Intrusion detection defense system, method, device, vehicle, medium and program product
By deploying a collaborative controller and multiple detection and defense devices on vehicles, collaborative intrusion detection and defense across nodes, domains, or regions can be achieved, solving the problem of insufficient accuracy in existing vehicle intrusion detection systems, improving the accuracy of vehicle security detection, and reducing security risks.
Patent Information
- Application Number
- CN202410710880.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-03
- Publication Date
- 2025-12-12
AI Technical Summary
Existing vehicle intrusion detection systems lack sufficient security detection accuracy, resulting in higher vehicle security risks. They also fail to effectively cover the entire vehicle network and are prone to false alarms and missed alarms.
A collaborative controller and multiple detection and defense devices are deployed on multiple target devices in the vehicle. The collaborative controller performs collaborative analysis and resource coordination on multiple detection and defense devices to achieve collaborative intrusion detection and defense across nodes, domains, or regions.
It improves the accuracy of vehicle safety detection, reduces safety risks, decreases false alarms and false alarms, enhances the robustness and security of the entire vehicle network, and reduces deployment costs.
Smart Images

Figure CN121125128A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle security technology, and in particular to an intrusion detection and prevention system, method, device, vehicle, medium, and program product. Background Technology
[0002] During vehicle use, vehicle networks are susceptible to intrusion attacks from various sources, making vehicles vulnerable to interference and control. To ensure vehicle security, intrusion detection technology has become an important means of vehicle network security testing.
[0003] Existing intrusion detection systems, such as Intrusion Detection Systems (IDS) and Intrusion Detection and Prevention Systems (IDPS), detect and defend against security attacks originating from external networks. However, the accuracy of existing intrusion detection systems is insufficient, leading to higher security risks for vehicles. Summary of the Invention
[0004] This invention provides an intrusion detection and prevention system, method, device, vehicle, medium, and program product to solve the problem that the security detection accuracy of existing stand-alone IDS and IDPS systems is insufficient, resulting in high vehicle security risks.
[0005] An intrusion detection and defense system is provided, including a cooperative controller and multiple detection and defense devices, each of which is deployed on multiple target devices of a vehicle. Each detection and defense device is used to: perform collaborative intrusion detection on multiple target devices, obtain intrusion detection data, and feed it back to the collaborative controller; The collaborative controller is used to: perform collaborative analysis based on intrusion detection data from each detection and defense device, and send defense commands to the corresponding detection and defense device when an abnormal event is detected. Each detection and defense device is also used to: respond to the defense commands of the coordination controller to carry out security defense against the corresponding target device.
[0006] Optionally, collaborative analysis is performed based on intrusion detection data from each detection and defense device, and defense commands are sent to the corresponding detection and defense device when an abnormal event is detected, including: When intrusion detection data is received from any detection and defense device, the detection and defense device and the detection and defense device that need to be detected together are referred to as the target detection and defense device. Collaborative analysis data is obtained by performing collaborative analysis on intrusion detection data from all target detection and defense devices. When collaborative analysis data indicates the detection of an abnormal event, a defense command is sent to the target detection defense device.
[0007] Optionally, collaborative analysis is performed based on intrusion detection data from all target detection and defense devices to obtain collaborative analysis data, including: If intrusion detection data from all target detection defense devices are received within a preset time period, collaborative analysis will be performed based on the intrusion detection data from all target detection defense devices.
[0008] Optionally, the collaborative controller is also used to: coordinate resources among multiple detection and defense devices to direct resource-sufficient detection and defense devices to perform intrusion detection on behalf of resource-deficient detection and defense devices.
[0009] Optionally, resource coordination is performed on multiple detection and defense devices to allocate resources to devices with sufficient resources to perform intrusion detection on behalf of those with insufficient resources, including: If a detection task coordination request is received from a detection and defense device, after determining that there are detection and defense devices with sufficient resources, a detection and defense device with sufficient resources is selected and recorded as the entrusted device, and the requested detection and defense device is recorded as the entrusting device. Send a detection task transfer instruction to the delegated device so that the delegated device responds to the detection task transfer instruction and executes the intrusion detection task transferred by the delegated device.
[0010] Optionally, the intrusion detection and prevention system also includes a cloud that communicates with the cooperative controller, the cloud being used to store vehicle rule update packages; The collaborative controller is also used to update the detection rule base of each detection and defense device based on the vehicle rule update package.
[0011] Optionally, the detection rule base of each detection and defense device is updated based on the vehicle rule update package, including: The node update rule packages for each detection and defense device are determined based on the vehicle rule update package. Each node update rule packet is sent to the corresponding detection and defense device, so that each detection and defense device updates the detection rule database with the received node update rule packet.
[0012] Optionally, each node update rule packet is sent to the corresponding detection and defense device, so that each detection and defense device updates its own detection rule base with the received node update rule packet, including: If no rule update request is received from the detection and defense device, the update rule package for each node will be sent to the corresponding detection and defense device so that each detection and defense device will update its own detection rule library with the received node update rule package.
[0013] Optionally, each node update rule packet is sent to the corresponding detection and defense device, so that each detection and defense device updates its own detection rule base with the received node update rule packet, including: If a rule update delegation request for a detection and defense device is received, the delegated detection and defense device is determined. Each node update rule packet is sent to the corresponding detection and defense device, and the node update rule packet requested by the detection and defense device is sent to the entrusted detection and defense device, so that each detection and defense device updates its own detection rule base with the received node update rule packet.
[0014] Optionally, the collaborative controller is also used to: receive log information from each detection and defense device and send it to the cloud, so that the cloud can perform vehicle safety analysis based on the log information from each detection and defense device.
[0015] Optionally, the target device includes a central gateway and multiple domain controllers on the vehicle; the coordination controller is deployed in the vehicle's cockpit domain.
[0016] Optionally, the target device includes a central computing platform and multiple zone controllers on the vehicle; the cooperative controller is deployed on the central computing platform of the vehicle.
[0017] An intrusion detection and defense method is provided, including: Multiple detection and defense devices are used to perform coordinated intrusion detection on multiple target devices of the vehicle, and intrusion detection data of each detection and defense device is obtained. The system performs collaborative analysis based on intrusion detection data from various detection and defense devices. When an abnormal event is detected, a defense command is sent to the corresponding detection and defense device so that the device can respond to the command and provide security protection for the target device.
[0018] An electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the functions of the cooperative controller in the intrusion detection and prevention system described above, or the steps of the intrusion detection and prevention method described above.
[0019] An intrusion detection and defense method is provided, characterized by comprising: Intrusion detection is performed on the target devices deployed by the detection and defense device itself to obtain intrusion detection data; Intrusion detection data is sent to the collaborative controller, so that after receiving intrusion detection data from multiple detection and defense devices, the collaborative controller performs collaborative analysis based on the multiple intrusion detection data, and sends defense instructions to the corresponding detection and defense device when an abnormal event is detected. It receives defense commands sent by the collaborative controller and responds to the defense commands to carry out security defense on the target devices it deploys.
[0020] An electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it performs the function of the detection and defense device in the intrusion detection and defense system described above, or the steps of the intrusion detection and defense method described above.
[0021] A vehicle is provided, comprising a cooperative controller and multiple detection and defense devices, each detection and defense device being deployed on multiple target devices covering the entire vehicle network; the cooperative controller cooperates with the multiple detection and defense devices to perform the functions of the aforementioned intrusion detection and defense system.
[0022] A readable storage medium is provided, which stores a computer program that, when executed by a processor, performs the functions of the aforementioned intrusion detection and prevention system.
[0023] In one solution provided by the aforementioned intrusion detection and prevention system, method, device, vehicle, media, and program products, detection and prevention devices are deployed on multiple target devices within a vehicle. In practical applications, each detection and prevention device performs collaborative intrusion detection on multiple target devices, obtains intrusion detection data, and feeds it back to a collaborative controller. The collaborative controller performs collaborative analysis based on the intrusion detection data from each detection and prevention device, and sends defense commands to the corresponding detection and prevention device when an abnormal event is detected. Each detection and prevention device responds to the defense commands from the collaborative controller to perform security defense on the corresponding target device and its network. In this embodiment, the collaborative controller manages and controls multiple detection and prevention devices collaboratively, enabling each detection and prevention device to perform distributed intrusion detection on multiple target devices. Furthermore, the collaborative controller performs collaborative analysis on the intrusion detection data from each detection and prevention device, and sends defense commands to the detection and prevention devices when an abnormal event is detected. This achieves collaborative intrusion detection and defense functions across nodes, domains, or regions within the vehicle, helping to improve the accuracy of vehicle security detection and thus reducing vehicle security risks. Attached Figure Description
[0024] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 This is a schematic diagram of an intrusion detection and defense system according to an embodiment of the present invention; Figure 2 This is an architecture diagram of an intrusion detection and defense system for a domain-based vehicle according to one embodiment of the present invention; Figure 3 This is an architecture diagram of an intrusion detection and defense system for a zone-structured vehicle according to an embodiment of the present invention; Figure 4 yes Figure 1 Flowchart of the implementation of collaborative analysis tasks by the collaborative controller in the middle; Figure 5 yes Figure 1 Flowchart of the implementation of the central coordination controller when performing resource coordination tasks; Figure 6 yes Figure 1 Flowchart of the implementation of the central collaborative controller when executing rule update tasks; Figure 7 This is a schematic diagram of the structure of a collaborative controller in one embodiment of the present invention; Figure 8 This is a schematic flowchart of an intrusion detection and defense method system in one embodiment of the present invention. Detailed Implementation
[0026] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0027] It should be understood that, when used in this specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or collections thereof. It should also be understood that, as used in this specification and the appended claims, the term "and / or" refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0028] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of the invention include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0029] It should be understood that the sequence number of each step in the following embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0030] To illustrate the technical solution of the present invention, specific embodiments are described below.
[0031] The intrusion detection and defense method provided in this embodiment of the invention can be applied to, for example... Figure 1 The intrusion detection and prevention system comprises a cooperative controller on the vehicle and multiple detection and prevention devices (including detection and prevention device 1 and detection and prevention device n, where n is an integer greater than 1). Each detection and prevention device is deployed on multiple target devices on the vehicle; one or more detection and prevention devices can be deployed on a single target device. Each detection and prevention device is connected to the cooperative controller, which coordinates and manages the multiple detection and prevention devices to achieve collaborative intrusion detection and prevention functions among the target devices.
[0032] Specifically, each detection and defense device is used to perform collaborative intrusion detection on multiple target devices, obtain intrusion detection data, and feed it back to the collaborative controller; the collaborative controller is used to perform collaborative analysis based on the intrusion detection data of each detection and defense device, and send defense instructions to the corresponding detection and defense device when an abnormal event is detected; each detection and defense device is also used to respond to the defense instructions of the collaborative controller to perform security defense on the corresponding target device.
[0033] It's important to understand that existing standalone IDS and IDPS systems cannot cover all external communication channels within a vehicle. Furthermore, existing vehicle networks are typically designed by domain or zone. For optimization and security reasons, a large amount of data transmission is confined to the local zone or domain. Standalone IDS and IDPS systems struggle to detect network conditions in other domains or zones, resulting in an inability to provide comprehensive security detection and defense covering the entire vehicle network. Once compromised, other internal vehicle components are directly exposed to the attack, posing a significant security risk. For example, interaction information between the cockpit system and external mobile phones is only retained in the cockpit domain and does not pass through the central gateway or intelligent driving domain. Intrusion detection devices on the central gateway or intelligent driving domain cannot detect communication between the cockpit system and external mobile phones. In addition, existing standalone IDS and IDPS systems are prone to false alarms during intrusion detection, such as due to lost data packets or equipment malfunctions. Security rules also have limitations, making it easy to miss or bypass detections, resulting in low accuracy for existing standalone IDS and IDPS systems.
[0034] The intrusion detection and defense system in this embodiment deploys multiple detection and defense devices on multiple target devices within the vehicle. A collaborative controller manages and controls these devices, enabling distributed intrusion detection across multiple target devices. The controller then collaboratively analyzes the intrusion detection data from each device, sending defense commands to execute them when anomalies are detected. This achieves collaborative intrusion detection and defense across nodes, domains, or regions within the vehicle, improving the accuracy of vehicle security detection and reducing security risks. Furthermore, the system allows multiple detection and defense devices to cross-verify each other, reducing false alarms and further enhancing accuracy. The separately deployed devices add multiple layers of defense, reducing the risk of rule bypassing in single-point deployments and enabling the detection of complex attacks that traditional IDS / IDPS systems cannot detect, resulting in stronger robustness and security for the entire vehicle's cybersecurity. Moreover, different target devices (such as ECUs) have different computational strengths, allowing for distributed deployment of detection and defense devices based on their characteristics, making it highly adaptable.
[0035] In this system, a detection and defense device is deployed on each target device in the vehicle, enabling timely and effective protection for each target device and its network. This achieves collaborative intrusion detection and defense functions across nodes, domains, or regions on the vehicle, improving the accuracy of vehicle security detection, reducing vehicle security risks, reducing the deployment cost of the detection and defense device, and increasing the universality of security detection functions.
[0036] The target device can be a device containing important network nodes on the vehicle, such as multiple domain controllers or multiple zone controllers on the vehicle. It's important to understand that some vehicle in-vehicle networks are typically designed by domain or zone. By placing detection and defense devices on multiple domain controllers or multiple zone controllers on the vehicle, it is possible to effectively cover important nodes and their networks throughout the vehicle. Through the collaborative controller, collaborative intrusion detection and defense functions across nodes, domains, or zones can be effectively realized, ensuring vehicle security.
[0037] In one embodiment, a network of multiple target devices forms a network capable of covering the entire vehicle, with each detection and defense device deployed on one of the target devices covering the vehicle network. In this embodiment, the target devices include not only multiple domain controllers or multiple zone controllers on the vehicle, but also target electronic control units (ECUs) on the vehicle. These target ECUs are computing platforms or electronic control units (ECUs) with sufficient computing power, such as a central computing platform, a central gateway, and individual ECUs with sufficient computing power. By additionally deploying detection and defense devices on some target ECUs, the detection range of multiple detection and defense devices can cover the entire vehicle network, further increasing the comprehensiveness of the intrusion detection and defense system, further reducing vehicle security risks, and thus improving vehicle security.
[0038] The collaborative controller and detection and defense devices can be deployed independently and decoupled. This means the deployment of the intrusion detection and defense system is independent of the vehicle's specific physical architecture. Multiple detection and defense devices can be deployed on a domain-based vehicle electronic and electrical architecture, a zone-based vehicle electronic and electrical architecture, or an earlier distributed vehicle electronic and electrical architecture. This allows the intrusion detection and defense system to be flexibly deployed according to actual vehicle model resources and needs, reducing deployment costs and improving the distributed detection and defense capabilities of the intrusion detection and defense system.
[0039] For example, when the vehicle has a domain-based vehicle electrical and electronic architecture, the target devices include a central gateway and multiple domain controllers on the vehicle, as well as some electronic control units (ECUs) within each domain; the cooperative controller is deployed in the vehicle's cockpit domain or central gateway, i.e., the architecture of the intrusion detection and prevention system is as follows. Figure 2 As shown. The vehicle's electronic and electrical architecture includes multiple domains, various instruments, a central gateway (an electronic control unit used for communication between multiple domain networks), and electronic control units for each domain. These domains include the cockpit domain (usually equipped with a T-Box), body domain, intelligent driving domain, powertrain domain, and chassis domain control. Each domain includes corresponding domain controllers and electronic control units. For example... Figure 2 As shown, each detection and defense device (DIDPS) is deployed on the domain controllers (including the cockpit domain controller, body domain controller, intelligent driving domain controller, powertrain domain controller, and chassis domain controller), the central gateway, and the target electronic control units (ECUs) of each domain. When the vehicle has a domain-based vehicle electronic and electrical architecture, to facilitate data transmission processing and compatibility of in-vehicle and out-of-vehicle communication, the cooperative controller is deployed in the cockpit domain, such as on the cockpit system or T-BOX within the cockpit domain. Figure 2 As shown. In other embodiments, the collaboration controller may also be deployed on a central gateway.
[0040] When the vehicle uses a domain-based vehicle electrical and electronic architecture, the target devices include a central computing platform and multiple zone controllers, as well as electronic control units (ECUs) within each zone; the cooperating controller is deployed on the vehicle's central computing platform, or in a zone integrating a cockpit system or T-BOX. That is, the architecture of the intrusion detection and prevention system is as follows: Figure 3 As shown. The vehicle's electronic and electrical architecture includes a central computing platform, multiple zones, subnets within each zone, and electronic control units. For example... Figure 3 As shown, each Detection and Defense System (DIDPS) is deployed on the respective zone controller, central computing platform, and target electronic control unit (ECU) of each zone. The cooperative controller is deployed in the zone integrating the cockpit system or T-BOX. Since the central computing platform of the zone architecture integrates multiple functions, such as body control, cockpit functions, powertrain, chassis, intelligent driving, and gateway functions, in other embodiments, the cooperative controller can also be deployed on the central computing platform.
[0041] In one embodiment, each detection and defense device also provides single-point intrusion detection and defense functionality. That is, each detection and defense device can perform single-point intrusion detection and defense on the target device (i.e., the deployment node of the detection and defense device), thereby reducing the security risks to the target device and its network. By deploying each detection and defense device on each domain controller (or each zone controller) and electronic control unit (ECU), and performing localized intrusion detection and defense, no additional network detectives are required, significantly reducing network bandwidth requirements. Furthermore, the intrusion detection and defense system is compatible with both single-point and collaborative intrusion detection and defense functions, further improving the accuracy of vehicle security detection and thus reducing vehicle security risks.
[0042] In one embodiment, collaborative analysis is performed based on intrusion detection data from each detection and defense device, and a defense command is sent to the corresponding detection and defense device when an abnormal event is detected. This includes: upon receiving intrusion detection data from any detection and defense device, the detection and defense device and the detection and defense device that need to be detected collaboratively are designated as target detection and defense devices; collaborative analysis is performed based on the intrusion detection data of all target detection and defense devices to obtain collaborative analysis data; and when the collaborative analysis data indicates that an abnormal event has been detected, a defense command is sent to the target detection and defense device.
[0043] Specifically, such as Figure 4 As shown, when executing collaborative analysis tasks, the collaborative controller specifically performs the following steps: S101: Upon receiving intrusion detection data from any detection and defense device, the detection and defense device and the detection and defense device that need to be detected in cooperation are referred to as the target detection and defense device.
[0044] In this embodiment, the detection rule library of the detection and defense device stores multiple single-point rules (local rules for target devices and networks) and collaborative rules (distributed detection rules). During the rule process of the detection and defense device, when the collaborative rule in the detection rule library of the detection and defense device is triggered, indicating a possible intrusion event, the detection and defense device detects an abnormal event that requires collaborative detection, and the detection and defense device sends the current intrusion detection data to the collaborative controller.
[0045] Among them, the intrusion detection data can include the ID of the triggered collaborative rule (ID represents the unique identification number), the ID of the detection and defense device (DIDPS), and the detection result after triggering the collaborative rule. The detection result after triggering the collaborative rule can be expressed by a boolean value.
[0046] For example, the collaborative rule is expressed as <ruleID, <Rules’, [collaboration]>; when the <ruleID, <Rules’, [collaboration]> in the detection rule library of the detection and defense device is triggered, that is, detecting a potential intrusion event, the detection and defense device generates intrusion detection data: <ruleID, DIDPSID, [boolean value list]>. Among them, ruleID represents the ID of the triggered collaborative rule; DIDPSID represents the ID of the detection and defense device; the boolean value list represents the detection result after triggering the collaborative rule, which is irreducible at the detection and defense device level and cannot be calculated into a single value. In other embodiments, the detection result after triggering the collaborative rule can also be represented in other forms. For example, the detection result after triggering the collaborative rule can be directly expressed by an abnormal event field or identifier.
[0047] When the collaborative controller receives the intrusion detection data of any detection and defense device, it records the detection and defense device and the detection and defense device that needs to be collaboratively detected as the target detection and defense device. Among them, the detection and defense device that needs to be collaboratively detected is, in a certain vehicle scenario, the deployment node corresponding to other detection and defense devices that need to work together with the deployment node corresponding to this detection and defense device. Specifically, when receiving the intrusion detection data of any detection and defense device, determine the multiple vehicle scenarios corresponding to this detection and defense device (that is, the vehicle scenarios that the deployment node of the detection and defense device needs to participate in), determine the other detection and defense devices in this vehicle scenario as the detection and defense devices that need to be collaboratively detected, and then record the detection and defense device and the detection and defense device that needs to be collaboratively detected as the target detection and defense device.
[0048] For example, in a car door opening scenario, Bluetooth, UWB (wireless car key), and NFC (Near Field Communication) typically need to work together. The door can only be opened when all three devices authenticate successfully. Each of the three NFC devices (target devices) is equipped with a detection and defense mechanism. When the collaborative controller receives intrusion detection data from any of the Bluetooth, UWB, or NFC detection and defense mechanisms, it will consider the detection and defense mechanisms of the remaining two devices as the detection and defense mechanisms requiring collaborative detection. Finally, the detection and defense mechanisms of all three are recorded as the target detection and defense mechanisms.
[0049] S102: Perform collaborative analysis based on intrusion detection data from all target detection and defense devices to obtain collaborative analysis data.
[0050] Then, the collaborative controller acquires intrusion detection data from all target detection defense devices and performs collaborative analysis based on this data to obtain collaborative analysis data. In system analysis, it's necessary to match the information flow of the network security analysis process (intrusion detection data) with the information flow of functional topology and functions. Different vehicles require different devices to cooperate, and the response times of each device may vary (it could be concurrent or sequential). Therefore, methods such as concurrent events, event chain timing, and multi-dimensional input / output correlation domains can be used to collaboratively analyze the intrusion detection data of all target detection and defense devices to determine whether the current abnormal event is genuine, thereby obtaining collaborative analysis data. Cross-domain and cross-node collaborative analysis across multiple dimensions, including timing, input / output dimensions, and concurrent signals, forms a more complete chain of detection and analysis evidence, thus improving detection accuracy.
[0051] For example, taking the multidimensional input-output association domain method for collaborative recognition, the vehicle is equipped with a left-side camera and a left-side radar. The left-side camera is equipped with a detection and defense device DIDPSx, and the left-side radar is equipped with a detection and defense device DIDPSy. If the collaborative controller receives intrusion detection information from DIDPSx, it indicates that the left-side camera has detected an obstacle, but does not receive intrusion detection information from the left-side radar, or receives intrusion detection information from the left-side radar indicating that no obstacle is detected on the left, it means that the core imaging parameters on the left-side camera may have been tampered with. This determines that the vehicle has encountered an intrusion or violation event, and the abnormal event is real, thus obtaining collaborative analysis data.
[0052] S103: When collaborative analysis data indicates that an abnormal event has been detected, a defense command is sent to the target detection defense device.
[0053] After obtaining the collaborative analysis data, if the data indicates that an anomaly has been detected, a defense command is sent to the target detection and defense device. If the data indicates that no anomaly has been detected, the intrusion detection data is ignored.
[0054] For example, after receiving intrusion detection data from all target detection and defense devices, the collaborative controller analyzes and judges the intrusion detection data from all target detection and defense devices to obtain collaborative analysis data. This collaborative analysis data is expressed through an extended Boolean expression, that is, the collaborative analysis result is expressed as true or false. If the collaborative analysis data is true, it means that the target detection and defense devices have jointly proven that the vehicle has encountered an intrusion or illegal event. In this case, the collaborative controller determines that an abnormal event has been detected and sends a defense command to each target detection and defense device, causing each target detection and defense device to respond to the defense command and perform security defense on the corresponding target device and its network.
[0055] In this embodiment, when the collaborative controller receives intrusion detection data from any detection and defense device, it designates the detection and defense device and the detection and defense devices requiring collaborative detection as target detection and defense devices. Based on the intrusion detection data from all target detection and defense devices, it performs collaborative analysis to obtain collaborative analysis data. When the collaborative analysis data indicates the detection of an abnormal event, it sends a defense command to the target detection and defense devices, causing each target detection and defense device to respond to the defense command and perform security defense on the corresponding target device and its network. Each detection and defense device performs its own detection work in daily operation. When it receives intrusion detection data from any detection and defense device in collaboration with others, it performs collaborative analysis based on the intrusion detection data from multiple collaboratively working detection and defense devices, which can avoid false alarms and missed alarms, further improving the accuracy of detection.
[0056] In other embodiments, upon receiving intrusion detection data from any detection and defense device, intrusion detection data from all detection and defense devices within a preset time period (a period before and after receiving the intrusion detection data from that device) can be directly acquired. These detection and defense devices are then matched against multiple preset vehicle scenarios. If no vehicle scenario is matched, it indicates that the vehicle is currently experiencing an intrusion or violation, and the abnormal event is determined to be true, resulting in collaborative analysis data: abnormal event is true. If a vehicle scenario is matched, the detection and defense device corresponding to that matched vehicle scenario is recorded as the target detection and defense device. Collaborative analysis is then performed based on the intrusion detection data from all target detection and defense devices to obtain collaborative analysis data. When the collaborative analysis data indicates that an abnormal event has been detected, a defense command is sent to the target detection and defense device. Performing vehicle scenario matching first can quickly determine some intrusion and violation times, improving response time.
[0057] In one embodiment, collaborative analysis is performed based on intrusion detection data from all target detection defense devices to obtain collaborative analysis data. This includes: determining whether intrusion detection data from all target detection defense devices has been received within a preset time period; if intrusion detection data from all target detection defense devices has been received within the preset time period, then collaborative analysis is performed based on the intrusion detection data from all target detection defense devices. Specifically, the collaborative controller is used to execute the following steps: S1021: Determine whether intrusion detection data from all target detection defense devices has been received within a preset time period.
[0058] Upon receiving intrusion detection data from any detection and defense device, the collaborative controller needs to identify the target detection and defense device and determine within a preset time period whether intrusion detection data from all target detection and defense devices has been received, thus determining the integrity of the current event group.
[0059] S1022: If intrusion detection data from all target detection defense devices are received within a preset time period, then collaborative analysis is performed based on the intrusion detection data from all target detection defense devices.
[0060] If intrusion detection data from all target detection defense devices is received within a preset time period, it indicates that the current event group is complete. Then, collaborative analysis is performed based on the intrusion detection data from all target detection defense devices to obtain collaborative analysis results. When the collaborative analysis data indicates that an abnormal event has been detected, a defense command is sent to the target detection defense device. After receiving the defense command, the target detection defense device performs security defense on the corresponding target device and network.
[0061] If intrusion detection data from all target detection defense devices is not received within a preset time period, it indicates that the current event group is incomplete. In this case, the target detection defense devices are notified to perform operations according to preset rules, or the event is ignored and no collaborative analysis of the intrusion detection data is performed.
[0062] In this embodiment, the collaborative controller determines whether it has received intrusion detection data from all target detection and defense devices within a preset time period. If it has received intrusion detection data from all target detection and defense devices within the preset time period, it performs collaborative analysis based on the intrusion detection data from all target detection and defense devices. Before performing collaborative analysis, it first performs an event group integrity judgment. Collaborative analysis is only performed when the event group is determined to be complete, thus ensuring the accuracy of the judgment.
[0063] In one embodiment, the collaborative controller includes a collaborative analysis module for performing collaborative analysis tasks on intrusion detection data. That is, the collaborative analysis module performs the steps described above.
[0064] In one embodiment, the collaborative controller further includes a resource coordination module, which is used to perform the above-mentioned resource coordination task, namely: to coordinate the resources of multiple detection and defense devices so as to regulate the detection and defense devices with sufficient resources to perform intrusion detection on behalf of the detection and defense devices with insufficient resources.
[0065] It's important to understand that many vehicle functions are not activated simultaneously. For example, during automatic parking, the in-vehicle entertainment system is usually turned off. This means the autonomous driving processor needs significant computing resources to support automatic parking, while the in-vehicle system remains largely idle. Traditional IDS / IDPS systems are deployed as single machines (single points) and lack distributed collaboration capabilities, making it impossible to ensure network security through task migration and collaboration. In this embodiment, the collaborative controller coordinates resources across multiple detection and defense devices. It can migrate intrusion detection tasks from busy target devices to detection and defense devices on idle target devices. Through adaptive collaboration of detection tasks, the utilization of computing resources can be maximized, effectively reducing the cost of the ECU, ensuring load balance across devices, aiding in power consumption and temperature control, and increasing the lifespan of the chips in each device.
[0066] In one embodiment, resource coordination is performed on multiple detection and defense devices to regulate the detection and defense devices with sufficient resources to perform intrusion detection on behalf of those with insufficient resources. This includes: if a detection task coordination request is received from a detection and defense device, after determining that there is a detection and defense device with sufficient resources, selecting one of the detection and defense devices with sufficient resources as the delegated device and recording the requesting detection and defense device as the delegated device; sending a detection task transfer instruction to the delegated device so that the delegated device responds to the detection task transfer instruction and executes the intrusion detection task transferred by the delegated device.
[0067] That is, such as Figure 5 As shown, when executing resource coordination tasks, the collaborative controller specifically performs the following steps: S201: Determine whether a detection task coordination request for the detection defense device has been received; S202: If a detection task coordination request is received from a detection defense device, after determining that there is a detection defense device with sufficient resources, select a detection defense device with sufficient resources and record it as the entrusted device, and record the requesting detection defense device as the entrusting device.
[0068] During operation, when the detection and defense device detects that the resources of the deployed target device are insufficient to complete the intrusion detection task of the target device, the detection and defense device sends a detection task coordination request to the coordination controller.
[0069] The detection task coordination request generation process is as follows: The detection and defense device will monitor the resource status of the deployed target device in real time. When it detects that the CPU or memory resources of the target device are under pressure, such as when the CPU consumption exceeds the calibrated threshold (which can be 80%), and the priority of the target device's current task is higher than that of the intrusion detection task, and the remaining resources cannot meet the needs of the intrusion detection task, a detection task coordination request is generated and sent to the coordination controller to delegate its own intrusion detection task to other detection and defense devices.
[0070] If a detection task coordination request is received from a detection and defense device, the coordination controller, after determining that there are detection and defense devices with sufficient resources, selects a detection and defense device with sufficient resources as the entrusted device and records the requesting detection and defense device as the entrusting device.
[0071] The determination of a detection and defense device with sufficient resources includes: after receiving a detection task coordination request, the collaborative controller sends a remaining resource feedback instruction to other detection and defense devices, so that the other detection and defense devices respond to the remaining resource feedback instruction and provide feedback on the remaining resource quantity of the corresponding target device; and after receiving feedback on the remaining resource quantity of the target device from other detection and defense devices of the collaborative controller, the detection and defense device whose remaining resource quantity meets the preset requirements (needs to meet the resource requirements of the intrusion detection task) is recorded as a detection and defense device with sufficient resources.
[0072] Selecting a resource-sufficient detection and defense device as the delegated device includes: determining the device type of the target device deployed by the delegated device, and determining the network distance between the delegated device and the delegated device. Based on the device type and network distance, a resource-sufficient detection and defense device is selected as the delegated device. For example, among multiple resource-sufficient detection and defense devices, one with a similar device type and / or the shortest network distance is selected as the delegated device. In other embodiments, a detection and defense device with the largest remaining resource quantity can also be selected as the delegated device.
[0073] If there are no sufficiently resourced detection and defense devices, the coordination controller cannot respond to the detection task coordination request and will send a notification to the delegated device that the detection task cannot be transferred. Upon receiving the notification that the detection task cannot be transferred, the delegated device will abandon the execution of the intrusion detection task to ensure the successful completion of high-priority tasks and will start a timer. If, after waiting for a certain time threshold, the target device still lacks sufficient resources, it will resend the task coordination request to the coordination controller.
[0074] S203: Send a detection task transfer instruction to the delegated device, so that the delegated device responds to the detection task transfer instruction and executes the intrusion detection task transferred by the delegated device.
[0075] After identifying the delegated device, the collaborative controller generates a task transfer instruction and sends it to the delegated device, notifying it to take over the intrusion detection task from the delegated device. Simultaneously, the collaborative controller notifies the delegated device that its intrusion detection task is being executed by the delegated device. The task transfer instruction includes the delegated device's ID.
[0076] After receiving the task transfer instruction, the delegated device responds to the task transfer instruction and executes the intrusion detection task transferred by the delegated device. Specifically, upon receiving the task transfer instruction, the delegated device establishes a secure connection with the delegated device using the delegated device's ID, obtains and caches the detection rules corresponding to the intrusion detection task to be transferred by the delegated device, recording them as delegated detection task rules. Then, it uses these delegated detection task rules to monitor the delegated device and obtain relevant data, thereby generating detection data. Furthermore, upon receiving the task transfer instruction, the delegated device determines whether it and the delegated device are in the same subnet. If they are in the same subnet, it directly calls the delegated detection task rules from the detection rule base; if they are not in the same subnet, it notifies the delegated device to forward the delegated detection task rules via routing assistance.
[0077] During the process of the delegated device responding to the detection task transfer instruction and executing the intrusion detection task transferred by the delegated device, the delegated device is also used to: if an abnormal event is detected (i.e., a rule is triggered in the delegated detection task rules), determine whether the rule triggered in the abnormal event is a collaborative rule; if the rule triggered in the abnormal event is not a collaborative rule, the delegated device generates intrusion detection data and sends the intrusion detection data to the collaborative controller, so that the collaborative controller executes the collaborative analysis task, i.e., executes steps S102 to S103. If the rule triggered in the abnormal event is a single-point rule, the delegated device generates single-point detection data and sends it to the delegated device, so that the delegated device performs security defense based on the single-point detection data. The single-point detection data includes the triggered rule ID and the detection result, so that after receiving the single-point detection data sent by the delegated device, the delegated device executes relevant defense strategies based on the triggered rule ID and the detection result in the single-point detection data, thereby completing the security defense.
[0078] The detection rule base of the detection and defense device stores rules including collaborative rules and single-point rules. Collaborative rules are application rules that require multiple detection and defense devices to perform collaborative detection, and subsequently, the collaborative controller performs collaborative analysis based on multiple intrusion detection data from these devices. In contrast to collaborative rules, single-point rules are rules used by the detection and defense device to detect local intrusion events on the corresponding target device. These rules are of the same type as the scheduling rules in traditional IDS / IDPS systems.
[0079] In this embodiment, during the execution of the transferred intrusion detection task, the detection and defense device will perform different feedback processing according to different types of abnormal events, so that the intrusion detection and defense system can perform different security defenses in a timely manner, reduce vehicle security risks, and improve vehicle safety.
[0080] Furthermore, during the process of the delegated device responding to the detection task transfer instruction and executing the intrusion detection task transferred by the delegated device (i.e., the delegated intrusion detection task), the delegated device will monitor its own resource status (i.e., the resource status of the corresponding target device) in real time. If it finds that its own resources are insufficient (i.e., insufficient to complete the currently delegated intrusion detection task or its own task), the delegated device will send a notification to the coordination controller that it cannot complete the delegation, and at the same time, it will delete the relevant data (including rules and monitoring data) of the delegated device in the cache to release resources. After receiving the notification from the delegated device that it cannot complete the delegation, the coordination controller will re-query the resource status of other remaining detection and defense devices, find a suitable detection and defense device to execute the intrusion detection task transferred by the delegated device, ensure that the intrusion detection task is completed, and guarantee vehicle security.
[0081] Simultaneously, after sending the intrusion detection task coordination request, the delegating device also monitors its own resource status in real time. When the delegating device detects sufficient resources to complete the transferred intrusion detection task, it sends a notification to the coordinating controller and the delegated device: terminate the delegation of the intrusion detection task. This causes the delegated device to respond to the notification, stop executing the delegated intrusion detection task, and delete the cached relevant data (including rules and monitoring data) of the delegating device to release resources. After sending this notification, the delegating device will begin executing the intrusion detection task.
[0082] In this embodiment, upon receiving a detection task coordination request from a detection and defense device, the coordination controller, after determining that a detection and defense device with sufficient resources exists, selects one such device as the delegated device and records the requesting device as the delegating device. It then sends a detection task transfer instruction to the delegated device, enabling it to respond and execute the intrusion detection task transferred by the delegating device. This adds an adaptive task coordination (migration) function to the intrusion detection and defense system, utilizing the vehicle's redundant computing power to mitigate potential resource contention risks. It avoids the problem of traditional single-point IDS / IDPS systems being unable to continuously provide security services to vehicles when local node resources are insufficient, further improving detection accuracy and reducing vehicle security risks.
[0083] In one embodiment, the intrusion detection and prevention system further includes a cloud that communicates with the cooperative controller, the cloud being used to store vehicle rule update packages. The cooperative controller also includes a rule update module, which is used to perform rule update tasks, namely: updating the detection rule base of each detection and prevention device based on the vehicle rule update package.
[0084] Traditional IDS / IDPS systems typically update the rules of the vehicle's IDS / IDPS system via the cloud. However, different vehicle models have different functions, and even vehicles of the same type may use different functions. Updating rules via the cloud presents challenges because the cloud cannot know the actual functional deployment of the vehicle. This can easily lead to rule update errors or conflicts. Furthermore, different vehicles have different functional deployments, resulting in different rule packages, requiring significant cloud resources for rule package maintenance and management. For example, detection and defense devices are deployed on the cockpit domain and the Advanced Driving Assistance System (ADAS) domain, and these two domains are connected to completely different networks. The cockpit domain connects to networks such as Wi-Fi, Bluetooth, 4 / 5G, CAN, and USB, while the ADAS domain typically uses networks like CAN, LIN, and LVDS. Moreover, the communication protocols of these networks are different. If the cloud directly sends the rule packages that need updating to the cockpit domain and the ADAS domain, the cloud must record the network topology of both the cockpit domain and the ADAS domain. Similarly, the functional configurations of different car models also vary. Even under a paid software service model, different vehicles of the same model will have different network communication and data usage characteristics due to different subscription services. Therefore, the cloud will have to maintain tens of millions of vehicle configuration records for each vehicle.
[0085] In this embodiment, when rule updates are needed, the collaborative controller directly obtains the vehicle-wide rule update package from outside the vehicle. Then, based on this update package, it updates the detection rule base of each detection and defense device, providing a rule distribution function. By decoupling the information coupling between the vehicle's external environment and on-board functions, as well as each detection and defense device, the collaborative controller can deploy, manage, and distribute rules according to the actual functions of the vehicle. This is more adaptable to vehicle function updates, reducing the possibility of rule update errors or conflicts caused by traditional cloud-based rule updates, improving rule update accuracy, and eliminating the need to maintain extensive information on the functional distribution of various vehicle models and the deployment of IDS / IDPS systems. This is beneficial for management in large-scale intelligent connected vehicle applications. Furthermore, it avoids large-scale modifications to cloud-based collection systems, increasing the compatibility of the in-vehicle intrusion prevention collaborative design.
[0086] In one embodiment, updating the detection rule base of each detection and defense device based on the vehicle rule update package includes: determining the node update rule package of each detection and defense device based on the vehicle rule update package; and sending each node update rule package to the corresponding detection and defense device so that each detection and defense device updates the received node update rule package into the detection rule base.
[0087] Specifically, such as Figure 6 As shown, when the collaborative controller executes a rule update task, it performs the following steps: S301: Determine the node update rule package for each detection and defense device based on the whole vehicle rule update package.
[0088] When a new vehicle rule update package is stored in the cloud, the collaborative controller securely retrieves the package from the cloud and then determines the node update rule packages for each detection and defense device based on it. To ensure data transmission security, encrypted communication is used when retrieving the vehicle rule update package.
[0089] In one embodiment, the vehicle rule update includes multiple detection rules from multiple detection and defense devices, which include multiple single-point rules and / or distributed rules. After obtaining the vehicle rule update package, the collaborative controller needs to decompress the package and perform security verification, such as vehicle rule update package security authentication and content integrity verification. After the security verification is passed, the collaborative controller needs to decompose the vehicle rule update package according to preset splitting rules to obtain node update rule packages for each detection and defense device.
[0090] The vehicle rule update package includes multiple detection rules, the ID of each detection rule (ruleID), a list of target functions protected by each detection rule (protected_functions), the minimum requirements for processor type and memory for each detection rule (Requirement), and optional pre-defined recommended deployment instructions (recommend). The target function list is the target device list, which includes the IDs of each target device protected by the detection rule.
[0091] These include multiple detection rules, specific content, and rule types (including single-point rules and collaborative rules). For example, through...<Rule,[Association Rules]> This represents a detection rule. `rule` specifies the details of this intrusion detection and defense rule, typically expressed as an extended Boolean. `[Association Rules]` is the associated rule expression, used to identify the rule type of this detection rule. If `[Association Rules]` is empty, it indicates that this detection rule is a single-point rule; if `[Association Rules]` is not empty, it indicates that this detection rule is a collaborative rule, i.e., a distributed detection rule.
[0092] Here, `recommend` is an optional, pre-defined recommended deployment instruction for the target device. This recommended deployment instruction can be either a mandatory or a reference type. When the recommended deployment instruction is mandatory, the cooperative controller must deploy the corresponding device as required by the instruction. When the recommended deployment instruction is reference type, the cooperative controller can deploy the device according to the actual situation of the vehicle, or even ignore the recommended deployment instruction.
[0093] After decompressing the vehicle rule update package and passing security verification, the collaborative controller needs to filter out the deployable target devices based on `protected_functions` and `Requirement`, and then group and package multiple detection rules according to the target device to obtain the node update rule package for each target device. This node update rule package for each target device is then used as the node update rule package for its corresponding detection defense device, resulting in the node update rule package for each detection defense device. In all node update rule packages, `protected_functions`, `requirement`, and `recommend` have been removed, retaining only the detection rules and their IDs.
[0094] During the process of grouping and packaging multiple detection rules according to the target device, the rule types of each detection rule are judged. If the rule type is a collaborative rule, the collaborative controller will record <ruleID, <Rule, [AssociationRules]>> locally, that is, record the ID of the collaborative rule, the specific rule content, and the rule type. Then, the rule content irrelevant to the target device is removed from the specific rule content of the collaborative rule to obtain new rule content, which is used as the specific rule content (Rules’) of the collaborative rule. Then, the ID of the detection rule, the new rule content, and the collaborative rule identifier (such as [Collaboration]) are packaged into the node update rule package of the target device. That is, after updating <ruleID, <Rule, [Association Rules]>> to <ruleID, Rules’, [Collaboration]>, it is then packaged into the node update rule package of the target device.
[0095] In other embodiments, the method for determining the node update rule packages of each detection and defense device based on the vehicle-wide rule update package can also be other methods. For example, through a pre-mapped relationship and rule update criteria, the vehicle-wide rule update package can be updated to node rule packages, thereby obtaining the node update rule packages of each detection and defense device, which will not be elaborated here.
[0096] S302: Send each node update rule package to the corresponding detection and defense device so that each detection and defense device updates the received node update rule package to the detection rule library.
[0097] After obtaining the node update rule packages of each detection and defense device, each node update rule package is sent to the corresponding detection and defense device respectively. After each detection and defense device receives the node update rule package, the detection rules in its node update rule package are updated to the detection rule library, and the detection and defense device starts to implement the detection rule.
[0098] In this embodiment, the collaborative controller communicates with the cloud as the unified proxy node on the vehicle side. The cloud does not need to know the internal topology network of different vehicle models and the deployment of detection and defense devices. It only needs to send the vehicle-wide rule update package to the collaborative controller. The collaborative controller decomposes the vehicle-wide rule update package into the node update rule packages of each detection and defense device, and then sends each node update rule package to the corresponding detection and defense device so that each detection and defense device updates the received node update rule package to the detection rule library. This can reduce the possibility of rule update errors or conflicts caused by traditional cloud rule updates and improve the accuracy of rule updates.
[0099] In one embodiment, step S302, sending each node update rule packet to the corresponding detection and defense device so that each detection and defense device updates its detection rule base with the received node update rule packet, includes: determining whether a rule update delegation request from a detection and defense device has been received; if no rule update delegation request has been received, then sending each node update rule packet to the corresponding detection and defense device so that each detection and defense device updates its own detection rule base with the received node update rule packet. If a rule update delegation request has been received, then determining the delegated detection and defense device; sending each node update rule packet to the corresponding detection and defense device, and simultaneously sending the node update rule packet of the requesting detection and defense device to the delegated detection and defense device so that each detection and defense device updates its own detection rule base with the received node update rule packet.
[0100] That is, the collaborative controller is also specifically used to perform the following steps: S3021: Determine whether a rule update delegation request for the detection defense device has been received.
[0101] After decomposing the vehicle rule update package into node update rule packages for each detection and defense device, it is determined whether a rule update delegation request has been received from the detection and defense device. This rule update delegation request is a task delegation request generated when the detection and defense device detects insufficient resources for its corresponding target device.
[0102] S3022: If no rule update request is received, the update rule package of each node is sent to the corresponding detection and defense device so that each detection and defense device updates the node rule library with the received node update rule package.
[0103] If no rule update request is received, the collaborative controller sends the rule update packets for each node to the corresponding detection and defense device. Each detection and defense device then updates its node rule database upon receiving the received rule update packets, and the changes take effect.
[0104] S3023: If a rule update delegation request is received, the delegated detection and defense device is determined.
[0105] If a rule update delegation request is received, the collaborative controller can determine the delegated detection and defense device based on the request. For example, if the request includes a specified detection and defense device (which performs the rule update task of the device that sent the request), then the device specified in the request can be used as the delegated device, which is simple and convenient.
[0106] In other embodiments, the collaborative controller may also have a corresponding business delegation database. This database stores each detection and defense device and the detection and defense devices specified by each device. This database can be stored in key-value pairs using the IDs of the detection and defense devices, eliminating the need for local storage. Upon receiving a rule update delegation request, the database is searched for the specified detection and defense device corresponding to the ID of the detection and defense device that sent the update request, and this device is designated as the delegated detection and defense device. By managing the specified detection and defense devices of each detection and defense device through the collaborative controller, each device itself does not need to store or search for its specified devices, reducing the resource consumption of each device.
[0107] S3024: Send the node update rule packets to the corresponding detection and defense devices, and at the same time send the node update rule packets of the requested detection and defense devices to the entrusted detection and defense devices, so that each detection and defense device will update the detection rule database with the received node update rule packets.
[0108] After determining the entrusted detection and defense device, each node update rule packet is sent to the corresponding detection and defense device. Simultaneously, the node update rule packet of the requesting detection and defense device (i.e., the detection and defense device that sent the rule update entrustment request) is sent to the entrusted detection and defense device. Upon receiving the node update rule packet, each detection and defense device updates its detection rule base and begins implementation.
[0109] In other words, the collaborative controller not only sends the node update rule packet from the detection and defense device that sent the rule update delegation request to the same device, but also simultaneously sends it to the delegated detection and defense device. That is, the delegated detection and defense device receives two types of node update rule packets: its own node update rule packet and the node update rule packet from the detection and defense device that sent the rule update delegation request. Specifically, when sending node update rule packets, the collaborative controller sends its own node update rule packet and the node update rule packet from the detection and defense device that sent the rule update delegation request to the delegated detection and defense device as two independent sub-packets.
[0110] Upon receiving two node update rule packets from the collaborative controller, the delegated detection and defense device updates its detection rule base with these two packets, and the update takes effect. The delegated detection and defense device and the detection and defense device that sent the rule update request share the same detection rules and can execute the same intrusion detection task simultaneously, facilitating subsequent resource balancing and management, and further improving the accuracy of intrusion detection. Furthermore, receiving a rule update request from a detection and defense device indicates that the target device is experiencing resource constraints. Forwarding its node update rule packets through the collaborative controller, rather than the detection and defense device itself forwarding them to the delegated detection and defense device, reduces resource consumption. Moreover, sending its own node update rule packets and the node update rule packets from the detection and defense device that sent the rule update request to the delegated detection and defense device simultaneously requires only one communication, reducing the overall network load.
[0111] In this embodiment, after the whole vehicle rule update package is decomposed into node update rule packages for each detection and defense device, the collaborative controller determines whether it has received a rule update request from the detection and defense device; then, based on the judgment, it executes different rule update strategies, which can realize the collaborative update of detection rules, facilitate subsequent resource balancing and management, and reduce the load on the entire network.
[0112] In one embodiment, the detection rule base of each detection and defense device includes a node rule base and a temporary rule base. The node rule base is used to store and apply the detection rules of the detection and defense device itself and needs to be stored locally. The temporary rule base is used to process and apply the detection rules of other detection and defense devices (such as the detection rules delegated when a rule update task is entrusted to it) and does not need to be stored locally. That is, after receiving two node update rule packets sent by the collaborative controller, the entrusted detection and defense device updates its own node update rule packets to its own node rule base, and updates the node update rule packets of the detection and defense device that sent the rule update delegation request to its temporary rule base. Using separate rule bases to store different types of detection rules avoids confusion between its own detection rules and the delegated detection rules, and avoids logical confusion when the detection and defense device performs intrusion detection tasks.
[0113] In one embodiment, to ensure efficient resource management, the coordination controller maintains two mandatory databases and one optional database. The two mandatory databases are a top-level rule database and a business delegation database; the optional database is a vehicle function inventory database. The top-level rule database is a distributed collaborative analysis rule database (which can store rules for different vehicle scenarios), used to aggregate intrusion detection data from various detection and defense devices for collaborative analysis to obtain collaborative analysis data. The business delegation database stores multiple detection and defense devices that require rule update delegation, as well as the delegated detection and defense devices. Both are stored using key-value pairs, eliminating the need for local storage and reducing resource consumption. The vehicle function inventory database stores all vehicle functions of the vehicle and deploys an ID for each vehicle function (target device). This ID is typically also the ID of the detection and defense device deployed on it. Each time the coordination controller obtains a vehicle rule update package, it needs to check the vehicle function inventory database to determine if all functions in the target function list of the vehicle rule update package exist in the vehicle function inventory database, ensuring that rules can be distributed correctly and accurately subsequently.
[0114] The vehicle function manifest library can also be maintained by other functions, such as the application manager. If the vehicle function manifest library and the coordination controller are not on the same target device node, such as the coordination controller being on the T-BOX while the vehicle function manifest library is on the cockpit system, each time the coordination controller obtains a vehicle rule update package, it needs to send the list of target functions in the vehicle rule update package to the other functions (other devices) being maintained. This allows the maintenance function of the vehicle function manifest library to check the vehicle function manifest library to determine if all the functions in the list of target functions in the vehicle rule update package exist in the vehicle function manifest library, and to feed back the detection results to the coordination manager so that the coordination manager can subsequently distribute rules correctly and accurately.
[0115] In one embodiment, the collaborative controller further includes a log management module, which is used to perform log management tasks, namely: receiving log information from each detection and defense device and sending it to the cloud, so that the cloud can perform vehicle safety analysis based on the log information from each detection and defense device.
[0116] Specifically, the collaborative controller can trigger log collection operations for each detection and defense device via external commands or a timer, and send log collection commands to each detection and defense device. Upon receiving the log collection command from the collaborative controller, each detection and defense device responds by compressing its log information and sending it to the collaborative controller. After sending the log collection command, the collaborative controller waits until it has collected log information from all detection and defense devices, then packages the log information and sends it to the cloud. This allows the cloud to perform vehicle safety analysis based on the log information from each detection and defense device, enabling relevant personnel to update vehicle functions promptly based on the analysis results. In other embodiments, after collecting the log information from all detection and defense devices, the collaborative controller can also perform vehicle safety analysis on the log information and send the resulting safety analysis data to relevant personnel (such as vehicle owners or manufacturers). The collaborative controller can also package the entire safety analysis data and the log information from all detection and defense devices and send it to the cloud.
[0117] The intrusion detection and prevention system in this embodiment aggregates the log information of each detection and prevention device through a collaborative controller and transmits it to the cloud, so that the data is unified to the outside world (the cloud) and only one device is reflected. It is compatible with existing common technical solutions in data transmission, which can avoid large-scale transformation of the cloud collection system and increase the compatibility of the design.
[0118] In one embodiment, each detection and defense device and the collaborative controller are equipped with a data encryption module, which is used to encrypt transmitted data (such as node update rule packets and log information) to ensure communication security.
[0119] In one embodiment, each detection and defense device is equipped with a data verification module. This data verification module is used to perform data authentication based on a preset symmetric key and data verification based on binary data and configuration files on the data received by the detection and defense device (such as node update rule packets) to ensure the security of transmitted data and reduce vehicle security risks.
[0120] In one embodiment, a vehicle is provided, the vehicle including a cooperative controller and a plurality of detection and defense devices, each detection and defense device being deployed on a plurality of target devices covering the entire vehicle network; the cooperative controller cooperates with the plurality of detection and defense devices to perform the functions of the aforementioned intrusion detection and defense system.
[0121] In one embodiment, such as Figure 7 As shown, an electronic device is provided, which may be a cooperative controller, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the functions of the cooperative controller in the above-described intrusion detection and prevention system, or implements the arrangement of the intrusion detection and prevention method described below.
[0122] In one embodiment, an electronic device is provided, which may be a detection and defense device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the function of the detection and defense device in the intrusion detection and defense system described above, or implements the arrangement of the intrusion detection and defense method described below.
[0123] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, performs the functions of the intrusion detection and prevention system described above.
[0124] In one embodiment, such as Figure 8 As shown, an intrusion detection and defense method is provided, which is applied to... Figure 1 Taking the collaborative controller in the example, the following steps are included: SA10: Collaborative intrusion detection of multiple target devices on a vehicle is performed by multiple detection and defense devices to obtain intrusion detection data from each detection and defense device; SA20: Performs collaborative analysis based on intrusion detection data from various detection and defense devices, and sends defense commands to the corresponding detection and defense devices when abnormal events are detected, so that the corresponding detection and defense devices can respond to the defense commands to perform security defense on the corresponding target devices.
[0125] In this embodiment, multiple detection and defense devices perform collaborative intrusion detection on multiple target devices covering the entire vehicle network, obtaining intrusion detection data from each device. Based on this data, collaborative analysis is performed, and when an abnormal event is detected, a defense command is sent to the corresponding detection and defense device. This enables the device to respond to the command and provide security protection for the target device. This achieves collaborative intrusion detection and defense across nodes, domains, or regions within the vehicle network, improving the accuracy of vehicle security detection and thus reducing vehicle security risks.
[0126] Furthermore, the cross-verification of multiple detection and defense devices reduces false alarms and further improves the accuracy of vehicle security detection. The separate deployment of multiple detection and defense devices effectively adds layers of defense, reducing the risk of rule bypassing through single-point deployments and enabling the detection of complex attacks that traditional IDS / IDPS systems cannot detect, thus enhancing the robustness and security of vehicle network security. Moreover, different target devices have different computational strengths, allowing for distributed deployment of detection and defense devices based on the characteristics of each target device, resulting in high adaptability.
[0127] In one embodiment, multiple detection and defense devices can also perform collaborative intrusion detection on multiple target devices covering the entire vehicle network, obtaining intrusion detection data from each detection and defense device. This data is then used for collaborative analysis and defense. This increases the detection range of the detection and defense devices, covering the entire vehicle network and further improving the robustness and security of vehicle security functions.
[0128] In one embodiment, an intrusion detection and defense method is provided, which is applied to... Figure 1 Taking the detection and defense device in the middle as an example, the following steps are included: SB10: The detection defense system performs intrusion detection on the target devices it deploys and obtains intrusion detection data; SB20: Intrusion detection data is sent to the collaborative controller so that after receiving intrusion detection data from multiple detection and defense devices, the collaborative controller performs collaborative analysis based on the multiple intrusion detection data and sends defense commands to the corresponding detection and defense devices when an abnormal event is detected.
[0129] SB30: Receives defense commands sent by the collaborative controller and responds to the defense commands to perform security defense on the target devices deployed by itself.
[0130] In this embodiment, intrusion detection is performed on the target device deployed by the detection and defense device itself to obtain intrusion detection data; Intrusion detection data is sent to a collaborative controller, which, upon receiving intrusion detection data from multiple detection and defense devices, performs collaborative analysis based on this data. When anomalies are detected, it sends defense commands to the corresponding detection and defense devices. Other devices receive these commands and respond accordingly to provide security protection for their deployed target devices. This achieves collaborative intrusion detection and defense across nodes, domains, or regions within vehicles, improving the accuracy of vehicle security detection and thus reducing vehicle security risks.
[0131] In one embodiment, an intrusion detection and defense method is provided, which is applied to... Figure 1 Taking intrusion detection and defense as an example, the following steps are included: S10: Each detection and defense device performs intrusion detection on the target device it deploys, and obtains the intrusion detection data of each detection and defense device.
[0132] S20: Each detection and defense device sends intrusion detection data to the coordinating controller.
[0133] S30: The collaborative controller receives intrusion detection data from each detection and defense device and performs collaborative analysis based on the intrusion detection data from each detection and defense device to analyze whether there are any abnormal events.
[0134] S40: When the cooperative controller analyzes an abnormal event, it generates a defense command and sends the defense command to each detection and defense device in the cooperative detection.
[0135] S50: Each detection and defense device receives defense instructions and responds to the defense instructions to carry out security defense on the target devices it has deployed.
[0136] In practical use, each detection and defense device performs intrusion detection on the target devices it deploys, obtaining intrusion detection data for each device, and then sends this data to the collaborative controller. The collaborative controller then receives the intrusion detection data from each device and performs collaborative analysis to determine if any abnormal events are detected. When an abnormal event is detected, the collaborative controller generates a defense command and sends it to each of the collaborative detection and defense devices. Finally, each device receives and responds to the defense command to provide security protection for its deployed target devices. This system enables collaborative intrusion detection and defense across nodes, domains, or regions within a vehicle network, improving the accuracy of vehicle security detection and reducing security risks. Furthermore, the detection and defense devices can be distributed and deployed according to the characteristics of each target device, offering strong adaptability; multiple devices can cross-verify each other, reducing false alarms and further improving the accuracy of vehicle security detection; and the separate deployment of multiple devices effectively adds multiple layers of defense, reducing the risk of rule bypassing in single-point deployments and enhancing the robustness and security of vehicle network security.
[0137] Specific limitations regarding intrusion detection and prevention methods can be found in the limitations of intrusion detection and prevention systems described above, and will not be repeated here. The various modules of the collaborative controller and detection and prevention devices in the aforementioned intrusion detection and prevention system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in hardware or independently of the processor in the computer device, or stored in software in the memory of the computer device, so that the processor can call and execute the corresponding operations of each module.
[0138] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the methods described above. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory.
[0139] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0140] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. An intrusion detection and prevention system, characterized in that, It includes a collaborative controller and multiple detection and defense devices, each of which is deployed on multiple target devices of the vehicle. Each of the aforementioned detection and defense devices is used to: perform coordinated intrusion detection on multiple target devices, obtain intrusion detection data, and feed it back to the coordinated controller; The collaborative controller is used to: perform collaborative analysis based on the intrusion detection data of each of the detection and defense devices, and send defense commands to the corresponding detection and defense devices when an abnormal event is detected. Each of the aforementioned detection and defense devices is further configured to: respond to the defense command of the cooperative controller to perform security defense on the corresponding target device.
2. The intrusion detection and prevention system as described in claim 1, characterized in that, The step of collaboratively analyzing intrusion detection data from each of the aforementioned detection and defense devices, and sending defense commands to the corresponding detection and defense devices when an abnormal event is detected, includes: Upon receiving intrusion detection data from any of the aforementioned detection and defense devices, the aforementioned detection and defense devices and the detection and defense devices that require collaborative detection are denoted as target detection and defense devices. Collaborative analysis data is obtained by performing collaborative analysis on intrusion detection data from all the aforementioned target detection and defense devices. When the collaborative analysis data indicates that the abnormal event has been detected, the defense command is sent to the target detection defense device.
3. The intrusion detection and prevention system as described in claim 2, characterized in that, The intrusion detection data based on all the target detection and defense devices is used for collaborative analysis to obtain collaborative analysis data, including: If intrusion detection data from all the target detection and defense devices are received within a preset time period, then collaborative analysis is performed based on the intrusion detection data from all the target detection and defense devices.
4. The intrusion detection and prevention system as described in claim 1, characterized in that, The collaborative controller is also used to: coordinate resources among multiple detection and defense devices to regulate the detection and defense devices with sufficient resources to perform intrusion detection on behalf of the detection and defense devices with insufficient resources.
5. The intrusion detection and prevention system as described in claim 4, characterized in that, The method of coordinating resources among multiple detection and defense devices to allocate resources to devices with sufficient resources to perform intrusion detection on behalf of those with insufficient resources includes: If a detection task coordination request is received from the detection and defense device, after determining that there is a detection and defense device with sufficient resources, a detection and defense device with sufficient resources is selected and recorded as the entrusted device, and the requesting detection and defense device is recorded as the entrusting device. A detection task transfer instruction is sent to the delegated device, so that the delegated device responds to the detection task transfer instruction and executes the intrusion detection task transferred by the delegated device.
6. The intrusion detection and prevention system as described in claim 1, characterized in that, The intrusion detection and defense system also includes a cloud that communicates with the cooperative controller, the cloud being used to store vehicle rule update packages; The collaborative controller is also used to update the detection rule library of each of the detection and defense devices based on the vehicle rule update package.
7. The intrusion detection and prevention system as described in claim 6, characterized in that, The update of the detection rule base of each of the detection and defense devices based on the whole vehicle rule update package includes: Based on the vehicle rule update package, determine the node update rule package for each of the detection and defense devices; Each node update rule packet is sent to the corresponding detection and defense device, so that each detection and defense device updates its own detection rule base with the received node update rule packet.
8. The intrusion detection and prevention system as described in claim 7, characterized in that, The step of sending each node update rule packet to the corresponding detection and defense device, so that each detection and defense device updates its own detection rule base with the received node update rule packet, includes: If no rule update request is received from the detection and defense device, the node update rule package is sent to the corresponding detection and defense device so that each detection and defense device updates its own detection rule library with the received node update rule package.
9. The intrusion detection and prevention system as described in claim 7, characterized in that, The step of sending each node update rule packet to the corresponding detection and defense device, so that each detection and defense device updates its own detection rule base with the received node update rule packet, includes: If a rule update delegation request is received from the detection and defense device, the delegated detection and defense device is identified. Each node update rule packet is sent to the corresponding detection and defense device, and the node update rule packet requested by the detection and defense device is sent to the entrusted detection and defense device, so that each detection and defense device updates its own detection rule base with the received node update rule packet.
10. The intrusion detection and prevention system according to any one of claims 1-9, characterized in that, The collaborative controller is also used to: receive log information from each of the detection and defense devices and send it to the cloud, so that the cloud can perform a vehicle safety analysis based on the log information from each of the detection and defense devices.
11. The intrusion detection and prevention system according to any one of claims 1-9, characterized in that, The target device includes a central gateway and multiple domain controllers on the vehicle; the coordination controller is deployed in the vehicle's cockpit domain.
12. The intrusion detection and prevention system according to any one of claims 1-9, characterized in that, The target device includes a central computing platform and multiple zone controllers on the vehicle; the collaborative controller is deployed on the central computing platform of the vehicle.
13. An intrusion detection and defense method, characterized in that, include: Multiple detection and defense devices are used to perform coordinated intrusion detection on multiple target devices of the vehicle, and intrusion detection data of each detection and defense device is obtained. Based on the intrusion detection data of each of the aforementioned detection and defense devices, a collaborative analysis is performed, and when an abnormal event is detected, a defense command is sent to the corresponding detection and defense device, so that the corresponding detection and defense device responds to the defense command to perform security defense on the corresponding target device.
14. An intrusion detection and defense method, characterized in that, include: Intrusion detection is performed on the target devices deployed by the detection and defense device itself to obtain intrusion detection data; The intrusion detection data is sent to the collaborative controller, so that after receiving the intrusion detection data sent by multiple detection and defense devices, the collaborative controller performs collaborative analysis based on the multiple intrusion detection data, and sends a defense command to the corresponding detection and defense device when an abnormal event is detected. The system receives the defense command sent by the collaborative controller and responds to the defense command to perform security defense on the target device it has deployed.
15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the function of the cooperative controller in the intrusion detection and prevention system according to any one of claims 1-12, or the steps of the intrusion detection and prevention method according to claim 13.
16. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the function of the detection and defense device in the intrusion detection and defense system according to any one of claims 1-12, or the steps of the intrusion detection and defense method according to claim 14.
17. A vehicle, characterized in that, The vehicle includes a cooperative controller and multiple detection and defense devices, each of which is deployed on multiple target devices of the vehicle; the cooperative controller cooperates with the multiple detection and defense devices to implement the function of the intrusion detection and defense system as described in any one of claims 1-12.
18. A readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the functions of the intrusion detection and prevention system as described in any one of claims 1 to 12.
19. A computer program product comprising a computer program or computer-executable instructions, characterized in that, When the computer program or computer-executable instructions are executed by a processor, they perform the functions of the intrusion detection and prevention system according to any one of claims 1 to 12.