Detection method, detection equipment and storage medium

By collecting and detecting data packets of different communication protocols in the terminal device and uploading abnormal information to the server for re-checking, the problem of insufficient communication security of terminal devices is solved, and comprehensive and reliable detection of the vehicle network is achieved.

CN120223330APending Publication Date: 2025-06-27BEIJING TUSEN WEILAI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311797912.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-25
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

With the increase in intelligence of terminal devices, the attack surface has also widened. How to ensure the communication security of terminal devices has become a technical problem that needs to be solved urgently.

Method used

A detection method is provided, through a gateway and a controller to collect and detect data packets based on different communication protocols in the terminal device, and upload abnormal detection information to the server for statistics and rechecking, realizing multi-type communication protocol detection and security monitoring of the terminal device.

Benefits of technology

The communication security of terminal devices is improved, and the terminal devices are detected with fewer requirements for computing resources, and complex detection is achieved using the server's computing resources to perform complex detection, achieving comprehensive and reliable detection of the vehicle network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223330A_ABST
    Figure CN120223330A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a detection method, and the method achieves the mixed detection of the first to-be-detected data and the second to-be-detected data of different communication protocols in the terminal equipment, achieves the detection of multiple types of communication protocols in the terminal equipment, and facilitates the improvement of the communication safety of the terminal equipment. Besides, according to the detection method, after the first to-be-detected data and the second to-be-detected data are respectively detected, the first detection information and the second detection information are respectively uploaded to the server, so that the server counts the alarm information and / or carries out redetection, the characteristic of sufficient computing resources of the server is brought into play, and the detection efficiency is improved. Alarm monitoring and / or further security detection are / is realized, and detection of terminal equipment can be realized based on cloud interconnection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of communication technologies. Specifically, it relates to network security technologies in the field of communication technologies. More specifically, it relates to a detection method, a terminal device, a server, and a storage medium. Background Art

[0002] With the continuous progress of technologies, the intelligence level of various terminal devices has been continuously improved. Taking vehicles as an example, the intelligent process of vehicles has been rapidly promoted. For example, through the integration of ADAS (Advanced Driving Assistance System), assisted driving or autonomous driving can be realized, and through Internet of Things technologies, the interconnection of all things such as vehicles and mobile phones can be achieved, etc.

[0003] However, with the continuous improvement of the intelligence level of terminal devices, the attack surface that terminal devices may face has been greatly broadened. How to ensure the communication security of terminal devices has become a technical problem to be solved urgently. Summary of the Invention

[0004] Embodiments of this specification provide a detection method, a terminal device, a server, and a storage medium, achieving the purpose of improving the communication network security of vehicles.

[0005] To achieve the above technical objectives, embodiments of this specification provide the following technical solutions:

[0006] In a first aspect, an embodiment of this specification provides a detection method, which is characterized in that it is applied to a terminal device. The terminal device includes a gateway and a controller. The detection method includes:

[0007] The gateway collects first data to be detected, and the first data to be detected includes mirror data packets based on a first communication protocol transmitted through the gateway;

[0008] The controller collects data generated when communicating based on a second communication protocol in the controller; the data generated when communicating based on the second communication protocol in the controller includes second data to be detected;

[0009] The gateway detects the first data to be detected. When the first data to be detected is detected as abnormal, it uploads first detection information to the server; the first data to be detected includes communication data based on the first communication protocol in the terminal device, and the first detection information is used for the server to count first-class alarm information or detect the first data to be detected; the first-class alarm information includes alarm information related to the first communication protocol;

[0010] The gateway detects the second data to be measured, and when the detection of the second data to be measured is abnormal, uploads the second detection information to the server; the second detection information is used for the server to count the second type of alarm information or detect the second data to be measured; the second type of alarm information includes alarm information related to the second communication protocol.

[0011] In a second aspect, an embodiment of the present specification provides a detection method, which is characterized in that it is applied to a server, the server is communicatively connected to a terminal device, the terminal device includes a gateway and a controller, and the detection method includes:

[0012] Receiving detection information, the detection information includes: first detection information and second detection information; the first detection information is the detection information uploaded by the gateway when the detection of the first data to be measured is abnormal; the first data to be measured includes communication data collected by the gateway based on the first communication protocol; the second detection information is the information uploaded by the gateway when detecting the second data to be measured and the detection of the second data to be measured is abnormal; the second data to be measured includes data generated when the controller communicates based on the second communication protocol in the controller; the data generated when the controller communicates based on the second communication protocol in the controller includes the second data to be measured;

[0013] Counting alarm information according to the detection information or rechecking the detection information; the alarm information includes the first type of alarm information related to the first communication protocol or the second type of alarm information related to the second communication protocol.

[0014] In a third aspect, an embodiment of the present specification further provides a detection device, which is applied to a vehicle. The detection device includes a memory and a processor, and the memory is used to store a computer program;

[0015] The processor is configured to implement the detection method applied to the terminal device as described in any one of the above by running the computer program stored in the memory.

[0016] In a fourth aspect, an embodiment of the present specification further provides a detection device, which is applied to a server. The detection device includes a memory and a processor, and the memory is used to store a computer program;

[0017] The processor is configured to implement the detection method as described in any one of the above by running the computer program stored in the memory.

[0018] In a fifth aspect, an embodiment of the present specification further provides a computing device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the above detection method is implemented.

[0019] In a sixth aspect, an embodiment of this specification further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above detection method is implemented.

[0020] In a seventh aspect, an embodiment of this specification provides a computer program product or a computer program. The computer program product includes a computer program, and the computer program is stored in a computer-readable storage medium; a processor of a computer device reads the computer program from the computer-readable storage medium, and when the processor executes the computer program, the steps of the above detection method are implemented.

[0021] As can be seen from the above technical solutions, the detection method provided by the embodiments of this specification realizes the mixed detection of the first data to be measured and the second data to be measured of different communication protocols in a terminal device, realizes the detection of multiple types of communication protocols in the terminal device, and is beneficial to improving the communication security of the terminal device. In addition, after the first data to be measured and the second data to be measured are respectively detected, the first detection information and the second detection information are respectively uploaded to the server, so that the server can count the alarm information and / or perform a re-inspection, which is beneficial to giving full play to the characteristics of sufficient computing resources of the server, realizing alarm monitoring and / or further security detection, and can realize the detection of the terminal device based on cloud interconnection. In addition, the detection method can perform the detection with less computing resource requirements on the terminal device, and perform the detection with greater computing resource requirements on the server, which is beneficial to giving full play to the advantage of the timeliness of detection of the terminal device on the basis of giving full play to the advantage that the server can rely on a large amount of computing resources to perform complex / comprehensive detection, and fully ensuring the communication network security of the terminal device. Description of the Drawings

[0022] In order to more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of this specification. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0023] Figure 1 It is a schematic diagram of a vehicle in which various technologies disclosed herein can be implemented.

[0024] Figure 2 It is a schematic flowchart of a detection method provided by an embodiment of this specification.

[0025] Figure 3 It is a schematic diagram of the communication architecture between a terminal device and a server provided by an embodiment of this specification.

[0026] Figure 4A flowchart of another detection method provided for an embodiment of this specification.

[0027] Figure 5 A schematic structural diagram of a computing device provided for an embodiment of this specification. Detailed implementation manners

[0028] Unless otherwise defined, technical terms or scientific terms used in the embodiments of this specification shall have the ordinary meanings understood by those of ordinary skill in the art to which this specification pertains. The terms "first", "second" and similar terms used in the embodiments of this specification do not denote any order, quantity or importance, but are only used to avoid confusion of components.

[0029] Unless otherwise required by the context, throughout this specification, "a plurality of" means "at least two", and "including" is interpreted in an open, inclusive sense, that is, "including, but not limited to". In the description of this specification, the terms "one embodiment", "some embodiments", "exemplary embodiments", "examples", "specific examples" or "some examples" etc. are intended to indicate that specific features, structures, materials or characteristics related to the embodiment or example are included in at least one embodiment or example of this specification. The schematic representations of the above terms are not necessarily referring to the same embodiment or example.

[0030] In the description of various examples in this specification, the terms used are only for the purpose of describing specific examples and are not intended to be restrictive. Unless the context clearly indicates otherwise, if the number of elements is not specifically limited, the element may be one or more. In addition, the term "and / or" used in this specification covers any one of the listed items and all possible combinations.

[0031] Next, the technical solutions in the embodiments of this specification will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this specification without creative efforts shall fall within the scope of protection of this specification.

[0032] Currently, vehicles face several technical limitations, especially in the field of autonomous driving, and these technical limitations hinder the interaction and adaptability of vehicles in the real world.

[0033] Currently, in the field of autonomous driving, autonomous driving technology is usually reactive, that is to say, decisions are based on the current situation or state. For example, an autonomous vehicle can be programmed to stop urgently when an object in the middle of the road is detected. However, current autonomous driving technology has high requirements for the stability of the in-vehicle communication network. If the in-vehicle communication network is interrupted or the communication rate fluctuates due to an attack, it may cause the information collected by the sensor to not be obtained by the controller in time, resulting in the failure to generate or transmit autonomous driving decisions in time, bringing unpredictable consequences. Therefore, it is of great significance to detect network anomalies in autonomous vehicles in a timely manner.

[0034] This specification describes a vehicle that can utilize the computing power of the vehicle's controller and gateway to achieve hybrid detection of first test data and second test data of different communication protocols, which is beneficial to improving the safety of the vehicle. In addition, after separately detecting the first test data and the second test data, the first detection information and the second detection information are respectively uploaded to the server, so that the server can count alarm information and / or conduct a re-inspection, which is beneficial to leveraging the characteristics of sufficient computing resources of the server to achieve alarm monitoring and / or further security detection. It can perform detection of terminal devices based on cloud connectivity, achieve comprehensive and reliable detection of the vehicle network, and timely discover possible network intrusion behaviors.

[0035] Now refer to Figure 1 , Figure 1 FIG. is a schematic diagram of a vehicle 100 in which the various technologies disclosed herein can be implemented. The vehicle 100 can be a car, a truck, a motorcycle, a bus, a ship, an airplane, a helicopter, a lawn mower, an excavator, a snowmobile, an aircraft, a recreational vehicle, an amusement park vehicle, a farm device, a construction device, a tram, a golf cart, a train, a trolleybus, or other vehicle. The vehicle 100 can operate in an autonomous driving mode completely or partially. In the autonomous driving mode, the vehicle 100 can control itself. For example, the vehicle 100 can determine the current state of the vehicle and the current state of the environment in which the vehicle is located, determine the predicted behavior of at least one other vehicle in the environment, determine the trust level corresponding to the possibility of the at least one other vehicle performing the predicted behavior, and control the vehicle 100 itself based on the determined information. When in the autonomous driving mode, the vehicle 100 can operate without human interaction.

[0036] Vehicle 100 may include various vehicle systems, such as drive system 142, sensor system 144, control system 146, user interface system 148, computing system 150, and communication system 152. Vehicle 100 may include more or fewer systems, and each system may include multiple units. Further, each system and unit of vehicle 100 may be interconnected. For example, computing system 150 can communicate data with one or more of drive system 142, sensor system 144, control system 146, user interface system 148, and communication system 152. Thus, one or more of the described functions of vehicle 100 may be divided into additional functional components or physical components, or combined into fewer functional components or physical components. In a further example, additional functional components or physical components may be added to the example as Figure 1 shown.

[0037] Drive system 142 may include multiple operable components (or units) that provide kinetic energy for vehicle 100. In one embodiment, drive system 142 may include an engine or motor, wheels, a transmission, an electronic system, and power (or a power source). The engine or motor may be any combination of the following devices: an internal combustion engine, an electric motor, a steam engine, a fuel cell engine, a propane engine, or other forms of engines or motors. In some embodiments, the engine may convert one power source into mechanical energy. In some embodiments, drive system 142 may include multiple engines or motors. For example, a hybrid vehicle may include a gasoline engine and an electric motor, and there may be other cases.

[0038] The wheels of vehicle 100 can be standard wheels. The wheels of vehicle 100 can be wheels in various forms, including unicycle, bicycle, tricycle, or four-wheel forms, such as the four wheels on a sedan or a truck. Other numbers of wheels are also possible, such as six wheels or more. One or more wheels of vehicle 100 can be operated to rotate in a direction different from that of other wheels. The wheels can be at least one wheel fixedly connected to a transmission. The wheels can include a combination of metal and rubber, or a combination of other substances. The transmission can include a unit operable to transmit the mechanical power of the engine to the wheels. For this purpose, the transmission can include a gearbox, a clutch, a differential gear, and a drive shaft. The transmission can also include other units. The drive shaft can include one or more axles that match the wheels. The electronic system can include a unit for transmitting or controlling the electronic signals of vehicle 100. These electronic signals can be used to activate multiple lights, multiple servo mechanisms, multiple motors, and other electronic drive or control devices in vehicle 100. The power source can be an energy source that powers the engine or the motor wholly or partly. That is, the engine or the motor can convert the power source into mechanical energy. Exemplarily, the power source can include gasoline, petroleum, petroleum-based fuels, propane, other compressed gas fuels, ethanol, fuel cells, solar panels, batteries, and other electrical energy sources. The power source can additionally or optionally include any combination of a fuel tank, a battery, a capacitor, or a flywheel. The power source can also supply energy to other systems of vehicle 100.

[0039] The sensor system 144 can include multiple sensors for sensing information about the environment and conditions of vehicle 100. For example, the sensor system 144 can include an inertial measurement unit (IMU), a global navigation satellite system (GNSS) transceiver (such as a global positioning system (GPS) transceiver), a radio detection and ranging device (RADAR, also known as millimeter-wave radar), a light detection and ranging system (LIDAR, also known as lidar), an acoustic sensor, an ultrasonic sensor, and an image capture device (such as a camera). The sensor system 144 can include multiple sensors for monitoring vehicle 100 (such as an oxygen (O2) monitor, a fuel gauge sensor, an engine oil pressure sensor, and temperature, humidity, and pressure sensors, etc.). Other sensors can also be configured. One or more sensors included in the sensor system 144 can be driven individually or collectively to update the position, orientation, or both of one or more sensors.

[0040] The IMU may include a combination of sensors (such as an accelerometer and a gyroscope) for sensing changes in the position and orientation of vehicle 100 based on inertial acceleration. The GPS transceiver can be any sensor for estimating the geographical location of vehicle 100. For this purpose, the GPS transceiver may include a receiver / transmitter to provide position information of vehicle 100 relative to the Earth. It should be noted that GPS is an example of a global navigation satellite system. Therefore, in some embodiments, the GPS transceiver can be replaced by a Beidou satellite navigation system transceiver or a Galileo satellite navigation system transceiver. The radar unit can use radio signals to sense objects in the environment where vehicle 100 is located. In some embodiments, in addition to sensing objects, the radar unit can also be used to sense the speed and forward direction of an object approaching vehicle 100. The LIDAR unit can be any sensor that uses lasers to sense objects in the environment where vehicle 100 is located. In one embodiment, the LIDAR unit may include a laser source, a laser scanner, and a detector. The LIDAR unit is used to operate in a continuous (such as using heterodyne detection) or discontinuous detection mode. The image capture device can include a device for capturing multiple images of the environment where vehicle 100 is located. An example of the image capture device is a camera, which can be a still image camera or a dynamic video camera.

[0041] The control system 146 is used to control the operation of vehicle 100 and its components (or units). Accordingly, the control system 146 may include various units, such as a steering unit, a power control unit, a braking unit, and a navigation unit.

[0042] The steering unit can be a mechanical combination for adjusting the forward direction of vehicle 100. The power control unit (such as an accelerator, for example) can be used to control the operating speed of the engine, and thus control the speed of vehicle 100. The braking unit can include a mechanical combination for decelerating vehicle 100. The braking unit can use friction in a standard manner to decelerate the vehicle. In other embodiments, the braking unit can convert the kinetic energy of the wheels into electric current. The braking unit can also take other forms. The navigation unit can be any system for determining a driving path or route for vehicle 100. The navigation unit can also dynamically update the driving path during the travel of vehicle 100. The control system 146 may additionally or optionally include other components (or units) not shown or described.

[0043] The user interface system 148 can be used to allow interaction between the vehicle 100 and external sensors, other vehicles, other computer systems, and / or the users of the vehicle 100. For example, the user interface system 148 can include a standard visual display device (e.g., a plasma display, a liquid crystal display (LCD), a touch screen display, a head-mounted display, or other similar displays), a speaker or other audio output device, a microphone or other audio input device. For example, the user interface system 148 can also include a navigation interface and an interface for controlling the internal environment of the vehicle 100 (e.g., temperature, fan, etc.).

[0044] The communication system 152 can provide a way for the vehicle 100 to communicate with one or more devices or other surrounding vehicles. In an exemplary embodiment, the communication system 152 can communicate directly or through a communication network with one or more devices. The communication system 152 can be, for example, a wireless communication system. For example, the communication system can use 3G cellular communication (e.g., CDMA, EVDO, GSM / GPRS) or 4G cellular communication (e.g., WiMAX or LTE), and can also use 5G cellular communication. Optionally, the communication system can communicate with a wireless local area network (WLAN) (e.g., using ). In some embodiments, the communication system 152 can communicate directly with one or more devices or other surrounding vehicles, for example, using infrared, Bluetooth , or ZIGBEE. Other wireless protocols, such as various vehicle communication systems, are also within the scope of the disclosure of this application. For example, the communication system can include one or more dedicated short range communication (DSRC) devices or V2X (Vehicle-to-Everything, including V2V, V2I, V2N, V2P, V2D, etc.) devices, which will perform public or private data communication with vehicles and / or roadside stations.

[0045] The computing system 150 can control some or all of the functions of the vehicle 100. The autonomous driving control unit in the computing system 150 can be used to identify, evaluate, and avoid or cross potential obstacles in the environment where the vehicle 100 is located. Generally, the autonomous driving control unit can be used to control the vehicle 100 in the absence of a driver, or to provide assistance to the driver in controlling the vehicle. In some embodiments, the autonomous driving control unit is used to combine data from sensors, such as data from a GPS transceiver, radar data, LIDAR data, camera data, and data from other vehicle systems, to determine the driving path or trajectory of the vehicle 100. The autonomous driving control unit can be activated to enable the vehicle 100 to be driven in an autonomous driving mode.

[0046] The computing system 150 may include at least one processor (which may include at least one microprocessor) that executes processing instructions (i.e., machine-executable instructions) stored in a non-volatile computer-readable medium such as a data storage device or memory. The computing system 150 may be composed of multiple computing devices that distributively control components or systems of the vehicle 100. In some embodiments, the memory may contain processing instructions (e.g., program logic) executed by the processor to implement various functions of the vehicle 100. In one embodiment, the computing system 150 is capable of communicating data with the drive system 142, the sensor system 144, the control system 146, the user interface system 148, and / or the communication system 152. Interfaces in the computing system are used to facilitate data communication between the computing system 150 and the drive system 142, the sensor system 144, the control system 146, the user interface system 148, and the communication system 152.

[0047] The memory may also include other instructions, including instructions for data transmission, instructions for data reception, instructions for interaction, or instructions for controlling the drive system 142, the sensor system 144, or the control system 146 or the user interface system 148.

[0048] In addition to storing processing instructions, the memory may store various information or data, such as image processing parameters, road maps, and path information. This information may be used by the vehicle 100 and the computing system 150 during operation of the vehicle 100 in an automatic mode, a semi-automatic mode, and / or a manual mode.

[0049] Although the autonomous driving control unit is shown as being separate from the processor and the memory, it should be understood that in some embodiments, some or all of the functions of the autonomous driving control unit may be implemented using program code instructions residing in one or more memories (or data storage devices) and executed by one or more processors, and the autonomous driving control unit may, in some cases, use the same processor and / or memory (or data storage device) to implement. In some embodiments, the autonomous driving control unit may be implemented at least in part using various dedicated circuit logics, various processors, various field programmable gate arrays (“FPGAs”), various application specific integrated circuits (“ASICs”), various real-time controllers, and hardware.

[0050] The computing system 150 can control the functions of the vehicle 100 based on inputs received from various vehicle systems (e.g., the drive system 142, the sensor system 144, and the control system 146), or inputs received from the user interface system 148. For example, the computing system 150 can use inputs from the control system 146 to control the steering unit to avoid obstacles detected by the sensor system 144. In one embodiment, the computing system 150 can be used to control multiple aspects of the vehicle 100 and its systems.

[0051] Although Figure 1 shows various components (or units) integrated into the vehicle 100, one or more of these components (or units) can be mounted on the vehicle 100 or separately associated with the vehicle 100. For example, the computing system can exist partially or entirely independently of the vehicle 100. Thus, the vehicle 100 can exist in the form of separate or integrated device units. The device units that make up the vehicle 100 can communicate with each other in a wired or wireless communication manner. In some embodiments, additional components or units can be added to each system or one or more of the above components or units can be removed from the system (e.g., Figure 1 the LiDAR or radar shown).

[0052] For application to Figure 1 the terminal device such as the vehicle 100 shown in Figure 2 as an example, an embodiment of this specification provides a detection method. As shown in Figure 3 , the terminal device includes a gateway and a controller, and the terminal device is connected to a server. Among them, the server can be the server 200 in

[0053] S201: The gateway collects first data to be measured, and the first data to be measured includes mirror data packets based on the first communication protocol transmitted through the gateway.

[0054] S202: The controller collects the data generated when communicating based on the second communication protocol in the controller; the data generated when communicating based on the second communication protocol in the controller includes second data to be measured.

[0055] S203: The gateway detects the first data to be measured. When the first data to be measured is detected as abnormal, the first detection information is uploaded to the server; the first data to be measured includes the communication data based on the first communication protocol in the terminal device, and the first detection information is used for the server to count the first type of alarm information or detect the first data to be measured; the first type of alarm information includes alarm information related to the first communication protocol.

[0056] S204: The gateway detects the second data to be measured. When the second data to be measured is detected as abnormal, the second detection information is uploaded to the server; the second detection information is used for the server to count the second type of alarm information or detect the second data to be measured; the second type of alarm information includes alarm information related to the second communication protocol.

[0057] The terminal device can be, for example, Figure 1 the vehicle 100 as shown, or other terminal devices with a gateway and a controller. Taking the vehicle 100 as an example of the terminal device, Figure 3 FIG. shows a simplified schematic diagram of the communication architecture of the vehicle 100 and a schematic diagram of the communication relationship between the vehicle 100 and the server 200. The vehicle 100 may include a Telematics Box (TBOX), an On-Board Diagnostics (OBD), an Advanced Driver Assistance Systems (ADAS), an In-Vehicle Infotainment (IVI), a Gateway, a Powertrain, a Body, and a Chassis system. The gateway is provided with a terminal detection engine, a first communication module, and a second communication module. The terminal detection engine can be used to detect the first data to be measured and the second data to be measured, and when the first data to be measured and / or the second data to be measured is detected as abnormal, the first detection information and / or the second detection information is uploaded to the server through the Telematics Box; the first communication module can be used for the transmission control of data packets based on the first communication protocol, and the second communication module can be used for the transmission control of data based on the second communication protocol; a first acquisition module may be provided in the first communication module, and the first acquisition module can acquire the first data to be measured passing through the first communication module and hand it over to the terminal detection engine for detection; a second acquisition module may be provided in the second communication module, and the second acquisition module can acquire the second data to be measured passing through the second communication module and hand it over to the terminal detection engine for detection. In systems or components such as the Telematics Box, the Advanced Driver Assistance Systems, and the In-Vehicle Infotainment system, a controller and a second acquisition module may be included. The controllers in each system or component can collect the data generated during communication based on the second communication protocol in each controller as the second data to be measured and transmit it to the gateway, and the gateway detects the second data to be measured. In Figure 3 FIG., the dotted arrows between the systems or components represent the transmission paths of data packets based on the first communication protocol, and the solid arrows can represent the transmission paths of data based on the second communication protocol.

[0058] In vehicle 100, the first communication protocol can be, for example, the CAN (Controller Area Network) communication protocol, and the second communication protocol can be, for example, the Ethernet (ETH) communication protocol. The vehicle 100 has established a communication connection with the server 200 through a remote communication box, and can transmit the data in the vehicle 100 to the server 200. The server 200 can include a detection system, where the detection system can be used to recheck the first detection information and the second detection information. In some embodiments, when all devices or components in the terminal device communicate normally, the size of the first data to be measured is smaller than the size of the second data to be measured.

[0059] In this embodiment, during the operation of the terminal device, the gateway collects the first data to be measured and detects the first data to be measured. When the first data to be measured is detected as abnormal, the first detection information is uploaded to the server. The first detection information can be used for the server to count a type of alarm information or detect the first data to be measured (i.e., recheck the first data to be measured), so as to realize the initial inspection of the first data to be measured based on the first communication protocol in the terminal device and the recheck in the server. Similarly, the controller collects the second data to be measured and detects the second data to be measured. When the second data to be measured is detected as abnormal, the second detection information is uploaded to the server. The second detection information is used for the server to count the second type of alarm information or detect the second data to be measured (i.e., recheck the second data to be measured). Through the above method, it is beneficial to give full play to the characteristics of sufficient computing resources of the server to realize alarm monitoring and / or further security detection, and the detection of the terminal device can be realized based on cloud interconnection. In addition, this detection method can place the detection with less computing resource requirements on the terminal device, and place the detection with larger computing resource requirements on the server, which is beneficial to give full play to the advantage of the detection timeliness of the terminal device and the advantage that the server can rely on a large amount of computing resources to perform complex / comprehensive detection, and fully ensure the communication network security of the terminal device.

[0060] In addition, in this embodiment, the first data to be measured collected by the gateway includes the mirror data packet based on the first communication protocol transmitted through the gateway. In this way, the detection can be performed without the need to detect on the basis of the original data packet, avoiding the possibility of damage to the original data packet caused by the detection, and ensuring the normal communication of the original data packet based on the first communication protocol.

[0061] Since the first data to be measured includes data packets based on the first communication protocol, and the data size of the data packets based on the first communication protocol is usually small, based on this characteristic, a first detection model with relatively low requirements for computing resources can be constructed and run in the gateway of the terminal device to achieve the purpose of the terminal device using the first detection model to detect the first data to be measured. Specifically, in one embodiment, the gateway detecting the first data to be measured includes: detecting the first data to be measured through the first detection model to obtain a detection result.

[0062] When the first data to be measured is detected as abnormal, uploading the first detection information to the server includes:

[0063] In response to the detection result output by the first detection model including an attack type based on the first communication protocol, uploading the first detection information including the attack type based on the first communication protocol to the server, where the attack type based on the first communication protocol is used for the server to count the first type of alarm information;

[0064] In response to the detection result output by the first detection model including no accurately matched attack type, uploading the first detection information including the first information to be identified to the server, where the first information to be identified is used for the server to re-check the first data to be measured; the first information to be identified includes the first data to be measured and the context of the first data to be measured.

[0065] The first detection model can be a machine learning model trained with training samples, for example, it can be a neural network model trained with training samples. Since the data scale of the first data to be measured is usually small, the features of the first data to be measured are also relatively few. Therefore, the network scale of the first detection model used to detect the first data to be measured can also be relatively small, enabling the terminal device to run the first detection model with relatively few computing resources and computing capabilities.

[0066] When training the first detection model, its training process can include:

[0067] (1) Obtain the dataset of the first detection model. These datasets can be publicly available datasets or datasets related to network security events based on the first communication protocol obtained through actual threat tracking analysis (this dataset can be called the Self-Calibrate Dataset). Taking the first communication protocol as the CAN communication protocol as an example, the publicly available datasets can include: the Normal CAN Dataset and the Open Source CAN Dataset. Among them, the Normal CAN Dataset can be normal CAN data packets collected from terminal devices. The Open Source CAN Dataset can be CAN network datasets obtained from open source datasets.

[0068] (2) Data Pre-Proceed: Preprocess the above-mentioned datasets to form a unified input data format for training. Taking the first communication protocol as the CAN communication protocol as an example, this input data format can be as shown in Table 1, for example:

[0069] Table 1 Input Data Format

[0070] Feature Number Feature Feature Description 1 f1 Timestamp 2 f2 Time of Previous Frame Data 3 f3 Frame ID Number 4 f4 Previous Frame ID Number 5 f5 Second Previous Frame ID Number 6 f6 Third Previous Frame ID Number 7 f7 Size of Data within Frame 8 f8 Data of the First Byte 9 f9 Data of the Second Byte 10 f10 Data of the Third Byte 11 f11 Data of the Fourth Byte 12 f12 Data of the Fifth Byte 13 f13 Data of the Sixth Byte 14 f14 Data of the Seventh Byte 15 f15 Data of the Eighth Byte

[0071] In Table 1, the timestamp is used to mark the generation time of the data packet, the frame represents the data packet, and a data packet is called a frame of data. The frame ID number is the identity identifier of the data packet.

[0072] (3) Extract features from the data packets with the same input data format obtained after preprocessing to obtain samples for machine learning training and verification (i.e., the training set and the verification set). In some embodiments, to ensure the effectiveness of the training and verification of the machine learning model, 70% of the samples can be used as the training set for machine training, and 30% of the samples can be used as the verification set to train and verify the trained machine learning model. When the verification accuracy does not reach the predetermined accuracy (such as 95%, 96%, etc.), the model parameters can be readjusted and trained again until the first detection model is obtained.

[0073] It can be understood that the above description of the training process of the first detection model is only an exemplary description and does not limit the first detection model provided by the embodiments of this specification. Those skilled in the art can adjust each step of the above training process according to actual needs. For example, in some cases, 80% of the samples can also be used as the training set and 20% of the samples can be used as the verification set, etc. This specification does not make any limitations in this regard.

[0074] In this embodiment, by detecting the first data to be detected based on the first detection model, the generalization ability of the machine learning model can be utilized to achieve anomaly detection for known types and some unknown types based on the first communication protocol, improve the anomaly detection ability of the terminal device for various anomalies based on the first communication protocol, and achieve timely discovery of known and unknown types of anomalies. For example, for known types of attacks included in the dataset, the first detection model can generally accurately identify the attack type of the first communication protocol from the first data packet to be detected. At this time, the first detection model can upload the first detection information including the attack type based on the first communication protocol to the server, so that the server can count the first type of alarm information based on the first detection information. For unknown types of attacks not included in the dataset, based on the generalization ability of the first detection model, the first detection model can also identify that there is an anomaly in the first data to be detected, and then output a detection result without an accurately matched attack type, and upload the first detection information including the first information to be identified for the server to conduct a re-inspection.

[0075] The first data to be detected in the first information to be identified may include mirror data packets, and the context of the first data to be detected may refer to the environment and related information of the first data to be detected. Taking the first communication protocol as the CAN communication protocol as an example, the context of the first data to be detected may include information such as the CAN ID number and the transmission frequency of the CAN data packet. The CAN ID number is the identity identifier of the data packet transmitted via CAN.

[0076] With the use of the first detection model, some data can be accumulated in the terminal device or the server as samples to update the first detection model, so as to improve the detection accuracy and / or generalization ability of the first detection model. For example, in one embodiment, the detection method further includes:

[0077] The gateway responds to an update instruction carrying model update parameters, and updates the first detection model according to the model update parameters; the model update parameters include the model parameters of the first detection model.

[0078] After the first detection model is put into use, the operation and maintenance personnel can analyze the first type of alarm information statistically in the server and / or the re-inspection result of the first data to be detected in the server to determine whether there are false alarms or missed alarms. By re-calibrating the data of false alarms or missed alarms as new samples, the parameters of the first detection model can be adjusted to obtain model update parameters. Taking the neural network model as an example, the model update parameters may include parameters such as the connection weights (Weight), biases (Bias), and activation functions between neurons. This specification does not limit this, and it depends on the actual situation specifically.

[0079] For the second data to be measured, since the second data to be measured is usually larger than the first data to be measured, correspondingly, the structure of the detection model for detecting the second data to be measured is usually larger, and the required computing resources and computing power are also relatively more. In order to reduce the hardware requirements of the terminal device for detecting the second data to be measured, in an embodiment of this specification, the second data to be measured includes log data generated during communication based on the second communication protocol; the gateway stores the correspondence between abnormal logs and abnormal types; the abnormal logs include abnormal logs generated during communication based on the second communication protocol, and the abnormal types include attack types based on the second communication protocol and abnormal traffic behaviors based on the second communication protocol.

[0080] The gateway's detection of the second data to be measured includes:

[0081] The gateway determines the matching result of the second data to be measured according to the correspondence between the abnormal logs and the abnormal types.

[0082] When the second data to be measured is detected as abnormal, uploading the second detection information to the server includes:

[0083] In response to the matching result including an attack type based on the second communication protocol, uploading second detection information including the attack type based on the second communication protocol to the server, and the attack type based on the second communication protocol is used for the server to count the second type of alarm information;

[0084] In response to the matching result including an abnormal traffic behavior based on the second communication protocol, uploading second detection information including second information to be identified to the server, and the second information to be identified is used for the server to re-check the second data to be measured; the second information to be identified includes data packets generated by the terminal device during communication based on the second communication protocol.

[0085] In this embodiment, the second data to be measured includes log data generated during communication based on the second communication protocol. Compared with a complete data packet based on the second communication protocol, the log data has the characteristics of a smaller data volume and contains key information, and has the characteristics of being lightweight and easy to process, which is beneficial to reducing the operation burden when the terminal device detects the second data to be measured. The log data includes, but is not limited to, system logs (System Log), process information (ProcessInfo) logs, port information (Port Info) logs, and file information (File Info) logs. System logs can record the activities, errors, and warning information of the operating system and system components. Process information logs can record the relevant information of each process running on the system, such as the process start and stop times, process IDs, resource consumption, etc. These logs can help understand the processes running on the system and are used for troubleshooting and performance analysis. Port information logs can record the relevant information of the ports used in network communication. Port information can include port numbers, protocol types, connection status, etc. These logs are very important for network security monitoring and identifying potential network attacks. File information logs can record the relevant information of files in the system, such as the creation, modification, and access times of files, file permissions, etc. These logs can be used for file system monitoring, auditing, and tracking of security events.

[0086] An abnormal log can refer to a log that records information different from that in a normal Ethernet log, or it can be considered that an abnormal log is a log that records abnormal communication behaviors and / or data. For example, during the Ethernet communication of a certain program, log A is generated, and log A records that the program requests to open port X, while the program cannot request to open port X under normal circumstances. Then, it can be determined that log A records abnormal communication behaviors and / or data, and thus log A is determined to be an abnormal log.

[0087] The correspondence between the exception logs stored in the gateway and the exception types can be referred to as a rule set. Taking the second communication protocol as Ethernet as an example, these rule sets can include: Known Security Issues, Open Rule Set, Baseline Rule Set, etc. Among them, the Known Security Issues rule set includes information such as the characteristics of some well-known Ethernet security vulnerabilities and can be used to detect some common security events. The Open Rule Set can include some publicly available host-based Ethernet intrusion detection rules and can be used to detect some common security events. The Baseline Rule Set can include Weak Password, Unnecessary Port Openings, etc. Among them, a weak password refers to using a password that is easy to guess, speculate, or crack to protect a system, account, or application. A weak password may include common dictionary words, simple combinations of numbers or letters, or passwords related to the user's personal information. Unnecessary Port Openings refer to the existence of unnecessary or unauthorized network port openings on the terminal device. Generally, unnecessary port openings mean that the listening ports of some network services, applications, or protocols are in an open state, but in fact, they are not needed or should not be made public. These open ports may provide an opportunity for potential attackers to invade the system, thereby increasing the risks faced by the system.

[0088] The correspondence between the exception logs and the exception types can include the correspondence between the exception logs and the attack types based on the second communication protocol. For example, exception log A corresponds to attack type 1; in addition, the correspondence between the exception logs and the exception types can also include the correspondence between the exception logs and the abnormal traffic behaviors based on the second communication protocol. For example, exception log B corresponds to abnormal traffic behavior 1. Abnormal traffic behavior can refer to the behavior where the network traffic does not match the required traffic. For example, assume that a certain program is in a dormant state during a specific period and does not process or request network data, while the network traffic recorded in the log at this time is significantly higher than the traffic when the program is in a dormant state. Then it can be considered that this log corresponds to abnormal traffic behavior.

[0089] In this embodiment, by storing the correspondence between the exception logs and the exception types in the gateway, only the terminal device needs to simply match the second data to be tested with this correspondence to achieve the detection of the second data to be tested in the terminal device. On the basis of meeting the requirement of detecting the second data to be tested with relatively few computing resources of the terminal device, the hardware resource requirements for the terminal device are reduced.

[0090] In addition, in this embodiment, similar to the detection of the network for the first data to be measured, when the second data to be measured corresponds to an abnormal log that has a corresponding relationship with an attack type based on the second communication protocol, a matching result including the attack type based on the second communication protocol can be output, and the second detection information including the attack type based on the second communication protocol can be uploaded to the server, so that the server can count the second type of alarm information.

[0091] When the second data to be measured corresponds to an abnormal log that has a corresponding relationship with an abnormal traffic behavior based on the second communication protocol, the second detection information including the second information to be identified can be uploaded to the server, so that the server can recheck the second data to be measured according to the second information to be identified. The second information to be identified may include data packets generated by the terminal device communicating based on the second communication protocol, so as to utilize the relatively powerful computing power of the server to recheck larger data packets generated by communicating based on the second communication protocol and achieve a comprehensive detection of the data packets.

[0092] Similar to the update of the first detection model, in order to improve the accuracy and comprehensiveness of the corresponding relationship between the abnormal log and the abnormal type, in some embodiments, the detection method further includes:

[0093] The gateway responds to an update instruction carrying rule update information, and updates the corresponding relationship between the abnormal log and the abnormal type according to the rule update information; the rule update information includes the correction information of the corresponding relationship between the abnormal log and the abnormal type or the newly added corresponding relationship between the abnormal log and the abnormal type.

[0094] The operation and maintenance personnel can collect the correction information of the corresponding relationship between the abnormal log and the abnormal type or the newly added corresponding relationship between the abnormal log and the abnormal type to form rule update information, and update the corresponding relationship between the abnormal log and the abnormal type stored in the gateway at the required time, so that the corresponding relationship record is more accurate or records more types of corresponding relationships between the abnormal log and the abnormal type, enabling the terminal device to achieve accurate and comprehensive detection of the second data to be measured based on the updated corresponding relationship.

[0095] Taking the application to the server as an example, an embodiment of this specification further provides a detection method, as Figure 4 shown, the server 200 is communicatively connected to a terminal device (such as the vehicle 100), the terminal device includes a gateway and a controller, and the detection method includes:

[0096] S401: Receive detection information, where the detection information includes: first detection information and second detection information; the first detection information is the detection information uploaded by the gateway when the first data to be detected is abnormally detected; the first data to be detected includes communication data collected by the gateway based on a first communication protocol; the second detection information is the information uploaded by the gateway when detecting second data to be detected and the second data to be detected is abnormally detected; the second data to be detected includes data generated when the controller communicates based on the second communication protocol and collected by the controller; the data generated when the controller communicates based on the second communication protocol includes the second data to be detected.

[0097] S402: Statistically analyze alarm information based on the detection information or recheck the detection information; the alarm information includes first-class alarm information related to the first communication protocol or second-class alarm information related to the second communication protocol.

[0098] Regarding the relevant limitations of the first detection information and the second detection information, reference can be made to the relevant descriptions in the previous text. In this embodiment, after receiving the detection information uploaded by the terminal device, the server can utilize the relatively powerful computing power and hardware resources on the server side to recheck the detection information, so as to achieve accurate detection of the first data to be detected and the second data to be detected in the terminal device.

[0099] In some embodiments, in order to utilize the powerful storage and computing capabilities of the server, a communication matrix based on the first communication protocol is stored in the server. The communication matrix is used to describe the legitimate communication data packets of the terminal device based on the first communication protocol, and the first data to be identified is rechecked based on the communication matrix. The first detection information includes the first data to be identified, and the first identification information includes the first data to be detected and the context of the first data to be detected.

[0100] Rechecking the first detection information includes:

[0101] In response to the first data to be identified not matching any of the legitimate communication data packets in the communication matrix, output a first attack result, where the first attack result is used to characterize the attack on the terminal device based on the first communication protocol.

[0102] In this embodiment, the communication matrix may record all or most of the legitimate communication data packets of the terminal device based on the first communication protocol. These large numbers of legitimate communication packets are stored in the server in the form of a communication matrix, enabling the server to identify whether the first information to be identified is a legitimate communication packet based on this communication matrix. If it is not a legitimate communication packet, it can be determined that the first data to be identified contains an attack based on the first communication protocol. In this way, accurate identification of attacks based on the first communication protocol can be achieved.

[0103] As described above, since the data packets included in the second information to be identified are usually large, the scale of the detection model with the function of detecting data packets based on the second communication protocol is usually large. Therefore, in some embodiments, the second detection model with the function of detecting data packets based on the second communication protocol may be run on the server, enabling the server to utilize the generalization ability of the second detection model to achieve the identification and detection of known and unknown attack types based on the second communication protocol. Specifically, in one embodiment, the second detection information includes the second information to be identified, and the second information to be identified includes the data packets generated by the terminal device during communication based on the second communication protocol.

[0104] The process by which the detection system reinspects the second detection information includes:

[0105] The detection system detects the second information to be identified through the second detection model to obtain a second attack result, and the second attack result is used to characterize the attack on the terminal device based on the second communication protocol.

[0106] Similar to the first detection model, the second detection model can also be a machine learning model trained with training samples, enabling the second detection model to have a certain generalization characteristic for the function of identifying attacks based on the second communication protocol, that is, it can identify some unknown attacks based on the second communication protocol. In this way, accurate and comprehensive detection of attacks based on the second communication protocol can be achieved.

[0107] In addition, the training process of the second detection model is similar to that of the first detection model, and can also include: dataset collection, data preprocessing, feature extraction, and model training. Different from the first detection model, when collecting the dataset, the type of the collected dataset is different from the type of the dataset used for training the first detection model. For example, taking the second communication protocol as the Ethernet communication protocol, the datasets used for training the second detection model can include publicly available Ethernet traffic detection datasets and datasets based on the network traffic of IoT devices. The publicly available Ethernet traffic detection datasets can include KDDcup1999datasets, UMASS datasets, and VPN-noVPN dataset, etc.; the datasets based on the network traffic of IoT devices can include: Bot-Iot dataset and Botnet dataset, etc.

[0108] The model architectures of the first detection model and the second detection model can be at least one of SVN (Support Vector Machine), DT (Decision Tree), KNN (k-Nearest Neighbors), and RNN (Recurrent Neural Network). The model architecture of the first detection model can be the same as or different from that of the second detection model. This specification does not make any limitations in this regard and depends on the actual situation.

[0109] In addition to being able to recheck the second data to be measured through the second detection model, in an embodiment of this specification, the server stores threat intelligence information, and the threat intelligence information is used to describe the characteristics of attack packets, and the attack packets are used to perform attacks based on the second communication protocol;

[0110] The process of rechecking the second detection information further includes:

[0111] Inputting the second information to be identified into the intelligence matching module to obtain a third attack result output by the intelligence matching module, and the third attack result is used to characterize the attack on the terminal device that matches the threat intelligence information.

[0112] The difference between threat intelligence information and the rule set is that threat intelligence information is used to describe the characteristics of attack packets, and the detection of attacks based on these characteristics can have certain generalization characteristics, that is, through threat intelligence information, some unknown attack types similar to the characteristics of attack packets can be identified.

[0113] In some cases, there may be a situation where the second attack result is different from the third attack result. To achieve accurate judgment, in an embodiment of this specification, the detection method further includes:

[0114] According to the second attack result and the third attack result, output a recheck result for the second detection information.

[0115] In this embodiment, by integrating the second attack result and the third attack result and outputting a recheck result for the second detection information, the second detection information is rechecked from multiple aspects, which is beneficial to improving the accuracy of the recheck of the second detection information.

[0116] To improve the detection accuracy and comprehensiveness of the terminal device and the server during operation, in an embodiment of this specification, a terminal detection engine runs in the gateway, and the terminal detection engine detects the first data to be measured and the second data to be measured.

[0117] The detection method further includes:

[0118] Obtain audit information, where the audit information includes audit information on the recheck result of the detection information;

[0119] According to the audit information, generate an update instruction, and the update instruction is used to update the terminal detection engine.

[0120] In some embodiments, the update instruction can also be used to update the server. Here, updating the server means updating the second detection model running in the server or the threat intelligence information stored, so as to improve the detection accuracy and comprehensiveness of the server.

[0121] As described above, similar to the audit information for the first detection model, the operation and maintenance personnel can audit the recheck result and generate audit information, so that the server generates an update instruction for updating the terminal detection engine according to the audit information. For example, after the second detection model is put into use, the operation and maintenance personnel can analyze the second type of alarm information statistically in the server and / or the recheck result of the second data to be measured in the server to determine whether there are false alarms or missed alarms. By recalibrating the misreported or missed data as new samples, the parameters of the second detection model can be adjusted to obtain model update parameters. Taking a neural network model as an example, the model update parameters can include parameters such as the connection weights (Weight), biases (Bias), and activation functions between neurons.

[0122] In addition, the operation and maintenance personnel can also generate audit information based on the updated threat intelligence information and / or the updated information of the communication matrix to update the threat intelligence information and / or the communication matrix stored in the server.

[0123] Exemplary Device

[0124] One embodiment of the present application further provides a detection device, which is applied to a vehicle. The detection device includes a memory and a processor. The memory is used to store a computer program;

[0125] The processor is configured to implement the detection method as described in any one of the above by running the computer program stored in the memory.

[0126] Another embodiment of the present application further provides a detection device, which is applied to a server. The detection device includes a memory and a processor. The memory is used to store a computer program;

[0127] The processor is configured to implement the detection method as described in any one of the above by running the computer program stored in the memory.

[0128] Another embodiment of the present application further proposes a computing device. Refer to Figure 5 As shown, an exemplary embodiment of the present specification further provides a computing device, including: a memory and a processor. The memory stores a computer program. When the processor executes the computer program, it executes the steps in the detection method according to various embodiments of the present specification described in the above embodiments of the present specification.

[0129] The internal structure of the computing device may be as Figure 5 As shown, the computing device includes a processor, a memory, a network interface, and an input device connected through a system bus. Among them, the processor of the computing device is used to provide computing and control capabilities. The memory of the computing device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computing device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it performs the steps in the detection method according to various embodiments of the present specification described in the above embodiments of the present specification.

[0130] The processor may include a main processor, and may also include a baseband chip, a modem, etc.

[0131] The memory stores a program for executing the technical solution of the present disclosure, and may also store an operating system and other critical services. Specifically, the program may include program code, and the program code includes computer operation instructions. More specifically, the memory may include a read-only memory (ROM), other types of static storage devices that can store static information and instructions, a random access memory (RAM), other types of dynamic storage devices that can store information and instructions, a disk memory, a flash memory, and so on.

[0132] The processor may be a general-purpose processor, such as a general-purpose central processing unit (CPU), a microprocessor, etc., or an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present disclosure. It may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0133] The input device may include a device for receiving user input data and information, such as a keyboard, a mouse, a camera, a scanner, a light pen, a voice input device, a touch screen, a pedometer or a gravity sensor, etc.

[0134] The output device may include a device for allowing outputting information to the user, such as a display screen, a printer, a speaker, etc.

[0135] The communication interface may include a device using any transceiver type to communicate with other devices or communication networks, such as Ethernet, a radio access network (RAN), a wireless local area network (WLAN), etc.

[0136] The processor executes the program stored in the memory and calls other devices, which can be used to implement each step of any one of the detection methods provided in the above embodiments of the present application.

[0137] The computing device may further include a display component and a voice component. The display component may be a liquid crystal display screen or an electronic ink display screen. The input device of the computing device may be a touch layer covered on the display component, or a button, a trackball or a touchpad provided on the housing of the computing device, or an external keyboard, a touchpad or a mouse, etc.

[0138] Those skilled in the art can understand, Figure 5The structure shown is only a block diagram of some of the structures related to the solution of this specification, and does not constitute a limitation on the computing device to which the solution of this specification is applied. The specific computing device may include more or fewer components than those shown in the figure, or combine some components, or have a different component arrangement.

[0139] Exemplary Computer Program Product and Storage Medium

[0140] In addition to the above methods and devices, the detection method provided by the embodiments of this specification may also be a computer program product, which includes computer program instructions. When the computer program instructions are run by a processor, the processor is caused to execute the steps in the detection methods according to various embodiments of this specification described in the "Exemplary Methods" section above of this specification.

[0141] The computer program product can be written in any combination of one or more programming languages to write program code for performing the operations of the embodiments of this specification. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as an independent software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0142] In addition, the embodiments of this specification also provide a computer-readable storage medium, on which a computer program is stored. The computer program is executed by a processor to perform the steps in the detection methods according to various embodiments of this specification described in the "Exemplary Methods" section above of this specification.

[0143] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in this specification can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0144] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0145] The above-described embodiments merely represent several implementation manners of this specification. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the solutions provided by the embodiments of this specification. It should be noted that for those of ordinary skill in the art, without departing from the concept of this specification, several modifications and improvements can still be made, and these all belong to the protection scope of this specification. Therefore, the protection scope of the patent of this specification should be subject to the appended claims.

Claims

1. A detection method, characterized in that, Applied to a terminal device, the terminal device includes a gateway and a controller; the detection method includes: The gateway collects first data to be measured, and the first data to be measured includes mirror data packets based on a first communication protocol transmitted through the gateway; The controller collects data generated when communicating based on a second communication protocol in the controller; the data generated when communicating based on the second communication protocol in the controller includes second data to be measured; The gateway detects the first data to be measured, and when the first data to be measured is detected as abnormal, uploads first detection information to the server; the first detection information is used for the server to count first-class alarm information or detect the first data to be measured; the first-class alarm information includes alarm information related to the first communication protocol; The gateway detects the second data to be measured, and when the second data to be measured is detected as abnormal, uploads second detection information to the server; the second detection information is used for the server to count second-class alarm information or detect the second data to be measured; the second-class alarm information includes alarm information related to the second communication protocol.

2. The method according to claim 1, characterized in that The gateway's detection of the first data to be measured includes: Detecting the first data to be measured through a first detection model to obtain a detection result; When the first data to be measured is detected as abnormal, uploading the first detection information to the server includes: In response to the detection result output by the first detection model including an attack type based on the first communication protocol, uploading the first detection information including the attack type based on the first communication protocol to the server, and the attack type based on the first communication protocol is used for the server to count the first-class alarm information; In response to the detection result output by the first detection model including no accurately matched attack type, uploading the first detection information including first information to be identified to the server, and the first information to be identified is used for the server to re-check the first data to be measured; the first information to be identified includes the first data to be measured and the context of the first data to be measured.

3. The method according to claim 2, wherein It further includes: The gateway, in response to an update instruction carrying model update parameters, updates the first detection model according to the model update parameters; the model update parameters include the model parameters of the first detection model.

4. The method according to claim 1, wherein The second data to be measured includes log data generated when communicating based on the second communication protocol; The gateway stores the correspondence between abnormal logs and abnormal types; the abnormal logs include abnormal logs generated when communicating based on the second communication protocol, and the abnormal types include attack types based on the second communication protocol and abnormal traffic behaviors based on the second communication protocol; The gateway's detection of the second data to be measured includes: The gateway determines the matching result of the second data to be measured according to the correspondence between the abnormal logs and the abnormal types; When the second data to be measured is detected as abnormal, uploading the second detection information to the server includes: In response to the matching result including an attack type based on the second communication protocol, upload second detection information including the attack type based on the second communication protocol to the server, where the attack type based on the second communication protocol is used for the server to count the second type of alarm information; In response to the matching result including abnormal traffic behavior based on the second communication protocol, upload second detection information including second information to be identified to the server, where the second information to be identified is used for the server to recheck the second data to be measured; the second information to be identified includes data packets generated by the terminal device during communication based on the second communication protocol.

5. The method according to claim 4, wherein It further includes: In response to an update instruction carrying rule update information, the gateway updates the correspondence between the abnormal log and the abnormal type according to the rule update information; the rule update information includes correction information on the correspondence between the abnormal log and the abnormal type or newly added correspondence between the abnormal log and the abnormal type.

6. A detection method, characterized in that, Applied to a server, the server has a communication connection with a terminal device, the terminal device includes a gateway and a controller, and the detection method includes: Receive detection information, where the detection information includes: first detection information and second detection information; the first detection information is the detection information uploaded by the gateway when the first data to be measured is detected abnormally; the first data to be measured includes communication data based on the first communication protocol collected by the gateway; the second detection information is the information uploaded by the gateway when detecting the second data to be measured and the second data to be measured is detected abnormally; the second data to be measured includes data generated during communication based on the second communication protocol in the controller collected by the controller; the data generated during communication based on the second communication protocol in the controller includes the second data to be measured; Count alarm information according to the detection information or recheck the detection information; the alarm information includes the first type of alarm information related to the first communication protocol or the second type of alarm information related to the second communication protocol.

7. The method according to claim 6, characterized in that, The server stores a communication matrix based on the first communication protocol, and the communication matrix is used to describe the legitimate communication data packets of the terminal device based on the first communication protocol; the first detection information includes first data to be identified, and the first information to be identified includes the first data to be measured and the context of the first data to be measured; Rechecking the first detection information includes: In response to the first data to be identified not matching any of the legitimate communication data packets in the communication matrix, output a first attack result, where the first attack result is used to characterize an attack on the terminal device based on the first communication protocol.

8. The method according to claim 6, characterized in that, The second detection information includes second information to be identified, and the second information to be identified includes data packets generated by the terminal device during communication based on the second communication protocol; The process of the detection system rechecking the second detection information includes: The detection system detects the second information to be identified through a second detection model to obtain a second attack result, and the second attack result is used to characterize the attack on the terminal device based on the second communication protocol.

9. The method according to claim 8, wherein The server stores threat intelligence information, and the threat intelligence information is used to describe the characteristics of attack data packets, and the attack data packets are used to conduct attacks based on the second communication protocol; The process of rechecking the second detection information further includes: Inputting the second information to be identified into the intelligence matching module to obtain a third attack result output by the intelligence matching module, and the third attack result is used to characterize the attack on the terminal device that matches the threat intelligence information.

10. The method according to claim 9, wherein It further includes: Outputting a recheck result of the second detection information according to the second attack result and the third attack result.

11. The method according to claim 6, characterized in that A terminal detection engine runs in the gateway, and the terminal detection engine detects the first data to be measured and the second data to be measured; The detection method further includes: Obtaining audit information, where the audit information includes audit information on the recheck result of rechecking the detection information; Generating an update instruction according to the audit information, and the update instruction is used to update the terminal detection engine.

12. A detection device, characterized in that, Applied to a vehicle, the detection device includes a memory and a processor, and the memory is used to store a computer program; The processor is configured to implement the detection method according to any one of claims 1 to 5 by running the computer program stored in the memory.

13. A detection device, characterized in that, Applied to a server, the detection device includes a memory and a processor, and the memory is used to store a computer program; The processor is configured to implement the detection method according to any one of claims 6 to 11 by running the computer program stored in the memory.

14. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the detection method according to any one of claims 1 to 11 is implemented.