Internet of vehicles intrusion behavior detection and defense method, device, equipment and medium

Through a hierarchical design of the Internet of Vehicles intrusion behavior detection method, the matching order of the rule base and the baseline library is utilized to quickly filter out known attacks and cover unknown attacks, solving the adaptability and real-time problems of Internet of Vehicles intrusion behavior detection and achieving efficient intrusion behavior detection.

CN120751389APending Publication Date: 2025-10-03ICLOUDSHIELD SECURITY TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510878903.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

The vehicle network intrusion behavior detection method cannot adapt to the ever-changing and evolving intrusion methods, and the detection real-time performance is low, which cannot meet the safety requirements of the AEB automatic emergency braking system.

Method used

A layered intrusion behavior detection method is adopted, and a pre-configured defense rule engine and baseline library are used to detect key vehicle information. This includes the matching order of the rule library and the baseline library, and the setting of the dynamic baseline library and the behavior baseline library. This allows for rapid filtering of known attacks and coverage of unknown attacks, improving detection efficiency and real-time performance.

Benefits of technology

It improves the detection efficiency and real-time performance of vehicle network intrusion behavior detection, reduces the false alarm rate, and can balance the real-time performance, accuracy and resource consumption of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120751389A_ABST
    Figure CN120751389A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of Internet of Vehicles, in particular to an Internet of Vehicles intrusion behavior detection and defense method and device, equipment and a medium. The method comprises the steps of obtaining to-be-detected key information of a target vehicle, wherein the to-be-detected key information comprises vehicle working condition data, environment sensing data, network communication data and an operation log; intrusion behavior detection is performed on the to-be-detected key information based on a matching sequence of a rule library and a baseline library included in a pre-configured defense rule engine, and corresponding processing is performed according to a detection result, and the baseline library comprises a dynamic baseline library and a behavior baseline library. The problems that Internet of Vehicles intrusion behavior detection cannot adapt to constantly changing intrusion means and the detection real-time performance is low are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of vehicle networking technology, and in particular to a vehicle networking intrusion behavior detection and defense method, device, equipment and medium. Background Art

[0002] With the rapid development of intelligent connected vehicles (ICVs), IoV attacks are becoming increasingly frequent. Consequently, IoV intrusion detection is becoming increasingly important. Current IoV intrusion detection methods typically rely on rules, feature engineering, and statistical methods. These methods rely on predefined rules and features, making them incapable of fully adapting to the ever-changing and evolving nature of intrusion methods. Furthermore, current IoV intrusion detection methods primarily employ a three-tiered architecture: on-board terminal, TSP platform, and cloud. These terminals only provide basic firewall functionality, and complex behavior analysis must be uploaded to the cloud. This approach fails to meet the rapid response security requirements of AEB systems, resulting in low real-time IoV intrusion detection. Summary of the Invention

[0003] In view of this, one of the technical problems solved by the embodiments of the present application is to provide a method, device, equipment and medium for detecting and defending intrusion behavior in the Internet of Vehicles, which solves the problem that intrusion behavior detection in the Internet of Vehicles cannot adapt to the ever-changing and evolving intrusion methods and the problem that the detection real-time performance is low.

[0004] According to a first aspect of an embodiment of the present application, a method for detecting and preventing intrusion in an Internet of Vehicles (IoV) is provided, the method comprising:

[0005] Obtain key information to be detected of the target vehicle, including vehicle operating condition data, environmental perception data, network communication data, and operation logs;

[0006] Based on the matching order of the rule library and baseline library included in the pre-configured defense rule engine, intrusion behavior detection is performed on the key information to be detected and corresponding processing is performed according to the detection results. Among them, the baseline library includes a dynamic baseline library for evaluating the degree to which the target vehicle deviates from the normal operating state of the group during driving, and a behavioral baseline library for evaluating the degree to which the target vehicle deviates from its own normal operating state.

[0007] In a second aspect of an embodiment of the present application, a vehicle network intrusion detection and prevention device is disclosed, the device comprising:

[0008] The vehicle test data acquisition module is used to obtain the key information to be tested of the target vehicle, including vehicle operating condition data, environmental perception data, network communication data and operation logs;

[0009] The intrusion behavior detection and defense module is used to perform intrusion behavior detection on key information to be detected based on the matching order of the rule library and baseline library included in the pre-configured defense rule engine, and perform corresponding processing according to the detection results. Among them, the baseline library includes a dynamic baseline library for evaluating the degree to which the target vehicle deviates from the normal operating state of the group during driving, and a behavioral baseline library for evaluating the degree to which the target vehicle deviates from its own normal operating state.

[0010] In a third aspect of an embodiment of the present application, an electronic device is disclosed. The electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above method are implemented.

[0011] In a fourth aspect of the embodiments of the present application, a computer-readable storage medium is disclosed, which stores a computer program. When the computer program is executed by a processor, the steps of the above method are implemented.

[0012] The embodiment of the present application obtains key information to be detected of the target vehicle, which includes vehicle operating condition data, environmental perception data, network communication data and operation logs, and thereby detects its intrusion behavior by utilizing the matching order of the rule base and baseline library included in the defense rule engine. This method of pre-setting the matching order for the rule base and baseline library locally implements a layered design for vehicle intrusion behavior detection, plays a role in quickly filtering attacks by utilizing the attack rule base of known intrusion behaviors, and improving detection efficiency. The design of the baseline library can cover the scope of intrusion behavior detection to unknown attacks as well as vehicle groups and individual vehicles, solving the problem that the vehicle network intrusion behavior detection cannot adapt to the ever-changing and evolving intrusion means and the low real-time detection, plays a role in reducing the false alarm rate of intrusion behavior detection, and enables the vehicle network intrusion behavior detection and defense to balance real-time, accuracy and resource consumption. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0014] Figure 1 A flowchart of a method for detecting and preventing intrusion in an Internet of Vehicles (IoV) according to one embodiment of the present application is provided;

[0015] Figure 2 A schematic diagram of an embodiment of vehicle network data interaction in a vehicle network intrusion behavior detection and prevention method provided by an embodiment of the present application;

[0016] Figure 3 A schematic diagram of the structure of a vehicle network intrusion behavior detection and prevention device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0017] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0018] It should be noted that although the functional modules are divided in the device schematic and the logical order is shown in the flowchart, in some cases, the steps shown or described can be performed in a different order than the module division in the device or the order in the flowchart.

[0019] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0020] According to an embodiment of the present application, a method for detecting and preventing intrusion behavior in an Internet of Vehicles is provided, such as Figure 1 As shown, the method includes step S101 and step S102.

[0021] Step S101: Acquire key information to be detected of the target vehicle, which includes vehicle operating condition data, environmental perception data, network communication data and operation log.

[0022] Specifically, the vehicle uses the CAN bus to obtain key information to be detected. This includes vehicle operating and real-time data, including real-time parameters such as vehicle speed, braking status, engine speed, and steering wheel angle; and environmental perception data, including weather, traffic flow, and road conditions (such as road wetness, road type, curve curvature, and slope).

[0023] Step S102: Based on the matching order of the rule library and baseline library included in the pre-configured defense rule engine, intrusion behavior detection is performed on the key information to be detected and corresponding processing is performed according to the detection results, wherein the baseline library includes a dynamic baseline library for evaluating the degree to which the target vehicle deviates from the normal operating state of the group during driving, and a behavioral baseline library for evaluating the degree to which the target vehicle deviates from its own normal operating state.

[0024] Specifically, the matching order between the rule base and baseline base in the defense rule engine can be configured based on business needs. During application, the matching order between the rule base and baseline base can be the same or different. For example, during real-time detection of a target vehicle, after detecting key information to be detected, it is matched against both the rule base and the baseline base. Alternatively, after detecting key information to be detected, it is matched against the rule base and, if no match is found in the rule base, the baseline base is matched.

[0025] Specifically, any baseline included in the baseline library is used to characterize the evaluation rules for evaluating whether a vehicle has intrusion behavior, including thresholds and logical judgments, such as exceeding the threshold three times of charging indicates an abnormality.

[0026] Specifically, the dynamic baseline library and the behavioral baseline library can be derived from the Internet of Vehicles cloud platform, that is, the target vehicle can use the Internet of Vehicles cloud platform to generate a behavioral baseline for the individual vehicle, which can reduce the computing overhead on the vehicle side; or the behavioral baseline library can use the pre-deployed roadside unit RUS for analysis to obtain a behavioral baseline library for the target vehicle individual.

[0027] The embodiment of the present application obtains key information to be detected of the target vehicle, which includes vehicle operating condition data, environmental perception data, network communication data and operation logs, and thereby detects its intrusion behavior by utilizing the matching order of the rule base and baseline library included in the defense rule engine. This method of pre-setting the matching order for the rule base and baseline library locally implements a layered design for vehicle intrusion behavior detection, plays a role in quickly filtering attacks by utilizing the attack rule base of known intrusion behaviors, and improving detection efficiency. The design of the baseline library can cover the scope of intrusion behavior detection to unknown attacks as well as vehicle groups and individual vehicles, solving the problem that the vehicle network intrusion behavior detection cannot adapt to the ever-changing and evolving intrusion means and the low real-time detection, plays a role in reducing the false alarm rate of intrusion behavior detection, and enables the vehicle network intrusion behavior detection and defense to balance real-time, accuracy and resource consumption.

[0028] In some embodiments, step S102 further includes:

[0029] Step S1021 (not shown in the figure): matching the key information to be detected with the rule base;

[0030] Step S1022 (not shown in the figure): If the key information to be detected does not hit the rule library, the priority of the dynamic baseline library and the behavioral baseline library is determined, and the dynamic baseline library and the behavioral baseline library are used according to the priority to perform intrusion behavior detection on the key information to be detected and perform corresponding processing based on the detection results.

[0031] Specifically, the rule base includes rules corresponding to various attacks. Each rule can include a regular expression and its corresponding logic. These rules are used to determine whether a target vehicle is attacked. For example, suppose the regular expression corresponding to a CAN flooding attack is a frequency threshold and an ID conflict, and the logic is to trigger simultaneously. That is, if the information to be detected meets both the frequency threshold and the ID conflict, the rule base is hit, and the target vehicle is under attack.

[0032] To speed up rule base filtering during application, the key information to be detected can be identified by matching inputs based on the data types corresponding to the various attack rules included in the rule base. For example, only network communication data and operation logs can be used as inputs for matching within the rule base. Because the rule base contains known attacks and generally relies on ECU operation logs and network communication data, attack detection can be completed without the need for vehicle operating data or environmental perception data, reducing the amount of data required for attack detection and thereby improving detection speed.

[0033] Specifically, the dynamic baseline library and the behavioral baseline library can be matched in any order, setting the IoV defense engine to a two-level system. First, the rule library for known attacks is used to quickly filter whether the vehicle is vulnerable to attacks, enabling rapid interception of known attacks. Then, a baseline comparison is performed when no known attacks are detected on the vehicle, achieving a secondary level of defense for IoV intrusion behavior detection. This prevents missed detections due to new attacks not being promptly included in the rule library. Specifically, the dynamic baseline library and the behavioral baseline library can also be matched in any order, setting the IoV defense engine to a three-level system.

[0034] In some embodiments, step S1021 further includes: if the priority of the dynamic baseline library and the behavioral baseline library is the same, the key information to be detected is matched with the dynamic baseline library and the behavioral baseline library respectively, and corresponding processing is performed based on the matching results; if the priority of the dynamic baseline library is greater than the priority of the behavioral baseline library, the key information to be detected is matched with the dynamic baseline library, and if the key information to be detected does not hit the dynamic baseline library, it is matched with the behavioral baseline library, and corresponding processing is performed based on the matching results.

[0035] This application controls the matching level of the defense rule engine by setting the matching order of the dynamic baseline library and the behavioral baseline library. In the embodiment of this application, the default setting is that the matching order of the dynamic baseline library is greater than the matching order of the behavioral baseline library.

[0036] In some embodiments, the dynamic baseline library includes a first dynamic baseline for determining whether the target vehicle group is in a normal group operation state and a plurality of second dynamic baselines for determining the degree of deviation of the target vehicle from the normal group operation state. The behavioral baseline library includes a first behavioral baseline for determining whether the target vehicle is in its own normal operation state and a plurality of second behavioral baselines for determining the degree of deviation of the target vehicle from its own normal operation state. Executing corresponding processing steps based on the matching results further includes: when the key information to be detected hits any second dynamic baseline, executing corresponding processing based on the degree of deviation of any second dynamic baseline; when the key information to be detected hits any second behavioral baseline, executing corresponding processing based on the degree of deviation of any second behavioral baseline. Specifically, different degrees of deviation are handled differently. For example, a slight degree of deviation can be processed as an alarm; severe deviation can be processed as an instruction to switch to block abnormality, switch to a backup control module, and so on.

[0037] In the embodiment of the present application, the priority of the dynamic baseline library is set to be greater than the priority of the behavioral baseline library, that is, after the rule library is used to quickly filter whether the vehicle has known attacks, it is evaluated whether the vehicle deviates from the normal behavior pattern of the group, and if not, it is evaluated whether the vehicle deviates from the normal behavior pattern of the individual vehicle, thereby realizing three-level defense of expert instructions, group and individual vehicles, and being able to perform different processing according to the degree of deviation of the vehicle.

[0038] In the embodiment of this application, the dynamic baseline library is derived from the Internet of Vehicles cloud platform. Figure 2As shown in the figure, the Internet of Vehicles cloud platform obtains a variety of data reported by several vehicles, including various data in normal operation and attack situations, including vehicle operating data (vehicle speed, brake status, engine speed, steering wheel angle, etc.), environmental perception data (road status, weather conditions, traffic flow, etc.), network communication data and operation logs. After receiving this data, the Internet of Vehicles cloud platform inputs it into the preset LSTM model for training, learns the normal behavior pattern of the vehicle, obtains the multi-dimensional dynamic threshold, and encapsulates it according to the multi-dimensional dynamic threshold and the corresponding logic to obtain the corresponding dynamic baseline and send it to the vehicle end. Specifically, the Internet of Vehicles cloud platform can also input data of the same vehicle model into the preset LSTM model for training, such as inputting data belonging to the same vehicle model A, the same vehicle model B, or the same vehicle model C into the preset LSTM model for training to obtain a multi-dimensional dynamic threshold, and encapsulate it according to the multi-dimensional dynamic threshold and the corresponding logic to obtain the corresponding dynamic baseline. At this time, the dynamic baseline is obtained according to the vehicle model, that is, a dynamic baseline for intrusion detection of vehicle model A, a dynamic baseline for intrusion detection of vehicle model B, and a dynamic baseline for intrusion detection of vehicle model C can be obtained. At this time, the Internet of Vehicles cloud platform stores the dynamic baselines of multiple vehicle models. In this way, when the vehicle side communicates with the Internet of Vehicles cloud platform, the corresponding dynamic baseline can be issued according to the vehicle model.

[0039] In some embodiments, the behavior baseline library is determined by:

[0040] Based on the historical vehicle operating condition data of the target vehicle in normal operating state, a first behavioral baseline of the target vehicle in normal operating state is determined; based on the historical key information to be detected when the vehicle state of the target vehicle is subject to intrusion attack, and based on the first behavioral baseline and the historical key information to be detected, multiple second behavioral baselines are determined for judging the degree of deviation of the target vehicle from its own normal operating state.

[0041] During application, the OBU deployed on the vehicle side can be used for analysis to obtain a behavioral baseline library for local vehicles. Specifically, the historical vehicle operating data of the target vehicle in normal operation under different scenarios can be obtained to analyze and obtain a first behavioral baseline to evaluate whether the target vehicle is in normal operation under different scenarios. For example, the historical vehicle operating data of the target vehicle in application scenarios such as autonomous driving, driving with an in-vehicle infotainment system, and driving on highways can be obtained to analyze the respective first behavioral baselines in these application scenarios. Alternatively, the first behavioral baselines under different application scenarios can be weighted and analyzed to obtain a comprehensive first behavioral baseline without paying attention to the application scenario. Specifically, the second behavioral baseline with different degrees of deviation under different attacks can be evaluated based on the first behavioral baseline.

[0042] In some embodiments, before the step of performing intrusion behavior detection on the key information to be detected based on the matching order of the rule library and baseline library included in the preconfigured defense rule engine and performing corresponding processing according to the detection results, it also includes: sending the vehicle-related information of the target vehicle to the Internet of Vehicles cloud platform; obtaining the dynamic baseline library and behavior baseline library issued by the Internet of Vehicles cloud platform based on the vehicle-related information.

[0043] Specifically, vehicle-related information can include the vehicle identification code (VIN), allowing the IoV cloud platform to identify the vehicle model based on the VIN and issue a dynamic baseline library corresponding to that model. This allows the use of dynamic baseline libraries for identical vehicles to improve the accuracy of IoV intrusion detection. Furthermore, the acquisition of the behavioral baseline library leverages the computing power of the IoV cloud platform to perform behavioral baseline analysis on individual vehicles, reducing computational overhead on the vehicle side.

[0044] In the above embodiment, the step of sending the target vehicle's vehicle-related information to the IoV cloud platform further includes: encrypting the vehicle-related information, signing it with a key pre-stored in the target vehicle's security domain, and then sending it to the IoV cloud platform. This embodiment of the application combines cryptographic calculations with the vehicle-side SIM card hardware security domain SE to protect communication between the vehicle and the IoV cloud platform, further enhancing the security of vehicle intrusion prevention.

[0045] An embodiment of the present application provides a vehicle network intrusion behavior detection and prevention device, such as Figure 3 As shown, the device 30 includes: a vehicle test data acquisition module 301 and an intrusion behavior detection and prevention module 302.

[0046] The vehicle test data acquisition module 301 is used to obtain the key information to be tested of the target vehicle, which includes vehicle operating condition data, environmental perception data, network communication data and operation log;

[0047] The intrusion behavior detection and defense module 302 is used to perform intrusion behavior detection on key information to be detected based on the matching order of the rule library and baseline library included in the preconfigured defense rule engine and perform corresponding processing according to the detection results, wherein the baseline library includes a dynamic baseline library for evaluating the degree to which the target vehicle deviates from the normal operating state of the group during driving, and a behavioral baseline library for evaluating the degree to which the target vehicle deviates from its own normal operating state.

[0048] The embodiment of the present application obtains key information to be detected of the target vehicle, which includes vehicle operating condition data, environmental perception data, network communication data and operation logs, and thereby detects its intrusion behavior by utilizing the matching order of the rule base and baseline library included in the defense rule engine. This method of pre-setting the matching order for the rule base and baseline library locally implements a layered design for vehicle intrusion behavior detection, plays a role in quickly filtering attacks by utilizing the attack rule base of known intrusion behaviors, and improving detection efficiency. The design of the baseline library can cover the scope of intrusion behavior detection to unknown attacks as well as vehicle groups and individual vehicles, solving the problem that the vehicle network intrusion behavior detection cannot adapt to the ever-changing and evolving intrusion means and the low real-time detection, plays a role in reducing the false alarm rate of intrusion behavior detection, and enables the vehicle network intrusion behavior detection and defense to balance real-time, accuracy and resource consumption.

[0049] Furthermore, the intrusion behavior detection and prevention module includes:

[0050] The rule base matching submodule is used to match the key information to be detected with the rule base;

[0051] The baseline library matching submodule is used to determine the priority of the dynamic baseline library and the behavioral baseline library if the key information to be detected does not hit the rule library, and use the dynamic baseline library and the behavioral baseline library to perform intrusion behavior detection on the key information to be detected according to the priority and perform corresponding processing according to the detection results.

[0052] Furthermore, the baseline library matching submodule includes:

[0053] The first-level baseline matching unit is used to match the key information to be detected with the dynamic baseline library and the behavioral baseline library respectively if the priority order of the dynamic baseline library and the behavioral baseline library is the same, and perform corresponding processing according to the matching results;

[0054] The second-level baseline matching unit is used to match the key information to be detected with the dynamic baseline library if the priority of the dynamic baseline library is greater than the priority of the behavioral baseline library, and to match it with the behavioral baseline library if the key information to be detected does not hit the dynamic baseline library, and perform corresponding processing based on the matching results.

[0055] Furthermore, the dynamic baseline library includes a first dynamic baseline for determining whether the target vehicle group is in a normal group operating state and multiple second dynamic baselines for determining the degree of deviation of the target vehicle from the normal group operating state. The behavioral baseline library includes a first behavioral baseline for determining whether the target vehicle is in its own normal operating state and multiple second behavioral baselines for determining the degree of deviation of the target vehicle from its own normal operating state. The baseline library matching submodule includes:

[0056] The first-level matching processing unit is configured to, when the key information to be detected hits any second dynamic baseline, perform corresponding processing according to the degree of deviation of any second dynamic baseline;

[0057] The second-level matching processing unit is configured to perform corresponding processing according to the degree of deviation of any second behavior baseline when the key information to be detected hits any second behavior baseline.

[0058] Furthermore, the behavior baseline library is determined as follows:

[0059] Determining a first behavior baseline of the target vehicle in a normal operating state based on historical vehicle operating condition data of the target vehicle in a normal operating state;

[0060] Based on the historical key information to be detected when the vehicle state of the target vehicle is attacked by an intrusion, and according to the first behavioral baseline and the historical key information to be detected, multiple second behavioral baselines are determined for judging the degree of deviation of the target vehicle from the normal operating state.

[0061] Furthermore, before the steps of performing intrusion behavior detection on the key information to be detected based on the matching order of the rule base and the baseline base included in the preconfigured defense rule engine and performing corresponding processing according to the detection results, the intrusion behavior detection and defense module further includes:

[0062] The cloud platform communication submodule is used to send the vehicle-related information of the target vehicle to the Internet of Vehicles cloud platform;

[0063] The baseline library acquisition submodule is used to obtain the dynamic baseline library and behavior baseline library issued by the Internet of Vehicles cloud platform based on vehicle-related information.

[0064] Furthermore, the cloud platform communication submodule is used to: encrypt the vehicle-related information, sign it with the key pre-stored in the target vehicle security domain, and then send it to the Internet of Vehicles cloud platform.

[0065] The vehicle network intrusion behavior detection and defense device of this embodiment can execute the vehicle network intrusion behavior detection and defense method shown in the embodiment of this application. Its implementation principle is similar and will not be repeated here.

[0066] Another embodiment of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above method when executing the computer program.

[0067] Specifically, a processor may be a CPU, a general-purpose processor, a DSP, an ASIC, an FPGA, or other programmable logic device, a transistor logic device, a hardware component, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. A processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.

[0068] Specifically, the processor is connected to the memory via a bus. The bus may include a path for transmitting information. The bus may be a PCI bus or an EISA bus. The bus may be divided into an address bus, a data bus, a control bus, etc.

[0069] The memory may be a ROM or other type of static storage device that can store static information and instructions, a RAM or other type of dynamic storage device that can store information and instructions, or an EEPROM, CD-ROM or other optical disk storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to these.

[0070] Optionally, the memory is used to store the code of the computer program that executes the solution of the present application, and the execution is controlled by the processor. The processor is used to execute the application program code stored in the memory to implement the actions of the device provided by the above embodiment.

[0071] Another embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions for executing the method provided in the above embodiment.

[0072] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.

[0073] Those skilled in the art will appreciate that all or some of the steps and systems in the method disclosed above can be implemented as software, firmware, hardware, and appropriate combinations thereof. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, and the computer-readable medium can include computer storage media (or non-transitory media) and communication media (or temporary media). As known to those skilled in the art, the term computer storage media is included in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data) and is volatile and non-volatile, removable, and non-removable. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory, or other memory technology, CD-ROM, digital versatile disks (DVD), or other optical disk storage, magnetic cassettes, magnetic tapes, disk storage, or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, as is well known to those skilled in the art, communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0074] The above is a specific description of the preferred implementation of the present application, but the present application is not limited to the above implementation mode. Technical personnel familiar with the field can also make various equivalent modifications or substitutions without violating the spirit of the present application. These equivalent modifications or substitutions are all included in the scope defined by the claims of the present application.

Claims

1. A method for detecting and preventing intrusion in Internet of Vehicles, characterized in that: include: Obtain key information to be detected of the target vehicle, including vehicle operating condition data, environmental perception data, network communication data, and operation logs; Based on the matching order of the rule library and baseline library included in the preconfigured defense rule engine, intrusion behavior detection is performed on the key information to be detected and corresponding processing is performed according to the detection results, wherein the baseline library includes a dynamic baseline library for evaluating the degree to which the target vehicle deviates from the normal operating state of the group during driving, and a behavioral baseline library for evaluating the degree to which the target vehicle deviates from its own normal operating state.

2. The method according to claim 1, characterized in that The intrusion behavior detection is performed on the key information to be detected based on the matching order of the rule library and the baseline library included in the pre-configured defense rule engine and corresponding processing is performed according to the detection result, including: Matching the key information to be detected with the rule base; If the key information to be detected does not hit the rule library, the priority of the dynamic baseline library and the behavioral baseline library is determined, and the dynamic baseline library and the behavioral baseline library are used according to the priority to perform intrusion behavior detection on the key information to be detected and perform corresponding processing according to the detection results.

3. The method according to claim 2, characterized in that The performing intrusion behavior detection on the key information to be detected by using the dynamic baseline library and the behavioral baseline library according to the priority order and performing corresponding processing according to the detection results includes: If the priority order of the dynamic baseline library and the behavioral baseline library is the same, the key information to be detected is matched with the dynamic baseline library and the behavioral baseline library respectively, and corresponding processing is performed according to the matching results; If the priority of the dynamic baseline library is greater than the priority of the behavioral baseline library, the key information to be detected is matched with the dynamic baseline library, and if the key information to be detected does not hit the dynamic baseline library, it is matched with the behavioral baseline library, and corresponding processing is performed based on the matching result.

4. The method according to claim 2, characterized in that The dynamic baseline library includes a first dynamic baseline for determining whether a target vehicle is in a normal operating state of a group and a plurality of second dynamic baselines for determining the degree of deviation of the target vehicle from the normal operating state of the group; the behavioral baseline library includes a first behavioral baseline for determining whether the target vehicle is in its own normal operating state and a plurality of second behavioral baselines for determining the degree of deviation of the target vehicle from its own normal operating state; and performing intrusion behavior detection on the key information to be detected using the dynamic baseline library and the behavioral baseline library in accordance with the priority order and performing corresponding processing according to the detection results, including: When the key information to be detected hits any of the second dynamic baselines, performing corresponding processing according to the degree of deviation of any of the second dynamic baselines; In the case where the key information to be detected hits any second behavior baseline, corresponding processing is performed according to the degree of deviation of any second behavior from the baseline.

5. The method according to claim 4, characterized in that The behavior baseline library is determined as follows: Determining a first behavior baseline of the target vehicle in a normal operating state based on historical vehicle operating condition data of the target vehicle in a normal operating state; Based on the historical key information to be detected when the vehicle status of the target vehicle is attacked by an intrusion, and according to the first behavioral baseline and the historical key information to be detected, multiple second behavioral baselines are determined to judge the degree of deviation of the target vehicle from its own normal operating state.

6. The method according to claim 4, characterized in that Before the step of performing intrusion behavior detection on the key information to be detected based on the matching order of the rule library and the baseline library included in the preconfigured defense rule engine and performing corresponding processing according to the detection result, the method further includes: Sending the vehicle-related information of the target vehicle to the Internet of Vehicles cloud platform; Obtain the dynamic baseline library and the behavioral baseline library issued by the Internet of Vehicles cloud platform based on the vehicle-related information.

7. The method according to claim 6, characterized in that The sending of the vehicle-related information of the target vehicle to the Internet of Vehicles cloud platform includes: After the vehicle-related information is encrypted, it is signed using the key pre-stored in the target vehicle security domain and then sent to the Internet of Vehicles cloud platform.

8. A vehicle network intrusion behavior detection and defense device, characterized in that: include: The vehicle test data acquisition module is used to obtain the key information to be tested of the target vehicle, which includes vehicle operating condition data, environmental perception data, network communication data and operation log; The intrusion behavior detection and defense module is used to perform intrusion behavior detection on the key information to be detected based on the matching order of the rule library and baseline library included in the preconfigured defense rule engine and perform corresponding processing according to the detection results. Among them, the baseline library includes a dynamic baseline library and a behavioral baseline library. The dynamic baseline library is used to evaluate the degree to which the target vehicle deviates from the normal operating state of the group during driving, and the behavioral baseline library is used to evaluate the degree to which the target vehicle deviates from its own normal operating state.

9. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores computer-readable instructions, and the processor is configured to execute the computer-readable instructions, wherein the computer-readable instructions execute the method according to any one of claims 1 to 7 when executed.

10. A computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Vehicle anomaly detection, reporting, and dynamic response

    CN115339464A

  • A multi-element detection method and system for intelligent connected vehicles based on cloud platform

    CN119788410A

  • Intrusion detection method and device of vehicle-mounted network, computer equipment and storage medium

    CN119835067A

Cited By

  • Highway toll collection system data processing method and system based on cloud architecture

    CN121239507A