Network security protection method, device and equipment for vehicle, vehicle and storage medium
By establishing a baseline model of normal communication behavior in the vehicle gateway, abnormal communication behavior can be detected and isolated in real time, solving the problem that traditional static defense mechanisms cannot cope with internal attacks, realizing the active immunity of the vehicle network, and improving security and reliability.
Patent Information
- Application Number
- CN202511785750.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-28
- Publication Date
- 2026-03-17
AI Technical Summary
Traditional vehicle network security protection relies on static defense mechanisms, which cannot effectively identify and respond to internal attacks, leading to network congestion and system paralysis, and affecting driving safety.
By establishing a baseline model of normal communication behavior in the vehicle gateway, abnormal communication behavior can be detected and isolated in real time. Network behavior self-learning is used to dynamically identify abnormal access, and an isolation mechanism is immediately activated when a threat is detected.
It enables the transformation of vehicle networks from passive defense to active immunity, enhances the ability to protect against unknown attacks, effectively prevents unauthorized control of safety-critical systems such as braking and steering, and ensures the security and reliability of vehicle networks.
Smart Images

Figure CN121690689A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle technology. In particular, it relates to a method, apparatus, device, vehicle, and storage medium for network security protection of vehicles. Background Technology
[0002] As vehicle electronic and electrical architecture evolves towards domain control and centralization, the in-vehicle gateway, as the core hub of the vehicle network, undertakes the critical task of data exchange and protocol conversion between different functional domains (such as powertrain domain, chassis domain, and body domain). While intelligent connected vehicle technology enhances the level of vehicle intelligence, it also significantly expands the network attack surface.
[0003] In related technologies, vehicle gateways mainly rely on firewalls based on fixed rules and static access control lists to achieve network security protection. However, static defense mechanisms cannot effectively identify and respond to internal attacks launched through legitimate access points. When an electronic control unit (ECU) causes bus errors or message flooding due to hardware or software failures, the source of the fault cannot be isolated in time, leading to network congestion or even system malfunction, affecting driving safety. Summary of the Invention
[0004] This application provides a method, apparatus, device, vehicle, and storage medium for network security protection of vehicles, aiming to improve the security and reliability of the vehicle's overall network.
[0005] To achieve the above objectives, a first aspect of this application provides a method for protecting the network security of a vehicle, the method comprising: Obtain real-time network messages from the vehicle's electronic control unit; Anomaly detection processing is performed on the real-time network packets based on a preset normal communication behavior baseline model to obtain detection results; the normal communication behavior baseline model is constructed based on learning the normal communication characteristics of the electronic control unit. If the detection results indicate that the electronic control unit has abnormal communication behavior, the electronic control unit shall be subjected to network security isolation.
[0006] In some embodiments, the method further includes: In the preset learning and modeling phase, normal communication features are extracted from the network packets of the electronic control unit, and the normal communication features are learned to establish a baseline model of the normal communication behavior of the electronic control unit. The baseline model of normal communication behavior is encrypted and stored.
[0007] In some embodiments, the anomaly detection processing of the real-time network packets based on a preset normal communication behavior baseline model includes: The real-time network packets are subjected to packet feature extraction to obtain real-time packet features; Extract the baseline model of normal communication behavior, and perform multiple anomaly comparison and detection between the real-time message features and the baseline model of normal communication behavior; the multiple anomaly comparison and detection includes illegal access comparison and detection, frequency anomaly comparison and detection, and value range anomaly comparison and detection.
[0008] In some embodiments, the method further includes: If the detection result indicates that the electronic control unit has abnormal communication behavior, an abnormal threat level assessment is performed on the detection result to obtain a threat level assessment result.
[0009] In some embodiments, the network security isolation process includes physical isolation and logical isolation; The network security isolation process for the electronic control unit includes: If the threat level assessment result indicates a high-risk behavioral threat, the physical isolation is performed on the electronic control unit to disconnect the bus port where the electronic control unit is located; If the threat level assessment result indicates a suspicious risk behavior threat, the electronic control unit is subjected to the logical isolation to discard the real-time network packets as abnormal packets.
[0010] In some embodiments, the method further includes: A security event log is generated based on the network security isolation processing of the electronic control unit; The security event logs are reported to the cloud via a normal end-to-cloud network channel; the normal network channel is the end-to-cloud network channel where the electronic control unit in the vehicle is located without network security isolation processing.
[0011] In some embodiments, the method further includes: Remove the network security isolation processing on the target electronic control unit and monitor whether the target electronic control unit has any abnormal communication behavior; the target electronic control unit is the electronic control unit that is subjected to network security isolation processing in the vehicle; If the target electronic control unit does not exhibit any abnormal communication behavior, the bus containing the target electronic control unit shall remain connected. In the event of abnormal communication behavior by the target electronic control unit, network security isolation measures are implemented on the target electronic control unit.
[0012] Furthermore, to achieve the above objectives, a second aspect of this application provides a network security protection device for a vehicle, the device comprising: The acquisition module is used to acquire real-time network messages from the vehicle's electronic control unit; An anomaly detection module is used to perform anomaly detection processing on the real-time network packets based on a preset normal communication behavior baseline model, and obtain the detection result; the normal communication behavior baseline model is constructed based on learning the normal communication characteristics of the electronic control unit; An isolation module is used to perform network security isolation on the electronic control unit when the detection result indicates that the electronic control unit has abnormal communication behavior.
[0013] Furthermore, to achieve the above objectives, a third aspect of the present application provides a computer device, which includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; When a processor executes a program stored in a memory, it implements the steps of the vehicle network security protection method described in the first aspect above.
[0014] To achieve the above objectives, a fourth aspect of this application provides a vehicle, the vehicle including a computer device, wherein when the processor of the computer device executes a computer program, it implements the steps of the network security protection method for the vehicle described in the first aspect.
[0015] To achieve the above objectives, a fifth aspect of this application provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the vehicle network security protection method described in the first aspect.
[0016] To achieve the above objectives, a sixth aspect of this application provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the vehicle network security protection method described in the first aspect.
[0017] The vehicle network security protection method, device, computer equipment, vehicle, computer-readable storage medium, and computer program product provided in this application embodiment acquire real-time network packets of the vehicle's electronic control unit; perform anomaly detection processing on the real-time network packets based on a preset normal communication behavior baseline model to obtain detection results; the normal communication behavior baseline model is constructed based on learning the normal communication characteristics of the electronic control unit; and when the detection results indicate that the electronic control unit has abnormal communication behavior, perform network security isolation processing on the electronic control unit.
[0018] Thus, this embodiment of the application constructs a baseline model of normal communication behavior by learning the normal communication characteristics of electronic control units (ECUs) in the vehicle beforehand. Then, based on this baseline model, it performs anomaly detection processing on the real-time network packets of the ECUs to obtain detection results. If the detection results indicate abnormal communication behavior in the ECU, it performs network security isolation processing on the ECU. Compared to traditional static defense mechanisms, this embodiment dynamically establishes the normal communication baseline of each ECU through network behavior self-learning, identifies abnormal access behavior in real time, and immediately activates the isolation mechanism when a threat is detected. This effectively solves the core problem that traditional static defense mechanisms cannot cope with internal vehicle network attacks and the spread of local ECU failures, improving the security and reliability of the entire vehicle network. It enables a fundamental shift in the vehicle network from passive defense to active immunity, effectively enhancing its protection against unknown attacks and preventing unauthorized control of safety-critical systems such as braking and steering. Attached Figure Description
[0019] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 A flowchart illustrating the steps of the vehicle network security protection method provided in some embodiments of this application; Figure 2 A schematic diagram of the overall architecture of the vehicle network security protection method provided in the embodiments of this application, involving the vehicle gateway system in some embodiments; Figure 3 A flowchart illustrating the steps of the vehicle network security protection method provided in this application embodiment in other embodiments; Figure 4 for Figure 1 A detailed flowchart of step S102; Figure 5 A flowchart illustrating the steps of the vehicle network security protection method provided in this application embodiment in other embodiments; Figure 6 for Figure 1 A detailed flowchart of step S103; Figure 7 A flowchart illustrating the steps of the vehicle network security protection method provided in this application embodiment in some other embodiments; Figure 8A flowchart illustrating the steps of the vehicle network security protection method provided in this application embodiment in some other embodiments; Figure 9 A schematic diagram illustrating the core workflow of the vehicle network security protection method provided in some embodiments of this application, involving the vehicle gateway system. Figure 10 A schematic diagram of the structure of the vehicle network security protection device provided in the embodiments of this application; Figure 11 This is a schematic diagram of the hardware structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0021] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0022] It should be noted that although functional modules are divided in the device schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0023] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0024] First, the overall concept of the embodiments of this application will be explained.
[0025] As vehicle electronic and electrical architecture evolves towards domain control and centralization, the on-board gateway, as the core hub of the vehicle network, undertakes the critical task of data exchange and protocol conversion between different functional domains (such as powertrain, chassis, and body domains). Furthermore, the widespread adoption of intelligent connected technologies enables vehicles to connect to cloud servers, mobile devices, and diagnostic tools through external interfaces such as the telematics processor T-Box, on-board diagnostic (OBD) interface, and Ethernet. While this enhances vehicle intelligence, it also significantly expands the network attack surface.
[0026] In related technologies, vehicle gateways primarily rely on firewalls based on fixed rules and static access control lists to achieve network security protection. However, solutions based on static defense mechanisms have significant limitations: First, traditional static defense mechanisms cannot effectively identify and respond to internal attacks initiated through legitimate access points. When hackers exploit vulnerabilities in the infotainment system, they can bypass boundary protection and move laterally within the vehicle network, attacking safety-critical electronic control units (ECUs) such as brake control units and steering controllers, causing serious security risks. Second, vehicle gateway systems based on static defense mechanisms cannot promptly isolate the source of faults when an ECU experiences bus errors or message flooding due to hardware or software failures, leading to network congestion or even system paralysis, affecting driving safety. Therefore, there is an urgent need in this field for a vehicle gateway system capable of real-time monitoring of network status, intelligent identification of abnormal behavior, and precise isolation to improve the security and reliability of the entire vehicle network.
[0027] To address this, this application provides a method, apparatus, computer device, vehicle, computer-readable storage medium, and computer program product for vehicle network security protection. Addressing the shortcomings of static defense mechanisms in traditional vehicle network architectures, it provides a system and method for network isolation of abnormal vehicle states based on an onboard gateway, effectively solving the core problem that traditional static defense mechanisms cannot cope with internal network attacks and the spread of local ECU failures. Through the network behavior self-learning module built into the onboard gateway, a normal communication baseline for each electronic control unit is dynamically established, abnormal access behavior is identified in real time, and an isolation mechanism is immediately activated upon detecting a threat. This innovative solution enables a fundamental shift in vehicle networks from passive defense to active immunity, significantly improving the ability to protect against unknown attacks, thereby effectively preventing unauthorized control of safety-critical systems such as braking and steering.
[0028] The system and method provided in this application can identify and isolate faulty nodes within milliseconds, preventing localized problems from causing network-wide paralysis and improving the reliability of the vehicle network. Furthermore, the software-defined implementation eliminates the need to modify existing hardware architecture to achieve advanced security functions, significantly reducing mass production costs and maintenance complexity. Moreover, the system and method provided in this application can be upgraded via Over-the-Air (OTA) technology to continuously evolve protection capabilities, thus providing reliable assurance for the large-scale commercialization of intelligent connected vehicles. Therefore, based on these advantages, the system and method provided in this application can improve vehicle network security while also considering practicality and economy, offering an innovative solution for the industry.
[0029] In this embodiment of the application, in order to improve the security and reliability of the vehicle network, the real-time network packets of the vehicle electronic control unit are acquired; the real-time network packets are subjected to anomaly detection processing based on a preset normal communication behavior baseline model to obtain the detection result; the normal communication behavior baseline model is constructed based on learning the normal communication characteristics of the electronic control unit; when the detection result indicates that the electronic control unit has abnormal communication behavior, the electronic control unit is subjected to network security isolation processing.
[0030] Thus, this embodiment of the application constructs a baseline model of normal communication behavior by learning the normal communication characteristics of electronic control units (ECUs) in the vehicle beforehand. Then, based on this baseline model, it performs anomaly detection processing on the real-time network packets of the ECUs to obtain detection results. If the detection results indicate abnormal communication behavior in the ECU, it performs network security isolation processing on the ECU. Compared to traditional static defense mechanisms, this embodiment dynamically establishes the normal communication baseline of each ECU through network behavior self-learning, identifies abnormal access behavior in real time, and immediately activates the isolation mechanism when a threat is detected. This effectively solves the core problem that traditional static defense mechanisms cannot cope with internal vehicle network attacks and the spread of local ECU failures, improving the security and reliability of the entire vehicle network. It enables a fundamental shift in the vehicle network from passive defense to active immunity, effectively enhancing its protection against unknown attacks and preventing unauthorized control of safety-critical systems such as braking and steering.
[0031] Based on the overall concept of the embodiments of this application described above, further specific embodiments of the vehicle network security protection method, device, computer equipment, vehicle, computer-readable storage medium, and computer program product provided in the embodiments of this application are proposed. First, the specific embodiments of the vehicle network security protection method provided in the embodiments of this application are described.
[0032] It should be noted that the vehicle network security protection method provided in this application embodiment can be applied to terminal devices configured in vehicles. It should also be understood that the vehicle network security protection method provided in this application embodiment can also be applied to servers communicating with vehicles. Alternatively, the vehicle network security protection method provided in this application embodiment can also be software running on the aforementioned terminal devices or servers. In some embodiments, the terminal device can be a smartphone, tablet, laptop, desktop computer, etc.; the server can be configured as an independent physical server, or as a server cluster or distributed system composed of multiple physical servers, or as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms; the software can be an application implementing the vehicle network security protection method, etc., but is not limited to the above forms.
[0033] Alternatively, this application can also be used in numerous general-purpose or special-purpose computer system environments or configurations that connect to vehicles for policy control of vehicle driving. For example, these computer system environments or configurations can be personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer computer devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types.
[0034] For ease of understanding and explanation, the following text will use the vehicle network security protection method provided in the embodiments of this application, applied to an onboard gateway system configured in a vehicle, as an example to provide a detailed description of this application. The implementation of the vehicle network security protection method provided in the embodiments of this application for any other subject matter described above can refer to the process of applying the vehicle network security protection method to an onboard gateway system as described below.
[0035] It should be noted that in the description of some embodiments, the vehicle gateway system may be referred to as the vehicle intelligent gateway system, or simply as the system.
[0036] Please refer to Figure 1 , Figure 1 The flowchart illustrates the steps of the vehicle network security protection method provided in some embodiments of this application. It should be understood that, although... Figure 1The figures show the execution order of some method steps, but based on different design needs in practical applications, the vehicle network security protection method provided in this application embodiment can of course adopt a different execution order of method steps than that shown in the figures. That is, Figure 1 The order of the method steps shown does not constitute a limitation on the execution logic order of the vehicle network security protection method provided in the embodiments of this application. Any other order based on... Figure 1 Reasonable changes to the sequence of steps shown should all be included within the protection scope of the vehicle network security protection method provided in the embodiments of this application.
[0037] like Figure 1 As shown, in some embodiments, the vehicle network security protection method provided in this application may include steps S101 to S103.
[0038] Step S101: Obtain real-time network messages from the vehicle's electronic control unit.
[0039] During the real-time monitoring phase of the vehicle network, the intelligent vehicle gateway (also known as the intelligent security gateway or simply vehicle gateway, gateway, etc.) automatically switches to real-time monitoring mode to monitor the messages of each electronic control unit in the vehicle in real time, thereby obtaining the real-time network messages of each electronic control unit.
[0040] It should be noted that the vehicle gateway system can be a pre-built collaborative defense system consisting of an intelligent vehicle gateway, a multi-port controllable bus switch array, and intelligent behavior analysis software. It can safely and automatically achieve vehicle network security protection through a set of rigorous localized anomaly detection and isolation logic.
[0041] like Figure 2 As shown, the components and their connections of an in-vehicle gateway system may include: an intelligent safety gateway (core decision-making unit), a vehicle functional domain network, an external interface network, and a cloud-based security management platform. Among them: The intelligent vehicle gateway is the core physical carrier of the vehicle network security protection method provided in this application embodiment, and its functionality can be enhanced based on traditional gateway hardware. It internally includes: Central processing module: responsible for running the core decision logic program of the vehicle network security protection method provided in the embodiments of this application.
[0042] Multi-port controllable bus switch array: It consists of multiple high-speed digital switch chips, each of which independently controls the on / off state of a physical bus and is directly controlled by the general-purpose input / output (GPIO) port of the central processing module.
[0043] Network interface module: includes multiple CAN / variable data rate CAN FD controllers, Ethernet controllers, etc., for connecting various functional domain networks.
[0044] Storage unit: Used to store normal behavior models and security policies.
[0045] In addition, the vehicle functional domain network is connected to the intelligent gateway via a multi-port switch array, including: Power domain network: connects safety-critical ECUs such as engine controller, transmission controller, and brake controller.
[0046] Body domain network: connects the body control module (BCM), door lock module, window controller, etc.
[0047] Infotainment domain network: connects host Head Units, displays, etc.
[0048] Furthermore, external interface network connections include the T-Box, OBD-II diagnostic port, and other external access points. The cloud-based security management platform can maintain a connection with the vehicle's T-Box via cellular network to receive security event logs uploaded by the vehicle and can send security policy updates to the smart gateway via OTA.
[0049] In some embodiments, the vehicle gateway system can capture all packets flowing through the gateway based on the mirror port through the intelligent vehicle gateway, thereby obtaining the real-time network packets of each electronic control unit in the vehicle.
[0050] In some embodiments, the vehicle gateway system may also include a dedicated AI chip for hardware-level acceleration.
[0051] Step S102: Perform anomaly detection processing on the real-time network packets based on a preset normal communication behavior baseline model to obtain the detection result; the normal communication behavior baseline model is constructed based on learning the normal communication characteristics of the electronic control unit.
[0052] It should be noted that the vehicle gateway system can learn the normal communication characteristics of the electronic control units in the vehicle in advance to build a baseline model of normal communication behavior.
[0053] During the real-time monitoring of the vehicle network, the vehicle gateway system accurately compares the real-time network packets of the electronic control unit with a pre-built baseline model of normal communication behavior. This allows for anomaly detection processing of the real-time network packets, thereby identifying abnormal network behavior of the electronic control unit in real time and obtaining corresponding detection results.
[0054] In some embodiments, since the normal communication behavior baseline model is established based on learning the normal communication characteristics of the electronic control unit, the vehicle gateway system can extract the message characteristics of the real-time network message in real time and compare them accurately with the normal behavior baseline model, thereby realizing the anomaly detection processing of the real-time network message and obtaining the detection result.
[0055] Step S103: If the detection result indicates that the electronic control unit has abnormal communication behavior, perform network security isolation processing on the electronic control unit.
[0056] During the real-time monitoring of the vehicle network, after the vehicle gateway system performs anomaly detection processing on real-time network packets based on the baseline model of normal communication behavior and obtains the detection results, if the detection results indicate that the electronic control unit has abnormal communication behavior, the vehicle gateway system will immediately activate the isolation mechanism to perform network security isolation processing on the electronic control unit.
[0057] In some embodiments, the vehicle gateway system can employ a hybrid isolation approach, combining SDN technology to achieve flexible isolation of the electronic control unit when performing network security isolation processing on the electronic control unit.
[0058] In this embodiment, a baseline model of normal communication behavior is constructed by pre-learning the normal communication characteristics of electronic control units (ECUs) in the vehicle. Then, based on this baseline model, anomaly detection processing is performed on the real-time network packets of the ECUs to obtain detection results. If the detection results indicate abnormal communication behavior of the ECU, network security isolation is performed on the ECU. Compared to traditional static defense mechanisms, this embodiment dynamically establishes the normal communication baseline of each ECU through network behavior self-learning, identifies abnormal access behavior in real time, and immediately activates the isolation mechanism when a threat is detected. This effectively solves the core problem that traditional static defense mechanisms cannot cope with internal vehicle network attacks and the spread of local ECU faults, improving the security and reliability of the entire vehicle network. It enables a fundamental shift from passive defense to active immunity in the vehicle network, effectively enhancing its protection against unknown attacks and preventing unauthorized control of safety-critical systems such as braking and steering.
[0059] In some embodiments, the vehicle gateway system may also employ a distributed detection approach, first performing preliminary detection through the domain controller (e.g., performing anomaly detection processing on real-time network packets based on a baseline model of normal communication behavior), and then reporting the detection results to the gateway for localized autonomous decision-making (i.e., when the detection results indicate that the electronic control unit has abnormal communication behavior, performing network security isolation processing on the electronic control unit).
[0060] In some embodiments, the vehicle gateway system may also employ a cloud-based collaborative approach, further reporting the detection results obtained from anomaly detection processing of real-time network packets based on a normal communication behavior baseline model locally to the cloud for vehicle-cloud collaborative analysis and processing, before deciding whether to activate the isolation mechanism. And / or, the vehicle gateway system may learn the normal communication characteristics of the electronic control unit based on cloud computing to construct a normal communication behavior baseline model.
[0061] Please refer to Figure 3 , Figure 3 The following are schematic flowcharts illustrating the steps of the vehicle network security protection method provided in this application embodiment in other embodiments.
[0062] like Figure 3 As shown in the embodiments of this application, the vehicle network security protection method may further include steps S301 and S302 as shown below.
[0063] Step S301: In the preset learning and modeling stage, normal communication features are extracted from the network packets of the electronic control unit, and the normal communication features are learned to establish a baseline model of the normal communication behavior of the electronic control unit.
[0064] Step S302: Encrypt and store the baseline model of normal communication behavior.
[0065] It should be noted that the preset learning and modeling stage can be the initial usage stage after the vehicle leaves the factory or a specific time period specified by the user. For example, the preset learning and modeling stage can be within 30 days or 1000 kilometers after the vehicle leaves the factory.
[0066] The vehicle gateway system can operate in learning mode during the learning and modeling phase. During this period, the intelligent gateway continuously monitors all network packets flowing through it and records the normal communication characteristics of each ECU through the behavior learning module, including the correspondence between source and destination addresses, packet identifiers, transmission frequency, and data value range, etc., to establish a complete normal behavior baseline model. This normal behavior baseline model is then encrypted and stored in the storage unit, thereby providing an accurate benchmark for subsequent anomaly detection.
[0067] In some embodiments, the in-vehicle gateway system can also perform threat prediction based on long-term monitoring of electronic control units (ECUs) in the vehicle, thereby achieving predictive protection for vehicle network security. For example, the system can learn from long-term monitored ECUs to establish a corresponding threat prediction model, and then use this model to predict the relevant communication behaviors of the ECUs. If the prediction results indicate that the ECUs may be affected by the network security, an isolation mechanism can be triggered to isolate the ECUs accordingly.
[0068] Please refer to Figure 4 , Figure 4 for Figure 1 A detailed flowchart of step S102.
[0069] like Figure 4 As shown, in some embodiments, the step of “performing anomaly detection processing on the real-time network packets based on a preset normal communication behavior baseline model” in step S102 above may include steps S401 and S402 as shown below.
[0070] Step S401: Extract message features from the real-time network messages to obtain real-time message features.
[0071] When the vehicle gateway system performs real-time monitoring of the vehicle network and performs anomaly detection processing on real-time network packets based on the normal communication behavior baseline model, it first extracts the packet features of the real-time network packets to obtain real-time packet features.
[0072] Step S402: Extract the baseline model of normal communication behavior, and perform multiple anomaly comparison and detection between the real-time message features and the baseline model of normal communication behavior; the multiple anomaly comparison and detection includes illegal access comparison and detection, frequency anomaly comparison and detection, and value range anomaly comparison and detection.
[0073] While extracting packet features from real-time network packets, the vehicle-mounted gateway system can also extract a pre-built baseline model of normal communication behavior from the storage unit. It then performs multiple anomaly comparisons and detections between the real-time packet features and this baseline model. Specifically, the central processing module sequentially performs multiple anomaly comparisons and detections: first, it checks if a source address is attempting to access a target address it never accessed during the learning phase, completing illegal access comparison detection; second, it checks if the packet transmission frequency is significantly higher than the baseline level, achieving frequency anomaly comparison detection; and finally, it checks if the data values within the packet exceed a reasonable range, completing value range anomaly comparison detection, thus forming a multi-layered security protection system.
[0074] Please refer to Figure 5 , Figure 5 The following are schematic flowcharts illustrating the steps of the vehicle network security protection method provided in this application embodiment in other embodiments.
[0075] like Figure 5 As shown in the embodiments of this application, the vehicle network security protection method may further include the following step S501.
[0076] Step S501: If the detection result indicates that the electronic control unit has abnormal communication behavior, perform an abnormal threat level assessment on the detection result to obtain a threat level assessment result.
[0077] After obtaining the detection results by performing anomaly detection processing on real-time network packets based on the baseline model of normal communication behavior, the vehicle gateway system enters the anomaly isolation autonomous decision-making stage. In this core stage, if the detection result indicates that the electronic control unit has abnormal communication behavior, the vehicle gateway system performs comprehensive calculation and threat level assessment on the detection result through the central processing module, thereby obtaining the corresponding threat level assessment result.
[0078] For example, when the central processing module performs comprehensive calculations and threat level assessments on the detection results, if the detection results are unauthorized access to a critical ECU (such as an ECU attempting to access a target address it has never communicated with before) or a message flooding attack (such as an abnormally high message sending frequency), the central processing module assesses that a high-risk anomaly has been detected; while if the detection results are only a temporary increase in the message sending frequency within a controllable range, the central processing module assesses that suspicious behavior has been detected.
[0079] In some embodiments, the network security isolation process includes physical isolation and logical isolation.
[0080] It should be noted that physical isolation can be used to physically disconnect the bus port where the source of the error is located, while logical isolation can be used to discard the error message.
[0081] Please refer to Figure 6 , Figure 6 for Figure 1 A detailed flowchart of step S103.
[0082] like Figure 6 As shown, in some embodiments, the step of “performing network security isolation processing on the electronic control unit” in step S103 above may include steps S601 and S602 as shown below.
[0083] Step S601: If the threat level assessment result is a high-risk behavioral threat, perform the physical isolation on the electronic control unit to disconnect the bus port where the electronic control unit is located.
[0084] In the core process of autonomous decision-making for anomaly isolation, when the threat level assessment result is a high-risk behavioral threat, that is, when the central processing module detects a high-risk anomaly (such as unauthorized access to a critical ECU or a message flooding attack), the vehicle gateway system immediately triggers the isolation mechanism to physically isolate the currently monitored electronic control unit: the electronic control unit is identified as the source of the anomaly, and the decision engine immediately sends a control command to the multi-port controllable bus switch array to physically disconnect the bus port where the anomaly source is located.
[0085] Step S602: If the threat level assessment result is a suspicious risk behavior threat, perform the logical isolation on the electronic control unit to discard the real-time network packet as an abnormal packet.
[0086] In the core process of autonomous decision-making for anomaly isolation, when the threat level assessment result is a suspicious risk behavior threat, that is, when the central processing module detects suspicious behavior (such as a temporary increase in the message sending frequency within a controllable range), the isolation mechanism is triggered to perform logical isolation on the currently monitored electronic control unit: the real-time network messages of the electronic control unit are treated as abnormal messages, and the abnormal messages are discarded by the decision engine through logical isolation.
[0087] In this embodiment, the process of the vehicle gateway system detecting and isolating real-time network packets of the electronic control unit is completed within milliseconds, thereby ensuring that security threats are eliminated in time before they cause actual harm to the vehicle's network security.
[0088] Please refer to Figure 7 , Figure 7 A flowchart illustrating the steps of the vehicle network security protection method provided in this application embodiment in some other embodiments.
[0089] like Figure 7 As shown, in some embodiments, the vehicle network security protection method provided in this application may further include steps S701 and S702 as shown below.
[0090] Step S701: Generate a security event log based on the network security isolation processing of the electronic control unit.
[0091] After detecting and isolating the real-time network packets of the electronic control unit, the vehicle gateway system further performs execution feedback processing, that is, it automatically records detailed security event logs for the current network security isolation of the electronic control unit.
[0092] In some embodiments, security event logs may include key information such as timestamps, exception types, source addresses, and triggering rules.
[0093] Step S702: Report the security event log to the cloud based on the normal end-to-cloud network channel; the normal network channel is the end-to-cloud network channel where the electronic control unit in the vehicle is located without network security isolation processing.
[0094] It should be noted that the cloud can be the aforementioned cloud security management platform.
[0095] After generating a security event log by performing network security isolation processing on the electronic control unit, the vehicle gateway system further reports the security event log to the cloud security management platform through the normal end-cloud network channel where the electronic control unit in the vehicle that has not undergone network security isolation processing is located (such as the network channel between the T-Box that has not been isolated and the cloud security management platform).
[0096] For example, when the vehicle gateway system detects an anomaly in the vehicle network, it first activates a security monitoring mechanism. The central processing module collects communication data (such as real-time network packets) from each ECU via the bus interface, analyzing packet characteristics and communication behavior in real time. Next, the processing module compares the real-time data (such as real-time packet characteristics) with pre-stored behavioral models (such as a pre-built baseline model of normal communication behavior) to identify abnormal access patterns, such as an ECU attempting to access a target address it has never communicated with before, or an abnormally high packet transmission frequency. Simultaneously, the processing module assesses the anomaly threat level. If a high-risk threat is identified, it immediately sends a command to the multi-port switch array to physically disconnect the bus connection of the abnormal ECU. Finally, the system records a security event log and uploads the alarm information to the cloud management platform through the normal network channel, while ensuring that communication with other normal systems remains unaffected. In this embodiment, the vehicle gateway system employs a dynamic safety baseline establishment technology based on behavioral learning to autonomously learn the normal communication patterns of each ECU in the vehicle. This establishes a complete normal behavior baseline model, which is then encrypted and stored in the storage unit, providing an accurate benchmark for subsequent anomaly detection. Furthermore, the vehicle gateway system utilizes a multi-dimensional anomaly detection mechanism, comprehensively analyzing multiple parameters such as communication relationships, frequency characteristics, and value ranges to collaboratively determine whether the ECU exhibits typical behavioral anomalies. Moreover, based on a security protection system combining tiered response and physical isolation, differentiated measures can be taken for different threat levels. A localized autonomous decision-making architecture enables rapid response; the process of detecting and isolating real-time network packets from the electronic control unit is completed within milliseconds, ensuring that security threats are eliminated before they pose a real threat to vehicle network security.
[0097] Please refer to Figure 8 , Figure 8 A flowchart illustrating the steps of the vehicle network security protection method provided in this application embodiment in some other embodiments.
[0098] like Figure 8 As shown, in some embodiments, the vehicle network security protection method provided in this application may further include steps S801 to S803 as shown below.
[0099] Step S801: Remove the network security isolation processing on the target electronic control unit and monitor whether the target electronic control unit has abnormal communication behavior; the target electronic control unit is the electronic control unit that performs network security isolation processing in the vehicle.
[0100] The vehicle gateway system can also, based on an intelligent self-recovery mechanism, release the network security isolation treatment of the electronic control unit that has been isolated in the vehicle after a safe interval, thereby automatically attempting to restore the connection of the isolated bus and continuing to perform monitoring tasks to monitor whether there is any abnormal communication behavior of the target electronic control unit.
[0101] In some embodiments, the vehicle gateway system monitors whether the target electronic control unit (ECU) exhibits abnormal communication behavior. This can be achieved by re-processing the real-time network packets of the target ECU for anomaly detection. The specific operation process can refer to the implementation process of anomaly detection processing of real-time network packets described in the above embodiments, and will not be repeated here.
[0102] Step S802: If the target electronic control unit does not exhibit any abnormal communication behavior, keep the bus where the target electronic control unit is located connected.
[0103] When the vehicle gateway system performs a monitoring task to monitor whether the target electronic control unit has abnormal communication behavior, if it finds that the previous abnormal behavior of the target electronic control unit has disappeared and no new abnormality has occurred, it is determined that the target electronic control unit does not have abnormal communication behavior, and in this case, the bus where the target electronic control unit is located is kept in a connected state.
[0104] Step S803: If the target electronic control unit exhibits abnormal communication behavior, perform network security isolation processing on the target electronic control unit.
[0105] When the vehicle gateway system performs monitoring tasks to check for abnormal communication behavior of a target electronic control unit (ECU), if it finds that the previously observed abnormal behavior of the target ECU has not disappeared and / or a new abnormality has occurred, it determines that the target ECU is still exhibiting abnormal communication behavior and immediately initiates an isolation mechanism to perform corresponding isolation operations on the target ECU again. In this way, a complete security protection loop for the vehicle network can be formed.
[0106] For example, such as Figure 9 As shown, when the vehicle network security protection method for vehicles provided in this application embodiment is executed, the vehicle gateway system can achieve network security protection through a rigorous localized decision-making mechanism based on the intelligent upgrade of the vehicle gateway. That is: The first stage is the learning and modeling phase. After the vehicle leaves the factory or during the initial usage phase specified by the user (such as within 30 days or 1000 kilometers), the system operates in learning mode. During this period, the intelligent gateway continuously monitors all network packets flowing through it, and records the normal communication characteristics of each ECU through the behavior learning module, including the correspondence between source and destination addresses, packet identifiers, transmission frequency, and data value range, etc., to establish a complete baseline model of normal behavior and encrypt and store it in the storage unit, providing an accurate benchmark for subsequent anomaly detection.
[0107] When entering the real-time monitoring phase, the intelligent gateway automatically switches to real-time monitoring mode. The monitoring module captures all packets flowing through the gateway through the mirror port, extracts packet features in real time, and performs precise comparisons with the stored normal behavior baseline model. The central processing module performs multiple anomaly detections in sequence: first, it detects whether a source address is attempting to access a target address it has never accessed during the learning phase, completing illegal access detection; second, it detects whether the packet transmission frequency is significantly higher than the baseline level, achieving frequency anomaly detection; finally, it detects whether the data values within the packet exceed a reasonable range, completing value range anomaly detection, forming a multi-layered security protection system.
[0108] In this core process of anomaly isolation and autonomous decision-making, the central processing module performs comprehensive calculations and threat level assessments on the detection results. When a high-risk anomaly is detected, such as unauthorized access to a critical ECU or a message flooding attack, the decision engine immediately sends a control command to the multi-port controllable bus switch array to physically disconnect the bus port where the anomaly source is located. When suspicious behavior is detected, logical isolation is used to discard the abnormal message. The entire detection and isolation process is completed within milliseconds, ensuring that security threats are eliminated in time before they cause actual harm.
[0109] During the execution and feedback phase, the system establishes a comprehensive follow-up processing mechanism. After isolation execution, the system automatically records detailed security event logs, including key information such as timestamps, exception types, source addresses, and trigger rules, and reports the logs to the cloud-based security management platform through the T-Box that has not yet been isolated. The system also features an intelligent self-recovery mechanism that automatically attempts to restore the connection of the isolated bus after a safe interval and continues to execute monitoring tasks. If the exception disappears, the normal connection is maintained; if the exception persists, the isolation operation is performed again, forming a complete security protection closed loop.
[0110] In this embodiment, the in-vehicle gateway system employs a triple protection mechanism of "learning modeling + real-time monitoring + physical isolation," effectively identifying and blocking various security threats. This fundamentally eliminates the risk of controlling critical ECUs through entry points such as the infotainment system, providing a solid guarantee for vehicle network security. Furthermore, the in-vehicle gateway system utilizes a localized autonomous decision-making mechanism, enabling rapid identification and isolation of faulty ECUs within milliseconds, preventing network paralysis caused by a single node failure and significantly improving the reliability of the entire vehicle network. Moreover, optimizing link judgment and reducing external dependencies through the in-vehicle gateway system also significantly improves the response speed and operational stability of anomaly handling. Furthermore, by fully utilizing existing gateway hardware resources and primarily relying on software algorithm upgrades, deployment can be achieved simply by adding a low-cost multi-port switch array, significantly reducing mass production costs.
[0111] Based on the same inventive concept, this application also provides a network security protection device for implementing the aforementioned vehicle.
[0112] The solution provided in this application for the vehicle network security protection device is similar to the solution described in the embodiments of the above-mentioned vehicle network security protection method. Therefore, the specific limitations of one or more vehicle network security protection device embodiments provided below can be found in the limitations of the vehicle network security protection method described above, and will not be repeated here.
[0113] In one embodiment, such as Figure 10 As shown, the vehicle network security protection device provided in this application embodiment includes: an acquisition module 1001, an anomaly detection module 1002, and an isolation module 1003, wherein: The acquisition module 1001 is used to acquire real-time network messages from the vehicle's electronic control unit; Anomaly detection module 1002 is used to perform anomaly detection processing on the real-time network packets based on a preset normal communication behavior baseline model to obtain detection results; the normal communication behavior baseline model is constructed based on learning the normal communication characteristics of the electronic control unit; The isolation module 1003 is used to perform network security isolation processing on the electronic control unit when the detection result indicates that the electronic control unit has abnormal communication behavior.
[0114] In some embodiments, the vehicle network security protection device provided in this application further includes: The self-learning module is used to extract normal communication features from the network packets of the electronic control unit during the preset learning modeling stage, and to learn the normal communication features to establish a baseline model of the normal communication behavior of the electronic control unit; the baseline model of normal communication behavior is encrypted and stored.
[0115] In some embodiments, the anomaly detection module 1002 is further configured to extract message features from the real-time network message to obtain real-time message features; extract the normal communication behavior baseline model, and perform multiple anomaly comparison detection between the real-time message features and the normal communication behavior baseline model; the multiple anomaly comparison detection includes illegal access comparison detection, frequency anomaly comparison detection, and value range anomaly comparison detection.
[0116] In some embodiments, the vehicle network security protection device provided in this application further includes: The graded response module is used to assess the abnormal threat level of the detection result when the detection result indicates that the electronic control unit has abnormal communication behavior, and obtain the threat level assessment result.
[0117] In some embodiments, the network security isolation process includes physical isolation and logical isolation; The isolation module 1003 is further configured to perform physical isolation on the electronic control unit to disconnect the bus port where the electronic control unit is located when the threat level assessment result is a high-risk behavior threat; and to perform logical isolation on the electronic control unit to discard the real-time network packet as an abnormal packet when the threat level assessment result is a suspicious risk behavior threat.
[0118] In some embodiments, the vehicle network security protection device provided in this application further includes: The execution feedback module is used to generate a security event log based on the network security isolation processing of the electronic control unit; and to report the security event log to the cloud based on the normal end-to-cloud network channel; the normal network channel is the end-to-cloud network channel where the electronic control unit in the vehicle that has not undergone network security isolation processing is located.
[0119] In some embodiments, the vehicle network security protection device provided in this application further includes: The recovery module is used to remove the network security isolation processing of the target electronic control unit and monitor whether the target electronic control unit has abnormal communication behavior; the target electronic control unit is the electronic control unit that performs network security isolation processing in the vehicle; if the target electronic control unit does not have abnormal communication behavior, the bus where the target electronic control unit is located is kept connected; if the target electronic control unit has abnormal communication behavior, network security isolation processing is performed on the target electronic control unit.
[0120] It should be noted that the various modules in the aforementioned vehicle network security protection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0121] Based on the same inventive concept, this application also provides a computer device, which can be a server, and its internal structure diagram can be as follows. Figure 11 As shown, this computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores model parameters related to liquid metal reactors. The I / O interfaces are used for information exchange between the processor and external devices. The communication interface is used for communication with external terminals via a network connection. When executed by the processor, the computer program implements a vehicle network security protection method.
[0122] When the processor of the computer device provided in this application executes a computer program, it performs the following steps: Obtain real-time network messages from the vehicle's electronic control unit; Anomaly detection processing is performed on the real-time network packets based on a preset normal communication behavior baseline model to obtain detection results; the normal communication behavior baseline model is constructed based on learning the normal communication characteristics of the electronic control unit. If the detection results indicate that the electronic control unit has abnormal communication behavior, the electronic control unit shall be subjected to network security isolation.
[0123] In some embodiments, when the processor executes a computer program, it further performs the following steps: In the preset learning and modeling phase, normal communication features are extracted from the network packets of the electronic control unit, and the normal communication features are learned to establish a baseline model of the normal communication behavior of the electronic control unit. The baseline model of normal communication behavior is encrypted and stored.
[0124] In some embodiments, the anomaly detection processing of the real-time network packets based on a preset normal communication behavior baseline model includes: The real-time network packets are subjected to packet feature extraction to obtain real-time packet features; Extract the baseline model of normal communication behavior, and perform multiple anomaly comparison and detection between the real-time message features and the baseline model of normal communication behavior; the multiple anomaly comparison and detection includes illegal access comparison and detection, frequency anomaly comparison and detection, and value range anomaly comparison and detection.
[0125] In some embodiments, when the processor executes a computer program, it further performs the following steps: If the detection result indicates that the electronic control unit has abnormal communication behavior, an abnormal threat level assessment is performed on the detection result to obtain a threat level assessment result.
[0126] In some embodiments, the network security isolation process includes physical isolation and logical isolation; The network security isolation process for the electronic control unit includes: If the threat level assessment result indicates a high-risk behavioral threat, the physical isolation is performed on the electronic control unit to disconnect the bus port where the electronic control unit is located; If the threat level assessment result indicates a suspicious risk behavior threat, the electronic control unit is subjected to the logical isolation to discard the real-time network packets as abnormal packets.
[0127] In some embodiments, when the processor executes a computer program, it further performs the following steps: A security event log is generated based on the network security isolation processing of the electronic control unit; The security event logs are reported to the cloud via a normal end-to-cloud network channel; the normal network channel is the end-to-cloud network channel where the electronic control unit in the vehicle is located without network security isolation processing.
[0128] In some embodiments, when the processor executes a computer program, it further performs the following steps: Remove the network security isolation processing on the target electronic control unit and monitor whether the target electronic control unit has any abnormal communication behavior; the target electronic control unit is the electronic control unit that is subjected to network security isolation processing in the vehicle; If the target electronic control unit does not exhibit any abnormal communication behavior, the bus containing the target electronic control unit shall remain connected. In the event of abnormal communication behavior by the target electronic control unit, network security isolation measures are implemented on the target electronic control unit.
[0129] Those skilled in the art will understand that Figure 11 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0130] Based on the same inventive concept, this application also provides a vehicle equipped with a computer device. The steps implemented by the processor of the computer device when executing a computer program are the same as the steps implemented by the processor of the aforementioned computer device when executing a computer program. The same content will not be described again here.
[0131] Based on the same inventive concept, embodiments of this application also provide a computer-readable storage medium, including a computer program. When the computer program is executed by a processor, the steps implemented are the same as the steps implemented by the processor in the computer device described above when it executes the computer program. The same content will not be described again here.
[0132] Based on the same inventive concept, this application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps implemented are the same as the steps implemented by the processor in the computer device when it executes the computer program. The same content will not be described again here.
[0133] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (Read-Only Memory). Memory includes ROM, magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application may include at least one of relational databases and non-relational databases. Non-relational databases may include distributed databases based on blockchain, etc., and are not limited thereto. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited thereto.
[0134] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0135] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A cyber security protection method of a vehicle, characterized by, The method comprises: acquiring real-time network packets of an electronic control unit of a vehicle; performing abnormality detection processing on the real-time network packets based on a preset normal communication behavior baseline model to obtain a detection result; the normal communication behavior baseline model is constructed based on learning normal communication characteristics of the electronic control unit; in the case where the detection result indicates that the electronic control unit has abnormal communication behavior, performing network security isolation processing on the electronic control unit.
2. The method of claim 1, wherein, The method further comprises: extracting normal communication characteristics from network packets of the electronic control unit in a preset learning modeling phase, and learning the normal communication characteristics to establish a normal communication behavior baseline model of the electronic control unit; performing encrypted storage on the normal communication behavior baseline model.
3. The method of claim 2, wherein, The abnormality detection processing on the real-time network packets based on the preset normal communication behavior baseline model comprises: performing packet characteristic extraction on the real-time network packets to obtain real-time packet characteristics; extracting the normal communication behavior baseline model, and performing multiple abnormality comparison and detection on the real-time packet characteristics and the normal communication behavior baseline model; the multiple abnormality comparison and detection comprises illegal access comparison and detection, frequency abnormality comparison and detection, and value range abnormality comparison and detection.
4. The method of claim 1, wherein, The method further comprises: in the case where the detection result indicates that the electronic control unit has abnormal communication behavior, performing abnormal threat level evaluation on the detection result to obtain a threat level evaluation result.
5. The method of claim 4, wherein, The network security isolation processing comprises physical isolation and logical isolation; The network security isolation processing on the electronic control unit comprises: in the case where the threat level evaluation result is a high-risk behavior threat, performing the physical isolation on the electronic control unit to disconnect a bus port where the electronic control unit is located; in the case where the threat level evaluation result is a suspicious risk behavior threat, performing the logical isolation on the electronic control unit to discard the real-time network packets as abnormal packets.
6. The method of claim 1, wherein, The method further comprises: generating a security event log based on the network security isolation processing on the electronic control unit; reporting the security event log to a cloud end based on a normal end-cloud network channel; the normal network channel is an end-cloud network channel where an electronic control unit of a vehicle that has not been subjected to network security isolation processing is located.
7. The method according to any one of claims 1 to 6, characterized in that, The method further comprises: removing the network security isolation processing on a target electronic control unit, and monitoring whether the target electronic control unit has abnormal communication behavior; the target electronic control unit is an electronic control unit of a vehicle that has been subjected to network security isolation processing; in the case where the target electronic control unit does not have abnormal communication behavior, keeping a bus where the target electronic control unit is located in a connected state; in the case where the target electronic control unit has abnormal communication behavior, performing network security isolation processing on the target electronic control unit.
8. A cyber security protection device for a vehicle, comprising: The device comprises: an acquisition module configured to acquire real-time network packets of an electronic control unit of a vehicle; Anomaly detection module, for performing anomaly detection processing on the real-time network message based on a preset normal communication behavior baseline model, to obtain a detection result; the normal communication behavior baseline model is constructed based on learning normal communication characteristics of the electronic control unit; Isolation module, for performing network security isolation processing on the electronic control unit in a case where the detection result indicates that the electronic control unit has abnormal communication behavior.
9. A computer device, comprising: The device includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory complete communication with each other through the communication bus; The memory is used to store a computer program; The processor is used to execute the program stored on the memory, and implement the steps of the vehicle network security protection method according to any one of claims 1-7.
10. A vehicle comprising a computer device, characterized in that The processor of the computer device executes the computer program, and implements the steps of the vehicle network security protection method according to any one of claims 1-7.
11. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor, and implements the steps of the vehicle network security protection method according to any one of claims 1-7.
12. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor, and implements the steps of the vehicle network security protection method according to any one of claims 1-7.