An attack path identification method and system for an automobile network target field traffic atlas

CN122845284APending Publication Date: 2026-09-29CHINA AUTOMOTIVE INTELLIGENT TECHNOLOGY (TIANJIN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611264612.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-20
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0003]现有靶场技术攻击路径识别方法存在以下不足,依赖单一流量特征如异常帧频率,难以关联多节点的攻击链路;未充分利用靶场中积累的测试用例库资源,导致已知攻击路径的识别效率低下;对疑似攻击节点的遍历缺乏优先级排序,易造成算力浪费或漏检

Benefits of technology

[0013]上述说明,仅是本发明技术方案的概述,为了能够更清楚了解本发明技术手段,可依照说明书的内容予以实施,并且为了让本发明的上述说明和其它目的、特征及优点能够更明显易懂,特举较佳实施例,详细说明如下。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845284A_ABST
    Figure CN122845284A_ABST
Patent Text Reader

Abstract

The application discloses a kind of attack path identification method and system of automobile network target field flow graph, it is related to automobile network security technical field, by constructing the flow graph path of the flow attack behavior of automobile network target field, the flow graph path of analysis, obtain the node of suspected attack in flow graph path, traverse the path including suspected attack node in test case library under test scene, obtain the attack path of automobile network target field flow graph.The application traverses high-risk node by node weight order priority, reduces invalid calculation, realizes automatic identification in combination with the path matching of test case library, reduces artificial cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of automotive network security technology, and in particular to an attack path identification method for automotive network range traffic maps, which is mainly used for the detection, tracing and analysis of automotive network attacks. Background Technology

[0002] As a highly realistic virtualized testing environment, the automotive network range is widely used to simulate vehicle electronic control units (ECUs), in-vehicle communication networks (such as CAN, LIN, Ethernet), and vehicle-to-cloud interaction scenarios to evaluate the security protection capabilities of vehicle networks against threats such as penetration attacks, data tampering, and malicious intrusion.

[0003] Existing attack path identification methods in target ranges have the following shortcomings: they rely on single traffic features such as abnormal frame frequency, making it difficult to associate attack links with multiple nodes; they do not make full use of the test case library resources accumulated in the target range, resulting in low efficiency in identifying known attack paths; and they lack priority sorting for traversing suspected attack nodes, which can easily lead to wasted computing power or missed detections.

[0004] Based on the above problems, this paper proposes an attack path identification method and system for automotive network target range traffic graphs. Summary of the Invention

[0005] Based on the above problems, this invention proposes an attack path identification method for automotive network target range traffic maps, characterized by the following steps: S1: Constructing the traffic graph path of traffic attack behavior in the automotive network test range; S2: Analyze the traffic graph path in S1 to obtain the set A of nodes suspected of being attacked in the traffic graph path; S3: Traverse the nodes in set A in descending order of their weights, and find the multiple first paths in the test case library corresponding to each node in the test scenario where the node is the last node. If any of the multiple first paths is a subset of the traffic graph paths in S1, then end the traversal; otherwise, execute S4. S4: Traverse the nodes in set A in descending order of their weights. Traverse multiple second paths in the test case library corresponding to the test scenario, with the node as the intermediate node. If any of the multiple second paths is a subset of the traffic graph path in S1, then end the traversal; otherwise, execute S5. S5: Manually analyze the traffic graph paths in S1 to identify the attack nodes; S6: Take the last node of the subset path in S3, the last node of the subset path in S4, or the attack node in S5 as the attack node to obtain the attack path of the automotive network range traffic graph.

[0006] Furthermore, step S1 specifically includes: S11: Collect user attack behavior; S12: Collect network traffic of each node in the automotive network test range; S13: Based on the attack behavior and the timestamps, operation triggers, context dependencies, and data response data in the node network traffic, determine the trigger response relationship between nodes and obtain the traffic graph path of the attack behavior.

[0007] Furthermore, step S2 specifically includes: Based on the node attributes of the traffic graph path, a multi-dimensional match is performed with the attack feature database to filter out a set A of nodes suspected of being attacked. Node attributes include timestamp, operation type, traffic status, and protocol characteristics; The attack signature database includes operational behavior characteristics and attack traffic characteristics.

[0008] Furthermore, step S3 specifically includes: S31: Traverse multiple first paths in the test case library of the test scenario corresponding to the node with the highest node weight in set A, with the node with the highest weight as the last node. If there is a subset of the traffic graph path in S1 among the multiple first paths, then end S31 and execute S6; otherwise, execute S32. S32: Traverse multiple first paths in the test case library of the test scenario corresponding to the node with the second highest node weight in set A, with the node with the second highest node weight as the last node. If there is a subset of the traffic graph path in S1 among the multiple first paths, then end S32 and execute S6. If it does not exist, then iterate through the multiple first paths in the test case library corresponding to the test scenario under the test scenario, except for the node with the highest weight and the node with the second highest weight. If any of the multiple first paths is a subset of the paths in the traffic graph of S1, then S32 ends and S6 is executed; otherwise, S4 is executed. The node weight is calculated by weighting the node's security level and historical attack frequency.

[0009] Furthermore, step S4 specifically includes: S41: Traverse multiple second paths in the test case library of the test scenario corresponding to the node with the highest node weight in set A, with the node with the highest weight as the intermediate node. If there is a subset of the traffic graph path in S1 among the multiple second paths, then end S41 and execute S6; otherwise, execute S42. S42, traverse multiple second paths in the test case library of the test scenario corresponding to the node with the second highest weight in set A, with the node with the second highest weight as the intermediate node. If there is a subset of the traffic graph path in S1 among the multiple second paths, then end S42 and execute S6. If it does not exist, then iterate through the multiple second paths in the test case library corresponding to the test scenario under the test scenario, except for the node with the highest weight and the node with the second highest weight. If any of the multiple second paths is a subset of the paths in the traffic graph of S1, then S42 ends and S6 is executed; otherwise, S5 is executed. The node weight is calculated by weighting the node's security level and historical attack frequency.

[0010] Furthermore, step S5 specifically includes: By manually reviewing the traffic graph paths of S1 by security analysts, and combining the abnormal characteristics of nodes, contextual relationships, and timestamps, the attacking nodes were identified.

[0011] Furthermore, step S6 specifically includes: Using the last node of the subset path in S3, the last node of the subset path in S4, or the manually analyzed attack node in S5 as the endpoint, trace back its associated nodes and edges in the traffic graph path in S1 to form a complete attack path.

[0012] This invention also proposes an attack path identification system for automotive network range traffic graphs, which is used to execute an attack path identification method for automotive network range traffic graphs.

[0013] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention, it can be implemented according to the contents of the specification. In order to make the above description and other objects, features and advantages of the present invention more obvious and understandable, preferred embodiments are provided and described in detail below. Attached Figure Description

[0014] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1 This is a flowchart of an attack path identification method for traffic graphs in an automotive network test range. Detailed Implementation

[0015] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0016] In the description of this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," "linking," "fixing," etc., should be interpreted broadly. For example, they can refer to a connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0017] Example 1 A method for identifying attack paths in a traffic graph of an automotive network test range, characterized by the following steps: S1: Constructing the traffic graph path of traffic attack behavior in the automotive network test range; S2: Analyze the traffic graph path in S1 to obtain the set A of nodes suspected of being attacked in the traffic graph path; S3: Traverse the nodes in set A in descending order of their weights, and find the multiple first paths in the test case library corresponding to each node in the test scenario where the node is the last node. If any of the multiple first paths is a subset of the traffic graph paths in S1, then end the traversal; otherwise, execute S4. S4: Traverse the nodes in set A in descending order of their weights. Traverse multiple second paths in the test case library corresponding to the test scenario, with the node as the intermediate node. If any of the multiple second paths is a subset of the traffic graph path in S1, then end the traversal; otherwise, execute S5. S5: Manually analyze the traffic graph paths in S1 to identify the attack nodes; S6: Take the last node of the subset path in S3, the last node of the subset path in S4, or the attack node in S5 as the attack node to obtain the attack path of the automotive network range traffic graph.

[0018] Furthermore, step S1 specifically includes: S11: Collect user attack behavior; S12: Collect network traffic of each node in the automotive network test range; S13: Based on the attack behavior and the timestamps, operation triggers, context dependencies, and data response data in the node network traffic, determine the trigger response relationship between nodes and obtain the traffic graph path of the attack behavior.

[0019] Node network traffic includes traffic data (such as CAN frames and IP packets), protocol information (such as frame ID, port number, and transport layer protocol), timestamps, etc.

[0020] Attack scenarios include CAN bus injection, packet replay, APP reverse control interface detection, weak WIFI protocol encryption detection, and unauthorized diagnostic sessions.

[0021] In the CAN bus injection test, the ID, transmission frequency, data field content, and timestamp of the CAN frame are collected. In the packet replay test, the structure, timestamps, and corresponding historical traffic data of the replay frames are collected. During the APP reverse control interface detection test, API call records and operation behavior logs are collected; In the weak encryption detection test of the WIFI protocol, the SSID detection sequence, authentication request frequency and timing were collected; During unauthorized diagnostic session testing, UDS protocol frames and diagnostic process status are collected.

[0022] Furthermore, step S2 specifically includes: Based on the node attributes of the traffic graph path, a multi-dimensional match is performed with the attack feature database to filter out a set A of nodes suspected of being attacked. Node attributes include timestamp, operation type, traffic status, and protocol characteristics; The attack signature database includes operational behavior characteristics and attack traffic characteristics. For example, in a CAN bus injection test, node attributes can be CAN frame ID, transmission frequency, and operation behavior log. The matching rules of the corresponding attack feature library are: 1) Frame frequency with the same ID > threshold, such as a threshold of 100 frames / second; 2) Operation flow is empty, such as no interactive interface operation.

[0023] The matching rule for packet replay testing is that no button action was performed during the operation, but a characteristic replay frame appeared, that is, no operation behavior and traffic highly matched historical traffic within a short period of time; The matching rules for APP reverse control interface detection test are unauthorized API calls, no API requests made by the operation, i.e. missing operation behavior and sudden API calls with traffic. The matching rules for the weak encryption detection test of the WIFI protocol are to detect multiple SSIDs in a short period of time and send repeated authentication requests, i.e., abnormal traffic time series and abnormal detection frequency. The matching rule for unauthorized diagnostic session testing is: UDS 0x10 service starts, and secure access 0x27 service passes, which means it is in the unauthorized testing process + the security service is bypassed.

[0024] Furthermore, step S3 specifically includes: S31: Traverse multiple first paths in the test case library of the test scenario corresponding to the node with the highest node weight in set A, with the node with the highest weight as the last node. If there is a subset of the traffic graph path in S1 among the multiple first paths, then end S31 and execute S6; otherwise, execute S32. S32: Traverse multiple first paths in the test case library of the test scenario corresponding to the node with the second highest node weight in set A, with the node with the second highest node weight as the last node. If there is a subset of the traffic graph path in S1 among the multiple first paths, then end S32 and execute S6. If it does not exist, then iterate through the multiple first paths in the test case library corresponding to the test scenario under the test scenario, except for the node with the highest weight and the node with the second highest weight. If any of the multiple first paths is a subset of the paths in the traffic graph of S1, then S32 ends and S6 is executed; otherwise, S4 is executed. Taking this node as the final node, meaning the endpoint of the simulated attack path in the test case, all nodes, edges, and temporal relationships of the subset path (i.e., the first path) are included in the traffic graph path. The test case library contains the path of node S, which can be found in the path set L1 corresponding to test scenario T1, the path set L2 corresponding to test scenario T2, and the path set L3 corresponding to test scenario T3. The position of node S in the path of node S may be at the end or in the middle of the path. The test case library can be traversed by node or test scenario.

[0025] In the CAN bus injection test, the first path in the test case library can be "attack tool → OBD interface → vehicle Ethernet switch → body control module (BCM) → CAN gateway → chassis domain controller → brake ECU (end point)". Among them, the vehicle Ethernet switch is responsible for converting the attack traffic accessed by the OBD interface into Ethernet format for transmission; the body control module (BCM) acts as an intermediate forwarding node, performing preliminary filtering of the traffic but not intercepting abnormal CAN frames; the chassis domain controller receives the traffic forwarded by the CAN gateway and issues commands to the brake ECU.

[0026] The first path in the test case library can also be "Attack Tool → OBD Interface → Vehicle Ethernet Switch → Body Control Module (BCM) → CAN Gateway → Chassis Domain Controller (Endpoint)". In this path, the vehicle Ethernet switch is responsible for converting the attack traffic accessed through the OBD interface into Ethernet format for transmission; the body control module (BCM) acts as an intermediate forwarding node, performing preliminary filtering of the traffic but not intercepting abnormal CAN frames; and the chassis domain controller receives the attack traffic forwarded by the CAN gateway.

[0027] The first path in the test case library can also be: attack terminal → vehicle Bluetooth module → vehicle entertainment system → Ethernet switch → body control module (BCM) → CAN gateway → chassis domain controller → brake ECU.

[0028] The node weight is calculated by weighting the node's security level and historical attack frequency.

[0029] Safety-critical components such as the braking ECU and steering ECU have a higher weight than the entertainment ECU.

[0030] If the braking ECU receives a high-frequency frame node, and if the CAN gateway, chassis domain controller, and braking ECU meet the above matching rules, then the CAN gateway, chassis domain controller, and braking ECU are determined to be suspected attacked nodes. Based on the node weight, the first path ending with the braking ECU is traversed first to determine if it is a subset of the traffic graph path. If it is, then the braking ECU is the attack node; if not, then the first path ending with the CAN gateway and chassis domain controller is determined sequentially. If the first path ending with the chassis domain controller is a subset of the traffic graph path, then the chassis domain controller is the attack node, and the braking ECU is not the final attack target. Its anomaly is caused by the chassis domain controller being attacked.

[0031] Furthermore, step S4 specifically includes: S41: Traverse multiple second paths in the test case library of the test scenario corresponding to the node with the highest node weight in set A, with the node with the highest weight as the intermediate node. If there is a subset of the traffic graph path in S1 among the multiple second paths, then end S41 and execute S6; otherwise, execute S42. S42, traverse multiple second paths in the test case library of the test scenario corresponding to the node with the second highest weight in set A, with the node with the second highest weight as the intermediate node. If there is a subset of the traffic graph path in S1 among the multiple second paths, then end S42 and execute S6. If it does not exist, then iterate through the multiple second paths in the test case library corresponding to the test scenario under the test scenario, except for the node with the highest weight and the node with the second highest weight. If any of the multiple second paths is a subset of the paths in the traffic graph of S1, then S42 ends and S6 is executed; otherwise, S5 is executed. This node is taken as an intermediate node, meaning the attack path in the test case passes through this node, and this node is not the endpoint. If there is no match in S3, the second path with the braking ECU as the intermediate node is traversed first to determine whether it is a subset of the flow graph path. If it does not exist, the second path with the chassis domain controller as the intermediate node is traversed to determine whether it is a subset of the flow graph path. If it is, the last node of the second path is the attack node.

[0032] Furthermore, step S5 specifically includes: By manually reviewing the traffic graph paths of S1 by security analysts, and combining the abnormal characteristics of nodes, contextual relationships, and timestamps, the attacking nodes were identified.

[0033] For novel variant attacks in scenarios with unmatched test cases, manual analysis based on scenario characteristics was conducted: the attacking node is the entertainment ECU, which injects malicious commands in collaboration with other nodes by sending segmented CAN frames, causing abnormal operation of the braking ECU; the attacking node is the Ethernet gateway, which converts malicious Ethernet frames into braking CAN commands due to a protocol conversion vulnerability, triggering braking abnormalities despite lacking high-frequency frame characteristics.

[0034] Furthermore, step S6 specifically includes: Using the last node of the first path in S3, the last node of the second path in S4, or the manually analyzed attack node in S5 as the endpoint, trace back its associated nodes and edges in the traffic graph path of S1 to form a complete attack path.

[0035] The attack path with the brake ECU as the attack point is: attack tool → OBD interface → vehicle Ethernet switch → body control module (BCM) → CAN gateway → chassis domain controller → brake ECU.

[0036] The attack path with the chassis domain controller as the attack point is: attack tool → OBD interface → vehicle Ethernet switch → body control module (BCM) → CAN gateway → chassis domain controller.

[0037] Example 2 An attack path identification system for automotive network range traffic graphs is provided, which is used to perform attack path identification methods for automotive network range traffic graphs.

[0038] The beneficial effects of this invention are as follows: 1) Based on the weight calculation of "security level + historical attack frequency", high-risk nodes are traversed first by sorting the node weights to reduce invalid calculations. Combined with path matching of the test case library, automated identification is achieved, reducing manual costs.

[0039] 2) Multi-node correlation analysis based on traffic graph avoids misjudgment based on a single feature, and subset path matching ensures consistency with known attack patterns.

[0040] 3) For scenarios with no matching test cases (such as hybrid protocol attacks), a visual graph interface is used to assist manual analysis. By combining node anomaly characteristics with contextual relationships, the manual analysis time can be shortened.

[0041] 4) It is applicable to different automotive network architectures, and the test case library can be dynamically updated to cover new types of attacks.

[0042] The above description is merely a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for identifying attack paths in automotive network target range traffic maps, characterized in that, Includes the following steps: S1: Constructing the traffic graph path of traffic attack behavior in the automotive network test range; S2: Analyze the traffic graph path in S1 to obtain the set A of nodes suspected of being attacked in the traffic graph path; S3: Traverse the nodes in set A in descending order of their weights, and find the multiple first paths in the test case library corresponding to each node in the test scenario where the node is the last node. If any of the multiple first paths is a subset of the traffic graph paths in S1, then end the traversal; otherwise, execute S4. S4: Traverse the nodes in set A in descending order of their weights. Traverse multiple second paths in the test case library corresponding to the test scenario, with the node as the intermediate node. If any of the multiple second paths is a subset of the traffic graph path in S1, then end the traversal; otherwise, execute S5. S5: Manually analyze the traffic graph paths in S1 to identify the attack nodes; S6: Take the last node of the subset path in S3, the last node of the subset path in S4, or the attack node in S5 as the attack node to obtain the attack path of the automotive network range traffic graph.

2. The attack path identification method for automotive network range traffic graphs according to claim 1, characterized in that, Step S1 specifically includes: S11: Collect user attack behavior; S12: Collect network traffic of each node in the automotive network test range; S13: Based on the attack behavior and the timestamps, operation triggers, context dependencies, and data response data in the node network traffic, determine the trigger response relationship between nodes and obtain the traffic graph path of the attack behavior.

3. The attack path identification method for automotive network range traffic graphs according to claim 1, characterized in that, Step S2 specifically includes: Based on the node attributes of the traffic graph path, a multi-dimensional match is performed with the attack feature database to filter out a set A of nodes suspected of being attacked. Node attributes include timestamp, operation type, traffic status, and protocol characteristics; The attack signature database includes operational behavior characteristics and attack traffic characteristics.

4. The attack path identification method for automotive network range traffic graphs according to claim 1, characterized in that, Step S3 specifically includes: S31: Traverse multiple first paths in the test case library of the test scenario corresponding to the node with the highest node weight in set A, with the node with the highest weight as the last node. If there is a subset of the traffic graph path in S1 among the multiple first paths, then end S31 and execute S6; otherwise, execute S32. S32: Traverse multiple first paths in the test case library of the test scenario corresponding to the node with the second highest node weight in set A, with the node with the second highest node weight as the last node. If there is a subset of the traffic graph path in S1 among the multiple first paths, then end S32 and execute S6. If it does not exist, then iterate through the multiple first paths in the test case library corresponding to the test scenario under the test scenario, except for the node with the highest weight and the node with the second highest weight. If any of the multiple first paths is a subset of the paths in the traffic graph of S1, then S32 ends and S6 is executed; otherwise, S4 is executed. The node weight is calculated by weighting the node's security level and historical attack frequency.

5. The attack path identification method for automotive network range traffic graphs according to claim 1, characterized in that, Step S4 specifically includes: S41: Traverse multiple second paths in the test case library of the test scenario corresponding to the node with the highest node weight in set A, with the node with the highest weight as the intermediate node. If there is a subset path of the traffic graph path in S1 among the multiple second paths, then end S41 and execute S6; otherwise, execute S42. S42, traverse multiple second paths in the test case library of the test scenario corresponding to the node with the second highest node weight in set A, with the node with the second highest weight as the intermediate node. If there is a subset of the traffic graph path in S1 among the multiple second paths, then end S42 and execute S6. If it does not exist, then iterate through the multiple second paths in the test case library corresponding to the test scenario under the test scenario, except for the node with the highest weight and the node with the second highest weight. If any of the multiple second paths is a subset of the paths in the traffic graph of S1, then S42 ends and S6 is executed; otherwise, S5 is executed. The node weight is calculated by weighting the node's security level and historical attack frequency.

6. The attack path identification method for automotive network range traffic graphs according to claim 1, characterized in that, Step S5 specifically includes: By manually reviewing the traffic graph paths of S1 by security analysts, and combining the abnormal characteristics of nodes, contextual relationships, and timestamps, the attacking nodes were identified.

7. The attack path identification method for automotive network range traffic graphs according to claim 1, characterized in that, Step S6 specifically includes: Using the last node of the subset path in S3, the last node of the subset path in S4, or the manually analyzed attack node in S5 as the endpoint, trace back its associated nodes and edges in the traffic graph path in S1 to form a complete attack path.

8. An attack path identification system for automotive network range traffic graphs, wherein the attack path identification system is used to execute the attack path identification method for automotive network range traffic graphs as described in any one of claims 1-7.