An attack and defense target system for a train network control system and an implementation method thereof
Patent Information
- Application Number
- CN202210551919.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-20
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2042-05-20
AI Technical Summary
[0036]本发明提供的用于列车网络控制系统的攻防靶场系统及其实现方法,通过列车网络控制系统和无线传输系统实物搭建攻防靶场的拓扑结构,并通过系统管理设备模拟列车网络控制系统和无线传输系统的业务数据,可以根据不同实际项目的通信协议对业务数据进行配置,从而在攻防靶场内进行实际的业务场景仿真。本发明提供的攻防靶场系统具有成本低,可扩展,可重构的优点,且同时具备列车网络数据传输和车地通信数据传输的业务场景仿真能力,可以支持网络安全攻防对抗、测试验证、评估分析、产品科研等功能需求。
Smart Images

Figure CN117134928B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of train network security technology, and in particular to an attack and defense test range system for train network control systems and its implementation method. Background Technology
[0002] For a long time, the Train Control and Management System (TCMS) has used proprietary network communication interfaces and protocols, making it difficult for external attackers to enter the system. This has led the rail transit industry to focus more on the functional safety of trains, while paying less attention to train network security. In recent years, on the one hand, the promulgation of a series of laws and regulations, such as the National Cybersecurity Law and the Cybersecurity Classified Protection Regulations, has made the rail transit industry increasingly aware of train network security. On the other hand, with the widespread application of technologies such as Ethernet, wireless communication, and autonomous driving in trains, the Train Control System is developing towards openness and universality, lowering the barrier to entry for attackers and making the security situation facing train networks increasingly severe. Therefore, higher requirements are now placed on the network security testing and evaluation of the Train Control System. In order to accurately assess the impact of various attacks on the system and verify the security protection capabilities of network devices, there is an urgent need to propose an attack and defense range system suitable for the Train Control System. Summary of the Invention
[0003] This invention provides an attack and defense test range system and its implementation method for train network control systems, in order to solve the problem that the prior art lacks an attack and defense test range suitable for train network control systems.
[0004] To achieve the above objectives, this invention provides an attack and defense test range system for a train network control system, comprising: a train network control system, a wireless transmission system, system management equipment, a testing toolset, a traffic analysis system, and a display system; wherein...
[0005] The train network control system and the wireless transmission system are used to build the topology of the attack and defense test range;
[0006] The system management device is used to simulate the service data of the train network control system and the wireless transmission system to form a simulated service scenario of the attack and defense range.
[0007] The testing toolset includes penetration testing tools, vulnerability scanning tools, and vulnerability discovery tools. The penetration testing tools are used to simulate attacks on the train network control system and the wireless transmission system. The vulnerability scanning tools and vulnerability discovery tools are used to detect vulnerabilities in the attack and defense range.
[0008] The traffic analysis system is used to monitor and analyze the inbound and outbound data of the train network under the simulated service scenario, and generate traffic monitoring logs.
[0009] The display system is used to collect and display the traffic monitoring logs sent by the traffic analysis system.
[0010] Preferably, the train network control system includes a switch, a central controller, a gateway module, an I / O chassis, an event recorder, and a display; wherein,
[0011] The switch is used to connect the various devices of the train network control system for network communication, and to audit the running data of its own ports and processes, generating audit logs.
[0012] The gateway module is used to simulate the communication data of each vehicle subsystem;
[0013] The I / O chassis is used to collect the train's input and output data;
[0014] The event recorder is used to record train operation data, which includes the train's input and output data as well as the communication data of each of the onboard subsystems.
[0015] The display is used to show status data extracted from the train operation data, and the status data includes status information of each of the on-board subsystems.
[0016] The central controller is used to centrally control the various devices of the train network control system.
[0017] Preferably, the input / output data of the train includes the status information of each switch control device in the train's hardwired circuit; the communication data of the onboard subsystem includes the status information and fault information of the onboard subsystem.
[0018] Preferably, the wireless transmission system includes a main control board, a wireless communication board, a switching board, a firewall board, and a power supply board; wherein,
[0019] The switching board is used to interact with the switch connected to the switching board and to send the service data of the train network control system and the wireless transmission system to the main control board.
[0020] The main control board is used to perform format conversion processing on the service data sent by the switching board, and send the processed service data to the wireless communication board;
[0021] The wireless communication board is used to communicate with the terrestrial network via a wireless channel and transmit the processed service data to the terrestrial network;
[0022] The firewall board is used to configure security protection policies and generate firewall logs;
[0023] The power board is used to supply power to the various components of the wireless transmission system.
[0024] Preferably, the system management device includes a first simulation unit and a second simulation unit; the first simulation unit is used to call the host computer management software to simulate the business data of the interaction between each on-board subsystem and the train network control system, and after the host computer management software is configured, to send the UDP packets corresponding to the business data to the gateway module, so that the gateway module can convert the UDP packets into TRDP packets and send them to the central controller.
[0025] The second simulation unit is used to simulate the business data of the interaction between the train network control system and the wireless transmission system according to the application of the project, and send the business data to the main control board. After the main control board performs format conversion processing on the business data, it is returned to the ground network through the wireless communication board.
[0026] Preferably, the display system is also used to collect audit logs sent by the train network control system and firewall logs sent by the wireless transmission system, and to display the audit logs and firewall logs.
[0027] Preferably, the simulation service scenarios include train network data transmission service scenarios and vehicle-to-ground communication data transmission service scenarios.
[0028] Furthermore, the present invention also provides a method for implementing an offensive and defensive target range system, comprising:
[0029] The topology of the attack and defense test range is constructed by using the train network control system and wireless transmission system.
[0030] The system management equipment simulates the service data of the train network control system and the wireless transmission system to form a simulated service scenario for the attack and defense range;
[0031] The penetration testing tools in the testing toolset are used to simulate attacks on the target business system, and the vulnerability scanning tools and vulnerability discovery tools in the testing toolset are used to detect vulnerabilities in the attack and defense range.
[0032] The traffic analysis system monitors and analyzes the incoming and outgoing data of the train network under the simulated service scenario, and generates traffic monitoring logs.
[0033] The system displays the traffic monitoring logs collected by the traffic analysis system.
[0034] Preferably, the method for implementing the attack and defense range system further includes:
[0035] The display system collects audit logs sent by the train network control system and firewall logs sent by the wireless transmission system, and displays the audit logs and firewall logs.
[0036] This invention provides an attack and defense range system and its implementation method for train network control systems. It constructs the topology of the attack and defense range using physical train network control and wireless transmission systems, and simulates the business data of these systems through system management equipment. The business data can be configured according to the communication protocols of different actual projects, thereby simulating real-world business scenarios within the attack and defense range. The attack and defense range system provided by this invention has the advantages of low cost, scalability, and reconfigurability, and simultaneously possesses the ability to simulate business scenarios for both train network data transmission and vehicle-to-ground communication data transmission. It can support functional requirements such as network security attack and defense confrontation, testing and verification, evaluation and analysis, and product research. Attached Figure Description
[0037] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0038] Figure 1 This is a schematic diagram of the attack and defense test range system for a train network control system in one embodiment of the present invention;
[0039] Figure 2 This is a schematic diagram of the structure of a train network control system in one embodiment of the present invention;
[0040] Figure 3 This is a schematic diagram of the structure of a wireless transmission system according to an embodiment of the present invention;
[0041] Figure 4 This is a flowchart illustrating the implementation of the attack and defense range system in one embodiment of the present invention. Detailed Implementation
[0042] To make the technical problems, technical solutions, and beneficial effects of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0043] like Figure 1As shown, an embodiment of the present invention provides an attack and defense test range system for a train network control system, including a train network control system 10, a wireless transmission system 20, a system management device 30, a test toolset 40, a traffic analysis system 50, and a display system 60; the train network control system 10 is connected to the wireless transmission system 20, the system management device 30, the test toolset 40, the traffic analysis system 50, and the display system 60 via Ethernet.
[0044] The train network control system 10 and the wireless transmission system 20 are used to build the topology of the attack and defense test range. Preferably, the train network control system 10 adopts Ethernet ring network technology, which can receive communication data sent by the on-board subsystem in real time. This communication data mainly includes the status information and fault information of the on-board subsystem. The wireless transmission system 20 is a key node connecting the train network network and the ground network corresponding to the train network control system 10. It is a potential target for attacks on the train network security and can receive train operation and maintenance data sent by the train network control system 10 in real time.
[0045] System management device 30 is used to simulate the business data of train network control system 10 and wireless transmission system 20 to simulate the business scenarios of train network control system 10 in an attack and defense range. In this embodiment, the business data of train network control system 10 refers to train operation data, including but not limited to train input and output data, communication data of each on-board subsystem, and control data generated based on input and output data and communication data; the business data of wireless transmission device 20 refers to train operation and maintenance data sent by train network control system 10 to wireless transmission device 20, which mainly includes status information, fault information, and operation logs generated based on status information and fault information of important on-board subsystems; the simulated business scenarios can be divided into train network data transmission business scenarios and vehicle-to-ground communication data transmission business scenarios.
[0046] The testing toolset 40 includes penetration testing tools, vulnerability scanning tools, and vulnerability discovery tools. The penetration testing tools are used to simulate attacks on the train network control system 10 and the wireless transmission system 20. The vulnerability scanning and vulnerability discovery tools are used to detect vulnerabilities in a network attack and defense testbed. In this embodiment, the penetration testing tools in the testing toolset 40 primarily target wireless communication network penetration, cracking of various protocols such as File Transfer Protocol (FTP), Telnet, and Secure Shell (SSH), and replay attacks. The vulnerability scanning tools in the testing toolset 40 use open-source software and primarily evaluate the robustness of the Real-Time Data Protocol (TRDP) within the TCP / IP protocol stack, discovering vulnerabilities that could potentially be exploited within the earliest possible timeframe, i.e., 0-day vulnerabilities. The vulnerability scanning tools utilize professional security testing equipment and integrate multiple security vulnerability libraries such as CVE, CNVD, CNNVD, and CWE, primarily targeting onboard subsystems using VxWorks and Linux operating systems for vulnerability detection.
[0047] The traffic analysis system 50 is used to monitor and analyze the inbound and outbound data of the train network in a simulated service scenario, and generate traffic monitoring logs. In this embodiment, the traffic analysis system 50 performs real-time traffic monitoring and analysis on the inbound and outbound data of the entire train network. By comparing the traffic and connection count of the inbound and outbound data, it determines whether there are abnormal changes in traffic and connection count. If any of the detected items in traffic and connection count changes abnormally, a corresponding abnormal alarm message is generated. Based on the abnormal alarm message, the recorded inbound and outbound data, etc., a traffic monitoring log is generated and transmitted to the display system 60.
[0048] The display system 60 is used to collect and display traffic monitoring logs sent by the traffic analysis system 50. In this embodiment, the display system 60 collects traffic monitoring logs sent by the traffic analysis system 50, parses the traffic monitoring logs to obtain abnormal alarm information related to abnormal traffic or abnormal connection count, and displays the parsed abnormal alarm information. At the same time, the display system 60 can also display structural information related to the topology of the attack and defense test range.
[0049] Understandably, the attack and defense range system for the train network control system in this embodiment uses the train network control system 10 and the wireless transmission system 20 to physically construct the topology of the attack and defense range. The system management device 30 simulates the service data of the train network control system 10 and the wireless transmission system 20. The service data can be configured according to the communication protocols of different actual projects, thereby simulating actual service scenarios within the attack and defense range. This attack and defense range system has the advantages of low cost, scalability, and reconfigurability, and simultaneously possesses the service scenario simulation capabilities for both train network data transmission and vehicle-to-ground communication data transmission. It can support functional requirements such as network security attack and defense confrontation, testing and verification, evaluation and analysis, and product research.
[0050] In an alternative embodiment, such as Figure 2 As shown, the train network control system 10 includes a switch 11, a central controller 12, a gateway module 13, an I / O chassis 14, an event recorder 15, and a display 16.
[0051] Switch 11 is used to connect various devices of the train network control system 10 for network communication and to audit the operation data of its own ports and processes, generating audit logs. That is, switch 11 connects the central controller 12, gateway module 13, IO chassis 14, event recorder 15, and display 16 to form a network, and at the same time audits the operation data such as the operation status and traffic of its own ports. If abnormal messages, abnormal processes, abnormal port startup, port traffic exceeding limits, broadcast storms, or other abnormal information are found, an audit log containing the abnormal information is generated and the audit log is sent directly to the display system 60.
[0052] The gateway module 13 is used to simulate the communication data sent by each onboard subsystem to the train network control system 10, and to send the communication data to the central controller 12. The onboard subsystems may include, but are not limited to, the braking system, traction system, door control system, air conditioning control system, auxiliary system, and broadcasting system; the communication data of the train network control system 10 mainly includes the status information and fault information of the onboard subsystems.
[0053] The I / O chassis 14 is used to collect the train's input and output data. This data includes the status information of various switch control devices in the train's hardwired circuitry; these devices can be buttons, relays, and sensors, etc.
[0054] The event recorder 15 is used to record train operation data, which includes the train's input and output data as well as communication data of various onboard subsystems. Furthermore, the event recorder 15 can also be used to record other train operation data besides input / output data and communication data, such as fault diagnosis information of the train itself.
[0055] The display 16 is used to display status data extracted from train operation data, which includes status information of each onboard subsystem.
[0056] The central controller 12 is used for centralized control of all devices in the train network control system 10. In this embodiment, the central controller 12 is the core processing device of the train network control system 10, and can be used for communication management, fault diagnosis, and logic control of the train network. Specifically, communication management is based on Ethernet-based train network communication and management, in accordance with the IEC61375 standard, to realize master-slave management, bandwidth allocation, and communication cycle management of the train network. Fault diagnosis specifically involves comprehensive analysis based on the status information of each onboard subsystem to realize fault alarms. Logic control specifically involves performing logical operations based on the train's input and output data and the communication data of each onboard subsystem to realize the output of control data. Understandably, the central controller 12 can acquire the status information of each switch control device collected by the IO chassis 14 in real time, and generate control data by combining the acquired status information of each onboard subsystem, and send the control data to the IO chassis 14. The central controller 12 can also acquire the communication data simulated by the gateway module 13, extract train operation and maintenance data from the communication data, and send it to the wireless transmission system 20 through the switch 11.
[0057] Understandably, the train network control system 10 of this embodiment can realize functions such as train network communication management, train fault diagnosis, data processing, status display and data recording.
[0058] In an alternative embodiment, such as Figure 3 As shown, the wireless transmission system 20 includes a main control board 21, a wireless communication board 22, a switching board 23, a firewall board 24, and a power supply board 25.
[0059] Among them, the switching board 23 is used to interact with the switch 11 in the train network control system 10 and send the business data of the train network control system 10 interacting with the wireless transmission system 20 to the main control board 21.
[0060] The main control board 21 is used to perform format conversion processing on the service data sent by the switching board 23, and send the processed service data to the wireless communication board 22;
[0061] The wireless communication board 22 is used to communicate with the terrestrial network through a wireless channel to transmit processed service data to the terrestrial network; optionally, the wireless channel is a wireless network, an LTE network, or a 5G network.
[0062] Firewall board 24 is used to configure security protection policies and generate firewall logs; firewall board 24 is connected to wireless communication board 22.
[0063] The power board 25 is used to supply power to the various components of the wireless transmission system 20.
[0064] In this embodiment, the service data exchanged between the train network control system 10 and the wireless transmission system 20 is train operation and maintenance data, which mainly includes status information, fault information and operation logs of important onboard subsystems.
[0065] Understandably, when the switching board 23 in the wireless transmission system 20 communicates with the switch 11 in the train network control system 10, the switching board 23 can obtain the train operation and maintenance data sent by the switch 11 and send the train operation and maintenance data to the main control board 21. At this time, the main control board 21 can obtain the train operation and maintenance data sent by the switching board 23, convert the train operation and maintenance data from the TRDP protocol format to a protocol format that can be transmitted by the wireless communication board 22, and then transmit it to the ground network through the wireless communication board 22.
[0066] Understandably, the wireless transmission system 20 in this embodiment can realize functions such as train operation and maintenance data collection, data processing, and wireless data transmission.
[0067] In an optional embodiment, the system management device 30 includes a first simulation unit and a second simulation unit; the first simulation unit is used to call the host computer management software to simulate the business data of the interaction between each on-board subsystem and the train network control system 10, and after the host computer management software is configured, to send the UDP packets corresponding to the business data to the gateway module 13, so that the gateway module 13 can convert the UDP packets into TRDP packets and send them to the central controller 12.
[0068] The second simulation unit is used to simulate the business data of the interaction between the train network control system 10 and the wireless transmission system 20 according to the application of the project, and send the business data to the main control board 21. After the main control board 21 performs format conversion processing on the business data, the processed business data is transmitted to the ground network through the wireless communication board 22.
[0069] Understandably, during cybersecurity attack and defense drills in the attack and defense range system, the first simulation unit calls the host computer management software to simulate the communication data of each vehicle system according to the project's communication protocol. After the host computer management software is configured, it sends the UDP packets corresponding to the communication data to the Ethernet gateway module. The Ethernet gateway module converts the UDP packets into TRDP packets and sends them to the central controller 12, forming the train network data transmission service scenario of the attack and defense range.
[0070] Furthermore, the second simulation unit simulates train operation and maintenance data according to the application of the project, and sends the corresponding TRDP messages to the main control board 21. The main control board 21 converts the TRDP messages into the communication protocol required by the wireless communication board 22 and then transmits them to the ground network, forming a vehicle-to-ground communication data transmission service scenario in the attack and defense test range. Preferably, the project in this embodiment refers to a project related to urban rail transit, including but not limited to subway lines, high-speed rail lines, and urban rail lines.
[0071] In an optional embodiment, when the train network control system 10 includes a switch 11 and the wireless transmission system 20 includes a firewall board 24, the display system 60 further includes collecting audit logs sent by the train network control system 10 and firewall logs sent by the wireless transmission system 20, and displaying the audit logs and firewall logs.
[0072] In addition, such as Figure 4 As shown, an embodiment of the present invention also provides a method for implementing an attack and defense test range system for a train network control system, specifically including:
[0073] Step S10: The topology of the attack and defense test range is established through the train network control system 10 and the wireless transmission system 20.
[0074] Step S20: The system management device 30 simulates the service data of the train network control system 10 and the wireless transmission system 20 to form a simulated service scenario of the attack and defense range.
[0075] Step S30: Use the penetration testing tools in the testing toolset 40 to simulate an attack on the target business system. At the same time, use the vulnerability scanning tools and vulnerability discovery tools in the testing toolset 40 to perform vulnerability detection on the attack and defense range and generate vulnerability logs.
[0076] Step S40: The traffic analysis system 50 performs traffic monitoring and analysis on the inbound and outbound data of the train network under the simulation business scenario, and generates a traffic monitoring log.
[0077] Step S50: Display the traffic monitoring logs collected by the traffic analysis system 50 through the display system 60.
[0078] Furthermore, after step S50, the following steps are also included: collecting audit logs sent by the train network control system and firewall logs sent by the wireless transmission system through the display system, and displaying the audit logs and firewall logs.
[0079] Understandably, the implementation method of the attack and defense range system in this embodiment first constructs the topology of the attack and defense range using the train network control system 10 and the wireless transmission system 20. Then, the system management device 30 simulates the business data of the target business system, performing actual business scenario simulation within the attack and defense range. Next, the penetration testing tools of the testing toolset 40 are used to simulate attacks on the target business system, and vulnerability scanning and vulnerability discovery tools are used to detect vulnerabilities in the attack and defense range. Furthermore, the traffic analysis system 50 monitors and analyzes the inbound and outbound traffic under the simulated business scenario, generating traffic monitoring logs. Finally, the display system 60 collects data results such as firewall logs, vulnerability logs, traffic monitoring logs, and audit logs from the attack and defense range, and displays the data results in real time. This implementation method of the attack and defense range system in this embodiment can promptly identify risks and vulnerabilities in the train network control system 10 based on the data results of the attack and defense range system, analyze and evaluate the effectiveness of network security protection strategies, propose optimization measures for the train network security protection system based on the network security protection strategies, and further update the network security protection system to prepare for the next network security attack and defense exercise. In addition, through continuous drills in the attack and defense test range system, the security of the train network control system 10 is gradually enhanced, and the security protection capability of the train network is improved.
[0080] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the invention is limited to these examples; within the framework of the invention, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of the invention as described above, which are not provided in detail for the sake of brevity.
[0081] The embodiments of this invention are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of this invention. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this invention should be included within the protection scope of this invention.
Claims
1. A test range system for attacking and defending train network control systems, characterized in that, include: Train network control system, wireless transmission system, system management equipment, testing toolset, traffic analysis system, and display system; among which, The train network control system and the wireless transmission system are used to build the topology of the attack and defense test range; the topology is built using the physical components of the train network control system and the wireless transmission system; the wireless transmission system is a node connecting the train network and the ground network corresponding to the train network control system, and is used to receive train operation and maintenance data sent by the train network control system. The system management device is used to simulate the service data of the train network control system and the wireless transmission system to form a simulated service scenario of the attack and defense range. The system management device includes a first simulation unit and a second simulation unit. The first simulation unit is used to call the host computer management software to simulate the service data of the interaction between each on-board subsystem and the train network control system according to the communication protocol of the project. After the host computer management software is configured, the UDP packets corresponding to the service data are sent to the gateway module, so that the gateway module converts the UDP packets into TRDP packets and sends them to the central controller, forming the train network data transmission service scenario of the attack and defense range. The gateway module is an Ethernet gateway module that converts UDP packets into TRDP packets. The second simulation unit is used to simulate the business data interaction between the train network control system and the wireless transmission system according to the application of the project, and send the business data to the main control board. After the main control board performs format conversion processing on the business data, it is returned to the ground network through the wireless communication board, forming the vehicle-to-ground communication data transmission business scenario of the attack and defense test range. The business data is train operation and maintenance data. The train operation and maintenance data sent to the main control board is TRDP message. The format conversion processing includes converting the TRDP message into the communication protocol required by the wireless communication board. The testing toolset includes penetration testing tools, vulnerability scanning tools, and vulnerability discovery tools. The penetration testing tools are used to simulate attacks on the train network control system and the wireless transmission system. The vulnerability scanning tools and vulnerability discovery tools are used to detect vulnerabilities in the attack and defense range. The traffic analysis system is used to monitor and analyze the inbound and outbound data of the train network under the simulated service scenario, and generate a traffic monitoring log. The traffic analysis system performs real-time traffic monitoring and analysis on the inbound and outbound data of the entire train network. By comparing the traffic and connection count of the inbound and outbound data, it determines whether the traffic and connection count have changed abnormally. If any of the detected items, traffic and connection count, changes abnormally, a corresponding abnormal alarm message is generated, and the traffic monitoring log is generated based on the abnormal alarm message and the recorded inbound and outbound data. The display system is used to collect and display the traffic monitoring logs sent by the traffic analysis system, and to parse the traffic monitoring logs to obtain abnormal alarm information related to abnormal traffic or abnormal connection count, and to display the parsed abnormal alarm information.
2. The attack and defense test range system for train network control systems according to claim 1, characterized in that, The train network control system includes a switch, a central controller, a gateway module, an I / O chassis, an event recorder, and a display; wherein, The switch is used to connect the various devices of the train network control system for network communication, and to audit the running data of its own ports and processes, generating audit logs. The gateway module is used to simulate the communication data of each vehicle subsystem; The I / O chassis is used to collect the train's input and output data; The event recorder is used to record train operation data, which includes the train's input and output data as well as the communication data of each of the onboard subsystems. The display is used to show status data extracted from the train operation data, and the status data includes status information of each of the on-board subsystems. The central controller is used to centrally control the various devices of the train network control system.
3. The attack and defense test range system for train network control systems according to claim 2, characterized in that, The train's input and output data includes the status information of each switch control device in the train's hardwired circuit; the onboard subsystem's communication data includes the status information and fault information of the onboard subsystem.
4. The attack and defense range system for train network control systems according to claim 2, characterized in that, The wireless transmission system includes a main control board, a wireless communication board, a switching board, a firewall board, and a power supply board; wherein, The switching board is used to interact with the switch connected to the switching board and to send the service data of the train network control system and the wireless transmission system to the main control board. The main control board is used to perform format conversion processing on the service data sent by the switching board, and send the processed service data to the wireless communication board; The wireless communication board is used to communicate with the terrestrial network via a wireless channel and transmit the processed service data to the terrestrial network; The firewall board is used to configure security protection policies and generate firewall logs; The power board is used to supply power to the various components of the wireless transmission system.
5. The attack and defense test range system for train network control systems according to claim 1, characterized in that, The display system is also used to collect audit logs sent by the train network control system and firewall logs sent by the wireless transmission system, and to display the audit logs and firewall logs.
6. The attack and defense test range system for train network control systems according to claim 1, characterized in that, The simulation service scenarios include train network data transmission service scenarios and vehicle-to-ground communication data transmission service scenarios.
7. A method for implementing an offensive and defensive target range system, characterized in that, include: The topology of the attack and defense test range is constructed using the train network control system and the wireless transmission system. The topology is constructed using the physical components of the train network control system and the wireless transmission system. The wireless transmission system is a node connecting the train network and the ground network corresponding to the train network control system, and is used to receive train operation and maintenance data sent by the train network control system. The system management device simulates the service data of the train network control system and the wireless transmission system to form a simulated service scenario of the attack and defense range. The system management device includes a first simulation unit and a second simulation unit. The first simulation unit is used to call the host computer management software to simulate the service data of the interaction between each on-board subsystem and the train network control system according to the communication protocol of the project. After the host computer management software is configured, the UDP packets corresponding to the service data are sent to the gateway module, so that the gateway module converts the UDP packets into TRDP packets and sends them to the central controller, forming the train network data transmission service scenario of the attack and defense range. The gateway module is an Ethernet gateway module that realizes the conversion of UDP packets into TRDP packets. The second simulation unit is used to simulate the business data interaction between the train network control system and the wireless transmission system according to the application of the project, and send the business data to the main control board. After the main control board performs format conversion processing on the business data, it is returned to the ground network through the wireless communication board, forming the vehicle-to-ground communication data transmission business scenario of the attack and defense test range. The business data is train operation and maintenance data. The train operation and maintenance data sent to the main control board is TRDP message. The format conversion processing includes converting the TRDP message into the communication protocol required by the wireless communication board. The penetration testing tools in the testing toolset are used to simulate attacks on the target business system, and the vulnerability scanning tools and vulnerability discovery tools in the testing toolset are used to detect vulnerabilities in the attack and defense range. The traffic analysis system monitors and analyzes the incoming and outgoing data of the train network under the simulated service scenario, and generates a traffic monitoring log. The traffic analysis system monitors and analyzes the incoming and outgoing data of the entire train network in real time, and determines whether the traffic and the number of connections have changed abnormally by comparing the traffic and the number of connections of the incoming and outgoing data. If any of the detection items, namely the traffic and the number of connections, changes abnormally, a corresponding abnormal alarm message is generated, and the traffic monitoring log is generated based on the abnormal alarm message and the recorded inbound and outbound data. The system collects and displays the traffic monitoring logs sent by the traffic analysis system, and parses the traffic monitoring logs to obtain abnormal alarm information related to abnormal traffic or abnormal connection count, and then displays the parsed abnormal alarm information.
8. The method for implementing the attack and defense range system according to claim 7, characterized in that, Also includes: The display system collects audit logs sent by the train network control system and firewall logs sent by the wireless transmission system, and displays the audit logs and firewall logs.
Citation Information
Patent Citations
Network security target range system and operation method thereof
CN112153010A
Multifunctional virtual test platform for train
CN113219950A