Automatic threat assessment method for intelligent network connection system
By constructing an automated threat assessment method for intelligent connected systems, the security assessment problem of intelligent connected systems is solved, enabling comprehensive security assessment and threat identification of intelligent connected systems, thereby improving the system's security and responsiveness.
Patent Information
- Application Number
- CN202511186009.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-22
- Publication Date
- 2025-11-18
AI Technical Summary
Existing technologies and methods are insufficient to effectively and dynamically perceive and quickly respond to intelligent means of security threat assessment in intelligent networks. Existing technologies are also insufficient to meet the needs of intelligent threat assessment and adapt to the highly dynamic and diverse security challenges of threats in the ICS environment.
This paper focuses on the construction of security technology for intelligent connected systems, particularly automated threat assessment methods for intelligent gateway systems. Specifically, it describes an automated threat assessment method for intelligent connected systems. This method involves constructing a security assessment mechanism for intelligent gateways, using a security information input module, and generating a visual assessment method for logical attack graphs through multi-stage attack paths. This enables the security assessment of intelligent connected systems.
It enables automated threat assessment of intelligent connected systems, provides comprehensive assessment results, helps identify and respond to potential threats, and improves system security and responsiveness.
Smart Images

Figure CN120979746A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of intelligent network contact system security, and particularly relates to an intelligent network contact system automatic threat evaluation method. BACKGROUND
[0002] With the continuous development of information technology, communication technology and intelligent control technology, intelligent connected systems (ICS) have been widely applied in intelligent transportation, industrial control, smart city, Internet of Vehicles and other fields. ICS realizes real-time interaction, data sharing and automatic control between systems by organically integrating sensing devices, communication networks, data processing platforms and intelligent decision systems, significantly improving operation efficiency and service level. However, the openness and high interconnectivity of ICS also bring unprecedented security risks. Due to the large number of various terminal devices, complex communication protocols and blurred network boundaries, attackers can easily initiate intrusion by exploiting system vulnerabilities, weak identity verification or malicious code, thereby posing a serious threat to the integrity, availability and confidentiality of the system. Therefore, although ICS has great technical advantages, it also faces increasingly severe security challenges.
[0003] ICS ecosystems usually cover multiple levels and components, including the sensing layer (sensors, cameras, etc.), the network layer (wired / wireless communication), the platform layer (edge / cloud computing platform), the application layer (control and management system), etc. These components are tightly coupled through various communication protocols and data interfaces. The system is highly heterogeneous, frequently updated, and has many participants (such as manufacturers, operators, users), making it difficult to clearly define the boundaries of security management. Attackers can start from any weak link and penetrate layer by layer, eventually controlling critical resources or disrupting system operation. For example, in the Internet of Vehicles scenario, attackers can invade the vehicle-mounted system through the wireless interface, causing automatic driving failure or traffic paralysis and other serious consequences. In addition, the real-time requirements in ICS also pose higher performance demands on security protection mechanisms, making it difficult for traditional static defense methods to meet the current threat situation. Therefore, it is an urgent need to build a security system that can dynamically perceive threats, respond quickly and perform risk assessment.
[0004] At present, there are still many deficiencies in the security threat assessment method for ICS. The traditional method depends on static rules, attack feature library or expert experience, lacks the perception ability of system dynamic change, and is difficult to adapt to the highly dynamic and diversified threat behavior in the ICS environment. Although some risk matrix-based models can present potential attack paths from the structure, there are problems such as complex construction, analysis lag, inaccurate evaluation and so on in actual application, which is difficult to meet the actual needs of ICS for efficient evaluation and rapid response. Therefore, a new type of threat assessment method is needed, which can automatically evaluate threats and provide more comprehensive evaluation results. SUMMARY
[0005] In view of the defects in the prior art, the application provides an intelligent network system automatic threat assessment method, which can reason multi-stage attack paths, calculate the feasibility and impact of each attack target, evaluate the overall risk of the attack path, and prioritize the attack path according to the risk value, providing comprehensive results for threat analysis and evaluation.
[0006] To achieve the above technical purpose, the application adopts the following technical solutions.
[0007] An intelligent network system automatic threat assessment method, specifically comprising the following steps:
[0008] Step (1) constructs a security information input module, which constructs a general security ontology model of the intelligent network system from two dimensions of physical entities and security elements, and constructs security information using the ontology model;
[0009] Step (2) constructs an attack path reasoning module, which uses the MulVAL framework to reason based on the input security information and the pre-designed reasoning rules, and generates a logical attack graph after attack graph decomposition and attack graph optimization;
[0010] Step (3) constructs a quantitative risk assessment module, which first disassembles the attack paths in the logical attack graph, generates a Bayesian attack graph by calculating the reachable probability and risk value of each attack path, and finally visualizes the Bayesian attack graph.
[0011] As a preferred embodiment, in step (1), the security ontology model comprehensively covers core elements such as intelligent network system, components, attributes, vulnerabilities and attack vectors.
[0012] As a preferred embodiment, on the basis of step (1), the security information input module further uses Datalog statements to represent attack targets, attack entrances, vulnerability sets and system configurations, and provides these structured data as input to the attack path reasoning module.
[0013] As a preferred embodiment, in the step (2), by parsing the XML file of the logical attack graph, the nodes and edges in the logical attack graph are associated to reveal the mutual relationship between each component in the attack path.
[0014] As a preferred embodiment, in the step (2), finally, the generated logical attack graph is optimized to eliminate the loops therein.
[0015] As a preferred embodiment, in the step (3), the risk of each attack path is quantitatively evaluated by means of the Common Vulnerability Scoring System (CVSS) to calculate the corresponding risk value.
[0016] As a preferred embodiment, in the step (3), the generated Bayesian attack graph is visualized by means of the Graphviz tool.
[0017] Beneficial effects:
[0018] (1) The present application proposes a general security ontology model of an intelligent network system, which refines the security elements therein to capture the complex dependency relationship between the ICS network system and physical entities, and provides a unified and standardized way for expressing system network security and protection knowledge.
[0019] (2) The present application proposes an automatic threat assessment method, which can reason about multi-stage attack paths, calculate the feasibility and impact of each attack target, assess the overall risk of the attack path, and prioritize the attack path according to the risk value, providing a comprehensive result for threat analysis and assessment.
[0020] (3) The Bayesian attack graph generated by the present application can clearly show the logical relationship, feasibility, impact and risk value of the nodes in the attack path, facilitating the understanding and analysis of security personnel.
[0021] (4) The present application is applied on a real open test vehicle to perform threat analysis and assessment on the Autonomous Driving Control Unit (ADCU) of the target vehicle, ensuring practicality. BRIEF DESCRIPTION OF DRAWINGS
[0022] Figure 1 The method flowchart of the present application;
[0023] Figure 2 The frame structure schematic diagram of the present application;
[0024] Figure 3 The general security ontology model diagram of the present application;
[0025] Figure 4A security element classification model diagram of the present application;
[0026] Figure 5 An execution process diagram of example one;
[0027] Figure 6 An overall logic attack diagram of example one;
[0028] Figure 7 A Bayesian attack diagram of example one;
[0029] Figure 8 An open experimental vehicle IVN topology diagram of example two;
[0030] Figure 9 A scenario one Bayesian attack diagram of example two;
[0031] Figure 10 A scenario two Bayesian attack diagram of example two. DETAILED DESCRIPTION
[0032] In order for those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.
[0033] The present application provides an intelligent network system automatic threat assessment method, as shown in the accompanying Figure 1 、 2 , the automatic threat assessment method is divided into a security information input module, an attack path reasoning module and a quantitative risk assessment module, and the method comprises the following steps:
[0034] S1, the security information input module constructs the attack target, the attack entry, the vulnerability set and the system configuration represented by the Datalog statement based on the ontology model, and takes them as the input of the attack path reasoning module.
[0035] 1, security ontology model construction:
[0036] As a formal semantic framework, the ontology model realizes the systematic representation of domain knowledge by defining entities, attributes, categories and their logical correlation. As shown in the accompanying Figure 3 , the intelligent network system general security ontology model constructed by the present application builds a comprehensive knowledge system from two dimensions of physical entities and security elements, covering core elements such as intelligent network system, components, attributes, vulnerabilities and attack vectors.
[0037] The constructed intelligent network contact system general security ontology model can form a connection between ICS physical entities and potential threats, and help to construct a security information (including attack targets, attack entrances, vulnerability characteristics and reasoning rules) in an automatic threat assessment method. Figure 4 .
[0038] 2. The input of the reasoning engine:
[0039] The input of the attack path reasoning in the application includes attack targets, attack entrances, vulnerability sets and system configurations, which are represented by Datalog, and the specific description is as follows:
[0040] (1) Attack target: This input specifies the specific target of logical reasoning, and describes the specific attack in ICS. For example, the following statement represents an attack target of hijacking control instructions through the Message Queuing Telemetry Transport (MQTT) of the edge computing node. The attack involves an attacker forging a legitimate publisher and sending malicious control commands through the MQTT channel, thereby interfering with the execution logic of the edge computing node or misleading downstream terminal devices:
[0041] attackGoal(attackerPublishMQTTFrom(edgeNode, mqttBroker)).
[0042] It is derived from a set of original nodes, including attack entrances, edge node information and possible vulnerabilities. In the attack path, such nodes are called attack nodes.
[0043] (2) Attack entrance: This input describes how the attacker obtains access to the critical components in the intelligent network contact system, which is also the starting point of the attack path. For example, the following statement assumes that the attacker can access the edge computing node through an Ethernet port or a public network interface:
[0044]
[0045] After obtaining access, the attacker can further detect the communication path, obtain system state information or inject malicious data, laying the foundation for the subsequent attack stage. In the attack path, such nodes are called entrance nodes.
[0046] (3) Vulnerability Set: This input consists of vulnerabilities that can lead to certain attacks. For example, the following statements describe the existence of Remote Code Execution (RCE), Authentication Bypass, and Insecure API Usage vulnerabilities in the edge computing node and Cloud Platform, which will serve as prerequisites for the attack nodes:
[0047]
[0048] Once these vulnerabilities are exploited, attackers can bypass access controls, execute malicious commands, or tamper with system data, forming a complete attack chain. In the attack path, such nodes are referred to as vulnerability nodes.
[0049] (4) System Configuration: This input includes intelligent network system-specific information required for attack path reasoning. Specifically, this information includes the connection topology between system components and the attributes of communication links. For example, the following statements indicate that the edge computing node and the Telematics Unit (TCU) are interconnected through an Ethernet link (ethernetLink), and this communication link has the property of being able to be monitored, which may lead to threats such as man-in-the-middle attacks:
[0050] This configuration is used to reason whether an attacker can monitor data or inject malicious instructions in this link, assisting in identifying high-risk paths. In the attack path, such information is referred to as fact nodes.
[0051] S2, Attack Path Reasoning Module: Based on the input security information and the designed reasoning rules, the MulVAL framework reasoning, attack graph reconstruction, and attack graph optimization are performed to generate a logical attack graph.
[0052] 1. Attack graph generation:
[0053] Attack graph theory aims to visualize complex attack paths to help security analysts effectively identify potential threats. In the process of constructing attack graphs, rules and deductions are the core elements. The process of generating attack graphs is similar to mathematical deduction problems, covering three key parts: initial conditions, rule systems, and goals. Among them, the initial conditions define the attack entry point through which the attacker can enter the system; the rule system describes the actions that the attacker may take, the corresponding response mechanism of the system, and the way of exploiting vulnerabilities; the goal clearly defines the attack purpose that the attacker expects to achieve. Based on the initial conditions, the attacker uses the rule system to gradually advance by exploiting the vulnerabilities and weaknesses of the system, and finally achieves the attack goal. The deduction engine automatically conducts deduction work according to the established rule system, and then generates attack paths and constructs attack graphs.
[0054] The reasoning rule, as a formal description of a single-step attack, focuses on the common characteristics of attack behavior and the results produced, rather than focusing on specific implementation details. The construction of reasoning rules is mainly based on system architecture, vulnerability exploitation methods, attacker behavior patterns, and the mutual relationship between system components. As shown in the intelligent network system general security ontology model, the construction of reasoning rules lays a foundation for the construction of reasoning rules, which can effectively guarantee the accuracy and consistency of the deduction process. Figure 3
[0055] The attack path reasoning module starts Datalog reasoning after receiving the above input security information and reasoning rules to determine the feasible attack path from the attack entry point to the attack target. The effectiveness of this reasoning process depends on the well-designed reasoning rules. For example, the following rules define how to achieve a privilege escalation attack by exploiting the "remote code execution" vulnerability (CVE-2025-10321) in the edge computing node. The attacker initially only has user-level (user) code execution permissions, and when the system has this vulnerability, the attacker can remotely trigger the privilege escalation logic to obtain "Root" permissions, thereby completely controlling the edge computing node.
[0056]
[0057] The Datalog attack path reasoning of the present application is based on the MulVAL reasoning framework and the XSB database system, and the generated logical attack graph is stored in the form of an Extensible Markup Language (XML) file.
[0058] 2. Attack graph decomposition:
[0059] The XML file of the logical attack graph describes two basic entities in the graph: nodes and edges. These entities, through their attributes and mutual relationships, jointly build the structure and logic of the attack graph. Each node contains four core attributes: number, content, state, and type. The number is used to uniquely identify the node, the content describes the specific information or behavior of the node, the state represents the current condition or numerical parameter of the node, and the type indicates the logical function of the node, including:
[0060] (1) AND type node: represents the "and" condition in the attack path, and the attack will continue only when all related conditions are met.
[0061] (2) OR type node: represents an "or" condition, and the attack path can continue as long as any one of the conditions is met.
[0062] (3) LEAF type node: represents an attack entry or factual description (such as system configuration, vulnerability information, etc.), which is the starting point or precondition of the attack path.
[0063] Each edge connects two nodes and has two attributes: start number and end number, which define the directional relationship between nodes. These attributes of edges and nodes are stored through the XML file format, providing structured data support for subsequent reasoning and analysis.
[0064] The predecessor and successor relationship between nodes, as well as the directionality of edges (such as the order of attack path progression), jointly constitute the foundation of attack graph construction. By parsing the XML description file, the association between nodes and edges in the graph can be achieved, revealing the mutual relationship between the components in the attack path. In the attack graph, each node is connected to its adjacent nodes through edges, forming a logical path from the attack entry to the attack target.
[0065] In addition, according to the specific content of the node, the node can be classified, such as dividing into attack nodes, vulnerability nodes, etc. For vulnerability nodes, the exploitability and impact degree need to be calculated according to the CVSS v3.1 index, so as to convert the logical attack graph into an attribute attack graph, in order to more deeply assess the potential risks contained in the attack path.
[0066] 3. Attack graph optimization:
[0067] During attack graph derivation, attack loop problems often occur, which are caused by attackers repeatedly using vulnerabilities or resources. Although they have no substantive meaning, they increase the complexity of the attack graph, making the graph difficult to interpret, reducing computational efficiency, and affecting the accuracy of threat assessment. Therefore, eliminating loops is the key to optimizing attack graphs.
[0068] The core of loop elimination is to delete the loop that has little effect on attack graph evaluation. The ideal method is to minimize the changes to the overall structure to ensure that effective information is provided for security analysis. Since the atomic attack node of the deepest path in the attack graph needs to complete all the pre-attack to execute, the probability of occurrence is low, and removing these nodes can effectively eliminate loops and have the least impact on network security risk assessment.
[0069] The application adopts a deepest atomic attack loop elimination algorithm based on depth first search (DFS). First, a stack structure is used for DFS, and the attack path is traversed from the attacker node. If a loop is found during the DFS process, the node with the highest attack difficulty or the lowest probability of occurrence in the path is identified and deleted. By removing the path nodes that are least likely to be used by the attacker, the impact on the overall structure of the attack graph is minimized. Finally, all loops are eliminated, and a loop-free logical attack graph is obtained.
[0070] Loop elimination in attack graph can simplify the graph structure and is closely related to subsequent Bayesian network analysis. Bayesian network presents node conditional dependence in directed acyclic graph and is used for inference calculation. However, loops can cause circular dependencies and disrupt inference logic, resulting in inaccurate results. An acyclic graph ensures that each node is conditionally independent given its parent nodes, allowing Bayesian network to accurately capture conditional independence and improve risk assessment accuracy.
[0071] S3, the quantitative risk assessment module disassembles the attack path of the logical attack graph, generates a Bayesian attack graph by calculating the reachable probability and risk value of the attack path, and finally visualizes the Bayesian attack graph.
[0072] 1. Introduction of CVSS base score indicators:
[0073] Common Vulnerability Scoring System (CVSS) v3.1 is a widely used vulnerability quantification scoring standard. Its base score is determined by exploitability sub-score and impact sub-score.
[0074] Exploitability refers to the likelihood of an attacker successfully exploiting a vulnerability. It measures the difficulty of successfully triggering and exploiting the vulnerability by the attacker. Exploitability is determined by four factors: attack vector (AV), attack complexity (AC), required privileges (PR), and user interaction (UI). The calculation formula is:
[0075] Exploitability Sub Score = 8.22 x AV x AC x PR x UI
[0076] Impact describes the consequences of a successful exploit on the system, and it measures the impact on confidentiality, integrity, and availability. Impact is determined by four factors: confidentiality impact (C), integrity impact (I), availability impact (A), and scope (S). The formula is:
[0077]
[0078] The final CVSS base score is calculated based on the exploitability sub-score and the impact sub-score. The formula is:
[0079]
[0080] The round function is used for rounding, and the min function is used to ensure that the score does not exceed 10. The base score ranges from 0 to 10, and the higher the score, the more serious the vulnerability.
[0081] 2. Attack path reachability probability calculation:
[0082] Based on the Datalog-based attack path reasoning, a logical attack graph is generated, which consists of logical attack paths and represents how an attacker achieves the attack goal from the attack entry. Then, the attack paths are disassembled, and a Bayesian attack graph is generated by calculating the reachability probability of the attack paths.
[0083] In calculating the Bayesian attack graph, in addition to inputting the acyclic property attack graph, the probabilities of each initial property node need to be obtained. These property nodes are generally derived from network security information, such as system configuration, permission setting, etc. The success probability of the LEAF-type node is the basis for calculating the success probability of a single atomic attack. Since the core of a single atomic attack is vulnerability exploitation, the remaining security information and preliminary steps are mostly for vulnerability exploitation, therefore, the prior probability of all leaf nodes that do not involve vulnerability information is set to 100% by default, i.e. the success probability of the attacker when performing actions other than vulnerability information exploitation is 100%.
[0084] As for the success probability of exploiting the vulnerability node, the influence sub-score in the CVSS v3.1 base score can be used for calculation. The CVSS scoring system gives a score of the exploitability of the vulnerability, which quantifies the possibility of the vulnerability being exploited, and thus provides data support for the calculation of the leaf nodes in the Bayesian attack graph.
[0085] The Bayesian probability calculation of the attack path quantifies the reachability probability of the target nodes in the attack path through a recursive method combined with different probability calculation formulas of LEAF, AND and OR nodes. In the Bayesian attack graph, nodes are mainly divided into three types: LEAF, AND and OR.
[0086] LEAF-type nodes are attack entry nodes, vulnerability nodes, etc. in the attack graph, represented by rectangles, representing initial attribute nodes. The probability of the LEAF node is determined by the exploitability sub-score in the CVSS base score, and the formula is as follows:
[0087] P LEAF =Exploitability Sb Score / 10
[0088] Wherein, the value range of Exploitability Sub Score is 0 to 10, and the higher the score, the greater the probability of successful exploitation of the vulnerability.
[0089] AND-type nodes are rule nodes in the attack graph, represented by ellipses, representing atomic attack nodes, which refer to one-step deduction in the attack graph generation process, i.e. one atomic attack (such as one vulnerability exploitation or one penetration behavior). The condition for an AND node to be true is that all its parent nodes are true. When calculating the probability of an AND node in the Bayesian attack graph, the formula is as follows:
[0090]
[0091] Wherein, n represents the number of parent nodes of the AND node.
[0092] OR-type nodes are attack target nodes in the attack graph, represented by prisms, and like LEAF-type nodes, they can also represent attribute nodes and be used as conditions for atomic attacks. OR nodes represent the attack result after an atomic attack, i.e. the enhanced attacker's ability after an atomic attack. The success probability of an OR node depends on the success probability of any one of its parent nodes, and the formula is as follows:
[0093]
[0094] Wherein, n represents the number of parent nodes of the OR node.
[0095] 3、Attack path risk value calculation:
[0096] In the intelligent network system, the risk value of a threat is determined not only by its feasibility, but also by its impact. The impact of an attack target node is the result of the comprehensive action of technical impact and business impact. Specifically, the impact sub-score in the CVSS base score of a vulnerability is used as the measurement basis of technical impact, and the weakest link model is used to expand the evaluation. Based on this, the criticality coefficient of an attack target is defined as a quantitative indicator of business impact.
[0097] The impact sub-score (ranging from 0 to 10) of the CVSS of a vulnerability on a path can be mapped to the technical impact of an attack target node. According to the importance of the target node in the business, the criticality coefficient (for example, ordinary, important and critical, taking values from 0 to 10) of the target node is defined as the business impact. The comprehensive impact of the target node is calculated by the weighted average of the technical impact and the business impact, and the formula is as follows:
[0098]
[0099] The risk value is calculated by the feasibility and the comprehensive impact of the attack target node, and the feasibility is determined by the reachable probability of the attack path. The formula for calculating the risk value is as follows, and the value range is 0 to 10:
[0100] Risk Value = Feasibility x Impact target
[0101] 4. Attack path visualization:
[0102] The present application visualizes the Bayesian attack graph with the help of Graphviz. Graphviz is an open source graph visualization tool, which is widely used to create directed graphs, undirected graphs and hierarchical structure graphs. In specific operation, a directed graph is first constructed, and different visual properties are set for each attack path and its node, including node shape, color and label, to distinguish different types of nodes and paths. Each attack path is represented as an independent subgraph, in which different node types (such as LEAF node, AND node and OR node) apply different styles. Through this visualization method, the logical relationship, feasibility, impact and risk value of the nodes in the attack path can be clearly shown, which is convenient for security personnel to understand and analyze.
[0103] Embodiment one
[0104] In this embodiment, the present application is applied to the threat assessment of Mazda automobile IVI system, and the execution process is as shown in the attached Figure 5 figure, and the attached Figure 6The overall logic attack graph is shown, and the multi-stage Bayesian attack graph of one attack path is shown in the accompanying Figure 7 As shown in the accompanying drawings, a method for automatically assessing threats in an intelligent network system includes the following steps:
[0105] Step 1: Build a security ontology model, build security information, and design reasoning rules.
[0106] Step 2: Input the security information and reasoning rules into the reasoning framework, generate a logic attack graph, and then perform attack graph decomposition and optimization.
[0107] Step 3: Disassemble the attack paths in the logic attack graph, calculate the reachable probability and risk value of the attack paths to generate a Bayesian attack graph, and visualize the Bayesian attack graph.
[0108] The specific process of the embodiment is described below:
[0109] (1) Using the collected vehicle networking security events, an intelligent network-connected vehicle security ontology model is constructed based on the intelligent network system security ontology model. On the basis of this ontology model, attack targets, attack entrances, vulnerability sets, vehicle configuration security information, and reasoning rules expressed in Datalog statements are constructed, which are input into the reasoning framework.
[0110] (2) After receiving the security information and reasoning rules, the MulVAL reasoning framework will immediately start the Datalog reasoning program, and then generate a logic attack graph saved in the form of an XML file. Subsequently, the XML description file is parsed to establish a correlation between the nodes and edges in the graph, so that the internal relationship between the components of the attack path can be clearly displayed. In this logic attack graph, each node is connected to adjacent nodes through edges, thereby constructing a logic path extending from the attack entrance to the attack target. In order to make the attack graph more clear and effective, a deepest atomic attack loop elimination algorithm based on depth-first search is used to eliminate loops in the attack graph.
[0111] (3) To analyze the attack path in depth, the attack path in the logic attack graph is first carefully disassembled. Then, relying on the universal vulnerability scoring system, the reachable probability of each attack path is accurately calculated, and a Bayesian attack graph is generated. On this basis, the risk values of each attack path in the Bayesian attack graph are again quantitatively evaluated by means of the universal vulnerability scoring system. Finally, the Graphviz tool is used to visualize the Bayesian attack graph, and the attack path and its risk situation are intuitively presented.
[0112] Figure 7 A multi-stage Bayesian attack graph is presented, showing an attack path. The attacker first contacts the IVI system through the USB interface, exploits the SQL injection vulnerability in the device manager (CVE-2024-8355) and the command injection vulnerability in the firmware update process (CVE-2024-8358, CVE-2024-8359, CVE-2024-8360) to execute arbitrary code with non-root privileges. These vulnerabilities enable the attacker to inject malicious commands through the USB interface, thereby executing arbitrary code in the system and initially gaining system control.
[0113] After successfully obtaining initial control, the attacker further exploits the verification vulnerability of the application SoC lacking hardware root trust (CVE-2024-8357) and the VIP MCU unsigned code vulnerability (CVE-2024-8356) to bypass the system's security mechanisms, gain root privileges, and achieve persistent control. Through these vulnerabilities, the attacker can elevate privileges, control critical components of the system, and thus consolidate their control position in the system. Once root privileges are obtained, the attacker can perform a variety of malicious operations, including tampering with vehicle network communication, stealing sensitive data, manipulating vehicle functions, and implanting persistent malicious software. In addition, the attacker can use the controlled system as a stepping stone to further attack other devices or systems in the vehicle network. For example, through cross-domain broadcast attacks, the attacker can penetrate other vehicle network systems, expanding their attack range.
[0114] This multi-stage attack path demonstrates how an attacker can gradually exploit multiple vulnerabilities from initial access to ultimately achieve full control of the vehicle system and further threaten the security of the entire vehicle network.
[0115] Embodiment Two
[0116] In this embodiment, the method of the present application is applied to the open test vehicle's Autonomous Driving Control Unit (ADCU) for multi-stage attack path analysis. The IVN topology of the open test vehicle is shown in the accompanying Figure 8 The design adopts a multi-level, multi-protocol design.
[0117] Embodiment Two and Embodiment One have basically the same implementation steps, which will be briefly described here. First, based on the IVN of the open test vehicle, an attack model is constructed, and MulVAL is used for attack path reasoning, and then Bayesian attack graph is used for quantitative analysis of path risk. Through simulation of multi-stage attack scenarios, the security impact of different attack paths on the ADCU is revealed, providing a reference for risk handling decisions.
[0118] In the process of attack promotion, the macroscopic attack surface of the whole vehicle end involves multiple dimensions outside and inside the vehicle. Outside the vehicle, there are Wi-Fi hotspots, Bluetooth, cellular mobile communication interfaces and potential attack targets such as GNSS, TPMS and intelligent driving sensors. Inside the vehicle, there are human-computer interaction and vehicle network intrusion points such as CAN bus and OBD-II interface. The main attack targets include key components such as anti-theft systems. Attackers usually start from outside the vehicle to obtain Shell permission of key modules or unlock the vehicle door to expand the attack range. Wi-Fi and Bluetooth outside the vehicle are vulnerable to protocol stack vulnerabilities and can be easily exploited. Cellular mobile communication faces various threats. Obtaining the Shell permission of the central gateway can implement deeper attacks, and the vehicle door can also be directly opened through various means. After the attacker enters the vehicle, Wi-Fi, Bluetooth, HMI, USB port and vehicle Ethernet can become attack entrances. Attackers can use various vulnerabilities and means such as vehicle infotainment system vulnerability debugging, unauthorized Bluetooth access, attacking HMI and IVI, exploiting USB device stack vulnerabilities, and penetrating vehicle Ethernet, to control the core systems of the vehicle.
[0119] Regardless of the way the attacker breaks into the permission of the vehicle door or other components, the ADCU will face the threat of being attacked. There are usually two main attack scenarios: one is that the attacker attacks other modules as a stepping stone to implement remote penetration through the central gateway; the second is that the attacker unlocks the vehicle door and directly contacts the system and further penetrates after entering the vehicle.
[0120] In the attack scenario (Scenario One: Multi-stage privilege escalation from IVI to vehicle Ethernet) attached Figure 9 , the attacker connects to the IVI Wi-Fi network by exploiting the default configuration vulnerabilities (such as weak password, not enabling encryption protocol) or known protocol stack vulnerabilities (such as WPA2 key reinstallation attack) of the IVI system Wi-Fi hotspot. By scanning open ports and services, the attacker obtains initial access permission by exploiting vulnerable network service vulnerabilities (such as buffer overflow, command injection). Then, the attacker obtains Root permission by exploiting low-privilege code execution vulnerabilities and privilege escalation vulnerabilities of the IVI system, realizes complete control of the IVI system, and then uses the connection between the IVI system and the vehicle gateway to move "horizontally" to the ADCU system by exploiting the lax security filtering of the gateway. Finally, the attacker exploits the low-privilege code execution and privilege escalation vulnerabilities existing in the ADCU system to execute code on the ADCU and escalate to Root, and finally completely controls the ADCU. The whole process shows the process of the attacker breaking through the defense line by exploiting multiple vulnerabilities and system connections to control the ADCU.
[0121] In the attack scenario (Scenario Two: Physical access to the vehicle) attached Figure 10In the illustrated attack scenario (Scenario Two: From malicious App to unlock vehicle physical intrusion), the attacker first installs malicious software on the victim's device, exploits the security vulnerabilities of improper mobile App key storage and lack of sufficient code protection, extracts the key or authentication credentials through reverse engineering to bypass the authentication mechanism, constructs malicious requests through the App and central gateway communication interface, performs a replay attack to obtain gateway control authority, and then manipulates the key ECU to send a fake unlock instruction to the BCM responsible for functions such as vehicle door locking and unlocking. After unlocking the vehicle, the attacker disassembles the ADCU hardware through physical contact, and implements multiple attacks when the ADCU lacks security protection, such as extracting firmware to steal core data, rewriting firmware to implant malicious code, enabling security start or firmware signature verification to write malicious firmware through the CAN bus, tampering with encryption keys, hijacking autonomous driving strategies, launching a man-in-the-middle attack to intercept and tamper with communication data through an unencrypted or unauthenticated vehicle Ethernet interface, obtaining Shell authority of the ADCU and horizontally attacking key ECU modules. Such physical intrusion can cause firmware tampering, data leakage, autonomous driving abnormalities, and attack chain propagation, posing a significant security risk.
[0122] The application provides an intelligent network system automatic threat evaluation method, which comprises the following steps: a security information input module, which is used for constructing an attack target, an attack entry, a vulnerability set and a vehicle configuration represented by a Datalog statement based on an ontology model, and taking the same as an input of an attack path reasoning module; the attack path reasoning module, which is used for generating a logical attack graph after reasoning, attack graph reconstruction and attack graph optimization based on the input security information and designed reasoning rules through a MulVAL framework; and a quantitative risk assessment module, which is used for decomposing attack paths of the logical attack graph, generating a Bayesian attack graph by calculating a reachable probability and a risk value of the attack paths, and finally visualizing the Bayesian attack graph.
[0123] The "first" and "second" in the names "first" and "second" mentioned in the embodiments of the application are only used for name identification, and do not represent the first and second in order.
[0124] From the above description of the embodiments, those skilled in the art can clearly understand that all or part of the steps in the above-mentioned method embodiments can be implemented by means of software plus a general hardware platform. Based on such an understanding, the technical solutions of the present application can be embodied in the form of a software product. The computer software product can be stored in a storage medium, and the storage medium can be various types of memories, such as random access memory (RAM), read only memory (ROM), flash memory, etc., such as read only memory (ROM) / RAM, magnetic disks, optical disks, etc., and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in various embodiments or some parts of the embodiments of the present application.
[0125] The above shows and describes the basic principles and main features of the present application and the advantages of the present application. Those skilled in the art should understand that the present application is not limited to the above-mentioned embodiments, and the above-mentioned embodiments and descriptions in the specification are only illustrative of the principles of the present application. Without departing from the spirit and scope of the present application, various changes and improvements can be made to the present application, and these changes and improvements all fall within the scope of the present application. The scope of protection of the present application is defined by the appended claims and their equivalents.
Claims
1. An automated threat assessment method for intelligent connected systems, characterized in that, Specifically, the steps include the following: Step (1) Construct a security information input module. This security information input module constructs a general security ontology model of an intelligent connected system from two dimensions: physical entities and security elements, and uses the ontology model to construct security information. Step (2) Construct an attack path reasoning module. This attack path reasoning module uses the MulVAL framework to perform reasoning based on the input security information and pre-designed reasoning rules. After attack graph deconstruction and attack graph optimization, a logical attack graph is generated. Step (3) Construct a quantitative risk assessment module. This module first decomposes the attack paths in the logic attack graph, generates a Bayesian attack graph by calculating the reachability probability and risk value of each attack path, and finally visualizes the Bayesian attack graph.
2. The automated threat assessment method for intelligent connected systems according to claim 1, characterized in that, In step (1), the security ontology model comprehensively covers core elements such as intelligent connected systems, components, attributes, vulnerabilities, and attack vectors.
3. The automated threat assessment method for intelligent connected systems according to claim 1, characterized in that, Based on step (1), the security information input module further uses Datalog statements to represent information such as attack targets, attack entry points, vulnerability sets, and system configurations, and provides this structured data as input to the attack path reasoning module.
4. The automated threat assessment method for intelligent connected systems according to claim 1, characterized in that, In step (2), the nodes and edges in the logic attack graph are associated by parsing the XML file of the logic attack graph, thereby revealing the interrelationship between the various components in the attack path.
5. The automated threat assessment method for intelligent connected systems according to claim 1, characterized in that, In step (2), the generated logic attack graph is finally optimized to eliminate loops.
6. The automated threat assessment method for intelligent connected systems according to claim 1, characterized in that, In step (3), the risk of each attack path is quantitatively assessed using the Common Vulnerability Scoring System (CVSS), and the corresponding risk value is calculated.
7. The automated threat assessment method for intelligent connected systems according to claim 1, characterized in that, In step (3), the generated Bayesian attack graph is visualized using the Graphviz tool.
8. The automated threat assessment method for intelligent connected systems according to claim 1, characterized in that, Specifically, the steps include the following: Step 1: Construct a security ontology model, build security information, and design inference rules; Step 2: Input security information and inference rules into the inference framework to generate a logic attack graph, and then deconstruct and optimize the attack graph; Step 3: Deconstruct the attack paths in the logic attack graph, calculate the reachability probability and risk value of the attack paths to generate a Bayesian attack graph, and visualize the Bayesian attack graph.
9. The automated threat assessment method for intelligent connected systems according to claim 1, characterized in that, Specifically, the steps include the following:
1. First, an attack model is built based on the IVN of the open test vehicle, and attack path inference is performed using MulVAL; 2. Then, combine the Bayesian attack graph to conduct a quantitative analysis of the path risk; 3. By simulating multi-stage attack scenarios, the security impact of different attack paths on ADCU is revealed, providing a reference for risk management decisions.