This invention provides an
attack detection method, apparatus, and electronic device, applied in the field of vehicle
network security technology. The invention acquires anchor messages configured with deadlines, collects the number of arbitration failures, queuing time, and actual
transmission time during the transmission process, calculates the queuing
waiting time, and generates a deadline violation indicator based on the deadline. Multiple transmission samples are aggregated within a specified sliding window, and a
fingerprint vector reflecting the
bus resource contention status is generated based on the above parameters. This
fingerprint vector is compared with a pre-built adaptive baseline to obtain an anomaly
score. When the anomaly
score exceeds a preset threshold, a disguised high-priority
flooding attack is identified. This invention improves the accuracy and robustness of
attack detection by monitoring underlying
resource contention characteristics and accurately identifying anomalies caused by disguised high-priority attacks.