Risk detection method and device, storage medium and electronic equipment

By analyzing the target security events of ECUs and using time window strategies and risk coefficients, the accuracy and dynamic problems of ECU security risk detection in existing technologies are solved, and accurate quantification and dynamic detection of ECU security risks are achieved.

CN120705874APending Publication Date: 2025-09-26VOYAH AUTOMOBILE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510784126.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

Existing technologies are unable to conduct targeted dynamic detection of safety risks in vehicle electronic control units (ECUs), and it is difficult to conduct accurate quantitative assessments in a changing operating environment.

Method used

By extracting and analyzing the target security events of the ECU, calling the corresponding time window strategy based on the event type, determining the basic risk coefficient, ECU contribution and related security events, and combining the environmental and static risk coefficients, the security risk of the ECU can be accurately quantified.

Benefits of technology

It achieves accurate quantification of ECU security risks, completes targeted dynamic detection of ECU security risks, and improves the accuracy and real-time performance of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705874A_ABST
    Figure CN120705874A_ABST
Patent Text Reader

Abstract

The invention discloses a risk detection method and device, a storage medium and electronic equipment. The method comprises the steps of obtaining at least one target safety event of an ECU of a target vehicle, determining a corresponding basic risk coefficient, an ECU contribution degree and a time window strategy for each target safety event according to an event type of the target safety event, and determining a risk coefficient of each target safety event from candidate safety events conforming to the time window strategy, the method comprises the steps of determining an associated security event corresponding to an event type, determining event associated information according to the associated security event, determining a basic risk coefficient of an ECU according to a basic risk coefficient of each target security event, an ECU contribution degree and the event associated information, and further determining a risk coefficient of the ECU according to the basic risk coefficient, an environmental risk coefficient and a static risk coefficient of the ECU. A risk score for the ECU is determined. Through the technical scheme provided by the invention, targeted dynamic detection can be performed on the safety risk of the ECU of the target vehicle so as to obtain an accurately quantified detection result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of vehicle detection technology, and in particular relates to a risk detection method, device, storage medium and electronic equipment. Background Art

[0002] The vehicle's ECU (Electronic Control Unit) can collect data through sensors and use a microprocessor to process this data to achieve real-time control of various electronic systems on the vehicle and ensure the normal operation of the vehicle. Therefore, the security protection of the ECU is crucial.

[0003] Currently, risk detection and security protection for ECUs generally rely on static rules, such as firewalls or whitelists. This approach is not adaptable to the ever-changing operating environment of vehicles, making it difficult to conduct targeted dynamic detection of ECU security risks and, consequently, to conduct accurate quantitative assessments. Summary of the Invention

[0004] The embodiments of the present application provide a risk detection method, device, storage medium and electronic device, which can extract and analyze at least one target security event of the ECU, call the corresponding time window strategy based on the event type, accurately quantify each target security event, and then accurately quantify the security risk of the ECU, thereby completing targeted dynamic detection of the security risk of the ECU.

[0005] Other features and advantages of the present application will become apparent from the following detailed description, or may be learned in part by practice of the present application.

[0006] According to a first aspect of an embodiment of the present application, a risk detection method is provided, comprising:

[0007] Obtaining at least one target security event of an electronic control unit (ECU) of a target vehicle;

[0008] For each target security event, determine the corresponding basic risk coefficient, ECU contribution, and time window strategy based on the event type of the target security event. From the candidate security events that meet the time window strategy, determine the associated security events corresponding to the event type, and determine the event correlation information based on the associated security events.

[0009] Determine the basic risk coefficient of the ECU based on the basic risk coefficient of each target security event, ECU contribution and event correlation information;

[0010] The risk score of the ECU is determined based on the basic risk coefficient, environmental risk coefficient and static risk coefficient of the ECU.

[0011] In some embodiments of the present application, based on the aforementioned solution, associated security events corresponding to the event type are determined from candidate security events that comply with the time window policy, and event correlation information is determined based on the associated security events, including:

[0012] Call the time window strategy to obtain the target window information of the target security event;

[0013] According to the target window information, the associated security events corresponding to the event type are determined from the candidate security events within the target time window, the number of associated security events is obtained, and the event association information is determined based on the number of associated security events.

[0014] In some embodiments of the present application, based on the aforementioned solution, the target window information includes first window information and second window information, the first window information includes a first window length, and the second window information includes a second window length;

[0015] Based on the target window information, determine the associated security events corresponding to the event type from the candidate security events within the target time window, obtain the number of associated security events, and determine event correlation information based on the number of associated security events, including:

[0016] Obtaining, based on the first window information, a first number of associated security events within the first time window;

[0017] Obtaining, based on the second window information, a second number of associated security events within a second time window; wherein both the first time window and the second time window are forward windows with the occurrence time of the target security event as the window end time, the second window length is greater than the first window length, and the second time window includes the first time window;

[0018] The ratio between the second number and the first number is used as event association information of the target security event.

[0019] In some embodiments of the present application, based on the aforementioned solution, the basic risk coefficient of the ECU is determined according to the basic risk coefficient of each target security event, the ECU contribution, and the event correlation information, including:

[0020] For each target security event, the product of the basic risk coefficient of the target security event, the ECU contribution and the event correlation information is used as the target risk coefficient of the target security event;

[0021] The target risk coefficients of each target safety event are summed up to obtain the basic risk coefficient of the ECU.

[0022] In some embodiments of the present application, based on the aforementioned solution, the risk score of the ECU is determined according to the basic risk coefficient, environmental risk coefficient, and static risk coefficient of the ECU, including:

[0023] The product of the basic risk coefficient, environmental risk coefficient and static risk coefficient of the ECU is used as the target risk coefficient of the ECU;

[0024] The risk score of the ECU is determined based on the comparison result between the target risk coefficient of the ECU and the preset risk coefficient threshold.

[0025] In some embodiments of the present application, based on the aforementioned solution, determining the risk score of the ECU according to a comparison result between the target risk coefficient of the ECU and a preset risk coefficient threshold includes:

[0026] If the target risk coefficient of the ECU is less than the preset risk coefficient threshold, the risk score of the ECU is determined based on the ratio between the target risk coefficient of the ECU and the preset risk coefficient threshold;

[0027] If the target risk coefficient of the ECU is not less than the preset risk coefficient threshold, the risk score of the ECU is determined to be the preset target value.

[0028] In some embodiments of the present application, based on the aforementioned solution, obtaining at least one target security event of an electronic control unit (ECU) of a target vehicle includes:

[0029] Obtaining a security log of the ECU of the target vehicle; wherein the log type of the security log includes at least one of communication security, host alarm, remote control security, and upgrade security;

[0030] At least one target security event is extracted from the security log.

[0031] According to a second aspect of an embodiment of the present application, a risk detection device is provided, comprising:

[0032] An event acquisition module, configured to acquire at least one target security event of an ECU of a target vehicle;

[0033] An event information determination module is used to determine the corresponding basic risk coefficient, ECU contribution, and time window strategy for each target security event based on the event type of the target security event, determine the associated security events corresponding to the event type from the candidate security events that meet the time window strategy, and determine event correlation information based on the associated security events;

[0034] ECU information determination module, used to determine the basic risk coefficient of the ECU based on the basic risk coefficient of each target security event, ECU contribution and event correlation information;

[0035] The risk score determination module is used to determine the risk score of the ECU based on the basic risk coefficient, environmental risk coefficient and static risk coefficient of the ECU.

[0036] According to a third aspect of an embodiment of the present application, a computer-readable storage medium is provided, in which computer program instructions are stored. When the computer program instructions are loaded and executed by a processor, the steps of the method as described in any one of the first aspects above are implemented.

[0037] According to a fourth aspect of an embodiment of the present application, an electronic device is provided, comprising a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the steps of any one of the methods in the first aspect above are implemented.

[0038] According to a fifth aspect of an embodiment of the present application, a computer program product is provided, comprising a computer program. When the computer program is executed by a processor, the computer program implements the steps of any one of the methods in the first aspect above.

[0039] In the present application, at least one target security event of the ECU of the target vehicle is obtained. For each target security event, the corresponding basic risk coefficient, ECU contribution and time window strategy are determined according to the event type of the target security event. From the candidate security events that meet the time window strategy, the associated security events corresponding to the event type are determined, and the event association information is determined according to the associated security events. Then, the basic risk coefficient of the ECU is determined according to the basic risk coefficient, ECU contribution and event association information of each target security event. Furthermore, the risk score of the ECU is determined according to the basic risk coefficient, environmental risk coefficient and static risk coefficient of the ECU. The technical solution provided by the present application can extract and analyze at least one target security event of the ECU, call the corresponding time window strategy based on the event type, accurately quantify each target security event, and then accurately quantify the security risk of the ECU, completing the targeted dynamic detection of the security risk of the ECU.

[0040] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] The accompanying drawings are incorporated into and constitute a part of the specification, illustrating embodiments consistent with the present application and, together with the specification, explaining the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application, and those skilled in the art can derive other drawings based on these drawings without inventive effort. In the drawings:

[0042] Figure 1 A schematic diagram showing a scenario in which the risk detection method according to an embodiment of the present application can be applied;

[0043] Figure 2 A flow chart of a risk detection method in an embodiment of the present application is shown;

[0044] Figure 3 A detailed flow chart of determining event association information in an embodiment of the present application is shown;

[0045] Figure 4 A detailed flow chart of determining the basic risk coefficient of an ECU in an embodiment of the present application is shown;

[0046] Figure 5 A detailed flow chart of determining the risk score of an ECU in an embodiment of the present application is shown;

[0047] Figure 6 Another flow chart of the risk detection method in an embodiment of the present application is shown;

[0048] Figure 7 A block diagram of a risk detection device in an embodiment of the present application is shown;

[0049] Figure 8 A schematic structural diagram of an electronic device in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0050] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0051] In addition, described feature, structure or characteristic can be combined in one or more embodiments in any suitable manner.In the following description, many specific details are provided so as to provide a full understanding of the embodiments of the present application. However, it will be appreciated by those skilled in the art that the technical scheme of the present application can be put into practice without one or more of the specific details, or other methods, components, devices, steps etc. can be adopted. In other cases, known methods, devices, implementations or operations are not shown or described in detail to avoid blurring the various aspects of the application.

[0052] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically separate entities. That is, these functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0053] The flowcharts shown in the accompanying drawings are for illustrative purposes only and do not necessarily include all contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may be decomposed, while others may be combined or partially combined. Therefore, the actual execution order may vary depending on the actual situation.

[0054] In order to make those skilled in the art better understand this application, first combine Figure 1 A brief description of the application scenarios involved in this application is given.

[0055] See also Figure 1 , which shows a schematic diagram of a scenario in which the risk detection method of an embodiment of the present application can be applied.

[0056] The vehicle-side controller 101 can obtain the security log of the ECU of the target vehicle based on the data acquisition module, and extract at least one target security event of the ECU from the security log based on the dynamic risk analysis module. Then, for each target security event, according to the event type of the target security event, the corresponding basic risk coefficient, ECU contribution and time window strategy are determined. From the candidate security events that meet the time window strategy, the associated security events corresponding to the event type are determined, and the event association information is determined based on the associated security events. Furthermore, according to the basic risk coefficient, ECU contribution and event association information of each target security event, the basic risk coefficient of the ECU is determined. According to the basic risk coefficient, environmental risk coefficient and static risk coefficient of the ECU, the risk score of the ECU is determined.

[0057] The vehicle-side controller 101 can also determine the risk level corresponding to the risk score based on the policy execution module and display it in real time on the target vehicle's central control screen, and / or send it to other execution terminals, such as the terminal device held by the driver or owner of the target vehicle, and / or upload it to the VSOC (Vehicle Security Operation Center) server 102 to complete the security risk reporting of the ECU. The VSOC server 102 can have a corresponding data storage system, and the VSOC server 102 and the vehicle-side controller 101 interact with each other through a communication network.

[0058] Among them, the data acquisition module can be the data acquisition module of the vehicle-mounted IDPS (Intrusion Detection and Prevention System), the dynamic risk analysis module can be deeply integrated with the vehicle-mounted IDPS, and the policy execution module can be the policy execution module of the vehicle-mounted IDPS. The deployment is completed in the form of software without the need for hardware modification, thereby reducing development redundancy.

[0059] In an exemplary embodiment, referring to Figure 2 , shows a flow chart of the risk detection method in an embodiment of the present application, which is described in detail as follows:

[0060] Step 201: Acquire at least one target security event of an electronic control unit ECU of a target vehicle.

[0061] Among them, the target vehicle is the vehicle that currently needs to be monitored in real time. The target vehicle can be configured with multiple ECUs. The embodiment of the present application takes any one of the ECUs as an example for illustration, that is, the risk detection method provided by the embodiment of the present application can be used for any ECU on the target vehicle.

[0062] At least one target security event of an ECU refers to all security events related to the ECU, including but not limited to brute force cracking security events, OTA (Over The Air) upgrade package decryption failure security events, etc.

[0063] Optionally, the security log of the ECU of the target vehicle is obtained, and at least one target security event is extracted from the security log. The security log type includes at least one of communication security, host alarm, remote control security, and upgrade security. Exemplarily, the at least one target security event can be obtained by obtaining all security logs of the ECU within a target period using the data acquisition module, and then extracting all security events from all security logs in parallel using the dynamic risk analysis module.

[0064] It should be noted that the target period can be a preset value, and the risk detection method provided in the embodiment of the present application is periodically executed based on the target period to complete real-time detection of safety risks of the ECU of the target vehicle.

[0065] Optionally, all security events related to the ECU are screened to determine the target security event. Exemplarily, based on the event type of the security event, a target security event of the required event type is determined from all security events.

[0066] Optionally, the target security event is parsed to read data such as the occurrence time, end time, event type, and key content of the target security event.

[0067] Step 202: For each target security event, determine the corresponding basic risk coefficient, ECU contribution and time window strategy based on the event type of the target security event, determine the associated security events corresponding to the event type from the candidate security events that meet the time window strategy, and determine event association information based on the associated security events.

[0068] Target security event types include, but are not limited to, remote attacks, CAN (Controller Area Network) bus attacks, diagnostic protocol abuse, and firmware vulnerabilities. Different target security event types have corresponding base risk coefficients and ECU contributions. The base risk coefficient of a target security event represents the degree of security risk posed by the target security event, while the ECU contribution of a target security event represents the degree of impact on the ECU.

[0069] Based on the event type of the target security event, the basic risk coefficient and ECU contribution corresponding to the event type are directly obtained. That is, the basic risk coefficient and ECU contribution are both preset values ​​based on experiments. The basic risk coefficient can be a positive integer. For example, the basic risk coefficient of the target security event of brute force attack is 1000, and the basic risk coefficient of the target security event of OTA upgrade package decryption failure is 2000. The embodiments of this application do not limit the specific values. The ECU contribution can be a positive number not greater than 1.

[0070] It should be noted that due to the different security risks faced by different ECUs, the basic risk coefficient and ECU contribution of the same event type may be different for different ECUs. The basic risk coefficient and ECU contribution of target security events of different event types can be pre-configured for different ECUs.

[0071] You can also pre-configure corresponding time window policies and associated security events for target security events of different event types. Associated security events refer to other security events that are somewhat related to the target security event. The associated security events for target security events of different event types may be inconsistent, and one target security event may be an associated security event for another target security event. For example, you can configure different time window policies and associated security events for brute force attacks and OTA upgrade package decryption failures, respectively.

[0072] Optionally, a knowledge graph of ECU security events is constructed with event types as nodes and association relationships as edges. By simply analyzing the knowledge graph, associated security events of target security events of different event types can be obtained, and then classified and stored in a table for easy use.

[0073] After acquiring the target security event, the time window policy corresponding to the target security event type is determined and invoked based on the event type of the target security event. Based on the time window policy, the time window corresponding to the target security event can be determined, and then other security events within the time window can be identified as candidate security events that meet the time window policy. Furthermore, based on the event type of the target security event, associated security events corresponding to the target security event are screened from the determined candidate security events to obtain time correlation information. There can be more than one time window, and this embodiment does not impose any restrictions on this.

[0074] Exemplarily, the event type of the target security event is a remote attack. The time window strategy pre-configured for the remote attack is called, and the corresponding time window is determined to be 20 minutes forward from the occurrence of the target security event. Other security events that occurred within these 20 minutes are determined to be candidate security events that meet the time window strategy. Then, the associated security events pre-configured for the remote attack are obtained, and the associated security events corresponding to the remote attack are screened out from the determined candidate security events. Based on the relevant information of the screened associated security events, the event association information of the target security event can be obtained.

[0075] Step 203 : determining the basic risk coefficient of the ECU based on the basic risk coefficient of each target security event, the ECU contribution and the event correlation information.

[0076] Among them, the basic risk coefficient of ECU is used to characterize the degree of security risk caused by the occurrence of all the above-mentioned target security events.

[0077] For each target security event, a comprehensive analysis is conducted on the basic risk coefficient, ECU contribution and event correlation information of the target security event, and then the analysis results of all target security events are summarized to determine the basic risk coefficient of the ECU.

[0078] Step 204 : determining the risk score of the ECU based on the basic risk coefficient, the environmental risk coefficient, and the static risk coefficient of the ECU.

[0079] The environmental risk factor is a dynamic value that changes with the target vehicle's state. A higher environmental risk factor indicates a greater security risk to the target vehicle's ECU. The environmental risk factor can range from [0.5 to 3]. For example, if the target vehicle is connected to a Wi-Fi (Wireless Fidelity) hotspot, the target vehicle's network security boundary expands, increasing the corresponding attack risk. Therefore, the environmental risk factor is higher.

[0080] The static risk coefficient is a dynamic value that changes with the state of the target vehicle's ECU. A higher static risk coefficient indicates a greater security risk to the target vehicle's ECU. The static risk coefficient can range from [0.5 to 3]. For example, if the target vehicle's ECU software hasn't been updated for a long time, there's a high probability of security vulnerabilities and the ECU's security risk is increasing, resulting in a higher static risk coefficient.

[0081] The target vehicle's ECU's current environmental risk coefficient and static risk coefficient are obtained, and then combined with the ECU's basic risk coefficient to analyze and determine the ECU's risk score. The ECU's risk score is expressed as any positive integer within 100. A higher ECU risk score indicates a greater security risk.

[0082] Optionally, the environmental risk coefficient is obtained according to the vehicle state of the target vehicle, and the static risk coefficient is obtained according to the ECU state of the ECU, so as to obtain the risk score of the ECU by combining the basic risk coefficient, environmental risk coefficient and static risk coefficient of the ECU.

[0083] Optionally, graded processing is performed based on the risk score of the ECU: when the risk score is lower than 20 points, the ECU is determined to be safe and the security policy is not executed; when the risk score is not lower than 20 points and lower than 50 points, the ECU is determined to be low risk, the risk score of the ECU is logged, and related target security events are recorded; when the risk score is not lower than 50 points and lower than 90 points, the ECU is determined to be medium risk, the risk score of the ECU is logged, and related target security events are recorded, and an alarm message is triggered to the central control screen, and / or the terminal device held by the driver or owner of the target vehicle, and / or the VSOC server; when the risk score is not lower than 90 points, the ECU is determined to be high risk, the risk score of the ECU is logged, and related target security events are recorded, and an alarm message is triggered to the central control screen, and / or the terminal device held by the driver or owner of the target vehicle, and / or the VSOC server. In addition, active defense needs to be triggered to eliminate security risks as soon as possible.

[0084] In the present application, at least one target security event of the ECU of the target vehicle is obtained. For each target security event, the corresponding basic risk coefficient, ECU contribution and time window strategy are determined according to the event type of the target security event. From the candidate security events that meet the time window strategy, the associated security events corresponding to the event type are determined, and the event association information is determined according to the associated security events. Then, the basic risk coefficient of the ECU is determined according to the basic risk coefficient, ECU contribution and event association information of each target security event. Furthermore, the risk score of the ECU is determined according to the basic risk coefficient, environmental risk coefficient and static risk coefficient of the ECU. The technical solution provided by the present application can extract and analyze at least one target security event of the ECU, call the corresponding time window strategy based on the event type, accurately quantify each target security event, and then accurately quantify the security risk of the ECU, completing the targeted dynamic detection of the security risk of the ECU.

[0085] Based on the above embodiments, in an exemplary embodiment, see Figure 3 , shows a detailed flow chart of determining event association information in an embodiment of the present application, specifically including:

[0086] Step 301: Call the time window strategy to obtain target window information of the target security event.

[0087] The target window information includes, but is not limited to, the window type and window length of the target time window. The target time window can be accurately determined based on the target window information. The window type can be a sliding window, a rolling window, or a dynamic window, and the window length can be 5 minutes, 10 minutes, or 15 minutes, etc., which are not limited in the embodiments of the present application. A corresponding time window policy is pre-configured for target security events of different event types, in which the target window information is recorded and can be directly obtained when the time window policy is called.

[0088] Step 302 , based on the target window information, determine associated security events corresponding to the event type from candidate security events within the target time window, obtain the number of associated security events, and determine event association information based on the number of associated security events.

[0089] According to the target window information, the target time window is determined, and then all security events within the target time window are determined as candidate security events. The associated security events configured for the target security event of this event type are screened out from the candidate security events, so as to obtain the number of associated security events of the target security event among the candidate security events within the target time window, and obtain the event association information of the target security event based on the number of associated security events.

[0090] For example, the event type of the target security event is OTA upgrade package decryption failure, and the time window strategy of OTA upgrade package decryption failure is called to obtain the target window information including the window type as a sliding window and the window length as 15 minutes. Therefore, the target time window is determined to be 15 minutes back from the time when the target security event of OTA upgrade package decryption failure occurs, and other security events that occurred within these 15 minutes are determined as candidate security events that comply with the time window strategy. Further, the event type of the associated security event of OTA upgrade package decryption failure is obtained, and based on the event type of the associated security event, the associated security events of the target security event of OTA upgrade package decryption failure are screened out from the candidate security events, thereby obtaining the number of associated security events. According to the number of associated security events, the event association information is determined. The event association information can be a dynamic value that changes with the number of associated security events, and the event association information is directly proportional to the number of associated security events.

[0091] Optionally, the event correlation information is graded based on the number of associated security events. For example, when the number of associated security events is below a first threshold, the event correlation information is determined to be a first target value; when the number of associated security events is not less than the first threshold and is less than a second threshold, the event correlation information is determined to be a second target value; and when the number of associated security events is not less than the second threshold, the event correlation information is determined to be a third target value. The first threshold is lower than the second threshold, and the first, second, and third target values ​​increase one by one.

[0092] Optionally, the event correlation information is determined based on a ratio of the associated security events to the candidate security events, for example, based on a ratio between the number of associated security events and the number of candidate security events.

[0093] Optionally, the target window information includes first window information and second window information, the first window information includes a first window length, and the second window information includes a second window length. Based on the first window information, a first number of associated security events within a first time window can be obtained; based on the second window information, a second number of associated security events within a second time window can be obtained; wherein, the first time window and the second time window are both forward windows with the occurrence time of the target security event as the window end time, the second window length is greater than the first window length, and the second time window includes the first time window; and the ratio between the second number and the first number is used as the event association information of the target security event.

[0094] For example, the first time window is a forward window with the occurrence time of the target security event as the window end time, and the length of the first window is 5 minutes. The associated security events within 5 minutes after the occurrence of the target security event are determined, and the number of associated security events within 5 minutes is obtained, which is recorded as the first number and expressed as RE i The second time window is a forward window with the occurrence time of the target security event as the window end time. The second window length is 20 minutes. The associated security events within 20 minutes before the occurrence of the target security event are determined, and the number of associated security events within 20 minutes is obtained, which is recorded as the second number and expressed as E i Then the ratio of the second quantity to the first quantity, namely E i / RE i , determined to be event-related information.

[0095] Optionally, the second time window is a sliding window, the second window length is 20 minutes, and includes multiple sub-windows, each sub-window has a window length of 5 minutes, that is, the second time window includes four sub-windows with a window length of 5 minutes. The associated security events in these four sub-windows are determined respectively, and then the sum of the number of associated security events in these four sub-windows is determined as the second number. Specifically, the number of associated security events in the 5-minute forward sub-window with the occurrence time of the target security event as the window end time is expressed as T i1 ;T i1 The window start time is the number of associated security events in the 5-minute forward sub-window of the window end time, denoted as T i2 ;T i2 The window start time is the number of associated security events in the 5-minute forward sub-window of the window end time, denoted as T i3 ;T i3 The window start time is the number of associated security events in the 5-minute forward sub-window of the window end time, denoted as T i4 Therefore the second quantity Ei=T i1 +T i2 +T i3 +T i4 , event association information is expressed as (T i1 +T i2 +T i3 +T i4 ) / RE i .

[0096] It should be noted that when the window type of the second time window is different, the sub-windows determined are different, and therefore the second number obtained is also different. For example, when the second time window is a rolling window, there may be overlap between the determined sub-windows. Similarly, the associated security events within each sub-window are determined separately, and the sum of the number of associated security events within each sub-window is then determined as the second number.

[0097] In this application, by calling the corresponding time window strategy according to the event type, a more appropriate target time window can be determined, avoiding the influence of a shorter target time window on the accuracy of risk detection, and avoiding the excessive occupation of vehicle-side controller processing resources by determining a longer target time window. Then, according to the event type, the associated security events are determined from the candidate security events within the target time window, taking into full account the correlation between different security events. The occurrence of one security event may affect the occurrence of another security event, thereby bringing about correlation risks. The event correlation information is determined based on the number of associated security events within the target time window, and the event correlation information is used to detect the security risks of the ECU, so that more accurate and true detection results can be obtained. On this basis, the specific division of the first time window and the second time window can more accurately analyze the degree of impact of the target security event on the operation of the ECU and obtain more accurate event correlation information.

[0098] Based on the above embodiments, in an exemplary embodiment, see Figure 4 , shows a detailed flow chart of determining the basic risk coefficient of the ECU in an embodiment of the present application, specifically including:

[0099] Step 401 : For each target security event, the product of the basic risk coefficient of the target security event, the ECU contribution and the event correlation information is used as the target risk coefficient of the target security event.

[0100] For example, the basic risk factor of the target security event is expressed as Es i , the ECU contribution of the target safety event is expressed as EW i , the event correlation information of the target security event is represented as E i / RE i , the target risk coefficient of the target security event is expressed as Es i ×(E i / RE i )×EW i .

[0101] Step 402 : summing the target risk coefficients of each target safety event to obtain a basic risk coefficient of the ECU.

[0102] For example, the basic risk factor of ECU is expressed as:

[0103]

[0104] Among them, BR ECU Expressed as the basic risk coefficient of ECU, ES i Expressed as the basic risk coefficient of the i-th target security event, E i / RE i Indicates the event correlation information of the i-th target security event, EW i It represents the ECU weight of the i-th target safety event, and ECU corresponds to n target safety events.

[0105] In this application, a general formula for determining the basic risk coefficient of an ECU is provided. By integrating the target risk coefficients of all target safety events, the basic risk coefficient of the ECU can be accurately quantitatively evaluated, which is conducive to improving the accuracy of risk detection of the ECU of the target vehicle.

[0106] Based on the above embodiments, in an exemplary embodiment, see Figure 5 , shows a detailed flow chart of determining the risk score of an ECU in an embodiment of the present application, specifically including:

[0107] Step 501: The product of the basic risk coefficient, the environmental risk coefficient and the static risk coefficient of the ECU is used as the target risk coefficient of the ECU.

[0108] For example, the basic risk factor of ECU is expressed as BR ECU , the environmental risk coefficient of ECU is expressed as EE, the static risk coefficient of ECU is expressed as TS, and the target risk coefficient of ECU is expressed as R ECU =BR ECU ×EE×TS.

[0109] Step 502: Determine the risk score of the ECU based on a comparison result between the target risk coefficient of the ECU and a preset risk coefficient threshold.

[0110] For each ECU of the target vehicle, a corresponding risk coefficient threshold is preset, which is expressed as R BASE , used to determine whether the ECU has a security risk and the degree of the security risk. The risk coefficient threshold corresponding to different ECUs may be different.

[0111] Alternatively, if the target risk coefficient of the ECU is less than a preset risk coefficient threshold, it indicates that the ECU does not pose a safety risk. Conversely, if the target risk coefficient of the ECU is not less than the preset risk coefficient threshold, it indicates that the ECU poses a safety risk. Furthermore, based on the comparison result between the target risk coefficient of the ECU and the preset risk coefficient threshold, different methods for determining the risk score of the ECU may be adopted, for example, a grading process may be performed based on the target risk coefficient of the ECU.

[0112] Optionally, the target risk coefficient is normalized based on the comparison result between the target risk coefficient and the risk coefficient threshold, thereby obtaining the risk score of the ECU. For example, the risk score of the ECU is represented by R, and its normalization formula is expressed as:

[0113]

[0114] Optionally, if the target risk coefficient of the ECU is less than a preset risk coefficient threshold, the risk score of the ECU is determined based on the ratio between the target risk coefficient of the ECU and the preset risk coefficient threshold; if the target risk coefficient of the ECU is not less than the preset risk coefficient threshold, the risk score of the ECU is determined as the preset target value.

[0115] That is, R ECU <R BASE , determine the risk score of the ECU R ECU ≥R BASE , determine the risk score of ECU += 100.

[0116] In this application, a general formula for determining the risk score of an ECU is provided. Normalization is performed based on the target risk coefficient of the ECU, which can accurately quantify the risk score of the ECU and help improve the accuracy of risk detection of the ECU of the target vehicle.

[0117] In order to enable those skilled in the art to better understand the present application as a whole, the application process of the present application scheme will be briefly described below using a specific embodiment:

[0118] See also Figure 6 , shows another flow chart of the risk detection method in an embodiment of the present application, specifically including:

[0119] Step 601: Obtain the security log of the ECU of the target vehicle.

[0120] The log type of the security log includes at least one of communication security, host alarm, remote control security and upgrade security.

[0121] Step 602: extract at least one target security event from the security log.

[0122] Step 603: For each target security event, determine the corresponding basic risk coefficient, ECU contribution and time window strategy according to the event type of the target security event.

[0123] Step 604: For each target security event, call the time window strategy to obtain first window information and second window information of the target security event.

[0124] Step 605: For each target security event, obtain a first number of associated security events within a first time window according to the first window information.

[0125] Step 606: For each target security event, obtain a second number of associated security events within a second time window according to the second window information.

[0126] Step 607: For each target security event, use the ratio of the second number to the first number as event association information of the target security event.

[0127] Among them, the first window information includes the first window length, the second window information includes the second window length, the first time window and the second time window are both forward windows with the occurrence time of the target security event as the window end time, the second window length is greater than the first window length, and the second time window includes the first time window.

[0128] Step 608 : For each target security event, the product of the basic risk coefficient of the target security event, the ECU contribution, and the event correlation information is used as the target risk coefficient of the target security event.

[0129] Step 609 : summing the target risk coefficients of each target safety event to obtain a basic risk coefficient of the ECU.

[0130] Step 610: The product of the basic risk coefficient of the ECU, the environmental risk coefficient and the static risk coefficient is used as the target risk coefficient of the ECU.

[0131] Step 611: determine whether the target risk coefficient of the ECU is less than a preset risk coefficient threshold.

[0132] If yes, go to step 612; if no, go to step 613.

[0133] Step 612: Determine the risk score of the ECU based on the ratio between the target risk coefficient of the ECU and a preset risk coefficient threshold.

[0134] Step 613: determine the risk score of the ECU as a preset target value.

[0135] In this application, it is possible to extract and analyze at least one target security event of the ECU, call the corresponding time window strategy based on the event type, accurately quantify each target security event, and then accurately quantify the security risk of the ECU, completing targeted dynamic detection of the security risk of the ECU.

[0136] The following describes an embodiment of the device of the present application, which can be used to perform the risk detection method in the above embodiment of the present application. For details not disclosed in the embodiment of the device of the present application, please refer to the embodiment of the risk detection method in the above embodiment of the present application.

[0137] See also Figure 7 , shows a block diagram of a risk detection device 700 in an embodiment of the present application, specifically comprising:

[0138] The event acquisition module 701 is configured to acquire at least one target safety event of the ECU of a target vehicle.

[0139] The event information determination module 702 is used to determine the corresponding basic risk coefficient, ECU contribution and time window strategy for each target security event according to the event type of the target security event, determine the associated security events corresponding to the event type from the candidate security events that meet the time window strategy, and determine event association information based on the associated security events.

[0140] The ECU information determination module 703 is used to determine the basic risk coefficient of the ECU based on the basic risk coefficient of each target security event, the ECU contribution and the event correlation information.

[0141] The risk score determination module 704 is configured to determine the risk score of the ECU based on the basic risk coefficient, the environmental risk coefficient, and the static risk coefficient of the ECU.

[0142] In an exemplary embodiment, the event information determination module 702 includes: a policy invocation unit configured to invoke a time window policy to obtain target window information for a target security event; and a correlation information determination unit configured to determine, based on the target window information, associated security events corresponding to the event type from candidate security events within the target time window, obtain the number of associated security events, and determine event correlation information based on the number of associated security events.

[0143] In an exemplary embodiment, the target window information includes first window information and second window information, the first window information includes a first window length, and the second window information includes a second window length. The above-mentioned association information determination unit includes: a first quantity determination subunit, which is used to obtain a first quantity of associated security events within a first time window based on the first window information. A second quantity determination subunit, which is used to obtain a second quantity of associated security events within a second time window based on the second window information; wherein, the first time window and the second time window are both forward windows with the occurrence time of the target security event as the window end time, the second window length is greater than the first window length, and the second time window includes the first time window. The association information determination subunit is used to use the ratio between the second quantity and the first quantity as event association information of the target security event.

[0144] In an exemplary embodiment, the ECU information determination module 703 includes: a first target coefficient determination unit configured to, for each target security event, determine the product of the target security event's base risk coefficient, the ECU contribution, and the event association information as the target risk coefficient for the target security event; and a summation processing unit configured to sum the target risk coefficients of each target security event to obtain the base risk coefficient for the ECU.

[0145] In an exemplary embodiment, the risk score determination module 704 includes a second target coefficient determination unit configured to determine the target risk coefficient of the ECU by taking the product of the ECU's base risk coefficient, the environmental risk coefficient, and the static risk coefficient. The risk score determination unit is configured to determine the ECU's risk score based on a comparison between the ECU's target risk coefficient and a preset risk coefficient threshold.

[0146] In an exemplary embodiment, the above-mentioned risk score determination unit is specifically used to determine the risk score of the ECU based on the ratio between the target risk coefficient of the ECU and the preset risk coefficient threshold if the target risk coefficient of the ECU is less than the preset risk coefficient threshold; if the target risk coefficient of the ECU is not less than the preset risk coefficient threshold, determine the risk score of the ECU as the preset target value.

[0147] Based on the same inventive concept, an embodiment of the present application provides a computer-readable storage medium, in which computer program instructions are stored. When the computer program instructions are loaded and executed by a processor, the steps of the risk detection method described above are implemented.

[0148] Based on the same inventive concept, the embodiment of the present application provides an electronic device, see Figure 8, shows a structural diagram of an electronic device in an embodiment of the present application, the electronic device includes one or more memories 804, one or more processors 802 and at least one computer program stored in the memory 804 and executable on the processor 802, and when the processor 802 executes the computer program, the steps of the risk detection method described above are implemented.

[0149] The bus architecture (represented by bus 800) may include any number of interconnected buses and bridges, and bus 800 links various circuits including one or more processors represented by processor 802 and memory represented by memory 804. Bus 800 may also link various other circuits such as peripherals, voltage regulators, and power management circuits, which are well known in the art and are therefore not described further herein. Bus interface 805 provides an interface between bus 800 and receiver 801 and transmitter 803. Receiver 801 and transmitter 803 may be the same component, namely a transceiver, which provides a unit for communicating with various other devices over a transmission medium. Processor 802 is responsible for managing bus 800 and general processing, while memory 804 may be used to store data used by processor 802 when performing operations.

[0150] The functions described herein may be implemented in hardware, software executed by a processor, firmware, or any combination thereof. If implemented in software executed by a processor, the functions may be stored as one or more instructions or codes on or transmitted via a computer-readable medium. Other examples and implementations are within the scope and spirit of this application and the appended claims. For example, due to the nature of software, the functions described above may be implemented using software executed by a processor, hardware, firmware, hardwiring, or a combination of any of these. Furthermore, the functional units may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit.

[0151] Based on the same inventive concept, an embodiment of the present application provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements the steps of the risk detection method as described above.

[0152] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0153] The units described as separate components may or may not be physically separate, and the components of the control device may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0154] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc. Various media that can store computer program instructions.

[0155] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present application shall be included within the scope of the claims of the present application.

Claims

1. A risk detection method, characterized in that: The method comprises: Obtaining at least one target security event of an electronic control unit (ECU) of a target vehicle; For each target security event, determine the corresponding basic risk coefficient, ECU contribution, and time window strategy based on the event type of the target security event; determine associated security events corresponding to the event type from candidate security events that meet the time window strategy; and determine event association information based on the associated security events; Determine the basic risk coefficient of the ECU based on the basic risk coefficient of each target security event, ECU contribution and event correlation information; The risk score of the ECU is determined according to the basic risk coefficient, the environmental risk coefficient and the static risk coefficient of the ECU.

2. The method according to claim 1, characterized in that The step of determining, from candidate security events that comply with the time window policy, associated security events corresponding to the event type, and determining event correlation information based on the associated security events, includes: Calling the time window strategy to obtain target window information of the target security event; According to the target window information, associated security events corresponding to the event type are determined from candidate security events within the target time window, the number of associated security events is obtained, and event association information is determined based on the number of associated security events.

3. The method according to claim 2, characterized in that The target window information includes first window information and second window information, the first window information includes a first window length, and the second window information includes a second window length; The step of determining, based on the target window information, associated security events corresponding to the event type from candidate security events within the target time window, obtaining the number of associated security events, and determining event association information based on the number of associated security events includes: Obtaining, based on the first window information, a first number of associated security events within a first time window; Obtaining, based on the second window information, a second number of associated security events within a second time window; wherein both the first time window and the second time window are forward windows with the occurrence time of the target security event as the window end time, the second window length is greater than the first window length, and the second time window includes the first time window; The ratio between the second number and the first number is used as the event association information of the target security event.

4. The method according to claim 1, wherein Determining the basic risk coefficient of the ECU based on the basic risk coefficient of each target security event, the ECU contribution and event correlation information includes: For each target security event, the product of the basic risk coefficient of the target security event, the ECU contribution and the event correlation information is used as the target risk coefficient of the target security event; The target risk coefficients of each target safety event are summed up to obtain the basic risk coefficient of the ECU.

5. The method according to claim 1, wherein Determining the risk score of the ECU based on the basic risk coefficient, the environmental risk coefficient, and the static risk coefficient of the ECU includes: The product of the basic risk coefficient, the environmental risk coefficient and the static risk coefficient of the ECU is used as the target risk coefficient of the ECU; The risk score of the ECU is determined based on a comparison result between a target risk coefficient of the ECU and a preset risk coefficient threshold.

6. The method according to claim 5, characterized in that Determining the risk score of the ECU based on a comparison result between the target risk coefficient of the ECU and a preset risk coefficient threshold includes: If the target risk coefficient of the ECU is less than a preset risk coefficient threshold, determining a risk score of the ECU based on a ratio between the target risk coefficient of the ECU and the preset risk coefficient threshold; If the target risk coefficient of the ECU is not less than a preset risk coefficient threshold, the risk score of the ECU is determined to be a preset target value.

7. The method according to claim 1, characterized in that The obtaining of at least one target security event of an electronic control unit ECU of a target vehicle includes: Obtaining a security log of the ECU of the target vehicle; wherein the log type of the security log includes at least one of communication security, host alarm, remote control security, and upgrade security; At least one target security event is extracted from the security log.

8. A risk detection device, characterized in that: The device comprises: An event acquisition module, configured to acquire at least one target security event of an ECU of a target vehicle; An event information determination module is configured to determine, for each target security event, a corresponding basic risk coefficient, an ECU contribution, and a time window strategy based on the event type of the target security event; determine associated security events corresponding to the event type from candidate security events that meet the time window strategy; and determine event association information based on the associated security events; ECU information determination module, used to determine the basic risk coefficient of the ECU based on the basic risk coefficient of each target security event, ECU contribution and event correlation information; The risk score determination module is used to determine the risk score of the ECU based on the basic risk coefficient, environmental risk coefficient and static risk coefficient of the ECU.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, which, when loaded and executed by a processor, implement the steps of the method according to any one of claims 1 to 7.

10. An electronic device comprising a memory and a processor, characterized in that: The memory stores a computer program, and when the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.