Network security processing method and device, electronic equipment and storage medium

By comparing data from the vehicle-to-everything (V2X) platform with mobile data, using drones to simulate vehicle data, and combining honeypot systems or network attack and defense platforms to trace the source of attacks, the technical problems of rapid defense and tracing the source of attacks after a vehicle has been hacked have been solved. This has enabled rapid security defense and attack tracing, improved network security and tracing the source of attacks when a vehicle is attacked, and ensured the effectiveness of improving vehicle network security and tracing attacks.

CN121151114APending Publication Date: 2025-12-16CHERY AUTOMOBILE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511585738.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-31
Publication Date
2025-12-16

AI Technical Summary

Technical Problem

Existing technologies make it difficult to quickly defend against cybersecurity breaches and trace the source of attacks after a vehicle has been hacked, resulting in reduced network security and increased difficulty in investigation.

Method used

By comparing vehicle data obtained from vehicles and mobile devices through the vehicle-to-everything (V2X) platform, and finding inconsistencies, drones are used to simulate vehicle data and interact with the network attack terminal. Combined with honeypot systems or network attack and defense platforms, the source of the attack is traced and the target address is determined.

Benefits of technology

It enables rapid activation of security defenses when a vehicle is attacked, accurately traces the source of the attack, reduces the probability of vehicle intrusion, and improves network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121151114A_ABST
    Figure CN121151114A_ABST
Patent Text Reader

Abstract

The invention discloses a network security processing method and device, electronic equipment and a storage medium, and the method comprises the steps: an Internet of Vehicles platform compares first vehicle data obtained from a vehicle with second vehicle data obtained from a mobile terminal, and controls an unmanned plane to simulate vehicle data under the condition that the comparison result is that the data are inconsistent; the unmanned aerial vehicle replaces the vehicle to become an attack object of the network attack end, and the target address of the network attack end is acquired according to the first interaction information between the unmanned aerial vehicle and the network attack end, so that the network security problem of the vehicle is solved from the source, and the technical effect of improving the network security of the vehicle is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and more particularly to a network security processing method and device, an electronic device and a storage medium. BACKGROUND

[0002] With the continuous progress of hacker technology, the number of events of car electronic systems being attacked by hackers is increasing, and the process of developing car electronic systems increasingly needs to consider and analyze hacker attacks as a factor to ensure that various functions and systems of new energy intelligent cars are not disturbed by malicious destruction and interference from the outside world.

[0003] Due to the strong support of the state for new energy vehicles, new energy intelligent cars have also been highly recognized by the market and have become the choice of more and more users for travel, but because intelligent cars carry more and more functions, network security problems and information security problems of vehicles occur frequently. In real life, vehicles have been invaded by hackers many times, causing vehicle users to be monitored for a long time. In recent years, intelligent networking has gradually become a necessary function of cars, so more attention should be paid to providing users with safe and reliable vehicle network services.

[0004] Therefore, how to immediately defend the vehicle network after the hacker invasion of the vehicle is discovered and trace the source of the invasion has become a problem to be solved. SUMMARY

[0005] Therefore, the embodiments of the present application provide a network security processing method and device, an electronic device and a storage medium, which can solve the network security problem of the vehicle and immediately defend the network and find the source of the attack when the intruder attacks the network of the vehicle.

[0006] The present application adopts the following technical solutions.

[0007] In a first aspect, the embodiments of the present application provide a network security processing method applied to a vehicle networking platform, the vehicle networking platform being in communication with a vehicle, a mobile terminal and a drone, and the processing method comprising: obtaining first vehicle data of a first time period from the vehicle and second vehicle data of the first time period from the mobile terminal, wherein the first vehicle data comprises positioning information, fuel quantity, power quantity and mileage of the vehicle, and the comparison result of the first vehicle data and the second vehicle data comprises data consistency or data inconsistency; if the comparison result is data inconsistency, a first control command is sent to the drone; the first control command is used to instruct the drone to simulate the first vehicle data of the vehicle; based on first interaction information between the drone and a network attack terminal, a target address of the network attack terminal is determined; the first interaction information comprises the first vehicle data sent to the network attack terminal through the drone.

[0008] In some embodiments, the second vehicle data in the mobile device is acquired from the vehicle via Bluetooth; before acquiring the second vehicle data for a first time period from the mobile device, the method includes: Send a second control command to the mobile device; the second control command is used to instruct the mobile device to obtain vehicle data for the first time period.

[0009] In some embodiments, after sending a first control command to the drone, the method includes: Store the first interaction information between the drone and the network attack client; back up a copy of the first interaction information.

[0010] In some embodiments, determining the target address of the network attacker based on the first interaction information between the drone and the network attacker includes: Using a copy of the first interactive information as the search space, determine the target information sent by the network attacker to the drone; obtain the target address of the network attacker based on the target information.

[0011] In some embodiments, after sending the first control command to the drone, the method further includes: Send a third control command to the drone; the third control command is used to instruct the drone to stop communicating with the vehicle-to-everything (V2X) platform and to communicate with the network attack and defense platform; the network attack and defense platform is used to determine the target address.

[0012] According to a second aspect of the embodiments of this application, a network security processing method is provided, applied to a drone, wherein the drone communicates with a vehicle networking platform, and the method includes: The system receives a first control command sent by the vehicle networking platform; simulates first vehicle data based on the first control command; wherein the first vehicle data includes the vehicle's location information, fuel level, battery level, and mileage; interacts with the network attack terminal based on the first vehicle data to obtain first interaction information; the first interaction information is used to determine the target address of the network attack terminal.

[0013] In some embodiments, after simulating first vehicle data of the vehicle according to a first control command, the method further includes: Receives a third control command sent by the vehicle networking platform; according to the third control command, stops communication with the vehicle networking platform and communicates with the network attack and defense platform; the network attack and defense platform is used to determine the target address.

[0014] According to a third aspect of the embodiments of this application, a network security processing apparatus is provided, applied to a vehicle-to-everything (V2X) platform, wherein the V2X platform communicates with vehicles, mobile terminals, and drones respectively, and the apparatus includes: A first acquisition module is used to acquire first vehicle data for a first time period from the vehicle and second vehicle data for a first time period from the mobile terminal; wherein, the first vehicle data includes the vehicle's location information, fuel level, battery level, and mileage; a second acquisition module is used to acquire the comparison result of the first vehicle data and the second vehicle data, the comparison result including whether the data is consistent or inconsistent; a first sending module is used to send a first control command to the drone if the comparison result is inconsistent; the first control command is used to indicate that the drone simulates the first vehicle data of the vehicle; a first processing module is used to determine the target address of the network attack terminal based on the first interaction information between the drone and the network attack terminal; the first interaction information includes the first vehicle data sent by the drone to the network attack terminal.

[0015] According to a fourth aspect of the embodiments of this application, a network security processing apparatus is provided, applied to a drone, wherein the drone communicates with a vehicle networking platform, the apparatus comprising: The first receiving module is used to receive the first control command sent by the vehicle networking platform; the second processing module is used to simulate the first vehicle data of the vehicle according to the first control command; wherein, the first vehicle data includes the vehicle's location information, fuel level, battery level, and mileage; the third processing module is used to interact with the network attack terminal based on the first vehicle data to obtain the first interaction information; the first interaction information is used to determine the target address of the network attack terminal.

[0016] According to a fifth aspect of the embodiments of this application, an electronic device is provided, the electronic device comprising: a processor; and a memory storing computer-readable instructions, wherein when the computer-readable instructions are executed by the processor, the above-described network security processing method is implemented.

[0017] According to a sixth aspect of the embodiments of this application, a computer-readable storage medium is provided, on which computer-readable instructions are stored, which, when executed by a processor or electronic device, implement the above-mentioned network security processing method.

[0018] In this application's solution, firstly, the vehicle-to-everything (V2X) platform obtains first vehicle data for a first time period from the vehicle and second vehicle data for a first time period from a mobile device. The mobile device can obtain vehicle data from the vehicle via Bluetooth and compares the first and second vehicle data. If a discrepancy is found, it indicates that the vehicle is under attack. Therefore, without consuming the vehicle's network, users can promptly detect whether their vehicle has been compromised through a mobile application. Secondly, when an attack is detected, a drone obtains vehicle data from the V2X platform and mimics the vehicle's network system, becoming the target of the attack instead of the vehicle, thus reducing the probability of vehicle intrusion. Finally, by recording and backing up the interaction information between the drone and the network attacker, the attack information launched by the network attacker against the drone can be accurately obtained, thereby locating the target address of the network attacker. Alternatively, a network attack and defense platform can replace the V2X platform to communicate with the drone, locating the target address of the network attacker. This achieves a fundamental solution to vehicle network security issues, enabling immediate activation of security defenses and tracing the source of the attack when a vehicle is attacked.

[0019] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0020] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.

[0021] Figure 1 This is a schematic diagram illustrating a network security processing method provided in an embodiment of this application.

[0022] Figure 2 This is a flowchart illustrating a network security processing method applied to a vehicle networking platform, as provided in an embodiment of this application.

[0023] Figure 3 This is a flowchart illustrating a method for obtaining a target address, as provided in an embodiment of this application.

[0024] Figure 4 This is a flowchart illustrating a network security processing method for unmanned aerial vehicles (UAVs) provided in an embodiment of this application.

[0025] Figure 5 This is a flowchart illustrating another method for obtaining a target address provided in an embodiment of this application.

[0026] Figure 6 This is a schematic diagram of a network security processing device provided in an embodiment of this application.

[0027] Figure 7 This is a schematic diagram of another network security processing device provided in an embodiment of this application.

[0028] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0029] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through specific embodiments. Detailed Implementation

[0030] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0031] In conventional technologies, the in-vehicle network system of new energy vehicles connects various components of the vehicle, including the battery management system, motor control system, and autonomous driving assistance system. Hackers can attack and infiltrate the vehicle's in-vehicle network system via wireless networks, controlling the vehicle's normal operation. When a vehicle is attacked by malicious software, it will immediately initiate network security defenses, typically using encryption and decryption technologies, firewalls, etc. However, hackers will immediately know that the vehicle has activated its security defenses, allowing them to launch guerrilla warfare across different vehicles on the vehicle networking platform. This not only compromises the vehicle's network security but also significantly increases the difficulty of tracing the source of the attack.

[0032] The network security processing method provided in this application is intended to solve the above-mentioned technical problems of the prior art.

[0033] The technical solution of this application and how it solves the above-mentioned technical problems will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.

[0034] Figure 1This is a schematic diagram illustrating a network security processing method provided in an embodiment of this application. Figure 1 As shown, the main body for executing the processing method provided in this application embodiment includes a first module 101 and a second module 102.

[0035] In one alternative implementation, the first module 101 refers to the vehicle networking platform.

[0036] In one alternative implementation, the second module 102 includes a drone 112, a vehicle 122, and a mobile terminal 132.

[0037] For example, the vehicle networking platform 101 may include, but is not limited to: drone server 111, network security module 121, and verification server 131.

[0038] For example, vehicle 122 may include, but is not limited to: Bluetooth, in-vehicle T-BOX.

[0039] Optionally, the aforementioned vehicle-to-everything (V2X) platform can communicate with the drone 112, vehicle 122, and mobile terminal 132 via a wireless connection. This wireless connection may include protocols such as Transmission Control Protocol / Internet Protocol (TCP / IP), Wireless Local Area Network (WLAN), and Remote Direct Memory Access (RDMA) over Converged Ethernet (RoCE).

[0040] Optionally, the vehicle 122 and the mobile terminal 132 can communicate via the vehicle's Bluetooth.

[0041] The following is combined with Figure 1The first module 101 and the second module 102 shown illustrate the network security processing method provided in this application embodiment: First, the vehicle network platform obtains first vehicle data from the vehicle-mounted T-BOX of the vehicle 122 and second vehicle data from the mobile terminal 132. The mobile terminal 132 obtains vehicle data from the vehicle via Bluetooth. The first vehicle data and the second vehicle data are compared by the verification server 131 to obtain a comparison result. When the comparison result shows that the data is inconsistent, the vehicle network platform sends a first control command to the drone and then determines the target address of the network attack terminal through the network security module 121. Second, the drone 112 receives the first vehicle data sent by the vehicle network platform through the drone server 111. Finally, the network security module 121 of the vehicle network platform determines the target address of the network attack terminal based on the first interaction information between the drone 112 and the network attack terminal.

[0042] Below Figure 1 Based on the first module 101 and the second module 102 shown, the network security processing method provided in the embodiments of this application will be further described, such as... Figure 2 The diagram illustrates a network security processing method applied to a vehicle-to-everything (V2X) platform. In a specific embodiment, this processing method can be applied to, for example... Figure 6 The first network security processing device 600 shown, or as... Figure 7 The second network security processing device 700 shown, and the electronic device 800 configured with the first network security processing device 600 or the second network security processing device 700. Figure 8 The specific process of the embodiments of this application will be described below. Of course, it is understood that this method can be executed by a cloud server with computing power.

[0043] The following will address... Figure 2 The process is described in detail. When applied to the vehicle networking platform, the vehicle networking platform communicates with the vehicle, mobile terminal and drone respectively. The network security handling method can specifically include the following steps 201 to 204.

[0044] Step 201: Obtain first vehicle data for a first time period from the vehicle and second vehicle data for a first time period from the mobile device; wherein, the first vehicle data includes the vehicle's location information, fuel level, battery level, and mileage.

[0045] In this embodiment, vehicle data is data related to vehicle performance, status, or driving behavior. In this embodiment, it may include vehicle location information, fuel level, battery level, mileage, etc. The location information can be obtained through an in-vehicle GPS positioning system or through navigation application software in a supporting mobile terminal.

[0046] In this embodiment of the application, the first vehicle data is vehicle data related to vehicle performance, status, or driving behavior that the vehicle networking platform directly obtains from the vehicle, and the second vehicle data is vehicle data related to vehicle performance, status, or driving behavior that the vehicle networking platform obtains from the mobile terminal.

[0047] In the first optional example, the vehicle's CAN bus collects vehicle data and transmits the collected vehicle data to the on-board T-BOX in real time. The on-board T-BOX then transmits the vehicle data to the vehicle networking platform in real time, and the vehicle networking platform obtains the first vehicle data directly from the vehicle.

[0048] Optionally, the mobile device obtains vehicle data from the vehicle in real time and stores it in the mobile application. The vehicle user can view the vehicle data in real time through the mobile application, and the vehicle networking platform can also obtain secondary vehicle data from the mobile application.

[0049] Optionally, when a vehicle's network is subjected to a malicious attack by a network attacker, the vehicle's data may be tampered with. At this time, the first vehicle data directly obtained by the vehicle networking platform from the vehicle may also be tampered with. However, since the mobile terminal's network has not been attacked, the vehicle data obtained by the vehicle networking platform from the mobile terminal will not change and will remain the data when the vehicle is in normal condition. Therefore, by comparing the first vehicle data and the second vehicle data in the same time period, it can be determined whether the vehicle has been attacked by a network attacker.

[0050] In one possible implementation, before obtaining the second vehicle data for the first time period from the mobile terminal in step 201, the specific implementation method of how the mobile terminal obtains the vehicle data for the first time period is further explained, including: Send a second control command to the mobile device; the second control command is used to instruct the mobile device to obtain vehicle data for the first time period.

[0051] In this embodiment of the application, the control command can be a programming language, which is used as an instruction for the management execution process and logic of the vehicle networking platform.

[0052] In this embodiment of the application, the second control command refers to the instruction sent by the vehicle networking platform to the mobile terminal to control the mobile terminal to perform the acquisition operation.

[0053] In the first optional example, when the vehicle is in motion, the second vehicle data on the mobile device is obtained from the vehicle in real time based on the Bluetooth connection between the mobile device and the vehicle. When the vehicle and the mobile device transmit data via Bluetooth, it will not occupy the vehicle's network or affect the vehicle's network performance.

[0054] Optionally, when the user gets out of the vehicle and locks it, the vehicle transmits the vehicle data from the last second before locking to the user's mobile device via Bluetooth. The mobile device then transmits the vehicle data to the vehicle networking platform. If the vehicle is attacked by a network attack after the user leaves the vehicle, the user can promptly detect whether their vehicle has been compromised through the communication between the mobile device and the vehicle networking platform.

[0055] Step 202: Obtain the comparison results of the first vehicle data and the second vehicle data. The comparison results include whether the data is consistent or inconsistent.

[0056] In this embodiment of the application, a verification server built in the vehicle network platform compares the first vehicle data and the second vehicle data obtained by the vehicle network platform to obtain the comparison result. When any one or more of the vehicle data, such as the vehicle's location information, fuel level, battery level, and mileage, are different, it is considered that the vehicle data has been tampered with, and the comparison result obtained by the vehicle network platform is that the data is inconsistent.

[0057] In the first optional example, select the first vehicle data and the second vehicle data within the same time period. If the location information in the first vehicle data and the location information in the second vehicle data are inconsistent within the same time period, and the comparison result is inconsistent, it indicates that the vehicle has been attacked by the network attack terminal.

[0058] In the second optional example, select the first vehicle data and the second vehicle data within the same time period. If the fuel level and battery level in the first vehicle data are inconsistent with those in the second vehicle data within the same time period, the comparison result will also be inconsistent, indicating that the vehicle has been attacked by the network attack terminal.

[0059] In the third optional example, select the first vehicle data and the second vehicle data within the same time period. If the location information, fuel level, battery level, and mileage in the first vehicle data within the same time period are consistent with the location information, fuel level, battery level, and mileage in the second vehicle data, and the comparison result is that the data is consistent, it means that the vehicle is in normal condition and has not been attacked by any network attack terminal.

[0060] Step 203: If the comparison result shows that the data is inconsistent, send a first control command to the UAV; the first control command is used to indicate: the first vehicle data of the UAV simulating the vehicle.

[0061] In this embodiment of the application, the first control command refers to the instruction sent by the vehicle networking platform to the drone for controlling the drone to perform simulated operations.

[0062] In the first optional example, if data inconsistency is detected, the vehicle-to-everything (V2X) platform can immediately start the drone and control it to simulate vehicle data by sending a first control command to the drone. The drone can also simultaneously simulate the network information of all hardware or software devices of the vehicle, including the network information of the vehicle-mounted T-BOX, host, pre-control, intelligent driving, and electric drive systems, etc., to deceive the network attacker into thinking that the drone is a vehicle and launching a network attack on it.

[0063] In the second alternative example, if data inconsistency is detected, the vehicle-to-everything (V2X) platform can also prompt the user to start the drone by sending an alarm signal to the mobile device. After the user confirms that the drone has been started via the mobile device, the V2X platform sends a first control command to the drone to control the vehicle data of the drone simulating the vehicle.

[0064] Step 204: Determine the target address of the network attacker based on the first interaction information between the drone and the network attacker; the first interaction information includes the first vehicle data sent from the drone to the network attacker.

[0065] In the embodiments of this application, interactive information refers to information generated during the process of information transmission, reception and feedback between different subjects through a certain channel or method.

[0066] In this embodiment of the application, the first interactive information is the information generated during the information transmission between the drone and the network attack terminal through network communication.

[0067] In this embodiment of the application, the target address is the IP address (Internet Protocol address) of the network device, which is key information for determining the communication device in the network communication process.

[0068] For example, in a communication network, each device connected to the network needs an IP address so that other devices can find and communicate with it. A network attacker attacks a vehicle's network system to tamper with the vehicle's data or perform other operations. Therefore, the network attacker must have the IP address of the device that launched the attack. Typically, network attackers use methods such as password acquisition, remote control intrusion, Trojan horse intrusion, and system vulnerability exploitation. Based on the interaction information between the network attacker and the drone during the attack, the IP address of the network attacker can be traced to find the IP address of the device that launched the attack, thereby solving the vehicle network security problem at its root.

[0069] For example, IP attribution is a method of analyzing and tracing network attack endpoints to determine the attacker's true identity and location; typically, methods of attribution by capturing the IP of network attack endpoints include security device alarms, honeypot systems, and network attack and defense platforms.

[0070] In the first optional example, IP tracing is performed using a honeypot system. This involves deploying a honeypot on the vehicle network platform to monitor and record intrusion behavior of network attackers, thereby obtaining host information, browser information, real IP address, and social information of the network attackers.

[0071] In the second alternative example, IP tracing is performed using a network attack and defense platform. This platform simulates and trains various network attack events, providing corresponding attack and defense strategies and practices. It can replace the vehicle network platform to obtain all information about the devices or servers of the network attacking party.

[0072] In this embodiment, firstly, the vehicle network platform compares first vehicle data obtained from the vehicle with second vehicle data obtained from the mobile terminal. Based on the inconsistency in the comparison results, it is determined that the vehicle has been attacked by a network attacker. The second vehicle data from the mobile terminal is obtained from the vehicle via Bluetooth, enabling data transmission without consuming the vehicle's network. Furthermore, since the data comparison is performed within the vehicle network platform, the vehicle's original architecture remains unchanged, preventing any increase in hardware costs. Secondly, the drone obtains vehicle data from the drone server within the vehicle network platform. This can be achieved by backing up the interaction information between the drone and the network attacker, obtaining the target address from the interaction information, or by using a network attack and defense platform to replace the vehicle network platform in communicating with the drone and implanting a Trojan horse into the network attacker to obtain the target address. This allows the drone to simulate vehicle data as the target of attack, ensuring the vehicle's network security.

[0073] After the vehicle-to-everything (V2X) platform sends the first control command to the drone, this application provides an optional implementation method for determining the target address of the network attack based on the first interaction information between the drone and the network attack target, such as... Figure 3 The flowchart shown illustrates a method for obtaining a target address, which may specifically include the following steps 301 to 304.

[0074] Step 301: Store the first interaction information between the drone and the network attack terminal.

[0075] In this embodiment, a honeypot system is used to trace the IP of the network attacking party. By monitoring and recording every interaction between the network attacking party and the drone in real time, such as login attempts, file access, command execution, etc., the information reflecting the activity trajectory and intent of the network attacking party can be stored in the log file of the honeypot system or the remote log file, which can improve the network security of the vehicle.

[0076] Step 302: Back up a copy of the first interactive information.

[0077] In this embodiment, since the first interaction information between the drone and the network attacker in the log file backed up in the honeypot system is easily deleted or tampered with by the network attacker, a remote log server under the same communication network is used to back up the first interaction information. The honeypot system monitors the vehicle networking platform, the drone and the remote log server at the same time. Since the remote log server has a more robust defense mechanism, it is not easy for the network attacker to break the remote log file, which further improves the network security of the vehicle.

[0078] Step 303: Use a copy of the first interaction information as the search space to determine the target information sent by the network attacker to the drone.

[0079] In this embodiment of the application, the target information is information containing the target address and possessing certain attack behavior patterns and characteristics.

[0080] In this embodiment, the honeypot system itself possesses the ability to identify patterns and characteristics of attack behavior, such as specific port scanning patterns and the behavioral characteristics of malware. By analyzing and identifying the first interaction information in the remote log file, the patterns and characteristics of the attack behavior launched by the network attacker against the drone can be obtained. By comparing this with a known attack pattern library, the type of attack and its possible source can be determined, and the target information sent by the network attacker to the drone can be obtained.

[0081] Step 304: Obtain the target address of the network attack terminal based on the target information.

[0082] For example, there are many ways to perform source tracing through honeypot systems, such as IP address tracing, domain name tracing, and malicious code analysis. In this embodiment, IP address tracing is used to obtain the target address of the network attack. This can be achieved by querying IP address databases and collaborating with internet service providers to determine the target address. The target address specifically includes the geographical location and affiliated organization of the IP address. Furthermore, by analyzing the target address's historical records and associated information, it can be determined whether it is part of a proxy server or a botnet, thus improving the accuracy and authenticity of the obtained target information.

[0083] In this embodiment, the honeypot system is used to obtain the target address of the network attacker. Combined with the technical means of remote log file backup of the first interaction information, all information of the entire interaction between the UAV and the network attacker can be completely obtained. This allows for the maximum depth of understanding of the multiple steps after the network attacker's attack behavior, providing more detection points and information for searching target information. Furthermore, the honeypot system does not require modification of the original network structure of the vehicle network platform. It is mostly integrated into the vehicle network platform in software form and will not misjudge normal requests of the vehicle network platform as attack behavior. It is friendly to the network environment of the vehicle network platform, with low deployment cost and high network security.

[0084] Based on the above, this application provides another optional implementation method for determining the target address of a network attacker based on the first interaction information between the drone and the network attacker. Specifically, it may include the following steps.

[0085] Send a third control command to the drone; the third control command is used to instruct the drone to stop communicating with the vehicle-to-everything (V2X) platform and to communicate with the network attack and defense platform; the network attack and defense platform is used to determine the target address.

[0086] In this embodiment of the application, the third control command refers to the instruction sent by the vehicle networking platform to the drone, which is used to control the drone to perform a disconnection or connection operation.

[0087] In this embodiment of the application, the network attack and defense platform provides a reliable method for responding to and handling network security incidents by simulating and training various network attack behaviors in the network communication between the vehicle network platform and the vehicle. Therefore, by replacing the vehicle network platform with the way the drone communicates with the drone, the network security defense capability of the vehicle can be improved.

[0088] For example, when the vehicle network platform receives a comparison result indicating data inconsistency, the vehicle network platform sends a third control command to the drone. The network attack and defense platform immediately connects to the communication with the drone and obtains all information about the network attack's device or server based on the first interaction information between the network attack and the drone, thus obtaining the target address of the network attack.

[0089] Based on the above, the following section addresses... Figure 4 The process shown will be explained in detail, such as Figure 4 The diagram shows a process flow chart for a network security processing method applied to drones. When applied to drones, the drone communicates with a vehicle networking platform. The network security processing method may specifically include the following steps 401 to 403.

[0090] Step 401: Receive the first control command sent by the vehicle networking platform.

[0091] In this embodiment of the application, the vehicle networking platform sends a first control command to the drone through a drone server set in the platform. After the drone receives the first control command, it immediately executes the first control command to simulate the first vehicle data operation of the vehicle.

[0092] For example, drones can be vehicle-mounted drones. As drone systems designed specifically for vehicle-mounted mobile platforms, vehicle-mounted drones typically feature portability, rapid deployment and retrieval, and adaptability to the vehicle environment. Based on the mobility and flexibility of vehicle-mounted drones, they can quickly take off and land while the vehicle is moving to complete specific tasks. For instance, a vehicle-mounted drone can fly away from the vehicle and send deceptive data to the network attack target to gain more interaction with the network attack target and increase the success rate of obtaining target information.

[0093] Step 402: According to the first control command, simulate the first vehicle data of the vehicle; wherein, the first vehicle data includes the vehicle's location information, fuel level, battery level, and mileage.

[0094] In this embodiment, the drone can masquerade as a vehicle and become the target of a network attack by simulating vehicle data, thereby ensuring the network security of the vehicle. Due to the high operability of the drone, the user can control the drone to fly away from the vehicle and send false data to the network attack. For example, the drone can fly to the sea where there is no vehicle. At this time, the drone's location information is sent to the network attack, and interactive behavior is carried out with the network attack. Useful information can be obtained from the attack behavior of the network attack as much as possible to improve the accuracy and success rate of IP tracing.

[0095] Step 403: Based on the first vehicle data, interact with the network attack terminal to obtain the first interaction information; the first interaction information is used to determine the target address of the network attack terminal.

[0096] In this embodiment, after the drone successfully impersonates a vehicle by simulating the first vehicle data, it sends the first vehicle data to the network attack terminal. Depending on the honeypot system deployed on the vehicle network platform, or the way the vehicle network platform is converted into a network attack and defense platform to communicate with the drone, the target address can be determined from the interaction information between the drone and the network attack terminal.

[0097] After simulating the first vehicle data according to the first control command, how to determine the target address of the network attack terminal? This application provides an optional implementation method, such as... Figure 5 The flowchart shown is another method for obtaining the target address, which may specifically include the following steps 501 to 502.

[0098] Step 501: Receive the third control command sent by the vehicle networking platform.

[0099] In this embodiment of the application, the vehicle networking platform sends a third control command to the drone through a drone server set in the platform. Upon receiving the third control command, the drone executes either a disconnect communication operation or a reconnect communication operation in the third control command.

[0100] Step 502: According to the third control command, stop communication with the vehicle network platform and communicate with the network attack and defense platform; the network attack and defense platform is used to determine the target address.

[0101] In this embodiment of the application, when a vehicle is attacked by a network attack, the drone executes a third control command after successfully simulating vehicle data. The drone disconnects from the vehicle network platform and immediately reconnects to the network attack and defense platform. Based on the various network attack behaviors in the network communication between the vehicle network platform and the vehicle, the network attack and defense platform can quickly provide corresponding handling methods when various attack behaviors are launched by the network attack, thereby obtaining the target address of the network attack.

[0102] For example, a network attacker launches an attack on a vehicle using a Trojan horse. After the drone implants the Trojan horse into the network attacker by simulating vehicle data, the drone disconnects from the vehicle network platform and connects to the network attack and defense platform. At this time, the network attack and defense platform can guide the network attacker to implant the Trojan horse into the network attack and defense platform. When the network attacker believes that it has broken through the vehicle network, the Trojan horse is implanted in reverse into the network attacker, which can obtain target information and also know all the hardware device information of the network attacker, thereby improving the vehicle's network security defense capabilities.

[0103] To achieve the functions of the above embodiments, the network security processing method includes hardware structures and / or software modules corresponding to each function. Those skilled in the art should readily recognize that, based on the units and method steps described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed through hardware or computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.

[0104] exist Figure 2 to Figure 5 Based on the network security processing method shown, this application embodiment also provides a first network security processing apparatus for further explanation, such as... Figure 6The diagram shows a network security processing device applied to a vehicle networking platform. The vehicle networking platform communicates with vehicles, mobile terminals, and drones respectively. The first network security processing device 600 includes: a first acquisition module 610, a second acquisition module 620, a first transmission module 630, and a first processing module 640.

[0105] The first acquisition module 610 is used to acquire first vehicle data for a first time period from the vehicle and second vehicle data for a first time period from the mobile terminal; wherein, the first vehicle data includes the vehicle's location information, fuel level, battery level, and mileage; wherein, the first acquisition module 610 may include, for example, Figure 1 The vehicle 122 and mobile terminal 132 in the first module 101 and the second module 102 shown.

[0106] The second acquisition module 620 is used to acquire the comparison result of the first vehicle data and the second vehicle data, the comparison result including whether the data is consistent or inconsistent; wherein, the second acquisition module 620 may include, for example, Figure 1 The first module 101 shown.

[0107] The first sending module 630 is used to send a first control command to the drone if the comparison result shows a data inconsistency; the first control command is used to indicate: the first vehicle data of the drone simulating a vehicle; wherein, the third control module 630 may include, for example, Figure 1 The first module 101 and the second module 102 shown contain the drone 112.

[0108] The first processing module 640 is used to determine the target address of the network attack terminal based on the first interaction information between the drone and the network attack terminal; the first interaction information includes first vehicle data sent from the drone to the network attack terminal; wherein, the first processing module 640 may include, for example, Figure 1 The first module 101 and the second module 102 shown contain the drone 112.

[0109] In some embodiments, the first acquisition module 610 includes: sending a second control command to a mobile terminal; the second control command is used to instruct: the mobile terminal to acquire vehicle data of the vehicle in a first time period.

[0110] In some embodiments, the first sending module 630 includes: storing first interaction information between the drone and the network attack terminal; and backing up a copy of the first interaction information.

[0111] In some embodiments, the first sending module 630 further includes: using a copy of the first interaction information as a search space to determine the target information sent by the network attacker to the drone; and obtaining the target address of the network attacker based on the target information.

[0112] In some embodiments, the first sending module 630 further includes: sending a third control command to the drone; the third control command is used to instruct: the drone to stop communicating with the vehicle networking platform and to communicate with the network attack and defense platform; the network attack and defense platform is used to determine the target address.

[0113] Similarly, in Figure 2 to Figure 5 Based on the network security processing method shown, this application embodiment also provides a second network security processing apparatus for further explanation, such as... Figure 7 The schematic diagram of another network security processing device shown is applied to a drone. The drone communicates with a vehicle networking platform. The second network security processing device 700 includes: a first receiving module 710, a second processing module 720, and a third processing module 730.

[0114] The first receiving module 710 is used to receive a first control command sent by the vehicle networking platform; wherein, the first receiving module 710 may include, for example, Figure 1 The first module 101 and the second module 102 shown contain the drone 112.

[0115] The second processing module 720 is used to simulate first vehicle data of the vehicle according to the first control command; wherein the first vehicle data includes the vehicle's location information, fuel level, battery level, and mileage; wherein the second processing module 720 may include, for example, Figure 1 The first module 101 and the second module 102 show the drone 112 and the vehicle 122.

[0116] The third processing module 730 is used to interact with the network attack terminal based on the first vehicle data to obtain first interaction information; the first interaction information is used to determine the target address of the network attack terminal; wherein, the third processing module 730 may include, for example, Figure 1 The first module 101 and the second module 102 shown contain the drone 112.

[0117] In some embodiments, the second processing module 720 includes: receiving a third control command sent by the vehicle networking platform; stopping communication with the vehicle networking platform and communicating with a network attack and defense platform according to the third control command; the network attack and defense platform is used to determine the target address.

[0118] According to one aspect of the embodiments of this application, Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 8 As shown, the electronic device 800 includes a processor 810 and one or more memories 820. The one or more memories 820 are used to store program instructions executed by the processor 810. When the processor 810 executes the program instructions, it implements the above-mentioned network security processing method.

[0119] Furthermore, the processor 810 may include one or more processing cores. The processor 810 runs or executes instructions, programs, code sets, or instruction sets stored in the memory 820, and retrieves data stored in the memory 820. Optionally, the processor 810 may be implemented using at least one hardware form selected from Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), and Programmable Logic Array (PLA). The processor 810 may integrate one or a combination of several of the following: a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), and a modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the displayed content; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor and may be implemented using a separate communication chip.

[0120] According to one aspect of this application, a computer-readable storage medium is also provided, which may be included in the electronic device described in the above embodiments; or it may exist independently and not assembled into the electronic device. The computer-readable storage medium carries computer-readable instructions that, when executed by a processor, implement the methods in any of the above embodiments.

[0121] It should be noted that the computer-readable medium shown in the embodiments of this application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such transmitted data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination thereof.

[0122] The units described in the embodiments of this application can be implemented in software or hardware, and the described units can also be located in a processor. The names of these units do not necessarily limit the specific unit itself.

[0123] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0124] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the embodiments disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein.

[0125] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A network security processing method, characterized in that, Applied to a vehicle-to-everything (V2X) platform, the V2X platform communicates with vehicles, mobile devices, and drones respectively. The method includes: The system obtains first vehicle data for a first time period from the vehicle and second vehicle data for the same time period from the mobile device; wherein the first vehicle data includes the vehicle's location information, fuel level, battery level, and mileage. Obtain the comparison result between the first vehicle data and the second vehicle data, wherein the comparison result includes whether the data is consistent or inconsistent; If the comparison result indicates data inconsistency, a first control command is sent to the drone; the first control command is used to instruct the drone to simulate the first vehicle data of the vehicle. Based on the first interaction information between the drone and the network attacker, the target address of the network attacker is determined; the first interaction information includes the first vehicle data sent by the drone to the network attacker.

2. The method according to claim 1, characterized in that, The second vehicle data in the mobile device is obtained from the vehicle via Bluetooth; before obtaining the second vehicle data for the first time period from the mobile device, the method includes: Send a second control command to the mobile terminal; the second control command is used to instruct the mobile terminal to acquire vehicle data of the vehicle during the first time period.

3. The method according to claim 1, characterized in that, After sending the first control command to the drone, the method includes: Store the first interaction information between the drone and the network attack terminal; Back up a copy of the first interactive information.

4. The method according to claim 3, characterized in that, The step of determining the target address of the network attacker based on the first interaction information between the drone and the network attacker includes: Using a copy of the first interactive information as the search space, determine the target information sent by the network attack terminal to the drone; The target address of the network attack terminal is obtained based on the target information.

5. The method according to claim 1, characterized in that, After sending the first control command to the drone, the method further includes: A third control command is sent to the drone; the third control command is used to instruct the drone to stop communicating with the vehicle network platform and to communicate with the network attack and defense platform; the network attack and defense platform is used to determine the target address.

6. A network security processing method, characterized in that, Applied to unmanned aerial vehicles (UAVs) that communicate with a vehicle-to-everything (V2X) platform, the method includes: Receive the first control command sent by the vehicle networking platform; According to the first control command, simulate the first vehicle data of the vehicle; wherein, the first vehicle data includes the vehicle's location information, fuel level, battery level, and mileage; Based on the first vehicle data, the attacker interacts with the network attack terminal to obtain first interaction information; the first interaction information is used to determine the target address of the network attack terminal.

7. The method according to claim 6, characterized in that, After simulating the first vehicle data according to the first control command, the method further includes: Receive the third control command sent by the vehicle networking platform; According to the third control command, communication with the vehicle network platform is stopped, and communication with the network attack and defense platform is initiated; the network attack and defense platform is used to determine the target address.

8. A network security processing device, characterized in that, The device is applied to a vehicle-to-everything (V2X) platform, which communicates with vehicles, mobile devices, and drones respectively. The device includes: The first acquisition module is used to acquire first vehicle data for a first time period from the vehicle and second vehicle data for the first time period from the mobile terminal; wherein, the first vehicle data includes the vehicle's location information, fuel level, battery level, and mileage; The second acquisition module is used to acquire the comparison result of the first vehicle data and the second vehicle data, wherein the comparison result includes whether the data is consistent or inconsistent. A first sending module is configured to send a first control command to the drone if the comparison result indicates data inconsistency; the first control command is configured to instruct the drone to simulate the first vehicle data of the vehicle. The first processing module is used to determine the target address of the network attack terminal based on the first interaction information between the drone and the network attack terminal; the first interaction information includes the first vehicle data sent by the drone to the network attack terminal.

9. A network security processing device, characterized in that, Applied to drones, wherein the drone communicates with a vehicle-to-everything (V2X) platform, the device includes: The first receiving module is used to receive the first control command sent by the vehicle networking platform; The second processing module is used to simulate the first vehicle data of the vehicle according to the first control command; wherein the first vehicle data includes the vehicle's location information, fuel level, battery level, and mileage; The third processing module is used to interact with the network attack terminal based on the first vehicle data to obtain first interaction information; the first interaction information is used to determine the target address of the network attack terminal.

10. A computer device, characterized in that, The computer device includes: processor; A memory storing computer-readable instructions, which, when executed by the processor, implement the processing method as described in any one of claims 1 to 7.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium contains program code that can be invoked by a processor or electronic device to execute the processing method as described in any one of claims 1 to 7.