Vehicle-mounted network security threat sensing system and method based on edge and cloud collaboration
By using an edge and cloud-integrated vehicle network security threat perception system, vehicle data is collected and processed in real time, hierarchical response decisions are made, and global analysis is performed in the cloud. This solves the problems of response latency and network bandwidth pressure in existing technologies, and achieves efficient and real-time security protection.
Patent Information
- Application Number
- CN202511432664.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-09
- Publication Date
- 2025-11-18
AI Technical Summary
Existing fleet-level network security monitoring technologies suffer from high response latency, high network bandwidth pressure, high communication costs, heavy cloud computing load, and a lack of local intelligence and collaboration mechanisms. They cannot meet the real-time response requirements of vehicle control systems and their protection capabilities drop sharply when the network is interrupted.
An edge- and cloud-based vehicle network security threat perception system is adopted. It collects multimodal data in real time at the edge layer for preprocessing and feature extraction, calculates threat confidence scores for graded response decisions, and generates threat metadata. Combined with global correlation analysis and defense system upgrades at the cloud platform layer, it realizes real-time edge response, in-depth cloud analysis, and bidirectional knowledge flow.
It greatly improves real-time performance, eliminates response delays, significantly reduces network bandwidth pressure, lowers communication costs, optimizes cloud computing resource load, enhances edge intelligence and group collaborative intelligence, and ensures all-weather, all-road-condition safety protection capabilities.
Smart Images

Figure CN120979820A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of vehicle network security, in particular to a vehicle network security threat perception system and method based on edge and cloud cooperation. BACKGROUND
[0002] The existing vehicle fleet-level network security monitoring technology is a scheme based on a centralized cloud platform. The scheme regards all vehicles as independent terminals, collects CAN bus, ECU state and other original security data by deploying a lightweight agent on the vehicle end, and relies on a cellular network to upload all the data to the central cloud platform continuously. In the cloud, relying on powerful computing and storage resources, massive data collected is analyzed and threat detected in a centralized manner by using big data, stream processing and complex machine learning models, and once a threat is found, an instruction is issued to the vehicle to execute a response.
[0003] However, the existing scheme has inherent defects. First, the long closed loop of "perception, upload, cloud computing and issuance" results in extremely high response delay, which cannot meet the stringent requirements of vehicle control systems for millisecond-level real-time response. Second, the transmission of all original data causes huge network bandwidth pressure and high cost, and also makes the cloud computing load too heavy and inefficient. In addition, the vehicle end lacks local intelligence, the protection capability drops sharply when the network is interrupted, and there is a lack of effective cooperation mechanism between vehicles and infrastructure, which cannot utilize group intelligence for rapid joint defense and control of local threats. SUMMARY
[0004] The technical problem to be solved by the present application is that the traditional vehicle network security threat perception system and method have high response delay, large network bandwidth pressure, high communication cost, heavy cloud computing load, low efficiency, lack of local intelligence and cooperation mechanism. To this end, the present application provides a vehicle network security threat perception system and method based on edge and cloud cooperation.
[0005] The technical solution adopted by the present application to solve the technical problem is: On the one hand, the present application provides a vehicle network security threat perception method based on edge and cloud cooperation, comprising the following steps: Step S1, collecting vehicle multi-modal data through an edge layer; Step S2, preprocessing the vehicle multi-modal data; Step S3, extracting features from the preprocessed vehicle multi-modal data to obtain a high-dimensional feature vector; Step S4, calculating a threat confidence score based on the high-dimensional feature vector through a multi-modal decision fusion algorithm; Step S5, making a hierarchical response decision based on the threat confidence score and a pre-defined response strategy library, and generating hierarchical response data; Step S6, threat metadata extraction based on hierarchical response data, and sending threat metadata to the cloud platform layer and at least one other collaborative node; Step S7, global correlation analysis based on threat metadata, obtaining global threat intelligence, and upgrading the defense system based on threat metadata; Step S8, based on global threat intelligence and the upgraded defense system, edge layer update, and then jump to step S1.
[0006] Further, the vehicle multi-modal data includes system-level data of the vehicle electronic control unit and network-level data of the vehicle-mounted network.
[0007] Further, the high-dimensional feature vector includes vehicle electronic control unit instruction frequency, network traffic entropy value, message interval time variance, and operation code sequence.
[0008] Further, the step S4 includes: Step S41, rule base matching, baseline model comparison, and machine learning inference on the high-dimensional feature vector, respectively obtaining rule matching scores, baseline deviation scores, and potential threat probability scores; Step S42, based on decision fusion logic, fusing the rule matching scores, baseline deviation scores, and potential threat probability scores to obtain threat confidence scores.
[0009] Further, in step S5, based on threat confidence scores and a pre-defined response strategy library, hierarchical response decisions are made, including: When the threat confidence score is ≥0.8, it is a high-scoring threat, and local response execution is performed; When 0.5≤threat confidence score<0.8, it is a medium-scoring threat, and a restrictive strategy is implemented; When the threat confidence score is <0.5, it is a low-scoring threat, and no interception operation is performed.
[0010] Further, the at least one other collaborative node includes a roadside unit and other vehicles.
[0011] Further, the threat metadata includes event identification, timestamp, vehicle identification code, latitude and longitude coordinates, threat type, threat confidence score, feature vector summary, electronic control unit identifier, and response action log.
[0012] Further, in step S7, the defense system is upgraded based on threat metadata, including: Based on threat metadata, threat detection model training and optimization are performed, and the trained and optimized threat detection model is subjected to lightweight processing; Updating an attack signature rule library based on threat metadata; Updating a response strategy library based on threat metadata.
[0013] In a second aspect, the present application provides an edge and cloud collaborative vehicle network security threat perception system, comprising an edge layer, a network transmission layer and a cloud platform layer. The edge layer is configured to collect vehicle multi-modal data, pre-process the vehicle multi-modal data, extract features from the pre-processed vehicle multi-modal data to obtain a high-dimensional feature vector, calculate a threat confidence score based on the high-dimensional feature vector, make a hierarchical response decision based on the threat confidence score, generate hierarchical response data, and extract threat metadata based on the hierarchical response data, and send the threat metadata to the network transmission layer. The network transmission layer is configured to receive the threat metadata sent by the edge layer and forward it to the cloud platform layer, and receive the global threat intelligence and the updated defense system sent by the cloud platform layer and forward them to the edge layer. The cloud platform layer is configured to receive the threat metadata sent by the network transmission layer, perform global correlation analysis based on the threat metadata to obtain global threat intelligence, and upgrade the defense system based on the threat metadata, and then send the global threat intelligence and the updated defense system to the network transmission layer.
[0014] Further, the cloud platform layer comprises a big data storage center, a global threat analysis engine and an AI model training platform. The big data storage center is configured to store the high-dimensional feature vectors and threat metadata from all vehicles. The global threat analysis engine is configured to perform global correlation analysis based on the threat metadata. The AI model training platform is configured to upgrade the defense system based on the threat metadata.
[0015] In a third aspect, the present application further provides an electronic device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the computer program is executed by the processor to implement the above-mentioned edge and cloud collaborative vehicle network security threat perception method.
[0016] In a fourth aspect, the present application further provides a readable storage medium, wherein when the instructions in the storage medium are executed by the processor of an electronic device, the electronic device can execute the above-mentioned edge and cloud collaborative vehicle network security threat perception method.
[0017] The present application has the following advantages: 1. Greatly improve real-time performance and eliminate response delay: By deploying a lightweight real-time detection engine on the vehicle edge side, attacks on critical systems such as vehicle brakes and steering can complete the "perception, analysis, response" closed loop locally, reducing the response time from seconds to milliseconds, completely avoiding the serious consequences caused by network transmission and cloud processing delay, and meeting the extreme requirements of vehicle control safety for real-time performance.
[0018] 2. Significantly reduce network bandwidth pressure and communication costs: The traditional full-volume raw data upload mode is overturned, intelligent preprocessing and feature extraction are performed at the edge layer, only a small amount of high-value information such as feature vectors and threat metadata is uploaded to the cloud, reducing invalid data transmission by more than 95%, greatly relieving network bandwidth pressure, making communication costs controllable when deploying large-scale vehicle fleets, and significantly enhancing system scalability.
[0019] 3. Optimize cloud computing resource load and improve analysis efficiency and value: The cloud no longer needs to process massive amounts of raw data without distinction, but focuses on global correlation analysis, deep mining, and complex AI model training of high-value feature information reported by the edge layer, which frees the cloud computing resources from heavy basic data processing and focuses on intelligent generation and knowledge refinement of higher value information, thereby greatly improving analysis efficiency and input-output ratio.
[0020] 4. Enhance edge intelligence and ensure security protection capability in offline and weak network environments: Give the vehicle edge side independent analysis and decision-making capabilities, so it is no longer a "dumb" terminal dependent on the network. Even in the case of network interruption in tunnels, remote areas, and other situations, vehicles can still rely on local lightweight real-time detection engines to maintain high-level security threat perception and response capabilities, achieving continuous security protection in all-weather and all-road conditions, and solving the single-point failure problem caused by network dependency in traditional solutions.
[0021] 5. Realize group collaborative intelligence and build an active defense system: Through the security communication protocol between vehicles and roadside units, a distributed collaborative perception network is established. Any local threat discovered by a single node can be quickly broadcasted and shared within the group, enabling regional instant warning and collaborative response, thereby effectively dealing with new and rapidly spreading network attacks and building a more powerful and flexible active defense system than a single node. BRIEF DESCRIPTION OF DRAWINGS
[0022] The application will be further described below in conjunction with the drawings and examples.
[0023] Figure 1 is a flowchart of the vehicle-mounted network security threat perception method based on edge and cloud collaboration provided by Embodiment One of the application; Figure 2 Method flow chart involved in step S4 provided by the embodiment one of the present application; Figure 3 Method flow chart involved in step S5 provided by the embodiment one of the present application; Figure 4 Method flow chart involved in step S7 provided by the embodiment one of the present application; Figure 5 Overall architecture diagram of the vehicle-mounted network security threat perception system based on edge and cloud collaboration provided by the embodiment two of the present application; Figure 6 Principle block diagram of the vehicle-mounted network security threat perception system based on edge and cloud collaboration provided by the embodiment two of the present application; Figure 7 Principle block diagram of the vehicle-mounted edge security device provided by the embodiment two of the present application; Figure 8 Partial block diagram of the electronic device provided by the embodiment two of the present application. DETAILED DESCRIPTION
[0024] Before the example embodiments are discussed in more detail, it should be mentioned that some of the example embodiments are described as processes or methods depicted as flow charts. Although the process is described herein as sequential process, many of the operations can be performed in parallel, concurrently or at the same time. In addition, the order of the operations can be re-arranged. The process can be terminated when its operations are completed, but can also have additional steps not included in the figure. The process can correspond to a method, function, procedure, subroutine, subprogram, etc.
[0025] It should be understood that, although the terms first, second, etc. can be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and, similarly, a second element could be termed a first element, without departing from the scope of example embodiments. The term and / or as used herein includes any and all combinations of one or more of the associated listed items.
[0026] The present application will now be described in detail in connection with the accompanying drawings. The drawings are schematic representations of the present application, which only show the essential structure of the present application, and thus only show the components related to the present application.
[0027] For the purpose of understanding, the inventive concept is set forth in general terms as follows before the embodiments of the present application are described in detail: The vehicle-mounted network security threat perception system based on edge and cloud cooperation provided by the application is composed of a cloud platform layer, a network transmission layer and an edge layer from top to bottom, which distributes computing intelligence and decision-making ability on demand to form an efficient cooperative defense system.
[0028] The edge layer at the bottom is the perception and immediate response unit of the system, which is composed of vehicle-mounted edge security devices embedded in each vehicle and edge computing nodes deployed in roadside units. It is not only responsible for real-time collection, preprocessing and feature extraction of local data, but also can use lightweight real-time detection engine to perform millisecond-level autonomous interception and response on high-score threats. Through communication between vehicles and between vehicles and infrastructure (roadside units), local threat intelligence sharing and cooperative defense are realized, greatly improving real-time performance.
[0029] The network transmission layer, as the information hub of the system, mainly relies on high-speed cellular networks, but its key role has fundamentally changed. Instead of transmitting raw data floods, it efficiently carries the "knowledge" flowing between the edge layer and the cloud platform layer, that is, the lightweight feature vectors and threat metadata refined by the edge layer go up, and the updated threat detection models and global threat intelligence issued by the cloud platform layer go down, thereby completely solving the bottleneck of huge bandwidth pressure in traditional solutions.
[0030] The cloud platform layer at the top is the brain and knowledge base of the system. It is relieved from heavy raw data processing and focuses on its global vision and powerful computing power advantages. Through a big data storage center, a global threat analysis engine and an AI model training platform, it performs global correlation analysis and complex model training and iteration on the gathered high-value information, and continuously issues evolved detection capabilities to the edge layer, so that the security protection level of the entire vehicle fleet can be continuously evolved.
[0031] Finally, the three levels are tightly coupled to realize a virtuous cycle of "edge real-time disposal, cloud deep analysis, knowledge bidirectional flow, and global cooperative perception", perfectly solving the inherent defects of centralized architecture such as response delay, bandwidth pressure, single-point vulnerability, etc.
[0032] Embodiment one As shown in Figure 1 The embodiment provides a vehicle-mounted network security threat perception method based on edge and cloud cooperation, which comprises the following steps: Step S1, collecting vehicle multi-modal data through the edge layer.
[0033] In some possible implementation manners, the vehicle-mounted edge security device in the edge layer collects system-level data of each vehicle electronic control unit in real time through a vehicle internal bus, the vehicle internal bus includes CAN FD, LIN, Ethernet, and the like, and the system-level data includes state information, instruction logs, memory occupancy, CPU load, and the like. The vehicle-mounted edge security device collects network-level data of a vehicle-mounted network through a network sniffing module, the vehicle-mounted network includes an Ethernet or a traditional bus network, and the network-level data includes communication traffic, protocol packets (such as Some / IP, DoIP), source / destination IP, and port numbers, and the like.
[0034] In some possible implementation manners, the vehicle multi-modal data further includes log streams of a vehicle firewall and an intrusion detection system (IDS).
[0035] Step S2, pre-processing is performed on the vehicle multi-modal data.
[0036] In some possible implementation manners, the pre-processing includes cleaning and standardizing the vehicle multi-modal data, specifically: parsing and field alignment are performed on unstructured logs; sliding window segmentation and normalization processing are performed on time series data (such as CAN messages); periodic broadcast messages (such as heartbeat packets) irrelevant to safety, invalid data, and noise are filtered. Through the above pre-processing methods, the data dimension can be effectively reduced.
[0037] Step S3, feature extraction is performed on the pre-processed vehicle multi-modal data, to obtain a high-dimensional feature vector.
[0038] In some possible implementation manners, the high-dimensional feature vector includes vehicle electronic control unit instruction occurrence frequency, network traffic entropy value, message interval time variance, and operation code sequence. The high-dimensional feature vector is generated through the following methods.
[0039] Specifically, the occurrence frequency of a specific vehicle electronic control unit instruction in a time window is calculated, to detect denial of service (DoS) attacks and instruction flooding anomalies. The calculation formula of the vehicle electronic control unit instruction occurrence frequency is as follows: frequency = instruction occurrence number / time window length.
[0040] Specifically, the network traffic entropy value is calculated, to discover communication mode anomalies such as scanning and probing. The calculation formula of the network traffic entropy value is as follows: wherein, represents the network traffic entropy value; represents a variable being counted; represents a specific value of the variable , for example, a specific source IP address; represents the frequency of occurrence of the feature .
[0041] Specifically, the message interval time variance is calculated to identify timing anomalies such as periodic communication being disturbed or injected. The formula for calculating the message interval time variance is as follows: , wherein, is the message interval time variance; is the arrival interval time of the i-th message; is the average value of all message intervals; is the sample number of message intervals.
[0042] Specifically, the opcode sequence is extracted, and subsequent sequence pattern matching is performed to identify illegal instruction sequences or control flow hijacking attacks.
[0043] Step S4, based on the high-dimensional feature vector, the threat confidence score is calculated by a multi-modal decision fusion algorithm.
[0044] Specifically, the generated high-dimensional feature vector is input in real time to the lightweight real-time detection engine of the edge layer. Exemplarily, the lightweight real-time detection engine is a pruned and quantized neural network model or a gradient boosting decision tree model. The lightweight real-time detection engine comprehensively judges the threat level by a multi-modal decision fusion algorithm. The vehicle edge side is given independent analysis and decision-making ability, so it is no longer a "dumb" terminal that relies on the network. Even in the case of network interruption in tunnels, remote areas, etc., the vehicle can still rely on the local lightweight real-time detection engine to maintain high-level security threat perception and response capability, realizing continuous security protection in all-weather and all-road conditions, and solving the single-point failure problem caused by network dependence in traditional solutions.
[0045] In some feasible embodiments, in combination with Figure 2 , step S4 includes: Step S41, the high-dimensional feature vector is subjected to rule library matching, baseline model comparison and machine learning inference, respectively obtaining a rule matching score, a baseline deviation score and a potential threat probability score.
[0046] Step S42, the rule matching score, the baseline deviation score and the potential threat probability score are fused to obtain a threat confidence score. The formula for calculating the threat confidence score is: .
[0047] Specifically, the rule library matching is to accurately match the feature vector with the known attack signatures in the local rule library. If the matching is successful, a high threat confidence score (such as 0.9 or above) is directly assigned.
[0048] Specifically, the baseline model comparison is to calculate the deviation degree of the current feature vector from the normal behavior baseline model, the greater the deviation degree, the more abnormal it represents, and the higher the baseline deviation score, wherein the normal behavior baseline model is usually constructed based on historical statistics or One-Class SVM model.
[0049] Specifically, the machine learning inference is to input the feature vector into a lightweight machine learning model to obtain a potential threat probability score based on the learning model, which is conducive to evaluating and identifying possible security risks. The lightweight machine learning model refers to a model processed by optimization techniques such as pruning, quantization or distillation to adapt to limited computing resources on the edge side. Typical representatives include but are not limited to: lightweight gradient boosting decision trees (such as LightGBM, XGBoost), structured reduced neural networks (such as pruned multi-layer perceptron MLP, one-dimensional convolutional neural network 1D-CNN), and efficient models designed for edge devices (such as variants of MobileNet, SqueezeNet), etc. These models have the common characteristics of small model size, fast inference speed and low computing overhead while ensuring high detection accuracy, perfectly fitting the running environment of the vehicle-mounted edge security device.
[0050] Specifically, in this embodiment, the results of the three dimensions of rule matching score, baseline deviation score and potential threat probability score are fused by an efficient decision fusion logic to output a comprehensive threat confidence score (0-1 score). The design principle of this fusion strategy is: Prioritize deterministic threats: use the max (rule matching score, potential threat probability score) operation, which aims to give priority to the highest threat indication given by the two detection methods. This ensures that whether it is a known attack based on signature (high rule matching score) or a new suspicious pattern identified by machine learning model (high potential threat probability score), as long as either method gives a high risk signal, the system will give high attention, so as to give priority to known threat response while not missing potential unknown threats.
[0051] Combine behavior anomaly context: multiply the above maximum value with the "baseline deviation score", which aims to bind the degree of threat certainty with the overall degree of abnormality of the current system behavior. Even if rule matching or machine learning inference gives a higher threat score, if the deviation degree of the current system behavior from the normal baseline is small (low baseline deviation score), the comprehensive confidence will be appropriately suppressed, which helps to reduce false positives. On the contrary, if the behavior itself is significantly abnormal (high baseline deviation score), the final threat confidence will be amplified, so as to quickly respond to real abnormal behavior.
[0052] The calculation formula realizes effective cooperation of multi-modal detection results with low calculation overhead, ensures that known attacks can be quickly responded to, unknown abnormal behaviors can be effectively detected, and false alarm risk is reduced through context awareness, and is very suitable for resource-limited edge real-time detection scenarios. In other embodiments, a weighted average fusion method can also be used according to specific needs.
[0053] Step S5, based on the threat confidence score and the pre-defined response strategy library, a hierarchical response decision is made, and hierarchical response data is generated. That is, while performing the response action, the system triggers the corresponding data recording process to provide data basis for subsequent threat metadata extraction and cloud uploading.
[0054] In some possible embodiments, in combination with Figure 3 As shown in the figure, step S5 includes: When the threat confidence score is a high threat score (threat confidence score ≥ 0.8), it is determined as a high-risk attack (such as remote brake command injection), and a local millisecond-level response closed loop is triggered immediately without waiting for cloud instructions. The closed loop of “perception, analysis, and response” is directly completed locally, the response time is shortened from seconds to milliseconds, the serious consequences caused by network transmission and cloud processing delay are completely avoided, and the extreme requirement of real-time performance for vehicle control safety is met. The response actions include: sending instructions to the gateway ECU through the hardware security module located in the vehicle-mounted edge security device to physically isolate the broken network segment; terminating malicious processes; issuing the highest level of audible and visual warnings to the driver and recommending to take over the control.
[0055] While performing the local response, the system quickly captures and saves the key context information triggering the alarm, such as the feature vector at the moment before the alarm is triggered, and the related ECU state, which will be used to generate threat metadata.
[0056] When the threat confidence score is a medium threat score (0.5 ≤ threat confidence score < 0.8), it is determined as suspicious behavior, and a deep diagnosis mode is started to implement a restrictive strategy, such as limiting some non-critical functions, such as in-vehicle atmosphere lights, video playback, and the like.
[0057] While implementing the restrictive strategy, the system deliberately records detailed and multi-dimensional context data for deep analysis, which specifically includes original data (such as original CAN message sequence in a specific time window) used to generate the feature vector extracted from the pre-processed data, and more extensive ECU state snapshots and network traffic mirroring. These data are temporarily cached and prepared to be uploaded to the cloud for analysis.
[0058] When the threat confidence score is low (threat confidence score < 0.5), it is usually unknown abnormality or false alarm, only recorded in the local log, no special threat metadata extraction process is triggered, and no interception operation is performed to save resources.
[0059] Step S6, threat metadata extraction is performed based on the hierarchical response data, and the threat metadata is sent to the cloud platform layer and at least one other collaborative node.
[0060] That is, for the medium and high threat events that trigger data recording, the edge layer performs threat metadata extraction on the recorded hierarchical response data. It overturns the traditional mode of uploading raw data in full, and through intelligent preprocessing and feature extraction in the edge layer, only the refined feature vector and a small amount of high-value information such as threat metadata are uploaded to the cloud, reducing more than 95% of invalid data transmission, greatly relieving the network bandwidth pressure, making the communication cost controllable when deploying a large-scale vehicle fleet, and significantly enhancing the system scalability.
[0061] In some possible embodiments, the threat metadata is a lightweight "knowledge" unit, usually including event identification, timestamp, vehicle identification code, latitude and longitude coordinates, threat type, threat confidence score, triggered feature vector summary (hash value), associated electronic control unit identifier, response action log, and key evidence (such as abnormal instruction sequence fragments) abstracted from the recorded detailed context.
[0062] In some possible embodiments, the at least one other collaborative node includes a roadside unit and other vehicles. For example, when the vehicle confirms that it is under attack (high threat), the on-board unit will immediately send threat metadata (such as attack feature fingerprint, attack source identifier, recommended mitigation measures) to surrounding other vehicles and roadside units in the form of broadcast or multicast through direct communication protocols such as DSRC or C-V2X. After receiving the threat metadata, the surrounding other vehicles can update the local detection engine's rule base as prior knowledge without the intervention of the cloud, achieving immunity or early protection against similar attacks. The roadside unit, as a regional information hub, aggregates, de-duplicates, and forwards the threat metadata to expand the collaborative protection range. Through the secure communication protocol between vehicles and roadside units, a distributed collaborative perception network is established, realizing group collaborative intelligence, which can effectively deal with new and rapidly spreading network attacks, and building a more powerful and flexible active defense system than a single node using group intelligence.
[0063] In some possible embodiments, when uploading to the cloud platform layer, the upload list is intelligently scheduled according to the current network status (such as 5G / 4G signal strength) and threat metadata priority to ensure that critical threat intelligence is uploaded to the cloud platform layer in priority and reliably.
[0064] Step S7, global correlation analysis based on threat metadata, global threat intelligence, and defense system upgrade based on threat metadata.
[0065] In some possible embodiments, the cloud platform layer receives threat metadata uploaded from vehicles across the network and stores it in the cloud platform layer's big data storage center. Through the global threat analysis engine, complex global correlation analysis algorithms are run, such as: through cluster analysis, geographically clustered similar abnormal reports are found to identify potential regional attacks; through time series correlation analysis, slow penetration APT attack chains are mined; through graph computing analysis techniques, attack events, affected vehicles, ECU models, component suppliers, etc. are abstracted as nodes, and their assembly, ownership, co-occurrence, etc. relationships are abstracted as edges, to build a large-scale threat relationship graph; through community discovery, path analysis, etc. algorithms, the potential propagation path of the attack among different vehicle models and ECU models is accurately depicted, so as to trace and identify common supply chain vulnerabilities, such as a single software library vulnerability provided by a supplier affecting multiple ECUs.
[0066] In some possible embodiments, in combination with Figure 4 As shown, defense system upgrade based on threat metadata includes: Threat detection model training and optimization based on threat metadata, and lightweight processing of the trained and optimized threat detection model. Specifically, the threat detection model can be a deep learning detection model (such as LSTM network, graph neural network, etc.), after training and optimization, through model distillation and compression techniques, the threat detection model is converted into a lightweight version that can run on the vehicle end.
[0067] Attack signature rule library update based on threat metadata. Specifically, the deterministic attack patterns output by the global threat analysis engine are solidified into new attack signature rules that can be quickly matched, and the deterministic attack patterns can be new attack sequences, malicious IP addresses, and specific exploit features identified.
[0068] Response strategy library update based on threat metadata. Specifically, based on the analysis of historical response effects (such as the false positive rate of a certain type of attack and the effectiveness evaluation of response actions) and the tactical characteristics of new threats, optimized response strategies are generated, for example, the optimized response strategies include adjusting the confidence threshold, optimizing the hierarchical response actions, and developing special monitoring strategies for slow APT attacks.
[0069] Instead of processing massive, indiscriminate raw data, the cloud can focus on global correlation analysis, deep mining and complex AI model training of high-value feature information reported by the edge layer, which liberates the cloud computing resources from heavy basic data processing and focuses on intelligent generation and knowledge refinement of higher value information, thereby greatly improving the analysis efficiency and input-output ratio.
[0070] Step S8, based on the global threat intelligence and the upgraded defense system, the edge layer is updated, and then jump to step S1.
[0071] In some possible embodiments, the cloud platform layer sends the global threat intelligence and the updated threat detection model, attack signature rule library, response strategy library to all vehicles and roadside units of the edge layer in the form of incremental update package through the downlink in a safe and reliable manner. The vehicle-mounted edge security device of the edge layer updates the local lightweight real-time detection engine and rule library without affecting real-time performance after receiving the incremental update package, so that the defense capability of the entire vehicle fleet evolves synchronously and continuously immunizes against new threats.
[0072] Embodiment Two As shown in Figure 5 The embodiment provides a vehicle-mounted network security threat perception method based on the edge and cloud collaborative vehicle-mounted network security threat perception system of embodiment one, which includes an edge layer, a network transmission layer and a cloud platform layer.
[0073] Specifically, the edge layer is used for collecting vehicle multi-modal data, pre-processing the vehicle multi-modal data, extracting features from the pre-processed vehicle multi-modal data to obtain a high-dimensional feature vector, calculating a threat confidence score according to the high-dimensional feature vector, making a hierarchical response decision according to the threat confidence score, generating hierarchical response data, and then extracting threat metadata based on the hierarchical response data and sending the threat metadata to the network transmission layer.
[0074] Specifically, the network transmission layer is used for receiving the threat metadata sent by the edge layer and forwarding it to the cloud platform layer, and receiving the global threat intelligence and the updated defense system sent by the cloud platform layer and forwarding it to the edge layer.
[0075] Specifically, the cloud platform layer is used for receiving the threat metadata sent by the network transmission layer, performing global correlation analysis according to the threat metadata to obtain global threat intelligence, and upgrading the defense system according to the threat metadata, and then sending the global threat intelligence and the updated defense system to the network transmission layer.
[0076] In some possible embodiments, in combination with Figure 6As shown, the edge layer includes intelligent connected vehicles and roadside units, the intelligent connected vehicles are deployed with vehicle-mounted edge security devices, and the roadside units are deployed with edge computing nodes.
[0077] In combination with Figure 7 As shown, the vehicle-mounted edge security device includes a data acquisition module, a preprocessing module, a feature extraction module, a lightweight real-time detection engine, a collaborative decision-making module, a local response execution module, a hardware security module, a gateway ECU, and a vehicle-mounted unit. The data acquisition module includes a network sniffing module; the collaborative decision-making module is used to make hierarchical response decisions based on threat confidence scores and a pre-defined response strategy library, generate hierarchical response data, and extract threat metadata based on the hierarchical response data and send the threat metadata to the cloud platform layer and at least one other collaborative node. The functions of all the above specific modules are mentioned in Embodiment One, and the related technical details mentioned in Embodiment One are also valid in Embodiment Two. In order to reduce repetition, they will not be repeated here. Correspondingly, the related technical details mentioned in this embodiment can also be applied in Embodiment Two.
[0078] It should be noted that the edge layer is the "senses and reflex nerves" of the entire system and is also the cornerstone of system innovation. By sinking computing power and intelligent decision-making capabilities to the closest location to the vehicle, efficient and collaborative security protection is achieved. This layer is composed of intelligent connected vehicles and roadside units (RSU). Each vehicle serves as a mobile intelligent security node, carrying a vehicle-mounted edge security device with local real-time data processing and immediate response capabilities. Roadside units are deployed at key locations such as intersections and toll stations as more powerful edge computing nodes that can aggregate multi-vehicle information, enable regional collaborative analysis, and provide local computing power support in the event of network disruption. The core role of the edge layer is threefold: first, local real-time processing and feature extraction filter out a large amount of invalid data, significantly reducing network load; second, millisecond-level immediate response to high-risk attacks (such as abnormal brake manipulation), forming a local "reflex arc" that does not rely on the cloud, completely solving the problem of response delay; third, edge collaboration, vehicles and roadside units can directly share threat intelligence. For example, after the lead vehicle identifies a new type of network attack, it can broadcast real-time warnings to the following vehicles, achieving group immunity and joint defense and control, and fundamentally overcoming the bottleneck of insufficient collaboration capability in traditional solutions.
[0079] In some feasible embodiments, in combination with Figure 6 As shown, the network transmission layer, as the "efficient neural network" of the system, mainly relies on low-latency and high-bandwidth cellular networks such as 5G / 4G, and integrates the Internet and dedicated lines to achieve efficient circulation of information within the system.
[0080] It should be noted that the core role of the network transmission layer is to transmit not the full amount of raw data, but high-value "knowledge" processed by edge intelligence, including lightweight feature vectors describing abnormal behavior, threat metadata containing only key attributes (such as type, time, and location), and local model increments generated by vehicle-side autonomous learning. The system builds a two-way intelligent information flow: uplink transmission of lightweight features and threat metadata, and downlink distribution of updated threat detection models and global threat intelligence. This efficient transmission mechanism centered on "knowledge" fundamentally alleviates network bandwidth pressure and significantly improves system overall response and collaboration efficiency.
[0081] In some feasible embodiments, in combination with Figure 6 As shown, the cloud platform layer includes a big data storage center, a global threat analysis engine, and an AI model training platform. The big data storage center is used to store high-dimensional feature vectors and threat metadata from all vehicles; the global threat analysis engine is used for global correlation analysis based on threat metadata; and the AI model training platform is used for upgrading the defense system based on threat metadata.
[0082] It should be noted that the cloud platform layer, as the "brain and knowledge base" of the system, realizes the role transformation from "tired processor" to "decision center in the war room". Among them, the big data storage center no longer retains massive raw data, but concentrates the high-value feature vectors and threat metadata from all network vehicles to build a systematic "threat knowledge base"; the global threat analysis engine identifies macro attack patterns that edge nodes cannot detect by correlating and deeply mining these micro features in space and time, such as discovering large-scale supply chain attacks by analyzing similar anomalies of the same ECU model reported by vehicles in multiple regions; the AI model training platform continuously trains and optimizes advanced threat detection models relying on global data, and distributes them to edge nodes in a lightweight form to realize the efficient collaboration of "cloud training and edge inference"; in addition, the cloud platform layer can also deploy a security posture visualization platform to provide macro security state and real-time alerts for operation and maintenance personnel. The core role of the cloud platform layer is to effectively deal with macro, slow, and advanced sustainable threats with the help of global vision and deep learning capabilities, and through continuous model iteration and strategy distribution, the defense capabilities of the entire vehicle fleet are constantly evolving, realizing the group intelligence improvement of "one vehicle learns, and the whole network benefits".
[0083] It is worth mentioning that each module involved in the embodiment is a logic unit, which can be a physical unit, a part of a physical unit, or a combination of multiple physical units in actual application. In addition, in order to highlight the innovative part of the application, units not closely related to solving the technical problems proposed by the application are not introduced in the embodiment, but this does not mean that there are no other units in the embodiment.
[0084] Embodiment three Please refer to Figure 8 The embodiment also provides an electronic device, including a memory and a processor; the memory stores at least one program instruction; and the processor implements the vehicle-mounted network security threat perception method based on edge and cloud collaboration provided in the embodiment by loading and executing the at least one program instruction.
[0085] The memory 702 and the processor 701 are connected in a bus manner, the bus can include any number of interconnected buses and bridges, and the bus connects one or more processors 701 and various circuits of the memory 702 together. The bus can also connect various other circuits such as peripheral devices, voltage stabilizers, and power management circuits together, which are well known in the art, and therefore, further description is not given herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be one element or multiple elements such as multiple receivers and transmitters, which provide a unit for communicating with various other devices on a transmission medium. The data processed by the processor 701 is transmitted on a wireless medium through an antenna, and further, the antenna also receives data and transmits the data to the processor 701.
[0086] The processor 701 is responsible for managing the bus and general processing, and can also provide various functions including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory 702 can be used to store data used by the processor 701 in performing operations.
[0087] Embodiment four The embodiment of the application also provides a storage medium, and the storage medium stores the vehicle-mounted network security threat perception method based on edge and cloud collaboration. When the vehicle-mounted network security threat perception program based on edge and cloud collaboration is executed, the steps of the vehicle-mounted network security threat perception method based on edge and cloud collaboration as described above are implemented. Since the storage medium adopts all the technical solutions of all the embodiments described above, it at least has all the beneficial effects brought by the technical solutions of the above embodiments, which will not be described here.
[0088] The above-mentioned are only embodiments of the present application, and the common knowledge of specific structures and characteristics in the scheme is not described too much herein. The ordinary skilled person in the art knows all the ordinary technical knowledge in the field of the present application before the application date or the priority date, can know all the prior art in the field, and has the ability to apply conventional experimental means before that date. The ordinary skilled person in the art can perfect and implement the present scheme under the guidance of the present application, combined with their own ability. Some typical known structures or known methods should not be an obstacle for the ordinary skilled person in the art to implement the present application. It should be noted that, for those skilled in the art, without departing from the structure of the present application, a number of modifications and improvements can be made, which should also be considered as the protection scope of the present application. The protection scope of the present application should be subject to the content of its claims, and the specific implementation mode and the like in the specification can be used to explain the content of the claims.
Claims
1. A method for detecting network security threats in vehicles based on edge and cloud collaboration, characterized in that, Includes the following steps: Step S1: Collect vehicle multimodal data through the edge layer; Step S2: Preprocess the vehicle multimodal data; Step S3: Extract features from the preprocessed vehicle multimodal data to obtain high-dimensional feature vectors; Step S4: Calculate the threat confidence score based on the high-dimensional feature vector using a multimodal decision fusion algorithm; Step S5: Based on the threat confidence score and a predefined response strategy library, make a graded response decision and generate graded response data; Step S6: Extract threat metadata based on the hierarchical response data and send the threat metadata to the cloud platform layer and at least one other cooperating node; Step S7: Perform global correlation analysis based on threat metadata to obtain global threat intelligence, and upgrade the defense system based on threat metadata; Step S8: Based on global threat intelligence and the upgraded defense system, perform edge layer updates, and then proceed to step S1.
2. The method for vehicle network security threat perception based on edge and cloud collaboration according to claim 1, characterized in that, The vehicle multimodal data includes system-level data from the vehicle's electronic control unit and network-level data from the in-vehicle network.
3. The method for vehicle network security threat perception based on edge and cloud collaboration according to claim 1, characterized in that, The high-dimensional feature vector includes the frequency of vehicle electronic control unit commands, network traffic entropy, message interval variance, and opcode sequence.
4. The method for vehicle network security threat perception based on edge and cloud collaboration according to claim 1, characterized in that, Step S4 includes: Step S41: Perform rule base matching, baseline model comparison and machine learning inference on the high-dimensional feature vector to obtain the rule matching score, baseline deviation score and potential threat probability score respectively; Step S42: Combine the rule matching score, baseline deviation score and potential threat probability score to obtain the threat confidence score. Threat confidence score = max(rule matching score, potential threat probability score) × baseline deviation score.
5. The method for vehicle network security threat perception based on edge and cloud collaboration according to claim 1, characterized in that, In step S5, a tiered response decision is made based on the threat confidence score and a predefined response strategy library, including: When the threat confidence score is ≥0.8, it is considered a high-score threat, and a local response will be executed. When 0.5 ≤ threat confidence score < 0.8, it is considered a neutral threat, and a restrictive strategy should be implemented. When the threat confidence score is less than 0.5, it is considered a low-score threat and no interception operation will be performed.
6. The method for vehicle network security threat perception based on edge and cloud collaboration according to claim 1, characterized in that, The at least one other cooperating node includes roadside units and other vehicles.
7. The method for vehicle network security threat perception based on edge and cloud collaboration according to claim 1, characterized in that, The threat metadata includes event identifier, timestamp, vehicle identification code, latitude and longitude coordinates, threat type, threat confidence score, feature vector summary, electronic control unit identifier, and response action log.
8. The method for vehicle network security threat perception based on edge and cloud collaboration according to claim 1, characterized in that, In step S7, the defense system is upgraded based on threat metadata, including: The threat detection model is trained and optimized based on threat metadata, and the trained and optimized threat detection model is then lightweighted. Update the attack signature rule base based on threat metadata; Update the response strategy library based on threat metadata.
9. A vehicle network security threat perception system applying the edge and cloud collaborative vehicle network security threat perception method as described in any one of claims 1 to 8, characterized in that, It includes the edge layer, network transport layer, and cloud platform layer; The edge layer is used to collect vehicle multimodal data, preprocess the vehicle multimodal data, extract features from the preprocessed vehicle multimodal data to obtain high-dimensional feature vectors, calculate threat confidence scores based on the high-dimensional feature vectors, make graded response decisions based on the threat confidence scores, generate graded response data, extract threat metadata based on the graded response data, and send the threat metadata to the network transport layer. The network transport layer is used to receive threat metadata sent by the edge layer and forward it to the cloud platform layer, as well as to receive global threat intelligence and updated defense systems sent by the cloud platform layer and forward them to the edge layer. The cloud platform layer is used to receive threat metadata sent by the network transport layer, perform global correlation analysis based on the threat metadata to obtain global threat intelligence, upgrade the defense system based on the threat metadata, and then send the global threat intelligence and the updated defense system to the network transport layer.
10. The vehicle-mounted network security threat perception system according to claim 9, characterized in that, The cloud platform layer includes a big data storage center, a global threat analysis engine, and an AI model training platform. The big data storage center is used to store high-dimensional feature vectors and threat metadata from all vehicles; The global threat analysis engine is used to perform global correlation analysis based on threat metadata. The AI model training platform is used to upgrade the defense system based on threat metadata.
Citation Information
Cited By
Intelligent bus operation and maintenance task scheduling method based on edge intelligent prediction model
CN121638943A
Cloud-based automobile information safety early warning method and system
CN121750374A
Communication security threat intelligent detection and protection method and device for vehicle-mounted terminal
CN122226527A