Data analysis method, vehicle, device, equipment and program product
By combining large language models with real-time traffic and historical data, intelligent analysis of vehicle network intrusion threats is achieved, solving the problem of single detection methods in existing technologies, improving analysis efficiency and accuracy, and enhancing vehicle security.
Patent Information
- Application Number
- CN202511247036.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-02
- Publication Date
- 2025-11-18
AI Technical Summary
In existing technologies, vehicle network intrusion detection methods are singular and rigid, making it difficult to cope with new attack methods, resulting in low analysis efficiency and accuracy, and reducing the overall security of vehicles.
By acquiring real-time traffic data and historical sample data, and using large language models for network intrusion threat analysis, combined with historical knowledge bases and vectorization processing, intelligent analysis of vehicle network intrusion threats by external devices can be achieved.
It improves the efficiency and accuracy of vehicle network intrusion analysis, enabling efficient identification of threats in complex and ever-changing network environments and enhancing vehicle security.
Smart Images

Figure CN120979769A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle technology, specifically to a data analysis method, vehicle, device, equipment, and program product. Background Technology
[0002] With the popularization of vehicle-to-everything (V2X) technology, the intelligence and connectivity of vehicles are constantly improving, and the interaction between vehicles and external networks and other devices is becoming increasingly frequent. This exposes vehicles to increasingly complex network attack risks, such as Bluetooth intrusion, data theft, and unauthorized control. Traditional detection methods, such as feature matching, protocol compliance checks, and identity verification, are singular and rigid, making it difficult to cope with new attack methods. The analysis efficiency and accuracy of vehicle network intrusions are low, thus reducing the overall security of vehicles. Summary of the Invention
[0003] Based on the deficiencies and shortcomings of the existing technology, this application proposes a data analysis method, vehicle, device, equipment, and program product that can intelligently analyze vehicle network intrusion threats by external devices through a large language model, based on real-time traffic data and historical sample data, thereby improving the efficiency and accuracy of vehicle network intrusion analysis.
[0004] According to a first aspect of this application, a data analysis method is provided, comprising: acquiring real-time traffic data during data interaction between a vehicle and an external device; acquiring first historical sample data corresponding to the real-time traffic data from various historical sample data in a historical knowledge base, wherein the historical sample data includes sample data generated at least once in history when the vehicle interacted with the external device; inputting the real-time traffic data and the historical sample data into a large language model, and acquiring the network intrusion threat analysis result of the external device on the vehicle output by the large language model.
[0005] According to the data analysis method provided in the first aspect of this application, the real-time traffic data includes the real-time traffic vector, and the historical sample data includes historical sample vectors; acquiring real-time traffic data during the data interaction process between the vehicle and the external device includes: collecting raw traffic data during the real-time data interaction process between the vehicle and the external device; performing vectorization processing on the raw traffic data to obtain the real-time traffic vector corresponding to the raw traffic data; acquiring the first historical sample data corresponding to the real-time traffic data from each historical sample data in the historical knowledge base includes: calculating the similarity between each historical sample vector in the historical knowledge base and the real-time traffic vector; and obtaining the first historical sample data based on the similarity.
[0006] According to the data analysis method provided in the first aspect of this application, the historical sample data includes attack sample data and normal sample data. The attack sample data is sample data of the external device launching a network attack on the vehicle, and the normal sample data is sample data of the external device interacting normally with the vehicle. The step of obtaining the first historical sample data corresponding to the real-time traffic data from each historical sample data in the historical knowledge base includes: matching the first attack sample data and the first normal sample data corresponding to the real-time traffic data in each historical sample data in the historical knowledge base.
[0007] According to the data analysis method provided in the first aspect of this application, the step of inputting the real-time traffic data and the historical sample data into a large language model to obtain the network intrusion threat analysis result of the external device on the vehicle output by the large language model includes: filling the real-time traffic data and the historical sample data into a preset prompt word template, wherein the prompt word template includes chained prompt information; inputting the filled prompt word template into the large language model to obtain the network intrusion threat analysis result of the external device on the vehicle output by the large language model.
[0008] According to the data analysis method provided in the first aspect of this application, after obtaining the network intrusion threat analysis result of the external device on the vehicle output by the large language model, the method further includes: if the network intrusion threat analysis result indicates that the external device has network attack behavior on the vehicle, then the real-time traffic data and the corresponding network intrusion threat analysis result are updated to the historical knowledge base.
[0009] According to the data analysis method provided in the first aspect of this application, the step of performing vectorization processing based on the original traffic data to obtain the real-time traffic vector corresponding to the original traffic data includes: preprocessing the original traffic data, wherein the preprocessing includes data filtering, structured processing and / or feature extraction; and performing vectorization processing on the preprocessed original traffic data to obtain the real-time traffic vector, wherein the real-time traffic vector and the historical sample vector have the same vector dimension.
[0010] According to a second aspect of this application, a vehicle is provided that, when interacting with external devices, analyzes real-time traffic data during the data interaction process using the data analysis method described in any of the first aspects.
[0011] According to a third aspect of this application, a data analysis apparatus is provided, comprising: a real-time data acquisition module for acquiring real-time traffic data during data interaction between a vehicle and an external device; a historical data acquisition module for acquiring first historical sample data corresponding to the real-time traffic data from various historical sample data in a historical knowledge base, wherein the historical sample data includes sample data generated at least once in history when the vehicle interacted with the external device; and a data analysis module for inputting the real-time traffic data and the historical sample data into a large language model to acquire the network intrusion threat analysis result of the external device on the vehicle output by the large language model.
[0012] According to a fourth aspect of this application, an electronic device is provided, comprising: a memory and a processor; the memory is connected to the processor and is used to store a program; the processor is used to implement the data analysis method as described in the first aspect by running the program in the memory.
[0013] According to a fifth aspect of this application, a computer program product is provided, comprising computer program instructions; said computer program instructions, when executed by a processor, cause the processor to perform the data analysis method as described in the first aspect.
[0014] This application acquires real-time traffic data during data interaction between a vehicle and external devices. From various historical sample data in a historical knowledge base, it acquires the first historical sample data corresponding to the real-time traffic data, whereby the historical sample data includes sample data generated during at least one historical data interaction between the vehicle and external devices. The real-time traffic data and historical sample data are input into a large language model to obtain the network intrusion threat analysis results of external devices against the vehicle output by the large language model. In the above process, a retrieval-enhanced large language model architecture is formed based on the historical knowledge base. Based on the real-time traffic data and the first historical sample data in the historical knowledge base, the large language model is guided to analyze the real-time threat of external devices to vehicle network intrusion, improving the intelligence level of vehicle network intrusion analysis. Even in complex and ever-changing network environments, it can still efficiently and accurately analyze the network intrusion threat of external devices against the vehicle, thus improving vehicle security. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0016] Figure 1A flowchart illustrating a data analysis method provided in an embodiment of this application;
[0017] Figure 2 A block diagram of a data analysis device provided in an embodiment of this application;
[0018] Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0019] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0020] Exemplary methods
[0021] In response to the complex and ever-changing data interaction environment between vehicles and external devices, this application provides a data analysis method to enhance the intelligent analysis of vehicle network intrusion threats by external devices. This method can be implemented as a software algorithm, and the software method implementing this method can run on any device with data processing capabilities, such as a processor configured on a vehicle, a cloud server independent of the vehicle, or a smart mobile device independent of the vehicle. The scope of protection of this application is not limited by the type of device on which the software algorithm implementing this data analysis method runs.
[0022] In one embodiment, such as Figure 1 As shown, the workflow steps for implementing the data analysis method include:
[0023] Step 101: Obtain real-time traffic data during the data interaction process between the vehicle and external devices.
[0024] In this embodiment, "vehicle" refers to a vehicle requiring network intrusion protection. "External device" refers to a device independent of the vehicle but capable of data interaction with it, such as a smart mobile device or a cloud server independent of the vehicle. During vehicle operation, the vehicle may interact with multiple devices, for example, with a smartphone or with a remote server providing map data. This method is applicable to the process of a vehicle interacting with any external device. If the vehicle interacts with multiple external devices simultaneously, the processing logic provided by this method can be implemented separately for each external device.
[0025] In this embodiment, network traffic is captured in real time during the data interaction between the vehicle and external devices to obtain real-time traffic data. Optionally, the Suricata open-source engine is used to achieve real-time traffic capture. Suricata is a high-performance open-source network security monitoring engine designed specifically for Real-time Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring (NSM). The Suricata open-source engine, combined with libpcap or WinPcap, completes low-level packet capture to meet the data acquisition needs in high-speed network environments. libpcap (Packet Capture Library) and WinPcap (Windows Packet Capture) are cross-platform network packet capture libraries widely used in network monitoring, security analysis, protocol debugging, and other fields.
[0026] Step 102: Obtain the first historical sample data corresponding to the real-time traffic data from the various historical sample data in the historical knowledge base. The historical sample data includes sample data generated at least once in history when the vehicle interacted with external devices.
[0027] In this embodiment, a historical knowledge base is pre-established, storing multiple historical sample data. Historically, the vehicle may have interacted with multiple external devices multiple times. For any historical data interaction with an external device, various data related to that interaction, such as network traffic data and network intrusion threat analysis data, can be compiled to form sample data for that interaction. The compilation and storage of multiple historical sample data forms the historical knowledge base, which can be used for real-time analysis of vehicle network intrusion threats.
[0028] In this embodiment, the historical sample data in the historical knowledge base is typically large in volume. Therefore, the persistent storage and efficient querying of this massive amount of historical sample data significantly impacts the real-time analysis of subsequent vehicle network intrusion threats. Optionally, Apache HDFS can be used to build a distributed storage system, supporting petabyte (PB) level data storage and multi-replica redundancy. Apache HDFS (Hadoop Distributed File System) is the core distributed file system of the Apache Hadoop project, designed specifically for massive data storage, and features high fault tolerance, high throughput, and low cost. Alternatively, a Cassandra distributed column family database can be used, with time-series partitioned storage to meet high-concurrency read requirements. Apache Cassandra is an open-source distributed NoSQL database system designed for handling large-scale datasets and high-concurrency read / write scenarios, possessing high availability, linear scalability, and strong fault tolerance. Optionally, InfluxDB time-series database can also be introduced to manage traffic trend statistics. InfluxDB is an open-source, high-performance time-series database designed specifically for processing time-series data, offering advantages such as high-throughput writing, efficient compressed storage, and flexible time-series query capabilities. Alternatively, the raw real-time traffic data initially collected can be compressed using Snappy or LZ4 lossless compression algorithms. This reduces storage costs while ensuring fast data decompression and parsing. Snappy is a high-speed, lossless data compression algorithm developed by Google, designed specifically for high-throughput data processing and widely used in databases, distributed computing, log processing, and other fields. LZ4 is an extremely high-speed lossless compression algorithm that focuses on compression / decompression speed and is suitable for real-time data processing and high-throughput scenarios.
[0029] Step 103: Input real-time traffic data and historical sample data into the large language model to obtain the network intrusion threat analysis results of external devices to the vehicle output by the large language model.
[0030] In this embodiment, the large language model possesses context learning capabilities. By providing a small number of samples (Few-Shot Prompting) or a direct instruction task (Zero-Shot Prompting) in the prompt words, the large language model can mimic sample patterns based on its pre-trained language understanding capabilities to complete tasks such as classification and judgment. The large language model provided in this method is a model pre-trained based on a network intrusion threat analysis task. Optionally, using carefully selected vehicle intrusion sample data, including network attack features and network intrusion type annotations, the large language model is fine-tuned using LoRA technology. Appropriate parameters are set for iterative training, and the model's performance is evaluated to optimize it. This achieves fine-tuning and optimization of the large language model. Low-Rank Adaptation (LoRA) is a technique for efficiently fine-tuning large pre-trained models. Its core idea is to freeze the original model parameters and train only a small number of newly added low-rank matrices to simulate parameter updates, thereby significantly reducing computational resources and memory requirements while maintaining near-full-parameter fine-tuning performance. The optimized large language model can respond quickly on edge devices, meeting real-time requirements.
[0031] In this embodiment, the large language model performs intelligent analysis, anomaly detection, and threat inference based on real-time traffic data and historical sample data, and outputs the analysis results of network intrusion threats to the vehicle from external devices. Optionally, the large language model can be any of the following: open-source model LLaMA 2-70B, Falcon-40B, or commercial model GPT-4API. Among them, LLaMA 2-70B is an open-source commercial-grade large language model launched by Meta, belonging to the flagship model with the largest parameter scale (70 billion parameters) in the LLaMA 2 series, designed specifically for high-performance natural language processing tasks; Falcon-40B is an open-source large language model developed by the UAE Institute of Technology Innovations, with 40 billion parameters, and is one of the most powerful open-source large language models currently available; GPT-4 is a large language model based on the Transformer architecture, and GPT-4API is an application programming interface (API) provided by OpenAI, allowing developers to call the powerful capabilities of the GPT-4 model through code to achieve various natural language processing (NLP) tasks such as text generation, dialogue interaction, translation, and code assistance.
[0032] In this embodiment, the historical knowledge base and the large language model form a Retrieval Augmented Generation (RAG) architecture. By combining external knowledge retrieval with large language model generation, the accuracy, timeliness, and reliability of the model output content are significantly improved.
[0033] In one embodiment, real-time traffic data includes real-time traffic vectors, and historical sample data includes historical sample vectors.
[0034] The process of acquiring real-time traffic data during the data interaction between the vehicle and external devices includes: collecting raw traffic data during the real-time data interaction between the vehicle and external devices; and performing vectorization processing on the raw traffic data to obtain the real-time traffic vector corresponding to the raw traffic data. From the historical sample data in the historical knowledge base, the process of acquiring the first historical sample data corresponding to the real-time traffic data includes: calculating the similarity between each historical sample vector in the historical knowledge base and the real-time traffic vector; and obtaining the first historical sample data based on the similarity.
[0035] In this embodiment, during the data interaction between the vehicle and external devices, Wireshark or Zeek is used to capture packet capture files (PCAPs) during the data interaction process. These PCAPs are then imported into the Hadoop Distributed File System (HDFS) for distributed storage via Flume, forming a raw traffic dataset partitioned by time. Wireshark is an open-source network protocol analysis tool used to capture, parse, and diagnose data packets in network communication. Zeek is an open-source network traffic analysis framework focused on deep protocol parsing, behavioral analysis, and security monitoring, widely used in intrusion detection, network forensics, and traffic analysis. Flume (Apache Flume) is an open-source distributed log collection, aggregation, and transmission system designed for efficient processing of massive log data, particularly suitable for real-time data acquisition and transmission in big data scenarios.
[0036] In this embodiment, the raw traffic data is vectorized to obtain real-time traffic vectors. Furthermore, for historical sample data in the historical knowledge base, the historical traffic data contained in each historical sample is pre-vectorized and stored in vector form. Of course, other historical descriptive information not involved in matching, such as historical network intrusion threat analysis results, can still be described in textual form. Based on the vectorization of real-time traffic data and historical sample data, historical sample vectors with higher similarity to the implemented traffic vectors are retrieved from the historical knowledge base. Semantic encoding is performed using a vector model, transforming the semantic information in the text into vector representations. The large language model directly understands the text's meaning based on semantic vectors, uncovering potential relationships between features, achieving an upgrade from "feature matching" to "semantic parsing." This provides the large language model with both real-time and historical knowledge support, improving the accuracy of the large language model's output. In addition, vectorization processing can overcome the limitations of structured data, enabling efficient integration and analysis of complex data from various sources in vehicles, such as CAN bus and sensors.
[0037] In this embodiment, the knowledge database can be stored in the form of a knowledge graph based on vectorized data to facilitate real-time semantic retrieval and provide historical knowledge references for large language model analysis. Optionally, Sentence-Transformers can be used to convert feature text into 768-dimensional vectors. Milvus is used as the core vector database, combined with HNSW or SHARDS indexing algorithms to achieve efficient storage of high-dimensional vectors (e.g., 768-dimensional and higher-dimensional vectors) and millisecond-level approximate nearest neighbor search; an Elasticsearch+Milvus hybrid retrieval architecture is constructed to realize multimodal comprehensive query of text keywords and vector similarity; in addition, outdated cases can be manually cleaned up periodically to ensure the retrieval performance of vector knowledge. Among them, Sentence-Transformers is a Python library based on the Transformer architecture, specifically designed to generate high-quality sentence, paragraph, or image embeddings, that is, to convert text or images into fixed-length dense vectors (such as 384-dimensional or 768-dimensional) for tasks such as semantic similarity calculation, clustering, and retrieval; Milvus is an open-source cloud-native vector database designed for handling large-scale vector similarity searches and widely used in the fields of artificial intelligence and machine learning; Hierarchical Navigable Small World (HNSW) is an efficient approximate nearest neighbor search algorithm designed for large-scale vector similarity retrieval in high-dimensional spaces; the Elasticsearch+Milvus hybrid retrieval architecture is a technical solution that combines the advantages of keyword retrieval and vector similarity search, aiming to solve the limitations of single engines in semantic understanding, performance, or scalability; in Elasticsearch, the core of the SHARDS indexing algorithm is to achieve distributed storage and retrieval of data through a sharding mechanism, and its core algorithms include sharding routing, load balancing, and consistency guarantees.
[0038] In one embodiment, vectorization processing is performed on the raw traffic data to obtain the real-time traffic vector corresponding to the raw traffic data, including: preprocessing the raw traffic data, wherein the preprocessing includes data filtering, structuring processing and / or feature extraction; and vectorizing the preprocessed raw traffic data to obtain the real-time traffic vector, wherein the real-time traffic vector and the historical sample vector have the same vector dimension.
[0039] In this embodiment, during the interaction between the vehicle and external devices, after the initial collection of raw traffic data, preprocessing is performed first, followed by vectorization. The preprocessing process includes, but is not limited to, data filtering, structuring, and / or feature extraction. Similarly, historical sample data also requires corresponding preprocessing.
[0040] For example, for massive amounts of raw historical sample data, the Apache Spark distributed processing framework performs parallel cleaning, deduplication, and anonymization of historical traffic data. Specifically, Spark removes duplicate records during data cleaning and anonymizes network layer (Internet Protocol, IP) / media access control (MAC) addresses. Pandas is used to perform refined feature engineering on small-scale samples, parsing the Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) payloads to extract Uniform Resource Locators (URLs), domain names, binary features, etc. NLTK / Spacy is used for tokenization and semantic parsing of the protocol text, and Scikit-learn is used for temporal feature standardization. Based on the TRAM / MISP threat intelligence platform, threat samples are mapped to the MITRE ATT&CK framework for automated labeling. Finally, historical text data in JSON format is obtained. Among them, Apache Spark is an open-source distributed computing framework designed for large-scale data processing, holding a core position in the big data field due to its high performance, ease of use, and versatility; Pandas is an open-source Python data analysis library designed for processing structured data; NLTK (Natural Language Toolkit) is an open-source Python library designed for teaching and research, providing rich linguistic tools and standardized corpora, supporting development from basic text processing to complex language models; spaCy is a natural language processing (NLP) library for industrial applications, emphasizing efficiency and production environment deployment, and supporting multilingual processing; Scikit-learn (sklearn) is one of the most popular open-source machine learning libraries in the Python ecosystem, designed for data mining and data analysis; TRAM refers to automated threat intelligence analysis technology; MISP (Malware Information Sharing Platform) is an open-source threat intelligence sharing platform designed for cybersecurity teams to efficiently collect, store, analyze, and share network threat data; MITRE ATT&CK (Adversarial Tactics, Techniques, and...) The CommonKnowledge framework is a globally used cybersecurity knowledge base designed to systematically describe attackers' tactics, techniques, and procedures, helping defenders identify, analyze, and respond to cyber threats.
[0041] The sample JSON example is as follows:
[0042] {
[0043] "sample_id":"vehicle_attack_001",
[0044] "attack_time":"2025-06-22 14:30:00",
[0045] "vehicle_info":{
[0046] "make":"ABC Motors",
[0047] "model":"XYZ 2023",
[0048] "vin":"1234567890ABCDEFG",
[0049] "ecu_types":["IVI","ECU1","ECU2","T-Box"]
[0050] },
[0051] "attack_source":{
[0052] "ip_address":"192.168.1.101",
[0053] "mac_address":"00:11:22:33:44:55",
[0054] "attack_vector":"Bluetooth vulnerability"
[0055] },
[0056] "attack_behavior":{
[0057] "initial_access":"Connects to the IVI system via Bluetooth, exploiting a known Bluetooth authentication bypass vulnerability",
[0058] "information_gathering":[
[0059] "Current vehicle location: 40.7128°N, 74.0060°W",
[0060] "To obtain the car owner's contact information: 123-456-7890"
[0061] Retrieve navigation history: ['Address 1', 'Address 2', 'Address 3']
[0062] ],
[0063] "control_attempts":[
[0064] "Attempted to increase engine speed, but without success."
[0065] "Car door lock successfully unlocked" ]
[0067] },
[0068] "system_response":{
[0069] "ivi_system": "An abnormal lag occurred, and some functions became unresponsive."
[0070] "ecu_cluster": "ECU1 and ECU2 detected abnormal communication, triggering a safety mechanism and restricting some non-critical functions."
[0071] "t-box": "Sends a security alert to the cloud server, reporting a potential intrusion incident."
[0072] },
[0073] "threat_label":{
[0074] "is_malicious":true,
[0075] "attack_type":"Bluetooth intrusion and function tampering",
[0076] "attack_subtype":"Information theft and unauthorized control",
[0077] "mitre_attack_id":"T1583.002",
[0078] "mitre_technique": "Lateral movement and attack via Bluetooth",
[0079] "confidence_level":"high",
[0080] "label_source":"Vehicle Intrusion Detection System + Security Research Report"
[0081] },
[0082] "additional_context":{
[0083] "software_versions":{
[0084] "ivi_system":"1.0.2",
[0085] "ecu1":"2.1.1",
[0086] "ecu2":"2.0.5",
[0087] "t-box":"3.0.0"
[0088] },
[0089] "connected_devices":["Mobile phone (device ID: 55:44:33:22:11:00)"],
[0090] "previous_security_updates": "On May 15, 2025, the Bluetooth driver for the IVI system was updated, but the vulnerability exploited in this instance was not fixed."
[0091] }
[0092] }
[0093] For example, for real-time raw traffic data, a distributed log collection system is built using Apache Flume to achieve real-time aggregation and format conversion (e.g., from PCAP format to JSON format) of multi-source data during data interaction between vehicles and external devices. Based on the Netflow v9 / sFlow standard, traffic quintuples, protocols, and other metadata are extracted, and user-space packet processing is implemented using the Data Plane Development Kit (DPDK) to reduce kernel-space switching overhead and improve collection efficiency and transmission stability. This process cleans, extracts features, and transforms the raw historical sample data to generate standardized data for subsequent analysis. NetFlow v9 is a flexible and scalable network traffic data export protocol, the 9th version of NetFlow technology, and one of the most advanced versions currently available. It achieves efficient monitoring and analysis of network traffic through template-based data formats and is widely used in network performance optimization, security threat detection, and traffic billing. sFlow is a packet sampling-based network traffic monitoring technology designed to provide real-time, lightweight traffic analysis capabilities for high-speed networks (e.g., 10 Gbit / s and above).
[0094] For example, for real-time raw traffic data, network traffic is parsed in real time using Suricata, and five-tuple metadata is extracted using Netflow. Valid traffic is filtered by protocols such as Hypertext Transfer Protocol (HTTP) / Transport Layer Security (TLS) and IP segment filtering. PCAP data is converted to JSON format, containing fields such as the communication source (src_ip), destination (dst_port), and payload. The Flink stream processing framework is used to calculate time-series characteristics such as traffic rate and packet size distribution in real time. NetFlow is a network traffic monitoring protocol used to collect and analyze IP traffic information flowing through network devices (such as routers and switches); it records statistical information of data flows to help network administrators monitor traffic patterns, optimize performance, detect abnormal behavior, and plan network billing. Apache Flink is an open-source distributed stream processing framework designed for processing unbounded (real-time) and bounded (batch) data streams. Its core goal is to achieve high-throughput, low-latency, and exact-once semantic streaming computation through a unified programming model, while supporting complex state management and fault tolerance mechanisms.
[0095] In this embodiment, the vector dimensions of the real-time traffic vector and the historical sample vector are kept consistent, thereby reducing the difficulty of subsequent vector processing and improving the speed and efficiency of data processing.
[0096] In one embodiment, the historical sample data includes attack sample data and normal sample data. The attack sample data is sample data of external devices launching network attacks on vehicles, and the normal sample data is sample data of external devices conducting normal data interactions with vehicles.
[0097] In the historical sample data of the historical knowledge base, the first historical sample data corresponding to the real-time traffic data is obtained, including: in the historical sample data of the historical knowledge base, the first attack sample data and the first normal sample data corresponding to the real-time traffic data are matched.
[0098] In this embodiment, the historical knowledge base includes attack sample data from multiple external devices launching network attacks against the vehicle, as well as normal sample data from multiple external devices interacting normally with the vehicle. Among the historical sample data in the historical knowledge base, first attack sample data and first normal sample data corresponding to real-time traffic data are matched. Optionally, if the real-time traffic data is converted into a real-time traffic vector, and each historical sample data in the historical knowledge base also includes a corresponding historical sample vector, then during matching, the similarity between each historical sample vector and the real-time traffic vector is calculated. The attack sample data corresponding to the attack sample vector with the highest similarity is taken as the first attack sample data, and the normal sample data corresponding to the normal sample vector with the highest similarity is taken as the first normal sample data. The first attack sample data and the first normal sample data are converted into natural language prompts, and the model is informed of the first attack sample data and the first normal sample data through examples. This allows the large language model to reason based on the real-time traffic data and the example's first attack sample data and first normal sample data. Inputting historical and real-time knowledge into the large language model improves the accuracy of the network intrusion threat analysis results output by the model and avoids the problem of the large language model being prone to illusions.
[0099] In one embodiment, inputting real-time traffic data and historical sample data into a large language model to obtain the network intrusion threat analysis results of external devices to the vehicle output by the large language model includes: filling real-time traffic data and historical sample data into a preset prompt word template, wherein the prompt word template includes chained prompt information; inputting the filled prompt word template into the large language model to obtain the network intrusion threat analysis results of external devices to the vehicle output by the large language model.
[0100] In this embodiment, a prompt word template is preset, and real-time traffic data and historical sample data are filled into the preset prompt word template. The historical sample data is used as example data, allowing the large language model to reason based on the newly collected real-time traffic data and the historical sample data of the example. This guides the large language model to analyze the newly generated real-time traffic data in combination with the historical sample data, thereby improving the accuracy of the output results of the large language model.
[0101] In this embodiment, the prompt word template includes chained prompt information, which requires the large language model to reason step by step. Chain-of-Thought Prompting is a prompting engineering method used to improve the reasoning ability of large language models (LLMs). By guiding the model to think step by step and showing the intermediate reasoning process, it significantly improves the accuracy of solving complex problems.
[0102] For example, taking historical sample data including historical attack case 1 and historical normal sample 1, and real-time traffic data including samples to be detected, based on a pre-set prompt word template, the final prompt words are as follows:
[0103] [System Prompt]: You are a senior automotive cybersecurity expert specializing in analyzing cyberattacks against vehicle systems. Your task is to conduct a threat assessment of new samples based on historical cases and your expertise, and output a detailed reasoning process and conclusions. Please strictly follow the steps below for analysis:
[0104] 1. Compare the similarity between the sample to be detected and historical attack cases, and list the matching attack features;
[0105] 2. Analyze the differences between the sample to be tested and normal samples to rule out the possibility of false alarms;
[0106] 3. Classify threat types according to the MITRE ATT&CK vehicle networking technology framework;
[0107] 4. Provide the final threat assessment result and corresponding handling recommendations.
[0108] [Historical Attack Case 1]:
[0109] Sample ID: vehicle_attack_001
[0110] Attack time: 2025-06-22 14:30:00
[0111] Vehicle Information: ABC Motors XYZ 2023 model, VIN: 1234567890ABCDEFG
[0112] Attack source: IP 192.168.1.101, MAC address 00:11:22:33:44:55, exploiting a Bluetooth authentication bypass vulnerability.
[0113] Attack behavior:
[0114] -Initial Access: Connect to the IVI system via Bluetooth
[0115] -Information collection: Obtain vehicle location, owner contact information, and navigation history.
[0116] -Control Attempt: Attempted to increase engine speed, successfully unlocked the car door.
[0117] System response: IVI freezes, ECU triggers safety mechanism, T-Box sends alarm.
[0118] MITRE Technical ID: T1583.002
[0119] Threat tags: malicious, Bluetooth intrusion and function tampering
[0120] [Historical Normal Sample 1]:
[0121] Sample ID: vehicle_normal_001
[0122] Timestamp: 2025-06-22 15:00:00
[0123] Vehicle Information: DEF Motors LMN 2022 model, VIN: 9876543210GFEDCBA
[0124] Device connection:
[0125] - The phone connects via Bluetooth to play music, only requesting audio permissions.
[0126] - The vehicle's infotainment system periodically sends fuel consumption data to the cloud.
[0127] Data transmission:
[0128] - Inbound traffic: 5000 bytes (map update data)
[0129] Outbound traffic: 2000 bytes (diagnostic information reporting)
[0130] Security status: Firewall enabled, no abnormal connection requests.
[0131] Threat tag: Normal, routine data interaction
[0132] [Sample to be tested]:
[0133] Sample ID: unknown_sample_001
[0134] Detection time: 2025-06-23 10:15:00
[0135] Vehicle Information: ABC Motors XYZ 2023 model, VIN: 1234567890ABCDEFG
[0136] Device connection:
[0137] - An unknown Bluetooth device (MAC: 66:55:44:33:22:11) was discovered and established a connection with the IVI system.
[0138] -T-Box frequently exchanges data with an unauthorized IP address (172.16.1.50).
[0139] Data transmission:
[0140] Inbound traffic: 20,000 bytes (including a large amount of encrypted data)
[0141] - Outbound traffic: 15,000 bytes (including real-time vehicle location information)
[0142] System error:
[0143] - The dashboard is intermittently blacking out.
[0144] - Car door locks are opening and closing automatically.
[0145] Please follow the analysis steps and output a detailed reasoning process and final conclusion:
[0146] 1. Similarity analysis: ...
[0148] 2. Comparison of differences: ...
[0150] 3. Threat Classification: ...
[0152] 4. Final conclusion: ...
[0154] In this embodiment, the historical sample data used as examples in the prompt word template can be set in multiple ways according to the actual situation and specific needs, as long as it corresponds to the number of the first historical sample data extracted from the historical knowledge base.
[0155] In one embodiment, after obtaining the network intrusion threat analysis results of the external device on the vehicle output by the large language model, the method further includes: if the network intrusion threat analysis results indicate that the external device has network attack behavior on the vehicle, then the real-time traffic data and the corresponding network intrusion threat analysis results are updated to the historical knowledge base.
[0156] In this embodiment, the real-time traffic data and corresponding network intrusion threat analysis results continuously collected during vehicle operation are updated to the historical knowledge base, expanding the sample data volume of the historical knowledge base. Through continuous data feedback, performance is optimized, and continuous optimization of the RAG framework is achieved.
[0157] In this embodiment, the system performance and large language model effectiveness are monitored in real time, and each module is optimized through a feedback loop to improve the overall detection accuracy. Technically, Prometheus + Grafana is used to collect and display core system metrics (e.g., QPS for traffic collection, vector retrieval latency, and model inference time); combined with the ELK Stack, end-to-end log tracing and anomaly analysis are achieved. After manual review of feedback cases, real-time traffic data and corresponding network intrusion threat analysis results are transmitted via a Kafka message queue, triggering automated updates to the historical knowledge base; the Airflow workflow scheduler is used to automatically execute optimization tasks such as adjusting large language model prompts and supplementing knowledge based on monitoring data. Prometheus + Grafana is a widely used open-source toolkit for monitoring and visualization. Working together, they provide a complete solution from data collection, storage, querying to visualization. The ELK Stack is an open-source log management and data analysis platform, primarily used for real-time collection, storage, search, analysis, and visualization of large-scale data (such as logs and metrics), and is widely used in operations monitoring, security analysis, and business intelligence. Kafka message queues are one of the core functionalities of Apache Kafka. It is a distributed, high-throughput, persistent publish / subscribe messaging system designed for real-time data stream processing. Apache Airflow is an open-source workflow scheduler and task orchestration platform designed for automating complex data processing workflows. It allows task dependencies to be defined using Python code and provides powerful scheduling, monitoring, and error handling capabilities, making it widely used in data engineering, machine learning model training, and other scenarios.
[0158] In one embodiment, after obtaining the network intrusion threat analysis results of the external device on the vehicle from the output of the large language model, the network intrusion threat analysis results are transformed into a visual report and decision-making suggestions to assist the security team in quickly understanding the threat and executing the response. Optionally, Superset is used to build an interactive dashboard, combined with pyecharts and D3.js to generate dynamic visual charts; structured document reports are generated through Python-docx to transform the technical analysis results into natural language descriptions; and SIEM (such as ELK Stack, Splunk) or SOAR (such as TheHive, Cortex XSOAR) platforms are integrated to achieve automated display, alerting, and response handling of threat data. Apache Superset is an open-source data visualization and business intelligence (BI) platform developed by Airbnb and donated to the Apache Software Foundation in 2017. It helps users explore, analyze, and visualize data through an intuitive interface, supporting various application scenarios from simple reports to complex dashboards. Pyecharts is an open-source data visualization library based on Python that generates interactive, dynamic, and beautiful charts through Python code. D3.js (Data-Driven Documents) is an open-source data visualization library based on JavaScript, focusing on dynamically generating and manipulating web documents through data-driven methods to achieve highly customized interactive visualization effects. Python-docx is a third-party Python library for manipulating Microsoft Word documents (.docx format). It allows developers to programmatically create, modify, and extract content from Word documents without manually opening the Word application. SIEM (Security Information and Event Management) is a comprehensive cybersecurity technology used to collect, analyze, correlate, and respond to security incident data from multiple sources in real time to improve enterprise threat detection and response capabilities. Its core components include Security Information Management (SIM) and Security Event Management (SEM), combined with log management, real-time monitoring, and threat intelligence integration to form a unified security operations platform. ELK Stack is an open-source SIEM solution, while Splunk is a commercial SIEM platform. SOAR (Security Orchestration, Automation, and Response) is an integrated cybersecurity technology platform designed to improve the efficiency and accuracy of security incident response through automated workflows and intelligent orchestration. TheHive is an open-source SOAR tool, while Cortex XSOAR is a commercial SOAR platform.
[0159] For example, taking historical sample data including historical attack case 1 and historical normal sample 1, and real-time traffic data including the sample to be detected, the generated visualization report is as follows:
[0160]
[0161]
[0162]
[0163] This application acquires real-time traffic data during data interaction between a vehicle and external devices. From various historical sample data in a historical knowledge base, it acquires the first historical sample data corresponding to the real-time traffic data, whereby the historical sample data includes sample data generated during at least one historical data interaction between the vehicle and external devices. The real-time traffic data and historical sample data are input into a large language model to obtain the network intrusion threat analysis results of external devices against the vehicle output by the large language model. In the above process, a retrieval-enhanced large language model architecture is formed based on the historical knowledge base. Based on the real-time traffic data and the first historical sample data in the historical knowledge base, the large language model is guided to analyze the real-time threat of external devices to vehicle network intrusion, improving the intelligence level of vehicle network intrusion analysis. Even in complex and ever-changing network environments, it can still efficiently and accurately analyze the network intrusion threat of external devices against the vehicle, thus improving vehicle security.
[0164] Exemplary vehicle
[0165] Accordingly, this application also provides a vehicle that, when interacting with external devices, analyzes real-time traffic data during the data interaction process using the data analysis method provided in any of the above embodiments.
[0166] The vehicle provided in this embodiment belongs to the same application concept as the data analysis method provided in the above embodiments of this application. It can be used with the data analysis method provided in any of the above embodiments of this application and has the corresponding beneficial effects of the execution method. Technical details not described in detail in this embodiment can be found in the specific processing content of the data analysis method provided in the above embodiments of this application, and will not be repeated here.
[0167] Exemplary device
[0168] Accordingly, embodiments of this application also provide a data analysis device, such as... Figure 2 As shown, the device may include:
[0169] The real-time data acquisition module 201 is used to acquire real-time traffic data during the data interaction process between the vehicle and external devices;
[0170] The historical data acquisition module 202 is used to acquire the first historical sample data corresponding to the real-time traffic data from various historical sample data in the historical knowledge base. The historical sample data includes sample data generated at least once in history when the vehicle interacted with external devices.
[0171] The data analysis module 203 is used to input real-time traffic data and historical sample data into the large language model to obtain the network intrusion threat analysis results of external devices to the vehicle output by the large language model.
[0172] In one embodiment, real-time traffic data includes a real-time traffic vector, and historical sample data includes a historical sample vector.
[0173] The real-time data acquisition module 201 is used to collect raw traffic data during the real-time data interaction between the vehicle and external devices; based on the raw traffic data, it performs vectorization processing to obtain the real-time traffic vector corresponding to the raw traffic data;
[0174] The historical data acquisition module 202 is used to calculate the similarity between each historical sample vector in the historical knowledge base and the real-time traffic vector; based on the similarity, the first historical sample data is obtained.
[0175] In one embodiment, the historical sample data includes attack sample data and normal sample data. The attack sample data is sample data of external devices launching network attacks against the vehicle, and the normal sample data is sample data of external devices conducting normal data interactions with the vehicle.
[0176] The historical data acquisition module 202 is used to match the first attack sample data and the first normal sample data corresponding to the real-time traffic data in various historical sample data of the historical knowledge base.
[0177] In one embodiment, the data analysis module 203 is used to fill real-time traffic data and historical sample data into a preset prompt word template, wherein the prompt word template includes chained prompt information; and input the filled prompt word template into a large language model to obtain the network intrusion threat analysis results of external devices to the vehicle output by the large language model.
[0178] In one embodiment, the data analysis device further includes a knowledge update module, which is used to update the real-time traffic data and the corresponding network intrusion threat analysis results to the historical knowledge base if the network intrusion threat analysis results indicate that the external device has network attack behavior against the vehicle.
[0179] In one embodiment, the real-time data acquisition module 201 is used to preprocess the raw traffic data, wherein the preprocessing includes data filtering, structuring processing and / or feature extraction; and to vectorize the preprocessed raw traffic data to obtain a real-time traffic vector, wherein the real-time traffic vector and the historical sample vector have the same vector dimension.
[0180] The data analysis apparatus provided in this embodiment belongs to the same concept as the data analysis method provided in the above embodiments of this application. It can execute the data analysis method provided in any of the above embodiments of this application and has the corresponding functional modules and beneficial effects of the method. Technical details not described in detail in this embodiment can be found in the specific processing content of the data analysis method provided in the above embodiments of this application, and will not be repeated here.
[0181] Exemplary electronic devices
[0182] This application also provides an electronic device, such as... Figure 3 As shown, the electronic device includes a memory 300 and a processor 301.
[0183] The memory 300 is connected to the processor 301 and is used to store programs.
[0184] The processor 301 is used to implement the data analysis method in the above embodiments by running the program stored in the memory 300.
[0185] Specifically, the aforementioned electronic device may also include: a communication interface 302, an input device 303, an output device 304, and a bus 305.
[0186] The processor 301, memory 300, communication interface 302, input device 303, and output device 304 are interconnected via a bus. Among them:
[0187] Bus 305 may include a pathway for transmitting information between various components of a computer system.
[0188] Processor 301 can be a general-purpose processor, such as a general-purpose central processing unit (CPU), a microprocessor, etc., or an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of the program of the present invention. It can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0189] Processor 301 may include a main processor, as well as a baseband chip, modem, etc.
[0190] The memory 300 stores a program that executes the technical solution of this invention, and may also store an operating system and other key business functions. Specifically, the program may include program code, which includes computer operation instructions. More specifically, the memory 300 may include read-only memory (ROM), other types of static storage devices capable of storing static information and instructions, random access memory (RAM), other types of dynamic storage devices capable of storing information and instructions, disk storage, flash memory, etc.
[0191] Input device 303 may include a device for receiving data and information input by the user, such as a keyboard, mouse, camera, scanner, light pen, voice input device, touch screen, pedometer, or gravity sensor.
[0192] Output device 304 may include devices that allow information to be output to a user, such as a display screen, printer, speaker, etc.
[0193] The communication interface 302 may include a device that uses any transceiver to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Network (WLAN), etc.
[0194] The processor 301 executes the program stored in the memory 300 and calls other devices, which can be used to implement the various steps of the data analysis method provided in the above embodiments of this application.
[0195] Exemplary computer program products and storage media
[0196] In addition to the methods and devices described above, embodiments of this application may also be computer program products, which include computer program instructions that, when executed by a processor, cause the processor to perform the steps in the data analysis method described in the embodiments of this application.
[0197] The computer program product can be written in any combination of one or more programming languages to perform the operations of the embodiments of this application. The programming languages include object-oriented programming languages such as Java and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0198] Furthermore, embodiments of this application may also be storage media storing a computer program, which is executed by a processor of the steps in the data analysis method described in the embodiments of this application.
[0199] For the foregoing method embodiments, in order to simplify the description, they are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, because according to this application, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0200] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For apparatus embodiments, since they are basically similar to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0201] The steps in the methods of the various embodiments of this application can be adjusted, merged, or deleted in order according to actual needs, and the technical features described in each embodiment can be replaced or combined.
[0202] The modules and sub-modules in the devices and terminals provided in the various embodiments of this application can be merged, divided, and deleted according to actual needs.
[0203] It should be understood that the disclosed terminals, devices, and methods can be implemented in other ways, given the several embodiments provided in this application. For example, the terminal embodiments described above are merely illustrative. For instance, the division of modules or sub-modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple sub-modules or modules may be combined or integrated into another module, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or modules, and may be electrical, mechanical, or other forms.
[0204] The modules or submodules described as separate components may or may not be physically separate. The components that constitute a module or submodule may or may not be physical modules or submodules; that is, they may be located in one place or distributed across multiple network modules or submodules. Some or all of the modules or submodules can be selected to achieve the purpose of this embodiment's solution, depending on actual needs.
[0205] Furthermore, the functional modules or sub-modules in the various embodiments of this application can be integrated into one processing module, or each module or sub-module can exist physically separately, or two or more modules or sub-modules can be integrated into one module. The integrated modules or sub-modules described above can be implemented in hardware or in the form of software functional modules or sub-modules.
[0206] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0207] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software unit executed by a processor, or a combination of both. The software unit can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0208] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0209] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A data analysis method, characterized by, The method comprises: obtaining real-time traffic data in a process of data interaction between a vehicle and an external device; obtaining first historical sample data corresponding to the real-time traffic data from each historical sample data in a historical knowledge base, wherein the historical sample data comprises sample data generated respectively when the vehicle and the external device perform data interaction at least once in history; inputting the real-time traffic data and the historical sample data into a large language model to obtain a network intrusion threat analysis result of the external device to the vehicle output by the large language model.
2. The data analysis method of claim 1, wherein, The real-time traffic data comprises a real-time traffic vector, and the historical sample data comprises a historical sample vector. The method of obtaining real-time traffic data in a process of data interaction between a vehicle and an external device comprises: collecting original traffic data in a process of real-time data interaction between the vehicle and the external device; performing vectorization processing based on the original traffic data to obtain a real-time traffic vector corresponding to the original traffic data. The method of obtaining first historical sample data corresponding to the real-time traffic data from each historical sample data in a historical knowledge base comprises: calculating a similarity between each historical sample vector in the historical knowledge base and the real-time traffic vector; obtaining the first historical sample data based on the similarity.
3. The data analysis method of claim 1, wherein, The historical sample data comprises attack sample data and normal sample data, the attack sample data is sample data of network attack of the external device to the vehicle, and the normal sample data set is sample data of normal data interaction between the external device and the vehicle. The method of obtaining first historical sample data corresponding to the real-time traffic data from each historical sample data in a historical knowledge base comprises: matching first attack sample data and first normal sample data corresponding to the real-time traffic data from each historical sample data in the historical knowledge base.
4. The data analysis method of claim 1, wherein, The method of inputting the real-time traffic data and the historical sample data into a large language model to obtain a network intrusion threat analysis result of the external device to the vehicle output by the large language model comprises: filling the real-time traffic data and the historical sample data into a preset prompt word template, wherein the prompt word template comprises chained prompt information; inputting the prompt word template after the filling processing into the large language model to obtain the network intrusion threat analysis result of the external device to the vehicle output by the large language model.
5. The data analysis method of claim 1, wherein, After obtaining the network intrusion threat analysis result of the external device to the vehicle output by the large language model, the method further comprises: if the network intrusion threat analysis result represents that the external device has network attack behavior to the vehicle, updating the real-time traffic data and the corresponding network intrusion threat analysis result to the historical knowledge base.
6. The data analysis method of claim 2, wherein, The method of performing vectorization processing based on the original traffic data to obtain a real-time traffic vector corresponding to the original traffic data comprises: performing preprocessing on the original traffic data, wherein the preprocessing comprises data filtering, structured processing and / or feature extraction; The original traffic data after preprocessing is vectorized to obtain the real-time traffic vector, wherein the vector dimensions of the real-time traffic vector and the historical sample vector are the same.
7. A vehicle characterized by comprising: When the vehicle interacts with the external device, the real-time traffic data in the data interaction process is analyzed by the data analysis method of any one of claims 1-6.
8. A data analysis device, characterized by The method comprises: a real-time data acquisition module for acquiring real-time traffic data in the data interaction process of the vehicle and the external device; a historical data acquisition module for acquiring first historical sample data corresponding to the real-time traffic data from each historical sample data in a historical knowledge base, wherein the historical sample data includes sample data generated respectively when the vehicle and the external device interacted with each other at least once in the past; a data analysis module for inputting the real-time traffic data and the historical sample data into a large language model to obtain a network intrusion threat analysis result of the external device to the vehicle output by the large language model.
9. An electronic device, comprising: The method comprises: a memory and a processor; the memory is connected with the processor and is used for storing programs; the processor is used for realizing the data analysis method of any one of claims 1-6 by running the programs in the memory.
10. A computer program product, characterised in that, The computer program instructions make the processor execute the data analysis method of any one of claims 1-6 when the computer program instructions are run by the processor.