Intrusion detection method and device, vehicle, electronic equipment and storage medium

By matching the attribute information of message data with a preset rule database, malicious intrusion data is isolated and non-malicious intrusion data is forwarded to the detection system, solving the problem of vehicle function abnormalities caused by Ethernet intrusion messages and achieving efficient intrusion detection and safety improvement.

CN120692031APending Publication Date: 2025-09-23BEIJING CO WHEELS TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410324450.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-20
Publication Date
2025-09-23

AI Technical Summary

Technical Problem

In a vehicle's electronic controller, when an Ethernet intrusion message invades from any port of an Ethernet switch, it causes malfunctions in terminal devices in the vehicle that do not have an Ethernet intrusion detection system, such as network paralysis, system scheduling abnormalities, or even a crash and restart.

Method used

By matching the attribute information of the message data with the preset rule database, malicious intrusion data is determined for isolation processing, and non-malicious intrusion data is forwarded to the preset detection system for intrusion detection. The detection results are used to determine whether it is abnormal data to avoid the spread of Ethernet intrusion messages.

Benefits of technology

It effectively avoids the free spread of Ethernet intrusion messages, improves vehicle safety, and increases the efficiency of intrusion detection without occupying MCU or SOC resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120692031A_ABST
    Figure CN120692031A_ABST
Patent Text Reader

Abstract

According to the intrusion detection method and device, the vehicle, the electronic equipment and the storage medium provided by the invention, the target message processing rule corresponding to the attribute information is matched from the preset rule database according to the attribute information of the received message data; under the condition that the message data is determined to be malicious intrusion data according to the target message processing rule, performing isolation processing on the malicious intrusion data; under the condition that the target message processing rule determines that the message data is non-malicious intrusion data, forwarding the non-malicious intrusion data to a port corresponding to a preset detection system; and intrusion detection is performed on the received non-malicious intrusion data through a preset detection system, and whether the non-malicious intrusion data is abnormal data is determined according to an intrusion detection result. Compared with the prior art, according to the embodiment of the invention, the message data is detected and processed through the message processing rule in the preset rule database, free diffusion of Ethernet intrusion messages can be avoided, and the safety of the vehicle is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of data processing technology, and in particular to an intrusion detection method and device, a vehicle, an electronic device, and a storage medium. Background Art

[0002] Currently, in a vehicle's electronic controller or electronic control unit (ECU), when an Ethernet intrusion message invades the entire system from any port of the Ethernet Switch, due to its broadcast and multicast characteristics, the Ethernet Switch will forward the intrusion message to other ports, and then flow into the Ethernet terminal devices in the vehicle that do not have an Ethernet intrusion detection system and / or the Ethernet terminal devices in the vehicle that have an Ethernet intrusion detection system.

[0003] Although the Ethernet terminal devices in the vehicle equipped with an Ethernet intrusion detection system can detect, record, and even issue alarms for intrusion messages, in this process, intrusion messages flowing into the Ethernet terminal devices in the vehicle that do not have an Ethernet intrusion detection system may cause functional abnormalities in the Ethernet terminal devices in the vehicle that do not have an Ethernet intrusion detection system, such as: network function paralysis, system scheduling abnormalities, or even crash and restart. Therefore, how to prevent the spread of Ethernet intrusion messages when they invade the entire system from any port of the Ethernet Switch is an urgent problem that needs to be solved. Summary of the Invention

[0004] The present disclosure provides an intrusion detection method and apparatus, a vehicle, an electronic device, and a storage medium, the main purpose of which is to prevent the spread of Ethernet intrusion messages when they invade the entire system from any port of an Ethernet switch.

[0005] According to a first aspect of the present disclosure, a method for intrusion detection is provided, comprising:

[0006] According to the attribute information of the received message data, a target message processing rule corresponding to the attribute information is matched from a preset rule database, wherein the preset rule database contains attribute information of different message data and corresponding message processing rules;

[0007] When the message data is determined to be malicious intrusion data according to the target message processing rule, isolating the malicious intrusion data, wherein the target message processing rule includes characteristics of the malicious intrusion data;

[0008] If the message data is determined to be non-malicious intrusion data according to the target message processing rule, forwarding the non-malicious intrusion data to a port corresponding to a preset detection system, wherein the target message processing rule includes port information corresponding to the preset detection device, and the preset detection system is used to perform intrusion detection on the message data;

[0009] The preset detection system performs intrusion detection on the received non-malicious intrusion data, and confirms whether the non-malicious intrusion data is abnormal data according to the intrusion detection result, and the hazard level of the abnormal data is lower than the hazard level of the malicious intrusion data.

[0010] Optionally, when it is determined according to the target message processing rule that the message data is non-malicious intrusion data, forwarding the non-malicious intrusion data to a port corresponding to a preset detection system includes:

[0011] determining whether the non-malicious intrusion data is abnormal data according to the target message processing rule, wherein the target message processing rule includes characteristics of the abnormal data;

[0012] In a case where the non-malicious intrusion data is determined to be abnormal data according to the target message processing rule, modifying the Ethernet type of the non-malicious intrusion data to a preset Ethernet type, the Ethernet type being included in the attribute information;

[0013] The non-malicious intrusion data after the Ethernet type is modified and other non-malicious intrusion data are forwarded to the port corresponding to the preset detection system; wherein, the preset Ethernet type is any type used as a data label, and the other non-malicious intrusion data is all non-malicious intrusion data except the non-malicious intrusion data after the Ethernet type is modified.

[0014] Optionally, performing intrusion detection on the received non-malicious intrusion data by the preset detection system, and confirming whether the non-malicious intrusion data is abnormal data according to the intrusion detection result includes:

[0015] Obtaining the Ethernet type of the non-malicious intrusion data;

[0016] If the Ethernet type is the preset Ethernet type, marking the non-malicious intrusion data as abnormal data, extracting data information from the non-malicious intrusion data, and recording the data information in a buffer area of ​​the preset detection system;

[0017] If the Ethernet type is not the preset Ethernet type, the non-malicious intrusion data is marked as normal data.

[0018] Optionally, isolating the malicious intrusion data includes:

[0019] Isolating the malicious intrusion data at the port receiving the message data;

[0020] The amount of the malicious intrusion data is recorded in a register corresponding to the port that receives the message data.

[0021] Optionally, after performing intrusion detection on the received non-malicious intrusion data by the preset detection system and confirming whether the non-malicious intrusion data is abnormal data according to the intrusion detection result, the method further includes:

[0022] Reading data in a register and a buffer area of ​​a preset detection system periodically using a preset time period;

[0023] The data in the register and the cache area of ​​the preset detection system are sent to the server, and the data in the register and the cache area of ​​the preset detection system are cleared.

[0024] Optionally, after performing intrusion detection on the received non-malicious intrusion data by the preset detection system and confirming whether the non-malicious intrusion data is abnormal data according to the intrusion detection result, the method further includes:

[0025] caching the data in the register and the buffer area of ​​the preset detection system in a data to be sent area, wherein the data to be sent area is an area for temporarily caching the data in the register and the buffer area of ​​the preset detection system;

[0026] When it is determined that the available storage space of the cache area of ​​the preset detection system is less than the preset space threshold, the data in the register cached in the data to be sent area and the cache area of ​​the preset detection system are sent to the server, and the data in the data to be sent area, the register and the cache area of ​​the preset detection system are cleared, wherein the storage space of the register and the data to be sent area is larger than the cache area of ​​the preset detection system.

[0027] According to a second aspect of the present disclosure, there is provided an intrusion detection apparatus, comprising:

[0028] a matching unit, configured to match, based on attribute information of received message data, a target message processing rule corresponding to the attribute information from a preset rule database, wherein the preset rule database contains attribute information of different message data and corresponding message processing rules;

[0029] an isolation unit, configured to isolate the malicious intrusion data if the message data is determined to be malicious intrusion data according to the target message processing rule, wherein the target message processing rule includes characteristics of the malicious intrusion data;

[0030] a forwarding unit, configured to, when determining that the message data is non-malicious intrusion data according to the target message processing rule, forward the non-malicious intrusion data to a port corresponding to a preset detection system, wherein the target message processing rule includes port information corresponding to the preset detection device, and the preset detection system is configured to perform intrusion detection on the message data;

[0031] The detection unit is used to perform intrusion detection on the received non-malicious intrusion data through the preset detection system, and confirm whether the non-malicious intrusion data is abnormal data according to the intrusion detection result, and the hazard level of the abnormal data is lower than the hazard level of the malicious intrusion data.

[0032] Optionally, the forwarding unit includes:

[0033] a determination module, configured to determine whether the non-malicious intrusion data is abnormal data according to the target message processing rule, wherein the target message processing rule includes characteristics of the abnormal data;

[0034] a modification module, configured to modify the Ethernet type of the non-malicious intrusion data to a preset Ethernet type when the non-malicious intrusion data is determined to be abnormal data according to the target message processing rule, wherein the Ethernet type is included in the attribute information;

[0035] A forwarding module is used to forward non-malicious intrusion data after the Ethernet type is modified and other non-malicious intrusion data to the port corresponding to the preset detection system; wherein, the preset Ethernet type is any type used as a data label, and the other non-malicious intrusion data is all non-malicious intrusion data except the non-malicious intrusion data after the Ethernet type is modified.

[0036] Optionally, the detection unit includes:

[0037] An acquisition module, configured to acquire the Ethernet type of the non-malicious intrusion data;

[0038] a marking module, configured to mark the non-malicious intrusion data as abnormal data when the Ethernet type is the preset Ethernet type;

[0039] a recording module, configured to extract data information from the non-malicious intrusion data and record the data information in a buffer area of ​​the preset detection system;

[0040] The marking module is further configured to mark the non-malicious intrusion data as normal data when the Ethernet type is not the preset Ethernet type.

[0041] Optionally, the isolation unit includes:

[0042] An isolation module, configured to isolate the malicious intrusion data at a port receiving the message data;

[0043] The recording module is used to record the amount of the malicious intrusion data in a register corresponding to the port that receives the message data.

[0044] Optionally, the device further includes:

[0045] A reading unit, configured to read data in a register and a buffer area of ​​a preset detection system in a periodic manner using a preset time period;

[0046] A sending unit, configured to send the data in the register and the buffer area of ​​the preset detection system to a server;

[0047] The clearing unit is used to clear the data in the register and the cache area of ​​the preset detection system.

[0048] Optionally, the device further includes:

[0049] a cache unit, configured to cache data in a register and a cache area of ​​the preset detection system in a data to-be-sent area, wherein the data to-be-sent area is an area for temporarily caching the data in the register and the cache area of ​​the preset detection system;

[0050] The sending unit is further configured to send the register cached in the data to be sent area and the data in the cache area of ​​the preset detection system to the server when it is determined that the available storage space of the cache area of ​​the preset detection system is less than a preset space threshold;

[0051] The clearing unit is further configured to clear data in the data to be sent area, the register, and the cache area of ​​a preset detection system, wherein the storage space of the register and the data to be sent area is larger than the cache area of ​​the preset detection system.

[0052] According to a third aspect of the present disclosure, a vehicle is provided, wherein the vehicle includes the intrusion detection device as described in the second aspect of the present disclosure.

[0053] According to a fourth aspect of the present disclosure, there is provided an electronic device, including:

[0054] at least one processor; and

[0055] a memory communicatively connected to the at least one processor; wherein,

[0056] The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the method described in the first aspect.

[0057] According to a fifth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable the computer to execute the method described in the first aspect.

[0058] According to a sixth aspect of the present disclosure, a computer program product is provided, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the method as described in the first aspect above.

[0059] The intrusion detection method and device, vehicle, electronic device and storage medium provided by the present disclosure match the target message processing rules corresponding to the attribute information of the received message data from a preset rule database, the preset rule database containing the attribute information of different message data and the corresponding message processing rules; when the message data is determined to be malicious intrusion data according to the target message processing rules, the malicious intrusion data is isolated and processed, wherein the target message processing rules contain the characteristics of the malicious intrusion data; when the message data is determined to be non-malicious intrusion data according to the target message processing rules, the non-malicious intrusion data is forwarded to the port corresponding to the preset detection system, the target message processing rules contain the port information corresponding to the preset detection device, and the preset detection system is used to perform intrusion detection on the message data; the received non-malicious intrusion data is subjected to intrusion detection by the preset detection system, and whether the non-malicious intrusion data is abnormal data is confirmed based on the intrusion detection result, and the hazard level of the abnormal data is less than the hazard level of the malicious intrusion data. Compared with related technologies, the embodiment of the present disclosure detects and processes message data through message processing rules in a preset rule database, isolates malicious intrusion data, forwards non-malicious intrusion data to specific ports, and performs intrusion detection on non-malicious intrusion data. This can prevent the free spread of Ethernet intrusion messages when they invade the entire system from any port of the Ethernet Switch, thereby improving the safety of the vehicle.

[0060] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] The accompanying drawings are provided to facilitate a better understanding of the present invention and do not constitute a limitation of the present disclosure.

[0062] Figure 1 A flowchart of an intrusion detection method provided by an embodiment of the present disclosure;

[0063] Figure 2 A schematic diagram of the principle of an intrusion detection method provided by an embodiment of the present disclosure;

[0064] Figure 3 A schematic diagram of a message data forwarding process provided by an embodiment of the present disclosure;

[0065] Figure 4 A schematic diagram of a process for performing intrusion detection according to a preset detection system provided in an embodiment of the present disclosure;

[0066] Figure 5 A schematic diagram of the structure of an intrusion detection device provided by an embodiment of the present disclosure;

[0067] Figure 6 A schematic diagram of the structure of another intrusion detection device provided by an embodiment of the present disclosure;

[0068] Figure 7 A schematic block diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0069] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0070] The following describes the intrusion detection method and apparatus, vehicle, electronic device, and storage medium according to embodiments of the present disclosure with reference to the accompanying drawings.

[0071] Figure 1 A flowchart of an intrusion detection method provided by an embodiment of the present disclosure.

[0072] like Figure 1 As shown, the method comprises the following steps:

[0073] Step 101: According to attribute information of received message data, a target message processing rule corresponding to the attribute information is matched from a preset rule database, wherein the preset rule database contains attribute information of different message data and corresponding message processing rules.

[0074] When processing the message data in the present disclosure, the enabled functions include but are not limited to: forwarding the message data that invades the vehicle to a specific port through the ternary content addressable memory (TCAM) function of the Switch (Ethernet switch), or directly isolating it at the intrusion port, and the specific embodiments of the present disclosure are not limited thereto.

[0075] In the embodiment of the present disclosure, the attribute information of the message data includes but is not limited to: destination MAC address (Media Access Control Address, Media Access Control Address) (Dst MAC), source MAC address (Src MAC), outer tag (S-TAG) in Doubletagged (double-tagged data packet), outer tag in Double tagged or tag (C-TAG) in Singletagged (single-tagged data packet), Ethernet frame type (ETYPE), IP (Internet Protocol) message header (IP Header), TCP (Transmission Control Protocol) message header (TCP Header), UDP (User Datagram Protocol) message header (UDP Header), etc.

[0076] The preset rule database is a database pre-defined by a technician. Different attribute information of message data is input into the database, and corresponding message processing rules are configured for each attribute information of message data. For details, please refer to Table 1 for the contents of the preset rule database:

[0077] Table 1

[0078]

[0079] Among them, ENTRY1-5: rule entry; Dst MAC: destination MAC address, Src MAC: source MAC address, S-TAG: outer tag in double tagged, C-TAG: outer tag in double tagged or tag in single tagged, ETYPE: Ethernet frame type, ETYPE (Modify): modified type of Ethernet frame, IP Header: IP message header, TCP Header: TCP message header, UDP Header: UDP message header, Rule: target message processing rule, including forwarding to a specific port or isolation. After setting the TCAM rules (different message data attribute information and corresponding message processing rules), a preset rule database will be automatically generated according to the rules. The Switch will load the preset rule database into the RAM space each time it starts. The messages received by each port will be processed according to the message processing rules in the preset rule database. It should be noted that the above Table 1 is only used for illustration to facilitate understanding of the contents of the preset rule database. Specifically, the embodiment of the present disclosure does not limit the data storage method in the preset rule database.

[0080] Step 102: When it is determined that the message data is malicious intrusion data according to the target message processing rule, the malicious intrusion data is isolated and processed, wherein the target message processing rule includes the characteristics of the malicious intrusion data.

[0081] In an embodiment of the present disclosure, when the attribute information of the message data matches attribute information consistent with the attribute information in the preset rule database, the message processing rule corresponding to the attribute information in the preset rule database is used as the target message processing rule, that is, if the combination of Dst MAC, Src MAC, S-TAG, C-TAG, ETYPE, IP Header, TCP Header, and UDP Header of the message data is consistent with an ENTRY in the preset rule database, this ENTRY becomes the target message processing rule, and the message data is processed by the Rule defined by this ENTRY.

[0082] Among them, the Rule defined by ENTRY is pre-customized, that is, the attribute information of the malicious intrusion data is stored in the preset rule database and the corresponding Rule is configured. When the corresponding ENTRY is matched according to the attribute information of the message data, the Rule defined by ENTRY directly instructs the system to isolate the malicious intrusion data (message data determined to be malicious intrusion data).

[0083] Step 103, when it is determined that the message data is non-malicious intrusion data according to the target message processing rule, the non-malicious intrusion data is forwarded to the port corresponding to the preset detection system, the target message processing rule includes the port information corresponding to the preset detection device, and the preset detection system is used to perform intrusion detection on the message data.

[0084] In the embodiment of the present disclosure, each target message processing rule (ENTRY) includes attribute information of the message data and a corresponding Rule. The attribute information of the non-malicious intrusion data is also configured with a corresponding Rule. When the corresponding ENTRY is matched according to the attribute information of the message data, the Rule defined by the ENTRY directly instructs the system to forward the message data determined to be non-malicious intrusion data. At the same time, the Rule defined by the ENTRY includes the port information corresponding to the preset detection device.

[0085] Step 104 : performing intrusion detection on the received non-malicious intrusion data through the preset detection system, and confirming whether the non-malicious intrusion data is abnormal data according to the intrusion detection result, and whether the hazard level of the abnormal data is lower than the hazard level of the malicious intrusion data.

[0086] In the embodiment of the present disclosure, the Ethernet type of the received non-malicious intrusion data (message data determined to be non-malicious intrusion data) is detected by the preset detection system to determine whether the non-malicious intrusion data is abnormal data. After determining that the non-malicious intrusion data is abnormal data, the information of the non-malicious intrusion data will be recorded, and the non-malicious intrusion data will be isolated by the preset detection system; after determining that the non-malicious intrusion data is not abnormal data, the non-malicious intrusion data will be uploaded to the vehicle media medium access control layer (Medium Access Control, MAC) through the preset detection system, and the non-malicious intrusion data will be handed over to the microcontroller (Micro Control Unit, MCU) or system on chip (System on Chip, SOC) for normal processing.

[0087] In order to facilitate understanding of the implementation process of the embodiment of the present disclosure, the embodiment of the present disclosure provides a schematic diagram of the principle of an intrusion detection method, as shown in FIG. Figure 2As shown, TCAM Table is the preset rule database, Ethernet intrusion message 2 represents malicious intrusion data, Ethernet intrusion message 1 represents non-malicious intrusion data, P4 represents the port corresponding to the preset detection system, P1 represents one of the ports for receiving message data, L2 represents Ethernet Layer 2 (data link layer) of message data, L3 represents Ethernet Layer 3 (network layer) of message data, L4 represents Ethernet Layer 4 (transport layer) of message data, and Payload represents the data content of message data (transmission data above Ethernet Layer 4).

[0088] The intrusion detection method provided by the present disclosure matches the target message processing rules corresponding to the attribute information of the received message data from a preset rule database, the preset rule database containing the attribute information of different message data and the corresponding message processing rules; when the message data is determined to be malicious intrusion data according to the target message processing rules, the malicious intrusion data is isolated and processed, wherein the target message processing rules contain the characteristics of the malicious intrusion data; when the message data is determined to be non-malicious intrusion data according to the target message processing rules, the non-malicious intrusion data is forwarded to the port corresponding to the preset detection system, the target message processing rules contain the port information corresponding to the preset detection device, and the preset detection system is used to perform intrusion detection on the message data; the received non-malicious intrusion data is subjected to intrusion detection by the preset detection system, and whether the non-malicious intrusion data is abnormal data is confirmed according to the intrusion detection result, and the hazard level of the abnormal data is lower than the hazard level of the malicious intrusion data. Compared with related technologies, the embodiment of the present disclosure detects and processes message data through message processing rules in a preset rule database, isolates malicious intrusion data, forwards non-malicious intrusion data to specific ports, and performs intrusion detection on non-malicious intrusion data. This can prevent the free spread of Ethernet intrusion messages when they invade the entire system from any port of the Ethernet Switch, thereby improving the safety of the vehicle.

[0089] In one possible implementation of the embodiment of the present disclosure, in order to facilitate the detection of message data determined to be non-malicious intrusion data by the preset detection system, after matching the target message processing rule, the target message processing rule will perform a type mark on the non-malicious intrusion data, so that the preset detection system can determine whether the non-malicious intrusion data is abnormal data according to the type mark. Therefore, in order to improve the detection efficiency of message data, the embodiment of the present disclosure provides a schematic diagram of a message data forwarding process, as shown in FIG. Figure 3 Shown, including:

[0090] Step 301: Determine whether the non-malicious intrusion data is abnormal data according to the target message processing rule, wherein the target message processing rule includes the characteristics of the abnormal data.

[0091] In the embodiment of the present disclosure, the attribute information of the abnormal data and the corresponding target message processing rules are pre-configured in the preset rule database. Therefore, when the message data matches the corresponding target message processing rules, it is possible to directly determine whether the message data is malicious intrusion data, and to judge whether the non-malicious intrusion data (message data determined to be non-malicious intrusion data) is abnormal data.

[0092] Step 302: When the non-malicious intrusion data is determined to be abnormal data according to the target message processing rule, the Ethernet type of the non-malicious intrusion data is modified to a preset Ethernet type, which is included in the attribute information.

[0093] In the embodiment of the present disclosure, the preset Ethernet type is a tag type of a custom setting, for example: 1234, abnormal data, etc., which can be used to mark the non-malicious intrusion data (message data determined to be non-malicious intrusion data). When the corresponding ENTRY is matched according to the attribute information of the message data to determine that it is non-malicious intrusion data, and the non-malicious intrusion data is determined to be abnormal data, the Rule defined by the ENTRY directly instructs the system to modify the Ethernet type of the non-malicious intrusion data, for example: Figure 2 As shown, the ETYPE in the Ethernet intrusion message 1 is the Ethernet type.

[0094] Step 303: forward the non-malicious intrusion data after the Ethernet type is modified and other non-malicious intrusion data to the port corresponding to the preset detection system; wherein the preset Ethernet type is any type used as a data label, and the other non-malicious intrusion data is all non-malicious intrusion data except the non-malicious intrusion data after the Ethernet type is modified.

[0095] In the embodiment of the present disclosure, after the Ethernet type of the non-malicious intrusion data is modified, the non-malicious intrusion data will be forwarded according to the port information corresponding to the preset detection device carried in the target message processing rule, for example: Figure 2 As shown, if the Ethernet intrusion message 1 is abnormal data, after P1 receives the Ethernet intrusion message 1, it modifies the ETYPE in the Ethernet intrusion message 1 according to the target message processing rule, and forwards the Ethernet intrusion message 1 after the Ethernet type is modified to P4.

[0096] In one possible implementation of the embodiment of the present disclosure, as a refinement of the above step 104, regarding the intrusion detection of the non-malicious intrusion data by the preset detection system, the embodiment of the present disclosure provides a flow chart of intrusion detection according to the preset detection system, such as Figure 4 Shown, including:

[0097] Step 401: Obtain the Ethernet type of the non-malicious intrusion data.

[0098] In the embodiment of the present disclosure, the Ethernet type of the non-malicious intrusion data can be directly extracted from the non-malicious intrusion data (the message data determined to be the non-malicious intrusion data) through the preset detection system.

[0099] Step 402: If the Ethernet type is the preset Ethernet type, the non-malicious intrusion data is marked as abnormal data, and data information in the non-malicious intrusion data is extracted and recorded in the buffer area of ​​the preset detection system.

[0100] In the embodiment of the present disclosure, the preset detection system is custom configured. For example, the preset detection system is configured to: when non-malicious intrusion data of a preset Ethernet type is detected, this non-malicious intrusion data is determined as abnormal data. At the same time, the rules for extracting the data information are also custom configured, for example, extracting the L2 header (L2 Header) of the message data and recording it, extracting the L3 Header of the message data and recording it, etc.

[0101] Step 403: If the Ethernet type is not the preset Ethernet type, the non-malicious intrusion data is marked as normal data.

[0102] In the embodiment of the present disclosure, after determining that the received non-malicious intrusion data is normal data, the non-malicious intrusion data can be processed normally, that is, after uploading the non-malicious intrusion data to the MAC, the non-malicious intrusion data is handed over to the MCU or SOC for normal processing.

[0103] In one implementable method of the embodiment of the present disclosure, when it is determined that the message data is malicious intrusion data, the malicious intrusion data (message data determined to be malicious intrusion data) needs to be isolated at the port that receives the message data to prevent the spread of the malicious intrusion data. Therefore, in order to prevent the impact of malicious intrusion data on the vehicle, it can be implemented in but not limited to the following manner: at the port that receives the message data, the malicious intrusion data is isolated; and in the register corresponding to the port that receives the message data, the number of malicious intrusion data is recorded.

[0104] In the disclosed embodiment, each port has a corresponding register (Port_Isolation: Switch isolated message counting register, one for each port). After the message data is isolated, the value of the register Port_Isolation will be increased by 1, and the information of the corresponding port and message data will be recorded.

[0105] In one implementable method of the embodiment of the present disclosure, the number of intrusion messages will be recorded and features will be extracted. At the same time, in order to understand the information and number of intrusion messages, the data in the register and the cache area of ​​the preset detection system will be periodically read, and the data will be uniformly reported to the cloud. Therefore, in order to record the intrusion messages, the following method can also be used but is not limited to: read the data in the register and the cache area of ​​the preset detection system periodically according to a preset time period; send the data in the register and the cache area of ​​the preset detection system to the server, and clear the data in the register and the cache area of ​​the preset detection system.

[0106] Related to the above embodiment, regarding the method of uniformly reporting the data of the register and the cache area of ​​the preset detection system to the cloud, the following method can also be adopted but is not limited to: caching the data in the register and the cache area of ​​the preset detection system in the data to be sent area, and the data to be sent area is an area for temporarily caching the data in the register and the cache area of ​​the preset detection system; when it is determined that the available storage space of the cache area of ​​the preset detection system is less than the preset space threshold, the data in the register and the cache area of ​​the preset detection system cached in the data to be sent area are sent to the server, and the data in the data to be sent area, the register and the cache area of ​​the preset detection system are cleared, wherein the storage space of the register and the data to be sent area is larger than the cache area of ​​the preset detection system.

[0107] In an embodiment of the present disclosure, the preset time period is a custom-set time period, such as 5 minutes, 10 minutes, etc., and the preset space threshold is a custom-set value, such as 5% of the total storage space, 1% of the total storage space, etc. Specifically, the embodiment of the present disclosure does not impose any restrictions on the preset time period and the preset space threshold.

[0108] In summary, the embodiments of the present disclosure can achieve the following effects:

[0109] 1. The disclosed embodiment detects and processes message data through message processing rules in a preset rule database, isolates malicious intrusion data, forwards non-malicious intrusion data to specific ports, and performs intrusion detection on non-malicious intrusion data. This can prevent the free spread of Ethernet intrusion messages when they invade the entire system from any port of the Ethernet Switch, thereby improving vehicle safety.

[0110] 2. The disclosed embodiment pre-detects message data through target message processing rules and implements Ethernet intrusion message detection through SwitchTCAM. Compared with traditional software blacklist and whitelist solutions, it is more efficient and can be detected inside the Switch without occupying MCU or SOC resources.

[0111] Corresponding to the above-mentioned intrusion detection method, the present invention also provides an intrusion detection device. Since the device embodiment of the present invention corresponds to the above-mentioned method embodiment, details not disclosed in the device embodiment can be referred to the above-mentioned method embodiment and will not be repeated in this invention.

[0112] Figure 5 A schematic diagram of the structure of an intrusion detection device provided by an embodiment of the present disclosure is shown as follows: Figure 5 Shown, including:

[0113] A matching unit 51 is configured to match the attribute information of the received message data with a target message processing rule corresponding to the attribute information from a preset rule database, wherein the preset rule database contains attribute information of different message data and corresponding message processing rules;

[0114] an isolation unit 52 for isolating the malicious intrusion data if the message data is determined to be malicious intrusion data according to the target message processing rule, wherein the target message processing rule includes characteristics of the malicious intrusion data;

[0115] a forwarding unit 53 configured to forward the non-malicious intrusion data to a port corresponding to a preset detection system when the message data is determined to be non-malicious intrusion data according to the target message processing rule, wherein the target message processing rule includes port information corresponding to the preset detection device, and the preset detection system is configured to perform intrusion detection on the message data;

[0116] The detection unit 54 is configured to perform intrusion detection on the received non-malicious intrusion data through the preset detection system, and confirm whether the non-malicious intrusion data is abnormal data according to the intrusion detection result, and whether the hazard level of the abnormal data is lower than the hazard level of the malicious intrusion data.

[0117] The intrusion detection device provided by the present disclosure matches the target message processing rules corresponding to the attribute information of the received message data from a preset rule database, the preset rule database containing the attribute information of different message data and the corresponding message processing rules; when the message data is determined to be malicious intrusion data according to the target message processing rules, the malicious intrusion data is isolated and processed, wherein the target message processing rules contain the characteristics of the malicious intrusion data; when the message data is determined to be non-malicious intrusion data according to the target message processing rules, the non-malicious intrusion data is forwarded to the port corresponding to the preset detection system, the target message processing rules contain the port information corresponding to the preset detection device, and the preset detection system is used to perform intrusion detection on the message data; the received non-malicious intrusion data is subjected to intrusion detection by the preset detection system, and whether the non-malicious intrusion data is abnormal data is confirmed according to the intrusion detection result, and the hazard level of the abnormal data is lower than the hazard level of the malicious intrusion data. Compared with related technologies, the embodiment of the present disclosure detects and processes message data through message processing rules in a preset rule database, isolates malicious intrusion data, forwards non-malicious intrusion data to specific ports, and performs intrusion detection on non-malicious intrusion data. This can prevent the free spread of Ethernet intrusion messages when they invade the entire system from any port of the Ethernet Switch, thereby improving the safety of the vehicle.

[0118] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Figure 6 As shown, the forwarding unit 53 includes:

[0119] a determination module 531, configured to determine whether the non-malicious intrusion data is abnormal data according to the target message processing rule, wherein the target message processing rule includes characteristics of the abnormal data;

[0120] a modification module 532 configured to modify the Ethernet type of the non-malicious intrusion data to a preset Ethernet type, the Ethernet type being included in the attribute information, when the non-malicious intrusion data is determined to be abnormal data according to the target message processing rule;

[0121] The forwarding module 533 is used to forward the non-malicious intrusion data after the Ethernet type is modified and other non-malicious intrusion data to the port corresponding to the preset detection system; wherein the preset Ethernet type is any type used as a data label, and the other non-malicious intrusion data is all non-malicious intrusion data except the non-malicious intrusion data after the Ethernet type is modified.

[0122] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Figure 6 As shown, the detection unit 54 includes:

[0123] An acquisition module 541 is configured to acquire the Ethernet type of the non-malicious intrusion data;

[0124] a marking module 542, configured to mark the non-malicious intrusion data as abnormal data when the Ethernet type is the preset Ethernet type;

[0125] A recording module 543 is configured to extract data information from the non-malicious intrusion data and record the data information in a buffer area of ​​the preset detection system;

[0126] The marking module 542 is further configured to mark the non-malicious intrusion data as normal data when the Ethernet type is not the preset Ethernet type.

[0127] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Figure 6 As shown, the isolation unit 52 includes:

[0128] An isolation module 521 is configured to isolate the malicious intrusion data at the port receiving the message data;

[0129] The recording module 522 is configured to record the amount of the malicious intrusion data in a register corresponding to the port that receives the message data.

[0130] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Figure 6 As shown, the device also includes:

[0131] A reading unit 55 is configured to read data in a register and a buffer area of ​​a preset detection system at a periodic basis of a preset time period;

[0132] A sending unit 56 is used to send the data in the register and the buffer area of ​​the preset detection system to the server;

[0133] The clearing unit 57 is used to clear the data in the register and the buffer area of ​​the preset detection system.

[0134] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Figure 6 As shown, the device also includes:

[0135] A cache unit 58 is configured to cache data in the register and the cache area of ​​the preset detection system in a data to-be-sent area, where the data to-be-sent area is a region for temporarily caching the data in the register and the cache area of ​​the preset detection system;

[0136] The sending unit 56 is further configured to send the data in the register cached in the data to be sent area and the cache area of ​​the preset detection system to the server when it is determined that the available storage space of the cache area of ​​the preset detection system is less than a preset space threshold;

[0137] The clearing unit 57 is further configured to clear data in the data to be sent area, the register, and the cache area of ​​the preset detection system, wherein the storage space of the register and the data to be sent area is larger than the cache area of ​​the preset detection system.

[0138] It should be noted that the above explanation of the method embodiment is also applicable to the device of the embodiment of the present disclosure, and the principles are the same, which is no longer limited in the embodiment of the present disclosure.

[0139] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0140] Figure 7 A schematic block diagram of an example electronic device 700 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0141] like Figure 7 As shown, the device 700 includes a computing unit 701, which can perform various appropriate actions and processes according to a computer program stored in a ROM (Read-Only Memory) 702 or a computer program loaded from a storage unit 708 into a RAM (Random Access Memory) 703. Various programs and data required for the operation of the device 700 can also be stored in the RAM 703. The computing unit 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An I / O (Input / Output) interface 705 is also connected to the bus 704.

[0142] Various components in device 700 are connected to I / O interface 705, including an input unit 706, such as a keyboard, mouse, etc.; an output unit 707, such as various types of displays, speakers, etc.; a storage unit 708, such as a magnetic disk, optical disk, etc.; and a communication unit 709, such as a network card, modem, wireless communication transceiver, etc. The communication unit 709 allows device 700 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0143] The computing unit 701 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a CPU (Central Processing Unit), a GPU (Graphic Processing Unit), various specialized AI (Artificial Intelligence) computing chips, various computing units that run machine learning model algorithms, a DSP (Digital Signal Processor), and any suitable processor, controller, microcontroller, etc. The computing unit 701 performs the various methods and processes described above, such as the intrusion detection method. For example, in some embodiments, the intrusion detection method can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 708. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 700 via the ROM 702 and / or the communication unit 709. When the computer program is loaded into the RAM 703 and executed by the computing unit 701, one or more steps of the method described above can be performed. Alternatively, in other embodiments, the computing unit 701 may be configured to execute the aforementioned intrusion detection method in any other appropriate manner (for example, by means of firmware).

[0144] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application-Specific Standard Products), SOCs (System on Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0145] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0146] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or apparatus. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, RAM, ROM, EPROM (Electrically Programmable Read-Only-Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0147] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0148] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: LAN (Local Area Network), WAN (Wide Area Network), the Internet, and blockchain networks.

[0149] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact via a communication network. This client-server relationship is established by computer programs running on the respective computers, establishing a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host, a host product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosts and VPS services ("Virtual Private Servers" or simply "VPS"). The server may also be a server in a distributed system or a server integrated with blockchain.

[0150] It's important to note that artificial intelligence (AI) is the study of how computers can simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). This encompasses both hardware and software technologies. AI hardware technologies generally include sensors, specialized AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily encompass computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graphs.

[0151] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not limited herein.

[0152] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1. A method for intrusion detection, characterized in that: include: According to the attribute information of the received message data, a target message processing rule corresponding to the attribute information is matched from a preset rule database, wherein the preset rule database contains attribute information of different message data and corresponding message processing rules; When the message data is determined to be malicious intrusion data according to the target message processing rule, isolating the malicious intrusion data, wherein the target message processing rule includes characteristics of the malicious intrusion data; If the message data is determined to be non-malicious intrusion data according to the target message processing rule, forwarding the non-malicious intrusion data to a port corresponding to a preset detection system, wherein the target message processing rule includes port information corresponding to the preset detection device, and the preset detection system is used to perform intrusion detection on the message data; The preset detection system performs intrusion detection on the received non-malicious intrusion data, and confirms whether the non-malicious intrusion data is abnormal data according to the intrusion detection result, and the hazard level of the abnormal data is lower than the hazard level of the malicious intrusion data.

2. The method according to claim 1, characterized in that When it is determined according to the target message processing rule that the message data is non-malicious intrusion data, forwarding the non-malicious intrusion data to a port corresponding to a preset detection system includes: determining whether the non-malicious intrusion data is abnormal data according to the target message processing rule, wherein the target message processing rule includes characteristics of the abnormal data; In a case where the non-malicious intrusion data is determined to be abnormal data according to the target message processing rule, modifying the Ethernet type of the non-malicious intrusion data to a preset Ethernet type, the Ethernet type being included in the attribute information; The non-malicious intrusion data after the Ethernet type is modified and other non-malicious intrusion data are forwarded to the port corresponding to the preset detection system; wherein, the preset Ethernet type is any type used as a data label, and the other non-malicious intrusion data is all non-malicious intrusion data except the non-malicious intrusion data after the Ethernet type is modified.

3. The method according to claim 2, characterized in that The performing intrusion detection on the received non-malicious intrusion data by the preset detection system, and confirming whether the non-malicious intrusion data is abnormal data according to the intrusion detection result includes: Obtaining the Ethernet type of the non-malicious intrusion data; If the Ethernet type is the preset Ethernet type, marking the non-malicious intrusion data as abnormal data, extracting data information from the non-malicious intrusion data, and recording the data information in a buffer area of ​​the preset detection system; If the Ethernet type is not the preset Ethernet type, the non-malicious intrusion data is marked as normal data.

4. The method according to claim 1, wherein The isolating the malicious intrusion data includes: Isolating the malicious intrusion data at the port receiving the message data; The amount of the malicious intrusion data is recorded in a register corresponding to the port that receives the message data.

5. The method according to any one of claims 1 to 4, characterized in that After performing intrusion detection on the received non-malicious intrusion data through the preset detection system and confirming whether the non-malicious intrusion data is abnormal data according to the intrusion detection result, the method further includes: Reading data in a register and a buffer area of ​​a preset detection system periodically using a preset time period; The data in the register and the cache area of ​​the preset detection system are sent to the server, and the data in the register and the cache area of ​​the preset detection system are cleared.

6. The method according to any one of claims 1 to 4, characterized in that After performing intrusion detection on the received non-malicious intrusion data through the preset detection system and confirming whether the non-malicious intrusion data is abnormal data according to the intrusion detection result, the method further includes: caching the data in the register and the buffer area of ​​the preset detection system in a data to be sent area, wherein the data to be sent area is an area for temporarily caching the data in the register and the buffer area of ​​the preset detection system; When it is determined that the available storage space of the cache area of ​​the preset detection system is less than the preset space threshold, the data in the register cached in the data to be sent area and the cache area of ​​the preset detection system are sent to the server, and the data in the data to be sent area, the register and the cache area of ​​the preset detection system are cleared, wherein the storage space of the register and the data to be sent area is larger than the cache area of ​​the preset detection system.

7. An intrusion detection device, characterized in that: include: a matching unit, configured to match, based on attribute information of received message data, a target message processing rule corresponding to the attribute information from a preset rule database, wherein the preset rule database contains attribute information of different message data and corresponding message processing rules; an isolation unit, configured to isolate the malicious intrusion data if the message data is determined to be malicious intrusion data according to the target message processing rule, wherein the target message processing rule includes characteristics of the malicious intrusion data; a forwarding unit, configured to, when determining that the message data is non-malicious intrusion data according to the target message processing rule, forward the non-malicious intrusion data to a port corresponding to a preset detection system, wherein the target message processing rule includes port information corresponding to the preset detection device, and the preset detection system is configured to perform intrusion detection on the message data; The detection unit is used to perform intrusion detection on the non-malicious intrusion data through the preset detection system, and confirm whether the non-malicious intrusion data is abnormal data according to the intrusion detection result, and the hazard level of the abnormal data is lower than the hazard level of the malicious intrusion data.

8. A vehicle, characterized in that: The vehicle includes the intrusion detection device as claimed in claim 7.

9. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 6.

10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 6.