Vehicle-mounted terminal system vulnerability detection method and system based on information security
By building a heterogeneous data fusion model that combines a virtual simulation environment with real-time monitoring in the vehicle terminal system and dynamically adjusting the detection strategy, the problems of insufficient real-time performance and low resource utilization in vulnerability detection in existing technologies are solved, and efficient and secure vulnerability detection is achieved.
Patent Information
- Application Number
- CN202510861500.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-09-19
AI Technical Summary
Existing vulnerability detection technologies for vehicle-mounted terminal systems suffer from problems such as insufficient real-time performance, incomplete coverage, low resource utilization, and insufficient security of detection modules, making it difficult to achieve efficient, comprehensive, and secure vulnerability detection.
By building a virtual simulation environment consistent with the on-board terminal system, combining real-time monitoring data for cross-validation, and using a heterogeneous data fusion model and the resource status index (RSI) for dynamic adjustment, adaptive vulnerability detection is achieved, and the vulnerability detection module security index (MSI) is introduced for self-protection.
It achieves accurate and comprehensive detection of vehicle terminal system vulnerabilities, improves the real-time detection and resource utilization, enhances the adaptability to unknown attacks and system stability, and ensures the security of the detection module.
Smart Images

Figure CN120671149A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of automobile information security, and in particular to a method and system for dynamic detection of vulnerabilities in an on-board terminal system based on information security. Background Art
[0002] With the rapid development of intelligent and connected vehicles, the functions of in-vehicle terminal systems are becoming increasingly diverse, including in-vehicle infotainment (IVI), vehicle-to-everything (V2X) communication systems, and remote over-the-air (OTA) upgrade systems. These terminal systems constantly exchange data with the outside world, making them vulnerable to cyberattacks and creating serious information security risks.
[0003] Currently, existing vulnerability detection technologies for in-vehicle terminal systems mostly rely on single-data source detection. Real-time monitoring methods are severely limited by on-board hardware resources, making it difficult to detect vulnerabilities in real time and efficiently. Virtual simulation methods struggle to fully simulate the actual in-vehicle environment, resulting in incomplete vulnerability detection coverage. Furthermore, existing technologies lack detection methods that dynamically adjust based on the terminal system's real-time resource load. Furthermore, the vulnerability detection module itself is vulnerable to attack and lacks security assurance. Therefore, the real-time, comprehensive, resource-adaptive, and inherently secure nature of vulnerability detection for in-vehicle terminal systems needs to be improved. Summary of the Invention
[0004] In order to solve the problems of incomplete vulnerability detection coverage, insufficient real-time performance, low resource utilization and insufficient security of the vulnerability detection module itself in the existing technology, the present invention proposes a dynamic vulnerability detection method and system for vehicle-mounted terminal systems based on information security.
[0005] In a first aspect, the present invention provides a method for detecting vulnerabilities in an in-vehicle terminal system based on information security, comprising the following steps: Generate actual environment data feature set based on real-time monitoring data collected by the vehicle terminal system; Constructing a virtual simulation environment consistent with the functions of the vehicle terminal system and generating a virtual environment data feature set; Performing real-time data cross-validation on the actual environment data feature set and the virtual environment data feature set to obtain a real-time difference feature set and identify suspected abnormal difference data; Determine the abnormal difference data based on the suspected abnormal difference data in combination with the heterogeneous data fusion model, and calculate the corresponding initial vulnerability risk value based on the determined abnormal difference data; Calculating an adaptive vulnerability risk value based on the current resource status index RSI of the vehicle terminal system and the initial vulnerability risk value; Dynamically adjust the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response according to the current resource status index RSI of the vehicle terminal system; A vulnerability detection result is output according to the adaptive vulnerability risk value, and a security policy is executed according to the vulnerability detection result.
[0006] In combination with the first aspect, in one embodiment, the actual environment data feature set is generated based on the real-time monitoring data collected by the vehicle-mounted terminal system, including: through the lightweight probe deployed in the vehicle-mounted terminal system, real-time monitoring of system process calls, memory reading and writing, network traffic and performance counter status data to generate the actual environment data feature set.
[0007] In this embodiment, by deploying lightweight probes in the vehicle terminal system, system process calls, memory reading and writing, network traffic and performance counter status data are collected in real time to generate a set of actual environment data features, which solves the problem of excessive system resource occupation in the data collection process in related technologies. At the same time, it ensures the comprehensiveness and real-time nature of the monitoring data, and effectively reduces the occupation of vehicle terminal system resources by data collection.
[0008] In combination with the first aspect, in one embodiment, the construction of a virtual simulation environment consistent with the function of the vehicle-mounted terminal system and the generation of a virtual environment data feature set include: constructing a virtual twin environment based on the image file of the vehicle-mounted terminal system, and simulating the V2X communication interface, OTA update process, and vehicle-mounted application ecological interaction process involved in the vehicle-mounted terminal system in real time to generate the virtual environment data feature set.
[0009] In this embodiment, a virtual twin environment with consistent functions as the vehicle-mounted terminal system is constructed based on the image file, and the V2X communication interface, OTA update process and vehicle-mounted application ecological interaction process are simulated in real time to generate a virtual environment data feature set. This solves the problem of insufficient consistency between the virtual environment and the actual system in related technologies and inability to cover complex attack scenarios, significantly improves the baseline reliability of vulnerability detection, and effectively enhances the vulnerability detection ability to discover unknown anomalies.
[0010] In combination with the first aspect, in one embodiment, the actual environment data feature set and the virtual environment data feature set are subjected to real-time data cross-validation to obtain a real-time difference feature set and identify suspected abnormal difference data, including: calculating the real-time difference between the actual environment data features and the virtual environment data features to form the real-time difference feature set; and identifying suspected abnormal difference data based on the real-time difference feature set through a preset abnormality discrimination threshold.
[0011] In this embodiment, by calculating the real-time difference between the actual environment data features and the virtual environment data features to form a real-time difference feature set, and preliminarily screening the difference features based on a preset abnormal discrimination threshold, the possible abnormal difference data can be quickly identified, thus solving the problem of vulnerability detection methods in related technologies being slow to respond to unknown attacks and unable to efficiently locate potential vulnerabilities. This preliminary screening process compares the operating status of the real system and the virtual environment in real time, and uses quantitative analysis of the difference amplitude to quickly predict abnormal behavior, providing an accurate input data set for the subsequent heterogeneous data fusion model. Furthermore, combined with the heterogeneous data fusion model, a multi-dimensional feature weighted analysis is performed on the suspected abnormal difference data, ultimately determining the true abnormal difference data and calculating the corresponding vulnerability risk value, thereby achieving accurate identification and risk grading of vulnerabilities. Through the staged preliminary screening and fine screening design, the redundant consumption of computing resources is reduced, and the accuracy of vulnerability detection and adaptability to complex attacks are significantly improved, forming an efficient and robust detection closed loop.
[0012] In conjunction with the first aspect, in one embodiment, an initial vulnerability risk value R of the heterogeneous data fusion model is obtained according to a first formula, where the first formula includes:
[0013] Where norm( ) is the normalization function; N is the total number of fused heterogeneous data features; αi is the weight of the i-th data feature; ΔFi is the difference between the actual environment data features and the virtual environment data features; exp( ) is an exponential function with a natural constant as the base.
[0014] In this embodiment, by constructing a heterogeneous data fusion model based on normalization function and exponential function, and combining the weight distribution of different data features to calculate the initial vulnerability risk value, the problem of insufficient accuracy and stability of vulnerability risk assessment in related technologies due to unreasonable feature weight distribution is solved, a quantifiable and scalable risk assessment framework is provided, and the accuracy and stability of vulnerability risk assessment are improved.
[0015] In combination with the first aspect, in one embodiment, the current resource status index RSI of the vehicle terminal system is obtained according to a second formula, where the second formula includes:
[0016] Among them, CPU% is the CPU occupancy rate of the vehicle terminal system, MEM% is the memory occupancy rate of the vehicle terminal system, NET% is the network load rate of the vehicle terminal system, ω cpu 、ω mem and ω net are the weight coefficients corresponding to CPU, memory and network load respectively, and satisfy ω cpu +ωmem +ω net =1.
[0017] In this embodiment, the resource status index RSI is generated by a weighted calculation formula based on CPU occupancy, memory occupancy and network load rate, which solves the problem in related technologies that the vulnerability detection process lacks the ability to adaptively adjust the real-time resource status of the system, ensures the rationality of dynamic resource allocation of the detection strategy in high-load and low-load scenarios, and effectively guarantees the adaptability of the vulnerability detection process to resources.
[0018] In combination with the first aspect, in one embodiment, the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response are dynamically adjusted based on the current resource status index RSI of the vehicle-mounted terminal system, including: when the current resource status index RSI of the vehicle-mounted terminal system exceeds a preset high load threshold, the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response are reduced; when the current resource status index RSI of the vehicle-mounted terminal system is lower than a preset low load threshold, the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response are increased.
[0019] In this embodiment, by dynamically adjusting the computational granularity and security policy triggering threshold of the heterogeneous data fusion model according to the high and low load states of the RSI, the problem of the inability to dynamically balance detection accuracy and resource utilization in related technologies is solved. When system resources are tight, the computational complexity is reduced to ensure stability, and when resources are sufficient, the detection sensitivity is improved to enhance security, thereby achieving a dynamic balance between detection accuracy and resource utilization.
[0020] In combination with the first aspect, in one embodiment, there is a preset mapping relationship between the current resource status index RSI of the vehicle-mounted terminal system and the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response. The calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response are adjusted according to the preset mapping relationship.
[0021] In this embodiment, by presetting the mapping relationship between the resource status index RSI and the parameter adjustment of the heterogeneous data fusion model, automatic adaptation of the calculation granularity and the risk threshold is achieved, which solves the problems of parameter adjustment lag and low response efficiency caused by reliance on manual experience in related technologies, and improves the intelligence level and real-time decision-making ability of the detection system.
[0022] In conjunction with the first aspect, in one embodiment, the vehicle terminal system vulnerability detection method further includes a vulnerability detection module's own security protection mechanism, specifically including: real-time monitoring of the vulnerability detection module's system calls, interface access behaviors, and resource usage anomalies; and calculating the vulnerability detection module's security index (MSI) according to a third formula, the third formula including:
[0023] Where norm( ) is the normalization function; K is the total number of monitored security features; β j is the jth security feature weight; S j is the real-time monitoring status value of the jth security feature; when the security index MSI of the vulnerability detection module is lower than the preset security threshold, the module security protection measures are triggered, and the module security protection measures include module isolation and degradation.
[0024] In this embodiment, by real-time monitoring of the system calls, interface access behaviors and resource usage anomalies of the vulnerability detection module, and triggering module isolation and degradation protection measures based on the security index MSI, the problem in related technologies that the detection system itself is vulnerable to attack or failure, resulting in the collapse of the overall security mechanism, is solved, the self-protection capability of the vulnerability detection module is constructed, and the robustness of the system is enhanced.
[0025] In the second aspect, an embodiment of the present application provides an information security-based vehicle terminal system vulnerability detection device, including a processor and a memory, wherein the memory stores computer program instructions. When the processor executes the instructions, the information security-based vehicle terminal system vulnerability detection method as described above is implemented.
[0026] The present invention has the following beneficial effects: The present invention achieves comprehensive and accurate detection of vulnerabilities in the vehicle terminal system by adaptively integrating virtual simulation data with real-time monitoring data, effectively solving the problem of insufficient vulnerability coverage in existing technologies. At the same time, the resource status index RSI is used to monitor the computing, storage and network resource status of the vehicle terminal in real time, and the vulnerability detection strategy is dynamically adjusted, effectively solving the problems of poor real-time detection and insufficient resource utilization in existing technologies. Furthermore, the present invention accurately discovers unknown and new vulnerabilities through a dynamic mapping anomaly recognition algorithm, significantly improving the detection and protection capabilities against advanced threats. In addition, the present invention introduces the vulnerability detection module security index (MSI) to monitor and protect the security status of the detection module itself in real time, avoiding the detection module from becoming an attack target, thereby effectively improving the overall security and stability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions and advantages of the embodiments of the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0028] Figure 1 This is a flow chart of a method for dynamic detection of vulnerabilities in an in-vehicle terminal system based on information security according to the present invention. DETAILED DESCRIPTION
[0029] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0030] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0031] In a first aspect, an embodiment of the present application provides a method for detecting vulnerabilities in an in-vehicle terminal system based on information security.
[0032] In one embodiment, referring to Figure 1 , Figure 1 This is a flow chart of the first embodiment of the vehicle terminal system vulnerability detection method based on information security of this application. Figure 1 The vehicle terminal system vulnerability detection method based on information security includes: S1. Generate a feature set of actual environmental data based on the real-time monitoring data collected by the vehicle terminal system; S2. Constructing a virtual simulation environment consistent with the functions of the vehicle terminal system and generating a virtual environment data feature set; S3, performing real-time data cross-validation on the actual environment data feature set and the virtual environment data feature set to obtain a real-time difference feature set and identify suspected abnormal difference data; S4. Determine the abnormal difference data based on the suspected abnormal difference data in combination with a heterogeneous data fusion model, and calculate the corresponding initial vulnerability risk value based on the determined abnormal difference data; S5. Calculating an adaptive vulnerability risk value based on the current resource status index RSI of the vehicle terminal system and the initial vulnerability risk value; S6. Dynamically adjust the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response according to the current resource status index RSI of the vehicle terminal system; S7. Output a vulnerability detection result according to the adaptive vulnerability risk value, and execute a security policy according to the vulnerability detection result.
[0033] The order of step S5 and step S6 can be interchanged or performed simultaneously. In addition, the definition of the risk threshold is clearly defined, that is, the critical value used by the system to determine whether to trigger a security policy response, that is, if the adaptive vulnerability risk exceeds this value, the system will take security measures.
[0034] In this embodiment, by constructing a real-time cross-validation mechanism for the actual environment data feature set and the virtual simulation environment data feature set, and combining the adaptive vulnerability risk value calculation and dynamic policy adjustment functions, the problems of poor real-time vulnerability detection, high resource usage and weak ability to identify unknown attacks in related technologies are solved, and at the same time, a dynamic balance between detection accuracy and system resource consumption is achieved.
[0035] Furthermore, in one embodiment, the actual environment data feature set is generated based on the real-time monitoring data collected by the vehicle-mounted terminal system, including: real-time monitoring of system process calls, memory reading and writing, network traffic and performance counter status data through lightweight probes deployed in the vehicle-mounted terminal system to generate the actual environment data feature set.
[0036] In this embodiment, by deploying lightweight probes in the vehicle terminal system, system process calls, memory reading and writing, network traffic and performance counter status data are collected in real time to generate a set of actual environment data features, which solves the problem of excessive system resource occupation in the data collection process in related technologies. At the same time, it ensures the comprehensiveness and real-time nature of the monitoring data, and effectively reduces the occupation of vehicle terminal system resources by data collection.
[0037] Furthermore, in one embodiment, the construction of a virtual simulation environment consistent with the functions of the vehicle-mounted terminal system and the generation of a virtual environment data feature set include: constructing a virtual twin environment based on the image file of the vehicle-mounted terminal system, and simulating the V2X communication interface, OTA update process, and vehicle-mounted application ecological interaction process involved in the vehicle-mounted terminal system in real time to generate the virtual environment data feature set.
[0038] In this embodiment, a virtual twin environment with consistent functions as the vehicle-mounted terminal system is constructed based on the image file, and the V2X communication interface, OTA update process and vehicle-mounted application ecological interaction process are simulated in real time to generate a virtual environment data feature set. This solves the problem of insufficient consistency between the virtual environment and the actual system in related technologies and inability to cover complex attack scenarios, significantly improves the baseline reliability of vulnerability detection, and effectively enhances the vulnerability detection ability to discover unknown anomalies.
[0039] Specifically, a lightweight probe is deployed within the vehicle terminal system (such as the vehicle-mounted system in an intelligent connected vehicle) to monitor the vehicle's system process call data, memory read and write operation data, network traffic data, and performance counter status data in real time. Performance counter status data includes CPU usage, memory usage, and network bandwidth usage. For example, the probe samples system data every 5 seconds, and after one minute of continuous sampling, a real-time data set is generated. Simultaneously, a digital twin virtual environment is built using the vehicle terminal system image file. This virtual environment accurately simulates the V2X communication interface, OTA update process, and vehicle application ecosystem interaction process in a real vehicle terminal system, thereby generating a virtual environment data feature set for the corresponding time period. This allows subsequent identification of abnormal data to rely on the interaction between virtual and real data, more accurately determining abnormalities in vehicle system operation.
[0040] Furthermore, in one embodiment, the real-time data cross-validation of the actual environment data feature set and the virtual environment data feature set is performed to obtain a real-time difference feature set, and suspected abnormal difference data is identified, including: calculating the real-time difference between the actual environment data feature and the virtual environment data feature to form the real-time difference feature set; and identifying suspected abnormal difference data based on the real-time difference feature set through a preset abnormality discrimination threshold.
[0041] Specifically, for example, feature data with a difference greater than 0.3 can be considered abnormal difference features. These features may correspond to abnormal behavior or potential vulnerabilities in the vehicle terminal system. This real-time difference feature set can quickly and effectively identify deviations from the standard simulation environment during actual vehicle operation, promptly identifying potential safety issues.
[0042] In this embodiment, by calculating the real-time difference between the actual environment data features and the virtual environment data features to form a real-time difference feature set, and preliminarily screening the difference features based on a preset abnormal discrimination threshold, the possible abnormal difference data can be quickly identified, thus solving the problem of vulnerability detection methods in related technologies being slow to respond to unknown attacks and unable to efficiently locate potential vulnerabilities. This preliminary screening process compares the operating status of the real system and the virtual environment in real time, and uses quantitative analysis of the difference amplitude to quickly predict abnormal behavior, providing an accurate input data set for the subsequent heterogeneous data fusion model. Furthermore, combined with the heterogeneous data fusion model, a multi-dimensional feature weighted analysis is performed on the suspected abnormal difference data, ultimately determining the true abnormal difference data and calculating the corresponding vulnerability risk value, thereby achieving accurate identification and risk grading of vulnerabilities. Through the staged preliminary screening and fine screening design, the redundant consumption of computing resources is reduced, and the accuracy of vulnerability detection and adaptability to complex attacks are significantly improved, forming an efficient and robust detection closed loop.
[0043] Furthermore, in one embodiment, the initial vulnerability risk value R of the heterogeneous data fusion model is obtained according to a first formula, wherein the first formula includes:
[0044] Where norm( ) is the normalization function; N is the total number of fused heterogeneous data features; αi is the weight of the i-th data feature; ΔFi is the difference between the actual environment data features and the virtual environment data features; exp( ) is an exponential function with a natural constant as the base.
[0045] Specifically, a heterogeneous data fusion model based on a lightweight Transformer architecture is used. This model integrates CAN bus data features, V2X communication data features, OTA upgrade data features, and in-vehicle app call behavior data features. This model uniformly analyzes and processes these real-time differential feature sets to determine the initial vulnerability risk value. For example, after calculating a differential feature data set using this formula, the initial vulnerability risk value obtained is 0.75, indicating that this feature set may have a high vulnerability risk.
[0046] In this embodiment, by constructing a heterogeneous data fusion model based on normalization function and exponential function, and combining the weight distribution of different data features to calculate the initial vulnerability risk value, the problem of insufficient accuracy and stability of vulnerability risk assessment in related technologies due to unreasonable feature weight distribution is solved, a quantifiable and scalable risk assessment framework is provided, and the accuracy and stability of vulnerability risk assessment are improved.
[0047] Furthermore, in one embodiment, the current resource status index RSI of the vehicle terminal system is obtained according to a second formula, and the second formula includes:
[0048] Among them, CPU% is the CPU occupancy rate of the vehicle terminal system, MEM% is the memory occupancy rate of the vehicle terminal system, NET% is the network load rate of the vehicle terminal system, ω cpu 、ω mem and ω net are the weight coefficients corresponding to CPU, memory and network load respectively, and satisfy ω cpu +ω mem +ω net =1.
[0049] In this embodiment, the resource status index RSI is generated by a weighted calculation formula based on CPU occupancy, memory occupancy and network load rate, which solves the problem in related technologies that the vulnerability detection process lacks the ability to adaptively adjust the real-time resource status of the system, ensures the rationality of dynamic resource allocation of the detection strategy in high-load and low-load scenarios, and effectively guarantees the adaptability of the vulnerability detection process to resources.
[0050] Furthermore, in one embodiment, the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response are dynamically adjusted based on the current resource status index RSI of the vehicle-mounted terminal system, including: when the current resource status index RSI of the vehicle-mounted terminal system exceeds a preset high load threshold, reducing the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response; when the current resource status index RSI of the vehicle-mounted terminal system is lower than a preset low load threshold, increasing the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response.
[0051] Specifically, for example, when the real-time calculated RSI is 0.85, which is higher than the preset high load threshold of 0.8, the calculation granularity of the heterogeneous data fusion model is automatically reduced, such as reducing the number of attention heads in the Transformer model to reduce resource usage; when the RSI drops to 0.4, which is lower than the preset low load threshold of 0.5, the model calculation granularity and sensitivity are automatically increased to improve the accuracy of vulnerability detection.
[0052] In this embodiment, by dynamically adjusting the computational granularity and security policy triggering threshold of the heterogeneous data fusion model according to the high and low load states of the RSI, the problem of the inability to dynamically balance detection accuracy and resource utilization in related technologies is solved. When system resources are tight, the computational complexity is reduced to ensure stability, and when resources are sufficient, the detection sensitivity is improved to enhance security, thereby achieving a dynamic balance between detection accuracy and resource utilization.
[0053] Further, in one embodiment, there is a preset mapping relationship between the current resource status index RSI of the vehicle-mounted terminal system and the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response. The calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response are adjusted according to the preset mapping relationship.
[0054] Specifically, the preset mapping relationship can adopt a mapping table of RSI, the number of force heads, and the risk threshold established during the offline test phase. And by setting a high risk threshold Thigh and a floating amount ε = 0.01, the vulnerability risk level is determined as follows: If R ≥ Thigh + ε, it is determined as a high risk; If Thigh − ε ≤ R < Thigh + ε, it is determined as a medium risk; If R < Thigh − ε, it is determined as a low risk.
[0055] In this embodiment, by presetting the mapping relationship between the resource status index RSI and the parameter adjustment of the heterogeneous data fusion model, the automatic adaptation of the calculation granularity and the risk threshold is achieved, solving the problems of parameter adjustment lag and low response efficiency caused by relying on manual experience in the related art, and improving the intelligent level and real-time decision-making ability of the detection system.
[0056] Further, in one embodiment, the vehicle-mounted terminal system vulnerability detection method further includes a self-security protection mechanism for the vulnerability detection module, specifically including: real-time monitoring of the system calls, interface access behaviors, and abnormal resource occupations of the vulnerability detection module; calculating the security index MSI of the vulnerability detection module according to the third formula, and the third formula includes:
[0057] where norm( ) is a normalization function; K is the total number of detected security features; β j is the weight of the jth security feature; S j is the real-time monitoring status value of the jth security feature; when the security index MSI of the vulnerability detection module is lower than the preset security threshold, trigger module security protection measures, and the module security protection measures include module isolation and degradation.
[0058] Specifically, when the MSI calculation result is lower than the preset security threshold (such as 0.6), automatically trigger security protection measures, including isolating the detection module or degrading its functions, to prevent the overall vehicle-mounted system security from being threatened by the exploitation of the module's own vulnerabilities.
[0059] In this embodiment, by real-time monitoring of the system calls, interface access behaviors and resource usage anomalies of the vulnerability detection module, and triggering module isolation and degradation protection measures based on the security index MSI, the problem in related technologies that the detection system itself is vulnerable to attack or failure, resulting in the collapse of the overall security mechanism, is solved, the self-protection capability of the vulnerability detection module is constructed, and the robustness of the system is enhanced.
[0060] Specific examples: First, the high-risk threshold Thigh is set to 0.7. In the first RSI sampling window, the system calculates the initial vulnerability risk value to be 0.75, which is higher than the high-risk threshold of 0.7+0.01, and the system determines it as high risk. The current RSI is 0.85, which is higher than the preset high-load threshold of 0.8. Then, corresponding measures are taken: (1) According to the mapping relationship, the calculation granularity is reduced, such as reducing the number of attention heads in the Transformer model and raising the risk threshold from 0.7 to 0.73; (2) The adaptive vulnerability risk value is calculated as 0.731 by the formula. At this time, the adaptive vulnerability risk value is still higher than 0.7+0.01, and the system still determines it as high risk. Moreover, the calculated adaptive vulnerability risk value is higher than the adjusted risk threshold, and the system triggers a security policy response. In this way, serious vulnerabilities can be guaranteed not to be missed even when resources are tight, but the difference between the adaptive vulnerability risk value and the risk threshold is significantly reduced.
[0061] Then, after an RSI sampling window, the system recalculates the initial vulnerability risk value to 0.72, which is higher than the high-risk threshold of 0.7+0.01, and the system determines it as high risk. The current RSI is still 0.85, which is higher than the preset high-load threshold of 0.8. Corresponding measures are taken: (1) According to the mapping relationship, the calculation granularity is reduced, such as reducing the number of attention heads in the Transformer model and raising the risk threshold from 0.7 to 0.73. (2) The adaptive vulnerability risk value is calculated as 0.702 using the formula. At this time, 0.7-0.01≤Adaptive Vulnerability Risk Value<0.7+0.01, and the system determines it as medium risk. Moreover, the calculated adaptive vulnerability risk value is lower than the adjusted risk threshold, and the system does not trigger a security policy response. In this way, an alarm of "tolerable risk" (medium risk) can be reduced when resources are tight.
[0062] In a second aspect, an embodiment of the present application provides an information security-based vehicle terminal system vulnerability detection device. The information security-based vehicle terminal system vulnerability detection device may be a device with data processing capabilities, such as a vehicle terminal controller.
[0063] In an embodiment of the present application, an information security-based vehicle terminal system vulnerability detection device may include a processor, a memory, a communication interface, and a communication bus. The communication bus may be of any type for interconnecting the processor, the memory, and the communication interface.
[0064] Communication interfaces include input / output (I / O), physical, and logical interfaces, used to interconnect components within the information security-based vehicle terminal system vulnerability detection device, as well as interfaces used to interconnect the information security-based vehicle terminal system vulnerability detection device with other devices (such as other computing devices or user devices). Physical interfaces can include Ethernet, fiber optic, and ATM interfaces; user devices can include displays and keyboards.
[0065] The memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.
[0066] The processor may be a general-purpose processor that can invoke an information security-based vehicle terminal system vulnerability detection program stored in a memory and execute the information security-based vehicle terminal system vulnerability detection method provided in the embodiments of the present application. For example, the general-purpose processor may be a central processing unit (CPU). The method executed when the information security-based vehicle terminal system vulnerability detection program is invoked can be referenced in the various embodiments of the information security-based vehicle terminal system vulnerability detection method of the present application and will not be further described here.
[0067] It should be noted that the serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0068] The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices. The terms "first", "second" and "third" are used to distinguish different objects, etc., and do not represent a sequence, nor do they limit the "first", "second" and "third" to different types.
[0069] In the description of the embodiments of this application, the words "exemplary," "for example," or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary," "for example," or "for example" in the embodiments of this application should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary," "for example," or "for example" is intended to present the relevant concepts in a concrete manner.
[0070] In the description of the embodiments of the present application, unless otherwise specified, “ / ” means or, for example, A / B can mean A or B; “and / or” in the text is merely a description of the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, “multiple” refers to two or more than two.
[0071] In some processes described in the embodiments of the present application, multiple operations or steps are included that appear in a specific order. However, it should be understood that these operations or steps may not be performed in the order in which they appear in the embodiments of the present application or may be performed in parallel. The sequence numbers of the operations are only used to distinguish between different operations, and the sequence numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations or steps may be performed in sequence or in parallel, and these operations or steps may be combined.
[0072] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, or the part that contributes to the existing technology, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above and includes a number of instructions for enabling a terminal device to execute the methods described in each embodiment of this application.
[0073] The above are only preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A method for detecting vulnerabilities in an in-vehicle terminal system based on information security, characterized in that: The following steps are involved: Generate actual environment data feature set based on real-time monitoring data collected by the vehicle terminal system; Constructing a virtual simulation environment consistent with the functions of the vehicle terminal system and generating a virtual environment data feature set; Performing real-time data cross-validation on the actual environment data feature set and the virtual environment data feature set to obtain a real-time difference feature set and identify suspected abnormal difference data; Determine the abnormal difference data based on the suspected abnormal difference data in combination with the heterogeneous data fusion model, and calculate the corresponding initial vulnerability risk value based on the determined abnormal difference data; Calculating an adaptive vulnerability risk value based on the current resource status index RSI of the vehicle terminal system and the initial vulnerability risk value; Dynamically adjust the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response according to the current resource status index RSI of the vehicle terminal system; A vulnerability detection result is output according to the adaptive vulnerability risk value, and a security policy is executed according to the vulnerability detection result.
2. The method for detecting vulnerabilities in an in-vehicle terminal system based on information security according to claim 1, characterized in that: The actual environment data feature set is generated based on the real-time monitoring data collected by the vehicle terminal system, including: The lightweight probe deployed in the vehicle terminal system monitors system process calls, memory reading and writing, network traffic and performance counter status data in real time to generate the actual environment data feature set.
3. The method for detecting vulnerabilities in an in-vehicle terminal system based on information security according to claim 1, characterized in that: The step of constructing a virtual simulation environment consistent with the functions of the vehicle-mounted terminal system and generating a virtual environment data feature set includes: A virtual twin environment is constructed based on the image file of the vehicle-mounted terminal system, and the V2X communication interface, OTA update process, and vehicle-mounted application ecological interaction process involved in the vehicle-mounted terminal system are simulated in real time to generate the virtual environment data feature set.
4. The method for detecting vulnerabilities in an in-vehicle terminal system based on information security according to claim 1, characterized in that: The performing real-time data cross-validation on the actual environment data feature set and the virtual environment data feature set to obtain a real-time difference feature set and identify suspected abnormal difference data includes: Calculating the real-time difference between the actual environment data feature and the virtual environment data feature to form the real-time difference feature set; According to the real-time difference feature set, suspected abnormal difference data is identified through a preset abnormality discrimination threshold.
5. The method for detecting vulnerabilities in an in-vehicle terminal system based on information security according to claim 1, characterized in that: An initial vulnerability risk value R of the heterogeneous data fusion model is obtained according to a first formula, wherein the first formula includes: Where norm( ) is the normalization function; N is the total number of fused heterogeneous data features; αi is the weight of the i-th data feature; ΔFi is the difference between the actual environment data features and the virtual environment data features; exp( ) is an exponential function with a natural constant as the base.
6. The method for detecting vulnerabilities in an in-vehicle terminal system based on information security according to claim 1, characterized in that: The current resource status index RSI of the vehicle terminal system is obtained according to a second formula, wherein the second formula includes: Among them, CPU% is the CPU occupancy rate of the vehicle terminal system, MEM% is the memory occupancy rate of the vehicle terminal system, NET% is the network load rate of the vehicle terminal system, ω cpu 、ω mem and ω net are the weight coefficients corresponding to CPU, memory and network load respectively, and satisfy ω cpu +ω mem +ω net =1.
7. The method for detecting vulnerabilities in an in-vehicle terminal system based on information security according to claim 1, characterized in that: The dynamically adjusting the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response according to the current resource status index RSI of the vehicle terminal system includes: When the current resource status index RSI of the vehicle terminal system exceeds a preset high load threshold, reducing the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response; When the current resource status index RSI of the vehicle terminal system is lower than a preset low load threshold, the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response are increased.
8. The method for detecting vulnerabilities in an in-vehicle terminal system based on information security according to claim 7, characterized in that: There is a preset mapping relationship between the current resource status index RSI of the vehicle terminal system and the calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response. The calculation granularity of the heterogeneous data fusion model and the risk threshold for triggering a security policy response are adjusted according to the preset mapping relationship.
9. The method for detecting vulnerabilities in an in-vehicle terminal system based on information security according to claim 1, characterized in that: The vehicle terminal system vulnerability detection method also includes a vulnerability detection module's own security protection mechanism, specifically including: Real-time monitoring of system calls, interface access behaviors, and resource usage anomalies of the vulnerability detection module; The security index MSI of the vulnerability detection module is calculated according to a third formula, wherein the third formula includes: Where norm( ) is the normalization function; K is the total number of monitored security features; β j is the jth security feature weight; S j is the real-time monitoring status value of the j-th security feature; When the security index MSI of the vulnerability detection module is lower than a preset security threshold, module security protection measures are triggered, and the module security protection measures include module isolation and degradation.
10. A vehicle terminal system vulnerability detection device based on information security, characterized in that: The method comprises a processor and a memory, wherein the memory stores computer program instructions, and when the processor executes the instructions, the method according to any one of claims 1 to 9 is implemented.