Commercial vehicle information security threat analysis and risk assessment method and system
By establishing a commercial vehicle risk assessment database and modular system, the problem of low efficiency in commercial vehicle information security threat analysis and risk assessment has been solved, achieving efficient and accurate risk assessment and control, standardizing the assessment process, and integrating it into the commercial vehicle development process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHAANXI HEAVY DUTY AUTOMOBILE CO LTD
- Filing Date
- 2024-11-18
- Publication Date
- 2026-05-19
AI Technical Summary
The information security threat analysis and risk assessment of commercial vehicles are inefficient, the assessment results are inaccurate, the assessment process is not standardized, the identified risks cannot be effectively controlled, and they cannot be integrated into the commercial vehicle development process.
Establish a database of input information for commercial vehicle risk assessment, including an asset database, a hazard database, a threat database, an attack database, and a risk value model database. The assessment is conducted using the HEAVENS security model, and combined with asset identification, risk assessment, and risk control modules, automated risk assessment and control are achieved.
It improved the efficiency and accuracy of risk assessment, standardized the assessment process, achieved closed-loop management of risk assessment, simplified data flow diagrams, reduced the workload of personnel, and improved the standardization and accuracy of assessment.
Smart Images

Figure CN122065320A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent connected vehicle technology, specifically to a method and system for analyzing and assessing information security threats and risks in commercial vehicles. Background Technology
[0002] With the increasing intelligence and connectivity of commercial vehicles, the various intelligent devices installed on them have greatly enhanced the level of information interaction with the outside world. The development of intelligent connected technology has brought more convenience, improved driving experience, and increased communication data and signals to commercial vehicles. However, at the same time, the information security issues of commercial vehicles are becoming increasingly prominent, making security protection for commercial vehicles particularly important. Security protection requires a detailed risk assessment of commercial vehicles to identify potential risks, and then designing security protection measures based on these identified risks. Threat analysis and risk assessment are analytical techniques that can be applied to the conceptual design stage. They can help commercial vehicles identify potential information security threats in advance and address or mitigate these risks through information security protection measures, thereby improving the safety of commercial vehicles. Existing traditional vehicle development platforms for commercial vehicles cannot integrate threat analysis and risk assessment activities. Currently, threat analysis and risk assessment mainly rely on information security engineers to conduct them manually. However, due to differences in their professional experience and skill levels, different information security engineers often result in inconsistent risk assessment processes, low efficiency, and inaccurate results. Furthermore, the current method of conducting threat analysis and risk assessment manually cannot standardize the input information for risk assessment, track and control all output risks, or integrate the threat analysis and risk assessment process into the commercial vehicle development process.
[0003] Therefore, a method and system for analyzing and assessing information security threats and risks in commercial vehicles are needed. Summary of the Invention
[0004] To address the issues of low efficiency, inaccurate assessment results, non-standard assessment processes, and ineffective risk management in commercial vehicle threat analysis and risk assessment, this invention aims to provide a method and system for commercial vehicle information security threat analysis and risk assessment.
[0005] The technical solution adopted by this invention to solve its technical problem is: a method for information security threat analysis and risk assessment of commercial vehicles, comprising the following steps:
[0006] S1: Establish a database of input information for commercial vehicle risk assessment, which includes an asset database, a hazard database, a threat database, an attack database, a risk value model database, and a safety target database.
[0007] S2: Based on the input information database, determine the relevance of the assessment object to the risk assessment of the functional units, identify external interfaces, identify data processing, identify data flow, and identify key stored data to obtain assets related to the risk assessment;
[0008] S3: Identify hazard scenarios by analyzing the security attribute failure scenarios of assets through the hazard database, and evaluate the impact value and impact level of the hazards using the HEAVENS security model;
[0009] S4: Identify threat scenarios by analyzing the threat database, identify attack paths by using the attack database, and assess the attack difficulty and feasibility level using the attack potential method;
[0010] S5: Determine the risk value of an asset based on the impact level of the hazard and the attack feasibility level using a risk value model library;
[0011] S6: Determine risk management strategies by combining the level of harm impact, threat scenario, attack path, and risk value;
[0012] S7: Based on the security target library, determine the information security targets of the assessment object through threat scenarios, attack paths and risk handling strategies.
[0013] A commercial vehicle information security threat analysis and risk assessment system includes an asset identification module, a risk assessment module, and a risk control module;
[0014] The asset identification module is used to identify commercial vehicles and information security-related functional units and to screen assets that require risk assessment.
[0015] The risk assessment module is used to assess the hazard impact level, attack potential, and risk value of identified assets.
[0016] The risk management module is used for risk management, information security objectives, and information security testing and verification management.
[0017] Preferably, the asset identification module includes risk assessment correlation determination of functional units, screening of external interfaces of functional units, data processing and data flow identification of functional units, and identification of key stored data of functional units.
[0018] Preferably, the risk assessment module includes a hazard impact level assessment, an attack potential assessment, and a risk value assessment.
[0019] Preferably, the risk management module includes risk handling, information security target determination, information security protection design, and information security testing and verification.
[0020] Preferably, the risk assessment relevance determination of the functional unit includes: whether the vehicle function implemented or executed by the assessment object uses E / E architecture technology, whether the assessment object contains the vehicle's external interface, whether the assessment object implements the vehicle's safe operation, whether the assessment object includes wireless network connection scenarios, whether the assessment object needs to collect user-related data when implementing or executing vehicle functions, and whether the assessment object implements vehicle functions based on network components.
[0021] The external interfaces of functional units are identified through three categories: remote, near-field, and physical contact.
[0022] The data processing and data stream identification of the functional unit includes identifying the specific name of the data being processed, identifying the source of the data, identifying the processing procedure of the data, and identifying the destination of the data.
[0023] Identifying key stored data for functional units includes: identifying the name of key stored data, the data storage location, and a description of the data's purpose.
[0024] Preferably, the hazard impact level assessment is based on a hazard database, which identifies hazard scenarios by analyzing the failure scenarios of the security attributes of assets, and adopts the HEAVENS security model to assess the impact value and impact level of the hazard through four dimensions: functional safety, financial, operability, and privacy.
[0025] The attack potential assessment module includes identifying threat scenarios based on the harm scenarios, identifying attack paths based on the threat scenarios, assessing the attack difficulty based on the attack paths using attack potential-based methods, and determining the attack feasibility level based on the attack difficulty.
[0026] Risk assessment determines the risk value of an asset by assessing the impact level of the hazard and the attack feasibility level.
[0027] Preferably, the risk management strategy is determined by combining the level of harm impact, threat scenario, attack path, and risk value.
[0028] Information security objectives are determined based on an information security objective database, through threat scenarios, attack paths, and risk mitigation strategies.
[0029] After the assessment object completes the information security protection design scheme, the information security protection design scheme is imported from the commercial vehicle development and management platform.
[0030] Information security testing and verification: After the evaluation object completes the information security testing and verification, the information security test report is imported from the commercial vehicle development and management platform to achieve closed-loop management of risk verification.
[0031] The present invention has the following beneficial effects:
[0032] 1) By providing methods for analyzing and assessing information security threats to commercial vehicles, technical personnel can quickly and accurately identify, assess, and manage the risks of commercial vehicle assets.
[0033] 2) The commercial vehicle information security threat analysis and risk assessment system provides users with a visual front-end interface. It can automatically match the impact level, attack potential and risk level of information security assets from the model library based on input information, reduce the workload of personnel, improve efficiency, and ensure the standardization of the risk assessment process.
[0034] 3) Through the asset identification module, the assets related to the risk assessment of commercial vehicles are analyzed and identified, the information security risk assessment process is optimized, the cumbersome data flow diagrams are avoided, the steps are simplified and time is saved;
[0035] 4) Through the data processing and data flow identification methods of the provided functional units, commercial vehicles and risk assessment-related assets can be automatically identified efficiently and accurately;
[0036] 5) By building the hazard, threat, and attack databases in the risk assessment module, and combining expert experience, commercial vehicle industry development trends, regulatory and standard requirements, and actual threats and attacks in the intrusion detection system, the efficiency and accuracy of risk assessment can be improved.
[0037] 6) By integrating the information security threat analysis and risk assessment system into the commercial vehicle development and management platform, the threat analysis and risk assessment system is incorporated into the forward development process of commercial vehicles. This enables risk disposal of commercial vehicle assets, determination of information security objectives, design of information security protection, and information security testing and verification, thereby achieving closed-loop management of risk assessment, risk mitigation, and risk verification for commercial vehicles. Attached Figure Description
[0038] Figure 1 This is a system structure block diagram of the present invention.
[0039] Figure 2 This is the flowchart for the asset identification module.
[0040] Figure 3 This is a flowchart for determining the relevance of risk assessment for functional units.
[0041] Figure 4 It is a flowchart of data processing and data flow identification for the functional unit.
[0042] Figure 5 This is a flowchart for identifying key stored data in a functional unit.
[0043] Figure 6 This is a flowchart for threat analysis and risk assessment.
[0044] Figure 7 This is a risk management flowchart. Detailed Implementation
[0045] The technical solutions of the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0046] like Figure 1-2 As shown, a commercial vehicle information security threat analysis and risk assessment system includes an asset identification module, a risk assessment module, and a risk control module. The asset identification module and the risk assessment module are interconnected, and the risk assessment module and the risk control module are interconnected. The system specifically includes the following steps:
[0047] During the asset identification phase, the asset identification module identifies commercial vehicles and information security-related functional units, and screens assets that require risk assessment.
[0048] During the risk assessment phase, the identified assets are assessed for hazard impact level, attack potential, and risk value using the risk assessment module, resulting in a risk assessment result (including impact level value, attack potential value, and risk level).
[0049] During the risk management phase, the risk management module is used to handle risks, define information security objectives, and formulate information security protection design schemes. After the commercial vehicle completes information security testing and verification, the information security test report is imported into the risk management module to achieve closed-loop management of commercial vehicle information security risk assessment. An information security threat analysis and risk assessment system is integrated into the commercial vehicle development management platform, enabling the threat analysis and risk assessment system to be incorporated into the forward development process of commercial vehicles.
[0050] The asset identification module includes four sub-modules: risk assessment relevance determination of functional units, screening of external interfaces of functional units, data processing and data flow identification of functional units, and identification of key stored data of functional units.
[0051] The risk assessment relevance determination submodule of the functional unit determines whether the assessment object and the risk assessment are relevant through 6 steps, including whether the vehicle function implemented or executed by the assessment object uses E / E architecture technology, whether the assessment object contains the vehicle's external interface, whether the assessment object implements the vehicle's safe operation, whether the assessment object includes wireless network connection scenarios, whether the assessment object needs to collect user-related data when implementing or executing vehicle functions, and whether the assessment object implements vehicle functions based on network components.
[0052] The functional unit external interface filtering submodule identifies external interfaces through three categories: remote, near-field, and physical contact.
[0053] The data processing and data flow identification submodule of the functional unit identifies the data flow assets of the functional unit through four steps, including identifying the specific name of the data to be processed, identifying the source of the data, identifying the processing process of the data, and identifying the destination of the data.
[0054] The key storage data identification submodule of the functional unit identifies key storage data assets through three steps, including identifying the key storage data name, data storage location, and data usage description.
[0055] The risk assessment module includes hazard impact level assessment, attack potential assessment, and risk value assessment.
[0056] The hazard impact assessment is based on a hazard database. By analyzing the failure scenarios of asset security attributes, hazard scenarios are identified. The HEAVENS safety model is used to assess the impact value and impact level of the hazard through four dimensions: functional safety, financial, operability, and privacy.
[0057] Attack potential assessment involves identifying threat scenarios based on the harm scenarios, identifying attack paths based on the threat scenarios, assessing the attack difficulty based on the attack paths using attack potential-based methods, and determining the attack feasibility level based on the attack difficulty.
[0058] Risk value assessment determines the risk value of an asset based on the impact level of the hazard and the attack feasibility level, using a risk value model library.
[0059] The risk management module includes risk handling, information security objectives, information security protection design, and information security testing and verification.
[0060] Risk management involves determining risk management strategies based on the severity of the hazard, the threat scenario, the attack path, and the risk value.
[0061] Information security objectives are determined based on an information security objective database, by considering threat scenarios, attack paths, and risk mitigation strategies.
[0062] Information security protection design: After the assessment object completes the information security protection design plan, the information security protection design plan is imported from the commercial vehicle development and management platform.
[0063] Information security testing and verification: After the evaluation object completes the information security testing and verification, the information security test report is imported from the commercial vehicle development and management platform to achieve closed-loop management of risk verification.
[0064] like Figure 3 The flowchart shown below illustrates the risk assessment relevance determination process for functional units.
[0065] (a1) Assess whether the vehicle functions implemented or executed by the functional units of commercial vehicles use E / E architecture technology. If the result is "no", then this functional unit is not related to the risk assessment; if the result is "yes", proceed to the next step.
[0066] (a2) Assess whether the functional unit of the commercial vehicle includes the vehicle's external interface. If the result is "yes", then this functional unit is related to the risk assessment; if the result is "no", proceed to the next step.
[0067] (a3) Assess whether the functional units of the commercial vehicle achieve safe operation of the vehicle. If the result is "yes", then this functional unit is related to the risk assessment; if the result is "no", proceed to the next step.
[0068] (a4) Assess whether the functional units of the commercial vehicle include wireless network connection scenarios. If the result is "yes", then this functional unit is related to the risk assessment; if the result is "no", proceed to the next step.
[0069] (a5) Assess whether the functional units of the commercial vehicle need to collect user-related data when implementing or performing vehicle functions. If the result is "yes", then this functional unit is related to risk assessment; if the result is "no", proceed to the next step.
[0070] (a6) Assess whether the functional units of a commercial vehicle are based on network components when implementing vehicle functions. If the result is "yes", then the functional unit is related to the risk assessment; if the result is "no", then the functional unit is not related to the risk assessment.
[0071] The external interfaces of the functional units are screened by identifying them through three categories: remote, near-field, and physical contact. Remote interfaces include 4G and 5G, near-field interfaces include Wi-Fi, Bluetooth, NFC, and RF, and physical contact interfaces include USB, Ethernet, CAN, CANFD, SPI, UART, JTAG, OBD, and I2C.
[0072] like Figure 4 The flowchart shown below illustrates the data processing and data flow identification process for the functional unit, including the following steps:
[0073] (b1) Identify the names of the data processed by the functional unit by combining the data stream name library;
[0074] (b2) Identify the source of data processed by the functional unit by combining the data address database;
[0075] (b3) Identify the data processing process of functional units by combining the data processing library;
[0076] (b4) Combine the data address database to identify the destination of the data processed by the functional unit.
[0077] Figure 5 The flowchart for identifying key stored data for a functional unit includes the following steps:
[0078] (c1) Identify the names of key stored data in the functional unit by combining the name database of the data storage;
[0079] (c2) Identify the location of data storage for functional units by combining the data storage address database;
[0080] (c3) Identify the data usage of functional units by combining the data usage database.
[0081] The risk assessment module is used to automatically identify the level of harm, attack potential, and risk value of an asset.
[0082] like Figure 6 The flowchart for threat analysis and risk assessment includes the following steps:
[0083] (d1) Hazard impact level assessment: Based on the hazard database, hazard scenarios are identified by analyzing the failure scenarios of the security attributes of assets. The HEAVENS safety model is used to assess the impact value and impact level of the hazard through four dimensions: functional safety, financial, operability and privacy.
[0084] (d2) Attack potential assessment: By analyzing the threat scenarios of assets and combining them with the threat database to identify threat scenarios and the attack database to identify attack paths, the attack potential method is used to assess the attack difficulty and attack feasibility level.
[0085] (d3) Risk value assessment: The risk value of an asset is determined by combining the risk value model library with the impact level of the hazard and the attack feasibility level.
[0086] The attack potential assessment employs four steps: identifying threat scenarios based on the harm scenarios, identifying attack paths based on the threat scenarios, assessing the attack difficulty based on the attack paths using attack potential-based methods, and determining the attack feasibility level based on the attack difficulty.
[0087] The hazard database can be dynamically updated based on actual business development, including expert experience hazard scenario databases, commercial vehicle industry hazard scenario databases, and hazard scenario databases from regulations and standards.
[0088] The attack potential approach uses the HEAVENS methodology to assess attack difficulty across four dimensions: expertise, product availability, window of opportunity, and equipment.
[0089] The threat database can be dynamically updated based on actual business development, including expert experience threat scenario databases, commercial vehicle industry threat scenario databases, threat scenario databases in regulations and standards, and threat scenarios identified by intrusion detection systems.
[0090] The attack library can be dynamically updated based on actual business development, including expert experience attack path library, commercial vehicle industry attack path library, attack path library in regulations and standards, and attack behaviors identified by intrusion detection systems.
[0091] The risk management module is used for asset risk disposal and risk management, such as... Figure 7 The flowchart for risk management, as shown, includes the following steps:
[0092] (e1) Risk management: Determine risk management strategies based on the level of harm, threat scenario, attack path and risk value.
[0093] (e2) Information security target determination: Based on the information security target database, the information security targets of the assessment object are determined through threat scenarios, attack paths and risk handling strategies.
[0094] (e3) Information security protection design: After the assessment object completes the information security protection design scheme, the information security protection design scheme is imported from the commercial vehicle development and management platform.
[0095] (e4) Information security testing and verification: After the evaluation object completes the information security testing and verification, the information security test report is imported from the commercial vehicle development and management platform.
[0096] This system standardizes the risk assessment process, improves the efficiency and accuracy of risk assessment, incorporates threat analysis and risk assessment processes into the commercial vehicle development process, and achieves closed-loop management of commercial vehicle risk assessment, risk mitigation, and risk verification.
[0097] Definitions of abbreviations and key terms:
[0098] Assets: Things that may cause harm to stakeholders due to non-compliance with information security attributes, including vehicle electronic components, sensors, actuators, connections between components, connections between internal parts of the ECU, and software in the ECU.
[0099] Attack: An attempt to damage, disclose, tamper with, harm, steal, or otherwise use assets without authorization. An attempt to intentionally interact with components and their environment to produce adverse consequences.
[0100] Attack Feasibility: An attribute of attack path attainment, describing the ease or difficulty of successfully executing the corresponding attack.
[0101] Attack path: A set of activities that can lead to the realization of a threat.
[0102] Attack potential: The likelihood of successfully carrying out a potential attack.
[0103] Hazard scenario: Adverse or adverse consequences resulting from the failure of one (or more) cybersecurity features of one or a group of assets to be met.
[0104] Risk: Risk refers to the uncertain impact on the information security of road vehicles.
[0105] Threat: A scenario or event that presents a potential hazard, which may involve financial, reputational, privacy, personal safety, or operational vulnerability. It is the potential cause of an undesirable event that could harm a system, organization, or users.
[0106] Threat scenario: A description of potential negative activities that could lead to a harmful scenario.
[0107] Commercial vehicle development management platform: The commercial vehicle development management platform is used to manage activities at each stage of commercial vehicle development, including pre-research planning, solution research, detailed development, development verification, production preparation, and market launch development.
[0108] E / E architecture: an abbreviation for Electrical / Electronic architecture, refers to the electronic and electrical architecture of commercial vehicles, which involves the design of the vehicle's hardware and software, including sensors, actuators, ECUs, wiring harnesses, and operating systems.
[0109] This invention is not limited to the above-described embodiments. Anyone should know that any structural changes made under the guidance of this invention, and any technical solutions that are the same as or similar to this invention, fall within the protection scope of this invention.
[0110] The technologies, shapes, and structures not described in detail in this invention are all known technologies.
Claims
1. A method for analyzing and assessing information security threats and risks in commercial vehicles, characterized in that, Includes the following steps: S1: Establish a database of input information for commercial vehicle risk assessment, which includes an asset database, a hazard database, a threat database, an attack database, a risk value model database, and a safety target database. S2: Based on the input information database, determine the relevance of the assessment object to the risk assessment of the functional units, identify external interfaces, identify data processing, identify data flow, and identify key stored data to obtain assets related to the risk assessment; S3: Identify hazard scenarios by analyzing the security attribute failure scenarios of assets through the hazard database, and evaluate the impact value and impact level of the hazards using the HEAVENS security model; S4: Identify threat scenarios by analyzing the threat database, identify attack paths by using the attack database, and assess the attack difficulty and feasibility level using the attack potential method; S5: Determine the risk value of an asset based on the impact level of the hazard and the attack feasibility level using a risk value model library; S6: Determine risk management strategies by combining the level of harm impact, threat scenario, attack path, and risk value; S7: Based on the security target library, determine the information security targets of the assessment object through threat scenarios, attack paths and risk handling strategies.
2. A commercial vehicle information security threat analysis and risk assessment system, characterized in that, It includes an asset identification module, a risk assessment module, and a risk management module; The asset identification module is used to identify commercial vehicles and information security-related functional units and to screen assets that require risk assessment. The risk assessment module is used to assess the hazard impact level, attack potential, and risk value of identified assets. The risk management module is used for risk management, information security objectives, and information security testing and verification management.
3. The commercial vehicle information security threat analysis and risk assessment system according to claim 2, characterized in that, The asset identification module includes risk assessment correlation determination of functional units, screening of external interfaces of functional units, data processing and data flow identification of functional units, and identification of key stored data of functional units.
4. The commercial vehicle information security threat analysis and risk assessment system according to claim 2, characterized in that, The risk assessment module includes hazard impact level assessment, attack potential assessment, and risk value assessment.
5. The commercial vehicle information security threat analysis and risk assessment system according to claim 2, characterized in that, The risk management module includes risk handling, information security target determination, information security protection design, and information security testing and verification.
6. The commercial vehicle information security threat analysis and risk assessment system according to claim 3, characterized in that, The risk assessment relevance determination of the functional unit includes: whether the vehicle function implemented or executed by the assessment object uses E / E architecture technology, whether the assessment object contains the vehicle's external interface, whether the assessment object implements the vehicle's safe operation, whether the assessment object includes wireless network connection scenarios, whether the assessment object needs to collect user-related data when implementing or executing vehicle functions, and whether the assessment object implements vehicle functions based on network components. The external interfaces of functional units are identified through three categories: remote, near-field, and physical contact. The data processing and data stream identification of the functional unit includes identifying the specific name of the data being processed, identifying the source of the data, identifying the processing procedure of the data, and identifying the destination of the data. Identifying key stored data for functional units includes: identifying the name of key stored data, the data storage location, and a description of the data's purpose.
7. The commercial vehicle information security threat analysis and risk assessment system according to claim 4, characterized in that, The hazard impact level assessment is based on a hazard database. It identifies hazard scenarios by analyzing the failure scenarios of asset security attributes and adopts the HEAVENS safety model to assess the impact value and impact level of the hazard through four dimensions: functional safety, financial, operability, and privacy. The attack potential assessment module includes identifying threat scenarios based on the harm scenarios, identifying attack paths based on the threat scenarios, assessing the attack difficulty based on the attack paths using attack potential-based methods, and determining the attack feasibility level based on the attack difficulty. Risk assessment determines the risk value of an asset by assessing the impact level of the hazard and the attack feasibility level.
8. The commercial vehicle information security threat analysis and risk assessment system according to claim 5, characterized in that, The risk management strategy is determined by combining the level of harm impact, threat scenario, attack path and risk value. Information security objectives are determined based on an information security objective database, through threat scenarios, attack paths, and risk mitigation strategies. After the assessment object completes the information security protection design scheme, the information security protection design scheme is imported from the commercial vehicle development and management platform. Information security testing and verification: After the evaluation object completes the information security testing and verification, the information security test report is imported from the commercial vehicle development and management platform to achieve closed-loop management of risk verification.