封面
市場調查報告書
商品編碼
2109330

汽車網路安全與資料安全市場(2026 年)

Automotive Cybersecurity and Data Security Research Report, 2026

出版日期: | 出版商: ResearchInChina | 英文 400 Pages | 商品交期: 最快1-2個工作天內

價格
簡介目錄

網路安全與資料安全調查-智慧互聯汽車進入系統性攻防和人工智慧主導的安全時代。

本報告整體情況了2026年智慧聯網汽車的網路安全和資料安全,分析了車輛各環節的攻擊場景、人工智慧帶來的攻擊面擴大、當前漏洞分析、全鏈路防護系統、資料分類與評級以及跨境合規等核心主題。此外,該報告還透過對保全服務,系統性地介紹了合規認證、技術應用和供應鏈安全管治的最新產業發展。此外,該報告還指出了將人工智慧引入汽車所帶來的新風險(例如供應鏈篡改和快速劫持),總結了智慧聯網汽車的安全解決方案,並預測了行業發展趨勢。

重點

以政策為導向的合規改進-從透過檢查到系統實施。

供應鏈漏洞頻繁-安全管治必須涵蓋所有領域和整個生命週期。

人工智慧是一把雙面刃——攻擊目標區域擴展到了有意層面,因此需要「人工智慧對抗人工智慧」的防禦方法。

網路安全正從被動應對轉變為主動威脅搜尋。

資料安全正從隱私合規轉向全環節管治,跨國資料管理正成為一項至關重要的挑戰。

安全保障需要從成本中心轉變為核心競爭優勢。

2026年,智慧網聯汽車(ICV)產業正處於關鍵的轉捩點。一方面,以GB 44495/44496為代表的國家強制性標準的全面實施,標誌著該行業正式從合規探索階段過渡到全面合規管理階段。另一方面,大規模人工智慧模型在車輛中的部署以及跨境資料流的規範化,正在迅速擴大車輛的攻擊面,帶來前所未有的安全挑戰。對於汽車製造商而言,僅僅被動地採取合規措施或單一防御手段已不足以應對複雜的網路威脅。如今,亟需轉向覆蓋整個生命週期和供應鏈的系統性攻防策略,並輔以人工智慧驅動的主動防禦。

一、以政策為導向的高級合規性—從「通過檢查」到系統性實施

2026年,中國汽車網路安全和資料安全法律規範形成封閉回路型。基於GB 44495-2024「汽車網路安全技術要求」和GB 44496-2024「汽車軟體更新通用技術要求」等強制性標準,以及「汽車資料境外傳輸安全指南(2026年版)」的實施,汽車製造商的合規要求從以往的建議性參考標準提升為可強制執行的最低規則。企業需要全面調整其安全策略、組織結構和營運流程。

此外,監管機構正透過巨額罰款來強制執行相關法規。 2026年5月,歐洲資料保護機構對叫車應用Yango的營運商處以1億歐元(約8.01億元)的罰款,原因是其在未採取歐盟法律規定的保護措施的情況下,將用戶個人資料傳輸至俄羅斯。同月,通用汽車(GM)因未經用戶同意收集和出售駕駛資料而被罰款約9,000萬元。這是自「加州消費者隱私法案」(CCPA)實施以來最大的一筆罰款。這些處罰背後的邏輯顯而易見:數據並非汽車製造商可以隨意取得和出售的資產。

面對監管的巨大壓力,各大汽車製造商正加速從被動合規轉向主動風險防範與管理。賽瑞斯(Seres)就是一個典型的例子。該公司建構了涵蓋「雲端、管、端、晶片」的多層防禦體系,成為中國首家獲得「汽車資料安全管理體系認證」和「國家資料安全成熟度模型(DSMM)3級認證」的企業,展現了其業界領先的系統化安全能力。同時,比亞迪正利用其自主研發的「iDDog」智慧安全平台,遵循「資料旁路、淨化、啟動」三階段邏輯,打破資料孤島,建構高品質的資料基礎架構。比亞迪還引入了三個關鍵人工智慧代理,以提升保全行動效率,並將合規要求轉化為強大的營運能力。由中國汽車工業協會(CAAM)主導的「五大合規檢查」持續推進,第三階段共有13家企業的49款車型通過檢查,第四階段共有9家企業的43款車型通過檢查。對車輛外部收集的人臉資料進行匿名化處理以及對車輛內部駕駛座資料進行處理等要求,正在成為行業標準配置。

事實證明,合規只是起點。將安全能力轉化為永續的營運優勢,才是企業在產業週期中保持競爭優勢的關鍵。

二、頻繁發生的供應鏈安全漏洞事件-安全管治必須涵蓋所有領域和整個生命週期。

如果問汽車產業在2025年將面臨的最慘痛的教訓是什麼,答案很可能是:「攻擊者將不再嘗試暴力破解來滲透系統,而是會透過可信的合作夥伴管道進行滲透。」智慧聯網汽車的供應鏈極其複雜,任何一個環節的漏洞都可能造成災難性後果,就像蟻巢導致水壩決堤一樣。

2025年3月,駭客「Rey」在暗網上洩漏了約700份捷豹路虎內部文件,包括原始碼、開發日誌和員工資料庫——但這只是開始。同年8月,駭客組織「Scattered Lapsus$Hunters」入侵了捷豹路虎的全球生產系統,迫使其英國工廠全面停產,33,000名員工被迫休假。同樣在8月,日產汽車的一家設計子公司遭到駭客組織「麒麟」的勒索軟體攻擊,導致4TB核心設計資料被竊。雲端儲存服務供應商Snowflake也遭到入侵,對包括汽車零件零售商Advance Auto Parts在內的165家下游公司造成了間接損失。到2025年底,全球領先的線束製造商矢崎集團(Yazaki Group)遭遇勒索軟體攻擊,350GB資料被盜,其中包括供應給寶馬和日產的零件的完整文件。泰國OEM廠商TRU的案例就是一個更典型的例子。該公司1TB的資料被盜,ESXi伺服器遭到加密攻擊,ERP和物流系統全面癱瘓,部分生產線被迫轉為人工排程。

綜合考慮這些事件,攻擊模式出現了三個明顯的變化:

明確目標-攻擊者正在升級他們的攻擊手段,從簡單的資料竊取發展到智慧財產權外洩和直接擾亂生產活動;

針對供應鏈的攻擊途徑-超過一半的攻擊事件都是透過雲端服務供應商、IT 子公司和第三方供應商間接進行的,這使得供應鏈成為最脆弱的部分;

定向勒索軟體-惡意攻擊者專門針對藍圖等高價值資料。

這些暴露出的漏洞促使各行業加強因應措施。汽車製造商被普遍認為是供應鏈安全的主要責任方,並透過簽署網路安全介面協議(CIA)將責任轉移給一級供應商。 ISO/SAE 21434認證已成為一級供應商的強制性准入要求;沒有這份「安全信用證」,企業無法進入核心供應鏈。對於目標市場為歐洲的企業而言,TISAX認證是不可避免的。然而,整體情況仍是「大型OEM廠商引領主導,而中小供應商則落後於人」。對於中小規模的二級和三級供應商,大多數汽車製造商僅進行文件審核,現場檢驗覆蓋率極低,且可追溯鏈不完整。

建構涵蓋所有領域和全生命週期的供應鏈安全系統已成為業界通用。吉利在這方面樹立了標竿。該公司建立了國內首批獲得CNAS認證的車聯網網路安全實驗室之一,從攻擊者的觀點出發,在系統安全、通訊安全和資料安全等12個關鍵測試領域開展了200多項常規測試,並將研究成果反饋到其領先的研發流程中。 2025年12月,吉利正式推出了「全球全局安全中心」和「全球安全2.0」技術體系。此2.0體系將安全觀點從「整車安全」擴展到「人、車、路、雲、衛星」的生態系統觀點。在保障生命安全、健康安全、財產安全和隱私安全四大核心安全領域的基礎上,該體系迭代升級九大關鍵安全系統,建構覆蓋所有場景和生命週期的安全防護網路。

同時,供應鏈製造商的安全合規性評估也在不斷完善,並引入了以下嚴格要求:第三方組件不得包含六個月前已披露但尚未修復的高風險漏洞;高風險漏洞必須在72小時內修復並重新檢驗;OTAOTA包必須使用OEM廠商的密鑰進行簽名,在某些終端下,還需要識別供應商和OEM機包必須更新包例如,Seres已將其一級供應商數量從300家減少到100家,並與寧德時代和博世建立了深度整合的安全合作夥伴關係,從而將安全管理範圍縮小到可控水平。例如,在底層硬體層面,ThinkTech 的 Alioth TTA8 系列 MCU 整合了 ASIL-D 功能安全標準和 EVITA FULL 網路安全,填補了國內底盤領域主控晶片的空白,並確保了從源頭對供應鏈的獨立控制和安全。

供應鏈安全的本質在於將安全邊界從「我們自己的車輛」擴展到「車輛內的所有代碼、所有晶片以及所有供應商」。涵蓋整個領域和整個生命週期至關重要,任何一個環節都不可忽視。

三、人工智慧是一把雙面刃——攻擊目標區域已擴展到意圖層面,防禦需要「用人工智慧對抗人工智慧」。

將大規模模型引入車輛不僅帶來了駕駛座,也帶來了全新的攻擊維度。人工智慧特有的風險,例如供應鏈污染、快速劫持和過度代理,正迅速轉移到車輛終端。隨著車輛中的大規模模型連接到導航、支付、充電和車輛控制等工具鏈,原本僅限於雲端聊天機器人的攻擊鏈可以直接移植到車輛上。尤其是在多控制器平台(MCP)連接生態系統中,工具投毒等高風險攻擊途徑直接威脅著運行Linux或Android系統的車載資訊娛樂系統(IVI)。

新型智慧體,例如 OpenClaw,擅長利用高階的系統權限,形成從理解意圖到完成任務的封閉回路型。然而,在汽車環境中,這意味著系統中存在持久的數位實體,它們擁有對車輛資料的部分進入許可權以及呼叫車輛控制命令的權限。提示注入可能導致智慧體執行非預期操作。篡改過的第三方導航插件可能充當持久的特洛伊木馬,洩漏駕駛習慣。此外,問答場景中看似無害的「幻覺」也可能升級為危險操作,例如在代理場景中刪除關鍵資料。更棘手的是監管方面的矛盾。 ISO 26262、UN R155/R156 和 GB 44495 等標準要求系統行為具有確定性、可預測性、檢驗和可追溯性,而智慧體本質上是非確定性的,並具有湧現特性。行業解決方案是「授予權限而非完全委託」。換句話說,權限沙箱和功能性隔離機制的實施,旨在將智慧體的活動限制在資訊娛樂系統和其他低風險區域。所有車輛控制請求都必須經過安全中間件層的仲裁。高風險操作也會透過人機介面 (HMI) 進行審查,確保所有安全關鍵決策都由人們參與。

隨著攻擊目標不斷演變,防禦機制也必須隨之進化。業界的解決方案很明確:以人工智慧對抗人工智慧。

面對人工智慧帶來的「長矛」,業界必須構築更鋒利的「盾牌」。例如,安霸科技為智慧網聯汽車(ICV)建構了全新的安全範式,即「人工智慧驅動的大規模模型保護+車輛通訊協定安全+閉合迴路供應鏈安全」。這使得安全功能從傳統的事後修補轉變為貫穿整個生命週期的主動管治:

該平台利用大規模模型,透過自然語言分析整車電子電氣架構文件、跨模型資料庫和車輛安全營運中心(VSOC)資產清單,自動識別電子控制單元(ECU)、感測器、通訊介面和其他關鍵資產,並將它們映射到資產關聯框架中。基於LLM的智慧型TARA平台能夠自動產生安全目標、安全需求、威脅場景和攻擊向量,從而實現自動化、視覺化的風險評估。

在風險緩解過程中,該平台結合影響嚴重性、攻擊可行性和風險評估矩陣,自動產生糾正措施決策並發出工作指示。這創建了一個「AI檢測—AI分析—AI決策—AI封閉回路型」的運行工作流程,顯著縮短了車輛安全評估週期。

QAX AISOC 是這種方法的典型範例。該系統包含八個代理,分別負責八個操作環節:資料收集、威脅偵測、智慧決策、智慧調查、智慧回應、事件遏制、最佳化回饋和報告產生。基於 OODA 循環,它建立了一個自主防禦系統,將保全行動從「主導威脅搜尋」轉變為「自動化威脅通知」。經過驗證的數據表明,一家全球豪華汽車製造商在部署 AISOC 後,將單一警報的分析和評估時間縮短至 9 秒以內,有效警報識別準確率達到 93.1%,與傳統的人工模式相比,性能提升了 2.7 倍。

傳統的安全分析流程 TARA 也正在利用人工智慧進行重構。 GoGoByte DefenseWeaver 整合了 GoGoAI 智慧體,將所有新的風險向量納入 TARA 的分析範圍,包括模型、訓練和推理資料、快速入口點、知識庫以及工具呼叫鏈。該工具能夠識別出風險不僅來自程式碼漏洞,還來自錯誤的模型、受污染的資料以及工具的誤用。一汽奔騰、立訊精密等客戶以及中國汽車技術研究院(CATARC)、招商局汽車技術研究院、中國汽車技術研究院(CEPREI)等國家級檢測機構都在使用該工具,其效率提升了 80%。 Callisto S3-TARA 則採用了不同的方法。超過 10 個智慧體協同工作,從 16 個候選的「思維鏈(CoT)」中選擇最佳解決方案。這得益於一個資料基礎,該基礎建立在超過 10 萬個因果鏈資料集、超過 300 萬個安全場景樣本和超過 100 萬個知識庫問答對之上。

汽車製造商也並未袖手旁觀。比亞迪的iDDog平台部署了三個人工智慧代理,分別針對電子郵件釣魚、設備資料外洩和異常流量,將安全事件的回應時間從45分鐘縮短至5分鐘。理想汽車與Volcano Engine合作開發了一款人工智慧助手,該助手在飛書群聊中接收指令後,可以自動產生工單、掃描碼、修復漏洞並進行檢驗。這實現了一站式、閉合迴路的解決方案流程,並最終由人工審核。人工智慧正在從最初的概念口號轉變為日常保全行動的一部分。

IV. 網路安全正從被動應對轉變為主動威脅搜尋。

在網路安全領域,傳統的被動防禦策略已無法應對快速演進的攻擊手段。光是2025年,就記錄了206起汽車安全事件和238個新的漏洞。威脅行為者正不斷升級其目標,從資料竊取到智慧財產權洩露,甚至直接擾亂生產製造營運。因此,汽車製造商必須建立具備主動威脅搜尋能力的、可操作的網路安全系統,涵蓋威脅偵測、分析、回應和修復。

安全專家提案的解決方案在於系統化防禦。 Seres部署了名為「雲端管道設備晶片」的多層深度防禦架構,並與QAX合作,在CAN總線、車載主機和乙太網路層實現了入侵偵測系統。該公司的VSOC平台監控約20萬輛汽車,並為出口到歐盟的車型頒發「網路安全合規證書」。其智慧安全系統涵蓋200多種車輛使用情境和400多項安全功能。 2026年4月,他們發布了「安全4.0」,實現了從被動安全和主動安全向智慧安全的演進。

專業安防服務供應商也在升級其工具包。 ACT VSOC+,這款新一代智慧連網車輛(ICV)保全行動平台,正是此理念的體現。它配備了AI流式運算引擎,威脅偵測性能提升500%,並基於超過2800個車輛訊號建構車輛安全數位孿生模型。此外,它還能從ECU、訊號和場景三個方面精準辨識威脅,將威脅偵測和回應週期從數天縮短至數分鐘。

在底層協定安全層,TICPSH 的「SmartRocket TestSec」是一款自動化智慧模糊滲透測試工具,可對 SOME/IP、DoIP 和 CAN/CAN FD 等主要車輛協定執行深度模糊攻擊和滲透測試,主動發現潛在漏洞,並將安全防線推進到研發 (R&D) 測試階段。 UniSentry Intelligent Technology 的 SecIC-HSM韌體已被約 30 家 OEM 廠商採用,在英飛凌 AURIX TC4X 上實現了 4.8Gbps 的 AES 吞吐量,從而能夠在不中斷 CAN 總線傳輸的情況下並行車載檢驗和安全車輛通訊 (SecOC) 更新。這些解決方案可協助汽車製造商從單純的合規轉向主動安全防護。

OEM廠商和供應商已達成共識,認為孤立的、獨立的安全產品無法解決系統性安全問題,而多層深度防禦和主動免疫系統才是正確的解決方案。

五、資料安全正從隱私合規轉向全鏈管治,跨國資料管理正成為一項重要的挑戰。

數據是智慧汽車的「命脈」,其安全貫穿整個生命週期:收集、傳輸、儲存、使用、共用和處置。汽車資料安全的獨特之處在於,資料直接支援感知訓練、地圖服務、模型迭代、遠端控制和事故溯源,同時兼具隱私性和合規性。不當的資料收集、傳輸、使用或篡改不僅會導致監管罰款,還會對車輛性能產生負面影響。

2026年2月3日,包括工業和資訊化部、國家電腦網路空間辦公室在內的八個部會聯合發布了「汽車資料境外傳輸安全指導意見(2026年版)」。該指導意見將境外傳輸的資料分為「一般」、「重要」和「機密」三類,並定義了九種豁免場景,包括品質保證和維護資料、OTA更新資料以及安全漏洞修復文件等。此外,該指導意見還明確了通知標準,要求企業在境外傳輸「重要」數據,或向境外營業單位共用超過100萬個人的個人資訊或超過1萬個機密資訊時,必須進行跨境數據傳輸安全評估。對於2026年上半年出口年增65.3%的中國汽車產業而言,該指導意見消除了跨境數據流動中的灰色地帶,並將業界的努力從「試驗探索」轉向「明確合規」。同時,境外監管也不斷加強。主要面向出口的原始設備製造商 (OEM) 需遵循 GDPR 的 12 步合規藍圖;日本修訂的「個人資訊保護法」(APPI 法) 首次引入了基於利潤的罰款計算方法;韓國的「個人資訊保護法」(PIPA) 也已進入嚴格管治階段。跨境資料流動管治已成為一項涉及多個司法管轄區的重要合規挑戰。

汽車製造商正在實施各自的應對措施。蔚來汽車的「哨兵模式」遠端監控功能實現了端到端加密和即時數據匿名化,自動模糊車牌和人臉,生成連蔚來自身都無法解密的影像,使其成為中國首家提供合規遠端監控功能的汽車製造商。蔚來自主研發的NPCC框架是業界首個設備雲一體化AI代理安全框架,對敏感資料嚴格執行「計算後即時擦除」的原則。躍躍欲試堅持車載處理原則,車載攝影機僅擷取特徵點進行本地運算,不上傳至雲端,所有通訊流量均採用AES-256端對端加密保護。 ZEEKR的「資料安全」系統實現了零信任多級存取控制,一旦檢測到未經授權或異常訪問,將在20秒內啟動資料電路斷流器,並具備物理銷毀儲存媒體上資料的功能。小鵬汽車與阿里雲合作,在其新款Model P7中引入了後量子安全演算法。這涵蓋了所有車輛模式下的數位鑰匙、車輛遠端控制和OTA更新。

NPCC(蔚來業界首個設備雲端整合AI代理安全框架)的「哨兵模式」下的「遠端檢視」

資料保全服務供應商正在不斷完善其解決方案。 Eagle Cloud Hub AI-DLP 將管治範圍從「人工」擴展到「人工+人工智慧」的雙主體,為兩者提供統一的身份管理、一致的安全策略和標準化的審計,並對外部分發、下載、複製和螢幕截圖等資料外洩路徑進行精細控制。其客戶包括吉利控股、理想汽車、躍躍欲試和賽瑞斯。 Agile Technology 的 EDLP 解決方案採用創新架構,深度整合加密和 DLP。該方案從資料來源出發,建立了一個完整的封閉回路型預防和控制系統,涵蓋「識別、分類、加密、存取控制和審計」,從而確保人工智慧時代關鍵商業機密(例如設計圖紙和研發資料)的安全。 2026 年 5 月,Agile Technology競標一家汽車產業領導者的 5000 節點資料安全專案。

為了實現跨境資料合規,CATARC 提供了一套全面的四階段服務工作流程——路由規劃、風險評估、政策制定和評估報告——以幫助 OEM 明確其資料流的整個路徑,並實現預防性、可控性和可追溯性的合規性。

六、安全需要從「成本中心」轉變為「核心競爭優勢」。

既然已經明確了發展趨勢,那麼工程設計該如何實施呢?借鑒各大公司的案例,汽車製造商應該立即採取以下幾項措施:

該系統應融入核心工作流程,而非僅被視為一份表面的合規文件。透過建構以 ISO/SAE 21434 標準為核心的全生命週期 CSMS/SUMS 系統,並將 TARA 威脅建模提前至概念和設計階段,以實現安全方面的「左移」。強制要求供應商提供 SBOM 和程式碼安全要求,並透過網路安全介面協定 (CIA) 將安全責任向下延伸。

將把車輛安全運行中心(VSOC) 從單純的警報儀表板轉型為核心營運樞紐。具體效率提升措施包括:將警報管治從「減少警報數量」轉變為「封閉回路型根本原因管理」,即為所有警報添加根本原因標籤;用動態加權模型取代靜態風險評級;通過一鍵式上下文封裝,減少人工分析時間(目前每個警報需要 15 分鐘);創建基於場景的緊急應變卡,並針對高頻響應場景實施半自動化的安全性編配場景劇本,以實現證據的自動存儲和報告生成;構建基礎車輛安全資料中心,使操作員無需登錄 5-6 個不同的系統即可獲取單個車輛識別碼 (VIN);在團隊層面,開發標準操作程序 (SOP) 庫和知識庫,並用定期的小規模練習取代大規模年度演習。

提供全鏈資料安全工程。基於資料分類和評級,加密、匿名化、存取控制和跨境監控是核心營運工具。對於跨境運營,採用四階段工作流程:「路線規劃→風險評估→策略制定→合規聲明」,從臨時專案響應過渡到標準化、持續運營。

將在合適的場景下部署人工智慧。將利用人工智慧TARA平台提高威脅建模效率,利用人工智慧SOC系統降低警告分析的開銷,採用數位孿生技術細化風險粒度,對車輛代理應用授權沙箱和功能圍欄,並對所有高風險操作保留人工核准環節。

安全發展必須從「成本中心」轉變為「核心能力」。合規性將是基礎,而保全行動將決定其限制。隨著產業進一步邁向人工智慧主導的汽車時代,這項原則將變得日益重要。

目錄

定義

第1章:汽車網路安全

  • 智慧型車輛網路安全攻擊場景
  • 網路安全攻擊場景 1:IVI
  • 網路安全攻擊場景 2:T-BOX
  • 網路安全攻擊場景 3:汽車閘道器
  • 網路安全攻擊場景 4:OTA
  • 網路安全攻擊場景 5:TSP
  • 網路安全攻擊場景 6:OBD
  • 網路安全攻擊場景 7:UDS
  • 網路安全攻擊場景 8:ADAS
  • 網路安全攻擊場景 9:充電網路系統
  • 網路安全攻擊場景 10:手機物聯網應用
  • 智慧駕駛的網路安全風險
  • 保護環節 1:硬體安全
  • 保護連結 2:韌體安全
  • 保護環節 3:系統安全
  • 保護環節 4:公車安全
  • Protection Link 5:無線安全
  • 保護環節 6:網路系統安全
  • 保護連結 7:雲端安全
  • 保護連結 8:感測器安全
  • 保護連結 9:演算法安全
  • 保護連結 10:資料安全風險
  • 受保護連結 11:業務邏輯的安全性
  • 2025年至2026年5月重大汽車安全事件概述
  • 觀察觀點1:網路安全威脅概述
  • 觀察觀點二:智慧聯網汽車漏洞現狀
  • 觀察觀點3:智慧連網汽車雲端平台的脆弱性現況 (1)
  • 觀察觀點3:智慧網聯網汽車雲端平台的脆弱性狀況
  • 應對措施:車輛雲端安全的 10 項建議
  • 攻擊趨勢及建構安全系統的建議
  • 智慧聯網汽車供應鏈安全
  • 智慧聯網汽車供應鏈的網路安全概念
  • 供應鏈網路安全管理現狀
  • 供應鏈網路安全問題分析
  • 供應鏈網路安全保護架構
  • 智慧聯網汽車供應鏈網路安全驗收評估
  • 汽車資料安全系統評估
  • 技術要求和測試評估
  • 人工智慧的引入擴大了攻擊目標範圍。
  • 分析將人工智慧引入汽車所帶來的新風險
  • 由於實施 OpenClaw 存在危險,因此在車輛中部署它需要「安全帶」。
  • 關於建構汽車網路安全的建議
  • AI攻擊回應案例研究1:QAX AISOC
  • AI攻擊回應案例研究2:AI TARA工具DefenseWeaver
  • AI攻擊反應案例研究3:ThreatTrace
  • AI攻擊反應案例研究4:SecZone SecONE

第2章:汽車資料安全

  • 資料安全風險
  • 中國乘用車國家強制標準概要
  • 智慧駕駛網路安全與資料安全政策法規
  • 智慧駕駛網路安全標準系統:網路安全標準
  • 智慧駕駛網路安全標準系統:資料安全標準
  • 智慧駕駛網路安全標準系統:人工智慧安全標準
  • 49 年式符合五項汽車資料安全合規要求。
  • 對企業而言,跨境資料傳輸是一項不可或缺的操作。
  • 汽車資料傳輸安全指南(2026)
  • 九種情況下,汽車資料傳輸到國外可免除通知要求。
  • 可預防、可控制、可追溯的資料安全系統解決方案案例研究:敏捷技術
  • GDPR合規的12步驟藍圖
  • 全球汽車製造商的跨境資料傳輸:日本到中國,中國到日本
  • 全球汽車製造商跨境資料傳輸:韓國至中國,中國至韓國
  • 全球汽車製造商跨境資料傳輸:韓國-中國、中國-韓國
  • 案例研究 1:CATARC 建構了跨境資料傳輸合規性的完整流程服務系統。
  • 案例研究 2:安永科技展望「全球跨境資料傳輸與汽車網路安全合規平台」解決方案
  • 資料安全案例研究 1:敏捷技術
  • 資料安全案例研究 2:鷹雲
  • 資料安全案例研究 3:SafePloy
  • 資料安全案例研究 4:宏途科技
  • 資料安全案例研究 5:吉林大學正源(JIT)
  • 資料安全案例研究 6:中國機械博業
  • 資料安全案例研究 7:盛安信息

第3章:典型OEM企業的網路安全/資料安全措施

  • Seres
  • Leapmotor
  • Xpeng
  • NIO
  • Li Auto
  • BYD
  • Geely

第4章:汽車安全硬體供應商代表

  • UniSentry Intelligent Technology
  • ThinkTech
  • Shanghai Hangxin
  • HSEC
  • Nsing Technologies
  • Huada Electronic
  • Tongxin Micro

第5章:主要汽車安全軟體供應商

  • 軟體安全供應商
  • Anban Tech
  • SOURCEGUARD
  • Swift SCA
  • TICPSH
  • Chiwu Technology
  • ZC Technology

第6章:通用車輛網際網路(IoV)安全供應商

  • Vecentek
  • Callisto Technology
  • R-IDPS
  • GoGoByte
  • INCHTEK
  • inTARA-NEO
  • inHSM
  • IDPS
  • Secdeer
  • Topsec
  • VSOC
  • Anda Tianxia
  • Zijin Zhilian
  • Sheng An Information

第7章 趨勢與總結

  • 主要汽車安全硬體供應商及其解決方案概述
  • 主要汽車安全軟體供應商及其解決方案概述
  • 領先的車聯網安全供應商及其解決方案概述
  • 主要OEM廠商網路安全與資料安全對比
  • 資料保全服務提供者的代表性解決方案概述
  • 智慧聯網汽車IDPS/VSOC及整合解決方案概述
  • 提高VSOC運作效率的實用方法
  • 趨勢
簡介目錄
Product Code: FZQ026

Cybersecurity & Data Security Research: Intelligent Connected Vehicles Enter the Era of "Systematic Offense-Defense and AI-Defined Security".

Centering on the panorama of intelligent connected vehicle cybersecurity and data security in 2026, this report analyzes core topics including vehicle full-domain attack scenarios and more attack surfaces brought by AI, vulnerability status analysis, full-link protection system, data classification & grading, and cross-border compliance. Furthermore, it systematically presents cutting-edge industry progress in compliance certification, technology implementation, and supply chain security governance through security protection practices of 41 enterprises of diverse types, covering 7 data security companies (Agile Technology, Eagle Cloud, etc.), 7 representative OEMs (Seres, NIO, BYD, etc.), 8 automotive security hardware suppliers (UniSentry Intelligent Technology, ThinkTech, etc.), 7 automotive security software suppliers (Software Security Technology, Anban Tech, etc.), and 12 Internet of Vehicles (IoV) security service providers (Vecentek, Callisto Technology, GoGoByte, etc.). Meanwhile, the report reveals new risks introduced by AI deployment on vehicles such as supply chain poisoning and prompt hijacking, summarizes security solutions for intelligent connected vehicles, and forecasts industrial development trends.

Highlights

Compliance upgrade driven by policies: From passing inspections to systematic operation

Frequent supply chain breaches: Security governance must cover full domains and full lifecycle

AI as a double-edged sword: Attack surfaces extend to the intent layer; defense requires "countering AI with AI"

Cybersecurity evolves from passive response to active threat hunting

Data security shifts from privacy compliance to full-link governance; cross-border data management becomes a mandatory task

Security needs to be transformed from a cost center into a core competitive edge

In 2026, the intelligent connected vehicle industry stands at a critical turning point. On one hand, the full enforcement of national mandatory standards represented by GB 44495/44496 marks the official transition of the industry from compliance exploration to in-depth compliance management. On the other hand, the deployment of large AI models on vehicles and normalized cross-border data flows are rapidly expanding vehicle attack surfaces, posing unprecedented security challenges. For automakers, simple passive compliance or single-point defense can no longer address complex cyber threats; transforming into systematic offense-defense operations featuring full-lifecycle, full-supply-chain, and AI-driven active defense has become inevitable.

I. Compliance Upgrade Driven by Policies: From "Passing Inspections" to Systematic Operation

In 2026, China's regulatory framework for automotive cybersecurity and data security has formed a closed loop. Based on mandatory standards including GB 44495-2024 Technical Requirements for Vehicle Cybersecurity and GB 44496-2024 General Technical Requirements for Software Update of Vehicles, plus the implementation of the Guidelines for Outbound Transfer Security of Automotive Data (2026), compliance requirements for automakers have been upgraded from previously recommended reference standards to enforceable bottom-line rules. Enterprises need to comprehensively reshape their security strategies, organizational structures, and operational workflows.

Regulation is also enforced through heavy fines. In May 2026, European data protection authorities imposed a fine of 100 million euros (approximately 801 million RMB) on the operator of ride-hailing app Yango for transferring users' personal data to Russia without implementing protective measures required by EU laws. In the same month, General Motors was fined nearly 90 million RMB for collecting and selling driving data without user consent, marking the largest penalty since the enactment of the California Consumer Privacy Act. The logic behind these penalties is clear: data is not the asset taken or sold arbitrarily by automakers.

Faced with stringent regulatory pressure, leading automakers are accelerating the shift from passive compliance to active risk prevention and control. Seres serves as a typical example. It has built an in-depth defense system covering "cloud-pipe-device-chip", and obtained China's first batch of Automotive Data Security Management System Certification and Level 3 National Data Security Maturity Model (DSMM) Certification, proving its industry-leading systematic security capabilities. Meanwhile, with its self-developed "iDDog" intelligent security platform, BYD follows a three-step logic of "diverting, purifying, and activating data" to break down data silos and build high-quality data infrastructure. It has deployed three major AI agents to boost efficiency in security operations, internalizing compliance requirements into robust operational capabilities. The "5 Compliance Inspections" initiated by the China Association of Automobile Manufacturers (CAAM) continue to advance; 49 vehicle models from 13 enterprises in the third batch and 43 vehicle models from 9 enterprises in the fourth batch have passed inspections. Requirements such as anonymization of human facial data collected outside vehicles and in-vehicle processing of cockpit data are becoming standard configurations in the industry.

Facts have proven that compliance is merely a starting point. Transforming security capabilities into sustainable operational internal strengths constitutes the competitive edges for enterprises to navigate industrial cycles.

II. Frequent Supply Chain Breaches: Security Governance Must Cover Full Domains and Full Lifecycle

If one were to ask for the most painful lesson of the automotive industry in 2025, the answer would likely be: Attackers no longer attempt brute-force intrusions, but infiltrate through trusted partner channels. The supply chain of intelligent connected vehicles is extremely complex; a single vulnerability in any link may trigger catastrophic consequences analogous to a dike collapsing due to an ant's nest.

In March 2025, hacker "Rey" leaked about 700 internal Jaguar Land Rover documents on the dark web, including source code, development logs, and employee databases-this was merely a prelude. In August of the same year, hacker group "Scattered Lapsus$ Hunters" intruded the company's global production systems, forcing full suspension of UK manufacturing plants and mandatory leave for 33,000 employees. Also in August, a design subsidiary under Nissan suffered a ransomware attack by threat actor "Qilin", resulting in the theft of 4TB of core design data. Cloud storage service provider Snowflake was breached, causing collateral damage to 165 downstream enterprises including auto parts retailer Advance Auto Parts. By late 2025, global wiring harness giant Yazaki Group had 350GB of data stolen by ransomware threat actors, containing complete documentation for components supplied to BMW and Nissan. The case of Thai OEM TRU is even more typical: 1TB of data was stolen, ESXi servers were targeted for encryption, ERP and logistics systems suffered widespread offline outages, and partial production lines were forced to switch to manual scheduling.

Collectively, these incidents reveal three clear shifts in attack patterns:

Target physicalization: Threat actors have escalated from data theft to intellectual property exfiltration and direct production paralysis;

Supply chain-oriented attack paths: Over half of all incidents are executed indirectly through cloud service providers, IT subsidiaries, and third-party suppliers, rendering supply chains the weakest link;

Targeted ransomware: Malicious actors specifically target high-value data such as design blueprints.

These exposed vulnerabilities have driven upgrades to industry countermeasures. Automakers are universally recognized as the primary responsible parties for supply chain security, transferring accountability to Tier 1 suppliers by signing Cybersecurity Interface Agreements (CIA). ISO/SAE 21434 certification has become a mandatory entry threshold for Tier 1 suppliers; without this "security letter of credit", enterprises cannot access core supply chains. For businesses targeting European markets, TISAX certification is an unavoidable requirement. Nevertheless, the overall landscape remains characterized by "leading OEMs take initiative while small and medium-sized suppliers lag behind". For small and medium Tier 2 and Tier 3 suppliers, most automakers only conduct documentary audits, with extremely low coverage of on-site verification and incomplete traceability chains.

Building a full-domain, full-lifecycle supply chain security system has been an industry consensus. Geely provides an exemplary benchmark. It constructed one of China's first national CNAS-accredited IoV cybersecurity laboratories, and conducts over 200 regular test items across 12 core testing dimensions including system security, communication security, and data security from an attacker's perspective, feeding research outcomes back into forward R&D workflows. In December 2025, Geely officially launched its Global Full-Domain Security Center and the Full-Domain Security 2.0 technical system. The 2.0 system expands its perspective from "whole-vehicle security" to an ecological view of "human-vehicle-road-cloud-satellite". While retaining four core security domains: life safety, health safety, property safety, and privacy safety, it iterates and upgrades nine major security systems to build a full-scenario, full-lifecycle protection network.

Meanwhile, the granularity of security acceptance evaluations for supply chain manufacturers is continuously refined, with several rigorous requirements implemented: Third-party components must not contain unaddressed high-risk vulnerabilities disclosed more than 6 months prior; high-risk vulnerabilities must be fixed and re-verified within 72 hours; OTA update packages must be signed with OEM proprietary keys, dual signatures by suppliers and OEMs are required in certain scenarios, and vehicle terminals must identify and intercept upgrade packages with missing, forged, or tampered signatures. For instance, Seres has streamlined its 300 Tier 1 suppliers down to 100, establishing deep embedded security collaboration with CATL and Bosch to narrow its security management radius to controllable scope. At the underlying hardware layer, for example, ThinkTech's Alioth TTA8 series MCUs integrate ASIL-D functional safety and EVITA FULL cybersecurity, filling domestic gaps in chassis domain master control chips and guaranteeing independent controllability and security of supply chains at the source.

The essence of supply chain security lies in extending the security boundary from "my vehicle" to "every line of code, every chip, and every supplier within my vehicle"-full domain and full lifecycle coverage are indispensable, with no links to be omitted.

III. AI as A Double-edged Sword: Attack Surfaces Extend to the Intent Layer, and Defense Requires "Countering AI with AI

The deployment of large models on vehicles brings not only smarter cockpits but also an entirely new attack dimension. AI-specific risks including supply chain poisoning, prompt hijacking, and excessive proxy are rapidly migrating to vehicle terminals. When vehicle large models connect tool chains for navigation, payment, charging, and vehicle control, attack chains originally limited to cloud chatbots can be intactly ported to vehicles. Particularly within MCP-connected ecosystems, high-risk attack vectors such as tool poisoning directly threaten IVI systems running Linux and Android.

Novel agents represented by OpenClaw excel at forming a closed loop from intent understanding to task completion thanks to their high-level system privileges. However, in vehicle environments, this translates to a persistent digital entity within the system that holds partial access rights to vehicle data and permissions to invoke vehicle control commands. Prompt injection can induce agents to execute unintended operations; a tampered third-party navigation plugin may act as a persistent Trojan horse leaking driving habits; benign hallucinations in Q&A scenarios can escalate to dangerous operations such as critical data deletion in proxy scenarios. What is even more thorny is the regulatory conflict: standards including ISO 26262, UN R155/R156, and GB 44495 mandate deterministic, predictable, testable, and traceable system behavior, while agents inherently feature non-determinism and emergent characteristics. The industry's solution is "empowerment rather than full delegation": deploy permission sandboxes and functional fences to restrict agents to infotainment and other low-risk domains; all vehicle control requests must be mandatorily arbitrated by a security middleware layer; high-risk operations must be confirmed via HMI, ensuring humans remain within the loop for all safety-critical decisions.

As attack surfaces evolve, defense mechanisms must advance in tandem. The industry's solution is straightforward: counter AI with AI.

Faced with the "spear" brought by AI, the industry must forge an even sharper "shield". For example, Anban Tech centers its new intelligent connected vehicle security paradigm on "AI large model-driven agent protection + vehicle communication protocol security + closed-loop supply chain security". It shifts security capabilities from traditional post-hoc patching to full-lifecycle proactive governance:

Leverage large models to parse full vehicle EE architecture documents, cross-model databases, and VSOC asset inventories via natural language, automatically identifying ECUs, sensors, communication interfaces, and other critical assets to map asset correlation frameworks. The LLM-powered intelligent TARA platform automatically generates security targets, security requirements, threat scenarios, and attack paths, enabling automated, visualized risk assessment.

During risk remediation, the platform combines impact severity, attack feasibility, and risk rating matrices to automatically generate remediation decisions and push work orders, forming an operational workflow of "AI detection - AI analysis - AI decision - AI closed-loop", drastically shortening vehicle security assessment cycles.

QAX AISOC is a representative example of this approach. It embeds 8 agents responsible for eight operational links: data collection, threat detection, intelligent judgment, intelligent investigation, intelligent response, incident eradication, optimization feedback, and report generation. Based on the OODA loop, it establishes an autonomous defense system transforming security operations from "human-initiated threat hunting" to "automated threat notification". Practical data demonstrates that a global luxury automaker utilizing AISOC has reduced the analysis and assessment time for a single alert to less than 9 seconds, with valid alert identification accuracy reaching 93.1%, a 2.7x improvement over traditional manual mode.

TARA, a traditional security analysis link, is also being rebuilt with AI. GoGoByte DefenseWeaver embeds the GoGoAI Agent, incorporating all new risk vectors such as models, training and inference data, prompt entry points, knowledge bases and tool invocation chains into the scope of TARA. Its judgment holds that risks stem not merely from code vulnerabilities, but also from misleading models, contaminated data and misused tools. This tool serves clients including FAW Bestune and Luxshare Precision, as well as national inspection institutions like CATARC, China Merchants Testing Vehicle Technology Research Institute and the CEPREI, boosting TARA efficiency by 80%. Callisto S3-TARA adopts a different approach: over ten agents work collaboratively to screen optimal solutions from 16 candidate Chains of Thought (CoT), supported by a data foundation built upon more than 100,000 causal chain datasets, over 3 million security scenario samples and over 1 million knowledge base Q&A pairs.

Automakers haven't been sitting idle, either. BYD's iDDog platform implements three AI agents targeting email phishing, terminal data leakage, and abnormal traffic, cutting security incident response time from 45 minutes to 5 minutes. Li Auto collaborated with Volcano Engine to develop an AI intelligent assistant capable of automatically creating work orders, scanning code, remediating vulnerabilities, and conducting re-verification upon receiving instructions in Feishu group chat, enabling one-stop closed-loop resolution with human authorization. AI native has transitioned from conceptual slogans to daily security operations.

IV. Cybersecurity Evolves from Passive Response to Active Threat Hunting

Within the cybersecurity domain, traditional passive defense idea can no longer keep pace with rapidly evolving attack vectors. 206 automotive security incidents and 238 newly discovered vulnerabilities were recorded in 2025 alone. Threat actors have escalated objectives from data theft to intellectual property exfiltration, and even direct paralysis of production and manufacturing operations. Automakers therefore must build combat-ready cybersecurity systems with active threat hunting capabilities covering threat detection, analysis, response and remediation.

The solution proposed by defenders lies in systematic defense. Seres deploys a multi-layer in-depth defense architecture of "cloud-pipe-device-chip", collaborating with QAX to deploy intrusion detection systems across CAN bus, on-board hosts, and Ethernet layers. Its VSOC platform monitors about 200,000 vehicles and issues "cybersecurity compliance certificates" for vehicle models exported to EU. Its intelligent security system covers over 200 vehicle usage scenarios and more than 400 security functions. In April 2026, it released Security 4.0, evolving from passive and active safety to intelligent security.

Professional security providers have also upgraded their toolkits. ACT VSOC+, a next-generation intelligent connected vehicle security operation platform, embodies this philosophy. Powered by an AI streaming computing engine, it delivers a 500% performance improvement in threat detection, constructs a vehicle security digital twin modeling over 2,800 vehicle signals, and enables triple precise threat localization across ECUs, signals, and scenarios, shortening threat detection and response cycles from day-level to minute-level.

At the underlying protocol security layer, TICPSH's SmartRocket TestSec automated intelligent fuzzy penetration testing tool executes deep fuzzy attacks and penetration testing against mainstream vehicle protocols including SOME/IP, DoIP, and CAN/CAN FD to proactively uncover latent vulnerabilities, shifting the security defense line forward to the R&D testing phase. UniSentry Intelligent Technology's SecIC-HSM firmware serves nearly 30 OEMs, achieving AES throughput of 4.8Gbps on Infineon AURIX TC4X, enabling parallel execution of OTA update verification and secure on-board communication (SecOC) without interrupting CAN bus transmission. These solutions help automakers make the leap from mandatory compliance to proactive security.

Consensus has formed across OEMs and suppliers: isolated standalone security products cannot resolve systemic security issues, and multi-layer in-depth defense and active immune systems represent the correct solutions.

V. Data Security Shifts from Privacy Compliance to Full-Link Governance, and Cross-Border Data Management Becomes A Mandatory Task

Data is the "blood" of intelligent vehicles, with its security spanning the full lifecycle of collection, transmission, storage, utilization, sharing, and destruction. The unique characteristic of automotive data security is that data carries both privacy and compliance attributes while directly supporting perception training, map services, model iteration, remote operations, and accident traceability. Improper collection, transmission, utilization, or tampering of data carries consequences extending far beyond regulatory fines, potentially exerting adverse impacts on vehicle behaviors.

On February 3, 2026, eight ministries including the Ministry of Industry and Information Technology and the Cyberspace Administration of China jointly issued the Guidelines for Outbound Transfer Security of Automotive Data (2026). The guidelines categorize outbound data into three tiers: general, important, and sensitive, while defining nine exemption scenarios including quality assurance maintenance data, OTA update data, and security vulnerability remediation materials. Clear filing thresholds are established: enterprises must conduct cross-border data transfer security assessments if transmitting important data overseas, or sharing personal information of over 1 million individuals / sensitive personal information of over 10,000 individuals with foreign entities. For China's automotive industry, which recorded a 65.3% year-on-year export growth in the first half of 2026, these guidelines eliminate the gray zone for cross-border data flows, shifting industry practices from tentative exploration to definitive compliance. Overseas regulation has simultaneously tightened: the 12-step GDPR compliance roadmap applies to export-focused OEMs; Japan's revised APPI Act introduces profit-based penalty calculations for the first time; South Korea's PIPA has entered a strict governance phase. Cross-border data flow governance has become a mandatory multi-jurisdictional compliance task.

Automakers have their own ways of responding. NIO's Sentry Mode remote view function implements end-to-end encryption and real-time data desensitization, automatically blurring license plates and human faces, with footage even NIO itself cannot decrypt, making it China's first OEM to deliver compliant remote view function. Its self-developed NPCC framework, the industry's first device-cloud integrated AI agent security framework, enforces "immediate data erasure post-computation" for sensitive data. Leapmotor adheres to an in-vehicle processing principle: in-vehicle cameras only collect feature points for local computing without cloud uploads, with all transmission traffic protected via AES-256 end-to-end encryption. ZEEKR's "Data Safe" system implements zero-trust tiered access control, activating data circuit breakers within 20 seconds upon detection of unauthorized abnormal access, with physical data destruction capabilities for storage media. Xpeng partnered with Alibaba Cloud to deploy post-quantum security algorithms on its new model P7, covering digital keys, remote vehicle control, and OTA for all vehicle modes.

"Remote View" in the "Sentry Mode" of NPCC (NIO's Industry-first Device-cloud Integrated AI Agent Security Framework)

Data security service providers have refined their solutions. Eagle Cloud Hub AI-DLP expands governance subjects from humans to dual entities of "human staff + AI staff", implementing unified identity management, consistent security policies, and standardized auditing for both, with refined control over data leakage vectors including external distribution, downloads, copying, and screen capture. Its clients include Geely Holding, Li Auto, Leapmotor, and Seres. Agile Technology's EDLP solution features an innovative architecture with deep integration of encryption and DLP. Starting from the source of data, it builds a full closed-loop prevention and control system covering "identification - classification - encryption - access control - audit", ensuring the security of core commercial secrets such as design drawings and R&D data amid the AI era. In May 2026, Agile Technology just won a 5,000-node data security project bid from a leader in the automotive industry.

For cross-border data compliance, CATARC delivers a full four-step service workflow: path planning - risk assessment - policy formulation - assessment declaration, enabling OEMs to clarify complete data flow routes and implement preventable, controllable, traceable compliance.

VI. Security Needs to Be Transformed from A Cost Center into A Core Competitive Edge

With clear trends identified, how to implement engineering? Drawing on the practices of leading companies, there are several actions automakers should take immediately:

Embed systems into core workflows rather than treating them as superficial compliance documentation. Build full-lifecycle CSMS/SUMS systems centered on ISO/SAE 21434 standards, shifting TARA threat modeling forward to concept and design phases to realize security left-shifting. Mandate SBOM and code security requirements for suppliers, cascading security accountability down via Cybersecurity Interface Agreements (CIA).

Transform VSOC (Vehicle Security Operations Center) from a mere alert dashboard into a core operations hub. Concrete efficiency improvement measures are as follows: shift alert governance from volume reduction to root-cause closed-loop management by tagging all alerts with root causes; replace static risk grading with dynamic weighting models; cut the 15-minute manual analysis time for each alert via one-click context encapsulation. Develop scenario-based emergency response cards and deploy semi-automated SOAR (Security Orchestration, Automation and Response) playbooks for high-frequency scenarios to auto-preserve evidence and generate reports automatically. Build an underlying vehicle security data center to eliminate the need for operators to log into five or six separate systems just to retrieve a single VIN. At the team level, establish SOP libraries and knowledge bases, and replace annual large-scale drills with regular small-scale practice sessions.

Implement full-link data security engineering. Data classification and grading serve as the foundation, with encryption, desensitization, access control and cross-border monitoring as core operational tools. Adopt a four-step workflow for cross-border businesses: route planning -> risk assessment -> policy formulation -> compliance declaration, shifting from ad-hoc project responses to normalized continuous operation.

Deploy AI in appropriate scenarios. Utilize AI TARA platforms to boost threat modeling efficiency, leverage AI SOC systems to reduce alert analysis overhead, and adopt digital twin technology to refine risk granularity, while enforcing permission sandboxes and functional fences for vehicle agents, retaining mandatory human approval gates for all high-risk operations.

Security development must shift from a "cost center" to a "core capability". Compliance serves as the foundation, while security operations determine the upper limit. As the industry advances deeper into the AI-defined vehicle era, this principle will grow increasingly weighty.

Table of Contents

Definitions

1 Automotive Cybersecurity

  • 1.1 Intelligent Vehicle Cybersecurity Attack Scenarios
  • Cybersecurity Attack Scenario 1: IVI
  • Cybersecurity Attack Scenario 2: T-BOX
  • Cybersecurity Attack Scenario 3: Automotive Gateway
  • Cybersecurity Attack Scenario 4: OTA
  • Cybersecurity Attack Scenario 5: TSP
  • Cybersecurity Attack Scenario 6: OBD
  • Cybersecurity Attack Scenario 7: UDS
  • Cybersecurity Attack Scenario 8: ADAS
  • Cybersecurity Attack Scenario 9: Charging Network System
  • Cybersecurity Attack Scenario 10: Phone IoV APP
  • 1.2 Intelligent Driving Cybersecurity Risks
  • Protection Link 1: Hardware Security
  • Protection Link 2: Firmware Security
  • Protection Link 3: System Security
  • Protection Link 4: Bus Security
  • Protection Link 5: Radio Security
  • Protection Link 6: Network System Security
  • Protection Link 7: Cloud Security
  • Protection Link 8: Sensor Security
  • Protection Link 9: Algorithm Security
  • Protection Link 10: Data Security Risks
  • Protection Link 11: Business Logic Security
  • 1.3 Summary of Major Automotive Security Incidents, 2025-May 2026 (1)
  • 1.3 Summary of Major Automotive Security Incidents, 2025-May 2026 (2)
  • 1.4 Observation Perspective 1: Cybersecurity Threat Panorama
  • 1.4 Observation Perspective 2: Vulnerability Status of Intelligent Connected Vehicles (1)
  • 1.4 Observation Perspective 2: Vulnerability Status of Intelligent Connected Vehicles (2)
  • 1.4 Observation Perspective 2: Vulnerability Status of Intelligent Connected Vehicles (6)
  • 1.4 Observation Perspective 3: Vulnerability Status of Intelligent Connected Vehicle Cloud Platforms (1)
  • 1.4 Observation Perspective 3: Vulnerability Status of Intelligent Connected Vehicle Cloud Platforms (2)
  • 1.4 Countermeasures: Ten Recommendations for Vehicle-Cloud Security
  • 1.5 Attack Transformation Trends and Security Construction Recommendations
  • 1.6 Intelligent Connected Vehicle Supply-chain Security (1)
  • 1.6 Intelligent Connected Vehicle Supply-chain Security (2)
  • Concept of Intelligent Connected Vehicle Supply-chain Cybersecurity
  • Status Quo of Supply-chain Cybersecurity Management
  • Analysis of Supply-chain Cybersecurity Issues (1)
  • Analysis of Supply-chain Cybersecurity Issues (2)
  • Analysis of Supply-chain Cybersecurity Issues (3)
  • Supply-chain Cybersecurity Protection Architecture
  • Acceptance Evaluation for Intelligent Connected Vehicle Supply-chain Cybersecurity
  • Evaluation of Automotive Data Security System
  • Technical Requirements and Testing Assessment (1)
  • Technical Requirements and Testing Assessment (2)
  • Technical Requirements and Testing Assessment (3)
  • 1.7 Attack Surfaces Expanded by Introducing AI
  • Analysis of New Risks Brought by AI Deployment on Vehicles
  • Introducing OpenClaw Is Risky and "Safety Belt" Is Needed for Deployment on Vehicles
  • Automotive Cybersecurity Construction Recommendations (1)
  • Automotive Cybersecurity Construction Recommendations (2)
  • AI Attack Response Case 1: QAX AISOC (1)
  • AI Attack Response Case 1: QAX AISOC (2)
  • AI Attack Response Case 2: AI TARA Tool DefenseWeaver
  • AI Attack Response Case 3: ThreatTrace (1)
  • AI Attack Response Case 3: ThreatTrace (2)
  • AI Attack Response Case 4: SecZone SecONE (1)
  • AI Attack Response Case 4: SecZone SecONE (2)

2 Automotive Data Security

  • 2.1 Data Security Risks
  • 2.2 Summary of Mandatory National Standards for Chinese Passenger Cars (1)
  • 2.2 Summary of Mandatory National Standards for Chinese Passenger Cars (2)
  • 2.2 Summary of Mandatory National Standards for Chinese Passenger Cars (3): Comparison between Three Standards and International Regulations
  • 2.3 Policies and Regulations Related to Intelligent Driving Cybersecurity and Data Security
  • 2.4 Standards Related to Intelligent Driving Cybersecurity and Data Security (1)
  • 2.4 Standards Related to Intelligent Driving Cybersecurity and Data Security (2)
  • 2.5 Intelligent Driving Cybersecurity Standard System: General Security and Basic Common Standards
  • 2.5 Intelligent Driving Cybersecurity Standard System: Cybersecurity Standards
  • 2.5 Intelligent Driving Cybersecurity Standard System: Data Security Standards
  • 2.5 Intelligent Driving Cybersecurity Standard System: AI Security Standards
  • 2.6 The 3rd Batch of 49 Vehicle Models Complying with 5 Automotive Data Security Compliance Requirements (1)
  • 2.6 The 3rd Batch of 49 Vehicle Models Complying with 5 Automotive Data Security Compliance Requirements (2)
  • 2.6 The 4th Batch of 43 Vehicle Models Complying with 5 Automotive Data Security Compliance Requirements
  • 2.7 Cross-border Data Transfer as a Mandatory Task for Companies
  • Guidelines for Outbound Transfer Security of Automotive Data (2026) (1)
  • Guidelines for Outbound Transfer Security of Automotive Data (2026) (2)
  • Guidelines for Outbound Transfer Security of Automotive Data (2026) (3)
  • Nine Scenarios Exempt from Filing for Outbound Transfer of Automotive Data
  • Case of Preventable, Controllable and Traceable Data Security System Solution: Agile Technology
  • GDPR 12-step Compliance Roadmap
  • Cross-border Data Transfer for Global Automakers: Japan-to-China, China-to-Japan (1)
  • Cross-border Data Transfer for Global Automakers: Japan-to-China, China-to-Japan (2)
  • Cross-border Data Transfer for Global Automakers: Japan-to-China, China-to-Japan (3)
  • Cross-border Data Transfer for Global Automakers: Japan-to-China, China-to-Japan (4)
  • Cross-border Data Transfer for Global Automakers: Japan-to-China, China-to-Japan (5) - Engineering Practice Recommendations
  • Cross-border Data Transfer for Global Automakers: Korea-to-China, China-to-Korea (1)
  • Cross-border Data Transfer for Global Automakers: Korea-to-China, China-to-Korea (2)
  • Cross-border Data Transfer for Global Automakers: Korea-to-China, China-to-Korea (3)
  • Cross-border Data Transfer for Global Automakers: Korea-to-China, China-to-Korea (4) - Engineering Practice Recommendations
  • Case 1: CATARC Builds Full-process Service System for Cross-border Data Transfer Compliance (1)
  • Case 1: CATARC Builds Full-process Service System for Cross-border Data Transfer Compliance (2)
  • Case 1: CATARC Builds Full-process Service System for Cross-border Data Transfer Compliance (3)
  • Case 2: EY Tech Horizon "Global Cross-border Data Transfer & Automotive Cybersecurity Compliance Platform" Solution (1)
  • Case 2: EY Tech Horizon "Global Cross-border Data Transfer & Automotive Cybersecurity Compliance Platform" Solution (2)
  • Case 2: EY Tech Horizon "Global Cross-border Data Transfer & Automotive Cybersecurity Compliance Platform" Solution (3)
  • 2.8 Data Security Case 1: Agile Technology
  • Data Security System
  • Data Leakage Prevention (DLP)
  • EDLP Product
  • Data Security Service Clients
  • 2.9 Data Security Case 2: Eagle Cloud
  • AI-native Product Matrix
  • "Human + AI" Unified Security Governance (1)
  • "Human + AI" Unified Security Governance (2)
  • Eagle Cloud Hub AI-DLP
  • Clients (1)
  • Clients (2)
  • 2.10 Data Security Case 3: SafePloy
  • Secure Access Solution for Electronic Control System Diagnostics Scenarios (1)
  • Secure Access Solution for Electronic Control System Diagnostics Scenarios (2)
  • 2.11 Data Security Case 4: Hongtu Technology
  • Automotive Data Security Solution
  • 2.12 Data Security Case 5: Jilin University Zhengyuan (JIT)
  • Intelligent Data Classification & Grading System
  • 2.13 Data Security Case 6: China Machinery Boye
  • Xuanyuan-Moses Integrated Intelligent Data Security Platform
  • Three Flagship Products Built on Xuanyuan-Moses Base Platform
  • 2.14 Data Security Case 7: Sheng An Information
  • Profile
  • IoV Security Business Panorama
  • Data Classification & Grading Platform
  • Data Desensitization Platform
  • Data Security Gateway
  • Transparent Data Encryption Gateway

3 Cybersecurity / Data Security Practices of Representative OEMs

  • 3.1 Seres
  • Data Security Practices
  • Cybersecurity Practices
  • Intelligent Security System (1)
  • Intelligent Security System (2)
  • Intelligent Security System (3)
  • 3.2 Leapmotor
  • Data Security Practices (1)
  • Data Security Practices (2)
  • Data Security Practices (6)
  • Cybersecurity System Construction & Certification (1)
  • Cybersecurity System Construction & Certification (2)
  • 3.3 Xpeng
  • AI Center-based Lingxi Platform
  • Post-quantum Security Practices
  • Relevant Security Practices (1)
  • Relevant Security Practices (2)
  • Relevant Security Practices (3)
  • 3.4 NIO
  • Cybersecurity Construction
  • NIO Independently Developed NPCC, the Industry-first Device-cloud Integrated AI-agent Security Framework (1)
  • NIO Independently Developed NPCC, the Industry-first Device-cloud Integrated AI-agent Security Framework (2)
  • Five-layer Data Privacy Protection System
  • 3.5 Li Auto
  • Self-developed Vehicle OS Security System
  • Defense-in-depth System for AI Intelligent Assistant (1)
  • Defense-in-depth System for AI Intelligent Assistant (2)
  • Livenet: High-resilience IoV Built on NDN
  • Livenet: High-resilience IoV Built on NDN
  • Livenet Application Scenarios (1)
  • Livenet Application Scenarios (2)
  • 3.6 BYD
  • iDDog Intelligent Security Platform (1)
  • iDDog Intelligent Security Platform (2)
  • iDDog Intelligent Security Platform (3)
  • 3.7 Geely
  • Quantum Security Protection Practices (1)
  • Quantum Security Protection Practices (2)
  • Zeekr Data Security Protection (1)
  • Zeekr Data Security Protection (2)
  • Zeekr Cybersecurity & Privacy Protection
  • Zeekr Privacy Protection Capabilities (1)
  • Zeekr Privacy Protection Capabilities (2)
  • Geely Creates New Paradigm of Defense-in-depth for IoV (1)
  • Geely Creates New Paradigm of Defense-in-depth for IoV (2)
  • Geely Builds "Cloud-Pipe-Device" Integrated Security System
  • Data Governance Work (1)
  • Data Governance Work (2)
  • Data Governance Work (5)
  • Full-Domain Security 2.0

4 Representative Automotive Security Hardware Suppliers

  • 4.1 UniSentry Intelligent Technology
  • Sutra Series Cybersecurity Agent Toolchain
  • Released DF30 Chip Integrating National Cryptography Algorithm and Post-Quantum Cryptography HSM Firmware
  • "Ultra-lightweight" HSM Lite Hardware IP
  • SecIC HSM Firmware: Hardware-software Co-control for Secure Debugging
  • SecIC HSM Firmware: Parallel Execution of OTA Update Verification and Secure Communication
  • SecIC HSM Firmware: OTA "Ciphertext Data Power-off Resume Transmission"
  • SecIC HSM Firmware: OTA Cloud-Vehicle Collaboration Resilient against "Store now decrypt later" Attacks
  • SecIC HSM Firmware: Automotive-grade Security Migration Empowers Embodied Artificial Intelligence
  • SecSOL CAN Intelligent Vehicle CAN Bus Security Test Solution
  • "AES+SM4" Lightweight Combined Cryptography Accelerator Hardware IP
  • Summary of New Qualifications & Certifications
  • Summary of Latest Ecosystem Cooperation
  • 4.2 ThinkTech
  • Mizar series Automotive-grade Secure Chips (1)
  • Mizar series Automotive-grade Secure Chips (2)
  • Alioth8 series Chips and Alioth9 Chip
  • Alioth8 Product Series
  • Alioth TTA8 MCU
  • TTA8T8X (1)
  • TTA8T8X (2)
  • TTA8T8X (3)
  • TTA9 MCU
  • Clients
  • 4.3 C*Core Technology
  • Security Product Portfolio (1)
  • Security Product Portfolio (2)
  • Security Product Portfolio (3)
  • IoV Information Security & Identity Authentication Solution
  • All-round Intelligent Cockpit Security Solutions
  • CCRC4XXX Series: High-performance Automotive Electronic AI MCU with "RISC-V + AI + Post-quantum" Architecture
  • CCRC4XXX Series: High-performance Automotive Electronic AI MCU with "RISC-V + AI + Post-quantum" Architecture
  • Cloud Secure Chip
  • Quantum-secure Chip A5Q
  • 4.4 Shanghai Hangxin
  • Automotive-grade Secure Chip ACL16 (1)
  • Automotive-grade Secure Chip ACL16 (2)
  • ACL16_S IoV Secure Chip (1)
  • ACL16_S IoV Secure Chip (2)
  • New-generation Quantum-security-grade Chip with Built-in Post-quantum Cryptography Engine
  • IoV Secure Chip: Hardware Root of Trust for V2X Communication
  • C-V2X Solution: Safeguard C-V2X Communication Security
  • 4.5 HSEC
  • Secure Chip Series Products
  • IoT Secure Chip Series Products
  • Automotive-grade Secure Chip HSC32C1 (1)
  • Automotive-grade Secure Chip HSC32C1 (1)
  • High-performance System-level Secure Chip: HSCTU
  • Terminal Secure Chip: HSCK2
  • HSRU3 High-performance SOC Secure Chip
  • Cybersecurity Partners
  • 4.6 Nsing Technologies
  • Introduction to Secure Chips
  • Secure Chip N32S032 (1)
  • Secure Chip N32S032 (2)
  • Secure Chip N32S032 (3)
  • Post-quantum Encryption Solution (1)
  • Post-quantum Encryption Solution (2)
  • Secure Chips Empowers Robots
  • 4.7 Huada Electronic
  • Security Product Matrix
  • Automotive-grade Secure Chip CIU98_B Series (1)
  • Automotive-grade Secure Chip CIU98_B Series (2)
  • 4.8 Tongxin Micro
  • Automotive Secure Chip T9 Series
  • Automotive-grade eSIM Security Assurance

5 Major Automotive Security Software Suppliers

  • 5.1 Software Security Technology
  • CodeHawk AI Code Review Platform (1)
  • CodeHawk AI Code Review Platform (2)
  • Code Issues Detectable by CodeHawk (1)
  • Code Issues Detectable by CodeHawk (2)
  • SoftSec SCA: Full-process Solution for SBOM Compliance (1)
  • SoftSec SCA: Full-process Solution for SBOM Compliance (2)
  • 5.2 Anban Tech
  • AI-driven New Paradigm for Connected-vehicle Security (1)
  • AI-driven New Paradigm for Connected-vehicle Security (2)
  • Large-model Security Test System (1)
  • Large-model Security Test System (2)
  • AI Security Series Product: Large Model Firewall System
  • Yizhi Large Model Security Evaluation System (1)
  • Yizhi Large Model Security Evaluation System (2)
  • Software Supply-chain Security Management Series Products
  • AI Large Model Red-blue Team Confrontation Platform
  • 5.3 SOURCEGUARD
  • Wisdom Lens: Agent-based Automated Vulnerability Mining System (1)
  • Wisdom Lens: Agent-based Automated Vulnerability Mining System (2)
  • Wisdom Lens: Agent-based Automated Vulnerability Mining System (3)
  • Wisdom Lens: Agent-based Automated Vulnerability Mining System (4)
  • Comparison between Wisdom Lens and Traditional Fuzzing / SAST / DAST Tools
  • Comparison between Wisdom Lens and Peer Tool AFL
  • Swift SCA
  • Swift SCA
  • 5.4 Automotive Cybersecurity Technology (ACT)
  • New-generation Intelligent Connected Vehicle Security Operation Platform: ACT VSOC+ (1)
  • New-generation Intelligent Connected Vehicle Security Operation Platform: ACT VSOC+ (2)
  • New-generation AI-native Intelligent Connected Vehicle Security Operation Platform
  • 5.5 TICPSH
  • SmartRocket PeneX Automotive Cybersecurity Test System
  • SmartRocket TestSec Automated Intelligent Fuzz Penetration Test Tool (1)
  • SmartRocket TestSec Automated Intelligent Fuzz Penetration Test Tool (2)
  • Intrusion Detection and Prevention System & Vehicle Security Operations Center (IDPS&VSOC) Integrated Platform (1)
  • Intrusion Detection and Prevention System & Vehicle Security Operations Center (IDPS&VSOC) Integrated Platform (2)
  • Intrusion Detection and Prevention System & Vehicle Security Operations Center (IDPS&VSOC) Integrated Platform (3)
  • Toolchain
  • 5.6 Chiwu Technology
  • RavenEye: Intelligent Binary Firmware Vulnerability Mining Platform (1)
  • RavenEye: Intelligent Binary Firmware Vulnerability Mining Platform (2)
  • RavenEye: Intelligent Binary Firmware Vulnerability Mining Platform (3)
  • RavenEye: Intelligent Binary Firmware Vulnerability Mining Platform (4)
  • 5.7 ZC Technology
  • Profile
  • "Basic Software + Toolchain + Service" Trinity (1)
  • "Basic Software + Toolchain + Service" Trinity (2)
  • Information Security Solutions
  • Xiaotian Information Security Algorithm Tool (1)
  • Xiaotian Information Security Algorithm Tool (2)
  • Xiaotian Information Security Algorithm Tool (3)

6 Typical Internet of Vehicles (IoV) Security Providers

  • 6.1 Vecentek
  • Full-link Automotive Cybersecurity Solution
  • SudoAI - Intelligent Security Test Tool with "Hands & Brain", Penetration Test Completed via Single Sentence (1)
  • SudoAI - Intelligent Security Test Tool with "Hands & Brain", Penetration Test Completed via Single Sentence (2)
  • SudoAI - Intelligent Security Test Tool with "Hands & Brain", Penetration Test Completed via Single Sentence (3)
  • SudoAI - One-click Subscription to Convert "AI Dialogue" into "Automated Workflow" (1)
  • SudoAI - One-click Subscription to Convert "AI Dialogue" into "Automated Workflow" (2)
  • SudoAI - One-click Subscription to Convert "AI Dialogue" into "Automated Workflow" (3)
  • IDPS&VSOC5.0 (1)
  • IDPS&VSOC5.0 (2)
  • Embedded Firmware Security Analysis Platform (1)
  • Embedded Firmware Security Analysis Platform (2)
  • Embedded Firmware Security Analysis Platform (3)
  • Embedded Firmware Security Analysis Platform (4)
  • 6.2 Callisto Technology
  • Security Data Operation Solution
  • "Compliance Full-life-cycle" Automotive Cybersecurity Product Matrix
  • Peace-of-Mind Driving Assistant (1)
  • Peace-of-Mind Driving Assistant (2)
  • R-IDPS
  • S3-TARA (1)
  • S3-TARA (2)
  • L3 Operation Monitoring Solution (1)
  • L3 Operation Monitoring Solution (2)
  • 6.3 GoGoByte
  • AI TARA Tool DefenseWeaver (1)
  • AI TARA Tool DefenseWeaver (2)
  • AI TARA Tool DefenseWeaver Client Cases (1)
  • AI TARA Tool DefenseWeaver Client Cases (2)
  • AI TARA Tool DefenseWeaver Client Cases (3)
  • AI TARA Tool DefenseWeaver Client Cases (4)
  • Cybersecurity Automated Test Platform: ThreatGo
  • Connected Vehicle Threat Intelligence Platform: ThreatHound
  • Security System Process Management Platform: RuleMate
  • MBSE + AI Full-life-cycle Cybersecurity Solution: ThreatTrace
  • 6.4 INCHTEK
  • Defense-in-depth System for Intelligent Connected Vehicles
  • Automotive Security Engine: inSE
  • Automotive Info-security Development Toolchain: inCSMS
  • Automotive Info-security Development Toolchain: inTARA
  • inTARA-NEO
  • inTARA-NEO V4.1.0
  • inTARA-NEO V4.3 (1)
  • inTARA-NEO V4.3 (2)
  • Automotive Info-security Development Toolchain: inDARA
  • Automotive Info-security Development Toolchain: inDARA
  • inDARA: Core Capabilities (1)
  • inDARA: Core Capabilities (2)
  • inDARA: Core Capabilities (3)
  • inHSM
  • IDPS
  • Vehicle Security Operation Platform: inVSOC (1)
  • Vehicle Security Operation Platform: inVSOC (2)
  • Automotive Security Gateway: A1000Plus
  • Automotive Security Gateway: A1000F
  • L3 Autonomous Driving Supervision Platform (1)
  • L3 Autonomous Driving Supervision Platform (2)
  • L3 Autonomous Driving Supervision Platform (3)
  • Embodied Artificial Intelligence "Security Cerebellum"
  • Systematic Empowerment: From Intelligent Connected Vehicles to Embodied Artificial Intelligence
  • 6.5 Secdeer
  • Taichu Crowd-Testing Platform
  • Taichu Remote Risk-control Access Gateway
  • Four Customized Services
  • IoV Crowd-Testing Service Platform: Taichu Fengshentai
  • 6.6 Topsec
  • VSOC
  • Vehicle-in-the-loop-based IoV Info-security Detection Platform
  • Adaptive Elastic Vehicle-road-cloud Integrated Security Solution
  • Winning Bid for Automotive Software Upgrade Test System Project of Authoritative Automotive Testing Institution
  • AI Gateway, Agent-oriented AI Security
  • Security AI Assistant, AI Security Testing
  • 6.7 Qingtian Xin'an
  • IDPS + VSOC End-to-end Solution
  • Vehicle Intrusion Detection & Prevention System (IDPS)
  • Vehicle Security Operation Center (VSOC)
  • Vehicle Cybersecurity Management System (CSMS)
  • 6.8 Anda Tianxia
  • Profile
  • "1+3+N" System Covering Full Life-cycle of Vehicle Cybersecurity (1)
  • "1+3+N" System Covering Full Life-cycle of Vehicle Cybersecurity (2)
  • 6.9 iLinkSec
  • AI-enabled Full-life-cycle IoV Info-security Solution
  • Digital Security Technology System
  • Digital Security Operation Center: iLinkSec.iSOC
  • Digital Security Protection Matrix: iLinkSec.iMatrix
  • Security Technical Service iLinkSec.TechService
  • Automotive Info-security Matrix: iLinkSec.SecMatrix
  • Automotive Security Algorithm Module: iLinkSec.HSM
  • Automotive Key Management & Filling System: iLinkSec.VKDMS
  • Key & Identity Management Syste: iLinkSec.iKIMS
  • Automotive Intelligent Security Operation Platform: iLinkSec.IVSOC
  • Automotive Data Outbound Transfer Security Monitoring & Management System: iLinkSec.VDMMS
  • Cross-border Data Security Monitoring & Analysis System: iLinkSec.iDSMS
  • Practice of Full-domain Coverage, Full-life-cycle Management and Graded Protection of Vehicle Cybersecurity & Data Security
  • 6.10 Zijin Zhilian
  • Product: Automotive Endogenous Security System
  • Mimic Elf Vehicle Endogenous Security System (VESS)
  • One-stop Test Platform for Intelligent Connected Vehicles
  • Overall Cybersecurity Solution for Intelligent Connected Vehicles
  • Product: Automotive CAN Security Gateway & Automotive Central Security Gateway
  • Product: Automotive Component Firmware Vulnerability Detection Tool
  • Automated Driving Data Recording System (DSSAD) (1)
  • Automated Driving Data Recording System (DSSAD) (2)
  • 6.11 Sheng An Information
  • Profile
  • IoV Security Business Panorama
  • SCMS System Construction Solution for an Automaker
  • 6.12 Safetime Information Technology
  • AI Compliance Design Tool: Panxi DOC

7 Trends and Summary

  • 7.1 Summary of Representative Automotive Security Hardware Suppliers and Their Solutions (1)
  • 7.1 Summary of Representative Automotive Security Hardware Suppliers and Their Solutions (2)
  • 7.2 Summary of Major Automotive Security Software Suppliers and Their Solutions (1)
  • 7.2 Summary of Major Automotive Security Software Suppliers and Their Solutions (2)
  • 7.3 Summary of Typical IoV Security Providers and Their Solutions (1)
  • 7.3 Summary of Typical IoV Security Providers and Their Solutions (2)
  • 7.3 Summary of Typical IoV Security Providers and Their Solutions (3)
  • 7.3 Summary of Typical IoV Security Providers and Their Solutions (4)
  • 7.3 Summary of Typical IoV Security Providers and Their Solutions (5)
  • 7.4 Comparison of Cybersecurity and Data Security between Major OEMs (1)
  • 7.4 Comparison of Cybersecurity and Data Security between Major OEMs (2)
  • 7.5 Summary of Representative Solutions of Data Security Service Providers
  • 7.6 Summary of IDPS / VSOC and Integrated Solutions for Intelligent Connected Vehicles
  • 7.7 Practices to Improve VSOC Operation Efficiency (1)
  • 7.7 Practices to Improve VSOC Operation Efficiency (10)
  • 7.7 Practices to Improve VSOC Operation Efficiency (11)
  • 7.8 Trend 1:
  • 7.9 Trend 2:
  • 7.10 Trend 3:
  • 7.10 Trend 4:
  • 7.11 Trend 5:
  • 7.12 Trend 6:
  • 7.13 Trend 7:
  • 7.14 Trend 8:
  • 7.15 Trend 9: