Train on-board communication information security risk assessment method, management and control method and device
Patent Information
- Application Number
- CN202311417732.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-27
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2043-10-27
AI Technical Summary
[0003]采用现有信息安全标准IEC62443-4-2中安全等级(Security Level,SL)的评价体系SL0~SL4对信息安全风险进行管控时,无法直观体现采取单一信息安全优化措施后对危害带来的优化程度,例如:某危害的当前对应SL1级,采取某一项优化措施后评价仍然对应SL1级,这样就无法体现该措施对该系统危害起到的优化作用
[0029]1、本发明提供的列车车载通信信息安全风险评估方法,通过结合STRIDE威胁模型和信息安全标准IEC62443,系统性的获得潜在风险清单,进而,综合多种影响风险发生可能性的因素对风险发生的可能性进行量化评估,综合多种影响风险影响程度的因素对风险影响程度进行量化评估,最后,结合风险发生可能性的量化评估结果和风险影响程度的量化评估结果,确定风险等级,为列车车载通信系统的信息安全设计提供了直观、可靠的风险评估结果;
Smart Images

Figure CN117478526B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of rail vehicle technology, and in particular to a method, control method and equipment for assessing and managing the security risks of train-mounted communication information. Background Technology
[0002] As the railway industry becomes increasingly information-driven and digitalized, railway operating companies, while leveraging information technology to improve system security and reliability, also bear extremely high risks associated with information security incidents. Under the concept of the Internet of Things (IoT) in railways, information security plays a role as crucial as functional safety. Defects in information systems can directly lead to train malfunctions, data loss, and even service interruptions, ultimately resulting in direct property damage. Identifying the information security level of communication systems through information security risk assessment is a fundamental task for railway information security. Information security risk assessment evaluates the confidentiality, integrity, availability, potential for damage, and consequences to information systems during their generation, storage, processing, and transmission. By conducting information security risk assessments and analyzing the asset value, potential security threats, system defects, and protective measures of information systems, major risks can be identified, and methods to mitigate these risks can be found, enabling targeted risk control measures.
[0003] When using the Security Level (SL) evaluation system (SL0-SL4) in the existing information security standard IEC62443-4-2 to manage information security risks, it is impossible to intuitively reflect the degree of optimization of the harm after taking a single information security optimization measure. For example, if a certain harm currently corresponds to SL1, and the evaluation still corresponds to SL1 after taking a certain optimization measure, it is impossible to reflect the optimization effect of the measure on the harm to the system. Moreover, the information security risk assessment of existing communication systems lacks evaluation traceability, which is not conducive to the management of information security risks in communication systems.
[0004] Therefore, how to provide an information security risk assessment method that is easy to optimize and manage information security risks and is applicable to the on-board communication system of rail trains is a technical problem that urgently needs to be solved. Summary of the Invention
[0005] To address the aforementioned technical problems, embodiments of the present invention provide a method for assessing and managing information security risks in train onboard communication systems, a computer device, and a computer-readable storage medium. This information security risk assessment method can quantitatively assess the information security risk level of train onboard communication systems, facilitating risk optimization and management.
[0006] In a first aspect, embodiments of the present invention provide a method for assessing the security risks of train-mounted communication information, comprising the following steps:
[0007] Obtain a list of potential risks: Combining the STRIDE threat model and the information security standard IEC62443, determine a list of potential risks existing in the train's onboard communication system to be evaluated;
[0008] Calculating the probability coefficient of risk occurrence: Each potential risk in the potential risk list is scored based on four aspects: system exposure level, attack complexity, required permissions, and user interaction. The sum of the scores for the four aspects is then normalized to obtain the probability coefficient L of risk occurrence. 可能性 ;
[0009] Calculating the Risk Impact Coefficient: The impact of each potential risk in the potential risk list is scored from five aspects: safety impact, financial impact, performance impact, reputational impact, and compliance impact. The sum of the scores from the five aspects is then normalized to obtain the Risk Impact Coefficient I. 影响 ;
[0010] Calculate the risk factor: according to the formula R 风险 =L 可能性 ×I 影响 Calculate the risk coefficient R 风险 ;
[0011] Determine the risk level: when 0 ≤ R 风险 When R < 0.04, the risk level is assessed as SL0; when R ≤ 0.04 风险 When R < 0.2, the risk level is assessed as SL1; when 0.2 ≤ R 风险 When R < 0.5, the risk level is assessed as SL2; when 0.5 ≤ R 风险 When R < 0.8, the risk level is assessed as SL3; when 0.8 ≤ R 风险 When the value is ≤1, the risk level is assessed as SL4.
[0012] In some embodiments, the specific steps for obtaining the potential risk list are as follows: Establish a mapping relationship between the STRIDE threat model and the basic requirements defined in the information security standard IEC 62443, based on the classification criteria of the STRIDE threat model; determine the category of each potential threat that may exist in the train's onboard communication system according to the STRIDE threat model, and determine the corresponding basic requirements based on the mapping relationship between the STRIDE threat model and the basic requirements, thereby obtaining the corresponding component requirements and system requirements; compare the train's onboard communication system to be evaluated with the obtained component requirements and system requirements to obtain the potential risk list.
[0013] In some embodiments, the step of calculating the probability coefficient of risk occurrence divides the system exposure level into four levels: wide area network exposure, short-distance connection exposure, local connection exposure, and physical protection exposure, and assigns different scores from high to low; the attack complexity is divided into two levels: low complexity and high complexity, and assigns different scores from high to low; the required permissions are divided into three levels: no permissions required, low permissions, and high permissions, and assign different scores from high to low; and user interaction is divided into two levels: no interaction and interaction required, and assigns different scores from high to low.
[0014] In some embodiments, the probability coefficient L of the risk occurring is... 可能性 The calculation formula is:
[0015]
[0016] Among them, W SE To score the level of system exposure, W AC To score the complexity of the attack, W PR Rate the required permissions, W UI Rate user interactions The total score is calculated by assigning the lowest possible scores to the system's exposure level, attack complexity, required permissions, and user interaction. The total score is the result of assigning the highest possible scores to the system's exposure level, attack complexity, required permissions, and user interaction.
[0017] In some embodiments, in the step of calculating the risk impact coefficient, the safety impact is divided into four levels according to the number of lives lost (from most to least) and the severity of injuries (from highest to lowest), and assigned different scores from high to low. When there is no safety impact, the safety impact score is 0. The financial impact is divided into four levels according to the proportion of economic losses caused to annual turnover (from highest to lowest), and assigned different scores from high to low. When there is no financial impact, the financial impact score is 0. The performance impact is divided into four levels according to the number of lines causing unplanned interruptions (from most to least) and... Interruption duration is categorized into four levels, from longest to shortest, and assigned a score from highest to lowest. Performance impact is scored as 0 when there is no performance impact. Reputational impact is also categorized into four levels, based on the level of attention received by adverse reports and the scope of attention, and assigned a score from highest to lowest. Reputational impact is scored as 0 when there is no reputational impact. Compliance impact is categorized into four levels, based on whether operations are restricted and the severity of penalties and responsibilities, and assigned a score from highest to lowest. Compliance impact is scored as 0 when there is no compliance impact.
[0018] In some embodiments, the risk impact factor I影响 The calculation formula is:
[0019]
[0020] Among them, W 安全 For the safety impact score, W 财政 To score the fiscal impact, W 性能 For performance impact scoring, W 声誉 For reputation impact rating, W 合规 Compliance affects the score. The total score is the result of assigning the highest possible score to each of the following impacts: security, finance, performance, reputation, and compliance.
[0021] Secondly, embodiments of the present invention provide a method for managing and controlling information security risks in train-mounted communication, comprising the following steps:
[0022] S1. Using the train onboard communication information security risk assessment method of the first aspect above, the risk level of the onboard communication system of the train to be assessed is evaluated.
[0023] S2. For potential risks with a risk level of SL2 or higher, implement risk mitigation measures;
[0024] S3. Using the train onboard communication information security risk assessment method of the first aspect above, reassess the risk level of the train onboard communication system to be assessed.
[0025] S4. Determine whether the risk levels of the remaining risks are all below SL1; if so, the risk is under control; if not, implement additional risk mitigation measures and return to step S3.
[0026] Thirdly, embodiments of the present invention provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the train onboard communication information security risk assessment method as described in the first aspect above.
[0027] Fourthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the train onboard communication information security risk assessment method as described in the first aspect above.
[0028] Compared with the prior art, the advantages and positive effects of the present invention are as follows:
[0029] 1. The train onboard communication information security risk assessment method provided by this invention systematically obtains a list of potential risks by combining the STRIDE threat model and the information security standard IEC62443. Then, it quantitatively assesses the probability of risk occurrence by comprehensively considering various factors that affect the probability of risk occurrence, and quantitatively assesses the degree of risk impact by comprehensively considering various factors that affect the degree of risk impact. Finally, it determines the risk level by combining the quantitative assessment results of the probability of risk occurrence and the quantitative assessment results of the degree of risk impact, thus providing an intuitive and reliable risk assessment result for the information security design of the train onboard communication system.
[0030] 2. The information security risk assessment method for train onboard communication provided by the invention is used to conduct information security risk assessment. It quantifies each risk in the potential risk list, which facilitates risk optimization and control.
[0031] 3. The train onboard communication information security risk management method provided by the present invention is based on the initial risk level assessment of the train onboard communication system to be evaluated. For potential risks with a risk level of SL2 or above, risk mitigation measures are implemented, and then the risk level is reassessed to determine whether the remaining risks are within the tolerable range. If there are still intolerable risks, additional risk mitigation measures are implemented until all risks are controlled within the tolerable range, thus realizing feedback optimization in the management process.
[0032] Details of one or more embodiments of the present invention are set forth in the following drawings and description, so that other features, objects and advantages of the invention will be more readily understood. Attached Figure Description
[0033] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this invention, illustrate exemplary embodiments of the invention and are used to explain the invention, but do not constitute an undue limitation of the invention. In the drawings:
[0034] Figure 1 This is a flowchart of a train onboard communication information security risk assessment method according to an embodiment of the present invention;
[0035] Figure 2 This is a flowchart of a train onboard communication information security risk management method according to an embodiment of the present invention. Detailed Implementation
[0036] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be described and illustrated below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention. All other embodiments obtained by those skilled in the art based on the embodiments provided by this invention without inventive effort are within the scope of protection of this invention.
[0037] Obviously, the accompanying drawings described below are merely some examples or embodiments of the present invention. Those skilled in the art can apply the present invention to other similar scenarios based on these drawings without any inventive effort. Furthermore, it is understood that although the efforts made in this development process may be complex and lengthy, for those skilled in the art related to the content disclosed in this invention, modifications to design, manufacturing, or production based on the technical content disclosed in this invention are merely conventional technical means and should not be construed as insufficient disclosure of the present invention.
[0038] In this invention, the reference to "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it a mutually exclusive, independent, or alternative embodiment. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described in this invention may be combined with other embodiments without conflict.
[0039] This embodiment provides a method for assessing the information security risks of train-mounted communication. Figure 1 This is a flowchart of a train onboard communication information security risk assessment method according to an embodiment of the present invention, such as... Figure 1 As shown, the process includes the following steps:
[0040] S101 Obtain a list of potential risks: Combine the STRIDE threat model and the information security standard IEC62443 to determine a list of potential risks in the train's onboard communication system to be evaluated;
[0041] S102 calculates the probability coefficient of risk occurrence: Each potential risk in the potential risk list is scored based on four aspects: system exposure level, attack complexity, required permissions, and user interaction. The sum of the scores from the four aspects is then normalized to obtain the probability coefficient L of risk occurrence. 可能性 ;
[0042] S103 Calculation of Risk Impact Coefficient: The impact of each potential risk in the potential risk list is scored from five aspects: safety impact, financial impact, performance impact, reputational impact, and compliance impact. The sum of the scores from the five aspects is normalized to obtain the risk impact coefficient I. 影响 ;
[0043] S104 calculates the risk coefficient: according to formula R 风险 =L 可能性 ×I 影响 Calculate the risk coefficient R 风险 ;
[0044] S105 Determines the risk level: When 0 ≤ R 风险 When R < 0.04, the risk level is assessed as SL0; when R ≤ 0.04 风险 When R < 0.2, the risk level is assessed as SL1; when 0.2 ≤ R 风险 When R < 0.5, the risk level is assessed as SL2; when 0.5 ≤ R 风险 When R < 0.8, the risk level is assessed as SL3; when 0.8 ≤ R 风险 When the value is ≤1, the risk level is assessed as SL4.
[0045] In the above-mentioned train onboard communication information security risk assessment method, it should be noted that step S102, which calculates the probability coefficient of the risk occurrence, and step S103, which calculates the degree coefficient of the risk impact, can be performed simultaneously, sequentially, or in reverse order.
[0046] The aforementioned train onboard communication information security risk assessment method, by combining the STRIDE threat model and the information security standard IEC 62443, systematically obtains a list of potential risks. Then, it quantifies the probability of risk occurrence by comprehensively considering various factors affecting the likelihood of risk occurrence, and quantifies the degree of risk impact by comprehensively considering various factors affecting the degree of risk impact. Finally, by combining the quantitative assessment results of the probability of risk occurrence and the quantitative assessment results of the degree of risk impact, the risk level is determined, providing intuitive and reliable risk assessment results for the information security design of train onboard communication systems. Furthermore, by employing this method, information security risk assessment is conducted on a case-by-case basis, quantifying each risk in the potential risk list, which facilitates risk optimization and control.
[0047] In some embodiments, the specific steps of S101 to obtain the potential risk list are as follows: Based on the classification criteria of the STRIDE threat model and the definition of basic requirements in the information security standard IEC62443, establish a mapping relationship between the STRIDE threat model and basic requirements; based on the STRIDE threat model, determine the category of each potential threat that may exist in the train's onboard communication system, and based on the mapping relationship between the STRIDE threat model and basic requirements, determine the basic requirements corresponding to the potential threat, and obtain the corresponding component requirements and system requirements; compare the train's onboard communication system to be evaluated with the obtained component requirements and system requirements to obtain the potential risk list.
[0048] It should be noted that the STRIDE threat model is a Microsoft model used to analyze the security of communication software components. It classifies threats into six categories, as shown in Table 1.
[0049] Table 1. Threat Category Descriptions in the STRIDE Threat Model
[0050]
[0051]
[0052] The information security standard IEC 62443 defines seven categories of basic requirements (FRs) for the implementation of information security in industrial control systems, along with corresponding component requirements (CRs) and system requirements (SRs). The seven categories of basic requirements are as follows:
[0053] 1. FR1 - Identification and authentication control (IAC): Identifies and authenticates all users (people, processes, and devices) and allows them access to systems or assets, protecting against unauthorized access.
[0054] 2. FR2 - Use control (UC): Authorizes users (personnel, processes, and equipment) to perform access to systems or assets according to assigned priorities, protecting against unauthorized operations on equipment.
[0055] 3. FR3 - Data Integrity (DI): Ensures the integrity of information in the channel and database, and protects against data tampering.
[0056] 4. FR4 - Data confidentiality (DC): Ensures the confidentiality of information and database data, and prevents data leakage.
[0057] 5. FR5 - Restricted Data Flow (RDF): Uses zones and pipes to segment the system to limit unnecessary data flow between zones and protect information.
[0058] 6. FR6 - Timely response to an event (TRE): Directly respond to the information security incident to the authoritative agency, provide conclusive evidence, take timely and appropriate actions after the cause is determined, notify the authoritative department of the infringement on information security, and report relevant evidence.
[0059] 7. FR7 - Resource Availability (RA): Ensures the availability of systems or assets and protects the entire network resources from denial-of-service (DoS) attacks.
[0060] Based on the classification standards of the STRIDE threat model and the definitions of the basic requirements in the information security standard IEC 62443, a mapping relationship from the STRIDE threat model to the basic requirements can be established as shown in Table 2.
[0061] Table 2 Mapping relationship between STRIDE threat model and FRs
[0062]
[0063] By establishing the mapping relationship between the above STRIDE threat model and basic requirements, the component requirements (CRs) and system requirements (SRs) corresponding to each threat category can be clearly defined, thereby obtaining a list of potential risks.
[0064] In some embodiments, in step S102, which calculates the probability coefficient of risk occurrence, the system exposure level is divided into four levels: wide area network exposure, short-distance connection exposure, local connection exposure, and physical protection exposure, and assigned different scores from high to low; attack complexity is divided into two levels: low complexity and high complexity, and assigned different scores from high to low; required permissions are divided into three levels: no permissions required, low permissions, and high permissions, and assigned different scores from high to low; user interaction is divided into two levels: no interaction and interaction required, and assigned different scores from high to low. Specifically, the assignment table of each influencing factor of the probability of risk occurrence is shown in Table 3.
[0065] Table 3. Value Assignment Table for Various Factors Affecting the Probability of Risk Occurrence
[0066]
[0067] In some embodiments, the probability coefficient L of the risk occurring is... 可能性 The calculation formula is:
[0068]
[0069] Among them, W SE To score the level of system exposure, W AC To score the complexity of the attack, W PR Rate the required permissions, W UI Rate user interactions The total score is calculated by assigning the lowest possible scores to the system's exposure level, attack complexity, required permissions, and user interaction. The total score is the result of assigning the highest possible scores to the system exposure level, attack complexity, required permissions, and user interaction. It should be noted that in this embodiment, Through the above normalization process, the probability score of risk occurrence can be transformed into a probability coefficient L between 0 and 1. 可能性 L 可能性 The higher the value, the higher the probability; the lower the value, the lower the probability.
[0070] In some embodiments, in step S103, which calculates the risk impact coefficient, the safety impact is divided into four levels based on the number of lives lost (from most to least) and the severity of injuries (from highest to lowest), and each level is assigned a score from highest to lowest. When there is no safety impact, the safety impact score is 0. The financial impact is also divided into four levels based on the proportion of economic losses to annual revenue (from highest to lowest), and each level is assigned a score from highest to lowest. When there is no financial impact, the financial impact score is 0. The performance impact is further divided based on the number of lines causing unplanned interruptions (from most to lowest). The impact of each risk factor is categorized into four levels based on the duration of the interruption, from longest to shortest, and assigned a score from highest to lowest. A performance impact score of 0 is assigned when there is no performance impact. Similarly, reputational impact is categorized into four levels based on the level of attention received by adverse reports, from highest to lowest, and the scope of attention, from largest to smallest, and assigned a score from highest to lowest. A reputational impact score of 0 is assigned when there is no reputational impact. Compliance impact is categorized into four levels based on whether operations are restricted and the severity of penalties and responsibilities, from most severe to least severe, and assigned a score from highest to lowest. A compliance impact score of 0 is assigned when there is no compliance impact. The specific values for each risk impact factor are shown in Table 4.
[0071] Table 4. Value Assignment Table for Each Influencing Factor of Risk Impact Level
[0072]
[0073] In some embodiments, the risk impact factor I 影响 The calculation formula is:
[0074]
[0075] Among them, W 安全 For the safety impact score, W 财政 To score the fiscal impact, W 性能 For performance impact scoring, W 声誉 For reputation impact rating, W 合规 Compliance affects the score. The total score is the result of assigning the highest possible scores to the impacts on security, finance, performance, reputation, and compliance. It should be noted that in this embodiment, Through the above normalization process, the risk impact score can be converted into a risk impact coefficient I between 0 and 1. 影响 I 影响 The higher the value, the greater the impact; the lower the value, the smaller the impact.
[0076] This embodiment also provides a method for managing and controlling information security risks in train onboard communication. Figure 2 This is a flowchart of a train onboard communication information security risk management method according to an embodiment of the present invention, such as... Figure 2 As shown, the process includes the following steps:
[0077] S1. Using the above-mentioned train onboard communication information security risk assessment method, conduct a risk level assessment of the train onboard communication system to be assessed;
[0078] S2. For potential risks with a risk level of SL2 or higher, implement risk mitigation measures;
[0079] S3. Using the above-mentioned train onboard communication information security risk assessment method, reassess the risk level of the train onboard communication system to be assessed.
[0080] S4. Determine whether the risk levels of the remaining risks are all below SL1. If so, the risk is under control; otherwise, implement additional risk mitigation measures and return to step S3.
[0081] The above-mentioned train onboard communication information security risk management method is based on the initial risk level assessment of the onboard communication system of the train to be evaluated. For potential risks with a risk level of SL2 or above, risk mitigation measures are implemented, and then the risk level is reassessed to determine whether the remaining risks are within the tolerable range. If there are still intolerable risks, additional risk mitigation measures are implemented until all risks are controlled within the tolerable range, thus realizing feedback optimization in the management process.
[0082] Furthermore, the train-mounted communication information security risk assessment method of this invention can be implemented by a computer device. This computer device may include a processor and a memory storing computer program instructions.
[0083] Specifically, the processor may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of the present invention.
[0084] The memory may include a large-capacity storage device for data or instructions. For example, and not limitingly, the memory may include a hard disk drive (HDD), a floppy disk drive, a solid-state drive (SSD), flash memory, an optical disk drive, a magneto-optical disk drive, magnetic tape, or a Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory may include removable or non-removable (or fixed) media. Where appropriate, the memory may be internal or external to the data processing device. In a particular embodiment, the memory is non-volatile memory. In a particular embodiment, the memory includes read-only memory (ROM) and random access memory (RAM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), an electrically alterable read-only memory (EAROM), or flash memory, or a combination of two or more of these. Where appropriate, the RAM can be Static Random-Access Memory (SRAM) or Dynamic Random-Access Memory (DRAM). DRAM can be Fast Page Mode Dynamic Random-Access Memory (FPMDRAM), Extended Data Out Dynamic Random-Access Memory (EDODRAM), Synchronous Dynamic Random-Access Memory (SDRAM), etc.
[0085] Memory can be used to store or cache various data files that need to be processed and / or communicated, as well as possible computer program instructions executed by the processor.
[0086] The processor reads and executes computer program instructions stored in the memory to implement any of the train onboard communication information security risk assessment methods in the above embodiments.
[0087] Furthermore, in conjunction with the train onboard communication information security risk assessment method in the above embodiments, this invention can be implemented using a computer-readable storage medium. This computer-readable storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the train onboard communication information security risk assessment methods in the above embodiments.
[0088] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0089] The embodiments described above are merely illustrative of several implementations of the present invention, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these all fall within the protection scope of the present invention. Therefore, the protection scope of this invention patent should be determined by the appended claims.
Claims
1. A method for assessing the information security risks of train-mounted communication, characterized in that, Includes the following steps: Obtain a list of potential risks: Combining the STRIDE threat model and the information security standard IEC62443, determine a list of potential risks existing in the train's onboard communication system to be evaluated; The specific steps for obtaining the potential risk list are as follows: Based on the classification criteria of the STRIDE threat model and the definitions of basic requirements in the information security standard IEC 62443, establish a mapping relationship between the STRIDE threat model and basic requirements; based on the STRIDE threat model, determine the category of each potential threat that may exist in the train's onboard communication system, and based on the mapping relationship between the STRIDE threat model and basic requirements, determine the corresponding basic requirements for that potential threat, obtaining the corresponding component requirements and system requirements; compare the train's onboard communication system to be evaluated with the obtained component requirements and system requirements to obtain the potential risk list. Calculating the probability coefficient of risk occurrence: Each potential risk in the potential risk list is scored based on four aspects: system exposure level, attack complexity, required permissions, and user interaction. The sum of the scores for these four aspects is then normalized to obtain the probability coefficient of risk occurrence. ; Calculating the risk impact coefficient: The impact of each potential risk in the potential risk list is scored from five aspects: safety impact, financial impact, performance impact, reputational impact, and compliance impact. The sum of the scores from the five aspects is then normalized to obtain the risk impact coefficient. ; Calculate the risk factor: according to the formula Calculate the risk coefficient ; Determine the risk level: When When the risk level is assessed, it is SL0; when When the risk level is assessed, it is SL1; when When the risk level is assessed, it is SL2; when When the risk level is assessed, it is SL3; when At that time, the risk level was assessed as SL4.
2. The train onboard communication information security risk assessment method according to claim 1, characterized in that, In the step of calculating the probability coefficient of risk occurrence, the system exposure level is divided into four levels: wide area network exposure, short-distance connection exposure, local connection exposure, and physical protection exposure, and assigned different scores from high to low respectively; the attack complexity is divided into two levels: low complexity and high complexity, and assigned different scores from high to low respectively; the required permissions are divided into three levels: no permission required, low permission, and high permission, and assigned different scores from high to low respectively. User interactions are divided into two levels: no interaction and interaction required, and then assigned different scores from high to low.
3. The train onboard communication information security risk assessment method according to claim 2, characterized in that, probability coefficient of risk occurrence The calculation formula is: in, To score the level of system exposure, Score the attack complexity. Rate the required permissions. Rate user interactions The total score is calculated by assigning the lowest possible scores to the system's exposure level, attack complexity, required permissions, and user interaction. The total score is the result of assigning the highest possible scores to the system's exposure level, attack complexity, required permissions, and user interaction.
4. The train onboard communication information security risk assessment method according to claim 1, characterized in that, In calculating the risk impact coefficient, the safety impact is categorized into four levels based on the number of lives lost (from highest to lowest) and the severity of injuries (from highest to lowest), with scores assigned sequentially from highest to lowest. A safety impact score of 0 is assigned when there is no safety impact. Similarly, the financial impact is categorized into four levels based on the percentage of economic loss relative to annual revenue (from highest to lowest), with scores assigned sequentially from highest to lowest. A financial impact score of 0 is assigned when there is no financial impact. The performance impact is categorized based on the number of lines experiencing unplanned outages (from highest to lowest) and the duration of the outages (from highest to lowest). The impact of negative reports is categorized into four levels, from longest to shortest, and assigned scores from highest to lowest. When there is no impact on performance, the performance impact score is 0. Similarly, the impact on reputation is categorized into four levels, from highest to lowest, based on the level of attention received and the scope of attention, and assigned scores from highest to lowest. When there is no impact on reputation, the reputation impact score is 0. Finally, the impact on compliance is categorized into four levels, from most severe to least severe, based on whether operations are restricted and the severity of penalties and responsibilities, and assigned scores from highest to lowest. When there is no impact on compliance, the compliance impact score is 0.
5. The train onboard communication information security risk assessment method according to claim 4, characterized in that, Risk impact coefficient The calculation formula is: in, The safety impact score is determined by the rating. Score the fiscal impact. Score for performance impact. To influence ratings based on reputation Compliance affects the score. The total score is the result of assigning the highest possible score to each of the following impacts: security, finance, performance, reputation, and compliance.
6. A method for managing and controlling information security risks in train-mounted communication, characterized in that, Includes the following steps: S1. Using the train onboard communication information security risk assessment method according to any one of claims 1-5, the risk level of the onboard communication system of the train to be assessed is evaluated. S2. For potential risks with a risk level of SL2 or higher, implement risk mitigation measures; S3. Using the train onboard communication information security risk assessment method according to any one of claims 1-5, reassess the risk level of the train onboard communication system to be assessed. S4. Determine whether the risk levels of the remaining risks are all below SL1; If so, then the risk is under control; If not, implement additional risk mitigation measures and return to step S3.
7. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the train onboard communication information security risk assessment method as described in any one of claims 1-5.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the train onboard communication information security risk assessment method as described in any one of claims 1-5.
Citation Information
Patent Citations
Intelligent network automobile information security risk assessment method and system
CN112329022A
Comprehensive traffic network security risk point identification method
CN114638539A