A method and device for monitoring network data transmission

By monitoring the handshake times, message length and message header fields of the transmission control protocol connection and data packet operations, the vehicle network security problem in automobile intelligence is solved, hacker attacks are prevented, and data transmission security and system stability are ensured.

CN120110809BActive Publication Date: 2025-09-05CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510592115.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-09-05
Estimated Expiration
2045-05-09

AI Technical Summary

Technical Problem

As the level of intelligence of automobiles increases, vehicle network security issues become prominent, hackers have many means of attack, and existing technologies cannot effectively prevent illegal connections and data tampering, which affects the normal operation of vehicle systems.

Method used

By monitoring the number of handshakes in the Transmission Control Protocol connection establishment operation, the message length of the data packet operation and the message header field of the fragmented data packet, security protection measures are implemented to ensure that only three-way handshake protocol connections are established, and an alarm or connection termination is issued in case of illegal operations to prevent data fragmentation tampering.

Benefits of technology

Effectively prevent hackers from bypassing security checks, reduce security risks brought by malicious connections, ensure data transmission security, prevent data from being illegally fragmented or tampered with, and avoid vehicle network operations being affected by attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110809B_ABST
    Figure CN120110809B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a network data transmission monitoring method and device, which monitors the transmission control protocol connection establishment operation between the sending end and the receiving end, and executes security protection measures according to the number of handshakes of the connection establishment operation; then monitors the data subpacketization operation of the sending end, and executes security protection measures according to the original message length corresponding to the data subpacketization operation, and / or the message header field parameters of the original message; and then monitors the fragmented data packets sent by the sending end based on the data subpacketization operation, and executes security protection measures according to the message header fields of the sent fragmented data packets, and / or the number of sent fragmented data packets, so as to effectively prevent hackers from using non-standard connection methods to bypass traditional security checks, reduce the security risks brought by malicious connection establishment, enhance the security of data transmission, and prevent hackers from tampering with data message headers or carrying out malicious attacks through a large number of fragmented data packets.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and in particular to a method and device for monitoring network data transmission. Background Art

[0002] As vehicles rapidly advance toward intelligent driving, the complexity of the various electronic control units (ECUs) and communication networks integrated into vehicles continues to grow. ECUs in various vehicle domains communicate and exchange data via communication networks, thereby supporting features such as intelligent driving, in-vehicle infotainment, and vehicle dynamics control.

[0003] However, as the intelligence level of vehicle systems increases, the security issues of vehicle networks have become increasingly prominent, and hackers have more and more means to carry out network attacks. Many hacking methods can even bypass network firewalls, intrusion detection and defense, thereby stealing sensitive information in the vehicle or affecting the normal operation of the vehicle system. Summary of the Invention

[0004] In view of the above problems, a network data transmission monitoring method and apparatus are proposed to overcome the above problems or at least partially solve the above problems, including:

[0005] A network data transmission monitoring method, applied to a sending end, comprising:

[0006] monitoring a transmission control protocol connection establishment operation between the sending end and the receiving end, and executing a security protection measure according to the number of handshakes in the connection establishment operation;

[0007] Monitoring the data subpacketization operation of the sending end, and executing security protection measures according to the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message;

[0008] The fragmented data packets sent by the sending end based on the data packetization operation are monitored, and security protection measures are performed according to the message header fields of the sent fragmented data packets and / or the number of the sent fragmented data packets.

[0009] Optionally, executing security protection measures according to the number of handshakes of the connection establishment operation includes:

[0010] When the handshake protocol adopted by the connection establishment operation is not a three-way handshake protocol, an alarm is issued and a process processing program corresponding to the connection establishment operation is deleted.

[0011] Optionally, the executing security protection measures according to the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message includes:

[0012] When the length of the original message corresponding to the data subpackaging operation is less than a preset message length, and / or when the fragmentation prohibition flag bit in the Internet Protocol message header field of the original message corresponding to the data subpackaging operation is set to 1, an alarm is issued and the process processing program corresponding to the data subpackaging operation is deleted.

[0013] Optionally, performing security protection measures according to a header field of the fragmented data packet sent and / or the number of the fragmented data packets sent includes:

[0014] When the actual transmission data packet length of the sent fragmented data packet covers the transmission control protocol and / or internet protocol message header field, and the covered transmission control protocol and / or internet protocol message header field conflicts with the original transmission control protocol and / or internet protocol message header field, issuing an alarm and closing the transmission control protocol connection; and / or,

[0015] When the number of the fragmented data packets sent exceeds a preset threshold, an alarm is issued and data transmission is terminated.

[0016] A network data transmission monitoring method, applied to a receiving end, comprising:

[0017] monitoring a transmission control protocol connection establishment operation between a sending end and the receiving end, and executing security protection measures according to the number of handshakes in the connection establishment operation;

[0018] Receive fragmented data packets sent by the sending end based on the data subpacketization operation, and perform security protection measures according to the message header fields of the received fragmented data packets and / or the number of the received fragmented data packets; wherein the sending end is used to monitor the data subpacketization operation of the sending end, and perform security protection measures according to the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message.

[0019] Optionally, executing security protection measures according to the number of handshakes of the connection establishment operation includes:

[0020] When the handshake protocol adopted by the connection establishment operation is not a three-way handshake protocol, an alarm is issued and a process processing program corresponding to the connection establishment operation is deleted.

[0021] Optionally, the sending end is further used to issue an alarm and delete the process handler corresponding to the data subpackaging operation when the original message length corresponding to the data subpackaging operation is less than a preset message length, and / or when the fragmentation prohibition flag bit in the Internet Protocol message header field of the data subpackaging operation is set to 1.

[0022] Optionally, performing security protection measures based on a header field of the received fragmented data packet and / or the number of the received fragmented data packets includes:

[0023] When the actual transmission data message length of the received fragmented data packet covers the transmission control protocol and / or internet protocol message header, and the covered transmission control protocol and / or internet protocol message header conflicts with the original transmission control protocol and / or internet protocol message header, issuing an alarm and closing the transmission control protocol connection; and / or,

[0024] When the number of the received fragmented data packets exceeds a preset threshold, an alarm is issued and data transmission is terminated.

[0025] A network data transmission monitoring device based on the above-mentioned network data transmission monitoring method is applied to a sending end, and the device includes:

[0026] a first transmission control protocol connection monitoring module, configured to monitor a transmission control protocol connection establishment operation between the sending end and the receiving end, and execute security protection measures according to the number of handshakes in the connection establishment operation;

[0027] a data subpacketization operation monitoring module, configured to monitor the data subpacketization operation of the sending end and execute security protection measures based on the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message;

[0028] The first fragmented data packet monitoring module is used to monitor the fragmented data packets sent by the sending end based on the data segmentation operation, and to perform security protection measures according to the message header fields of the fragmented data packets sent and / or the number of the fragmented data packets sent.

[0029] A network data transmission monitoring device based on the above-mentioned network data transmission monitoring method is applied to a receiving end, and the device includes:

[0030] a second transmission control protocol connection monitoring module, configured to monitor the transmission control protocol connection establishment operation between the sending end and the receiving end, and execute security protection measures according to the number of handshakes in the connection establishment operation;

[0031] The second fragmented data packet monitoring module is used to receive fragmented data packets sent by the sending end based on the data subpacketization operation, and to perform security protection measures according to the message header fields of the received fragmented data packets and / or the number of the received fragmented data packets; wherein, the sending end is used to monitor the data subpacketization operation of the sending end, and to perform security protection measures according to the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message.

[0032] An electronic device includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program implements the network data transmission monitoring method described above when executed by the processor.

[0033] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the network data transmission monitoring method described above is implemented.

[0034] The embodiments of the present invention have the following advantages:

[0035] In an embodiment of the present invention, by monitoring the transmission control protocol connection establishment operation between the sending end and the receiving end, and executing security protection measures according to the number of handshakes of the connection establishment operation; then monitoring the data packetization operation of the sending end, and executing security protection measures according to the original message length corresponding to the data packetization operation, and / or the message header field parameters of the original message; and then monitoring the fragmented data packets sent by the sending end based on the data packetization operation, and executing security protection measures according to the message header fields of the fragmented data packets sent, and / or the number of fragmented data packets sent, the method effectively prevents hackers from using non-standard connection methods to bypass traditional security checks, reduces the security risks brought by malicious connection establishment, and ensures that the data packetization process is not used by hackers to bypass security checks, can prevent data from being illegally fragmented or maliciously tampered with, enhances the security of data transmission, and can ensure that each fragmented data packet in the transmission process complies with predetermined rules, prevents hackers from tampering with data message headers or using a large number of fragmented data packets to carry out malicious attacks, thereby minimizing the impact of hacker attacks on the normal operation of the vehicle system on the vehicle network. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the technical solution of the present invention, the following briefly introduces the drawings required for use in the description of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0037] Figure 1is a flowchart of the steps of a network data transmission monitoring method provided by some embodiments of the present invention;

[0038] Figure 2 This is a diagram of the vehicle electrical and electronic architecture provided by some embodiments of the present invention;

[0039] Figure 3 is a schematic diagram of a one-time handshake connection principle provided by some embodiments of the present invention;

[0040] Figure 4 is a schematic diagram of the two-way handshake connection principle provided by some embodiments of the present invention;

[0041] Figure 5 is a schematic diagram of the three-way handshake connection principle provided by some embodiments of the present invention;

[0042] Figure 6 is a data structure diagram of Ethernet provided by some embodiments of the present invention;

[0043] Figure 7 This is a schematic diagram of a normal network fragment (slice) data transmission process provided by some embodiments of the present invention;

[0044] Figure 8 This is another schematic diagram of a normal network fragment (slice) data transmission process provided by some embodiments of the present invention;

[0045] Figure 9 is a flowchart of the steps of another network data transmission monitoring method provided by some embodiments of the present invention;

[0046] Figure 10 is an example diagram of the configuration of the transmitting end and the receiving end modules provided in some embodiments of the present invention;

[0047] Figure 11 is a schematic structural diagram of a network data transmission monitoring device based on a network data transmission monitoring method provided by some embodiments of the present invention;

[0048] Figure 12 It is a structural diagram of another network data transmission monitoring device based on the network data transmission monitoring method provided by some embodiments of the present invention. DETAILED DESCRIPTION

[0049] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments described are only a portion of the embodiments of the present invention, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without inventive effort are also within the scope of protection of the present invention.

[0050] As vehicles rapidly advance toward intelligent capabilities, the complexity of the various electronic control units (ECUs) and communication networks integrated into vehicles continues to grow. ECUs in various vehicle domains communicate and exchange data via communication networks, thereby supporting features such as intelligent driving, in-vehicle infotainment, and vehicle dynamics control.

[0051] However, as the intelligence level of vehicle systems increases, the security issues of vehicle networks have become increasingly prominent, and hackers have more and more means to carry out network attacks. Many hacking methods can even bypass network firewalls, intrusion detection and defense, thereby stealing sensitive information in the vehicle or affecting the normal operation of the vehicle system.

[0052] In the embodiments of the present invention, based on the core technical concept of performing targeted monitoring of transmission control protocol connection establishment operations, data packetization operations, and fragmented data packets, the network data transmission monitoring method in the related art is improved. The present invention will be described in detail below with reference to the accompanying drawings:

[0053] Reference Figure 1 , shows a flowchart of a method for monitoring network data transmission provided by some embodiments of the present invention, which is applied to a sending end and may specifically include the following steps:

[0054] Step 101, monitoring the transmission control protocol connection establishment operation between the sending end and the receiving end, and executing security protection measures according to the number of handshakes in the connection establishment operation;

[0055] In the specific implementation, Figure 2The diagram below shows the vehicle's electrical and electronic architecture (EEA). It shows that the various ECUs within the vehicle's system architecture are connected via a CAN (Controller Area Network) bus or Ethernet bus for communication and signal exchange. The vehicle system exchanges data and information with the outside world via the CDC (Cockpit Domain Controller). The Vehicle Dynamics Control (VDC) integrates the control systems of major assemblies, including the vehicle's braking, drive, suspension, steering, and engine, both functionally and structurally. This ensures excellent directional stability and optimal driving performance in various harsh conditions, such as icy and snowy roads, split-roads, and curves, as well as during evasive maneuvers, lane changes, braking, acceleration, and downhill driving. The VIU is primarily responsible for collecting and processing body control signals (such as those for doors, windows, and lighting).

[0056] On this basis, in order to prevent the various domain ECU components in the vehicle system architecture from being attacked by hackers when they are connected through the CAN bus or Ethernet bus for communication message transmission and signal interaction, the Transmission Control Protocol (TCP) connection establishment operation between the sender and the receiver can be monitored when network data is transmitted between the various domain ECU components in the vehicle, and security protection measures can be implemented based on the number of handshakes in the connection establishment operation.

[0057] For example, you can pre-set the number of handshakes that should be taken when establishing a TCP connection, and execute corresponding security protection measures to ensure data transmission security when the number of handshakes taken for the connection establishment operation does not match the pre-set value.

[0058] In some embodiments of the present invention, executing security protection measures according to the number of handshakes of the connection establishment operation includes:

[0059] When the handshake protocol adopted by the connection establishment operation is not a three-way handshake protocol, an alarm is issued and a process processing program corresponding to the connection establishment operation is deleted.

[0060] In a specific implementation, when performing a Transmission Control Protocol connection, the connection establishment operation can generally use a no-handshake protocol (TCP virtual connection) connection and a one-time / two-time handshake protocol connection. However, the no-handshake protocol (TCP virtual connection) connection and the one-time / two-time handshake protocol connection cannot prevent the establishment of historical connections (hacker attacks can use this to initiate illegal connections), resulting in a waste of resources and unable to guarantee reliable synchronization of the sequence number transmission between the two parties.

[0061] For example, Figure 3 The following is a schematic diagram of the handshake connection principle: Figure 4 The figure shows the principle diagram of two-way handshake connection. Figure 3 As can be seen from the content, during a handshake connection, the client (sender) only needs to send a SYN (Synchronize, synchronization flag) message to the server (receiver) to establish a transmission control protocol connection; Figure 4 As can be seen in the following text, during a two-way handshake, the client sends a SYN packet to the server, and the server returns a SYN-ACK (Acknowledgment) packet to establish a Transmission Control Protocol connection. Neither method prevents the establishment of a previous connection nor guarantees sequence number synchronization between the two parties, which could affect subsequent data transmission.

[0062] On this basis, if Figure 5 The figure shows a schematic diagram of the three-way handshake connection principle adopted by the present invention. When the sender and receiver establish a Transmission Control Protocol connection based on the three-way handshake protocol, the client sends a SYN message (seq (Sequence Number) = x) to request connection establishment. This causes the client to enter the SYN_SENT (Synchronization Flag Message_Sent) state. The server then returns a SYN-ACK message: ack (Acknowledgement Number) = x + 1; seq = y (generating the server's initial sequence number). The server enters the SYN_RECEIVED (Synchronization Flag Message_Received) state. The client then sends an ACK message (ack = y + 1) to confirm the server's sequence number. Both parties enter the ESTABLISHED (Connection Established) state, and data transmission begins.

[0063] By ensuring that the handshake protocol used in the connection establishment operation is the three-way handshake protocol, it is possible to prevent the establishment of historical connections, negotiate the starting sequence number, maximum transmission packet size, window scaling size, etc. for subsequent communications between the two parties, and ensure that data packets are not repeated, lost, and transmitted in order. Therefore, the source address, destination address, and port number of each ECU in the vehicle can be encrypted and stored, and the connection is strictly carried out in accordance with the three-way handshake when establishing a TCP connection between the sending and receiving ends. If there is a process program that establishes a virtual connection or one or two handshakes, an alarm is immediately issued and the process handler is deleted. This allows for timely detection of illegal TCP connections, ensuring that only connections that comply with the standard three-way handshake protocol are allowed to be established, avoiding the risk of hackers using non-standard protocols to establish connections. Furthermore, by deleting the relevant process handler, illegal connections can be prevented from further affecting system security.

[0064] Step 102: monitoring the data subpacketization operation of the transmitting end, and executing security protection measures according to the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message;

[0065] In the specific implementation, Figure 6 The following diagram shows the Ethernet data structure. The Ethernet data structure generally consists of the link layer field (Eth Header), the IP (Internet Protocol) message field (IP Header), the TCP / UDP (User Datagram Protocol) message field (TCP / UDP Header), the data message, and the checksum field (FCS). The specific structure of the IP and TCP / UDP message fields is shown. The Ethernet frame format typically ranges from 64 to 1522 bytes, with the data message length being 1500 bytes, consisting of a 20-byte IP header and a 20-byte TCP header. The data payload is 1500-20-20 = 1460 bytes. If the data exceeds 1460 bytes, the sender must split the data into packets, and the receiver must reassemble the message. Packet fragmentation is typically identified in the 3-bit FLAG field of the IP header: bit 1: DF (Don't Fragment) = 0, fragmentation is permitted; DF = 1, fragmentation is not permitted; bit 2: MF (More Fragments) = 0, last fragment; MF = 1, more fragments; bit 0: Reserved. The fragment offset, typically 13 bits, indicates the location of the fragment within the datagram.

[0066] On this basis, in order to prevent hackers from carrying out network attacks through illegal data packet operations (such as tampering with the IP layer DF and / or MF fields to inject malicious instructions, sending a large number of fragmented data packets to force the receiving end to continuously wait for subsequent fragments, exhausting buffer resources, and causing system crashes or denial of service), after the transmission control protocol connection is established, the data packet operation of the sending end can be monitored, and security protection measures can be implemented based on the original message length corresponding to the data packet operation and / or the message header field parameters of the original message. For example, it can be set that the sending end application performs fragment encryption processing, and the IP message no longer performs fragmentation processing and monitors the IP message field parameters. For example, when the original message length corresponding to the data packet operation is outside a preset range and / or the message header field parameters of the original message indicate that the IP message is fragmented, corresponding security protection measures can be implemented.

[0067] In some embodiments of the present invention, executing security protection measures based on the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message includes:

[0068] When the length of the original message corresponding to the data subpackaging operation is less than a preset message length, and / or when the fragmentation prohibition flag bit in the Internet Protocol message header field of the original message corresponding to the data subpackaging operation is set to 1, an alarm is issued and the process processing program corresponding to the data subpackaging operation is deleted.

[0069] In practical applications, for data packets with a length greater than or equal to a preset packet length (e.g., 1460 bytes), the sending application can perform fragmented encryption, eliminating IP packet fragmentation. The IP header's DF field is forcibly set to 0, preventing IP header fragmentation and transmission. If a packet modifies this field, an alarm is immediately triggered, and the process handler that modified it is located and deleted. This means that the sending side can be monitored to ensure that DF=1 (fragmentation) is not set, and data with a length less than a preset packet length (e.g., 1460 bytes) cannot be fragmented. Upon detection of this operation, an alarm is immediately triggered, and the process handler that modified this field is located and deleted. This prevents security risks caused by incorrect packet fragmentation or packet field tampering, ensuring the accuracy and integrity of data packetization.

[0070] Step 103: monitor the fragmented data packets sent by the sending end based on the data segmentation operation, and perform security protection measures according to the message header fields of the sent fragmented data packets and / or the number of the sent fragmented data packets.

[0071] In the specific implementation, Figure 7The figure shows a normal process of data transmission of network fragments (fragments). As can be seen from the figure, during the first transmission, MF (More Fragments) = 1, indicating that there is more fragmented data to be transmitted, and the offset (Offset) is 0; during the second transmission, MF = 1, indicating that there is more fragmented data to be transmitted, and the offset is 1480, which is 20 bytes of TCP header + 1460 bytes of data = 1480; during the third transmission, MF = 0, indicating that the data transmission is complete, and the offset is 2960, which is the sum of the data transmitted in the first two times.

[0072] And as Figure 8 The following diagram illustrates another normal process of fragmented network data transmission. As can be seen, during the first transmission, MF = 1, indicating that more fragmented data needs to be transmitted, and the offset is 0. During the second transmission, MF = 1, indicating that more fragmented data needs to be transmitted, the offset is changed to 1460. The offset should be 1480, which is the value of the TCP header (20 bytes) + the data (1460 bytes). This change in offset to 1460 occurs because the transmitted data overwrites the IP header data, allowing hackers to tamper with IP header fields, such as the source address, destination address, and type of service. During the third transmission, MF = 0, indicating that the data transmission is complete, with an offset of 2920. In fact, hackers could have tampered with the IP header configuration by overwriting it in both transmissions, and could also combine and splice complete message data to attack the entire vehicle network. This method is undetectable by network firewalls and intrusion detection systems. Furthermore, if the message consistently displays MF = 1, data transmission will continue until the receive buffer overflows, causing a system crash. That is, if hackers define the TCP maximum transmission packet size as a smaller value, for example, setting it to 100 bytes as a unit to transmit illegal attack fragmented data in packets, the receiving end cannot analyze whether the data is illegal based on the one-sided data packet and can only allow it to pass through and be received. Then, the receiving end will reassemble the data and attack the system, causing system abnormalities.

[0073] Therefore, after monitoring the data packetization operation of the sending end, the fragmented data packets sent by the sending end based on the data packetization operation can be continued to be monitored, and security protection measures can be performed according to the header fields of the fragmented data packets sent, and / or the number of fragmented data packets sent. For example, it can be detected whether the header fields of the fragmented data packets have tampered with the IP header configuration by overwriting, and / or whether the number of fragmented data packets sent is too large and there is suspicion of a fragmentation flood attack.

[0074] In some embodiments of the present invention, performing security protection measures based on header fields of the fragmented data packets sent and / or the number of the fragmented data packets sent includes:

[0075] When the actual transmission data packet length of the sent fragmented data packet covers the transmission control protocol and / or internet protocol message header field, and the covered transmission control protocol and / or internet protocol message header field conflicts with the original transmission control protocol and / or internet protocol message header field, issuing an alarm and closing the transmission control protocol connection; and / or,

[0076] When the number of the fragmented data packets sent exceeds a preset threshold, an alarm is issued and data transmission is terminated.

[0077] In practical applications, the message header fields of the fragmented data packets sent may be monitored, and when the actual transmission data message length of the fragmented data packets sent covers the TCP / IP header field, and the covered TCP / IP header field conflicts with the original TCP / IP header field, an alarm is issued and the TCP connection is closed; and / or,

[0078] When the number of fragmented data packets sent exceeds a preset threshold (such as 10) or the number of times fragmented data packets are sent exceeds a preset threshold (such as 10 times), an alarm is issued and data transmission is terminated.

[0079] In this embodiment, by monitoring the header fields of outgoing fragmented packets, the system effectively prevents header tampering or overwriting. If a fragmented packet overwrites the TCP / IP header and conflicts with the original header, the system immediately issues an alarm and closes the connection, preventing hackers from launching attacks through header tampering. Furthermore, by monitoring the number of fragmented packets, hackers can effectively prevent denial-of-service (DoS) attacks that could deplete system resources by using large numbers of fragmented packets.

[0080] Reference Figure 9 , shows a flowchart of another method for monitoring network data transmission provided by some embodiments of the present invention, which is applied to a receiving end and may specifically include the following steps:

[0081] Step 901: monitoring a transmission control protocol connection establishment operation between a transmitting end and a receiving end, and executing a security protection measure according to the number of handshakes in the connection establishment operation;

[0082] In the specific implementation, Figure 2 The figure shows the electronic and electrical architecture of the vehicle. It can be seen that the ECU components in each domain of the vehicle system architecture are connected through the CAN bus or Ethernet bus to transmit communication messages and interact with signals. The vehicle system interacts with the outside world through the CDC for data information.

[0083] On this basis, in order to prevent the various domain ECU components in the vehicle system architecture from being attacked by hackers when they are connected through the CAN bus or Ethernet bus for communication message transmission and signal interaction, it is possible to monitor the transmission control protocol connection establishment operation between the sender and the receiver when network data is transmitted between the various domain ECU components in the vehicle, and execute security protection measures based on the number of handshakes in the connection establishment operation.

[0084] For example, you can pre-set the number of handshakes that should be taken when establishing a TCP connection, and execute corresponding security protection measures to ensure data transmission security when the number of handshakes taken for the connection establishment operation does not match the pre-set value.

[0085] In some embodiments of the present invention, executing security protection measures according to the number of handshakes of the connection establishment operation includes:

[0086] When the handshake protocol adopted by the connection establishment operation is not a three-way handshake protocol, an alarm is issued and a process processing program corresponding to the connection establishment operation is deleted.

[0087] When performing a Transmission Control Protocol connection, the connection establishment operation can generally use a no-handshake protocol (TCP virtual connection) connection and a one-time / two-time handshake protocol connection. However, the no-handshake protocol (TCP virtual connection) connection and the one-time / two-time handshake protocol connection cannot prevent the establishment of historical connections (hackers can use this to initiate illegal connections), resulting in a waste of resources and unable to guarantee reliable synchronization of the sequence number transmission between the two parties.

[0088] For example, Figure 3 The following is a schematic diagram of the handshake connection principle: Figure 4 The figure shows the principle diagram of two-way handshake connection. Figure 3 As can be seen from the content, during a handshake connection, the client (sender) only needs to send a SYN message to the server (receiver) to establish a transmission control protocol connection; Figure 4 As can be seen in the following text, during a two-way handshake, the client sends a SYN packet to the server, and the server returns a SYN-ACK packet to establish a TCP connection. Neither method can prevent the establishment of a previous connection, nor can it guarantee the synchronization of sequence numbers between the two parties, thus affecting subsequent data transmission.

[0089] On this basis, if Figure 5The figure shows a schematic diagram of the three-way handshake connection principle employed by the present invention. When the sender and receiver establish a Transmission Control Protocol connection based on the three-way handshake protocol, the client sends a SYN packet (SEQ=X) to request a connection. This causes the client to enter the SYN_SENT state. The server then returns a SYN-ACK packet: ACK=X+1 (confirming the client's sequence number); SEQ=Y (generating the server's initial sequence number). The server enters the SYN_RECEIVED state. The client then sends an ACK packet (ACK=Y+1) to confirm the server's sequence number. Both parties enter the ESTABLISHED state, and data transmission begins.

[0090] By ensuring that the handshake protocol used in the connection establishment operation is the three-way handshake protocol, it is possible to prevent the establishment of historical connections, negotiate the starting sequence number, maximum transmission packet size, window scaling size, etc. for subsequent communications between the two parties, and ensure that data packets are not repeated, lost, and transmitted in order. Therefore, the source address, destination address, and port number of each ECU in the vehicle can be encrypted and stored, and the connection is strictly carried out in accordance with the three-way handshake when establishing a TCP connection between the sending and receiving ends. If there is a process program that establishes a virtual connection or one or two handshakes, an alarm is immediately issued and the process handler is deleted. This allows for timely detection of illegal TCP connections, ensuring that only connections that comply with the standard three-way handshake protocol are allowed to be established, avoiding the risk of hackers using non-standard protocols to establish connections. Furthermore, by deleting the relevant process handler, illegal connections can be prevented from further affecting system security.

[0091] Step 902: Receive the fragmented data packets sent by the sending end based on the data subpacketization operation, and perform security protection measures according to the message header fields of the received fragmented data packets, and / or the number of the received fragmented data packets; wherein, the sending end is used to monitor the data subpacketization operation of the sending end, and perform security protection measures according to the original message length corresponding to the data subpacketization operation, and / or the message header field parameters of the original message.

[0092] In the specific implementation, in the specific implementation, such as Figure 7 The figure shows a normal process of data transmission of network fragments (fragments). As can be seen from the figure, during the first transmission, MF=1, indicating that there is more fragmented data to be transmitted, and the offset is 0; during the second transmission, MF=1, indicating that there is more fragmented data to be transmitted, and the offset is 1480, TCP header 20 bytes + data 1460 bytes = 1480; during the third transmission, MF=0, indicating that the data transmission is complete, and the offset is 2960, which is the sum of the data transmitted in the first two times.

[0093] And as Figure 8The following diagram illustrates another normal process of fragmented network data transmission. As can be seen, during the first transmission, MF = 1, indicating that more fragmented data needs to be transmitted, and the offset is 0. During the second transmission, MF = 1, indicating that more fragmented data needs to be transmitted, the offset is changed to 1460. The offset should be 1480, which is the value of the TCP header (20 bytes) + the data (1460 bytes). This change in offset to 1460 occurs because the transmitted data overwrites the IP header data, allowing hackers to tamper with IP header fields, such as the source address, destination address, and type of service. During the third transmission, MF = 0, indicating that the data transmission is complete, with an offset of 2920. In fact, hackers could have tampered with the IP header configuration by overwriting it in both transmissions, and could also combine and splice complete message data to attack the entire vehicle network. This method is undetectable by network firewalls and intrusion detection systems. Furthermore, if the message consistently displays MF = 1, data transmission will continue until the receive buffer overflows, causing a system crash. That is, if hackers define the TCP maximum transmission packet size as a smaller value, for example, setting it to 100 bytes as a unit to transmit illegal attack fragmented data in packets, the receiving end cannot analyze whether the data is illegal based on the one-sided data packet and can only allow it to pass through and be received. Then, the receiving end will reassemble the data and attack the system, causing system abnormalities.

[0094] Therefore, after the Transmission Control Protocol connection is established, the fragmented data packets received by the receiving end can be monitored, and security protection measures can be performed based on the header fields of the received fragmented data packets and / or the number of received fragmented data packets. For example, it can be detected whether the header fields of the received fragmented data packets have tampered with the IP header configuration by overwriting, and / or whether the number of received fragmented data packets is too large and there is suspicion of a fragmentation flood attack.

[0095] In addition, if Figure 6The following diagram shows the Ethernet data structure. The Ethernet data structure generally consists of the link layer field (Eth Header), IP header field (IP Header), TCP / UDP header field (TCP / UDP Header), data packet, and checksum field. The specific structure of the IP and TCP / UDP headers is shown. The Ethernet frame format typically ranges from 64 to 1522 bytes, with the data packet length being 1500 bytes, consisting of a 20-byte IP header and a 20-byte TCP header, resulting in a payload of 1500-20-20 = 1460 bytes. If the data exceeds 1460 bytes, the sender must fragment it, and the receiver must reassemble the packet. Fragmentation (fragmented data packets) is typically indicated by the 3-bit FLAG field in the IP header: bit 1: DF = 0, fragmentation possible; DF = 1, fragmentation not possible; bit 2: MF = 0, last fragment; MF = 1, further fragments; bit 0: reserved. The segment offset is generally 13 bits, and this field indicates the specific location of the fragment in the data message.

[0096] On this basis, in order to prevent hackers from carrying out network attacks through illegal data packet operations (such as tampering with the IP layer DF and / or MF fields to inject malicious instructions, sending a large number of fragmented data packets to force the receiving end to continuously wait for subsequent fragments, exhausting buffer resources, and causing system crashes or denial of service), after the transmission control protocol connection is established, the data packet operation of the sending end can be monitored at the sending end, and security protection measures can be implemented at the sending end based on the original message length corresponding to the data packet operation and / or the message header field parameters of the original message. For example, the sending end can be set to perform fragment encryption processing by the application, and no longer fragment processing by the IP message and monitoring the IP message field parameters. For example, when the original message length corresponding to the data packet operation is outside a preset range and / or the message header field parameters of the original message indicate that the IP message is fragmented, corresponding security protection measures can be implemented.

[0097] In some embodiments of the present invention, the sending end is further used to issue an alarm and delete the process handler corresponding to the data subpackaging operation when the original message length corresponding to the data subpackaging operation is less than a preset message length, and / or when the fragmentation prohibition flag bit in the Internet Protocol message header field of the data subpackaging operation is set to 1.

[0098] In practical applications, on the sending end, for data packets with a length greater than or equal to a preset packet length (e.g., 1460 bytes), the application can perform fragmented encryption, eliminating IP packet fragmentation. The IP header's DF field is forcibly set to 0, preventing IP header fragmentation and transmission. If a packet modifies this field, an alarm is immediately generated, and the process handler that modified the field is identified and deleted. This means that the sending side can be monitored to ensure that DF = 1 (fragmentation) is not set, and data with a length less than a preset packet length (e.g., 1460 bytes) cannot be fragmented. Upon detection of such an operation, an alarm is immediately generated, and the process handler that modified the field is identified and deleted. This prevents security risks caused by incorrect packet fragmentation or packet field tampering, ensuring the accuracy and integrity of data packetization.

[0099] In some embodiments of the present invention, performing security protection measures based on the header fields of the received fragmented data packets and / or the number of the received fragmented data packets includes:

[0100] When the actual transmission data message length of the received fragmented data packet covers the transmission control protocol and / or internet protocol message header, and the covered transmission control protocol and / or internet protocol message header conflicts with the original transmission control protocol and / or internet protocol message header, issuing an alarm and closing the transmission control protocol connection; and / or,

[0101] When the number of the received fragmented data packets exceeds a preset threshold, an alarm is issued and data transmission is terminated.

[0102] In practical applications, the header fields of received fragmented data packets can be monitored, and when the actual transmission data packet length of the received fragmented data packet covers the TCP / IP header field, and the covered TCP / IP header field conflicts with the original TCP / IP header field, an alarm is issued and the TCP connection is closed; and / or,

[0103] When the number of received fragmented data packets exceeds a preset threshold (such as 10) or the number of times fragmented data packets are sent exceeds a preset threshold (such as 10 times), an alarm is issued and data transmission is terminated.

[0104] In this embodiment, by monitoring the header fields of received fragmented packets, the system effectively prevents tampering or overwriting of packet header fields. If a fragmented packet overwrites the TCP / IP header and conflicts with the original header fields, the system immediately issues an alarm and closes the connection, preventing hackers from launching attacks through header tampering. Furthermore, by monitoring the number of received fragmented packets, hackers can effectively prevent denial-of-service (DoS) attacks that deplete system resources by using large numbers of fragmented packets.

[0105] The following combination Figure 10 The embodiments of the present invention are exemplarily described as follows:

[0106] Depend on Figure 10 As can be seen from the content, in order to implement the above-mentioned network data transmission monitoring method of the present invention, corresponding modules can be set at the sending end and the receiving end respectively to realize the monitoring function; specifically, at the sending end, in addition to the conventional application layer, link layer, physical layer and write buffer data packets, a TCP connection monitoring module can be set to monitor the transmission control protocol connection establishment operation between the sending end and the receiving end, a subpacketization strategy monitoring module can be set to monitor the data subpacketization operation of the sending end, and a network fragmentation monitoring module can be set to monitor the fragmented data packets sent by the sending end based on the data subpacketization operation. At the receiving end, in addition to the conventional application layer, link layer, physical layer and read buffer data packets, a TCP connection monitoring module can be set to monitor the transmission control protocol connection establishment operation between the sending end and the receiving end, a packetization strategy monitoring module can be set to monitor the integrity of the received data packets, and a network fragmentation monitoring module can be set to monitor the fragmented data packets sent by the receiving end based on the data subpacketization operation.

[0107] It should be noted that for the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.

[0108] Reference Figure 11 , shows a schematic structural diagram of a network data transmission monitoring device based on the above-mentioned network data transmission monitoring method provided by some embodiments of the present invention, which is applied to a sending end and may specifically include the following modules:

[0109] A first transmission control protocol connection monitoring module 1101 is used for monitoring the transmission control protocol connection establishment operation between the sending end and the receiving end, and executing security protection measures according to the number of handshakes in the connection establishment operation;

[0110] The data subpacketization operation monitoring module 1102 is configured to monitor the data subpacketization operation of the transmitting end and execute security protection measures based on the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message;

[0111] The first fragmented data packet monitoring module 1103 is used to monitor the fragmented data packets sent by the sending end based on the data segmentation operation, and perform security protection measures according to the message header fields of the fragmented data packets sent and / or the number of the fragmented data packets sent.

[0112] In some embodiments of the present invention, the first transmission control protocol connection monitoring module 1101 includes:

[0113] The first transmission control protocol connection monitoring submodule is used to issue an alarm and delete the process processing program corresponding to the connection establishment operation when the handshake protocol adopted by the connection establishment operation is not a three-way handshake protocol.

[0114] In some embodiments of the present invention, the data subpacketization operation monitoring module 1102 includes:

[0115] The data subpacketization operation monitoring submodule is used to issue an alarm and delete the process processing program corresponding to the data subpacketization operation when the length of the original message corresponding to the data subpacketization operation is less than a preset message length and / or when the fragmentation prohibition flag bit in the Internet interconnection protocol message header field of the original message corresponding to the data subpacketization operation is set to 1.

[0116] In some embodiments of the present invention, the first fragmented data packet monitoring module 1103 includes:

[0117] a first fragmented data packet monitoring submodule, configured to generate an alarm and close the transmission control protocol connection when the actual transmission data packet length of the sent fragmented data packet covers the transmission control protocol and / or internet protocol message header field, and the covered transmission control protocol and / or internet protocol message header field conflicts with the original transmission control protocol and / or internet protocol message header field; and / or,

[0118] When the number of the fragmented data packets sent exceeds a preset threshold, an alarm is issued and data transmission is terminated.

[0119] Reference Figure 12 , shows a schematic structural diagram of another network data transmission monitoring device based on the above-mentioned network data transmission monitoring method provided by some embodiments of the present invention, which is applied to a receiving end and may specifically include the following modules:

[0120] a second transmission control protocol connection monitoring module 1201, configured to monitor the transmission control protocol connection establishment operation between the sending end and the receiving end, and execute security protection measures according to the number of handshakes in the connection establishment operation;

[0121] The second fragmented data packet monitoring module 1202 is used to receive fragmented data packets sent by the sending end based on the data subpacketization operation, and to perform security protection measures according to the message header field of the received fragmented data packet and / or the number of the received fragmented data packets; wherein, the sending end is used to monitor the data subpacketization operation of the sending end, and to perform security protection measures according to the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message.

[0122] In some embodiments of the present invention, the second transmission control protocol connection monitoring module 1201 includes:

[0123] The second transmission control protocol connection monitoring submodule is used to issue an alarm and delete the process processing program corresponding to the connection establishment operation when the handshake protocol adopted by the connection establishment operation is not a three-way handshake protocol.

[0124] In some embodiments of the present invention, the second fragmented data packet monitoring module 1202 includes:

[0125] a second fragmented data packet monitoring submodule, configured to generate an alarm and close the transmission control protocol connection when the actual transmission data packet length of the received fragmented data packet covers the transmission control protocol and / or internet protocol message header, and the covered transmission control protocol and / or internet protocol message header conflicts with the original transmission control protocol and / or internet protocol message header; and / or,

[0126] When the number of the received fragmented data packets exceeds a preset threshold, an alarm is issued and data transmission is terminated.

[0127] Some embodiments of the present invention further provide an electronic device, which may include a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, the above network data transmission monitoring method is implemented.

[0128] Some embodiments of the present invention further provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned network data transmission monitoring method is implemented.

[0129] Some embodiments of the present invention further provide a computer program product, including a computer program, which implements the above network data transmission monitoring method when executed by a processor.

[0130] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0131] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0132] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatus, or computer program products. Thus, embodiments of the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0133] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0134] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0135] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0136] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0137] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the above elements.

[0138] The above is a detailed introduction to a network data transmission monitoring method and device provided. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for general technical personnel in this field, based on the ideas of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting the present invention.

Claims

1. A method for monitoring network data transmission, characterized in that: Applied to a sending end, the method includes: monitoring a transmission control protocol connection establishment operation between the sending end and the receiving end, and executing a security protection measure according to the number of handshakes in the connection establishment operation; Monitoring the data subpacketization operation of the sending end, and executing security protection measures according to the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message; monitoring fragmented data packets sent by the sending end based on the data segmentation operation, and determining, based on header fields of the sent fragmented data packets, whether an internet protocol header field configuration has been tampered with by overwriting, and / or the number of the sent fragmented data packets, and executing security protection measures; The executing of security protection measures according to the number of handshakes of the connection establishment operation includes: When the handshake protocol adopted by the connection establishment operation is not a three-way handshake protocol, an alarm is issued and a process processing program corresponding to the connection establishment operation is deleted.

2. The method according to claim 1, characterized in that The executing of security protection measures according to the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message includes: When the length of the original message corresponding to the data subpackaging operation is less than a preset message length, and / or when the fragmentation prohibition flag bit in the Internet Protocol message header field of the original message corresponding to the data subpackaging operation is set to 1, an alarm is issued and the process processing program corresponding to the data subpackaging operation is deleted.

3. The method according to claim 1, characterized in that The performing of security protection measures according to the header fields of the fragmented data packets sent and / or the number of the fragmented data packets sent includes: When the actual transmission data packet length of the sent fragmented data packet covers the transmission control protocol and / or internet protocol message header field, and the covered transmission control protocol and / or internet protocol message header field conflicts with the original transmission control protocol and / or internet protocol message header field, issuing an alarm and closing the transmission control protocol connection; and / or, When the number of the fragmented data packets sent exceeds a preset threshold, an alarm is issued and data transmission is terminated.

4. A network data transmission monitoring method, characterized in that: Applied to a receiving end, the method includes: monitoring a transmission control protocol connection establishment operation between a sending end and the receiving end, and executing security protection measures according to the number of handshakes in the connection establishment operation; receiving fragmented data packets sent by the sending end based on a data subpacketization operation, and determining, based on header fields of the received fragmented data packets, whether an Internet Protocol header field configuration has been tampered with by overwriting, and / or the number of received fragmented data packets, and executing security protection measures; wherein the sending end is configured to monitor the data subpacketization operation of the sending end and execute security protection measures based on the original message length corresponding to the data subpacketization operation and / or message header field parameters of the original message; The executing of security protection measures according to the number of handshakes of the connection establishment operation includes: When the handshake protocol adopted by the connection establishment operation is not a three-way handshake protocol, an alarm is issued and a process processing program corresponding to the connection establishment operation is deleted.

5. The method according to claim 4, characterized in that The sending end is further configured to issue an alarm and delete the process processing program corresponding to the data subpackaging operation when the original message length corresponding to the data subpackaging operation is less than a preset message length and / or when the fragmentation prohibition flag bit in the Internet Protocol message header field of the data subpackaging operation is set to 1.

6. The method according to claim 4, characterized in that The performing of security protection measures according to the header fields of the received fragmented data packets and / or the number of the received fragmented data packets includes: When the actual transmission data message length of the received fragmented data packet covers the transmission control protocol and / or internet protocol message header, and the covered transmission control protocol and / or internet protocol message header conflicts with the original transmission control protocol and / or internet protocol message header, issuing an alarm and closing the transmission control protocol connection; and / or, When the number of the received fragmented data packets exceeds a preset threshold, an alarm is issued and data transmission is terminated.

7. A network data transmission monitoring device based on the network data transmission monitoring method according to any one of claims 1 to 3, characterized in that: Applied to a transmitting end, the device includes: a first transmission control protocol connection monitoring module, configured to monitor a transmission control protocol connection establishment operation between the sending end and the receiving end, and execute security protection measures according to the number of handshakes in the connection establishment operation; a data subpacketization operation monitoring module, configured to monitor the data subpacketization operation of the sending end and execute security protection measures based on the original message length corresponding to the data subpacketization operation and / or the message header field parameters of the original message; a first fragmented data packet monitoring module, configured to monitor the fragmented data packets sent by the sending end based on the data subpacketization operation, and determine, based on header fields of the sent fragmented data packets, whether an Internet Protocol header field configuration has been tampered with by overwriting, and / or the number of the sent fragmented data packets, and execute security protection measures; The first transmission control protocol connection monitoring module includes: The first transmission control protocol connection monitoring submodule is used to issue an alarm and delete the process processing program corresponding to the connection establishment operation when the handshake protocol adopted by the connection establishment operation is not a three-way handshake protocol.

8. A network data transmission monitoring device based on the network data transmission monitoring method according to any one of claims 4 to 6, characterized in that: Applied to a receiving end, the device includes: a second transmission control protocol connection monitoring module, configured to monitor the transmission control protocol connection establishment operation between the sending end and the receiving end, and execute security protection measures according to the number of handshakes in the connection establishment operation; a second fragmented data packet monitoring module, configured to receive fragmented data packets sent by the sending end based on a data subpacketization operation, and determine, based on header fields of the received fragmented data packets, whether an Internet Protocol header field configuration has been tampered with by overwriting, and / or the number of received fragmented data packets, and execute security protection measures; wherein the sending end is configured to monitor the data subpacketization operation of the sending end and execute security protection measures based on the original message length corresponding to the data subpacketization operation and / or message header field parameters of the original message; The second transmission control protocol connection monitoring module includes: The second transmission control protocol connection monitoring submodule is used to issue an alarm and delete the process processing program corresponding to the connection establishment operation when the handshake protocol adopted by the connection establishment operation is not a three-way handshake protocol.

Citation Information

Patent Citations

  • Security detection method and device for controller area network and electronic equipment

    CN115022058A

  • Security protection method and device for IP fragmented message

    CN116506182A

  • Bidding method based on identity authentication

    CN117614694A