IoV Security Alarm Standardization and Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network security defense systems face challenges in effectively monitoring and responding to new network security threats, particularly in intelligent traffic and autonomous driving scenarios, where accurate and timely detection of attack behaviors is crucial.
Innovation Solution
A method and apparatus for processing security information that standardizes security alarm data, determines similarity with attack behavior knowledge base data, and updates security information based on this similarity, utilizing a threat analysis platform and attack behavior knowledge base to enhance the accuracy of threat detection and response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network security defense systems are used, then basic protection capabilities are maintained, but monitoring and response effectiveness deteriorate under new network security threats
Solution Approach 1:
The system performs preliminary actions by pre-processing security alarm information through standardization and building an attack behavior knowledge base in advance. This allows the system to quickly match and respond to new threats without extensive real-time analysis, improving monitoring and response efficiency while maintaining defense reliability
Solution Approach 2:
The system implements feedback mechanisms by continuously updating the attack behavior knowledge base based on analyzed security alarms and attack patterns. This feedback loop enables the system to learn from new threats and improve its monitoring and response capabilities over time, addressing the effectiveness deterioration under evolving threats
2Measurement precision
If security alarm information is processed without standardization, then processing speed is maintained, but detection accuracy deteriorates
Solution Approach 1:
The system performs standardization processing on security alarm information as a preliminary action before analysis. By standardizing data formats, fields, and structures in advance, the system ensures high detection accuracy when comparing against the attack behavior knowledge base without significant time loss during critical analysis phases
3Reliability
If comprehensive attack analysis is performed on all security alarms, then detection completeness is improved, but system complexity increases
Solution Approach 1:
The system segments the security analysis process into distinct modules: standardization module, similarity determination module, and knowledge base update module. This segmentation allows comprehensive attack analysis to be performed through coordinated simple operations in each module, maintaining detection completeness while managing system complexity through modular architecture
Solution Approach 2:
The attack behavior knowledge base serves as an intermediary between raw security alarms and detection results. It mediates the analysis process by storing pre-analyzed attack patterns and serving as a reference for similarity comparison, enabling comprehensive detection without requiring complex real-time analysis of every alarm
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A method of processing security information, a device, a storage medium and a computer program are provided, which are related to a field of computer technology, and in particular to a field of Internet of Vehicles and a field of information security technology. The method includes standardizing a security alarm information for a target device to obtain standardization data; determining a similarity between the standardization data and attack data in an attack behavior knowledge base; and updating a security information of the target device according to the similarity.