Internet of vehicles safety judgment method and terminal
By establishing the correlation table of the attack chain and the risk value calculation in the Internet of Vehicles, the problem that traditional methods cannot globally analyze the security of the Internet of Vehicles is solved, and the identification and effective prevention of unknown risks are achieved.
Patent Information
- Application Number
- CN202311842298.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-07-08
AI Technical Summary
The prior art cannot comprehensively analyze the safety risks of the Internet of Vehicles from a global perspective, cannot identify unknown risks, and the traditional vehicle intrusion detection and defense system (IDPS) cannot adapt to the comprehensive risk analysis of heterogeneous data sources.
By extracting security feature data in the Internet of Vehicles, establishing a correlation table between attack behavior and security feature data, formulating an attack chain, and formulating risk values for each node, cumulative risk values for security alarms, and using a global judgment method.
It realizes the global judgment of the security of the Internet of Vehicles, can identify unknown attack risks, make up for the shortcomings of IDPS, simplifies the computing volume, and reduces the risk of misjudgment.
Smart Images

Figure CN120281489A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of the Internet of Things, and particularly to a method and a terminal for determining vehicle networking security. Background Art
[0002] The emergence of intelligent connected vehicles involves multiple levels such as the cloud and big data, resulting in a large number of network security risks, threatening the information security of the people and the country. Therefore, information security detection and protection at all levels of vehicle information security are required.
[0003] In the prior art, traditional in-vehicle IDPS (Intrusion Detection & Prevention System) is used for security determination. Its principle is to analyze by constructing a rule base to form a one-to-one matching relationship. However, it cannot comprehensively analyze and evaluate risks from a global perspective, and at the same time, it cannot identify unknown risks, making it unsuitable for comprehensive risk analysis of a large number of heterogeneous data sources (cloud, vehicle, user APP, etc.) in the future. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a method and a terminal for determining vehicle networking security, which trigger the determination of vehicle networking security from a global perspective and take into account the protection against unknown attacks.
[0005] To solve the above technical problem, the technical solution adopted by the present invention is as follows:
[0006] A method for determining vehicle networking security includes the steps of:
[0007] S1. Extract security feature data in the vehicle networking; when the node where the security feature data is located is attacked, some data fields of the security feature data can change;
[0008] S2. Establish an association table between attack behaviors and the security feature data in the corresponding attacked nodes;
[0009] S3. Draw up an attack chain affecting vehicle networking security according to the association table, and assign a risk value to the security feature data in each node of each attack chain. If the cumulative risk value in the attack chain exceeds a preset warning value, a security warning is issued.
[0010] To solve the above technical problem, another technical solution adopted by the present invention is as follows:
[0011] A vehicle networking security determination terminal includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are completed:
[0012] S1. Extract the security feature data in the vehicle networking. When the node where the security feature data is located is attacked, some data fields of the security feature data can change;
[0013] S2. Establish an association table between the attack behavior and the security feature data in the corresponding attacked node;
[0014] S3. Draw up an attack chain affecting the security of the vehicle networking according to the association table, and draw up a risk value for the security feature data in each node in each attack chain. If the cumulative risk value in the attack chain exceeds the preset warning value, a security warning is issued.
[0015] The beneficial effects of the present invention are as follows: A vehicle networking security determination method and a terminal are provided. By extracting the data fields (security feature data) that change when the nodes in the vehicle networking are attacked and associating them with the corresponding attack behaviors to form an association table, the data and corresponding behaviors with information security analysis significance are refined. Subsequently, an attack chain affecting the security of the vehicle networking is drawn up according to the association table, and a risk value is drawn up for the security feature data of each node in the chain. If this node is attacked, the security feature data will change, so as to determine the risk value of this node, and then the risk values of the entire attack chain are cumulatively calculated to determine the security of the vehicle networking from a global perspective, making up for the deficiencies of the IDPS scheme;
[0016] At the same time, since the risk values in multiple possible attack chains are drawn up and monitored, rather than matching each single node one by one, it is more conducive to preventing unknown attack risks. Brief Description of the Drawings
[0017] Figure 1 It is a flowchart in a vehicle networking security determination method in an embodiment of the present invention;
[0018] Figure 2 It is a specific flowchart in a vehicle networking security determination method in an embodiment of the present invention;
[0019] Figure 3 It is a schematic diagram of a vehicle networking security determination terminal in an embodiment of the present invention;
[0020] Label Description:
[0021] 1. A vehicle networking security determination terminal; 2. A memory; 3. A processor. Detailed Embodiments
[0022] To illustrate the technical content, the achieved objectives and the effects of the present invention in detail, the following is described in combination with the embodiments and in coordination with the drawings.
[0023] Please refer to Figure 1 and Figure 2, A vehicle networking security determination method, comprising the steps of:
[0024] S1. Extract security feature data in the vehicle networking; when the node where the security feature data is located is attacked, some data fields of the security feature data can change;
[0025] S2. Establish an association table between attack behaviors and the security feature data in the corresponding attacked nodes;
[0026] S3. Draw up an attack chain affecting the security of the vehicle networking according to the association table, and draw up a risk value for the security feature data in each node in each attack chain. If the cumulative value of the risk values in the attack chain exceeds a preset warning value, security warning is carried out.
[0027] As can be seen from the above description, the beneficial effects of the present invention are as follows: By extracting the data fields (security feature data) that change when the nodes in the vehicle networking are attacked, and associating them with the corresponding attack behaviors to form an association table, refining the data and corresponding behaviors with information security analysis significance. Subsequently, an attack chain affecting the security of the vehicle networking is drawn up according to the association table, and a risk value is drawn up for the security feature data of each node in the chain. If this node is attacked, the security feature data will change, so as to determine the risk value of this node, and then the risk values of the entire attack chain are cumulatively calculated, and the security of the vehicle networking is determined from a global perspective, making up for the deficiencies of the IDPS solution; at the same time, since the risk values in multiple possible attack chains are drawn up and monitored, rather than matching each single node one by one, it is more conducive to preventing unknown attack risks.
[0028] It should be noted that the attacked nodes of the vehicle networking include hardware, software, systems, applications, data, etc.; during the operation of the vehicle networking, malicious attacks on the nodes or user misoperations will affect the security feature data in the nodes and cause the security feature data to change. That is, malicious attacks or misoperations and other behaviors that cause the security feature data to change will be regarded as attack behaviors by the terminal. In order to avoid misjudgments of security caused by unintentional behaviors such as misoperations, in this example, the risk value of the entire attack chain is calculated and compared with the preset warning value. If the risk value of the entire attack chain exceeds the preset warning value, it is considered a malicious attack behavior to avoid misjudgments. At the same time, by monitoring each node from a global perspective through the drawn-up attack chain, it is possible to better cope with unknown risks.
[0029] In an embodiment of the present invention, the step S3 is specifically:
[0030] S31. Draw up an attack chain affecting the security of the vehicle networking according to the association table;
[0031] S32. Determine the risk value of each piece of the security feature data in each attack chain. If the node where the security feature data is located is not triggered, the risk value is regarded as 0;
[0032] If the node where the security feature data is located is normally triggered, the risk value is regarded as 1;
[0033] If the node where the security feature data is located is attacked, the risk value is regarded as a predefined value;
[0034] S33. Cumulatively calculate the risk values of all nodes in the attack chain. If the cumulative calculation result of the risk values exceeds the preset alarm value, a security alarm is issued.
[0035] As can be seen from the above description, in order to consider information security issues for the vehicle networking from a global perspective, first, all possible attack chains are determined through the above-mentioned association table, including the possible node paths to be attacked in various heterogeneous data sources (cloud, vehicle side, user APP, etc.). Subsequently, in order to judge the location of the attacked node and the activated attack chain, the judgment conditions of the risk value are set;
[0036] Specifically, if the node is not triggered, that is, not attacked or normally executed, the risk value of this node is regarded as 0; if the node is normally triggered, in some embodiments of the present invention, that is, the security feature data has not changed, the risk value is regarded as 1; if the node is attacked, that is, the security feature data has changed, the risk value is regarded as a predefined value; subsequently, in the activated attack chain, the risk values of each node are cumulatively calculated. If the cumulative calculation result of all nodes included in the entire attack chain exceeds the preset alarm value, it is regarded as being maliciously attacked and a security alarm is issued.
[0037] In an embodiment of the present invention, the step S32 further includes:
[0038] Obtain the normal trigger probability and the deviation trigger probability of each node within a preset period, and determine the normal value A and the deviation value B according to the normal trigger probability and the deviation trigger probability;
[0039] Set the normal trigger interval (A, x*B), where x is a preset fluctuation coefficient;
[0040] Calculate the trigger value of the node within a preset period. If the trigger value exceeds the normal trigger interval, the risk value is regarded as a predefined value; otherwise, the risk value is regarded as 1.
[0041] As can be seen from the above description, in order to avoid misjudgment and simplify the computing workload of the terminal, the normal trigger probability and deviation trigger probability of each node within a preset period are first obtained, where the deviation trigger is regarded as a trigger caused by user error or acceptable abnormal behavior, and normal values and deviation values are determined. A normal trigger range is set according to the normal values and deviation values, that is, a deviation behavior within the normal trigger range is also regarded as a normal trigger; among them, due to various influencing factors of the deviation value, the inventor has adjusted the model many times and set a preset fluctuation coefficient x. Preferably, the range of x is between 1.00 and 1.01; specifically preferably, x = 1.01.
[0042] Specific examples are as follows:
[0043] Taking the wireless key unlocking attack scenario as an example, the attacker may frequently unlock in various ways. If the number of incorrect unlocks within a unit time is too large, it is very likely a malicious attack behavior. Based on this scenario, the specific algorithm is as follows: Select a 1-week custom security time period, calculate the value of the number of failed unlocks per hour / 60 within this week. Under normal circumstances, the average value is zero or a value very close to zero, and this value is A. If under attack, for example, 2 or 3 unlock signal failure faults (possibly due to authentication failure, signal debugging, etc.) are detected within 1 hour, then this value is 2 / 60 or 3 / 60. After collecting multiple such abnormal values, the value with the largest deviation (assumed to be 3 / 60) is selected using the isolation forest algorithm, then B = 3 / 60. Then, we consider (A, 1.01B) to be the normal trigger range. If the specific trigger value C (number of failed unlocks per hour / 60) of this node is continuously collected subsequently, if it is greater than 1.01B, it indicates that an attack is very likely.
[0044] In the embodiment of the present invention, the step S33 is specifically:
[0045] Calculate the product of the risk values of all nodes in the attack chain within a preset period. If the product of the risk values exceeds the preset alarm value, a security alarm is issued.
[0046] As can be seen from the above description, since the weight ratios of different nodes in each attack chain are different, in order to conveniently reflect the risk value in the attack chain, the method of cumulative multiplication of the risk values of each node in the attack chain is adopted. Specific examples are as follows:
[0047] Taking the wireless key attack scenario as an example, if the attack successfully opens the car door in this scenario, the risk value of this node is regarded as a predefined value, which is regarded as 100 in this example. In the subsequent engine start scenario, if the engine and key authentication fail (the predefined value is 200), then the combined risk value is 100 * 200 = 20000. If the preset alarm value of this attack chain is 1000, then when the above two warning attacks occur simultaneously, they will enter the warning system for warning.
[0048] In this example, the risk accumulation of the non - attack path means that abnormal user behavior may still lead to an alarm. For example, abnormal data caused by abnormal user habits, such as restarting the car 10 times a day, which exceeds the normal trigger range, and the risk value is regarded as 100 (pre - defined value). However, if such abnormal data accumulates a lot (such as starting at midnight, frequently inserting USB, etc.) and the combined value reaches a certain level, it will still enter the alarm state.
[0049] In the embodiment of the present invention, before step S2, there is also step S20:
[0050] Standardize the security feature data from different sources in the vehicle - to - everything (V2X) network.
[0051] From the above description, it can be seen that due to the existence of different vehicle models, vehicle manufacturers and other data in the V2X network, there is a lot of noise data in the security feature data pointing to the same node. Standardizing such data is convenient for judgment. For example: for different data fields of different vehicle models and manufacturers, which are essentially fields related to information security, uniformly rename them to the same field data and store them separately as higher - quality data for subsequent steps of extraction. The specific application is as follows:
[0052] When different vehicle models record user login data, the user fields used can be "user", "user", and "in - vehicle computer account". These different names are essentially login user names and can be classified and integrated into one category name (such as custom - defined as login user).
[0053] A vehicle - to - everything (V2X) network security judgment terminal includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the above steps are completed.
[0054] From the above description, it can be seen that providing an execution carrier for the above - mentioned vehicle - to - everything (V2X) network security judgment method, when executing the steps in the vehicle - to - everything (V2X) network security judgment method, by extracting the data fields (security feature data) that change when a node in the vehicle - to - everything (V2X) network is attacked and associating them with the corresponding attack behaviors to form an association table, refining the data and corresponding behaviors with information security analysis significance, then formulating an attack chain affecting the vehicle - to - everything (V2X) network security according to the association table, and formulating a risk value for the security feature data of each node in the chain. If this node is attacked, the security feature data will change, thereby determining the risk value of this node, and then cumulatively calculating the risk value of the entire attack chain to conduct vehicle - to - everything (V2X) network security judgment from a global perspective, making up for the deficiencies of the IDPS solution; at the same time, since the risk values in multiple possible attack chains are formulated and monitored, rather than matching each single node one by one, it is more conducive to preventing unknown attack risks.
[0055] A method and a terminal for determining vehicle networking security provided by the present invention are mainly applied to the guarantee of vehicle networking information security, and will be specifically described below with reference to embodiments:
[0056] Please refer to Figures 1 to 2 , Embodiment 1 of the present invention is as follows:
[0057] A method for determining vehicle networking security includes the steps of:
[0058] S1. Extract security feature data in the vehicle networking; when the node where the security feature data is located is attacked, some data fields of the security feature data can change;
[0059] S2. Establish an association table between attack behaviors and the security feature data in the corresponding attacked nodes;
[0060] S3. Draw up an attack chain affecting vehicle networking security according to the association table, and assign a risk value to the security feature data in each node of each attack chain. If the cumulative risk value in the attack chain exceeds a preset warning value, a security warning is issued.
[0061] That is, in this embodiment, by extracting the data fields (security feature data) that change when the nodes in the vehicle networking are attacked and associating them with the corresponding attack behaviors to form an association table, data and corresponding behaviors with information security analysis significance are refined. Subsequently, an attack chain affecting vehicle networking security is drawn up according to the association table, and a risk value is assigned to the security feature data of each node in the chain. If this node is attacked, the security feature data will change, so as to determine the risk value of this node, and then the risk values of the entire attack chain are calculated cumulatively, and vehicle networking security is determined from a global perspective to make up for the deficiencies of the IDPS scheme; at the same time, since the risk values in multiple possible attack chains are drawn up and monitored, rather than matching each single node one by one, it is more conducive to preventing unknown attack risks.
[0062] Please refer to Figures 1 to 2 , Embodiment 2 of the present invention is as follows:
[0063] Based on Embodiment 1, the step S3 is specifically as follows:
[0064] S31. Draw up an attack chain affecting vehicle networking security according to the association table;
[0065] S32. Assign a risk value to each security feature data in each attack chain. If the node where the security feature data is located is not triggered, the risk value is regarded as 0;
[0066] If the node where the security feature data is located is normally triggered, the risk value is regarded as 1;
[0067] When the node where the security feature data is located is attacked, the risk value is regarded as a predefined value;
[0068] S33. Cumulatively calculate the risk values of all nodes in the attack chain. If the cumulative calculation result of the risk values exceeds the preset alarm value, a security alarm is issued.
[0069] Specifically, if a node is not triggered, that is, not attacked or executed normally, the risk value of this node is regarded as 0; if a node is normally triggered, in some embodiments of the present invention, that is, the security feature data has not changed, the risk value is regarded as 1; if a node is attacked, that is, the security feature data has changed, the risk value is regarded as a predefined value; subsequently, in the activated attack chain, the risk values of each node are cumulatively calculated. If the cumulative calculation result of all nodes included in the entire attack chain exceeds the preset alarm value, it is regarded as being maliciously attacked and a security alarm is issued.
[0070] The step S32 further includes:
[0071] Obtain the normal trigger probability and deviation trigger probability of each node within a preset period, and formulate a normal value A and a deviation value B according to the normal trigger probability and deviation trigger probability;
[0072] Set a normal trigger interval (A, x*B), where x is a preset fluctuation coefficient;
[0073] Calculate the trigger value of the node within a preset period. If the trigger value exceeds the normal trigger interval, the risk value is regarded as a predefined value; otherwise, the risk value is regarded as 1.
[0074] The step S33 is specifically:
[0075] Perform a product calculation on the risk values of all nodes in the attack chain within a preset period. If the product of the risk values exceeds the preset alarm value, a security alarm is issued.
[0076] That is, in this embodiment, in order to avoid misjudgment and simplify the computing amount of the terminal, first obtain the normal trigger probability and deviation trigger probability of each node within a preset period, where the deviation trigger is regarded as the trigger caused by user error or acceptable abnormal behavior, and formulate the normal value and deviation value. Set the normal trigger interval according to the normal value and deviation value, that is, the deviation behavior in the normal trigger area is also regarded as a normal trigger; among them, due to various influencing factors of the deviation value, the inventor has adjusted the model many times and set the preset fluctuation coefficient x. Preferably, x = 1.01; at the same time, since the weight ratios of different nodes in each attack chain are different, in order to conveniently reflect the risk value in the attack chain, the method of cumulative product of the risk values of each node in the attack chain is used for calculation.
[0077] Please refer to Figures 1 to 2, Embodiment 3 of the present invention is as follows:
[0078] Based on Embodiment 1, before step S2, step S20 is further included:
[0079] Normalize the security feature data from different sources in the vehicle networking.
[0080] As can be seen from the above description, due to the existence of different vehicle models, vehicle manufacturers and other data in the vehicle networking, there is a lot of noise data in the security feature data pointing to the same node. Normalizing such data is convenient for judgment. For example: for different data fields of different vehicle models and vehicle manufacturers, which are essentially fields related to information security, they are uniformly renamed to the same field data and stored separately as higher-quality data for subsequent steps of extraction. The specific application is as follows:
[0081] When different vehicle models record user login data, the user fields used can be "user", "user", and "in-vehicle computer account". These different names are essentially login user names and can be classified and integrated into one category name (such as custom-defined as logged-in user).
[0082] Please refer to Figures 1 to 2 , Embodiment 4 of the present invention is as follows:
[0083] A vehicle networking security determination method is specifically executed as follows:
[0084] First, based on the analysis of vehicle Tara and understanding of information security attacks, list all possible attacked nodes of the vehicle (hardware, software, system, application, data, etc.).
[0085] Secondly, according to the fact that a certain data field will change when the attacked node is attacked, establish an association table of the mapping relationship between vehicle information security attacks and data fields. Specifically, by building an interface middleware for the existing database, read the data in a certain time interval of this field into the new table field according to the mapping table. Similarly, for other data sources, such as log libraries, diagnostic systems, etc., data collection middleware can be built to extract fields with information security analysis significance into the new table field.
[0086] Then, establish a data preprocessing module, mainly realizing data cleaning work such as synonymous classification and integration, format unification, and abnormal data deletion for the data in the association table. Finally, store the information security field data from different data sources separately as higher-quality data for subsequent steps of extraction. The specific steps are: for different data fields of different vehicle models and vehicle manufacturers, which are essentially fields related to information security, they are uniformly renamed to the same field data for subsequent analysis.
[0087] After that, a risk analysis AI model is established, specifically: using the vulnerabilities in the vehicle information security attack chain or passing through the physical software and hardware system nodes, a model with a large number of parameters is established. The parameters processed by this model are the vulnerabilities involved in all possible attack chains, and corresponding risk values are defined. When a certain parameter is not triggered, the risk value is zero; when it is normally triggered, the risk value is 1; when it is attacked, it is a predefined value.
[0088] The details of the model are as follows: Since most vehicles are safe most of the time, multiple physical vehicles of this type of vehicle model are used to generate normal values and deviation values. Specifically, a custom security time period is defined, the data average value is set to A, and a type of data with a large deviation (the value can be customized, or the data with the largest deviation can be screened out using the isolation forest algorithm) is defined as B. The interval (A, 1.01B) is the non-alarm interval, that is, the normal trigger interval, and an alarm will be activated outside this interval. At this time, the interval (A, 1.01B) will be used as one of the historical record values of a certain parameter C (trigger value) of the corresponding analysis model of this data. If the data of parameter C received at a certain time later exceeds (A, 1.01B), the data of parameter C will change from 1 to a predefined value.
[0089] Subsequently, within a specific time interval (which can be defined by oneself as months, days, hours, etc.), if the alarm value exceeds a certain high value when the model runs, alarm processing will be carried out; if it does not reach this value, it means that the data in this time period does not prove a high risk, which may be a user's accidental touch or signal debugging, and it can be directly discarded.
[0090] Please refer to Figure 3 In the fifth embodiment of the present invention: A vehicle networking security determination terminal 1 includes a memory 2, a processor 3, and a computer program stored on the memory 2 and operable on the processor 3. When the processor 3 executes the computer program, the steps in any one of the vehicle networking security determination methods in the above-mentioned Embodiments 1 to 4 are completed.
[0091] Preferably, the terminal includes a data collection module, a data preprocessing module, a data analysis and modeling module, and a data alarm and display module. The main functions of each module are as follows:
[0092] Data collection module: Establish an interface module middleware suitable for different data sources (databases, logs, alarms, etc.), clean and screen out irrelevant data, and execute data extraction strategies to improve the quality of data collection related to vehicle information security.
[0093] Data preprocessing module: Preprocess data of different types and meanings and convert it into data that can be analyzed by the data analysis module.
[0094] Data analysis module: By establishing an AI model with a large number of parameters, it conducts a risk assessment at the information security level on the input data, obtains the overall risk values of individual and group vehicles, and discloses the attack situations that the evaluated object has suffered as a whole at a specific time through the risk values.
[0095] Data alarm and display module: Adjusts and classifies the results of the data analysis module, and defines and outputs the alarm display forms.
[0096] In summary, a vehicle networking security determination method and terminal provided by the present invention define and associate data values related to vehicle networking security, and use AI algorithms to quickly analyze data deviations caused by network security threats and attacks, can accurately locate known vehicle network security attacks, and at the same time can detect unknown threats and attacks, filling the blank of security detection in the vehicle networking big data method, making up for the deficiencies of the IDPS scheme, and setting a leading example for the cloud big data security analysis of vehicle networking V2X and APP security. This solution covers all intelligent connected vehicle models of automobile manufacturers on a large scale at a relatively low cost, greatly reducing the security compliance cost of manufacturers.
[0097] The above are only embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. All equivalent transformations made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in related technical fields, are equally included in the patent protection scope of the present invention.
Claims
1. A vehicle networking security determination method, characterized in that: Including the steps: S1. Extract security feature data in the vehicle networking; when the node where the security feature data is located is attacked, some data fields of the security feature data can change; S2. Establish an association table between attack behaviors and the security feature data in the corresponding attacked nodes; S3. Draw up an attack chain affecting the security of the vehicle networking according to the association table, and draw up a risk value for the security feature data in each node in each attack chain. If the cumulative value of the risk values in the attack chain exceeds a preset warning value, security warning is carried out.
2. The vehicle networking security determination method according to claim 1, characterized in that: The specific step S3 is as follows: S31. Draw up an attack chain affecting the security of the vehicle networking according to the association table; S32. Draw up a risk value for each security feature data in each attack chain. If the node where the security feature data is located is not triggered, the risk value is regarded as 0; If the node where the security feature data is located is normally triggered, the risk value is regarded as 1; If the node where the security feature data is located is attacked, the risk value is regarded as a predefined value; S33. Carry out cumulative calculation on the risk values of all nodes in the attack chain. If the cumulative calculation result of the risk values exceeds a preset warning value, security warning is carried out.
3. The vehicle networking security determination method according to claim 2, characterized in that: The step S32 further includes: Obtain the normal trigger probability and deviation trigger probability of each node within a preset period, and draw up a normal value A and a deviation value B according to the normal trigger probability and deviation trigger probability; Set a normal trigger interval (A, x*B), where x is a preset fluctuation coefficient; Calculate the trigger value of the node within a preset period. If the trigger value exceeds the normal trigger interval, the risk value is regarded as a predefined value; otherwise, the risk value is regarded as 1.
4. The vehicle networking security determination method according to claim 2, wherein: The specific step S33 is as follows: Carry out product calculation on the risk values of all nodes in the attack chain within a preset period. If the product of the risk values exceeds a preset warning value, security warning is carried out.
5. A vehicle networking security determination method according to claim 1, characterized in that: Before the step S2, there is also a step S20: Standardize the security feature data from different sources in the vehicle networking.
6. A vehicle networking security determination terminal, characterized in that: Including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are completed: S1. Extract security feature data in the vehicle networking; when the node where the security feature data is located is attacked, some data fields of the security feature data can change; S2. Establish an association table between attack behaviors and the security feature data in the corresponding attacked nodes; S3. Draw up an attack chain affecting the security of the vehicle networking according to the association table, and draw up a risk value for the security feature data in each node in each attack chain. If the cumulative value of the risk values in the attack chain exceeds a preset warning value, security warning is carried out.
7. The vehicle networking security determination terminal according to claim 6, wherein: The specific step S3 is as follows: S31. Draw up an attack chain affecting the security of the vehicle networking according to the association table; S32. Draw up a risk value for each security feature data in each attack chain. If the node where the security feature data is located is not triggered, the risk value is regarded as 0; If the node where the security feature data is located is normally triggered, the risk value is regarded as 1; When the node where the security feature data is located is attacked, the risk value is regarded as a predefined value; S33. Cumulatively calculate the risk values of all nodes in the attack chain. If the cumulative calculation result of the risk values exceeds the preset alarm value, a security alarm is issued.
8. The vehicle networking security determination terminal according to claim 7, characterized in that: The step S32 further includes: Obtain the normal trigger probability and the deviation trigger probability of each node within a preset period, and formulate a normal value A and a deviation value B according to the normal trigger probability and the deviation trigger probability; Set a normal trigger interval (A, x*B), where x is a preset fluctuation coefficient; Calculate the trigger value of the node within a preset period. If the trigger value exceeds the normal trigger interval, the risk value is regarded as a predefined value; otherwise, the risk value is regarded as 1.
9. The vehicle networking security determination terminal according to claim 7, wherein: The step S33 is specifically: Perform a product calculation on the risk values of all nodes in the attack chain within a preset period. If the product of the risk values exceeds the preset alarm value, a security alarm is issued.
10. The vehicle networking security determination terminal according to claim 6, characterized in that: Before the step S2, there is also a step S20: Unify the security feature data from different sources in the vehicle networking.