A railway information infrastructure security management and control system based on data processing
By deploying an integrated unit of storage, computing and transmission and three-white baseline evaluation module in the railway information infrastructure, combining software-defined network controllers, dynamically adjusting the acquisition frequency and baseline thresholds, the problem of insufficient multi-dimensional analysis in the existing technology is solved, and efficient identification of complex attacks and secure control of resource optimization is achieved.
Patent Information
- Application Number
- CN202510949350.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-10
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2045-07-10
AI Technical Summary
The existing railway information infrastructure security monitoring methods lack the ability to collaborate multi-dimensional analysis and cannot accurately capture complex attack paths. The data acquisition frequency solidification leads to waste of resources or lag in monitoring, making it difficult to efficiently process large-scale behavioral data in real time.
The integrated storage, computing and transmission unit is used to collect network behavior elements, and the timing logic verification is performed through the three-white baseline evaluation module to generate a security situation evaluation report, and the elastic defense strategy is implemented through software-defined network controllers, and the acquisition frequency and baseline threshold are dynamically adjusted in combination with the closed-loop optimization module.
It realizes deep identification of complex high-order threats and traceability of attack paths, dynamically adjusts data acquisition frequency and baseline thresholds, improves resource utilization efficiency and protection response capabilities, and outputs a structured security situation evaluation report.
Smart Images

Figure CN120434067B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of railway information infrastructure security management and control, and in particular to a railway information infrastructure security management and control system based on data processing. Background Art
[0002] With the digitalization and intelligent development of railway information infrastructure, the security threats faced by railway network systems are becoming increasingly complex. Modern railway systems rely on a large number of network devices, sensors, control systems and business application systems, involving multi-level data interactions such as device instructions, network communication environment and business operation behaviors. Due to the diverse behavior combinations and huge data volumes, traditional security monitoring methods mostly focus on a single dimension, such as abnormal instruction detection, network performance monitoring or business process tracking, and lack multi-dimensional collaborative analysis capabilities. When faced with new threats and complex and diverse attack paths, they are prone to delayed identification and missed reports. At the same time, during the data collection process, the fixed setting of the collection frequency will cause waste of system resources or monitoring lags, making it difficult to dynamically balance security monitoring and system resource consumption.
[0003] In existing technologies, centralized collection and analysis architectures can achieve centralized data management and facilitate rapid detection and alerting of some known anomalies. They have certain advantages in terms of simplicity of implementation, convenient management, and certain abnormal behavior detection capabilities. However, existing technologies lack multi-dimensional data fusion and analysis capabilities and are unable to accurately capture and restore complex attack paths. The collection frequency and dimensions of behavioral data are fixed and cannot be dynamically adjusted according to attack frequency and system load, resulting in waste of resources or risk omissions. Data compression and modeling capabilities are limited, making it difficult to process large-scale behavioral data efficiently and in real time. At the same time, they lack the ability to output key information such as attack paths and risk levels in a structured manner. Summary of the Invention
[0004] In order to solve the technical problems mentioned in the current background technology, the present invention proposes a railway information infrastructure security management and control system based on data processing.
[0005] To this end, the technical solution adopted in the present invention is as follows:
[0006] Railway information infrastructure security management and control system based on data processing, the system includes:
[0007] M1, the perception module, collects network behavior elements through the storage, computing and transmission integrated unit deployed at the edge of the railway information infrastructure network, performs security event decompression and spatial compression on the network behavior elements through the element traversal mechanism, and generates a behavior chain dataset;
[0008] M2, three white baseline assessment module, the three white baselines include white operation baseline, white environment baseline and white behavior baseline, the behavior chain dataset is subjected to temporal logic verification by the three white baselines, and a security situation assessment report including risk level and attack path is generated;
[0009] M3, a flexible defense execution module, analyzes the security situation assessment report based on the software-defined network controller and, based on the analysis results, executes the Level 4 security elastic defense strategy through the secure link reconstruction unit;
[0010] M4, a closed-loop optimization module, dynamically adjusts the verification threshold of the three white baselines and the collection frequency of the network behavior elements according to the execution effect of the defense strategy.
[0011] Furthermore, the storage, computing and transmission integrated unit is divided into a local storage sub-unit, an edge computing sub-unit and a high-speed secure communication sub-unit.
[0012] The network behavior elements include device operation instructions D, communication environment parameters P and service behavior sequence S.
[0013] Furthermore, the specific steps of the element traversal mechanism are:
[0014] 1) Collection Network behavior elements, each network behavior element Mapped into a behavioral feature vector ;
[0015] 2) Perform cluster analysis on all behavioral feature vectors using density clustering algorithm to identify A representative behavioral pattern cluster is represented as:
[0016] ;
[0017] The network behavior elements From the original Instances compressed into The K behavior patterns are further organized into a behavior chain in the order of timestamps to generate a behavior chain data set.
[0018] Furthermore, the verification formula of the white operation baseline is:
[0019] ;
[0020] in, A standard set of legal operation instructions; Indicates that the device operation instructions in behavior mode k are legal; , indicating illegality;
[0021] The verification of the white environment baseline is divided into single indicator judgment and multi-indicator joint judgment. The single indicator is verified by the Z score method, and the multi-indicator is further verified. The multi-indicator joint judgment formula is:
[0022] ;
[0023] in, is the overall trustworthiness score of the communication environment parameters in behavior pattern k, L is the total number of indicators, Indicator In the trustworthy range; when the overall trustworthiness score is less than the set score threshold, the communication environment parameters in the behavior pattern are not in the trustworthy parameter range;
[0024] The white behavior baseline verifies whether the business behavior sequence conforms to the set normal logic and timing trajectory.
[0025] Furthermore, the risk level is obtained through the sequential logic verification result of the three white baselines, and the formula is:
[0026] ;
[0027] in, is the comprehensive risk score of the network behavior elements in behavior pattern k; 、 and They are the passing rates of the three white baselines; 、 and are the weights of the white operation baseline, white environment baseline, and white behavior baseline respectively;
[0028] By means of the comprehensive risk score, a low risk level is defined , medium risk level and high risk level .
[0029] Furthermore, the attack path is obtained through a graph structure G constructed based on the behavior chain dataset. The nodes of the graph structure G are behavior patterns, and the edges are the behavior pattern sequence edges connected by time. The attack path is expressed as:
[0030] ;
[0031] in, It represents the behavior pattern of verification failure, and P is the attack path.
[0032] Furthermore, the analysis of the software-defined network controller is specifically as follows:
[0033] 1) Call the risk mapping function , converting the risk level into three types of strategy labels, expressed as:
[0034] ;
[0035] in, It’s a record label; is the access control tag; It is a blocking isolation label;
[0036] 2) Map each node in the attack path to a network node to generate an attack path link, which can be expressed as:
[0037] ;
[0038] in, is the set of attack path links, Represents a slave node To Node A single network link; Representation node The behavior of the node happened before;
[0039] The four-level security elastic defense strategy includes: Tags initiate millisecond-level link reconstruction and blocking, Tag implementation access control policy adjustment and Tags record information.
[0040] Furthermore, the training formula of the deep learning model is:
[0041] ;
[0042] in, represents the loss function; Indicates the number of training samples; Indicates the The training samples in The actual threshold adjustment value in the round of training, Indicates the The training samples in Threshold adjustment value for round prediction
[0043] The dynamic adjustment formula of the verification threshold of the three white baselines is:
[0044] ;
[0045] in, is the baseline The verification threshold for round t; is the accuracy change adjustment coefficient; is the change in detection accuracy in this round; represents a symbolic function; is the minimum acceptable range of accuracy change; is to handle delayed changes; is the maximum tolerance threshold for latency growth.
[0046] Furthermore, the collection frequency of the network behavior elements is expressed as:
[0047] ;
[0048] in, is the sampling period; the dynamic adjustment of the sampling frequency depends on the attack frequency index and resource load index, and the adjustment formula is:
[0049] ;
[0050] in, is the sampling period at time t, and They are the sampling period reduction ratio coefficient and the sampling period relaxation ratio coefficient; is the attack frequency indicator; and They are the upper and lower thresholds of attack frequency respectively; and They are the current load status of the perception module and the tolerable maximum load threshold.
[0051] Compared with the prior art, the advantages of the present invention are:
[0052] The present invention integrates multi-dimensional factors such as device operation, network environment and business behavior, compresses the behavior space through methods such as vectorization and clustering, and constructs a behavior chain that meets temporal continuity and logical correlation, thereby supporting in-depth identification of complex high-level threats and tracing of attack paths.
[0053] Through a dynamic sampling mechanism and feedback optimization, the present invention can adjust the data collection frequency and baseline threshold in real time according to the risk situation, achieving efficient and flexible protection against attacks of different intensities and types while taking into account resource utilization efficiency.
[0054] 3. This invention introduces collaborative assessment of three white baselines and graphical model attack path analysis to automatically output a structured security situation assessment report, including risk level, attack path, and three white baseline verification results, providing data support for the precise execution and continuous optimization of subsequent defense strategies. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0056] Figure 1 This is a flow chart of the railway information infrastructure security management and control system of the present invention;
[0057] Figure 2 This is a flow chart of the perception module of the present invention;
[0058] Figure 3 This is a flow chart of the three-white baseline assessment module of the present invention. DETAILED DESCRIPTION
[0059] To achieve the above objectives, the present invention is implemented through the following technical solutions: the present invention provides a railway information infrastructure security management and control system based on data processing, please refer to Figures 1 to 3 , the system comprises:
[0060] M1, the perception module, collects network behavior elements through the storage, computing and transmission integrated unit deployed at the edge of the railway information infrastructure network, decompresses the network behavior elements through the element traversal mechanism, and generates a behavior chain data set.
[0061] The perception module adopts a distributed deployment and edge intelligent processing architecture, with a core unit of storage, computing and transmission. It mainly realizes the efficient collection, feature processing, behavior chain formation and secure upload of data in the entire railway information infrastructure network.
[0062] The storage, computing and transmission integrated unit integrates three sub-units, namely the local storage sub-unit, the edge computing sub-unit and the high-speed secure communication sub-unit; the local storage sub-unit is used to temporarily cache collected data, characterization data and compressed behavior chain data, and supports looping, breakpoint resumption and batch scheduling; the edge computing sub-unit is equipped with an efficient embedded processor (such as ARM, FPGA, etc.) for on-site execution of feature calculation, event screening, statistical analysis and behavior chain generation. This sub-unit greatly reduces the volume of data to be uploaded and improves real-time warning and response capabilities; the high-speed secure communication sub-unit has a built-in gigabit network or industrial bus interface and an integrated hardware encryption module to achieve secure and fast transmission of all data to the back-end, and adopts encryption algorithms and digital signatures such as TLS / SM4 to ensure data integrity and confidentiality.
[0063] The storage, computing, and transmission integrated unit first collects network behavior elements, which include device operation instructions D, communication environment parameters P, and business behavior sequences S. In this embodiment, device operation instructions include input and output commands for on-site devices, communication environment parameters include indicators reflecting environmental stability such as network link latency, bandwidth utilization, and packet loss rate, and business behavior sequences include the time sequence and logical path of user operations such as accessing the system and completing ticket purchases. Each collected record can be abstracted as a network behavior element X, expressed as:
[0064] ;
[0065] in, Indicates the The timestamp of collecting each network behavior element.
[0066] Since there may be thousands of behavior combinations in the actual operation process, the perception module needs to use a compression mechanism to reduce computational redundancy. Therefore, the feature traversal mechanism is proposed. The core of this mechanism is to extract a set of representative behavior patterns from network behavior elements by vectorizing, similarity classification and feature fusion, thereby significantly reducing the dimension and complexity of subsequent modeling. The specific steps are as follows:
[0067] 1) Collection Network behavior elements, each network behavior element Mapped into a behavioral feature vector of uniform length , obtained through expert rule extraction (such as behavior frequency, command code type encoding, etc.) or with the help of representation learning methods in machine learning, expressed as
[0068] ;
[0069] in, Represents feature transformation processing;
[0070] 2) Perform cluster analysis on all behavioral feature vectors using density clustering algorithms (such as density-based spatial clustering DBSCAN or hierarchical density clustering HDBSCAN) to identify A representative behavioral pattern cluster is represented as:
[0071] ;
[0072] Each behavior pattern cluster represents a class of operation sequences, communication conditions or business scenarios with high similarity, which is a compressed representation of the entire behavior space, transforming the behavior space from the original Instances compressed into An abstract behavior pattern that satisfies , significantly reducing computing resource requirements.
[0073] After completing the compression of network behavior elements, the perception module will construct multiple continuous behavior sequences according to the time sequence and business logic, namely the behavior chain. The behavior chain not only reflects the order of events, but also reveals the causal relationship between operations, communications and business.
[0074] When building a behavior chain, the following two conditions must be met: temporal continuity and logical relevance. Temporal continuity means that the timestamps of each behavior pattern are in a strictly increasing relationship. Logical relevance means that adjacent behavior patterns must have a causal path at the business layer or system layer. For example, identity authentication behavior should precede order generation behavior.
[0075] The constructed behavior chain will be output as a behavior chain dataset according to unified specifications for reception and use by the three-white baseline assessment module.
[0076] M2, three white baseline assessment module, three white baselines include white operation baseline, white environment baseline and white behavior baseline, through the three white baselines to perform temporal logic verification on the behavior chain data set, generate a security situation assessment report including risk level and attack path,
[0077] The three-white baseline assessment module aims to verify the compliance and credibility of the behavior chain dataset, determine whether the network behavior conforms to the normal state, and then identify potential risks and attack paths. This module uses the white operation baseline, white environment baseline and white behavior baseline as the core logical framework to build a multi-dimensional and multi-level baseline model, and combines time series analysis with graph logic reasoning to output a structured security situation assessment report.
[0078] First, three types of baseline standards are established: the white operation baseline is a standard set of legal operation instructions, the white environment baseline is the trusted parameter range of the communication environment, and the white behavior baseline is the normal logic and timing trajectory of the business behavior sequence;
[0079] The white operation baseline is used to determine whether the device operation instructions of all behavior patterns in the behavior chain dataset comply with the defined compliance operation set. The determination formula is:
[0080] ;
[0081] in, A standard set of legal operation instructions; It indicates that the device operation instruction in behavior pattern k is legal; otherwise, it indicates an abnormality. This judgment is used to quickly identify whether there are illegal instructions such as unauthorized operation or misoperation.
[0082] The white environment baseline is used to verify whether the network communication environment is within the trusted parameter range. The verification indicators mainly include network delay, packet loss rate, bandwidth utilization, etc.
[0083] First, a single indicator is evaluated. For example, network latency is used to collect the current network latency, historical mean, and standard deviation. The Z-score method is used to calculate the degree to which the current network latency deviates from the historical normal trustworthy range. This is then compared to the set deviation threshold. If the deviation exceeds the threshold, it is considered out of the trustworthy range. Similarly, the remaining verification indicators are verified.
[0084] Then, multiple indicators are jointly judged. After each indicator is judged to be within the credible range, the overall credibility score is calculated. The formula is:
[0085] ;
[0086] in, is the overall trustworthiness score of the communication environment parameters in behavior pattern k, L is the total number of indicators, Indicator If the overall credibility score is less than the set score threshold, the communication environment parameters in the behavior pattern are not within the credibility parameter range.
[0087] The white behavior baseline is used to verify whether the business behavior sequence conforms to the normal logic and timing trajectory.
[0088] Defines the normal logic and timing traces of a business behavior sequence, where the rules represent the business behavior Must be in business conduct Previously, in the embodiment, identity authentication must be performed before order generation, and order generation must be performed before invoice printing, etc.; if there is a sequence that violates the rules in the business behavior sequence, it indicates an abnormal sequence, otherwise it is a normal sequence.
[0089] The temporal logic verification results of the three white baselines are integrated to obtain their respective pass rates and calculate the comprehensive risk score, which is expressed as:
[0090] ;
[0091] in, is the comprehensive risk score of the network behavior elements in behavior pattern k, ; 、 and They are the passing rates of the three white baselines; 、 and are the weights of the white operation baseline, white environment baseline, and white behavior baseline respectively;
[0092] In the embodiment, three risk level intervals are defined: , , , when the comprehensive risk score is in the first interval, the risk level is low risk , the second interval is medium risk , in the third interval is high risk .
[0093] After completing the sequential logic verification, we extract the path segments formed by the failed verification connections from the entire behavior chain data set based on the behavior pattern of failed verification, and construct the attack path to reflect the propagation trajectory of the attack in the behavior chain.
[0094] A graph structure G is constructed based on the behavior chain dataset. The graph nodes represent behavior patterns, and the graph edges represent the sequence of behavior patterns connected by time. In the graph structure, the graph nodes are connected to form a path, and the attack path is obtained, which is expressed as:
[0095] ;
[0096] in, It represents the behavior pattern of verification failure, and P is the attack path.
[0097] The final output is a structured security situation assessment report, including behavior chain number, three hundred baseline verification results, attack path and risk level.
[0098] M3, the flexible defense execution module, analyzes the security situation assessment report based on the software-defined network (SDN) controller and executes the Level 4 security elastic defense strategy through the security link reconstruction unit based on the analysis results.
[0099] The system is deployed with a centralized SDN controller for network management operations such as issuing flow tables, restricting access, isolating devices, and resetting paths, and establishing a southbound control channel with various railway information infrastructures.
[0100] The SDN controller receives the security situation assessment report and then parses the report content, specifically,
[0101] Calling the risk mapping function , converting the risk level into three types of strategy labels, expressed as:
[0102] ;
[0103] in, It’s a record label; is the access control tag; It is a blocking isolation label;
[0104] Map each node in the attack path to a network node to generate an attack path link, which can be expressed as:
[0105] ;
[0106] in, is the set of attack path links, Represents a slave node To Node A single network link; Representation node The behavior of the node It happened before, that is, there is a time or logical sequence in the behavior chain; after the analysis is completed, we can get who initiated the risk behavior, what the path is, and what the risk level is.
[0107] The Level 4 security protection elastic defense strategy includes initiating millisecond-level link reconstruction and blocking for high-risk attack paths, adjusting access control policies for medium-risk behaviors, and recording information for low-risk behaviors. Specifically,
[0108] When the policy tag is , enter the active isolation mode, issue blocking instructions to all attack path links, and find the shortest delay path without attack path for the affected normal business flow. The formula is:
[0109] ;
[0110] in, It is a new communication path reconstructed from the normal service flow, i.e., an alternative path that does not pass through the attack path link; Represents the set of all feasible paths after removing the attack path links from the current graph structure G; Indicates a link This path will be sent to the infrastructure as a new communication path. Mathematical optimization symbol, indicating taking the parameter value that minimizes the objective function.
[0111] When the policy tag is , implement a restrictive defense strategy, specifically, reduce communication bandwidth, limit target access sets, and enable multi-factor authentication (MFA) mechanisms to strengthen identity authentication;
[0112] When the policy tag is , does not directly intervene, and only records the following information, including attack path and link mapping, risk level and three-white baseline verification results, and communication context data.
[0113] After each defense strategy is executed, the defense effect is evaluated in real time, including multiple indicators such as strategy execution success rate, defense resource consumption, and delay changes. Based on the evaluation results, the system automatically adjusts the strategy. In the embodiment, when the strategy misjudgment rate increases, the sensitivity is improved by changing the risk level judgment interval; when the defense delay is too high, the sampling frequency is relaxed and resource allocation is optimized; when the real-time load is too high, priority is given to execution. and , to avoid network paralysis caused by excessive computing consumption
[0114] M4, a closed-loop optimization module, dynamically adjusts the verification threshold of the three white baselines and the collection frequency of the network behavior elements based on the execution effect of the deep learning model and defense strategy.
[0115] The closed-loop optimization module dynamically adjusts key parameters in the security detection and perception mechanism based on the actual execution effect of the flexible defense execution module, including the verification threshold in the three-white baseline assessment module and the network behavior element collection frequency in the perception module.
[0116] The dynamic adjustment of the verification threshold in the three-white baseline not only relies on feedback signals but also achieves intelligent optimization through deep neural networks (DNNs). The deep learning model is trained based on historical feedback data (such as changes in accuracy, latency, and attack frequency) and learns the optimal threshold adjustment strategy, that is, the adjustment range of the verification threshold.
[0117] A multi-layer fully connected neural network is used. The input layer contains the features in the historical feedback data, and the output layer is the new verification threshold. The model training process learns an optimal threshold adjustment function by minimizing the error function. The error function uses the mean square error (MSE) to measure the difference between the actual threshold and the predicted threshold. Specifically,
[0118] The three-white baseline verification includes a set of verification thresholds to determine whether it meets the normal state, expressed as:
[0119] ;
[0120] in, is the threshold for determining the legality of operations in the white operation baseline; is the threshold of the communication environment credibility in the white environment baseline; It is the threshold of the temporal legitimacy of the business behavior sequence in the white behavior baseline;
[0121] The model training process is expressed as:
[0122] ;
[0123] in, represents the loss function; Indicates the number of training samples; Indicates the The training samples in The actual threshold adjustment value in the round of training, Indicates the The training samples in The predicted threshold adjustment value is used to adjust the three-white baseline verification threshold. During the training process, the deep learning model continuously adjusts the threshold value based on historical data and the actual threshold adjustment value, and finally outputs a model that can accurately predict the threshold adjustment value.
[0124] After the deep learning model training is completed, the threshold adjustment amount is predicted based on the current status (such as accuracy change, latency change, etc.) and directly applied to the dynamic adjustment. The formula is:
[0125] ;
[0126] in, yes The validation threshold for the baseline round t; is the accuracy change adjustment coefficient; is the change in detection accuracy in this round; represents the sign function, which is used to indicate the direction of raising or lowering the threshold; is the minimum acceptable range of accuracy change; is to handle delayed changes; is the maximum tolerance threshold for delay growth;
[0127] In an embodiment, when When , it means that the detection accuracy does not meet the requirements, then , tighten the threshold, i.e. Reduce and improve detection sensitivity to reduce missed alarms and false alarms;
[0128] when , indicating that the response time exceeds the tolerance range, then , relax the threshold, that is Increase, reduce sensitivity, and avoid excessive consumption of resources.
[0129] Set the default frequency of collecting network behavior elements , expressed as:
[0130] ;
[0131] in, is the sampling period at time t, is the sampling period;
[0132] The dynamic adjustment of the sampling frequency depends on the attack frequency index and resource load index. The attack frequency index is the number of times the defense strategy is triggered within the sampling period, and the resource load index is the CPU and memory usage of the perception module. The adjustment formula is:
[0133] ;
[0134] in, is the sampling period at time t, and They are the sampling period reduction coefficient and the sampling period relaxation coefficient, which indicate that sampling is accelerated when attacks are frequent and slowed down when the load is high or the situation is stable. is the attack frequency indicator; and They are the upper and lower thresholds of attack frequency respectively; and They are the current load status of the sensing module and the tolerable maximum load threshold;
[0135] When in high frequency attack and low load, that is , indicating that there are sufficient resources to perform more frequent sampling, therefore, shortening the sampling period , that is, increase the sampling frequency , thereby improving the detection response capability and helping the system quickly identify potential attack patterns or abnormal behaviors;
[0136] When in low frequency attack or high load, that is , the sampling period needs to be extended , that is, reducing the sampling frequency , can effectively reduce resource consumption and avoid resource waste and performance degradation caused by excessively high sampling frequency. At this time, the goal of reducing the sampling frequency is to optimize resource usage and avoid unnecessary occupation of computing resources in low-threat scenarios.
[0137] By introducing a feedback regulation mechanism, the sampling frequency of network behavior elements can be adaptively adjusted according to the network attack situation and system resource status, which not only improves the detection effect, but also ensures the rational use of resources and enhances operational resilience and dynamic regulation capabilities.
[0138] The railway information infrastructure security management and control system based on data processing proposed in the present invention collects network behavior elements in real time through the integrated storage, computing and transmission unit deployed at the edge of the railway information network, compresses the behavior space through the element traversal mechanism and density clustering algorithm, and constructs a logically continuous behavior chain data set; on this basis, the three white baselines are used to verify the operational compliance, communication credibility and behavioral logic of the behavior chain in time, and generate structured risk assessment results and attack paths; then combined with the software-defined network controller to implement a four-level security elastic defense strategy, and take measures such as link reconstruction, access control, and information recording according to high, medium and low risk levels; finally, the closed-loop optimization module dynamically adjusts the detection threshold and collection frequency according to the defense effect, so as to realize the system's adaptive regulation of attack situation and resource status.
[0139] In summary, the present invention has achieved three major breakthroughs based on the traditional railway information security management and control system: first, it integrates multi-dimensional elements and temporal logic to build a behavior chain to realize dynamic identification and path tracing of complex attacks; second, it combines SDN to realize the elasticity of policy execution and network layer linkage defense mechanism; third, it introduces closed-loop optimization control based on defense feedback, which has strong scenario adaptability and operational resilience; the system as a whole improves the detection accuracy, response timeliness and resource utilization efficiency of the railway information system in the face of multi-source threats, and has good promotion and application value.
[0140] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. Railway information infrastructure security management and control system based on data processing, characterized by: The system includes: M1, the perception module, collects network behavior elements through the storage, computing and transmission integrated unit deployed at the edge of the railway information infrastructure network, compresses the network behavior elements into security event space through the element traversal mechanism, and generates a behavior chain data set. The storage, computing and transmission integrated unit is divided into a local storage subunit, an edge computing subunit and a high-speed secure communication subunit. The network behavior elements include device operation instructions D, communication environment parameters P and business behavior sequence S; M2, three white baseline assessment module, the three white baselines include white operation baseline, white environment baseline and white behavior baseline, the behavior chain dataset is subjected to temporal logic verification by the three white baselines, and a security situation assessment report including risk level and attack path is generated; M3, a flexible defense execution module, analyzes the security situation assessment report based on the software-defined network controller and, based on the analysis results, executes the Level 3 security elastic defense strategy through the secure link reconstruction unit; M4, a closed-loop optimization module, dynamically adjusts the verification threshold of the three white baselines and the collection frequency of the network behavior elements based on the execution effect of the deep learning model and defense strategy; The specific steps of the element traversal mechanism are: 1) Collection Network behavior elements, each network behavior element Mapped into a behavioral feature vector , 2) Perform cluster analysis on all behavioral feature vectors using density clustering algorithm to identify A representative behavioral pattern cluster is represented as: ; The network behavior elements From the original Instances compressed into behavior patterns, further organizing the K behavior patterns into a behavior chain in timestamp order to generate a behavior chain dataset; The analysis of the software-defined network controller is specifically as follows: 1) Call the risk mapping function , converting the risk level into three types of strategy labels, expressed as: ; in, It’s a record label; is the access control tag; It is a blocking isolation tag. 2) Map each node in the attack path to a network node to generate an attack path link, which can be expressed as: ; in, is the set of attack path links, Represents a slave node To Node A single network link; Representation node The behavior of the node Before it happened, The three-level security elastic defense strategy includes: Tags initiate millisecond-level link reconstruction and blocking, Tag implementation access control policy adjustment and Tags record information; The dynamic adjustment of the verification threshold is specifically as follows: 1) Define a set of verification thresholds in the three-white baseline verification, expressed as: ; in, is the threshold for determining the legality of operations in the white operation baseline; is the threshold of the communication environment credibility in the white environment baseline; is the threshold value of the temporal legitimacy of the business behavior sequence in the white behavior baseline, 2) Train the deep learning model. The formula is: ; in, represents the loss function; Indicates the number of training samples; Indicates the The training samples in The actual threshold adjustment value in the round of training, Indicates the The training samples in Threshold adjustment value for round prediction, 3) Based on the trained deep learning model, output the predicted threshold adjustment value to further adjust the verification threshold of the three white baselines. The formula is: ; in, is the baseline The verification threshold for round t; is the accuracy change adjustment coefficient; is the change in detection accuracy in this round; represents a symbolic function; is the minimum acceptable range of accuracy change; is to handle delayed changes; is the maximum tolerance threshold for delay growth; The collection frequency of the network behavior elements is expressed as: ; in, is the sampling period; the dynamic adjustment of the sampling frequency depends on the attack frequency index and resource load index, and the adjustment formula is: ; in, is the sampling period at time t, and They are the sampling period reduction ratio coefficient and the sampling period relaxation ratio coefficient; is the attack frequency indicator; and They are the upper and lower thresholds of attack frequency respectively; and They are the current load status of the perception module and the tolerable maximum load threshold.
2. The railway information infrastructure security management and control system based on data processing according to claim 1 is characterized in that: The verification formula of the white operation baseline is: ; in, A standard set of legal operation instructions; Indicates that the device operation instructions in behavior mode k are legal; , indicating illegality; The verification of the white environment baseline is divided into single indicator judgment and multi-indicator joint judgment. The single indicator is verified by the Z score method, and the multi-indicator is further verified. The multi-indicator joint judgment formula is: ; in, is the overall trustworthiness score of the communication environment parameters in behavior pattern k, L is the total number of indicators, Indicator In the trustworthy range; when the overall trustworthiness score is less than the set score threshold, the communication environment parameters in the behavior pattern are not in the trustworthy parameter range; The white behavior baseline verifies whether the business behavior sequence conforms to the set normal logic and timing trajectory.
3. The railway information infrastructure security management and control system based on data processing according to claim 2 is characterized in that: The risk level is obtained through the sequential logic verification result of the three white baselines, and the formula is: ; in, is the comprehensive risk score of the network behavior elements in behavior pattern k; 、 and They are the passing rates of the three white baselines; 、 and are the weights of the white operation baseline, white environment baseline, and white behavior baseline respectively; By means of the comprehensive risk score, a low risk level is defined , medium risk level and high risk level .
4. The railway information infrastructure security management and control system based on data processing according to claim 3 is characterized in that: The attack path is obtained through a graph structure G constructed based on the behavior chain dataset. The nodes of the graph structure G are behavior patterns, and the edges are the behavior pattern sequence edges connected in time. The attack path is expressed as: ; in, It represents the behavior pattern of verification failure, and P is the attack path.
Citation Information
Patent Citations
Intrusion detection and response method and system of satellite internet target range
CN119155101A
Computer information security processing method and system based on big data
CN119989353A