Information acquisition method and device, vehicle and storage medium
By conducting hazard analysis, general vulnerability scoring and threat analysis on vehicle objects, combined with weight calculation, the problem of the inability to comprehensively evaluate the overall safety of vehicle objects in existing technologies is solved, a comprehensive safety assessment of vehicle objects is achieved, and the accuracy of the assessment results is improved.
Patent Information
- Application Number
- CN202510769016.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-09-16
AI Technical Summary
Existing technologies are unable to effectively assess the overall safety of objects on a vehicle, and are unable to comprehensively consider the results of functional safety and network security assessments, resulting in R&D personnel being unable to fully understand the safety of the vehicle.
By conducting hazard analysis and risk assessment, common vulnerability scoring system and threat analysis on the target object, the functional safety risk level and network security risk level of the target object are determined, and the comprehensive safety risk level is calculated using the preset correspondence. The comprehensive risk index is calculated in combination with the weight to achieve an overall safety assessment of the vehicle object.
It realizes the overall safety assessment of vehicle objects, provides a method for vehicle R&D personnel to understand the overall safety of objects on the vehicle, and improves the accuracy and comprehensiveness of the assessment results.
Smart Images

Figure CN120654243A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of vehicle technology, and specifically to an information acquisition method, device, vehicle, and storage medium. Background Art
[0002] Assessing the safety of vehicle components, systems, and other objects on a vehicle is a key step in vehicle development and testing. Functional safety and cybersecurity are core safety indicators for vehicle objects.
[0003] In the related art, the functional safety assessment results and the network security assessment results of objects on the vehicle are provided to vehicle developers separately, which prevents the vehicle developers from understanding the overall safety of the objects on the vehicle. Summary of the Invention
[0004] In view of this, embodiments of the present application provide an information acquisition method, device, vehicle, and storage medium.
[0005] In a first aspect, an embodiment of the present application provides an information acquisition method, the method comprising:
[0006] determining a target functional safety risk level of the target object on the target vehicle based on a first score of the target object obtained by applying a hazard analysis and risk assessment to the target object;
[0007] determining a target cybersecurity risk level of the target object based on a second score and a third score of the target object, wherein the second score is obtained by applying a common vulnerability scoring system to the target object, and the third score is obtained by applying a threat analysis and risk assessment to the target object;
[0008] According to the preset correspondence, the comprehensive security risk level corresponding to the target level combination is determined, and the comprehensive security risk level corresponding to the target level combination is determined as the comprehensive security risk level of the target object, the target level combination includes: the target functional safety risk level, the target network security risk level, the preset level combination includes: functional safety risk level, network security risk level, and the preset correspondence indicates the comprehensive security risk level corresponding to each preset level combination in multiple preset level combinations.
[0009] In one possible implementation, determining the comprehensive security risk level corresponding to the target level combination according to the preset correspondence includes:
[0010] Calculating a weighted sum of the normalized score of the first score, the normalized score of the second score, and the normalized score of the third score based on the weight of the normalized score of the first score, the weight of the normalized score of the second score, and the weight of the normalized score of the third score, and determining the weighted sum as a comprehensive risk index of the target object;
[0011] Determining a target comprehensive risk index interval in which the comprehensive risk index of the target object lies from a plurality of preset comprehensive risk index intervals, wherein each preset comprehensive risk index interval corresponds to a different preset corresponding relationship;
[0012] According to the preset corresponding relationship corresponding to the target comprehensive risk index interval, the comprehensive safety risk level corresponding to the target level combination is determined.
[0013] In one possible implementation, the weight of the normalized score of the first score is a first weight of the target object; and the method further includes:
[0014] A first weight of the target object is determined according to the domain to which the target object belongs and the target functional safety risk level.
[0015] In one possible implementation, determining the first weight of the target object according to the domain to which the target object belongs and the target functional safety risk level includes:
[0016] A first weight of the target object is determined based on the domain to which the target object belongs, the target functional safety risk level, and functional safety association information of the target object, wherein the functional safety association information indicates at least one of the following items: whether the target object is cascaded with other objects, and whether the target object has a failure mode.
[0017] In one possible implementation, the weight of the normalized score of the second score is the second weight of the target object; and the method further includes:
[0018] A second weight of the target object is determined based on the domain to which the target object belongs and vulnerability association information of the target object, where the vulnerability association information includes at least one of the following items: a Common Vulnerability Scoring System level of the target object and software features related to the target object, where the software features indicate at least one of the following items: a code volume level of code related to the target object, whether the code related to the target object is open source, and whether the target object is used to run an operating system.
[0019] In one possible implementation, the weight of the normalized score of the third score is the third weight of the target object; and the method further includes:
[0020] A third weight of the target object is determined according to the domain to which the target object belongs and attack association information of the target object, wherein the attack association information indicates at least one of the following items: an attack feasibility level of the target object and an attack method against the target object.
[0021] In a second aspect, an embodiment of the present application provides an information acquisition device, the information acquisition device comprising:
[0022] a target functional safety risk level determination unit, configured to determine a target functional safety risk level of the target object on the target vehicle based on a first score of the target object, wherein the first score is obtained by applying hazard analysis and risk assessment to the target object;
[0023] a target network security risk level determination unit, configured to determine a target network security risk level of the target object based on a second score and a third score of the target object, wherein the second score is obtained by applying a common vulnerability scoring system to the target object, and the third score is obtained by applying a threat analysis and risk assessment to the target object;
[0024] The comprehensive security risk level determination unit is used to determine the comprehensive security risk level corresponding to the target level combination according to a preset corresponding relationship, and determine the comprehensive security risk level corresponding to the target level combination as the comprehensive security risk level of the target object, the target level combination includes: the target functional safety risk level, the target network security risk level, the preset level combination includes: functional safety risk level, network security risk level, and the preset corresponding relationship indicates the comprehensive security risk level corresponding to each preset level combination in multiple preset level combinations.
[0025] In one possible implementation, the comprehensive security risk level determination unit is further used to calculate the weighted sum of the normalized score of the first score, the normalized score of the second score, and the normalized score of the third score based on the weight of the normalized score of the first score, the weight of the normalized score of the second score, and the weight of the normalized score of the third score, and determine the weighted sum as the comprehensive risk index of the target object; determine the target comprehensive risk index interval in which the comprehensive risk index of the target object is located from multiple preset comprehensive risk index intervals, wherein each preset comprehensive risk index interval corresponds to a different preset corresponding relationship; and determine the comprehensive security risk level corresponding to the target level combination based on the preset corresponding relationship corresponding to the target comprehensive risk index interval.
[0026] In a possible implementation, the weight of the normalized score of the first score is the first weight of the target object; and the information acquisition device further includes:
[0027] The first weight determination unit is configured to determine a first weight of the target object according to the domain to which the target object belongs and the target functional safety risk level.
[0028] In one possible implementation, the first weight determination unit is also used to determine the first weight of the target object based on the domain to which the target object belongs, the target functional safety risk level, and the functional safety association information of the target object, where the functional safety association information indicates at least one of the following items: whether the target object is cascaded with other objects, and whether the target object has a failure mode.
[0029] In one possible implementation, the weight of the normalized score of the second score is the second weight of the target object; and the information acquisition apparatus further includes:
[0030] A second weight determination unit is used to determine a second weight of the target object based on the domain to which the target object belongs and vulnerability association information of the target object, the vulnerability association information including at least one of the following items: a Common Vulnerability Scoring System level of the target object and software features related to the target object, the software features indicating at least one of the following items: a code amount level of the code amount of the code related to the target object, whether the code related to the target object is open source, and whether the target object is used to run an operating system.
[0031] In a possible implementation, the weight of the normalized score of the third score is the third weight of the target object; and the information acquisition device further includes:
[0032] The third weight determination unit is configured to determine a third weight of the target object based on the domain to which the target object belongs and attack association information of the target object, wherein the attack association information indicates at least one of the following items: an attack feasibility level of the target object and an attack method against the target object.
[0033] In a third aspect, an embodiment of the present application provides a vehicle comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, computer instructions being stored in the memory, and the processor executing the method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0034] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the method of the above-mentioned first aspect or any corresponding embodiment thereof.
[0035] In a fifth aspect, the present invention provides a computer program product comprising computer instructions for causing a computer to execute the method of the first aspect or any corresponding embodiment thereof.
[0036] The information acquisition method provided in the embodiment of the present application determines the target functional safety risk level of the target object based on the first score of the target object on the target vehicle; determines the target network security risk level of the target object based on the second score and the third score of the target object; determines the comprehensive safety risk level corresponding to the target level combination based on a preset correspondence, and determines the comprehensive safety risk level corresponding to the target level combination as the comprehensive safety risk level of the target object. Thus, based on the target functional safety risk level of the target object and the target network security risk level of the target object, an assessment result reflecting the overall safety of the target object, namely the comprehensive safety risk level of the target object, is determined. This allows vehicle R&D personnel to understand the overall safety of objects on the vehicle. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the specific implementation methods of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the specific implementation methods or the description of the prior art. Obviously, the drawings described below are some implementation methods of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0038] Figure 1 Schematic diagram of the information acquisition method provided in the embodiment of the present application;
[0039] Figure 2 is a flow chart of another information acquisition method provided in an embodiment of the present application;
[0040] Figure 3 It is a structural diagram of a computer device on a vehicle provided in an embodiment of the present application for executing the information acquisition method provided in an embodiment of the present application. DETAILED DESCRIPTION
[0041] To make the purpose, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.
[0042] refer to Figure 1 , which shows a flow chart of the information acquisition method provided in an embodiment of the present application.
[0043] As an example, the information acquisition method provided in the embodiment of the present application can be executed by a fusion security risk assessment model. The fusion security risk assessment model includes: a joint system modeling layer. The joint system modeling layer is used to define related items. Related items represent objects that need to be evaluated, such as equipment on the vehicle, components on the vehicle, systems on the vehicle, etc. The joint system modeling layer covers functional modules such as sensors, controllers and network assets such as communication protocols and key storage, and represents the coupling relationship between functional failure and network attacks through a two-way mapping of data flow diagrams (DFDs) and function block diagrams (FBDs). The fusion security risk assessment model can define a normal driving scenario (Driving Scenario), a damaged scenario (Damage Scenario), and a threat scenario (Threat Scenario). Among them, the damaged scenario refers to a scenario in which an asset is damaged due to the persecution of a certain property of an asset. The normal driving scenario may include location (Location), road conditions (Road Conditions), vehicle state (Vehicle State), etc.
[0044] In step S101 , a target functional safety risk level of a target object on a target vehicle is determined according to a first score of the target object.
[0045] The target object on the target vehicle may be equipment on the target vehicle, parts on the target vehicle, systems on the target vehicle, etc.
[0046] As an example, the target object is an ECU on a target vehicle.
[0047] As another example, the target object is an autonomous driving system on a target vehicle.
[0048] The first score for the target object on the target vehicle is obtained by applying a hazard analysis and risk assessment (HARA) to the target object. For details on HARA, refer to the international standards ISO 26262 and SAE J2980. Hazard analysis and risk assessment includes hazard identification and hazard classification.
[0049] It should be noted that the first score of the target object may be called the HARA score of the target object.
[0050] The functional safety risk level of the target object refers to the Automotive Safety Integrity Levels (ASIL) of the target object.
[0051] It should be noted that the functional safety risk level of the target object can be called the target functional safety risk level of the target object.
[0052] In step S101, a target HARA score interval within which the first score of the target object falls can be determined based on a correspondence between HARA score intervals and ASIL levels. The ASIL level corresponding to the target HARA score interval is determined as the ASIL level of the target object, i.e., the target functional safety risk level of the target object.
[0053] In step S102, a target network security risk level of the target object is determined based on the second score and the third score of the target object.
[0054] Cybersecurity risk levels can be divided into five levels: 5, 4, 3, 2, and 1. The risk level indicated by 5 is greater than the risk level indicated by 4. The risk level indicated by 4 is greater than the risk level indicated by 3. The risk level indicated by 3 is greater than the risk level indicated by 2. The risk level indicated by 2 is greater than the risk level indicated by 1.
[0055] It should be noted that, in the embodiment of the present application, the network security risk level of the target object may be referred to as the target network security risk level of the target object.
[0056] The second score of the target object is obtained by applying the Common Vulnerability Scoring System (CVSS) to the target object.
[0057] The second score of the target object is: the CVSS score of the target object. The second score of the target object is in the interval [0, 10].
[0058] In an embodiment of the present application, the CVSS rating of the target object can be determined based on the second score of the target object. The CVSS rating interval within which the CVSS rating of the target object falls can be determined based on the correspondence between the CVSS rating interval and the Common Vulnerability Scoring System rating. The Common Vulnerability Scoring System rating of the target object falls within the CVSS rating interval. The CVSS rating corresponding to the CVSS rating interval is determined as the Common Vulnerability Scoring System rating of the target object.
[0059] It should be noted that the Common Vulnerability Scoring System level of the target object can be called the CVSS level of the target object.
[0060] The third score of the target object is obtained by applying Threat Analysis and Risk Assessment (TARA) to the target object. For details of threat analysis and risk assessment, please refer to the part of TARA in the international standard ISO 21434 and SAE J2980. Among them, threat analysis and risk assessment include: threat identification and attack path analysis. Threat analysis and risk assessment are mainly evaluated from the aspects of security, controllability, property, privacy, etc. Among them, the target object can have multiple network security attributes. One network security attribute can correspond to multiple damage scenarios. One damage scenario can correspond to multiple threat scenarios. Applying threat analysis and risk assessment to the target object may include: evaluating the size of the risk of network attacks related to the target object. The network attacks related to the target object occur in the threat scenarios involved in the target object.
[0061] The third score of the target object is: the attack feasibility score of the target object.
[0062] In an embodiment of the present application, the attack feasibility rating of the target object can be determined based on the third score of the target object. Based on the corresponding relationship between the attack feasibility rating interval and the attack feasibility rating, the target attack feasibility rating interval in which the third score of the target object, i.e., the attack feasibility rating, falls can be determined. The attack feasibility rating of the target object is within the target attack feasibility rating interval. The attack feasibility rating corresponding to the target attack feasibility rating interval is determined as the attack feasibility rating of the target object.
[0063] Table 1 shows a schematic diagram of ASIL level, CVSS level, and attack feasibility level.
[0064] Table 1
[0065]
[0066]
[0067] ASIL levels are divided into ASILQM, ASILA, ASILB, ASILC, and ASILD. ASILD indicates a greater risk than ASILC, which in turn indicates a greater risk than ASILB, which in turn indicates a greater risk than ASILA. ASILA indicates a greater risk than ASILQM.
[0068] CVSS levels are classified into Critical, High, Medium, Low, and None. Critical indicates a greater risk than High, which in turn indicates a greater risk than Medium, which in turn indicates a greater risk than Low, which in turn indicates a greater risk than None.
[0069] Attack feasibility levels are categorized as High, Medium, Low, Very Low, and None. High indicates a greater risk than Medium, which in turn is greater than Low, which in turn is greater than Very Low, which in turn is greater than None.
[0070] In one possible implementation, step S102 determines the average of the normalized CVSS score of the target object's second score and the normalized third score of the target object. A target score interval within which the average falls is determined from multiple score intervals associated with network security risk levels. The multiple score intervals associated with network security risk levels are pre-set. The network security risk level corresponding to the target score interval is determined as the target network security risk level for the target object.
[0071] In another possible implementation, in step S102, the maximum value of the normalized CVSS score of the target object's second score and the normalized third score of the target object is determined. A target score interval in which the maximum value falls is determined from multiple score intervals associated with network security risk levels. The multiple score intervals associated with network security risk levels are pre-set. The network security risk level corresponding to the target score interval is determined as the target network security risk level of the target object.
[0072] In step S103 , the comprehensive security risk level corresponding to the target level combination is determined according to the preset corresponding relationship, and the comprehensive security risk level corresponding to the target level combination is determined as the comprehensive security risk level of the target object.
[0073] In an embodiment of the present application, the comprehensive security risk level can be divided into: Critical, High, Medium, Low, and Quality Management (QM). Among them, the size of the risk indicated by Critical is greater than the size of the risk indicated by High. The size of the risk indicated by High is greater than the size of the risk indicated by Medium, the size of the risk indicated by Medium is greater than the size of the risk indicated by Low, and the size of the risk indicated by Low is greater than the size of the risk indicated by QM. The risk handling method corresponding to Critical, the risk handling method corresponding to High, and the risk handling method corresponding to Medium are all required to be reduced. The risk handling method corresponding to Low is optional reduction. The risk handling method corresponding to Quality Management does not need to be reduced.
[0074] The target level combination includes: the target functional safety risk level of the target object and the target cybersecurity risk level of the target object.
[0075] The preset level combinations include: functional safety risk level and network security risk level.
[0076] For a preset level combination, the preset level combination is different from any preset level combination other than the preset level combination.
[0077] The preset corresponding relationship indicates: the comprehensive security risk level corresponding to each preset level combination in multiple preset level combinations.
[0078] The preset corresponding relationship can be represented by a matrix.
[0079] In step S103, a target preset level combination matching the target level combination is determined from the plurality of preset level combinations, and the comprehensive security risk level corresponding to the target preset level combination is determined as the comprehensive security risk level corresponding to the target level combination.
[0080] As an example, if the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 5, then the target level combination includes: ASILD, 5. The target preset level combination that matches the target level combination includes: ASILD, 5. If the comprehensive security risk level corresponding to the target preset level combination is Critical, then the comprehensive security risk level corresponding to the target level combination is Critical, and the comprehensive security risk level of the target object is Critical.
[0081] In the embodiment of the present application, if the comprehensive safety risk level (AASIL) of the target object is critical, the functional safety of the target object is developed and tested in accordance with the ISO 26262 ASILD standard. For the network security of the target object, the development and testing of the network security of the target object are carried out in accordance with the requirements of ISO 21434 Risk Level 5.
[0082] In this embodiment, if the target object's overall safety risk level (AASIL) is High, development and testing related to the target object's functional safety are performed in accordance with the ISO 26262 ASILC standard. For the target object's cybersecurity, development and testing documents are developed and tested in accordance with ISO 21434 Risk Level 4 requirements.
[0083] In this embodiment of the present application, if the target object's comprehensive safety risk level (AASIL) is medium, development and testing related to the target object's functional safety are performed in accordance with the ISO 26262 ASILB standard. For the target object's cybersecurity, development and testing related to the target object's cybersecurity are performed in accordance with the ISO 21434 Risk Level 3 requirements.
[0084] In the embodiments of the present application, if the target object's comprehensive safety risk level (AASIL) is low, development and testing related to the target object's functional safety are performed in accordance with the ISO 26262 ASILA standard. For the target object's cybersecurity, development and testing related to the target object's cybersecurity are performed in accordance with the ISO 21434 Risk Level 2 requirements.
[0085] In the embodiment of the present application, if the comprehensive safety risk level (AASIL level) of the target object is quality management (ASILQM), development and testing related to the functional safety of the target object are performed in accordance with the ISO26262 ASILQM standard. For the network security of the target object, development and testing related to the network security of the target object are performed in accordance with the requirements of ISO21434 Risk Level 1.
[0086] refer to Figure 2 , which shows a flow chart of another information acquisition method provided in an embodiment of the present application.
[0087] In step S201 , a target functional safety risk level of a target object on a target vehicle is determined according to a first score of the target object.
[0088] In step S202 , a target network security risk level of the target object is determined based on the second score and the third score of the target object.
[0089] In step S203, the comprehensive risk index of the target object is determined based on the first score of the target object, the second score of the target object, and the third score of the target object; the target comprehensive risk index range in which the comprehensive risk index of the target object lies is determined; the comprehensive security risk level corresponding to the target level combination is determined based on the preset correspondence corresponding to the target comprehensive risk index range; and the comprehensive security risk level corresponding to the target level combination is determined as the comprehensive security risk level of the target object.
[0090] It should be noted that, in the embodiment of the present application, the comprehensive risk index interval in which the comprehensive risk index of the target object is located is called the target comprehensive risk index interval.
[0091] In step S203, a comprehensive risk index for the target object is determined, reflecting the magnitude of the overall security risk of the target object. This index takes into account the correlation between the magnitude of the overall security risk of the target object and the comprehensive security risk level of the target object. Thus, when determining the comprehensive security risk level of the target object, the correlation between each of the functional safety risk level and the target network security risk level of the target object and the comprehensive security risk level of the target object is considered, as well as the correlation between the magnitude of the overall security risk of the target object and the comprehensive security risk level of the target object, thereby improving the accuracy of the determined comprehensive security risk level of the target object.
[0092] Step S203 includes: step S2031-step S2033.
[0093] In step S2031, based on the weight of the normalized score of the first score of the target object, the weight of the normalized score of the second score of the target object, and the weight of the normalized score of the third score of the target object, the weighted sum of the normalized score of the first score of the target object, the normalized score of the second score of the target object, and the normalized score of the third score of the target object is calculated, and the weighted sum is determined as the comprehensive risk index of the target object.
[0094] In step S2031, the first score of the target object can be normalized to the interval [0, 1] to obtain a normalized score of the first score of the target object. The second score of the target object can be normalized to the interval [0, 1] to obtain a normalized score of the second score of the target object. The third score of the target object can be normalized to the interval [0, 1] to obtain a normalized score of the third score of the target object.
[0095] In a possible implementation, in step S3031, a Min-Max normalization method may be used to normalize the first score of the target object, the second score of the target object, and the third score of the target object to the interval [0, 1] respectively.
[0096] Table 2 shows an example of the corresponding relationship between security risk levels and normalized scoring intervals.
[0097] Table 2
[0098]
[0099]
[0100] In this example, for an object with a functional safety risk level of ASILD, the normalized score of the first score of the object is within [0.9, 1]. For an object with a functional safety risk level of ASILC, the normalized score of the first score of the object is within [0.75, 0.9). For an object with a functional safety risk level of ASILB, the normalized score of the first score of the object is within [0.4, 0.75). For an object with a functional safety risk level of ASILA, the normalized score of the first score of the object is within [0.2, 0.4). For an object with a functional safety risk level of ASILQM, the normalized score of the first score of the object is within [0, 0.2).
[0101] In this example, for an object with a CVSS rating of Critical, the normalized score of the second score of the object is within [0.9, 1]. For an object with a CVSS rating of High, the normalized score of the second score of the object is within [0.75, 0.9). For an object with a CVSS rating of Medium, the normalized score of the second score of the object is within [0.4, 0.75). For an object with a CVSS rating of Low, the normalized score of the second score of the object is within [0.2, 0.4). For an object with a CVSS rating of None, the normalized score of the second score of the object is within [0, 0.2).
[0102] In this example, for an object with a high attack feasibility level (High), the normalized score of the third score of the object is within [0.9, 1). For an object with a medium attack feasibility level (Medium), the normalized score of the third score of the object is within [0.75, 0.9). For an object with a low attack feasibility level (Low), the normalized score of the third score of the object is within [0.4, 0.75). For an object with a very low attack feasibility level (Very Low), the normalized score of the third score of the object is within [0.2, 0.4). For an object with a none attack feasibility level (None), the normalized score of the third score of the object is within [0, 0.2).
[0103] It should be noted that the weight of the normalized score of the first score is the first weight of the target object, the weight of the normalized score of the second score is the second weight of the target object, and the weight of the normalized score of the third score is the third weight of the target object.
[0104] The weight of the normalized score of the first score, that is, the first weight of the target object, can be recorded as α, the weight of the normalized score of the second score, that is, the second weight of the target object, can be recorded as β, and the weight of the normalized score of the third score, that is, the third weight of the target object, can be recorded as γ.
[0105] It should be noted that α, β, and γ are not less than 0, and α, β, and γ are not greater than 1. α, β, and γ are all within [0, 1].
[0106] The comprehensive risk index of the target object can be expressed as:
[0107] CRI=α·ASILnorm+β·CVSSnorm+γ·Attack Feasibility
[0108] Among them, CRI represents the comprehensive risk index of the target object, α is the weight of the normalized score of the target object's first score, β is the weight of the normalized score of the target object's second score, γ is the weight of the normalized score of the target object's third score, ASILnorm represents the normalized score of the target object's first score, CVSSnorm represents the normalized score of the target object's second score, and Attack Feasibility represents the normalized score of the target object's third score.
[0109] In step S2032, a target comprehensive risk index interval in which the comprehensive risk index of the target object lies is determined from a plurality of preset comprehensive risk index intervals.
[0110] Among them, each preset comprehensive risk index interval corresponds to a different preset corresponding relationship.
[0111] In the embodiment of the present application, the comprehensive risk index interval in which the comprehensive risk index of the target object is located is called the target comprehensive risk index interval.
[0112] In one possible implementation, the first preset comprehensive risk index interval is a left-closed and right-open interval with a left endpoint of 0. The last preset comprehensive risk index interval is a left-closed and right-closed interval with a right endpoint of the preset maximum comprehensive risk index. The preset comprehensive risk index interval between the first preset comprehensive risk index interval and the last preset comprehensive risk index interval is a left-closed and right-open interval. The right endpoint of the preset comprehensive risk index interval between the first preset comprehensive risk index interval and the last preset comprehensive risk index interval is less than the preset maximum comprehensive risk index, and the left endpoint of the preset comprehensive risk index interval between the first preset comprehensive risk index interval and the last preset comprehensive risk index interval is greater than 0.
[0113] In step S2033, the comprehensive security risk level corresponding to the target level combination is determined according to the preset corresponding relationship corresponding to the target comprehensive risk index interval.
[0114] The preset corresponding relationship indication corresponding to the target comprehensive risk index interval is: within the target comprehensive risk index interval, the comprehensive safety risk level corresponding to each preset level combination in the multiple preset level combinations.
[0115] In step S2033, a preset level combination matching the target level combination is determined, and the comprehensive security risk level corresponding to the preset level combination within the target comprehensive risk index range is determined as the comprehensive security risk level corresponding to the target level combination.
[0116] It should be noted that the comprehensive security risk level can be called the AASIL level. The preset correspondence relationship can be represented by a matrix. The matrix representing the preset correspondence relationship can be called the AASIL matrix. The cybersecurity risk level can be called the Cybersecurity Risk Level.
[0117] Table 3 shows an example of the AASIL matrix corresponding to the preset comprehensive risk index interval [0, 1).
[0118] Table 3
[0119]
[0120] In the example shown in Table 3, if the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 5, the AASIL level of the target object is severe, i.e., Critical. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 4, the AASIL level of the target object is severe, i.e., Critical. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 3, the AASIL level of the target object is severe, i.e., Critical. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 2, the AASIL level of the target object is high, i.e., High. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 1, the AASIL level of the target object is high, i.e., High.
[0121] In the example shown in Table 3, if the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 5, the AASIL level of the target object is severe, i.e., Critical. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 4, the AASIL level of the target object is severe, i.e., Critical. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 3, the AASIL level of the target object is high, i.e., High. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 2, the AASIL level of the target object is high, i.e., High. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 1, the AASIL level of the target object is medium, i.e., Medium.
[0122] Table 4 shows an example of the AASIL matrix corresponding to the preset comprehensive risk index interval [1, 2).
[0123] Table 4
[0124]
[0125] In the example shown in Table 4, if the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 5, the AASIL level of the target object is severe, i.e., Critical. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 4, the AASIL level of the target object is severe, i.e., Critical. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 3, the AASIL level of the target object is high, i.e., High. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 2, the AASIL level of the target object is medium, i.e., Medium. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 1, the AASIL level of the target object is low, i.e., Low.
[0126] In the example shown in Table 4, if the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 5, the AASIL level of the target object is severe, i.e., Critical. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 4, the AASIL level of the target object is high, i.e., High. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 3, the AASIL level of the target object is high, i.e., High. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 2, the AASIL level of the target object is medium, i.e., Medium. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 1, the AASIL level of the target object is medium, i.e., Medium.
[0127] Table 5 shows an example of the AASIL matrix corresponding to the preset comprehensive risk index interval [2, 3].
[0128] Table 5
[0129]
[0130]
[0131] In the example shown in Table 5, if the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 5, the AASIL level of the target object is severe, i.e., Critical. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 4, the AASIL level of the target object is severe, i.e., Critical. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 3, the AASIL level of the target object is high, i.e., High. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 2, the AASIL level of the target object is medium, i.e., Medium. If the target ASIL level of the target object is ASILD and the target cybersecurity risk level of the target object is 1, the AASIL level of the target object is low, i.e., Low.
[0132] In the example shown in Table 5, if the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 5, the AASIL level of the target object is severe, i.e., Critical. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 4, the AASIL level of the target object is high, i.e., High. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 3, the AASIL level of the target object is high, i.e., High. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 2, the AASIL level of the target object is medium, i.e., Medium. If the target ASIL level of the target object is ASILC and the target cybersecurity risk level of the target object is 1, the AASIL level of the target object is low, i.e., Low.
[0133] In a possible implementation, the information acquisition method provided in the embodiment of the present application further includes: step S204.
[0134] In step S204 , a first weight of the target object is determined according to the domain to which the target object belongs and the target functional safety risk level of the target object.
[0135] In a possible implementation, the greater the target functional safety risk level of the target object is, the greater the first weight α of the target object is.
[0136] The first weight of the target object indicates the degree to which the size of the target function safety risk score of the target object affects the size of the comprehensive risk index of the target object.
[0137] In step S204, the domain to which the target object belongs, the target function safety risk level of the target object, and the magnitude correlation of the target function safety risk score of the target object are considered to improve the accuracy of the determined first weight of the target object and the accuracy of the comprehensive safety risk level of the target object.
[0138] For the domain to which the target object belongs, a one-to-one correspondence between multiple functional safety risk levels and multiple first weights under the domain is preset.
[0139] For each functional safety risk level in the multiple functional safety risk levels, the one-to-one correspondence between the multiple functional safety risk levels and the multiple first weights under the domain to which the target object belongs indicates: the first weight corresponding to the functional safety risk level under the domain to which the target object belongs.
[0140] For the target object, based on the one-to-one correspondence between multiple functional safety risk levels and multiple first weights under the domain to which the target object belongs, the first weight corresponding to the target functional safety risk level under the domain to which the target object belongs is determined, and the first weight corresponding to the target functional safety risk level under the domain to which the target object belongs is determined as the first weight of the target object.
[0141] As an example, the target object is an object in the body domain. The α of the target object is in the range [0-0.4]. The functional safety risk level of the ECU in the body domain is low. Only the functional safety risk level of the body control module in the body domain is ASILB. The functional safety risk level of most components in the body domain is ASILA or QM. The higher the target functional safety risk level of the target object, the larger the α of the target object can be. If the target functional safety risk level of the target object is higher than ASILA, the α of the target object can be greater than 0.2. If the target functional safety risk level of the target object is higher than ASILB, the α of the target object can be 0.4. If the target functional safety risk level of the target object is equal to ASILB, the α of the target object can be 0.3. If the target functional safety risk level of the target object is ASILA, the α of the target object can be 0.2. If the target functional safety risk level of the target object is QM, the α of the target object can be 0.
[0142] As an example, the target object is an object in the cockpit domain, and the α of the target object is within [0, 0.5]. The functional safety risk level of the ECU in the cockpit domain is relatively low. Only the functional safety risk level of the cockpit main module in the cockpit domain is ASILB, and the functional safety risk level of most objects in the cockpit domain is ASILA or QM. The higher the functional safety risk level of the object in the cockpit domain, the larger the α of the object in the cockpit domain can be. If the functional safety risk level of the target object is higher than ASILA, the α of the target object can be greater than 0.2. If the functional safety risk level of the target object is ASILB, the α of the target object can be 0.5. If the functional safety risk level of the target object is ASILA, the α of the target object can be 0.2. If the functional safety risk level of the target object is QM, the α of the target object can be 0.
[0143] As an example, the target object is an object in the intelligent driving domain. α is within the weight range [0.4, 0.6]. The functional safety risk level of the ECU in the intelligent driving domain is relatively high, and the energy safety risk level of the ADAS controller is ASILB. The energy safety risk level of the sensor is ASILA or ASILB. The actuator path planning is ASILB. The higher the functional safety risk level of the object in the intelligent driving domain, the larger the object's α can be. If the functional safety risk level of the target object is higher than ASILB, the target object's α can be 0.6. If the functional safety risk level of the target object is ASILB, the target object's α can be 0.5. If the functional safety risk level of the target object is ASILA, the target object's α can be 0.4.
[0144] As an example, the target object is an object in the chassis domain. The α of the chassis domain is in the range [0.7, 1]. The higher the functional safety risk level of the object in the chassis domain, the larger the α of the object can be. If the functional safety risk level of the target object is higher than ASILB, the α of the target object can be greater than 0.8. If the functional safety risk level of the target object is ASILD, the α of the target object can be 1. If the functional safety risk level of the target object is ASILC, the α of the target object can be 0.9. If the functional safety risk level of the target object is ASILB, the α of the target object can be 0.8. If the functional safety risk level of the target object is ASILA, the α of the target object can be 0.7.
[0145] As an example, the target object is an object in the power domain. The α of the power domain is within [0.7, 1]. The functional safety risk level of the ECU in the power domain is relatively high. If the functional safety risk level of the target object is higher than ASILB, the α of the target object can be greater than 0.8. If the functional safety risk level of the target object is ASILD, the α of the target object can be 1. If the functional safety risk level of the target object is ASILC, the α of the target object can be 0.9. If the functional safety risk level of the target object is ASILB, the α of the target object can be 0.8. If the functional safety risk level of the target object is ASILA, the α of the target object can be 0.7.
[0146] In a possible implementation, step S204 includes: step S2041.
[0147] In step S2041, determining the first weight of the target object according to the domain to which the target object belongs and the target functional safety risk level of the target object includes: determining the first weight of the target object according to the domain to which the target object belongs, the target functional safety risk level of the target object, and functional safety association information of the target object, the functional safety association information of the target object indicating at least one of the following items: whether the target object is cascaded with other objects, and whether the target object has a failure mode.
[0148] The second weight of the target object indicates the degree to which the size of the target function safety risk score of the target object affects the size of the comprehensive risk index of the target object.
[0149] In step S2041, the correlation between the functional safety association information of the target object and the target functional safety risk score of the target object is considered to improve the accuracy of the determined first weight of the target object and the accuracy of the comprehensive safety risk level of the target object.
[0150] In an embodiment of the present application, a plurality of preset functional safety association information is pre-set.
[0151] For each preset functional safety-related information in the plurality of preset functional safety-related information, the preset functional safety-related information indicates at least one of the following items: whether the object is cascaded with other objects, and whether the object has a failure mode.
[0152] It should be noted that an object being cascaded with other objects may mean that the object is connected to other objects of the same type. For example, if an ECU is connected to other ECUs, then the ECU is considered an object cascaded with other objects. An object having a failure mode may mean that a failure condition associated with the object exists that poses a threat to the vehicle. This failure condition may include a malfunction of the object or an attack on the object.
[0153] In an embodiment of the present application, a one-to-one correspondence between multiple preset information for determining the first weight and multiple first weights is pre-set under the domain to which the target object belongs. The preset information for determining the first weight includes: preset functional safety association information and preset functional safety risk level.
[0154] For each piece of preset information for determining the first weight in multiple pieces of preset information for determining the first weight, the one-to-one correspondence between the multiple pieces of preset information for determining the first weight and the multiple first weights under the domain to which the target object belongs indicates: under the domain to which the target object belongs, the first weight corresponding to the preset information for determining the first weight.
[0155] In the embodiment of the present application, the target functional safety risk level of the target object and the functional safety association information of the target object constitute the target information used to determine the first weight.
[0156] In step S2041, preset information for determining the first weight that matches the target information for determining the first weight is determined, and the first weight corresponding to the preset information for determining the first weight is determined as the first weight of the target object.
[0157] As an example, if the target object is an ECU in the body domain and the target functional safety risk level is ASILB, the target object is cascaded with other objects, and the target object has a failure mode, then the target object's α can be 0.4. If the target functional safety risk level is ASILA, the target object is cascaded with other objects, and the target object has a failure mode, then the target object's α can be 0.3. If the target functional safety risk level is ASILQM, the target object is cascaded with other objects, and the target object has a failure mode, then the target object's α can be 0.1.
[0158] As an example, the target object is an ECU in the cockpit domain. If the target functional safety risk level of the target object is ASILB, the target object is cascaded with other objects, and the target object has a failure mode, the target object's α can be 0.5. If the target functional safety risk level of the target object is ASILA, the target object is cascaded with other objects, and the target object has a failure mode, the target object's α can be 0.3. If the target functional safety risk level of the target object is ASILQM, the target object is cascaded with other objects, and the target object has a failure mode, the target object's α can be 0.1.
[0159] As an example, if the target object is an object in the intelligent driving domain and the target functional safety risk level is ASILB and the target object is a domain controller, the target object's α can be 0.6. If the target functional safety risk level is ASILB and the target object is a sensor, the target object's α can be 0.5. If the target functional safety risk level is ASILA and the target object is a domain controller, the target object's α can be 0.5. If the target functional safety risk level is ASILA and the target object is a sensor, the target object's α can be 0.4.
[0160] In a possible implementation, the information acquisition method provided in the embodiment of the present application further includes: step S205.
[0161] In step S205, a second weight of the target object is determined based on the domain to which the target object belongs and vulnerability association information of the target object. The vulnerability association information of the target object includes at least one of the following: a Common Vulnerability Scoring System (CVSS) level of the target object and software features associated with the target object. The software features associated with the target object indicate at least one of the following: a code volume level of the code associated with the target object, whether the code associated with the target object is open source, and whether the target object is used to run an operating system. For the domain to which the target object belongs, a one-to-one correspondence between multiple preset vulnerability association information and multiple second weights is pre-set for the domain.
[0162] The second weight of the target object indicates the degree to which the magnitude of the Common Vulnerability Scoring System score of the target object affects the magnitude of the comprehensive risk index of the target object.
[0163] In step S205, the Common Vulnerability Scoring System (CVSS) level of the target object and the correlation between the CVSS score and at least one of the software features associated with the target object are considered to improve the accuracy of the second weight determined for the target object and the accuracy of the comprehensive security risk level of the target object.
[0164] In a possible implementation, the higher the CVSS level of the target object, the greater the second weight β of the target object.
[0165] In the embodiment of the present application, a one-to-one correspondence between multiple code amount intervals and multiple code amount levels is preset.
[0166] The code related to the target object includes: the code executed by the target object.
[0167] In step S205 , the code amount interval of the code related to the target object is determined, and the code amount level corresponding to the code amount interval is determined as the code amount level of the code related to the target object.
[0168] In the embodiment of the present application, a plurality of preset vulnerability association information is pre-set.
[0169] For each preset vulnerability association information in the multiple preset vulnerability association information, the preset vulnerability association information indicates at least one of the following items: a common vulnerability scoring system level, a preset software feature, and the preset software feature indicates at least one of the following items: a code volume level, whether the code is open source, and whether the code is used to run an operating system.
[0170] In the embodiment of the present application, a one-to-one correspondence between a plurality of preset vulnerability association information and a plurality of second weights is pre-set under the domain to which the target object belongs.
[0171] For each preset vulnerability association information in the multiple preset vulnerability association information, the one-to-one correspondence between the multiple preset vulnerability association information and the multiple second weights under the domain to which the target object belongs indicates: the second weight corresponding to the preset vulnerability association information under the domain to which the target object belongs.
[0172] In step S205 , preset vulnerability association information matching the vulnerability association information of the target object is determined, and a second weight corresponding to the preset vulnerability association information is determined as the second weight of the target object.
[0173] As an example, the target object is an object in the body domain. The β value of the target object is in the range [0.2, 0.5]. Most objects in the body domain are firmware and AutoSAR-related components. The code associated with objects in the body domain is relatively small, and the CVSS scores of objects in the body domain are generally low. Therefore, the highest β value for objects in the body domain can be 0.5. If the CVSS level of the target object is Critical or High, the β value of the target object can be greater than 0.4. If the CVSS level of the target object is lower than Medium, the β value of the target object can be less than 0.4. When determining the second weight of the target object based on the code level of the code associated with the target object, if the target object is a body control module, the β value of the target object can be 0.5. If the code associated with the target object is firmware, the β value of the target object can be 0.2. When determining the β value of the target object based on whether the target object is used to run an operating system, if the target object is not used to run an operating system, the β value of the target object can be 0.2. If the target object is used to run a small operating system, such as a microcontroller, the β value of the target object can be 0.35. If the target object is used to run a large operating system, for example, the target object is a component defined by AutoSAR, then β of the target object can be 0.5.
[0174] As an example, the target object is an object in the cockpit domain. The β value for the target object is in the range [0.5, 1]. For most objects in the cockpit domain, the code associated with the object is open source, and the object's CVSS score is generally high. The highest β value for a cockpit domain object can be 1. If the target object's CVSS score is Critical or High, the β value for the target object can be greater than 0.7. If the target object's CVSS score is less than Medium, the β value for the target object can be less than 0.7. HeadUnits in the cockpit domain have the most open source code and the most vulnerabilities, so the β value for HeadUnits can be 1. Firmware in the cockpit domain, such as in-car cameras, can have a β value of 0.5. When determining the β value of a target object based on whether the target object is used to run an operating system and whether the code associated with the target object is open source, if the target object is not used to run an operating system and the code associated with the target object is not open source, the β value for the target object can be 0.5. If the target object is used to run an operating system and the code associated with the target object is not open source, the β value for the target object can be 0.75. If the target object is used to run a large operating system and the code associated with the target object is open source, the β value for the target object can be 1.
[0175] As an example, the target object is an object in the intelligent driving domain. The β of the target object is within [0.2, 0.6]. Most objects in the intelligent driving domain are firmware and AutoSAR-related parts. For most objects in the intelligent driving domain, there is relatively little open source code related to the object. The CVSS scores of objects in the intelligent driving domain are generally low, and the maximum CVSS score can be 0.6. The β of the intelligent driving domain controller in the intelligent driving domain can be 0.6. The β of the sensor in the intelligent driving domain can be 0.2. If the CVSS level of the target object is Critical or High, the β of the target object can be greater than 0.5. When determining the β of the target object based on whether the target object is used to run an operating system, if the target object is not used to run an operating system, the β of the target object can be 0.2. If the target object is used to run a small operating system, the β of the target object can be 0.4. If the target object is used to run a large operating system, the β of the target object can be 0.6.
[0176] As an example, the target object is an object in the chassis domain. The β of the target object is in the range [0, 0.4]. If the CVSS level of the target object is Critical or High, the β of the target object can be greater than 0.2. If the target object is a chassis domain controller, the β of the target object can be 0.4. If the target object is a suspension component or sensor, the β of the target object can be 0. When determining the β of the target object based on whether the target object is used to run an operating system, if the target object is not used to run an operating system, the β of the target object is 0. If the target object is used to run a small operating system, the β of the target object can be 0.2. If the target object is used to run a large operating system, the β of the target object can be 0.4.
[0177] As an example, the target object is an object in the power domain. The β of the target object is within [0.2, 0.6]. Most objects in the power domain are firmware and AutoSAR-related parts. For most objects in the power domain, there is relatively little open source code related to the objects. The CVSS scores of objects in the power domain are generally low. The maximum β of an object in the power domain can be 0.6. If the CVSS level of the target object is Critical or High, the β of the target object can be greater than 0.4. If the target object is a power domain controller, the β of the target object can be 0.6. If the target object is a sensor, the β of the target object can be 0.2. When determining the β of the target object based on whether the target object is used to run an operating system, if the target object is not used to run an operating system, the β of the target object is 0.2. If the target object is used to run a small operating system, the β of the target object can be 0.4. If the target object is used to run a large operating system, the β of the target object can be 0.6.
[0178] In a possible implementation, the information acquisition method provided in the embodiment of the present application further includes: step S206.
[0179] In step S206, a third weight of the target object is determined based on the domain to which the target object belongs and the attack association information of the target object, where the attack association information of the target object indicates at least one of the following items: an attack feasibility level of the target object and an attack method against the target object.
[0180] The third weight of the target object indicates the degree of influence of the attack feasibility score of the target object on the magnitude of the comprehensive risk index of the target object.
[0181] In step S206, the domain to which the target object belongs and the magnitude correlation of each of the attack association information of the target object with the attack feasibility score of the target object are considered to improve the accuracy of the determined third weight of the target object and the accuracy of the comprehensive security risk level of the target object.
[0182] In a possible implementation, the higher the attack feasibility level of the target object is, the greater the third weight γ of the target object is.
[0183] In the embodiment of the present application, a plurality of preset attack association information may be pre-set.
[0184] For each attack association information in the plurality of preset vulnerability association information, the preset attack association information indicates at least one of the following items: an attack feasibility level, and an attack method against an object.
[0185] In the embodiment of the present application, a one-to-one correspondence between a plurality of preset attack association information and a plurality of third weights under the domain to which the target object belongs may be preset.
[0186] For each preset attack association information in the multiple preset attack association information, the one-to-one correspondence between the multiple preset attack association information under the domain to which the target object belongs and the multiple third weights indicates: the third weight corresponding to the attack association information under the domain to which the target object belongs.
[0187] In step S206, preset attack association information matching the attack association information of the target object is determined, and a third weight corresponding to the preset attack association information is determined as the third weight of the target object.
[0188] As an example, the target object is an object in the vehicle body domain. The γ of the target object is within [0.3, 0.6). When determining the third weight of the target object based on the attack method against the target object, if the attack method against the target object is a physical attack against the target object, the γ of the target object can be 0.3. If the attack method against the target object is to attack the target object through a component used for communication on the target vehicle, such as attacking the target object through a TBOX and a gateway, the γ of the target object can be 0.5. If the attack method against the target object is to attack the target object by invading the domain to which the target object belongs, such as attacking the target object by invading the cockpit through short-range communication, the γ of the target object can be 0.4.
[0189] As an example, the target object is an object in the cockpit domain. The γ of the target object is within [0.7, 1]. When determining the third weight of the target object based on the attack method against the target object, if the attack method against the target object is a physical attack against the target object, the γ of the target object can be 0.7. If the attack method against the target object is to attack the target object through a component used for communication on the target vehicle, such as attacking the target object through a TBOX and a gateway, the γ of the target object can be 0.8. If the attack method against the target object is to attack the target object by invading the domain to which the target object belongs, such as attacking the target object by invading the cockpit through short-range communication, the γ of the target object can be 0.9.
[0190] As an example, the target object is an object in the intelligent driving domain. The γ of the target object is within the weight interval [0.4, 0.7]. When the third weight of the target object is determined based on the attack method against the target object, if the attack method against the target object is a physical attack against the target object, the γ of the target object can be 0.4. If the attack method against the target object is to attack the target object through the components used for communication on the target vehicle, such as attacking the target object through TBOX and gateway, the γ of the target object can be 0.6. If the attack method against the target object is to attack the target object when invading the domain to which the target object belongs, such as attacking the target object when invading the cockpit through short-range communication, the γ of the target object can be 0.5.
[0191] As an example, the target object is an object in the chassis domain. The γ of the target object is within [0.1, 0.4]. When determining the third weight of the target object based on the attack method against the target object, if the attack method against the target object is a physical attack against the target object, the γ of the target object can be 0.1. If the attack method against the target object is to attack the target object through a component used for communication on the target vehicle, such as attacking the target object through a TBOX and a gateway, the γ of the target object can be 0.4. If the attack method against the target object is to attack the target object by invading the domain to which the target object belongs, such as attacking the target object by invading the cockpit through short-range communication, the γ of the target object can be 0.3.
[0192] As an example, the target object is an object in the power domain. The γ of the target object is within [0.1, 0.4]. When determining the third weight of the target object based on the attack method against the target object, if the attack method against the target object is a physical attack against the target object, the γ of the target object can be 0.1. If the attack method against the target object is to attack the target object through the components used for communication on the target vehicle, such as attacking the target object through TBOX and gateway, the γ of the target object can be 0.4. If the attack method against the target object is to attack the target object by invading the domain to which the target object belongs, such as attacking the target object by invading the cockpit through short-range communication, the γ of the target object can be 0.3.
[0193] The embodiments of the present application provide an information acquisition device. This device is used to implement the above-mentioned embodiments and preferred embodiments, and the details already described will not be repeated. As used below, the term "unit" may refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.
[0194] The information acquisition device includes:
[0195] a target functional safety risk level determination unit, configured to determine a target functional safety risk level of the target object on the target vehicle based on a first score of the target object, wherein the first score is obtained by applying hazard analysis and risk assessment to the target object;
[0196] a target network security risk level determination unit, configured to determine a target network security risk level of the target object based on a second score and a third score of the target object, wherein the second score is obtained by applying a common vulnerability scoring system to the target object, and the third score is obtained by applying a threat analysis and risk assessment to the target object;
[0197] The comprehensive security risk level determination unit is used to determine the comprehensive security risk level corresponding to the target level combination according to a preset corresponding relationship, and determine the comprehensive security risk level corresponding to the target level combination as the comprehensive security risk level of the target object, the target level combination includes: the target functional safety risk level, the target network security risk level, the preset level combination includes: functional safety risk level, network security risk level, and the preset corresponding relationship indicates the comprehensive security risk level corresponding to each preset level combination in multiple preset level combinations.
[0198] In one possible implementation, the comprehensive security risk level determination unit is further used to calculate the weighted sum of the normalized score of the first score, the normalized score of the second score, and the normalized score of the third score based on the weight of the normalized score of the first score, the weight of the normalized score of the second score, and the weight of the normalized score of the third score, and determine the weighted sum as the comprehensive risk index of the target object; determine the target comprehensive risk index interval in which the comprehensive risk index of the target object is located from multiple preset comprehensive risk index intervals, wherein each preset comprehensive risk index interval corresponds to a different preset corresponding relationship; and determine the comprehensive security risk level corresponding to the target level combination based on the preset corresponding relationship corresponding to the target comprehensive risk index interval.
[0199] In a possible implementation, the weight of the normalized score of the first score is the first weight of the target object; and the information acquisition device further includes:
[0200] The first weight determination unit is configured to determine a first weight of the target object according to the domain to which the target object belongs and the target functional safety risk level.
[0201] In one possible implementation, the first weight determination unit is also used to determine the first weight of the target object based on the domain to which the target object belongs, the target functional safety risk level, and the functional safety association information of the target object, where the functional safety association information indicates at least one of the following items: whether the target object is cascaded with other objects, and whether the target object has a failure mode.
[0202] In one possible implementation, the weight of the normalized score of the second score is the second weight of the target object; and the information acquisition apparatus further includes:
[0203] A second weight determination unit is used to determine a second weight of the target object based on the domain to which the target object belongs and vulnerability association information of the target object, the vulnerability association information including at least one of the following items: a Common Vulnerability Scoring System level of the target object and software features related to the target object, the software features indicating at least one of the following items: a code amount level of the code amount of the code related to the target object, whether the code related to the target object is open source, and whether the target object is used to run an operating system.
[0204] In a possible implementation, the weight of the normalized score of the third score is the third weight of the target object; and the information acquisition device further includes:
[0205] The third weight determination unit is configured to determine a third weight of the target object based on the domain to which the target object belongs and attack association information of the target object, wherein the attack association information indicates at least one of the following items: an attack feasibility level of the target object and an attack method against the target object.
[0206] In this embodiment, the device is presented in the form of a functional unit, where the unit refers to an ASIC circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0207] The further functional description of each of the above units is the same as that of the above corresponding embodiments and will not be repeated here.
[0208] refer to Figure 3, which shows a schematic structural diagram of a computer device for executing the information acquisition method provided by an embodiment of the present application on a vehicle provided by an embodiment of the present application, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. The various components are connected to each other using different buses for communication, and can be installed on a common motherboard or installed in other ways as needed. The processor can process instructions executed in the computer device, including instructions stored in or on the memory to display graphical information of the GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system).
[0209] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.
[0210] The memory 20 stores instructions that can be executed by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.
[0211] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0212] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0213] The computer device further includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means.
[0214] The input device 30 can receive input digital or character information and generate key signal input related to user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touch pad, an indicator stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 can include a display device, an auxiliary lighting device (e.g., an LED), and a tactile feedback device (e.g., a vibration motor). The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display, and a plasma display. In some optional embodiments, the display device can be a touch screen.
[0215] The embodiments of the present application also provide a computer-readable storage medium. The above-mentioned method according to the embodiment of the present application can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.
[0216] A portion of the embodiments of the present application may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the form in which the computer program instruction exists in a computer-readable medium includes but is not limited to a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to the computer.
[0217] Although the embodiments of the present application have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present application, and such modifications and variations shall fall within the scope defined by the appended claims.
Claims
1. A method for obtaining information, characterized in that: The method comprises: determining a target functional safety risk level of the target object on the target vehicle based on a first score of the target object obtained by applying a hazard analysis and risk assessment to the target object; determining a target cybersecurity risk level of the target object based on a second score and a third score of the target object, wherein the second score is obtained by applying a common vulnerability scoring system to the target object, and the third score is obtained by applying a threat analysis and risk assessment to the target object; According to the preset correspondence, the comprehensive security risk level corresponding to the target level combination is determined, and the comprehensive security risk level corresponding to the target level combination is determined as the comprehensive security risk level of the target object, the target level combination includes: the target functional safety risk level, the target network security risk level, the preset level combination includes: functional safety risk level, network security risk level, and the preset correspondence indicates the comprehensive security risk level corresponding to each preset level combination in multiple preset level combinations.
2. The method according to claim 1, characterized in that According to the preset corresponding relationship, the comprehensive security risk level corresponding to the target level combination is determined as follows: Calculating a weighted sum of the normalized score of the first score, the normalized score of the second score, and the normalized score of the third score based on the weight of the normalized score of the first score, the weight of the normalized score of the second score, and the weight of the normalized score of the third score, and determining the weighted sum as a comprehensive risk index of the target object; Determining a target comprehensive risk index interval in which the comprehensive risk index of the target object lies from a plurality of preset comprehensive risk index intervals, wherein each preset comprehensive risk index interval corresponds to a different preset corresponding relationship; According to the preset corresponding relationship corresponding to the target comprehensive risk index interval, the comprehensive safety risk level corresponding to the target level combination is determined.
3. The method according to claim 2, characterized in that The weight of the normalized score of the first score is the first weight of the target object; And the method further comprises: A first weight of the target object is determined according to the domain to which the target object belongs and the target functional safety risk level.
4. The method according to claim 3, characterized in that Determining a first weight of the target object according to the domain to which the target object belongs and the target functional safety risk level includes: A first weight of the target object is determined based on the domain to which the target object belongs, the target functional safety risk level, and functional safety association information of the target object, wherein the functional safety association information indicates at least one of the following items: whether the target object is cascaded with other objects, and whether the target object has a failure mode.
5. The method according to claim 2, characterized in that The weight of the normalized score of the second score is the second weight of the target object; And the method further comprises: A second weight of the target object is determined based on the domain to which the target object belongs and vulnerability association information of the target object, where the vulnerability association information includes at least one of the following items: a Common Vulnerability Scoring System level of the target object and software features related to the target object, where the software features indicate at least one of the following items: a code volume level of code related to the target object, whether the code related to the target object is open source, and whether the target object is used to run an operating system.
6. The method according to claim 2, characterized in that The weight of the normalized score of the third score is the third weight of the target object; And the method further comprises: A third weight of the target object is determined according to the domain to which the target object belongs and attack association information of the target object, wherein the attack association information indicates at least one of the following items: an attack feasibility level of the target object and an attack method against the target object.
7. An information acquisition device, characterized in that: The device comprises: a target functional safety risk level determination unit, configured to determine a target functional safety risk level of the target object on the target vehicle based on a first score of the target object, wherein the first score is obtained by applying hazard analysis and risk assessment to the target object; a target network security risk level determination unit, configured to determine a target network security risk level of the target object based on a second score and a third score of the target object, wherein the second score is obtained by applying a common vulnerability scoring system to the target object, and the third score is obtained by applying a threat analysis and risk assessment to the target object; The comprehensive security risk level determination unit is used to determine the comprehensive security risk level corresponding to the target level combination according to a preset corresponding relationship, and determine the comprehensive security risk level corresponding to the target level combination as the comprehensive security risk level of the target object, the target level combination includes: the target functional safety risk level, the target network security risk level, the preset level combination includes: functional safety risk level, network security risk level, and the preset corresponding relationship indicates the comprehensive security risk level corresponding to each preset level combination in multiple preset level combinations.
8. A vehicle, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method according to any one of claims 1 to 6 by executing the computer instructions.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 6.
10. A computer program product, characterized in that The method comprises computer instructions for causing a computer to execute the method according to any one of claims 1 to 6.