Train control system-oriented security defense method, device, equipment, medium and product
By obtaining and analyzing the monitoring data of the train control system in real time, predicting security risk status and formulating response strategies, the problem of insufficient traditional passive security defense mechanisms is solved, and the active security defense and effective response to the train control system is achieved.
Patent Information
- Application Number
- CN202510254330.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-05-23
AI Technical Summary
When the existing train control system faces cyber attacks, the traditional passive security defense mechanism is not enough to deal with the inherent vulnerabilities of collaborative attacks and software systems, resulting in the threat of system stability.
By obtaining monitoring data in real time, including access control data, authentication data, security incidents and alarm data, conducting correlation analysis, predicting security risk status, and formulating response policies, generating response control scripts to drive response control tools to perform response recovery operations.
It realizes active security defense against the train control system, can deal with network attacks, and ensures that the system maintains safe operation in a threat environment.
Smart Images

Figure CN120024380A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of railway safety technology, and in particular to a safety defense method, device, equipment, medium and product for a train control system. Background Art
[0002] The Chinese Train Control System (CTCS) is a highly data-dependent system whose automatic control functions require the continuity and integrity of key data such as line data and train operation status. To ensure the reliability, availability, maintainability and safety of the system, CTCS adopts security designs including dual-machine hot standby and 2x2-out-of-2 redundant fault-tolerant architecture, as well as cross-validation and constraint mechanisms to protect the system from most potential attacks. Despite this, the design of CTCS mainly focuses on traditional security threats without fully considering information security risks. The Railway Signal Safety Protocol is a dedicated track communication protocol designed to handle risks such as data duplication, deletion, insertion, reordering, corruption, delay and forgery. Although software redundancy and "fail-safe" design in application software increase the difficulty of malicious attacks, existing statistical indicators mainly focus on functional safety assessment and fail to fully assess the temporary or sudden impact of cyber threats on system stability.
[0003] At present, the security protection of the railway industry mainly relies on traditional security measures such as firewalls, intrusion detection, authentication and encryption. However, with the introduction of new digital functions in track control systems, as well as the diversification and complexity of attack methods (such as APT, DDoS, data theft), traditional passive security defense mechanisms are no longer sufficient to deal with coordinated attacks and inherent vulnerabilities in software systems. Therefore, there is an urgent need to develop an active security defense method suitable for railway train control systems.
[0004] The field equipment of the train control system, including roadside physical equipment such as signals, turnouts, and transponders, is vulnerable to physical tampering and unauthorized access due to the lack of network security protection. For example, sending telegrams in plain text and lacking integrity and timestamp checks make them vulnerable to tampering and replay attacks. Although monitoring layer equipment such as the Radio Block Center (RBC), the Temporary Speed Restriction Server (TSRS), and the Train Control Center (TCC) have achieved boundary isolation and host reinforcement protection, this single-point protection measure cannot effectively resist coordinated attacks. Summary of the invention
[0005] The present invention provides a security defense method, device, equipment, medium and product for a train control system to ensure that the train control system can maintain safe operation when a network attack occurs.
[0006] According to one aspect of the present invention, a security defense method for a train control system is provided, the method comprising:
[0007] Acquire monitoring data in real time; wherein the monitoring data includes at least one of access control data, identity authentication data, security event and alarm data, system configuration and change data, environment and sensor data, user behavior data, and security indicator measurement data;
[0008] Based on the monitoring data, correlation analysis is performed on the behavior patterns of each control system in the train control system to obtain a safety risk status;
[0009] Predicting a response strategy for the security risk status to obtain a target response strategy;
[0010] The target response strategy is transformed to obtain a response control script; wherein the response control script is used to drive the corresponding response control tool to perform a response recovery operation on the train control system in a task execution environment.
[0011] According to another aspect of the present invention, a safety defense device for a train control system is provided, the device comprising:
[0012] A monitoring data acquisition module, used to acquire monitoring data in real time; wherein the monitoring data includes at least one of access control data, identity authentication data, security event and alarm data, system configuration and change data, environment and sensor data, user behavior data, and security indicator measurement data;
[0013] A correlation analysis module, used to perform correlation analysis on the behavior patterns of each control system in the train control system based on the monitoring data to obtain a safety risk status;
[0014] A strategy determination module, used to predict the response strategy for the security risk state and obtain a target response strategy;
[0015] A response recovery module is used to transform the target response strategy to obtain a response control script; wherein the response control script is used to drive the corresponding response control tool to perform a response recovery operation on the train control system in a task execution environment.
[0016] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0017] at least one processor; and
[0018] a memory communicatively connected to the at least one processor; wherein,
[0019] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the security defense method for the train control system described in any embodiment of the present invention.
[0020] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the safety defense method for a train control system described in any embodiment of the present invention when executed.
[0021] According to another aspect of the present invention, a computer program product is provided. The computer program product includes a computer program. When the computer program is executed by a processor, the computer program implements the security defense method for a train control system according to any embodiment of the present invention.
[0022] The technical solution of the embodiment of the present invention is to obtain monitoring data in real time; wherein the monitoring data includes at least one of access control data, identity authentication data, security events and alarm data, system configuration and change data, environment and sensor data, user behavior data, and security indicator measurement data; then, based on the monitoring data, the behavior patterns of each control system in the train control system are correlated and analyzed to obtain the security risk status, and then the response strategy for the security risk status is predicted to obtain the target response strategy, and finally the target response strategy is transformed to obtain the response control script; wherein the response control script is used to drive the corresponding response control tool to perform response recovery operations on the train control system in the task execution environment. The above technical solution, by obtaining the monitoring data of the train control system in real time, analyzes and predicts the security risk status, and then determines the response strategy for active response, which can cope with the changing threat environment, and at the same time, in the event of a network attack, it can ensure the safe operation of the train control system.
[0023] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0025] Figure 1 is a flow chart of a security defense method for a train control system provided according to an embodiment of the present invention;
[0026] Figure 2 is a flow chart of a security defense method for a train control system provided according to an embodiment of the present invention;
[0027] Figure 3 is a system architecture diagram of a security defense method for a train control system provided according to an embodiment of the present invention;
[0028] Figure 4 is a structural schematic diagram of an association analysis module provided according to an embodiment of the present invention;
[0029] Figure 5 is a schematic diagram of the structure of a collaborative protection module provided according to an embodiment of the present invention;
[0030] Figure 6 is a structural diagram of a perception monitoring module provided according to an embodiment of the present invention;
[0031] Figure 7 is a structural schematic diagram of a response recovery module provided according to an embodiment of the present invention;
[0032] Figure 8 is a schematic diagram of the structure of a safety defense device for a train control system provided according to an embodiment of the present invention;
[0033] Fig. 9 It is a schematic diagram of the structure of an electronic device for implementing the safety defense method for a train control system according to an embodiment of the present invention. DETAILED DESCRIPTION
[0034] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0035] It should be noted that the terms "first", "second", "target", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0036] In addition, it should be noted that the collection, storage, use, processing, transmission, provision and disclosure of the detection data involved in the technical solution of the present invention are in compliance with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0037] The digital transformation of industrial control systems is a key trend in the Industrial 4.0 era. As industrial control systems continue to evolve and become more complex, system vulnerabilities and the risk of attacks are also increasing. Existing network security protection solutions for train control systems are mainly deployed to the system boundary using plug-in network security devices such as firewalls, gateways, intrusion detection and other integrated applications. This stacking of traditional security defense devices can resist some known threats, but cannot resist unknown threats and coordinated attacks. There is currently no research on active defense methods related to train control systems.
[0038] Current research status: There is no research on active defense methods related to train control systems. The following are some similar studies, such as a model-based zero-trust network security architecture that strengthens the access control strategy of in-depth defense. It is an active defense architecture, but there are potential single point failures that may affect the access control of the entire system. For example, the application of the adaptive security framework in the network security of railway information systems, combined with the network security protection needs of railway information systems under the new situation, mainly provides a capability-oriented network security planning idea from four key research directions: risk in-depth security defense, data in-depth security detection, automated rapid response, and security intelligence warning, breaking through the existing traditional external network security equipment stacking defense idea. However, the article focuses on building a superimposed evolutionary architecture and mainly analyzes active defense security technology, without clearly specifying the adaptive method and data interaction with the train control system.
[0039] In summary, although existing research has made certain progress in the study of active network security protection, there are still many issues in its specific active defense process and implementation mechanism that need to be further explored and resolved.
[0040] Figure 1 This is a flowchart of a security defense method for a train control system provided according to an embodiment of the present invention. This embodiment is applicable to situations in which a train control system responds to network attacks. The method can be executed by a security defense device for a train control system. The device can be implemented in the form of hardware and / or software. The device can be configured in an electronic device that carries a security defense function for a train control system, such as a train control system. Optionally, the device can be integrated with the control and sensor equipment of the train control system and deployed in layers at various levels of the train control system. Figure 1 As shown, the method includes:
[0041] S110. Acquire monitoring data in real time.
[0042] In this embodiment, monitoring data refers to data related to network security in the train control system; optionally, the monitoring data may include at least one of access control data, identity authentication data, security events and alarm data, system configuration and change data, environment and sensor data, user behavior data, and security indicator measurement data; wherein, access control data includes but is not limited to monitoring access requests to key CTCS system resources such as maintenance machines, network security equipment firewalls, network gates, etc.; identity authentication data includes but is not limited to collected and verified user information, identity information of on-board and trackside equipment, etc.; system configuration and change data refers to data that tracks changes in system configuration, including but not limited to software updates, hardware changes, and equipment adjustments; security indicator measurement data includes but is not limited to trusted measurements, etc.
[0043] Specifically, the monitoring data can be obtained in real time through the communication infrastructure of the train control system.
[0044] S120. Based on the monitoring data, correlation analysis is performed on the behavior patterns of each control system in the train control system to obtain a safety risk status.
[0045] Among them, the security risk status refers to the fault point status or potential fault point of system behavior in the train control system, as well as possible network attack behaviors (such as attack scenarios, etc.).
[0046] Specifically, the behavior models of each control system in the train control system can be analyzed based on the monitoring data to determine whether they meet expectations, and the safety risk status of the train control system can be determined by performing statistical analysis, pattern recognition and correlation analysis on the monitoring data.
[0047] An optional method is to perform data fusion analysis on the monitoring data to obtain system behavior characteristics; based on the system behavior characteristics, a behavior correlation analysis is performed on the behavior patterns of each control system in the train control system to obtain the safety risk status.
[0048] Among them, the system behavior characteristics refer to the characteristics obtained after data analysis of the monitoring data, which can be expressed in the form of matrix or vector.
[0049] Specifically, the monitoring data can be subjected to data fusion analysis, for example, the monitoring data can be subjected to data cleaning and normalization processing to obtain processed monitoring data, so as to eliminate the direct dimensional influence of abnormal data and different data sources, and then feature extraction, such as dimensionality reduction processing, can be performed on the processed monitoring data to obtain system behavior characteristics, so that by extracting key information of different dimensions from the processed monitoring data, the system behavior patterns of different dimensions can be characterized, and the processing efficiency can be improved and the computational complexity can be reduced. Afterwards, cluster analysis and artificial intelligence algorithms are used to perform behavioral correlation analysis on the behavior models of each control system in the train control system according to the system behavior characteristics to obtain the security risk status, for example, data time series correlation is performed according to the system behavior characteristics, that is, the attack activity data of the same source IP address and the same target IP address in different time periods are correlated; for example, source correlation is performed according to the system behavior characteristics, that is, the attack activity data of the same source IP address are correlated; for example, target correlation is performed according to the system behavior characteristics, that is, the attack activity data of different source IP addresses attacking the same target IP address are correlated; for example, causal correlation analysis is performed according to the system behavior characteristics, that is, the attack step data of the attack activity are correlated.
[0050] It is understandable that cluster analysis and artificial intelligence algorithms are used to mine the complementary, implicit and associated relationships between data contents, and the adaptive capabilities of data contents are used to achieve attack scenario splicing, restoration and prediction.
[0051] S130: predicting a response strategy for the security risk status to obtain a target response strategy.
[0052] Among them, the target response strategy refers to the final response strategy for the security risk status, including but not limited to system resources, system configuration, security defense strategy, etc.
[0053] An optional method is to predict the response strategy for the security risk status to obtain candidate response strategies; the candidate response strategies include system resources, system configuration, and security policies; the candidate response strategies are evaluated to obtain a target response strategy, and the target response strategy is used.
[0054] Among them, the candidate response strategy refers to the response strategy obtained by preliminary strategy formulation and selection for the security risk status.
[0055] Specifically, multi-dimensional collaborative protection is carried out in combination with the security risk status and the analysis results of the system, station, and line. An optimized multi-layer defense strategy is selected or formulated from the strategy library to obtain candidate response strategies. The candidate response strategies are then evaluated for consistency, such as principle consistency and target consistency, to obtain a target response strategy.
[0056] It can be understood that consistency analysis and evaluation are carried out based on adaptive response strategies to ensure that system security strategies work together. Based on the principles of minimizing deviations and costs, it is ensured that response strategies follow the system's security principles of availability, integrity, and confidentiality, and that security measures at all levels follow established security standards and support each other.
[0057] S140. Convert the target response strategy to obtain a response control script; wherein the response control script is used to drive the corresponding response control tool to perform response recovery operations on the train control system in a task execution environment.
[0058] Specifically, the target response strategy may involve data such as the type of operation implemented in response, extended parameters, and operation instructions. Therefore, the target response strategy is converted to obtain a response control script, which drives the corresponding response control tool to implement response recovery operations on the train control system in the task execution environment to implement safety strategies and response measures, such as adjusting equipment configuration, updating network configuration, or deploying new safety measures to ensure the safety and reliability of the train control system operation. For example, it may be necessary to disconnect the network connection between different network segment levels, downgrade the system, and take emergency stop and other safety measures. If the system fails, the execution module has the ability to restore the basic functions of the system.
[0059] The technical solution of the embodiment of the present invention is to obtain monitoring data in real time; wherein the monitoring data includes at least one of access control data, identity authentication data, security events and alarm data, system configuration and change data, environment and sensor data, user behavior data, and security indicator measurement data; then, based on the monitoring data, the behavior patterns of each control system in the train control system are correlated and analyzed to obtain the security risk status, and then the response strategy for the security risk status is predicted to obtain the target response strategy, and finally the target response strategy is transformed to obtain the response control script; wherein the response control script is used to drive the corresponding response control tool to perform response recovery operations on the train control system in the task execution environment. The above technical solution, by obtaining the monitoring data of the train control system in real time, analyzes and predicts the security risk status, and then determines the response strategy for active response, which can cope with the changing threat environment, and at the same time, in the event of a network attack, it can ensure the safe operation of the train control system.
[0060] On the basis of the above embodiment, as an optional method of the present invention, after converting the target response strategy to obtain the response control script, it also includes: after identifying that the response control script is executed, obtaining the execution result and the current status data of the system to update the monitoring data.
[0061] Specifically, after identifying that the response control script has been executed, that is, after the security control instruction is executed, the execution result and the current status data of the system are obtained to update the monitoring data, which is used for the system to evaluate the execution effect and make the next adaptive adjustment.
[0062] Figure 2 is a flow chart of a security defense method for a train control system provided according to an embodiment of the present invention. Based on the above embodiment, this embodiment further describes the perception optimization of monitoring data and provides an optional implementation scheme. Figure 2 As shown, the security defense method for the train control system of this embodiment may include:
[0063] S210, acquiring monitoring data in real time.
[0064] The monitoring data includes at least one of access control data, identity authentication data, security event and alarm data, system configuration and change data, environment and sensor data, user behavior data, and security indicator measurement data.
[0065] S220: Perform perception monitoring on the monitoring data to obtain system resource threat data.
[0066] Among them, system resource threat data refers to data that poses a threat to the train control system.
[0067] An optional method is to sense the monitoring data to obtain monitoring status data; the monitoring status data includes vehicle status, ground equipment status and environmental status; the monitoring status data is monitored to obtain system resource threat data; the system resource threat data includes dynamic resource usage of equipment, business characteristics and environmental changes.
[0068] Specifically, the perception tool may be called to perceive the monitoring data to obtain the monitoring status data, and then the monitoring status data may be monitored to obtain the system resource threat data.
[0069] It is understandable that through dynamic perception and monitoring and evaluation, security technology perceives and updates the understanding of the threat environment and proactively discovers system resource threat data in a timely manner.
[0070] S230, quantify the system resource threat data to obtain a system resilience index and a system resilience level, and dynamically update the system resilience index and the system resilience level in real time.
[0071] Specifically, the system resource threat data may be quantified to obtain the system resilience index and the system resilience level, and the system resilience index and the system resilience level may be dynamically updated in real time.
[0072] S240. Based on the monitoring data, correlation analysis is performed on the behavior patterns of each control system in the train control system to obtain a safety risk status.
[0073] S250: predicting a response strategy for the security risk status to obtain a target response strategy.
[0074] S260. Convert the target response strategy to obtain a response control script; wherein the response control script is used to drive the corresponding response control tool to perform response recovery operations on the train control system in the task execution environment.
[0075] The technical solution of the embodiment of the present invention is to obtain monitoring data in real time; wherein the monitoring data includes at least one of access control data, identity authentication data, security events and alarm data, system configuration and change data, environment and sensor data, user behavior data, and security indicator measurement data, and then sense and monitor the monitoring data to obtain system resource threat data, quantify the system resource threat data, obtain system elasticity indicators and system elasticity levels, and dynamically update the system elasticity indicators and system elasticity levels in real time, and then, based on the monitoring data, perform correlation analysis on the behavior patterns of each control system in the train control system to obtain the security risk state, and then predict the response strategy for the security risk state to obtain the target response strategy, and finally transform the target response strategy to obtain the response control script; wherein the response control script is used to drive the corresponding response control tool to implement response recovery operations on the train control system in the task execution environment. The above technical solution obtains the monitoring data of the train control system in real time to analyze and predict the security risk state and then determine the response strategy for active response, which can respond to the changing threat environment, and at the same time, in the event of a network attack, it can ensure the safe operation of the train control system.
[0076] On the basis of the above embodiments, train control related standards and known threat intelligence can also be stored, in addition to the experience, security policies, rules and other data in the operation process of the train control system. This information is used to assist the system in monitoring, analysis, planning and execution to achieve more efficient and accurate adaptive control.
[0077] It should be noted that the technical solution provided by the present invention is optimized and modified on the basis of the MAPE-K model in combination with the safety requirements of the train control system, giving the train control system the function of dynamically adjusting its behavior according to environmental changes, and it has the ability of self-repair, self-optimization and self-configuration. Details are as follows Figure 3As shown in the figure, A (Analysis) is association analysis, including data fusion analysis and behavior association analysis. Data fusion analysis includes preprocessing and feature extraction; behavior association analysis includes time series association, source association, target association, causal association, as well as scene splicing, scene restoration and scene prediction. Figure 4 As shown; Optionally, cluster analysis and artificial intelligence algorithms are used to mine the complementary, implicit and associated relationships between data contents, and attack scenario splicing, restoration and prediction are achieved based on the adaptive capabilities of data contents. C (coordination) is collaborative protection, that is, strategy determination, including adaptive response and consistency assessment, where adaptive response includes system resources, system configuration and security policies; consistency assessment includes consistency assessment of principle consistency and target consistency of system resources, system configuration and security policies, such as Figure 5 M (Monitoring) refers to perception monitoring, including dynamic perception and monitoring evaluation, such as Figure 6 E (Execute) is response recovery, including response implementation and function recovery. Through response recovery, the operation type, extended parameters, operation instruction data, etc. of the response implementation can be obtained, such as Figure 7 shown.
[0078] Figure 8 This is a schematic diagram of the structure of a security defense device for a train control system provided according to an embodiment of the present invention. This embodiment is applicable to how a train control system responds to network attacks. The device can be implemented in the form of hardware and / or software. The device can be configured in an electronic device that carries a security defense function for a train control system, such as a train control system; optionally, the device can be integrated with the control and sensor equipment of the train control system and deployed in layers at various levels of the train control system. Figure 8 As shown, the device comprises:
[0079] A monitoring data acquisition module 310 is used to acquire monitoring data in real time; wherein the monitoring data includes at least one of access control data, identity authentication data, security event and alarm data, system configuration and change data, environment and sensor data, user behavior data, and security indicator measurement data;
[0080] The correlation analysis module 320 is used to perform correlation analysis on the behavior patterns of each control system in the train control system based on the monitoring data to obtain the safety risk status;
[0081] A strategy determination module 330 is used to predict a response strategy for a security risk state and obtain a target response strategy;
[0082] A response recovery module 340 is configured to transform a target response policy to obtain a response control script, where the response control script is used to drive a corresponding response control tool to perform a response recovery operation on the train control system in a task execution environment.
[0083] In the technical solution of the embodiment of the present invention, monitoring data is obtained in real time, where the monitoring data includes at least one of access control data, authentication data, security event and alarm data, system configuration and change data, environment and sensing data, user behavior data, and security metric data. Then, based on the monitoring data, an association analysis is performed on the behavior patterns of each control system in the train control system to obtain a security risk state. Furthermore, a response policy prediction is performed on the security risk state to obtain a target response policy. Finally, the target response policy is transformed to obtain a response control script, where the response control script is used to drive a corresponding response control tool to perform a response recovery operation on the train control system in a task execution environment. The above technical solution can actively respond by analyzing and predicting the security risk state after obtaining the monitoring data of the train control system in real time, can cope with the changing threat environment, and can ensure the safe operation of the train control system in the event of a cyber attack.
[0084] Optionally, the association analysis module 320 is specifically configured to:
[0085] Perform a data fusion analysis on the monitoring data to obtain system behavior characteristics;
[0086] According to the system behavior characteristics, perform a behavior association analysis on the behavior patterns of each control system in the train control system to obtain a security risk state.
[0087] Optionally, the policy determination module 330 is specifically configured to:
[0088] Perform a response policy prediction on the security risk state to obtain candidate response policies, where the candidate response policies include system resources, system configurations, and security policies;
[0089] Evaluate the candidate response policies to obtain a target response policy and output the target response policy.
[0090] Optionally, the device further includes a perception monitoring module, configured to:
[0091] Before performing an association analysis on the behavior patterns of each control system in the train control system based on the monitoring data to obtain a security risk state, perform a perception monitoring on the monitoring data to obtain system resource threat data;
[0092] Quantify the system resource threat data to obtain a system resilience index and a system resilience level, and update the system resilience index and the system resilience level in real time and dynamically.
[0093] Optionally, the perception monitoring module is specifically used for:
[0094] The monitoring data is sensed to obtain monitoring status data; the monitoring status data includes vehicle status, ground equipment status and environmental status;
[0095] The monitoring status data is monitored to obtain system resource threat data; the system resource threat data includes dynamic resource usage of equipment, business characteristics and environmental changes.
[0096] Optionally, the device further includes a data updating module, which is used to:
[0097] After converting the target response strategy to obtain the response control script, after identifying that the response control script has been executed, the execution result and the current status data of the system are obtained to update the monitoring data.
[0098] The security defense device for a train control system provided in an embodiment of the present invention can execute the security defense method for a train control system provided in any embodiment of the present invention, and has functional modules and beneficial effects corresponding to the execution method.
[0099] According to an embodiment of the present invention, the present invention also provides an electronic device, a readable storage medium and a computer program product.
[0100] Fig. 9 It is a schematic diagram of the structure of an electronic device for implementing the safety defense method for a train control system according to an embodiment of the present invention.
[0101] Fig. 9 A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0102] like Fig. 9As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0103] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0104] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as a security defense method for a train control system.
[0105] In some embodiments, the security defense method for the train control system may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the security defense method for the train control system described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute the security defense method for the train control system in any other appropriate manner (for example, by means of firmware).
[0106] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0107] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0108] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0109] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).
[0110] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0111] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.
[0112] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.
[0113] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A security defense method for a train control system, characterized in that: include: Acquire monitoring data in real time; wherein the monitoring data includes at least one of access control data, identity authentication data, security event and alarm data, system configuration and change data, environment and sensor data, user behavior data, and security indicator measurement data; Based on the monitoring data, correlation analysis is performed on the behavior patterns of each control system in the train control system to obtain a safety risk status; Predicting a response strategy for the security risk status to obtain a target response strategy; The target response strategy is transformed to obtain a response control script; wherein the response control script is used to drive the corresponding response control tool to perform a response recovery operation on the train control system in a task execution environment.
2. The method according to claim 1, characterized in that Based on the monitoring data, the behavior patterns of each control system in the train control system are correlated and analyzed to obtain the safety risk status, including: Performing data fusion analysis on the monitoring data to obtain system behavior characteristics; According to the system behavior characteristics, a behavior correlation analysis is performed on the behavior patterns of each control system in the train control system to obtain a safety risk status.
3. The method according to claim 1, characterized in that Predicting a response strategy for the security risk state to obtain a target response strategy includes: Predicting a response strategy for the security risk state to obtain a candidate response strategy; the candidate response strategy includes system resources, system configuration, and security strategy; The candidate response strategies are evaluated to obtain a target response strategy, and the target response strategy is used.
4. The method according to claim 1, characterized in that: Based on the monitoring data, the behavior patterns of the control systems in the train control system are analyzed for correlation, and before the safety risk status is obtained, the following is also included: Performing perception monitoring on the monitoring data to obtain system resource threat data; The system resource threat data is quantified to obtain a system resilience index and a system resilience level, and the system resilience index and the system resilience level are dynamically updated in real time.
5. The method according to claim 4, characterized in that The monitoring data is sensed and monitored to obtain system resource threat data, including: The monitoring data is sensed to obtain monitoring status data; the monitoring status data includes vehicle status, ground equipment status and environmental status; The monitoring status data is monitored to obtain system resource threat data; the system resource threat data includes dynamic resource usage of equipment, business characteristics and environmental changes.
6. The method according to claim 1, characterized in that After converting the target response strategy to obtain a response control script, the following steps are also included: After identifying that the response control script is executed, the execution result and the current status data of the system are obtained to update the monitoring data.
7. A safety defense device for a train control system, characterized in that: include: A monitoring data acquisition module, used to acquire monitoring data in real time; wherein the monitoring data includes at least one of access control data, identity authentication data, security event and alarm data, system configuration and change data, environment and sensor data, user behavior data, and security indicator measurement data; A correlation analysis module, used to perform correlation analysis on the behavior patterns of each control system in the train control system based on the monitoring data to obtain a safety risk status; A strategy determination module, used to predict the response strategy for the security risk state and obtain a target response strategy; A response recovery module is used to transform the target response strategy to obtain a response control script; wherein the response control script is used to drive the corresponding response control tool to perform a response recovery operation on the train control system in a task execution environment.
8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the security defense method for the train control system according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the safety defense method for a train control system according to any one of claims 1 to 6 when executed.
10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the computer program implements the safety defense method for a train control system according to any one of claims 1 to 6.