V-Copilot - Callisto VSOC operation AI agent

An intelligent companion for vehicle security center operations

Challenge

A major challenge in current automotive security operations is how to accurately and efficiently identify security threats from the vast amounts of automotive security data generated by millions of vehicles.

Massive alarms
Faced with millions of vehicle alarms, security staff are heavily burdened, and existing processes and technologies struggle to respond efficiently, leading to potential risks that may not be addressed in time, impacting vehicle cybersecurity and operation.
Rapidly growing threats
The rapidly growing number of threats overwhelms the operation and maintenance team, leading to overlooked advanced, concealed threats. An outbreak could seriously compromise vehicle security and expose inadequate defenses.
Vehicle cybersecurity talent shortage
The VSOC system is highly specialized, making the technical threshold for security operation relatively high. The training cycle for automotive network security talents is long, resulting in a shortage of security analysis and operations talents.
Solution

The VSOC security operation AI agent uses natural language to simplify data queries, analysis, and reporting for automotive network security personnel, reducing daily operation time by 65%. It operates 24/7, offering continuous insights from specific event analysis to broader security threat trends. For example, operators can ask: "What is the security threat trend of the C1 model in the past week?" or analyze specific incidents like: "Investigate the 'Bluetooth signal relay attack' from the past week that affected vehicle assets."

How it works

Ability to understand automotive cybersecurity data

The VSOC operation AI agent uses the Butterfly Large Model as its capability base. When faced with 40+ application scenarios of automobile intelligent services, it can accurately understand 3000+ signals from vehicle ECUs, 20+ key ECUs and automobile-related cybersecurity events, and grasp Interrelationships between various types of data.

Intent and vehicle cybersecurity scenarios understanding

Leveraging technologies like intent identification, task refinement, and data analysis, the AI agent enables vehicle cybersecurity operation engineers to issue customized data insight requests based on their specific security threat investigation needs.

Vehicle security threat insight task execution

Based on understanding the data and breaking down the task, necessary data is collected from VSOC. Relevant tools are then used to further analyze and integrate this data, and the survey results are returned.

Value

Efficiency of data mining and insight

The AI agent uses natural language interaction to understand and respond to the operation engineer's personalized data mining needs, simplifying query and processing procedures for quick access to insights.

Reduce the operational complexity of VSOC

The AI agent simplifies the learning and operation of the complex VSOC system for operators, effectively reducing their workload and speeding up the training process.

Significantly improve operational efficiency

The agent enhances data mining, analysis, and statistical processes, easing the operators' burden. When high-threat alarms rise, it accurately filters alarm information, aiding the team in resource allocation, focusing on rapid responses to high-risk events, and boosting operational efficiency and speed.

Use Case

The picture bellow shows how to use natural language interaction to allow the AI agent to complete data insights into the cybersecurity status of specific vehicle models in VSOC

Step 1: Issue data investigation requirements to the AI agent for "abnormal event trends that have occurred in the remote control scenario of the C1 model in the past week"

Step 2: Investigate the vehicles affected by the "High mobile APP remote control request frequency" event that occurs frequently in remote control scenarios.

Step 3: Extract the data of the incident and the affected vehicles to form an incident investigation document and email it to the operation personnel for further analysis.

Get Started

Learn what cybersecurity services Callisto and the S3 platform can provide to you and your automotive network.

Contact us about our automotive cybersecurity services

With the transformation of automobiles into intelligent ones, automobile cybersecurity challenges are becoming increasingly prominent, and automobile companies urgently need to upgrade their cybersecurity protection systems.
Callisto (Beijing) Technology Co., Ltd. is a national high-tech enterprise founded by one of the world's first technical experts focusing on automotive network security, invested by world-renowned institutions, and possessing a number of independent intellectual property rights.
Chinese vehicle cybersecurity standard:
General Technical Requirements for Automobile Information Security
Comply with" Guidelines for the Construction of Internet of Vehicles Network Security and Data Security Standard System",meet GB/T 40861-2021 "General Technical Requirements for Automobile Information Security", establish and provide automobile network security services. Any data we process for our customers and any risks we discover are the private assets of our customers and cannot be accessed without authorization.
©2022 Callisto (Beijing) Technology Co., Ltd.ICP No. 2022011284-1
Vehicle cybersecurity certification:
ISO/SAE 21434 and UN R155UN R156

Contact us for ISO and WP.29 certification services to meet EU regulations.

Tel: 4001059410

Address: 201, Building 2A, Silicon Valley Liangcheng, Haidian District, Beijing