Network security detection method and apparatus for vehicle, vehicle, and storage medium

WO2026179432A1PCT designated stage Publication Date: 2026-09-03CHERY AUTOMOBILE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/071023
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-02-25
Filing Date
2026-01-07
Publication Date
2026-09-03

Smart Images

  • Figure CN2026071023_03092026_PF_FP_ABST
    Figure CN2026071023_03092026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a network security detection method and apparatus for a vehicle, a vehicle, and a storage medium. The method comprises: generating a threat and risk analysis result of a vehicle on the basis of network security damage impact assessment data and attack feasibility assessment data of the vehicle; determining a network security log development range and network security log format content of the vehicle, and determining, on the basis of the network security log development range and the network security log format content, whether the vehicle triggers a network security event that satisfies a preset condition; and diagnosing a network security log of the vehicle on the basis of log development content of the vehicle, and detecting the network security log.
Need to check novelty before this filing date? Find Prior Art

Description

Cybersecurity testing methods, devices, vehicles, and storage media for automobiles

[0001] This disclosure is based on and claims priority to Chinese Patent Application No. 202510211955.X, filed on February 25, 2025, entitled “Network Security Monitoring Method, Device, Vehicle and Storage Medium for Automobiles”, the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of intelligent connected vehicle technology, and in particular to a network security detection method, device, vehicle, and storage medium for automobiles. Background Technology

[0003] With the rapid development of technology and the times, automobiles have far surpassed the traditional definition of a means of transportation. Modern cars are not merely transportation tools, but complex systems integrating various advanced technologies and components, evolving into multifunctional mobile terminals. The increase in connectivity and the complexity of in-vehicle networks have led to a continuous increase in information security risks for modern automobiles.

[0004] Various automotive cybersecurity measures already exist, such as firewalls, intrusion detection systems (IDS), and data encryption technologies. These measures have improved the security of vehicle network systems to a certain extent. Furthermore, standards for automotive functional safety, such as ISO 26262, are widely used in the automotive industry to reduce risks caused by electrical and electronic system failures.

[0005] However, in related technologies, vehicle network systems face various threats such as cyberattacks and malware intrusions, leading to serious consequences such as tampering with vehicle control systems and leakage of user data, endangering driving safety, causing overload of the in-vehicle network, and consequently affecting the normal operation of the vehicle, thus urgently requiring improvement. Especially for non-connected vehicles, solutions for achieving on-vehicle network security detection are urgently needed. Summary of the Invention

[0006] This application provides a method, device, vehicle, and storage medium for network security detection of automobiles, in order to solve the problems in related technologies, such as vehicle network systems facing various threats from hacker attacks and malicious software intrusions, which lead to serious consequences such as tampering with vehicle control systems and leakage of user data, endangering driving safety, causing overload of the vehicle network, and thus affecting the normal operation of the vehicle.

[0007] One embodiment of this application provides a method for detecting cybersecurity in a vehicle, comprising the following steps: generating threat and risk analysis results for the vehicle based on cybersecurity damage impact assessment data and attack feasibility assessment data; determining the scope of cybersecurity log development and the format and content of the vehicle's cybersecurity logs based on the threat and risk analysis results, and determining whether the vehicle has triggered a cybersecurity event that meets preset conditions based on the scope of cybersecurity log development and the format and content of the cybersecurity logs; if the vehicle triggers the cybersecurity event that meets the preset conditions, diagnosing the vehicle's cybersecurity logs based on the log development content of the vehicle, generating cybersecurity diagnostic data for the vehicle, and detecting the cybersecurity logs to generate a cybersecurity detection result for the vehicle.

[0008] Optionally, in one embodiment of this application, the method further includes: detecting the network security log of the vehicle based on the network security detection result to generate detection data of the vehicle; generating at least one acoustic alarm action and / or at least one optical alarm action of the vehicle based on the detection data, and executing the at least one acoustic alarm action and / or the at least one optical alarm action to alert the driver to the network security status of the vehicle.

[0009] Optionally, in one embodiment of this application, the step of diagnosing the vehicle's cybersecurity logs and generating cybersecurity diagnostic data based on the vehicle's log development content includes: extracting timestamp information from the cybersecurity logs based on the vehicle's log development content, and determining the time information of the cybersecurity logs based on the timestamp information; identifying the event types of the cybersecurity logs and checking the actual operation results recorded in the cybersecurity logs; and generating the vehicle's cybersecurity diagnostic data based on the time information of the cybersecurity logs, the event types, and the actual operation results.

[0010] Optionally, in one embodiment of this application, the step of detecting the network security log to generate a network security detection result for the vehicle includes: reading the network security log stored on the vehicle's terminal to generate network security reading data for the vehicle; uploading the network security reading data to generate an upload result, and detecting network security risks of the vehicle based on the upload result to generate risk warning information corresponding to the network security risks; and adjusting the risk assessment level of the vehicle based on the risk warning information to generate a network security detection result for the vehicle based on the risk assessment level.

[0011] Optionally, in an embodiment of the present application, the method further comprises: if the vehicle triggers at least one of a high-risk abnormal external connection record, detection data, controller resource usage, and suspected security event information, determining that the vehicle triggers the network security event meeting the preset condition.

[0012] In another aspect, an embodiment of the present application provides a network security detection device for a vehicle, comprising: a generation module configured to generate threat and risk analysis results of the vehicle based on network security damage impact evaluation data and attack feasibility evaluation data of the vehicle; a determination module configured to determine network security log development range and network security log format content of the vehicle based on the threat and risk analysis results of the vehicle, and determine whether the vehicle triggers a network security event meeting a preset condition according to the network security log development range and the network security log format content; and a first detection module configured to, if the vehicle triggers the network security event meeting the preset condition, diagnose a network security log of the vehicle according to log development content of the vehicle, generate network security diagnosis data of the vehicle, and detect the network security log to generate network security detection results of the vehicle.

[0013] Optionally, in an embodiment of the present application, the method further comprises: a second detection module configured to detect the network security log of the vehicle according to the network security detection results to generate detection data of the vehicle; and a prompt module configured to generate at least one acoustic alarm action and / or at least one optical alarm action of the vehicle according to the detection data, and execute the at least one acoustic alarm action and / or the at least one optical alarm action to prompt a driver of the vehicle about a network security state of the vehicle.

[0014] Optionally, in an embodiment of the present application, the first detection module comprises: an extraction unit configured to extract timestamp information in the network security log based on the log development content of the vehicle, and determine time information of the network security log according to the timestamp information; a checking unit configured to identify an event type of the network security log, and check an actual operation result recorded in the network security log; and a generation unit configured to generate the network security diagnosis data of the vehicle according to the time information of the network security log, the event type, and the actual operation result.

[0015] Optionally, in an embodiment of the present application, the first detection module comprises: a reading unit configured to read the network security log stored in the vehicle end to generate network security reading data of the vehicle; an uploading unit configured to upload the network security reading data to generate an uploading result, and detect a network security risk of the vehicle according to the uploading result to generate risk warning information corresponding to the network security risk; and a detection unit configured to adjust a risk assessment level of the vehicle according to the risk warning information, and generate a network security detection result of the vehicle according to the risk assessment level.

[0016] Optionally, in an embodiment of the present application, the device further comprises a determination module configured to determine that the vehicle triggers the network security event satisfying the preset condition when the vehicle triggers at least one of a high-risk abnormal external connection record, detection data, controller resource usage, and suspected security event information.

[0017] In another aspect, an embodiment of the present application provides a vehicle, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the network security detection method of the vehicle according to the above-described embodiments.

[0018] In another aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the network security detection method of the vehicle according to the above-described embodiments.

[0019] In another aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the program is executed by a processor to implement the network security detection method of the vehicle according to the above-described embodiments.

[0020] In another aspect, an embodiment of the present application provides a computer program product, which stores at least one program code, and the at least one program code is loaded and executed by a processor to implement the network security detection method of the vehicle according to the above-described embodiments.

[0021] The embodiment of the present application can record, collect and analyze the vehicle end safety events of non-networked vehicles, avoid network security risks from the vehicles, and combine the non-networking continuous detection scheme with the IDPS scheme to include all OEM vehicles in the continuous detection range, use the existing diagnostic path, open the interface between the existing diagnostic cloud and the V-SOC cloud, and realize continuous network security detection. Therefore, the problems in the related art that the vehicle network system is threatened by hacking attacks, malicious software intrusion and other threats, resulting in serious consequences such as tampering of the vehicle control system, user data leakage, endangering driving safety, overloading the vehicle network, and affecting the normal operation of the vehicle are solved.

[0022] Additional aspects and advantages of the present application will be in part apparent and in part pointed out hereinafter. BRIEF DESCRIPTION OF DRAWINGS

[0023] The above and / or additional aspects and advantages of the present application will become apparent and be readily appreciated from the following description, including the accompanying drawings, wherein:

[0024] Fig. 1 is a flowchart of a network security detection method of a vehicle according to an embodiment of the present application;

[0025] Fig. 2 is a flowchart of a network security detection method of a vehicle according to an embodiment of the present application;

[0026] Fig. 3 is a structural schematic diagram of a network security detection device of a vehicle according to an embodiment of the present application;

[0027] Fig. 4 is a structural schematic diagram of a vehicle according to an embodiment of the present application;

[0028] Fig. 5 is a structural schematic diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0029] The embodiments of the present application are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference signs represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the accompanying drawings are exemplary and are intended to explain the present application, and cannot be understood as limiting the present application.

[0030] The network security detection method, device, vehicle and storage medium of the automobile according to the embodiments of the present application are described below with reference to the accompanying drawings. In view of the problems in the related art mentioned above, the vehicle network system is threatened by hacking attacks, malicious software intrusion and other threats, which leads to serious consequences such as tampering of the vehicle control system, user data leakage, endangering driving safety, overloading the vehicle network, and affecting the normal operation of the vehicle. The present application provides a network security detection method for an automobile. In the method, vehicle-side security event recording, collection and analysis can be performed on non-networked vehicles to avoid network security risks from the vehicles. The non-networking continuous detection scheme combined with the IDPS (Intrusion Detection and Prevention Systems) scheme can include all vehicles of the OEM (Original Equipment Manufacturer) in the continuous detection range, use the existing diagnostic path, and connect the existing diagnostic cloud and V-SOC (Vehicle Security Operations Center) cloud interface to realize continuous network security detection. Thus, the problems in the related art, such as the vehicle network system being threatened by hacking attacks, malicious software intrusion and other threats, which leads to serious consequences such as tampering of the vehicle control system, user data leakage, endangering driving safety, overloading the vehicle network, and affecting the normal operation of the vehicle, are solved.

[0031] The embodiments of the present application provide an implementation environment of a network security detection method for an automobile, which includes a vehicle, a diagnostic instrument, a CDMS (Cloud Diagnostic Management System) and a V-SOC platform. The vehicle is electrically connected to the diagnostic instrument, the diagnostic instrument is electrically connected to the CDMS, and the CDMS platform is electrically connected to the V-SOC platform.

[0032] The electrical connection includes at least one of a circuit connection and a wireless connection. If the electrical connection is a circuit connection, the connection mode can be a cable connection, such as a CAN (Controller Area Network) bus. If the electrical connection is a wireless connection, the connection mode can be an Ethernet connection, an infrared connection or a WiFi (Wireless Fidelity) network connection.

[0033] The diagnostic instrument is connected to the vehicle by being inserted into the OBD (On-Board Diagnostics) port of the vehicle.

[0034] Diagnostic instrument: It is a portable intelligent automobile self-checking instrument for detecting automobile log and fault. It can be used to quickly read the network security log in the automobile electric control system, display the log information through the liquid crystal display screen, and upload the network security log to the CDMS platform through the screen button. The embodiment of the application can insert the diagnostic instrument into the vehicle OBD port, enter the network security log function interface, start reading the magnet, and at the same time, the diagnostic instrument adds the vehicle VIN (Vehicle Identification Number) number and the log upload time to the network security log information, which is used to assist subsequent analysis and disposal.

[0035] CDMS platform: diagnostic backend service system, that is, diagnostic instrument cloud platform. The network security log read by the diagnostic instrument is uploaded to the CDMS platform, and the CDMS platform transmits the network security log to the VSOC platform.

[0036] V-SOC platform: responsible for accessing and analyzing the network security log data uploaded by CDMS, identifying possible security risks, and providing visual data display.

[0037] Among them, the CDMS platform can be at least one of a server, a server cluster composed of multiple servers, a cloud server, a cloud computing platform and a virtualization center. The V-SOC platform can be at least one of a server, a server cluster composed of multiple servers, a cloud server, a cloud computing platform and a virtualization center.

[0038] Specifically, FIG. 1 is a flowchart of a network security detection method for an automobile provided by an embodiment of the application.

[0039] As shown in FIG. 1, the network security detection method for the automobile includes the following steps:

[0040] In step S101, based on the network security damage impact assessment data and the attack feasibility assessment data of the automobile, the threat and risk analysis result of the automobile is generated.

[0041] It can be understood that the automobile in the embodiment of the application can be a non-networked automobile; the damage impact assessment in the embodiment of the application can be to determine the negative impact that may be caused by a security event, and the attack feasibility assessment can be the actual possibility of an attacker attacking using a specific vulnerability.

[0042] In actual execution process, as shown in FIG. 2, based on the network security damage impact assessment data and the attack feasibility assessment data of the automobile, the embodiment of the application can identify the key controller of the automobile network security, and generate the threat and risk analysis result of the automobile, so as to effectively identify and alleviate the potential threat and risk in the field of automobile network security.

[0043] The vehicle network security key controller in FIG. 2 is generally an important controller in the vehicle, such as a DMC (Digital Media Controller), a CGW (Central Gateway), and an ADCC (Autonomous Driving Control Computer). The vehicle network security key controller is usually a high-risk component obtained through vehicle network security analysis. When the vehicle component is subjected to a suspected network security attack, a network security event is triggered, and a diagnostic DID (Data Identifier) is recorded and stored in the controller. The network security key controller detection range is selected as follows:

[0044] Central Gateway (CGW): It is the core component of the vehicle network, responsible for the connection and management of the internal network of the vehicle, and is one of the most vulnerable targets of attack in the vehicle network, so it needs to be continuously detected.

[0045] Sound host (DMC): It is the control center of the vehicle infotainment system. The sound host is usually connected to external networks such as WiFi, Bluetooth, USB (Universal Serial Bus), etc., so it also needs to be continuously detected.

[0046] Autonomous driving controller (ADCC): It is a component closely related to safe driving, and needs to continuously ensure its normal operation and data integrity, so it also needs to be continuously detected.

[0047] In step S102, based on the threat and risk analysis results of the automobile, the network security log development range and the network security log format content of the automobile are determined, and it is judged whether the automobile triggers a network security event that meets the preset condition according to the network security log development range and the network security log format content.

[0048] It can be understood that the network security log format content in the embodiment of the application includes but is not limited to event occurrence time, event type, event occurrence reason and other related information; the network security event that meets the preset condition can be an abnormal event that triggers network security.

[0049] Among them, the embodiment of the application can define the network security log development range according to the network security key controller and its network security risk exposure surface based on the threat and risk analysis results of the automobile, and clearly define the format content of the network security log, and judge whether the automobile triggers a network security event that meets certain conditions according to the network security log development range and the network security log format content.

[0050] The embodiments of this application can implement a targeted response mechanism based on the judgment result, effectively detect and identify cybersecurity events in automobiles, and ensure vehicle cybersecurity.

[0051] Optionally, in one embodiment of this application, if the vehicle triggers at least one of the following: high-risk abnormal external connection records and detection data, controller resource usage, and suspected security event information, then the vehicle is determined to have triggered a network security event that meets preset conditions.

[0052] It is understood that the high-risk abnormal external connection records and detection data in the embodiments of this application usually involve unauthorized or abnormal external network connections and network security detection data; controller resource usage is an important indicator for evaluating system performance and stability; suspected security incident information usually involves behaviors or events that may threaten network security, but have not yet been confirmed as real security incidents.

[0053] In this embodiment of the application, when a vehicle triggers network security events such as high-risk abnormal external connection records and detection data (e.g., WiFi, Bluetooth, USB connection data), controller resource usage (e.g., CPU (Central Processing Unit) usage), memory usage and application processes, and suspected security event information (e.g., abnormal processes, configuration tampering, and firewalls), it determines that the vehicle has triggered a network security event that meets certain conditions.

[0054] This application embodiment, through the collection and analysis of high-risk abnormal external connection records and detection data, controller resource usage, and suspected security event information, not only helps to promptly detect and respond to potential security threats, but also provides strong protection for the long-term stable operation of the system.

[0055] It should be noted that the preset conditions can be set by those skilled in the art according to the actual situation, and no specific restrictions are imposed here.

[0056] In step S103, if the vehicle triggers a network security event that meets preset conditions, the vehicle's network security logs are diagnosed based on the vehicle's log development content, network security diagnostic data of the vehicle is generated, and network security logs are checked to generate network security detection results of the vehicle.

[0057] It is understood that the network security logs in this application embodiment can be diagnosed using the core controller on the vehicle side, read by a diagnostic tool and uploaded to the CDMS platform.

[0058] In actual implementation, this application embodiment can trigger and record the vehicle's network security logs based on the vehicle's log development content when the vehicle triggers a network security event that meets certain conditions, generate network security diagnostic data, and use a diagnostic tool to read the network security logs from the vehicle through the vehicle's OBD port and upload them to the CDMS platform to detect the network security logs and generate the vehicle's network security detection results.

[0059] In this embodiment, when a suspected cybersecurity incident or high-risk external connection occurs, the vehicle-side cybersecurity key controller records the event and stores it in the form of a diagnostic DID within the controller. Secure access control is designed for the log storage. The cybersecurity log includes the event type, cause, and time of the event, which can assist in subsequent cybersecurity incident analysis. When a cybersecurity incident occurs, the cybersecurity log stored on the vehicle side can be read via the vehicle's OBD port using a diagnostic tool. After successful reading, clicking the log upload button on the diagnostic tool screen uploads the vehicle-side cybersecurity log to the CDMS platform. The CDMS platform then transmits the received cybersecurity log to the V-SOC platform.

[0060] In other words, the diagnostic tool reads the cybersecurity logs stored on the vehicle through the vehicle's OBD port. After successful reading, it enters the cybersecurity log function interface, which includes a log upload button. When the log upload button is triggered, the read cybersecurity logs are uploaded to the CDMS platform, and the CDMS platform then transmits the received cybersecurity logs to the V-SOC platform.

[0061] This application embodiment can utilize existing diagnostic paths, connect existing diagnostic clouds with V-SOC cloud interfaces, and achieve continuous network security detection, solving the problems of recording, collecting, and analyzing network security incidents of non-connected vehicles, as well as the compliance issues of non-connected vehicles going global.

[0062] Optionally, in one embodiment of this application, after generating the network security detection result of the vehicle, the method further includes: detecting the network security log of the vehicle based on the network security detection result to generate detection data of the vehicle; generating at least one acoustic alarm action and / or at least one optical alarm action of the vehicle based on the detection data, and executing at least one acoustic alarm action and / or at least one optical alarm action to alert the driver to the network security status of the vehicle.

[0063] It is understood that, in the embodiments of this application, at least one acoustic alarm action can be a sound alarm from the vehicle horn, and at least one optical alarm action can be a flashing alarm from the vehicle display screen.

[0064] In actual implementation, after receiving network security logs from the diagnostic tool, the CDMS platform in this embodiment can directly transmit the network security logs to the V-SOC. The V-SOC platform develops a parsing dictionary based on the diagnostic DID content. When receiving network security logs, it can parse and issue alarms according to the defined parsing dictionary. Based on the network security detection results, this embodiment detects the vehicle's network security logs to generate vehicle detection data. Based on the detection data, it executes at least one acoustic alarm action and / or at least one optical alarm action to alert the driver to the vehicle's network security status.

[0065] This application embodiment can utilize the V-SOC platform to receive network security logs from the vehicle via the CDMS platform. The security analysis engine of the V-SOC platform can perform security detection and analysis on the received network security logs, and issue alarms based on the operational configuration after detecting anomalies, thereby solving the problems of recording, collecting, and analyzing network security events of non-connected vehicles and the compliance issues of non-connected vehicles going overseas.

[0066] Optionally, in one embodiment of this application, diagnosing the vehicle's cybersecurity logs based on the vehicle's log development content to generate vehicle cybersecurity diagnostic data includes: extracting timestamp information from the cybersecurity logs based on the vehicle's log development content, and determining the time information of the cybersecurity logs based on the timestamp information; identifying the event types of the cybersecurity logs and checking the actual operation results recorded in the cybersecurity logs; and generating vehicle cybersecurity diagnostic data based on the time information, event types, and actual operation results of the cybersecurity logs.

[0067] It is understood that the timestamp in this application embodiment is an important identifier for recording the time when an event occurs, which helps to determine the specific time of occurrence; this application embodiment can use a diagnostic instrument to diagnose network security logs.

[0068] In actual implementation, this application embodiment can extract timestamp information from the network security log based on the content of the vehicle's logs, and determine the time information of the network security log based on the timestamp information. This application embodiment can identify the event type of the network security log. Clarifying the event type helps to quickly locate possible security threats or vulnerabilities, and check the actual operation results recorded in the network security log to verify the result of each network security event, such as whether an unauthorized access attempt was successfully blocked, or whether any data leakage occurred.

[0069] In one possible implementation, the diagnostic tool reads the network security logs stored on the vehicle and, based on the log content, diagnoses the vehicle's network security logs to generate network security diagnostic data. When the diagnostic tool uploads the network security logs to the CDMS platform, it also uploads the network security diagnostic data. Similarly, when the CDMS platform transmits the network security logs to the V-SOC platform, it can also transmit the network security diagnostic data.

[0070] In another possible implementation, the diagnostic tool uploads network security logs to the CDMS platform, the CDMS platform transmits the network security logs to the V-SOC platform, and the V-SOC platform diagnoses the vehicle's network security logs based on the content of the vehicle's logs to generate network security diagnostic data for the vehicle.

[0071] Based on cybersecurity diagnostic data, the V-SOC platform can effectively detect and manage the cybersecurity status of non-connected vehicles, ensuring that potential security threats can be detected and responded to in a timely manner even without a network connection.

[0072] The embodiments of this application can not only effectively improve the network security protection capabilities of vehicles, but also ensure the stability and reliability of the system, providing users with a safer and more reliable driving experience.

[0073] Optionally, in one embodiment of this application, detecting network security logs to generate a network security detection result for a vehicle includes: reading network security logs stored on the vehicle's end to generate network security reading data for the vehicle; uploading the network security reading data to generate an upload result, and detecting network security risks of the vehicle based on the upload result to generate risk warning information corresponding to the network security risks; and adjusting the risk assessment level of the vehicle based on the risk warning information to generate a network security detection result for the vehicle based on the risk assessment level.

[0074] It is understood that, in this embodiment of the application, the diagnostic tool can read the network security logs stored on the vehicle through the vehicle's OBD port, and the generated network security read data can be uploaded to the diagnostic cloud platform (CDMS).

[0075] In actual operation, the diagnostic tool can read the network security logs stored on the vehicle to generate network security read data, which is then uploaded to the CDMS platform. When uploading network security read data, it is crucial to ensure data security and integrity to prevent tampering or leakage. The CDMS platform transmits the network security read data to the V-SOC platform. The V-SOC platform analyzes the uploaded data to identify potential network security risks, such as unauthorized access, data breaches, and malware infections. In this embodiment, the V-SOC platform can detect network security risks, generate corresponding risk warnings, and adjust the vehicle's risk assessment level based on these warnings. This ensures timely detection and warnings of potential network security risks, generating network security detection results. Based on these results, the platform records the vehicle's network security status, identified risks, and corresponding mitigation measures in detail.

[0076] The automotive network security detection method proposed in this application can record, collect, and analyze vehicle-side security events for non-networked vehicles, mitigating network security risks from vehicles. This continuous non-networked detection solution, combined with the IDPS solution, can include all vehicles of the OEM within the scope of continuous detection. Utilizing existing diagnostic paths, it connects the existing diagnostic cloud with the V-SOC cloud interface to achieve continuous network security detection. This solves the problem in related technologies where vehicle network systems face various threats from hacker attacks and malware intrusions, leading to serious consequences such as vehicle control system tampering and user data leakage, endangering driving safety, causing in-vehicle network overload, and ultimately affecting the normal operation of the vehicle.

[0077] Next, with reference to the accompanying drawings, a cybersecurity detection device for automobiles according to an embodiment of this application is described.

[0078] Figure 3 is a schematic diagram of the structure of a vehicle network security detection device according to an embodiment of this application.

[0079] As shown in Figure 3, the network security detection device 10 for the car includes: a generation module 100, a judgment module 200, and a first detection module 300.

[0080] Specifically, the generation module 100 is used to generate threat and risk analysis results for automobiles based on cybersecurity damage impact assessment data and attack feasibility assessment data.

[0081] The judgment module 200 is used to determine the scope of development and format of network security logs for the vehicle based on the threat and risk analysis results of the vehicle, and to determine whether the vehicle has triggered a network security event that meets preset conditions based on the scope of development and format of the network security logs.

[0082] The first detection module 300 is used to diagnose the vehicle's network security logs based on the content of the vehicle's logs when the vehicle triggers a network security event that meets preset conditions, generate network security diagnostic data for the vehicle, and detect the network security logs to generate network security detection results for the vehicle.

[0083] Optionally, in one embodiment of this application, the vehicle network security detection device 10 further includes a second detection module and a prompting module.

[0084] The second detection module is used to detect the vehicle's network security logs based on the network security detection results, in order to generate vehicle detection data.

[0085] The alert module is used to generate at least one acoustic alarm action and / or at least one optical alarm action for the vehicle based on the detection data, and to execute at least one acoustic alarm action and / or at least one optical alarm action to alert the driver to the vehicle's cybersecurity status.

[0086] Optionally, in one embodiment of this application, the first detection module 300 includes: an extraction unit, an inspection unit, and a generation unit.

[0087] The extraction unit is used to develop content based on vehicle logs, extract timestamp information from network security logs, and determine the time information of network security logs based on the timestamp information.

[0088] The inspection unit is used to identify the event types in the network security logs and to inspect the actual operational results recorded in the network security logs.

[0089] The generation unit is used to generate cybersecurity diagnostic data for the vehicle based on the time information, event type, and actual operation results of the cybersecurity logs.

[0090] Optionally, in one embodiment of this application, the first detection module 300 includes: a reading unit, an uploading unit, and a detection unit.

[0091] The reading unit is used to read the network security logs stored on the vehicle's end to generate network security reading data for the vehicle.

[0092] The upload unit is used to upload network security read data to generate upload results, and to detect network security risks of the vehicle based on the upload results to generate risk warning information corresponding to the network security risks.

[0093] The detection unit is used to adjust the risk assessment level of the vehicle based on the risk warning information, and to generate the vehicle's cybersecurity detection results based on the risk assessment level.

[0094] Optionally, in one embodiment of this application, the vehicle network security detection device 10 further includes a determination module.

[0095] The determination module is used to determine whether a vehicle has triggered a cybersecurity event that meets preset conditions if at least one of the following is found: high-risk abnormal external connection records and detection data, controller resource usage, and suspected security event information.

[0096] It should be noted that the foregoing explanation of the embodiment of the vehicle network security detection method also applies to the vehicle network security detection device of this embodiment, and will not be repeated here.

[0097] The automotive network security detection device proposed in this application can record, collect, and analyze vehicle-side security events for non-networked vehicles, mitigating network security risks from vehicles. This continuous non-networked detection solution, combined with the IDPS solution, can include all vehicles of the OEM within the scope of continuous detection. Utilizing existing diagnostic paths, it connects the existing diagnostic cloud with the V-SOC cloud interface to achieve continuous network security detection. This solves the problem in related technologies where vehicle network systems face various threats from hacker attacks and malware intrusions, leading to serious consequences such as vehicle control system tampering and user data leakage, endangering driving safety, causing in-vehicle network overload, and ultimately affecting the normal operation of the vehicle.

[0098] Figure 4 is a structural schematic diagram of a vehicle provided in an embodiment of this application. The vehicle may include:

[0099] The memory 401, the processor 402, and the computer program stored on the memory 401 and capable of running on the processor 402.

[0100] When processor 402 executes the program, it implements the vehicle network security detection method provided in the above embodiments.

[0101] Furthermore, the vehicle also includes:

[0102] Communication interface 403 is used for communication between memory 401 and processor 402.

[0103] The memory 401 is used to store computer programs that can run on the processor 402.

[0104] The memory 401 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.

[0105] If the memory 401, processor 402, and communication interface 403 are implemented independently, they can be interconnected via a bus to communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, only one thick line is used in Figure 4, but this does not imply that there is only one bus or one type of bus.

[0106] Optionally, in a specific implementation, if the memory 401, processor 402, and communication interface 403 are integrated on a single chip, then the memory 401, processor 402, and communication interface 403 can communicate with each other through an internal interface.

[0107] Processor 402 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application.

[0108] Figure 5 is a schematic diagram of the structure of the electronic device provided in the embodiment of this application. The electronic device can be a diagnostic instrument, a CDMS platform, or a V-SOC platform, and there is no specific limitation thereto.

[0109] The electronic device 500 can vary considerably depending on its configuration or performance. It may include a central processing unit (CPU) 501 and a memory 502. The memory 502 stores at least one line of program code, which is loaded and executed by the processor 501 to implement the vehicle network security detection method provided in the above embodiments. Of course, the electronic device 500 may also have wired or wireless network interfaces, a keyboard, and input / output interfaces for input and output. The electronic device 500 may also include other components for implementing device functions, which will not be elaborated upon here.

[0110] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the above-described vehicle network security detection method.

[0111] This application also provides a computer program product that stores at least one piece of program code, which is loaded and executed by a processor to implement the vehicle network security detection method in the above embodiments.

[0112] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0113] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "N" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0114] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or N executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.

[0115] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.

[0116] It should be understood that the various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, the N steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0117] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0118] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0119] The storage medium mentioned above can be a read-only memory, a disk, or an optical disk, etc. Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.

Claims

1. A method for detecting cybersecurity issues in automobiles, wherein, The method includes: Based on cybersecurity damage impact assessment data and attack feasibility assessment data of the vehicle, threat and risk analysis results of the vehicle are generated; Based on the threat and risk analysis results of the vehicle, the development scope and format of the network security log for the vehicle are determined, and based on the development scope and format of the network security log, it is determined whether the vehicle has triggered a network security event that meets preset conditions. If the vehicle triggers a network security event that meets the preset conditions, then based on the content of the vehicle's log development, the vehicle's network security log is diagnosed, network security diagnostic data of the vehicle is generated, and the network security log is detected to generate network security detection results of the vehicle.

2. The method according to claim 1, wherein, The method further includes: Based on the network security detection results, the network security logs of the vehicle are detected to generate detection data for the vehicle; Based on the detection data, at least one acoustic alarm action and / or at least one optical alarm action of the vehicle are generated, and the at least one acoustic alarm action and / or the at least one optical alarm action are executed to alert the driver to the network security status of the vehicle.

3. The method according to claim 1, wherein, The step of developing and diagnosing the vehicle's network security logs based on the vehicle's log content, and generating network security diagnostic data for the vehicle, includes: Based on the log content of the vehicle, the timestamp information in the network security log is extracted, and the time information of the network security log is determined according to the timestamp information. Identify the event type in the network security logs and examine the actual operation results recorded in the network security logs; Based on the time information of the network security logs, the event type, and the actual operation results, network security diagnostic data for the vehicle is generated.

4. The method according to claim 1, wherein, The process of detecting the network security logs to generate network security detection results for the vehicle includes: Read the network security logs stored on the vehicle's end to generate network security read data for the vehicle; The network security read data is uploaded to generate an upload result, and based on the upload result, the network security risks of the vehicle are detected to generate risk warning information corresponding to the network security risks. Based on the risk warning information, the risk assessment level of the vehicle is adjusted, and a cybersecurity detection result for the vehicle is generated based on the risk assessment level.

5. The method according to claim 1, wherein, The method further includes: If the vehicle triggers at least one of the following: high-risk abnormal external connection records and detection data, controller resource usage, and suspected security event information, then the vehicle is determined to have triggered a network security event that meets the preset conditions.

6. A cybersecurity detection device for automobiles, wherein, The device includes: The generation module is used to generate threat and risk analysis results for the vehicle based on cybersecurity damage impact assessment data and attack feasibility assessment data. The judgment module is used to determine the scope of network security log development and the format and content of network security logs for the vehicle based on the threat and risk analysis results of the vehicle, and to determine whether the vehicle has triggered a network security event that meets preset conditions based on the scope of network security log development and the format and content of the network security logs. The first detection module is used to, when the vehicle triggers a network security event that meets preset conditions, diagnose the vehicle's network security logs based on the log development content of the vehicle, generate network security diagnostic data for the vehicle, and detect the network security logs to generate network security detection results for the vehicle.

7. The apparatus according to claim 6, wherein, The device further includes: The second detection module is used to detect the network security logs of the vehicle based on the network security detection results, so as to generate detection data for the vehicle. The alert module is configured to generate at least one acoustic alarm action and / or at least one optical alarm action for the vehicle based on the detection data, and execute the at least one acoustic alarm action and / or the at least one optical alarm action to alert the driver to the network security status of the vehicle.

8. The apparatus according to claim 6, wherein, The first detection module includes: The extraction unit is used to extract timestamp information from the network security log based on the log development content of the vehicle, and determine the time information of the network security log according to the timestamp information; The inspection unit is used to identify the event type of the network security log and inspect the actual operation results recorded in the network security log; The generation unit is used to generate network security diagnostic data for the vehicle based on the time information of the network security log, the event type, and the actual operation result.

9. The apparatus according to claim 6, wherein, The first detection module includes: A reading unit is used to read the network security logs stored on the vehicle's terminal to generate network security reading data for the vehicle. An upload unit is used to upload the network security read data to generate an upload result, and based on the upload result, detect the network security risks of the vehicle to generate risk warning information corresponding to the network security risks; The detection unit is used to adjust the risk assessment level of the vehicle based on the risk warning information, so as to generate the network security detection result of the vehicle based on the risk assessment level.

10. The apparatus according to claim 6, wherein, The device further includes: The determination module is used to determine that the vehicle has triggered a network security event that meets preset conditions if the vehicle triggers at least one of the following: high-risk abnormal external connection records and detection data, controller resource usage, and suspected security event information.

11. A vehicle, wherein, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, the processor executing the program to implement the cybersecurity detection method for a vehicle as described in any one of claims 1-5.

12. An electronic device, wherein, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, the processor executing the program to implement the cybersecurity detection method for a vehicle as described in any one of claims 1-5.

13. A computer-readable storage medium having a computer program stored thereon, wherein, The program is executed by the processor to implement the cybersecurity detection method for automobiles as described in any one of claims 1-5.

14. A computer program product, wherein, The computer program product stores at least one piece of program code, which is loaded and executed by a processor to implement the vehicle network security detection method as described in any one of claims 1-5.