System topology graph-based vehicle-network interaction network attack path deduction method and device

By using a system topology diagram approach, combined with physical consistency verification and spatiotemporal correlation analysis, potential attack segments in the vehicle-to-network (V2N) interaction system are identified, solving the problem of distinguishing between batch scheduling and attack behavior, and achieving precise protection and business continuity.

CN122226397APending Publication Date: 2026-06-16ECONOMIC TECH RES INST OF STATE GRID HENAN ELECTRIC POWER +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ECONOMIC TECH RES INST OF STATE GRID HENAN ELECTRIC POWER
Filing Date
2026-03-23
Publication Date
2026-06-16

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively distinguish between batch scheduling behaviors and network attack behaviors in vehicle-to-grid interaction systems, leading to misjudgments or missed detections, resulting in poor protection. Furthermore, traditional defense methods may cause charging service interruptions, failing to meet business continuity requirements.

Method used

A system topology-based approach is adopted to obtain the original control command set and charging station transformer telemetry records, perform physical consistency verification and spatiotemporal correlation analysis, identify network segments covered by abnormal commands, and determine potential attack network segments by combining the network logical topology structure, and implement access control.

Benefits of technology

It enables accurate identification and protection against attacks, ensuring the security and business continuity of the vehicle-to-everything (V2X) interaction system, and improving the system's security and availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122226397A_ABST
    Figure CN122226397A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network security, in particular to a vehicle-network interaction network attack path deduction method and device based on a system topology graph, which comprises the following steps: acquiring original control instruction sets, charging station transformer telemetry records and network logical topology structures within a preset time length; performing physical consistency verification on the original control instruction sets and the charging station transformer telemetry records to obtain verified control instruction sets; performing space-time correlation analysis on the verified control instruction sets based on IP addresses and control time points in each verified control instruction in the verified control instruction sets to identify abnormal instruction coverage network segments; determining at least one potential attack network segment based on the abnormal instruction coverage network segments and the network logical topology structures; and performing access control on the at least one potential attack network segment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, specifically to a method and apparatus for deducing attack paths in vehicle-to-network interaction based on system topology diagrams. Background Technology

[0002] Vehicle-to-grid (V2G) systems utilize a cloud platform to schedule a massive number of distributed charging stations to participate in grid regulation. In actual operation, to respond to grid regulation needs, the cloud platform often needs to concurrently issue scheduling commands to charging stations within a specific area. This batch operation manifests in communication traffic as a surge of connection requests targeting a large number of Internet Protocol (IP) addresses. Meanwhile, network attacks typically employ automated attack scripts to perform lateral movement scans on internal network terminals.

[0003] In related technologies, these two behaviors are usually distinguished based on shallow statistical indicators such as traffic thresholds and connection frequency.

[0004] However, this kind of batch control behavior is highly similar to attack behavior in terms of statistical characteristics. It is difficult to effectively distinguish them based on shallow statistical indicators alone, which may lead to misjudgment or missed detection of attack behavior and poor protection effect. Summary of the Invention

[0005] To address the technical challenge of distinguishing between batch control behaviors and attack behaviors based on shallow statistical indicators such as traffic thresholds and connection frequency, this application aims to provide a method and apparatus for deducing attack paths in vehicle-to-network (V2N) interactive networks based on system topology diagrams. The specific technical solution adopted is as follows: This application provides a method for inferring attack paths in a vehicle-to-grid (V2G) network based on a system topology diagram. The method includes: acquiring an original control instruction set, charging station transformer telemetry records, and a network logical topology within a preset time period. The original control instruction set includes multiple original control instructions, each including an Internet Protocol (IP) address, a control time, and a power control amount. The charging station transformer telemetry records are used to record the bus voltage value of the charging station transformer in one sampling period. Based on the power control amount included in each original control instruction and the bus voltage value in each sampling period, a physical consistency check with negative correlation constraints is performed on the original control instruction set and the charging station transformer telemetry records to obtain a verified control instruction set. This verified control instruction set includes verified control instructions capable of triggering real physical responses. Based on the IP address and control time in each verified control instruction in the verified control instruction set, spatiotemporal correlation analysis is performed on the verified control instruction set to identify abnormal instruction coverage network segments, which include multiple IP addresses. Based on the abnormal instruction coverage network segments and the network logical topology, at least one potential attack network segment is determined. Access control is then applied to the at least one potential attack network segment.

[0006] Optionally, the above-mentioned analysis of the spatiotemporal correlation of the verified control instruction set based on the IP address and control time of each control instruction in the verified control instruction set to identify the network segment covered by abnormal instructions includes: determining M independent operation chains based on the IP address and control time of each verified control instruction in the verified control instruction set, where each independent operation chain includes at least two verified control instructions, and M is an integer greater than or equal to 1; determining the spatiotemporal ranking correlation coefficient of each independent operation chain based on the IP address and control time of each verified control instruction in each independent operation chain; determining abnormal independent operation chains based on the spatiotemporal ranking correlation coefficient of each independent operation chain; and identifying the network segment to which the IP address included in the abnormal independent operation chain belongs as the network segment covered by abnormal instructions.

[0007] Optionally, the above-mentioned determination of multiple independent operation chains based on the IP address and control time of each verified control instruction in the verified control instruction set includes: dividing a preset duration into multiple time windows based on a preset step size; determining the time difference between the control times of any two verified control instructions and the address span between their IP addresses within each time window; traversing the verified control instructions within each time window and establishing a directed connection between two verified control instructions whose time difference is less than a time difference threshold and whose address span is less than an address span threshold; and extracting multiple independent operation chains based on the directed connection relationships between multiple verified control instructions.

[0008] Optionally, the above-mentioned extraction of multiple independent operation chains based on the directed connection relationship between multiple verified control commands includes: constructing a spatiotemporal correlation graph based on the directed connection relationship between multiple verified control commands; extracting a weakly connected subgraph from the spatiotemporal correlation graph, and identifying the weakly connected subgraph as an independent operation chain.

[0009] Optionally, determining the spatiotemporal order correlation coefficient of each independent operation chain based on the IP address and control time of each verified control instruction in each independent operation chain includes: generating a time-ordered index sequence and an address-ordered index sequence for the first independent operation chain based on the IP address and control time of each verified control instruction in the first independent operation chain, wherein the first independent operation chain is any one of multiple independent operation chains; and determining the spatiotemporal order correlation coefficient of the first independent operation chain based on the sequence number of each verified control instruction in the time-ordered index sequence and the address-ordered index sequence, respectively.

[0010] Optionally, the above-mentioned determination of abnormal independent operation chains based on the spatiotemporal ordering correlation coefficient of each independent operation chain includes: if the absolute value of the spatiotemporal ordering correlation coefficient of the first independent operation chain is greater than the correlation coefficient threshold, the first independent operation chain is determined as an abnormal independent operation chain.

[0011] Optionally, the above-mentioned determination of at least one potential attack network segment based on the network segment covered by the abnormal instruction and the network logical topology includes: determining the adjacent network segments of the network segment covered by the abnormal instruction based on the network logical topology; and determining the adjacent network segments as the at least one potential attack network segment.

[0012] Optionally, the above-mentioned access control of the at least one potentially attacked network segment includes: generating a lateral isolation policy, which is used to block traffic from the network segment covered by the abnormal instruction to the potentially attacked network segment; and performing access control on the at least one potentially attacked network segment based on the lateral isolation policy.

[0013] Optionally, the above-mentioned access control of the at least one potentially attacked network segment further includes: generating a vertical keep-alive policy, which allows traffic sent from the network segment covered by the abnormal instruction to the cloud platform scheduling server; and performing access control on the at least one potentially attacked network segment based on the vertical keep-alive policy.

[0014] This application also provides a device for inferring network attack paths for vehicle-to-grid interaction based on a system topology diagram, including a data acquisition module, an analysis module, and a control module. The data acquisition module is used to acquire a set of original control instructions, charging station transformer telemetry records, and the network logical topology within a preset time period. The set of original control instructions includes multiple original control instructions, each including an Internet Protocol (IP) address, control time, and power control amount. The charging station transformer telemetry records are used to record the bus voltage value of the charging station transformer in one sampling period. The analysis module is used to analyze the original control instructions based on the power control amount included in each original control instruction and the bus voltage value in each sampling period. The control instruction set and the telemetry records of the transformer at the charging station are subjected to physical consistency verification under negative correlation constraints to obtain a verified control instruction set. This verified control instruction set includes verified control instructions that can trigger real physical responses. The analysis module is also used to perform spatiotemporal correlation analysis on the verified control instruction set based on the IP address and control time of each verified control instruction in the verified control instruction set to identify abnormal instruction coverage network segments, which include multiple IP addresses. The analysis module is also used to determine at least one potential attack network segment based on the abnormal instruction coverage network segment and the network logical topology. The control module is used to perform access control on the at least one potential attack network segment.

[0015] This application has the following beneficial effects: In this application, the authenticity of the analyzed data is first ensured through physical consistency verification. Based on the initially screened authentic data, spatiotemporal correlation analysis is performed to accurately identify the network segments covered by abnormal commands using spatiotemporal characteristics. Then, by combining the adjacency relationships between network segments in the network logical topology, potential attack targets are deduced. Finally, access control is implemented, which can accurately identify attack behaviors, achieve precise protection against attack behaviors, ensure business continuity, and significantly improve the security and availability of the vehicle-to-everything (V2X) interactive system. Attached Figure Description

[0016] To more clearly illustrate the technical solutions and advantages in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 A schematic diagram illustrating a method for deducing attack paths in a vehicle-to-everything (V2X) network based on a system topology diagram, provided as an embodiment of this application. Figure 2A schematic diagram of another method for inferring attack paths in a vehicle-to-network interaction system based on a system topology diagram, provided as an embodiment of this application; Figure 3 This is a structural diagram of a vehicle-to-network (V2N) attack path deduction device based on a system topology diagram, provided as an embodiment of this application. Detailed Implementation

[0018] To further illustrate the technical means and effects adopted by this application to achieve the intended purpose of the invention, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of a method and apparatus for deducing vehicle-to-everything (V2X) network attack paths based on a system topology diagram proposed in this application. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.

[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains.

[0020] Vehicle-to-the-Gate (V2G) systems utilize a cloud platform to dispatch a massive number of distributed charging stations to participate in grid regulation. In actual operation, to respond to grid regulation demands, the cloud platform often needs to concurrently issue dispatch commands to charging stations within a specific area. This batch operation manifests in communication traffic as a surge of connection requests targeting a large number of IP addresses. This behavior is statistically highly similar to the lateral movement scanning behavior of network attackers using automated attack scripts on internal network terminals; both result in a short-term surge in traffic.

[0021] Traditional detection systems based on traffic thresholds or frequency analysis struggle to distinguish between these two behaviors, easily misreporting normal grid dispatching as attacks or failing to detect genuine internal network infiltration under the cover of massive concurrent dispatching. Furthermore, charging pile terminals have limited computing resources, making it difficult to deploy deep packet inspection probes. Existing defense methods mostly employ a network-wide blocking strategy; once triggered, this leads to a disruption of charging services in the affected area, failing to meet the business continuity requirements of vehicle-to-grid interaction systems. Therefore, how to differentiate between cloud-based concurrent dispatching and internal network lateral movement without relying on terminal deep packet inspection probes, and achieve precise blocking, is a key technical problem that needs to be solved.

[0022] The following description, in conjunction with the accompanying drawings, details the specific scheme of the method and apparatus for deriving vehicle-to-network (V2N) attack paths based on system topology diagrams provided in this application.

[0023] Please see Figure 1The diagram illustrates a flowchart of a method for inferring attack paths in a vehicle-to-network interaction system based on a system topology diagram, provided in one embodiment of this application.

[0024] like Figure 1 As shown, the method for inferring the attack path of the vehicle-to-network interaction network based on the system topology diagram includes S101-S105.

[0025] S101. Obtain the original control instruction set, charging station transformer telemetry records, and network logical topology within a preset time period.

[0026] The original control instruction set includes multiple original control instructions. Each original control instruction includes an IP address, control time, and power control amount. The charging station transformer telemetry record is used to record the bus voltage value of the charging station transformer in each sampling period. The network logical topology is used to characterize the adjacency relationship between network segments.

[0027] It should be understood that the original control command is used to regulate the active power output of the charging pile. When responding to the grid regulation needs, the cloud scheduling platform of the vehicle-grid interaction system will issue the original control command to the charging pile.

[0028] Optionally, all control instructions issued within a preset time period (e.g., the past 24 hours) can be obtained from the cloud-based scheduling platform to form the original control instruction set.

[0029] Optionally, an initial control command may also include the controlled power and the original power, wherein the controlled power is the power after the charging pile is controlled, and the original power is the current power of the charging pile before the command is executed.

[0030] It should be understood that the telemetry record of the charging station transformer is the bus voltage value collected and recorded by the monitoring terminal of each charging station transformer according to a fixed sampling period. This preset duration should include an integer number of fixed sampling periods. To perform subsequent physical consistency verification, the sampling sequence should ensure that the original control command set and the telemetry record of the charging station transformer cover the same analysis time range, that is, the acquisition time lengths of the two should be aligned, i.e., both are data collected within the preset duration.

[0031] Optionally, the setting of the fixed sampling period needs to take into account both the routine configuration of the power grid monitoring system and the timeliness requirements of attack detection. An example value could be 5 minutes, and an example value for the preset duration could be 24 hours.

[0032] It should be understood that the telemetry record of the charging station transformer includes multiple telemetry records, and each telemetry record includes the bus voltage value of a charging station transformer at the end of a sampling period.

[0033] Alternatively, telemetry records of charging station transformers within a predefined market can be obtained from a distribution automation system used to manage charging station transformers.

[0034] Optionally, a charging station transformer telemetry record may also include a transformer identifier (used to uniquely identify a charging station transformer).

[0035] It should be understood that the logical network topology includes multiple network segments. The adjacency relationship between these multiple network segments includes the continuity of IP address segments (i.e., the IP addresses of two network segments are numerically consecutive or within the same larger address block) and the affiliation and continuity of VLANs (i.e., the VLAN IDs of two network segments are the same, or they belong to the same security domain or routing domain in network planning, or the VLAN ID values ​​are consecutive).

[0036] It should be understood that a network segment is a structured division of IP addresses. One network segment corresponds to a specific range of IP addresses. Multiple IP addresses are planned to belong to the same network segment. A network segment is a collection carrier of IP addresses.

[0037] Optionally, the network logical topology can be in the form of a network logical adjacency list, which records the adjacency relationships between network segments, with network segments as the basic unit.

[0038] S102. Based on the power regulation amount included in each original control command and the bus voltage value in each sampling period, perform a physical consistency check of the original control command set and the telemetry records of the charging station transformer with negative correlation constraints.

[0039] The set of verified control commands includes verified control commands that can trigger real physical responses.

[0040] It should be understood that since network attackers can typically only generate log traffic at the communication layer and cannot manipulate real power electronic loads to generate current changes at the physical layer, physical consistency verification based on this physical unforgeability can initially eliminate fake traffic.

[0041] Optionally, based on the consistency between the power indicated in the original control command set and the actual voltage difference, a false flow can be identified, the false flow can be extracted, and a verified control command can be obtained.

[0042] In one implementation of this application, the charging station transformer corresponding to each original control command can be determined; based on the charging station transformer corresponding to each original control command and the controlled power and original power included in each original control command, the total controlled power of the same charging station transformer in each sampling period of the charging station transformer telemetry record is determined, and based on the telemetry record of the same charging station transformer in each sampling period, the voltage response difference of each charging station transformer in each sampling period is determined; physical consistency verification is performed on whether the total controlled power and the voltage response difference in each sampling period satisfy the negative correlation constraint to obtain the verification result of each sampling period; the original control commands included in the sampling period that pass the physical consistency verification are determined as verified control commands, and the verified control command set is constructed based on the verified control commands.

[0043] Optionally, a transformer-charging station association table can be obtained, which includes the mapping relationship between the IP address of each charging station and the unique charging station transformer identifier. Based on this transformer-charging pile association table, the charging station transformer corresponding to the IP address included in each original control command can be determined.

[0044] Based on the above description, it should be understood that the telemetry records of the charging station transformer are recorded with a fixed sampling period. Therefore, the physical consistency can be analyzed based on the sampling period.

[0045] It is understandable that, based on the charging station transformer corresponding to each control command, at least one control command corresponding to each charging station transformer can be extracted. Then, based on the control time included in each control command, the control command corresponding to the same charging station transformer in each sampling period can be further separated. Furthermore, based on the controlled power and the original power included in each control command, the total controlled power of the same charging station transformer in each sampling period can be determined.

[0046] Optionally, the controlled power amount (i.e., the difference between the controlled power and the original power value) corresponding to each instruction can be accumulated to obtain the total controlled power amount of the transformer of the same charging station within the sampling period.

[0047] It should be understood that this voltage response difference is used to reflect the voltage fluctuation amplitude of the power grid physical layer caused by load power changes during a sampling period of the charging station transformer.

[0048] Optionally, the telemetry records of each charging station transformer can be extracted, and then the absolute value of the difference between the bus voltage value of a charging station transformer in one sampling period (e.g., sampling period 1) and the bus voltage value corresponding to the previous sampling period (e.g., sampling period 2) can be determined as the voltage response difference of the charging station transformer in sampling period 1.

[0049] It should be understood that when the load on a charging station changes significantly, the line voltage will fluctuate in the opposite direction: an increase in load will lead to increased line losses, and the voltage at the terminal bus will inevitably drop; a decrease in load will reduce line losses, and the voltage at the terminal bus will inevitably rise. Therefore, within the same sampling period, the sum of the commanded power corresponding to the transformer of the same charging station (reflecting the total change in the charging station load within that period) and the voltage response difference (reflecting the physical response amplitude of the power grid to this load change) must show an inverse correlation, with one increasing and the other decreasing, and the change amplitude must exceed a preset threshold to exclude noise interference from the true control command; that is, the two must necessarily satisfy the negative correlation constraint.

[0050] In one alternative implementation, a positive power threshold, a negative power threshold, a positive voltage threshold, and a negative voltage threshold can be preset, and physical consistency verification can be performed based on these four thresholds.

[0051] Optionally, if the total controlled power of a charging station transformer within a sampling period is greater than a preset positive power threshold (indicating a significant increase in the load of the charging station transformer within the sampling period), and the corresponding voltage response difference is less than a preset negative voltage threshold (indicating a significant drop in the bus voltage within the sampling period), then the sampling period is determined to have passed the physical consistency check.

[0052] Optionally, if the total controlled power of a charging station transformer within a sampling period is less than a preset negative power threshold (indicating that the load of the charging station transformer has decreased significantly within the sampling period), and the corresponding voltage response difference is greater than a preset positive voltage threshold (indicating that the bus voltage has increased significantly within the sampling period), then the sampling period is determined to have passed the physical consistency check.

[0053] Optionally, if the change in the sum of the controlled power and the voltage response does not satisfy the above negative correlation constraint, then the sampling period is determined to have failed the physical consistency check.

[0054] It should be understood that this threshold is preset based on the line impedance parameters of the distribution network, the load characteristics of the charging piles, and the noise level of the telemetry data, and is used to distinguish significant power changes and voltage fluctuations.

[0055] For example, taking a 10kV / 0.4kV, 200kVA charging station transformer as an example, the preset positive power threshold can be 8.5KW, the negative power threshold can be -8.5KW, the positive voltage threshold can be 1.3V, and the negative voltage threshold can be -1.3V.

[0056] After verifying all sampling periods, the sampling periods with the verification result of "passed physical consistency verification" are selected. All original control commands contained in these sampling periods are extracted and marked as verified control commands. All verified control commands are arranged in chronological order of control time and integrated to form a set of verified control commands.

[0057] Optionally, for sampling periods that fail the physical consistency check, the original control commands within that sampling period are marked as communication noise or spurious injections and discarded, thereby ensuring that subsequent steps only process behavioral data with physical authenticity.

[0058] It should be noted that the verified control instruction needs to retain the complete information of the original control instruction.

[0059] Understandably, this verified set of control commands only includes control commands that can trigger real physical responses, eliminating spurious commands at the communication level, thus providing a high-quality and highly reliable data source for subsequent spatiotemporal correlation analysis.

[0060] The method provided in S102 above, by precisely associating the original control commands with the charging station transformers, calculates the sum of the controlled power and the voltage response difference of the same charging station transformer within each sampling period, and performs physical consistency verification based on the negative correlation constraint between the two. This effectively eliminates false commands that exist only at the communication level and cannot trigger a real physical response. This approach establishes a direct correlation between commands and the physical response of the power grid, providing a high-quality and highly reliable data foundation for subsequent spatiotemporal correlation analysis. It reduces the interference of false data on attack identification results from the source and further improves the accuracy of attack detection.

[0061] S103. Based on the IP address and control time of each verified control instruction in the verified control instruction set, perform spatiotemporal correlation analysis on the verified control instruction set to identify the network segments covered by abnormal instructions.

[0062] The abnormal instruction covers multiple IP addresses within the network segment.

[0063] It should be understood that attacks using automated attack scripts are limited by single-threaded or controlled multi-threaded logic, which is very rigid and regular. Subsequent connections can only be initiated after the preceding nodes have been compromised. At the same time, attackers tend to scan logically adjacent network segments in order to circumvent firewalls. Therefore, there is a very strong sequential nature in both time and space.

[0064] Based on this feature, the timing and IP address of each charging station transformer can be used to determine the temporal and spatial order, and the network segments where IP addresses are connected and their timings are adjacent can be identified as abnormal instruction coverage network segments.

[0065] S104. Based on the abnormal instruction coverage network segment and network logical topology, identify at least one potential attack network segment.

[0066] Understandably, based on the network logical topology, the attacker's attack path is deduced to obtain the potential attack network segment. This potential attack network segment is used to characterize a network segment as the attacker's next possible target.

[0067] In one alternative implementation, the adjacent network segments of the network segment covered by the abnormal instruction are determined based on the network logical topology; and the adjacent network segments are identified as the at least one potential attack network segment.

[0068] It should be understood that since attacks using automated attack scripts have spatial regularity, the network segments adjacent to the network segment covered by the abnormal instruction are likely to be the next attack target. Therefore, all network segments adjacent to the network segment covered by the abnormal instruction can be identified as potential attack network segments.

[0069] Based on the description of the above embodiments, the adjacency relationship includes the continuity of IP address ranges and the affiliation and continuity of VLANs. Therefore, path deduction can be performed based on these three adjacency relationships to determine adjacent network segments.

[0070] Specifically, the method for determining adjacency based on the continuity of IP address ranges is as follows: extract the IP address range corresponding to the classless inter-domain routing (CIDR) address of the network segment covered by the abnormal instruction, and compare it with the IP address range of other network segments in the network logical topology. If the IP address ranges of the two network segments are seamlessly connected in binary values ​​(for example, the network segment covered by the abnormal instruction is 192.168.1.0 / 24, and the other network segment is 192.168.2.0 / 24), then it is determined that the two satisfy the continuity of IP address ranges, and the two network segments are determined to be adjacent.

[0071] The method for determining adjacency based on VLAN affiliation is as follows: query the VLAN identifier of the network segment covered by the abnormal command in the network logical topology (VLAN is used to divide network security boundaries, and network segments within the same VLAN usually have direct communication permissions). If other network segments have the same VLAN identifier as the network segment covered by the abnormal command, it is determined that the two meet the continuity of IP address range, and it is determined that other network segments are adjacent to this network segment.

[0072] The method for determining the continuity of VLAN IDs is as follows: extract the VLAN IDs (such as VLAN 10) of the network segment covered by the abnormal command, filter the network segments in the network logical topology whose VLAN IDs are continuous with the ID values ​​(such as the network segments corresponding to VLAN 9 and VLAN 11), determine that these network segments and the network segment covered by the abnormal command satisfy the VLAN ID continuity adjacency relationship, and determine that these network segments have an adjacency relationship.

[0073] Based on the method provided in S103 above, by making full use of the network logical topology, network segments that meet the adjacent relationship of continuous IP address range, identical VLAN representation, or continuous VLAN identifier with the network segment covered by the abnormal command are selected as potential attack network segments. This accurately predicts the attacker's next attack path, avoids blindly expanding the scope of protection, provides accurate protection targets for subsequent targeted access control, and improves the efficiency and targeting of protection.

[0074] S105. Implement access control for at least one potentially vulnerable network segment.

[0075] It should be understood that the purpose of access control over the at least one potentially attacked network segment is to prevent attackers from further attacking the potentially attacked network segment from the network segment covered by abnormal instructions. Therefore, the access control should at least be able to block communication from the network segment covered by abnormal instructions to the potentially attacked network segment.

[0076] In one alternative implementation, a lateral isolation policy can be generated; based on this lateral isolation policy, access control can be applied to at least one potentially vulnerable network segment.

[0077] The lateral isolation strategy is used to block traffic from the network segment covered by the abnormal command to the potentially attacked network segment.

[0078] It should be understood that this lateral isolation strategy should include source address, destination address, and action settings.

[0079] Specifically, the source address is the network segment covered by the abnormal instruction, the destination address is at least one potentially attacked network segment, and the action is "deny communication". That is, when traffic matching the above source and destination addresses is received, the traffic is directly discarded, without establishing a connection or forwarding it, thus cutting off the attack propagation link at the physical level.

[0080] Optionally, the lateral isolation strategy may also include a protocol type, which can be set to IP protocol, including all upper-layer network protocols such as TCP, UDP, and ICMP, to ensure comprehensive blocking of various attack traffic (such as TCP connection scanning, UDP probing, ICMP liveness detection, etc.) and prevent attackers from bypassing the protection through specific protocols.

[0081] Optionally, the lateral isolation policy can be distributed to network devices responsible for connecting the network segment covered by abnormal commands and the network segment potentially attacked, including key node devices such as aggregation layer gateways and subnet boundary firewalls, so that the network devices can execute the lateral isolation policy.

[0082] In another alternative implementation, a vertical keep-alive strategy can be generated on top of the horizontal isolation strategy; access control is then performed on the at least one potentially attacked network segment based on this vertical keep-alive strategy.

[0083] The vertical keep-alive strategy is used to allow traffic sent from the network segment covered by the abnormal instruction to the cloud platform scheduling server.

[0084] It should be understood that the goal of this vertical keep-alive strategy is to block attacks while allowing legitimate cloud scheduling traffic, ensuring that uninfected terminals can respond normally to power grid control commands.

[0085] Optionally, this vertical keep-alive strategy also includes source address, destination address, action settings, and protocol type. Specifically, the source address remains the network segment covered by the abnormal command; the destination address is a specific IP address or network segment of the cloud scheduling platform; the action setting is "allow communication"; and the protocol type is limited to the dedicated protocol for vehicle-to-everything (V2X) interactive services to prevent attackers from using the vertical keep-alive channel to initiate malicious communication and ensure that only legitimate business traffic is allowed.

[0086] Optionally, the vertical keep-alive strategy may also include ports, which are limited to dedicated ports for vehicle-to-everything (V2X) services (such as TCP ports 80 and 443 or preset private protocol ports).

[0087] Optionally, the priority of the vertical keep-alive strategy can be set higher than that of the horizontal isolation strategy. When the same traffic matches both strategies at the same time, the device will prioritize the "allow communication" action of the vertical keep-alive strategy to avoid the legitimate scheduled traffic being blocked by mistake.

[0088] It should be understood that by generating a lateral isolation strategy, directly blocking traffic transmission from the network segment covered by abnormal commands to the potentially attacked network segment, the spread path of the attack can be cut off at the network level. This approach specifically curbs the expansion of the attack scope, preventing the attack from spreading to more network segments and reducing the losses caused by the attack. Simultaneously, based on lateral isolation of attack traffic, a vertical keep-alive strategy is generated to allow legitimate traffic transmission from the network segment covered by abnormal commands to the cloud platform scheduling server, achieving a balance between security protection and business continuity. This solution ensures that the core cloud scheduling business of the vehicle-to-grid interaction system remains unaffected while effectively resisting the spread of attacks, ensuring that the system can still perform its power grid regulation function normally under security protection.

[0089] In this embodiment, the authenticity of the analyzed data is first ensured through physical consistency verification. Based on the initially screened authentic data, spatiotemporal correlation analysis is performed to accurately identify the network segments covered by abnormal instructions using spatiotemporal features. Then, by combining the adjacency relationships between network segments in the network logical topology, potential attack targets are deduced. Finally, access control is implemented, which can accurately identify attack behaviors, achieve precise protection against attack behaviors, ensure business continuity, and significantly improve the security and availability of the vehicle-to-everything (V2X) interactive system.

[0090] Combination Figure 1 ,like Figure 2 As shown, the above S103 can be specifically implemented through the following S201-S204.

[0091] S201. Based on the IP address and control time of each verified control instruction in the verified control instruction set, determine M independent operation chains.

[0092] Each independent operation chain includes at least two verified control instructions, where M is an integer greater than or equal to 1.

[0093] It should be understood that an independent operation chain is a sequence of continuous actions initiated by the same actor (such as an automated attack script or a cloud scheduling platform). The independent operation chain includes a set of control instructions with temporal continuity and spatial correlation.

[0094] In one optional implementation, the preset duration can be divided into multiple time windows based on a preset step size; the time difference between the control times of any two verified control instructions and the address span between IP addresses can be determined within each time window; the verified control instructions within each time window can be traversed, and a directed connection relationship can be established between two verified control instructions whose time difference is less than a time difference threshold and whose address span is less than an address span threshold; based on the directed connection relationship between multiple verified control instructions, multiple independent operation chains can be extracted.

[0095] Optionally, the preset step size can be set in conjunction with the single-step operation cycle of the automated attack script (usually hundreds of milliseconds to several minutes) to ensure that each time window can fully capture the continuous actions of a short-cycle attack, while avoiding the inclusion of a large number of unrelated legitimate scheduling instructions due to excessively long windows.

[0096] For example, the preset step size can be 5 minutes.

[0097] It should be understood that a time window is an observation window for an attack step, and subsequent control command analysis is carried out independently within a single time window to ensure that the analysis scope is focused and to improve the accuracy and efficiency of correlation analysis.

[0098] It is understandable that, for any two verified control commands within each time window (e.g., verified control command 1 and verified control command 2), the time difference between their control times is used to characterize the execution interval of the two verified control commands, reflecting whether they may be launched consecutively by the same automated attack script.

[0099] It should be noted that the timing of this adjustment should be accurate to the millisecond level to improve the accuracy of independent operation chain analysis.

[0100] It should be understood that this address span is used to characterize the degree of logical adjacency between two IP addresses in the network, reflecting whether they belong to the address range that attackers prioritize scanning.

[0101] Optionally, the IP addresses of the two instructions can be converted into 32-bit integers, and the absolute value of the two integer values ​​can be used to determine the address span between them.

[0102] Understandably, if the time difference between the control times of two verified control commands is less than a time difference threshold, it indicates that the time difference is within a preset reasonable range of continuity, suggesting that the two verified control commands may have been issued consecutively. Similarly, if the address span between the IP addresses of two verified control commands is less than an address span threshold, it indicates that the IP addresses corresponding to the two verified control commands are logically adjacent in the network, belonging to the same or adjacent subnets, consistent with the scanning behavior characteristics of an attacker moving laterally. Therefore, it can be determined that two verified control commands with a time difference less than the time difference threshold and an address span less than the address span threshold are targets of consecutive attacks by the same automated attack script, and a directed connection can be established between them.

[0103] It should be understood that the time difference threshold needs to be determined by combining the single-step operation time of the automated attack script (such as the total time for establishing a connection, sending a command, and receiving a response) with network transmission latency to ensure that only commands launched consecutively within a short period of time are identified as potentially associated commands. The address span threshold needs to be determined based on the IP address planning scheme of the vehicle-to-everything (V2X) system (such as the subnetting granularity), and is usually matched with the address range corresponding to the subnet mask to ensure that only IP addresses within the same subnet or adjacent subnets are identified as potentially associated addresses.

[0104] For example, the time difference threshold can be set to 200 milliseconds to 2000 milliseconds, and the address span threshold can be set to 256.

[0105] It should be understood that the direction in a directed connection represents the timing order of instruction execution, with the direction pointing from the instruction executed first to the instruction executed later.

[0106] Optionally, a connected chain can be extracted based on the directed connection relationship between multiple verified control commands.

[0107] Optionally, connected chains with a number of verified control instructions less than the minimum number of instructions can be filtered out, and connected chains with a number of verified control instructions greater than or equal to the minimum number of instructions can be identified as independent operation chains.

[0108] It should be understood that this minimum number of instructions is used to exclude spurious associations formed by two unrelated verified control instructions that happen to satisfy the constraints. This ensures that each independent operation chain contains a sufficient number of associated instructions, which is of statistical significance.

[0109] For example, the minimum number of instructions can be 3.

[0110] In one alternative implementation, a spatiotemporal correlation graph can be constructed based on the directed connection relationships between multiple verified control commands; weakly connected subgraphs can be extracted from the spatiotemporal correlation graph and identified as independent operation chains.

[0111] It should be understood that a spatiotemporal correlation graph is a graphical data structure used to intuitively present the spatiotemporal correlation between verified control commands. Its core components include nodes and directed edges, where: nodes correspond to verified control commands, and each node stores the core information of the command (IP address and control time); directed edges correspond to directed connections that satisfy the constraints of time difference threshold and address span threshold.

[0112] It is understandable that a time window corresponds to a spatiotemporal relationship graph.

[0113] It is understandable that a weakly connected subgraph refers to a subgraph in a spatiotemporal relational graph in which, without considering the direction of directed edges, there exists at least one path (composed of one or more edges) connecting any two nodes.

[0114] Alternatively, weakly connected component extraction algorithms in graph theory (such as depth-first search and breadth-first search) can be used to traverse and analyze the spatiotemporal relational graph to extract all non-overlapping weakly connected subgraphs.

[0115] Alternatively, for each extracted weakly connected subgraph, the number of nodes it contains may be checked to see if it meets the minimum number of instructions, and only weakly connected subgraphs with the required number of nodes may be retained as independent operation chains.

[0116] Based on the method provided in S201 above, by dividing the time window with a preset step size, focusing on instructions within a specific time range, and then using the dual constraints of time difference and address span to filter out potentially related instruction pairs and establish directed connections, it is possible to efficiently extract independent operation chains with temporal continuity and spatial correlation. Furthermore, by transforming the directed connection relationship into a spatiotemporal correlation graph, and then extracting weakly connected subgraphs as independent operation chains, the spatiotemporal correlation between instructions can be presented intuitively and clearly. This approach considers both the temporal characteristics of attack behavior and the spatial characteristics of attackers tending to scan adjacent IP addresses, ensuring that independent operation chains accurately reflect potential attack action sequences, avoiding the mixing of irrelevant instructions, and improving the efficiency and accuracy of subsequent correlation analysis.

[0117] S202. Based on the IP address and control time of each verified control instruction in each independent operation chain, determine the spatiotemporal ordering correlation coefficient of each independent operation chain.

[0118] It should be understood that the spatiotemporal ordering correlation coefficient is used to characterize the strength of the correlation between the temporal execution order of verified control instructions and the IP address distribution order within the same independent operation chain.

[0119] Understandably, the sequential operations of automated attack scripts exhibit a strong correlation between "chronological order" and "IP address distribution order," while legitimate scheduling instructions are affected by factors such as routing jitter and load balancing, and their chronological order has no fixed correlation with IP address distribution order. Therefore, by constructing a sorted sequence of time and address and calculating the strength of the correlation between the two, this difference can be quantified.

[0120] In one optional implementation, a time-sorted index sequence and an address-sorted index sequence of the first independent operation chain can be generated based on the IP address and control time of each verified control instruction in the first independent operation chain; and the spatiotemporal sorting correlation coefficient of the first independent operation chain can be determined based on the sequence number of each verified control instruction in the time-sorted index sequence and the address-sorted index sequence, respectively.

[0121] The first independent operation chain can be any one of multiple independent operation chains.

[0122] It should be understood that the time-sorted index sequence is a sequence of verified control instructions ordered from earliest to latest according to the control time. Each verified control instruction in this sequence is assigned a unique time ranking number. The address-sorted index sequence is a sequence of verified control instructions ordered from smallest to largest according to the integer values ​​corresponding to the IP addresses. Each verified control instruction in this sequence is assigned a unique address ranking number.

[0123] Optionally, based on the sequence number of each verified control instruction in the time sorting index sequence and the address sorting index sequence, the difference between the time ranking sequence number and the address ranking sequence number of each verified control instruction (i.e., the sequence number deviation) is calculated, and the spatiotemporal sorting correlation coefficient is determined based on the sequence number deviation.

[0124] It should be understood that the sequence number deviation is used to characterize the degree of matching between the temporal execution order and the spatial distribution order of a single verified control instruction. The smaller the sequence number deviation, the more the execution time order of the verified control instruction matches the IP address distribution order; the larger the sequence number deviation, the lower the degree of matching between the two.

[0125] Optionally, the spatiotemporal ordering correlation coefficient of the first independent operation chain can be obtained by combining the sum of squares of these index deviations using the Spearman rank correlation coefficient algorithm.

[0126] It should be noted that the core logic of the Spearman rank correlation coefficient algorithm is that it does not rely on the absolute values ​​of variables, but only quantifies the overall correlation strength between two sequences through the deviation of their sorted indices. This effectively avoids the impact of nonlinear interference such as WAN routing jitter and instruction transmission delay fluctuations on the analysis results. If the indices of most instructions have small deviations, it indicates that the time sorting and address sorting are generally consistent, and the absolute value of the correlation coefficient is large. If the indices are scattered and large, it indicates that the two sortings have no fixed correlation, and the absolute value of the correlation coefficient is small.

[0127] Optionally, the spatiotemporal ordering correlation coefficient of an independent operation chain satisfies the following formula: in, Indicates an independent operation chain The spatiotemporal ordering correlation coefficient, Indicates an independent operation chain The total number of nodes containing verified control commands. Indicates an independent operation chain The first in The sequence number of each node in the time-sorted index sequence. This indicates an independent operation chain. The first in The index number of each node in the address sorting index sequence.

[0128] In this formula, Indicates the first The index deviation of each node; the constant 6 in the numerator is an inherent coefficient of the Spearman correlation coefficient formula, used for standardization in theoretical derivation. This indicates the overall degree of inconsistency among the sequence number deviations of all nodes in the entire independent operation chain; This indicates that when two sorting sequences are completely different (i.e., one sequence is the complete inversion of the other), The theoretical maximum value that can be achieved; therefore, This represents the proportion of inconsistency to the total possible inconsistency, and is the degree of inconsistency observed in the population. Its value ranges from [0, 2]. (1 minus...) This achieves the transformation from an "inconsistency measure" to a "consistency measure". The value range is [-1, 1].

[0129] It should be understood that the sign of the spatiotemporal ordering correlation coefficient only reflects the direction of the correlation between the time-ordered index sequence and the address-time-ordered index sequence; the absolute value reflects the strength of the correlation. When the spatiotemporal ordering correlation coefficient is positive, it indicates that the execution order of instructions within the independent operation chain is positively correlated with the distribution order of IP addresses; when the spatiotemporal ordering correlation coefficient is negative, it indicates that the two are negatively correlated.

[0130] The method provided in S202 above transforms the control time and IP address characteristics of instructions into quantifiable sorting indicators by generating time-sorted index sequences and address-sorted index sequences. It then calculates the spatiotemporal sorting correlation coefficient based on the sequence number deviation, achieving precise quantification of the spatiotemporal correlation of instructions. This approach avoids interference from absolute time and IP address values, focusing on relative sorting relationships. It can reliably capture the ordered operation characteristics of automated attack scripts, providing an objective and reliable quantitative basis for judging attack behavior.

[0131] S203. Based on the spatiotemporal ordering correlation coefficient of each independent operation chain, determine the abnormal independent operation chain.

[0132] It should be understood that the larger the absolute value of the spatiotemporal order correlation coefficient, the stronger the correlation between the time execution order of verified control instructions and the IP address distribution order within the same independent operation chain. The spatiotemporal distribution of verified control instructions exhibits significant orderliness, perfectly matching the behavior characteristics of automated attack scripts operating continuously according to preset logic. Conversely, the smaller the spatiotemporal order correlation coefficient, the weaker the correlation between the time execution order of verified control instructions and the IP address distribution order within the independent operation chain. The spatiotemporal distribution of verified control instructions exhibits obvious randomness, consistent with the characteristics of legitimate cloud scheduling being affected by factors such as routing jitter and load distribution.

[0133] In one alternative implementation, the first independent operation chain is identified as an abnormal independent operation chain if the absolute value of the spatiotemporal ordering correlation coefficient of the first independent operation chain is greater than the correlation coefficient threshold.

[0134] It is understandable that if the absolute value of the spatiotemporal ordering correlation coefficient of the first independent operation chain is greater than the correlation coefficient threshold, it indicates that the correlation strength has significantly exceeded the normal range of legitimate scheduling. Its ordered characteristics are highly consistent with the programmatic execution logic of the automated attack script. Therefore, the first independent operation chain can be identified as an abnormal independent operation chain.

[0135] For example, the correlation coefficient threshold can be set to 0.7.

[0136] The method provided in S203 above, by using a preset correlation coefficient threshold as the criterion for judging abnormal independent operation chains, can quickly and clearly identify attack behaviors and avoid the uncertainty caused by subjective judgment.

[0137] S204. Determine the network segment to which the IP address included in the abnormal independent operation chain belongs as the network segment covered by the abnormal instruction.

[0138] Specifically, the IP addresses included in the verified control instructions are extracted from the abnormal independent operation chain. Then, the network segment to which each IP address belongs is determined. Then, the network segment to which each IP address belongs is deduplicated. All the deduplicated network segments are integrated to form the abnormal instruction coverage network segment.

[0139] Combining the methods provided in S201-S204 above, by extracting independent operation chains from the set of verified control commands, focusing the scattered verified control commands into a set of related actions, and then quantifying the spatiotemporal correlation of the commands by calculating the spatiotemporal order correlation coefficient, it is possible to accurately identify abnormal independent operation chains with attack characteristics, and thus lock the network segment covered by abnormal commands.

[0140] like Figure 3 As shown in the figure, this application embodiment also provides a vehicle-to-network (V2N) attack path deduction device based on system topology diagram. The V2N attack path deduction device 30 based on system topology diagram includes a data acquisition module 301, an analysis module 302, and a control module 303.

[0141] The data acquisition module 301 is used to acquire the original control instruction set, charging station transformer telemetry records, and network logical topology within a preset time period.

[0142] The original control instruction set includes multiple original control instructions. Each original control instruction includes an Internet Protocol IP address, control time, and power control amount. The charging station transformer telemetry record is used to record the bus voltage value of the charging station transformer in one sampling cycle.

[0143] Analysis module 302 is used to perform physical consistency verification of the original control instruction set and the telemetry records of the charging station transformer based on the power control amount included in each original control instruction and the bus voltage value of each sampling period, so as to obtain the verified control instruction set.

[0144] The set of verified control commands includes verified control commands that can trigger real physical responses.

[0145] The analysis module 302 is also used to perform spatiotemporal correlation analysis on the verified control instruction set based on the IP address and control time of each verified control instruction in the verified control instruction set, and to identify the network segments covered by abnormal instructions.

[0146] The abnormal instruction covers multiple IP addresses within the network segment.

[0147] The analysis module 302 is also used to identify at least one potential attack network segment based on the abnormal instruction coverage network segment and network logical topology.

[0148] The control module 303 is used to perform access control on the at least one potentially attacked network segment.

[0149] It should be noted that the vehicle-to-network interaction attack path deduction device 30 based on system topology diagram provided in this application embodiment can also implement any of the above-mentioned optional vehicle-to-network interaction attack path deduction methods based on system topology diagram.

[0150] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0151] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.

Claims

1. A method for inferring attack paths in a vehicle-to-network (V2N) interaction network based on a system topology diagram, characterized in that, include: The system acquires the original control instruction set, charging station transformer telemetry records, and network logical topology within a preset time period. The original control instruction set includes multiple original control instructions, and each original control instruction includes an Internet Protocol IP address, control time, and power control amount. The charging station transformer telemetry records are used to record the bus voltage value of the charging station transformer in one sampling period. Based on the power regulation amount included in each original control instruction and the bus voltage value in each sampling period, the physical consistency verification of the original control instruction set and the telemetry record of the charging station transformer with negative correlation constraints is performed to obtain the verified control instruction set. The verified control instruction set includes verified control instructions that can trigger real physical responses. Based on the IP address and control time of each verified control instruction in the verified control instruction set, a spatiotemporal correlation analysis is performed on the verified control instruction set to identify abnormal instruction coverage network segments, which include multiple IP addresses. Based on the network segments covered by abnormal commands and the network logical topology, at least one potential attack network segment is identified. Access control shall be implemented for the at least one potentially attacked network segment.

2. The method for inferring attack paths in a vehicle-to-network interaction system based on a system topology diagram as described in claim 1, characterized in that, The step of performing spatiotemporal correlation analysis on the verified control instruction set based on the IP address and control time of each control instruction in the verified control instruction set to identify network segments covered by abnormal instructions includes: Based on the IP address and control time of each verified control instruction in the verified control instruction set, M independent operation chains are determined. Each independent operation chain includes at least two verified control instructions, and M is an integer greater than or equal to 1. Based on the IP address and control time of each verified control instruction in each independent operation chain, determine the spatiotemporal ordering correlation coefficient of each independent operation chain; Based on the spatiotemporal ordering correlation coefficient of each independent operation chain, abnormal independent operation chains are identified; The network segment to which the IP address belongs in the abnormal independent operation chain is determined as the network segment covered by the abnormal instruction.

3. The method for inferring attack paths in a vehicle-to-network interaction system based on a system topology diagram according to claim 2, characterized in that, The process involves determining multiple independent operation chains based on the IP address and control time of each verified control instruction in the verified control instruction set, including: The preset duration is divided into multiple time windows based on the preset step size; Determine the time difference between the control times of any two verified control commands within each time window and the address span between IP addresses; Iterate through the verified control instructions within each time window and establish a directed connection between two verified control instructions whose time difference is less than the time difference threshold and whose address span is less than the address span threshold. Based on the directed connection relationship between multiple verified control commands, multiple independent operation chains are extracted.

4. The method for inferring attack paths in a vehicle-to-network interaction system based on a system topology diagram according to claim 3, characterized in that, The extraction of multiple independent operation chains based on the directed connection relationships between multiple verified control commands includes: Based on the directed connection relationships between multiple verified control commands, a spatiotemporal correlation graph is constructed; Weakly connected subgraphs are extracted from the spatiotemporal correlation graph, and the weakly connected subgraphs are identified as independent operation chains.

5. The method for inferring vehicle-to-network (V2N) attack paths based on system topology diagrams according to claim 2, characterized in that, The determination of the spatiotemporal ordering correlation coefficient for each independent operation chain, based on the IP address and control time of each verified control instruction in each independent operation chain, includes: Based on the IP address and control time of each verified control instruction in the first independent operation chain, a time-sorted index sequence and an address-sorted index sequence of the first independent operation chain are generated. The first independent operation chain is any one of multiple independent operation chains. Based on the sequence number of each verified control instruction in the time-sorted index sequence and the address-sorted index sequence, the spatiotemporal sorting correlation coefficient of the first independent operation chain is determined.

6. The method for inferring attack paths in a vehicle-to-network interaction system based on a system topology diagram according to claim 2, characterized in that, The determination of anomalous independent operation chains based on the spatiotemporal ordering correlation coefficient of each independent operation chain includes: If the absolute value of the spatiotemporal ordering correlation coefficient of the first independent operation chain is greater than the correlation coefficient threshold, the first independent operation chain is identified as an anomalous independent operation chain.

7. The method for inferring attack paths in a vehicle-to-network interaction system based on a system topology diagram according to claim 1, characterized in that, The method of identifying at least one potential attack network segment based on the abnormal instruction coverage network segment and network logical topology includes: Based on the network logical topology, determine the adjacent network segments of the network segment covered by the abnormal instruction; The adjacent network segments are identified as at least one potential attack network segment.

8. The method for inferring attack paths in a vehicle-to-network interaction system based on a system topology diagram according to claim 1, characterized in that, The access control for the at least one potentially attacked network segment includes: Generate a lateral isolation policy, which is used to block traffic from the network segment covered by the abnormal command to the potential attack network segment; Based on the aforementioned lateral isolation strategy, access control is applied to at least one potentially vulnerable network segment.

9. The method for inferring attack paths in a vehicle-to-network interaction system based on a system topology diagram according to claim 8, characterized in that, The access control for the at least one potentially attacked network segment further includes: Generate a vertical keep-alive policy, which allows traffic to be sent from the network segment covered by the abnormal instruction to the cloud platform scheduling server; Access control is performed on the at least one potential attack network segment based on the vertical keep-alive strategy.

10. A device for predicting attack paths in a vehicle-to-network (V2N) interactive network based on a system topology diagram, characterized in that, It includes a data acquisition module, an analysis module, and a control module; The data acquisition module is used to acquire the original control instruction set, charging station transformer telemetry records and network logical topology within a preset time period. The original control instruction set includes multiple original control instructions. Each original control instruction includes an Internet Protocol IP address, control time and power control amount. The charging station transformer telemetry records are used to record the bus voltage value of the charging station transformer in one sampling period. The analysis module is used to perform a physical consistency check on the original control instruction set and the charging station transformer telemetry record based on the power control amount included in each original control instruction and the bus voltage value of each sampling period, and to obtain a verified control instruction set. The verified control instruction set includes verified control instructions that can trigger real physical responses. The analysis module is also used to perform spatiotemporal correlation analysis on the verified control instruction set based on the IP address and control time of each verified control instruction in the verified control instruction set, and to identify abnormal instruction coverage network segments, wherein the abnormal instruction coverage network segments include multiple IP addresses. The analysis module is also used to identify at least one potential attack network segment based on the abnormal instruction coverage network segment and network logical topology. The control module is used to perform access control on the at least one potential attack network segment.