A vehicle-cloud collaborative threat intrusion management method, system and readable storage medium

Through the vehicle-cloud collaborative threat intrusion management system, using lightweight AI detection models and multiple AI analysis models, dynamic perception and collaborative defense of multiple types of attacks on intelligent connected vehicles are achieved, improving the security protection capabilities of the entire vehicle network system and ensuring user data and driving safety.

CN120434066BActive Publication Date: 2025-09-09ZHEJIANG UNBOUNDED MATRIX TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510948050.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-09-09
Estimated Expiration
2045-07-10

AI Technical Summary

Technical Problem

With the development of intelligent connected vehicles, vehicle information security issues are becoming increasingly prominent. Existing technologies are difficult to effectively improve the security protection capabilities of the entire vehicle network system, especially in the identification and defense of multiple types of attacks in an open network environment.

Method used

By collaboratively deploying lightweight AI detection models and multiple AI analysis models between vehicles and cloud platforms, real-time collection, preprocessing, anomaly detection, and threat intrusion detection of vehicle data can be achieved. Combined with in-depth analysis of the cloud platform, potential attacks can be dynamically identified and responded to.

Benefits of technology

It achieves dynamic perception, precise identification and coordinated defense of multiple types of attacks, improves the security protection capabilities of the entire vehicle network system, and ensures user data and driving safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434066B_ABST
    Figure CN120434066B_ABST
Patent Text Reader

Abstract

The present application discloses a vehicle-cloud collaborative threat intrusion management system, comprising: an on-board security data acquisition module, configured to collect at least one preset dimension of the vehicle's data to be processed in real time; a data preprocessing module, configured to preprocess the data to be processed and obtain feature data of the data to be processed; a vehicle-side AI detection module, configured to perform anomaly detection on the data to be processed based on the feature data of the data to be processed and at least one lightweight AI detection model, and obtain anomaly detection results of the data to be processed; an intrusion detection module, configured to perform threat intrusion detection on the target data based on multiple AI analysis models according to the feature data of the target data and the anomaly detection results of the target data, and obtain threat intrusion detection results; and a response control module, configured to execute corresponding security response operations on the vehicle according to the threat intrusion detection results. In this way, the security protection capability of the entire vehicle network system can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of vehicle safety technology, and in particular to a vehicle-cloud collaborative threat intrusion management method and system, and a computer-readable storage medium. Background Art

[0002] With the rapid development of intelligent connected vehicles, cars, as mobile terminals that integrate information, networking, and intelligence, are gradually evolving into "computing platforms on wheels." Vehicle-to-everything (V2X) communication technology enables information interconnection with other vehicles, infrastructure, and cloud platforms, significantly improving user experience, road safety, and traffic efficiency. However, as in-vehicle systems are increasingly exposed to open networks, information security issues are becoming increasingly prominent. Research is ongoing to improve the security of vehicle network systems. Summary of the Invention

[0003] The purpose of this application is to provide a vehicle-cloud collaborative threat intrusion management method and system, and a computer-readable storage medium, which can realize dynamic perception, accurate identification and collaborative defense of multiple types of attacks, thereby effectively improving the security protection capabilities of the entire vehicle network system and improving the safety of user data and driving.

[0004] To achieve the above objectives:

[0005] In a first aspect, an embodiment of the present application provides a vehicle-cloud collaborative threat intrusion management system, comprising: an intrusion detection module and a response control module deployed in a cloud platform, and an on-board safety data acquisition module, a data preprocessing module, a vehicle-side AI detection module, and a communication interface module deployed in a vehicle; wherein,

[0006] The vehicle safety data collection module is configured to collect data to be processed in at least one preset dimension of the vehicle in real time;

[0007] A data preprocessing module is configured to preprocess the data to be processed to obtain feature data of the data to be processed;

[0008] The vehicle-side AI detection module is configured to perform anomaly detection on the data to be processed based on the feature data of the data to be processed and using at least one lightweight AI detection model, obtain anomaly detection results for the data to be processed, and upload the feature data of the target data and the anomaly detection results of the target data to the cloud platform via the communication interface module; the target data is the data to be processed that is determined to have an anomaly based on the anomaly detection results;

[0009] An intrusion detection module is configured to perform threat intrusion detection on the target data based on the characteristic data of the target data and the abnormality detection result of the target data based on multiple AI analysis models to obtain a threat intrusion detection result;

[0010] The response control module is configured to perform corresponding security response operations on the vehicle according to the threat intrusion detection results.

[0011] Optionally, the vehicle-mounted safety data collection module is configured to collect data to be processed of at least one preset dimension of the vehicle in real time through deployed sensor agents and communication probes.

[0012] Optionally, the data preprocessing module is configured to perform data cleaning and / or data desensitization on the data to be processed, and then perform feature extraction on the data to be processed to obtain feature data of the data to be processed.

[0013] Optionally, the data to be processed includes at least one of the following data: operating system running status data, in-vehicle communication data, out-of-vehicle communication data, and application behavior data.

[0014] Optionally, the AI ​​detection model includes at least one of the following: a hidden Markov model, a mutation point detection model, and a behavior baseline shift analysis model; and the vehicle-side AI detection module is configured to perform at least one of the following operations:

[0015] Anomaly detection of in-vehicle communication data using hidden Markov models;

[0016] Performing anomaly detection on in-vehicle communication data and / or out-vehicle communication data using a mutation point detection model;

[0017] Anomaly detection is performed on application behavior data and / or operating system running status data through a behavior baseline deviation analysis model.

[0018] Optionally, the anomaly detection result of the target data includes an anomaly label of the target data, and the threat intrusion detection result includes a potential attack path; the AI ​​analysis model includes a time series anomaly detection model based on an LSTM or GRU algorithm, a disordered collaborative detection model based on an FP-Growth algorithm, and a graph reasoning model based on a GNN algorithm and a threat knowledge graph; the intrusion detection module is configured to:

[0019] In response to the target data being an ordered behavior sequence, the attack state is predicted using a time series anomaly detection model based on the characteristic data of the target data to obtain the attack state sequence probability;

[0020] Based on the abnormal labels of the target data, the disordered collaborative detection model is used to mine collaborative attacks and obtain high-frequency collaborative attack events.

[0021] Based on the attack state sequence probability and high-frequency coordinated attack events, threat intrusion detection is performed through the graph reasoning model to obtain potential attack paths.

[0022] Optionally, the response control module is configured to: input the threat intrusion detection results, vehicle status data and historical action effects into the constructed DQN model, obtain the security response operation predicted and output by the DQN model, and send the security response operation to the vehicle; the security response operation includes at least one of the following: network isolation; limiting network bandwidth; logging and remote uploading; security policy OTA issuance; service blocking; local reminder.

[0023] In a second aspect, an embodiment of the present application provides a vehicle-cloud collaborative threat intrusion management method, which is applied to a vehicle, and the method includes:

[0024] Collecting data to be processed in at least one preset dimension of the vehicle in real time;

[0025] Preprocess the data to be processed to obtain feature data of the data to be processed;

[0026] Based on the characteristic data of the data to be processed, anomaly detection is performed on the data to be processed according to at least one lightweight AI detection model to obtain the anomaly detection result of the data to be processed, and the characteristic data of the target data and the anomaly detection result of the target data are uploaded to the cloud platform; the target data is the data to be processed that is determined to have anomalies based on the anomaly detection results.

[0027] In a third aspect, an embodiment of the present application provides a vehicle-cloud collaborative threat intrusion management method, which is applied to a cloud platform. The method includes:

[0028] Based on the characteristic data of the target data and the abnormal detection results of the target data, threat intrusion detection is performed on the target data based on multiple AI analysis models to obtain threat intrusion detection results;

[0029] Perform corresponding security response actions on the vehicle based on the threat intrusion detection results.

[0030] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the above-mentioned vehicle-cloud collaborative threat intrusion management method is implemented.

[0031] Embodiments of the present application provide a vehicle-cloud collaborative threat intrusion management method and system, and a computer-readable storage medium. The system includes: an intrusion detection module and a response control module deployed in a cloud platform, and an on-board safety data acquisition module, a data preprocessing module, a vehicle-side AI detection module, and a communication interface module deployed in a vehicle; wherein the on-board safety data acquisition module is configured to collect, in real time, data to be processed of at least one preset dimension of the vehicle; the data preprocessing module is configured to preprocess the data to be processed and obtain feature data of the data to be processed; the vehicle-side AI detection module is configured to perform anomaly detection on the data to be processed based on the feature data of the data to be processed and according to at least one lightweight AI detection model, obtain anomaly detection results for the data to be processed, and upload the feature data of the target data and the anomaly detection results of the target data to the cloud platform via the communication interface module; the target data is the data to be processed that is determined to have an anomaly based on the anomaly detection results; the intrusion detection module is configured to perform threat intrusion detection on the target data based on multiple AI analysis models based on the feature data of the target data and the anomaly detection results of the target data, and obtain a threat intrusion detection result; and the response control module is configured to execute corresponding security response operations on the vehicle based on the threat intrusion detection results. In this way, by deploying a lightweight AI detection model on the vehicle side and combining it with the AI ​​analysis model of the cloud platform, multi-source information such as the vehicle operating system, communication data, and application behavior can be collected and intelligently processed in a three-dimensional manner to achieve multi-dimensional perception and intelligent analysis; key data can be reported to the cloud platform through a secure communication interface to achieve the combination of vehicle-side detection and cloud platform analysis, improve the accuracy and coverage of detection, and realize vehicle-cloud linkage intrusion detection; based on the threat intrusion detection results, security response operations are automatically issued to the vehicle to automatically block and isolate the attack behavior, realizing dynamic security response and closed-loop protection mechanism. In other words, the vehicle-cloud collaborative threat intrusion management method and system and computer-readable storage medium provided in the embodiments of the present application, by integrating the real-time perception capabilities of the vehicle side with the intelligent analysis capabilities of the cloud platform, can achieve dynamic perception, accurate identification and collaborative defense of multiple types of attacks, improve the real-time identification, dynamic response and continuous learning capabilities of the entire vehicle network system to malicious behavior and security risks, thereby improving the security protection capabilities of the entire vehicle network system and effectively protecting user data and driving safety. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 A schematic diagram of the structure of the vehicle-cloud collaborative threat intrusion management system provided in an embodiment of the present invention.

[0033] Figure 2 Schematic diagram of the process of the vehicle-cloud collaborative threat intrusion management method provided by the embodiment of the present invention Figure 1 .

[0034] Figure 3Schematic diagram of the process of the vehicle-cloud collaborative threat intrusion management method provided by the embodiment of the present invention Figure 2 . DETAILED DESCRIPTION

[0035] Here, exemplary embodiments will be described in detail, and examples thereof are shown in the accompanying drawings. When the following description relates to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device comprising a series of elements includes not only those elements, but also includes other elements that are not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, the parts, features, and elements with the same name in different embodiments of the present application may have the same meaning or may have different meanings, and their specific meanings need to be determined by their explanation in the specific embodiment or further in conjunction with the context in the specific embodiment.

[0036] It should be understood that, although the various steps in the flowchart in the embodiment of the present application are shown in sequence according to the indication of the arrows, these steps are not necessarily performed in sequence in the order indicated by the arrows. Unless clearly stated herein, the execution of these steps is not strictly limited in order, and they can be performed in other orders. Moreover, at least a portion of the steps in the figure may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and their execution order is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.

[0037] It should be noted that in this article, step codes such as S101 and S102 are used for the purpose of expressing the corresponding content more clearly and concisely, and do not constitute a substantial limitation on the order. When implementing the step, those skilled in the art may execute S102 first and then S101, etc., but these should all be within the scope of protection of this application.

[0038] It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application.

[0039] In the subsequent description, the use of suffixes such as "module", "component" or "unit" to represent elements is only for the purpose of facilitating the description of the present application and has no specific meaning. Therefore, "module", "component" or "unit" can be used interchangeably.

[0040] See Figure 1 , is a vehicle-cloud collaborative threat intrusion management system provided in an embodiment of the present application. The vehicle-cloud collaborative threat intrusion management system provided in this embodiment includes: an on-board security data acquisition module 10, a data preprocessing module 11, a vehicle-side AI detection module 12, and a communication interface module 13 deployed in a vehicle 1, and an intrusion detection module 20 and a response control module 21 deployed in a cloud platform 2; wherein,

[0041] The vehicle safety data collection module 10 is configured to collect data to be processed of at least one preset dimension of the vehicle in real time;

[0042] The data preprocessing module 11 is configured to preprocess the data to be processed and obtain feature data of the data to be processed;

[0043] The vehicle-side AI detection module 12 is configured to perform anomaly detection on the data to be processed based on the feature data of the data to be processed and according to at least one lightweight AI detection model, obtain an anomaly detection result of the data to be processed, and upload the feature data of the target data and the anomaly detection result of the target data to the cloud platform 2 via the communication interface module 13; the target data is the data to be processed that is determined to have an anomaly based on the anomaly detection result;

[0044] The intrusion detection module 20 is configured to perform threat intrusion detection on the target data based on the characteristic data of the target data and the abnormality detection result of the target data based on multiple AI analysis models to obtain a threat intrusion detection result;

[0045] The response control module 21 is configured to perform corresponding security response operations on the vehicle according to the threat intrusion detection result.

[0046] During actual vehicle operation, multiple functional modules within the vehicle system (such as the vehicle control module, camera module, gateway module, and vehicle Ethernet interface) may become attack entry points. Therefore, the data to be processed refers to low-level data directly collected from one or more of these functional modules without in-depth processing. The preset dimension can be at least one of the following: operating system behavior, communication, or application. In one embodiment, the data to be processed may include at least one of the following: operating system operating status data, in-vehicle communication data, out-of-vehicle communication data, and application behavior data. Operating system operating status data may include process tables, system call sequences (including system call frequency), user access logs, and process behavior traces. In-vehicle communication data may include CAN bus messages (including ID numbers, timestamps, data frame content, load rates, etc.) and protocol interaction data such as in-vehicle Ethernet. Out-of-vehicle communication data may include V2X (vehicle-to-vehicle and vehicle-to-infrastructure) interaction data, as well as external communication messages and status information from cellular networks (4G / 5G), WiFi, and Bluetooth. Application behavior data may include application permission call records (such as access data to devices such as GPS, cameras, microphones, etc.), sensitive API call logs (such as encryption interfaces, data storage interfaces), etc. In one embodiment, the data to be processed may also include peripheral interface status data, which may include sensor data call records (such as ADAS camera, radar data), USB, Ethernet port and other peripheral interface status and connection logs. In an embodiment of the present application, the communication interface module may use an encrypted secure channel (such as TLS) and an efficient message protocol (such as MQTT) to upload vehicle-side data to the cloud platform to ensure the integrity, confidentiality and verifiability of data transmission, and support high-frequency data synchronization and low-latency instruction issuance between the vehicle and the cloud platform. In addition, the data uploaded to the cloud platform through the communication interface module may also include context information (such as timestamp, module ID, etc.) and / or original fragments of the target data.

[0047] In one embodiment, the on-board safety data acquisition module 10 is configured to collect at least one predetermined dimension of vehicle data in real time through the deployment of sensor agents and communication probes. Specifically, sensor agents (also referred to as sensor agent modules) and communication probes (also referred to as communication probe modules) are deployed within functional modules such as the on-board control module, camera module, and gateway module that require the collection of data to be processed, enabling non-invasive acquisition of the corresponding data to be processed. The sensor agents consume minimal resources such as CPU and memory during operation, without impacting the real-time performance of the vehicle's existing functions. Furthermore, data collection requires no modifications to on-board software or firmware, and is performed solely through hardware interfaces or standard APIs provided by the operating system. For example, the communication probe module can be deployed within the microkernel layer of a vehicle operating system (such as QNX or AutoSAR OS), relying solely on basic kernel services (such as process scheduling and memory management) and, through secure permissions, directly accessing the underlying communication stack (such as the socket interface and CAN driver layer) to capture raw operating system operational status data in real time. This enables non-invasive, high-frequency acquisition of vehicle data with convenient operation.

[0048] In one embodiment, the data preprocessing module 11 is configured to perform data cleaning and / or data desensitization on the data to be processed, and then perform feature extraction on the data to be processed to obtain feature data of the data to be processed. Data cleaning includes noise filtering, such as removing redundant, repeated, or invalid data (such as sensor false alarms, communication interference noise, etc.). Data desensitization includes desensitizing sensitive information (such as user identity, location data, etc.) to ensure data compliance. Furthermore, the data to be processed can be format-standardized, that is, multi-source heterogeneous data (such as CAN bus messages and network logs) can be unified into a structured format to facilitate subsequent analysis. Feature extraction involves extracting security-related features (such as CAN frame periods, network traffic mutation points, system call sequence patterns, etc.) from the data to be processed. Furthermore, the extracted feature data can be compressed, such as using a lightweight algorithm (such as LZ4) to reduce transmission bandwidth usage.

[0049] Among them, feature data is the key attributes extracted from the data to be processed to characterize behavioral patterns or anomalies, mainly including: (1) temporal features, including CAN bus message cycle, ID distribution, load rate (such as the number of messages per unit time); frequency and order of system call sequences (such as process startup, file access timing patterns). (2) statistical features, including network traffic mean, variance, peak value (such as burst traffic statistics of V2X communication); frequency distribution of application permission calls (such as GPS access times, sensitive API call frequency). For example, for CAN bus messages, the extracted feature data may include frame frequency, ID entropy value, load mean, etc.; for system call sequences, the extracted feature data may include key call paths, resource access frequency, etc. In this way, through feature extraction, the cloud platform does not need to process raw data, effectively reducing computing load and storage costs, and further improving the efficiency of vehicle safety protection.

[0050] Lightweight refers to a small size and consumes fewer system resources to complete the same computing task. Therefore, a lightweight AI detection model occupies less storage space and requires less computing resources. In one embodiment, the AI ​​detection model includes at least one of the following: a hidden Markov model, a mutation point detection model, and a behavioral baseline shift analysis model; the vehicle-side AI detection module is configured to perform at least one of the following operations:

[0051] Anomaly detection of in-vehicle communication data using hidden Markov models;

[0052] Performing anomaly detection on in-vehicle communication data and / or out-vehicle communication data using a mutation point detection model;

[0053] Anomaly detection is performed on application behavior data and / or operating system running status data through a behavior baseline deviation analysis model.

[0054] Hidden Markov models (HMMs) can detect anomalies in CAN bus communication within in-vehicle communication data. This includes detecting message injection attacks (such as forged command frames), DoS attacks (such as flooding the bus with abnormally high-frequency messages), and message tampering (abnormal payload content). The detection principle involves modeling the CAN bus message sequence as a time series and calculating the optimal state path using the Viterbi algorithm to determine whether the current sequence deviates from the historical normal behavior trajectory. The HMM's role is to establish a probabilistic model for time series data (such as CAN bus message sequences), describing the dependency between hidden states (such as normal / abnormal behavior) and observed data (such as message content). The Viterbi algorithm's role is to efficiently calculate the optimal hidden state sequence within the HMM framework (e.g., detecting anomaly injection attacks on the CAN bus).

[0055] A mutation point detection model, constructed using the empirical distribution function (EDF) and the Grubbs test algorithm, can be used to detect sudden communication interference and behavioral mutations. This includes detecting sudden increases or decreases in network traffic (such as signs of a DDoS attack), abnormal system call frequency (such as malicious process activation), and sudden changes in sensor data (abnormal physical interference). The specific detection principle is to establish a historical data distribution baseline based on the empirical distribution function and use the Grubbs test to identify outliers that deviate statistically significantly from the baseline. For example, for in-vehicle communication data, the bus message frequency / load rate can be monitored, the historical distribution can be established using the EDF, and the Grubbs test can be used to identify sudden outliers (such as traffic surges caused by DoS attacks).

[0056] The behavioral baseline deviation analysis model can be used to detect persistent abnormal behaviors at the application and system layers, including detecting whether there is abuse of permissions (such as illegal calls to sensitive APIs), long-term resource occupation (such as Trojans), and slow penetration behavior. The specific detection principle is to build a statistical baseline model (such as mean and variance) based on historical behavior data, and identify anomalies through the deviation measurement of real-time behavior and baseline (such as Mahalanobis distance).

[0057] All of these models can be run on the vehicle itself, performing local initial screening tasks and significantly reducing the load on the cloud platform. Based on the anomaly detection results, data to be processed that contains anomalies can be identified. For example, if the HMM detects an anomaly in a CAN bus message, the identified anomaly data, or target data, can then be reported to Cloud Platform 2, triggering in-depth analysis. Furthermore, data identified as high-risk by anomaly detection results will be prioritized for reporting to Cloud Platform 2. This enables lightweight, real-time preliminary data detection on the vehicle side, enabling rapid and initial identification of anomalies and providing high-quality input data to Cloud Platform 2, reducing false positives.

[0058] Among them, the anomaly detection results may include anomaly labels, which are the classification results of the AI ​​detection model on the vehicle side for data, used to identify the risk type or anomaly level, including: (1) anomaly type labels, including attack categories (such as CAN injection attacks, DoS attacks, and abuse of authority) and risk levels (low, medium, and high risks, determined according to the degree of deviation from normal behavior). (2) behavior state labels, including normal behavior (normal sequence paths that conform to HMM modeling), suspicious behavior (partial deviation from the baseline but not reaching the attack threshold), and confirmed attack (clear malicious patterns are detected, such as ID conflicts or abnormal message loads). (3) response priority labels, including real-time high priority (needs to be reported to the cloud immediately, such as abnormal control instructions) and batch processing priority (regular data synchronization, such as periodic behavior logs).

[0059] In addition, the anomaly detection results may also include metadata, which is auxiliary descriptive information for feature data and labels, used to support contextual analysis and cloud processing, including: (1) Data source information, including module ID (such as vehicle control module, gateway module, etc.) and data acquisition interface (such as CAN bus, V2X communication module). (2) Time and space information, including timestamp (used for timing alignment and attack chain reconstruction) and geographic location (such as vehicle coordinates obtained through GPS, uploaded after desensitization). (3) Processing status information, including data version number and encryption status (such as TLS encryption identifier, data signature hash value). (4) Contextual association information, including attack stage speculation (such as MITRE ATT&CK tactical stage preliminary judgment) and associated event ID (logical association identifier of cross-module alarm events).

[0060] In one embodiment, the anomaly detection result of the target data includes an anomaly label of the target data, and the threat intrusion detection result includes a potential attack path; the AI ​​analysis model includes a time series anomaly detection model based on the LSTM or GRU algorithm, a disordered collaborative detection model based on the FP-Growth algorithm, and a graph reasoning model based on the GNN algorithm and the threat knowledge graph; the intrusion detection module 20 is configured to:

[0061] In response to the target data being an ordered behavior sequence, the attack state is predicted using a time series anomaly detection model based on the characteristic data of the target data to obtain the attack state sequence probability;

[0062] Based on the abnormal labels of the target data, the disordered collaborative detection model is used to mine collaborative attacks and obtain high-frequency collaborative attack events.

[0063] Based on the attack state sequence probability and high-frequency coordinated attack events, threat intrusion detection is performed through the graph reasoning model to obtain potential attack paths.

[0064] Time series anomaly detection models can be built based on LSTM or GRU algorithms. They can detect data types including ordered behavior sequences, such as vehicle CAN bus message timing (frame ID, period, and payload sequence); system call sequences (process startup and file access timing paths); and network session flows (continuous interaction events in V2X / cellular communications). Key anomalies identified include covert attack chains (e.g., APT attacks: reconnaissance → infiltration → data exfiltration); message injection / tampering (e.g., CAN bus timing offset); and low-frequency data leakage (e.g., anomalous outbound traffic patterns). Time series anomaly detection models primarily learn long-term dependencies to predict the probability of attack state sequences. For example, for target data collected regarding identity authentication bypass, an LSTM-based time series anomaly detection model can analyze the attack state sequence probability of "command injection, probability 0.92." The time series anomaly detection model can be trained based on historical ordered behavior sequences and the corresponding historical attack state sequence probabilities. The specific model training process can be referenced in existing technologies.

[0065] The unordered collaborative detection model can be built based on the FP-Growth algorithm and is used to detect discrete data sets, including cross-module alarm logs (such as simultaneously triggered CAN anomalies and permission anomalies) and non-continuous security events (such as multi-point vulnerability scan records in different time periods). Its main anomaly identification methods include collaborative attack mining (such as distributed DoS attacks where multiple ECUs simultaneously send abnormal messages) and cross-layer penetration (such as the combination of network scanning, privilege escalation, and data access). The detection principle is to compress event data into an FP-Tree using the FP-Growth algorithm, mine frequent itemsets, and output high-frequency collaborative attack events. For example, based on anomaly labels, frequent combinations of TCAM camera access, OTA interface calls, and sensitive file reads can be mined from scattered alarms. The unordered collaborative detection model can be trained based on anomaly labels from historical data and the corresponding historical high-frequency collaborative attack events.

[0066] Among them, the graph reasoning model can be constructed based on the GNN algorithm and the threat attack knowledge graph. By mapping the detected behavior nodes (i.e., attack state sequence probability and high-frequency coordinated attack events) to the threat attack knowledge graph, the attack path, stage evolution and potential targets are deduced, thereby outputting the predicted potential attack path. It should be noted that the threat attack knowledge graph can be integrated with the following: (1) MITRE ATT&CK attack matrix, including tactical stages such as coverage reconnaissance, initial access, persistence, and privilege escalation; (2) Kill Chain model, used to describe the attack life cycle and stage evolution path; (3) attack entity graph, whose nodes include attack technology, target resources, security events, response strategies, etc. For example, assuming that the input of the graph reasoning model is "CAN injection, probability 0.93" and "CAN injection + privilege escalation behavior", the graph reasoning model deduces that the next attack path may be data destruction, thereby triggering preventive isolation. Among them, the graph reasoning model can be trained based on the historical attack state sequence probability and historical high-frequency coordinated attack events and the corresponding historical potential attack paths. In this way, through the multi-model linkage mechanism and the combination of deep learning and graphs, the system's ability to identify variant attacks, low-frequency high-risk behaviors and cross-module collaborative attacks is significantly enhanced, further improving the security protection capabilities of the entire vehicle network system.

[0067] In one embodiment, the response control module 21 is configured to: input the threat intrusion detection results, vehicle status data and historical action effects into the constructed DQN (Deep Q-Network) model, obtain the security response operation predicted and output by the DQN model, and issue the security response operation to the vehicle so that the vehicle performs the security response operation; the security response operation includes at least one of the following: network isolation; limiting network bandwidth; logging and remote uploading; OTA issuance of security policies; service blocking; local reminders.

[0068] Vehicle status data, including speed and geographic location, can be uploaded to the cloud platform by the onboard security data acquisition module via the communication interface module. Historical action results indicate the effectiveness of security response actions taken based on historical vehicle status data and historical threat intrusion detection results, such as the success rate of threat intrusion defense. Network isolation can involve disconnecting a module's communication permissions, such as isolating a communication module. Network bandwidth throttling can involve limiting CAN bandwidth, for example. Service blocking can involve shutting down or restricting remote interface calls. For example, if the threat intrusion detection result is a CAN injection attack and the vehicle status data indicates driving on a highway, the security response can be set to limit the CAN bandwidth and alert the driver to prevent loss of control due to isolation, prioritizing speed reduction and manual intervention. For another example, if the threat intrusion detection result is malicious OTA flashing and the vehicle status data indicates the vehicle is parked, the security response can be set to block the OTA port and log the information. The DQN model can be trained based on historical threat intrusion detection results, historical vehicle status data, historical action results, and historical security response actions. Furthermore, the DQN model can be optimized using user feedback data and / or logs. It should be noted that after the response control module 21 issues a security response action to vehicle 1, vehicle 1 can execute the security response action accordingly. Optionally, vehicle 1 can also deploy an execution module configured to execute the security response action. In this way, security response actions are dynamically generated and issued based on real-time security events, achieving adaptive optimization and closed-loop control of security policies.

[0069] In one embodiment, in order to adapt to the ever-evolving attack forms, the AI ​​analysis model is also updated through a self-learning mechanism in the embodiment of the present application, including: the intrusion detection module receives the detection log and user feedback data sent by the vehicle end, automatically updates the AI ​​analysis model parameters (such as incremental fine-tuning LSTM, updating GNN edge weights, etc.), and dynamically adjusts the node weights and path structure in the threat attack knowledge graph.

[0070] In order to improve the robustness and evolutionary capabilities of the system in response to new threats, the on-board safety data acquisition module 10 can also transmit the target data or the original data corresponding to the target data and the vehicle's response records to the security response operation back to the cloud platform through the communication interface module 13, so that the intrusion detection module 20 can perform online fine-tuning and incremental training on the AI ​​analysis model, as well as node expansion, relationship reconstruction, and risk value update on the threat attack knowledge graph structure.

[0071] In summary, in the vehicle-cloud collaborative threat intrusion management system provided by the above embodiment, by deploying a lightweight AI detection model on the vehicle side and combining it with the AI ​​analysis model of the cloud platform, the vehicle operating system, communication data, application behavior and other multi-source information are collected and intelligently processed to achieve multi-dimensional perception and intelligent analysis; key data is reported to the cloud platform through a secure communication interface to achieve the combination of vehicle-side detection and cloud platform analysis, improve the accuracy and coverage of detection, and realize vehicle-cloud linkage intrusion detection; according to the threat intrusion detection results, security response operations are automatically issued to the vehicle to automatically block and isolate the attack behavior, and realize dynamic security response and closed-loop protection mechanism. In other words, in the vehicle-cloud collaborative threat intrusion management system provided by the embodiment of the present application, by integrating the real-time perception capability of the vehicle side and the intelligent analysis capability of the cloud platform, dynamic perception, accurate identification and collaborative defense of multiple types of attacks can be achieved, which improves the real-time identification, dynamic response and continuous learning capabilities of the entire vehicle network system to malicious behaviors and security risks, thereby improving the security protection capabilities of the entire vehicle network system and effectively protecting user data and driving safety.

[0072] See Figure 2 , a vehicle-cloud collaborative threat intrusion management method provided in an embodiment of the present application, applied to a vehicle, the vehicle-cloud collaborative threat intrusion management method provided in this embodiment includes:

[0073] Step S101: collecting data to be processed of at least one preset dimension of the vehicle in real time.

[0074] Step S102: Preprocess the data to be processed to obtain feature data of the data to be processed.

[0075] Step S103: Based on the feature data of the data to be processed, anomaly detection is performed on the data to be processed according to at least one lightweight AI detection model to obtain an anomaly detection result of the data to be processed, and the feature data of the target data and the anomaly detection result of the target data are uploaded to the cloud platform; the target data is the data to be processed that is determined to have anomalies based on the anomaly detection result.

[0076] It should be noted that the specific implementation process of the above-mentioned vehicle-cloud collaborative threat intrusion management method can refer to the description of the vehicle-cloud collaborative threat intrusion management system in the above-mentioned embodiment, which will not be repeated here.

[0077] In summary, the vehicle-cloud collaborative threat intrusion management method provided in the above embodiments, by integrating the real-time perception capabilities of the vehicle side and the intelligent analysis capabilities of the cloud platform, can realize dynamic perception, accurate identification and collaborative defense of multiple types of attacks, and improve the real-time identification, dynamic response and continuous learning capabilities of the entire vehicle network system to malicious behaviors and security risks, thereby improving the security protection capabilities of the entire vehicle network system and effectively protecting user data and driving safety.

[0078] See Figure 3 , a vehicle-cloud collaborative threat intrusion management method provided in an embodiment of the present application, applied to a cloud platform, the vehicle-cloud collaborative threat intrusion management method provided in this embodiment includes:

[0079] Step S201: Acquire feature data of target data reported by a vehicle and anomaly detection results of the target data.

[0080] Step S202: Based on the characteristic data of the target data and the anomaly detection result of the target data, threat intrusion detection is performed on the target data based on multiple AI analysis models to obtain a threat intrusion detection result.

[0081] Step S203: Execute corresponding security response operations on the vehicle according to the threat intrusion detection result.

[0082] It should be noted that the specific implementation process of the above-mentioned vehicle-cloud collaborative threat intrusion management method can refer to the description of the vehicle-cloud collaborative threat intrusion management system in the above-mentioned embodiment, which will not be repeated here.

[0083] In summary, the vehicle-cloud collaborative threat intrusion management method provided in the above embodiments, by integrating the real-time perception capabilities of the vehicle side and the intelligent analysis capabilities of the cloud platform, can realize dynamic perception, accurate identification and collaborative defense of multiple types of attacks, and improve the real-time identification, dynamic response and continuous learning capabilities of the entire vehicle network system to malicious behaviors and security risks, thereby improving the security protection capabilities of the entire vehicle network system and effectively protecting user data and driving safety.

[0084] Based on the same inventive concept as the above-mentioned embodiment, this embodiment also provides a computer-readable storage medium, in which a computer program is stored. The computer-readable storage medium may be a magnetic random access memory (FRAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory, a magnetic surface memory, an optical disc, or a read-only optical disc (CD-ROM) or other memory; or it may be various devices including one or any combination of the above-mentioned memories, such as a mobile phone, a computer, a tablet device, a personal digital assistant, etc. When the computer program stored in the computer-readable storage medium is executed by the processor, the above-mentioned vehicle-cloud collaborative threat intrusion management method is implemented. For the specific steps implemented when the computer program is executed by the processor, please refer to Figure 2 or Figure 3 The description of the illustrated embodiment will not be repeated here.

[0085] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0086] As used herein, the terms "comprises," "comprising," or any other variation thereof, are intended to cover a non-exclusive inclusion of elements other than the listed elements and may also include additional elements not specifically listed.

[0087] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A vehicle-cloud collaborative threat intrusion management system, characterized by: include: The intrusion detection module and response control module deployed in the cloud platform, as well as the vehicle-mounted safety data acquisition module, data pre-processing module, vehicle-side AI detection module and communication interface module deployed in the vehicle; among them, The vehicle safety data collection module is configured to collect data to be processed of at least one preset dimension of the vehicle in real time; A data preprocessing module is configured to preprocess the data to be processed to obtain feature data of the data to be processed; The vehicle-side AI detection module is configured to perform anomaly detection on the data to be processed based on the feature data of the data to be processed and using at least one lightweight AI detection model, obtain anomaly detection results for the data to be processed, and upload the feature data of the target data and the anomaly detection results of the target data to the cloud platform via the communication interface module; the target data is the data to be processed that is determined to have an anomaly based on the anomaly detection results; An intrusion detection module is configured to perform threat intrusion detection on the target data based on the characteristic data of the target data and the abnormality detection result of the target data based on multiple AI analysis models to obtain a threat intrusion detection result; a response control module, configured to execute corresponding security response operations on the vehicle based on the threat intrusion detection results; The anomaly detection results of target data include the anomaly labels of the target data, and the threat intrusion detection results include potential attack paths. The AI ​​analysis models include time series anomaly detection models based on LSTM or GRU algorithms, disordered collaborative detection models based on FP-Growth algorithms, and graph reasoning models based on GNN algorithms and threat knowledge graphs. The intrusion detection module is specifically configured as follows: In response to the target data being an ordered behavior sequence, the attack state is predicted using a time series anomaly detection model based on the characteristic data of the target data to obtain the attack state sequence probability; Based on the abnormal labels of the target data, the disordered collaborative detection model is used to mine collaborative attacks and obtain high-frequency collaborative attack events. Based on the attack state sequence probability and high-frequency coordinated attack events, threat intrusion detection is performed through the graph reasoning model to obtain potential attack paths; The response control module is specifically configured to: input threat intrusion detection results, vehicle status data and historical action effects into the constructed DQN model, obtain the security response operation predicted by the DQN model output, and issue the security response operation to the vehicle; the security response operation includes at least one of the following: network isolation; limiting network bandwidth; logging and remote upload; OTA issuance of security policies; service blocking; local reminders.

2. The system according to claim 1, wherein: The vehicle-mounted safety data acquisition module is configured to collect data to be processed in at least one preset dimension of the vehicle in real time through deployed sensor agents and communication probes.

3. The system according to claim 1, wherein: The data preprocessing module is configured to perform data cleaning and / or data desensitization on the data to be processed, and then perform feature extraction on the data to be processed to obtain feature data of the data to be processed.

4. The system according to any one of claims 1 to 3, characterized in that The data to be processed includes at least one of the following data: operating system running status data, in-vehicle communication data, out-vehicle communication data, and application behavior data.

5. The system according to claim 4, characterized in that The AI ​​detection model includes at least one of the following: a hidden Markov model, a mutation point detection model, and a behavior baseline shift analysis model. The vehicle-side AI detection module is configured to perform at least one of the following operations: Anomaly detection of in-vehicle communication data using hidden Markov models; Performing anomaly detection on in-vehicle communication data and / or out-vehicle communication data using a mutation point detection model; Anomaly detection is performed on application behavior data and / or operating system running status data through a behavior baseline deviation analysis model.

6. A vehicle-cloud collaborative threat intrusion management method, characterized in that: The method comprises: The vehicle collects data to be processed of at least one preset dimension of the vehicle in real time; The vehicle pre-processes the data to be processed to obtain feature data of the data to be processed; The vehicle performs anomaly detection on the data to be processed based on the feature data of the data to be processed using at least one lightweight AI detection model, obtains anomaly detection results for the data to be processed, and uploads the feature data of the target data and the anomaly detection results of the target data to the cloud platform; the target data is the data to be processed that is determined to have an anomaly based on the anomaly detection results, and the anomaly detection results of the target data include an anomaly label for the target data; The cloud platform obtains the characteristic data of the target data reported by the vehicle and the anomaly detection results of the target data; The cloud platform performs threat intrusion detection on the target data based on the characteristic data of the target data and the anomaly detection results of the target data based on multiple AI analysis models to obtain threat intrusion detection results, including: in response to the target data being an ordered behavior sequence, based on the characteristic data of the target data, attack status prediction is performed through a time series anomaly detection model to obtain the attack status sequence probability; based on the anomaly labels of the target data, collaborative attack mining is performed through an unordered collaborative detection model to obtain high-frequency collaborative attack events; based on the attack status sequence probability and high-frequency collaborative attack events, threat intrusion detection is performed through a graph reasoning model to obtain potential attack paths; AI analysis models include a time series anomaly detection model built based on the LSTM or GRU algorithm, an unordered collaborative detection model built based on the FP-Growth algorithm, and a graph reasoning model built based on the GNN algorithm and the threat knowledge graph. The threat intrusion detection results include potential attack paths; The cloud platform performs corresponding security response operations on the vehicle based on the threat intrusion detection results, including: inputting the threat intrusion detection results, vehicle status data and historical action effects into the constructed DQN model, obtaining the security response operations predicted and output by the DQN model, and issuing security response operations to the vehicle; security response operations include at least one of the following: network isolation; limiting network bandwidth; logging and remote upload; OTA issuance of security policies; service blocking; and local reminders.

7. A computer-readable storage medium, characterized in that A computer program is stored, and when the computer program is executed by a processor, the vehicle-cloud collaborative threat intrusion management method described in claim 6 is implemented.

Citation Information

Patent Citations

  • Safety protection method and device for intelligent networked automobile

    CN119299215A

  • Vehicle-mounted communication safety protection method and related equipment

    CN120128399A