Safety risk analysis system and method applied to vehicle networking joint control system

By designing a multi-module security risk analysis system in the vehicle networking and control system, multi-dimensional risk analysis of data exchange, supervision services and sharing services is carried out, and the all-round problem of system security risk analysis is solved, achieving the safe operation and stability of the system.

CN120146565AInactive Publication Date: 2025-06-13CCCC XINJIE TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510209691.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-06-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

How to conduct a comprehensive security risk analysis to ensure the safe operation of the vehicle networked and controlled system, especially when facing code vulnerabilities, open source component security risks, development environment risks, API security risks, middleware risks, big data and cloud security risks, big data model security risks and supply relationship risks.

Method used

A security risk analysis system including data exchange risk analysis module, regulatory service risk analysis module and shared service risk analysis module was designed. By conducting multi-dimensional risk analysis of data exchange, regulatory service and shared service of vehicle networking control system, and implementing corresponding disposal strategies based on the analysis results.

Benefits of technology

It realizes a comprehensive safety risk analysis of the vehicle networked and controlled system, and can promptly identify and respond to various potential safety threats, ensuring the safe operation and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120146565A_ABST
    Figure CN120146565A_ABST
Patent Text Reader

Abstract

The invention provides a safety risk analysis system and method applied to a vehicle networking joint control system. The system comprises a data exchange risk analysis module, a supervision business risk analysis module and a sharing business risk analysis module. Wherein the data exchange risk analysis module is used for carrying out risk analysis on behaviors of a data exchange service of the vehicle networking joint control system and executing a corresponding first disposal strategy according to a first risk analysis result; the supervision business risk analysis module is used for carrying out risk analysis on the supervision business of the vehicle networking joint control system and executing a corresponding second disposal strategy according to a second risk analysis result; and the shared service risk analysis module is used for carrying out risk analysis on the shared service of the vehicle networking joint control system and executing a corresponding third disposal strategy according to a third risk analysis result. According to the invention, omnibearing safety risk analysis of the vehicle networking joint control system is realized, and safe operation of the system is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicle networking, and particularly relates to a security risk analysis system and method applied to a vehicle networking and joint control system. Background Art

[0002] Vehicle-to-everything (V2X) technology has changed the connectivity and safety of vehicles. Through vehicle-to-vehicle communication, vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), vehicle-to-pedestrian (V2P), and vehicle-to-network (V2N) communications are realized. These technologies not only improve road safety but also promote the development of autonomous driving.

[0003] The core of vehicle networking and joint control lies in the vehicle networking platform. The security of the data on the vehicle networking platform is particularly important. How to conduct security risk analysis to ensure the security of the system has always been a technical problem that needs to be solved urgently. Summary of the Invention

[0004] One of the purposes of the present invention is to provide a security risk analysis system and method applied to a vehicle networking and joint control system, realizing a comprehensive security risk analysis of the vehicle networking and joint control system and ensuring the safe operation of the system.

[0005] A security risk analysis system applied to a vehicle networking and joint control system provided by an embodiment of the present invention includes: a data exchange risk analysis module, a supervision service risk analysis module, and a shared service risk analysis module;

[0006] Among them, the data exchange risk analysis module is used to conduct risk analysis on the behaviors of the data exchange services of the vehicle networking and joint control system, and execute corresponding first disposal strategies according to the first risk analysis results;

[0007] The supervision service risk analysis module is used to conduct risk analysis on the supervision services of the vehicle networking and joint control system, and execute corresponding second disposal strategies according to the second risk analysis results;

[0008] The shared service risk analysis module is used to conduct risk analysis on the shared services of the vehicle networking and joint control system, and execute corresponding third disposal strategies according to the third risk analysis results.

[0009] Preferably, the data exchange risk analysis module includes:

[0010] An exchange event analysis unit for conducting event risk assessment on exchange events;

[0011] An exchange target analysis unit for conducting target risk assessment on exchange targets;

[0012] The comprehensive monitoring unit is used to generate a first risk analysis result based on the first evaluation result of event risk assessment and the second evaluation result of target risk assessment.

[0013] Preferably, the regulatory business risk analysis module includes:

[0014] The vehicle operation characteristic supervision and analysis unit is used to conduct risk analysis on the vehicle operation characteristic supervision and analysis data to obtain a vehicle operation risk analysis result;

[0015] The platform operation supervision and analysis unit is used to conduct risk analysis on the platform operation supervision data to obtain a platform operation risk analysis result;

[0016] The vehicle accident service risk analysis unit is used to conduct risk analysis on the supervision data of vehicle accident services to obtain a vehicle accident service risk analysis result;

[0017] The integration monitoring unit is used to integrate the vehicle operation risk analysis result, the platform operation risk analysis result, and the vehicle accident service risk analysis result to obtain a second risk analysis result.

[0018] Preferably, the shared business risk analysis module includes:

[0019] The access behavior risk analysis unit is used to conduct risk analysis on the access behavior of logged-in users;

[0020] The component risk analysis unit is used to conduct risk analysis on shared open-source components.

[0021] Preferably, the component risk analysis unit conducts risk analysis on shared open-source components, including:

[0022] Taking the received open-source component as the target to be tested;

[0023] Placing the target to be tested into a pre-configured test environment for testing to obtain test results;

[0024] Comparing the target to be tested with other components in the vehicle networked control system, and determining a first reference group based on the comparison result;

[0025] Taking the components developed by the developer corresponding to the target to be tested in the past as the second reference group;

[0026] Obtaining the operation monitoring data of the components in the first reference group and the second reference group;

[0027] Conducting risk analysis on the operation monitoring data to obtain first reference analysis data and second reference analysis data;

[0028] Generating risk analysis data based on the test results, the first reference analysis data, and the second reference analysis data.

[0029] The present invention also provides a security risk analysis method applied to a vehicle networking and joint control system, including:

[0030] Performing risk analysis on the behaviors of the data exchange services of the vehicle networking and joint control system, and executing corresponding first disposal strategies according to the first risk analysis results;

[0031] Performing risk analysis on the supervision services of the vehicle networking and joint control system, and executing corresponding second disposal strategies according to the second risk analysis results;

[0032] Performing risk analysis on the sharing services of the vehicle networking and joint control system, and executing corresponding third disposal strategies according to the third risk analysis results.

[0033] Preferably, performing risk analysis on the behaviors of the data exchange services of the vehicle networking and joint control system, and executing corresponding first disposal strategies according to the first risk analysis results includes:

[0034] Performing event risk assessment on the exchange events;

[0035] Performing target risk assessment on the exchange targets;

[0036] Generating first risk analysis results based on the first evaluation results of the event risk assessment and the second evaluation results of the target risk assessment.

[0037] Preferably, performing risk analysis on the supervision services of the vehicle networking and joint control system, and executing corresponding second disposal strategies according to the second risk analysis results includes:

[0038] Performing risk analysis on the supervision analysis data of vehicle operation characteristics to obtain vehicle operation risk analysis results;

[0039] Performing risk analysis on the platform operation supervision data to obtain platform operation risk analysis results;

[0040] Performing risk analysis on the supervision data of vehicle accident services to obtain vehicle accident service risk analysis results;

[0041] Integrating the vehicle operation risk analysis results, the platform operation risk analysis results, and the vehicle accident service risk analysis results to obtain second risk analysis results.

[0042] Preferably, performing risk analysis on the sharing services of the vehicle networking and joint control system, and executing corresponding third disposal strategies according to the third risk analysis results includes:

[0043] Performing risk analysis on the access behaviors of the logged-in users;

[0044] Performing risk analysis on the shared open-source components.

[0045] Preferably, risk analysis is performed on shared open-source components, including:

[0046] Taking the received open-source component as the target to be tested;

[0047] Placing the target to be tested into a pre-configured test environment for testing to obtain test results;

[0048] Comparing the target to be tested with other components within the vehicle networking and interlocking control system, and determining the first reference group based on the comparison results;

[0049] Taking the components developed by the developer corresponding to the target to be tested in the past as the second reference group;

[0050] Obtaining the operation monitoring data of the components within the first reference group and the second reference group;

[0051] Performing risk analysis on the operation monitoring data to obtain the first reference analysis data and the second reference analysis data;

[0052] Generating risk analysis data based on the test results, the first reference analysis data, and the second reference analysis data.

[0053] Other features and advantages of the present invention will be described in the subsequent specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained by the structures specifically pointed out in the written specification and the drawings.

[0054] The technical solution of the present invention will be further described in detail below through the drawings and embodiments. Description of the Drawings

[0055] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention, and do not constitute a limitation to the present invention. In the drawings:

[0056] Figure 1 It is a schematic diagram of a security risk analysis system applied to a vehicle networking and interlocking control system in an embodiment of the present invention;

[0057] Figure 2 It is a schematic diagram of a security risk analysis method applied to a vehicle networking and interlocking control system in an embodiment of the present invention. Detailed Embodiments

[0058] The following describes the preferred embodiments of the present invention with reference to the drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0059] An embodiment of the present invention provides a security risk analysis system applied to a vehicle networking and joint control system, as follows Figure 1 shown, including: a data exchange risk analysis module 1, a supervision service risk analysis module 2, and a shared service risk analysis module 3;

[0060] Among them, the data exchange risk analysis module 1 is used to perform risk analysis on the behaviors of the data exchange services of the vehicle networking and joint control system, and execute corresponding first disposal strategies according to the first risk analysis results;

[0061] The supervision service risk analysis module 2 is used to perform risk analysis on the supervision services of the vehicle networking and joint control system, and execute corresponding second disposal strategies according to the second risk analysis results;

[0062] The shared service risk analysis module 3 is used to perform risk analysis on the shared services of the vehicle networking and joint control system, and execute corresponding third disposal strategies according to the third risk analysis results.

[0063] Starting from the application system composition diagram and conducting a preliminary analysis of the networked joint control system, it can be seen that the application system includes three categories: data exchange, regulatory services, and sharing services. Further statistics show that each business system contains multiple sub-modules, and each sub-module contains multiple functional modules. Among them, the sharing service functions include: the secure login portal sub-module (login authentication), the big data basic platform sub-module (data collection, data storage, data processing, data monitoring, data application, security, operation and maintenance); the regulatory service functions include: the vehicle operation characteristics analysis platform sub-module (analysis of the operation status of road transport vehicles, analysis of hot topics, intelligent analysis and display), the performance evaluation index analysis sub-module (platform connectivity rate, cross-domain data exchange success rate, vehicle network access rate, vehicle online rate, trajectory integrity rate, data qualification rate, satellite positioning drift vehicle rate, platform inspection response rate, average number of vehicle speeding times, average fatigue driving duration), the vehicle spot check sub-module (vehicle screening, vehicle attention, analysis of the operation of spot-checked vehicles, summary statistics, generation of spot-check reports, spot-check tracking analysis, query and statistics of historical spot-check information), the platform operation monitoring sub-module (query of business information, platform disconnection alarm service, analysis and display of the real-time vehicle flow direction, drill-down display of online statistical information, real-time cross-domain information display, vehicle aggregation analysis, query and analysis of abnormal vehicles, real-time ranking service), the provincial platform performance evaluation management sub-module (query of relevant policies and systems for platform performance evaluation, automatic monthly scoring of the provincial platform, automatic generation of monthly reports of the provincial platform, analysis of annual operation indicators of the provincial platform, automatic generation of annual reports of the provincial platform, monthly scoring of key enterprises, performance evaluation of social monitoring platforms and terminals, real-time ranking service, year-on-year and month-on-month analysis of evaluation results, evaluation anomaly analysis, average reference value for evaluation, query and download of historical monthly reports, query and download of historical annual reports); the vehicle accident service analysis sub-module (associated analysis of public security accident information, associated analysis of work safety accident information, analysis of violation behaviors, comparison and analysis of vehicle historical operation records, enterprise association analysis, accident information management, accident analysis report); the data exchange function includes: the dynamic information exchange sub-module (core data exchange service, KUDU database import proxy service, big data query interface service, timed data push service, data caching service, data fusion service, industry data sharing service, traffic monitoring service, process monitoring service, data transmission log, query and statistics). Therefore, the technical risks targeted can be summarized as: code vulnerability security risks, open source component security risks, development environment risks, API security risks, middleware risks, big data and cloud security risks, big data model security risks, and supply relationship risks.

[0064] Among them, the security risks of code vulnerabilities mainly occur during the system design and development by developers. Programmers may make various coding mistakes, such as buffer overflows, null pointer references, integer overflows, logical design flaws or imperfections, etc. These mistakes may cause the software to exhibit unpredictable behaviors under specific conditions, thus triggering security vulnerabilities. These mistakes occur frequently in the design and development of various systems, and the potential losses vary.

[0065] Classified according to their nature and threat levels, there are mainly the following categories: (1) Code execution vulnerabilities. Attackers can remotely execute malicious code and control the target system, which will cause the joint control ministerial-level system to lose system control and lead to system chaos; (2) Identity authentication and authorization vulnerabilities: Incorrect configuration or implementation of access control mechanisms, resulting in attackers obtaining unauthorized access rights, which will cause files, data, etc. of the joint control ministerial-level system to be illegally accessed or modified, leading to system anomalies; (3) Information leakage vulnerabilities: Attackers obtain sensitive information, such as user credentials, personal identity information, etc., which will cause the leakage of user information in the joint control ministerial-level system and may further cause anomalies in other related systems; (4) Vulnerabilities caused by logical errors: Security vulnerabilities caused by program logic design flaws, such as zero-dollar shopping, etc. In the joint control ministerial-level system, program logic design errors will also lead to code execution vulnerabilities, resulting in data leakage, personal information leakage and other problems; (5) Denial-of-Service (DoS) attack vulnerabilities: Attackers utilize application vulnerabilities to exhaust the resources of the target system, causing the joint control ministerial-level system to be unavailable.

[0066] The joint control ministerial-level system is used to monitor key operating vehicles at the provincial and ministerial levels. Once such security risks of code vulnerabilities occur, it will cause the provincial-level systems and the ministerial-level system to be unable to communicate with each other or the system to lose control, the status of operating vehicles cannot be tracked in a timely manner, or be controlled by illegal users, disrupting the normal monitoring status. Once an emergency security incident occurs, the latest status cannot be obtained in a timely manner, affecting the implementation of work such as vehicle tracking, traffic monitoring, and traffic guidance, resulting in very serious consequences.

[0067] Among them, the security risks of open-source components include: vulnerabilities in open-source components and security risks of open-source licenses. The use of open-source software simplifies the development difficulty of the joint control ministerial-level system and increases the possibility of innovation. On the other hand, open-source software has the characteristics of open code, easy access, and reusability, making the joint control ministerial-level system face greater risks. The vulnerabilities and defects of open-source components and frameworks are gradually increasing, and open-source software is distributed in major communities with a relatively wide range of use. However, vulnerability information cannot be promptly included by the official, resulting in a reduction in the ability to track and rectify vulnerabilities. If the risk points and response capabilities before procurement are not considered in advance, it is very likely that in the event of a software attack or vulnerability, the software risk points cannot be quickly located, the spread of the risk cannot be promptly contained, and software problems cannot be quickly updated, which will affect the use of the joint control ministerial-level system. The more intuitive losses brought about are the impact on the normal operation of the business, or the system crash, leakage of traffic information data, etc. Common open-source software license compliance risks include: (1) Failure to retain copyright notices and license information: Some open-source licenses require users to retain the original author's copyright notice and license information when using or distributing open-source software. Failure to do so may violate the license requirements, leading to copyright issues and legal disputes. (2) Inconsistent modification and distribution licenses: Certain open-source licenses require that when distributing modified open-source software, the same or compatible open-source license must be used. If an inconsistent license is used, it may violate the original license provisions, resulting in compliance issues and legal risks. (3) Closing the source of open-source software: Some open-source licenses require that the source code of modifications or derivative works based on open-source software be open. If an enterprise closes the source of open-source software or fails to open the source code as required by the license, it may violate the rights and interests of the open-source community and face compliance issues and legal risks. (4) Failure to follow the distribution requirements of open-source software: Some open-source licenses require providing the original code or a link to the location of the original code when distributing open-source software. Failure to follow these requirements may violate the license provisions, resulting in compliance issues and legal risks. (5) Mixing open-source software with different licenses: Multiple open-source software are used simultaneously in a project, but these software use different licenses. If this mixed use situation is not properly handled, it may lead to license conflicts and compliance issues.

[0068] The risks in the development environment mainly refer to: in the software development stage, programming is required to implement business functions with the help of pre-prepared development tools. JetBrains Idea, Eclipse, VSCode, etc. are usually selected for the backend, and JetBrains WebStorm, VSCode, etc. are usually selected for the frontend. As the programming environment in the development process, how to select development tools is particularly important. Once the development tools are contaminated and unsafe development tools are used, the developed system may be implanted with vulnerabilities or unknown codes, and there is a high possibility of security risks, resulting in abnormalities in the national key operating vehicle networking and control ministerial-level system.

[0069] The security risk analysis system applied to the vehicle networking and control system of the present invention analyzes data exchange risks, supervision business risks, and shared business risks respectively, realizes multi-dimensional security risk analysis of the vehicle networking and control system (system software component analysis, technical risks, API security risks, middleware risks, big data and cloud security risks, big data model security risks, and supply relationship risks), and obtains security risk analysis results; based on the security risk analysis results, responds to and disposes of vulnerabilities and threats, and at the same time generates threat intelligence from the confirmed information, realizes intelligence sharing in combination with the threat intelligence capabilities in the software supply chain situation awareness, and realizes targeted push for business systems with the same software supply chain risks, improving the timeliness of risk perception.

[0070] The avoidance of API risks mainly focuses on the secure design and development of APIs. Unreasonable and non-standard design and development will not only increase the integration cost of application programs, reduce the development efficiency of software systems, but also reduce the readability of APIs, which is not conducive to the management and maintenance of APIs, and even bring serious security hazards to the system, resulting in data leakage and abnormal operation of the national key operating vehicle networking and control ministerial-level system, generating vulnerable factors such as serious security vulnerabilities and malicious bugs, and threatening interface security and other issues.

[0071] A large number of middleware are applied in the system for interacting with other systems, as well as for internal data exchange, sharing, and operation and maintenance. After sorting out, it is found that the following middleware are applied in the system: To achieve data storage and exchange, the MySQL database is introduced for data storage, the Redis cache database is used for caching frequently used data, and the HDFS data warehouse of the Hadoop system is used for business storage; To achieve data access, the nginx server is used to deploy the data access JT / T809 server; To achieve data sharing, the kafka message queue software is used to receive data from other systems such as the networked control system, the freight public platform, the hazardous goods transportation electronic waybill system, and the chartered vehicle management system; To achieve data exchange and sharing, various data exchange and sharing are realized through middleware such as kafka message queue, zookeeper distributed application coordination service, FTP file sharing service, and DataX heterogeneous data synchronization; To run WEB applications, the Apache Tomcat application middleware is used; To achieve system operation and maintenance, monitoring is realized through the log management component Loki, the system resource monitoring Prometheus, and the synchronization tool DataX. Middleware is an important software component that lies between the operating system and applications and is responsible for realizing the interconnection and interoperability between systems. With the wide application of cloud computing, the security issues of middleware have gradually attracted attention. Middleware plays a connecting role in the system. It interacts with the operating system downward and provides services for various applications upward. Once the middleware is attacked or fails, the entire system will be affected, resulting in service interruption or data leakage. Middleware security issues are common security challenges in enterprise-level applications and cloud environments. Common middleware, such as message queues, database connection pools, cache services, etc., are key components for communication and data exchange between applications. After analysis and summary, some common middleware security issues are summarized as follows: (1) Unauthorized access: If the middleware service does not have appropriate authentication and authorization mechanisms, attackers may be able to access sensitive data or perform operations without authorization; (2) Improper configuration: Incorrect configuration settings, such as default passwords, open network ports, unnecessary service exposures, etc., can provide an entry point for attackers; (3) Software vulnerabilities: Vulnerabilities in middleware software, if not patched in time, may be exploited for attacks, such as remote code execution, denial of service (DoS) attacks, etc.; (4) Data leakage: Insecure data processing and storage may lead to the leakage of sensitive information, including user data, authentication credentials, etc.; (5) Man-in-the-middle attack (MITM): In unencrypted or insufficiently encrypted communications, attackers may intercept and tamper with data; (6) Resource exhaustion: Inappropriate resource management and limitations may lead to resource exhaustion, affecting system performance and availability; (7) Insufficient logging and monitoring: The lack of effective logging and monitoring mechanisms makes it difficult to detect and respond to security incidents.

[0072] Big data and cloud security risks include: All kinds of security risks and threats, including malware, illegal access, internal threats, and compliance violations, can affect the cloud computing environment. Due to the shared nature of cloud computing infrastructure and the dependence on third-party providers, these risks may become worse. From the analysis of the national key operating vehicle networking and control ministerial system, it can be found that there are some relatively prominent security risks in big data and cloud computing security, summarized as follows: (1) Data leakage and unauthorized access: The risks of data leakage and unauthorized access are very concerning issues in the field of cloud computing. Hackers can use vulnerabilities to obtain sensitive information, posing a major threat to data integrity and confidentiality; (2) Internal threats and data loss: Contractors or staff with access to sensitive information may inadvertently leak data, which may lead to information loss or leakage due to malicious activities. Whether intentional or not, internal risks are key risks in cloud security; (3) Vulnerabilities in shared infrastructure: Since an attack on the information or applications of one user may affect other users with similar infrastructure, there are vulnerabilities in this shared model. Cloud computing usually depends on a shared framework that allows a small number of users to share assets and services.

[0073] Big data model security risks include: Big model data risks. Big models require a large amount of high-quality data for training to achieve their due effects. However, the security data of the transportation supply chain is usually relatively sensitive, involving corporate trade secrets, supplier information, and customer privacy, etc., and it is difficult to obtain and share. Moreover, the existing supply chain security data sources are scattered, the formats are not unified, and the quality is uneven, and they cannot be directly used for big model training. In addition, if a large amount of transportation data is collected, once not effectively managed, it will cause data leakage. (2) Big model technology risks. Big model technology has high complexity, high training and deployment costs. The data volume in the transportation industry is very large and requires a large amount of computing resources and storage space; moreover, due to factors such as data, big models will have problems such as low performance and accuracy in actual applications, and the real-time requirements for transportation still need to be improved; in addition, big models have poor interpretability, and the decision-making process is difficult to intuitively understand, resulting in model biases and ambiguities. (3) Big model laws and regulations risks. There may be ethical issues such as privacy leakage and algorithmic biases in the application in supply chain security. First is the privacy leakage risk. Transportation data belongs to sensitive data, and improper storage and use will lead to the leakage of transportation sensitive data, supplier information, etc.; in addition, big model technology is highly correlated with data. Once the training data is biased, the decision-making process will also be abnormal; in addition, it also involves the issue of liability determination. Once a supply chain security accident is caused due to big model decision-making or technical factors, it is difficult to define the responsibilities of the relevant parties.

[0074] Supply relationship risks: At the software developer level, there are risks of closed source, discontinuation of operation and maintenance, and discontinuation of updates. When enterprises or individuals use open-source software, due to the developers or maintainers stopping maintenance, updates, or providing support, the software cannot be promptly repaired for vulnerabilities, upgraded, or problems resolved. Specifically, it includes: (1) Security vulnerabilities cannot be repaired in a timely manner: If open-source software stops being maintained or updated, newly discovered security vulnerabilities will not be repaired in a timely manner, giving attackers the opportunity to exploit them. (2) Functional defects cannot be resolved: Open-source software that stops being maintained will not be able to resolve known functional defects or problems, which may affect the normal operation of the system or the realization of business functions. (3) Incompatibility issues: As the system or environment changes, open-source software that stops being maintained may have incompatibility issues with the new environment, resulting in system instability or inability to operate normally. (4) Legal compliance issues: Some open-source software may contain specific licenses or depend on other components, and discontinuation of maintenance may lead to compliance issues or infringement risks.

[0075] Among them, the data exchange risk analysis module 1 includes:

[0076] An exchange event analysis unit for performing event risk assessment on exchange events;

[0077] An exchange target analysis unit for performing target risk assessment on exchange targets;

[0078] An integrated monitoring unit for generating a first risk analysis result based on the first evaluation result of event risk assessment and the second evaluation result of target risk assessment.

[0079] The exchange event analysis unit performs event risk assessment on the exchange event itself, mainly evaluating the type of the exchange event and whether there are risks in the exchange data corresponding to the exchange event; the specific risk assessment steps are as follows: According to the type of the exchange event, retrieve the corresponding risk assessment library, then extract the features of the exchange data, and determine the first evaluation result from the event risk assessment library based on the extracted features; among them, the extracted features include whether there are keywords in the sensitive word library of the system configuration, the data length, the frequency or number of sensitive words appearing in the data, etc.

[0080] The exchange target analysis unit conducts a risk assessment on the exchange target of the requested exchange to obtain the risk assessment result representing the exchanger; the specific risk assessment steps are as follows: Obtain the historical access records of the exchange target; extract features from the historical access records, and based on the extracted access record features, retrieve the corresponding second assessment result of the target risk assessment from the pre-configured target risk assessment library; among them, when extracting features from the historical access records, the extracted access record features include: the number of accesses within the currently preset time interval, the number of times of accessing sensitive data within the system (data with a configured security level greater than or equal to the preset level can be considered sensitive data), the average value of the time of each access, the amount of data downloaded for each access, etc.;

[0081] Among them, the regulatory business risk analysis module 2 includes:

[0082] The vehicle operation feature supervision analysis unit is used to conduct a risk analysis on the vehicle operation feature supervision analysis data to obtain the vehicle operation risk analysis result; the vehicle operation feature supervision analysis data is the data obtained from the supervision analysis of the vehicle operation features, and the supervision of the vehicle operation features includes: vehicle speed, permanent starting position, permanent ending position, vehicle operation area range, etc.; then, through the pre-configured risk analysis library, the corresponding vehicle operation risk analysis result is obtained; risks can be discovered through supervision, for example: the normal operation area range of vehicle A is the urban area, and since the beginning of a month, the normal operation area range has become cross-city, at this time the vehicle has a relatively high risk and a warning can be issued;

[0083] The platform operation supervision analysis unit is used to conduct a risk analysis on the platform operation supervision data to obtain the platform operation risk analysis result; conduct a risk analysis on the supervision data according to the pre-configured supervision analysis database, that is, extract features from the supervision data, and retrieve the corresponding risk analysis result from the supervision analysis database with the extracted feature parameters;

[0084] The vehicle accident service risk analysis unit is used to conduct a risk analysis on the supervision data of vehicle accident services to obtain the vehicle accident service risk analysis result; the supervision data of vehicle accident services includes: the location of the accident, the cause of the accident, the on-site pictures of the accident, the accident liability determination, etc.; it is also possible to conduct a risk analysis through the pre-configured accident service risk analysis library to obtain the corresponding risk analysis result;

[0085] The integration monitoring unit is used to integrate the vehicle operation risk analysis result, the platform operation risk analysis result and the vehicle accident service risk analysis result to obtain the second risk analysis result.

[0086] Among them, the sharing business risk analysis module 3 includes:

[0087] An access behavior risk analysis unit for performing risk analysis on the access behavior of logged-in users; the analysis of access behavior mainly depends on whether the location where the user logs in is the usual login location, the distance from the previous login location, and whether the login interval time is reasonable (i.e., whether the user can move this distance during the login interval), the specific operations during access, etc.; by extracting features from the data of access behavior, using the extracted behavior parameters to query the pre-configured behavior risk analysis library to obtain the corresponding behavior risk analysis results; among them, the extracted behavior features include: parameters representing the login time interval, parameters representing the distance of the login location, parameters representing the operation codes of each operation, etc.

[0088] A component risk analysis unit for performing risk analysis on shared open-source components.

[0089] Among them, the component risk analysis unit performs risk analysis on shared open-source components, including:

[0090] Taking the received open-source component as the target to be tested;

[0091] Placing the target to be tested into a pre-configured test environment for testing to obtain test results;

[0092] Comparing the target to be tested with other components in the vehicle networking and joint control system, and determining the first reference group according to the comparison results; the first reference group is essentially the components in the system that are similar to the target to be tested; by extracting features from the data of the components, a feature set is constructed; then, the components with the similarity of the feature set greater than the preset threshold are used as the first reference group; the data in the feature set includes: parameter data of the component type, parameter data of the types of input and output data of the component;

[0093] Taking the components developed by the developer corresponding to the target to be tested in the past as the second reference group; the components developed by the developer in the past can reflect the risks of the target to be tested from the side; therefore, the components developed in the past are used as the second reference group when evaluating the component to be tested;

[0094] Obtaining the operation monitoring data of the components in the first reference group and the second reference group; the operation monitoring data includes: the number of errors, the number of running freezes, the number of times of accessing data in sensitive areas during operation, etc.;

[0095] Performing risk analysis on the operation monitoring data to obtain the first reference analysis data and the second reference analysis data;

[0096] Generating risk analysis data based on the test results, the first reference analysis data, and the second reference analysis data. Respectively extract features from the test results, the first reference analysis data, and the second reference analysis data, and retrieve the corresponding risk analysis data from the pre-configured risk analysis library according to the extracted feature parameters.

[0097] Risk analysis data can be quantified as a risk value. Open-source components with a risk value greater than a preset threshold cannot be released and used through the system and need to be modified and tested before they can be; however, since the modification takes a long time and the risk of the open-source component is only a value slightly exceeding the threshold, a guarantee mechanism can be enabled. Developers can seek guarantees from other developers or post to a public interface to receive guarantees from other developers, and can be released and run through the guarantee; among them, the guarantee rules are as follows:

[0098] Based on the authority of the guarantor, the guarantee score held by the guarantor, the running status of open-source components similar to the guaranteed open-source component released by the guarantor, and the understanding of the guaranteed open-source component by the guarantor, determine the guarantee score range; the guarantee score range is determined according to the guarantee score held by the guarantor, that is, the maximum value of the largest guarantee score range corresponds to the maximum value of the guarantee score held by the guarantor; in addition, based on the authority, running status, and understanding, according to the coefficient library, determine the coefficient; the coefficient and the maximum value of the guarantee score held by the guarantor determine the maximum value of the guarantee score range.

[0099] Send the guarantee score range to the guarantor for the guarantor to select;

[0100] Through the difference between the risk value of the guaranteed open-source component and the threshold, query the preset risk-guarantee value correspondence table to determine the required guarantee value;

[0101] When the total guarantee value is greater than or equal to the required guarantee value, the guarantee is successful;

[0102] Configure a feedback time. When running to the feedback time after the guarantee is successful, it is necessary to give feedback on the guarantee score held by the guarantor according to the running status of the open-source component.

[0103] Among them, based on the authority, running status, and understanding, according to the coefficient library, determine the coefficient. Specifically, use the parameters represented by the authority, the first quantization parameter that quantifies the running status, and the second quantization parameter that quantifies the understanding as index labels, and index the corresponding coefficient from the coefficient library; among them, the first quantization parameter includes: parameters such as the number of errors occurring during operation, the number of times of retrieving data in the sensitive area, and the number of times of running jams; the second quantization parameter includes: parameters such as the time of running the open-source component and the type of operation executed.

[0104] The rules for feedback include: conducting a risk assessment on open-source components. When the risk value of the risk assessment is still greater than or equal to the threshold, adjust the guarantee score of the guarantor according to the pre-configured penalty rules. For example, the score used by the guarantor for guarantee can be deducted. When the risk value of the risk assessment is less than the threshold, rewards for the guarantee score can be given according to the pre-configured reward rules. The rewarded guarantee score queries the conversion table based on the operating conditions of the open-source component (such as the number of users, number of accesses, etc.) to determine the total amount of guarantee reward scores, and then distributes them according to the proportion of the guarantee scores of each guarantor.

[0105] The present invention also provides a security risk analysis method applied to a vehicle networking and joint control system, as Figure 2 shown, including:

[0106] Step 1: Conduct a risk analysis on the behavior of the data exchange service of the vehicle networking and joint control system, and execute the corresponding first disposal strategy according to the first risk analysis result;

[0107] Step 2: Conduct a risk analysis on the supervision service of the vehicle networking and joint control system, and execute the corresponding second disposal strategy according to the second risk analysis result;

[0108] Step 3: Conduct a risk analysis on the sharing service of the vehicle networking and joint control system, and execute the corresponding third disposal strategy according to the third risk analysis result.

[0109] Among them, conducting a risk analysis on the behavior of the data exchange service of the vehicle networking and joint control system, and executing the corresponding first disposal strategy according to the first risk analysis result includes:

[0110] Conduct an event risk assessment on the exchange event;

[0111] Conduct a target risk assessment on the exchange target;

[0112] Generate the first risk analysis result based on the first evaluation result of the event risk assessment and the second evaluation result of the target risk assessment.

[0113] Among them, conducting a risk analysis on the supervision service of the vehicle networking and joint control system, and executing the corresponding second disposal strategy according to the second risk analysis result includes:

[0114] Conduct a risk analysis on the vehicle operation feature supervision analysis data to obtain the vehicle operation risk analysis result;

[0115] Conduct a risk analysis on the platform operation supervision data to obtain the platform operation risk analysis result;

[0116] Conduct a risk analysis on the supervision data of the vehicle accident service to obtain the vehicle accident service risk analysis result;

[0117] Integrate the vehicle operation risk analysis results, the platform operation risk analysis results, and the vehicle accident service risk analysis results to obtain the second risk analysis result.

[0118] Among them, risk analysis is carried out on the shared services of the vehicle networking and control system, and according to the third risk analysis result, the corresponding third disposal strategy is executed, including:

[0119] Carry out risk analysis on the access behavior of logged-in users;

[0120] Carry out risk analysis on shared open-source components.

[0121] Among them, carrying out risk analysis on shared open-source components includes:

[0122] Take the received open-source component as the target to be tested;

[0123] Place the target to be tested in a pre-configured test environment for testing to obtain test results;

[0124] Compare the target to be tested with other components in the vehicle networking and control system, and determine the first reference group according to the comparison result;

[0125] Take the components developed by the corresponding developer of the target to be tested in the past as the second reference group;

[0126] Obtain the operation monitoring data of the components in the first reference group and the second reference group;

[0127] Carry out risk analysis on the operation monitoring data to obtain the first reference analysis data and the second reference analysis data;

[0128] Generate risk analysis data based on the test results, the first reference analysis data, and the second reference analysis data.

[0129] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. A safety risk analysis system applied to a vehicle networking joint control system, characterized in that: include: Data exchange risk analysis module, regulatory business risk analysis module and shared business risk analysis module; The data exchange risk analysis module is used to perform risk analysis on the behavior of the data exchange business of the vehicle networking joint control system, and execute the corresponding first disposal strategy according to the first risk analysis result; A supervision business risk analysis module, used to perform risk analysis on the supervision business of the vehicle networking joint control system, and execute a corresponding second disposal strategy according to a second risk analysis result; The shared business risk analysis module is used to perform risk analysis on the shared business of the vehicle networking joint control system and execute the corresponding third disposal strategy based on the third risk analysis result.

2. The safety risk analysis system for vehicle networking joint control system according to claim 1, characterized in that: The data exchange risk analysis module includes: An exchange event analysis unit, used to conduct event risk assessment on exchange events; An exchange target analysis unit, used to conduct target risk assessment on exchange targets; The comprehensive monitoring unit is used to generate a first risk analysis result based on a first assessment result of the event risk assessment and a second assessment result of the target risk assessment.

3. The safety risk analysis system for vehicle networking joint control system according to claim 1, characterized in that: The regulatory business risk analysis module includes: A vehicle operation characteristic supervision and analysis unit is used to perform risk analysis on the vehicle operation characteristic supervision and analysis data to obtain a vehicle operation risk analysis result; The platform operation supervision and analysis unit is used to perform risk analysis on the platform operation supervision data and obtain the platform operation risk analysis results; A vehicle accident service risk analysis unit is used to perform risk analysis on the supervision data of vehicle accident services and obtain the vehicle accident service risk analysis results; The integrated monitoring unit is used to integrate the vehicle operation risk analysis results, the platform operation risk analysis results and the vehicle accident service risk analysis results to obtain a second risk analysis result.

4. The safety risk analysis system for vehicle networking joint control system according to claim 1, characterized in that: The shared business risk analysis module includes: Access behavior risk analysis unit, used to perform risk analysis on the access behavior of logged-in users; The component risk analysis unit is used to perform risk analysis on shared open source components.

5. The safety risk analysis system for vehicle networking joint control system according to claim 4, characterized in that: The component risk analysis unit performs risk analysis on shared open source components, including: Take the received open source components as the target to be tested; Place the target to be tested into a pre-configured test environment for testing and obtain the test results; Compare the target to be tested with other components in the vehicle networking joint control system, and determine the first reference group according to the comparison results; The components developed historically by the developers corresponding to the target to be tested are used as the second reference group; Acquire operation monitoring data of components in the first reference group and the second reference group; Perform risk analysis on the operation monitoring data to obtain first reference analysis data and second reference analysis data; Risk analysis data is generated based on the test results, the first reference analysis data and the second reference analysis data.

6. A safety risk analysis method applied to a vehicle networking joint control system, characterized in that: include: Performing a risk analysis on the behavior of the data exchange service of the vehicle networking joint control system, and executing a corresponding first disposal strategy according to a first risk analysis result; Conduct risk analysis on the supervision business of the vehicle networking joint control system, and execute the corresponding second disposal strategy based on the second risk analysis result; Conduct a risk analysis on the shared business of the vehicle networking joint control system, and execute a corresponding third disposal strategy based on the third risk analysis result.

7. The safety risk analysis method for a vehicle networking joint control system according to claim 6, characterized in that: Performing a risk analysis on the behavior of the data exchange service of the vehicle networking joint control system, and executing a corresponding first disposal strategy according to the first risk analysis result includes: Conduct event risk assessments for exchange events; Conduct target risk assessments on exchange targets; A first risk analysis result is generated based on the first assessment result of the event risk assessment and the second assessment result of the target risk assessment.

8. The safety risk analysis method for a vehicle networking joint control system according to claim 6, characterized in that: Conducting risk analysis on the supervision business of the vehicle networking joint control system, and executing the corresponding second disposal strategy according to the second risk analysis result includes: Conduct risk analysis on the vehicle operation characteristic supervision and analysis data to obtain the vehicle operation risk analysis results; Conduct risk analysis on platform operation supervision data to obtain platform operation risk analysis results; Conduct risk analysis on the regulatory data of vehicle accident services to obtain risk analysis results of vehicle accident services; The vehicle operation risk analysis results, platform operation risk analysis results and vehicle accident service risk analysis results are integrated to obtain a second risk analysis result.

9. The safety risk analysis method for a vehicle networking joint control system according to claim 6, characterized in that: Conduct risk analysis on the shared business of the vehicle networking joint control system, and execute the corresponding third disposal strategy according to the third risk analysis result, including: Conduct risk analysis on the access behavior of logged-in users; Perform risk analysis on shared open source components.

10. The safety risk analysis method for a vehicle networking joint control system according to claim 9, characterized in that: Perform risk analysis on shared open source components, including: Take the received open source components as the target to be tested; Place the target to be tested into a pre-configured test environment for testing and obtain the test results; Compare the target to be tested with other components in the vehicle networking joint control system, and determine the first reference group according to the comparison results; The components developed historically by the developers corresponding to the target to be tested are used as the second reference group; Acquire operation monitoring data of components in the first reference group and the second reference group; Perform risk analysis on the operation monitoring data to obtain first reference analysis data and second reference analysis data; Risk analysis data is generated based on the test results, the first reference analysis data and the second reference analysis data.

Citation Information

Patent Citations

  • Risk control processing method and device, computer equipment and storage medium

    CN112363831A

  • External access client risk control method and device, equipment and storage medium

    CN112446613A

  • Internet of vehicles information security analysis method and system, and readable storage medium

    CN117649783A

  • Collaborative Mobility Risk Assessment Platform

    US20220155796A1