Safety reinforcement method, device, terminal and storage medium for rail transit operation equipment
By obtaining device information and vulnerability library information, generating trust parameters and dynamically evaluating the equipment's security status, the network security risks of rail transit operation equipment are solved, security reinforcement and isolation are achieved, and the stability of the system is improved.
Patent Information
- Application Number
- CN202111683344.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-31
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2041-12-31
AI Technical Summary
The equipment management system of existing rail transit operation equipment is prone to virus implantation or attack during communication, resulting in network security risks and thus affecting the stable operation of the entire system.
By obtaining the basic information of the device, permission information and authentication information, combining the vulnerability library information to generate device trust parameters, and setting baseline parameters and alarm parameters, dynamically assessing the security status of the device to achieve security reinforcement.
It realizes safe isolation of rail transit operation equipment, improves the security and stability of the equipment management system, effectively prevents network attacks, and ensures the continuous and stable operation of the system.
Smart Images

Figure CN114329497B_ABST
Abstract
Description
Technical Field
[0001] This application relates to a security reinforcement solution. Specifically, it is a security reinforcement method, device, terminal, and storage medium for rail transit operation equipment, belonging to the technical field of data information security. Background Art
[0002] With the continuous development of China's urbanization process and the acceleration of national infrastructure investment, various urban infrastructure facilities are also in a process of rapid construction. As a typical representative of urban infrastructure, rail transit has made great progress in terms of the number of projects, technical levels, and the renewal of supporting equipment.
[0003] In recent years, in order to meet the increasingly modern rail transit operation and maintenance needs, various rail transit operation equipment adapted to rail transit projects have emerged one after another. Common rail transit operation equipment includes escalators, AFC (Automatic Fare Collection) systems, platform screen doors, automatic doors, vehicle air conditioners, central air conditioners, ventilation equipment, water supply and drainage equipment, fire sprinkler systems, subway vehicle traction, switch turnout equipment, power control systems, etc. In order to achieve centralized and automated management of the above-mentioned rail transit operation equipment, the industry has gradually begun to try to incorporate various rail transit operation equipment into a complete set of equipment management systems, and through the system, centralized control of each device can be achieved. As a result, at the present stage, large-scale equipment management systems have also emerged in the industry and have been put into use.
[0004] In the existing equipment management system for rail transit operation equipment, there are relatively high security risks during actual operation. Specifically, in the system, the communication between various rail transit operation equipment and the industrial control service platform is based on IP (Internet Protocol) and uses UDP (User Datagram Protocol) to achieve. Its communication process can be simply described as the receiving party listens on a fixed port, the sending party sends UDP to the fixed port of the target receiving party, and the receiving party receives the request through this fixed port to complete the communication. However, due to the large scale of rail transit projects, there are thousands of rail transit operation equipment distributed at various locations along the track. The direct connection method between the above-mentioned equipment and the platform is very easy to be implanted with viruses or attacked when applied. Once a cyber attack occurs, hackers can use the victimized equipment to launch an attack on the industrial control service platform, thereby causing the entire equipment management system to crash.
[0005] In summary, how to propose a brand-new security reinforcement solution for rail transit operation equipment on the basis of the existing technology to ensure the continuous and stable operation of the equipment management system has become a common concern of technical personnel in this field. Summary of the Invention
[0006] In view of the above defects in the prior art, the object of the present invention is to propose a safety reinforcement method, device, terminal and storage medium for rail transit operation equipment, which are specifically as follows.
[0007] A safety reinforcement method for rail transit operation equipment, comprising:
[0008] Obtain the device basic information, device permission information and device authentication information of the rail transit operation equipment, combine with the vulnerability library information to generate device trust parameters, and set corresponding baseline parameters and alarm parameters for the device trust parameters;
[0009] When the evaluation period of the rail transit operation equipment of a certain device type within the device trust parameters is reached, obtain the device actual parameters of the rail transit operation equipment corresponding to the device type, and obtain the parameter trust score and alarm level value of the rail transit operation equipment according to the comparison result of the device actual parameters and the baseline parameters, combined with the alarm parameters, and obtain a parameter trust score record by combining the parameter trust score and the alarm level value;
[0010] Calculate the device trust score by using the parameter trust score record, and perform safety reinforcement operations according to the device trust score.
[0011] Preferably, the obtaining the device basic information, device permission information and device authentication information of the rail transit operation equipment, combining with the vulnerability library information to generate device trust parameters, and setting corresponding baseline parameters and alarm parameters for the device trust parameters includes:
[0012] For the rail transit operation equipment, obtain the device basic information, device permission information and device authentication information of the rail transit operation equipment;
[0013] For the externally public vulnerability library, obtain the vulnerability library information covering the rail transit operation equipment;
[0014] Integrate the device basic information, the device permission information, the device authentication information and the vulnerability library information to summarize and obtain device trust parameters;
[0015] Through device monitoring and data analysis, set corresponding baseline parameters and alarm parameters for each parameter in the device trust parameters.
[0016] Preferably, when the evaluation period of the rail transit operation equipment of a certain device type within the device trust parameters is reached, obtain the device actual parameters of the rail transit operation equipment corresponding to the device type, and obtain the parameter trust score and alarm level value of the rail transit operation equipment according to the comparison result of the device actual parameters and the baseline parameters, combined with the alarm parameters, and obtain a parameter trust score record by combining the parameter trust score and the alarm level value, including:
[0017] According to the device trust parameters, when the evaluation period of the rail transit operation device of a certain device type within the device trust parameters is reached, it is judged whether the current evaluation period falls within the applicable time range of the device type. If so, then;
[0018] Obtain the actual device parameters of all the rail transit operation devices corresponding to the device type, compare the actual device parameters with the baseline parameters corresponding to the device trust parameters, and based on the comparison results and combined with the alarm parameters, obtain the parameter trust score and the corresponding alarm level value of each rail transit operation device. Combine the parameter trust score and the alarm level value to obtain the parameter trust score record of each rail transit operation device.
[0019] Preferably, the obtaining of the actual device parameters of all the rail transit operation devices corresponding to the device type includes:
[0020] For the rail transit operation devices that can obtain data, obtain the actual device parameters of the rail transit operation device and mark the online status of the rail transit operation device as online;
[0021] For the rail transit operation devices that cannot obtain data, retry the data acquisition operation. When the data still cannot be obtained after reaching the preset retry limit, set the running time of the rail transit operation device to zero and mark the online status as offline.
[0022] Preferably, calculate the device trust score by using the parameter trust score record, and perform security reinforcement operations according to the device trust score, including:
[0023] Calculate according to the parameter trust score in the parameter trust score record and in combination with the preset parameter weights to obtain the device trust score;
[0024] Compare the device trust score with the preset trust score upper limit. When the device trust score exceeds the preset trust score upper limit, perform security reinforcement operations corresponding to the alarm level according to the alarm level value in the parameter trust score record.
[0025] Preferably, the security reinforcement operations at least include issuing a security alarm and preventing the device from accessing.
[0026] A security reinforcement device for rail transit operation devices, including:
[0027] A trust parameter preparation module, configured to obtain the device basic information, device permission information, and device authentication information of the rail transit operation device, generate device trust parameters in combination with the vulnerability library information, and set corresponding baseline parameters and alarm parameters for the device trust parameters;
[0028] A scoring record acquisition module, configured to obtain the actual device parameters of the rail transit operation device corresponding to a certain device type within the device trust parameter when the evaluation period of the rail transit operation device of the certain device type is reached, obtain the parameter trust score and the alarm level value of the rail transit operation device according to the comparison result between the actual device parameters and the baseline parameters and in combination with the alarm parameters, and obtain a parameter trust score record in combination with the parameter trust score and the alarm level value;
[0029] A reinforcement operation execution module, configured to calculate a device trust score by using the parameter trust score record and execute a security reinforcement operation according to the device trust score.
[0030] A terminal includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps in the security reinforcement method of the rail transit operation device as described above are implemented.
[0031] A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps in the security reinforcement method of the rail transit operation device as described in the foregoing claims are implemented.
[0032] The advantages of the present invention are mainly reflected in the following aspects:
[0033] A security reinforcement method for a rail transit operation device proposed by the present invention completes the dynamic perception of the security threats faced by each rail transit operation device through continuous monitoring and dynamic evaluation, and then realizes threat warning and blocking of devices with greater security threats according to the perception results. The method of the present invention effectively realizes the security isolation of the rail transit operation device, greatly improves the security during the operation of the device management system, and ensures its continuous and stable operation.
[0034] Corresponding to the above method, a security reinforcement device, a terminal, and a storage medium for a rail transit operation device proposed by the present invention numericalize the security threats faced by each rail transit operation device with a systematic and standardized data processing process, and thus provide a basis for the subsequent development of security control measures. The adaptability and compatibility of the hardware solution are relatively high, and it can be effectively applied to the risk prevention and control scenarios of rail transit projects.
[0035] The present invention also provides a reference for other solutions related to security reinforcement technology, and can be extended and studied in depth based on this, having a very broad application prospect.
[0036] The following will further elaborate on the specific implementation manners of the present invention in combination with the accompanying drawings of the embodiments, so that the technical solutions of the present invention are easier to understand and master. Brief Description of the Drawings
[0037] The drawings forming a part of this application are used to provide a further understanding of this application, making other features, objectives, and advantages of this application more obvious. The schematic embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation of this application. In the drawings:
[0038] Figure 1 is a schematic flowchart of the method for securing rail transit operation equipment of the present invention;
[0039] Figure 2 is a schematic architecture diagram of the device for securing rail transit operation equipment of the present invention. Detailed Description of the Embodiments
[0040] In order to enable those skilled in the art to better understand the solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application.
[0041] The present invention discloses a method, device, terminal, and storage medium for securing rail transit operation equipment, which realizes the security isolation of rail transit operation equipment through a dynamic device security trust assessment technology. The specific solutions are as follows.
[0042] On the one hand, the present invention relates to a method for securing rail transit operation equipment, and its process is as Figure 1 shown, including the following steps:
[0043] S1. Obtain the device basic information, device permission information, and device authentication information of the rail transit operation equipment, combine the vulnerability database information, generate device trust parameters, and set corresponding baseline parameters and alarm parameters for the device trust parameters. In this solution, this step can be specifically implemented as the following process.
[0044] S11. For the rail transit operation equipment, obtain the device basic information, device permission information, and device authentication information of the rail transit operation equipment.
[0045] The device basic information is used to identify the device identity and device information. For example, it includes the device name, device type, device model, MAC address, hardware ID / serial number, IP address, device port, processor model, memory capacity (unit: MB), hard disk capacity (unit: G), transmitted traffic (unit: kbit / s), received traffic (unit: kbit / s), operating system, operating system version number, processes, location, application software, application software version, and custom attributes.
[0046] The device permission information is used to mark various operation permissions of the device. For example, it includes which device ports the device is allowed to access, which device ports the device is allowed to be accessed by, the whitelist of device operation instructions, and the blacklist of device operation instructions.
[0047] The device authentication information is used to select one or more of them as the identity authentication method for device access according to the defined device identity information, so as to achieve safe and efficient device identity authentication. Except for some content that duplicates with the device basic information and the device permission information, the device authentication information also includes, for example, the device GUID (Globally Unique Identifier), the preset trust score upper limit, and the security hardening operation method.
[0048] S12. For the externally public vulnerability library, obtain the information in the vulnerability libraries of CVE\CNVD (Common Vulnerability Disclosure / National Information Security Vulnerability Sharing Platform) and CNNVD (National Information Security Vulnerability Database) that cover the rail transit operation equipment.
[0049] S13. Integrate the device basic information, the device permission information, the device authentication information, and the vulnerability library information to summarize and obtain the device trust parameters.
[0050] It should be emphasized that there are two important parameters in the device trust parameters, namely the applicable start time, the applicable end time, and the evaluation period (unit: times / hour). The applicable start time and the applicable end time only include the hour and minute data, do not include the date data, and the applicable end time should be after the applicable start time. The value of the evaluation period is a positive integer between 1 and 59, and its timing start time is at the whole hour.
[0051] In addition, the device trust parameters also include the preset parameter weights corresponding to each parameter, and their values are between 0 and 1, reserved to two decimal places.
[0052] S14. Through device monitoring and data analysis, set the corresponding baseline parameters and alarm parameters for each parameter in the device trust parameters.
[0053] The baseline parameters can be obtained by continuously monitoring the device, analyzing the data over a period of time, and taking the maximum value. The alarm parameters at least include the alarm threshold and the corresponding alarm level value, that is, what alarm threshold corresponds to a first-level alarm, what alarm threshold corresponds to a second-level alarm, etc.
[0054] S2. When the evaluation period of the rail transit operation equipment of a certain equipment type within the equipment trust parameters is reached, obtain the actual equipment parameters of the rail transit operation equipment corresponding to this equipment type. Based on the comparison result between the actual equipment parameters and the baseline parameters, and in combination with the alarm parameters, obtain the parameter trust score and the alarm level value of the rail transit operation equipment, and combine the parameter trust score and the alarm level value to obtain a parameter trust score record. In this solution, this step can be specifically implemented as the following process.
[0055] S21. According to the equipment trust parameters, when the evaluation period of the rail transit operation equipment of a certain equipment type within the equipment trust parameters is reached, determine whether the current evaluation period falls within the applicable time range of this equipment type. The applicable time range can be comprehensively determined by the applicable start time and the applicable end time. If so, proceed to the subsequent process.
[0056] S22. Obtain the actual equipment parameters of all the rail transit operation equipment corresponding to this equipment type with valid status, compare the actual equipment parameters with the baseline parameters corresponding to the equipment trust parameters, and based on the comparison result and in combination with the alarm parameters, obtain the parameter trust score and the corresponding alarm level value of each rail transit operation equipment. Combine the parameter trust score and the alarm level value to obtain the parameter trust score record of each rail transit operation equipment.
[0057] It should be clear in this process that during the process of obtaining the actual equipment parameters of all the rail transit operation equipment corresponding to this equipment type, there are the following two situations.
[0058] For the rail transit operation equipment for which data can be obtained, obtain the actual equipment parameters of this rail transit operation equipment, mark the online status of this rail transit operation equipment as online, and record the running time of this rail transit operation equipment.
[0059] For the rail transit operation equipment for which data cannot be obtained, retry the data acquisition operation. When the data still cannot be obtained after reaching the preset retry upper limit (3 times in the embodiments of this solution), mark the online status of this rail transit operation equipment as offline and set the running time to zero.
[0060] The parameter trust score described here is determined by the dichotomy method, and there are only two values, 1 or 10. When the actual equipment parameter is less than or equal to the baseline parameter, it is 10, indicating the highest trust level. When the actual equipment parameter is greater than the baseline parameter, it is 1, indicating the lowest trust level. And when the actual equipment parameter cannot be obtained, the parameter trust score is 1.
[0061] S3. Calculate the device trust score using the parameter trust score record, and perform security reinforcement operations based on the device trust score. In this solution, this step can be specifically implemented as the following process.
[0062] S31. Calculate the device trust score by combining the parameter trust scores in the parameter trust score record with preset parameter weights. The calculation formula is
[0063] Cs = P1 * W1 + P2 * W2 + …… + Pn * Wn,
[0064] where Cs is the Credit score, i.e., the device trust score, Pn represents the parameter trust score of the nth parameter, and Wn represents the preset parameter weight of the nth parameter.
[0065] The full score of the device trust score is 10 points, indicating that the device is very secure at this time. When calculating the device trust score, the latest value of each parameter trust score needs to be taken. For example, when calculating the value of P1 currently, if the latest values of P2…Pn were calculated yesterday, the values at the last calculation yesterday should be taken.
[0066] S32. Compare the device trust score with the preset trust score upper limit. When the device trust score exceeds the preset trust score upper limit, perform security reinforcement operations corresponding to the alarm level based on the alarm level value in the parameter trust score record.
[0067] The security reinforcement operations in the embodiments of this solution at least include issuing security alarms and blocking device access. The above two operation methods can be triggered simultaneously in practical applications. The security alarm can be a level-1 alarm, a level-2 alarm, a level-3 alarm, or even a level-4 alarm, and their severity levels increase gradually, but only single selection of the alarm level is supported.
[0068] In summary, a security reinforcement method for rail transit operation equipment proposed by the present invention completes the dynamic perception of security threats faced by each rail transit operation equipment through continuous monitoring and dynamic evaluation, and then realizes threat alarms and blocking for equipment with relatively large security threats based on the perception results. The method of the present invention effectively realizes the security isolation of rail transit operation equipment, greatly improves the security during the operation of the equipment management system, and ensures its continuous and stable operation.
[0069] On the other hand, the present invention also relates to a security reinforcement device for rail transit operation equipment, and its architecture is as Figure 2 shown, including:
[0070] A trust parameter preparation module, configured to obtain the basic device information, device permission information, and device authentication information of rail transit operation equipment, and combine the vulnerability library information to generate device trust parameters, and set corresponding baseline parameters and alarm parameters for the device trust parameters;
[0071] A scoring record acquisition module, configured to, when the evaluation period of the rail transit operation equipment of a certain device type within the device trust parameters is reached, obtain the actual device parameters of the rail transit operation equipment corresponding to the device type, and obtain the parameter trust score and alarm level value of the rail transit operation equipment based on the comparison result between the actual device parameters and the baseline parameters and in combination with the alarm parameters, and obtain a parameter trust scoring record in combination with the parameter trust score and the alarm level value;
[0072] A reinforcement operation execution module, configured to calculate a device trust score using the parameter trust scoring record, and execute a security reinforcement operation based on the device trust score.
[0073] In a possible implementation manner, the trust parameter preparation module includes:
[0074] A device information acquisition unit, configured to obtain the basic device information, device permission information, and device authentication information of the rail transit operation equipment for the rail transit operation equipment;
[0075] A vulnerability information acquisition unit, configured to obtain vulnerability library information covering the rail transit operation equipment for an externally public vulnerability library;
[0076] A trust parameter summary generation unit, configured to comprehensively summarize the basic device information, the device permission information, the device authentication information, and the vulnerability library information to obtain device trust parameters;
[0077] An alarm baseline setting unit, configured to, through device monitoring and data analysis, set corresponding baseline parameters and alarm parameters for each parameter in the device trust parameters.
[0078] In a possible implementation manner, the scoring record acquisition module includes:
[0079] An evaluation period determination unit, configured to, based on the device trust parameters, when the evaluation period of the rail transit operation equipment of a certain device type within the device trust parameters is reached, determine whether the current evaluation period falls within the applicable time range of the device type, and if so;
[0080] A trust score record summary generation unit, configured to obtain the actual device parameters of all the rail transit operation devices corresponding to the device type, compare the actual device parameters with the baseline parameters corresponding to the device trust parameters, and obtain the parameter trust score and the corresponding alarm level value of each rail transit operation device according to the comparison result and in combination with the alarm parameters. Then, in combination with the parameter trust score and the alarm level value, obtain the parameter trust score record of each rail transit operation device.
[0081] In a possible implementation manner, the score record acquisition module includes:
[0082] A device trust score generation unit, configured to calculate a device trust score according to the parameter trust score in the parameter trust score record in combination with a preset parameter weight;
[0083] A score comparison and operation execution unit, configured to compare the device trust score with a preset trust score upper limit. When the device trust score exceeds the preset trust score upper limit, execute a security reinforcement operation corresponding to the alarm level according to the alarm level value in the parameter trust score record.
[0084] On the other hand, the present invention also relates to a terminal, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps in the security reinforcement method of the rail transit operation device as described above are implemented, for example Figure 1 the steps shown. Or, when the processor executes the computer program, the functions of each module / unit in the above device embodiments are implemented, for example Figure 2 the functions of each module / unit shown.
[0085] On yet another hand, the present invention also relates to a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps in the security reinforcement method of the rail transit operation device as described above are implemented.
[0086] Among them, the readable storage medium can be a computer storage medium or a communication medium. The communication medium includes any medium that facilitates the transmission of a computer program from one place to another. The computer storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer. For example, the readable storage medium is coupled to the processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an Application Specific Integrated Circuits (ASIC). Additionally, the ASIC can be located in the user equipment. Of course, the processor and the readable storage medium can also exist as discrete components in the communication device. The readable storage medium can be a read-only memory (ROM), a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0087] Corresponding to the above method content, a security reinforcement device, a terminal, and a storage medium for rail transit operation equipment proposed by the present invention numerically represent the security threats faced by each rail transit operation equipment through a systematic and standardized data processing process, thereby providing a basis for the subsequent development of security control measures. The adaptability and compatibility of the hardware solution are relatively high, and it can be effectively applied to the risk prevention and control scenarios of rail transit projects.
[0088] The present invention also provides a reference for other solutions related to security reinforcement technology, and can be extended and studied in depth based on this, having a very broad application prospect.
[0089] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and without departing from the spirit and basic characteristics of the present invention, the present invention can be implemented in other specific forms. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, it is intended to include all changes falling within the meaning and scope of the equivalent elements of the claims in the present invention.
[0090] Finally, it should be understood that although this specification is described according to embodiments, not every embodiment only contains an independent technical solution. This narrative way of the specification is only for clarity. Those skilled in the art should regard the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.
Claims
1. A safety reinforcement method for rail transit operation equipment, characterized in that, Including: Obtain the basic device information, device permission information, and device authentication information of rail transit operation devices, combine the information in the vulnerability database, generate device trust parameters, and set corresponding baseline parameters and alarm parameters for the device trust parameters; The basic device information is used to identify the device identity and device information; The device permission information is used to mark various operation permissions of the device; The device authentication information is used to select one or more of them as the identity authentication method for device access according to the defined device identity information, so as to achieve safe and efficient device identity authentication; For the publicly available vulnerability database, obtain the information in the vulnerability database covering the General Vulnerability Disclosure / National Information Security Vulnerability Sharing Platform and the National Information Security Vulnerability Database of the rail transit operation devices, so as to obtain the vulnerability database information; When the evaluation period of the rail transit operation devices of a certain device type within the device trust parameters is reached, obtain the actual device parameters of the rail transit operation devices corresponding to the device type, and obtain the parameter trust score and alarm level value of the rail transit operation devices based on the comparison result between the actual device parameters and the baseline parameters and in combination with the alarm parameters, and obtain the parameter trust score record in combination with the parameter trust score and the alarm level value; Calculate the device trust score using the parameter trust score record, and perform security reinforcement operations according to the device trust score; Based on the parameter trust score in the parameter trust score record, calculate in combination with the preset parameter weights to obtain the device trust score. The calculation formula is: Cs = P1 * W1 + P2 * W2 + …… + Pn * Wn, where Cs is the Credit score, i.e., the device trust score, Pn represents the parameter trust score of the nth parameter, and Wn represents the preset parameter weight of the nth parameter; Compare the device trust score with the preset upper limit of the device trust score. When the device trust score exceeds the preset upper limit of the device trust score, perform security reinforcement operations corresponding to the alarm level according to the alarm level value in the parameter trust score record.
2. The safety reinforcement method of the rail transit operation equipment according to claim 1, wherein, The obtaining of the basic device information, device permission information, and device authentication information of the rail transit operation devices, combining the information in the vulnerability database, generating device trust parameters, and setting corresponding baseline parameters and alarm parameters for the device trust parameters includes: For the rail transit operation devices, obtain the basic device information, device permission information, and device authentication information of the rail transit operation devices; For the publicly available vulnerability database, obtain the vulnerability database information covering the rail transit operation devices; Comprehensively combine the basic device information, the device permission information, the device authentication information, and the vulnerability database information to summarize and obtain the device trust parameters; Through device monitoring and data analysis, set corresponding baseline parameters and alarm parameters for each parameter in the device trust parameters.
3. The safety reinforcement method of the rail transit operation equipment according to claim 2, characterized in that, When the evaluation period of the rail transit operation equipment of a certain equipment type within the device trust parameters is reached, obtain the actual device parameters of the rail transit operation equipment corresponding to this equipment type. Based on the comparison result between the actual device parameters and the baseline parameters, and in combination with the alarm parameters, obtain the parameter trust score and alarm level value of the rail transit operation equipment. Combine the parameter trust score and the alarm level value to obtain a parameter trust score record, including: Based on the device trust parameters, when the evaluation period of the rail transit operation equipment of a certain equipment type within the device trust parameters is reached, determine whether the current evaluation period falls within the applicable time range of this equipment type. If so; Obtain the actual device parameters of all the rail transit operation equipment corresponding to this equipment type, compare the actual device parameters with the baseline parameters corresponding to the device trust parameters, and based on the comparison result and in combination with the alarm parameters, obtain the parameter trust score and corresponding alarm level value of each rail transit operation equipment. Combine the parameter trust score and the alarm level value to obtain the parameter trust score record of each rail transit operation equipment.
4. The safety reinforcement method of the rail transit operation equipment according to claim 3, wherein, The obtaining of the actual device parameters of all the rail transit operation equipment corresponding to this equipment type includes: For the rail transit operation equipment that can obtain data, obtain the actual device parameters of this rail transit operation equipment and mark the online status of this rail transit operation equipment as online; For the rail transit operation equipment that cannot obtain data, retry the data acquisition operation. When the data still cannot be obtained after reaching the preset retry upper limit, reset the running time of this rail transit operation equipment to zero and mark the online status as offline.
5. The safety reinforcement method of the rail transit operation equipment according to claim 1, characterized in that: The security hardening operation at least includes issuing a security alarm and preventing device access.
6. A safety reinforcement device for rail transit operation equipment, characterized in that, Including: A trust parameter preparation module, configured to obtain the basic device information, device permission information, and device authentication information of the rail transit operation equipment, and in combination with the vulnerability database information, generate device trust parameters, and set corresponding baseline parameters and alarm parameters for the device trust parameters; The basic device information is used to identify the device identity and device information; The device permission information is used to mark various operation permissions of the device; The device authentication information is used to select one or more of them as the identity authentication method for device access according to the defined device identity information, so as to achieve safe and efficient device identity authentication; For the externally public vulnerability database, obtain the information in the vulnerability database covering the Common Vulnerabilities and Exposures / National Information Security Vulnerability Sharing Platform and the National Information Security Vulnerability Database of the rail transit operation equipment to obtain the vulnerability database information; A score record acquisition module, configured to when the evaluation period of the rail transit operation equipment of a certain equipment type within the device trust parameters is reached, obtain the actual device parameters of the rail transit operation equipment corresponding to this equipment type, and based on the comparison result between the actual device parameters and the baseline parameters, and in combination with the alarm parameters, obtain the parameter trust score and alarm level value of the rail transit operation equipment. Combine the parameter trust score and the alarm level value to obtain a parameter trust score record; The reinforcement operation execution module is configured to calculate the device trust score using the parameter trust score record and execute the security reinforcement operation based on the device trust score; The reinforcement operation execution module is further configured to: Calculate the device trust score by combining the parameter trust scores in the parameter trust score record with preset parameter weights. The calculation formula is: Cs = P1 * W1 + P2 * W2 + …… + Pn * Wn, where Cs is the Credit score, i.e., the device trust score, Pn represents the parameter trust score of the nth parameter, and Wn represents the preset parameter weight of the nth parameter; Compare the device trust score with the preset upper limit of the device trust score. When the device trust score exceeds the preset upper limit of the device trust score, execute the security reinforcement operation corresponding to the alarm level according to the alarm level value in the parameter trust score record.
7. A terminal, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps in the security reinforcement method of the rail transit operation device as described in any one of claims 1 to 5.
8. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps in the security reinforcement method of the rail transit operation device as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Railway traffic device state detecting and maintaining method and system
CN110647133A