A security vulnerability management system of an intelligent networked vehicle terminal
By collecting data from the in-vehicle terminal of intelligent connected vehicles, calculating the probability of anomalies in events and continuously controlling abnormal parameters, the problem of insufficient identification of advanced malicious attacks is solved, security vulnerability management of in-vehicle terminals is realized, and the security and response efficiency of the system are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-21
- Publication Date
- 2026-04-10
AI Technical Summary
Existing intelligent connected vehicle in-vehicle terminals are unable to effectively identify abnormal events when facing advanced malicious attacks, especially in the continuous control logic, resulting in inadequate security vulnerability management.
Event control data is acquired through the data acquisition module, the abnormal probability of the event is calculated using the preliminary probability module, and the continuous control abnormal parameters are calculated by combining the control relationship and timing logic. Finally, the vulnerability management module performs risk assessment and remediation.
It enables refined security analysis of in-vehicle communication events, improves the ability to identify and respond to complex network threats, and ensures the security and reliability of intelligent connected vehicle communication processes.
Smart Images

Figure CN121547306B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and in particular to a security vulnerability management system of a smart connected vehicle vehicle terminal. BACKGROUND
[0002] With the rapid development of smart connected vehicle technology, the vehicle terminal, as an important part of the smart vehicle, undertakes key functions such as vehicle control, information interaction and data processing. However, the security problem of the vehicle terminal has gradually exposed, which has become one of the bottlenecks restricting the development of smart connected vehicles. Especially in the event of command interaction between vehicle terminals (referred to as event), it faces security vulnerabilities such as remote intrusion, data tampering, and malicious software attacks, which directly affect vehicle safety.
[0003] In the event of abnormal detection between vehicle terminals, the existing analysis is often based on the matching relationship between the events corresponding to the terminals and the frequency of event occurrence, that is, abnormality is identified by repeated events with high frequency. Some advanced malicious attacks may be able to mimic the frequency of event occurrence, resulting in low accuracy of existing methods; at the same time, the control between vehicle terminals in practice is complex and often accompanied by continuous control logic, and advanced malicious attacks cannot mimic the continuous control between terminals, so general abnormal event identification methods do not analyze the continuous control between events, resulting in some advanced malicious attacks cannot be identified, affecting the security vulnerability management of vehicle terminals. SUMMARY
[0004] The present application provides a security vulnerability management system of a smart connected vehicle vehicle terminal to solve the existing problems.
[0005] The security vulnerability management system of a smart connected vehicle vehicle terminal of the present application adopts the following technical solutions:
[0006] An embodiment of the present application provides a security vulnerability management system of a smart connected vehicle vehicle terminal, which comprises the following modules:
[0007] A data acquisition module for acquiring event control data, the event control data containing a plurality of events, each event corresponding to a sending timestamp and a receiving timestamp, and an initiating terminal and a receiving terminal;
[0008] A preliminary probability module for calculating the preliminary abnormal probability of an event by the frequency of event occurrence;
[0009] An abnormal probability module for taking any event as a target event, obtaining the same event as the receiving terminal corresponding to the target event, and adjusting the preliminary abnormal probability of the target event in combination with the frequency of event occurrence to obtain the abnormal probability of the target event;
[0010] an abnormality control module, configured to calculate a continuous abnormality parameter of a target event according to a control relationship on an initiating terminal and a receiving terminal of the event, and a sequence before and after the event occurs, and in combination with an abnormality probability of the event;
[0011] a vulnerability management module, configured to perform vulnerability risk assessment and repair by using the abnormality probability and the continuous abnormality parameter of the event.
[0012] Optionally, the method for calculating the preliminary abnormality probability of the event by using the frequency of the event comprises the following specific steps:
[0013] acquiring a frequency of any event, denoted as a first frequency of the event;
[0014] taking a sending time stamp of any event as an occurrence time of the corresponding event, and presetting a time length parameter and constructing a time window with a length of , taking the occurrence time of the event as a center point of the time window, acquiring a frequency of the event in the time window, denoted as a local frequency of the event, and taking a ratio of the local frequency of the event to the time length parameter corresponding to the time window as a local occurrence frequency of the event;
[0015] obtaining a preliminary abnormality probability of the event according to a difference between the local occurrence frequency of any event and the first frequency of the event.
[0016] Optionally, the method for acquiring the same event as the target event corresponding to the receiving terminal comprises the following specific steps:
[0017] acquiring a receiving terminal and an initiating terminal corresponding to the target event, and denoting the receiving terminal and the initiating terminal as a target receiving terminal and a target initiating terminal of the target event respectively, and taking the target receiving terminal as a first event of all events of the target receiving terminal.
[0018] Optionally, the specific calculation method of the abnormality probability of the target event comprises the following specific steps:
[0019] acquiring a first frequency of all first events, and taking an accumulated value of the first frequencies of all first events as a second frequency of the target event;
[0020] obtaining a relative frequency of the target event according to a difference between the first frequency and the second frequency of the target event, and adjusting the relative frequency of the target event by using the preliminary abnormality frequency of the target event to obtain the abnormality probability of the target event, wherein the first frequency and the preliminary abnormality probability of the target event are positively correlated with the abnormality probability of the target event, and the second frequency of the target event is negatively correlated with the abnormality probability of the target event.
[0021] Optionally, the control relationship of different events on the initiating terminal and the receiving terminal, and the sequence of the occurrence of the events, and the abnormal probability of the events are combined to calculate the continuous control abnormality parameter of the target event, including the specific method of:
[0022] The prerequisite event and the same control prerequisite event of the event are obtained according to the control relationship of different events on the initiating terminal and the receiving terminal, and the sequence of the occurrence of the events, and the continuous control logic abnormality degree of the target event is calculated based on the first frequency of the prerequisite event and the same control prerequisite event of the target event.
[0023] The time correlation deviation of the target event and the same control prerequisite event is calculated according to the interval of the target event and the same control relationship event from the corresponding prerequisite event in the occurrence time, and combined with the abnormal probability of the same control prerequisite event corresponding to the same control relationship event of the target event; the continuous control logic abnormality degree of the target event and the time correlation deviation are combined to obtain the continuous control abnormality parameter of the target event.
[0024] Optionally, the control relationship of different events on the initiating terminal and the receiving terminal, and the sequence of the occurrence of the events, and the abnormal probability of the events are combined to calculate the continuous control abnormality parameter of the target event, including the specific method of:
[0025] The same event of the target initiating terminal and the target receiving terminal corresponding to the target event is taken as the same control relationship event of the target event, and the time corresponding to the occurrence time closest to the occurrence time of the target event is taken as the prerequisite event of the target event, so as to obtain the prerequisite event of each event.
[0026] The initiating terminal and the receiving terminal corresponding to the prerequisite event of the target event are obtained, which are recorded as the prerequisite initiating terminal and the prerequisite receiving terminal of the target event; in the prerequisite events of all the same control relationship events of the target event, the prerequisite events corresponding to the prerequisite initiating terminal and the prerequisite receiving terminal of the target event are obtained, which are recorded as the same control prerequisite event of the target event.
[0027] Optionally, the control relationship of different events on the initiating terminal and the receiving terminal, and the sequence of the occurrence of the events, and the abnormal probability of the events are combined to calculate the continuous control abnormality parameter of the target event, including the specific method of:
[0028] In the prerequisite events of all the same control relationship events of the target event, the first frequency of the corresponding event under the same initiating terminal and receiving terminal is counted, which is recorded as the same control prerequisite frequency of the target event, and the continuous control logic abnormality degree of the target event is calculated according to the same control prerequisite frequency of the target event and the first frequency of the prerequisite event of the target event.
[0029] Optionally, the time correlation deviation between the target event and the same control premise event is calculated according to the interval between the target event and the same control relationship event and the corresponding premise event in the occurrence time, and in combination with the abnormal probability of the same control premise event corresponding to the same control relationship event of the target event, and the specific method comprises:
[0030] The time interval between the occurrence time corresponding to the target event and the premise event of the target event is obtained, and is recorded as the premise interval of the target event; the time interval between the occurrence time corresponding to the target event and the same control relationship event and the corresponding same control premise event is obtained, and is recorded as the premise interval of the same control relationship event of the target event; and the interval deviation between the target event and the same control relationship event is obtained according to the difference between the premise interval of the target event and the premise interval of the same control relationship event.
[0031] The abnormal probability of the same control premise event corresponding to the same control relationship event of the target event is obtained by using the abnormal probability acquisition method of the event; and the time correlation deviation between the target event and the same control premise event is obtained in combination with the abnormal probability of the same control premise event of the target event and the interval deviation.
[0032] Optionally, the continuous control abnormality parameter of the target event is obtained by combining the continuous control logic abnormality degree of the target event and the time correlation deviation, and the specific method comprises:
[0033] The cumulative value of the time correlation deviation between the target event and all the same control relationship events is recorded as the continuous control time deviation of the target event; the continuous control abnormality parameter of the target event is obtained by combining the continuous control logic abnormality degree of the target event and the continuous control time deviation; and the continuous control logic abnormality degree and the continuous control time deviation are positively correlated with the continuous control abnormality parameter.
[0034] Optionally, the vulnerability risk assessment and repair are performed by using the abnormal probability of the event and the continuous control abnormality parameter, and the specific method comprises:
[0035] The product of the abnormal probability of the target event and the continuous control abnormality parameter is obtained as the final abnormal factor of the target event; the final abnormal factors of all the events are linearly normalized to obtain the final abnormal coefficient of any event; and the event whose final abnormal coefficient is greater than or equal to the abnormal threshold is taken as an abnormal event.
[0036] The risk level of the abnormal event is set by using the final abnormal coefficient of the abnormal event, corresponding risk management is performed on the abnormal events of different risk levels, and the vulnerabilities involved in the abnormal events are repaired.
[0037] The beneficial effects of the technical solutions of the present application are: through multi-module cooperation, fine safety analysis and risk assessment of vehicle-mounted communication events are realized. The data acquisition module comprehensively acquires event control data containing time stamps and communication party information, providing a reliable data basis for subsequent analysis; the preliminary probability module performs statistical analysis based on event frequency, preliminarily identifies potential abnormal behaviors, and improves the objectivity of abnormal detection; the abnormal probability module further combines the associated event information of the same initiating terminal, dynamically adjusts the abnormal probability of each event, and enhances the accuracy of judgment and context perception ability; the control anomaly module introduces the control relationship and timing logic between terminals, comprehensively considers the rationality of the event in the actual control logic, effectively identifies behaviors that violate the normal control logic, and significantly improves the detection ability of hidden attacks or illegal operations; the vulnerability management module integrates abnormal probability and continuous control anomaly parameters, realizes comprehensive risk assessment of system security vulnerabilities, and supports subsequent warning and repair decisions. The whole system realizes full-process coverage from data acquisition to risk closed-loop management, improves the identification ability and response efficiency of the vehicle-mounted terminal to complex network threats, and guarantees the safety and reliability of the intelligent networked vehicle communication process. BRIEF DESCRIPTION OF DRAWINGS
[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description only constitute some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor.
[0039] Figure 1 The structure block diagram of the security vulnerability management system of the intelligent networked vehicle vehicle-mounted terminal according to the present application. DETAILED DESCRIPTION
[0040] In order to further illustrate the technical means and effects adopted by the present application to achieve the predetermined invention purpose, the specific implementation, structure, features and effects of the security vulnerability management system of the intelligent networked vehicle vehicle-mounted terminal according to the present application will be described in detail below in combination with the drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures or characteristics in one or more embodiments can be combined in any suitable form.
[0041] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs.
[0042] The specific scheme of the security vulnerability management system of the intelligent networked vehicle vehicle-mounted terminal provided by the present application will be specifically described below in combination with the drawings.
[0043] Referring to Figure 1 , a structural block diagram of a security vulnerability management system of a smart connected vehicle vehicle terminal provided by an embodiment of the present application is shown, and the system comprises the following modules:
[0044] The data acquisition module 101 is configured to acquire event control data.
[0045] It should be noted that in vehicle control, the control event from the vehicle terminal to the terminal is the core carrier of the "terminal-to-terminal instruction interaction" in the smart connected vehicle, and is directly related to the vehicle function execution and state cooperation, so the control communication security between the vehicle terminals is the key detection object of the vehicle terminal security detection.
[0046] In order to realize the security vulnerability management system of the smart connected vehicle vehicle terminal provided by the embodiment, the event control data needs to be acquired first, and the specific process is as follows:
[0047] First, the acquisition tool and interface are determined, and data acquisition is performed.
[0048] As an optional embodiment, the specific process of determining the acquisition tool and interface and performing data acquisition includes:
[0049] Bus acquisition: access the vehicle CAN / LIN / ethernet bus through devices such as CANoe and VN1630, and analyze the instruction frames (including initiating / receiving terminal ID and data field) on the bus.
[0050] Terminal log: a log module is built into the decision class / execution class terminal to record "instruction receiving time, execution result, and abnormal reason".
[0051] Time synchronization: ensure that the timestamp error of each terminal is ≤1ms through the vehicle clock synchronization protocol.
[0052] Then, the acquired data is recorded in a structured format using the CSV format.
[0053] It should be noted that the data recorded in a structured format using the CSV format is exemplified by Table 1 as shown in Table 1; in addition, the data acquired by the above process includes data in the actual normal driving process of the vehicle and data in the simulation of typical working conditions in the hardware-in-the-loop (HIL) simulation environment.
[0054]
[0055] At this point, the event control data is obtained by the above method.
[0056] The preliminary probability module 102 is configured to calculate the preliminary abnormal probability of the event through the occurrence frequency of the event.
[0057] It should be noted that when performing CAN / LIN bus (hereinafter referred to as bus) detection, the main focus is on event requests (hereinafter referred to as events) used by the terminal to control the vehicle. One event includes a request command and a receiving terminal. For example, an event is "turn signal on". Then, by identifying abnormal events of the terminal, bus vulnerabilities are identified. In the vehicle terminal, the occurrence of each event must conform to the vehicle control logic. In vehicle control, all events are designed with different operating conditions and application scenarios in mind. Considering various scenarios, all events will have a frequency, i.e., the frequency of event occurrence. When the vehicle terminal is subjected to malicious attacks, it generally manifests as multiple consecutive attacks, which will change the frequency of event occurrence. Therefore, for the same event, the greater the deviation between its current occurrence frequency and the frequency under normal operating conditions, the more abnormal the current event behavior. Therefore, this embodiment of the invention obtains the preliminary abnormal probability of the event by performing deviation analysis on the occurrence frequency of the event.
[0058] Specifically, as a preferred embodiment, the method for obtaining the preliminary anomaly probability is as follows:
[0059] First, obtain the frequency of any event, and denote it as the first frequency of the event.
[0060] Then, the sending timestamp of any event is used as the occurrence time of the corresponding event, with a preset duration parameter. And construct a length of The time window is defined by taking the occurrence time of the event as the center point of the time window, obtaining the frequency of the event within the time window, and recording it as the local frequency of the event. The ratio of the local frequency of the event to the duration parameter corresponding to the time window is taken as the local occurrence frequency of the event.
[0061] It should be noted that the preset duration parameters are based on experience. The duration is 10 seconds, but it can be adjusted according to the actual situation. This embodiment of the invention does not impose a specific limitation.
[0062] Finally, the preliminary anomalous probability of the event is obtained based on the difference between the local occurrence frequency of any event and the first frequency of the event.
[0063] As an optional embodiment, the specific method for calculating the preliminary anomaly probability of any event is as follows:
[0064]
[0065] in, Indicates the initial probability of an event being anomalous; Indicates the local frequency of occurrence of an event; represents the first frequency of an event; represents an absolute value function; represents the first frequency of an event; represents a linear normalization function.
[0066] It should be noted that, for the preliminary abnormal probability of the event, the deviation degree of the occurrence frequency of the event in the local time window and the historical normal frequency is analyzed, and the abnormal probability is normalized to quantify the abnormal possibility, which represents the significance of the event frequency deviating from the vehicle design working condition. The greater the frequency deviation, the more likely the event is affected by external interference or malicious attack. Thus, it is convenient to quickly identify potential threats caused by abnormally high or low frequency triggering, improve the real-time perception ability of the system to sudden attack behavior, reduce the false alarm risk based on single threshold judgment, and lay a data foundation for subsequent refined analysis.
[0067] At this point, the preliminary abnormal probability of any event is obtained by the above method.
[0068] The abnormal probability module 103 takes any event as a target event, adjusts the preliminary abnormal probability of the target event according to the occurrence sequence of different events and the target event, and the event corresponding to the initiating terminal and the receiving terminal, and combines the occurrence frequency of the event, to obtain the abnormal probability of the target event.
[0069] It should be noted that for the vehicle terminal, when the vehicle control is performed, a certain control logic needs to be followed, and in the common control logic, the essence is a control relationship, that is, "who controls who", so each event corresponding to the terminal contains an initiating terminal corresponding to the event request, and the event also corresponds to a receiving terminal to which the request is directed, that is, the initiating terminal initiates an event request to the receiving terminal, and then the receiving terminal responds to the event request, and then the initiating terminal and the receiving terminal constitute a control relationship. In addition, in the vehicle control process, there are many control terminals, and the control logic is strict, and the control relationship of each event is determined through strict design and experiment, so the control relationship of the initiating terminal and the receiving terminal corresponding to the event needs to strictly follow the design logic. In the design of the vehicle control, malicious attacks from the outside world always disturb the control relationship of the vehicle design, so there is a significant difference between the control relationship of the malicious attack when there is a security vulnerability and the control relationship of the vehicle design. The difference between the control relationships is first manifested in the mismatch between the initiating terminal and the receiving terminal. The control relationship of the current event is known, that is, the initiating terminal and the receiving terminal of the current event, and then the same control relationship is searched in the test data, at this time, if there is no same control relationship, it can be directly determined that the current event is an abnormal event; if there is a same control relationship, further analysis is needed. For example, the current event is "air conditioner sends command to wiper", and there is no event of air conditioner controlling wiper in actual vehicle control, so it can be directly determined that the current event is an abnormal event.
[0070] It should be further noted that the above analysis of the control relationship is only for the corresponding relationship between the initiating terminal and the receiving terminal of the event, but in practice, the same terminal can act as an initiating terminal or a receiving terminal in different events, that is, a terminal as a receiving terminal, the initiating terminal in the corresponding event of the terminal may not be the same. In the above frequency analysis, only the events corresponding to the receiving terminal are considered, and the corresponding initiating terminal is not emphasized, that is, the event frequency counted in the above process may contain different initiating terminals, at this time, in order to highlight the frequency relationship between the receiving terminal and the initiating terminal corresponding to the event, the frequency distribution of the events corresponding to the receiving terminal in the test data corresponding to different initiating terminals needs to be analyzed.
[0071] Specifically, as a preferred embodiment, the specific acquisition method of the abnormal probability of the event is:
[0072] First, any event is recorded as a target event, the receiving terminal and the initiating terminal corresponding to the target event are obtained, and are recorded as the target receiving terminal and the target initiating terminal of the target event respectively, all events of the target receiving terminal as a receiving terminal are recorded as first events of the target receiving terminal, and all initiating terminals corresponding to all first events are recorded as first initiating terminals.
[0073] The acquisition process of the first initiating terminal is as follows: for any event, the receiving terminal of the event is recorded as terminal The initiating terminal of the event is recorded as terminal The first frequency of the event is acquired All events with terminal as the receiving terminal are recorded as first events, and the initiating terminals corresponding to all first events include several types. All initiating terminals corresponding to all first events are acquired and recorded as first initiating terminals, and the first initiating terminals corresponding to all first events are obtained, and the set formed by all first initiating terminals is represented as , where represents the first initiating terminal corresponding to the th first event.
[0074] Then, the first frequencies of all first events are acquired, and the cumulative value of the first frequencies of all first events is recorded as the second frequency of the target event.
[0075] The acquisition process of the second frequency is as follows: for any first event, the first event has terminal and a first initiating terminal, and the first frequency of the first event is obtained by using the acquisition method of the first frequency The set formed by the first frequencies of all first events is represented as The cumulative value of the first frequencies of all first events is recorded as the second frequency , where represents the first frequency of the th first event.
[0076] It should be noted that the preliminary abnormal probability of the current event is only limited to the receiving terminal, so the preliminary abnormal probability includes events corresponding to different initiating terminals. At this time, in order to highlight the performance of the initiating terminal and the receiving terminal corresponding to the current event in the preliminary abnormal probability , it is necessary to analyze the relative relationship between the frequency of the event with the same initiating terminal and the same receiving terminal as the current event and the frequency of the current event, that is, in the event with the initiating terminal and the receiving terminal terminal A, the relative frequency of the event with the same initiating terminal and the same receiving terminal as the current event, that is, the control relationship relative frequency corresponding to the current event, the higher the control relationship relative frequency corresponding to the current event, the higher the credibility of the preliminary abnormal probability of the current event. Accordingly, based on the corresponding control relationship relative frequency of the current event, the preliminary abnormal probability of the event is corrected as follows:
[0077] Finally, based on the difference between the first and second frequencies of the target event, the relative frequency of the target event is obtained. The relative frequency of the target event is adjusted using the initial abnormal frequency of the target event to obtain the abnormal probability of the target event. The first frequency and the initial abnormal probability of the target event are positively correlated with the abnormal probability of the target event, while the second frequency of the target event is negatively correlated with the abnormal probability of the target event.
[0078] As an optional embodiment, the specific method for calculating the anomaly probability of any event is as follows:
[0079]
[0080] in, Indicates the probability of an event being abnormal; Indicates the first frequency of the target event; Indicates the second frequency of the target event; This indicates the initial probability of an event being anomalous.
[0081] It should be noted that the anomaly probability of an event is used to reflect the reasonableness of the event within the rigorously designed terminal control logic of the vehicle, highlighting the impact of control relationship matching degree on anomaly judgment; in In this study, by introducing specific control relationship constraints between the event initiating terminal and the receiving terminal based on the initial anomaly probability, the relative frequency of this control relationship in the overall event flow is calculated and dynamically corrected. This enables the effective identification of instructions or logical conflict behaviors initiated by unauthorized terminals (such as abnormal instructions between non-design-related terminals), significantly enhancing the detection accuracy of covert logic attacks, avoiding misjudging reasonable frequency fluctuations under normal operating conditions as anomalies, and thus improving the context adaptability and reliability of vulnerability identification.
[0082] Thus, the anomalous probability of the target event is obtained through the above method.
[0083] The control anomaly module 104 is used to calculate the continuous control anomaly parameters of the target event based on the control relationship between different events on the initiating terminal and the receiving terminal, the order in which the events occur, and the anomaly probability of the events.
[0084] It should be noted that in order to ensure the safety control of the vehicle, the control logic of the vehicle is generally multiple and rigorous, so there are some multiple control or continuous control control logic, that is, after the completion of an event, another event often occurs, or the premise of the occurrence of an event requires the completion of another event, and general malicious attacks are often simply continuous attacks without continuous control performance. In addition, in the actual vehicle control test data, all control processes are often basically fully covered, so there are a large number of continuous control events in the test data, so the deviation of the continuous control process of the current event from the existing continuous control needs to be reflected to reflect the continuous control anomaly of the current event.
[0085] Specifically, in step S401, the premise event and the same control premise event of the target event are obtained according to the control relationship of different events on the initiating terminal and the receiving terminal, and the order before and after the event occurs. The first frequency of the premise event and the same control premise event of the target event is calculated based on the target event, and the continuous control logic anomaly degree of the target event is calculated.
[0086] Firstly, the same event as the target event corresponding to the target initiating terminal and the target receiving terminal is taken as the same control relationship event of the target event, and the time corresponding to the time closest to the time before the target event corresponding to the occurrence time is taken as the premise event of the target event, so as to obtain the premise event of each event.
[0087] Then, the initiating terminal and the receiving terminal corresponding to the premise event of the target event are obtained, which are respectively recorded as the premise initiating terminal and the premise receiving terminal of the target event; in the premise events of all same control relationship events of the target event, the premise events corresponding to the initiating terminal and the receiving terminal are obtained. The premise event of the target event is recorded as the same control premise event of the target event.
[0088] It should be noted that in all test data, the premise event of the same control relationship event can reflect the continuous control logic, specifically, the more stable the premise event of the same control relationship event, the more obvious the characteristics in the continuous control logic; the higher the frequency of the same control relationship (same initiating terminal and same receiving terminal) in the premise event of the same control relationship event, the more stable the premise event of the same control relationship event.
[0089] Finally, in all premise events of the same control relationship events of the target event, the first frequency of the corresponding event under all same initiating terminal and receiving terminal is counted, which is recorded as the same control premise frequency of the target event. The continuous control logic anomaly degree of the target event is calculated according to the same control premise frequency of the target event and the first frequency of the premise event of the target event.
[0090] As an optional embodiment, the specific calculation method of the continuous control logic abnormality degree of the target event is as follows:
[0091]
[0092] Wherein, represents the continuous control logic abnormality degree of the target event; represents the maximum value of the same control premise frequency of the target event; represents the first frequency of the premise event of the target event.
[0093] It should be noted that, embodies the stability of the premise event of the same control relationship event of the target event, and the greater the value is, the more stable the premise event of the same control relationship event is, that is, the more obvious the continuous control logic of the same control relationship is; when the control relationship of the premise event of the target event is that the initiating terminal is terminal and the receiving terminal is terminal , and the premise event of the same control relationship event of the target event is that the initiating terminal is terminal and the receiving terminal is terminal , the event frequency is the same control premise frequency, and at this time, the closer the first frequency of the premise event of the target event is to the maximum value of the same control premise frequency of the target event, the more the premise event of the current event satisfies the continuous control logic; otherwise, the greater the difference between the first frequency of the premise event of the target event and the maximum value of the same control premise frequency of the target event is, the less the continuous control logic between the target event and the corresponding premise event satisfies the continuous control logic under the same control relationship, and then the more abnormal the continuous control logic of the target event is; at the same time, for the more obvious control relationship, the greater the difference between the first frequency of the premise event of the target event and the maximum value of the same control premise frequency of the target event is, the more the abnormality of the target event on the continuous control logic can be represented.
[0094] In step S402, the time correlation deviation between the target event and the same control premise event is calculated according to the interval of the target event and the same control relationship event and the corresponding premise event at the occurrence time, and in combination with the abnormal probability of the same control premise event corresponding to the same control relationship event of the target event; the continuous control logic abnormality degree of the target event and the time correlation deviation are combined to obtain the continuous control abnormality parameter of the target event.
[0095] It should be noted that for continuous control of the vehicle, there is generally a time correlation, that is, the time interval between the occurrence of an event and its premise event has a certain stable relationship, at this time, the time interval deviation of the current event relative to the time interval deviation of the premise event and its premise time can be used to reflect the continuous control time deviation of the current event, thereby reflecting the continuous control anomaly of the current event; wherein the time corresponding to an event is the time when the terminal receives the signal.
[0096] It should be noted that the time interval between the current event and its premise event is Among all the events with the same control relationship, the event whose initiating terminal is terminal , the receiving terminal is terminal , and the time interval between the selected event and its premise event is , wherein represents the time correlation between the selected event and its premise event, at this time, the time interval is The deviation of the time interval , that is, the satisfaction of the time correlation between the current event and its premise event.
[0097] First, the time interval between the occurrence time corresponding to the target event and the premise event of the target event is obtained, denoted as the premise interval of the target event; the time interval between the occurrence time corresponding to any same control relationship event of the target event and the corresponding same control premise event is obtained, denoted as the premise interval of the same control relationship event of the target event, and the interval deviation between the target event and the same control relationship event is obtained according to the difference between the premise interval of the target event and the premise interval of any same control relationship event.
[0098] Then, the abnormal probability of the same control premise event corresponding to any same control relationship event of the target event is obtained by using the event abnormal probability obtaining method, and the time correlation deviation of the target event and the same control premise event is obtained by combining the abnormal probability of any same control premise event of the target event and the interval deviation.
[0099] As an optional embodiment, the specific calculation method of the time correlation deviation of the target event and the same control premise event is:
[0100]
[0101] Among them, represents the time correlation deviation of the target event and the first same control relationship event; represents the abnormal probability of the same control premise event corresponding to the first same control relationship event of the target event; a premise interval representing a target event; a premise interval representing a target event and a control relationship event; a premise interval representing a target event and a control relationship event; representing the absolute value symbol.
[0102] It should be noted that, for the time correlation deviation of the target event and the control premise event, the difference between the time interval of the target event and its premise event and the time interval of the control relationship event is quantified, and the abnormal probability of the premise event is used as a weight for weighted calculation, so as to represent the stability of the time sequence in the continuous control process. The greater the deviation value is, the more the event time sequence violates the time sequence constraint of the vehicle control logic, so that the system can accurately capture the abnormal performance of the time correlation in the malicious attack (such as the time interval disorder of the attack instruction), strengthen the recognition ability of the continuous control logic attack, ensure that the system effectively distinguishes between normal operation and malicious behavior in the time sequence dimension, and improve the defense robustness against complex time sequence attacks.
[0103] Finally, the cumulative value of the time correlation deviation of the target event and all control relationship events is recorded as the continuous control time deviation of the target event. The continuous control time deviation and the continuous control logic abnormality degree of the target event are combined to obtain the continuous control abnormality parameter of the target event. The continuous control logic abnormality degree and the continuous control time deviation are positively correlated with the continuous control abnormality parameter.
[0104] As an optional embodiment, the specific calculation method of the continuous control abnormality parameter of the target event is as follows:
[0105]
[0106] wherein, the continuous control abnormality parameter of the target event; the continuous control logic abnormality degree of the target event; the continuous control time deviation of the target event.
[0107] It should be noted that the continuous control abnormality parameter integrates the continuous control logic abnormality degree and the time correlation deviation, and forms a unified parameter by fusing the two to comprehensively evaluate the event abnormality, which represents the overall abnormality degree of the corresponding event in the vehicle multi-layer control process, covers the dual dimensions of logical relationship and time sequence, realizes the all-round detection of the continuous control attack, effectively identifies the composite abnormal behavior that violates the design logic (such as the coexistence of logic conflict and time sequence disorder), significantly reduces the false negative rate, provides an objective basis for vulnerability risk grading, and thus improves the safety protection efficiency and response accuracy of the system under complex working conditions.
[0108] Thus, the continuous control abnormality parameter of any event is obtained by the above method.
[0109] Vulnerability management module 105 is used to assess and remediate vulnerability risks by utilizing the abnormal probability of events and continuously controlling abnormal parameters.
[0110] Specifically, first, the product of the abnormal probability of the target event and the continuously controlled abnormal parameters is obtained as the final abnormal factor of the target event; the final abnormal factors of all events are linearly normalized to obtain the final abnormal coefficient of any event; an abnormal threshold is preset, and events with a final abnormal coefficient greater than or equal to the abnormal threshold are regarded as abnormal events.
[0111] It should be noted that the preset abnormal threshold is 0.7 based on experience, and can be adjusted according to the actual situation. This embodiment of the invention does not impose specific limitations. Based on the above steps, abnormal identification of control events in the CAN bus is realized.
[0112] Then, using the final anomaly coefficient of the abnormal event, the risk level of the abnormal event is set, and corresponding risk management is carried out for abnormal events of different risk levels, and the vulnerabilities involved in the abnormal event are repaired.
[0113] As an optional embodiment, the method of using the final anomaly coefficient of the anomaly event to set the risk level of the anomaly event and performing corresponding risk management for anomalies of different risk levels includes: […]. The system is divided into four equal-sized range intervals. These intervals are then arranged in descending order of their values to form a range interval sequence. Each range interval in this sequence is assigned a risk level: P1, P2, P3, and P4. When an abnormal event occurs, for P1, the vehicle firewall (such as a CAN gateway) temporarily blocks the abnormal ID or data. For P2, the maximum number of frames for a given ID per unit time is limited. For P3 and P4, unnecessary functions are suspended to cut off attack paths.
[0114] It should be noted that, regarding the risk levels, P1 indicates emergency, which can be remotely exploited by hackers (such as braking command vulnerabilities) and directly affects driving safety; P2 indicates high risk, which requires physical contact to affect the corresponding safety functions (such as tampering with mileage after OBD-II access); P3 indicates medium risk, which, if exploited, will only affect non-safety functions (such as the IVI system sending garbage frames to the CAN bus); and P4 indicates low risk, which is extremely difficult for hackers to exploit and poses no actual harm (such as a low-priority ID verification defect).
[0115] As an optional embodiment, the method for repairing the vulnerability involved in the abnormal event comprises: for the protocol layer vulnerability, adding a MAC (Message Authentication Code) to a CAN (Controller Area Network) frame, and verifying the MAC before the ECU (Electronic Control Unit) receives; upgrading to CANFD (CAN Flexible Data-rate) or vehicle Ethernet: transmitting authentication information by using the extended data field of CAN FD, or realizing end-to-end encryption by using the TLS 1.3 of Ethernet; for the software logic vulnerability, repairing the defects in the ECU firmware, and verifying the effectiveness of the repair by static code analysis (Coverity); for the vehicle sold, upgrading the target ECU firmware by differential OTA; for the hardware design defect, replacing the defective CAN transceiver for the vehicle not yet shipped; for the vehicle sold, disabling the vulnerability interface by a firmware patch; and migrating the key and authentication algorithm to an independent security chip to avoid key leakage caused by the vulnerability of the main chip.
[0116] Thus, the embodiment is completed.
[0117] The above merely provides the preferred embodiment of the present application but not for limiting the present application, and any modification, equivalent replacement, improvement, etc. within the principle of the present application shall be included in the protection scope of the present application.
Claims
1.A security vulnerability management system of an intelligent connected vehicle terminal, characterized in that, The system comprises the following modules: a data collection module for collecting event control data, wherein the event control data comprises a plurality of events, each event corresponding to a sending timestamp and a receiving timestamp, and an initiating terminal and a receiving terminal; a preliminary probability module for calculating a preliminary abnormal probability of an event based on the frequency of occurrence of the event; an abnormal probability module for taking any event as a target event, obtaining events corresponding to the same receiving terminal as the target event, and adjusting the preliminary abnormal probability of the target event based on the frequency of occurrence of the events to obtain the abnormal probability of the target event; a control abnormality module for calculating a continuous control abnormality parameter of a target event based on the control relationship of different events on the initiating terminal and the receiving terminal, the sequence before and after the occurrence of the events, and the abnormal probability of the events; a vulnerability management module for performing vulnerability risk assessment and repair based on the abnormal probability of the events and the continuous control abnormality parameter. 2.The intelligent connected vehicle terminal security vulnerability management system according to claim 1, characterized in that, The method for calculating the preliminary abnormal probability of an event based on the frequency of occurrence of the event comprises the following steps: obtaining the frequency of any event, denoted as the first frequency of the event; The sending time stamp of any event is taken as the occurrence time of the corresponding event, and a preset time length parameter and a time window with a length of is constructed, the occurrence time of the event is taken as the center point of the time window, the frequency of the event within the time window is obtained, denoted as the local frequency of the event, and the ratio of the local frequency of the event to the time length parameter corresponding to the time window is taken as the local occurrence frequency of the event. obtaining the preliminary abnormal probability of the event based on the difference between the local frequency of occurrence of any event and the first frequency of the event. 3.The intelligent connected vehicle terminal security vulnerability management system of claim 1, wherein, The method for obtaining events corresponding to the same receiving terminal as the target event comprises the following steps: obtaining the receiving terminal and the initiating terminal corresponding to the target event, denoted as the target receiving terminal and the target initiating terminal of the target event, and recording all events of the target receiving terminal as the first events of the target receiving terminal. 4.The intelligent connected vehicle terminal security vulnerability management system of claim 3, wherein, The specific calculation method for the abnormal probability of the target event comprises the following steps: obtaining the first frequencies of all first events, and recording the cumulative value of the first frequencies of all first events as the second frequency of the target event; obtaining the relative frequency of the target event based on the difference between the first frequency and the second frequency of the target event, adjusting the relative frequency of the target event based on the preliminary abnormal frequency of the target event to obtain the abnormal probability of the target event, wherein the first frequency and the preliminary abnormal probability of the target event are positively correlated with the abnormal probability of the target event, and the second frequency of the target event is negatively correlated with the abnormal probability of the target event. 5.The intelligent connected vehicle terminal security vulnerability management system of claim 2, wherein, The method for calculating the continuous control abnormality parameter of a target event based on the control relationship of different events on the initiating terminal and the receiving terminal, the sequence before and after the occurrence of the events, and the abnormal probability of the events comprises the following steps: obtaining the prerequisite events and the same-control prerequisite events of an event based on the control relationship of different events on the initiating terminal and the receiving terminal, and the sequence before and after the occurrence of the events, calculating the continuous control logic abnormality degree of the target event based on the first frequencies of the prerequisite events and the same-control prerequisite events of the target event; calculating the time correlation deviation between the target event and the same-control prerequisite events based on the interval between the target event and the same-control relationship events and the corresponding prerequisite events in the occurrence time, and the abnormal probability of the same-control prerequisite events corresponding to the same-control relationship events of the target event; combining the continuous control logic abnormality degree and the time correlation deviation of the target event to obtain the continuous control abnormality parameter of the target event. 6.The intelligent networked vehicle terminal security vulnerability management system of claim 5, wherein, The method for obtaining the prerequisite events and co-control prerequisite events based on the control relationship between different events on the initiating terminal and the receiving terminal, as well as the order in which the events occur, includes the following specific methods: Events that are identical to the target initiating terminal and the target receiving terminal corresponding to the target event are taken as the same control relationship events of the target event. The time corresponding to the time that is closest in time to the occurrence time of the target event is taken as the premise event of the target event, thus obtaining the premise event of each event. The initiating terminal and receiving terminal corresponding to the prerequisite events of the target event are obtained and denoted as the prerequisite initiating terminal and prerequisite receiving terminal of the target event, respectively. Among all the prerequisite events of the target event and the events with the same control relationship, the prerequisite events in which the corresponding initiating terminal and the receiving terminal are both prerequisite initiating terminal and prerequisite receiving terminal of the target event are denoted as the prerequisite events of the target event. 7.The intelligent networked vehicle terminal security vulnerability management system of claim 5, wherein, The method for calculating the degree of continuous control logic anomaly of the target event based on the first frequency of the prerequisite events and co-control prerequisite events is as follows: In the prerequisite events of all events with the same control relationship to the target event, the first frequency of the corresponding events under the same initiating terminal and receiving terminal is counted and recorded as the common control prerequisite frequency of the target event. Based on the common control prerequisite frequency of the target event and the first frequency of the prerequisite events of the target event, the degree of continuous control logic anomaly of the target event is calculated. 8.The intelligent networked vehicle terminal security vulnerability management system of claim 5, wherein, The method for calculating the time correlation deviation between the target event and the co-control relationship event based on the time interval between the occurrence of the target event, the co-control relationship event, and the corresponding prerequisite event, and in combination with the anomaly probability of the co-control relationship event corresponding to the co-control prerequisite event of the target event, includes the following specific methods: The time interval between the occurrence times of the target event and its prerequisite events is obtained and denoted as the prerequisite interval of the target event. The time interval between the occurrence times of any co-control relationship event of the target event and its corresponding co-control prerequisite events is obtained and denoted as the prerequisite interval of the co-control relationship event of the target event. Based on the difference between the prerequisite interval of the target event and the prerequisite interval between any co-control relationship events, the interval deviation between the target event and the co-control relationship events is obtained. By using the method for obtaining the abnormal probability of an event, the abnormal probability of the pre-control event corresponding to any pre-control event of the target event is obtained. By combining the abnormal probability of any pre-control event of the target event and the interval deviation, the time correlation deviation between the target event and the pre-control event is obtained. 9.The intelligent network connected vehicle terminal security vulnerability management system of claim 5, wherein, The specific method for combining the degree of continuous control logic anomaly of the target event with the time correlation deviation to obtain the continuous control anomaly parameters of the target event includes: The cumulative value of the time correlation deviation between the target event and all events with the same control relationship is recorded as the continuous control time deviation of the target event. Combining the degree of continuous control logic anomaly of the target event and the continuous control time deviation, the continuous control anomaly parameter of the target event is obtained. Both the degree of continuous control logic anomaly and the continuous control time deviation are positively correlated with the continuous control anomaly parameter. 10.The intelligent connected vehicle terminal security vulnerability management system of claim 1, wherein, The vulnerability risk assessment and repair using the abnormal probability of the event and the continuous control abnormal parameter comprises the specific method that: The product of the abnormal probability of the target event and the continuous control abnormal parameter is obtained as the final abnormal factor of the target event; the final abnormal factors of all events are linearly normalized to obtain the final abnormal coefficient of any event; An abnormal threshold is preset, and the event whose final abnormal coefficient is greater than or equal to the abnormal threshold is regarded as an abnormal event; The final abnormal coefficient of the abnormal event is used to set the risk level of the abnormal event, and the abnormal events of different risk levels are subjected to corresponding risk management, and the vulnerabilities involved in the abnormal events are repaired.
Citation Information
Patent Citations
Security processing method and server
CN112437056A
Functional safety concept stage analysis method and brake control system
CN114348009A