IoV Security Alarm Standardization and Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network security defense systems face challenges in effectively monitoring and responding to new network security threats, particularly in intelligent traffic and autonomous driving scenarios, where accurate and timely detection of attack behaviors is crucial.

Innovation Solution

A method and apparatus for processing security information that standardizes security alarm data, determines similarity with attack behavior knowledge base data, and updates security information based on this similarity, utilizing a threat analysis platform and attack behavior knowledge base to enhance the accuracy of threat detection and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security defense systems are used, then basic protection capabilities are maintained, but monitoring and response effectiveness deteriorate under new network security threats

Engineering Contradiction:
Improvesecurity defense reliabilityVSAvoidmonitoring and response efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-processing security alarm information through standardization and building an attack behavior knowledge base in advance. This allows the system to quickly match and respond to new threats without extensive real-time analysis, improving monitoring and response efficiency while maintaining defense reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously updating the attack behavior knowledge base based on analyzed security alarms and attack patterns. This feedback loop enables the system to learn from new threats and improve its monitoring and response capabilities over time, addressing the effectiveness deterioration under evolving threats

Inventive Principle:
Principle #23Feedback

2Measurement precision

If security alarm information is processed without standardization, then processing speed is maintained, but detection accuracy deteriorates

Engineering Contradiction:
Improveattack behavior detection accuracyVSAvoidinformation processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs standardization processing on security alarm information as a preliminary action before analysis. By standardizing data formats, fields, and structures in advance, the system ensures high detection accuracy when comparing against the attack behavior knowledge base without significant time loss during critical analysis phases

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive attack analysis is performed on all security alarms, then detection completeness is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection completenessVSAvoidanalysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the security analysis process into distinct modules: standardization module, similarity determination module, and knowledge base update module. This segmentation allows comprehensive attack analysis to be performed through coordinated simple operations in each module, maintaining detection completeness while managing system complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The attack behavior knowledge base serves as an intermediary between raw security alarms and detection results. It mediates the analysis process by storing pre-analyzed attack patterns and serving as a reference for similarity comparison, enabling comprehensive detection without requiring complex real-time analysis of every alarm

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4102772B1Method and apparatus of processing security information, device and storage medium
Publication Date: 2023.12.27 APOLLO INTELLIGENT CONNECTIVITY (BEIJING) TECH CO LTD
  • EP4102772B1 patent drawingFigure 1
  • EP4102772B1 patent drawingFigure 2~3
  • EP4102772B1 patent drawingFigure 4

AI summary

A method of processing security information, a device, a storage medium and a computer program are provided, which are related to a field of computer technology, and in particular to a field of Internet of Vehicles and a field of information security technology. The method includes standardizing a security alarm information for a target device to obtain standardization data; determining a similarity between the standardization data and attack data in an attack behavior knowledge base; and updating a security information of the target device according to the similarity.