Internet of vehicles threat modeling and dynamic protection system based on ATTCK attack library

Through the threat modeling and dynamic protection system based on the ATT&CK attack library, threat models are generated and protection strategies are initiated, which solves the problem of the Internet of Vehicles system failing to perform real-time modeling and protection in complex environments, and realizes dynamic protection and security improvement of the Internet of Vehicles system.

CN120729613AInactive Publication Date: 2025-09-30SUZHOU QIMIFENG INFORMATION SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511029157.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-25
Publication Date
2025-09-30
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In existing technologies, the Internet of Vehicles system lacks the real-time threat modeling and dynamic protection capabilities for complex and changing network environments, resulting in potential threats not being discovered and effectively responded to in a timely manner.

Method used

A threat modeling and dynamic protection system based on the ATT&CK attack library is adopted, including threat data collection, modeling, dynamic protection and linkage response modules. Threat models are generated through security data from multiple sources, and protection strategies are initiated when key nodes in the attack path are detected. The execution order of protection strategies is coordinated, and the AES-256 encryption algorithm and TLS 1.3 protocol are used to ensure data transmission security.

Benefits of technology

It realizes real-time modeling and dynamic protection of the Internet of Vehicles system, which can effectively deal with potential threats in complex and changing network environments and improve the overall security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729613A_ABST
    Figure CN120729613A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of Internet of Vehicles security, and discloses an ATTamp-based Internet of Vehicles security system. The invention discloses an Internet of Vehicles threat modeling and dynamic protection system of a CK attack library. The system comprises a threat data acquisition module, a threat modeling module, a dynamic protection module and a linkage response module. The system generates a threat model by collecting multi-source data such as a vehicle-mounted sensor log, starts a protection strategy when detecting that an attack path key node is triggered, and coordinates the execution sequence of a plurality of protection strategies at the same time. According to the invention, real-time modeling and dynamic protection of Internet of Vehicles security threats can be realized, and the security of the system in a complex network environment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet of Vehicles security technology, and specifically to an Internet of Vehicles threat modeling and dynamic protection system based on the ATT&CK attack library. Background Art

[0002] With the rapid development of connected vehicle (IoV) technology, intelligent, connected vehicles (IoVs) have become an integral part of modern transportation. By integrating communication, computing, and control functions, IoV systems enable real-time interaction between vehicles and the external environment, improving the driving experience and traffic efficiency. However, the widespread use of IoV systems also poses significant security threats, as attackers could exploit system vulnerabilities to carry out malicious activities.

[0003] Existing threat analysis methods based on the ATT&CK attack library have been introduced into the cybersecurity field to identify potential attack paths and methods. However, in practice, existing protection mechanisms often focus on static rule matching or single-scenario protection strategies, lacking the ability to model and protect against the dynamic characteristics of the Internet of Vehicles in real time. This limitation can result in some potential threats not being discovered and effectively addressed in a complex and changing network environment. Summary of the Invention

[0004] The purpose of the embodiments of the present invention is to provide a vehicle network threat modeling and dynamic protection system based on the ATT&CK attack library, aiming to solve the problem in the existing technology that vehicle network security threats are difficult to model and dynamically protect in real time.

[0005] The embodiment of the present invention is implemented as follows: on the one hand, a vehicle network threat modeling and dynamic protection system based on the ATT&CK attack library includes: A threat data collection module is configured to receive security data from multiple sources, including at least vehicle sensor logs, communication protocol traffic records, and cloud interaction behavior logs. A threat modeling module is configured to generate a threat model based on the security data, wherein the threat model at least includes attack path analysis, attack method classification, and potential target area labeling; A dynamic protection module is configured to: initiate a protection strategy upon detecting that a key node of an attack path in a threat model is triggered, wherein the protection strategy includes subsequent actions to block the attack path, isolate the affected target area, and record detailed information about the attack behavior; The linkage response module is used to: when trigger conditions are detected on multiple attack paths at the same time, coordinate the execution order of different protection strategies and ensure that key protection measures are completed first through a priority mechanism.

[0006] As a further solution of the present invention, the threat data collection module specifically includes: A data acquisition unit is used to acquire real-time operation data from the vehicle-mounted terminal device, wherein the real-time operation data includes a log of vehicle control instructions, data packets of in-vehicle network communication, and operation records of external access interfaces; A data processing unit is used to preprocess the real-time operation data, wherein the preprocessing includes data cleaning, format standardization, and time stamp calibration to generate a standard data stream that meets the input requirements of the threat modeling module.

[0007] As a further embodiment of the present invention, the threat modeling module specifically includes: The attack path generation unit is used to generate possible attack paths based on the tactics and technical descriptions in the ATT&CK attack library and the architectural characteristics of the current Internet of Vehicles system. The attack method matching unit is used to compare the collected security data with the technical features in the ATT&CK attack library to identify existing attack methods in the current environment; The target area marking unit is used to mark target areas that may be threatened based on the identified attack methods. The target areas include the vehicle-mounted electronic control unit, the in-vehicle communication network and the cloud service platform.

[0008] As a further solution of the present invention, the dynamic protection module further includes an anomaly detection unit, which specifically includes: The behavior pattern analysis subunit is used to analyze the historical operation data of the target area and extract the characteristic parameters of the normal behavior pattern; The abnormality determination subunit is used to compare the real-time operation data with the characteristic parameters of the normal behavior pattern, and determine it as abnormal behavior when the deviation exceeds a preset threshold; The anomaly detection unit is also used to: classify abnormal behaviors through a machine learning algorithm, and the classification results include malicious attack behaviors, erroneous operation behaviors, and environmental interference behaviors; the classification results are used to guide the dynamic protection module to select corresponding protection strategies.

[0009] As a further solution of the present invention, the linkage response module specifically includes: The priority evaluation unit is used to calculate the execution priority of each protection strategy based on the impact range of the attack path, the complexity of the attack method, and the importance of the target area; The policy scheduling unit is used to execute protection policies in order of priority. When the high-priority policy is executed, resources are released for use by the low-priority policy. The feedback adjustment unit is used to monitor the status changes of the target area in real time during the execution of the protection strategy, and adjust the execution parameters of the protection strategy if the status does not achieve the expected effect.

[0010] As a further solution of the present invention, the dynamic protection module further includes a recovery unit, which specifically includes: The status recording subunit is used to record the initial status of the target area before the protection strategy is executed, wherein the initial status includes hardware configuration, software version and network connection status; The recovery execution subunit is used to: after the protection strategy is executed, if the function of the target area still cannot be restored to normal, perform a rollback operation based on the initial state; The verification subunit is used to: after the rollback operation is completed, comprehensively verify the functions of the target area, and the verification results include functional integrity, performance stability and security.

[0011] As a further solution of the present invention, the threat modeling module and the dynamic protection module are connected through a bidirectional communication link, and the bidirectional communication link adopts an encrypted transmission protocol to ensure the confidentiality and integrity of data during transmission; the encrypted transmission protocol includes the AES-256 encryption algorithm and the TLS 1.3 protocol.

[0012] The Internet of Vehicles threat modeling and dynamic protection system based on the ATT&CK attack library provided by an embodiment of the present invention obtains security data from multiple sources through a threat data acquisition module, and uses a threat modeling module to generate a threat model covering attack paths, attack methods and target areas. On this basis, the dynamic protection module can activate the corresponding protection strategy when it detects that a key node of the attack path is triggered, blocking the attack path and isolating the affected target area. In addition, the linkage response module coordinates the execution order of multiple protection strategies through a priority mechanism to ensure that key protection measures are completed first. Through the above-mentioned structural design, the present invention can perform real-time modeling and protection for the dynamic characteristics of the Internet of Vehicles system, effectively respond to potential threats in a complex and changeable network environment, and improve the overall security of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 This is a block diagram of the overall system structure of the present invention; Figure 2 This is a functional structure diagram of the threat data acquisition module of the present invention; Figure 3 This is a functional structure diagram of the threat modeling module of the present invention; Figure 4 This is a structural block diagram of the dynamic protection module of the present invention; Figure 5 This is a flowchart of the workflow of the linkage response module of the present invention; Figure 6 This is a logic block diagram of the recovery unit operation of the present invention.

[0014] Among them, 1. Threat data collection module; 2. Threat modeling module; 3. Dynamic protection module; 4. Linkage response module; 5. Data acquisition unit; 6. Data processing unit; 7. Attack path generation unit; 8. Attack means matching unit; 9. Target area marking unit; 10. Anomaly detection unit; 11. Behavior pattern analysis subunit; 12. Anomaly determination subunit; 13. Priority evaluation unit; 14. Policy scheduling unit; 15. Feedback adjustment unit; 16. Recovery unit; 17. Status recording subunit; 18. Recovery execution subunit; 19. Verification subunit. DETAILED DESCRIPTION

[0015] The following will clearly and completely describe the technical solution of the present invention in conjunction with the accompanying drawings. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0016] The embodiment of the present invention provides a vehicle network threat modeling and dynamic protection system based on the ATT&CK attack library, the overall structure of which is as follows: Figure 1 As shown in the figure, it includes threat data collection module 1, threat modeling module 2, dynamic protection module 3 and linkage response module 4. These modules form a complete Internet of Vehicles security protection system through logical connection and data interaction.

[0017] Threat data acquisition module 1 is the data input end of the entire system, and its functional structure is as follows: Figure 2 As shown, it includes a data acquisition unit 5 and a data processing unit 6. The data acquisition unit 5 extracts real-time operating data from the on-board terminal device. These data include logs of vehicle control instructions, data packets of in-vehicle network communications, and operation records of external access interfaces. The data acquisition unit 5 communicates with the in-vehicle electronic control unit through the CAN bus protocol, and establishes a connection with the cloud service platform through Ethernet or wireless communication protocol. After receiving the raw data, the data processing unit 6 performs preprocessing operations on it. The preprocessing process includes data cleaning to remove redundant and invalid information, format standardization to unify the expression of data from different sources, and timestamp calibration to ensure the time consistency of the data. The standard data stream after preprocessing is transmitted to the threat modeling module 2 as the basis for subsequent threat modeling.

[0018] The functional structure of threat modeling module 2 is as follows Figure 3As shown, the system consists of an attack path generation unit 7, an attack method matching unit 8, and a target area labeling unit 9. The attack path generation unit 7 generates possible attack paths based on the tactics and technical descriptions in the ATT&CK attack library and the architectural characteristics of the current connected vehicle system. For example, an attack path against the in-vehicle entertainment system might include invading the in-vehicle entertainment console via the Bluetooth interface, thereby exploiting unauthorized access rights to spread to the in-vehicle network. The attack method matching unit 8 compares the security data provided by the threat data collection module 1 with the technical features in the ATT&CK attack library to identify existing attack methods in the current environment. For example, if an abnormal communication behavior is detected that meets the technical description of "remote code execution" in the ATT&CK attack library, it is determined to be a potential attack method. The target area labeling unit 9 labels target areas that may be threatened based on the identified attack methods. These target areas include the vehicle's electronic control unit, the in-vehicle communication network, and the cloud service platform. For example, if an attack method involves illegal control of the vehicle's braking system, the target area labeling unit 9 will mark the vehicle's braking system as a high-risk area.

[0019] The structure of dynamic protection module 3 is as follows Figure 4 As shown, it includes an anomaly detection unit 10 and its subunits, a behavior pattern analysis subunit 11 and an anomaly determination subunit 12. The behavior pattern analysis subunit 11 extracts characteristic parameters of the normal behavior pattern by analyzing the historical operation data of the target area. For example, for an in-vehicle navigation system, its normal behavior pattern may include sending no more than 10 location update requests per second. The anomaly determination subunit 12 compares the real-time operation data with the characteristic parameters of the normal behavior pattern, and determines it as abnormal behavior when the deviation exceeds a preset threshold. For example, if the in-vehicle navigation system suddenly sends more than 100 location update requests per second within a certain period of time, it is determined to be abnormal behavior. The anomaly detection unit 10 also classifies abnormal behaviors through a machine learning algorithm, and the classification results include malicious attack behaviors, misoperation behaviors, and environmental interference behaviors. The classification results are used to guide the dynamic protection module 3 to select the corresponding protection strategy. For example, if the classification result is a malicious attack behavior, the subsequent action of blocking the attack path is initiated and the affected target area is isolated.

[0020] The workflow of linkage response module 4 is as follows: Figure 5As shown, it includes a priority evaluation unit 13, a strategy scheduling unit 14 and a feedback adjustment unit 15. The priority evaluation unit 13 calculates the execution priority of each protection strategy based on the impact range of the attack path, the complexity of the attack means and the importance of the target area. For example, the attack path against the vehicle power system will be given the highest priority because of its wide impact range and may cause serious consequences. The strategy scheduling unit 14 executes the protection strategies in order of priority, and releases resources for low-priority strategies when the high-priority strategy is executed. For example, when the attack paths against the vehicle entertainment system and the vehicle power system are detected at the same time, the attack path against the vehicle power system is blocked first. The feedback adjustment unit 15 monitors the state changes of the target area in real time during the execution of the protection strategy, and adjusts the execution parameters of the protection strategy if the state does not achieve the expected effect. For example, if abnormal communication behavior still exists in the target area after blocking a certain attack path, the intensity or range of the blocking strategy is adjusted.

[0021] The dynamic protection module 3 also includes a recovery unit 16, whose operation logic is as follows: Figure 6 As shown, it includes a status recording subunit 17, a recovery execution subunit 18 and a verification subunit 19. The status recording subunit 17 records the initial state of the target area before the protection strategy is executed. The initial state includes the hardware configuration, software version and network connection status. For example, for a vehicle air-conditioning system, its initial state may include the current temperature being set to 25 degrees Celsius, the wind speed being set to mid-range and the network connection status being online. After the protection strategy is executed, if the function of the target area still cannot be restored to normal, the recovery execution subunit 18 performs a rollback operation based on the initial state. For example, if the protection strategy causes the vehicle air-conditioning system to be unable to adjust the temperature normally, the recovery execution subunit 18 rolls the system state back to the initial state. After the rollback operation is completed, the verification subunit 19 performs a comprehensive verification of the function of the target area. The verification results include functional integrity, performance stability and safety. For example, the verification subunit 19 checks whether the vehicle air-conditioning system can adjust the temperature normally, whether the wind speed is adjustable and whether the network connection is stable.

[0022] Threat Modeling Module 2 and Dynamic Protection Module 3 are connected via a bidirectional communication link. This link utilizes the AES-256 encryption algorithm and the TLS 1.3 protocol to ensure confidentiality and integrity of data during transmission. For example, when Threat Modeling Module 2 generates a new threat model, it transmits the threat model to Dynamic Protection Module 3 via the bidirectional communication link. Dynamic Protection Module 3 then adjusts its protection strategy based on the threat model. Similarly, feedback generated by Dynamic Protection Module 3 during the execution of its protection strategy is also transmitted to Threat Modeling Module 2 via the bidirectional communication link for optimization of the threat model generation process.

[0023] The connections and collaboration mechanisms between the various modules and units mentioned above ensure the efficient operation of the system. For example, the threat data acquisition module 1 provides high-quality security data to the threat modeling module 2 through the data acquisition unit 5 and the data processing unit 6. The threat modeling module 2 generates an accurate threat model through the attack path generation unit 7, the attack method matching unit 8, and the target area annotation unit 9. The dynamic protection module 3 accurately identifies and protects against threats through the anomaly detection unit 10 and its subunits, the behavior pattern analysis subunit 11 and the anomaly determination subunit 12. The linkage response module 4 coordinates the execution order of multiple protection strategies through the priority evaluation unit 13, the policy scheduling unit 14, and the feedback adjustment unit 15. The recovery unit 16 ensures that the target area's functions are restored to normal through the status recording subunit 17, the recovery execution subunit 18, and the verification subunit 19.

[0024] In order to better enable relevant personnel in this technical field to fully understand and implement the present invention, the specific implementation principle of the present invention is supplemented below with reference to a specific application scenario. In the connected car environment, when the in-car entertainment system of a certain intelligent connected car is connected to external devices via the Bluetooth interface, it may face the risk of unauthorized access. In this case, the operation process of the connected car threat modeling and dynamic protection system based on the ATT&CK attack library is as follows: First, the data acquisition unit 5 in the threat data acquisition module 1 extracts security data from the vehicle's terminal devices in real time. This data includes communication records received by the in-vehicle entertainment system via the Bluetooth interface, vehicle control command logs, and data packets from in-vehicle network communications. The data processing unit 6 preprocesses the received raw data, such as removing redundant information, standardizing the data format, and calibrating timestamps to ensure temporal consistency. This preprocessed standard data stream is then transmitted to the threat modeling module 2.

[0025] Subsequently, the attack path generation unit 7 in the threat modeling module 2 generates possible attack paths based on the tactical and technical descriptions in the ATT&CK attack library and the architectural characteristics of the current Internet of Vehicles system. For example, the attack path against the in-vehicle entertainment system may include invading the in-vehicle entertainment host through the Bluetooth interface, and then using unauthorized access rights to spread to the in-vehicle network. The attack means matching unit 8 compares the security data provided by the threat data acquisition module 1 with the technical features in the ATT&CK attack library to identify the attack means that already exist in the current environment. For example, when an abnormal communication behavior is detected that meets the technical description of "remote code execution" in the ATT&CK attack library, the behavior is determined to be a potential attack means. The target area marking unit 9 marks the target area that may be threatened according to the identified attack means, such as marking the in-vehicle entertainment system as a high-risk area.

[0026] Next, the anomaly detection unit 10 in the dynamic protection module 3 starts working. The behavior pattern analysis subunit 11 extracts the characteristic parameters of the normal behavior pattern by analyzing the historical operation data of the in-vehicle entertainment system. For example, for the in-vehicle entertainment system, its normal behavior pattern may include receiving no more than 5 Bluetooth connection requests per minute. The abnormality judgment subunit 12 compares the real-time operation data with the characteristic parameters of the normal behavior pattern, and determines it as abnormal behavior when the deviation exceeds the preset threshold. For example, if the in-vehicle entertainment system suddenly receives more than 50 Bluetooth connection requests per minute within a certain period of time, it is determined to be abnormal behavior. The anomaly detection unit 10 also classifies abnormal behaviors through machine learning algorithms, and the classification results include malicious attack behaviors, misoperation behaviors, and environmental interference behaviors. The classification results are used to guide the dynamic protection module 3 to select the corresponding protection strategy. For example, if the classification result is malicious attack behavior, the subsequent action of blocking the attack path is initiated and the affected target area is isolated.

[0027] In the linkage response module 4, the priority evaluation unit 13 calculates the execution priority of each protection strategy based on the impact range of the attack path, the complexity of the attack means, and the importance of the target area. For example, the attack path against the in-vehicle entertainment system will be given a higher priority because it may lead to the leakage of sensitive data. The strategy scheduling unit 14 executes the protection strategies in order of priority, and releases resources for low-priority strategies to use after the execution of the high-priority strategy is completed. For example, when the attack paths against the in-vehicle entertainment system and the in-vehicle power system are detected at the same time, the attack path against the in-vehicle power system is blocked first. The feedback adjustment unit 15 monitors the state changes of the target area in real time during the execution of the protection strategy, and adjusts the execution parameters of the protection strategy if the state does not achieve the expected effect. For example, if abnormal communication behavior still exists in the target area after blocking a certain attack path, the intensity or range of the blocking strategy is adjusted.

[0028] In addition, the recovery unit 16 in the dynamic protection module 3 plays a role after the protection strategy is executed. The status recording subunit 17 records the initial state of the target area before the protection strategy is executed. For example, the initial state of the in-vehicle entertainment system may include the current volume being set to 15, the play mode being random play, and the Bluetooth connection status being off. The recovery execution subunit 18 performs a rollback operation based on the initial state if the function of the target area still cannot be restored to normal after the protection strategy is executed. For example, if the protection strategy causes the in-vehicle entertainment system to be unable to play music normally, the recovery execution subunit 18 rolls the system state back to the initial state. The verification subunit 19 performs a comprehensive verification of the function of the target area after the rollback operation is completed. The verification results include functional integrity, performance stability, and safety. For example, the verification subunit 19 checks whether the in-vehicle entertainment system can play music normally, whether the volume is adjustable, and whether the Bluetooth connection is stable.

[0029] Throughout the entire process, Threat Modeling Module 2 and Dynamic Protection Module 3 are connected via a bidirectional communication link. This bidirectional communication link utilizes the AES-256 encryption algorithm and the TLS 1.3 protocol to ensure confidentiality and integrity of data during transmission. For example, when Threat Modeling Module 2 generates a new threat model, it transmits the threat model to Dynamic Protection Module 3 via the bidirectional communication link. Dynamic Protection Module 3 then adjusts its protection strategy based on the threat model. Similarly, feedback generated by Dynamic Protection Module 3 during the execution of its protection strategy is also transmitted to Threat Modeling Module 2 via the bidirectional communication link for optimization of the threat model generation process.

[0030] Through the above steps, the IoV threat modeling and dynamic protection system based on the ATT&CK attack library provided by this embodiment of the present invention can effectively respond to potential threats in complex and changing network environments, improving the overall security of the system. This operational process ensures efficient collaboration between various modules and units, enabling real-time modeling and dynamic protection of the IoV system.

[0031] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A vehicle network threat modeling and dynamic protection system based on the ATT&CK attack library, characterized by: include: A threat data collection module (1) is used to: receive security data from multiple sources, the security data at least including vehicle sensor logs, communication protocol flow records, and cloud interaction behavior logs; A threat modeling module (2) is used to generate a threat model based on the security data, wherein the threat model at least includes attack path analysis, attack method classification, and potential target area marking; A dynamic protection module (3) is used to: when a key node of an attack path in a threat model is detected to be triggered, initiate a protection strategy, wherein the protection strategy includes subsequent actions of blocking the attack path, isolating the affected target area, and recording detailed information of the attack behavior; The linkage response module (4) is used to: when trigger conditions are detected for multiple attack paths at the same time, coordinate the execution order of different protection strategies and ensure that key protection measures are completed first through a priority mechanism.

2. The IoV threat modeling and dynamic protection system based on the ATT&CK attack library according to claim 1 is characterized in that: The threat data collection module (1) specifically includes: A data acquisition unit (5) is used to acquire real-time operation data from the vehicle-mounted terminal device, wherein the real-time operation data includes a log of vehicle control instructions, data packets of in-vehicle network communication, and operation records of external access interfaces; The data processing unit (6) is used to pre-process the real-time operation data, wherein the pre-processing includes data cleaning, format standardization, and time stamp calibration to generate a standard data stream that meets the input requirements of the threat modeling module (2).

3. The IoV threat modeling and dynamic protection system based on the ATT&CK attack library according to claim 1 is characterized in that: The threat modeling module (2) specifically includes: Attack path generation unit (7), used to: generate possible attack paths based on the tactics and technical descriptions in the ATT&CK attack library and the architectural characteristics of the current Internet of Vehicles system; Attack means matching unit (8), used to: compare the collected security data with the technical features in the ATT&CK attack library to identify the existing attack means in the current environment; The target area marking unit (9) is used to mark target areas that may be threatened according to the identified attack means, wherein the target areas include the vehicle-mounted electronic control unit, the vehicle-mounted communication network and the cloud service platform.

4. The IoV threat modeling and dynamic protection system based on the ATT&CK attack library according to claim 1 is characterized in that: The dynamic protection module (3) further includes an anomaly detection unit (10), and the anomaly detection unit (10) specifically includes: The behavior pattern analysis subunit (11) is used to: analyze the historical operation data of the target area and extract characteristic parameters of the normal behavior pattern; The abnormality determination subunit (12) is used to compare the real-time operation data with the characteristic parameters of the normal behavior pattern, and determine it as abnormal behavior when the deviation exceeds a preset threshold; The anomaly detection unit (10) is further used to classify abnormal behaviors through a machine learning algorithm, wherein the classification results include malicious attack behaviors, misoperation behaviors, and environmental interference behaviors; and the classification results are used to guide the dynamic protection module (3) to select a corresponding protection strategy.

5. The IoV threat modeling and dynamic protection system based on the ATT&CK attack library according to claim 1 is characterized in that: The linkage response module (4) specifically includes: A priority evaluation unit (13) is used to calculate the execution priority of each protection strategy according to the impact range of the attack path, the complexity of the attack means and the importance of the target area; A policy scheduling unit (14) is used to: execute the protection policies in order of priority, and release resources for use by low-priority policies after the high-priority policies are executed; The feedback adjustment unit (15) is used to monitor the state change of the target area in real time during the execution of the protection strategy, and adjust the execution parameters of the protection strategy if the state does not achieve the expected effect.

6. The Internet of Vehicles threat modeling and dynamic protection system based on the ATT&CK attack library according to claim 1 is characterized in that: The dynamic protection module (3) further includes a recovery unit (16), and the recovery unit (16) specifically includes: A status recording subunit (17) is used to: record the initial status of the target area before the protection strategy is executed, wherein the initial status includes hardware configuration, software version and network connection status; The recovery execution subunit (18) is used to: after the protection strategy is executed, if the function of the target area still cannot be restored to normal, perform a rollback operation based on the initial state; The verification subunit (19) is used to: after the rollback operation is completed, comprehensively verify the functions of the target area, wherein the verification results include functional integrity, performance stability and security.

7. The IoV threat modeling and dynamic protection system based on the ATT&CK attack library according to claim 1 is characterized in that: The threat modeling module (2) and the dynamic protection module (3) are connected via a bidirectional communication link, and the bidirectional communication link uses the AES-256 encryption algorithm and the TLS 1.3 protocol to ensure the confidentiality and integrity of data during transmission.

8. The IoV threat modeling and dynamic protection system based on the ATT&CK attack library according to claim 1 is characterized in that: When the dynamic protection module (3) records detailed information of the attack behavior, the detailed information includes the triggering time of key nodes in the attack path, the technical characteristics of the attack means, and the specific identification of the affected target area.