Train-mounted network security protection method and device and electronic equipment
Through the National Secret algorithm and dynamic measurement technology, combined with the dynamic defense strategy of on-board firewall and security database, the problem of weak on-board network security of trains is solved, trusted monitoring and encrypted communications are achieved throughout the life cycle, and network security defense capabilities are improved.
Patent Information
- Application Number
- CN202510404361.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-04
AI Technical Summary
The train-on-vehicle network has insufficient encryption algorithm capabilities, weak security authentication mechanisms, and lack of in-depth protocol analysis and abnormal detection, resulting in high network security risks and it is difficult for traditional protection methods to effectively prevent unknown threats.
The Guomi algorithm is used to perform static and dynamic measurements of firmware and operating systems, combined with whitelist filtering and bypass monitoring of on-board firewalls, and dynamic defense strategy updates are used to achieve trusted monitoring and encrypted communication throughout the life cycle.
It improves the security level of train-on-vehicle networks, enhances the defense capabilities and efficiency of unknown threats, and ensures a trusted environment and stable operation of the network security.
Smart Images

Figure CN120263467A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of on-vehicle network security protection for EMUs and urban rail transit trains, and particularly relates to a method, device, and electronic device for on-vehicle network security protection of trains. Background Art
[0002] High-speed railways and urban rail transit, as important basic strategic resources in China, play an important role in the national infrastructure construction stage. At present, the security situation of industrial control information systems is severe. In the field of rail transit, which is related to the national economy and people's livelihood, the existing hidden dangers may cause particularly serious consequences. In the process of the continuous deep integration of rail transit and informatization, it has brought huge security risks to the imperfect on-vehicle network security protection system of trains.
[0003] The train communication network is the "brain and nerves" of rail transit vehicles. With the progress of technology and the development of rail transit intelligence, train communication network technology is gradually transitioning towards on-vehicle Ethernet and integrated control network-based directions, with advantages such as high bandwidth, high transmission rate, and convenient and flexible networking. The large bandwidth provides a channel foundation for the informatization and intelligent applications of rail transit trains. At the same time, the integration of control systems has also broken the pattern of the previous closed network, and there are more and more interfaces for interconnection and interoperability with external systems. While improving flexibility and convenience, the risks of network security have extended from external networks to vehicle-ground communication networks and train internal communication networks, bringing more computer technology-based security risks to on-vehicle communication networks. The information security of the network system faces severe challenges, and improving the security protection ability of the train network system has become a key and fundamental problem that needs to be solved urgently.
[0004] Currently, on-vehicle networks of trains generally have insufficient encryption algorithm capabilities, weak security authentication mechanisms, and imperfect authorization permissions, increasing the attractiveness of eavesdropping, tampering, and impersonation attacks at the network layer. At the same time, due to the lack of an anomaly detection and auditing system based on in-depth protocol analysis, when the system is infected with malicious code, there is a risk of sending illegal instructions to the underlying execution system; there is a lack of baseline security reinforcement and measures to prevent malicious code in the system, resulting in high vulnerability.
[0005] The rail transit control network belongs to the industrial control network and has significant differences from general industrial control networks. For example:
[0006] 1) Different network protocols. The underlying bus network protocols and standards are different: Train networks have certain industry characteristics, such as the Train Real-Time Ethernet Protocol (TRDP); while most general industrial control systems use standard industrial protocols, such as ModBus TCP, OPC, IEC, etc.
[0007] 2) Different network architectures. Generally, the topologies and access devices of industrial control networks and train networks are different, and the integration degree of train networks is higher. In view of this, the security guarantee system of general industrial control networks cannot be directly applied to the network security guarantee of train control networks.
[0008] 3) Different device operating environments. The devices in general industrial control systems adopt an integrated form, and the devices themselves have a chassis and a power supply. While in train networks, most of them adopt a plug-in form and do not have an independent chassis and power supply.
[0009] The currently adopted traditional protection technical means of "anti-virus, firewall, intrusion detection" can only repair the damage that has been caused and cannot fundamentally solve the problem. In addition, there are a large number of information islands in the traditional information security defense system. The deployed information security products stick to their respective "positions" in isolation, and there is a lack of coordinated operations among the security components in the entire defense system. Intruders can bypass a certain security line and easily invade the system. Summary of the Invention
[0010] To solve the above problems, the present invention proposes a train on-vehicle network security protection method, device and electronic device, which can improve the trusted environment of the on-vehicle network, essentially improve the security level of the on-vehicle network, and enhance the defense ability and efficiency of the on-vehicle network against unknown threats.
[0011] In a first aspect, a train on-vehicle network security protection method provided by the present invention includes:
[0012] Obtain on-vehicle device firmware information and operating system images;
[0013] Use national cryptography algorithms to determine the hash value of the firmware information, and verify the hash value using the firmware reference value pre-stored on a trusted chip to obtain a first verification result; wherein, the national cryptography algorithms include SM2 algorithm, SM3 algorithm and / or SM4 algorithm;
[0014] In response to the success of the first verification result, load the operating system; use the national cryptography algorithms and a dynamic measurement engine pre-installed on the trusted chip to perform periodic dynamic measurement on the operating system image to obtain a second verification result;
[0015] In response to the success of the second verification result, use an on-vehicle firewall to perform in-depth filtering of TRDP protocol information based on a whitelist on on-vehicle communication data to obtain filtered communication data; and use the national cryptography algorithms to encrypt the filtered communication data to obtain encrypted communication data;
[0016] Use a bypass mirror monitoring device to perform intrusion detection on the filtered communication data to detect abnormal traffic attacks and generate threat event logs;
[0017] Update the blocking policy of the in-vehicle firewall based on the in-vehicle security management center and the threat event log, and synchronize the vulnerability blacklist with the ground security management center to obtain the dynamic defense result;
[0018] Obtain the system operation data of the in-vehicle device;
[0019] Based on the system operation data and the dynamic defense result, verify the defense effectiveness using the event restoration records in the security database to obtain the verification result;
[0020] Update the dynamic measurement engine according to the verification result, and synchronize the updated dynamic measurement engine to the trusted chip for subsequent periodic verification.
[0021] In an optional implementation, the using the national cryptographic algorithm to determine the hash value of the firmware information, and using the firmware reference value pre-stored on the trusted chip to verify the hash value to obtain the first verification result includes:
[0022] Use the SM3 algorithm built in the trusted chip to determine the hash value of the firmware information, compare the hash value with the firmware reference value, and if they match, the first verification result is successful;
[0023] The using the national cryptographic algorithm and the dynamic measurement engine pre-installed on the trusted chip to perform periodic dynamic measurement on the operating system image to obtain the second verification result includes:
[0024] Use the trusted chip to monitor the integrity of the in-vehicle device memory control instructions, and use the SM4 algorithm to encrypt the process call whitelist in the dynamic measurement engine to generate the second verification result;
[0025] When the deviation between the second verification result and the dynamic measurement engine exceeds the preset first threshold, freeze the abnormal process and generate an alarm event, and send the alarm event to the security database.
[0026] In an optional implementation, the using the bypass mirror monitoring device to perform intrusion detection on the filtered communication data to detect abnormal traffic attacks and generate threat event logs includes:
[0027] Use the bypass mirror monitoring device to mirror the filtered communication data to generate mirror data; wherein the bypass mirror monitoring device is deployed bypass the mirror port of the in-vehicle network switch;
[0028] Extract the first network features of the mirror data, where the first network features include device fingerprint features, clock offset, and communication frequency distribution features;
[0029] Match the first network feature with the TRDP attack feature in the intrusion detection rule library to obtain a protocol feature matching result; wherein, the intrusion detection rule library is stored in the bypass mirror monitoring device;
[0030] In response to the protocol feature matching result being a match, generate a threat event log, input the threat event log into the security database, and generate an alarm message for alarming.
[0031] In an alternative embodiment, the use of the in-vehicle firewall to perform deep filtering of the TRDP protocol information based on the whitelist for the in-vehicle communication data to obtain the filtered communication data includes:
[0032] Parse the TRDP protocol information, extract the function code, source address, and value range to generate an initial whitelist policy set;
[0033] Cross-validate the initial whitelist policy set with the vulnerability blacklist to screen and remove risk policies to obtain a whitelist policy set;
[0034] Dynamically update the whitelist policy set according to the attack type in the threat event log;
[0035] Discard the TRDP protocol information that violates the whitelist policy and record the discard event in the security database.
[0036] In an alternative embodiment, after using the bypass mirror monitoring device to mirror the filtered communication data to generate mirror data, it further includes:
[0037] Use a protocol parsing engine to extract the second network feature of the mirror data, where the second network feature includes protocol function code, device address, timestamp feature, and packet length distribution feature;
[0038] Generate an information interaction record according to the second network feature;
[0039] Use a pre-established behavior baseline model to perform dynamic threshold matching on the second network feature, and mark the communication data corresponding to the second network feature that exceeds the dynamic threshold as abnormal behavior information; wherein, the behavior baseline model is obtained by performing time series modeling on historical communication data using a self-learning algorithm, and the behavior baseline model is stored in the security database;
[0040] Store the information interaction record and the abnormal behavior information in the security database.
[0041] In an alternative embodiment, based on the system operation data and the dynamic defense result, use the event restoration record in the security database to verify the defense effectiveness to obtain a verification result, including:
[0042] Obtain the threat event log and the event restoration record from the security database, and associate the attack source device identifier and the operation time series;
[0043] Use the jump host to backtrack and analyze the transit devices on the attack link, and generate a preliminary attack path topology;
[0044] Use the industrial control system honeypot pre-deployed in the in-vehicle network nodes to capture the attack code sample and record the injection point and vulnerability exploitation behavior;
[0045] Decompile and perform sandbox behavior analysis on the attack code sample to obtain the attack code characteristics;
[0046] Match and verify the attack path topology, the attack code characteristics with the vulnerability blacklist to obtain the verification result; the verification result includes the attack source host, the attack organization and the attack path.
[0047] In an alternative embodiment, updating the blocking policy of the in-vehicle firewall based on the in-vehicle security management center and the threat event log includes:
[0048] Obtain multi-dimensional data of the in-vehicle device, where the multi-dimensional data includes setting status data, network traffic characteristics and program process logs;
[0049] Use the pre-deployed probe to perform anomaly detection on the multi-dimensional data to obtain the anomaly detection result;
[0050] Perform correlation analysis and cross-verification on the anomaly detection result and the threat event log respectively to achieve cross-domain security situation awareness and linkage disposal, and obtain the security situation awareness result;
[0051] Update the blocking policy of the in-vehicle firewall according to the security situation awareness result.
[0052] In an alternative embodiment, encrypting the filtered communication data using the national cryptography algorithm to obtain the encrypted communication data includes:
[0053] Generate multi-layer session keys using the national cryptography algorithm according to the confidentiality level of the filtered communication data;
[0054] Store the session key in the trusted chip.
[0055] In a second aspect, a train in-vehicle network security protection device provided by the present invention includes:
[0056] A first acquisition module for acquiring in-vehicle device firmware information and operating system images;
[0057] A trusted computing module, used to determine the hash value of the firmware information using a national secret algorithm, and verify the hash value using a firmware reference value pre-stored on the trusted chip to obtain a first verification result; wherein the national secret algorithm includes an SM2 algorithm, an SM3 algorithm and / or an SM4 algorithm;
[0058] A national secret algorithm module, configured to load the operating system in response to a successful first verification result; and perform periodic dynamic measurement on the operating system image using the national secret algorithm and a dynamic measurement engine pre-installed on the trusted chip to obtain a second verification result;
[0059] The vehicle-mounted firewall module is used for, in response to the success of the second verification result, using the vehicle-mounted firewall to perform deep filtering of TRDP protocol information based on the whitelist on the vehicle-mounted communication data to obtain filtered communication data; and using the national secret algorithm to encrypt the filtered communication data to obtain encrypted communication data;
[0060] An intrusion detection module is used to detect filtered communication data using a bypass mirror monitoring device to detect abnormal traffic attacks and generate threat event logs;
[0061] A situation awareness module, used to update the blocking strategy of the vehicle-mounted firewall based on the vehicle-mounted security management center and the threat event log, and synchronize the vulnerability blacklist with the ground security management center to obtain dynamic defense results;
[0062] The second acquisition module is used to acquire system operation data of the vehicle-mounted device;
[0063] A tracing module is used to verify the effectiveness of defense based on the system operation data and the dynamic defense results by using the event restoration records in the security database to obtain a verification result;
[0064] The information storage module is used to update the dynamic measurement engine according to the verification result, and synchronize the updated dynamic measurement engine to the trusted chip for subsequent periodic verification.
[0065] In a third aspect, the present invention provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method described in any one of the aforementioned implementations when executing the computer program.
[0066] In a fourth aspect, the present invention provides a computer-readable medium having a non-volatile program code executable by a processor, wherein the program code enables the processor to execute the method described in any one of the aforementioned embodiments.
[0067] The beneficial effects brought by the technical solutions provided in the embodiments of the present invention are as follows: For the train on-vehicle network security protection method, device and electronic device of the present invention, the firmware is statically measured using the national cryptography algorithm, and the operating system is dynamically measured using the national cryptography algorithm and the dynamic measurement engine. Therefore, by adopting the static trusted boot and dynamic measurement technologies, the trusted monitoring of the entire life cycle of the on-vehicle network is realized; the on-vehicle firewall is used to deeply filter the TRDP protocol information based on the whitelist for the on-vehicle communication data, and the blocking policy of the on-vehicle firewall is updated based on the on-vehicle security management center and the threat event log, and the event restoration records in the security database are used to verify the effectiveness of the defense. It can be seen that the on-vehicle network firewall, on-vehicle security management center and security database are used to effectively prevent the on-vehicle network security risks and achieve the purpose of ensuring the safe and stable operation of the train on-vehicle network; the national cryptography algorithm and lightweight communication encryption technology are adopted to solve the trusted problems of network communication and network boundaries. The present invention can improve the trusted environment of the on-vehicle network, essentially improve the security level of the on-vehicle network, and enhance the defense ability and efficiency of the on-vehicle network against unknown threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] Figure 1 It is a schematic flowchart of the train on-vehicle network security protection method provided by the embodiment of the present invention;
[0069] Figure 2 It is a schematic diagram of the train on-vehicle network intrusion detection principle provided by the embodiment of the present invention;
[0070] Figure 3 It is a schematic flowchart of the train on-vehicle network firewall provided by the embodiment of the present invention;
[0071] Figure 4 It is a schematic diagram of the train on-vehicle network security situation awareness and analysis principle provided by the embodiment of the present invention;
[0072] Figure 5 It is another schematic diagram of the train on-vehicle network security situation awareness and analysis principle provided by the embodiment of the present invention;
[0073] Figure 6 It is a schematic system diagram of the train on-vehicle network security protection device provided by the embodiment of the present invention;
[0074] Figure 7 It is a schematic system diagram of the electronic device provided by the embodiment of the present invention.
[0075] In the figure: 100 - First acquisition module; 200 - Trusted computing module; 300 - National cryptographic algorithm module; 400 - In-vehicle firewall module; 500 - Intrusion detection module; 600 - Situation awareness module; 700 - Second acquisition module; 800 - Tracing and source-tracing module; 900 - Information storage module; 1000 - Electronic device; 1001 - Communication interface; 1002 - Processor; 1003 - Memory; 1004 - Bus. Detailed implementation manners
[0076] The present invention relates to a method, device and electronic device for protecting the security of an in-vehicle network of a train. In order to solve the actual security problems of the in-vehicle network of EMUs and urban rail transit trains, prevent serious network threats caused by insufficient in-vehicle network security defense capabilities, etc., and also in response to the national network security strategy and corresponding standards, laws and regulations requirements, an embedded trusted protection system is adopted to achieve secure and trusted protection, realize trusted access control, dynamic measurement determination and static startup protection based on national cryptographic algorithm technology, and build an in-vehicle network security protection system for trains with the goal of security and controllability and the feature of security immunity. This technical method belongs to the field of in-vehicle network security protection of rail transit EMUs and urban rail transit trains. The present invention will be described in detail below with reference to the drawings and in conjunction with the embodiments.
[0077] Refer to Figure 1 , a method for protecting the security of an in-vehicle network of a train, including the following steps S100 to step S900.
[0078] Step S100, acquire the firmware information of in-vehicle devices and the operating system image.
[0079] Step S200, use the national cryptographic algorithm to determine the hash value of the firmware information, and verify the hash value using the firmware reference value pre-stored on the trusted chip to obtain the first verification result; wherein, the national cryptographic algorithm includes SM2 algorithm, SM3 algorithm and / or SM4 algorithm.
[0080] Specifically, this embodiment is based on an architecture that combines a hardware security chip and a dedicated security device. The trusted chip can be a TPCM chip or a TCM chip. The national cryptographic algorithm can be loaded onto a national cryptographic algorithm acceleration card, which can support in-vehicle communication encryption and identity authentication. For example, use the SM4 algorithm for symmetric encryption or decryption, and use the SM2 algorithm for signature and signature verification operations. In this embodiment, the SM3 algorithm can be used to calculate the hash value of the firmware information.
[0081] Step S300, in response to the success of the first verification result, load the operating system; use the national cryptographic algorithm and the dynamic measurement engine pre-installed on the trusted chip to perform periodic dynamic measurement on the operating system image to obtain the second verification result.
[0082] Here, in this embodiment, the running memory data of the in-vehicle operating system is also dynamically measured. The SM3 hash value of the operating system image can be calculated using a national cryptography acceleration card, and signature and verification are performed using the SM2 algorithm.
[0083] Step S400, in response to the success of the second verification result, use the in-vehicle firewall to perform deep filtering of the in-vehicle communication data based on the whitelist for TRDP protocol information, obtaining the filtered communication data; and encrypt the filtered communication data using the national cryptography algorithm to obtain the encrypted communication data.
[0084] For example, if the second verification result is successful (normal), then negotiate the session key through the SM2 algorithm and encrypt the in-vehicle communication data using the SM4 algorithm. The in-vehicle firewall (or security gateway) performs in-depth parsing of the in-vehicle communication data based on the whitelist policy and the TRDP protocol to filter illegal communications. Among them, the TRDP protocol (Train Real-time Data Protocol) is a real-time data communication protocol designed specifically for rail transit vehicles (such as high-speed trains, subways, etc.), mainly used for efficient data transmission between train control systems and in-vehicle devices. Here, the SM4 can still be used to encrypt the filtered communication data.
[0085] Step S500, use the bypass mirror monitoring device to perform intrusion detection on the filtered communication data to detect abnormal traffic attacks and generate threat event logs.
[0086] The intrusion here includes DDoS detection, that is, use the bypass mirror monitoring device to monitor abnormal traffic such as DDoS to obtain the filtered legitimate traffic and threat event logs. The bypass mirror monitoring device generally includes an optical splitter and a security audit box, that is, use the optical splitter to encrypt the filtered communication data into the security audit box, detect DDoS attack characteristics and generate threat event logs.
[0087] Step S600, update the blocking policy of the in-vehicle firewall based on the in-vehicle security management center and the threat event logs, and synchronize the vulnerability blacklist with the ground security management center to obtain the dynamic defense result.
[0088] The in-vehicle security management center updates the blocking policy of the in-vehicle firewall according to the threat event logs, and in step S700, obtain the system operation data of the in-vehicle device.
[0089] Step S800, based on the system operation data and the dynamic defense result, use the event restoration records in the security database to verify the defense effectiveness and obtain the verification result.
[0090] Step S900, update the dynamic measurement engine according to the verification result, and synchronize the updated dynamic measurement engine to the trusted chip for subsequent periodic verification.
[0091] Modify the dynamic measurement engine according to the verification result through a trusted chip, such as adjusting the hash verification frequency, updating the whitelist rules, or updating the blacklist rules.
[0092] In this embodiment, static trusted startup and dynamic measurement are performed during the startup phase of the in-vehicle device. When the measurement passes, the operating system is loaded and the security protection in the system running phase is entered. During the system running phase, the in-vehicle firewall is used to parse the TRDP protocol header and match the whitelist policy, and the abnormal traffic is detected by the bypass mirror monitoring device to obtain the threat event log. The in-vehicle security management center updates the blocking policy of the in-vehicle firewall based on the threat event log and synchronizes it to the ground center. The trusted chip verifies the key processes and updates the dynamic measurement engine according to the verification result.
[0093] This embodiment breaks through the data traffic monitoring technology, supplements the deployment of security monitoring devices in a bypass mirror mode, deeply integrates the system functional safety and network information security, performs trusted access control, static startup protection and dynamic measurement determination based on the lightweight national cryptographic algorithm technology, enhances the authentication process with the help of cryptographic technology and trusted computing system, improves the trusted environment of the in-vehicle network, essentially improves the security level, enhances the defense ability and efficiency against unknown threats, integrates various industrial control system information security technologies, enables the in-vehicle network security protection system to have fine-grained monitoring and auditing capabilities, solves the security real-time warning, provides effective event restoration capabilities, enhances the post-event analysis and investigation and evidence collection capabilities, and avoids continuous damage to the system. At the same time, adopt the firewall policy and the deeply managed TRDP protocol policy, and assist with common DDOS attack defense and traffic control capabilities; adopt the security deployment in the form of a whitelist, and re-screen the vulnerability blacklist on top of the whitelist; establish an in-vehicle security management center, form a network security protection mechanism of dynamic defense, monitoring and early warning, and response and disposal through data linkage with the ground security management center, and ensure the whole life cycle of safe production and the whole process of operation of the in-vehicle TCMS system; at the same time, establish an in-vehicle network information security database to form a hierarchical and multi-domain in-depth defense system, and build an in-vehicle network security protection barrier with the goal of security and controllability and the characteristic of security immunity.
[0094] This embodiment constructs an integrated in-vehicle network security solution that applies national cryptographic algorithms and is supported by trusted computing core technologies. It includes the application adaptation of the built-in security active defense technology of the trusted computing 3.0 dual-system architecture in the train in-vehicle network. By using static trusted boot and dynamic measurement technologies, it realizes the trusted monitoring of the entire life cycle of the in-vehicle network. On this basis, an in-vehicle network firewall, an in-vehicle network monitoring and auditing system, and a security management platform are designed to effectively prevent in-vehicle network security risks and ensure the safe and stable operation of the train in-vehicle network. At the same time, lightweight communication encryption and decryption technologies and access control technologies based on national cryptographic algorithms are used to solve the trust problems of network communication and network boundaries.
[0095] In some possible embodiments, step S200 specifically includes: using the SM3 algorithm built in the trusted chip to determine the hash value of the firmware information, comparing the hash value with the firmware reference value, and if they match, the first verification result is successful.
[0096] Further, step S300 includes the following steps S310 to S320.
[0097] In step S310, the trusted chip is used to monitor the integrity of the in-vehicle device memory control instructions, and the process call whitelist in the dynamic measurement engine is encrypted using the SM4 algorithm to generate a second verification result.
[0098] Specifically, according to the first verification result, a startup instruction for the trusted chip to load the operating system image is triggered. During the operation of the operating system, the integrity of the memory control instructions is monitored in real time through the trusted chip.
[0099] In step S320, when the deviation between the second verification result and the dynamic measurement engine exceeds a preset first threshold, the abnormal process is frozen and an alarm event is generated, and the alarm event is sent to the security database.
[0100] Specifically, when it is detected that the process call behavior deviates from the dynamic measurement engine, the abnormal process is frozen and the alarm event is saved to the security database.
[0101] In this embodiment, trusted computing is a technology that ensures the predictability of the system. It refers to performing security protection during the computing process, making the calculation results always the same as the expected values, making the entire computing process measurable and controllable, and not being interfered with. It is a way of active immunity. This embodiment adopts the dual-system architecture of trusted computing 3.0, conducts an integrated structural design of the traditional computing system and the security control system, integrates security functions into the hardware level, especially inside the processor, realizes parallel processing of computing and security protection, and enhances the overall security of the system through technical measures such as trusted encryption cards, firmware, operating systems, memory control protection measures, and application layer protection. The dual-system architecture of trusted computing 3.0 aims to work in coordination with hardware-level security measures and operating system-level policies to form a comprehensive system that can not only efficiently perform conventional computing tasks but also effectively resist internal and external security threats. Applying the on-vehicle network embedded trusted computing technology, it realizes trusted measurement and verification in the field of on-vehicle networks, can comprehensively measure and control the startup program, operating system, applications, data, and business behaviors, constructs a trusted computing environment based on the dual-system architecture of the on-vehicle network security device's trusted startup and dynamic measurement method; constructs a system trusted boundary through methods such as trusted transmission of on-vehicle network perception data, trusted exchange of process data, trusted distribution of logical data, and trusted verification of result data to ensure the anti-tampering of on-vehicle network data; realizes on-vehicle trusted network access authentication through trusted access authentication and user trusted access methods. By implementing strict identity authentication and access control mechanisms, only authenticated users and devices can access network resources to ensure the security of the network.
[0102] In some possible embodiments, step S400 includes the following steps S410 to S440.
[0103] Step S410, parse the TRDP protocol information, extract the function code, source address, and value range to generate an initial whitelist policy set.
[0104] Step S420, perform cross-verification on the initial whitelist policy set with the vulnerability blacklist to screen and remove risk policies to obtain a whitelist policy set.
[0105] Step S430, dynamically update the whitelist policy set according to the attack types in the threat event log.
[0106] Step S440, discard the TRDP protocol information that violates the whitelist policy and record the discard event in the security database.
[0107] Specifically, the dynamic update here refers to dynamically adding temporary blocking rules to the firewall blocking policy. The firewall is an essential device for the information security of the train on-vehicle network and is the foundation of information security technology. It can achieve regional control, divide the security areas of the control system, isolate and protect the security areas, and protect legitimate users' access to network resources. While protecting against behaviors such as virus propagation and hacker attacks from the network, the on-vehicle enhanced firewall has the functions of global Bypass and full-transparency non-stop deployment, avoiding network failures caused by single-point failures during straight-line deployment. In case of equipment failures, the hardware bypass function is automatically enabled, allowing data traffic to pass through normally without being affected by the failures, ensuring the continuity of business; adopting the whitelist mechanism, it can be less upgraded or even not upgraded at all, which conforms to the application characteristics of the train on-vehicle network. Through machine learning, it can automatically complete the in-depth parsing of the communication protocol (i.e., the TRDP protocol) within the on-vehicle control network, and can be less upgraded or even not upgraded at all, which conforms to the application characteristics of the on-vehicle network. At the same time, an access control "white environment" is formed based on the function code and timestamp. Only the data packets that conform to the function code characteristics and data sending and receiving time periods in the specification can pass through, ensuring that only trusted devices can enter the network at the network boundary between regions. After enabling intelligent learning, it can extract the function code, source address, and value range in the network traffic, automatically generate whitelist policies, and cross-verify them with the vulnerability blacklist to eliminate risk policies with known attack characteristics, and finally generate a trusted whitelist policy set. The on-vehicle network firewall has the function of dynamic policy library management, supporting policy library update, local encrypted storage of the policy library, and emergency rule push update. According to the threat event logs collected in real time, it can identify the attack types (such as DoS, data tampering, etc.), dynamically adjust the weights of the whitelist policies or add new interception rules, and perform data integrity verification and data encryption on the update transmission process of the policy library to ensure the integrity and confidentiality of the data. It performs real-time discard operations on the TRDP protocol data packets that violate the whitelist policy, and encrypts and stores fields such as the timestamp, source address, and violated function code of the discard event in the security database. The policy library management supports data integrity verification and encrypted transmission to ensure the integrity and confidentiality of the policies during the update process. When the device fails, the hardware Bypass function is only started after the signature verification of the policy library passes, avoiding data leakage caused by policy failures.
[0108] In some possible embodiments, the working process of the on-vehicle network firewall is as Figure 3 shown, including the following steps: starting the trusted software, loading the DPDK driver, loading the protocol decoding driver, configuring the parsing, loading the service module, starting the log service, and the data processing engine is ready.
[0109] In some possible embodiments, step S500 includes the following steps S510 to step S540.
[0110] Step S510: Use a bypass mirror monitoring device to mirror and filter the communication data to generate mirror data. The bypass mirror monitoring device is deployed in parallel to the mirror port of the in-vehicle network switch. In some embodiments, monitoring devices are deployed in parallel to the mirror ports of the network switches at the front and rear of the vehicle to mirror in real time all the TRDP protocol data traffic interactions within the in-vehicle communication network and generate mirror data of the original traffic.
[0111] Step S520: Extract the first network features of the mirror data. The first network features include device fingerprint features, clock offset, and communication frequency distribution features. Generate device fingerprints through time-domain or frequency information, analyze the clock offset and communication frequency distribution features, and capture the abnormal function code call patterns of remote frames.
[0112] Step S530: Match the first network features with the TRDP attack features in the intrusion detection rule library to obtain a protocol feature matching result. An intrusion detection rule library is stored in the bypass mirror monitoring device. The TRDP attack features include traffic features and / or a DDoS attack pattern library. The intrusion detection rule library in this embodiment is pre-optimized, and the first network features are matched with the optimized intrusion detection rule library to detect DDoS attacks, port scans, and malware propagation.
[0113] Step S540: In response to the protocol feature matching result being a match, generate a threat event log, input the threat event log into the security database, and generate an alarm message for alarming. For the packets determined to be abnormal, call the log module to record the attack time window, source device identifier, and attack feature type, and trigger the alarm module to generate a real-time alarm signal.
[0114] Step S500 adopts train on-vehicle network intrusion detection technology. Intrusion detection technology is the core issue in the research of train on-vehicle network security. The intrusion detection system (IDS) is deployed bypass on the on-vehicle network switch. By monitoring and analyzing activities on the host or network, it detects threats to the system from internal and external attacks. By optimizing the intrusion detection rule base, it improves the intrusion detection efficiency and strengthens the pertinence of attack detection. The optimization of the intrusion detection rule base can be carried out through the following methods, including rule simplification and merging strategies, removing outdated or redundant rules, reducing false positives and false negatives, merging similar rules, reducing the number of rules, and improving the processing speed; sorting according to the importance or urgency of the rules to ensure that high-risk threats can be detected and responded to preferentially, using machine learning algorithms to automatically analyze historical data, identifying the most effective rules, and giving them higher execution priorities; automatically adjusting the rule matching threshold according to network traffic and activity patterns to adapt to network environment changes in different time periods, automatically updating and adjusting the rule base based on threat intelligence to ensure coverage of the latest attack features; using data mining and statistical analysis methods to extract the most representative features from a large number of logs, performing dimensionality reduction processing on the features, reducing the computational complexity, and improving the detection efficiency; analyzing the resource consumption of rule execution, optimizing or adjusting the execution timing of resource-intensive rules, using parallel processing technology to disperse rule matching tasks, and accelerating the detection speed; developing customized rules for specific network environments and business requirements to improve the pertinence and effectiveness of detection, etc. Through the analysis of the on-vehicle network architecture and network protocols, it is found that the network features available for intrusion detection observation include device fingerprints (extracted through time-domain and frequency-domain information), clock offsets, frequency observations, and remote frames, etc. It can achieve high detection accuracy for specific attack models, and has the characteristics of short response time and low network bandwidth overhead. It can effectively collect and detect potential attacks on the on-vehicle network and improper behaviors of the vehicle-ground wireless network, such as denial of service (DoS) / distributed denial of service (DDoS), port scanning, malware or ransomware, etc. Intrusion detection checks the packets copied by the bypass by parsing the rules, and judges whether the Ethernet network is normal based on the rule matching method. For the packets determined to be abnormal, it calls the log module and the alarm module to record and alarm.
[0115] In some possible embodiments, as Figure 2 shown in the flow schematic diagram of the intrusion detection technology. An intrusion detection module is provided at the vehicle end. This module collects packet data and device status, and is configured with a detection rule base. When an intrusion event is detected, it reports to the server end. The server end issues an intrusion alarm and generates an intrusion response to feedback to the vehicle end. The vehicle end updates the protection strategy to execute the updated protection strategy in the next intrusion detection cycle.
[0116] Further, after step S510, the following steps S550 to S580 are further included.
[0117] Step S550, using a protocol parsing engine to extract the second network features of the mirror data, where the second network features include protocol function codes, device addresses, timestamp features, and packet length distribution features. Here, the protocol parsing engine is deployed in the aforementioned security audit box.
[0118] Step S560, generating an information interaction record according to the second network features.
[0119] Step S570, using a pre-established behavior baseline model to perform dynamic threshold matching on the second network features, and marking the communication data corresponding to the second network features that exceed the dynamic threshold as abnormal behavior information; wherein, the behavior baseline model is obtained by performing time series modeling on historical communication data using a self-learning algorithm, and the behavior baseline model is stored in the security database.
[0120] Step S580, storing the information interaction record and the abnormal behavior information in the security database.
[0121] Here, steps S550 to S580 are used for in-vehicle network security auditing, providing network monitoring, protocol analysis, and security auditing functions, mainly involving threat modeling and grading, detection of known vulnerability exploitation attacks, detection of unknown threats, and detection of protocol-based business attacks, etc. Monitoring and auditing are deployed bypassing the network switches at the front and rear of the vehicle. All the interactive data traffic within the train communication network passing through these switches is mirrored to the monitoring and auditing platform through the switch mirror ports for comprehensive analysis and auditing records. Detect threats to the system from internal and external attacks by monitoring and analyzing activities on the host or network. Improve the intrusion detection efficiency and strengthen the pertinence of attack detection by optimizing the intrusion detection rule library. Check the packets copied bypass by parsing rules, and judge whether the Ethernet network is normal based on rule matching. For the packets determined to be abnormal, call the log module and the alarm module for recording and alarming. Through a self-learning algorithm, based on the traffic, learn the behavior baseline in the in-vehicle network according to time scheduling, and display asset details, protocol interaction patterns, and traffic models. Support TRDP real-time Ethernet protocol identification and in-depth parsing, and support abnormal behavior analysis based on the TRDP protocol.
[0122] In some possible embodiments, step S600 includes the following steps S610 to S640.
[0123] Step S610, obtaining multi-dimensional data of the in-vehicle device, where the multi-dimensional data includes setting status data, network traffic characteristics, and program process logs.
[0124] Step S620: Use pre-deployed probes to perform anomaly detection on the multi-dimensional data to obtain an anomaly detection result. Security probes are pre-deployed in the controller of the operating system (such as Linux or QNX), and the multi-dimensional data of the device is collected through the security probes.
[0125] Step S630: Perform correlation analysis and cross-verification on the anomaly detection result and the threat event log respectively to achieve cross-domain security situation awareness and linkage disposal, and obtain a security situation awareness result. The threat event log includes DDoS attack characteristics (such as traffic peaks, abnormal connection density) and protocol tampering events. When performing correlation analysis, the attack path can be identified through the matching degree between the resource occupancy rate and the attack characteristics.
[0126] Step S640: Update the blocking policy of the in-vehicle firewall according to the security situation awareness result. This includes updating the traffic rate limit rule in the blocking policy to suppress DDoS attack traffic; adjusting the process call permissions of the dynamic measurement rule library to block abnormal processes. After the blocking policy is updated, the attack path topology diagram, firewall blocking situation, and device resource alarm information are displayed through the in-vehicle security management center, and the analysis data is stored in the security database.
[0127] Step S600 involves the security situation awareness and analysis of the train in-vehicle network, correlates the data information in several dimensions of devices, networks, devices, applications, and data, and at the same time integrates the business information of each specialty to timely detect and respond to network threats, provides a set of management interfaces, and supports administrators to configure firewalls and defense strategies, and can visually display the vehicle security situation, support the collection of events, logs, and traffic, and provides a database to realize the storage and query of the platform business data.
[0128] In some possible embodiments, the situation awareness is realized through the following steps (a)-(c).
[0129] (a) According to the requirements of the vehicle network security design, the in-vehicle network security system combines the vehicle network architecture and deploys probes in the controller that meets the corresponding resources and processing capabilities. For example, probes are deployed in the controller that supports operating systems such as LINUX / QNX to comprehensively monitor the security of the vehicle's controllers.
[0130] (b) The deployed probes detect various abnormal behaviors of the system and report the detection results and security events to the management platform uniformly;
[0131] (c) The central management platform realizes the trustworthy aggregation and monitoring of monitoring data, conducts correlation analysis and cross-verification on the monitoring data, realizes cross-domain security situation awareness and linkage disposal, and presents it visually. By identifying abnormal events and attack events against the in-vehicle network, measures are taken for network security defense, so as to ensure the application security, communication security, system security, access point security, and data security of the in-vehicle Ethernet network system.
[0132] In a possible embodiment, as Figure 4 shown, the situation awareness system can realize internal risk awareness, external risk awareness, and risk awareness in configuration services. Among them, internal risk awareness includes asset awareness (such as parsed information, management information, business weights, and asset scopes, etc.), operation awareness (such as business continuity, device performance, network status, and regular monitoring, etc.), and vulnerability awareness (such as business vulnerabilities, scanned vulnerabilities, and 1-day vulnerabilities, etc.), external risk awareness includes attack awareness (such as threat intelligence, malicious addresses, and threat matching, etc.) and threat awareness (such as log collection and log rules, etc.), and configuration service awareness includes infringement log collection services and rule preset services.
[0133] In some possible embodiments, step S800 includes the following steps S810 to step S850.
[0134] Step S810, obtain the threat event log and the event restoration record from the security database, and associate the attack source device identifier and the operation time series. Among them, the event restoration record includes network malicious behavior feature data.
[0135] Step S820, use the jump host to trace back and analyze the transit devices on the attack link to generate a preliminary attack path topology.
[0136] Step S830, use the industrial control system honeypot pre-deployed in the in-vehicle network nodes to capture the attack code sample and record the injection point and vulnerability exploitation behavior. Match and analyze the attack code sample with the threat event log to obtain the attack code sample, and the sample includes attack organization characteristics.
[0137] Step S840, decompile and analyze the sandbox behavior of the attack code sample to extract the code injection point, vulnerability exploitation method, and persistent residence characteristics, and obtain the attack code characteristics.
[0138] Step S850, match and verify the attack path topology, the attack code characteristics with the vulnerability blacklist to obtain the verification result; the verification result includes the attack source host, the attack organization, and the attack path.
[0139] Step S800 of this embodiment involves the technologies of vehicle in-vehicle network system attack forensics and tracing. The system attack forensics and tracing technology is a key technology for critical infrastructure defense. By comprehensively using technologies and resources such as log-based collaborative tracing technology, network malicious behavior characteristics, jump host backtracking, industrial control system honeypots, attack code analysis, and threat intelligence libraries, trace the attack source host, attack organization, and attack path to provide support for in-depth system defense.
[0140] In some possible embodiments, step S400 further includes steps S450 to S460.
[0141] Step S450, according to the confidentiality level of the filtered communication data, generate multi-layer session keys using national cryptographic algorithms. Here, the SM2 algorithm can be used to generate multi-layer session keys (for example, including primary keys and secondary keys), where control instructions are encrypted using primary keys and status data are encrypted using secondary keys.
[0142] Step S460, store the session keys in the trusted chip.
[0143] Steps S450 to S460 of this embodiment involve communication encryption and decryption technologies based on lightweight commercial cryptographic algorithms. In the vehicle-ground wireless communication part, commercial cryptographic technologies are used to encrypt vehicle-mounted information to prevent it from being obtained by external organizations. Mathematical algorithms are used to encrypt information, and serial numbers are used to encrypt vehicle-ground data. For example, keys can be used for encryption. According to the confidentiality level of the information, multi-layer keys are superimposed to enhance the confidentiality effect. For the computers used for maintenance, digital signature technology is used to identify the identity through signatures and ensure the recipient of the information, thereby ensuring the security and privacy of information data; adopt security measures such as encryption and authentication to protect the confidentiality, integrity, availability, and anti-replay attack of critical communication data; encrypt and store relevant information such as keys for secure communication.
[0144] In some possible embodiments, this embodiment also involves train in-vehicle network data collection and fusion analysis technologies. The data collection and fusion analysis technology is the basis for train in-vehicle network threat monitoring and early warning, and situation awareness, and involves links such as information collection, data formatting, preprocessing, protocol deep parsing, and business data association. Through the collection and processing of real-time data traffic, network protocols, communication behaviors, control instructions, device states, and behavior data of the train in-vehicle network, combined with the established analysis models for known protocols and unknown private protocols, deep parsing of control protocols is achieved.
[0145] In some possible embodiments, such as Figure 5As shown in the figure, the functional modules set in the train vehicle end system include security log, firewall, intrusion detection, system security, application security, communication security, intrusion prevention, access security, secure boot, and data security. The functional modules set on the server side include security situation awareness, security monitoring, asset management, threat intelligence library (which can be used to store threat intelligence logs), and vulnerability management library. The display end visually presents the comprehensive security situation, device security situation, attack situation, and risk situation.
[0146] In summary, traditional passive defenses are difficult to meet the network security guarantee requirements under the trend of digital transformation, and the concept of building an active security defense system has gradually become the mainstream. Therefore, the in-vehicle network security protection system based on Ethernet needs to have the characteristics of its own network environment, application environment, and physical environment, conduct targeted security strategy demonstration, security model design, and security product research and development, establish and improve the in-vehicle network security protection system based on Ethernet, and ensure that important systems are protected from hackers, viruses, malicious codes, etc. through the implementation of unified security strategies. In particular, it can resist malicious attacks launched by external organized groups and threat sources with rich resources, and can quickly restore the main functions after the system is damaged, ensuring the effectiveness of the functions of each functional module in the train control system and the stable operation of the train.
[0147] This embodiment adopts the theories and methods of secure and trustworthy technologies, focuses on the common key technologies of the train on-vehicle network security and trust assurance system, and constructs a trusted computing environment based on the trusted startup and dynamic measurement methods of train on-vehicle network security devices with a dual-system architecture. It adopts methods for trusted transmission of train on-vehicle network perception data, trusted exchange of process data, trusted distribution of logical data, and trusted verification of result data to construct a system trusted boundary and ensure the anti-tampering of train on-vehicle network data; and adopts trusted access authentication and user trusted access methods to achieve trusted network access authentication for train on-vehicles. It uses train on-vehicle network security monitoring and situation awareness technologies to collect and store the monitoring data of the train on-vehicle network, realizing trusted aggregation and trusted monitoring of the monitoring data; and studies methods for correlation analysis and cross-verification of monitoring data, cross-domain security situation awareness, and linkage disposal. It adopts train on-vehicle network security collaborative protection strategies and mechanisms, and based on the intelligent decision-making method for multi-level security protection in the on-vehicle network environment, supports the integrated protection decision-making of equipment, control, network, data, and applications; and through a deep trusted linkage response mechanism, realizes the coordination of policy distribution and response. It adopts a system security protection framework and security assessment method based on domestic cryptographic technologies, and around typical security problems of the train on-vehicle network, constructs a comprehensive, stable, and efficient network security protection framework covering the entire life cycle of system operation to ensure the security of the train on-vehicle network. It uses technologies in the field of information security that integrate multiple industrial control systems to enable the train on-vehicle network security protection system to have fine-grained monitoring and auditing capabilities, solve real-time security early warning, provide effective event restoration capabilities, enhance the ability to analyze and investigate evidence after the event, and avoid continuous damage to the system.
[0148] The beneficial effects of this embodiment are as follows:
[0149] (1) It proposes a method for constructing a secure and trustworthy computing system architecture for train on-vehicle networks, supports the dual-system trusted startup of train on-vehicle network security devices and the dynamic measurement of real-time operation control software, and constructs a completely autonomous and controllable trusted operating environment for the train on-vehicle network system; for the first time, it applies embedded trusted computing and communication trusted computing technologies to the train on-vehicle network system.
[0150] Facing the security requirements of in-vehicle networks, based on trusted computing technology, access control technology, and communication encryption and decryption technology using lightweight cryptographic algorithms, in-vehicle network security protection is achieved; the application of the endogeneous security active defense technology of the trusted computing 3.0 dual-system architecture in in-vehicle networks is adapted to implement static trusted boot and dynamic measurement technology, achieve trusted monitoring throughout the product life cycle, and on this basis, design an in-vehicle network firewall, in-vehicle intrusion detection, log auditing system, and security management platform, and design security function extension capabilities to effectively prevent in-vehicle network security risks and ensure the safe and stable operation of in-vehicle networks; at the same time, lightweight communication encryption and decryption technology based on national cryptographic algorithms, access control technology, etc. are used to solve the trust problems of network communication and network boundaries.
[0151] (2) Construct a collaborative protection strategy for train in-vehicle network security, establish a network protection mechanism, achieve integrated collaborative protection of equipment, control, network, data, and applications, and construct a security protection architecture with intelligent defense, multi-level collaboration, and global linkage.
[0152] The main functions of the system include intrusion detection, security logs, system security, firewalls, dynamic policy library management, malicious code detection capabilities, etc., with abnormal log recording, alarm functions, and emergency response capabilities, which can be used to collect and record abnormal data, send alarms, and make response measures. The firewall policy is used to separate potential attack interfaces from the in-vehicle network, perform access control, boundary integrity checks, and malicious code prevention on the boundary; perform in-depth analysis and auditing of the traffic in the in-vehicle network, detect traffic anomalies, malicious attacks, and network intrusions, analyze anomalies based on the TRDP protocol, deploy in-vehicle monitoring and auditing through ECN switches (between information networks) at both ends of the in-vehicle information system, enable the intrusion detection function, receive mirrored network traffic, and analyze whether there are malicious attacks and intrusion behaviors against the vehicle in the network, and at the same time give different alarms based on the different levels of malicious attack and intrusion events.
[0153] (3) Adopt the high-real-time communication encryption and decryption technology of the train in-vehicle network security system, and through loading the national cryptographic algorithm engine, based on technologies such as certificate verification and key exchange, realize the communication of the train in-vehicle network based on the SSL protocol using national cryptographic algorithms.
[0154] Apply commercial cryptography technology to dynamically monitor the security system integrating network security devices and in-vehicle networks, as well as the network security situation, forming a three-dimensional vertical security guarantee system based on the coordination of commercial cryptography technology, and creating a self-controlled industrial cyber space with cryptography as its core. Adopt communication encryption and decryption technology using lightweight cryptographic algorithms. Relying on the application of commercial cryptography technology in the underlying in-vehicle network control system and security protection system, through the adoption of active information security defense technologies such as authentication, access control, and encryption technology, introduce a fixed security mechanism to ensure the confidentiality, integrity, and authentication of data frames, prevent attackers from obtaining access rights to the system, and thus effectively protect the data security of in-vehicle networks and protect communications and data from external network attacks and theft.
[0155] (4) Construct a comprehensive in-vehicle network integrated security monitoring system for trains to achieve reliable aggregation and monitoring of monitoring data, and solve the problem of the lack of in-vehicle network security monitoring means for trains.
[0156] Currently, aiming at the characteristics of complex attack techniques, diverse attack means, and concealed attack methods for industrial control networks, deploy monitoring and auditing products in bypass mode on the head and tail network switches of the train formation network. Configure all the interactive data traffic in the train communication network passing through this switch to the monitoring and auditing platform through the switch mirror port for comprehensive analysis and audit recording. Through the deployment of monitoring and auditing devices, real-time monitoring, security auditing, event tracing, professional vulnerability identification, and unknown device monitoring can be carried out.
[0157] (5) Propose a deep integration solution for the secure trusted computing architecture and in-vehicle network devices of trains to achieve integrated multi-level security linkage and global security guarantee for business processing and security protection under the secure trusted system.
[0158] Relying on the application of commercial cryptography technology in the underlying in-vehicle network control system and security protection system, through the security situation awareness and analysis system, follow the principle of "integrating resources, unifying the architecture, and business collaboration" to achieve the security situation awareness and analysis function that meets business requirements. To enhance the ability of in-vehicle networks of trains to respond to network attacks in complex environments, it is necessary to adopt big data analysis technology, threat modeling technology, and commercial cryptography encryption technology to quickly build a network security situation awareness and analysis platform. Combine traditional security situation awareness technology with the achievements of industrial control security technology to achieve security situation awareness and analysis in the business scenario of in-vehicle networks of trains, and at the same time comprehensively sort out the overall technical architecture and business process of security situation awareness and analysis.
[0159] See Figure 6, a train on-vehicle network security protection device provided by an embodiment of the present invention includes... a first acquisition module 100, a trusted computing module 200, a national cryptography algorithm module 300, an on-vehicle firewall module 400, an intrusion detection module 500, a situation awareness module 600, a second acquisition module 700, a tracing and source-tracing module 800, and an information storage module 900. The first acquisition module 100 is used to acquire on-vehicle device firmware information and an operating system image. The trusted computing module 200 is used to determine the hash value of the firmware information by using a national cryptography algorithm, and verify the hash value by using a firmware reference value pre-stored on a trusted chip to obtain a first verification result; wherein, the national cryptography algorithm includes SM2 algorithm, SM3 algorithm, and / or SM4 algorithm. The national cryptography algorithm module 300 is used to, in response to the success of the first verification result, load the operating system; perform periodic dynamic measurement on the operating system image by using the national cryptography algorithm and a dynamic measurement engine pre-installed on the trusted chip to obtain a second verification result. The on-vehicle firewall module 400 is used to, in response to the success of the second verification result, perform in-depth filtering of TRDP protocol information based on a whitelist on on-vehicle communication data by using an on-vehicle firewall to obtain filtered communication data; and encrypt the filtered communication data by using the national cryptography algorithm to obtain encrypted communication data. The intrusion detection module 500 is used to detect the filtered communication data by using a bypass mirror monitoring device to detect abnormal traffic attacks and generate threat event logs. The situation awareness module 600 is used to update the blocking policy of the on-vehicle firewall based on an on-vehicle security management center and the threat event logs, and synchronize a vulnerability blacklist with a ground security management center to obtain a dynamic defense result. The second acquisition module 700 is used to acquire system operation data of the on-vehicle device. The tracing and source-tracing module 800 is used to verify the effectiveness of the defense based on the system operation data and the dynamic defense result by using event restoration records in a security database to obtain a verification result. The information storage module 900 is used to update the dynamic measurement engine according to the verification result, and synchronize the updated dynamic measurement engine to the trusted chip for subsequent periodic verification.
[0160] In an optional embodiment, the trusted computing module 200 is specifically used to determine the hash value of the firmware information by using the SM3 algorithm built in the trusted chip, compare the hash value with the firmware reference value, and if they match, the first verification result is successful.
[0161] In an alternative embodiment, the national cryptographic algorithm module 300 includes a second verification result module and an alarm module. The second verification result module is used to monitor the integrity of the in-vehicle device memory control instruction by using the trusted chip, and encrypt the process call whitelist in the dynamic measurement engine by using the SM4 algorithm to generate a second verification result. The alarm module is used to freeze the abnormal process and generate an alarm event when the deviation between the second verification result and the dynamic measurement engine exceeds a preset first threshold, and send the alarm event to the security database.
[0162] In an alternative embodiment, the intrusion detection module 500 includes a mirror data module, a first network feature module, a feature matching module, and a log generation module. The mirror data module is used to monitor the communication data filtered by the mirror of the bypass mirror monitoring device to generate mirror data; wherein the bypass mirror monitoring device is deployed in the mirror port bypass of the in-vehicle network switch. The first network feature module is used to extract the first network features of the mirror data, and the first network features include device fingerprint features, clock offset, and communication frequency distribution features. The feature matching module is used to match the first network features with the TRDP attack features in the intrusion detection rule library to obtain a protocol feature matching result; wherein, the intrusion detection rule library is stored in the bypass mirror monitoring device. The log generation module is used to generate a threat event log in response to the protocol feature matching result being a match, input the threat event log into the security database, and generate an alarm message for alarming.
[0163] In an alternative embodiment, the in-vehicle firewall module 400 includes a parsing module, a cross-verification module, a dynamic update module, and a discard module. The parsing module is used to parse the TRDP protocol information, extract the function code, source address, and value range to generate an initial whitelist policy set. The cross-verification module is used to cross-verify the initial whitelist policy set with the vulnerability blacklist to screen and remove the risk policies to obtain a whitelist policy set. The dynamic update module is used to dynamically update the whitelist policy set according to the attack type in the threat event log. The discard module is used to discard the TRDP protocol information that violates the whitelist policy and record the discard event in the security database.
[0164] In an optional embodiment, the device also includes a monitoring and auditing module, which is connected after the mirror data module, and the monitoring and auditing module includes a second network feature module, an interaction record module, a threshold matching module and an abnormal data storage module. The second network feature module is used to extract the second network feature of the mirror data using a protocol parsing engine, and the second network feature includes a protocol function code, a device address, a timestamp feature and a data packet length distribution feature. The interaction record module generates an information interaction record based on the second network feature. The threshold matching module uses a pre-established behavior baseline model to perform dynamic threshold matching on the second network feature, and marks the communication data corresponding to the second network feature that exceeds the dynamic threshold as abnormal behavior information; wherein the behavior baseline model is obtained by using a self-learning algorithm to perform time series modeling on historical communication data, and the behavior baseline model is stored in the security database. The abnormal data storage module is used to store the information interaction record and the abnormal behavior information in the security database.
[0165] In an optional embodiment, the tracking and tracing module 800 includes an association module, an attack path topology module, a capture module, a feature analysis module, and a matching verification module. The association module is used to obtain the threat event log and the event restoration record from the security database, and associate the attack source device identifier and the operation time series. The attack path topology module is used to use the springboard host to backtrack and analyze the transit devices on the attack link to generate a preliminary attack path topology. The capture module is used to use the industrial control system honeypot pre-deployed in the vehicle network node to capture attack code samples and record injection points and vulnerability exploitation behaviors. The feature analysis module is used to decompile and sandbox behavior analysis of the attack code samples to obtain attack code features. The matching verification module is used to match and verify the attack path topology, the attack code features, and the vulnerability blacklist to obtain a verification result; the verification result includes the attack source host, the attack organization, and the attack path.
[0166] In an optional embodiment, the situation awareness module 500 includes a multi-dimensional data module, an anomaly detection module, an association analysis module and a policy update module. The multi-dimensional data module is used to obtain multi-dimensional data of the vehicle-mounted device, and the multi-dimensional data includes setting status data, network traffic characteristics and program process logs. The anomaly detection module is used to use pre-deployed probes to perform anomaly detection on the multi-dimensional data to obtain anomaly detection results. The association analysis module is used to perform association analysis and cross-validation on the anomaly detection results and the threat event logs, respectively, to achieve cross-domain security situation awareness and linkage disposal, and obtain security situation awareness results. The policy update module is used to update the blocking strategy of the vehicle-mounted firewall according to the security situation awareness results.
[0167] By using the device provided in the embodiment of the present application, since the device has the same inventive concept as the above-mentioned method provided in the embodiment of the present application, on the premise that the method can solve the technical problem, the device can also solve the technical problem, and details are not described herein again.
[0168] Referring to Figure 7 , an embodiment of the present invention further provides an electronic device 1000, including a communication interface 1001, a processor 1002, a memory 1003, and a bus 1004. The processor 1002, the communication interface 1001, and the memory 1003 are connected through the bus 1004; the above-mentioned memory 1003 is used to store a computer program that supports the processor 1002 to execute the above-mentioned train on-vehicle network security protection method, and the above-mentioned processor 1002 is configured to execute the program stored in the memory 1003.
[0169] Optionally, an embodiment of the present invention further provides a computer-readable medium having non-volatile program code executable by the processor 1002, and the program code causes the processor 1002 to execute the train on-vehicle network security protection method as described in the above embodiment.
[0170] As is known by common technical knowledge, the present invention can be implemented by other embodiments that do not depart from its spiritual essence or essential features. Therefore, the above-disclosed embodiments are illustrative in all respects and not exclusive. All changes within the scope of the present invention or within the scope equivalent to the present invention are encompassed by the present invention.
Claims
1. A method for protecting the on-vehicle network security of a train, characterized in that, Including: Obtain in-vehicle device firmware information and operating system images; Use national cryptographic algorithms to determine the hash value of the firmware information, and verify the hash value using the firmware reference value pre-stored on the trusted chip to obtain a first verification result; wherein, the national cryptographic algorithms include SM2 algorithm, SM3 algorithm, and / or SM4 algorithm; In response to the success of the first verification result, load the operating system; use the national cryptographic algorithms and the dynamic measurement engine pre-installed on the trusted chip to perform periodic dynamic measurement on the operating system image to obtain a second verification result; In response to the success of the second verification result, use the in-vehicle firewall to perform in-depth filtering of TRDP protocol information based on a whitelist for in-vehicle communication data to obtain filtered communication data; and use the national cryptographic algorithms to encrypt the filtered communication data to obtain encrypted communication data; Use a bypass mirror monitoring device to perform intrusion detection on the filtered communication data to detect abnormal traffic attacks and generate threat event logs; Update the blocking policy of the in-vehicle firewall based on the in-vehicle security management center and the threat event logs, and synchronize the vulnerability blacklist with the ground security management center to obtain a dynamic defense result; Obtain the system operation data of the in-vehicle device; Based on the system operation data and the dynamic defense result, use the event restoration records in the security database to verify the defense effectiveness to obtain a verification result; Update the dynamic measurement engine according to the verification result, and synchronize the updated dynamic measurement engine to the trusted chip for subsequent periodic verification.
2. The train on-vehicle network security protection method according to claim 1, characterized in that The use of national cryptographic algorithms to determine the hash value of the firmware information, and the verification of the hash value using the firmware reference value pre-stored on the trusted chip to obtain a first verification result includes: Use the SM3 algorithm built into the trusted chip to determine the hash value of the firmware information, compare the hash value with the firmware reference value, and if they match, the first verification result is successful; The use of the national cryptographic algorithms and the dynamic measurement engine pre-installed on the trusted chip to perform periodic dynamic measurement on the operating system image to obtain a second verification result includes: Use the trusted chip to monitor the integrity of the in-vehicle device memory control instructions, and use the SM4 algorithm to encrypt the process call whitelist in the dynamic measurement engine to generate a second verification result; When the deviation between the second verification result and the dynamic measurement engine exceeds a preset first threshold, freeze the abnormal process and generate an alarm event, and send the alarm event to the security database.
3. The train on-vehicle network security protection method according to claim 1, characterized in that The use of a bypass mirror monitoring device to perform intrusion detection on the filtered communication data to detect abnormal traffic attacks and generate threat event logs includes: Use a bypass mirror monitoring device to mirror the filtered communication data to generate mirror data; wherein the bypass mirror monitoring device is deployed in the bypass of the mirror port of the in-vehicle network switch; Extract the first network features of the mirror data, and the first network features include device fingerprint features, clock offset, and communication frequency distribution features; Match the first network feature with the TRDP attack feature in the intrusion detection rule library to obtain a protocol feature matching result; wherein, the intrusion detection rule library is stored in the bypass mirror monitoring device; In response to the protocol feature matching result being a match, generate a threat event log, input the threat event log into the security database, and generate an alarm message for alarm.
4. The train on-vehicle network security protection method according to claim 1, characterized in that The in-vehicle firewall performs in-depth filtering of the TRDP protocol information based on the whitelist for the in-vehicle communication data, and the filtered communication data obtained includes: Parse the TRDP protocol information, extract the function code, source address, and value range to generate an initial whitelist policy set; Cross-verify the initial whitelist policy set with the vulnerability blacklist to screen and remove risk policies to obtain a whitelist policy set; Dynamically update the whitelist policy set according to the attack type in the threat event log; Discard the TRDP protocol information that violates the whitelist policy and record the discard event in the security database.
5. The train on-vehicle network security protection method according to claim 3, characterized in that, After using the bypass mirror monitoring device to mirror the filtered communication data and generate mirror data, it further includes: Use a protocol parsing engine to extract the second network feature of the mirror data, and the second network feature includes protocol function code, device address, timestamp feature, and packet length distribution feature; Generate an information interaction record according to the second network feature; Use a pre-established behavior baseline model to perform dynamic threshold matching on the second network feature, and mark the communication data corresponding to the second network feature that exceeds the dynamic threshold as abnormal behavior information; wherein, the behavior baseline model is obtained by performing time series modeling on historical communication data using a self-learning algorithm, and the behavior baseline model is stored in the security database; Store the information interaction record and the abnormal behavior information in the security database.
6. The train on-vehicle network security protection method according to claim 1, wherein Based on the system operation data and the dynamic defense result, use the event restoration record in the security database to verify the defense effectiveness, and the verification result includes: Obtain the threat event log and the event restoration record from the security database, and associate the attack source device identifier and the operation time series; Use a jump host to backtrack and analyze the transit devices on the attack link to generate a preliminary attack path topology; Use the industrial control system honeypot pre-deployed in the in-vehicle network node to capture the attack code sample and record the injection point and vulnerability exploitation behavior; Decompile and perform sandbox behavior analysis on the attack code sample to obtain attack code features; Match and verify the attack path topology and the attack code features with the vulnerability blacklist to obtain a verification result; the verification result includes the attack source host, the attacking organization, and the attack path.
7. The train on-vehicle network security protection method according to claim 1, characterized in that Based on the in-vehicle security management center and the threat event log, update the blocking policy of the in-vehicle firewall, including: Obtain multi-dimensional data of the in-vehicle device, and the multi-dimensional data includes setting status data, network traffic characteristics, and program process logs; Use a pre-deployed probe to perform anomaly detection on the multi-dimensional data to obtain an anomaly detection result; The anomaly detection result and the threat event log are respectively subjected to correlation analysis and cross-validation to achieve cross-domain security situation awareness and linkage disposal, and obtain security situation awareness results; The blocking strategy of the vehicle-mounted firewall is updated according to the security situation awareness result.
8. The train on-vehicle network security protection method according to claim 1, characterized in that The method of encrypting the filtered communication data using the national secret algorithm to obtain the encrypted communication data includes: According to the confidentiality level of the filtered communication data, a multi-layer session key is generated using the national secret algorithm; The session key is stored in the trusted chip.
9. A train on-vehicle network security protection device, characterized in that, include: A first acquisition module is used to acquire vehicle-mounted device firmware information and operating system image; A trusted computing module, used to determine the hash value of the firmware information using a national secret algorithm, and verify the hash value using a firmware reference value pre-stored on the trusted chip to obtain a first verification result; wherein the national secret algorithm includes an SM2 algorithm, an SM3 algorithm and / or an SM4 algorithm; A national secret algorithm module, configured to load the operating system in response to a successful first verification result; and perform periodic dynamic measurement on the operating system image using the national secret algorithm and a dynamic measurement engine pre-installed on the trusted chip to obtain a second verification result; The vehicle-mounted firewall module is used for, in response to the success of the second verification result, using the vehicle-mounted firewall to perform deep filtering of TRDP protocol information based on the whitelist on the vehicle-mounted communication data to obtain filtered communication data; and using the national secret algorithm to encrypt the filtered communication data to obtain encrypted communication data; An intrusion detection module is used to detect filtered communication data using a bypass mirror monitoring device to detect abnormal traffic attacks and generate threat event logs; A situation awareness module, used to update the blocking strategy of the vehicle-mounted firewall based on the vehicle-mounted security management center and the threat event log, and synchronize the vulnerability blacklist with the ground security management center to obtain dynamic defense results; The second acquisition module is used to acquire system operation data of the vehicle-mounted device; A tracking and tracing module is used to verify the effectiveness of defense based on the system operation data and the dynamic defense results, using the event restoration records in the security database to obtain a verification result; The information storage module is used to update the dynamic measurement engine according to the verification result, and synchronize the updated dynamic measurement engine to the trusted chip for subsequent periodic verification.
10. An electronic device, characterized in that, The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method described in any one of claims 1 to 8 when executing the computer program.
Citation Information
Cited By
PLC behavior measurement method, device and equipment based on trusted 3.0 and national cryptographic algorithms
CN120871729A
Rail transit vehicle-ground security encryption control method and device based on national secret algorithm
CN120980522A
Asset state detection platform, asset state detection method, equipment and storage medium
CN121262118A