Automatic safety test method, device and equipment for automobile bus network and storage medium

By performing multi-level security detection on the operating data of the automotive CAN bus network, including packet integrity verification, malicious virus detection and in-depth detection, the problem of inaccurate security detection of the automotive CAN bus network is solved and effective protection against network attacks is achieved.

CN120200781APending Publication Date: 2025-06-24DONGFENG MOTOR GRP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510243030.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The network security detection of the automotive CAN bus is inaccurate and it is difficult to effectively prevent network attacks.

Method used

By obtaining the operation data of the detection device, packet integrity verification, filtering and malicious virus detection are carried out to obtain the first security detection result. If the data is safe, obtain the preset running data threshold, compare the data based on the neural network model, obtain the second security detection result, and conduct in-depth detection to confirm the data security.

Benefits of technology

Accurate security detection of the automotive CAN bus network is realized, ensuring that the detection equipment is operating normally, and improving the protection ability of network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200781A_ABST
    Figure CN120200781A_ABST
Patent Text Reader

Abstract

The invention discloses an automobile bus network automatic safety test method, device and equipment and a storage medium, and relates to the technical field of automobile network safety detection, and the method comprises the steps: obtaining the operation data of detection equipment; performing security detection on the operation data to obtain a first security detection result; and when the safety detection result is that the data is safe, obtaining a preset operation data threshold value, and performing threshold value comparison on the operation data based on the preset operation data threshold value to obtain a second safety detection result, so that the safety of each controller on the CAN bus can be accurately detected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of electric vehicle motor control, and particularly to an automatic safety testing method, device, equipment and storage medium for an automotive bus network. Background Art

[0002] With the maturity of automotive electrification, automotive electrical systems have become increasingly complex. Currently, ordinary automobiles generally have dozens of electronic control units (ECUs), and the operating code of a luxury car is close to 100 million lines. These in-vehicle information are interconnected through in-vehicle buses. In recent years, most of the frequent automotive information security incidents are based on physical access or remote attacks on in-vehicle buses. Attackers can control the input of key nodes, such as automotive throttle valves, steering gears, brakes, etc., through vulnerabilities in in-vehicle ECUs. In automotive buses, Controller Area Network (CAN) is widely used due to its high performance and reliability.

[0003] To protect automotive buses from network attacks, relevant technical solutions based on CAN network analysis have gradually attracted the attention and emphasis of the industry.

[0004] The above content is only used to assist in understanding the technical solution of the present invention, and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main object of the present invention is to provide an automatic safety testing method, device, equipment and storage medium for an automotive bus network, aiming to solve the technical problem of inaccurate security detection of automotive CAN bus networks.

[0006] To achieve the above object, the present invention provides an automatic safety testing method for an automotive bus network. The automatic safety testing method for an automotive bus network includes the following steps:

[0007] Obtain the operation data of the detection device;

[0008] Perform security detection on the operation data to obtain a first security detection result;

[0009] When the security detection result is data security, obtain a preset operation data threshold, and perform threshold comparison on the operation data based on the preset operation data threshold to obtain a second security detection result.

[0010] In an embodiment, the step of performing security detection on the operation data to obtain a first security detection result includes:

[0011] Perform packet integrity verification on the operation data to determine whether the operation data is complete;

[0012] After the operation data passes the data packet integrity check, filter the data packets in the operation data that do not meet the security test;

[0013] After the filtering process is completed, perform malicious virus detection on the operation data to determine whether there is sensitive information and viruses in the operation data, and obtain the first security detection result.

[0014] In one embodiment, the step of obtaining a preset operation data threshold, comparing the operation data with the preset operation data threshold, and obtaining a second security detection result includes:

[0015] Obtain a preset operation data threshold, where the preset operation data threshold is stored in a neural network model;

[0016] Compare the operation data with the preset operation data threshold through the neural network model to determine whether the operation data is within the range of the preset operation data threshold;

[0017] When the operation data is within the range of the preset operation data threshold, determine that the second security detection result is data security;

[0018] When the operation data is not within the range of the preset operation data threshold, determine that the second security detection result is data insecurity.

[0019] In one embodiment, after the step of obtaining the second security detection result, it further includes:

[0020] When the second security detection result is data insecurity, determine the insecure data in the operation data, and obtain the relevant data of the insecure data;

[0021] Perform in-depth detection based on the insecure data and the relevant data to obtain an in-depth detection result.

[0022] In one embodiment, after the step of performing in-depth detection based on the insecure data and the relevant data to obtain an in-depth detection result, it further includes:

[0023] When the in-depth detection result is data insecurity, determine that the detection device is operating abnormally, trigger an alarm mechanism for alarm processing, and share the in-depth detection result with the monitoring end.

[0024] In one embodiment, the step of obtaining the operation data of the detection device includes:

[0025] Obtain the CAN bus differential level signal;

[0026] Convert the CAN bus differential level signal into a digital level signal to obtain CAN data in standard frame format;

[0027] Compress the CAN data in the standard frame format to obtain the operation data of the detection device.

[0028] In one embodiment, before the step of obtaining the operation data of the detection device, the method further includes:

[0029] Perform resistance detection, voltage detection, and signal detection on the CAN bus to determine whether the CAN bus is loose;

[0030] When the CAN bus is loose, perform alarm feedback processing;

[0031] When the CAN bus is not loose, execute the step of obtaining the operation data of the detection device.

[0032] In addition, to achieve the above object, the present invention further provides an automatic safety testing device for an automotive bus network, the device includes:

[0033] A data acquisition module for acquiring the operation data of the detection device;

[0034] A first safety detection module for performing safety detection on the operation data to obtain a first safety detection result;

[0035] A second safety detection module for, when the safety detection result is data security, acquiring a preset operation data threshold, and comparing the operation data with the preset operation data threshold to obtain a second safety detection result.

[0036] In addition, to achieve the above object, the present invention further provides an automatic safety testing device for an automotive bus network, the device includes: a memory, a processor, and an automotive bus network automatic safety testing program stored on the memory and executable on the processor, the automotive bus network automatic safety testing program is configured to implement the steps of the automotive bus network automatic safety testing method as described above.

[0037] In addition, to achieve the above object, the present invention further provides a storage medium, on which an automotive bus network automatic safety testing program is stored, and when the automotive bus network automatic safety testing program is executed by a processor, it implements the steps of the automotive bus network automatic safety testing method as described above.

[0038] One or more technical solutions proposed in this application have at least the following technical effects:

[0039] Obtain the operating data of the detection device; perform security detection on the operating data to obtain the first security detection result; when the security detection result is data security, obtain the preset operating data threshold, compare the operating data with the preset operating data threshold to obtain the second security detection result, and filter the voltage signal obtained from the CAN bus, so as to ensure the normal progress of subsequent detection. During the detection process, when it is found that the device under test is operating abnormally, it is necessary to perform re-detection, obtain the unsafe data and the data related to the unsafe data, and finally determine through multiple detections, so as to accurately detect the security of each controller on the CAN bus. Brief Description of the Drawings

[0040] The drawings here are incorporated into the specification and form a part of this specification, showing the embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0042] Figure 1 It is a schematic flowchart provided for Embodiment 1 of the automatic safety test method for an automotive bus network of the present application;

[0043] Figure 2 It is a system logic block diagram provided for Embodiment 1 of the automatic safety test method for an automotive bus network of the present application;

[0044] Figure 3 It is a schematic connection structure diagram of the CAN bus and the distance sensor provided for Embodiment 1 of the automatic safety test method for an automotive bus network of the present application;

[0045] Figure 4 It is a schematic flowchart provided for Embodiment 2 of the automatic safety test method for an automotive bus network of the present application;

[0046] Figure 5 It is a schematic flowchart provided for Embodiment 3 of the automatic safety test method for an automotive bus network of the present application;

[0047] Figure 6 It is a schematic module structure diagram of the automatic safety test device for an automotive bus network in the embodiments of the present application;

[0048] Figure 7 It is a schematic device structure diagram of the hardware operating environment involved in the automatic safety test method for an automotive bus network in the embodiments of the present application.

[0049] The realization of the purpose, functional features and advantages of this application will be further described in conjunction with the embodiments with reference to the accompanying drawings. Specific Embodiments

[0050] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of this application and are not used to limit this application.

[0051] In order to better understand the technical solutions of this application, the following will be described in detail in conjunction with the accompanying drawings of the specification and specific embodiments.

[0052] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device, an automotive bus network automatic safety test device, etc. that can implement the above functions. Hereinafter, an automotive bus network automatic safety test device will be taken as an example to describe this embodiment and the following embodiments.

[0053] Based on this, the embodiments of this application provide an automotive bus network automatic safety test method, referring to Figure 1 , Figure 1 is a schematic flow chart of the first embodiment of the automotive bus network automatic safety test method of this application.

[0054] In this embodiment, the automotive bus network automatic safety test method includes steps S10 to S30:

[0055] Step S10, obtaining the operation data of the detection device;

[0056] It should be noted that the operation data is the operation data of each controller on the CAN bus.

[0057] It should be understood that this strategy can be applied to an automotive CAN bus network automatic safety test device such as Figure 2 shown, Figure 2 is a system logic block diagram, including: a data processor, a signal acquisition end, a CAN bus, a communication module and a log library.

[0058] Among them, the data processor has a built-in test model, analyzes and processes the collected data based on the test model, and the data processor sets a data transmission interface, which is used to connect and transmit input and output data; one end interface of the CAN bus is connected to the vehicle device to be detected, and the other end interface of the CAN bus is connected to the signal acquisition end, and the signal output end of the signal acquisition end is connected to the data processor; the communication module is connected to the data processor, and the data processor shares the analysis result of the data obtained from the CAN bus with the monitoring end through the communication module; the log library is connected to the data processor, and the data processor stores the analysis process and result of the data obtained from the CAN bus in the log library, and the analysis process and result within 15 days are stored in the log library.

[0059] In specific implementation, the operation status of the network device is periodically collected from the CAN bus: the CAN bus periodically obtains the operation data of the vehicle device to be detected and forms a data packet with the operation data; the data obtained by the CAN bus is compressed separately, and then the separately compressed obtained data sets are combined into a data packet. During subsequent detection, the compressed obtained data can be separately retrieved for detection.

[0060] In a feasible implementation manner, in step S10, it includes steps A11 to A13:

[0061] Step A11: Obtain the differential level signal of the CAN bus;

[0062] It should be noted that the CAN bus is a serial communication protocol used in automobiles for connecting and controlling various electronic control units (ECUs) in the vehicle. The CAN bus allows ECUs to share sensor data and control information.

[0063] The differential level signal is a signal transmission method that uses two wires to transmit signals, where one wire carries a positive voltage and the other wire carries a negative voltage. This transmission method helps to reduce noise interference and improve the anti-interference ability of the signal.

[0064] Step A12: Convert the differential level signal of the CAN bus into a digital level signal to obtain CAN data in the standard frame format;

[0065] It should be noted that the digital level signal is a form of signal, referring to two states of high level and low level, which is used to represent binary data (0 and 1) in digital circuits.

[0066] Step A13: Perform compression processing on the CAN data in the standard frame format to obtain the operation data of the detection device.

[0067] It should be noted that the standard frame format means that data is encapsulated in a standard frame format, including parts such as frame start, arbitration field, control field, data field, check field, confirmation field, and frame end.

[0068] Compression processing is a technology to reduce the size of data. It removes redundant information in the data through algorithms for easy storage and transmission.

[0069] It can be understood that in the prior art during use, the acquired data cannot be initially filtered. If the acquired data is directly transmitted, it will directly pose a threat to the system's security. And for whether the device is operating normally, it is only detected once, and such detection has the problem of inaccuracy. Therefore, in this strategy for the CAN bus network security test system, the acquired data is initially filtered, the insecure data is detected again, and the data related to the insecure data is acquired and detected. This ensures the security and accuracy of the detection. The signal acquisition end includes a signal receiving unit, a signal detection unit, and a signal filtering unit. The voltage signal acquired by the signal receiving unit on the CAN bus is detected and filtered by the signal detection unit and the filtering unit. The CAN bus is connected to the signal detection unit through the signal receiving unit, the output end of the signal detection unit is connected to the signal filtering unit, and the signal filtering unit is a firewall.

[0070] Further, before the step of acquiring the operation data of the detection device, the following steps are also included:

[0071] Perform resistance detection, voltage detection, and signal detection on the CAN bus to determine whether the CAN bus is loose;

[0072] When the CAN bus is loose, perform alarm feedback processing;

[0073] When the CAN bus is not loose, execute the step of acquiring the operation data of the detection device.

[0074] In specific implementation, detect whether the CAN bus is loose: pre-detect the CAN bus to check whether it is loose. When it is loose, give an alarm and feedback;

[0075] It should be noted that as Figure 3As shown in the figure, where 1: CAN bus; 2: distance sensor; A distance sensor is connected to the side wall of the interface of the CAN bus. The distance sensor is arranged side by side with the interface of the CAN bus. The detection end of the distance sensor faces the outer end of the interface of the CAN bus, and the signal output end of the distance sensor is connected to the data processor. After the distance sensor measures the distance between the interface of the CAN bus and the device to be detected on the vehicle, the distance between the interface of the CAN bus and the device to be detected on the vehicle remains constant. When the interface of the CAN bus becomes loose from the device to be detected on the vehicle, the distance sensor will measure an increase in the distance between the interface of the CAN bus and the device to be detected on the vehicle, and this is used as the basis for judging whether the interface of the CAN bus is loose from the device to be detected on the vehicle.

[0076] Step S20: Perform a security check on the operation data to obtain the first security check result;

[0077] It should be noted that the first security check result refers to the result after the first security check, indicating whether the data is secure, whether there are abnormalities, or whether further processing is required.

[0078] In a specific implementation, it is determined whether the collected data is secure: the obtained data packet is decompressed and it is detected whether the data packet is secure. When the data is not secure, the obtained data is filtered. When the obtained data is secure, the next step is entered;

[0079] In a feasible implementation manner, in step S20, it includes steps A21 to A23:

[0080] Step A21: Perform a data packet integrity check on the operation data to determine whether the operation data is complete;

[0081] It should be noted that the data packet integrity check is a technique for detecting whether data has been tampered with or damaged during transmission, and algorithms such as CRC (Cyclic Redundancy Check) can be used to implement it.

[0082] Step A22: After the operation data passes the data packet integrity check, filter the data packets in the operation data that do not meet the security test;

[0083] It should be noted that the criteria for the security test can include an abnormal data packet size, an unexpected data type, a suspicious source address, etc.

[0084] The filtering process can be to use a software or hardware filter to screen the data packets according to preset security rules. The filter can be rule-based or use machine learning algorithms to identify abnormal behaviors.

[0085] Step A23: After the filtering process is completed, perform malicious virus detection on the running data to determine whether there is sensitive information and viruses in the running data, and obtain the first security detection result.

[0086] It should be noted that in addition to virus detection, it is also necessary to detect whether the data packet contains sensitive information, such as personal identity information, passwords, etc., and use data loss prevention (DLP) tools to identify and protect sensitive data.

[0087] Step S30, when the security detection result is data security, obtain a preset running data threshold, and compare the running data with the preset running data threshold to obtain a second security detection result.

[0088] It should be noted that the second security detection result refers to the result after the second security detection, indicating whether the data is secure, whether there are abnormalities, or whether further processing is required;

[0089] The preset running data threshold is a set of predefined values used to determine the normal range of device running data. If the actual data exceeds these thresholds, it indicates that there is a problem with the device.

[0090] In a specific implementation, compare the collected data with the preset data and analyze: the reasonable threshold when the preset device to be detected is running. The data processor compares the acquired data with the reasonable threshold. When the acquired data is within the reasonable threshold range, it is considered that the controller to be detected is running normally; otherwise, the controller to be detected is running abnormally and the acquired data is not secure. For example, after acquiring the collected data, compare the collected data with the data within the reasonable threshold one by one. When the collected data matches the reasonable threshold, it is considered that the device to be detected is running normally. Here, for example, if the value of a certain signal of the controller on the CAN bus to be collected should be 1, and the data of the reasonable threshold is 0 - 3, if the collected data is 0 - 4, it is not within the reasonable threshold range, then the collected data is considered insecure.

[0091] This embodiment provides an automatic security testing method for an automotive bus network, which acquires the running data of a detection device; performs security detection on the running data to obtain a first security detection result; when the security detection result is data security, obtains a preset running data threshold, and compares the running data with the preset running data threshold to obtain a second security detection result. The voltage signal obtained from the CAN bus is filtered through a signal acquisition end to ensure the normal progress of subsequent detection and accurately detect the security of each controller on the CAN bus.

[0092] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar content as the above-mentioned embodiment one can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 4, when the security detection result is data security, step S30 includes steps S301 to S304:

[0093] Step S301, obtain a preset operation data threshold, where the preset operation data threshold is stored in the neural network model;

[0094] It should be noted that when training a neural network model to enable it to learn and remember the data thresholds of different devices during normal operation, the training data should include historical operation data and its corresponding security thresholds, and then store the learned thresholds in the weight and bias parameters of the neural network. These parameters define the decision boundary of the network.

[0095] Step S302, compare the operation data with the threshold through the neural network model to determine whether the operation data is within the range of the preset operation data threshold;

[0096] In a specific implementation, the neural network infers based on the input data and calculates the matching degree between the data and the preset threshold.

[0097] Step S303, when the operation data is within the range of the preset operation data threshold, determine that the second security detection result is data security;

[0098] It should be noted that compare the collected data with the preset data and analyze: the reasonable threshold when the preset device under test is running, and the data processor compares the acquired data with the reasonable threshold.

[0099] In a specific implementation, if the output result of the neural network indicates that the operation data is within the preset threshold range, confirm that the data is secure.

[0100] Step S304, when the operation data is not within the range of the preset operation data threshold, determine that the second security detection result is data insecurity.

[0101] In a specific implementation, if the output result of the neural network indicates that the operation data is not within the preset threshold range, confirm that the data is insecure.

[0102] It should be understood that when the acquired data is within the reasonable threshold range, it is considered that the controller under test is running normally; otherwise, the controller under test is running abnormally and the acquired data is insecure; for example, after acquiring the collected data, compare the collected data with the data within the reasonable threshold one by one. When the collected data matches the reasonable threshold, it is considered that the device under test is running normally. Here, for example, if the value of a certain signal of the controller on the CAN bus to be collected should be 1 and the data within the reasonable threshold is 0 - 3, if the collected data is 0 - 4, it is not within the reasonable threshold range, then the collected data is considered insecure.

[0103] This embodiment provides an automatic safety testing method for an automotive bus network, which obtains a preset operation data threshold, where the preset operation data threshold is stored in a neural network model; compares the operation data with the threshold through the neural network model to determine whether the operation data is within the range of the preset operation data threshold; when the operation data is within the range of the preset operation data threshold, determines that the second safety detection result is data security; when the operation data is not within the range of the preset operation data threshold, determines that the second safety detection result is data insecurity.

[0104] Based on the first and second embodiments of the present application, in the third embodiment of the present application, the same or similar content as the above embodiments can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 5 , after step S30, it further includes steps S310 to S330:

[0105] Step S310, when the second safety detection result is data insecurity, determines the insecure data in the operation data and obtains the relevant data of the insecure data;

[0106] It should be noted that when analyzing data insecurity, further in-depth detection is performed: when the obtained data is insecure, the data processor issues an instruction to detect the insecure data obtained from the CAN bus again, obtains the relevant data of the insecure data, and detects it. The relevant data of the insecure data includes the running time, service life, and environment of the device under test.

[0107] It should be understood that after obtaining the relevant data of the insecure data, data correlation analysis will also be performed to determine the potential connections between the insecure data and the possible impacts they may have on the system.

[0108] Step S320, based on the insecure data and the relevant data, performs in-depth detection to obtain an in-depth detection result;

[0109] It should be understood that by using the same method to detect the confirmed insecure data again, since the detection result of a single detection may be inaccurate, the credibility of the result obtained through re-detection is improved.

[0110] It should be noted that in-depth detection can be to deeply analyze the insecure data and its relevant data to determine the specific reasons for data insecurity; identify possible abnormal behavior patterns in the data, such as abnormal data access, unusual data streams, etc.; evaluate the possible security vulnerabilities in the data and the risks that these vulnerabilities may be exploited.

[0111] Step S330, when the in-depth detection result is data insecurity, determines that the detection device is operating abnormally, triggers an alarm mechanism for alarm processing, and shares the in-depth detection result with the monitoring end;

[0112] It should be noted that if the deep detection result confirms that the data is insecure and determines that the relevant device is operating abnormally, an alarm processing procedure is executed, including recording the alarm event, notifying relevant personnel, starting an emergency response plan, etc., and sharing the deep detection result with the monitoring end through a secure communication channel for remote monitoring and analysis.

[0113] This embodiment provides an automatic safety testing method for an automotive bus network. When the second safety detection result indicates that the data is insecure, the insecure data in the running data is determined, and the relevant data of the insecure data is obtained; based on the insecure data and the relevant data, a deep detection is performed to obtain a deep detection result; when the deep detection result indicates that the data is insecure, it is determined that the detection device is operating abnormally, an alarm mechanism is triggered for alarm processing, and the deep detection result is shared with the monitoring end; when it is found that the device under test is operating abnormally, a re-detection is performed, the insecure data and the relevant data of the insecure data are obtained, and multiple detections are finally determined to ensure the accuracy of the detection.

[0114] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the automatic safety testing method of the automotive bus network of this application. Based on this technical concept, more forms of simple transformations are within the protection scope of this application.

[0115] This application also provides an automatic safety testing device for an automotive bus network. Please refer to Figure 6 , and the automatic safety testing device for the automotive bus network includes:

[0116] A data acquisition module 10 for acquiring the running data of the detection device;

[0117] A first safety detection module 20 for performing a safety detection on the running data to obtain a first safety detection result;

[0118] A second safety detection module 30 for, when the safety detection result indicates that the data is secure, obtaining a preset running data threshold and comparing the running data with the preset running data threshold to obtain a second safety detection result.

[0119] The automatic safety testing device for the automotive bus network provided by this application adopts the automatic safety testing method for the automotive bus network in the above embodiment, and can solve the technical problem of inaccurate safety detection of the automotive CAN bus network. Compared with the prior art, the beneficial effects of the automatic safety testing device for the automotive bus network provided by this application are the same as those of the automatic safety testing method for the automotive bus network provided by the above embodiment, and other technical features in the automatic safety testing device for the automotive bus network are the same as those disclosed in the method of the above embodiment, and will not be elaborated here.

[0120] In one embodiment, the first security detection module 20 is further configured to perform a packet integrity check on the operation data to determine whether the operation data is complete;

[0121] After the operation data passes the packet integrity check, filter the packets in the operation data that do not meet the security test;

[0122] After the filtering process is completed, perform a malicious virus detection on the operation data to determine whether there is sensitive information and viruses in the operation data, and obtain a first security detection result.

[0123] In one embodiment, the second security detection module 30 is further configured to obtain a preset operation data threshold, where the preset operation data threshold is stored in a neural network model;

[0124] Compare the operation data with the threshold through the neural network model to determine whether the operation data is within the range of the preset operation data threshold;

[0125] When the operation data is within the range of the preset operation data threshold, determine that the second security detection result is data security;

[0126] When the operation data is not within the range of the preset operation data threshold, determine that the second security detection result is data insecurity.

[0127] In one embodiment, when the second security detection result is data insecurity, the second security detection module 30 is further configured to determine the insecure data in the operation data and obtain the relevant data of the insecure data;

[0128] Perform a deep detection based on the insecure data and the relevant data to obtain a deep detection result.

[0129] In one embodiment, when the deep detection result is data insecurity, the second security detection module 30 is further configured to determine that the detection device is operating abnormally, trigger an alarm mechanism for alarm processing, and share the deep detection result with the monitoring end.

[0130] In one embodiment, the data acquisition module 10 is further configured to acquire a CAN bus differential level signal;

[0131] Convert the CAN bus differential level signal into a digital level signal to obtain CAN data in a standard frame format;

[0132] Compress the CAN data in the standard frame format to obtain the operation data of the detection device.

[0133] In one embodiment, the data acquisition module 10 is further configured to perform a resistance detection, a voltage detection, and a signal detection on the CAN bus to determine whether the CAN bus is loose;

[0134] When the CAN bus becomes loose, alarm feedback processing is performed;

[0135] When the CAN bus is not loose, the step of obtaining the operation data of the detection device is executed.

[0136] This application provides an automatic safety testing device for an automotive bus network. The automatic safety testing device for an automotive bus network includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the automatic safety testing method for an automotive bus network in the first embodiment above.

[0137] Next, refer to Figure 7 , which shows a schematic structural diagram of an automatic safety testing device for an automotive bus network suitable for implementing the embodiments of this application. The automatic safety testing device for an automotive bus network in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The shown automatic safety testing device for an automotive bus network is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of this application.

[0138] As Figure 7As shown, the automotive bus network automatic safety testing device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the automotive bus network automatic safety testing device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the automotive bus network automatic safety testing device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows an automotive bus network automatic safety testing device having various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems can be alternatively implemented or had.

[0139] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through the communication device, or installed from the storage device 1003, or installed from the ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are executed.

[0140] The automotive bus network automatic safety testing device provided by the present application adopts the automotive bus network automatic safety testing method in the above-mentioned embodiment, and can solve the technical problem of inaccurate safety detection of the automotive CAN bus network. Compared with the prior art, the beneficial effects of the automotive bus network automatic safety testing device provided by the present application are the same as those of the automotive bus network automatic safety testing method provided by the above-mentioned embodiment, and other technical features in the automotive bus network automatic safety testing device are the same as the features disclosed in the method of the previous embodiment, and will not be elaborated here.

[0141] It should be understood that each part disclosed in this application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0142] As described above, it is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application, and all should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0143] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the automotive bus network automatic safety testing method in the above embodiments.

[0144] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, device, or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.

[0145] The above computer-readable storage medium can be included in the automotive bus network automatic safety testing device; or it can exist separately without being assembled into the automotive bus network automatic safety testing device.

[0146] The above computer-readable storage medium carries one or more programs, which, when executed by the automotive bus network automatic safety testing device, cause the automotive bus network automatic safety testing device to: obtain the operation data of the detection device; perform a safety detection on the operation data to obtain a first safety detection result; when the safety detection result is data security, obtain a preset operation data threshold, and perform a threshold comparison on the operation data based on the preset operation data threshold to obtain a second safety detection result.

[0147] Computer program code for performing the operations of the present application may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0148] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that, in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0149] The modules described in the embodiments of the present application may be implemented in software or in hardware. In some cases, the name of the module does not constitute a limitation on the unit itself.

[0150] The readable storage medium provided by this application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned automotive bus network automatic security testing method, and can solve the technical problem of inaccurate security detection of automotive CAN bus networks. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by this application are the same as those of the automotive bus network automatic security testing method provided by the above embodiments, and will not be elaborated here.

[0151] This application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the above-mentioned automotive bus network automatic security testing method.

[0152] The computer program product provided by this application can solve the technical problem of inaccurate security detection of automotive CAN bus networks. Compared with the prior art, the beneficial effects of the computer program product provided by this application are the same as those of the automotive bus network automatic security testing method provided by the above embodiments, and will not be elaborated here.

[0153] The above are only some embodiments of this application, and thus do not limit the patent scope of this application. Any equivalent structural transformation made by using the content of the specification and drawings of this application under the technical concept of this application, or any direct / indirect application in other related technical fields, is included in the patent protection scope of this application.

Claims

1. A method for automatic safety testing of a vehicle bus network, characterized in that: The method for automatic safety testing of a vehicle bus network comprises the following steps: Obtain operating data of testing equipment; Performing a safety test on the operating data to obtain a first safety test result; When the security detection result is that the data is safe, a preset operating data threshold is obtained, and a threshold comparison is performed on the operating data based on the preset operating data threshold to obtain a second security detection result.

2. The method for automatic safety testing of a vehicle bus network according to claim 1, characterized in that: The step of performing a safety check on the operating data to obtain a first safety check result includes: Performing a data packet integrity check on the operation data to determine whether the operation data is complete; After the operation data passes the data packet integrity check, filtering the data packets in the operation data that do not meet the security test; After the filtering process is completed, malicious virus detection is performed on the operating data to determine whether the operating data contains sensitive information and viruses, and a first security detection result is obtained.

3. The method for automatic safety testing of a vehicle bus network according to claim 1, characterized in that: The step of obtaining a preset operating data threshold, performing a threshold comparison on the operating data based on the preset operating data threshold, and obtaining a second safety detection result includes: Obtaining a preset operating data threshold, wherein the preset operating data threshold is stored in a neural network model; Performing a threshold comparison on the operating data through the neural network model to determine whether the operating data is within the range of the preset operating data threshold; When the operating data is within the preset operating data threshold range, determining that the second safety detection result is data safety; When the operating data is not within the preset operating data threshold range, the second security detection result is determined to be data unsafe.

4. The method for automatic safety testing of a vehicle bus network according to claim 1, characterized in that: After the step of obtaining the second safety detection result, the method further includes: When the second security detection result is that the data is unsafe, determining the unsafe data in the operating data, and obtaining relevant data of the unsafe data; A deep detection is performed based on the unsafe data and the related data to obtain a deep detection result.

5. The method for automatic safety testing of a vehicle bus network as claimed in claim 4, characterized in that: After the step of performing a deep detection based on the unsafe data and the related data to obtain a deep detection result, the method further includes: When the deep detection result is that the data is unsafe, it is determined that the detection device is operating abnormally, an alarm mechanism is triggered to perform alarm processing, and the deep detection result is shared with the monitoring end.

6. The method for automatic safety testing of a vehicle bus network according to claim 1, characterized in that: The step of obtaining the operating data of the detection device includes: Get the CAN bus differential level signal; Convert the CAN bus differential level signal into a digital level signal to obtain CAN data in a standard frame format; The CAN data in the standard frame format is compressed to obtain the operation data of the detection device.

7. The method for automatic safety testing of a vehicle bus network according to claim 1, characterized in that: Before the step of obtaining the operating data of the detection device, the method further includes: Perform resistance detection, voltage detection and signal detection on the CAN bus to determine whether the CAN bus is loose; When the CAN bus is loose, an alarm feedback process is performed; When the CAN bus is not loose, the step of acquiring the operating data of the detection device is performed.

8. An automatic safety test device for a vehicle bus network, characterized in that: The device comprises: A data acquisition module, used to acquire the operating data of the detection equipment; A first safety detection module, used for performing a safety detection on the operation data to obtain a first safety detection result; The second safety detection module is used to obtain a preset operating data threshold when the safety detection result is data safety, and perform a threshold comparison on the operating data based on the preset operating data threshold to obtain a second safety detection result.

9. An automatic safety test device for a vehicle bus network, characterized in that: The device comprises: a memory, a processor, and an automatic vehicle bus network safety test program stored in the memory and executable on the processor, wherein the automatic vehicle bus network safety test program is configured to implement the steps of the automatic vehicle bus network safety test method as described in any one of claims 1 to 7.

10. A storage medium, characterized in that: The storage medium stores an automatic vehicle bus network safety test program, which, when executed by a processor, implements the steps of the automatic vehicle bus network safety test method according to any one of claims 1 to 7.