Threat analysis and risk assessment method and system

By collecting multi-source vehicle data in real time to generate environmental context information, and combining it with a dynamic threat knowledge base for risk assessment and strategy adjustment, the problem of mismatch between protection capabilities under static analysis and actual needs is solved, and dynamic adjustment and improvement of vehicle network security is realized.

CN122053239APending Publication Date: 2026-05-15NEUSOFT REACH AUTOMOBILE TECH (SHENYANG) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NEUSOFT REACH AUTOMOBILE TECH (SHENYANG) CO LTD
Filing Date
2026-03-30
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing methods for analyzing and assessing vehicle cybersecurity threats are ill-suited to the dynamic changes in the connected vehicle environment in a static setting, resulting in a mismatch between protection capabilities and actual needs, and an inability to adjust risks in real time.

Method used

By collecting multi-source vehicle data in real time, structured environmental context information is generated and matched with a pre-built dynamic threat knowledge base to determine target threat scenarios, conduct risk quantification assessments, and dynamically adjust security response strategies.

Benefits of technology

It enables on-demand and dynamic adjustment of vehicle network security protection strategies, improves the protection level in the dynamic environment of vehicle networking, and can accurately reflect the real risks of vehicles under specific operating conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053239A_ABST
    Figure CN122053239A_ABST
Patent Text Reader

Abstract

The invention discloses a threat analysis and risk assessment method and system, and is applied to a vehicle. According to the scheme, multi-source data in an Internet of Vehicles environment where a vehicle is located is collected in real time; based on the multi-source data, structured environmental context information representing a current environmental state of the vehicle is generated. And matching the environment context information with a pre-constructed dynamic threat knowledge base, and determining a target threat scene. And performing risk quantitative evaluation on the target threat scene based on the environment context information and the risk calculation parameter associated with the target threat scene to obtain a corresponding risk value. And determining a corresponding safety response strategy from a pre-constructed response strategy library according to the risk value. And matching a corresponding safety response strategy from a response strategy library according to the risk value. According to the technical scheme of the invention, the real and instant risk of the vehicle can be accurately reflected, the dynamic adjustment of the protection strategy is realized, and the protection level of the vehicle network security in the dynamic environment of the Internet of Vehicles is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle cybersecurity technology, and in particular to a threat analysis and risk assessment method and system. Background Technology

[0002] As the connectivity and intelligence of vehicles continue to improve, vehicles are no longer isolated mechanical units, but intelligent terminals deeply integrated into the Internet of Vehicles (IoV). While this transformation brings a wealth of applications and services, it also makes the information security threats facing vehicles increasingly severe. To address these challenges, industry regulations require vehicles to have cybersecurity management capabilities throughout their entire lifecycle. The existing approach involves conducting static Threat Analysis and Risk Assessment (TARA) during the vehicle design phase. TARA defines the security requirements of the entire vehicle in one go, based on a fixed asset inventory and pre-defined attack scenarios.

[0003] However, the connected vehicle environment is highly dynamic, with vehicle operating status, geographical location, network connection methods, and surrounding environment constantly changing. This static analysis method struggles to adapt to the dynamically changing environment and adjust dynamically based on real-time risk conditions, resulting in a mismatch between protection capabilities and actual needs. Summary of the Invention

[0004] To address the aforementioned issues, this application provides a threat analysis and risk assessment method and system, aiming to accurately reflect the real security risks of vehicles under specific operating conditions, enabling vehicle cybersecurity protection strategies to be dynamically adjusted according to real-time risk conditions, achieving a match between protection capabilities and actual security needs, and improving the level of vehicle cybersecurity protection in the dynamic environment of vehicle networking.

[0005] The embodiments of this application disclose the following technical solutions: The first aspect of this application provides a threat analysis and risk assessment method applied to vehicles, the method comprising: Real-time collection of multi-source data from the vehicle's connected vehicle environment; Based on the multi-source data, structured environmental context information is generated; the environmental context information represents the current environmental state of the vehicle. The environmental context information is matched with a pre-built dynamic threat knowledge base to determine the target threat scenario; the dynamic threat knowledge base stores multiple threat scenarios, and each threat scenario is associated with context conditions and risk calculation parameters used to trigger the threat scenario; Based on the environmental context information and the risk calculation parameters associated with the target threat scenario, a risk quantification assessment of the target threat scenario is performed to obtain the corresponding risk value. Based on the risk value, the corresponding security response strategy is determined from a pre-built response strategy library.

[0006] In an optional implementation, the step of matching environmental context information with a pre-built dynamic threat knowledge base to determine the target threat scenario includes: Traverse the threat scenarios in the dynamic threat knowledge base and determine whether the environmental context information satisfies the context conditions associated with the threat scenario; Threat scenarios that satisfy the aforementioned contextual conditions are identified as the target threat scenarios.

[0007] In an optional implementation, generating structured environmental context information based on the multi-source data includes: The multi-source data is fused to generate fused data; The fused data is semantically abstracted, and the original data is mapped into context information items with preset security meanings. These context information items constitute the environmental context information.

[0008] In an optional implementation, the step of performing a risk quantification assessment of the target threat scenario based on the environmental context information and the risk calculation parameters associated with the target threat scenario to obtain a corresponding risk value includes: Based on the environmental context information and the risk calculation parameters associated with the target threat scenario, a first risk value for the target threat scenario is determined; the first risk value is used to characterize the probability that the target threat scenario will pose a threat. Based on the environmental context information and the risk calculation parameters associated with the target threat scenario, a second risk value for the target threat scenario is determined; the second risk value is used to characterize the degree of impact of the threat posed by the target threat scenario. The risk value is obtained based on the first risk value, the second risk, and the risk calculation parameter value associated with the target threat scenario.

[0009] In an optional implementation, the risk calculation parameters include a basic first risk value and a basic second risk value; the risk calculation parameters associated with the environmental context information and the target threat scenario, used to determine the first risk value of the target threat scenario, include: Based on the environmental context information, a first correction factor corresponding to the environmental context information is determined from a predefined first risk quantification table; The first risk value is obtained by calculating the basic first risk value and the first correction factor using a preset first aggregation function; The step of determining the second risk value of the target threat scenario based on the environmental context information and the risk calculation parameters associated with the target threat scenario includes: Based on the environmental context information, determine the corresponding second correction factor from the predefined second risk quantification table; The second risk value is obtained by calculating the basic second risk value and the second correction factor using a preset second aggregation function.

[0010] In an optional implementation, the risk calculation parameters include risk association parameters, and obtaining the risk value based on the first risk value and the second risk value includes: Based on the risk association parameters, the first risk value and the second risk value are correlated and calculated to obtain the risk value.

[0011] In an optional implementation, after determining the corresponding security response strategy from a pre-built response strategy library based on the risk value, the method further includes: Execute the security response strategy; The dynamic threat knowledge base is updated and optimized based on the feedback information generated from executing the security response strategy.

[0012] In an optional implementation, the feedback information includes environmental context information that triggers the target threat scenario, the corresponding risk value, the determined security response strategy, and the effect data of executing the security response strategy; The updating and optimization of the dynamic threat knowledge base includes: The feedback information is used to optimize the contextual conditions and / or risk calculation parameters associated with the threat scenario.

[0013] In an optional implementation, the multi-source data includes one or more of vehicle status data, network connection data, environmental perception data, and mission-critical data.

[0014] A second aspect of this application provides a threat analysis and risk assessment system for use in vehicles, the system comprising: A multi-source data acquisition module is used to collect multi-source data in the vehicle network environment in which the vehicle is located in real time; An environmental information generation module is used to generate structured environmental context information based on the multi-source data; the environmental context information represents the current environmental state of the vehicle. The threat scenario determination module is used to match the environmental context information with a pre-built dynamic threat knowledge base to determine the target threat scenario; the dynamic threat knowledge base stores multiple threat scenarios, and each threat scenario is associated with context conditions and risk calculation parameters used to trigger the threat scenario; The risk quantification and assessment module is used to perform risk quantification and assessment of the target threat scenario based on the environmental context information and the risk calculation parameters associated with the target threat scenario, and obtain the corresponding risk value. The response strategy determination module is used to determine the corresponding security response strategy from a pre-built response strategy library based on the risk value.

[0015] Compared with the prior art, this application has the following beneficial effects: This application's technical solution is applied to vehicles. First, it collects multi-source data from the vehicle's connected vehicle environment in real time. Based on this multi-source data, it generates structured environmental context information, which represents the vehicle's current environmental state. The environmental context information is then matched with a pre-built dynamic threat knowledge base to determine target threat scenarios. The dynamic threat knowledge base stores multiple threat scenarios, each associated with contextual conditions and risk calculation parameters used to trigger the scenario. Based on the environmental context information and the risk calculation parameters associated with the target threat scenario, a risk quantification assessment is performed on the target threat scenario to obtain a corresponding risk value. Based on the risk value, a corresponding security response strategy is determined from a pre-built response strategy library. It is evident that this application's technical solution, by introducing real-time dynamic environmental context information, extends risk assessment from the vehicle design stage to the actual operation stage, breaking the rigid limitations of static analysis and accurately reflecting the real-time risks of vehicles under specific operating states, network environments, and geographical scenarios. Meanwhile, by matching the corresponding security response strategy with the dynamically quantified risk value, the protection strategy can be adjusted on demand and dynamically, allowing the vehicle's network security protection measures to change in real time according to the actual risk situation, thereby improving the protection level of vehicle network security in the dynamic environment of vehicle networking. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 A flowchart of a threat analysis and risk assessment method provided in this application embodiment; Figure 2 This is a schematic diagram of the structure of a threat analysis and risk assessment system provided in an embodiment of this application. Detailed Implementation

[0018] As described earlier, with the continuous improvement of vehicle connectivity and intelligence, vehicles are no longer isolated mechanical units, but intelligent terminals deeply integrated into the Internet of Vehicles (IoV). While this transformation brings a wealth of applications and services, it also makes the information security threats facing vehicles increasingly severe. To address these challenges, industry regulations require vehicles to have cybersecurity management capabilities throughout their entire lifecycle. Current methods involve static threat analysis and risk assessment during the vehicle design phase, defining the overall vehicle security requirements based on a fixed asset inventory and pre-defined attack scenarios.

[0019] However, the connected vehicle environment is highly dynamic, with vehicle operating status, geographical location, network connection methods, and surrounding environment constantly changing. This static analysis method struggles to adapt to this dynamic environment, and its limitations are becoming increasingly apparent. First, its risk assessment results are fixed and cannot reflect the true risks faced by vehicles under specific operating conditions. Second, protection strategies designed based on static analysis are often outdated and difficult to adjust dynamically according to real-time risk conditions, resulting in a mismatch between protection capabilities and actual needs.

[0020] To address the aforementioned problems, the inventors have proposed a threat analysis and risk assessment method and system after research.

[0021] Applied to vehicles, this method first collects multi-source data from the vehicle's connected vehicle environment in real time. Based on this multi-source data, structured environmental context information is generated. This environmental context information represents the vehicle's current environmental state. The environmental context information is then matched with a pre-built dynamic threat knowledge base to determine the target threat scenario. The dynamic threat knowledge base stores multiple threat scenarios, each associated with contextual conditions and risk calculation parameters used to trigger the scenario. Based on the environmental context information and the risk calculation parameters associated with the target threat scenario, a risk quantification assessment is performed on the target threat scenario to obtain a corresponding risk value. Based on the risk value, a corresponding security response strategy is determined from a pre-built response strategy library. It is evident that this technical solution, by introducing real-time dynamic environmental context information, extends risk assessment from the vehicle design stage to the actual operation stage, breaking the rigid limitations of static analysis and accurately reflecting the real-time risks of the vehicle under specific operating states, network environments, and geographical scenarios. Simultaneously, matching the corresponding security response strategy based on the dynamically quantified risk value enables on-demand and dynamic adjustment of protection strategies, allowing vehicle network security protection measures to change in real time according to actual risk conditions, thus improving the protection level of vehicle network security in the dynamic environment of connected vehicles.

[0022] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.

[0023] See Figure 1 This figure is a flowchart of a threat analysis and risk assessment method provided in an embodiment of this application. Figure 1 As shown, this method is applied to a vehicle and includes the following steps: S101. Real-time collection of multi-source data in the vehicle network environment where the vehicle is located.

[0024] In this embodiment, the vehicle-to-everything (V2X) environment refers to the network environment formed by the interconnection of vehicles with terminals such as vehicle-road-cloud and people, encompassing the overall environment composed of the vehicle's internal network, vehicle-to-vehicle communication links, vehicle-to-cloud communication channels, and surrounding infrastructure such as roadside units. Multi-source data refers to various real-time dynamic data reflecting the status of vehicles and their surrounding environment, obtained from different data sources within the V2X environment.

[0025] In one example implementation, data can be collected from devices such as controllers and sensors inside the vehicle via an onboard gateway, while simultaneously acquiring data from an external cloud platform and roadside devices via an onboard telematics box (TBox) and roadside unit interaction interface.

[0026] In another example implementation, a GPS / IMU combined positioning module and an onboard network interface can be used to collect dynamic vehicle location data and network connection data, respectively. The parallel acquisition of data by multiple modules enables real-time data acquisition.

[0027] In one alternative implementation, in order to comprehensively and accurately reflect the current state of the vehicle's connected vehicle environment and provide a complete data foundation for subsequent contextual analysis, multi-source data includes one or more of the following: vehicle status data, network connection data, environmental perception data, and mission-critical data.

[0028] In this embodiment, vehicle status data refers to various data reflecting the vehicle's own operating status, including driving mode, vehicle speed, operating status of various vehicle controllers, and vehicle bus communication status. Network connection data refers to data reflecting the vehicle's network access and communication status, including network connection type (4G / 5G), Wireless Fidelity (Wi-Fi), Vehicle to Everything (V2X), Wi-Fi Service Set Identifier (SSID) and encryption method, network signal strength, network trust level, and cellular network connection status. Environmental perception data refers to data reflecting the physical environment and surrounding infrastructure status of the vehicle, including vehicle location, road type (urban road, highway, tunnel), roadside unit deployment, and communication status of surrounding vehicles. Task-critical data refers to data reflecting the importance and key attributes of the task currently being performed by the vehicle, including in-vehicle application operating scenarios (entertainment, navigation, autonomous driving, and task criticality level).

[0029] This application embodiment uses multi-source, real-time dynamic data collection to enable subsequent threat analysis and risk assessment to be carried out based on real data from actual vehicle operation, laying a data foundation for achieving dynamic risk assessment.

[0030] S102. Generate structured environmental context information based on multi-source data.

[0031] In the embodiments of this application, the environmental context information represents the current environmental state of the vehicle. It is a comprehensive description of the vehicle's operation and surrounding environment that is machine-understandable and structured after standardization, fusion, and semantic processing.

[0032] In one example implementation, multi-source data such as vehicle speed, driving mode, Wi-Fi encryption method, and geographical location are fused to generate structured environmental context information that includes highway driving, L3 autonomous driving mode, connection to unencrypted public Wi-Fi, and good 5G signal.

[0033] In another example implementation, multiple data sources, such as vehicle parking status, geographical location within the park, connection to in-vehicle private Wi-Fi, and operation of entertainment applications, are processed to generate corresponding structured environmental context information, which accurately reflects the environmental status of the vehicle's static operation scenario.

[0034] In one optional implementation, in order to transform heterogeneous, raw, multi-source data into effective and unified security analysis data, and improve the accuracy and efficiency of subsequent threat scenario matching, step S102 includes: S1021. Perform fusion processing on multi-source data to generate fused data.

[0035] In this embodiment, the fusion processing of multi-source data includes data cleaning, filtering, and spatiotemporal alignment and correlation. Data cleaning and filtering are used to remove noise, outliers, and invalid data from the original data to ensure data accuracy. Spatiotemporal alignment and correlation are used to match and integrate relevant information from different sensors and data sources according to time and space dimensions to form a unified context snapshot, ensuring data relevance and integrity.

[0036] In one example implementation, the geographic location data collected by the GPS / IMU module, the Wi-Fi connection data collected by the vehicle network interface, and the driving mode data collected by the autonomous driving domain controller at the same timestamp are spatiotemporally aligned. At the same time, signal drift noise in the GPS data and temporary connection fluctuation data in the network data are filtered out to generate a unified data set after fusion.

[0037] S1022. Semantically abstract the fused data and map the original data into context information items with preset security meanings. The context information items constitute environmental context information.

[0038] In this embodiment, "raw data" refers to various types of data that remain underlying data points after fusion processing, such as specific SSID names, encryption type strings, vehicle speed values, and road type codes. "Preset security meaning" refers to the security attribute meaning defined based on the network security protection requirements of the Internet of Vehicles (IoV), which can be directly used for threat scenario identification and risk assessment, such as network trust level, attack surface exposure degree, and mission criticality level. "Context information item" refers to a structured, single environmental attribute description with a preset security meaning; it is the basic unit constituting environmental context information, and each information item contains an attribute name and a corresponding attribute value.

[0039] In one example implementation, the original data SSID (high-speed free public network), encryption method (open and dynamic threat knowledge base list of trusted networks), is abstracted into a contextual information item with a preset security meaning: network wireless fidelity trust level is untrusted. The original data driving mode (L3 autonomous driving), vehicle speed (100km / h), and road type (highway) are abstracted into a contextual information item with the highest vehicle mission criticality level. Multiple such contextual information items together constitute structured environmental contextual information.

[0040] This application embodiment achieves the transformation from raw heterogeneous data to structured security context information through the fusion and semantic abstraction of multi-source data, enabling various states of the vehicle network environment to be presented in machine-recognizable security semantics, providing a unified and effective analytical basis for accurate matching of subsequent threat scenarios.

[0041] S103. Match the environmental context information with the pre-built dynamic threat knowledge base to determine the target threat scenario.

[0042] In this embodiment of the application, the dynamic threat knowledge base refers to a database that is built based on models and structures, stores various threat-related information in the Internet of Vehicles environment and supports online updates. It serves as a think tank and memory for the system to identify threat scenarios and conduct risk assessments.

[0043] The dynamic threat knowledge base stores multiple threat scenarios, each associated with contextual conditions and risk calculation parameters used to trigger that scenario. Contextual conditions refer to a set of logical expressions based on the vehicle's context state, representing a combination of real-time conditions that must be met to activate the corresponding threat scenario. Risk calculation parameters refer to various basic parameters and rules used to calculate the risk value of the threat scenario, which may include basic threat probability, basic impact level, risk matrix, and correction factor quantification table, etc.

[0044] In this application embodiment, the target threat scenario refers to a potential threat scenario that is determined to be activated in the current vehicle network environment when the current environmental context information meets its triggering conditions.

[0045] In one example implementation, environmental context information representing L3 autonomous driving mode, highway driving, and connection to untrusted Wi-Fi is matched with threat scenarios in a dynamic threat knowledge base to determine that the activated autonomous vehicle is subjected to a man-in-the-middle attack through untrusted Wi-Fi as the target threat scenario.

[0046] In another example implementation, the parking status, the environment context information such as being in the park, connected to a private Wi-Fi network, and running entertainment applications are matched with a dynamic threat knowledge base. If no threat scenario that meets all the triggering conditions is found, it is determined that there is currently no active target threat scenario.

[0047] In one optional implementation, in order to accurately and efficiently identify potential threat scenarios activated in the current vehicle-to-everything (V2X) environment and ensure the comprehensiveness and accuracy of threat scenario matching, step S103 includes: S1031. Traverse the threat scenarios in the dynamic threat knowledge base and determine whether the environmental context information meets the context conditions associated with the threat scenario.

[0048] In this embodiment of the application, the traversal process involves retrieving and analyzing all predefined threat scenarios in the dynamic threat knowledge base one by one. The judgment process involves parsing the logical expression in the context conditions of each threat scenario, extracting the real-time value of the corresponding attribute from the current structured environmental context information, substituting it into the logical expression for logical operations such as equal to, greater than, contain, AND, OR, NOT, etc. If the result of the logical expression operation is true, it is determined that the environmental context information satisfies the context conditions of the threat scenario; otherwise, it does not.

[0049] In one example implementation, the scenario of an autonomous vehicle suffering a man-in-the-middle attack via untrusted Wi-Fi is traversed through the dynamic threat knowledge base. The context conditions are: the vehicle driving mode is equal to L3 autonomous driving, the network wireless fidelity trust level is equal to untrusted, and the location road type is equal to highway. The corresponding attribute values ​​are extracted from the current environmental context information as L3 autonomous driving, untrusted, and highway, respectively. After substituting them into the context, the logical operation result is true, and it is determined that the context conditions of the scenario are met.

[0050] S1032. The threat scenarios that meet the context conditions are identified as target threat scenarios.

[0051] In this embodiment of the application, if the context conditions of multiple threat scenarios are met at the same time, all threat scenarios that meet the conditions are identified as target threat scenarios, and an activated scenario list is generated; if there are multiple related or mutually exclusive target threat scenarios, they will be processed according to predefined scenario priorities or conflict resolution rules to ensure the consistency of subsequent risk assessment and response decisions.

[0052] In one example implementation, the current environmental context information simultaneously satisfies the context conditions of two threat scenarios: an autonomous vehicle being attacked in the middle via untrusted Wi-Fi and the vehicle-to-cloud communication link being eavesdropped on via an open network. Both threat scenarios are identified as target threat scenarios. At the same time, according to the scenario priority rules, the autonomous vehicle being attacked in the middle via untrusted Wi-Fi is set as a high-priority target threat scenario.

[0053] This application embodiment achieves automatic identification of real-time activated threat scenarios in the vehicle network environment by accurately matching structured environmental context information with a dynamic threat knowledge base, enabling threat analysis to be carried out in accordance with the actual operating status of the vehicle.

[0054] S104. Based on environmental context information and risk calculation parameters associated with the target threat scenario, perform a risk quantification assessment of the target threat scenario to obtain the corresponding risk value.

[0055] In this embodiment, risk quantification assessment refers to the process of dynamically correcting and quantifying the probability of occurrence and the degree of impact of a target threat scenario by combining the vehicle's current environmental context information, ultimately obtaining a quantified value or level that can characterize the overall risk level of the scenario. The risk value refers to an indicator obtained through quantification assessment that reflects the true risk level of the target threat scenario in the current vehicle-to-everything (V2X) environment; it can be a specific numerical value or a preset risk level such as low risk, medium risk, or high risk.

[0056] In one example implementation, for the target threat scenario of autonomous vehicles suffering man-in-the-middle attacks through untrusted Wi-Fi, the basic threat probability and basic impact are dynamically adjusted by combining the current environmental context information of unencrypted Wi-Fi and L3 autonomous driving at high speed, and finally a high-risk value is calculated.

[0057] In another example implementation, for a target threat scenario where the vehicle-to-cloud communication link is eavesdropped on through an open network, if the vehicle is currently in a parking entertainment scenario, a medium-risk risk value is calculated after correction based on environmental context information.

[0058] In one optional implementation, in order to achieve accurate and dynamic quantification of the risk level of the target threat scenario and to ensure that the risk assessment results can truly reflect the real-time risks under the current operating scenario of the vehicle, step S104 includes: S1041. Based on environmental context information and risk calculation parameters associated with the target threat scenario, determine the first risk value of the target threat scenario.

[0059] In this embodiment of the application, the first risk value is used to characterize the likelihood of a threat occurring in the target threat scenario, and can be expressed in numerical form or semantic level form such as low, medium, high, and extremely high.

[0060] In one alternative implementation, to dynamically adjust the probability of threat occurrence based on the actual environmental conditions of the vehicle, and to ensure that the first risk value accurately reflects the true probability of threat occurrence in the current scenario, the risk calculation parameters include a basic first risk value and a basic second risk value. The basic first risk value refers to the baseline value of the inherent probability of threat occurrence in the target threat scenario itself under static analysis. It can be mapped to numerical baselines such as low (0.3), medium (0.6), and high (0.9), and serves as the basis for dynamic adjustment. The basic second risk value refers to the baseline value of the inherent degree of harm and impact of the target threat scenario itself after its occurrence under static analysis. It can be mapped to numerical baselines such as negligible (0.2), moderate (0.5), severe (0.8), and catastrophic (1.0), and serves as the benchmark for subsequent dynamic adjustment of the threat impact degree based on the actual environmental conditions of the vehicle.

[0061] In one alternative implementation, step S1041 includes: Step 1: Based on the environmental context information, determine the first correction factor corresponding to the environmental context information from the predefined first risk quantification table.

[0062] In this embodiment, the first correction factor refers to a coefficient used to dynamically adjust the basic first risk value. Its value is determined based on various contextual factors affecting the probability of a threat occurring, and its range can be preset to 0.5-2.0. A value greater than 1 indicates an increased probability of a threat occurring, while a value less than 1 indicates a decreased probability of a threat occurring. The first risk quantification table refers to a predefined mapping table in the dynamic threat knowledge base, containing various contextual factors affecting the probability of a threat, such as attack surface exposure, network connection security, and network signal strength, and their corresponding first correction factors. This table serves as the basis for determining the correction factor.

[0063] In one example implementation, a predefined first risk quantification table specifies that the first correction factor corresponding to the Wi-Fi encryption method being open and unencrypted is 1.8, and the first correction factor corresponding to the attack surface being fully exposed is 1.5. Based on the current environmental context information that the Wi-Fi encryption method is open and the attack surface exposure level is fully exposed, the corresponding first correction factors extracted from the first risk quantification table are 1.8 and 1.5, respectively.

[0064] Step 2: Calculate the basic first risk value and the first correction factor using a preset first aggregation function to obtain the first risk value.

[0065] In this embodiment of the application, the first aggregation function refers to a function used to comprehensively calculate the basic first risk value with one or more first correction factors, including weighted geometric average, product operation, weighted sum, etc. The specific function type can be predefined in the dynamic threat knowledge base according to the vehicle network security protection requirements.

[0066] In one example implementation, the first aggregation function is preset to be a product operation, the basic first risk value of the target threat scenario is mapped to the level of the numerical baseline 0.6, the first correction factor is determined to be 1.8, and by calculating 0.6×1.8=1.08, the numerical result is mapped back to the semantic level of high, and the first risk value is high.

[0067] S1042. Based on environmental context information and risk calculation parameters associated with the target threat scenario, determine the second risk value of the target threat scenario.

[0068] In the embodiments of this application, the second risk value is used to characterize the degree of impact of the target threat scenario, and can be expressed in numerical form or semantic level form such as negligible, moderate, severe, catastrophic, etc.

[0069] In one optional implementation, in order to dynamically adjust the threat impact level based on the actual vehicle operating mode and mission criticality level, so that the second risk value can accurately reflect the actual harm caused by the threat in the current scenario, step S1042 includes: Step 1: Based on the environmental context information, determine the corresponding second correction factor from the predefined second risk quantification table.

[0070] In this embodiment, the second risk quantification table refers to a predefined mapping table in the dynamic threat knowledge base, containing various contextual factors affecting the degree of threat impact, such as vehicle operating mode, mission criticality level, vehicle speed, road type, etc., and their corresponding second correction factors. The second correction factor is a coefficient used to dynamically adjust the basic second risk value. Its value is determined based on various contextual factors affecting the consequences of the threat, and the value range can be preset according to needs. A value greater than 1 indicates an amplification of the impact caused by the threat, and the larger the value, the more significant the amplification effect.

[0071] In one example implementation, the predefined second risk quantification table specifies that the second correction factor corresponding to L3 autonomous driving mode plus highway driving is 2.0, and the second correction factor corresponding to the vehicle being in the highest mission critical level state is 1.8. Based on the current environmental context information, relevant context factors are extracted, and the corresponding second correction factor is determined to be 2.0 from the second risk quantification table.

[0072] Step 2: Calculate the basic second risk value and the second correction factor using the preset second aggregation function to obtain the second risk value.

[0073] In this embodiment, the second aggregation function refers to a function used to comprehensively calculate the basic second risk value with one or more second correction factors, including product operation, weighted geometric mean, weighted sum, etc., similar to the first aggregation function. Its type can be predefined according to the vehicle network security protection requirements. The basic second risk value refers to the inherent impact benchmark value after the occurrence of the target threat scenario under static analysis, which can be mapped to a numerical baseline, such as negligible, moderate, severe, and catastrophic, corresponding to 0.2, 0.5, 0.8, and 1.0, respectively.

[0074] In one example implementation, the second aggregation function is preset to be a product operation. The base second risk value of the target threat scenario is mapped to a numerical baseline of 0.8 (high level). The determined second correction factor is 2.0. By calculating 0.8 × 2.0 = 1.6, the numerical result is mapped back to the semantic level of severe, and the second risk value is obtained as severe.

[0075] S1043. Calculate the risk value based on the first risk value, the second risk value, and the risk calculation parameter value associated with the target threat scenario.

[0076] In this embodiment of the application, the probability of a threat occurring, represented by the first risk value, and the degree of threat impact, represented by the second risk value, are used as the core assessment dimensions. Combined with the preset rules in the risk calculation parameters, a comprehensive calculation is performed to obtain the final risk value. The risk value can be expressed as a specific quantitative value or a standardized risk level of low, medium, or high, which is the direct basis for subsequent security response decisions.

[0077] In one example implementation, the first risk value is high and the second risk value is severe. Combining the risk matrix in the risk calculation parameters, the risk level corresponding to the intersection point is found to be high risk, which is the final risk value of the target threat scenario.

[0078] In one optional implementation, in order to achieve a comprehensive assessment of the overall risk of the target threat scenario based on two core dimensions—the probability of the threat occurring and the degree of its impact—the risk calculation parameters include risk correlation parameters. Step S1043 includes: Based on the risk correlation parameters, the first risk value and the second risk value are correlated and calculated to obtain the risk value.

[0079] In this embodiment, correlation calculation refers to the process of fusing a first risk value, representing the likelihood of a threat occurring, with a second risk value, representing the degree of threat impact, based on predefined rules and models in the risk correlation parameters, to obtain a comprehensive assessment of the overall risk level of the target threat scenario. The core correlation calculation model is a risk matrix model, but other models such as numerical weighted fusion may also be included. Risk correlation parameters refer to various rules and model parameters used to guide the correlation calculation of the first and second risk values, including a two-dimensional risk matrix table and weighting coefficients for numerical fusion. The risk matrix is ​​a two-dimensional table with the likelihood of threat occurring as rows and the degree of impact as columns, where each intersection point corresponds to a preset risk level or quantified value.

[0080] In one example implementation, the risk association parameter is a preset two-dimensional risk matrix table. The first risk value is high and the second risk value is severe. The intersection of the high probability row and the severe impact column is found in the risk matrix table. The risk level corresponding to the intersection point is high risk. The risk value of the target threat scenario is calculated as high risk through this association. If the first risk value and the second risk value are in numerical form, and the risk association parameter is a weighting coefficient, the preset weighting coefficient is 0.5. Then, the final quantified risk value is obtained by calculating the risk value = 0.5 × first risk value + 0.5 × second risk value.

[0081] This application embodiment dynamically corrects and quantifies the probability and impact of the target threat scenario, and then obtains a comprehensive risk value through correlation calculation. This realizes the transformation from static risk assessment to dynamic risk quantification assessment, allowing the risk value to accurately reflect the real and immediate risks faced by the vehicle in the current specific vehicle network environment, and providing accurate decision-making basis for subsequent adaptive safety response.

[0082] S105. Based on the risk value, determine the corresponding security response strategy from the pre-built response strategy library.

[0083] In this embodiment, the response strategy library refers to a pre-built database storing different risk values ​​and corresponding security response measures. For low, medium, and high risk values, the library predefines appropriate, tiered security response measures, and the response strategy library can be updated in conjunction with a dynamic threat knowledge base. A security response strategy refers to a combination of security response measures matched from the response strategy library based on the risk value of the target threat scenario. The type and intensity of these measures are adapted to the risk value; the higher the risk value, the stronger and more targeted the response measures.

[0084] In one example implementation, the risk value of the target threat scenario is high risk, and the corresponding security response policy matched from the response policy library is a combination of measures such as downgrading the alarm notification function and network isolation.

[0085] In another example implementation, if the risk value of the target threat scenario is medium risk, the corresponding security response strategy matched from the response strategy library is a combination of lightweight alerts and network encryption hardening measures; if the risk value is low risk, the response strategy of mild background monitoring alerts is matched.

[0086] This application embodiment achieves on-demand and dynamic adjustment of security protection strategies by matching corresponding security response strategies based on dynamically quantified risk values. This allows vehicle network security protection measures to match the actual level of risk, improving the accuracy and effectiveness of protection.

[0087] In one optional implementation, in order to effectively implement the security response strategy and truly achieve security protection for the target threat scenario, while also enabling learning and evolution from the actual protection process, the threat analysis and risk assessment method after step S105 further includes: S106. Implement security response strategy.

[0088] In this embodiment of the application, executing a security response strategy refers to converting a security response strategy determined from the response strategy library into a specific execution instruction and sending it to vehicle-related actuators such as vehicle gateways, vehicle controllers, and network management interfaces, so that the actuators can complete the specific security response actions. During the execution process, the issuance and execution status of the instructions are monitored in real time to ensure that the response measures are implemented.

[0089] In one example implementation, for the network isolation security response strategy of the alarm prompt function corresponding to high risk, the system translates it into specific execution instructions: send an alarm instruction to the instrument cluster via the Controller Area Network (CAN) bus to display a red safety warning icon and play a continuous alarm sound; send a function downgrade instruction to the autonomous driving domain controller to downgrade the driving mode from L3 to L2; send a network isolation instruction to the network management interface of the vehicle gateway to disconnect the current untrusted Wi-Fi and switch to the 5G cellular network, and each actuator completes the corresponding action after receiving the instruction.

[0090] S107. Update and optimize the dynamic threat knowledge base based on the feedback information generated by the execution of security response strategies.

[0091] In this embodiment, feedback information refers to various types of data generated throughout the entire process of security response strategy execution, reflecting the threat handling process and protection effectiveness. Update optimization refers to the process of using feedback information as learning data to adjust, improve, and optimize various models, parameters, and rules in the dynamic threat knowledge base, achieving self-learning and continuous evolution.

[0092] In one example implementation, the triggering context during the execution of the security response strategy is L3 autonomous driving at high speed, connecting to unencrypted Wi-Fi, with a risk value of high risk. The response strategy is alarm downgrade and isolation, and the execution effect is feedback information such as successful threat resolution, driver takeover in 3 seconds, and successful network switching. This information is used to optimize the correction factor and risk matrix parameters for the corresponding threat scenario in the dynamic threat knowledge base.

[0093] In one optional implementation, to ensure that the updating and optimization of the dynamic threat knowledge base are based on real threat handling cases, guaranteeing the relevance and effectiveness of the optimization, the feedback information includes the environmental context information that triggers the target threat scenario, the corresponding risk value, the determined security response strategy, and the effect data of executing the security response strategy. Step S107 includes: Optimize the contextual conditions and / or risk calculation parameters associated with the threat scenario using feedback information.

[0094] In this application embodiment, the effect data refers to data reflecting the execution results and protection effects of the safety response strategy, including whether the response measures were successfully executed, whether the threat was effectively resolved, whether the vehicle status returned to normal, whether any abnormalities occurred during the execution process, and the operation feedback from the driver or user.

[0095] In one example implementation, if multiple feedback messages indicate that a certain threat scenario, under the context of L2 autonomous driving mode on urban roads, achieves good threat mitigation after the actual execution of the response strategy, and the risk value obtained from the original risk calculation parameters is too high, the context conditions of the threat scenario are refined using this feedback information, and the first and second correction factors in the risk calculation parameters are adjusted to reduce the risk value of the scenario under the aforementioned context conditions. If the feedback information indicates that a new environmental context will trigger a new type of threat, the corresponding threat scenario is added to the dynamic threat knowledge base using this feedback information, and its context conditions and risk calculation parameters are defined.

[0096] This application's embodiments introduce real-time dynamic environmental context information, enabling threat analysis and risk quantification to align with the vehicle's real-time operating status, network environment, and geographical context. This accurately reflects the real, immediate risks faced by the vehicle under specific conditions, avoiding the overestimation or underestimation of risks inherent in static assessments. Simultaneously, by matching dynamically quantified risk values ​​with corresponding security response strategies, on-demand dynamic adjustments to protection strategies are achieved. Different risk levels correspond to different strengths and types of response measures, optimizing resource consumption while ensuring vehicle network security and resolving the issues of outdated, wasteful, or insufficient protection from static strategies. A closed-loop feedback mechanism uses the feedback information from the entire security response strategy execution process for updating and optimizing the dynamic threat knowledge base. This allows for learning from actual security incidents, continuously improving threat scenario models, adjusting risk calculation parameters, and optimizing response strategies. This provides the potential to address new threats and unknown attacks in the connected vehicle environment, achieving self-evolution and ultimately enhancing the protection level of vehicle network security in the dynamic environment of connected vehicles.

[0097] Based on the threat analysis and risk assessment method provided in the foregoing embodiments, this application also provides a threat analysis and risk assessment system. Figure 2 This is a schematic diagram of the structure of a threat analysis and risk assessment system provided in an embodiment of this application. Figure 2 As shown, the threat analysis and risk assessment system includes: a multi-source data acquisition module 201, an environmental information generation module 202, a threat scenario determination module 203, a risk quantification assessment module 204, and a response strategy determination module 205.

[0098] The multi-source data acquisition module 201 is used to collect multi-source data in the vehicle network environment in real time.

[0099] The environmental information generation module 202 is used to generate structured environmental context information based on multi-source data; the environmental context information represents the current environmental state of the vehicle.

[0100] The threat scenario determination module 203 is used to match environmental context information with a pre-built dynamic threat knowledge base to determine the target threat scenario. The dynamic threat knowledge base stores multiple threat scenarios, and each threat scenario is associated with context conditions and risk calculation parameters used to trigger the threat scenario.

[0101] The risk quantification assessment module 204 is used to perform risk quantification assessment of the target threat scenario based on environmental context information and risk calculation parameters associated with the target threat scenario, and obtain the corresponding risk value.

[0102] The response strategy determination module 205 is used to determine the corresponding security response strategy from a pre-built response strategy library based on the risk value.

[0103] This embodiment of the application, through the coordinated operation of the multi-source data acquisition module 201, the environmental information generation module 202, the threat scenario determination module 203, the risk quantification assessment module 204, and the response strategy determination module 205, achieves dynamic analysis of the entire process from real-time acquisition of multi-source data to precise matching of security response strategies in the vehicle network environment. This allows threat analysis and risk assessment to align with the actual operating status of the vehicle, accurately reflecting immediate risks, while enabling dynamic adjustment of protection strategies as needed. This effectively solves the problems of rigidity in static assessment and lag in protection strategies, improving the protection capability and response efficiency of vehicle network security in the dynamic environment of the vehicle network.

[0104] In the optional implementation, the threat scenario determination module 203 is specifically used for: Iterate through the threat scenarios in the dynamic threat knowledge base and determine whether the environmental context information satisfies the context conditions associated with that threat scenario. Threat scenarios that meet the context conditions are identified as target threat scenarios.

[0105] In the optional implementation, the environment information generation module 202 is specifically used for: Multi-source data is fused to generate fused data. Semantic abstraction is then performed on the fused data, mapping the original data into contextual information items with predefined security meanings. These contextual information items constitute the environmental context information.

[0106] In an optional implementation, the risk quantification assessment module 204 includes a first determination unit, a second determination unit, and a risk calculation unit.

[0107] The first determining unit is used to determine the first risk value of the target threat scenario based on environmental context information and risk calculation parameters associated with the target threat scenario; the first risk value is used to characterize the probability that the target threat scenario will cause a threat.

[0108] The second determining unit is used to determine the second risk value of the target threat scenario based on environmental context information and risk calculation parameters associated with the target threat scenario; the second risk value is used to characterize the degree of impact of the target threat scenario.

[0109] The risk calculation unit is used to obtain the risk value based on the first risk value, the second risk value, and the risk calculation parameter value associated with the target threat scenario.

[0110] In the optional implementation, the risk calculation parameters include a basic first risk value and a basic second risk value. The first determining unit is specifically used for: Based on the environmental context information, a first correction factor corresponding to the environmental context information is determined from a predefined first risk quantification table. The first risk value is obtained by calculating the basic first risk value and the first correction factor using a preset first aggregation function.

[0111] The second determining unit is specifically used for: Based on the environmental context information, the corresponding second correction factor is determined from a predefined second risk quantification table. The second risk value is then calculated using a preset second aggregation function on the basic second risk value and the second correction factor.

[0112] In the optional implementation, the risk calculation parameters include risk-related parameters, and the risk calculation unit is specifically used for: Based on the risk correlation parameters, the first risk value and the second risk value are correlated and calculated to obtain the risk value.

[0113] In optional implementations, the threat analysis and risk assessment system also includes a security policy enforcement module and a knowledge base optimization module.

[0114] The security policy execution module is used to execute security response policies.

[0115] The knowledge base optimization module is used to update and optimize the dynamic threat knowledge base based on feedback information generated from the execution of security response policies.

[0116] In the optional implementation, the feedback information includes the environmental context information of the scenario that triggered the target threat, the corresponding risk value, the determined security response strategy, and the effect data of executing the security response strategy. The knowledge base optimization module is specifically used for: Optimize the contextual conditions and / or risk calculation parameters associated with the threat scenario using feedback information.

[0117] In the optional implementation, the multi-source data collected by the multi-source data acquisition module 201 includes one or more of the following: vehicle status data, network connection data, environmental perception data, and mission-critical data.

[0118] It should be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for the system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments. The system embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separate. The components indicated as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the solution in this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0119] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A threat analysis and risk assessment method, characterized in that, Applied to vehicles, the method includes: Real-time collection of multi-source data from the vehicle's connected vehicle environment; Based on the multi-source data, structured environmental context information is generated; the environmental context information represents the current environmental state of the vehicle. The environmental context information is matched with a pre-built dynamic threat knowledge base to determine the target threat scenario; the dynamic threat knowledge base stores multiple threat scenarios, and each threat scenario is associated with context conditions and risk calculation parameters used to trigger the threat scenario; Based on the environmental context information and the risk calculation parameters associated with the target threat scenario, a risk quantification assessment of the target threat scenario is performed to obtain the corresponding risk value. Based on the risk value, the corresponding security response strategy is determined from a pre-built response strategy library.

2. The method according to claim 1, characterized in that, The step of matching environmental context information with a pre-built dynamic threat knowledge base to determine the target threat scenario includes: Traverse the threat scenarios in the dynamic threat knowledge base and determine whether the environmental context information satisfies the context conditions associated with the threat scenario; Threat scenarios that satisfy the aforementioned contextual conditions are identified as the target threat scenarios.

3. The method according to claim 1, characterized in that, The generation of structured environmental context information based on the multi-source data includes: The multi-source data is fused to generate fused data; The fused data is semantically abstracted, and the original data is mapped into context information items with preset security meanings. These context information items constitute the environmental context information.

4. The method according to claim 1, characterized in that, The step of performing a risk quantification assessment of the target threat scenario based on the environmental context information and the risk calculation parameters associated with the target threat scenario to obtain the corresponding risk value includes: Based on the environmental context information and the risk calculation parameters associated with the target threat scenario, a first risk value for the target threat scenario is determined; the first risk value is used to characterize the probability that the target threat scenario will pose a threat. Based on the environmental context information and the risk calculation parameters associated with the target threat scenario, a second risk value for the target threat scenario is determined; the second risk value is used to characterize the degree of impact of the threat posed by the target threat scenario. The risk value is obtained based on the first risk value, the second risk, and the risk calculation parameter value associated with the target threat scenario.

5. The method according to claim 4, characterized in that, The risk calculation parameters include a basic first risk value and a basic second risk value; The risk calculation parameters associated with the environmental context information and the target threat scenario are used to determine a first risk value for the target threat scenario, including: Based on the environmental context information, a first correction factor corresponding to the environmental context information is determined from a predefined first risk quantification table; The first risk value is obtained by calculating the basic first risk value and the first correction factor using a preset first aggregation function; The step of determining the second risk value of the target threat scenario based on the environmental context information and the risk calculation parameters associated with the target threat scenario includes: Based on the environmental context information, determine the corresponding second correction factor from the predefined second risk quantification table; The second risk value is obtained by calculating the basic second risk value and the second correction factor using a preset second aggregation function.

6. The method according to claim 4, characterized in that, The risk calculation parameters include risk correlation parameters, and obtaining the risk value based on the first risk value and the second risk value includes: Based on the risk association parameters, the first risk value and the second risk value are correlated and calculated to obtain the risk value.

7. The method according to claim 1, characterized in that, After determining the corresponding security response strategy from a pre-built response strategy library based on the risk value, the method further includes: Execute the security response strategy; The dynamic threat knowledge base is updated and optimized based on the feedback information generated from executing the security response strategy.

8. The method according to claim 7, characterized in that, The feedback information includes the environmental context information that triggered the target threat scenario, the corresponding risk value, the determined security response strategy, and the effect data of executing the security response strategy. The updating and optimization of the dynamic threat knowledge base includes: The feedback information is used to optimize the contextual conditions and / or risk calculation parameters associated with the threat scenario.

9. The method according to claim 1, characterized in that, The multi-source data includes one or more of the following: vehicle status data, network connection data, environmental perception data, and mission-critical data.

10. A threat analysis and risk assessment system, characterized in that, Applied to vehicles, the system includes: A multi-source data acquisition module is used to collect multi-source data in the vehicle network environment in which the vehicle is located in real time; An environmental information generation module is used to generate structured environmental context information based on the multi-source data; the environmental context information represents the current environmental state of the vehicle. The threat scenario determination module is used to match the environmental context information with a pre-built dynamic threat knowledge base to determine the target threat scenario; the dynamic threat knowledge base stores multiple threat scenarios, and each threat scenario is associated with context conditions and risk calculation parameters used to trigger the threat scenario; The risk quantification and assessment module is used to perform risk quantification and assessment of the target threat scenario based on the environmental context information and the risk calculation parameters associated with the target threat scenario, and obtain the corresponding risk value. The response strategy determination module is used to determine the corresponding security response strategy from a pre-built response strategy library based on the risk value.