature to the risk score. By adjusting the weight of the feature, the importance of certain key features in risk assessment can be emphasized. For example, if the anomaly of network traffic affects car safety more than other sensor data, then the corresponding ω i The weight should be greater.
[0064] θ i is the dynamic adjustment coefficient of the ith feature, which is used to reflect the influence of the ith feature in the current system state. This coefficient may be dynamically updated based on real-time data or historical data. The role of the dynamic adjustment coefficient is to flexibly adjust the risk contribution of each feature based on factors such as system status, attack detection, and historical performance. For example, if the system detects an abnormal performance of a feature (such as a high value of a temperature sensor), then the θ of the feature i The coefficient may be increased, thereby increasing its weight in the risk assessment.
[0065] λ i is the attenuation factor of the i-th feature, which is usually used to control the attenuation speed of the impact of historical data in risk assessment. i The larger the attenuation factor, the smaller the impact of historical data on the current risk assessment. The attenuation factor is used to reduce the impact of long-standing historical abnormal records on the current system risk assessment. As time goes by, the impact of certain historical events should gradually weaken, so λ i The decay rate is controlled. For example, a small-scale fault experienced by a vehicle system may have a small impact on the risk assessment of the current system.
[0066] y i is the historical anomaly record of the ith feature, indicating the number or degree of anomalies of feature i in the past. Historical anomaly records can be failures, attacks, or other abnormal behaviors. Historical anomaly records can reflect whether the feature has had anomalies in the past and the severity of the anomalies. For example, if a sensor has failed or failed many times, then the y of the feature i A higher value indicates that the risk of the feature encountering anomalies in the future is also higher, thus increasing the weight of the feature in risk assessment.
[0067] α is the first balancing parameter, which is used to adjust the overall weight of the risk score. It mainly controls the weight distribution of the two parts in the formula, and determines the contribution of the first part (the part based on the feature weight and the dynamic adjustment coefficient) to the final risk score. α controls the impact of the risk assessment part of the feature dimension on the total risk score. Appropriate adjustment of α can make the system pay more attention to the risk of the feature dimension, or make the system consider all factors more balanced. By adjusting this value, the system can dynamically optimize the sensitivity of the risk score.
[0068] β is the second balancing parameter, which is used to adjust the weight of the historical anomaly record part in the formula. It controls the impact of the second part (the part based on historical anomaly records) on the risk score. The size of the β parameter determines the degree of influence of historical data on the current risk assessment. If β is large, the impact of historical anomaly records is strong, indicating that the system is more inclined to consider past events when assessing risks. If β is small, the impact of historical anomaly records is relatively weak, and the system relies more on current real-time data.
[0069] n is the number of feature dimensions, which indicates the number of features in the input data. Each feature may represent a different parameter or data source (e.g., network traffic, sensor data, ECU status, etc.). The number of feature dimensions n is used to adjust the risk score to a uniform measure. By performing a weighted sum and product calculation on all features and then performing an nth root process, it ensures that the number of different feature dimensions does not have an excessive impact on the final risk score.
[0070] The risk assessment function is equivalent to a risk assessment model that integrates multiple factors. It aims to evaluate the real-time data and historical abnormal records of various dimensions of the automotive system and calculate a comprehensive score that reflects the current system risk level. Through flexible balancing parameters and dynamic adjustment coefficients, the weight and impact of each feature can be adjusted according to the current system status and historical performance to ensure the accuracy of risk assessment.
[0071] Specifically, the first part α∑(ω i ×θ i ×log(1+θ i ))The impact of each feature on risk is evaluated through feature weights, dynamic coefficients, and logarithmic transformation. Part II Based on historical anomaly records and attenuation factors, the impact of historical data on risk assessment is further quantified. The risk assessment model of this risk assessment function can adapt to different environments and threat conditions through a flexible adjustment mechanism, timely discover potential security risks, provide accurate risk assessment support, and provide a basis for the subsequent generation of dynamic protection strategies.
[0072] In some embodiments, the method of the present application may further include:
[0073] Constructing a multi-layer neural network for detecting anomalies in the automobile information;
[0074] Performing anomaly detection on the features of the automobile information according to the activation function of the multi-layer neural network to obtain a corresponding anomaly score;
[0075] Abnormal automobile information is determined according to the abnormality score.
[0076] In some embodiments, the activation function of the multi-layer neural network is expressed as:
[0077]
[0078] Among them, ActivFunc(z) is the activation function of the multi-layer neural network, tanh(z) is the hyperbolic tangent function, σ(z) is the sigmoid function, arc tanh(z) is the inverse hyperbolic tangent function, and z is the input value of the neural network.
[0079] Among them, ActivFunc(z) is the activation function of the multi-layer neural network. Tanh(z) is the hyperbolic tangent function. The output range of the hyperbolic tangent function is (-1,1), which is often used as an activation function in neural networks. Its characteristic is to smoothly compress the input value so that the output value is between -1 and 1. The hyperbolic tangent function can enhance the nonlinear fitting ability of the neural network to the input data. The output range is fixed at (-1,1), which can make the training of the neural network more stable because it will not allow the output value to increase or decrease infinitely. Standardizing the input data helps to speed up the training process. When the input value is large or small, the gradient will be very small, which may lead to the gradient disappearance problem.
[0080] σ(z) is the sigmoid function, and its output range is (0,1). It compresses the input value to between 0 and 1, and is often used in probability calculation and binary classification tasks. The characteristic of the Sigmoid function is that for positive input, its output is close to 1, and for negative input, its output is close to 0. It is very suitable for model output representation probability or binary classification tasks, because its value range is between 0 and 1 and can be directly used for probability interpretation. The Sigmoid function also encounters the problem of gradient disappearance, especially when the input value is very large or very small, the gradient will become very small, thus affecting the training effect.
[0081] Arc tanh(z) is the inverse hyperbolic tangent function, which is the inverse function of the hyperbolic tangent function and is used to map the input value back to an original range. The input value is scaled to between -1 and 1 to fit within the domain of the inverse hyperbolic tangent function. The inverse hyperbolic tangent function performs a nonlinear transformation on the input z so that the output value falls within arrive It has a strong compression effect and helps to eliminate excessive differences in input data. Compared with the hyperbolic tangent function and the sigmoid function, the inverse hyperbolic tangent function has a wider asymptotic limit and can provide richer changes, which is particularly suitable for nonlinear relationship modeling. The calculation process involves logarithmic operations and may be more complicated than the hyperbolic tangent function and the sigmoid function.
[0082] z is the input value of the neural network. It is the input value of a certain layer in the neural network. It is usually the result of the weighted sum of the previous layer plus the bias. After the activation function, it becomes the output value of the layer. As an input value, z determines how the neural network calculates and learns at each layer. Through appropriate activation function processing, the neural network can learn features from these inputs and make accurate predictions.
[0083] 1-e -|z| This is an exponential decay term, which means that the absolute value of z is decayed. -|z| Represents the exponential decay of |z|. Subtracting this term means that as the input increases, the decay effect becomes stronger. The role of this decay term is to scale the response of the activation function. Especially when the input value z is large, the decay effect is significant and can suppress excessive responses. This term can effectively suppress the impact of excessive input values, reduce overreaction to extreme inputs, and prevent the neural network from outputting inappropriate results when faced with extreme data. In some cases, excessive decay may limit the sensitivity of the neural network to certain specific patterns.
[0084] In summary, the present application uses different combinations of nonlinear functions, and the activation function can help the neural network better capture the complex patterns of the input data. It helps to limit the excessive impact of large input values on the output, avoid abnormally large or small values output by the activation function, and enhance the stability of the model. Combined with the hyperbolic tangent, sigmoid and inverse hyperbolic tangent functions, the activation function can adapt to the needs of different types of data, such as smoothing of extreme values and probabilistic output. This custom activation function enables the neural network to show higher robustness and stronger nonlinear modeling capabilities when facing changeable and complex data, which helps to improve the performance and effect of the neural network in practical applications.
[0085] Step S30: generating a dynamic protection strategy for the automobile information according to the risk score of the automobile information.
[0086] In some embodiments, step S30 may include:
[0087] Determining a strategy factor and a threat level for each of the features based on the risk assessment and anomaly score of each of the features;
[0088] Obtaining a load adjustment parameter for adjusting the relationship between network protection strength and system load;
[0089] The protection response strength to the vehicle information is determined according to the strategy factor and threat level of each feature and the load adjustment parameter to generate the dynamic protection strategy.
[0090] In some embodiments, the protection response strength may include:
[0091]
[0092] Among them, Response is the protection response strength, which is the final execution strength of the protection measures and determines the strength of the protection actions taken by the system.
[0093] μ i is the strategy factor of the ith feature, indicating the strength of the protection strategy associated with the ith feature.
[0094] RiskScore i It is the risk score of the i-th feature, which reflects the size of the security risk corresponding to the feature and is usually calculated through a risk assessment model.
[0095] v i It is the threat level of the i-th feature, indicating the threat intensity of the feature. Generally, the higher the threat level, the greater the security threat faced by the feature.
[0096] w is a load adjustment parameter, which is used to adjust the relationship between the protection response strength and the system load to avoid excessive protection measures leading to system overload.
[0097] μ i The policy factor of the ith feature, which reflects the policy strength that should be given in the protection response based on the importance or characteristics of the feature. This factor can be a constant, or dynamically calculated based on external factors (such as system configuration, resource requirements, etc.). The role is to weight the protection strategy so that the protection response strength of different features varies according to their corresponding policy factors. For example, some features may pose a higher security threat than other features, and therefore require a stronger protection response.
[0098] RiskScore i It is usually calculated through a predefined risk assessment function (such as RiskScore in this solution), reflecting the possible risk of the feature. The higher the risk score, the greater the security risk of the feature. It is used to measure the potential risk of the system on a specific feature. Features with high risk scores indicate that this part of the system may be under greater threat of attack or abnormal behavior, so more protection measures are needed.
[0099] v i It is usually determined by analyzing multi-dimensional data such as network traffic, sensor data, and historical anomaly records. The higher the threat level, the greater the severity of the attack or anomaly event faced by the feature. The threat level has a direct impact on the strength of the protection response. In the formula, the role of the threat level is expressed by The exponential decay function of is used to model the threat level, so that features with high threat levels will have a stronger inhibitory effect on the protection response. In other words, the higher the threat level, the weaker the protection response, because the system needs to balance the protection strength and system load.
[0100] μ i ×RiskScore i It is the activation part of the protection response, indicating that the strength of the protection response varies with the risk score and strategy factor of the feature. The higher the risk score of the feature or the larger the strategy factor, the stronger the protection response.
[0101] is an exponential decay term, which suppresses the protection response of the threat level by exponentially decaying the threat level. i The higher it is, the greater the value of this term is, thus reducing the strength of the protection response. Exponential decay function The role of is to suppress features with greater threats, ensuring that the system does not overreact to features with high threat levels. The final result is that the higher the risk score of the feature, the stronger the strategy factor, but when the threat level is higher, the strength of the protection response is suppressed. This balance ensures that the system can ensure security during the protection process while avoiding the load caused by excessive protection.
[0102] The max(0,min(1,·)) part ensures that the value of the protection response strength is always between 0 and 1. The value range of the protection response is limited to [0,1], which can avoid excessive protection response caused by system resource consumption. max(0,·) ensures that the response value is not negative; min(1,·) ensures that the response value does not exceed 1. This operation is to limit the protection response strength to a reasonable range, which cannot be negative (that is, no protection) or exceed 1 (that is, the protection strength is too high). This limitation can ensure that the protection system does not exceed the system's carrying capacity when working.
[0103] w is a system load adjustment parameter used to adjust the load of the system when executing the protection response. It can be adjusted dynamically according to the current state of the system, load conditions or resource availability. The role is to adjust the strength of the protection response according to the actual load of the system. If the system load is high, the value of w can be adjusted to a lower value to reduce the burden on the system. Conversely, when the system load is low, the strength of the protection response can be increased to improve the protection capability.
[0104] In summary, this application dynamically calculates the strength of the protection response by comprehensively considering multiple factors such as the risk score, threat level, and strategy factor of the feature. Through exponential decay and weighted strategies, it ensures that the protection response can effectively respond to high-risk and high-threat situations while avoiding the problem of excessive system load caused by excessive protection. This method can achieve more accurate and efficient dynamic protection and ensure the security and stability of the system.
[0105] Step S40: executing protection measures corresponding to the dynamic protection strategy on the automobile information.
[0106] In some embodiments, the protective measures may at least include: network traffic control, interface access restriction, system resource isolation and emergency response triggering of the vehicle information.
[0107] Specifically, corresponding protection measures can be implemented according to the solved protection response strength. Network traffic control refers to the management and monitoring of internal vehicle network communications to ensure that the vehicle network (such as CAN bus, Ethernet, etc.) is not occupied by malicious traffic or abnormal data traffic. Protection measures may include: limiting the rate of data transmission to prevent network congestion or denial of service attacks (DoS). Prevent unauthorized devices or systems from accessing the vehicle network. Analyze and identify abnormal traffic patterns (such as abnormal ECU communication), and intercept or alarm suspicious traffic.
[0108] In some embodiments, interface access restriction refers to the control and management of access rights to various interfaces (such as diagnostic ports, communication interfaces, etc.) in the vehicle system. Protective measures may include: restricting access to certain interfaces, such as OBD-II ports, to authorized users or systems only. For certain interfaces, a dual authentication mechanism is used to ensure that only legitimate devices can connect and exchange data. Encryption, identity authentication and other means are used to prevent malicious use of interfaces and prevent external attackers from invading through physical interfaces.
[0109] System resource isolation refers to isolating the various systems and modules in the car to prevent the failure or attack of one system from affecting other systems. Protective measures may include: separating different ECUs and key systems (such as brake systems, engine control, in-car entertainment systems, etc.) in independent virtual environments or subsystems, so that the compromise of one system will not affect the normal operation of other systems. Limiting resource sharing between systems, such as memory, processors, etc., to prevent malicious code from spreading in the system.
[0110] Emergency response triggering means that when the car information detects a potential threat or anomaly, the system can automatically initiate the corresponding emergency response measures. These measures can include: automatically entering protection mode, such as shutting down certain affected modules, or switching the vehicle to low power mode. Activating the alarm system to alert the owner, vehicle manufacturer or security monitoring center to notify relevant personnel to take action. Triggering the remote diagnosis function to perform fault analysis and repair through the remote control system.
[0111] The core goal of the protection measures of this application is to ensure the normal operation, data integrity and user safety of the vehicle information system by implementing dynamic protection strategies to timely identify and respond to potential security risks. In different situations (such as attacks, network failures, system anomalies, etc.), these protection measures can be automatically adjusted and executed to maximize the safety of the vehicle and the owner.
[0112] Step S50: Evaluate and provide feedback on the protection effect of the protection measures, and optimize the security protection process for the automobile information based on the protection effect.
[0113] In some embodiments, step S50 may include:
[0114] Obtaining a time weight, a protection response time, a threat weight, and a threat level for each of the features;
[0115] Obtain the system performance impact factor for adjusting the protection effect;
[0116] According to the time weight, protection response time, threat weight and threat level of each feature, and the system performance influencing factor, the protection effectiveness score of the protection measure is determined, so as to evaluate and provide feedback on the protection effectiveness of the protection measure according to the protection effectiveness score.
[0117] In some embodiments, the protection effect score can be expressed as:
[0118]
[0119] Among them, DefenseScore is the protection effect score, which is used to measure the overall effect of the protection mechanism, indicating the effectiveness of the protection measures and the degree of impact on the system. The higher the value, the better the protection effect.
[0120] k i is the time weight of the i-th feature, which measures the impact of the protection response time on the protection effect. The larger the time weight, the greater the impact of the protection response time of the feature on the overall protection effect.
[0121] ResponseTime iis the protection response time of the ith feature, which indicates the time taken to take protection measures for a specific feature. A shorter response time usually indicates a more efficient protection mechanism.
[0122] ρ i is the threat weight of the ith feature, reflecting the contribution of the threat level of the feature to the protection effect. The larger the threat weight, the more important the threat of the feature is, and the greater the impact on the protection effect.
[0123] ThreatLevel i is the threat level of the ith feature, indicating the intensity of the security threat faced by the feature. The higher the threat level, the greater the risk of the feature being attacked or subjected to abnormal events.
[0124] φ is a system performance influencing factor used to adjust the balance between protection effect and system performance. It is a constant or adjustable parameter to ensure that the protection effect score does not increase excessively when the system load is too high.
[0125] k i It is the time weight of the i-th feature, which is used to indicate the impact of the protection response time on the protection effect score. It can be adjusted according to the specific requirements of the system. The larger the weight, the more important the response time of the feature is to the protection effect. Protection response timeResponseTime i It is an important factor in evaluating the protection efficiency. A longer response time usually indicates that the efficiency of the protection measures is low, which affects the overall protection effect. i Weighting can more accurately reflect the impact of time factors on protection effectiveness.
[0126] ResponseTime i is the protection response time of the ith feature, which indicates the time required to implement protection measures for a specific feature. This value reflects the reaction speed of the protection system to the feature. Protection response time is an important indicator to measure the effectiveness and timeliness of the protection mechanism. The shorter the response time, the faster the system can respond to security threats and prevent the spread of attacks or abnormal behaviors, thereby improving the protection effect score. Therefore, the protection response time will be weighted in the protection effect score through a logarithmic function, and the shorter the response time, the greater the contribution to the score.
[0127] ρ i is the threat weight of the ith feature, indicating the relative importance of the threat of this feature relative to other features. The larger the threat weight, the more serious the threat faced by this feature, and the more protection is needed. The threat weight is used to perform a weighted assessment of the threats of different features. For features with higher threat levels, their threat weights should be larger so that they can be given higher weights in the protection effect score.
[0128] ThreatLevel i is the threat level of the ith feature, indicating the intensity of the security threat faced by the feature. The higher the threat level, the greater the risk of the feature being attacked or having abnormal behavior, and the system needs stronger protection measures to resist the threat. The threat level is a key factor in measuring system risk. Features with high threat levels require more protection response time and resources, so the threat level also contributes greatly to the protection effect score. The threat level affects the calculation of the protection effect score by multiplying it with the threat weight.
[0129] Specifically, ∑(k i ×log(1+ResponseTime i )) is the weighted sum of the protection response time, taking into account the impact of time factors on the protection effect. i ) compresses the response time to ensure that the score increases more when the protection response time is shorter, avoiding the negative impact of the long response time on the overall protection effect score. i ×ThreatLevel i It is a weighted sum of the threat levels, reflecting the combination of threat weight and threat level, reflecting the total amount of threats faced by the system. Features with higher threats will have a greater impact on the protection effectiveness score, ensuring that the priority of the protection response matches the threat level.
[0130] φ is the system performance impact factor, which is used to adjust the calculation of the protection effect score so that appropriate adjustments can be made when the system load is high to prevent excessive protection from adversely affecting system performance. During the implementation of protection measures, the system's resource usage may affect the protection effect. In order to balance the protection strength and system load, the protection effect score will be multiplied by the system performance impact factor φ to ensure the rationality of the score. When the system load is high, φ can adjust the protection effect score to prevent too many protection measures from affecting the normal operation of the system.
[0131] The present invention comprehensively measures the effectiveness of the protection mechanism by comprehensively considering factors such as protection response time, threat level and time weight. By logarithmically weighting the protection response time, shorter response times can contribute more to the score, while also avoiding the negative impact of protection measures that slow down the response time too much. The combination of threat weight and threat level ensures that protection measures give priority to more serious threats, and the system performance impact factor ensures a balance between protection effect and system resources to avoid system overload. Through this comprehensive scoring mechanism, the overall effect of the protection system can be evaluated, and the protection strategy can be further adjusted as needed.
[0132] In some embodiments, the method for optimizing the security protection process for automobile information includes at least: adjusting the weight of each feature, updating the parameters of the risk assessment function, optimizing the parameters of the protection response strength algorithm, and changing the anomaly detection threshold for anomaly detection of features.
[0133] In the specific implementation, when constructing the vehicle information features, each feature may have different influences on the safety protection decision. Adjusting the weight of each feature refers to the importance and reliability of different features.
[0134] For example, if the network traffic characteristics of a car are more critical to determining the risk of attack at a certain moment, the weight of the network traffic characteristics can be increased; if sensor data anomalies (such as speed, acceleration changes, etc.) are more important than ECU status, the influence of these sensor characteristics may need to be enhanced.
[0135] The weight adjustment can be achieved by analyzing historical data, attack patterns, vehicle behavior, etc., to ensure that the system can make the most appropriate decisions for different scenarios (such as normal driving, extreme conditions, attack moments, etc.).
[0136] The risk assessment function can be used to assess the security risk of the current system based on the collected information of various vehicles (such as network traffic, ECU status, sensor data, etc.). The optimization of the risk assessment function is to update the parameters in it so that the assessment results can more accurately reflect the degree of threat in reality.
[0137] For example, in some environments, the ECU status may better reflect the risk level of the vehicle than sensor data, or certain abnormal patterns (such as cyber attacks, sensor failures, etc.) may require the introduction of new parameters for evaluation.
[0138] Updating the parameters of the risk assessment function may include adjusting the contribution of different features to the overall risk score, or adding new risk factors (eg, external environment, vehicle history status, etc.).
[0139] The protection response strength algorithm determines the strength of the protection measures to be taken based on the risk assessment results. For example, when a serious threat is detected, the protection response should be high-intensity, while when the risk is lower, a lower-intensity protection measure can be used. The parameters of the optimization of the protection response strength algorithm are designed to make the protection measures both effective in responding to threats and not excessively interfering with normal driving.
[0140] Optimization methods can include adjusting response thresholds to determine when the protection response should be enhanced and when the response strength should be reduced. For example, if the risk assessment function shows that a certain ECU has a serious abnormality, it may be necessary to increase the system's protection response strength, such as limiting the access rights of the ECU, enabling emergency mode, etc.
[0141] In addition, the optimization of the protection response strength can also determine the response mode and strength according to the driving environment and the current operating state of the car (such as low-speed or high-speed driving).
[0142] Anomaly detection can be used to identify abnormal patterns in data (such as abnormal ECU behavior, sensor data fluctuations, etc.) and trigger corresponding protective measures. By adjusting the threshold of anomaly detection, the system can be made more sensitive or tolerant to different types of anomalies.
[0143] If the current detection threshold is too high, it may result in missed detection (i.e., failure to detect attacks or anomalies); if the threshold is too low, it may result in false positives (i.e., normal fluctuations are mistaken for attacks). Therefore, by optimizing the threshold, the accuracy of anomaly detection can be improved.
[0144] For example, for network traffic characteristics, stricter thresholds may be set in some cases (such as bursts of packet traffic) to deal with potential denial of service (DoS) attacks; while in other cases (such as high-speed driving), the thresholds can be appropriately relaxed to avoid overreaction to normal driving behavior.
[0145] Through these optimization methods, the security protection process of the automobile information system can be dynamically adjusted according to the actual situation, making the protection measures more accurate, flexible and efficient. Specific optimization methods include: adjusting the weight of features: allowing more important features to occupy a larger proportion in the decision-making process; updating the parameters of the risk assessment function: ensuring that the risk assessment can reflect the current state of the vehicle and changes in the external environment; optimizing the protection response strength algorithm: adjusting the strength of the protection response according to the risk level to avoid over-protection or under-protection; changing the anomaly detection threshold: improving the accuracy of anomaly detection and reducing false positives and false negatives.
[0146] Through these optimizations, the information security protection system of the car can better cope with various attacks and abnormal situations, thereby improving the safety and reliability of the car.
[0147] It should be noted that in the embodiment of the present application, if the above-mentioned method for automobile information security protection based on artificial intelligence AI is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the relevant technology can be embodied in the form of a software product, which is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory (ROM), a disk or an optical disk. In this way, the embodiment of the present application is not limited to any specific hardware, software or firmware, or any combination of hardware, software, and firmware.
[0148] An embodiment of the present application provides a computer system, including a memory and a processor, wherein the memory stores a computer program that can be executed on the processor, and when the processor executes the program, some or all of the steps in the above method are implemented.
[0149] The embodiment of the present application provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, some or all of the steps in the above method are implemented. The computer-readable storage medium can be transient or non-transient.
[0150] An embodiment of the present application provides a computer program, including a computer-readable code. When the computer-readable code is run in a computer device, a processor in the computer device executes some or all of the steps for implementing the above method.
[0151] The embodiment of the present application provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and when the computer program is read and executed by a computer, some or all of the steps in the above method are implemented. The computer program product can be implemented specifically by hardware, software or a combination thereof. In some embodiments, the computer program product is specifically embodied as a computer storage medium, and in other embodiments, the computer program product is specifically embodied as a software product, such as a software development kit (SDK) and the like.
[0152] It should be noted here that the description of the various embodiments above tends to emphasize the differences between the various embodiments, and the same or similar aspects can be referenced to each other. The description of the above device, storage medium, computer program and computer program product embodiments is similar to the description of the above method embodiment, and has similar beneficial effects as the method embodiment. For technical details not disclosed in the embodiments of the device, storage medium, computer program and computer program product of this application, please refer to the description of the method embodiment of this application for understanding.
[0153] Figure 2 A hardware entity diagram of a computer system provided in an embodiment of the present application is shown in FIG. Figure 2 As shown, the hardware entity of the computer system 1000 includes: a processor 1001 and a memory 1002, wherein the memory 1002 stores a computer program that can be run on the processor 1001, and the processor 1001 implements the steps in the method of any of the above embodiments when executing the program.
[0154] The memory 1002 stores computer programs that can be run on the processor. The memory 1002 is configured to store instructions and applications executable by the processor 1001. It can also cache data to be processed or processed by the processor 1001 and various modules in the computer system 1000 (for example, image data, audio data, voice communication data, and video communication data). This can be achieved through flash memory (FLASH) or random access memory (Random Access Memory, RAM).
[0155] When the processor 1001 executes the program, the steps of any of the above-mentioned methods for protecting automobile information security based on artificial intelligence AI are implemented. The processor 1001 generally controls the overall operation of the computer system 1000.
[0156] An embodiment of the present application provides a computer storage medium, which stores one or more programs. The one or more programs can be executed by one or more processors to implement the steps of the method for protecting automobile information security based on artificial intelligence AI as in any of the above embodiments.
[0157] It should be noted here that the description of the above storage medium and device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects as the method embodiments. For the technical details not disclosed in the storage medium and device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding. The above processor can be at least one of a target application integrated circuit (Application Specific Integrated Circuit, ASIC), a digital signal processor (Digital Signal Processor, DSP), a digital signal processing device (Digital Signal Processing Device, DSPD), a programmable logic device (Programmable Logic Device, PLD), a field programmable gate array (Field Programmable Gate Array, FPGA), a central processing unit (Central Processing Unit, CPU), a controller, a microcontroller, and a microprocessor. It can be understood that the electronic device that realizes the above processor function can also be other, and the embodiments of the present application are not specifically limited.
[0158] The above-mentioned computer storage medium / memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory (Flash Memory), a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM) and the like; it can also be various terminals including one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.
[0159] It should be understood that the "one embodiment" or "one embodiment" mentioned throughout the specification indicates that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in one embodiment" appearing in various places throughout the specification may not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the size of the sequence number of each step / process above does not indicate the order of execution, and the execution order of each step / process should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiment of the present application. The above-mentioned sequence number of the embodiment of the present application is only for description and does not represent the advantages and disadvantages of the embodiment. It should be noted that, in this article, the term "include", "comprise" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements includes not only those elements, but also includes other elements that are not explicitly listed, or also includes elements inherent to such process, method, article or device. Without more constraints, an element defined by the phrase "comprising a..." does not exclude the existence of other identical elements in the process, method, article or apparatus comprising the element.
[0160] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.
[0161] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units; they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0162] In addition, all functional units in the embodiments of the present application may be integrated into one processing unit, or each unit may be a separate unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.
[0163] A person skilled in the art can understand that all or part of the steps of implementing the above method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above method embodiment; and the aforementioned storage medium includes: mobile storage devices, read-only memories (ROM), magnetic disks or optical disks, etc., various media that can store program codes.
[0164] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can essentially or in other words, the part that contributes to the relevant technology can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROMs, magnetic disks, or optical disks.
[0165] The above is only an implementation method of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application.
Claims
1. A method for automobile information security protection based on artificial intelligence AI, characterized in that: include: Acquire vehicle information and construct features of the vehicle information; the vehicle information at least includes network traffic, ECU status, and sensor data; Constructing a risk assessment function, and calculating a risk score of the vehicle information according to the risk assessment function; generating a dynamic protection strategy for the automobile information according to the risk score of the automobile information; Executing protection measures corresponding to the dynamic protection strategy on the automobile information; The protective effect of the protective measures is evaluated and feedback is given, and the security protection process for the automobile information is optimized based on the protective effect.
2. The method according to claim 1, characterized in that The step of constructing a risk assessment function comprises: Obtaining a feature weight, a dynamic adjustment coefficient, an attenuation factor, and a historical abnormal record for each of the features; Acquire a first balancing parameter for adjusting the overall risk of the feature, and a second balancing parameter for adjusting the historical abnormal record; The risk assessment function is constructed according to the number of feature dimensions of the feature, the feature weight, dynamic adjustment coefficient, attenuation factor and historical abnormality record of each feature, as well as the first balance parameter and the second balance parameter.
3. The method according to claim 2, characterized in that The risk assessment function is expressed as: Among them, RiskScore is the risk assessment function, ω i is the feature weight of the i-th feature, θ i is the dynamic adjustment coefficient of the i-th feature, λ i is the attenuation factor of the i-th feature, y i is the historical anomaly record of the i-th feature, α is the first balance parameter, β is the second balance parameter, and n is the number of feature dimensions.
4. The method according to claim 3, characterized in that The method further comprises: Constructing a multi-layer neural network for detecting anomalies in the automobile information; Performing anomaly detection on the features of the automobile information according to the activation function of the multi-layer neural network to obtain a corresponding anomaly score; Abnormal automobile information is determined according to the abnormality score.
5. The method according to claim 4, characterized in that The activation function of the multi-layer neural network is expressed as: Among them, ActivFunc(z) is the activation function of the multi-layer neural network, tanh(z) is the hyperbolic tangent function, σ(z) is the sigmoid function, arc tanh(z) is the inverse hyperbolic tangent function, and z is the input value of the neural network.
6. The method according to claim 5, characterized in that Generating a dynamic protection strategy for the automobile information according to the risk score of the automobile information includes: Determining a strategy factor and a threat level for each of the features based on the risk assessment and anomaly score of each of the features; Obtaining a load adjustment parameter for adjusting the relationship between network protection strength and system load; The protection response strength to the vehicle information is determined according to the strategy factor and threat level of each feature and the load adjustment parameter to generate the dynamic protection strategy.
7. The method according to claim 6, characterized in that The evaluation and feedback of the protective effect of the protective measures include: Obtaining a time weight, a protection response time, a threat weight, and a threat level for each of the features; Obtain the system performance impact factor for adjusting the protection effect; According to the time weight, protection response time, threat weight and threat level of each feature, and the system performance influencing factor, the protection effectiveness score of the protection measure is determined, so as to evaluate and provide feedback on the protection effectiveness of the protection measure according to the protection effectiveness score.
8. The method according to claim 7, characterized in that The protection measures at least include: network traffic control, interface access restriction, system resource isolation and emergency response triggering of the automobile information.
9. The method according to claim 8, characterized in that The method for optimizing the security protection process of the automobile information at least includes: adjusting the weight of each of the features, updating the parameters of the risk assessment function, optimizing the parameters of the protection response strength algorithm, and changing the anomaly detection threshold for anomaly detection of the features.
10. A computer system comprising a memory and a processor, wherein the memory stores a computer program executable on the processor, wherein: When the processor executes the program, the steps in the method according to any one of claims 1 to 9 are implemented.