Vehicle-mounted terminal vulnerability detection method, device and equipment and storage medium
By using ADB connection and vulnerability database comparison method in the Internet of Vehicles environment, the problem of low vulnerability recognition rate in the on-board terminal is solved, and efficient and accurate vulnerability detection is achieved.
Patent Information
- Application Number
- CN202510700477.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-07-29
AI Technical Summary
The prior art is difficult to accurately identify the equipment information of the on-board terminals in the environment of the Internet of Vehicles, resulting in a significant reduction in the vulnerability identification effect, especially in firewalls or communication scenarios that cannot be effectively vulnerability scanning.
By establishing an ADB connection between the on-board terminal and the vulnerability detection device, using ADB instructions to obtain the on-board terminal information, and comparing the features with the vulnerability database, obtaining the operating system, system kernel version and application software information, and combining the vulnerability script verification library to simulate the attack to determine the real existence of the vulnerability.
It improves the vulnerability identification rate, shortens the detection time, and ensures the accuracy of vulnerability detection results, avoiding inconsistencies in the results caused by differences in the level of detectors.
Smart Images

Figure CN120389901A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular, to a method, device, equipment and storage medium for detecting vulnerabilities of in-vehicle terminals. Background Art
[0002] For Internet of Things devices, conventional vulnerability scanning is mainly based on transport layer protocols to remotely scan the target, identify information through the open ports of the target, and the target objects of scanning mainly focus on IT devices such as servers, PCs, and personal laptops.
[0003] In the context of vehicle networking security, in-vehicle terminals mainly use WIFI, Bluetooth, cellular networks, etc. for communication. The operating systems of these devices are mainly Android systems, and the exposed ports are few. Conventional vulnerability scanning is to perform network vulnerability scanning through methods such as wifi / ethernet. However, when the device under test is in scenarios such as a firewall (denying external communication) or a non-communication scenario design (such as an in-vehicle ECU without wifi or ethernet function), normal network vulnerability scanning cannot be carried out properly. Moreover, conventional vulnerability scanning only performs message communication through transport layer protocols and cannot log in to the internal of the test device to view version permissions, file interaction, etc. Conventional vulnerability scanning technology is difficult to accurately identify its device information, and too little information collected will also greatly reduce the effect of vulnerability identification. Therefore, new security scanning technology is needed to solve the problems of identifying and discovering vulnerabilities of vehicle networking devices.
[0004] Therefore, how to obtain more information about the vehicle terminal under test to improve the vulnerability identification rate is a technical problem that needs to be solved urgently at present. Summary of the Invention
[0005] The main purpose of the present invention is to provide a method, device, equipment and storage medium for detecting vulnerabilities of in-vehicle terminals, which can improve the vulnerability identification rate, not only shorten the detection time, but also ensure the accuracy of the vulnerability detection result.
[0006] In a first aspect, the present application provides a method for detecting vulnerabilities of in-vehicle terminals, and the method includes the steps of:
[0007] Establish an ADB connection relationship between the in-vehicle terminal and the vulnerability detection device;
[0008] Based on the ADB connection relationship, obtain the required in-vehicle terminal information according to ADB instructions, and compare the characteristics of the in-vehicle terminal information with a vulnerability database to detect vulnerabilities of the in-vehicle terminal.
[0009] Combined with the above first aspect, as an optional implementation, establish an ADB connection between the in-vehicle terminal and the vulnerability detection device by using a wired or wireless method, so that the in-vehicle terminal enters the developer option settings to obtain multiple in-vehicle terminal information.
[0010] In combination with the first aspect described above, as an alternative implementation, use ADB commands to verify whether the vehicle-mounted terminal and the vulnerability detection device have successfully established a connection.
[0011] In combination with the first aspect described above, as an alternative implementation, obtain the ROOT permission of the vehicle-mounted terminal, and use the vulnerability detection device to send ADB commands to the vehicle-mounted terminal to obtain the required vehicle-mounted terminal information, where the vehicle-mounted terminal information includes: operating system information, system kernel version, and operation instructions for application software information;
[0012] According to the ADB commands received from the vulnerability detection device, feedback the corresponding information to the vulnerability detection device;
[0013] Based on the information fed back by the vehicle-mounted terminal, search for vulnerabilities matching the fed-back information in the set vulnerability database to determine the type and level of the vulnerabilities.
[0014] In combination with the first aspect described above, as an alternative implementation, based on the corresponding vulnerability script verification library stored in the vulnerability database, use the vulnerability scripts in the vulnerability script verification library to simulate attacks on the detected vulnerabilities to determine whether the vulnerabilities actually exist.
[0015] In combination with the first aspect described above, as an alternative implementation, synchronously update the vulnerability database within a preset period.
[0016] In a second aspect, the present application provides a vehicle-mounted terminal vulnerability detection device, which includes:
[0017] An establishment module, which is used to establish an ADB connection relationship between the vehicle-mounted terminal and the vulnerability detection device;
[0018] A processing module, which is used to, based on the ADB connection relationship, obtain the required vehicle-mounted terminal information according to ADB commands, and compare the features of the vehicle-mounted terminal information with the vulnerability database to detect vulnerabilities of the vehicle-mounted terminal.
[0019] In combination with the second aspect described above, as an alternative implementation, the establishment module is further used to establish an ADB connection between the vehicle-mounted terminal and the vulnerability detection device by using a wired or wireless method, so that the vehicle-mounted terminal enters the developer option settings to obtain multiple pieces of vehicle-mounted terminal information.
[0020] In a third aspect, the present application further provides an electronic device, which includes: a processor; a memory, on which computer-readable instructions are stored, and when the computer-readable instructions are executed by the processor, the method described in any item of the first aspect is implemented.
[0021] Fourthly, the present application also provides a computer-readable storage medium storing computer program instructions, which, when executed by a computer, cause the computer to execute the method according to any one of the first aspect.
[0022] A vehicle-mounted terminal vulnerability detection method, device, equipment and storage medium provided by the present application, wherein the method includes the steps of: establishing an ADB connection relationship between the vehicle-mounted terminal and the vulnerability detection device; based on the ADB connection relationship, obtaining the required vehicle-mounted terminal information according to ADB instructions, and comparing the characteristics of the vehicle-mounted terminal information with a vulnerability database to detect vulnerabilities of the vehicle-mounted terminal. The present application can improve the recognition rate of vulnerabilities, not only shorten the detection time, but also ensure the accuracy of the vulnerability detection result.
[0023] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present invention, and are used together with the specification to explain the principles of the present invention.
[0025] Figure 1 It is a flowchart of a vehicle-mounted terminal vulnerability detection method provided in an embodiment of the present application;
[0026] Figure 2 It is a schematic diagram of a vehicle-mounted terminal vulnerability detection device provided in an embodiment of the present application;
[0027] Figure 3 It is a schematic diagram of an electronic device provided in an embodiment of the present application;
[0028] Figure 4 It is a schematic diagram of a computer-readable program medium provided in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] Here, an exemplary embodiment will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.
[0030] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities.
[0031] The embodiments of the present application will be further described in detail below with reference to the accompanying drawings.
[0032] Referring to Figure 1 , Figure 1 The following is a flowchart of a method for detecting vulnerabilities in a vehicle-mounted terminal provided by the present invention. As Figure 1 shown, the method includes the steps:
[0033] Step S101: Establish an ADB connection relationship between the vehicle-mounted terminal and the vulnerability detection device.
[0034] Specifically, use a wired or wireless method to establish an ADB connection between the vehicle-mounted terminal and the vulnerability detection device, so that the vehicle-mounted terminal enters the developer option settings to obtain multiple vehicle-mounted terminal information.
[0035] In one embodiment, use ADB commands to verify whether the vehicle-mounted terminal and the vulnerability detection device are successfully connected.
[0036] For easy understanding, an example is given. Use USB to establish an ADB connection between the vehicle-mounted terminal and the vulnerability scanning tool. Enter the developer option settings for the vehicle-mounted terminal, start the USB debugging mode. After the settings are completed and the USB connection is made, you can check whether the vehicle-mounted terminal is recognized through the device manager, and use ADB commands to confirm that the vehicle-mounted terminal has been connected. For example, run the adb devices command from the android_sdk / platform-tools / directory to verify whether the connection is successful. For example, after the sample is connected to the test device via a USB cable and the adb devices command is run, a reply with the device name will pop up. At this time, after running adb shell, if the main device name and path of the command line become the test device after running, the connection is successful.
[0037] Optionally, use the WLAN method to establish an ADB connection between the vehicle-mounted terminal and the vulnerability scanning tool. First, connect the vehicle-mounted terminal and the vulnerability scanning tool to the same wireless network. Enter the developer option settings for the vehicle-mounted terminal, start the WLAN debugging mode and complete the pairing. This method can establish a connection and perform vulnerability scanning remotely, thus avoiding common USB connection problems (such as problems with driver installation). It should be noted that conventional vulnerability scanning can only identify the device version information and the list of open ports through the port, but this method can obtain more vehicle-mounted terminal information after entering its system and obtaining root privileges through adb scanning.
[0038] ADB (Android Debug Bridge) is a debugging tool for Android. On the computer side, this tool can be used to connect to devices running the Android system to perform a series of operations, such as installing packages, running debug commands, and controlling the system, etc.
[0039] Step S102: Based on the ADB connection relationship, obtain the required in-vehicle terminal information according to ADB instructions, and compare the characteristics of the in-vehicle terminal information with the vulnerability database to detect vulnerabilities in the in-vehicle terminal.
[0040] Specifically, obtain the ROOT permission of the in-vehicle terminal, and use the vulnerability detection device to send ADB commands to the in-vehicle terminal to obtain the required in-vehicle terminal information. The in-vehicle terminal information includes: operating system information, system kernel version, and operation instructions for application software information;
[0041] According to the ADB instructions received from the vulnerability detection device, feedback the corresponding information to the vulnerability detection device;
[0042] According to the information fed back by the in-vehicle terminal, search for vulnerabilities matching the fed-back information in the set vulnerability database, and generate a vulnerability list to determine the type and level of the vulnerabilities.
[0043] For easy understanding, an example is given. Through ADB scanning, after entering its system and obtaining root privileges, information such as version patches, selinux status, architecture, and SDK version can be obtained. The vulnerable device sends an ADB request command to the in-vehicle terminal to query device information. This instruction includes operation instructions for obtaining the operating system information, system kernel version, and application software information of the in-vehicle terminal. The vulnerable device receives the device information fed back by the in-vehicle terminal, which includes: the returned operating system information covers the system version, patches, SDK version, and developer manufacturers; the returned system kernel information is the system kernel version; the returned application software information covers the software name and version. According to the information fed back by the in-vehicle terminal, look for vulnerabilities in the set vulnerability database that match the fed-back information to determine the type and level of the vulnerability. For example, after adb vulnerability scanning, corresponding scanning result information will be obtained. The scanning result is compared with the vulnerability database in the scanning platform for feature recognition to determine the type, level, etc. of the vulnerability. Assume: For a linux device, after scanning with ADB, the following results are obtained: There is an unpatched security vulnerability on the device, which allows remote attackers to obtain sensitive information of the device through specific network requests. Compare the current scanning result with the local vulnerability database and look for vulnerabilities in the local vulnerability database that match this description. Assume that a vulnerability named "CVE-XXXX-YYYY" is found, whose description is the same as or similar to the description in the scanning result, and the affected range includes our device model and operating system version. Therefore, it can be determined that the device has the "CVE-XXXX-YYYY" vulnerability, and corresponding repair measures are proposed, such as updating system patches, disabling relevant services, etc.
[0044] In one embodiment, based on the ADB connection relationship, after obtaining in-vehicle terminal information and comparing the in-vehicle terminal information with the vulnerability database for feature comparison to detect vulnerabilities in the in-vehicle terminal, it includes: Based on the corresponding vulnerability script verification library stored in the vulnerability database, use the vulnerability scripts in the vulnerability script verification library to simulate attacks on the detected vulnerabilities to determine whether the vulnerabilities actually exist. It can be understood that after determining the vulnerability number and type according to the scanning result, there is a corresponding vulnerability poc script verification library synchronously stored in the vulnerability database. There are corresponding reproducible and operable attack scripts in the verification library. After scanning out a vulnerability, the corresponding poc verification script can be sent immediately. If the problem is successfully reproduced after verification, it can be determined that the vulnerability actually exists.
[0045] In one embodiment, within a preset period, the vulnerability database is synchronously updated. It can be understood that to ensure the comprehensiveness of the vulnerability database module, this module is compatible with authoritative vulnerability databases such as CVE, CNVD, and CNNVD and is updated regularly; it supports the import of vulnerabilities related to in-vehicle terminals.
[0046] In summary, the present application not only realizes the vulnerability detection of the in-vehicle terminal, but also quickly locates potential vulnerabilities and verifies the existence of vulnerabilities based on the collection of vulnerability information and the simulated attack of vulnerability scripts. It not only shortens the detection time, but also ensures the accuracy of the detection results, and will not affect the consistency of the detection results due to the level of the detection personnel.
[0047] Referring to Figure 2 , Figure 2 The figure shows a schematic diagram of a device for detecting vulnerabilities in an in-vehicle terminal provided by the present invention. As Figure 2 shown, the device includes:
[0048] Establishment module 201: It is used to establish an ADB connection relationship between the in-vehicle terminal and the vulnerability detection device.
[0049] Processing module 202: It is used to obtain the required in-vehicle terminal information according to the ADB instruction based on the ADB connection relationship, and compare the characteristics of the in-vehicle terminal information with the vulnerability database to detect the vulnerabilities of the in-vehicle terminal.
[0050] Further, in a possible implementation manner, the establishment module is further used to establish an ADB connection between the in-vehicle terminal and the vulnerability detection device in a wired or wireless manner, so that the in-vehicle terminal enters the developer option settings to obtain multiple in-vehicle terminal information.
[0051] Further, in a possible implementation manner, the processing module is further used to verify whether the in-vehicle terminal and the vulnerability detection device are successfully connected by using the ADB instruction.
[0052] Further, in a possible implementation manner, the processing module is further used to obtain the ROOT permission of the in-vehicle terminal and send an ADB command to the in-vehicle terminal by using the vulnerability detection device to obtain the required in-vehicle terminal information. The in-vehicle terminal information includes: operating system information, system kernel version, and operation instructions of application software information;
[0053] According to the received ADB instruction sent by the vulnerability detection device, the corresponding information is fed back to the vulnerability detection device;
[0054] According to the information fed back by the in-vehicle terminal, look up the vulnerabilities matching the fed-back information in the set vulnerability database to determine the type and level of the vulnerabilities.
[0055] Further, in a possible implementation manner, the processing module is further used to simulate an attack on the detected vulnerabilities by using the vulnerability scripts in the corresponding vulnerability script verification library stored in the vulnerability database to determine whether the vulnerabilities actually exist.
[0056] Further, in a possible implementation, the processing module is further configured to synchronously update the vulnerability database within a preset period.
[0057] The following refers to Figure 3 to describe the electronic device 300 according to this implementation of the present invention. Figure 3 The shown electronic device 300 is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention.
[0058] As Figure 3 shown, the electronic device 300 is presented in the form of a general computing device. The components of the electronic device 300 may include but are not limited to: the at least one processing unit 310 described above, the at least one storage unit 320 described above, and a bus 330 connecting different system components (including the storage unit 320 and the processing unit 310).
[0059] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 310, so that the processing unit 310 executes the steps according to various exemplary embodiments of the present invention described in the "Embodiment Method" section of this specification.
[0060] [[ID=18]]The storage unit 320 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 321 and / or a cache storage unit 322, and may further include a read-only storage unit (ROM) 323.
[0061] The storage unit 320 may further include a program / utility 324 having a set (at least one) of program modules 325. Such program modules 325 include but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.
[0062] The bus 330 may represent one or more of several types of bus structures, including a storage unit bus or a storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any bus structure in a variety of bus structures.
[0063] The electronic device 300 can also communicate with one or more external devices (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 300, and / or communicate with any device that enables the electronic device 300 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 350. Moreover, the electronic device 300 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 360. As shown in the figure, the network adapter 360 communicates with other modules of the electronic device 300 through the bus 330. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 300, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0064] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or can be implemented by the way of software combined with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, and the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.
[0065] According to the solution of the present disclosure, there is also provided a computer-readable storage medium, on which a program product capable of implementing the above method of this specification is stored. In some possible embodiments, various aspects of the present invention can also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to enable the terminal device to execute the steps according to various exemplary embodiments of the present invention described in the above "Exemplary Method" section of this specification.
[0066] Reference Figure 4 As shown, a program product 400 for implementing the above method according to an embodiment of the present invention is described. It can adopt a portable compact disc read-only memory (CD-ROM) and include program code, and can run on a terminal device, such as a personal computer. However, the program product of the present invention is not limited thereto. In this document, the readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device.
[0067] The program product may employ any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples of the readable storage medium (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0068] A computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal may take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable signal medium may also be any readable medium other than a readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.
[0069] The program code contained on the readable medium may be transmitted with any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0070] The program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).
[0071] In addition, the above-mentioned drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present invention, rather than for limiting purposes. It is easy to understand that the processes shown in the above-mentioned drawings do not indicate or limit the chronological order of these processes. Additionally, it is also easy to understand that these processes may be executed, for example, synchronously or asynchronously in multiple modules.
[0072] The above are only specific embodiments of the present application, enabling those skilled in the art to understand or implement the present application. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown herein, but rather will be accorded the widest scope consistent with the principles and novel features claimed herein.
[0073] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device generate means for implementing the functions specified in Figure 1 one or more of the flows or multiple flows and / or blocks Figure 1 one or more of the blocks or multiple blocks.
Claims
1. A vehicle terminal vulnerability detection method, characterized in that, Including: Establish an ADB connection relationship between the in-vehicle terminal and the vulnerability detection device; Based on the ADB connection relationship, obtain the required in-vehicle terminal information according to the ADB instruction, and compare the characteristics of the in-vehicle terminal information with the vulnerability database to detect the vulnerabilities of the in-vehicle terminal.
2. The method according to claim 1, wherein The establishing an ADB connection relationship between the in-vehicle terminal and the vulnerability detection device includes: Establish an ADB connection between the in-vehicle terminal and the vulnerability detection device by using a wired or wireless method, so that the in-vehicle terminal enters the developer option settings to obtain multiple in-vehicle terminal information.
3. The method according to claim 2, characterized in that, It also includes: Use the ADB instruction to verify whether the in-vehicle terminal and the vulnerability detection device are successfully connected.
4. The method according to claim 1, characterized in that, The based on the ADB connection relationship, obtaining the required in-vehicle terminal information according to the ADB instruction, and comparing the characteristics of the in-vehicle terminal information with the vulnerability database to detect the vulnerabilities of the in-vehicle terminal includes: Obtain the ROOT permission of the in-vehicle terminal, and use the vulnerability detection device to send an ADB command to the in-vehicle terminal to obtain the required in-vehicle terminal information, where the in-vehicle terminal information includes: operating system information, system kernel version, and operation instructions of application software information; According to the received ADB instruction sent by the vulnerability detection device, feedback the corresponding information to the vulnerability detection device; According to the information fed back by the in-vehicle terminal, search for vulnerabilities matching the fed-back information in the set vulnerability database to determine the type and level of the vulnerabilities.
5. The method according to claim 1, wherein, After the based on the ADB connection relationship, obtaining the in-vehicle terminal information, and comparing the characteristics of the in-vehicle terminal information with the vulnerability database to detect the vulnerabilities of the in-vehicle terminal, it includes: Based on the corresponding vulnerability script verification library stored in the vulnerability database, use the vulnerability scripts in the vulnerability script verification library to simulate an attack on the detected vulnerabilities to determine whether the vulnerabilities really exist.
6. The method according to claim 1, characterized in that, It also includes: Synchronously update the vulnerability database within a preset period.
7. An in-vehicle terminal vulnerability detection device, characterized in that, Including: A establishing module, which is used to establish an ADB connection relationship between the in-vehicle terminal and the vulnerability detection device; A processing module, which is used to based on the ADB connection relationship, obtain the required in-vehicle terminal information according to the ADB instruction, and compare the characteristics of the in-vehicle terminal information with the vulnerability database to detect the vulnerabilities of the in-vehicle terminal.
8. The device according to claim 7, wherein: The establishing module is further used to establish an ADB connection between the in-vehicle terminal and the vulnerability detection device by using a wired or wireless method, so that the in-vehicle terminal enters the developer option settings to obtain multiple in-vehicle terminal information.
9. An electronic device, characterized in that, The electronic device includes: A processor; A memory, on which computer-readable instructions are stored, and when the computer-readable instructions are executed by the processor, the method described in any one of claims 1 to 6 is implemented.
10. A computer-readable storage medium, characterized in that, It stores computer program instructions, and when the computer program instructions are executed by a computer, the computer is made to execute the method described in any one of claims 1 to 6.
Citation Information
Cited By
Internet-of-vehicles equipment vulnerability scanning method and device based on remote access channel and computer equipment
CN121462280A