Railway train control system security data network monitoring system, method, equipment and medium
By deploying a monitoring system for channel monitoring equipment and center maintenance equipment in the railway train control system, the channel communication data of the secure data network is collected and analyzed in real time, the problem that existing systems cannot accurately locate communication abnormalities is solved, and more efficient fault analysis and operation and maintenance status repair is achieved.
Patent Information
- Application Number
- CN202510190693.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-27
AI Technical Summary
The existing railway train control system network management system cannot accurately locate communication abnormalities in the secure data network and record communication data in full, resulting in increased difficulty in fault analysis.
A railway train control system security data network monitoring system is designed, and the channel communication data of station equipment and central equipment is collected in real time through channel monitoring equipment, and sent to the central maintenance equipment through an independent supervision data network. The center maintenance equipment performs multi-dimensional processing and intelligent analysis, including channel traffic analysis, RTT time abnormality warning analysis, and communication connection group abnormality inspection analysis to determine abnormalities in channel communication data.
It realizes accurate abnormal positioning and data collection of the railway train control system security data network, improves the state repair capability of operation and maintenance, and reduces the difficulty of fault repair.
Smart Images

Figure CN120050304A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of rail transit, and particularly relates to a monitoring system, method, device and medium for the safety data network of a railway train control system. Background Art
[0002] As a key facility of the train control system, the safety data network of the railway train control system is currently mainly maintained by a network management system. The network management system can maintain devices such as switches, firewalls, and network management servers in the safety data network, including network topology, performance management, alarm management, security management, and log management, providing good support for the safety maintenance and fault diagnosis of the safety data network. However, the safety data network is the carrier of secure communication between safety devices (train control center TCC, interlocking, RBC, and TSRS) in the train control system. A large amount of data is carried in the network, and the interaction period between them is very short, all of which are millisecond-level communications. As long as there are abnormal communication data (such as packet sticking, packet loss, and packet error), various communication anomalies in the communication session between devices will be caused. For these abnormal situations, the existing network management system cannot accurately locate the cause of the fault, nor can it completely record the communication data, which increases the difficulty for users and device manufacturers to analyze the fault. Summary of the Invention
[0003] To solve the above problems, a monitoring system, method, device and medium for the safety data network of a railway train control system provided by this application have the effects of strong sampling accuracy, strong security, and precise abnormal positioning. Through intelligent analysis, it can realize the transformation of the operation and maintenance of the safety data network from fault repair to status repair.
[0004] To achieve the above object, this application adopts the following technical solutions:
[0005] In a first aspect, this application further provides a monitoring system for the safety data network of a railway train control system, including a channel monitoring device and a central maintenance device. The channel monitoring device is deployed on the station device and / or the central device side in the safety data network of the railway train control system. The channel monitoring device and the central maintenance device are independently networked to form a supervision data network;
[0006] The channel monitoring device is used to collect the channel communication data of the station device and / or the central device in the safety data network of the railway train control system in real time; it is also used to send the collected channel communication data to the central maintenance device through the supervision data network;
[0007] The central maintenance device is used to receive the channel communication data collected in real time and perform multi-dimensional processing on the channel communication data to determine the abnormal analysis result of the channel communication data.
[0008] Further, the channel monitoring device is also used to collect the channel communication data of the station equipment and / or the central equipment of the railway train control system safety data network by combining optical fiber splitting monitoring, Ethernet TAP monitoring, and port mirroring monitoring.
[0009] Further, the central maintenance device is also used to receive the channel communication data collected in real time, and perform channel traffic analysis, RTT time anomaly warning analysis, and communication connection group anomaly inspection analysis on the channel communication data to determine the anomaly of the channel communication data of the railway train control system safety data network.
[0010] Further, the central maintenance device includes a network topology unit, a data analysis unit, and a channel warning unit;
[0011] The network topology unit is used to receive the channel communication data collected in real time, and parse and store the channel communication data;
[0012] The data analysis unit is used to perform channel traffic analysis, RTT time anomaly warning analysis, and communication connection group anomaly inspection analysis on the channel communication data to determine the anomaly analysis result of the channel communication data;
[0013] The channel warning unit is used to generate an anomaly alarm and display the anomaly alarm in a visual manner based on the anomaly analysis result of the channel communication data.
[0014] Further, the network topology unit is also used to display the main line network topology diagram of the safety data network in a visual manner, and display the channel session traffic ranking, channel IP traffic ranking, and channel port traffic ranking in a list form.
[0015] Further, the data analysis unit includes: a channel traffic analysis module, an RTT time anomaly warning analysis module, and a communication connection group anomaly inspection analysis module;
[0016] The channel traffic analysis module is used to determine the anomaly analysis result of the channel communication data by using a real-time active anomaly detection algorithm based on the time series characteristics of the channel communication data;
[0017] The RTT time anomaly warning analysis module is used to determine the anomaly analysis result of the channel communication data by using an adaptive retransmission algorithm based on the RTT time of the channel communication data;
[0018] The communication connection group anomaly inspection analysis module is used to determine the anomaly analysis result of the channel communication data based on the IP information in the network layer IPV4 protocol packet in the channel communication data.
[0019] Further, the channel warning unit is also used to receive the device alarm messages collected in real time and perform incremental processing on the device alarm messages.
[0020] In a second aspect, the present application provides a method for monitoring the safety data network of a railway train control system, including:
[0021] The channel monitoring device collects the channel communication data of the station device and / or the central device in the safety data network of the railway train control system in real time, and sends the collected channel communication data to the central maintenance device through the supervision data network;
[0022] The central maintenance device receives the channel communication data collected in real time, and performs multi-dimensional processing on the channel communication data to determine the abnormal analysis result of the channel communication data.
[0023] Further, the channel monitoring device adopts a combination of optical fiber splitting monitoring, Ethernet TAP monitoring, and port mirroring monitoring to collect the channel communication data of the station device and / or the central device in the safety data network of the railway train control system in real time.
[0024] Further, the central maintenance device receives the channel communication data collected in real time, and performs channel traffic analysis, RTT time abnormal early warning analysis, and communication connection group abnormal inspection analysis on the channel communication data to determine the abnormality of the channel communication data of the safety data network of the railway train control system.
[0025] In a third aspect, the present application further provides an electronic device, including: a processor and a memory;
[0026] The processor is coupled with the memory;
[0027] Wherein, the processor is configured to read and execute the program or instruction stored in the memory, so that the device executes the method as described in the second aspect.
[0028] In a fourth aspect, the present application further provides a computer-readable storage medium, storing a computer program, and when the program is executed by a processor, the method as described in the second aspect is implemented.
[0029] The technical solution provided by the present application has at least the following technical effects or advantages:
[0030] The solution of this application deploys the channel monitoring devices in the system to the station devices and / or the central device side of the railway train control system safety data network, and independently forms a supervision data network with the central maintenance device to collect data, which can be physically isolated from the main line network of the safety data network and has strong security. The data is collected by combining fiber optic splitting monitoring, Ethernet TAP monitoring, and port mirroring monitoring. Based on the characteristics of different hardware devices used in the three methods, it can meet the requirements of different application scenarios in the safety data network and ensure the sampling accuracy of the channel communication data in the safety data network for collection. The central maintenance device receives the channel communication data and conducts intelligent analysis on the channel communication data, such as channel traffic analysis, RTT time anomaly early warning analysis, and communication connection group anomaly inspection analysis, etc., which can accurately determine the anomalies in the channel communication data, help to timely discover the potential faults in the safety data network, and then realize the transformation of the safety data network operation and maintenance from fault repair to condition-based repair.
[0031] Other features and advantages of this application will be described in the subsequent specification. And, partly, they will become obvious from the specification, or be understood by implementing this application. The objectives and other advantages of this application can be realized and obtained through the structures pointed out in the specification, claims, and drawings. Brief Description of the Drawings
[0032] In order to more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0033] Figure 1 It is a schematic structural diagram of a railway train control system safety data network monitoring system in an embodiment of this application;
[0034] Figure 2 It is a schematic structural diagram of a railway train control system safety data network monitoring system incorporated into the railway train control system safety data network in an embodiment of this application;
[0035] Figure 3 It is a schematic data processing flow diagram of the network topology unit of the central maintenance device in an embodiment of this application;
[0036] Figure 4 It is a schematic flow diagram of the real-time active anomaly detection algorithm in an embodiment of this application;
[0037] Figure 5 It is a schematic flow diagram of the adaptive retransmission algorithm in an embodiment of this application;
[0038] Figure 6It is a schematic flow diagram of communication connection group anomaly inspection in the embodiments of the present application;
[0039] Figure 7 It is a schematic flow diagram of a monitoring method for the safety data network of a railway signaling system provided in the embodiments of the present application;
[0040] Figure 8 It is a schematic structural diagram of an electronic device provided in the embodiments of the present application. Detailed implementation manners
[0041] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0042] Figure 1 It is a schematic structural diagram of a monitoring system for the safety data network of a railway signaling system in the embodiments of the present application; Figure 2 It is a schematic structural diagram of a monitoring system for the safety data network of a railway signaling system incorporated into the safety data network of a railway signaling system in the embodiments of the present application;
[0043] As Figure 1 , Figure 2 shown, a monitoring system for the safety data network of a railway signaling system proposed by the present application includes a channel monitoring device and a central maintenance device, and its structure in the safety data network of a railway signaling system is as Figure 1As shown in the figure, the channel monitoring device is deployed on the side of the station equipment (TCC or interlocking) and / or the central equipment (RBC or TSRS) in the safety data network of the railway train control system, and is used to collect the channel communication data of the station equipment and / or the central equipment in the safety data network of the railway train control system in real time. The channel monitoring device is independently networked with the central maintenance device, which is called the supervision data network and does not affect the normal communication of the main line of the safety data network of the railway train control system. The channel monitoring device sends the collected channel communication data to the central maintenance device through the supervision data network. The central maintenance device is used to receive the channel communication data collected in real time, and perform multi-dimensional processing and analysis on the channel communication data to determine the abnormal analysis result of the channel communication data. The channel communication data refers to the communication data transmitted through the network channels between the devices in the safety data network of the railway train control system. The channel communication data includes: channel physical status, communication service data, device alarm information, etc. The channel physical status includes physical quantities such as data traffic, channel status, and optical power. The data traffic refers to the number of bytes of communication data monitored per second (KB / s or MB / s); the channel status is the channel communication status of the main line of the safety data network, which can be defined as an enumerated quantity and is divided into normal, abnormal, and undetected. The abnormal can be further divided into level 1, level 2, level 3, etc. By statistically analyzing multiple physical quantities included in the channel physical status and combining the number of error data packets and discarded data packets within a period of time, the communication ability and communication quality of the channels in the safety data network of the railway train control system can be evaluated. The communication service data refers to the service interaction data between the communication devices in the safety data network of the railway train control system, such as the temporary speed limit command of the TSRS device in accordance with the frame format of the RSSP security protocol. For the convenience of describing the technical solution of this application, the safety data network of the railway train control system in this application can also be referred to as the safety data network.
[0044] According to different access methods to the safety data network, the channel monitoring device adopts three monitoring schemes to collect the channel communication data of the station equipment and / or the central equipment in the safety data network of the railway train control system in real time, which can ensure the sampling accuracy of the channel communication data of the safety data network. The three monitoring schemes include: optical fiber splitting monitoring, Ethernet TAP monitoring, and port mirroring monitoring.
[0045] Optical fiber splitting monitoring: The switches in the ring network of the safety data network are connected by optical fibers. A splitter device is added on one side close to the ring network to monitor physical quantities such as the optical power of the safety data network. Such as Figure 1As shown in the figure, on one side close to the station (TCC or interlocking) and / or the central equipment (RBC or TSRS), a splitter is inserted into the communication line of the safety data network. Through the splitter, a monitoring interface connection channel is separated to connect to the channel monitoring equipment, so as to monitor physical quantities such as the optical power of the safety data network. As a passive device, the splitter has a low failure rate and little possibility of affecting the normal communication of the main line of the safety data network. It can physically isolate the supervision data network and the main line network of the safety data network, with strong security.
[0046] Ethernet TAP monitoring: An Ethernet TAP device is added on one side of the safety data network close to the ring network to fully monitor the channel communication data of the safety data network. As Figure 1 shown in the figure, on one side close to the station equipment (TCC or interlocking) and / or the central equipment (RBC or TSRS), the Ethernet TAP device is inserted into the signal safety data network. Through the M port of the TAP device, a monitoring interface connection channel is led out to connect to the channel monitoring equipment, so as to fully monitor the channel communication data of the safety data network. The TAP device can monitor the equipment within the local area network without filtering or discarding the monitoring information, and can fully monitor the channel communication data of the safety data network.
[0047] Port mirroring monitoring: On one side of the safety data network close to the ring network, port mirroring is used on the existing switches in the safety data network to forward the data traffic of the key ports of the safety network to the mirror port. Through the monitoring of the mirror port, the channel communication data of the safety data network is monitored. As Figure 1 shown in the figure, on one side close to the station equipment (TCC or interlocking) and / or the central equipment (RBC or TSRS), using the existing switch equipment in the safety data network, one of the spare ports of the switch is used as the mirror port, and the data traffic of the key ports of the safety data network is forwarded to the mirror port. The mirror port is connected to the channel monitoring equipment to monitor the communication service data of the safety data network. The port mirroring function means that on the switch, the data traffic of one or more source ports is forwarded to a specified port to monitor the network data. The specified port is called the "mirror port" or "destination port". In industrial switches, a network data operation unit and a management operation unit are generally set, and the port mirroring function generally executes operations through the management operation unit. Therefore, enabling the port mirroring function will not affect the normal operation of the current switch.
[0048] In the three monitoring schemes, different hardware devices are used to collect the channel communication data of the safety data network. The characteristics of different hardware devices can meet the requirements of different application scenarios in the safety data network and ensure the sampling accuracy of collecting the channel communication data of the safety data network, while not affecting the channel communication quality of the main line of the safety data network. The hardware device uses a dedicated acquisition chip with high time precision, which can further meet the requirement of millisecond-level event resolution of the safety data network. The acquisition card and the acquisition card driver software in the channel monitoring device convert the physical signals collected by the hardware device into digital signals, which are then convenient for computer software to process. The converted digital signals are used as the channel communication data of the safety data network, and the collected channel communication data is sent to the central maintenance device through the supervision data network.
[0049] On the basis of completing the connection with the channel monitoring device, the central maintenance device performs multi-dimensional processing on the channel communication data of the station equipment and / or the central equipment in the railway train control system safety data network collected by the channel monitoring device in real time. The multi-dimensional processing includes real-time data reception, protocol parsing, data storage, data analysis, abnormal warning and other processing. The central maintenance device includes a network topology unit, a data analysis unit, and a channel warning unit. The network topology unit is used to receive the channel communication data collected in real time, parse and store the channel communication data; it is also used to display the network topology diagram of the main line of the safety data network in a visual manner, and display information such as the channel session traffic ranking, the channel IP traffic ranking, and the channel port traffic ranking in a list form. The data analysis unit is used to perform channel traffic analysis, RTT time abnormal early warning analysis, and communication connection group abnormal inspection analysis on the channel communication data to determine the abnormal analysis result of the channel communication data; the channel warning unit is used to generate an abnormal warning based on the abnormal analysis result of the channel communication data and display the abnormal warning in a visual manner.
[0050] The network topology unit of the channel monitoring device and the central maintenance device conducts data interaction through subscription and publication (such as MQTT). The core of subscription and publication is the determination of the topic. According to the set topic, the subscriber only accepts the data of the subscribed topic, which is a reliable remote communication protocol. The channel monitoring device will conduct a preliminary protocol analysis on the real-time monitored channel communication data, mark different protocol data (that is, mark which type of protocol this is), and then put it into the topic related to the protocol. The central maintenance device will process the messages of different topics correspondingly according to the subscribed different topics (first judge the topic type, and then distribute them to different processing programs). After receiving the messages of different topics, the central maintenance device will distribute them to different processing units. At this time, the received channel communication data are all original and unprocessed data (usually byte arrays), which are not very suitable for direct analysis and interface display. Therefore, for the received channel communication data, different data structure conversion processing is carried out based on the railway signal safety communication protocol, that is, hierarchical protocol analysis processing of the channel communication data based on the RSSP protocol (railway signal safety communication protocol). The channel communication data mainly follows two protocols, RSSP-I and RSSP-II of the railway signal safety communication protocol. The parsing process of the RSSP security protocol depends on what data is monitored, which is different from the general sequential execution application program process and belongs to an event-driven process. Therefore, a processing method combining a finite state machine and a timer is adopted for the parsing of the above channel communication data following the security protocol. The finite state machine has several attributes, specifically the current state (the current state of the state machine), the event (which can also be called a condition), the action (the action executed after the condition is met. After the action is executed, it can migrate to a new state or still maintain the original state. The action is not necessary. When the condition is met, no action can also be executed and directly migrate to a new state), and the next state (the new state to be migrated to after the condition is met. The "next state" is relative to the "current state". Once the "next state" is activated, it becomes the new "current state"). The timer is a technology often used in the field of RSSP security protocol communication technology to handle the situation of message waiting timeout during the communication process. During the communication process, normally, after a data frame with information is sent, the receiving party needs to send an acknowledgment message back to the sending party to let the sending party know that the data frame has been successfully received by the receiving party before continuing to send the subsequent data frames. This is done to ensure that the receiving party can receive the messages in sequence and completely. However, if the message fails to be successfully received by the receiving party (such as the data frame is lost during transmission or the transmission process is garbled) or the acknowledgment message of the receiving party fails to reach the sending end, if there is no time limit at this time, the sending end will wait forever, resulting in the entire interaction process being blocked.The time of the timer is generally set in advance (this time may vary for different devices or manufacturers), and if no confirmation is received within the timer time after the previous data frame is sent, the previous data frame will be retransmitted until a confirmation message is received or the number of retransmissions exceeds the upper limit (at this time, the connection between the two parties will be disconnected). The processing method combining the finite state machine and the timer includes: performing hierarchical parsing on each frame of the received channel communication data, that is, for each frame of the received channel communication data, performing hierarchical parsing based on the application layer, security layer, transport layer, network layer, link layer, and physical layer, and generating message type events of the state machine within each layer protocol; processing the state machine within each layer protocol in the order of physical layer - link layer - network layer - transport layer - security layer - application layer - security layer - transport layer - network layer - link layer - physical layer, so that the state machine transfers from the current state to the next state, and then obtaining the parsed channel communication data. When processing the state machine, traverse all current timer states to determine whether there is a timeout. If there is a timeout, generate a timeout event to trigger message retransmission, that is, if the confirmation time of the received message exceeds the set timeout time, generate a timeout event to trigger the message retransmission mechanism.
[0051] The above hierarchical parsing and processing of the protocol for channel communication data based on the RSSP protocol (Railway Signal Safety Communication Protocol) can capture the data packets of the channel communication data during network transmission using wireshark (a network protocol analysis tool) and save them in the form of a pcap file. Wireshark performs detailed parsing on each captured data packet to obtain the protocol hierarchy structure corresponding to each data packet and the values of the protocol fields; performs unpacking, repackaging, and verification processing on the parsed channel communication data; and stores the processed channel communication data in a database. When storing the channel communication data, due to the large amount of data, the snowflake algorithm is used to ensure the uniqueness of the data. The database used in this application can be a redis database, or other high-performance key-value storage databases or relational database repositories. The specific method of storing data in the database is a conventional means for those skilled in the art and will not be elaborated here.
[0052] Figure 3 It is a schematic diagram of the data processing flow of the network topology unit of the central maintenance device in the embodiment of this application.
[0053] Such as Figure 3 shown, before the network topology unit of the central maintenance device performs hierarchical parsing and processing of the protocol for channel communication data, it also performs processing in multiple dimensions such as channel session traffic ranking, channel IP traffic ranking, and channel port traffic ranking to obtain multi-dimensional ranking data of the channel communication data.
[0054] The channel session traffic ranking processing includes:
[0055] Step 1: Create a traffic buffer for five-tuples (source IP, source port, destination IP, destination port, protocol).
[0056] Step 2: Set to transfer the data in the buffer to the Redis database every second, and count the number of packets and the total number of bytes therein.
[0057] Step 3: Sort all five-tuples according to the number of bytes counted per second, and arrange them in descending order of the number of bytes.
[0058] Step 4: Determine whether a stop timer is set for the current line during each statistics. There will be no such timer during the first judgment, and a new stop timer will be set at this time; then, during each subsequent statistics, determine whether the timer is triggered (triggered means that the timing time of the stop timer meets the specified stop time). If triggered, clear the traffic buffer, clear the previous stop timer, and then set a new stop timer.
[0059] Step 5: Repeat Steps 2 - 4 to obtain the channel session traffic ranking data of the channel communication data.
[0060] The channel IP traffic ranking process includes:
[0061] Step 1: Create a channel IP traffic buffer.
[0062] Step 2: Set to transfer the data in the buffer to the Redis database every second, and count the number of packets and the total number of bytes therein.
[0063] Step 3: Sort all channel IPs according to the number of bytes counted per second, and arrange them in descending order of the number of bytes.
[0064] Step 4: Determine whether a stop timer is set for the current line during each statistics. There will be no such timer during the first judgment, and a new stop timer will be set at this time; then, during each subsequent statistics, determine whether the timer is triggered (triggered means that the timing time of the stop timer meets the specified stop time). If triggered, clear the traffic buffer, clear the previous stop timer, and then set a new stop timer.
[0065] Step 5: Repeat Steps 2 - 4 to obtain the channel IP traffic ranking data of the channel communication data.
[0066] The channel port traffic ranking process includes:
[0067] Step 1: Create a channel port traffic buffer.
[0068] Step 2: Set to transfer the data in the buffer to the Redis database every second, and count the number of packets and the total number of bytes therein.
[0069] Step 3: Sort all channel ports according to the number of bytes counted per second, arranging them in descending order of the number of bytes.
[0070] Step 4: Determine whether a stop timer is set for the current line during each count. There won't be one during the first judgment, and at this time, a new stop timer will be set; during each subsequent count, determine whether the timer is triggered (triggered means that the timing time of the stop timer meets the specified stop time). If triggered, clear the traffic buffer, clear the previous stop timer, and then set a new stop timer.
[0071] Step 5: Repeat steps 2 - 4 to obtain the channel port traffic ranking data of the channel communication data.
[0072] The network topology unit of the central maintenance device analyzes and records logs for the stored channel communication data, restores the interaction process according to the service logic interaction logic and the communication timing sequence of the channel communication data, and displays the network topology diagram of the main line of the security data network in a visual manner; based on the obtained multi - dimensional ranking data of the channel communication data, display the corresponding ranking information in a list form, namely, channel session traffic ranking, channel IP traffic ranking, channel port traffic ranking, etc.
[0073] The data analysis unit of the central maintenance device conducts channel traffic analysis, RTT time anomaly warning analysis, and communication connection group anomaly check analysis on the monitored channel communication data to determine the channel communication data anomaly analysis results; the channel communication data anomaly analysis results can be presented in a visual way.
[0074] Channel traffic analysis:
[0075] Based on the time - series characteristics of the obtained channel communication data, adopt a real - time active anomaly detection algorithm to determine the channel communication data anomaly analysis results. The real - time active anomaly detection algorithm includes three stages: the buffering stage, the training stage, and the verification stage; the buffering stage refers to the stage from the start of the real - time active anomaly detection algorithm to the set buffering time length; the training stage refers to after the buffering stage ends, using the channel communication data sequence corresponding to the specified training time length obtained in the buffering stage as the channel communication data training set of the machine - learning model to train the machine - learning model and predict the channel communication data at the next moment; the verification stage refers to after the training stage ends, performing anomaly detection on the real - time channel communication data obtained at the next moment.
[0076] Specifically, in the buffering stage, a machine learning model (such as a Long Short-Term Memory (LSTM) model) is constructed, and the model parameters and buffering time length are initialized. Since the amount of channel communication data obtained at the beginning of the active anomaly detection algorithm does not meet the minimum dataset size for training and thus model training cannot be carried out, during the stage from the start of the real-time active anomaly detection algorithm to the set buffering time length, channel communication data is obtained in real time and saved. After the buffering stage ends, in the training stage, a channel communication data sequence corresponding to a specified training time length is obtained as the channel communication data training set for the machine learning model. The specified training time length is usually the same as the buffering time length. The machine learning model is trained using the channel communication data training set. During the training process, an evaluation index - Average Absolute Relative Error (AARE) - which quantifies the difference between the real-time channel communication data and the predicted channel communication data at the same moment, is introduced. Each time real-time channel communication data is obtained, the machine learning model is trained. After each training, the channel communication data for the next moment is predicted to obtain the predicted channel communication data for the next moment, and this predicted channel communication data is cached until the real-time channel communication data for the next moment is obtained, at which time the AARE value between the real-time channel communication data and the predicted channel communication data is calculated and saved. After the training stage ends, in the verification stage, a dual-strategy anomaly detection mechanism with secondary judgment is adopted to determine the channel traffic anomaly analysis result. The dual-strategy anomaly detection mechanism with secondary judgment includes a first detection mechanism and a second detection mechanism. The first detection mechanism includes: when real-time channel communication data is obtained, calculate a first difference evaluation index AARE t of the difference between the real-time channel communication data at the current moment t and the corresponding predicted channel communication data; calculate the mean and standard deviation of the difference index of the difference between the channel communication data sequence from the start of the training stage to the current moment t and the corresponding predicted channel communication data, and according to the 3-σ criterion in statistics, determine the anomaly threshold thd1 of the difference evaluation index of the difference between the real-time channel communication data at the current moment t and the corresponding predicted channel communication data; compare the first difference evaluation index AARE t at the current moment t with the anomaly threshold thd1 of the difference evaluation index. If AARE t < t hd1 , then the real-time channel communication data at the current moment t is normal data; if AARE t ≥ t hd1 , then the channel communication data sequence during the most recent training time length at the current moment t is used as a training set to retrain the machine learning model, and then the real-time channel communication data at the current moment t is predicted, and a second difference evaluation index AAREt; The second difference evaluation index at the current moment t AARE Compare t with the abnormal threshold thd1 of the difference evaluation index. If AARE t≥t hd1 , then the real-time channel communication data at the current moment t is abnormal data. The second detection mechanism is similar to the first detection mechanism. The difference is that in the second detection mechanism, when determining the abnormal threshold thd1 of the difference evaluation index that determines the difference between the real-time channel communication data at the current moment t and the corresponding predicted channel communication data, the channel communication data sequence and the corresponding predicted channel communication data from the start of the training phase to the current moment t are all normal data. The above channel traffic analysis results can be displayed in a visual way.
[0077] RTT time abnormal warning analysis:
[0078] Based on the RTT time of the channel communication data, use the adaptive retransmission algorithm to determine the abnormal analysis result of the channel communication data. In the security data network, for the channel communication data when security devices communicate pairwise, there is a transmission time in the network. The time elapsed from when the sending device sends data to when the receiving device responds or replies data is called the RTT time. Since the communication between security devices faces a complex data network and the RTT time is variable, the estimated value of the RTT time of the channel communication data is updated in real time in the adaptive retransmission algorithm, and the estimated value of the RTT time of the channel communication data is compared with the set threshold to determine the abnormal analysis result of the RTT time of the channel communication data. Figure 5 It is a schematic flow chart of the adaptive retransmission algorithm in the embodiment of the present application.
[0079] Specifically, as Figure 5As shown, when the adaptive retransmission algorithm starts to execute, the parameter α for calculating the estimated value of the RTT time of the channel communication data is initialized. This parameter is a smoothing factor, usually taking values between 0 and 1, and can be set to 0.125. Specify the channel to be analyzed, the target device IP, and the source device IP. Extract the data transmission and reception pairs of the communication between the target device IP and the source device IP from the received channel communication data and calculate the RTT time of the data transmission and reception pairs. If it is the first time to calculate the RTT time of the data transmission and reception pairs, record it as SampleRTT and use it as the estimated value EstimatedRTT of the RTT time of the channel communication data. If it is not the first time to calculate the RTT time of the data transmission and reception pairs, then combine the RTT time of the first calculation of the data transmission and reception pairs, the estimated value EstimatedRTT of the RTT time of the channel communication data, and the parameter α for calculating the estimated value to recalculate the estimated value EstimatedRTT of the RTT time of the channel communication data. Compare the estimated value EstimatedRTT of the RTT time of the channel communication data with the set threshold. If it exceeds the threshold, it is determined that the RTT time of the channel communication data is abnormal. If it does not exceed the threshold, the RTT time of the channel communication data is normal. Loop through the above steps to calculate the estimated value of the RTT time of the newly received channel communication data, and then determine the abnormality of the RTT time of the channel communication data. When the RTT time of the channel communication data is abnormal, an abnormal alarm is issued.
[0080] Abnormal check and analysis of communication connection group:
[0081] The communication connection group of the secure data network refers to two independent ring networks, divided into the left ring network and the right ring network. The interface IP addresses of the application devices of the two ring networks are used. The left ring network uses odd network segments, and the right ring network uses even network segments. A channel monitoring device in the secure data network only monitors one ring network, and the IP network segment of this ring network is set in advance. The source IP address and destination IP address carried in the network layer IPV4 protocol packet in the channel communication data monitored by the channel monitoring device in real time are within the IP network segment of this ring network and comply with the "Railway Signal Secure Data Network (TB / T 3547)" standard. There is physical isolation between the two ring networks, and the IP addresses used by the security devices in the two networks are generally not in the same network segment. Messages sent from other network segments should not appear in an independent ring network. To prevent the ring network from being connected in series and causing chaos in the secure data network messages, an abnormal check of the communication connection group is performed. Real-time obtain the network layer data stored after protocol analysis of the channel communication data. Based on the regulations of the "Railway Signal Secure Data Network (TB / T 3547)" standard, judge the IP information in the network layer IPV4 protocol to determine whether there is a series connection abnormality in the independent ring network, and then determine the abnormality of the channel communication data of the secure data network. Figure 6 This is a schematic flow chart of the abnormal check of the communication connection group in the embodiment of the present application.
[0082] Specifically, as Figure 6 shown, obtain the network layer data stored after protocol parsing of the channel communication data in real time; obtain the source IP address and destination IP address in the IPv4 protocol packet structure from the network layer data; compare whether the IP network segment in the IPv4 protocol packet structure is the same as the ring network segment where the security device is located. If they are not the same, determine whether there is a series connection anomaly in the independent ring network, and then determine the anomaly of the channel communication data of the security data network, and prompt the anomaly; loop through the above steps to check and analyze the communication connection group anomaly of the newly received channel communication data.
[0083] The channel alarm unit of the central maintenance device generates an anomaly alarm and displays the anomaly alarm in a visual manner based on the above channel communication data anomaly analysis result.
[0084] The channel monitoring device and the channel alarm unit of the central maintenance device perform data interaction (such as mqtt) through the method of subscription and publication. The channel monitoring device monitors the station (TCC or interlocking) and / or the central device in real time, identifies the device alarm message generated by the anomaly, and publishes the identified device alarm message as incremental alarm information. The channel alarm unit of the central maintenance device subscribes to the incremental alarm information published by the channel monitoring device from the channel monitoring device and performs incremental processing on the device alarm message.
[0085] Specifically, the channel alarm unit of the central maintenance device subscribes to the incremental alarm information published by the channel monitoring device, and obtains the channel monitoring device ID in the incremental alarm information; obtains the set of all channel monitoring device IDs stored in advance, and determines whether the set contains the channel monitoring device ID in the incremental alarm information. If it contains, the process ends and the incremental alarm information is not processed; if it contains, according to the recovery time in the incremental alarm information, it is determined whether the incremental alarm information is a new alarm or an alarm recovery; if the recovery time in the incremental alarm information is empty, the incremental alarm information is a new alarm, queries the preset alarm filtering rule table in the database, and obtains the corresponding alarm filtering rule set according to the channel monitoring device ID in the incremental alarm information, polls the rule set, and screens the incremental alarm information according to the alarm occurrence time and alarm type in the incremental alarm information; if a certain rule is hit during the polling of the rule set, the incremental alarm information is screened and not processed, that is, it is not written into the database and not displayed on the front-end interface; if no rule is hit during the polling of the rule set, it is queried whether the incremental alarm information already exists in the database according to the channel monitoring device ID in the incremental alarm information. If it exists, the same alarm is prompted; if it does not exist, the alarm is prompted and the incremental alarm information is written into the database. If the recovery time in the incremental alarm information is not empty, the incremental alarm information is an alarm recovery; it is queried whether the incremental alarm information already exists in the database according to the channel monitoring device ID in the incremental alarm information. If it exists, the alarm status of the corresponding incremental alarm information in the database is updated to recovered; if it does not exist, it is not processed.
[0086] The channel alarm unit of the central maintenance device can use the line code, station code, device ID, alarm type, alarm level, alarm status, time, etc. in the incremental alarm information as query conditions to query historical alarm information and display it on the visual front-end interface. The query conditions can be set through the front-end interface, and the historical alarm information of all devices in the security data network is queried from the cache or database according to the query conditions.
[0087] The technical solutions in the embodiments of the present application have at least the following technical effects or advantages:
[0088] The solution of this application deploys channel monitoring devices in the station devices and / or center devices of the railway signaling system safety data network in the system, and independently forms a network with the central maintenance device as a supervision data network to collect data, which can be physically isolated from the main line network of the safety data network and has strong security. The data is collected by combining fiber optic splitting monitoring, Ethernet TAP monitoring, and port mirroring monitoring. Based on the characteristics of different hardware devices used in the three methods, it can meet the requirements of different application scenarios in the safety data network and ensure the sampling accuracy of the channel communication data of the safety data network. The central maintenance device receives the channel communication data, and performs intelligent analysis such as channel traffic analysis, RTT time anomaly warning analysis, and communication connection group anomaly inspection analysis on the channel communication data, which can accurately determine the anomalies of the channel communication data, help to timely discover the potential faults of the safety data network, and then realize the transformation of the operation and maintenance of the safety data network from fault repair to condition-based maintenance.
[0089] Figure 7 It is a schematic flowchart of a method for monitoring a railway signaling system safety data network provided in an embodiment of this application. As shown in the figure, this method includes:
[0090] The channel monitoring device continuously collects the channel communication data of the station devices and / or center devices in the railway signaling system safety data network, and sends the collected channel communication data to the central maintenance device through the supervision data network;
[0091] The central maintenance device receives the channel communication data collected continuously, and performs multi-dimensional processing on the channel communication data to determine the abnormal analysis result of the channel communication data.
[0092] Figure 8 It is a schematic structural diagram of an electronic device provided in an embodiment of this application. As shown in the figure, this electronic device includes: a processor and a memory;
[0093] Among them, the processor is used to read and execute the programs and instructions stored in the memory, so that the electronic device executes the method embodiments described above.
[0094] It should be noted that, for the sake of convenience of description, Figure 8 Exemplarily, only the main components of the electronic device are shown. In actual applications, this electronic device may also include components or assemblies not shown in the figure.
[0095] This application also provides a computer-readable storage medium, storing programs or instructions, and when the computer reads and executes the programs or instructions, it enables the computer to execute the method embodiments described above.
[0096] Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A railway train control system safety data network monitoring system, characterized in that: It includes channel monitoring equipment and central maintenance equipment. The channel monitoring equipment is deployed on the station equipment and / or central equipment side in the railway train control system safety data network. The channel monitoring equipment and the central maintenance equipment are independently networked as a supervision data network. Channel monitoring equipment, used to collect channel communication data of station equipment and / or central equipment in the railway train control system safety data network in real time; also used to send the collected channel communication data to the central maintenance equipment through the supervision data network; The central maintenance equipment is used to receive the channel communication data collected in real time, and perform multi-dimensional processing on the channel communication data to determine the abnormal analysis results of the channel communication data.
2. The railway train control system safety data network monitoring system according to claim 1, characterized in that: The channel monitoring equipment is also used to collect channel communication data of station equipment and / or central equipment of the railway train control system safety data network in real time by combining optical fiber splitting monitoring, Ethernet TAP monitoring and port mirroring monitoring.
3. The railway train control system safety data network monitoring system according to claim 1, characterized in that: The central maintenance equipment is also used to receive channel communication data collected in real time, and perform channel flow analysis, RTT time anomaly warning analysis, and communication connection group anomaly inspection analysis on the channel communication data to determine channel communication data anomalies of the railway train control system safety data network.
4. The railway train control system safety data network monitoring system according to claim 3 is characterized in that: The central maintenance equipment includes a network topology unit, a data analysis unit, and a channel warning unit; A network topology unit is used to receive channel communication data collected in real time, and to parse and store the channel communication data; A data analysis unit is used to perform channel flow analysis, RTT time anomaly warning analysis, and communication connection group anomaly inspection analysis on the channel communication data, and determine the anomaly analysis results of the channel communication data; The channel warning unit is used to generate abnormal alarms based on the abnormal analysis results of channel communication data and display the abnormal alarms in a visual manner.
5. The railway train control system safety data network monitoring system according to claim 4, characterized in that: The network topology unit is also used to display the main line network topology diagram of the security data network in a visual manner, and to display the channel session traffic ranking, channel IP traffic ranking, and channel port traffic ranking in a list form.
6. The railway train control system safety data network monitoring system according to claim 4, characterized in that: The data analysis unit includes: a channel flow analysis module, an RTT time anomaly warning analysis module, and a communication connection group anomaly inspection analysis module; The channel traffic analysis module is used to determine the abnormal analysis results of the channel communication data based on the time series characteristics of the channel communication data and using a real-time active anomaly detection algorithm; The RTT time anomaly warning analysis module is used to determine the anomaly analysis results of the channel communication data based on the RTT time of the channel communication data and using an adaptive retransmission algorithm; The communication connection group anomaly inspection and analysis module is used to determine the anomaly analysis result of the channel communication data based on the IP information in the network layer IPV4 protocol message in the channel communication data.
7. The railway train control system safety data network monitoring system according to claim 4, characterized in that: The channel warning unit is also used to receive device alarm messages collected in real time and perform incremental processing on the device alarm messages.
8. A method for monitoring a railway train control system safety data network, characterized in that: include: The channel monitoring equipment collects the channel communication data of the station equipment and / or the central equipment in the railway train control system safety data network in real time, and sends the collected channel communication data to the central maintenance equipment through the supervision data network; The central maintenance equipment receives the channel communication data collected in real time, and processes the channel communication data in multiple dimensions to determine the abnormal analysis results of the channel communication data.
9. The method for monitoring the railway train control system safety data network according to claim 8, characterized in that: The channel monitoring equipment uses a combination of fiber optic splitting monitoring, Ethernet TAP monitoring, and port mirroring monitoring to collect channel communication data of station equipment and / or central equipment in the railway train control system safety data network in real time.
10. The railway train control system safety data network monitoring method according to claim 8, characterized in that: The central maintenance equipment receives the channel communication data collected in real time, and performs channel flow analysis, RTT time anomaly warning analysis, and communication connection group anomaly inspection analysis on the channel communication data to determine the anomaly of the channel communication data of the railway train control system safety data network.
11. An electronic device, characterized in that: include: Processor and memory; The processor is coupled to a memory; The processor is used to read and execute the program or instruction stored in the memory, so that the device executes the method according to any one of claims 8 to 10.
12. A computer-readable storage medium, characterized in that: A computer program is stored, and when the program is executed by a processor, the method according to any one of claims 8 to 10 is implemented.
Citation Information
Cited By
System and method for monitoring secure data network of railway train control system, device, and medium
WO2026174821A1