Test method, device, processor and electronic device for detection system in vehicle
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- FAW JIEFANG AUTOMOTIVE CO
- Filing Date
- 2026-05-13
- Publication Date
- 2026-08-07
AI Technical Summary
[0004]本申请实施例提供了一种车辆中检测系统的测试方法、装置、处理器和电子设备,以至少解决对车辆中检测系统进行测试的效率低的技术问题
[0019]根据本申请实施例的另一方面,还提供了一种车辆。该车辆包括存储器和处理器。其中,存储器,存储有可执行程序;处理器,用于运行程序,程序运行时实现本申请实施例的上述方法。
Smart Images

Figure CN122533804A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle testing technology, and more specifically, to a testing method, apparatus, processor, and electronic equipment for a vehicle detection system. Background Technology
[0002] Currently, testing of vehicle detection systems (such as in-vehicle bus intrusion detection systems) largely relies on real-vehicle road tests or simplified simulation environments. This makes it difficult to fully simulate the complex communication scenarios and real navigation and positioning conditions of a vehicle under controlled and safe laboratory conditions. This results in incomplete test coverage, limited attack scenarios, and an inability to verify end-to-end response loops, thus hindering effective verification of the detection system. Therefore, the technical problem of low efficiency in testing vehicle detection systems remains.
[0003] There is currently no effective solution to the aforementioned technical problems. Summary of the Invention
[0004] This application provides a testing method, apparatus, processor, and electronic device for a vehicle detection system, to at least solve the technical problem of low efficiency in testing vehicle detection systems.
[0005] According to one aspect of the embodiments of this application, a testing method for a detection system in a vehicle is provided. The method may include: in response to the detection system being in a working state, constructing a simulation environment for vehicle operation based on vehicle simulation environment data, wherein the simulation environment data is used to simulate the dynamic operating information of the vehicle during operation; injecting multiple types of abnormal attack messages into the simulation environment, wherein different types of abnormal attack messages are used to simulate different attack behaviors of the vehicle in a real in-vehicle network environment; identifying attack status messages containing attack event information from the multiple types of abnormal attack messages, and comparing the attack status messages with target attack status messages to obtain a comparison result, wherein the target attack status message is used to characterize the abnormal attack message corresponding to the original attack event, and the abnormal attack message is recorded by hardware devices in the simulation environment; and testing the detection system based on the comparison result to obtain a test result, wherein the test result is used to indicate the effectiveness of the detection system in identifying attack events in a communication link.
[0006] Optionally, from various types of abnormal attack messages, an attack status message containing attack event information is identified, including: identifying the abnormal attack message and obtaining an identification result, wherein the identification result is used to indicate whether the abnormal attack message conforms to a preset attack behavior; based on the identification result, associating the message status of the abnormal attack message with the location information carried in the attack status message to obtain the attack status message.
[0007] Optionally, the method further includes: converting the attack status message to obtain a wireless radio frequency signal; and using a wireless communication strategy to transmit the wireless radio frequency signal to the cloud.
[0008] Optionally, the attack status message is compared with the target attack status message to obtain a comparison result, including: determining the message anomaly type of the attack status message, where the message anomaly type includes at least one of the following: anomaly type related to message identifier, anomaly type related to message length, anomaly type related to message period, anomaly type related to message value, and anomaly type related to bus load rate; comparing the message anomaly type of the attack status message with the message anomaly type field of the target attack status message to obtain a first comparison result; comparing the location information carried in the attack status message with the location information field of the target attack status message to obtain a second comparison result; and determining the comparison result based on the first comparison result and the second comparison result.
[0009] Optionally, based on the first comparison result and the second comparison result, the comparison result is determined, including: in response to the first comparison result being that the message anomaly type of the attack state message is the same as the message anomaly type field of the target attack state message, and the second comparison result being that the location information carried in the attack state message is consistent with the location information field of the target attack state message within the target range, the comparison result is determined to be that the attack state message and the target attack state message match in the attack feature identification dimension and the location information association dimension.
[0010] Optionally, based on the comparison results, the detection system is tested to obtain test results, including: in response to the comparison result that the attack status message and the target attack status message match in the attack feature identification dimension and the location information association dimension, the test result is determined to be that the effectiveness of the detection system in identifying attack events in the communication link is higher than the effectiveness threshold; in response to the comparison result that the attack status message and the target attack status message do not match in either the attack feature identification dimension or the location information association dimension, the test result is determined to be that the effectiveness of identifying attack events is lower than the effectiveness threshold.
[0011] Optionally, the method further includes: transmitting the attack status message to the vehicle's onboard terminal; and / or, the simulation environment data includes the vehicle's bus data, positioning data, and control signals of the operating status, and the method further includes: recording and / or displaying the simulation environment data in the onboard terminal.
[0012] According to another aspect of the embodiments of this application, a testing apparatus for a detection system in a vehicle is also provided. The apparatus may include: a construction unit, configured to construct a simulation environment for vehicle operation based on vehicle simulation environment data in response to the detection system being in a working state, wherein the simulation environment data is used to simulate the dynamic operating information of the vehicle during operation; an injection unit, configured to inject various types of abnormal attack messages into the simulation environment, wherein different types of abnormal attack messages are used to simulate different attack behaviors of the vehicle in a real in-vehicle network environment; a comparison unit, configured to identify attack status messages containing attack event information from the various types of abnormal attack messages, and to compare the attack status messages with target attack status messages to obtain a comparison result, wherein the target attack status message is used to characterize the abnormal attack message corresponding to the original attack event, and the abnormal attack message is recorded by hardware devices in the simulation environment; and a testing unit, configured to test the detection system based on the comparison result to obtain a test result, wherein the test result is used to indicate the effectiveness of the detection system in identifying attack events in the communication link.
[0013] According to another aspect of the embodiments of this application, a processor is also provided. The processor is used to run a program, wherein the program is executed by the processor to perform the methods described in the embodiments of this application.
[0014] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods in various embodiments of this application when it runs.
[0015] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of this application.
[0016] According to another aspect of the embodiments of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the methods of various embodiments of this application.
[0017] According to another aspect of the embodiments of this application, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the methods in various embodiments of this application.
[0018] According to another aspect of the embodiments of this application, a computer program is also provided, which, when executed by a processor, implements the methods of the various embodiments of this application.
[0019] According to another aspect of the embodiments of this application, a vehicle is also provided. The vehicle includes a memory and a processor. The memory stores an executable program; the processor is used to run the program, which, when running, implements the methods described in the embodiments of this application.
[0020] In this embodiment, when the detection system is operational, a simulation environment for vehicle operation is constructed based on vehicle simulation environment data. Since the simulation environment data can simulate the dynamic operating information of the vehicle during operation, it overcomes the limitations of related technologies that rely on real-vehicle road tests or static message playback. Subsequently, various types of abnormal attack messages can be injected into the simulation environment. From these messages, attack status messages containing attack event information are identified, and then compared with target attack status messages to obtain comparison results. Based on the comparison results, the detection system is tested to obtain test results, ensuring the scientific rigor and security of the testing. This solves the technical problem of low efficiency in testing vehicle detection systems and achieves the technical effect of improving the efficiency of testing vehicle detection systems. Attached Figure Description
[0021] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0022] Figure 1 This is a flowchart of a test method for a vehicle detection system according to an embodiment of this application;
[0023] Figure 2 This is a schematic diagram of a vehicle information security testing system for functional testing of an in-vehicle bus intrusion detection system according to an embodiment of this application;
[0024] Figure 3 This is a flowchart of a test method for an in-vehicle bus intrusion detection system according to an embodiment of this application;
[0025] Figure 4 This is a flowchart of a method for displaying wireless radio frequency signals according to an embodiment of this application;
[0026] Figure 5 This is a schematic diagram of a test apparatus for a vehicle detection system according to an embodiment of this application;
[0027] Figure 6 This is a structural diagram of an electronic device provided in an embodiment of this application. Detailed Implementation
[0028] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0029] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, functional component, or device that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, functional components, or devices.
[0030] According to an embodiment of this application, an embodiment of a test method for a detection system in a vehicle is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0031] Figure 1 This is a flowchart of a test method for a vehicle detection system according to an embodiment of this application, such as... Figure 1 As shown, the method may include the following steps.
[0032] Step S102: In response to the detection system being in working state, a simulation environment for vehicle operation is constructed based on the vehicle's simulation environment data.
[0033] In the technical solution provided by step S102 of this application, the simulation environment data can be used to simulate the dynamic operation information of the vehicle during operation.
[0034] In this embodiment, the detection system can be an in-vehicle bus intrusion detection system. If the detection system is in working condition, that is, the in-vehicle bus intrusion detection system has been powered on and initialized, a simulation environment of vehicle operation can be constructed based on the vehicle's simulation environment data, providing a basis for the subsequent testing process and avoiding misjudgments due to the detection system not being ready.
[0035] Optionally, the vehicle bus intrusion detection system has been powered on and initialized. For example, the hardware module of the vehicle bus intrusion detection system has communication capability, which means that it can receive Controller Area Network (CAN) messages, process attack events and output alarm information.
[0036] Optionally, the aforementioned hardware modules may be an intrusion detection processing unit, a vehicle-mounted remote communication unit (TelematicsBox, or T-BOX for short), or a vehicle-mounted user interface (UI for short).
[0037] Optionally, the simulation environment data mentioned above can be a set of real-time signals with clear technical meanings generated collaboratively by multiple physical devices. For example, the simulation environment data may include vehicle dynamic positioning data, hard-wired switch signals, and virtual vehicle status signals; this is merely an example and no specific limitations are imposed here.
[0038] Optionally, the aforementioned vehicle dynamic positioning data can be output by a Global Navigation Satellite System (GNSS) simulator to simulate the spatial displacement of the vehicle on real roads. The aforementioned hard-wired switch signals can be simulated and generated by an input / output (I / O) board, which can be used to trigger the detection system to perceive the context of the vehicle's operating status. The aforementioned virtual vehicle status signals can be virtually generated by a real-time processor through a bus interface card to construct a complete vehicle operating context, enabling the detection system to determine whether an attack is threatening based on real-world conditions.
[0039] Optionally, the simulation environment data mentioned above is not a static configuration file, but can be dynamically generated in real time by each physical device according to a predetermined strategy through unified scheduling by a host computer. For example, the GNSS simulator receives a preset driving trajectory file and outputs continuously changing positioning data at a millisecond frequency. I / O boards output switch transitions according to the test case sequence. The real-time processor periodically sends virtual messages conforming to the vehicle communication protocol according to instructions, forming a communication environment highly consistent with the real vehicle.
[0040] Optionally, the construction of the above simulation environment can rely on a highly integrated test platform. For example, the power management unit provides a stable power supply to the controller under test to ensure normal startup. The electromagnetic shielding box encloses the vehicle-mounted remote communication unit (T-BOX), effectively shielding it from external real satellite signals and wireless interference, ensuring that the positioning data of the GNSS simulator is the only source. The bus interface card, as the access node of the CAN network, serves as both an injection channel for attack messages and an entry point for communication data acquisition. The real-time processor acts as the core coordinator, synchronously controlling each device to ensure that positioning data, switch signals, and CAN messages are strictly aligned on the timeline, achieving precise synchronization of the multi-dimensional environment.
[0041] In this embodiment of the application, the above steps can be used to reproduce the complete communication and operating state that the vehicle may encounter during driving in a closed environment that isolates the real vehicle from external interference, providing a reliable background noise and context baseline for subsequent injection attacks.
[0042] Step S104: Inject various types of abnormal attack messages into the simulation environment.
[0043] In the technical solution provided in step S104 of this application, different types of abnormal attack messages can be used to simulate different attack behaviors of vehicles in a real vehicle network environment.
[0044] In this embodiment, the abnormal attack message can be an abnormal attack message for the vehicle bus.
[0045] Optionally, injecting various types of abnormal attack messages into the simulation environment is a precise, controllable, and reproducible way to simulate typical attack behaviors that hackers may carry out in real vehicle communication networks, thereby comprehensively verifying the vehicle bus intrusion detection system's identification capabilities and response accuracy in the face of diverse threats.
[0046] Optionally, abnormal attack messages refer to CAN messages that are artificially constructed and injected with specific malicious characteristics, outside of the normal automotive CAN bus communication protocol specifications. These CAN messages are not random errors, but are derived from the analysis and summarization of real attack cases.
[0047] Optionally, the injection of abnormal attack messages can be centrally controlled by a real-time processor, directly connected to the CAN bus via a bus interface card as the physical channel. The real-time processor can inject abnormal attack messages one by one into the CAN bus according to a preset test case script, following a precise time sequence, message format, and transmission frequency. The injection process is synchronized with other dynamic signals in the simulation environment (e.g., vehicle speed changes, ignition state switching, GNSS positioning movement). For example, under the simulated condition of "vehicle speed of 80km / h and normal engine temperature," an abnormal vehicle speed message with a period of 5ms, an identifier (ID) of 0x18F, and data of 0xFF can be injected to simulate an attacker attempting to tamper with vehicle speed information to mislead the autonomous driving system. Alternatively, when the vehicle is in the "ignition on, doors closed" state, a frequent door state flip message can be injected to test whether the detection system can identify this behavior as a continuous interference attack rather than genuine signal jitter.
[0048] In this embodiment of the application, through the above steps, the injection process of injecting various types of abnormal attack messages into the simulation environment no longer relies on manual intervention, but is automatically controlled by the host computer, ensuring that the type, time, and parameters of each abnormal attack message can be tracked and reproduced.
[0049] Step S106: Identify attack status messages containing attack event information from various types of abnormal attack messages, and compare the attack status messages with the target attack status messages to obtain the comparison results.
[0050] In the technical solution provided in step S106 of this application, the target attack status message can be used to characterize the abnormal attack message corresponding to the original attack event. The abnormal attack message is recorded by the hardware device in the simulation environment.
[0051] In this embodiment, by comparing objective and quantifiable data, it can be determined whether the vehicle bus intrusion detection system accurately, completely, and timely identifies and reports attack events in a real communication environment, thereby verifying the effectiveness and reliability of the vehicle bus intrusion detection system.
[0052] Optionally, when an abnormal attack message injected into the simulation environment arrives at the processing unit of the detection system via the CAN bus, the detection system can analyze each abnormal attack message according to its built-in detection rules (such as message ID whitelist verification, periodic anomaly detection, data validity judgment, etc.). If an abnormal attack message matches the preset attack characteristics (for example, detecting an unauthorized message with ID 0x999, or an illegal value of -150km / h), the detection system will initiate a response process, encapsulating the type, time, location, and specific message characteristics of the abnormal attack message into a structured attack status message according to the format defined by the communication matrix.
[0053] Optionally, the aforementioned attack status message can be sent to two key outputs via the CAN bus. The first is the vehicle-mounted UI display interface, used to locally prompt the user. The second is the vehicle-mounted remote communication unit (T-BOX), used to encapsulate the attack event along with current GNSS positioning data (e.g., longitude, latitude, altitude, speed, and time), upload it to the cloud (e.g., a cloud server) via the cellular network, and finally present it visually on the intrusion detection client platform.
[0054] Optionally, the aforementioned target attack status messages are not generated by the detection system, nor are they artificially set ideal values. Instead, they are raw attack message data collected, recorded, and stored in real time by hardware devices (real-time processors and bus interface cards) in the simulation environment during the attack injection process. These target attack status messages are independent of the detection system, do not participate in the judgment, and serve as the factual benchmark for the attack event.
[0055] Optionally, the above comparison process can be automated by the testing platform. The attack event information displayed on the intrusion detection client platform and the vehicle-mounted UI, such as "An abnormal message with ID 0x999 detected, located at 39.9°N, 116.4°E, speed 62.3km / h, time 14:25:03.456," can be compared field-by-field with the corresponding original record in the target attack status message to obtain the comparison results.
[0056] In this embodiment of the application, the above steps realize the process from attack injection (input) → detection system identification and encapsulation (processing) → local display and remote reporting (output) → cloud display (result presentation) to determine whether the whole process is accurate.
[0057] Step S108: Based on the comparison results, the detection system is tested to obtain the test results.
[0058] In the technical solution provided by step S108 of this application, the test results can be used to indicate the effectiveness of the detection system in identifying attack events in the communication link.
[0059] In this embodiment, based on the comparison results, a systematic and quantitative comprehensive evaluation of the vehicle bus intrusion detection system's perception, response, and reporting capabilities throughout the entire communication link is conducted, thereby obtaining the effectiveness of the detection system in identifying attack events within the communication link.
[0060] Optionally, after completing the field-by-field comparison between the attack status message and the target attack status message, the detection system no longer relies on manual observation or experience-based judgment. Instead, it automatically summarizes each comparison item of the comparison results according to predefined judgment logic, thereby obtaining the effectiveness of the detection system in identifying attack events in the communication link.
[0061] In this embodiment of the application, the above steps realize the full-link validity verification of the detection system from attack detection to information reporting, rather than just verifying whether the detection system has alarms.
[0062] In steps S102 to S108 of this application, when the detection system is in operation, a simulation environment for vehicle operation is constructed based on vehicle simulation environment data. Since the simulation environment data can simulate the dynamic operating information of the vehicle during operation, it overcomes the limitations of related technologies that rely on real-vehicle road tests or static message playback. Subsequently, various types of abnormal attack messages can be injected into the simulation environment. From these abnormal attack messages, attack status messages containing attack event information are identified, and then compared with target attack status messages to obtain comparison results. Based on the comparison results, the detection system is tested to obtain test results, ensuring the scientific validity and safety of the testing of the detection system. This solves the technical problem of low efficiency in testing detection systems in vehicles, achieving the technical effect of improving the efficiency of testing detection systems in vehicles.
[0063] The method described in this embodiment will be further described below.
[0064] As an optional embodiment, step S106 involves identifying an attack status message containing attack event information from various types of abnormal attack messages, including: identifying the abnormal attack message and obtaining an identification result, wherein the identification result is used to indicate whether the abnormal attack message conforms to a preset attack behavior; based on the identification result, associating the message status of the abnormal attack message with the location information carried in the attack status message to obtain the attack status message.
[0065] In this embodiment, the real-time processor can simulate abnormal attack messages on the vehicle bus according to instructions from the host computer. These messages are sent to the intrusion detection processing unit via the bus interface card. After identifying the network attack, the intrusion detection processing unit can convert the abnormal attack message into an attack status message based on its status and current location information. This attack status message can be a CAN attack status message.
[0066] Optionally, attack status messages can also be sent to the vehicle UI display interface and the vehicle remote communication unit via the bus interface card. The real-time processor can record and save real-time bus data, providing a basis for evaluating and judging the accuracy of the vehicle bus intrusion detection system.
[0067] In this embodiment of the application, after the detection system identifies a network attack, it binds the attack characteristics with real-time location data to generate a structured attack status message, providing a basis for subsequent comparison with the target attack status message.
[0068] As an optional embodiment, the method further includes: converting the attack status message to obtain a wireless radio frequency signal; and transmitting the wireless radio frequency signal to the cloud using a wireless communication strategy.
[0069] In this embodiment, the content of the received attack status message can be displayed on the screen through the vehicle-mounted UI display interface to inform the user. The vehicle-mounted remote communication unit converts the content of the received attack status message into a wireless radio frequency signal and transmits it to the cloud server through wireless communication.
[0070] Optionally, the cloud server can further process the wireless radio frequency signals and display them in a user-friendly interface through an intrusion detection client platform.
[0071] Optionally, the attack status message generated by the vehicle intrusion detection system is initially transmitted within the vehicle's internal network in the form of a standard CAN bus message. The attack status message may include the attack type, abnormal message ID, data value, period, load rate, and precise latitude, longitude, speed, timestamp, and other positioning data synchronously provided by a GNSS simulator. After being received by the vehicle-mounted remote communication unit (T-BOX), this data is not directly uploaded in CAN format. Instead, it undergoes protocol conversion and encapsulation by the T-BOX's internal communication protocol stack. Specifically, the T-BOX parses the CAN-formatted attack status message into structured data and reassembles it into uplink data packets in JavaScript Object Notation (JSON) or binary format according to a preset vehicle communication protocol. Then, the modem module loads this data packet into the cellular wireless communication baseband signal, which is finally converted into a wireless radio frequency signal compliant with 4G / 5G network standards by the radio frequency front-end circuit and transmitted from the vehicle's antenna.
[0072] In testing related technologies, the focus is often only on verifying whether the detection system displays an alarm on the local screen, neglecting the remote communication capabilities crucial in real-world automotive environments. If the T-BOX fails to correctly parse messages, encryption fails, the protocol is corrupted, or the signal is interrupted, even if the detection system accurately identifies the attack, the security operations center will still be unable to detect the attack, rendering the overall protection capability of the detection system ineffective. However, this application's embodiment, by reproducing the aforementioned critical aspects in a simulated environment (e.g., a laboratory environment), ensures that attack events can be uploaded to the security monitoring platform via a remote communication channel.
[0073] As an optional embodiment, step S106 compares the attack status message with the target attack status message to obtain a comparison result, including: determining the message anomaly type of the attack status message, where the message anomaly type includes at least one of the following: anomaly type related to message identifier, anomaly type related to message length, anomaly type related to message period, anomaly type related to message value, and anomaly type related to bus load rate; comparing the message anomaly type of the attack status message with the message anomaly type field of the target attack status message to obtain a first comparison result; comparing the location information carried in the attack status message with the location information field of the target attack status message to obtain a second comparison result; and determining the comparison result based on the first comparison result and the second comparison result.
[0074] In this embodiment, the attack status message refers to a structured event report actively generated and reported by the detection system under test after detecting an attack. Based on the vehicle communication matrix definition, this attack status message can be sent to the vehicle UI and T-BOX via the CAN bus. Its content may include attack characteristic information and the vehicle's current spatiotemporal state. The target attack status message is not an ideal value set by humans, nor is it a preset template in the simulation environment. Instead, it is a complete picture of the real attack event composed of raw attack message data synchronously collected and recorded by the real-time processor and bus interface card in the detection system during the attack injection process, and positioning data output by a precisely aligned GNSS simulator. The target attack status message is an objective, tamper-proof, timestamped, hardware-level raw record.
[0075] Optionally, comparing the attack status message with the target attack status message can include two key dimensions. The first dimension is the comparison of message anomaly types, and the second dimension is the comparison of location information.
[0076] Optionally, message anomaly type comparison, that is, matching the attack category (such as message ID anomaly, length anomaly, period anomaly, data value anomaly, bus load rate anomaly) identified by the attack status message with the corresponding field in the target attack status message item by item.
[0077] Optionally, a location information comparison is performed, that is, comparing the location information such as longitude, latitude, altitude, speed, and timestamp carried in the attack status message with the original location data actually output by the GNSS simulator in the target attack status message to see if they are completely consistent. Since the T-BOX operates inside an electromagnetic shielded box, it only receives the location signal provided by the simulator, ensuring that the location information source is unique and interference-free. Therefore, the location fields in the attack status message must match the original location data recorded in the simulation environment with millisecond-level accuracy. For example, if the reported latitude is "39.9001°" when the attack occurs, while the target records "39.9000°", it is considered a location drift, which may be due to communication delay, clock asynchrony, or detection system processing error. Such deviations pose a risk in high-security scenarios.
[0078] In the embodiments of this application, the first comparison result is the accuracy of the attack feature content, and the second comparison result is the spatiotemporal consistency of the attack context, which together constitute the final comparison result.
[0079] As an optional embodiment, the comparison result is determined based on the first comparison result and the second comparison result, including: in response to the first comparison result being that the message anomaly type of the attack status message is the same as the message anomaly type field of the target attack status message, and the second comparison result being that the location information carried in the attack status message is consistent with the location information field of the target attack status message within the target range, the comparison result is determined to be that the attack status message and the target attack status message match in the attack feature identification dimension and the location information association dimension.
[0080] In this embodiment, based on the first comparison result and the second comparison result, it can be determined whether the comparison result is that the attack status message and the target attack status message match in the attack feature identification dimension and the location information association dimension.
[0081] Optionally, the first comparison result refers to the consistency judgment of each attack feature field in the attack status message, such as message ID, length, period, data value, bus load rate, etc., with the corresponding field in the target attack status message. These fields together constitute the attack feature dimension, which is the core basis for judging whether the detection system accurately identifies and reconstructs the attack behavior. For example, if the injected attack message is an abnormal message with ID=0x3FF, length=10, and period=15ms, then the target attack status message record should completely contain these three original attributes. If the attack status message reported by the detection system also completely contains these three pieces of information, and there are no false alarms, misreports, or missing information, then the first comparison result is consistent.
[0082] Optionally, the second comparison result refers to a spatial and temporal comparison of the positioning information carried in the attack status message, such as longitude, latitude, altitude, speed, and timestamp, with the synchronous positioning data in the target attack status message. This synchronous positioning data originates from the actual trajectory data output by the GNSS simulator at the moment the attack occurs. If the positioning information reported by the detection system is within the target range, that is, consistent within the allowable error range (e.g., longitude deviation ≤ 0.0001°, timestamp deviation ≤ 100ms), the second comparison result is considered consistent within the target range.
[0083] As an optional embodiment, step S108 involves testing the detection system based on the comparison results to obtain test results, including: in response to the comparison result showing that the attack status message and the target attack status message match in both the attack feature identification dimension and the location information association dimension, determining that the test result shows that the detection system's effectiveness in identifying attack events in the communication link is higher than the effectiveness threshold; in response to the comparison result showing that the attack status message and the target attack status message do not match in either the attack feature identification dimension or the location information association dimension, determining that the test result shows that the effectiveness of identifying attack events is lower than the effectiveness threshold.
[0084] In this embodiment, the detection system is tested based on the comparison results to obtain test results. This can transform the original subjective judgment of whether the detection system is working properly into an objective engineering standard based on dual-dimensional alignment.
[0085] Optionally, the aforementioned attack feature identification dimension includes fields such as abnormal attack message ID, length, period, message value, and load rate, i.e., whether the detection system accurately identifies and reports the technical characteristics of the attack on the CAN bus. The aforementioned location information association dimension includes GNSS data such as navigation positioning longitude, latitude, altitude, time, and speed, i.e., whether the detection system correctly binds the attack event to the real spatiotemporal location. These two dimensions—attack feature identification and location information association—together constitute the two elements of an attack event: behavioral characteristics and contextual information.
[0086] Optionally, when the attack status message and the target attack status message match in both the attack feature identification dimension and the location information association dimension, the test result can be determined as the effectiveness of the detection system in identifying the attack event in the communication link being higher than the effectiveness threshold. When the attack status message and the target attack status message do not match in either the attack feature identification dimension, the location information association dimension, or both, the test result can be determined as the effectiveness of the attack event identification being lower than the effectiveness threshold.
[0087] In this embodiment of the application, the detection system is tested based on the comparison results, and the test results are obtained. This enables the comparison of the content displayed on the vehicle UI display interface and the intrusion detection client platform with the message data recorded and saved by the real-time processor through the CAN interface card, thereby evaluating the function of the vehicle bus intrusion detection system.
[0088] As an optional embodiment, the method further includes: transmitting the attack status message to the vehicle's on-board terminal; and / or, the simulation environment data includes the vehicle's bus data, positioning data, and control signals of operating status, and the method further includes: recording and / or displaying the simulation environment data in the on-board terminal.
[0089] In this embodiment, the attack status message can be transmitted to the vehicle's onboard terminal. The onboard terminal can be an onboard UI display interface.
[0090] Optionally, the in-vehicle UI display interface can be used to visually demonstrate attack events to people inside the vehicle (such as test engineers).
[0091] Optionally, the aforementioned attack status message can be sent from the intrusion detection processing unit to the vehicle terminal via the CAN bus. After protocol parsing, the attack type, abnormal message ID, occurrence time, and other information are presented in a graphical interface (such as pop-up windows, log lists, and status icons), allowing testers to confirm whether the system has triggered an alarm in real time at the test site without relying on a remote platform.
[0092] Optionally, simulation environment data refers to the input signals generated by external devices and injected into the vehicle under test during the operation of the detection system. These signals may include bus data, positioning data, and control signals of the operating status, which together construct the real-world input environment on which the detection system depends for operation.
[0093] Optionally, the bus data can be virtual vehicle bus data, which may include vehicle speed, engine speed, door status, light status, wiper status, engine temperature, fuel level, etc.
[0094] Optionally, the positioning data can be satellite navigation positioning data, which may include GPS navigation data, BeiDou navigation data, Galileo satellite navigation system (Galileo) navigation data, and GLONASS satellite navigation system (GLONASS) navigation data, etc.
[0095] Optionally, the control signal for the operating status can be a hard-wired switching signal, which may include the ignition switch accessory position (ACC), the ignition switch ignition position (ON), the ignition switch start position (START), the brake pedal switch signal, etc.
[0096] Optionally, during testing, the vehicle-mounted terminal can not only receive and display attack status messages from the detection system, but also simultaneously record or display the underlying simulation environment data upon which the operation depends. For example, when the detection system reports "an abnormal message with ID=0x3FF detected," the vehicle-mounted UI can simultaneously display "current vehicle speed is 62.3 km / h, location is 39.9001° North latitude, ignition status is START, and braking signal is high level." This is not generated by the detection system, but rather by the vehicle-mounted terminal actively reading and parsing the raw simulation environment data sent by the real-time processor via the CAN bus or a dedicated diagnostic interface, and displaying it in conjunction with the attack event on the same screen.
[0097] In this embodiment, when the detection system is operational, a simulation environment for vehicle operation is constructed based on vehicle simulation environment data. Since the simulation environment data can simulate the dynamic operating information of the vehicle during operation, it overcomes the limitations of related technologies that rely on real-vehicle road tests or static message playback. Subsequently, various types of abnormal attack messages can be injected into the simulation environment. From these messages, attack status messages containing attack event information are identified, and then compared with target attack status messages to obtain comparison results. Based on the comparison results, the detection system is tested to obtain test results, ensuring the scientific rigor and security of the testing. This solves the technical problem of low efficiency in testing vehicle detection systems and achieves the technical effect of improving the efficiency of testing vehicle detection systems.
[0098] The technical solutions of the embodiments of this application will be illustrated below with reference to preferred embodiments.
[0099] Currently, traditional vehicles are gradually evolving into intelligent terminals integrating sensors, controllers, and communication modules. The complexity of vehicle electronic and electrical architecture and communication networks is increasing daily. While this technological evolution improves the user experience, it also significantly expands the vehicle's attack surface. Hackers can exploit the vehicle's exposed physical communication interfaces to illegally control it.
[0100] The vehicle bus serves as the communication bridge for the vehicle controller. However, the plaintext communication nature of the vehicle bus makes it relatively easy to launch attacks. Such attacks can lead to driving-related safety accidents. Therefore, during the vehicle development phase, it is necessary not only to develop an intrusion detection system specifically designed to detect and handle abnormal bus messages, but also to test and verify the vehicle bus intrusion detection system to ensure its effectiveness and accuracy, enhance vehicle information security monitoring and protection capabilities, and meet standard requirements.
[0101] To address the aforementioned issues, this application proposes a testing method for an in-vehicle bus intrusion detection system. Based on a vehicle information security testing system, and addressing the functional requirements of simulating vehicle CAN network traffic and abnormal bus messages in the in-vehicle bus intrusion detection system, the method comprises a power management unit, I / O boards, a real-time processor, a bus interface card, a GNSS simulator and shielding box, a cloud server, and an intrusion detection client platform to implement the testing process.
[0102] Figure 2 This is a schematic diagram of a vehicle information security testing system for functional testing of an in-vehicle bus intrusion detection system according to an embodiment of this application, as shown below. Figure 2 As shown, it includes a vehicle information security testing system 20, a vehicle terminal 21, a shielded box 22, a cloud server 23, and an intrusion detection client platform 24.
[0103] The vehicle information security testing system 20 includes a power management unit 201, an I / O board 202, a bus interface card 203, a real-time processor 204, a GNSS simulator 205, and a router 206.
[0104] The vehicle-mounted component 21 includes an in-vehicle UI display interface 211 and an intrusion detection and processing unit 212.
[0105] The shielded box 22 includes an onboard remote communication unit 221.
[0106] In this embodiment, the power management unit receives instructions from the host computer controller, provides power to the relevant controllers of the vehicle-side bus intrusion detection system based on the I / O board, and generates various voltage signal values. Subsequently, the real-time processor, based on the bus interface card, simulates the vehicle's CAN network nodes, constructs the vehicle network communication environment, simulates CAN bus attack messages, and monitors and records the generated CAN data in real time, serving as a verification basis for the effectiveness and accuracy of the vehicle-side bus intrusion detection system's functionality. The GNSS simulator can simulate vehicle navigation and positioning signals in real time, including positioning status data such as longitude, latitude, elevation, speed, and time. Finally, the vehicle-side intrusion detection processing unit, after collecting, identifying, and processing the CAN bus attack messages, sends the attack event information to the vehicle's UI display interface and the vehicle-side remote communication unit in CAN message format. The vehicle-side remote communication unit encapsulates the event information and the positioning data received from the GNSS simulator according to a predetermined format, sends it to the remote cloud server via a cellular wireless base station, and finally displays it on the intrusion detection client platform. The information displayed on the intrusion detection client platform and the vehicle UI interface is compared and analyzed with the CAN bus process log data and navigation positioning data to verify the functionality of the vehicle bus intrusion detection system.
[0107] Figure 3 This is a flowchart of a test method for an in-vehicle bus intrusion detection system according to an embodiment of this application, such as... Figure 3 As shown, it includes the following steps.
[0108] Step S301: Power on and confirm that each controller is working properly and that communication data can reach each other.
[0109] In this embodiment, the controllers of the vehicle bus intrusion detection system can be connected to the power management unit via power cables to provide power. They are connected to the bus interface card via CAN cables, enabling each controller to establish a CAN bus communication network. Power-on verification confirms that each controller is functioning correctly and that communication data is readily available between them.
[0110] Step S302: Import the configuration file into the GNSS simulator and set the GNSS simulator to remote control mode.
[0111] In this embodiment, a configuration file can be imported into the GNSS simulator and set to remote control mode. It can be confirmed that the connection between the RF output port and the satellite positioning antenna port of the vehicle-mounted remote communication unit in the electromagnetic shielding box is stable. Simultaneously, the communication port of the vehicle-mounted remote communication unit is connected to the external antenna of the electromagnetic shielding box.
[0112] In step S303, the host computer establishes a local area network connection with the GNSS simulator and real-time processor through a router.
[0113] In this embodiment, the host computer can establish a local area network connection with the GNSS simulator and real-time processor via a router, controlling the GNSS simulator to simulate satellite navigation and positioning data of the vehicle trajectory curve in real time. Simultaneously, the real-time processor controls the I / O boards and bus interface cards to provide hard-wired switch signals and virtual vehicle bus data. The virtual vehicle bus data may include vehicle speed, engine speed, door status, light status, wiper status, engine temperature, and fuel level.
[0114] Optionally, satellite navigation and positioning data may include GPS navigation data, BeiDou navigation data, Galileo navigation data, and GLONASS navigation data.
[0115] Step S304: The real-time processor simulates abnormal attack messages on the vehicle bus according to the instructions of the host computer.
[0116] In this embodiment, the real-time processor simulates abnormal attack messages on the vehicle bus according to instructions from the host computer and sends them to the intrusion detection processing unit via the bus interface card. After identifying a network attack, the intrusion detection processing unit converts the data into a CAN attack status message based on the attack message status and current location information, and sends it to the vehicle UI display interface and the vehicle remote communication unit via the bus interface card. The real-time processor records and saves real-time bus data, providing a basis for evaluating and determining the accuracy of the vehicle bus intrusion detection system.
[0117] Optionally, the types of abnormal attack messages on the vehicle bus may include abnormal message ID, abnormal message length, abnormal message period, abnormal message value, and abnormal bus load rate.
[0118] Step S305: Display the wireless radio frequency signal.
[0119] Figure 4 This is a flowchart of a method for displaying wireless radio frequency signals according to an embodiment of this application, such as... Figure 4 As shown, it includes the following steps.
[0120] In step S401, the vehicle-mounted UI displays the received attack status message on the screen to inform the user.
[0121] In step S402, the vehicle-mounted remote communication unit converts the received status message content into a wireless radio frequency signal.
[0122] Step S403: Transmit the wireless radio frequency signal to the cloud server via wireless communication.
[0123] In step S404, the cloud server reprocesses the wireless radio frequency signal and displays it in a user-friendly interface through the intrusion detection client platform.
[0124] Optionally, the attack status message content may include navigation positioning longitude, latitude, altitude, time, speed, abnormal attack message ID, length, period, message value, and load rate.
[0125] Step S306: Evaluate the functionality of the vehicle bus intrusion detection system.
[0126] In this embodiment, the content displayed on the vehicle UI and the intrusion detection client platform can be compared with the message data recorded and saved by the real-time processor through the CAN interface card to evaluate the function of the vehicle bus intrusion detection system.
[0127] In this embodiment of the application, the above-mentioned testing method can not only simulate satellite navigation and positioning data in a laboratory environment using a GNSS simulator, but also simulate the internal communication network under the operation of the vehicle, thereby avoiding unexpected safety accidents caused by actual vehicle testing. At the same time, based on the CAN bus interface card, the bus data of the test process is recorded and saved in real time and compared with the content displayed on the vehicle UI display interface and the intrusion detection client platform, realizing end-to-end testing of the vehicle bus intrusion detection system.
[0128] In this application embodiment, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0129] According to an embodiment of this application, a testing apparatus for a vehicle-mounted detection system is also provided. It should be noted that this testing apparatus for a vehicle-mounted detection system can be used to perform the testing method for the vehicle-mounted detection system described in the embodiments.
[0130] Figure 5This is a schematic diagram of a testing device for a vehicle detection system according to an embodiment of this application. Figure 5 As shown, the testing device 500 of the detection system in the vehicle may include: a construction unit 502, an injection unit 504, a comparison unit 506, and a testing unit 508.
[0131] The construction unit 502 is used to construct a simulation environment for vehicle operation based on the vehicle's simulation environment data in response to the detection system being in a working state. The simulation environment data is used to simulate the dynamic operation information of the vehicle during operation.
[0132] The injection unit 504 is used to inject various types of abnormal attack messages into the simulation environment. The different types of abnormal attack messages are used to simulate different attack behaviors of vehicles in a real vehicle network environment.
[0133] The comparison unit 506 is used to identify attack status messages containing attack event information from various types of abnormal attack messages, and to compare the attack status messages with the target attack status messages to obtain a comparison result. The target attack status message is used to characterize the abnormal attack message corresponding to the original attack event. The abnormal attack message is recorded by the hardware device in the simulation environment.
[0134] Test unit 508 is used to test the detection system based on the comparison results and obtain test results, wherein the test results are used to indicate the effectiveness of the detection system in identifying attack events in the communication link.
[0135] Optionally, the comparison unit 506 includes: an identification subunit, used to identify the abnormal attack message and obtain an identification result, wherein the identification result is used to indicate whether the abnormal attack message conforms to a preset attack behavior; and an association subunit, used to associate the message status of the abnormal attack message with the location information carried in the attack status message based on the identification result, and obtain the attack status message.
[0136] Optionally, the test device 500 of the detection system in the vehicle further includes: a conversion subunit for converting the attack status message to obtain a radio frequency signal; and a first transmission subunit for transmitting the radio frequency signal to the cloud using a wireless communication strategy.
[0137] Optionally, the comparison unit 506 includes: a first determining subunit, configured to determine the message anomaly type of the attack state message, wherein the message anomaly type includes at least one of the following: anomaly type for message identifier, anomaly type for message length, anomaly type for message period, anomaly type for message value, and anomaly type for bus load rate; a first comparison subunit, configured to compare the message anomaly type of the attack state message with the message anomaly type field of the target attack state message to obtain a first comparison result; a second comparison subunit, configured to compare the location information carried in the attack state message with the location information field of the target attack state message to obtain a second comparison result; and a second determining subunit, configured to determine a comparison result based on the first comparison result and the second comparison result.
[0138] Optionally, the second determining subunit includes: a third determining subunit, configured to determine, in response to the first comparison result being that the message anomaly type of the attack state message is the same as the message anomaly type field of the target attack state message, and the second comparison result being that the location information carried in the attack state message is consistent with the location information field of the target attack state message within the target range, that the comparison result is that the attack state message and the target attack state message match in the attack feature identification dimension and the location information association dimension.
[0139] Optionally, the test unit 508 includes: a fourth determining subunit, configured to determine that the test result is that the detection system's effectiveness in identifying attack events in the communication link is higher than the effectiveness threshold, in response to the comparison result being that the attack status message and the target attack status message match in the attack feature identification dimension and the location information association dimension; and a fifth determining subunit, configured to determine that the test result is that the effectiveness of the attack event identification is lower than the effectiveness threshold, in response to the comparison result being that the attack status message and the target attack status message do not match in either the attack feature identification dimension or the location information association dimension.
[0140] Optionally, the testing device 500 for the detection system in the vehicle further includes: a second transmission subunit for transmitting attack status messages to the vehicle's on-board terminal; and / or, the simulation environment data includes the vehicle's bus data, positioning data, and control signals of the operating status. The testing device 500 for the detection system in the vehicle further includes: a recording subunit for recording and / or displaying the simulation environment data in the on-board terminal.
[0141] In this embodiment, the construction unit 502, in response to the detection system being in a working state, constructs a simulation environment for vehicle operation based on vehicle simulation environment data. This simulation environment data is used to simulate the dynamic operating information of the vehicle during operation. The injection unit 504 injects various types of abnormal attack messages into the simulation environment. Different types of abnormal attack messages are used to simulate different attack behaviors of the vehicle in a real in-vehicle network environment. The comparison unit 506 identifies attack status messages containing attack event information from the various types of abnormal attack messages and compares these attack status messages with target attack status messages to obtain a comparison result. The target attack status message is used to characterize the abnormal attack message corresponding to the original attack event, and the abnormal attack message is recorded by hardware devices in the simulation environment. The testing unit 508 tests the detection system based on the comparison result to obtain a test result. This test result indicates the effectiveness of the detection system in identifying attack events in the communication link, solving the technical problem of low efficiency in testing detection systems in vehicles and achieving the technical effect of improving the efficiency of testing detection systems in vehicles.
[0142] This application also provides an electronic device 60, please refer to... Figure 6 , Figure 6 This is a structural diagram of an electronic device provided in one embodiment of the present application, including a processor 610 and a memory 620, wherein the memory 620 is used to store computer programs; the processor 610 is used to execute the programs stored in the memory 620 to implement the methods described in any embodiment of the present application.
[0143] Embodiments of this application also provide a computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of this application.
[0144] Embodiments of this application also provide a computer program product, including a computer program that, when executed by a processor, implements the methods of various embodiments of this application.
[0145] Embodiments of this application also provide a computer program product, including a non-volatile computer-readable storage medium for storing a computer program that, when executed by a processor, implements the methods in various embodiments of this application.
[0146] Embodiments of this application also provide a computer program that, when executed by a processor, implements the methods described in the various embodiments of this application.
[0147] According to another aspect of the embodiments of this application, a vehicle is also provided. The vehicle includes a memory and a processor. The memory stores an executable program; the processor is used to run the program, which, when running, implements the methods described in the embodiments of this application.
[0148] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0149] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0150] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0151] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0152] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0153] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A testing method for a detection system in a vehicle, characterized in that, include: In response to the detection system being in operation, a simulation environment for the vehicle's operation is constructed based on the vehicle's simulation environment data, wherein the simulation environment data is used to simulate the dynamic operating information of the vehicle during operation; Multiple types of abnormal attack messages are injected into the simulation environment, wherein different types of abnormal attack messages are used to simulate different attack behaviors of the vehicle in a real vehicle network environment; From the various types of abnormal attack messages, an attack status message containing attack event information is identified, and the attack status message is compared with the target attack status message to obtain a comparison result. The target attack status message is used to characterize the abnormal attack message corresponding to the original attack event, and the abnormal attack message is recorded by the hardware device in the simulation environment. Based on the comparison results, the detection system is tested to obtain test results, wherein the test results are used to indicate the effectiveness of the detection system in identifying attack events in the communication link.
2. The method according to claim 1, characterized in that, From the various types of abnormal attack messages, attack status messages containing attack event information are identified, including: The abnormal attack message is identified to obtain an identification result, wherein the identification result is used to indicate whether the abnormal attack message conforms to a preset attack behavior; Based on the identification result, the message status of the abnormal attack message is associated with the location information carried in the attack status message to obtain the attack status message.
3. The method according to claim 2, characterized in that, The method further includes: The attack status message is converted to obtain a wireless radio frequency signal; The wireless radio frequency signal is transmitted to the cloud using a wireless communication strategy.
4. The method according to claim 1, characterized in that, The attack status message is compared with the target attack status message to obtain the comparison result, including: Determine the message anomaly type of the attack status message, wherein the message anomaly type includes at least one of the following: anomaly type for message identifier, anomaly type for message length, anomaly type for message period, anomaly type for message value, and anomaly type for bus load rate. The packet anomaly type of the attack status packet is compared with the packet anomaly type field of the target attack status packet to obtain a first comparison result; The location information carried in the attack status message is compared with the location information field of the target attack status message to obtain a second comparison result. The comparison result is determined based on the first comparison result and the second comparison result.
5. The method according to claim 4, characterized in that, Determining the comparison result based on the first comparison result and the second comparison result includes: In response to the first comparison result being that the message anomaly type of the attack status message is the same as the message anomaly type field of the target attack status message, and the second comparison result being that the location information carried in the attack status message is consistent with the location information field of the target attack status message within the target range, it is determined that the comparison result is that the attack status message and the target attack status message match in the attack feature identification dimension and the location information association dimension.
6. The method according to claim 5, characterized in that, Based on the comparison results, the detection system is tested to obtain test results, including: In response to the comparison result that the attack status message and the target attack status message match in the attack feature identification dimension and the location information association dimension, the test result is determined to be that the detection system's effectiveness in identifying the attack event in the communication link is higher than the effectiveness threshold. If the comparison result shows that the attack status message and the target attack status message do not match in either the attack feature identification dimension or the location information association dimension, then the test result is determined to be that the validity of the identification of the attack event is lower than the validity threshold.
7. The method according to any one of claims 1 to 6, characterized in that, The method further includes: Transmit the attack status message to the vehicle's onboard terminal; and / or, The simulation environment data includes the vehicle's bus data, positioning data, and control signals for its operating status. The method further includes recording and / or displaying the simulation environment data on the vehicle-mounted terminal.
8. A testing device for a vehicle detection system, characterized in that, include: A construction unit is configured to, in response to the detection system being in a working state, construct a simulation environment for the vehicle's operation based on the vehicle's simulation environment data, wherein the simulation environment data is used to simulate the dynamic operating information of the vehicle during operation; An injection unit is used to inject various types of abnormal attack messages into the simulation environment, wherein the different types of abnormal attack messages are used to simulate different attack behaviors of the vehicle in a real vehicle network environment. The comparison unit is used to identify attack status messages containing attack event information from the various types of abnormal attack messages, and to compare the attack status messages with target attack status messages to obtain a comparison result. The target attack status message is used to characterize the abnormal attack message corresponding to the original attack event, and the abnormal attack message is recorded by the hardware device in the simulation environment. The testing unit is used to test the detection system based on the comparison results and obtain test results, wherein the test results are used to indicate the effectiveness of the detection system in identifying attack events in the communication link.
9. A processor, characterized in that, The processor is used to run a program, wherein the program executes the method according to any one of claims 1 to 7 when it runs.
10. An electronic device, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the method according to any one of claims 1 to 7.